2025-11-16 12:42:03
from my link log —
Compiler options hardening guide for C and C .
https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C .html
saved 2025-11-15
from my link log —
Compiler options hardening guide for C and C .
https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C .html
saved 2025-11-15
Apple will now require app developers to disclose and obtain users' permission before sharing personal data with third-party AI providers and companies (Sarah Perez/TechCrunch)
https://techcrunch.com/2025/11/13/appl
Cracking CodeWhisperer: Analyzing Developers' Interactions and Patterns During Programming Tasks
Jeena Javahar, Tanya Budhrani, Manaal Basha, Cleidson R. B. de Souza, Ivan Beschastnikh, Gema Rodriguez-Perez
https://arxiv.org/abs/2510.11516
The Handala hacker group has put a bounty for information on over a dozen Israelis it claims are developers of Patriot, Arrow, and David's Sling air defense systems.
https://www.jpost.com/israel-news/defense-news/article-880394
If you're in Austin and want to attend #LonghornPHP next week but can't swing the ticket price, we still have some donated in-person tickets available. Pay $20 now, then get that $20 refunded when you show up. https:/…
"Rachel Reeves, boasted to corporate executives that she has “unblocked” a large housing development in Sussex being held up by “some snails … a protected species or something … microscopic snails that you cannot even see”. .. The very rare little whirlpool ramshorn snail, by no means microscopic, is an indicator of fresh water not affected by sewage pollution"
"These were the times of Justine Ezarik opening a box containing the 300 pages of her first AT&T bill. Of Joe Hewitt releasing the iUI framework. Of Steve Ballmer laughing at the iPhone. Of James Duncan Davidson’s iconic photo of the iPhone inside a glass screen.
The iPhone SDK and the App Store did not come alone. They were accompanied by an infamous NDA that lasted until October 2008. It prevented devs from asking questions on a new website called “Stack Overflow”."
Folks creating free and open software for the common good: here’s a checklist of everything else you should be doing so corporations can make the best use of your free labour.
I mean, sure, some good security tips here and worth reading anyway but do fuck off with holding free software developers to account for supply chain attacks. It’s your fucking supply chain, not ours, you fucking corporation.
A Survey of Vibe Coding with Large Language Models
Yuyao Ge, Lingrui Mei, Zenghao Duan, Tianhao Li, Yujia Zheng, Yiwei Wang, Lexin Wang, Jiayu Yao, Tianyu Liu, Yujun Cai, Baolong Bi, Fangda Guo, Jiafeng Guo, Shenghua Liu, Xueqi Cheng
https://arxiv.org/abs/2510.12399
Monorepo vs Multi-repo vs #Git submodule vs Git Subtree: A Complete Guide for Developers
https://levelup.gitcon…
How Skövde, a small Swedish city of 58,000, built a local video game ecosystem via a degree for game developers at University of Skövde and a startup incubator (Ralph Jones/The Guardian)
https://www.theguardian.com/games/2025/dec/12/sko…
"Before we go into what is missing, let us take a moment to understand why this partial story is so popular. Many software engineers do not engage with the broad “software engineering literature” very much: through the act of reading this magazine you are placing yourself at the pinnacle of software engineering curiosity!"
https…
AI-assisted Programming May Decrease the Productivity of Experienced Developers by Increasing Maintenance Burden
Feiyang (Amber), Xu, Poonacha K. Medappa, Murat M. Tunc, Martijn Vroegindeweij, Jan C. Fransoo
https://arxiv.org/abs/2510.10165
»A pragmatic guide to modern CSS colours - part one:
For most developers, the only time they touch colour values is when they copy them from a design file and paste them into their editor. We are developers and not designers, after all.«
— by @… on @…
Visual Studio 2026 is now generally available! #VisualStudio2026
https://devblogs.microsoft.com/visualstudio/visual-st…
Google DeepMind launches an enhanced Gemini Deep Research agent accessible to developers via its new Interactions API, along with a new DeepSearchQA benchmark (The Keyword)
https://blog.google/technology/developers/deep-research-agent-gemini-api/
“Legal Corner: Apple’s “notarisation” – blocking software freedom of developers and users!” — via FSFE
https://fsfe.org/news/2025/news-20251105-01.en.html
from my link log —
The reverse tabnabbing vulnerability in HTML.
https://techblog.topdesk.com/security/developers-need-know-reverse-tabnabbing/
saved 2020-10-28
It appears that the latest version of Portainer has a significant bug that prevents access to the local server environment, meaning you cannot manage your containers.
