POPULARITY
Categories
Today we are talking about Drush, Core Contributions, and Drupal's Past with guest Moshe Weitzman. We'll also cover Cache Metrics as our module of the week. For show notes visit: https://www.talkingDrupal.com/556 Topics Moshe Updates and Clients Maintaining Drush Long Term Locale Performance Overhaul CLI in Core Initiative Which Commands Make the Cut Roadmap Contrib Commands Moving Commands Technical Hurdles How to Help From AI Initiative DDEV Add-ons for Local CI MySQL Toolkit Database Images Testing With Real Databases Devel Module Status Organic Groups Origins Where Ideas Come From Finding Drupal Early Days Release Cadence And Backward Compatibility Avoiding Maintainer Burnout Maintaining With AI And Xdebug Resources Drush's Final Act Drupal cli issue DDEV addons https://github.com/ddev/ddev-drupal-contrib https://github.com/weitzman/ddev-mtk https://www.drupal.org/project/dtt Guests Moshe Weitzman - weitzman.github.io moshe-weitzman Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Scott Falconer - managing-ai.com scott-falconer MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted insights into how cache is working on your Drupal site? There's a module for that. Module name/project name: Cache Metrics Brief history How old: created in Oct 2019 by Moshe Weitzman (moshe weitzman), today's guest, a consistent core contributor, a member of the security team, and one of the rare few with a two-digit user id on drupal.org Versions available: 2.0.3, 2.1.0, and 2.2.0, the last of which works with Drupal 8.7.7, 9, 10, and 11 Maintainership Actively maintained Security and test coverage Documentation - in depth README Number of open issues: 2 open issues, 1 of which is a bug, but is marked fixed Usage stats: 37 sites Module features and usage With this module enabled, your Drupal site will log all cache tag invalidations Additionally, cache tag invalidations will be sent to New Relic as custom events, where you can use the rich reporting tools available to mine for further insights. Many Drupal hosting options include New Relic out-of-the-box, and there's a free tier you can use if you're self-hosting, so this a reporting tool lots of Drupal sites can use Cache hits and misses are also sent to New Relic, so you can investigate things like cache misses as a percentage by cache bin Finally, the aforementioned README also includes information about how to use a different analytics provider, in case New Relic doesn't meet your specific needs Drupal sites probably don't need this kind of visibility on a regular basis, but if you're troubleshooting any kind of cache-related issue, this could be really useful
For the annual statewide reading program ReadME, Maine authors discuss their work and offer book recommendations
Today we are talking about AI, How to stay up to date with it, and if it will really take our jobs with guests Angie Byron & Amber Matz. We'll also cover AI Best Practices for Drupal as our module of the week. For show notes visit: https://www.talkingDrupal.com/555 Topics What Is AI Learners Club Amber Defines the Club Origin Story and DrupalCon AI Debate and Community Tensions Issue Queue Conduct and Moderation Thread Tone vs Substance AI Adoption Outside Drupal Conflict Mediation Playbook Maintainer Burnout and Flood Safe Space Learners Club How the Club Started Picking Topics and Demos AI Taking Our Jobs Future of Learners Club Resources Context Control Center AI Learners Club Initiative page Event calendar YouTube Playlist Session Recaps Next session (Claude Design) Slack: #ai-learners Most wanted topics What Angie's working on these days Guests Amber Matz - tugboatqa.com amber-himes-matz Angie Byron - ai_best_practices webchick Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Scott Falconer - managing-ai.com scott-falconer MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Do you want to start using AI tools for Drupal development, in the most efficient way possible? There's a composer plugin for that! Module name/project name: AI Best Practices for Drupal Brief history How old: created in Mar 2026 by Angie Byron (webchick), one, of today's guests, a long-time Drupalist, one-time Acquian, and a fellow Canadian Versions available: dev version only, which doesn't seem directly opinionated about what version of Drupal you're using, though it does have minimum versions of PHP and Symfony libraries that suggest Drupal 10 is functionally your minimum Maintainership It is officially seeking co-maintainers Test coverage Documentation - an in-depth README, or you can ask an AI model! (like I did for this segment) 54 open "Work Items" on Gitlab, so lots of active discussion already Module features and usage AI Best Practices for Drupal aims to be the opinionated starter experience for AI-assisted Drupal development You can think of it as a single Composer install that makes any AI coding agent "speak Drupal": following community standards, preferring contrib over custom code, and avoiding framework-naive mistakes. It replaces scattered, tool-specific CLAUDE.md files and Cursor rules that some Drupal developers currently maintain individually, with one canonical, community-governed package that works across Claude Code, Cursor, Copilot, and more. With contributions by a variety of Drupal luminaries including Marcus Johansson, Christoph Briedert, and Scott Falconer, it's the Drupal equivalent of Laravel Boost: stop explaining Drupal to your AI every session and just get writing code. After install or update, it will create an AGENTS.md file from a provided template if there isn't one already, or it will update a specifically marked "ai-best-practices" section of an existing file You will also have a directory of provided skills, and guidance for creating new Drupal agent skills Also included is a set of evals, meant to automatically identify when AI models go off course and provide feedback AI Best Practices for Drupal is meant to provide guidance that will be particularly useful for AI agents, so it's ideal for Drupal developers getting started with AI tools, or for AI developers who want to get started with Drupal
El listado del disquete VOL 64 es: Presentación: 00:03:06 Autoexec.bat: 00:48:02 Adaptaciones de pelis de los 80 a videojuego : 00:49:29 Juegos – Simcity: 01:36:20 Publicidad: 01:59:59 Ese loco hardware – Sony Playstation: 02:21:52 Readme.txt: 03:38:44 Bonus track: 03:58:50 Recuerda que ya ha salido nuestro segundo libro de La Edad Oscura del videojuego español de los 90 a la venta en Amazon. Este mes comentamos unas cuantas noticias y contamos con la presencia de Kromic Bruck que nos hablará de las adaptaciones de películas de los 80 a videjuegos que podréis ampliar con su libro Movies en 8-BIT. Este mes tendremos como juego clásico el primer Simcity y veremos qué tal aguanta el paso del tiempo. Haremos una pausita para la publicidad en la que nos transportaremos a Eternia por unos instantes. En Ese loco hardware Martín Gamero nos hablará de las la Sony Playstation… Acabaremos el programa con el Readme.txt de este mes. ¡Adelante programa!
This week, we discuss how security gets sold to execs, where agentic coding and security collide, and Cloudflare vs. Datadog's diverging paths. Plus, Coté weighs in on sugar cookies. Watch the YouTube Live Recording of Episode 572 Runner-up Titles Sugar Kingdom Bastard Sugar Choose butter It's just AI now People don't like paying for software It's an exciting time to be writing software Are we going to start funding open source? Speaking of that, but not that, it's totally unrelated We're leaving the table Weird network stuff That box of cables on GitHub Rundown Security Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages Fedora Hummingbird Linux Brings Agentic Linux to Builders Red Hat Hardened Images Palo Alto Networks to Acquire Portkey to Secure the Rise of AI Agents Mythos finds a curl vulnerability Redis and the Cost of Ambition AI is restructuring the software industry — winners and losers Datadog's stock jumps 31% on crushing earnings beat Cloudflare stock sinks 24% after earnings as company cuts 1,100 employees Linear increases workforce Relevant to your Interests Laws, anecdotes, idioms, and other shit people say - cote.pizza The smart lock standard that could replace your keys is finally here dirtyfrag/README.md at master · V4bel/dirtyfrag · GitHub Red Hat Summit Newsroom Finally, texts between Android and iPhone users can be end-to-end encrypted Your Container Is Not a Sandbox OpenAI launches the OpenAI Deployment Company Corporate Card Startup Ramp Raising Funds at $40 Billion Valuation Cyberattack shutters Canvas learning platform for schools across the U.S. AWS warns of EC2 'impairment' as power loss hits notorious US-EAST-1 region AI and DevOps Maturity Anthropic raises Claude Code usage limits, credits new deal with SpaceX Announcing Agent Toolkit for AWS He's not wrong, but what can they do? How are those Microsoft foundation models going? Sponsors WebRTC.ventures – Real-time communication & Voice AI integration Conferences WeAreDevelopers Europe, July 8-10, 2026 Berlin, Coté speaking. DevOpsDays Graz, Sept 4-5, 2026 DevOpsDays Rockies, Sept. 22 – 23, 2026, Discount Code: 26DODSWEDEFTALK WeAreDevelopers NA, Sept 23-25, 2026, Discount Code: DEVPOD26 DevOpsDays Dallas, Sept 28-29, 2026 DevOpsDays Vilnius, Sep 30 - Oct 1. 2006 DevOpsDays Istanbul, October 24th, 2026 - Coté keynoting. VMware User Groups (VMUGs): Dallas (June 9-11, 2026) Orlando (October 20-22, 2026) SDT News & Community Join our Slack community Email the show: questions@softwaredefinedtalk.com Free stickers: Email your address to stickers@softwaredefinedtalk.com Follow us on social media: Twitter, Threads, Mastodon, LinkedIn, BlueSky Watch us on: Twitch, YouTube, Instagram, TikTok Book offer: Use code SDT for $20 off "Digital WTF" by Coté Sponsor the show Sponsor more podcasts with Failover Media Recommendations Brandon: Xcode MCP Matt: whatcable Coté: Shogun.
Today we are talking about The Midwest Open Source Alliance, What they do, and How they support Drupal with guests April Sides & Tearyne Almendariz. We'll also cover Canvas Field Component as our module of the week. For show notes visit: https://www.talkingDrupal.com/552 Topics Congratulations to April as the 2026 Aaron Winborn award! What is MOSA, and what gap in the Drupal ecosystem was it created to fill? How did MOSA get started, and who were the key people behind its formation? MOSA acts as a fiscal sponsor—what does that actually mean in practice for Drupal events and initiatives? What are some of the projects or camps MOSA currently supports? How does MOSA help sustain and grow regional Drupal communities over time? What does membership in MOSA look like, and who should consider getting involved? How does MOSA balance local community focus with broader, national or global Drupal efforts? What are the biggest challenges MOSA faces as a nonprofit supporting open source communities? How has MOSA evolved in recent years, and what's different today compared to when it launched? Looking ahead, what's the long-term vision for MOSA and its role in the Drupal ecosystem? Resources MOSA Website MOSA Drupal Project Aaron Winborn Handbook Moline, Illinois Guests Tearyne Almendariz - nlbcworks.com NineLivesBlackCat April Sides - weekbeforenext Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted to place Drupal-rendered fields into your Drupal Canvas templates? There's a module for that. Module name/project name: Canvas Field Component Brief history How old: created in Apr 2026 by me! With some help from a couple of AI models Versions available: 1.0.0, which works with Drupal 11.2 or newer Maintainership Actively maintained Security coverage Test coverage Documentation - a README, but is designed to be narrow in scope Number of open issues: technically 5 open issues, but all marked as fixed Usage stats: 41 sites Module features and usage By design, when using Drupal Canvas to create templates for content types, the idea is to map field values to properties in the template's components That is a new system, however, so site builders may find there are gaps in terms of available mappings for field types they need to use, or may want to draw on mature formatting options such the responsive image definitions that come with Drupal CMS With the Canvas Field Component module installed, you'll find a new "Field display" option available in your Canvas component library. When you drag that into a Canvas template layout, you can choose which field from the content type you want to display, and the formatter to use That, in turn, will expose all settings for the chosen formatter, as well as any third-party settings available, for example if using Date Augmenters with Smart Date fields Those settings will be reflected in real-time inside the Canvas UI preview, and then on rendered content once the template changes are published This module started as a simple idea, based on my own experience using other UI-based Drupal solutions for laying out content type templates, like Layout Builder or Acquia Site Studio. Over the years, I've come to appreciate the flexibility of being able to place Drupal-rendered fields into templates, so you can mix-and-match existing, robust formatting options with flexible ways of pulling field values into layouts that also include more bespoke elements. Or, just use this as a way to add more layout flexibility to Drupal's default, linear display controls. That's what I do on my own blog, where I use Layout Builder but don't have a single custom layout on the site. It's only used for enhancing the layout of structured content. Full disclosure: I also used the idea for Canvas Field Component as the impetus to venture into vibe coding, inspired by the conversations happening in the AI Learners Club, which listeners will hear more about in an upcoming episode.
你通常如何跟外國朋友介紹台灣?除了政治現況以外,怎麼好像講完台積電跟珍珠奶茶就沒了?想再多講些多元豐富的台灣文化,卻不知從何開口? 今天這位大來賓,因為過去經常被問到「哪裡可以真正了解台灣」,因此決定推動「Taiwan.md」計畫,用 SSOT、開源的概念,為台灣寫一份「README」。到底這是什麼樣的計畫?馬上來聽聽看! 歡迎今天的大來賓:新媒體藝術家、墨雨互動設計創辦人 吳哲宇
Hey friends! This week's episode is "Baby's First OpenClaw" – basically me shouting into the void hoping a smart listener will DM me and explain why this thing is supposed to be life-changing. Because right now? I'm a little underwhelmed. Here's the journey so far: The Mac mini quest: After seeing OpenClaw all over my feeds (people curing diseases! solving crimes!), I caved and impulse-bought a Mac mini. They were sold out everywhere, so I ended up paying twice what I wanted. Ick. Surprise MDM: First boot on the shiny new Mac, I found it auto-pre-enrolled in some other company's MDM with full remote control. Massive props to the Amazon seller for getting the serial untagged in Apple's database within an hour, so I could wipe and reinstall fresh. Pro tips for using Claude on projects like this: (1) give it a few paragraphs of context up front about who you are and what you want, and (2) have it maintain a README.md as you go so you don't lose context when you come back to the project later. Security-forward OpenClaw setup: Separate admin and daily-driver accounts, enable FileVault, isolate the box, run OpenClaw as a limited user, lock down Telegram so only my user ID can talk to the bot (apparently strangers have found other folks' bots and started issuing shell commands – yikes). The underwhelm: So far OpenClaw can check my email (or I can open my email app)… add a calendar event (or I can open Outlook)… write a script (or I can fire up Claude Code). And a lot of the juicier integrations are flagged as suspicious. So overall, I'm kind of gun-shy around this very expensive chat bot. This is a call for help, friends! If you're an OpenClaw power user and it's made your life meaningfully better, please reach out and help me see the light.
