A URL Rewrite Is a Component Transform, Not String Surgery
Fresh Astro and WordPress fixes expose three URL failure classes. Preserve component boundaries, suffixes, identity, and invalid-input policy.
Read ->// blog
Notes on software engineering, side projects, and building for the web.
Fresh Astro and WordPress fixes expose three URL failure classes. Preserve component boundaries, suffixes, identity, and invalid-input policy.
Read ->pnpm now coordinates npm, Python, and Cargo, but keeps their resolvers, lockfiles, and build authority separate. That distinction shapes safe adoption.
Read ->GitHub's privacy-safe API returns weekly buckets, not stargazer events. Handle pagination, partial weeks, churn, and attribution explicitly.
Read ->Shopify POS now resolves barcode aliases and surfaces eligible online baskets. Keep lookup evidence separate from transaction authority.
Read ->Playwright 1.63 adds named locks as Astro 7.3 permits concurrent previews. Isolate environments first, then serialize only true shared state.
Read ->npm now accepts multiple OIDC publishers while GitHub exposes reusable-workflow identity. Audit release authority as a union of paths.
Read ->Google's site reputation update makes one manual action behave differently inside and outside the EEA. Split detection, remediation, and disputes by region.
Read ->GitHub’s new AI approvals affect merge state. Separate assessment, review coverage, path eligibility, ownership, and commit freshness.
Read ->Fresh Cloudflare cache work shows why storage encoding, selected representation, wire content, validators, and ranges must stay separate.
Read ->Fresh Schema.org changes can describe richer product options, but dimensions, valid combinations, offers, and consumer support remain separate contracts.
Read ->Explicit inheritance, network history restores, error swaps, and morphing change who owns UI state. Migrate by provenance, not search-and-replace.
Read ->Shopify’s routing-based US tax and balance activity report expose separate order, balance, and payout clocks. Reconcile them without rewriting history.
Read ->Fresh BotBase and preference-sync releases expose a four-way join among request proof, declared use, site policy, and path enforcement.
Read ->Fresh Cloudflare, Weaviate, and DeepEval catalogs expose a shared discovery shape—and the interoperability tests operators should run first.
Read ->New Vercel and GitHub dashboards expose posture and rule events, but mutes, unreadable checks, and path exceptions can quietly narrow coverage.
Read ->Fresh Chat SDK and Copilot releases show why shared handlers still require channel-aware identity, retries, context, capabilities, and approvals.
Read ->Longer Bun functions and global sandboxes now overlap on capacity. Trust, durability, and evidence—not runtime length—should decide where agent work runs.
Read ->Fresh Cloudflare and GitHub controls show why closing an alert must not erase the difference between detection, containment, repair, and validation.
Read ->Native soft-navigation measurement can raise pageviews and split Core Web Vitals by route. Preserve dual baselines before calling either a trend.
Read ->Fresh Cloudflare and Vercel changes show how agents should turn API denials into narrow approvals without exposing the credential they receive.
Read ->Cloudflare's mitigated remote Spectre proof and GitHub's targeted revocation controls show why containment depends on four separate clocks.
Read ->Cloudflare's MCP traffic detection and the stateless MCP spec expose agent tool calls in ordinary HTTP headers. Detection is now cheap; enforcement is not.
Read ->Stripe's expanded settlement currencies and instant conversion make presentment, settlement, and conversion separately controllable. Model all three legs before optimising any one.
Read ->Vercel ECH and Cloudflare certificate alerts show why visitor privacy, domain inventory, certificate issuance, and routing need separate evidence.
Read ->New Cloudflare Access and GitHub OAuth controls make preview URLs, callbacks, token rotation, and retirement one deployment-level contract.
Read ->Shopify now recommends richer checkout data. Test each field against completion, fulfilment, consent, and downstream utility before applying it.
Read ->Agent Plugins 1.0 makes skills and MCP tools portable, but installation, execution, authority, and updates still need separate review.
