Between and I took 3309 steps.
Liked
Kefimochi 👏 HIRE ME 👏 (@kefimochi.bsky.social)
Post details
I have never passed a single LeetCode-type interview. Because I didn't ever have to use this skill professionally & consider it ridiculous in the first place. That said, I have this interview today & I didn't have enough time to prepare. Yolo 🤪 Failing is still practice!
Listened to
The CEO of htmx likes codin' dirty featuring Carson Gross (Changelog Interviews #646)

Post details
Jerod is joined by Carson Gross, the creator of htmx –a small, zero-dependency JavaScript library that he says, "completes HTML as a hypertext". Carson built it because he's big on hypermedia, he even wrote a book called Hypermedia Systems. Carson has a lot of strong opinions weakly held that we dive into in this conve...
Between and I took 7366 steps.
Liked
If a note can be public, it should be
by
Post details
A few years ago, I quietly adopted a small principle that has changed how I think about publishing on my website. It's a principle I've been practicing for a while now, though I don't think I've ever …
Between and I took 2407 steps.
Liked
GitHub - charmbracelet/fang: The CLI starter kit

Post details
The CLI starter kit. Contribute to charmbracelet/fang development by creating an account on GitHub.
Listened to
How to Secure the Software Supply Chain by The Tech Trek

Post details
In this episode of The Tech Trek, Amir sits down with Matt Moore, CTO and co-founder of Chainguard, to explore the escalating importance of software supply chain security. From Chainguard’s origin story at Google to the systemic risks enterprises face when consuming open source, Matt shares the lessons, best practices, and technical innovations that help make open source software safer and more reliable. The conversation also touches on AI’s impact on the attack surface, mitigating threats with engineering rigor, and why avoiding long-lived credentials could be your best defense.🔑 Key Takeaways:Security Starts with Engineering: Doing engineering right makes security (and even compliance) much easier.Control the Full Chain: Building from source and applying best practices at every build stage significantly reduces exposure to CVEs.Attackers Exploit the Edges: Most attacks start small—with a leaked credential or compromised dependency—and cascade through the ecosystem.AI Introduces New Vectors: As AI tools integrate deeper into dev workflows, they bring both value and new risks that require thoughtful containment.You Can’t Leak What You Don’t Have: Eliminating long-lived credentials is one of the simplest and most effective ways to reduce breach risk.⏱ Timestamped Highlights:00:45 – What Chainguard does: securing open source consumption and curating safe containers.02:56 – Chainguard’s origin story and co-founders’ experience at Google.06:50 – Building minimal, hardened container images from source to mitigate CVEs.09:40 – Real-world example: how compiler hardening flags protected Chainguard from a high-severity CVE.10:59 – The invisible sprawl of open source in enterprise stacks—from Kubernetes to AWS SDKs.15:45 – How leaked credentials power cascading supply chain attacks.22:30 – “You can't leak what you don't have”: Chainguard's credential-less auth approach.24:30 – Most breaches come from known vulnerabilities—not zero-days.25:38 – AI and security: new use cases, new threats, and the need for explainability.30:41 – AI adoption in enterprises: security best practices still apply, just to new tools and risks.34:43 – Learn more at chainguard.dev and explore hardened images at images.chainguard.dev.💼 Career Tips (from the episode):Don’t wait for zero-days: Most real-world breaches stem from unpatched, well-known vulnerabilities. Ship secure, stay patched.Build from source: If you're in a security or DevOps role, aim to build and control your stack from the source code up—this provides auditability and trust.Engineering rigor is a differentiator: Whether you're launching a startup or working in enterprise tech, applying fundamental engineering principles helps you scale securely.📚 Resources Mentioned:🛡️ OpenSSF Projects – e.g., SIGstore, Scorecards, SLSA.🛠Projects Mentioned: Kubernetes, Istio, Flux, Tekton, Cert-Manager, Cloud Code.💬 Quote of the Episode:“If you do engineering right, security becomes easier. And if you do security right, compliance becomes easier.” — Matt Moore

Listened to
Shipping 22 products to find the true product - Utpal from Digger.dev - Scaling DevTools

Post details
Utpal Nadiger is the cofounder of Digger.dev. Digger built a popular open source IaC orchestration tool. Their new product Infrabase is an AI DevOps agent that ...