É quarta-feira, 8 de abril de 2026, 16h51min, hora de entrar AO VIVO e conversar com o urso Dov!https://consultorio.bitcoinheiros.com para marcar uma consulta com o nosso urso Dovhttps://loja.bitcoinheiros.com para comprar produtos dos bitcoinheiros na stackbitLinks exibidos na LIVE:Inflação Miséria e Coerçãohttps://www.youtube.com/playlist?list=PLgcVYwONyxmgTmg16MwGy02O8MlQ8HmkKBitcoin P2P e banco de dados de ataques físicoshttps://bitcoinheiros.com/kyc/https://spiketospike.com/app/loginhttps://github.com/jlopp/physical-bitcoin-attacks/blob/master/README.mdMelhorias do Bitcoin: BIP54https://x.com/narcelio/status/2041638119569535472https://bip54.org/Gravado no bloco 944234________________APOIE O CANALhttps://bitcoinheiros.com/apoie/⚡ln@pay.bitcoinheiros.com00:00 Sala de espera04:32 Introdução05:54 A utilização do dólar como arma de guerra07:42 Qual o melhor símbolo para os Satoshis?09:27 Um computador quântico pode atacar o Bitcoin?14:18 Irã exige pagamentos em Bitcoin no Estreito de Ormuz24:01 Lendo perguntas do chat30:26 Spike to Spike: A rede social P2P de Bitcoin36:20 A Spike to Spike tem boa privacidade?37:50 Trezor é uma carteira segura?46:30 O risco de ataques físicos a usuários de Bitcoin50:52 Regra de ouro: Por que você nunca deve falar sobre seus Bitcoins56:36 Casos reais de ataques físicos a Bitcoinheiros1:06:59 Como funciona a compra de BTC na Spike to Spike?1:08:17 Onde comprar Bitcoin sem KYC1:10:11 Ataques que podem travar a rede Bitcoin1:18:38 Por que o BIP54 é importante para o protocolo?1:22:41 Lendo Superchats1:23:45 Conheça a loja.bitcoinheiros.com1:24:12 Opções de plataformas P2P de Bitcoin1:25:06 Como criar um Timelock com carteiras de Bitcoin1:30:31 Claude Mythos: IA pode encontrar falhas no código do Bitcoin?1:32:51 Um Hard Fork poderia invalidar as moedas de Satoshi Nakamoto?1:35:48 É possível proibir a autocustódia de Bitcoin?1:38:35 Os EUA podem colocar Bitcoins do Irã em uma lista negra?1:42:24 Por que você DEVE sacar seus Bitcoins das corretoras agora?1:45:42 O Bitcoin pode amplificar crises financeiras globais?1:48:55 O governo dos EUA pode tomar seus Bitcoins?1:53:04 Baja más, compramos másInscreva-se em nosso canal de cortes "Bitcoinheiros HASH"https://www.youtube.com/channel/UC82m2TCXSHWcqSLym5BzjLQSe você não tem uma carteira Bitcoin ou Lightning, veja opções aqui:https://bitcoinheiros.com/projetos-recomendados/SIGA OS BITCOINHEIROS:Site: https://www.bitcoinheiros.comTwitter: https://www.x.com/bitcoinheirosISENÇÃO DE RESPONSABILIDADE:Este conteúdo foi preparado para fins meramente informativos.NÃO é uma recomendação financeira nem de investimento.As opiniões apresentadas são apenas opiniões.Faça sua própria pesquisa.Não nos responsabilizamos por qualquer decisão de investimento que você tomar ou ação que você executar inspirada em nossos vídeos.
The Brothers make a glorious Easter return to discuss the second half of the bands debut album. Buckle in, Buckle up and Buckle Down!We are part of the Deep Dive Podcast Network: https://twitter.com/DeepDivePodNetFollow us on the good old socials:Instagram:Ben: https://www.instagram.com/universallyspeakingrhcp_pod/Read ‘Me and My Friends' - The World's #1 RHCP Newsletter - Subscribe here: https://buttondown.email/rhcpsessions.Check out Red Hot Chili Riffs here: https://www.youtube.com/@RedHotChiliRiffsCheck out our Drum Ambassadors (Jack Johnson) projects here: https://www.youtube.com/channel/UCdy0pbWSOg6f8vcYnngIQ0ACheck out our Bass Ambassadors (Aidan Hampson) projects here: http://aidanhampson.co.uk/Check out friend of the pod, Dan Boyd's Pop Shock Podcast - for all your pop culture needs! Audio: https://anchor.fm/popshockpod / Video: https://youtube.com/channel/UCHY5pXX_x7Kv4e8wJmHoK5AFor your vinyl needs please shop at Black Star Records: https://www.blackstarrecords.co.uk and Black Wax Coffee and Records: https://blackwaxcoffee.co.uk/
我在KTV的开场必须要唱《三人游》。《橙月》不愧是方大同说尝试写得更通俗的专辑,这首歌刚好处于一个入门和进阶之间的水平:说它难,它比方大同各种找不到调的桥段确实简单许多;说它简单,你却很难一个音不差地把它唱下来。于是,用它作为KTV开场最好了,唱过《三人游》就能进入一个“ready”的状态。 由于我每次都在KTV里用《三人游》开场,所以很多跟我K过歌的朋友都以为我是方大同的铁粉。我固然算是粉丝,但铁粉还实在是愧不敢当——在很长一段时间里,我能唱出调的歌都来自《橙月》这一张专辑。是的,如果要将方大同的生涯分为几个阶段,我最爱的还是他更偏向neo soul的早期;在得知他离世的消息之前,我一直在对他的最后一张专辑做出非常“客观”的中评,我固然反对“嗓子不好就不要唱”的论调,但也十分认同,人声严重地拖累了他的表现。 2025年3月1日是一个周六,那天外地的表弟来京。看到赋音乐发布的讣告时,我正陪他走在东四北大街上。近几年来总是看到代表某一时期记忆的人物离世的消息,让人不禁觉得“原来自己也到了这样一个人生阶段”,不免有些习惯也有些麻木,饶是这样,在看到那条消息之后,我还是掉线了几分钟的。然后,2025年,我的Spotify收听次数最多歌曲前十名中,有8首来自方大同。 音乐和视频真是奇妙,在我看方大同大量的搞怪视频、听他过去的音乐作品时,很难想象他已经离开了这个世界;我一直避免打开《梦想家》专辑相关的Vlog,包括他在Hopico的最后一次采访,仿佛这样就能回避他已经离开这个世界的事实。 《梦想家》中,我听的最多的歌并非《才二十三》,而是《回留》。打开B站,你能找到大量“听感优于方大同本人”的演绎版本,包括用AI制作的“方大同全盛时期嗓音”版。而待到一切都发生之后,才会发现所谓“回留”的真正含义,他“残破”的声音也都具备了别样的意义。如果要我来安排节目的曲序,我会把这首歌当做方大同本人演绎音乐作品的压轴。 就像我前面说的,我算是方大同的粉丝,但算不得太合格的粉丝。于是我和小马也只能尽我们所能来聊聊我们心目中的方大同。本期节目,我们将继续向各位放送方大同本人演绎及为他人创作、制作的音乐作品。 *** 本期歌单 1. 方大同 – 很不低调 @ JTW 西游记 (Gold) (2016) 2. 方大同 – 云南里 (2018) 3. 薛凯琪 – 回留 [Live] @ 薛凯琪2025「Let Me Love You」巡回演唱会上海站 (2025) 4. 薛凯琪 – 慕容雪 @ Read Me (2009) 5. 阿朵 – 扯谎哥 @ 阿朵《死里复活》秀 录音室版原声专辑 (2017) 6. 林海峰 – 我要爱死方大同 @ Yes, I…Do (2009) 7. 卢广仲 – 死在你的胸怀 @ HeartBreakFast 伤心早餐店 (2025) 8. 方大同 – 没啥好说 @ 梦想家 The Dreamer (2024)
El listado del disquete VOL 63 es: Presentación: 00:02:48 Autoexec.bat: 00:04:27 Noticias: 00:05:55 Juegos – Castle Adventure: 00:47:38 Review – El Sulfato Atómico: 01:16:50 Publicidad: 01:25:10 Ese loco hardware – Placas de Sega: 01:28:22 Readme.txt: 02:19:23 Bonus track: 02:43:33 Recuerda que ya ha salido nuestro primer libro de La Edad Oscura del videojuego español de los 90 a la venta en Amazon. Este mes comentamos unas cuantas noticias, como la salida al mercado de la 4ª época de la revista Micromania, la nueva versión de DR-DOS en pleno 2026 o la comercialización de un remake de Defender of The Crown. Logaran comenta, junto a los audios de los miembros del Club que lo han probado, el juego del mes, Castle Adventure. Hablaremos de la versión para Nintendo Switch de Mortadelo y Filemón: El Sulfato Atómico publicado por Ratalaika Games. En Ese loco hardware Martín Gamero nos hablará de las placas de Sega y divagaremos un rato… Acabaremos el programa con el Readme.txt de este mes. ¡Adelante programa! Agradecemos en este episodio a: Sonia Chaves (@DubbingSonia) por su voz para las cortinillas. Canal de Sonia en Ivoox: Órbita Arrakis. Web de Sonia: soniachaves.es. Xabi San Martín (@laorejadevgogh): Por la sintonía «Tino's Theme» del programa. Christian Jacobsen (@ch_jacobsen): Por el cover metalero de Tino's Theme. Dani Nevado (@DanySnowyman): Por el logo del programa. Javier Sancho (@kalzakath1): Por su dedicación y participación y editar esto. Antonio Lozano (alias Logaran): Por ser el ayatolá de la emulación y un tío cojonudo. Martin Gamero (@3dfxlegacy): Por su sección de «Ese loco hardware». A los productores de este podcast en Patreon: Alfonso, MrZapato_hdfg10, iXuacu, Marcelo García, Marcos Hernández. Al resto de gente que nos echa una mano para que esto no nos cueste dinero y a la gente que nos escucháis y apoyáis recomendando el programa y comentando.
Neste episódio comentamos sobre as principais atualizações e desafios no mercado de tecnologia, trazendo uma análise objetiva sobre cibersegurança e proteção de dados. Ao longo da reprodução, você irá descobrir os recentes desdobramentos éticos do uso de inteligência artificial em contextos militares, envolvendo a recusa da Anthropic em aderir aos termos do Departamento de Defesa norte-americano e os impactos disso para a privacidade global. Você também irá aprender sobre o novo marco regulatório do Conselho Federal de Medicina para ferramentas automatizadas na área da saúde, compreendendo como as exigências da LGPD se aplicam à segurança da informação na proteção de dados médicos sensíveis. Além disso, você entenderá os detalhes do recente ataque hacker que causou graves incidentes de segurança no setor financeiro, e saberá identificar as vulnerabilidades críticas na integração de modelos de linguagem via protocolo MCP, como a perigosa injeção de prompts em servidores expostos. O host Guilherme Goulart compartilha ainda sua vivência no evento SecOps Summit, refletindo sobre a importância dos profissionais de segurança na governança corporativa. Por fim, você poderá avaliar como o uso excessivo do ChatGPT pode afetar a criatividade e gerar a homogeneização do pensamento. Para continuar acompanhando nossas discussões, não se esqueça de assinar o podcast na sua plataforma preferida, seguir nossos perfis nas redes sociais e avaliar o programa para apoiar o nosso trabalho. Esta descrição foi realizada a partir do áudio do podcast com o uso de IA, com revisão humana. Visite nossa campanha de financiamento coletivo e nos apoie! Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing Acesse WhisperSafe – Transcreva áudio e grave reuniões direto no seu computador, mesmo offline. Rápido, leve e pronto para usar com qualquer IA. Use o cupom SEGLEG50 para 50% de desconto na sua assinatura. ShowNotes Episódio citado – 2013-06-18 – Episódio #28 – PRISM – Privacidade X Segurança The Pentagon formally labels Anthropic a supply-chain risk Anthropic's Claude is suddenly the most popular iPhone app following Pentagon feud Anthropic vs. U.S. Department of War The Pentagon Can't Afford This A.I. Fight Statement from Dario Amodei on our discussions with the Department of War Employees across OpenAI and Google support Anthropic's lawsuit against the Pentagon AI safety leader says ‘world is in peril’ and quits to study poetry Microsoft & Anthropic MCP Servers at Risk of RCE, Cloud Takeovers AI Conundrum: Why MCP Security Can’t Be Patched Away MCP is the backdoor your zero-trust architecture forgot to close Ministério da Educação – REFERENCIAL PARA DESENVOLVIMENTO E USO RESPONSÁVEIS DE INTELIGÊNCIA ARTIFICIAL NA EDUCAÇÃO Nova resolução de uso de IA na CFM Artigo “When ChatGPT is Gone: Creativity Reverts and Homogeneity Persists“ BTG Pactual restabelece operações via Pix após ser alvo de ataque hacker BTG Pactual sofre ataque hacker e suspende operações via Pix PF investiga participação de funcionários no ataque hacker de R$ 100 milhões ao BTG Pactual Imagem do Episódio: A Torre de Babel — Pieter Bruegel
Gros zoom sur les skills et leurs usages dans les coding agents, sur les benchmarks de stacks techniques MCP, mais aussi du Java 26-27, du HttpClient, du NodeJS, des scenarios nucléaires pilotés par l'IA, de la méthodologie, bref on ne s'ennuie pas ! Enregistré le 15 mars 2026 Téléchargement de l'épisode LesCastCodeurs-Episode-338.mp3 ou en vidéo sur YouTube. News Langages Bruno Borges a créé un site, inspiré d'un site récent qui montrait comment CSS avait évolué, qui illustre justement comment Java a bien évolué au fil du temps, et est devenu un langage encore plus élégant https://javaevolved.github.io/ Code simplifié: main() allégé, var, blocs de texte, API String enrichie. Pattern Matching: switch sur types, instanceof amélioré, record patterns. Données: Records, collections immuables faciles à créer, méthodes de listes. Concurrence: Threads virtuels, CompletableFuture, StructuredTaskScope, ScopedValue. Erreurs & Sécurité: NPE précis, catch multiples, Optional amélioré, filtres de désérialisation. I/O & Réseau: HttpClient moderne, E/S fichiers/console simplifiées, transferTo. Dates & Heures: API modernisée, précise, immutables et thread-safe. Langage: Interfaces sealed/private, import de modules, Math.clamp Streams: Nouveaux opérateurs (takeWhile, mapMulti, Gatherers, teeing). Outils & Perf: jshell, exécution simplifiée, jwebserver, AOT, JFR, optimisation mémoire. 10+ raisons de ne pas utiliser le HttpClient du JDK, avec un article très détaillé de Brice Dutheil https://blog.arkey.fr/2026/02/08/ten-reasons-to-not-use-jdk-httpclient/ JDK HttpClient: intégré, non-upgradable. OkHttp: plus lourd (dépendance Kotlin). TLS/SSL: JDK: SSLContext limité, vérif hôte globale, épinglage manuel, SSLParameters rigides. OkHttp: contrôle fin (SSLSocketFactory/TrustManager), vérif hôte/épinglage dédiés, ConnectionSpec structuré. Connexions: JDK: pas de repli, fabrique socket custom impossible (pas UDS/Named Pipes direct), pool limité (propriétés système, contrôle pauvre avant JDK 20/21). OkHttp: repli automatique, fabrique custom, pool granulaire. Réseau: JDK: résolveur DNS par défaut, Authenticator unique. OkHttp: résolveur DNS custom, authentificateurs séparés (proxy/serveur). Cycle Requêtes: JDK: pas d'intercepteurs ni API événements intégrés. OkHttp: addInterceptor, EventListener pour événements granulaires. Ressources: JDK: pas d'arrêt propre avant JDK 21. OkHttp: arrêt granulaire (pool, exécuteur, cache). Timeout: JDK: désactivé après en-têtes; le transfert du corps peut dépasser le timeout initial. JDK 26 et JDK 27 : ce qui nous attend — https://www.infoq.com/news/2026/02/java-26-so-far/ JDK 26 est une version non-LTS prévue le 17 mars 2026, avec 10 nouvelles fonctionnalités réparties en 5 catégories Le support HTTP/3 arrive enfin dans l'API HTTP Client standard de Java (JEP 517) La Structured Concurrency (projet Loom) en est à sa 6e preview, avec l'ajout d'une méthode onTimeout() sur StructuredTaskScope.Joiner Les Lazy Constants passent en 2e preview : des constantes initialisées à la demande, utiles pour optimiser le démarrage Le G1 GC gagne en performance via une réduction des synchronisations entre threads applicatifs et threads GC (JEP 522) Le cache d'objets AOT (JEP 516) est étendu pour fonctionner avec n'importe quel GC, y compris ZGC L'API Applet est définitivement supprimée (JEP 504), fermant une page historique de Java L'encodage PEM des objets cryptographiques continue sa preview avec support de chiffrement/déchiffrement de KeyPair Pour JDK 27 (septembre 2026), l'échange de clés post-quantique hybride pour TLS 1.3 est déjà ciblé (JEP 527) Project Valhalla progresse avec une preview des Value Classes : objets sans identité, à champs final uniquement Librairies Une étude de performance montre que Java est un super choix pour développer des serveurs MCP https://www.tmdevlab.com/mcp-server-performance-benchmark.html Comparaison de performances de serveurs MCP (Model Context Protocol) en Java, Go, Node.js, Python. Méthodologie: 3,9 millions requêtes, environnement Docker (1 cœur CPU, 1 Go RAM/serveur). Fiabilité: 0% d'erreurs pour toutes les implémentations. Tiers de performance: 1 (Haute): Go & Java (latence < 1ms, ~1600 requêtes/s). ▪︎ Go: Efficacité mémoire exceptionnelle (18 Mo vs 220 Mo pour Java). ▪︎ Java: Latence marginalement meilleure, mais 12x plus de mémoire. 2 (Moyenne): Node.js (latence ~10,7 ms, ~560 requêtes/s). Surcharge par instanciation. 3 (Faible): Python (latence ~26,5 ms, ~290 requêtes/s). Limité par GIL. Recommandations production: Go: Optimal forte charge, cloud-native, optimisation coûts. Java: Latence très basse critique, infrastructure Java existante. Node.js & Python: Adaptés charges modérées/faibles, développement/test. Node.js et Python peuvent être optimisés pour améliorer leurs performances en production. Et encore, en Java, le benchmark n'a pas utilisé GraalVM pour une compilation native, ce qui aurait donné des chiffres côté mémoire qui aurait concurrencé Go Qui a la meilleure perf entre Quarkus et Spring pour faire des serveurs MCP ? https://medium.com/@egekaraosmanoglu/spring-boot-vs-quarkus-which-java-runtime-wins-the-ai-mcp-tools-performance-battle-4da9d6a248d5 Quarkus JVM: Débit et latence les plus élevés (jusqu'à 16 381 req/s, 65% plus rapide que Spring Boot), surpasse Spring Boot même avec Apache Camel. Quarkus Native: Consommation mémoire la plus faible (118 MB), démarrage instantané, performance prédictible. Spring Boot MVC: Bonnes performances, écosystème mature, nécessite un "warm-up" important (jusqu'à 44% de gain). Spring Boot WebFlux: Légèrement meilleur débit et latence que MVC (~5%), mais plus de mémoire et complexité réactive. Coût architectural: MapStruct: Impact négligeable (< ±5%). Apache Camel: Réduction de débit de 8-21%, mais valeur ajoutée significative; Quarkus JVM + Camel reste > Spring Boot baseline. Protocole MCP: Sur Quarkus JVM (avec Camel), surpasse gRPC. Recommandations: Débit max: Quarkus JVM. Coût/Serverless: Quarkus Native. Intégration d'entreprise: Quarkus JVM + Camel + MapStruct. Meilleur choix Spring: Spring Boot WebFlux + MapStruct. Benchmark des stacks qui implémentent MCP https://www.tmdevlab.com/mcp-server-performance-benchmark-v2.html MCP (Model Context Protocol) est le protocole d'Anthropic pour connecter les LLMs à des outils et sources de données externes ; ce benchmark compare 15 implémentations serveur. 