Open source web application framework, written in PHP
POPULARITY
Categories
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksPause All Queues and a New artisan dev UI in Laravel 13.25Read-Through Disks and Debounced Listeners in Laravel 13.26Laravel Read-Through Filesystem: Lazy Storage MigrationDebounced Queued Event Listeners in LaravelQueue::forward(): Reroute Laravel Queues in One PlaceAgent Run Observability in Laravel AI SDK 0.11Laravel AI: Trace Agent Runs With Lifecycle EventsLaravel AI: Get Raw HTTP Responses and Rate LimitsMock PHP Classes in Tests With the Double LibraryNativePHP v4: Build Native iOS and Android UI in BladeLet's Encrypt HTTPS on an IP Address With FrankenPHPStatamic Mailables Viewer Previews Laravel Emails in the Control PanelLaravel Discount: Coupon Codes, Usage Limits, and StackingLaravel Chores: Resumable Data Operations and CleanupsLaravel Tackle: Run an AI Coding Agent in Your Laravel AppTutorialsLaravel Terminal UI for the artisan dev CommandPause All Laravel Queues During a Deploy
Ian and Aaron discuss Aaron's trip to Copenhagen for Laravel Live DK, meeting DHH, having "the hell trip home", using AI to beat Air Canada's bureaucracy, and so much more.Sponsored by Bento, DropInBlog, Valorin Security, and Svix.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.(00:00) - Back In the Land of the Free (01:52) - Happy Anniversary! (04:22) - Aaron's First Intl Biz Class Flight (12:04) - Laravel Live DK (22:05) - Aaron's Talk & Meeting DHH (32:58) - DHH & Taylor's Fireside Chat (42:27) - The Spoon Is An Airplane (56:22) - The Hell Trip Home (01:17:41) - Scheming With Codex (01:27:34) - A Quick Controversy Links:Abigail Otwell's airport photo (Aaron in line behind Taylor & Abigail)Laravel Live DKDHH on Twitter/XOmacom Foundation launches with $8 million (Omarchy blog)GeocodioTom Crary on Twitter/XTaylor's video of Aaron trying caviarFlighty (iOS app)Ian's tweet of the chairs Aaron slept on
Ian is joined by Jesse Hanley, founder of Bento, to discuss everything from Grok Bot to finding your ideal customer to the future of knowledge work and so much more.Sponsored by Bento, DropInBlog, Valorin Security, and Svix.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.(00:00) - Settle All Family Business (02:04) - Grok's Bot (12:43) - AI & Knowledge Work (35:17) - How much can one person automate? (46:42) - Will normies use bots? (59:29) - Jesse's videos (01:12:17) - Growing Revenue (01:20:11) - Finding your ideal customer (01:33:56) - Cameras (01:41:51) - Life in Japan Links:Jesse Hanley / @jessethanley — founder-in-the-park videos live hereGrok "bot" agent app (xAI)OpenClaw Hermes Agent (Nous Research) Less Annoying CRMBen Orenstein Laravel Live Japan TatamiMax MRR articleHidden Multipliers (book/audiobook)Find Your Carol workshopA Smart Bear blogJason CohenSony FX30Sony a6000 (body)Tamron 17-70mm f/2.8 (Sony E)Sony 70-200mm f/2.8 GM II Sony 300mm f/2.8 GM OSS (Ian's)Kase FiltersPatrick McKenzie
Ian & Aaron discuss what's coming to Solo, how Aaron's running marketing at Laravel, why Ian swears by a cabana, and so much more.Sponsored by Bento, DropInBlog, Valorin Security, and Svix.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.(00:00) - Cabana Life (12:44) - Using Linear for Marketing (22:57) - Who's agent should you use? (33:02) - Marketing = Engineering? (45:37) - Aaron's hit tweet (56:42) - Solo Updates (01:04:27) - Laravel Live Denmark Links:Sandpearl Resort, Clearwater BeachMartha's VineyardSurf StyleJason Cohen has the DropInBlog founder on the showJason Cohen's new book, Hidden MultipliersLaracon US photosSam Sappenfield's tweet"We built laracon.us/photos. We're not developers."Aaron's codebase-audit tweetSolotermLaravel Live DenmarkAaron's DSA audit prompt gist
In this episode, Michael and Jake recap Laracon US Boston, from Malaysian food and an undefeated dodgeball run to Laraprom, the great nachos-with-rice debate, conference logistics, Aaron Francis stepping into Laravel's VP of Marketing and Community role, and a reminder to make room for silly software.Jake shares his work rebuilding Boom Party, the fast-paced Bomberman clone his team used to play after stand-up, along with hosting decisions and a creative workflow involving Claude, Gemini, and Suno.Michael closes things out with what was supposed to be an easy Pest 5 upgrade but turned into a much bigger test-suite adventure: converting old PHPUnit-style tests, untangling inheritance, tracking down mysterious parallel test failures, discovering the pain of stray exit statements, and ultimately getting repeat runs across an approximately 18,000-test suite down to just eight seconds.Show linksPomplamooseSpindriftIZZELaracon USAaron FrancisSidecarWhimsy-driven development by Christina MartinezBoom PartyFly.io
PHP Podcast – August 13, 2026 Hosts: Eric Van Johnson & John Congdon Eric and John reunite after weeks apart to talk Laracon in Boston, more diverse voices coming to this time slot, CPX finally giving PHP an npx, a stripped-down PHPStorm Light, and PHP Tek’s extended CFP. Stepping Back to Make Room for More Voices Eric and John open by explaining a shift in the show: they’re not disappearing, but they’re stepping back a little so more people from the PHP Architect team can take the mic. As John put it, the goal is “more diverse voices of the community,” and folks like Joe, Sarah, and Holly have been stepping into this time slot. Eric and John have committed to appearing at least once a month, since they have the most holistic view of what’s happening across the company. When they’re on, expect the “inside baseball” episodes — the behind-the-scenes look at what PHP Architect is up to. The rest of the time, this slot will keep going with other hosts, so the show never goes dark. They also reminded listeners there’s both a live stream and an audio RSS feed. Some folks apparently only recently discovered the audio version, while longtime audio listeners never realize the show streams live. Either way, head to phparch.com, click on podcasts, and you’ll find every way to subscribe. Eric’s Laracon Boston Recap Eric attended Laracon in Boston and, as always, has a love/hate relationship with it. On the plus side, it’s where he catches up with a lot of friends, and the talks were solid — Pauline Voss gave a great presentation on JJ (Jujutsu) and atomic commits, and Nuno showed off Pest 5. Eric noted the framework itself is moving much slower now, which is actually a good thing for anyone running a business on it, even if it makes the conference less essential-viewing than it once was. The venue was industrial and good-looking with a fantastic stage setup, but seating was a genuine problem this year. Eric arrived late to Nuno’s talk and there was nowhere to sit; the team scrambled to bring in more chairs. When it rained on day two, they ran out again. Despite that, staying in the same hotel as folks like Eric Barnes, TJ, Jake Bennett, and Michael Dorinda made for the kind of hallway-and-breakfast camaraderie he values most. Eric also hit the social events he usually skips — he sat out dodgeball (bad knees, slip-on shoes, and being a big target), but went to the Laracon Prom, which required an RSVP and an approved request. It turned out to be way cooler than expected, with people fully decked out, DJs, and an after-party plus a VIP dinner where Laravel’s marketing team worked the room. He also caught up with folks like Matthew Weier O’Phinney of Zend/Perforce and had a chat with Taylor. Running the Laravel Magazine Site and Taylor’s Blessing Eric shared that PHP Architect is now running the Laravel Magazine website, which previously belonged to Marijn (Marion) Pop. He’s been publishing tutorials, keeping things current, and making changes to the site he’s proud of. The articles are short, quick reads — and one of the Laravel wrap-up pieces mirrors the same article on the PHP Architect site. At the after-party dinner, Eric took the opportunity to run the name past Taylor directly, since he wasn’t sure the original owner had ever gotten official approval to use the Laravel name for a magazine. Taylor’s response was essentially “that’s fine, don’t worry about it” — so Laravel Magazine lives on. Eric even set up a newsletter signup, though he admits he’s not sure yet whether he’ll actually send a newsletter. CPX — A PHP-World npx One of Eric’s favorite discoveries from Laracon was CPX, essentially the PHP equivalent of npx. Just as npx lets you run JavaScript packages without installing them into a specific project, CPX lets you run tools without a global