Between and I took 7145 steps.
Listened to
Demystifying Cyber Resilience and the Tools That Help | Open at Intel
by

Post details
In this episode, Michael Lieberman, Co-founder and CTO of Kusari, walks us through the intersection of open source software and security. We discuss Mike's extensive involvement in OpenSSF projects like SLSA and GUAC, which provide essential frameworks for securing the software development life cycle (SDLC) and managing software supply chains. He explains how these tools help verify software provenance and manage vulnerabilities. Additionally, we explore regulatory concerns such as the Cyber Resilience Act (CRA) and the vital role of the recently released Open SSF Security Baseline (OSPS Baseline) in helping organizations comply with such regulations. Mike also shares insights into the evolution of open source security practices, the importance of reducing complexity for developers, and the potential benefits of orchestrating security similarly to Kubernetes. We conclude with a look at upcoming projects and current pilots aiming to simplify and enhance open source security.  00:00 Introduction and Guest Welcome 00:19 Mike's Background and Role in Open Source 01:35 Exploring SLSA and GUAC Projects 04:57 Cyber Resiliency Act Overview 06:54 OpenSSF Security Baseline 11:29 Encouraging Community Involvement 18:39 Final Thoughts  Resources: OpenSSF's OSPS Baseline GUAC SLSA KubeCon Keynote: Cutting Through the Fog: Clarifying CRA Compliance in C... Eddie Knight & Michael Lieberman  Guest: Michael Lieberman is co-founder and CTO of Kusari where he helps build transparency and security in the software supply chain. Michael is an active member of the open-source community, co-creating the GUAC and FRSCA projects and co-leading the CNCF’s Secure Software Factory Reference Architecture whitepaper. He is an elected member of the OpenSSF Governing Board and Technical Advisory Council along with CNCF TAG Security Lead and an SLSA steering committee member. Â

Listened to
Giving developers what they want with Deepak Prabhakara - Scaling DevTools

Post details
Deepak Prabhakara is the CEO and Co-founder of BoxyHQ. BoxyHQ enables you to add plug-and-play enterprise-ready features to your SaaS product.What we coverAn in...

Listened to
Open Source Security: Hobbyist Maintainers with Thomas DePierre

Post details
Thomas DePierre joins Open Source Security to discuss the central idea from his blog post, "You are all on the hobbyist maintainers turf now," exploring the massive disconnect between the corporate world that consumes open source and the hobbyist community that actually produces it. The conversation reveals this isn't a new problem, but a long-standing reality whose consequences for security, stability, and the future of software we are only now beginning to truly confront. The show notes and blog post for this episode can be found at
Between and I took 2840 steps.
Liked
JP (@justinpoliachik.com)
Post details
Goofiness is by far the most underrated green flag trait I just want people I can goof off with, vibe out, have a good time and not care about what others might think Crazy how rare that is tho
Listened to
Cup o' Go | Agentic workflows and AI firewalls, so pretty much cancelling ourselves out

Post details
Don't forget to visit cupogo dot dev, where you can find links to all the things!🤖 Ezo Saleh - How We Built Rock-Solid Agentic Orchestration with Go🔥 Anubis🥨 Godump - pretty printer🪳 gcassert💧 isLitOrSingle

Liked
The New Stack (@thenewstack.io)

Post details
✨ Author Spotlight: Jennifer Riggins ✨ She’s never written a line of code — and that’s her superpower. With a background in journalism and a career shaped by dev storytelling, @jkriggins.bsky.social helps bridge the gaps between developers, business leaders, and everyday users.
Liked
Lars (@lars-ellingsen.dev)
Post details
Zulip may be a good alternative
Listened to
Killing features with Josh Twist, founder of Zuplo - Scaling DevTools

Post details
Josh Twist is the founder of Zuplo, an API gatewayIntroducing Josh Twist, the founder of Zuplo. 0:00Zuplo vs Azure API management.How do you make this fit into ...