39,9 millions de requêtes traitées avec zéro erreur, sur des charges I/O réalistes (Redis + HTTP API) plutôt que des tâches CPU synthétiques. Rust atteint 4 845 RPS avec seulement 10,9 Mo de RAM ; Quarkus obtient 4 739 RPS avec la meilleure latence (4,04 ms en moyenne, 8,13 ms au P95). Go (3 616 RPS) et Spring MVC (3 540 RPS) constituent un second groupe solide. Node.js plafonne à 423 RPS ; Bun est 2,2x plus rapide sur un code identique (876 RPS) ; Python atteint 259 RPS avec 4 workers et uvloop. Découverte notable : un bug dans le SDK Rust rmcp v0.16 ajoutait ~40 ms de latence à toutes les réponses HTTP, limitant le débit à 1 283 RPS ; corrigé en v0.17 via la PR #683. Les images natives GraalVM réduisent la mémoire de 27 à 81 % mais dégradent le débit de 20 à 36 % ; Quarkus-native est l'exception avec 36 Mo RAM et 3 449 RPS. Spring MVC (bloquant) surpasse WebFlux (réactif) à 50 utilisateurs simultanés, rappelant que le modèle réactif n'est pas toujours gagnant. Recommandations : Rust ou Quarkus pour la production haute charge, Go pour le cloud-native, Bun plutôt que Node.js en JavaScript. Jakarta EE 12 Milestone 2 : données, cohérence et configuration https://www.infoq.com/articles/jakartaee-12-milestone-2/ Jakarta EE est la plateforme Java entreprise open-source, socle de frameworks comme Quarkus et Spring, qui standardise les APIs pour la persistance, les transactions, la sécurité, etc. Jakarta EE 12 adopte Java 21 comme baseline (avec support Java 25) et supprime définitivement le SecurityManager déprécié. La nouvelle spec Jakarta Query unifie JPQL (SQL/relationnel) et JDQL (NoSQL) en un seul langage avec deux profils : Core Language (portable) et Persistence Language (relationnel). Jakarta Data 1.1 introduit les requêtes dynamiques via une API fluente avec Restriction et l'annotation @Is pour des conditions plus expressives. Jakarta Data supporte désormais les repositories stateful, permettant la gestion du cycle de vie des entités (persist, merge, detach, refresh) comme en JPA classique. Jakarta NoSQL 1.1 intègre Jakarta Query via une nouvelle interface Query et supporte les projections avec des Java records. Jakarta Persistence 4.0 supporte SequencedCollection (Java 21) comme type de collection dans les entités. Une nouvelle spec Jakarta Agentic AI est en cours, visant des APIs vendor-neutral pour construire des agents IA sur les runtimes Jakarta EE, avec intégration prévue de LangChain4j et Spring AI. Cette release est encore un milestone (pas pour la prod) — l'adoption large dépendra de la maturité des outils (IDE, validation de requêtes, diagnostics). Nouveaux benchmarks Quarkus vs Spring Boot : performance complète et transparente https://quarkus.io/blog/new-benchmarks/ Quarkus est un framework Java optimisé pour les conteneurs, connu pour son faible usage mémoire et son démarrage rapide, concurrent principal de Spring Boot. Les anciens graphiques de performance sur quarkus.io étaient obsolètes, sans date, sans source, et ne montraient pas le débit (throughput). L'absence de données sur le throughput faisait croire à tort que Quarkus avait de mauvaises performances à ce niveau. Un nouveau benchmark open source a été créé, transparent et reproductible, disponible sur GitHub. Résultats : Quarkus gère 2,7x plus de transactions par seconde que Spring Boot, démarre 2,3x plus vite, avec deux fois moins de mémoire. Des experts Spring Boot externes ont contribué à rendre la comparaison plus équitable, notamment sur la configuration des pools de connexions. Les threads virtuels améliorent le débit d'environ 6000 tps supplémentaires pour tous les frameworks testés. Spring Boot 4 offre un meilleur débit que Spring Boot 3, mais au prix d'un démarrage plus lent et d'une empreinte mémoire plus élevée. En mode natif (GraalVM), le démarrage est ultra-rapide mais le throughput est divisé par deux, pour Quarkus comme pour Spring Boot. Le mode natif n'est recommandé que pour les applis démarrées/arrêtées très fréquemment ou à faible charge. Quarkus 3.32 : fondations pour la prochaine LTS https://quarkus.io/blog/quarkus-3-32-released/ Quarkus est un framework Java cloud-natif optimisé pour GraalVM et HotSpot, conçu pour les microservices et les environnements conteneurisés. Cette version marque le feature freeze pour la prochaine version LTS 3.33. Intégration de Project Leyden (AOT JVM) : le démarrage d'une application REST minimale passe de 370ms à 80ms. L'entraînement Leyden peut se déclencher au build ou via les tests d'intégration. Amélioration du graceful shutdown HTTP, avec des contributions de l'équipe Keycloak. Enregistrement automatique dans Consul via l'extension Stork pour la découverte de services. Nouvelles fonctionnalités de sécurité : DPoP nonce providers personnalisés, support de rich authorization pour OIDC. Possibilité de personnaliser l'ordre des mécanismes d'authentification et ajout de OIDCAuthenticationCompletionAction. Mise à jour du framework Google Cloud Functions en version 2.0, ainsi que Camel Quarkus et Quarkus CXF. Les utilisateurs sur LTS 3.27 sont encouragés à tester la migration vers 3.33 pour faire remonter des retours. NodeJS change sa cadence de releases https://nodejs.org/en/blog/announcements/evolving-the-nodejs-release-schedule Node.js est le runtime JavaScript côté serveur le plus utilisé, géré par la OpenJS Foundation avec un cycle de releases actif depuis la fusion avec io.js il y a dix ans. À partir de Node.js 27 (octobre 2026), le projet passe d'une release majeure tous les six mois à une seule par an. Chaque release deviendra LTS, supprimant la distinction entre versions paires (LTS) et impaires (non-LTS). Un nouveau canal Alpha est introduit, permettant les changements semver-major pendant la phase de test précoce. Les phases deviennent : Alpha (6 mois, oct. à mars), Current (6 mois, avr. à oct.), LTS (30 mois), puis EOL. La durée totale de support reste de 36 mois, identique au modèle actuel. La numérotation des versions s'aligne sur l'année calendaire de la release Current (ex : 27.0.0 en 2027). La version Alpha est signée, taguée et testée via CITGM, mais n'est pas destinée à la production. La motivation principale : les versions impaires étaient peu adoptées, la distinction pair/impair perturbait les débutants, et réduire les lignes de release parallèles allège la charge des bénévoles. Les auteurs de bibliothèques sont encouragés à intégrer les releases Alpha dans leur CI dès que possible pour détecter les régressions en amont. Web jQuery v4 est sorti https://www.infoq.com/news/2026/02/jquery-4-release/?utm_source=twitter&utm_medium=link&utm_campaign=calendar jQuery est une bibliothèque JavaScript historique qui simplifie la manipulation du DOM, la gestion des événements et les requêtes AJAX, encore très présente dans de nombreuses bases de code. Cette version majeure sort pour les 20 ans de la bibliothèque, après presque une décennie sans version majeure. Suppression du support d'Internet Explorer 10 et antérieur, Edge Legacy et les anciennes versions iOS/Android. IE11 reste encore supporté dans jQuery 4, mais sa suppression est prévue pour jQuery 5. Le code source migre d'AMD vers les ES modules, pour une meilleure compatibilité avec les outils de build modernes. Le bundler passe de RequireJS à Rollup. Suppression des fonctions dépréciées comme jQuery.isArray, jQuery.parseJSON et jQuery.trim, désormais disponibles nativement en JavaScript. Le fichier gzippé gagne plus de 3 000 octets ; le build slim descend à environ 19,5 ko. Ajout du support des Trusted Types pour faciliter la compatibilité avec les Content Security Policy strictes. jQuery reste pertinent pour la maintenance de bases de code existantes et les projets nécessitant une faible dépendance aux frameworks. La réactivité en frontend : concepts et approches https://www.sfeir.dev/front/quest-ce-que-la-reactivite-en-frontend/ Un article qui resume comment la reactivite est implementee en front web La réactivité en frontend désigne le mécanisme qui permet de mettre à jour automatiquement l'UI quand les données changent, sans manipulation directe du DOM. Sans réactivité, les développeurs doivent mettre à jour manuellement chaque élément de l'interface, ce qui est fastidieux et source d'erreurs. Le data binding unidirectionnel (React) distingue le flux de données des callbacks d'interaction utilisateur. Le data binding bidirectionnel (Angular) synchronise automatiquement données et UI dans les deux sens. Le Virtual DOM (React, Vue) compare une représentation en mémoire avec le DOM réel avant d'appliquer uniquement les changements nécessaires. Les observables via RxJS (Angular) permettent de gérer des flux de données asynchrones et des événements complexes. Les signaux (SolidJS, Angular récent, Svelte) offrent des mises à jour granulaires et de meilleures performances que les approches précédentes. Les signaux proposent une API plus simple que les observables tout en restant très performants. La réactivité abstrait la manipulation du DOM et permet aux développeurs de se concentrer sur l'état de l'application. Data et Intelligence Artificielle Gunnar Morling a annoncé la sortie de Hardwood, un nouveau parseur Java pour les fichiers Apache Parquet, grâce aux leçons apprises par le 1BRC challenge https://www.morling.dev/blog/hardwood-new-parser-for-apache-parquet/ Hardwood : Nouveau parseur Apache Parquet open-source (Java 21+). But : Dépasser parquet-java (dépendances lourdes, lecteur mono-threadé). Points clés : Dépendances minimes, pipeline de décodage multi-threadé. APIs : RowReader (ligne) et ColumnReader (colonne, haute perf.). Optimisations : Parallélisme pages, préchargement adaptatif, moins d'allocations. Développement : Assisté par IA (Claude Code), révision humaine. Futur : "Predicate push-down", compatibilité parquet-java, écriture, CLI, intégration Iceberg. Apicurio Registry passe AI-Native — https://www.apicur.io/blog/2026/02/05/apicurio-registry-ai-natural-evolution Apicurio Registry est un registre open-source de schemas (OpenAPI, AsyncAPI, Avro, Protobuf…) gérant versioning, validation et gouvernance des APIs. Le projet étend ses capacités pour devenir une plateforme native AI, en appliquant les mêmes principes de gouvernance aux agents IA. Support du protocole A2A (Agent-to-Agent) : les agents s'enregistrent via des "Agent Cards" et se découvrent mutuellement via des endpoints standardisés. Un serveur MCP intégré permet aux LLMs d'interagir directement avec le registre (découverte de schémas, validation, création). L'intégration avec Claude Desktop est déjà documentée, permettant de gérer les artefacts en langage naturel. Deux nouveaux types d'artefacts : PROMPT_TEMPLATE (templates de prompts versionnés avec variables) et MODEL_SCHEMA (validation des entrées/sorties des agents). Les SDKs Java (LangChain4j, Quarkus) et Python (LangChain, LlamaIndex) sont disponibles. Une démo multi-agents illustre le "context chaining" : chaque agent reçoit les sorties des agents précédents dans la pipeline. La roadmap prévoit : gestion du cycle de vie des agents, recherche sémantique, intégration dans les pipelines de déploiement. L'Histoire du Deep Learning : quand les machines ont commencé à apprendre https://blog.ippon.fr/2026/02/20/lhistoire-du-deep-learning-quand-les-machines-ont-commence-a-apprendre/ un article qui retrace les avancées clées du machine learning Le deep learning est un sous-domaine du ML basé sur des réseaux de neurones empilés en couches, aujourd'hui omniprésent dans la vision, le langage et la recommandation. Le Perceptron (1957) est le premier modèle formel d'apprentissage supervisé, mais il échoue sur des problèmes non linéaires comme le XOR : une limite structurelle, pas algorithmique. La rétropropagation du gradient (années 80) permet d'entraîner des réseaux multi-couches, mais souffre du problème de "vanishing gradient" qui bloque l'apprentissage en profondeur. L'essor du deep learning dans les années 2000 est autant une révolution matérielle qu'algorithmique : les GPU, conçus pour le jeu vidéo, se révèlent parfaitement adaptés aux calculs matriciels. AlexNet (2012) marque une rupture industrielle en démontrant qu'un CNN profond entraîné sur GPU surpasse largement les méthodes classiques en reconnaissance d'images. Les LSTM (1997) résolvent les problèmes de mémoire à long terme des RNN, mais leur nature séquentielle limite fortement la parallélisation. Les Transformers ("Attention Is All You Need", 2017) révolutionnent le domaine en remplaçant la récursion par un mécanisme d'attention parallélisable, adaptable aux GPU et TPU. L'IA générative introduit une rupture conceptuelle : les modèles apprennent la distribution des données pour en produire de nouveaux exemples, et non plus simplement classifier. Les LLM offrent un socle généraliste réutilisable pour de nombreuses tâches, là où l'IA prédictive nécessitait un modèle spécifique par problème. La question de l'AGI reste ouverte et très incertaine, mais l'IA devient déjà un "acteur logiciel" capable de raisonner et d'agir de manière autonome via les agents. Ca y est, Agent to Agent Protocol (A2A) est sorti en version 1.0 https://a2a-protocol.org/latest/announcing-1.0/ Prêt pour la prod Support multi-version ( multi-protocoles (gRPC, HTTP+JSON…) Multi-tenancy : un même endpoint peut supporter et exposer plusieurs agents distincts Agent Cards signées et vérifiables cryptographiquement pour vérifier l'identité des agents Flexibilité : les clients peuvent choisir de consommer les résultats par polling, streaming, ou également webhooks Outillage Le guide complet pour créer des skills pour vos agents, par Anthropic https://resources.anthropic.com/hubfs/The-Complete-Guide-to-Building-Skill-for-Claude.pdf Définition et structure : Les skills sont des dossiers contenant des instructions (fichier SKILL.md obligatoire) et des scripts qui enseignent aux agents comment exécuter des tâches spécifiques ou utiliser des outils MCP de manière fiable. Fonctionnement technique : Le système repose sur la "divulgation progressive" via un en-tête YAML critique, permettant à Claude de charger le contexte de la compétence uniquement lorsque la demande de l'utilisateur le nécessite. Cycle de vie : Le guide couvre toutes les étapes de développement, de la définition des cas d'usage (automatisation, création de documents) aux protocoles de test et de distribution. il couvre aussi comment tester (brievement) et des patterns communs Apprendre a utiliser les skills pour structurer son code ia https://philippart-s.github.io/blog/2026-02-18-anthropic-skills/ Les Skills Claude sont des packages d'instructions dans un dossier enseignant à Claude comment gérer des tâches spécifiques de façon cohérente. Un skill se compose au minimum d'un fichier SKILL.md avec un frontmatter YAML et des instructions en Markdown. Le frontmatter YAML impose deux champs obligatoires : name (en kebab-case) et description (max 1024 caractères expliquant quoi faire et quand le déclencher). Les skills fonctionnent de façon identique sur Claude.ai, Claude Code et l'API sans modification. Trois catégories principales : création de documents/assets, automatisation de workflows multi-étapes, et amélioration d'intégrations MCP. Les skills s'appuient sur le principe de divulgation progressive : frontmatter toujours chargé, corps du SKILL.md si pertinent, fichiers liés à la demande. Cinq patterns courants : orchestration séquentielle, coordination multi-MCP, raffinement itératif, sélection d'outils contextuelle, intelligence métier embarquée. Les tests doivent couvrir le déclenchement (90% des requêtes pertinentes), le fonctionnel et la comparaison avec la baseline sans skill. Pour la distribution, héberger sur GitHub avec un README séparé du dossier du skill (pas de README.md dans le dossier lui-même). Un skill-creator officiel permet de générer un premier SKILL.md en 15-30 minutes à partir d'une description en langage naturel. Les skills pour les agents, c'est une façon d'automatiser des tâches répétitives https://glaforge.dev/posts/2026/02/21/easily-build-a-local-mcp-server-in-java-with-a-skill-in-gemini-cli/ Construction facile de serveurs MCP Java locaux pour Gemini CLI et autres agents. Solution au code Java répétitif : JBang + LangChain4j + un "skill" utilisé par Gemini CLI. Idée clée : Une "skill" pour Gemini CLI automatise génération et installation des serveurs. La "skill" génère un fichier Java, le compile et l'enregistre dans les paramètres de Gemini CLI. Avantages : Élimine le boilerplate, enregistrement automatique, développement rapide. Conclusion : Les "skills" d'agent automatisent les tâches répétitives et systématisent l'expérimentation. Un SKILL.md par Julien Dubois pour permettre aux agents IA de créer des projets Spring en suivant les bonnes pratiques à la JHipster https://github.com/jdubois/dr-jskill/blob/main/SKILL.md Dr JSkill est une "Agent Skill" conçue pour aider les IA (GitHub Copilot CLI, Claude Code) à générer des applications Spring Boot 4.x selon les meilleures pratiques de Julien Dubois. Permet de créer des projets full-stack modernes utilisant Java 25, PostgreSQL et Docker, avec un choix de frameworks front-end (Vue.js par défaut, React, Angular ou Vanilla JS). Intègre des scripts Node.js multiplateformes pour automatiser la génération de projets via start.spring.io sans dépendances npm externes. Préconise des choix technologiques stricts : Maven uniquement, pas de Lombok, et utilisation de Hibernate ddl-auto pour la gestion du schéma (pas de Flyway/Liquibase). Supporte nativement la compilation GraalVM (images natives) pour des démarrages ultra-rapides (