composer install or a per-project dependency. Eric already swapped his global PHP CS Fixer and Laravel Pint setup over to CPX aliases, so he now always runs the latest version without dependency headaches. John pushed back a bit, pointing out that tools like PHP unit and Rector usually live in your vendor directory anyway because your CI pipeline depends on them. Eric agreed that’s a valid workflow, but framed CPX as ideal for the occasional-use tools and for lowering the barrier for people outside the PHP world who want to dip in without fully committing. Chat chimed in with Rector as a great CPX use case, and they walked through examples like spinning up a fresh Laravel app. Laravel LSP and PHP Storm Light Eric was genuinely excited that Laravel now has its own Language Server Protocol. Most IDEs had already built their own Laravel-aware workarounds, but for Eim’s Neovim setup, the LSP finally makes things like jumping from a route to the view it points to work correctly — something PHP Storm had solved long ago but Vim hadn’t. He also spotted something called PHP Storm Light at the JetBrains booth: a trimmed-down, experimental build with faster startup, lower memory, and fewer features. It’s available through the Toolbox app as an EAP, so it’s free and explicitly experimental. John, who’d been hitting memory limits in regular PHP Storm, decided to install it on the spot, and Joe mentioned using it for one-off file edits — sparking a conversation about whether it fills the gap left by JetBrains’ old standalone editor. PHP Tek CFP Extended + Ticket Options John announced that the PHP Tek call for speakers has been extended through October 31st. The team experimented with opening the CFP very early this year to help attendees whose fiscal-year approvals depend on a locked schedule, but the community felt it was too early to know what would be relevant next April. So they extended the window and made cfp.phptek.io point straight to the call for presenters (thanks to a suggestion from A. Woods). On tickets, they’ve broken out a bundle that includes hotel nights so attendees can hand their boss a single lump-sum figure (airfare not included). There are also food-and-beverage-only tickets for partners and kids, single-day track options, and dedicated days for Laravel, JavaScript, and DevOps — one track each, with the other two tracks running the usual PHP Tek content. John flagged a possible issue with DevOps being the default CFP track, since it’s pulling in a flood of generic, seemingly AI-submitted talks he’ll need to sort through. Links from the show: PHP Tek — CFP extended through October 31, conference + hotel bundle available PHP Tek Call for Presenters OurCVEs — watch your repos and servers for CVEs Host: Eric Van Johnson X: @shocm Mastodon: @eric@phparch.social Bluesky: @ericvanjohnson.bsky.social PHPArch.me: @eric John Congdon X: @johncongdon Mastodon: @john@phparch.social Bluesky: @johncongdon.bsky.social PHPArch.me: @john Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – Eric, John, and the team are available for consulting, team augmentation, direction, code review, and even mobile development work. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. PHP Architect Consulting Your PHP codebase deserves a partner, not a contractor PHP Architect provides long-term technical partnerships for organizations that need senior-level PHP expertise that you can depend on. https://www.phparch.com/consulting/ Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post The PHP Podcast 2026.08.13 appeared first on PHP Architect.
Ian and Aaron discuss Aaron's first week as VP of Marketing & Community at Laravel, why he's writing manifestos in Notion, Ian's huge week with AI coding, and an update on Nachogate.Plus Ian's live from a cabana, ending Token Town (RIP to a real one), and so much more.Sponsored by Bento, DropInBlog, Valorin Security, and Svix.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.(00:00) - Live from a cabana (03:26) - The End of Token Town (10:39) - Aaron's First Week (28:03) - A few manifestos (44:24) - 1:1's (53:40) - Ian's Mega AI Coding Week (01:10:21) - Nachogate Update (01:12:43) - Aaron's Studio Update (01:18:25) - The next Illustrated Classics Links:Aaron's Notion setupTaylor's tweet about TrelloRands In Repose: The Update, The Vent, and The Disaster John O'Nolan's tweet indicating some discrepancies with the nacho storyGreat Illustrated Classics
Laravel любят за скорость разработки, ругают за магию и регулярно обвиняют в том, что он плодит жирные контроллеры. Вместе с Аделем Файзрахмановым – автором плагина Laravel Idea для PhpStorm и книги «Архитектура сложных веб-приложений. С примерами на Laravel» – разбираемся, что именно делает этот фреймворк лучшим на сегодняшний день способом писать код на PHP. Также ждем вас, ваши лайки, репосты и комменты в мессенджерах и соцсетях! Telegram-чат: https://t.me/podlodka Telegram-канал: https://t.me/podlodkanews Twitter-аккаунт: https://twitter.com/PodcastPodlodka Ведущие в выпуске: Евгений Кателла, Егор Толстой Полезные ссылки: Сайт Laravel https://laravel.com/ Книга «Архитектура сложных веб-приложений. С примерами на Laravel» https://github.com/adelf/acwa_book_ru
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksRouteKey Model Attribute in Laravel 13.21BindWhen Container Attribute in Laravel 13.22Monthly Log Driver in Laravel 13.23Inertia DevTools Is Now on the Chrome Web StorePest 5 Released With Test Impact Analysis, Agent Verification, and EvalsPhpStorm 2026.2 ReleasedLaravel Announces the Founders Summit, a One-Day Event for FoundersLaravel LSP: A First-Party Language Server Announced at Laracon US 2026Blade Formatting in Laravel PintLaravel AI SDK Adds Human-in-the-Loop Tool ApprovalCPX: The Composer Package Executor for PHPOfficial Laravel Zed Extension: LSP for PHP & BladeHeimdall: A Minimum Age Policy for Your Composer DependenciesQueue-SQL: Run Mass Deletes and Updates Across Parallel Queue JobsLaravel Doctor: Diagnose Your App With One Artisan CommandLaravel Head: Manage Meta Tags, Open Graph, and JSON-LDTutorialsA Practical Guide to Laravel's First-Party Image ProcessingBuilding a Live Match Scoreboard With Laravel ReverbBuilding and Deploying a Laravel App With Claude Code on Zerops
Ian and Aaron are back for a second episode this week to talk about more LaraProm & Laracon follow up, why Ian will never ship Outro (kidding), and.....adding rice to your nachos?Sponsored by Bento, DropInBlog, Valorin Security, and Svix.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.(00:00) - Aaron's First Real Day (04:38) - LaraProm -> Laracon (23:05) - Never Ship (37:33) - Nachos With Rice (47:06) - First Class Is Better (53:29) - Aaron's Sewing Machine (01:02:47) - Shower Wine Follow Up Links:Laracon US Day 1 StreamLaracon US Day 2 StreamHannah Gzehoviak on TwitterHouse of Blanks
Ian and Aaron are back after Laracon US to talk about....Aaron's new job as VP of Marketing & Community at Laravel?!Plus a recap of LaraProm, something called "shower wine", and more.Sponsored by Bento, DropInBlog, Valorin Security, and Svix.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.(00:00) - We're back, baby (01:26) - VP of Marketing & Community (14:15) - What prepared Aaron for this position? (27:31) - Grand Unifying Theory of Laravel Marketing (50:21) - What's next for Try Hard? (55:28) - Shower wine (?) (01:04:06) - The future of MT (01:16:11) - LaraProm Links:Laracon USLaravel Live UKAaron's tweet announcing his new jobChris Fidao on TwitterSoloIan's LaraProm Photos
Have you ever fixed a failing test by adding a variable to phpunit.xml and moved on, not thinking twice about whether that was actually the right call?In the latest episode of the No Compromises podcast, we discuss a real pull request disagreement about where environment variables belong and why it actually matters.We draw an important distinction between credentials and workflow configuration in your env file, and why that difference should determine exactly what goes into phpunit.xml and what stays out.We also get into why zeroing out API keys and hostnames in your test environment is not optional, and how a small oversight in one PR can quietly expose your tests to real third-party services.(00:00) - A real PR disagreement about phpunit.xml (01:07) - Credentials vs workflow config in your env file (03:17) - Why Aaron is glad his tests failed (04:49) - How to properly isolate third-party test keys (07:25) - Silly bit Come talk through decisions like these with developers who care in the No Compromises community.