Liked
Carol 🪩 (@carol.gg)

Post details
big up for the monzo pals on stage at #LDX3 #LeadDev ✨
Listened to
Developer onboarding with Kilian from Polypane - Scaling DevTools

Post details
How do you do onboarding in a way developers actually like?Kilian is the founder of Polypane - The browser for ambitious web developers https://polypane.app/Kil...

Listened to
Scaling DevTools

Post details
Lessons from 100+ DevTool founders - DevTools successes, failures and stories in a free weekly email and podcast.

Between and I took 6960 steps.
Week Notes 25#23 (3 mins read).
What happened in the week of 2025-06-09?
Liked
Corey Quinn (@quinnypig.com)
Post details
Came for the democracy, stayed for the systemd [contains quote post or other embedded content]
Listened to
Saltiness about frostiness with Justin Searls (Changelog & Friends #97)

Post details
Justin Searls joins Jerod in Apple's WWDC wake for hot takes about frosty UIs. We go (almost) point-by-point through the keynote, dissecting and reacting along the way. Concentricity!
Liked
The Nuanced Writer (@skriptble.me)
Post details
Just finished mastering episode 24 of @fallthrough.fm, which is actually our 25th episode since our first was episode 0. For one, I’m amazed that we’ve been able to not only ship 25 episodes, but also do so every week (on the same weekday with a couple exceptions).
Listened to
Cloud Native Compass | The Future of Sustainability in Open Source

Post details
The Future of Sustainability in Open Source Can open source ever truly be sustainable?In this mind-bending episode, Hazel Weakly guides us through the social, economic, and emotional layers of open...

Liked
Justin Garrison (@justingarrison.com)
Post details
I wonder how many people at #nokings protests today didn't show up at the polls last year If you want democracy, you have to vote
Between and I took 2946 steps.
Liked
Roscoe Rubin-Rottenberg (@knotbin.com)
Post details
Please answer the question again. I should remind you, you are under OAuth.
Liked
weggles (@weggles.bsky.social)
Post details
They're called "no tyrants" protests in Commonwealth nations đź« .
Between and I took 3109 steps.
Liked
Autumn Nash (@withenoughcoffee.com)

Post details
Odin learned how to dig today. Also his name is now “Odin Bartholomew Cornelius, god of thunder roasted marshmallow Nash”
Listened to
go podcast() | 041: Speaking at conferences with Matt Boyle

Post details
Getting out there, showing what you're currently doing / learning, starting a blog, creating content to help other software engineers, those are all good way to distinguish yourself. You might want to consider speaking at conferences as well. In this episode we're talking with Matt Boyle about...

Listened to
SE Radio 643: Ganesh Datta on Production Readiness – Software Engineering Radio

Post details

Between and I took 5490 steps.
Liked
GitHub - olimorris/codecompanion.nvim: ✨ AI-powered coding, seamlessly in Neovim

Post details
✨ AI-powered coding, seamlessly in Neovim. Contribute to olimorris/codecompanion.nvim development by creating an account on GitHub.
Between and I took 2882 steps.
Listened to
Scott & Mark Learn To... How Not to Ship the Org Chart | Scott & Mark Learn To...

Post details
Listen to Scott & Mark Learn To... How Not to Ship the Org Chart from Scott & Mark Learn To.... In this episode of Scott & Mark Learn To, Scott Hanselman and Mark Russinovich discuss the concept of shipping the org chart, a term used to describe when different teams' outputs are inconsistently integrated, reflecting the organizational structure rather than a cohesive product. Scott recounts his experience test-driving an electric vehicle with a disjointed interface, which made him question the internal coordination within the automaker. Mark explains how Microsoft addresses this issue through standardization and tooling, emphasizing the need for consistent APIs and user experiences. They also debate the balance between maintaining consistency and fostering innovation, and how large tech companies like Microsoft and Apple manage these challenges.   Takeaways:    Establishing UX design standards helps maintain a consistent user experience across features Inconsistent design or functionality can impact user perception and trust in a product Integrating quality checks early (shift left) helps prevent issues and reduces later fixes    Who are they?     View Scott Hanselman on LinkedIn  View Mark Russinovich on LinkedIn          Listen to other episodes at scottandmarklearn.to  Watch Scott and Mark Learn on YouTube         Discover and follow other Microsoft podcasts at microsoft.com/podcasts   Download the Transcript Â