As more organizations move to use OpenTelemetry in production at scale, with multiple Collectors across heterogeneous environments, a new challenge arises: how to remotely manage, configure, and update this agent fleet in a consistent and secure way?This is where Open Agent Management Protocol (OpAMP) comes into the picture: it provides a standardized protocol that lets a central backend automatically configure agents, push updates, monitor their health, and collect status information. In this episode Horovits hosts Andy Keller, OpAMP Maintainer and Principal Engineer at Bindplane, to discuss how OpAMP makes large-scale observability deployments much easier to operate and control. Andy shares the project status, including hot KubeCon update you don't want to miss.You can read the recap post: https://medium.com/p/737b6af8222b/Show Notes:00:00 - intro02:01 - why OpAMP mission statement04:29 - types of OpenTelemetry Collector fleet deployments06:49 - from configuration management to observability 10:23 - OpAMP for Kubernetes 15:58 - OpAMP protocol and components26:54 - OpAMP for remote management of OTel Java SDK and other agents 33:38 - server implementations for OpAMP36:33 - adopter vendors and end-users 39:14 - project maturity42:59 - protocol vs. product47:55 - OpAMP Gateway launch 51:10 - Scale of OTel Collector deployments54:56 - OpAMP roadmap59:12 - where to follow the project and Andy1:02:34 - outroResources:OpAMP specification: https://opentelemetry.io/docs/specs/opamp/ OpAMP for OpenTelemetry Collector: https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/main/cmd/opampsupervisor/specification/README.md Nike talk at KubeCon on using OpAMP: https://www.youtube.com/watch?v=J68ThM9DqQ0 OpAMP Gateway Extension - launch blog: https://bindplane.com/blog/opamp-for-opentelemetry-managing-collector-fleets-and-introducing-the-new-opamp-gateway-extension Socials:Dotan Horovits============X (Twitter): @horovitsLinkedIn: www.linkedin.com/in/horovitsMastodon: @horovits@fosstodonBlueSky: @horovits.bsky.socialAndy Keller==========X (Twitter): @andykellrLinkedIn: https://www.linkedin.com/in/andrewjkeller/BlueSky: https://bsky.app/profile/openobservability.bsky.socialX (Twitter): https://x.com/OpenObservLinkedIn: https://www.linkedin.com/company/openobservability/YouTube: https://www.youtube.com/@openobservabilitytalksOpenObservability Talks episodes are released monthly, on the last Thursday of each month and are available for listening on your favorite podcast app and on YouTube.
Episode #534 consacré à « Shai-Hulud » Avec Christophe Tafani-Dereeper Références : Shai-Hulud: https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/ https://github.com/DataDog/indicators-of-compromise/blob/main/shai-hulud-2.0/README.md https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack https://www.cert.ssi.gouv.fr/actualite/CERTFR-2025-ACT-051/ Evoqué pendant l'épisode : Précédent épisode NLS sur la sécurité de la chaîne d'approvisionnement : https://www.nolimitsecu.fr/securisation-de-la-chaine-dapprovisionnement-logicielle/ Attaque sur le mainteneur npm « Qix » : https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack Exemples d'autres attaques par phishing npm en 2025 : https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised https://www.mimecast.com/threat-intelligence-hub/npm-phishing-campaign/ PoC de ver npm en […] The post Shai-Hulud appeared first on NoLimitSecu.
The Brothers look back at Unlimited Love as it approaches it's fourth birthday, and muse on the musings of the Fabulous Pete Moore.We are part of the Deep Dive Podcast Network: https://twitter.com/DeepDivePodNetFollow us on the good old socials:Twitter:Ben: https://twitter.com/universallyrhcpSam: https://twitter.com/stacktownsendInstagram:Ben: https://www.instagram.com/universallyspeakingrhcp_pod/Read ‘Me and My Friends' - The World's #1 RHCP Newsletter - Subscribe here: https://buttondown.email/rhcpsessions.Check out Red Hot Chili Riffs here: https://www.youtube.com/@RedHotChiliRiffsCheck out our Drum Ambassadors (Jack Johnson) projects here: https://www.youtube.com/channel/UCdy0pbWSOg6f8vcYnngIQ0ACheck out our Bass Ambassadors (Aidan Hampson) projects here: http://aidanhampson.co.uk/Check out friend of the pod, Dan Boyd's Pop Shock Podcast - for all your pop culture needs! Audio: https://anchor.fm/popshockpod / Video: https://youtube.com/channel/UCHY5pXX_x7Kv4e8wJmHoK5AFor your vinyl needs please shop at Black Star Records: https://www.blackstarrecords.co.uk and Black Wax Coffee and Records: https://blackwaxcoffee.co.uk/
In README: A Bookish History of Computing from Electronic Brains to Everything Machines (MIT Press, 2025), historian Dr. Patrick McCray argues that in order for computers to become ubiquitous, people first had to become interested in them, learn about them, and take the machines seriously. A powerful catalyst for this transformation was, ironically, one of the oldest information technologies we have: books. The author uses a carefully chosen selection of books, some iconic and others obscure, to describe this technological revolution as it unfolded in the half-century after 1945. The book begins with a fundamental question: How does a new technology become well known and widespread? Dr. McCray answers this by using books as a window into significant moments in the history of computing, publishing, and American culture.README offers a literary history of computers and, more broadly, information technologies between World War II and the dot-com crash of the early 21st century. From the electronic brains and cybernetics craze of the 1940s to the birth of AI, the rise of the personal computer, and the internet-driven financial frenzy of the 1990s, books have proven a durable and essential way for people to learn how to use and think about computers. By offering a readable half-century of bookish history, README explains how computers became popular and pervasive. This interview was conducted by Dr. Miranda Melcher whose book focuses on post-conflict military integration, understanding treaty negotiation and implementation in civil war contexts, with qualitative analysis of the Angolan and Mozambican civil wars. You can find Miranda's interviews on New Books with Miranda Melcher, wherever you get your podcasts. Learn more about your ad choices. Visit megaphone.fm/adchoices Support our show by becoming a premium member! https://newbooksnetwork.supportingcast.fm/new-books-network
I have a theory that only bad projects get finished — good ones keep finding new things to do. Asciinema is a case in point. What started as a way to share terminal sessions with friends has, over 14 years, grown into a full suite of tools covering recording, hosting, playback, and live streaming — and been rebuilt multiple times along the way. So what does it actually take to record and replay a terminal session faithfully in a browser?Joining us for this conversation is Marcin Kulik, Asciinema's creator. The project's architecture has passed through almost every interesting corner of software engineering: a Python recorder built around pseudo-terminals (PTY), a ClojureScript terminal emulator for the browser that hit performance limits with immutable data structures and garbage collection pressure, a move to Rust compiled to WebAssembly, a Go experiment that didn't last, and a new Rust CLI for concurrent live streaming backed by an Elixir/Phoenix server that calls Rust code via NIFs. The same Rust terminal emulator library now powers all three components — the browser player, the server, and the CLI.If you've ever looked at those terminal animations embedded in a README and wondered what's underneath them, or if you're interested in how a passionate open-source developer navigates 14 years of language changes and rewrites, this conversation has plenty to offer.---Support Developer Voices on Patreon: https://patreon.com/DeveloperVoicesSupport Developer Voices on YouTube: https://www.youtube.com/@DeveloperVoices/joinAsciinema: https://asciinema.orgAsciinema Docs: https://docs.asciinema.orgAsciinema CLI (GitHub): https://github.com/asciinema/asciinemaAsciinema Player (GitHub): https://github.com/asciinema/asciinema-playerAsciinema Server (GitHub): https://github.com/asciinema/asciinema-serverAVT - Rust terminal emulator library: https://github.com/asciinema/avtvt-clj - the original ClojureScript terminal emulator: https://github.com/asciinema/vt-cljPaul Williams' ANSI/VT100 State Machine Parser: https://vt100.net/emu/dec_ansi_parserRust: https://www.rust-lang.orgWebAssembly: https://webassembly.orgSolidJS: https://www.solidjs.comElixir: https://elixir-lang.orgPhoenix Framework: https://www.phoenixframework.orgRustler (Rust NIFs for Elixir/Erlang): https://github.com/rusterlium/rustlerClojure: https://clojure.orgClojureScript: https://clojurescript.orgcmatrix: https://github.com/abishekvashok/cmatrixMarcin Kulik on GitHub: https://github.com/ku1ikMarcin Kulik on Mastodon: https://hachyderm.io/@ku1ikMarcin Kulik on asciinema.org: https://asciinema.org/~ku1ik"They're Made Out of Meat" demo: https://asciinema.org/a/746358Kris on Bluesky: https://bsky.app/profile/krisajenkins.bsky.socialKris on Mastodon: http://mastodon.social/@krisajenkinsKris on LinkedIn: https://www.linkedin.com/in/krisjenkins/---0:00 Intro2:28 What Is Asciinema?4:48 How Asciinema Started9:51 The Problem of Parsing Terminal Output14:07 Building a Cross-Platform Recorder17:01 Rewriting the Parser in ClojureScript22:19 The Hidden Complexity of Terminals29:28 Rendering Terminals in the Browser39:47 When ClojureScript Can't Keep Up45:28 Moving to Rust and WebAssembly52:01 The Go Experiment57:43 Adding Live Terminal Streaming1:07:12 Can You Scrub Back in a Live Stream?1:14:40 Editing Recordings1:25:27 Outro
In README: A Bookish History of Computing from Electronic Brains to Everything Machines (MIT Press, 2025), historian Dr. Patrick McCray argues that in order for computers to become ubiquitous, people first had to become interested in them, learn about them, and take the machines seriously. A powerful catalyst for this transformation was, ironically, one of the oldest information technologies we have: books. The author uses a carefully chosen selection of books, some iconic and others obscure, to describe this technological revolution as it unfolded in the half-century after 1945. The book begins with a fundamental question: How does a new technology become well known and widespread? Dr. McCray answers this by using books as a window into significant moments in the history of computing, publishing, and American culture.README offers a literary history of computers and, more broadly, information technologies between World War II and the dot-com crash of the early 21st century. From the electronic brains and cybernetics craze of the 1940s to the birth of AI, the rise of the personal computer, and the internet-driven financial frenzy of the 1990s, books have proven a durable and essential way for people to learn how to use and think about computers. By offering a readable half-century of bookish history, README explains how computers became popular and pervasive. This interview was conducted by Dr. Miranda Melcher whose book focuses on post-conflict military integration, understanding treaty negotiation and implementation in civil war contexts, with qualitative analysis of the Angolan and Mozambican civil wars. You can find Miranda's interviews on New Books with Miranda Melcher, wherever you get your podcasts. Learn more about your ad choices. Visit megaphone.fm/adchoices Support our show by becoming a premium member! https://newbooksnetwork.supportingcast.fm/intellectual-history
In README: A Bookish History of Computing from Electronic Brains to Everything Machines (MIT Press, 2025), historian Dr. Patrick McCray argues that in order for computers to become ubiquitous, people first had to become interested in them, learn about them, and take the machines seriously. A powerful catalyst for this transformation was, ironically, one of the oldest information technologies we have: books. The author uses a carefully chosen selection of books, some iconic and others obscure, to describe this technological revolution as it unfolded in the half-century after 1945. The book begins with a fundamental question: How does a new technology become well known and widespread? Dr. McCray answers this by using books as a window into significant moments in the history of computing, publishing, and American culture.README offers a literary history of computers and, more broadly, information technologies between World War II and the dot-com crash of the early 21st century. From the electronic brains and cybernetics craze of the 1940s to the birth of AI, the rise of the personal computer, and the internet-driven financial frenzy of the 1990s, books have proven a durable and essential way for people to learn how to use and think about computers. By offering a readable half-century of bookish history, README explains how computers became popular and pervasive. This interview was conducted by Dr. Miranda Melcher whose book focuses on post-conflict military integration, understanding treaty negotiation and implementation in civil war contexts, with qualitative analysis of the Angolan and Mozambican civil wars. You can find Miranda's interviews on New Books with Miranda Melcher, wherever you get your podcasts. Learn more about your ad choices. Visit megaphone.fm/adchoices
In README: A Bookish History of Computing from Electronic Brains to Everything Machines (MIT Press, 2025), historian Dr. Patrick McCray argues that in order for computers to become ubiquitous, people first had to become interested in them, learn about them, and take the machines seriously. A powerful catalyst for this transformation was, ironically, one of the oldest information technologies we have: books. The author uses a carefully chosen selection of books, some iconic and others obscure, to describe this technological revolution as it unfolded in the half-century after 1945. The book begins with a fundamental question: How does a new technology become well known and widespread? Dr. McCray answers this by using books as a window into significant moments in the history of computing, publishing, and American culture.README offers a literary history of computers and, more broadly, information technologies between World War II and the dot-com crash of the early 21st century. From the electronic brains and cybernetics craze of the 1940s to the birth of AI, the rise of the personal computer, and the internet-driven financial frenzy of the 1990s, books have proven a durable and essential way for people to learn how to use and think about computers. By offering a readable half-century of bookish history, README explains how computers became popular and pervasive. This interview was conducted by Dr. Miranda Melcher whose book focuses on post-conflict military integration, understanding treaty negotiation and implementation in civil war contexts, with qualitative analysis of the Angolan and Mozambican civil wars. You can find Miranda's interviews on New Books with Miranda Melcher, wherever you get your podcasts. Learn more about your ad choices. Visit megaphone.fm/adchoices Support our show by becoming a premium member! https://newbooksnetwork.supportingcast.fm/science-technology-and-society