The PHP Podcast – July 30, 2026 Hosts: Joe Ferguson, Sara Golemon & Holly Schilling Time travel is real, birds aren’t. The gang argues about Fahrenheit vs. Celsius, boiling rocks, and stones (the weight kind), then gets into PSR-3 logging, the PHP ecosystem, AI slop bug reports, Codeberg’s anti-AI stance, and Laravel Cloud’s scale-to-zero magic. Fahrenheit, Boiling Rocks, and Byte-Ordering Dates The show opened with Joe admitting he jumbles her hours, minutes, and seconds — and getting mocked by Europeans for a cache-control header PR on the PHP website. That kicked off a tangent about how the American month-day-year ordering is, as Sara put it, “middle-endian” nonsense that makes no sense as a byte ordering. From there the crew tumbled down a rabbit hole of measurement units. Joe planted his flag on Fahrenheit as the human-centered temperature scale, while Sara argued that if you stop being “speciesist” about it, water-based Celsius wins. The debate somehow escalated into whether rocks boil, with Google eventually schooling everyone that molten rock vaporizes north of 3,000°C (5,400°F), and a callback to British “stones” as boomer energy nobody younger than half a century actually uses. Proper Logging with PSR-3 Joe walked through Marco Pivetta’s blog post on proper logging with PSR-3, praising it as a great write-up on injecting loggers via dependency injection and the “some logs are better than no logs” philosophy. A common trap Marco calls out: apps stuffed with beautifully descriptive info-level logs that nobody ever sees because production never runs in info mode. The big selling point of sticking to a PSR-3-compatible interface is minimal dependencies — instead of pulling in three or four packages and wiring up a pile of configuration, the upstream decisions are already made for you. Holly pushed back on the ergonomics of `$this->logger->error()` feeling heavy for every log call, which spun off a delightfully unhinged RFC pitch: built-in emoji functions where the emoji logs an error and logs a panic. The Ecosystem Is Why People Stay The hosts pushed back on the recurring “PHP needs feature X because language Y has it” argument. Sara’s take: if another language is genuinely the better tool, nothing stops you from using it — and revamping PHP’s onboarding process is a far better way to attract newcomers than chasing features would-be developers may never even use. Holly cut to what everyone had glossed over: the ecosystem. You can write Swift on the server with Vapor, but you won’t have the libraries. Whatever you need in PHP, it already exists. A listener even pointed Joe at Brent Roose’s Tempest framework mid-stream to solve a code-highlighting problem on his blog. That gravitational pull of “whatever you need, it’s here” is what keeps people in the PHP orbit. AI, Layoffs, and Graybeards Sparked by Gemma’s blog post “Infrastructure and Other Paradoxes” — where an LLM cheerfully suggested folding four brand-new tools (Terraform, Nix, NixOS, Guix) into a team that’s expert in none of them — the crew dug into where AI helps and where it hurts. The consensus: AI is a force multiplier for research and analysis, but it can’t replace the human judgment of knowing what *not* to ship. Joe brought up an Inc.com article claiming 55% of leadership now regret their major layoffs, with companies like Ford rehiring graybeards because nobody left knew how the software worked. Holly noted this cycle isn’t new, just operating at a terrifying new scale, and Sara emphasized that AI accelerates shipping crap just as easily as it accelerates shipping good work — you still have to fundamentally understand the changes you’re applying. Codeberg’s Anti-AI Stance & the Slop Bug Report Problem Holly introduced Codeberg — the nonprofit, community-led GitHub alternative built on Forgejo — and its new policy banning AI/vibe-coded contributions, including a clause flagging work disproportionate to a project’s contributor count. The hosts respected the position but worried it might spell the end of Codeberg, since experienced open-source folks lean on AI tooling (like partner CodeRabbit and traditional static analyzers) as force multipliers. That led into Sara’s frustration with AI-generated security slop. Daniel Stenberg shut down Curl’s bug bounty program over reports where someone’s own test program deliberately creates RCEs and blames Curl. The fix, Sara argued, is a one-paragraph “elevator pitch” summary — and a plea to maintainers to mark every slop report as spam so GitHub eventually bans the account. The group riffed on adversarial AI (two Claude contexts checking each other, like Apple Intelligence verifying sports-game summaries) as a defensive triage layer, while acknowledging people are simply too dumb to run “double-check this before submitting.” Laracon: Laravel Cloud Scale-to-Zero Eric was off at Laracon, which meant peak morale at PHP Architect. The coolest announcement, in Joe’s view, was Laravel Cloud’s scale-to-zero: your entire stack — app server, Valkey, and MySQL — can scale down to nothing when idle and spin back up in under 500 milliseconds on the next request. That’s a potential game-changer for side projects with bursty, uneven traffic and no DevOps army. Holly and Sara were skeptical about how you cold-start a MySQL instance that fast — almost certainly a pause/resume rather than a true cold start. Other Laracon news: a Laravel language server protocol for better autocomplete and code navigation, plus managed queues that also scale to zero and only wake when a job needs firing. Links from the show: PHP Tek 2027 — Chicago, April 27–29, CFP open through end of August Join us live in Discord PHP Arch Swag Store Proper logging in PHP with PSR-3 Codeberg — Software development, but free Tempest by Brent Roose infraslopture and other paradoxes companies regret laying off humans for AI Hosts: Joe Ferguson Mastodon: @joepferguson@phpc.social PHPArch.me: @svpernova09 Sara Golemon Mastodon: @pollita@phpc.social Holly Schilling Mastodon: @TheCodeLorax@tech.lgbt Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – the team is available for consulting, infrastructure work, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. PHP Architect Consulting Your PHP codebase deserves a partner, not a contractor PHP Architect provides long-term technical partnerships for organizations that need senior-level PHP expertise that you can depend on. https://www.phparch.com/consulting/ Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post The PHP Podcast 2026.07.30 appeared first on PHP Architect.
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksHTTP Query Method Support in Laravel 13.19First-Party Image Processing in Laravel 13.20Scaffold Packages with the laravel package Command in Laravel Installer v5.31.0AI Review for Laravel UpgradesUvora: A macOS Menu Bar App for Finding Laravel ProjectsBuild a Laravel Scout Search Endpoint With the HTTP QUERY MethodLaravel MPP: Charge AI Agents for API Access with 402 Payment RequiredIntercept: Middleware Guardrails for Laravel AI AgentsPasswordless Sign-In with Fortify Two-Factor Support in LaravelLaravel Quota: Usage Budgets for Calendar PeriodsLaravel Legacy Bridge: Carry Authenticated Sessions from a Legacy App into LaravelEnforce Per-Action Waiting Periods in Laravel with CooldownVocalizer: Local Text-to-Speech for PHPTutorialsShip AI with Laravel: I Tricked My Own AI Into Leaking Everything
Ian and Aaron discuss letting Sol Ultra rip for over 2 days straight, Aaron's new side project, problems with macOS, trying to price AI usage in apps, and more.Sponsored by Bento & DropInBlog.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.Going to Laracon? Sign up for the Mostly Technical Pre-Party!(00:00) - Tim Cook's Office (06:00) - Introducing cfmpeg (12:27) - Ian & ElevenLabs (15:04) - Subscriptions In Outro (18:45) - World Cup (24:06) - Sol Ultra (28:07) - An Update on HelpSpot AI Pricing (52:04) - Aaron's Custom Model (01:07:40) - Next Week: Laracon US! (01:10:23) - Great Illustrated Classics Links:cfmpegElevenLabsGPT-5.6 SolIan on Notes on WorkHelpSpot AIToken Town Episode 008BigSkyDevConfLaracon USGreat Illustrated Classics
Have you ever let an AI agent run commands on your production server because you were stuck, telling yourself it would be fine?In the latest episode of the No Compromises podcast, we discuss why giving AI agents access to your production environment is as reckless as the bad old days of FTPing code straight to your server.We make the case that AI agents are non-deterministic and carry no responsibility, which makes them far more dangerous than a developer making a manual mistake on a live server.We also cover why you should never blindly run complex chained commands that an agent suggests, how to verify what your agent is actually doing, and why a little friction in your workflow is worth the safety it buys you.(00:00) - FTPing to production is still wrong in 2026 (01:50) - Running Tinker on production is no better (02:28) - AI agents on production servers is even worse (07:11) - How to verify what your agent is actually doing (move from 07:00) (11:03) - Silly bit Stop letting non-deterministic tools make deterministic mistakes in your codebase. Get a code review.Subscribe to our newsletter and get practical Laravel tips delivered to your inbox every day.