Read ->Persistent memory, retrieval, MCP tools, and gateway logs create separate context copies. Map each boundary before calling an agent private.
Read ->Cloudflare's new Turnstile setup flow exposes a useful rule: protect availability, request integrity, and business acceptance separately.
Read ->WebMCP and hybrid human-agent journeys can bypass clicks and pixels. Measure tool calls, confirmations, and business outcomes at the server.
Read ->GitHub's fresh Copilot ROI, effort-level, and agent usage updates make AI productivity measurable only when work evidence joins the spend.
Read ->GitHub Spark's shutdown shows AI-built mini apps need ownership, runtime, inference, and export records before they become useful.
Read ->GitHub's Copilot billing app retirement shows AI cost records must survive dashboard moves, policy changes, and usage rollups.
Read ->GitHub's fresh code scanning and coverage setup changes make security and quality configuration an operating artifact.
Read ->GitHub's fresh Copilot automation triggers and reasoning controls make comments an execution surface that needs typed intent.
Read ->Vercel's fresh AI Gateway budgets and model additions show cost control moving into request routing, not monthly cleanup.
Read ->GitHub's team-level Copilot policies and model retirements show model access now needs role, surface, and fallback records.
Read ->Fresh Copilot IDE updates and GitHub Models retirement show agent concurrency needs workspace, model, and evidence boundaries.
Read ->GitHub stacked PRs, self-repository actions, and managed remote control turn large change management into explicit workflow design.
Read ->Copilot code review skills, read-only MCP, default model policy, and usage rollups make review context an operable system.
Read ->Fresh npm and Dependabot changes make package trust a workflow design problem, not just an alert triage problem.
Read ->Fresh Vercel and GitHub controls show AI governance moving into per-request region, client, workflow, and approval decisions.
Read ->Claude Opus 5 in Copilot, mobile agent fixes, and stateless MCP shift agent risk from launch approval to mid-run control.
Read ->GitHub's new multi-select fields and agent automation controls make queue taxonomy an execution boundary, not admin decoration.
Read ->Vercel's latest Blob WAF and workflow-duration updates show uploads need edge policy, async processing, and evidence trails.
Read ->Fresh GitHub updates move agents into Issues, Linear, Mobile, and MCP. Design intake rules before autonomous work spreads across queues.
Read ->Vercel MCP purchases and installable agent extensions make spending a tool permission. Treat purchase authority as audited product surface.
Read ->Fresh Copilot and Vercel updates show AI teams need routing rules for model choice, cost, latency, and approval boundaries.
Read ->GitHub's AI credit pool controls make Copilot spend easier to allocate, but only if teams separate license-funded usage from metered overage.
Read ->GitHub Code Quality is GA with dashboards, coverage gates, APIs, and AI autofix. Roll it out as measured policy, not a blanket blocker.
Read ->Copilot code review now reads branch instructions, setup files, and runner policies. Treat review context as executable infrastructure.
Read ->GitHub's fresh Copilot metrics updates make AI work visible by repo, app, and mobile fix path. Turn usage into outcome review.
Read ->Fresh GitHub and Vercel updates show queues, cache writes, and Slack agents becoming queryable operating surfaces.
Read ->Fresh GitHub, Vercel, and Cloudflare updates show secrets, connectors, and flag CLIs becoming operational control planes.
Read ->Dependabot's default cooldown changes dependency updates from pure freshness work into release-risk routing for small teams.
Read ->GitHub's new security-review command and agentic autofix make security work earlier, but only if teams capture evidence.
Read ->GitHub's clearer detector names and AI scanning updates show why alert labels should route action, not just decorate queues.
Read ->Copilot can now summarise unfamiliar repos. Make those summaries safer by documenting owners, risk zones, and contribution limits.
Read ->CodeQL prompt-injection detection turns AI app security into review work. Route findings by exploit path, not scanner severity alone.
Read ->GitHub's new PR dashboard and Code Quality targeting make review queues more useful when they sort by business risk, not noise.
Read ->GitHub's new Copilot controls make agent activity observable and enforceable. Route that telemetry into incident, cost, and release processes.