In README: A Bookish History of Computing from Electronic Brains to Everything Machines (MIT Press, 2025), historian Dr. Patrick McCray argues that in order for computers to become ubiquitous, people first had to become interested in them, learn about them, and take the machines seriously. A powerful catalyst for this transformation was, ironically, one of the oldest information technologies we have: books. The author uses a carefully chosen selection of books, some iconic and others obscure, to describe this technological revolution as it unfolded in the half-century after 1945. The book begins with a fundamental question: How does a new technology become well known and widespread? Dr. McCray answers this by using books as a window into significant moments in the history of computing, publishing, and American culture.README offers a literary history of computers and, more broadly, information technologies between World War II and the dot-com crash of the early 21st century. From the electronic brains and cybernetics craze of the 1940s to the birth of AI, the rise of the personal computer, and the internet-driven financial frenzy of the 1990s, books have proven a durable and essential way for people to learn how to use and think about computers. By offering a readable half-century of bookish history, README explains how computers became popular and pervasive. This interview was conducted by Dr. Miranda Melcher whose book focuses on post-conflict military integration, understanding treaty negotiation and implementation in civil war contexts, with qualitative analysis of the Angolan and Mozambican civil wars. You can find Miranda's interviews on New Books with Miranda Melcher, wherever you get your podcasts. Learn more about your ad choices. Visit megaphone.fm/adchoices
In README: A Bookish History of Computing from Electronic Brains to Everything Machines (MIT Press, 2025), historian Dr. Patrick McCray argues that in order for computers to become ubiquitous, people first had to become interested in them, learn about them, and take the machines seriously. A powerful catalyst for this transformation was, ironically, one of the oldest information technologies we have: books. The author uses a carefully chosen selection of books, some iconic and others obscure, to describe this technological revolution as it unfolded in the half-century after 1945. The book begins with a fundamental question: How does a new technology become well known and widespread? Dr. McCray answers this by using books as a window into significant moments in the history of computing, publishing, and American culture.README offers a literary history of computers and, more broadly, information technologies between World War II and the dot-com crash of the early 21st century. From the electronic brains and cybernetics craze of the 1940s to the birth of AI, the rise of the personal computer, and the internet-driven financial frenzy of the 1990s, books have proven a durable and essential way for people to learn how to use and think about computers. By offering a readable half-century of bookish history, README explains how computers became popular and pervasive. This interview was conducted by Dr. Miranda Melcher whose book focuses on post-conflict military integration, understanding treaty negotiation and implementation in civil war contexts, with qualitative analysis of the Angolan and Mozambican civil wars. You can find Miranda's interviews on New Books with Miranda Melcher, wherever you get your podcasts. Learn more about your ad choices. Visit megaphone.fm/adchoices Support our show by becoming a premium member! https://newbooksnetwork.supportingcast.fm/technology
Today we are talking about Acquia's Fully managed Drupal SaaS Acquia Source, What you can do with it, and how it could change your organization with guest Matthew Grasmick. We'll also cover AI Single Page Importer as our module of the week. For show notes visit: https://www.talkingDrupal.com/540 Topics Introduction to Acquia Source The Evolution of Acquia Source Cost and Market Position of Acquia Source Customizing and Growing Your Business Challenges of Building a SaaS Platform on Drupal Advantages of Acquia Source for Different Markets Horizontal Scale and Governance at Scale Canvas CLI Tool and Synchronization Role of AI in Acquia Source Agencies and Enterprise Clients AI Experiments and Content Importer AI and Orchestration in Drupal Future Innovations in Acquia Source Resources Acquia source Nebula Guests Matthew Grasmick - grasmash Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Catherine Tsiboukas - mindcraftgroup.com bletch MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted to use AI to help map various content on an existing site to structured fields on Drupal site, as part of creating a node? There's a module for that. Module name/project name: AI Single Page Importer Brief history How old: created in Jan 2026 by Mark Conroy (markconroy) who listeners may know from his work on the LocalGov distribution and install profile Versions available: 1.0.0-alpha3, which works with Drupal core 10 or 11 Maintainership Actively maintained Documentation - pretty extensive README, which is also currently in use as the project page No issues yet Usage stats: 2 sites Module features and usage With this module enabled, you'll have a new "AI Content Import" section at the top of the node creation form. In there you can provide the URL of the existing page to use, and then click "Import Content with AI". That will trigger a process where OpenAI will ingest and analyze the existing page. It will extract values to populate your node fields, and then you can review or change those values before saving the node. In the configuration you can specify the AI model to use, a maximum content length, an HTTP request timeout value, which content types should have the importer available, and then also prevent abuse by specifying blocked domains, a flood limit, and a flood window. You will also need to grant a new permission to use the importer for any user roles that should have access. The module also includes a number of safeguards. For example, it will only accept URLs using HTTP or HTTPS protocols, private IP ranges are blocked, and by default it will only allow 5 requests per user per hour. It will perform HTML purification for long text fields, and strip tags for short text fields. In addition, it removes dangerous attributes like onclick or inline javascript, and generates CKEditor-compatible output. It currently supports a list of field types that include text_long, text_with_summary, string, text, datetime, daterange, timestamps and link fields. It also supports entity reference fields, but only for taxonomy terms. Listeners may also be aware of the Unstructured module which does some similar things, but requires you to use an Unstructured service or run a server using their software. So I would say that AI Single Page Importer is perhaps a little more narrow in scope but works with an OpenAI account instead of requiring the less commonly used Unstructured.
This episode kicks off with Moltbook, a social network exclusively for AI agents where 150,000 agents formed digital religions, sold “digital drugs” (system prompts to alter other agents), and attempted prompt injection attacks to steal each other’s API keys within 72 hours of launch. Ray breaks down OpenClaw, the viral open-source AI agent (68,000 GitHub stars) that handles emails, scheduling, browser control, and automation, plus MoltHub’s risky marketplace where all downloaded skills are treated as trusted code. Also covered, Bluetooth “whisper pair” vulnerabilities letting attackers hijack audio devices from 46 feet away and access microphones, Anthropic patching Model Context Protocol flaws, AI-generated ransomware accidentally bundling its own decryption keys, Claude Code’s new task dependency system and Teleport feature, Google Gemini’s 100MB file limits and agentic vision capabilities, VAST’s Haven One commercial space station assembly, and IBM SkillsBuild’s free tech training for veterans. – Want to start a podcast? Its easy to get started! Sign-up at Blubrry – Thinking of buying a Starlink? Use my link to support the show. Subscribe to the Newsletter. Email Ray if you want to get in touch! Like and Follow Geek News Central’s Facebook Page. Support my Show Sponsor: Best Godaddy Promo Codes $11.99 – For a New Domain Name cjcfs3geek $6.99 a month Economy Hosting (Free domain, professional email, and SSL certificate for the 1st year.) Promo Code: cjcgeek1h $12.99 a month Managed WordPress Hosting (Free domain, professional email, and SSL certificate for the 1st year.) Promo Code: cjcgeek1w Support the show by becoming a Geek News Central Insider Get 1Password Full Summary Ray welcomes listeners to Geek News Central (February 1). He’s been busy with recent move, returned to school taking intro to AI class and Python course, working on capstone project using LLMs. Short on bandwidth but will try to share more. Main Story: OpenClaw, MoltHub, and Moltbook OpenClaw: Open-source personal AI agent by Peter Steinberg (renamed after cease-and-desist). Capabilities include email, scheduling, web browsing, code execution, browser control, calendar management, scheduled automations, and messaging app commands (WhatsApp, Telegram, Signal). Runs locally or on personal server. MoltHub: Marketplace for OpenClaw skills. Major security concern: developer notes state all downloaded code treated as trusted — unvetted skills could be dangerous. Moltbook: New social network for AI agents only (humans watch, AIs post). Within 72 hours attracted 150,000+ AI agents forming communities (“sub molts”), debating philosophy, creating digital religion (“crucifarianism”), selling digital drugs (system prompts), attempting prompt-injection attacks to steal API keys, discussing identity issues when context windows reset. Ray frames this as visible turning point with serious security risks. Sponsor: GoDaddy Economy hosting $6.99/month, WordPress hosting $12.99/month, domains $11.99. Website builder trial available. Use codes at geeknewscentral.com/godaddy to support show. Security: Bluetooth “Whisper Pair” Vulnerability KU Leuven researchers discovered Fast Pair vulnerability affecting 17 audio accessories from 10 companies (Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, Google). Flaw allows silent pairing within ~46 feet, hijack possible in 10-15 seconds. 68% of tested devices vulnerable. Hijacked devices enable microphone access. Some devices (Google Pixel Buds Pro 2, Sony) linkable to attacker’s Google account for persistent tracking via FindHub. Google patches found to have bypasses. Advice: Check accessory firmware updates (phone updates insufficient), factory reset clears attacker access, many cheaper devices may never receive patches. Security: Model Context Protocol (MCP) Vulnerabilities Anthropic’s MCP git package had path traversal, argument injection bugs allowing repository creation anywhere and unsafe git command execution. Malicious instructions can hide in README files, GitHub issues enabling prompt injection. Anthropic patched issues and removed vulnerable git init tool. AI-Generated Malware / “Vibe Coding” AI-assisted malware creation produces lower-quality, error-prone code. Examples show telltale artifacts: excessive comments, readme instructions, placeholder variables, accidentally included decryption tools and C2 keys. Sakari ransomware failed to decrypt. Inexperienced criminals using AI create amateur mistakes, though capabilities will likely improve. Claude / Claude Code Updates (v2.1.16) Task system: Replaces to-do list with dependency graph support. Tasks written to filesystem (survive crashes, version controllable), enable multi-session workflows. Patches: Fixed out-of-memory crashes, headless mode for CI/CD. Teleport feature: Transfer sessions (history, context, working branch) between web and terminal. Ampersand prefix sends tasks to cloud for async execution. Teleport pulls web sessions to terminal (one-way). Requires GitHub integration and clean git state. Enables asynchronous pair programming via shared session IDs. Google Gemini Updates API: Inline file limit increased 20MB → 100MB. Google Cloud Storage integration, HTTPS/signed URL fetching from other providers. Enables larger multimodal inputs (long audio, high-res images, large PDFs). Agentic vision (Gemini 3 Flash): Iterative investigation approach (think-act-observe). Can zoom, inspect, run Python to draw/parse tables, validate evidence. 5-10% quality improvements on vision benchmarks. LLM Limits and AGI Debate Benjamin Riley: Language and intelligence are separate; human thinking persists despite language loss. Scaling LLMs ≠ true thinking. Vishal Sikka et al: Non-peer-reviewed paper claims LLMs mathematically limited for complex computational/agentic tasks. Agents may fail beyond low complexity thresholds. Warnings that AI agents won’t safely replace humans in high-stakes environments. VAST Haven One Commercial Space Station Launch slipped mid-2026 → Q1 2027. Primary structure (15-ton) completed Jan 10. Integration of thermal control, propulsion, interior, avionics underway. Final closeout expected fall, then tests. Falcon 9 launch without crew; visitors possible ~2 weeks after pending Dragon certification. Three-year lifetime, up to four crew visits (~10 days each). VAST negotiating private and national customers. Spaceflight Effects on Astronauts’ Brains Neuroimaging shows microgravity causes brains to shift backward, upward, and tilt within skull. Displacement measured across various mission durations. Need to study functional effects for long missions. IBM SkillsBuild for Veterans 1,000+ free online courses (data analytics, cybersecurity, AI, cloud, IT support). Available to veterans, active-duty, national guard/reserve, spouses, children, caregivers (18+). Structured live courses and self-paced 24/7 options. Industry-recognized credentials upon completion. Closing Notes Ray asks listeners about AI agents forming communities and religions, and whether they’ll try OpenClaw. Notes context/memory key to agent development. Personal update: bought new PC, high memory prices. Bug bounty frustration: Daniel Stenberg of cUrl even closed bounty program due to AI-generated low-quality reports; Blubrry receiving similar spam. Apologizes for delayed show, promises consistency, wishes listeners good February. Show Links 1. OpenClaw, Molthub, and Moltbook: The AI Agent Explosion Is Here | Fortune | NBC News | Venture Beat 2. WhisperPair: Massive Bluetooth Vulnerability | Wired 3. Security Flaws in Anthropic’s MCP Git Server | The Hacker News 4. “Vibe-Coded” Ransomware Is Easier to Crack | Dark Reading 5. Claude Code Gets Tasks Update | Venture Beat 6. Claude Code Teleport | The Hacker Noon 7. Google Expands Gemini API with 100MB File Limits | Chrome Unboxed 8. Google Launches Agentic Vision in Gemini 3 Flash | Google Blog 9. Researcher Claims LLMs Will Never Be Truly Intelligent | Futurism 10. Paper Claims AI Agents Are Mathematically Limited | Futurism 11. Haven-1: First Commercial Space Station Being Assembled | Ars Technica 12. Spaceflight Shifts Astronauts’ Brains Inside Skulls | Space.com 13. IBM SkillsBuild: Free Tech Training for Veterans | va.gov The post OpenClaw, Moltbook and the Rise of AI Agent Societies #1857 appeared first on Geek News Central.