Michael and Jake catch up ahead of Laracon in Boston, beginning with Michael's increasingly complicated home extension. Jake shares a family trip to Cedar Point, then the conversation moves to how a Laravel Cloud weekend challenge inspired Michael to build Fitrack, a personal app for coordinating training around a single fitness goal. We then move on to home network and security upgrades, including a larger rack cabinet, a new NAS, locally accessible alarms and CCTV, Power over Ethernet cameras, Home Assistant, HomeKit, RTSP feeds, and using Claude to handle unfamiliar smart-home configuration. We also discuss Kitze hacking his NordicTrack treadmill and Michael's experience connecting his own treadmill with Apple Fitness.Finally, Michael and Jake look ahead to Laracon, discuss conference merchandise and accommodation in Boston, and finish with a conversation about donuts, candy, and the lengths parents go to when quietly disposing of their children's leftover sweets.Show linksCedar PointLaravel CloudTaylor's Laravel Cloud weekend shipping challengeEdwin's Google Meet alternativeFitrackDavid HemphillHome AssistantAqara camerasKitze's treadmill hackCaleb Porzio on code imprinting on our brainsLaracon USMoxy Boston Downtown
Ian and Aaron talk about pricing AI usage in apps, what's coming next for HelpSpot, a Jay-Z concert in NYC, and so much more.Sponsored by Bento & DropInBlog.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.Going to Laracon? Sign up for the Mostly Technical Pre-Party!(00:00) - Aaron got a ticket (06:45) - Jay-Z Concert (11:47) - World Cup Update (22:36) - Blogging & SEO (29:19) - Pricing AI Usage In Apps (43:43) - HelpSpot & AI (59:54) - GPT Sol & Fable Links:Jay-Z at Yankee StadiumClock Radio Speakers Patreon19th.comGPT Sol 5.6Token Town Episode 007
PHP Podcast – July 9, 2026 Hosts: Eric Van Johnson & John Congdon | Guest: Holly Schilling A PHP RFC for extension methods that PHP definitely should have had by now. Holly Schilling, Uninvited but Welcome Holly was originally just planning to heckle from the Discord chat room. She had about 45 minutes’ notice before the show that she’d be on camera instead, which she took in stride — minus the PHP swag shirt she would have worn if she’d known. Eric is happy to hand her the show; she’s been in the backstage feed and notes that the zero-latency view means she actually gets the jokes, unlike the 3–5 second delay that makes jokes land after everyone’s moved on. PHP Tek 2027 CFP: Now Open The call for papers for PHP Tek 2027 is open, and the deadline is end of August. This year, PHP Tek is doing three tracks: two traditional PHP-focused tracks and a third rotating track that will change each day — one day dedicated to AI talks, one to Laravel talks, one to DevOps talks. The goal is to get submissions in and the schedule published early enough that attendees can put it in their budget before their fiscal year closes. Holly (who now manages the submission review) has a note for repeat submitters: if your talk was accepted and given at a previous PHP Tek, don’t submit it again. Also: bot submissions from automated systems that spam every CFP in SessionEyes are a real problem, and Holly’s job is to filter them out before the blind evaluation round begins. The evaluation process is designed to keep Eric and John out of the loop until after the first pass — so they can’t accidentally influence votes for speakers they already like. PHP Tek 2027 Hotel + Conference Bundle Brief reprise from last week: the hotel and conference bundle is available at phptek.io — one price that includes your conference pass, hotel nights, and conference lunches and breakfasts, designed to make the ask to a manager or CFO as simple as possible. Eric is working on a short video to explain it rather than just dumping pricing on the homepage. Joe Ferguson at Merge PHP — Today Joe Ferguson — PHP Architect team member and co-release manager of PHP 8.6 — is presenting at Merge PHP immediately after this podcast wraps. His talk: “Ansible for PHP Developers: Configure, Deploy, and Update Your Infrastructure.” Eric was trying to reach Joe for an hour before the show (Joe was apparently already in the Merge PHP stream watching the podcast). If you’re listening after the fact, the recording may be available. Holly’s RFC: Class Extension Methods Holly has spent the past week doing a caffeine-fueled deep dive into PHP internals C code and has come out the other side with a draft RFC and working proof-of-concept code for class extension methods — a feature she kept assuming PHP had, tried to write, and found didn’t exist. The idea: you can add methods to an existing class without subclassing it. Swift has this, Kotlin has it, C# has it. The canonical PHP example is something like adding isWeekday() or isWeekend() to DateTimeImmutable — you get to call it as an instance method on the native class, not on a subclass you’d have to propagate everywhere. Under the hood it’s syntactic sugar: the implementation in C# is a static method with the class passed as the first parameter, and Holly is taking a similar approach. No performance penalty — a few people have already tested it. Early concern about performance impact has not materialized. The feature naturally extends to scalar methods, which Laracon’s Levi Koop and others have discussed: the ability to write $str->length() instead of strlen($str). This part is harder because $this in PHP must always be an object, so scalars need special hooks to work as receivers. That complexity is why Holly broke the implementation into three phases. She has posted GitHub Gists rather than a formal PHP wiki RFC so far — she submitted for a wiki account yesterday and is waiting to hear back. Outlook has been eating her PHP internals mailing list emails (treating new posters as spam), so she’s in the process of switching to a new email address. Joe Ferguson is in the chat offering to help expedite the wiki account. Feedback is coming in, changes are being made, and this is moving toward a formal RFC. Holly’s motivation is pure: she built this for herself because she needed it. Eric quoted himself from the “PHP Ugly Days” era, telling the community that if there’s a feature you want and nobody’s building it, it’s on you. Holly has resented and credited that line in equal measure ever since. NativePHP Mobile: Holly Is Building the Longhorn App Holly has started building a conference app for Longhorn PHP using NativePHP Mobile. Eric’s reaction ranges between excitement (someone’s doing it!) and mild betrayal (it’s not for PHP Tek). Holly also submitted a talk to Longhorn PHP about what actually distinguishes a real native mobile app from a website wrapped in an app shell — and the answer isn’t the language, the transitions, or the scroll animations. It’s state management. Native apps treat the local device copy as authoritative or at minimum authoritative enough that you’re not reaching the server for every interaction. Web apps don’t do this; native apps have to. Holly has real-world context here: one of her earlier jobs was building the Chicago Sun-Times native app and then white-labeling it for 70+ publications across the country. She says she’d never do that again. Every single publication has brand style guidelines, logo clearance zones, and color adjacency rules. Multiply that by 70 and you start to understand why white-labeling at scale is a nightmare. Longhorn PHP CFP — Closes Tomorrow The call for papers for Longhorn PHP is open through tomorrow night (July 10). It had been briefly reported as closed last week; it got extended. If you want to speak at Longhorn, head to cfp.longhornphp.com now. The conference is in Austin at the Holiday Inn. WordPress: Stewardship, Backward Compatibility, and the Laravel Fork Question Holly’s experience white-labeling apps prompted a broader conversation about WordPress — specifically a genuine acknowledgment of how technically impressive it is that a WordPress installation can look completely different from any other, at the scale WordPress operates. Eric respects the technical accomplishment but has longstanding criticism of how WordPress positioned itself in relation to the PHP community. His view: WordPress was the Laravel of its day, arguably the thing that kept PHP relevant for a decade. But rather than leaning into the broader PHP ecosystem and pushing the language forward from the inside — the way Facebook tried to (even if it eventually forked into HHVM/Hack) — WordPress was laser-focused on backwards compatibility. The result was that PHP internals couldn’t move as fast as it might have because WordPress’s enormous install base created a de facto veto on any change