Until the developers fix the problem, the temporary solution is to use version 2.20.2.
https://github.com/portainer/portainer
How Students Use Generative AI for Software Testing: An Observational Study
Baris Ardic, Quentin Le Dilavrec, Andy Zaidman
https://arxiv.org/abs/2510.10551 https://
Data-Model Co-Evolution: Growing Test Sets to Refine LLM Behavior
Minjae Lee, Minsuk Kahng
https://arxiv.org/abs/2510.12728 https://arxiv.org/pdf/2510.1272…
Back in April, District Court Judge Yvonne Gonzalez Rogers delivered a scathing judgment
finding that Apple was in “willful violation” of her 2021 injunction
intended to open up iOS App Store payments.
That contempt of court finding has now been almost entirely upheld by the Ninth Circuit Court of Appeals,
a development that Epic Games’ Tim Sweeney tells Ars he hopes will
“do a lot of good for developers and start to really change the App Store situation worldwi…
advogato: Advogato trust network (2009)
A network of trust relationships among users on Advogato, an online community of open source software developers. Edge direction indicates that node i trusts node j, and edge weight denotes one of four increasing levels of declared trust from i to j: observer (0.4), apprentice (0.6), journeyer (0.8), and master (1.0).
This network has 6541 nodes and 51127 edges.
Tags: Social, Online, Weighted
TALP-Pages: An easy-to-integrate continuous performance monitoring framework
Valentin Seitz, Jordy Trilaksono, Marta Garcia-Gasulla
https://arxiv.org/abs/2510.12436 https://
seemingly normal well adjusted software developers keep following me
actually now that I typed that I'm not sure if those actually exist
Good things developers never learned that DDT helps you code faster.
Talking about #neomutt today. Hopefully, it'll be easier to read than it was to write :)
https://www-gem.codeberg.page/cli_neomutt
I host my own Mastodon instance, and my (retired) blog.
https://www.xda-developers.com/self-hosting-digital-independence/
Said no one ever... 🙂
I switched from Docker Compose to Kubernetes at home, and it's been awesome
https://www.xda-developers.com/switched-from-docker-compose-to-kubernetes-thoughts/
Enshittification starts here
"Qualcomm to Acquire Arduino—Accelerating Developers’ Access to its Leading Edge Computing and AI"
https://www.qualcomm.com/news/releases/2025/10/qualcomm-to-acquire-arduino-accelerating-…
🪞 Inside a global campaign hijacking open-source project identities
https://www.fullstory.com/blog/inside-a-global-campaign-hijacking-open-source-project-identities/
Dear Webapp Developers: if you are going to display elided text that doesn't reveal the full string on hover, please don't fucking bother, just print "STRING TOO BIG. FU." to manage our expectations.
Thank you for your attention.
Three suspected developers of Meduza Stealer malware arrested in Russia https://therecord.media/meduza-stealer-malware-suspected-developers-arrested-russia
“Honestly, I feel like web developers are constantly being gaslit into thinking that complex over-engineered solutions are the only option. When the discourse is being dominated by people invested in frameworks and libraries, all our default thinking will involve frameworks and libraries. That’s not good for users, and I don’t think it’s good for us either.”
Mic drop by @…
Google führt ein, dass Devoloper von Android-Apps sich identifizieren müssen
Alle Hersteller von LLM GPT führen Vibe Coding ein.
Wie funktioniert das? Der GPTbot identifiziert sich bei Google und verantwortet die App mit allen Modifikationen des menschlichen "Developers"?
Der menschliche Developer identifiziert sich und haftet für alle Halluzinationen des vibe-bots, die er weder versteht noch kennt?
Google führt ein, dass Devoloper von Android-Apps sich identifizieren müssen
Alle Hersteller von LLM GPT führen Vibe Coding ein.
Wie funktioniert das? Der GPTbot identifiziert sich bei Google und verantwortet die App mit allen Modifikationen des menschlichen "Developers"?
Der menschliche Developer identifiziert sich und haftet für alle Halluzinationen des vibe-bots, die er weder versteht noch kennt?
A great replacement for Putsmail HTML email testing! https://htmltest.email/
Michael @… wins Innoexplorer Grant!
https://nerds.itu.dk/2025/12/11/michael-wins-innoexplorer-grant/
I always find it interesting to compare my work with other developers' work. In this case I built a migration utility for Mastodon written in Python. After I posted to the "Support Post Migration" thread on Github someone else posted with their solution.
https://github.com/mastodon/mastodon/i
from my link log —
MPTCP / multipath TCP for Linux.
https://www.mptcp.dev/
saved 2025-10-14 https://dotat.at/:/0CAFI.html…
We're gathering momentum for slipmux, a transport of #CoAP over serial ports. That specification allows #embedded developers on simple boards that just have a UART to use the same tools with it as for talking to devices across the Internet. This includes security: I guess I just sent the first encrypted…
Welcome to the world of the field, engineering.