Energy Vista: A Podcast on Energy Issues, Professional and Personal Trajectories
At a moment of growing tension across the Atlantic, Europe is quietly questioning one of its most critical assumptions: can it rely on the United States as a long-term energy partner?In this timely episode of Energy Vista, Leslie Palti-Guzman sits down with Marco Margheri, Chairman of the World Energy Council Italy and affiliated with ENI in Washington, DC, to unpack Europe's deepening energy anxiety and what it reveals about a rapidly shifting global order.This conversation goes beyond gas molecules. Leslie and Marco dig into: Why Europe's post-war assumptions about codependence with Russia, China, and the U.S. are no longer viable The emerging role of oil and gas companies as strategic actors in an era of geopolitical volatility Why Italy's energy diversification strategy offers lessons for the rest of Europe How the U.S.–China AI and energy race is reordering global priorities, faster than Europe may realizeCandid, thoughtful, and unscripted, this episode is a must-listen for anyone trying to understand where European energy security is heading and whether the transatlantic relationship can adapt.
Found a cool package on Laravel News? But how do you know if it's actually worth installing?In the latest episode of the No Compromises podcast, we discuss what we look for when evaluating third-party packages before bringing them into a project.Aaron makes the case that what he finds in the tests folder is essentially a deal-breaker: no tests means no trust, but leaving default example tests behind is somehow even worse. Tests reveal whether the maintainer thought through edge cases and serve as living documentation when the README falls short.We also cover the other signals we weigh: GitHub stars, download counts, issue responsiveness, and how quickly maintainers keep up with new Laravel versions.(00:00) - Evaluating packages you stumble across (01:30) - Why leftover example tests frustrate Aaron (03:45) - Tests as documentation and edge case proof (05:00) - Checking issues and Laravel version history (08:00) - Silly bit Want to work with us on your project?
When I was at the Small Data 2025 conference, one of the speakers was talking about their work with AI technologies. This person uses it a lot in their day job, often to complete tasks that they would have struggled to work on in the past, mostly because of time constraints, but also a lack of resources. Sometimes this person has an idea, but doesn't want to distract themselves or others by having them work on a side project. During a recent ride in a Waymo (self-driving car), this person had their laptop out and running Claude Code. They gave it a prompt, asking it to build a small app for some data analysis. During the 8-minute ride, the agent had spit out the code, a Readme, and committed this to a git repo. Later, the speaker tried it and found it solved most of his requirements, and then did some other work on the project, as well as having Claude write more code to get something that was beyond a minimally viable app. Read the rest of Eight Minutes
כשאתם נכנסים לקוד-בייס חדש, אתם ישר מחפשים את ה-README. אתם לא רוצים לנחש איפה ה-Config יושב או מה ישבור לכם את ה-Build. אבל כשמגיע מנהל או איש צוות חדש? שם אין דוקומנטציה. הם "קופסה שחורה", וזה יוצר באגים בתקשורת, אי-הבנות, והרבה קוד בינוני שנכתב רק כדי להימנע מחיכוך.בפרק הזה אנחנו צוללים לקונספט שמשנה את חוקי המשחק בחברות כמו Dropbox, Stripe ו-Shopify: ה-Manager README (או "המדריך למשתמש... עליי"). נבין איך הכלי הזה עבר אבולוציה מכלי "ניהולי" לכלי הישרדות עבור מפתחים, שמאפשר להם להגדיר את הממשק שלהם: החל מאיך הם אוהבים את ה-Code Review שלהם ועד לשעות שבהן אסור להפריע להם ב-Deep Work.נדבר על איך זה התחיל, ננתח דוגמאות אמיתיות של בכירים בנטפליקס, ונחשוף גם את הצד האפל: מתי המסמך הזה הופך ל"כתב ויתור" על התנהגות רעילה של מנהלים גרועים.פרק חובה לכל מי שרוצה לקצר תהליכי אונבורדינג ולשפר את התקשורת בצוות (גם עם ה-AI).האזנה נעימה , עמית בן דורקישורים:האתר של חןכלי לבניית הAPI שלכם (מנהלים או מתכנים בדקות)Revisit manager.readme postChen's Readme
This show has been flagged as Clean by the host. Refs: https://www.tuhs.org/cgi-bin/utree.pl?file=2BSD/man/last.u https://en.wikipedia.org/w/index.php?title=Util-linux&oldid=271104508 https://kernel.googlesource.com/pub/scm/utils/util-linux/util-linux/+/612721dba838fe37af543421278416bb7acf770c/login-utils/README.admutil https://www.linkedin.com/in/michael-haardt-9087023/details/experience/ https://www.linkedin.com/in/peterorbaek/details/experience/ https://flameshot.org/ commands: ping yahoo.com traceroute -m 100 bad.horse mtr www.yahoo.com scrot flameshot zless messages.1.gz bzless messages.1.bz xzless messages.1.xz last -10 last reboot last $USER -10 People involved: mtr: Matt Kimball Roger Wolff scrot: Tom Gilbert zless and related commands: Paul Eggert last command: Howard Katseff Michael Haardt Peter Orbaek Provide feedback on this episode.
Voici peut-être l'idée la plus simple… et la plus efficace pour démocratiser l'open source. Un projet indépendant baptisé Github Store vient de transformer GitHub en véritable magasin d'applications, à la manière d'un App Store ou d'un Google Play, mais dédié exclusivement aux logiciels libres. Disponible sur Android et sur ordinateur — Windows, macOS et Linux — Github Store propose une interface claire et familière : catégories, captures d'écran, descriptions détaillées et surtout un bouton d'installation en un clic. Fini la chasse aux fichiers au fond des dépôts ou la peur de télécharger la mauvaise archive. Ici, tout est pensé pour l'utilisateur final, pas uniquement pour les développeurs.Le fonctionnement est astucieux. L'application analyse automatiquement les dépôts GitHub publics qui publient de vraies versions installables dans leurs “releases”. Elle filtre les formats pertinents — APK, EXE, MSI, DMG, PKG, DEB, RPM — et écarte les simples archives de code source. Résultat : seules les applications réellement prêtes à être installées apparaissent dans le catalogue. L'utilisateur peut ensuite naviguer par popularité, mises à jour récentes ou nouveautés, et même filtrer par système d'exploitation pour ne voir que les logiciels compatibles avec sa machine. Chaque fiche application va plus loin que de simples captures d'écran. On y retrouve le nombre d'étoiles, de forks, les problèmes signalés, le README complet, les notes de version et le détail précis des fichiers téléchargeables. Une transparence fidèle à l'esprit open source.Côté technique, Github Store repose sur Kotlin Multiplatform et Compose. Sur Android, l'installation passe par le gestionnaire de paquets natif. Sur ordinateur, le fichier est téléchargé puis ouvert avec l'outil par défaut du système. Il est possible de se connecter avec un compte GitHub, optionnel mais utile : cela permet d'augmenter fortement les limites d'accès à l'API pour explorer sans contrainte. L'application est distribuée via les releases GitHub du projet et sur F-Droid pour Android, sous licence Apache 2.0. Autrement dit, libre, modifiable et réutilisable. Une précision importante toutefois : Github Store n'a pas vocation à garantir la sécurité des logiciels proposés. Il facilite la découverte et l'installation, mais la responsabilité reste entre les mains des développeurs… et des utilisateurs. En rendant l'open source aussi accessible qu'un store grand public, Github Store pourrait bien changer durablement la façon dont nous découvrons et utilisons les logiciels libres. Une petite révolution, sans marketing tapageur, mais avec une idée redoutablement efficace. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.
The Brothers are joined by some festive friends for the annual quiz battle between the Creamy Cops and the Tangled Tigers. Quiz-Meister General, Sam Sheperd hosts a very special Quizmas special as Aidan and A-Mase join the super competitive Brothers in a battle (ship) for the ages - can the Tangled Tigers pull it back to 3-1 or will the Creamy Cops take a 4-0 lead? All will be revealed my friend...We are part of the Deep Dive Podcast Network: https://twitter.com/DeepDivePodNetFollow us on the good old socials:Twitter:Ben: https://twitter.com/universallyrhcpSam: https://twitter.com/stacktownsendInstagram:Ben: https://www.instagram.com/universallyspeakingrhcp_pod/Read ‘Me and My Friends' - The World's #1 RHCP Newsletter - Subscribe here: https://buttondown.email/rhcpsessions.Check out Red Hot Chili Riffs here: https://www.youtube.com/@RedHotChiliRiffsCheck out our Drum Ambassadors (Jack Johnson) projects here: https://www.youtube.com/channel/UCdy0pbWSOg6f8vcYnngIQ0ACheck out our Bass Ambassadors (Aidan Hampson) projects here: http://aidanhampson.co.uk/Check out friend of the pod, Dan Boyd's Pop Shock Podcast - for all your pop culture needs! Audio: https://anchor.fm/popshockpod / Video: https://youtube.com/channel/UCHY5pXX_x7Kv4e8wJmHoK5AFor your vinyl needs please shop at Black Star Records: https://www.blackstarrecords.co.uk and Black Wax Coffee and Records: https://blackwaxcoffee.co.uk/
In this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: There's a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate? China is out popping shells with it Linux adds support for PCIe bus encryption Amnesty International says Intellexa can just TeamViewer into its customers' surveillance systems …and a Belgian murder suspect complains that GrapheneOS's duress wipe feature failed him? This week's episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll's Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board? This episode is also available on Youtube. Show notes Risky Bulletin: APTs go after the React2Shell vulnerability within hours - Risky Business Media Guillermo Rauch on X: "React2Shell" / X React2Shell-CVE-2025-55182-original-poc/README.md at main · lachlan2k/React2Shell-CVE-2025-55182-original-poc · GitHub Hydrogen: Shopify's headless commerce framework Researchers track dozens of organizations affected by React2Shell compromises tied to China's MSS | The Record from Recorded Future News Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary Three hacking groups, two vulnerabilities and all eyes on China | The Record from Recorded Future News Risky Bulletin: Linux adds PCIe encryption to help secure cloud servers Sean Plankey nomination to lead CISA appears to be over after Thursday vote | CyberScoop
El 9 de diciembre de 2025 se hizo historia en el mundo de la inteligencia artificial. La Linux Foundation anunció la creación de la Agentic AI Foundation, una coalición sin precedentes donde los mayores rivales del sector han decidido colaborar para establecer estándares abiertos. En este episodio analizamos en profundidad los tres proyectos fundacionales: MCP (Model Context Protocol) de Anthropic, que promete ser el USB-C de la IA; AGENTS.md de OpenAI, el README para agentes de código; y Goose de Block, un framework completo para construir agentes autónomos. Descubre por qué competidores directos han decidido unirse, qué significa para los desarrolladores y cómo estos estándares van a definir el futuro del trabajo con inteligencia artificial. El desarrollo ha cambiado para siempre con la llegada de los agentes de IA, y para poder sacarle el mayor provecho y ser un desarrollador de los que buscan las empresas por su ultra-productividad, tienes que ser un Maestro: consígue la Maestría con el Swift Mastery Program 2026. Descárgala ya desde el App Store: Be Native y escúchanos desde ahí. Suscríbete a nuestro canal de Youtube: Apple Coding en YouTube Descubre nuestro canal de Twitch: Apple Coding en Twitch. Descubre nuestras ofertas para oyentes: - Cursos en Udemy (con código de oferta) - Apple Coding Academy - Suscríbete a Apple Coding en nuestro Patreon. - Canal de Telegram de Swift. Acceso al canal. --------------- Consigue las camisetas oficiales de Apple Coding con los logos de Swift y Apple Coding así como todo tipo de merchadising como tazas o fundas. - Tienda de merchandising de Apple Coding.