that would have required sites to update. Holly pushed back gently: WordPress’s backwards compatibility constraint wasn’t really a choice they could have made differently given the scale of self-hosted installs and third-party plugins. Eric acknowledges the constraint while still wishing they’d engaged more with internals. The Hack language comes up as a counterpoint: HHVM/Hack, whatever its ultimate fate, was the provocation that woke up PHP internals. PHP 7’s massive performance improvements and modern type system features largely came out of internals saying “Hack has a point, let’s do this properly.” Almost every good idea from Hack eventually got ported into PHP. Eric’s darker hypothetical: if Laravel today had an existential need for a PHP feature that internals kept rejecting, and Taylor Otwell forked PHP — that could be a genuine death blow to the ecosystem. Holly thinks the community would survive; Eric thinks the math on maintaining a language fork is nastier than it looks. Composer, Supply Chain Security, and the 48-Hour Question A viewer asked whether Composer has a way to skip packages released in the last 48 hours when running an update — the motivation being supply chain attacks, where a compromised package gets published and immediately picked up by the next composer update run. Eric’s short answer: not natively, and the real mitigation is to not run composer update blindly. Holly points out the harder version of this problem: languages like Swift allow pre-compiled binary packages, which are far scarier than source packages because you can’t even do a code review. Eric mentions that Packagist and Composer have been doing real work on supply chain integrity (covered on the show a few weeks back). If you want the deeper treatment, Eric Mann’s upcoming Security Corner column in the July issue of PHP Architect covers exactly this — Composer and the PHP supply chain. Look for it in the next few weeks. Eric’s Laptop Saga, Chapter N The new “clean install” MacBook Pro that Eric has been using to solve his connectivity issues dropped partway through the show. Eric switched to his older laptop (which was still running and still connected), but couldn’t get his camera to re-appear in the stream source list, couldn’t add himself back, and eventually gave up and wrapped up audio-only. John and Holly carried the last few minutes. The older laptop that never dropped is now, apparently, the better one. Eric is running out of explanations and considering a career in farming. Links from the show: PHP Tek 2027: Call for Speakers @ Sessionize.com PHP RFC: Extension Methods · GitHub PHP RFC: Scalar Extension Methods · GitHub php-rfc_Extensions+Visibility.md · GitHub Longhorn PHP Conference 2026 Host: Eric Van Johnson X: @shocm Mastodon: @eric@phparch.social Bluesky: @ericvanjohnson.bsky.social PHPArch.me: @eric John Congdon X: @johncongdon Mastodon: @john@phparch.social Bluesky: @johncongdon.bsky.social PHPArch.me: @john Guest: Holly Schilling PHP internals contributor; author of the Surfaces RFC and now Class Extensions RFC Primary mobile developer; built the PHP Tek 2026 conference app; building the Longhorn PHP app in NativePHP Mobile Based near Chicago, IL Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – Joe and the team are available for consulting, infrastructure work, Ansible playbooks, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel The post The PHP Podcast 2026.07.09 appeared first on PHP Architect.
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksRoute Metadata Support in Laravel 13.17Worker Metrics on the WorkerStopping Event in Laravel 13.18Help make Filament faster!Clonio CLI: Clone Production Databases With Anonymized DataA Copy/Paste Detector CLI for PHP 8.5+EnvKit: A Local Development Stack for Laravel on Windows and macOSMonitor and Control Schedules, Queues, and Errors in Laravel with WatchtowerYammi Audit Log: Track Who Really Made a Change Across Jobs and QueuesUSAIGE: Track Token Usage and Costs for Laravel AI SDK RequestsTurn PHP Attributes Into Docs With SignalLaravel WhatsApp: Two Backends Behind One Facade Laravel AI Tasks: An AI Orchestration Package for Queues, Logging, and Cost ControlTutorialsShip AI with Laravel: Failover, Queues, and Middleware for AI AgentsShip AI with Laravel: Test Your AI System with Zero API Calls
Ian and Aaron talk about saving a kid's life (!), Solo's big update, and an emerging controversy - do you still need to read the code?Sponsored by Bento & DropInBlog.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.Going to Laracon? Sign up for the Mostly Technical Pre-Party!(00:00) - Aaron Saved A Life (05:18) - No Good Comes From A Bounce House (11:40) - 4th of July Parades (15:20) - Workspaces In Solo (24:33) - Should You Still Read The Code? (40:05) - Aaron's Breakout Tweet (51:05) - Outro Update Links:Big Tex is Destroyed By FireSoloAaron's tweet about Louis CKNate BargatzeJim GaffiganFilament
PHP Podcast – July 2, 2026 Hosts: Eric Van Johnson & John Congdon Eric’s new laptop won’t share its screen. John lost a fight with a leaf blower. PHP 8.6 alpha dropped. 100+ people showed up to make PHP seem cool again. Normal show. Eric’s Fresh Install and the Screen That Wouldn’t Share Eric has been wrestling with connectivity drops for weeks, and this week he took drastic action: a fresh install on an older MacBook Pro with almost nothing on it. He installed exactly three apps — 1Password, Ghosty, and Tailscale — and is running Discord and Slack through Safari to minimize variables. The irony is immediate: the new setup can’t share its screen during the show, something that was a central part of what they planned to cover. He hits every macOS security dialog in real time, can never quite get there, and eventually gives up and goes verbal. The fresh-install theory is that one of his previously installed apps was causing his streaming dropouts. Whether it worked is TBD, but at least he stayed connected. PHP Architect July Issue — Published Live John published this month’s magazine live on the show — walked through the admin steps in real time, which Eric found appropriately chaotic. The monster feature article this month is “Building Secure REST APIs for Healthcare Applications with PHP and Laravel,” running 21–22 pages, making it likely the longest single feature they’ve ever run without splitting it across issues. The page count is mostly because of the volume of code samples. It will not be the free article of the month, which Eric admitted immediately creates extra work for John. Eric also noticed for the first time that Edward Bernard has an ad running in the magazine (Wizard’s Lens, his book) — which has apparently been there for a while. John’s Week: Leaf Blower, Racquetball, and AI Pull Requests John started the week by getting hit in the eyebrow with a leaf blower. The full story: his wife wanted the leaves blown off the top of the pergola, he figured out he could push the leaf blower up there and let gravity return it to his hand like a boomerang, it worked three times, and on the fourth attempt it went straight to the eyebrow. He’s on enough medications that he bruises instantly. He then played racquetball, found himself in an extended session with an 80-year-old and a much better 35-year-old, took a hard ball to the back of the leg, and is expecting to regret it tomorrow. On the development side: he’s still reviewing pull requests where roughly 80% of the code is written by Claude and submitted by non-developers. He talked to one of the authors about it, and the author’s response was that he does learn from John’s feedback — he reads it, tells Claude about it, and asks Claude not to do it again. John is… accepting of this. Laravel Verbs, Eloquent Hooks, and a Client Project That May Be Back A previous client project — originally built in Laravel 7, heavily involving event sourcing — may be reviving. Eric spent the last few weeks using Claude to walk the application from Laravel 7 to Laravel 13, then tackle the event sourcing library migration. The original library is no longer maintained, so Eric and Claude moved everything to Laravel Verbs. Eric has a nuanced view of Verbs: it’s great for developers new to event sourcing because it’s approachable, but gets a little murky when you start talking about projections in Laravel terms versus event sourcing terms. To police CRUD operations and ensure nothing bypasses Verbs, Claude suggested hooking into Eloquent’s lifecycle callbacks — so whenever any CRUD action is called on a model, it first fires through Verbs. Eric loved this; John had reservations, arguing it inverts the paradigm (the change causes the event rather than the event causing