Read ->Browser agents are getting semantic page views. Use accessibility trees to test what they can understand before they act.
Read ->Vercel Flags segments are now scriptable from the CLI. That makes rollout targeting reviewable, but only if teams diff it like code.
Read ->Cloudflare Cache Rules now honor Vary. That helps multilingual and format-aware pages, but only if teams control variant keys.
Read ->Pointer Events Level 3 is now a W3C Recommendation. Treat touch, pen, and mouse behaviour as a funnel contract, not browser trivia.
Read ->Vercel Agent Runs and GitHub Copilot usage metrics show why AI work needs inspectable logs, not just accepted diffs.
Read ->Vercel dry-run deploys and service bindings are useful, but teams need explicit release contracts before agents ship.
Read ->GitHub and Vercel updates show why small teams need to watch public leaks, stale credentials, and project-level security drift together.
Read ->Vercel and GitHub's latest agent pricing changes make token spend an operating metric, not an accounting surprise.
Read ->GitHub's .npmrc change is a useful reminder: dependency automation should use named registry rules, not inferred package-manager state.
Read ->Vercel's Ship 2026 announcements show a practical pattern for coding agents: scoped identities, temporary access, and measurable deploy risk.
Read ->GitHub's latest Copilot changes make model choice and adoption reporting an operations problem, not a preferences menu.
Read ->GitHub's new Copilot merge totals are useful only when teams compare them against review quality, risk, and delivery context.
Read ->Cloudflare's rollback-handler update is a useful reminder: business automations need explicit recovery paths, not just retry buttons.
Read ->Vercel's new CLI Web Analytics query is a useful pattern: make performance and conversion checks repeatable, not dashboard archaeology.
Read ->Fresh GitHub, Vercel, and Cloudflare updates point to the same operator lesson: scope credentials tightly and rehearse revocation before an incident.
Read ->Vercel shipped AI SDK 7 with typed messages, resumable streams, and MCP tools. Treat the upgrade as an agent UI contract, not a package bump.
Read ->NN/g’s fresh diary-study incentive guide is a reminder: before changing a checkout or quote funnel, watch what customers do over time.
Read ->Fresh NN/g, Cloudflare, and GitHub updates show agentic workflows moving into real operations. Treat them as systems, not clever prompts.
Read ->Recent Stripe and GitHub data show AI spend is becoming measurable. Operators should track AI tools like product usage, not software overhead.
Read ->Fresh AI search research points to a practical SEO shift: build pages around the situation buyers describe, not just the keyword they type.
Read ->Safari 27 is adding customizable select support. Form-heavy sites should test native styling before reaching for custom dropdown JavaScript.
Read ->Cloudflare made DMARC Management generally available. Small teams should treat SPF, DKIM, and DMARC as deliverability infrastructure, not DNS trivia.
Read ->Bots and AI agents are becoming normal website traffic. Operators need cleaner analytics, crawler policy, and separate metrics for machine visitors.
Read ->Cloudflare scaled Security Insights 10x without new hardware. The builder lesson is to treat audits and scanners as pipelines, not cron jobs.
Read ->GitHub added org runner controls, content exclusion, and larger custom instructions to Copilot code review. Treat that as review infrastructure, not decoration.
Read ->Chrome is testing WebMCP so websites can expose structured tools to browser agents. Here is what builders should do before agents start using their UI.
Read ->Anthropic launched Fable 5, then suspended it after a US export-control directive. The useful lesson is about governing model capability, not one jailbreak.
Read ->A deep dive comparing Better Fetch to ScrapingBee, ScraperAPI, Zyte, Bright Data, Firecrawl, Scrapfly, Apify, Browserless, Browserbase, and Jina Reader — on pricing, billing model, and what they cost when JavaScript and anti-bot kick in.
Read ->Vercel is adding HarnessAgent to AI SDK 7. The practical lesson is that agent runtimes are becoming app infrastructure, not just CLI tools.
Read ->