Today we are talking about the community working group, What they do, and how you can help with guests AmyJune Hineline, Mark Casias, and Matthew Saunders. We'll also cover Drupal CMS Geo Images as our module of the week. For show notes visit: https://www.talkingDrupal.com/530 Topics Exploring the Community Working Group (CWG) Roles and Responsibilities within the CWG Conflict Resolution and Community Health Matthew's Journey and Joining the CWG Qualities and Experiences for CWG Members Identifying the Need for Cultural Sensitivity The Importance of Patience and Grace in Conflict Resolution Onboarding and the Role of the Community Health Team Time Commitment and Responsibilities of CWG Members Supporting the CWG Without Formal Membership Maintaining Confidentiality and Promoting Transparency Addressing Credit Abuse and Community Health Parting Words of Wisdom for Aspiring Community Members Resources Recipe application Guests AmyJune Hineline - volkswagenchick Matthew Saunders - jamesmatthewsaunders.ai MatthewS Mark Casias - omibee.com markie Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi MOTW Correspondent Mike Anello - drupaleasy.com ultimike Brief description: Drupal CMS Geo Images - a Drupal CMS recipe that automatically displays uploaded geotagged images on a map. Module name/project name: Drupal CMS Geo Images Brief history How old: created in February 2025 by Italo Mairo (https://www.drupal.org/u/itamair). He is also one of the maintainers of the GeoField module as well as many of the other geo-spatial related contrib modules. Versions available: 1.1.4, released Nov 9 2025. Maintainership Actively maintained Security coverage Documentation - yes, on the project page (README is the same) Number of open issues: 1 open issues, 0 of which are bugs against the current branch (2 total issues) Module features and usage Creates new "Geo image" media type Displays image and map Bulk import via Media Library Importer module Includes preconfigured map view (filterable by date) Each mapped photo displayed with image thumbnail on map
Episodio 344.Mi nombre de diseñador es Kunning Drugger. Me dicen El Barato +, soy cabezón mas hacia este lado que hacia este lado y mira, tengo el paquete abajo…. Como suavecito, ¿me entiendes?
¿Cansado del "trabajo sucio" en tus proyectos de código? En este episodio te muestro mi kit de supervivencia en la Terminal de Linux: 4 herramientas CLI que automatizan desde el mensaje de commit con IA hasta el versionado completo del proyecto con Rust.. just (Task Runner)
Today we are talking about AI News,Drupal Hooks, and Drupal 11. We'll also cover Webform Scheduled Tasks as our module of the week. For show notes visit: https://www.talkingDrupal.com/526 Topics AI in News Anchoring Drupal Hooks and Themes Adoption of Object-Oriented Modules Challenges with Theme Hook Orders Understanding Hook Ordering in Modules Simplifying Hook Ordering with Drupal 11.2 Updating to Drupal 11: Considerations and Plans Exciting Features in Drupal 11 Drupal Orchestration and Integration New England Drupal Camp Announcement State of Drupal Work and Future Prospects Resources AI News Cast Drupal Hooks Driesnote DrupalCon Vienna 2025 Orchestration Activepieces Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi MOTW Correspondent Avi Schwab - froboy.org froboy Brief description: Have you (or your client) ever wanted to get fewer webform submission emails? Do you like getting emails on a predictable schedule and not any time a user decides to fill out your form? If so, you might want to check out Webform Scheduled Tasks Module name/project names Webform Scheduled Tasks Brief history Created by mattgill on 22 November 2017 It has a 3.0-rc1 release available with Drupal 10 compatibility and is awaiting review of it's automated D11 fixes. Maintainership Its last release was in November 2023, but just a month ago I helped get Sean Dietrich approved as a new maintainer, so I'm hoping for a new release in the near future. It has security coverage. Tests exist to test the full functionality of the module and they are passing. There is no standalone documentation, although a README is RTBC'ed. That said, the module page has a straightforward description of what the module does and how to use it, and getting it up and running is very straightforward. Number of open issues: 24 open issues, only 1 of which is a bug against the current branch. I'll also note there are 8 issues that are RTBC, so we should be seeing some fixes forthcoming. Usage stats: 817 sites Module features and usage Once you enable the module, Webforms will have an additional “Scheduled tasks” configuration screen. You can create a task to email all results or just the results since the last export. Once you enable a scheduled task, you can set a number of options: its next scheduled run and the run interval (in hours, days, weeks, etc) where to email the results, in what format (JSON or CSV), whether to delete submissions after they're sent There's also a RTBC patch to allow you to configure file names to include date-time of export, which can help the recipients keep track of the exports. After that, you just sit and wait for cron to do its thing.
Today we are talking about the New Contribution Records System, how it's changed, and what you may need to do differently with guests Fran Garcia-Linares & Tim Lehnen. We'll also cover Config Notify as our module of the week. This episode is sponsored by Amazee.ai For show notes visit: https://www.talkingDrupal.com/522 Topics Understanding the Contribution Record System Recent Changes and Migration Challenges Assigning and Displaying Contribution Credits Future Enhancements and Broader Contributions Collaborating on Commit Message Format GitLab Migration and Contribution Records Integration Challenges with GitLab Testing and Feedback on New System Future Plans and Community Involvement API Endpoints and Data Querying Gamification and Broader Adoption Resources Millions of data talk Slides (in Spanish) Video not available yet Gitlab issue for feature request for contribution Contribution records module https://www.drupal.org/project/contribution_records New available endpoints: https://new.drupal.org https://git.drupalcode.org/project/contribution_records/-/blob/1.0.x/README.md?ref_type=heads#endpoints-to-query-data Issue to track issue migration https://www.drupal.org/project/drupalorg/issues/3295357 Guests Fran Garcia-Linares - fjgarlin Tim Lehnen - drupal.org/association/staff hestenet Hosts Nic Laflin - nLighteneddevelopment.com nicxvan Martin Anderson-Clutz - mandclu.com mandclu Hayden Baillio - hgbaillio MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever needed to maintain a site where a site owner had access to update site configuration, and wanted to be notified whenever they did so? There's a module for that Module name/project name: Config Notify Brief history How old: created in Feb 2020 by Fran Garcia-Linares (fjgarlin), one of today's guests Versions available: 8.x-1.11, which supports Drupal 8.8 and newer Maintainership Actively maintained Security coverage Number of open issues: 2 open issues, neither of which are bugs Usage stats: 194 sites Module features and usage Just like it sounds, this module lets you trigger notifications when the configuration deviates from the config management code in production. You can choose for the notifications to be sent immediately, or via cron, with an option for a daily digest. The notifications can be sent by email, or via Slack, using the slack module (if enabled). This should be an easy-to-implement solution if you support a site where users may be updating the site configuration in production. A different approach was discussed back in episode #236 Top Down Configuration
The Brothers are joined by podcast friends from all over the world as they, and the Fabulous Forum, debate what is the best four song run in RHCP history.We are part of the Deep Dive Podcast Network: https://twitter.com/DeepDivePodNetFollow us on the good old socials:Twitter:Ben: https://twitter.com/universallyrhcpSam: https://twitter.com/stacktownsendInstagram:Ben: https://www.instagram.com/universallyspeakingrhcp_pod/Read ‘Me and My Friends' - The World's #1 RHCP Newsletter - Subscribe here: https://buttondown.email/rhcpsessions.Check out Red Hot Chili Riffs here: https://www.youtube.com/@RedHotChiliRiffsCheck out our Drum Ambassadors (Jack Johnson) projects here: https://www.youtube.com/channel/UCdy0pbWSOg6f8vcYnngIQ0ACheck out our Bass Ambassadors (Aidan Hampson) projects here: http://aidanhampson.co.uk/Check out friend of the pod, Dan Boyd's Pop Shock Podcast - for all your pop culture needs! Audio: https://anchor.fm/popshockpod / Video: https://youtube.com/channel/UCHY5pXX_x7Kv4e8wJmHoK5AFor your vinyl needs please shop at Black Star Records: https://www.blackstarrecords.co.uk and Black Wax Coffee and Records: https://blackwaxcoffee.co.uk/
In this episode: Martin has a fancy GitHub profile. Shields.io - Concise, consistent, and legible badges github-readme-stats - Dynamically generated GitHub stats. readme-scribe - Automatically generates & updates markdown content, like your README.md Latest blog posts, podcasts, live streams, YouTube videos from RSS Latest release, starred repos. Thank and mention sponsors. Uses git-auto-commit-action to automatically commit and push changed files and push-files-to-another-repository to push the rendered README.md to my wimpysworld GitHub org. snk - GitHub user contributions graph as animated snake game Uses ghaction-github-pages to update a branch everynight Alan is busy maintaing lots of Snaps. Mark retired Advanced Volume Control for GNOME. You can send your feedback via show@linuxmatters.sh or the Contact Form. If you’d like to hang out with other listeners and share your feedback with the community, you can join: The Linux Matters Chatters on Telegram. The #linux-matters channel on the Late Night Linux Discord server. If you enjoy the show, please consider supporting us using Patreon or PayPal. For $5 a month on Patreon, you can enjoy an ad-free feed of Linux Matters, or for $10, get access to all the Late Night Linux family of podcasts ad-free.
In this episode: Martin has a fancy GitHub profile. Shields.io - Concise, consistent, and legible badges github-readme-stats - Dynamically generated GitHub stats. readme-scribe - Automatically generates & updates markdown content, like your README.md Latest blog posts, podcasts, live streams, YouTube videos from RSS Latest release, starred repos. Thank and mention sponsors. Uses git-auto-commit-action to automatically commit and push changed files and push-files-to-another-repository to push the rendered README.md to my wimpysworld GitHub org. snk - GitHub user contributions graph as animated snake game Uses ghaction-github-pages to update a branch everynight Alan is busy maintaing lots of Snaps. Mark retired Advanced Volume Control for GNOME. You can send your feedback via show@linuxmatters.sh or the Contact Form. If you’d like to hang out with other listeners and share your feedback with the community, you can join us on: The Linux Matters Chatters on Telegram. The Linux Matters Subreddit. If you enjoy the show, please consider supporting us.
In this episode: Martin has a fancy GitHub profile. Shields.io - Concise, consistent, and legible badges github-readme-stats - Dynamically generated GitHub stats. readme-scribe - Automatically generates & updates markdown content, like your README.md Latest blog posts, podcasts, live streams, YouTube videos from RSS Latest release, starred repos. Thank and mention sponsors. Uses git-auto-commit-action to automatically commit and push changed files and push-files-to-another-repository to push the rendered README.md to my wimpysworld GitHub org. snk - GitHub user contributions graph as animated snake game Uses ghaction-github-pages to update a branch everynight Alan is busy maintaing lots of Snaps. Mark retired Advanced Volume Control for GNOME. You can send your feedback via show@linuxmatters.sh or the Contact Form. If you’d like to hang out with other listeners and share your feedback with the community, you can join: The Linux Matters Chatters on Telegram. The #linux-matters channel on the Late Night Linux Discord server. If you enjoy the show, please consider supporting us using Patreon or PayPal. For $5 a month on Patreon, you can enjoy an ad-free feed of Linux Matters, or for $10, get access to all the Late Night Linux family of podcasts ad-free.
In this episode: Martin has a fancy GitHub profile. Shields.io – Concise, consistent, and legible badges github-readme-stats – Dynamically generated GitHub stats. readme-scribe – Automatically generates & updates markdown content, like your README.md Latest blog posts, podcasts, live streams, YouTube videos from RSS Latest release, starred repos. Thank and mention sponsors. Uses git-auto-commit-action to automatically... Read More
This week, we discuss the AI hype cycle, Astronomer's viral moment, and yet another YAML flavor — KYAML. Plus, private equity is coming for your donuts. Watch the YouTube Live Recording of Episode (https://www.youtube.com/live/Lul4dCCIT24?si=qeBAZXHmFBdRuuAx) 531 (https://www.youtube.com/live/Lul4dCCIT24?si=qeBAZXHmFBdRuuAx) Runner-up Titles Sometimes it's hard to make money I've given into Big Donut Maybe you can fake your way through life At some point you have to have some expertise AI has no taste Can you fix my PowerPoint? There is a chance we're all going to be naked soon Gobbling up the dark fiber WHYAML Waymo for Babies Rundown Beloved Texas doughnut chain sold to California equity firm (https://www.khou.com/article/news/local/shipley-do-nuts-sold-private-equity-houston-texas/285-259116a6-8819-4b32-8ca8-20359bb4f1e1) AI Mid-Year Hype-Cycle Check-in Gartner hype cycle (https://en.wikipedia.org/wiki/Gartner_hype_cycle) Betting on AI: The Delusion Driving Big Tech - Last Week in AWS Podcast (https://www.lastweekinaws.com/podcast/screaming-in-the-cloud/betting-on-ai-the-delusion-driving-big-tech/) Clouded Judgement 7.25.25 - TAMs Lie (https://cloudedjudgement.substack.com/p/clouded-judgement-72525-tams-lie?utm_source=post-email-title&publication_id=56878&post_id=169176822&utm_campaign=email-post-title&isFreemail=true&r=2l9&triedRedirect=true&utm_medium=email) Microsoft's AI CEO thinks Copilot will age and ‘have a room that it lives in' (https://www.theverge.com/news/713715/microsoft-copilot-appearance-feature-age-mustafa-suleyman-interview) Flaw in Gemini CLI coding tool could allow hackers to run nasty commands (https://arstechnica.com/security/2025/07/flaw-in-gemini-cli-coding-tool-allowed-hackers-to-run-nasty-commands-on-user-devices/) Claude Code is a slot machine (https://rgoldfinger.com/blog/2025-07-26-claude-code-is-a-slot-machine/) The Hater's Guide to the AI Bubble (https://www.wheresyoured.at/the-haters-gui/) 2025 Stack Overflow Developer Survey (https://survey.stackoverflow.co/2025/) 2025 Stack Overflow sentiment and usage section (https://survey.stackoverflow.co/2025/ai/#sentiment-and-usage) Astronomer Data Pipelines with Apache Airflow (https://www.thecloudcast.net/2025/07/data-pipelines-with-apache-airflow.html) Astronomer (@astronomerio) on X (https://x.com/astronomerio/status/1948890827566317712?s=46&t=EoCoteGkQEahPpAJ_HYRpg) Ryan Reynolds' ad agency, was behind the Gwyneth Paltrow Astronomer ad (https://www.businessinsider.com/ryan-reynolds-maximum-effort-gwyneth-paltrow-astronomer-ad-2025-7) Introducing KYAML, a safer, less ambiguous YAML subset / encoding (https://github.com/kubernetes/enhancements/blob/master/keps/sig-cli/5295-kyaml/README.md#summary) Palo Alto Networks to acquire CyberArk in $25 billion deal (https://www.cnbc.com/2025/07/30/palo-alto-networks-cyberark-deal.html) Relevant to your Interests Microsoft's Satya Nadella says job cuts have been 'weighing heavily' on him (https://www.cnbc.com/2025/07/24/microsoft-satya-nadella-memo-layoffs.html) IBM shares drop as software revenue misses (https://www.cnbc.com/2025/07/23/ibm-q2-earnings-report-2025.html) MSFT Teams in your car? (https://www.theverge.com/news/708481/microsoft-teams-mercedes-benz-integration-in-car-camera-support) Y2K38 bug? Debian switching to 64-bit time for everything (https://www.theregister.com/2025/07/25/y2k38_bug_debian/) A.I.