the change). Eric’s counterpoint: the Eloquent hook fires before the model touches the database, so Verbs still logs first, and it solves the very real problem of a developer seeing a venues table and just using the model directly. Holly, watching in the Discord chat, noted that Verbs calls the aggregate root a “state” rather than using the standard event sourcing term “root” — which is exactly the kind of terminology drift Eric finds frustrating about Verbs, even as he thinks it’s the right tool for this project. The client meeting itself went well; their CFO grasped event sourcing immediately because it maps perfectly to accounting ledgers, where every entry is permanent and any correction requires its own entry and explanation. Laracon and NativePHP Mobile Laracon is July 28–29, and Eric is going. NativePHP Mobile is holding a one-day mini-conference immediately after on July 30 — “Vibes with Native PHP” — for an additional $129. Eric is likely not staying for it due to flight constraints, but he used it as an excuse to hype NativePHP mobile again. He’s been talking about this project for a while and still hasn’t shipped a real app with it himself, which frustrates him. His pitch: if you’re a PHP developer who has ever wanted to do mobile development and found the barrier too steep, this is the moment. NativePHP is pushing more native functionality on both iOS and Android, the license fees are gone, and the project is in its second wave. There is also an ongoing campaign — which Eric is actively encouraging in this episode — to pressure Holly Schilling into building the PHP Tek conference app using NativePHP Mobile. Surfaces RFC & Friends RFC Holly’s Surfaces RFC came up briefly — Eric wanted to discuss it more but they ran out of time, mostly because Holly was busy in the Discord getting called out for doing a conference app for Longhorn PHP. The short version: the Friends RFC (in discussion) allows a class to explicitly grant another class access to its private properties without requiring inheritance — the canonical use case is a builder that needs to set private fields on an object without requiring setters, which would make those fields effectively public. Holly’s Surfaces RFC extends the idea to roles rather than just specific classes. Eric and John agree they need to have Holly on as a guest to actually discuss it properly — a plan they’ve now made twice. Chris Miller Submits a PR to PHP Core Their team member Chris Miller found a bug in the PHP JIT compiler: code that goes through the JIT was returning a different result than the same code without the JIT, specifically with the bitwise NOT operator. He opened an issue, looked at the C code, figured out the cause, and submitted a pull request to fix it. The same fix already existed for the bitwise OR and XOR operators — this PR adds the bitwise NOT. Eric loves this kind of story: a developer using PHP, noticing something odd, going all the way to the C source to understand why, and contributing a fix rather than just filing a bug. There’s a known separate JIT issue in PHP 8.5 tracing mode affecting background workers (not the main application); Eric upgraded his client’s app to 8.5 and ran into it, and believes it’s addressed in 8.5.7. PHP 8.6.0 Alpha 1 — Released Today Joe Ferguson — their friend, PHP community member, and occasional target of friendly on-air ribbing — released PHP 8.6.0 Alpha 1 today. Joe is one of the release managers for PHP 8.6, with Daniel Scherzer serving as the senior release manager (the PHP Foundation recently updated the title from “mentor”). Eric and John congratulated Joe warmly, mostly by pointing out that Chris Miller is smarter than Joe. Joe was apparently on the PHP Foundation Ambassador call as well. PHP Tek 2027: Hotel + Conference Bundle PHP Tek 2027 is doing something new this year: an optional bundle where you can buy your conference ticket and hotel stay together. Two options — three nights (Mon–Wed) or four nights (Mon–Thu). The pitch: one all-in number is easier to take to a manager or a CFO than itemizing conference pass, lunches, breakfasts, and lodging separately. Eric and John are explicit that they make less money doing it this way; the benefit is that your room is booked immediately when you pay, so you won’t forget and find rooms sold out later. Breakfast in the room is free for the first person, half price for a second person in the same room. Dinners and travel are still on you. CFPs: Find-a-Conference and Longhorn PHP Someone in the community pointed Eric to a website aggregating call-for-papers listings across conferences — not PHP-specific, and not geographically locked to the US. Useful if you’re a speaker (or want to be one) and want to see where to submit. Eric mentioned it as a resource for PHP community members to speak at non-PHP conferences, which the community generally doesn’t do enough. Specifically: Longhorn PHP’s CFP is open until July 10 at cfp.longhornphp.com. That’s one week from now as of this recording. PHP Foundation Ambassador Program Eric joined the PHP Foundation’s new Ambassador Program and attended its first meeting. He expected a modest turnout — the meeting had 114 people in the call. Three of them were from PHP Architect. Elizabeth Barron organized it and was apparently worried nobody would show up; Eric was not worried. The program’s focus is getting the word out about PHP to new developers and making the language feel more approachable — something the community has been trying to do for years without a coordinating structure. There was one slide. They talked about the slide for the whole meeting. There are multiple programs under the Foundation you can sign up for (including security-focused groups); you sign up via a Google Form, you don’t have to speak in the meetings, and it’s open to anyone regardless of PHP skill level. Eric’s one note to Elizabeth: please don’t make the coordination mechanism a mailing list. AI Note Takers — The Open Meeting Debate Eric’s AI note taker was running in the Foundation meeting, and some attendees objected. Eric is a defender of AI note takers: he gets summaries, can reference meetings later, and gets a Monday morning digest of the previous week. His position is that banning agents from an open, public meeting doesn’t prevent recording — it just means the notes disappear into the ether. For genuinely sensitive work — he describes a government-adjacent client where developers need background checks and fingerprints — he’s fully supportive of restrictions and will pull his agent without complaint. For an open PHP Foundation meeting, he finds the concern disproportionate, and says if agents are banned outright, he’d stop participating because he doesn’t have the bandwidth to rely on someone else’s notes. He also acknowledged that the irony was not lost on him: the same AI capability that makes voice recording feel threatening also makes it trivially easy to deepfake a voice regardless of whether an agent was in the room. Ethical Ads Tessa mentioned a developer-focused advertising platform called Ethical Ads on a recent Live and Kicking episode. Eric found it interesting enough to flag on the show — it’s an ad network specifically for developer-focused content that emphasizes privacy and non-tracking approaches. Eric and John are always trying to figure out better ways to promote PHP Architect, the magazine, and PHP Tek; this may be worth exploring as an alternative to standard ad networks that don’t align well with developer sensibilities. Links from the show: OurCVEs.com — Track your security posture across GitHub repos and servers (created by Artisan Build) Laravel Magazine — Under PHP Architect PHP Tek 2027 — Conference + hotel bundle available (phptek.io) Longhorn PHP CFP — Open until July 10 Ethical Ads — Developer-focused advertising PHP Tech TV — PHP Tek 2026 talks PHP Architect Discord Surfaces RFC · GitHub JIT: Inline ZEND_BW_NOT by millerphp · Pull Request #22560 · php/php-src · GitHub All active call for papers – CfP Watch The PHP Ambassador Program is Open — The PHP Foundation — Supporting, Advancing, and Developing the PHP Language The PHP Foundation Special Interest Groups General Interest Form Host: Eric Van Johnson X: @shocm Mastodon: @eric@phparch.social Bluesky: @ericvanjohnson.bsky.social PHPArch.me: @eric John Congdon X: @johncongdon Mastodon: @john@phparch.social Bluesky: @johncongdon.bsky.social PHPArch.me: @john Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – Joe and the team are available for consulting, infrastructure work, Ansible playbooks, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post The PHP Podcast 2026.07.02 appeared first on PHP Architect.
Jake shares lessons from rebuilding a permissions system around flexible roles, temporary permission leases, and delegated user management. He also discusses adding Apple Pay and Google Pay, plus designing automated text-message payment flows that use numbered choices instead of complicated keywords.Michael talks about building lender integrations, the importance of adding real context to API documentation, and using Claude to turn JSON specifications into PHP DTOs and enums. He also reflects on his team's new helpdesk rotation, where direct exposure to users has uncovered long-standing bugs, inefficient manual processes, and opportunities for developers to better understand the people using their software.They finish with the challenges of parenting teenagers, preparations for Laracon US in Boston, including a search for coffee, donuts, bagels, and cannoli. (00:00) - Club World Cup surprises and sports talk (03:12) - UFC, LeBron and basketball moves (06:33) - Rebuilding roles and permissions (08:39) - Permission leases and delegated management (10:02) - Apple Pay, Google Pay and text-based payments (11:50) - Lender integrations and better API documentation (14:08) - A new developer and the helpdesk rotation (17:13) - Automated tickets and failed queue jobs (18:54) - The address autocomplete bug (19:58) - When tiny code changes create hidden failures (23:02) - Why support requests need a real ticket (25:17) - Developers learning directly from customers (27:53) - Cross-department training and business context (30:51) - Building trust beyond Slack (32:02) - Weekly stress, workload and personal check-ins (35:18) - Parenting teenagers and setting curfews (37:10) - Planning for Laracon US in Boston (40:00) - Australian and American school calendars (42:51) - Vacations, PTO and wrapping up
Ian and Aaron discuss Ian's misadventures with poker, a huge update for Solo (Windows!), why Aaron thinks languages don't matter but frameworks & ecosystems do, and so much more.Sponsored by Laracon AU, Honeybadger, Bento, Vask, and DropInBlog.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.Going to Laracon? Sign up for the Mostly Technical Pre-Party!(00:00) - Mostly Poker (10:55) - Poker Town? (13:34) - Outro Update (20:46) - Solo for Windows (!) (30:50) - Pricing Advice (33:52) - Laravel Live UK (42:58) - Languages Don't Matter (56:09) - LaraProm Update (01:04:46) - World Cup Links:World Series of PokerResorts World Las VegasOutroSolo
PHP Podcast – June 25, 2026 Hosts: Eric Van Johnson & John Congdon Eric and John are back. Sara and Holly did a better job. Eric’s computer still hates him. Eric’s Connectivity Saga: A Possible Resolution For weeks, Eric has been dealing with a maddening streaming issue — he could see and hear everyone, but nobody could hear or see him. It only happened during Zoom, Slack huddles, and Restream sessions. No one could explain it, including Eric. The apparent fix came by accident: while helping his kid troubleshoot a similar issue, Eric pulled up his own DNS settings and discovered they were only pointing to his router with no upstream fallback. He manually added Google’s 8.8.8.8 and Cloudflare’s 1.1.1.1 — and for the first time in weeks, had zero issues all week. Does DNS explain streaming dropouts? Almost certainly not. Does it appear to have fixed it? So far, yes. Computers are stupid. Eric needs to retire and open a landscaping business. Two Weeks Off: Road Trip, Pittsburgh, and a Graduation John took the family on a road trip that included national park hikes, biking across the Golden Gate Bridge, and a swing through Universal Studios. Eric headed to Pittsburgh, technically West Virginia, for his niece’s high school graduation. Eric came away impressed with how much Pittsburgh has changed: what was once a gritty steel city has quietly become a genuinely beautiful place. He’s half-serious about looking at it as a future PHP Tek location. Sara and Holly: The Better Hosts Eric and John opened with a heartfelt thank-you to Sara Golemon and Holly Schilling for covering the last two weeks. John’s take: Sara and Holly showed up with documents, had a plan, and ran a tighter show. He’s joking about handing over the keys — mostly. PHP Architect Takes Over Laravel Magazine Here’s the announcement Eric was teasing before the break: PHP Architect has taken over the Laravel Magazine brand. It was originally a Statamic, which Eric rebuilt from scratch over the past couple of weeks. No plans to create a print magazine — it will remain a web-only publication. Eric is thinking about opening it to outside contributors, and there’s a real possibility of a dedicated Laravel column eventually appearing in the PHP Architect magazine. The new consulting section Eric built for the site looks sharp enough that John immediately pointed out it looks better than what’s currently on phparch.com. Foam Burner Feature: Proof of Concept Wars John got a big feature in Foam Burner across the finish line — or at least mostly across — recorded a screencast, and sent it off to the people who care. The immediate response: a list of compliance concerns and edge cases. This is a proof of concept. John is sympathetic, having just had to tell Eric the same thing about Laravel Magazine. The cycle of building something you’re proud of and then having someone find the things that aren’t done yet is a universal developer experience. Code Review in the Age of AI — What’s the Point? John is in a strange spot: he’s doing careful code review on pull requests written entirely by Claude, submitted by non-developers. His detailed, educational feedback — the kind meant to help a developer understand why something was done a particular way — is just being fed back into Claude to generate revisions. Nobody’s learning anything. An incident during his vacation reinforced why the reviews matter: someone deployed AI-generated code that wasn’t well reviewed, it broke overnight, and the team had to revert it the next morning. His position: keep reviewing, even if the audience is an AI. But the nature of what you’re reviewing for has to change — you’re no longer nurturing a developer; you’re being a gate. Eric’s broader point: if you’re a developer who cares about the craft, don’t let AI make you lazy. Learn from how it implements things. Ask it why. The thing that will differentiate developers when AI really matures is genuine understanding of what the code is doing — and that only comes from staying curious. PHP Generics RFC — Closed The Generics RFC was shut down while Eric and John were away, and Eric is genuinely disappointed. The proposal was for syntax-only generics: type annotations that static analyzers could read but that would be stripped at the opcode level, meaning no runtime performance impact. The goal was to standardize the generics syntax so PHPStan, Psalm, and other tools all read it the same way — right now they each implement their own dialect. Sara voted no (she explained her reasoning in the June 17 episode). Joe abstained. Whether an active abstain requires a deliberate action or is the default for a non-vote is apparently still a matter of some debate. PHP Tek 2026 Talks Now on PHP Tech TV Talks from PHP Tek 2026 are being uploaded to phptech.tv. Subscribers can watch the full library. Several speakers have given permission to make their talks free, and Ben Ramsey’s is one of them. John also added video progress tracking to the platform — it now remembers how far into a video you’ve watched. This Week in PHP Internals (Artisan Build) While looking for a PHP Internals podcast that Nuno appears to have started (possibly in connection with the PHP Foundation after PHPverse), Eric stumbled on a different show: This Week in PHP Internals, hosted on the Artisan Build site, with four episodes out. Eric doesn’t know who runs it but says it’s good — short, focused, and gets to the point. He’s also still looking for confirmation on what exactly Nuno’s new podcast is and who it’s for. For reference: the original PHP Internals podcast was Derick Rethans’ show, which he hasn’t updated in four or five years. The ecosystem growing new shows is a good sign. PHP Friends RFC — Under Discussion John has been watching the friends RFC, currently in the discussion phase. The idea: a class can explicitly declare another class as a “friend,” granting it access to private properties without requiring inheritance. The canonical use case is a builder pattern — a UserBuilder that needs to set private fields on User without a thousand public setters, and without making those fields non-private. Holly, in chat, noted that the friend model is a special case of a “surfaces” model she proposed a few years back. She also shared that Swift doesn’t have protected at all (just public and private) — something she initially found frustrating but has come to appreciate. Eric admits he’s been guilty of abusing inheritance over the years and is more thoughtful about it now. The RFC is still under discussion; no vote yet. Eric Drops PHPStorm — Falls Back in Love with Vim Eric canceled his JetBrains All Products subscription. Not because there’s anything wrong with PHPStorm — he’s explicit about that — but because he’s been doing so much work via Claude Code and making only targeted, smaller changes himself that the license fee no longer made sense. His replacement workflow: VS Code for some things, Vim for others. The Vim part was supposed to be supplemental. Instead, his terminal has taken over: it went from a panel alongside PHPStorm to taking up two-thirds of his screen to now living on its own separate virtual desktop. He’s running Spotify in the terminal. He briefly ran Slack in the terminal. He uses Tmux religiously. “I have problems,” he acknowledged. He would not take this back. Links from the show: Laravel Magazine — Now under PHP Architect PHP Tech TV — PHP Tek 2026 talks now uploading PHP RFC Wiki — All RFCs under discussion PHP Tek 2027 — April 27–29 (phptek.io) PHP Architect Discord Host: Eric Van Johnson X: @shocm Mastodon: @eric@phparch.social Bluesky: @ericvanjohnson.bsky.social PHPArch.me: @eric John Congdon X: @johncongdon Mastodon: @john@phparch.social Bluesky: @johncongdon.bsky.social PHPArch.me: @john Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – Joe and the team are available for consulting, infrastructure work, Ansible playbooks, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ PHPScore Put Your Technical Debt on Autopay with PHPScore CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post The PHP Podcast 2026.06.25 appeared first on PHP Architect.