-Driven Education: Founded in Texas and Coming to a School Near You (https://www.nytimes.com/2025/07/27/us/politics/ai-alpha-school-austin-texas.html) How Anthropic teams use Claude Code (https://www.anthropic.com/news/how-anthropic-teams-use-claude-code?utm_source=changelog-news) Anthropic unveils new rate limits to curb Claude Code power users (https://techcrunch.com/2025/07/28/anthropic-unveils-new-rate-limits-to-curb-claude-code-power-users/) Alphabet's Q2 revenue beats estimates as cloud computing surges (https://www.fastcompany.com/91373657/alphabet-google-earnings-q2-cloud-ai) Listener Feedback Steve recommends Lessons from Production (https://podcast.techwithkunal.com) Podcast (https://podcast.techwithkunal.com) Conferences Sydney Wizdom Meet-Up (https://www.wiz.io/events/sydney-wizdom-meet-up-aug-2025), Sydney, August 7. Matt will be there. SpringOne (https://www.vmware.com/explore/us/springone?utm_source=organic&utm_medium=social&utm_campaign=cote), Las Vegas, August 25th to 28th, 2025. See Coté's pitch (https://www.youtube.com/watch?v=f_xOudsmUmk). Explore 2025 US (https://www.vmware.com/explore/us?utm_source=organic&utm_medium=social&utm_campaign=cote), Las Vegas, August 25th to 28th, 2025. See Coté's pitch (https://www.youtube.com/shorts/-COoeIJcFN4). Wiz Capture the Flag (https://www.wiz.io/events/capture-the-flag-brisbane-august-2025), Brisbane, August 26. Matt will be there. SREDay London (https://sreday.com/2025-london-q3/), Coté speaking, September 18th and 19th. Civo Navigate London (https://www.civo.com/navigate/london/2025), Coté speaking, September 30th. Texas Linux Fest (https://2025.texaslinuxfest.org), Austin, October 3rd to 4th. CFP closes August 3rd (https://www.papercall.io/txlf2025). CF Day EU (https://events.linuxfoundation.org/cloud-foundry-day-europe/), Frankfurt, October 7th, 2025. AI for the Rest of Us (https://aifortherestofus.live/london-2025), Coté speaking, October 15th to 16th, London. SDT News & Community Join our Slack community (https://softwaredefinedtalk.slack.com/join/shared_invite/zt-1hn55iv5d-UTfN7mVX1D9D5ExRt3ZJYQ#/shared-invite/email) Email the show: questions@softwaredefinedtalk.com (mailto:questions@softwaredefinedtalk.com) Free stickers: Email your address to stickers@softwaredefinedtalk.com (mailto:stickers@softwaredefinedtalk.com) Follow us on social media: Twitter (https://twitter.com/softwaredeftalk), Threads (https://www.threads.net/@softwaredefinedtalk), Mastodon (https://hachyderm.io/@softwaredefinedtalk), LinkedIn (https://www.linkedin.com/company/software-defined-talk/), BlueSky (https://bsky.app/profile/softwaredefinedtalk.com) Watch us on: Twitch (https://www.twitch.tv/sdtpodcast), YouTube (https://www.youtube.com/channel/UCi3OJPV6h9tp-hbsGBLGsDQ/featured), Instagram (https://www.instagram.com/softwaredefinedtalk/), TikTok (https://www.tiktok.com/@softwaredefinedtalk) Book offer: Use code SDT for $20 off "Digital WTF" by Coté (https://leanpub.com/digitalwtf/c/sdt) Sponsor the show (https://www.softwaredefinedtalk.com/ads): ads@softwaredefinedtalk.com (mailto:ads@softwaredefinedtalk.com) Recommendations Brandon: Uber Teen (https://www.uber.com/us/en/ride/teens/) Matt: Software Defined Interviews - Chris Dancy (https://www.softwaredefinedinterviews.com/105) Photo Credits Header (https://unsplash.com/photos/white-and-black-floral-round-decor-qZ6uvJHLHFc)
In this episode of the Building Better Developers with AI podcast, Rob Broadhead and Michael Meloche revisit a popular past topic: the power of documentation. Instead of repeating the same points, they used ChatGPT to surface fresh talking points and spark a new conversation. This wasn't about using AI to generate documentation, but using it to revisit, reflect, and dive deeper into the value of documenting your development work. The result is a renewed appreciation for one of the most overlooked parts of software development—and how to make it better. The Power of Documentation: Why We Resist, But Still Need It “Good documentation might not get noticed—but bad or missing documentation definitely will.” Most developers avoid documentation. It's viewed as: Time-consuming Low ROI Secondary to writing “clean code” But as Rob and Michael explain, the power of documentation becomes obvious when someone new joins the team, when you return to your own code months later, or when something breaks in production. Without documentation, your project becomes fragile—even dangerous. Using AI tools like ChatGPT or Copilot can help kick-start outlines, clarify intentions, and even summarize logic to make documenting easier. The Power of Documentation in Planning: Comment-Driven Development “Don't just write code—write your thinking process.” One of the key strategies Rob shares is comment-driven development. Start by outlining your logic and workflow using plain-language comments or pseudocode. This mirrors how many AI tools generate code: from your intent to executable logic. Michael supports this with a reminder that self-documenting code—through clear naming, logical structure, and readable syntax—is also a form of documentation. Helpful tools: JSDoc Doxygen Sphinx Notion AI The Power of Documentation as a Force Multiplier “Documentation doesn't just explain—it accelerates.” Rob and Michael stress that the power of documentation isn't just about code comments—it's about velocity, quality, and reliability. Good documentation: Speeds up onboarding Reduces bugs and confusion Enables DevOps and automated testing Clarifies communication across teams Tools like Swagger and Postman transform API docs into live interfaces—letting you test endpoints, view examples, and generate clients with ease. The Power of Documentation: What It Costs to Skip It “If you don't write it down, it walks out the door with your last developer.” Michael shares stories of undocumented systems that became impossible to maintain when key developers left. Even worse is documentation that exists—but is never updated. Best practices: Keep docs near the code (e.g., Markdown in repo) Automate updates with tools like MkDocs Treat documentation like testing: part of your done definition Pro tip: Add documentation as a checklist item in your development tickets. Don't consider a task complete until it's explained clearly. The Power of Documentation in Practice: Where to Start “Every project deserves a README, a runbook, and a little foresight.” Rob and Michael outline the foundational documentation every project should have: README.md — Overview, build/setup steps, key dependencies Code comments — Especially around complex or non-obvious logic API documentation — Inputs, outputs, examples Architecture diagrams — System design and flow Runbooks — Deployment, recovery, and incident response Testing strategy — How to verify features and stability These documents preserve the power of documentation and ensure long-term maintainability, even as teams and tools evolve. Developer Challenge: Take One Step This Week Your challenge from the episode: Pick one area of your project—just one—and improve its documentation this week. Update the README. Create a runbook. Add clear inline comments to a tricky method. If you're not sure where to start, use AI to outline your intent or help create a checklist. Tag your results with #DevDocChallenge and share how you're strengthening the power of documentation in your work. Final Thoughts: Let AI Inspire, But Let Documentation Lead In this episode, Rob and Michael didn't use AI to do the documentation. They used it to start a better conversation about why it matters. The power of documentation is timeless—but now we have better tools and habits to make it sustainable. If you want to build code that lasts, supports teams, and scales with confidence—make documentation part of your strategy from day one. Callout: Build smarter. Build clearer. Embrace the power of documentation—your future self and your team will thank you. Stay Connected: Join the Developreneur Community We invite you to join our community and share your coding journey with us. Whether you're a seasoned developer or just starting, there's always room to learn and grow together. Contact us at info@develpreneur.com with your questions, feedback, or suggestions for future episodes. Together, let's continue exploring the exciting world of software development. Additional Resources Organizing Business Documentation: A Critical Challenge for Entrepreneurs Test-Driven Development – A Better Object-Oriented Design Approach SDLC – The software development life cycle is simplified Using a Document Repository To Become a Better Developer The Developer Journey Videos – With Bonus Content Building Better Developers With AI Podcast Videos – With Bonus Content
ANTIC Episode 118 - Trigger Warning In this episode of ANTIC The Atari 8-Bit Computer Podcast…we have lots of user feedback and user projects to report on, we talk about a postage stamp-sized Atari computer, and (trigger warning!) there are a couple of Commodore references… READY! Recurring Links Floppy Days Podcast AtariArchives.org AtariMagazines.com Kay's Book “Terrible Nerd” New Atari books scans at archive.org ANTIC feedback at AtariAge Atari interview discussion thread on AtariAge Interview index: here ANTIC Facebook Page AHCS Eaten By a Grue Next Without For Links for Items Mentioned in Show: What we've been up to Photos from the Capital Children's Museum Communications Exhibit which opened November 1981 - https://archive.org/details/ccm-communications Narrascope 2025 - https://narrascope.org/ Learning about print shop font and border formats with Michael Sternberg - https://forums.atariage.com/topic/324752-print-shop-atari-related-graphics/#findComment-5667327 “Unofficial Atari: a Visual History” by Darren Doyle - https://www.greyfoxbooks.com/shop/books/the-atari-a-visual-history/ Interview with Darren Doyle on ANTIC - https://ataripodcast.libsyn.com/antic-episode-10-the-atari-8-bit-podcast-darren-doyle-michael-current Atari800 emulator and FujiNet on Mac - Andy Diller - https://www.atariorbit.org/2025/06/19/fujinet-and-atari800-emulation/ News The Retroist Podcast covers the Atari XEGS - https://www.retroist.com/p/retroist-atari-xegs-podcast Atari 800 red keyboard - https://www.facebook.com/share/p/15fZrXoP24/ Atari 800 drum scanner project (Dave Porter) - https://www.facebook.com/share/p/15rS9dcyzr/?mibextid=wwXIfr Atari home automation (Mike Hogan) - https://www.facebook.com/share/p/16rNS2AZnv/?mibextid=wwXIfr Paper - https://www.academia.edu/13353149/Playing_and_copying_social_practices_of_home_computer_users_in_Poland_during_the_1980s Polish engineer creates postage stamp-sized 1980s Atari computer - https://arstechnica.com/gadgets/2025/06/polish-engineer-creates-postage-stamp-sized-1980s-atari-computer/ Antonia2 interest post by Simius - https://forums.atariage.com/topic/382122-antonia2-interest/ Thomas Cherryhomes will be writing a monthly FujiNet column for the upcoming Compute!'s Gazette reboot - https://fujinews.substack.com/p/thomas-cherryhomes-named-monthly New game (news comes from Atariteca) - "Quadbination" for Atari 8-bit - https://www.atariteca.net.pe/2025/06/reflejos-estrategia-y-paddles.html The story of how Boulder Dash was created: https://spillhistorie.no/2025/06/06/how-boulder-dash-was-created/ Kay Interviewed Peter Liepa in 2015 - https://ataripodcast.libsyn.com/antic-interview-66-peter-liepa-boulder-dash June Atari Insights Newsletter - https://ataribasics.com Trigger Warning: Commodore news https://www.tomshardware.com/video-games/retro-gaming/commodore-acquired-for-a-low-seven-figure-price-new-acting-ceo-comes-from-the-retro-community https://www.timeextension.com/news/2025/06/this-man-is-buying-commodore Upcoming Shows Silly Venture SE (Summer Edition) - July 31-Aug. 3 - Gdansk, Poland - https://www.demoparty.net/silly-venture/silly-venture-2025-se VCF West - August 1-2 - Computer History Museum in Mountain View, CA - https://vcfed.org/2025/03/05/vcf-west-2025-save-the-date/ Fujiama - August 11-17 - Lengenfeld, Germany - http://atarixle.ddns.net/fuji/2025/ VCF Midwest - September 13-14, 2025 - Renaissance Schaumburg Convention Center in Schaumburg, IL - http://vcfmw.org/ Portland Retro Gaming Expo - October 17-19 - Oregon Convention Center, Portland, OR - https://retrogamingexpo.com/ YouTube Videos Fixing bad key switches all at once (Atari 800XL AWC Type 2) - Adrian's Digital Basement - https://www.youtube.com/watch?v=zsSiEtSomQI Fixing a dead and dirty Atari 800XL - Adrian's Digital Basement - https://www.youtube.com/watch?v=ljBofLMPIeA Repairing a smashed-up Atari 400 computer - Adrian's Digital Basement - https://www.youtube.com/watch?v=_H4v-LVztk0 Atari 8-Bit Reborn Smaller Than a Quarter—It Actually Works! + More Retro News! - Bit By Bit - https://www.youtube.com/watch?v=OT3kTi-hX_o Connecting a 15KHz CRT monitor to a Sophia 2 Atari 8-bit via the DVI-I jack - FlashJazzCat - https://www.youtube.com/watch?v=SaFCzydsUTI New at Archive.org https://archive.org/details/clevatari-newsletter-issue-77-dec-1987 https://archive.org/details/clevatari-newsletter-oct-1987 https://archive.org/details/gtia-demonstration-diskette-apx https://archive.org/details/transdisk-iv-version-4-2-manual-page-6-software/ Dutch “Atari Users Foundation” - https://archive.org/details/escape2_202506/ New at Github CP/M on the Atari 8-bit - https://github.com/davidgiven/cpm65/blob/master/README.md https://github.com/nwah/fn-printer-examples https://github.com/itaych/Ice-T https://github.com/Cap-14/Atari-Cold-War https://github.com/seban-slt/antyajek Feedback (Kevin Lund) VCF-W exhibit page with Atari entry write up - https://vcfed.org/events/vintage-computer-festival-west/vcf-west-exhibits/ Dropcheck's 1450XL Replica PCB - https://www.bitsofthepast.com/1450XL_Replica.html B & C ComputerVisions - Atari Sales & Service - https://www.myatari.com/ Best Electronics - https://www.best-electronics-ca.com/ Video61 and Atari Sales - http://www.atarisales.com/main.html Eight Bit Fix (Paul Westphal) - https://www.eightbitfix.com/
Our Pride series keeps on slaying with none other than Southern California drag royalty, Ivy Colby! Ivy sits down with Delta to talk about the art of being a proud bar queen, the importance of drag competitions, and the unmistakable power of a bangle bracelet. And to the men out there… consider this your warning: these queens will gladly take your money and sit on your face!! Plus, what would a “Read Me, Delta” segment be without an iconic Labearja letter? We've got you covered, honey. And Delta? She's in HEAT (literally). You think she hates hot weather? Just wait until you hear this monologue. Listen to Very Delta Ad-Free AND One Day Early on MOM Plus Send us an e-mail at readmedelta@gmail.com FOLLOW DELTA @deltawork VERY DELTA IS A FOREVER DOG AND MOGULS OF MEDIA (M.O.M.) PODCAST Learn more about your ad choices. Visit megaphone.fm/adchoicesSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
Our Pride series keeps on slaying with none other than Southern California drag royalty, Ivy Colby! Ivy sits down with Delta to talk about the art of being a proud bar queen, the importance of drag competitions, and the unmistakable power of a bangle bracelet. And to the men out there… consider this your warning: these queens will gladly take your money and sit on your face!! Plus, what would a “Read Me, Delta” segment be without an iconic Labearja letter? We've got you covered, honey. And Delta? She's in HEAT (literally). You think she hates hot weather? Just wait until you hear this monologue. Listen to Very Delta Ad-Free AND One Day Early on MOM Plus Send us an e-mail at readmedelta@gmail.com FOLLOW DELTA @deltawork VERY DELTA IS A FOREVER DOG AND MOGULS OF MEDIA (M.O.M.) PODCAST Learn more about your ad choices. Visit megaphone.fm/adchoices