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksJSON Schema Deserialization in Laravel 13.14Typed Translation Accessors in Laravel 13.15.0The artisan dev Command in Laravel 13.16.0The State of PHP 2026 Survey Is Now OpenLaracon US 2026 Reveals Its Full Speaker LineupHow We Cached Laravel News at the Edge with Fast LaravelWatch the Teaser for 'The Story of PHP' DocumentaryShowcase Your PhpStorm Expertise on LinkedInRefresh Your Laravel Database Without Dropping Every TableVersion-Controlled Documentation Inside Your Laravel App with LaradocsToolkit: Reusable AI Tools for the Laravel AI SDKSubscriptionify: Feature-Based Subscription Management for LaravelFilament Storage Monitor: Track Disk Usage From Your Filament DashboardLaraOwl: Self-Hosted Monitoring for Laravel ApplicationsLattice: Describe Inertia UIs in PHPMonitor Laravel Queues, Commands, and Schedulers on Any Driver with VigilancePrivacy Filter: Detect PII in Text from LaravelTutorialsShip AI with Laravel: Give Your AI Agent Live Web Search
Aaron is joined by John & Daniel of Thunk to talk about why you should think like a PM, what they want to see from Solo, trash cans in New York, "footy", and a whole lot more.Sponsored by Laracon AU, Honeybadger, Bento, Vask, and DropInBlog.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.Going to Laracon? Sign up for the Mostly Technical Pre-Party!(00:00) - Introduction to the Thunk Boys (04:13) - Working on Laravel Forge (09:22) - What does Daniel do? (14:30) - Big week for New York (22:34) - World Cup Social Media (29:13) - Laravel Live (36:33) - AI Code Responsibilities (41:52) - Think Like A PM (51:08) - Do Old Best Practices Still Apply? (58:12) - Daniel's Solo Gripes & Asks (01:20:34) - Tidy (01:24:02) - Where Is Ian? Links:ThunkTalking BusinesslyTightenLaravel ForgeLaravel Live UKLaravel Live JapanLaravel Live DenmarkSoloTidy
In this milestone 10-year anniversary episode of North Meets South, Michael and Jake reflect on a decade of podcasting, from their first awkward recordings and early Laravel community connections to the friendships, conferences, and recurring topics that have shaped the show over nearly 200 episodes. A large part of the episode focuses on Michael's work-in-progress event ticketing platform inspired by the challenges of running Laracon AU. He explains the limitations of existing conference ticketing systems, the difficulties of collecting attendee information for multiple conference-adjacent events, and his vision for a more attendee-centric system that manages profiles, dietary requirements, event registrations, and conference networks across multiple Laravel events. To wrap up, Michael and Jake discuss giving developers direct database access, the security implications of SSH access, database permissions, and Laravel filesystem configuration, including why enabling exception throwing for filesystem operations can help avoid silent failures.Show linksLaracon AULaracon US TicketTailor Transistor Laravel News PodcastNo Plans to Merge Notes on WorkTalking BusinesslyLarabelles LaraProm WalletWalletLaravel filesystem throw on fail
Ian and Aaron discuss why HelpSpot raised prices, what Aaron's building for teams with Solo, the short-lived reign of Fable 5, pros & cons of DJ's, and so much more.Sponsored by Laracon AU, Honeybadger, Bento, Vask, and DropInBlog.Interested in sponsoring Mostly Technical? Head to https://mostlytechnical.com/sponsor to learn more.Going to Laracon? Sign up for the Mostly Technical Pre-Party!(00:00) - The Great DJ Debate (07:58) - Aaron's Going To Laravel Live UK (14:22) - Ian Raised Prices (27:26) - Teams & New Solo Pricing (42:45) - New Frontiers (56:51) - RIP Fable 5 (01:09:43) - Outro's Sponsorship System Links:"Forever Young"Laravel Live UKHelpSpot PricingRIP Fable 5
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksScheduler Attributes and Listener Discovery Control in Laravel 13.12.0Bulk Job Dispatching with Bus::bulk() in Laravel 13.13The PHP Foundation Launches an Ecosystem Security TeamAegis for Laravel: Scaffolding and Validation Helpers for Value ObjectsMalware Blocking and Dependency Policies in Composer 2.10Laracon AU 2026 Announces Full Speaker Lineup, Schedule, and WorkshopsShift + AI = Fully Automated Laravel UpgradesLaravel Cloud Adds Scale-to-Zero and Spending LimitsCommunity Laravel Extension for ZedDetect and Resolve Laravel Schema Drift with MigrAlignLaravel Fluent Validation: An Object-Oriented Rule BuilderManage Subscription Plans and Entitlements in Laravel with Laravel EntitlementsPlaya: Cookie-Based Temporary Players for LaravelTyped Objects for Eloquent with ExpressiveParsel: Parse PDFs, Office Documents, and Images in PHPIn-Memory Eloquent Models with TruffleAudit Laravel Apps for Security Issues with CheckpointAdvanced Eloquent Query Filtering with FilterableScheduler List: A Web Dashboard for Laravel's Scheduled TasksGenerate Short, URL-Safe IDs From Numbers With SqidsTutorials
Michael and Jake are joined by Jason "JMac" McCreary to talk the impact of AI on Laravel Shift and modern upgrade workflows, and his latest Fast Laravel course focused on edge caching and application performance.Jason shares how Laravel Shift has evolved alongside AI-assisted development, why recent Laravel releases have changed the upgrade landscape, and why he still believes there's value in keeping applications aligned with the latest framework conventions rather than simply running composer update. The conversation explores how AI tools are influencing developer workflows, the future of upgrade automation, and new ways Shift is integrating with agentic coding tools. The second half of the episode dives deep into Fast Laravel, Jason's course on making Laravel applications dramatically faster using Cloudflare edge caching. Drawing on decades of web development experience, he explains why page caching remains one of the most effective performance techniques available, how Laravel's default stateful behaviour can prevent effective caching, and the practical steps required to achieve cache rates approaching 99% on real-world applications.Show LinksLaravel ShiftShift AI SkillsFast LaravelSeparate `static` middlewareManaged queues on Laravel CloudLaravel Cloud
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Microsoft Access VBA https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012 An Example of Stack String in High Level Language https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008 Cross-Platform NPM Stealer https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006 Laravel Lang Compromised with RCE Backdoor Across https://socket.dev/blog/laravel-lang-compromise Google API keys keep working after you delete them https://www.aikido.dev/blog/google-api-keys-deletion