For a long time, we've hired very few into sales, mktg, support or consulting that don't already gobs of experience elsewhere.
✅ How #Microsoft’s developers are using #AI - The Verge
What is #auth? It's more complicated than you probably thought, even though #software #developers sling the word around all the time.
🎅 Since it's the holiday season, give yourself an eas…
We’re pleased to announce the publication of GCVE-BCP-02 – Practical Guide to Vulnerability Handling and Disclosure, now available in its version 1.3.
This Best Current Practice document provides actionable guidance for organisations, researchers, and GCVE Numbering Authorities (GNAs) on managing and disclosing vulnerabilities effectively, both within the GCVE ecosystem and beyond
First talk of the day: @… introducing us to #HTMX for PHP developers
«The tech industry is being taken over by merchants of services, and the Open Source community is starting to depend on them. We've seen this coming, with GitHub being a startup, bought by Microsoft which is now pushing AI. They are the means of production.»
And FLOSS would be doing well to divest from the industrial-owened means of production sooner rather than later.
What AI is doing to developers - (not) my ideas
https://notmyidea.org/what-ai-is-doing-to-developers.html
The HTML-First Approach: Why htmx and Lightweight Frameworks Are Revolutionizing Web Development
📊 #html
Runware, which operates a developer tool platform that generates images, video, and audio in real-time, raised a $50M Series A, taking its total funding to $66M (Dominic-Madori Davis/TechCrunch)
https://techcrunch.com/2025/12/11/runw
No surprised.
"The government published its planning and infrastructure bill in March. Before and after the bill’s publication the chancellor, Rachel Reeves, and housing minister Matthew Pennycook have met dozens of developers in numerous meetings. The body representing professional ecologists, meanwhile, has not met one minister despite requests to do so."
Developers met ministers dozens of times over planning bill while ecologists were shut out.
CodeWatcher: IDE Telemetry Data Extraction Tool for Understanding Coding Interactions with LLMs
Manaal Basha, Aime\^e M. Ribeiro, Jeena Javahar, Cleidson R. B. de Souza, Gema Rodr\'iguez-P\'erez
https://arxiv.org/abs/2510.11536
Google says Gemini 2.5 Flash Image, aka Nano Banana, is now generally available and supports more aspect ratios, priced at $0.039/image and $30/1M output tokens (Google Developers Blog)
https://developers.googleblog.com/en/gemini-2…
"We are not Future-ready": Understanding AI Privacy Risks and Existing Mitigation Strategies from the Perspective of AI Developers in Europe
Alexandra Klymenko, Stephen Meisenbacher, Patrick Gage Kelley, Sai Teja Peddinti, Kurt Thomas, Florian Matthes
https://arxiv.org/abs/2510.00909
Demystifying #AutomaticInstrumentation: How the Magic Actually Works
https://www.causely.ai/blog/demystifying-automatic-instrumentation
Is that an open source alternative to Framer/WebFlow? #Frappe #webdevelopment
Show Your Title! A Scoping Review on Verbalization in Software Engineering with LLM-Assisted Screening
Gerg\H{o} Balogh, D\'avid K\'osz\'o, Homayoun Safarpour Motealegh Mahalegi, L\'aszl\'o T\'oth, Bence Szak\'acs, \'Aron B\'ucs\'u
https://arxiv.org/abs/2510.12294
Nvidia says it will begin selling the DGX Spark mini PC for AI developers on October 15 on Nvidia.com and select third-party retailers for $3,999 (Michael Kan/PCMag)
https://www.pcmag.com/news/nvidia-to-start-selling-3999-dgx-spark-mini-pc-this-week…
advogato: Advogato trust network (2009)
A network of trust relationships among users on Advogato, an online community of open source software developers. Edge direction indicates that node i trusts node j, and edge weight denotes one of four increasing levels of declared trust from i to j: observer (0.4), apprentice (0.6), journeyer (0.8), and master (1.0).
This network has 6541 nodes and 51127 edges.
Tags: Social, Online, Weighted
Apple unveils Mini Apps Partner Program, offering a reduced 15% commission on IAPs for mini apps, or "self-contained" experiences built with web tech like HTML5 (Sarah Perez/TechCrunch)
https://techcrunch.com/2025/11/13/apple-halves-commissions-for-m…
eye2vec: Learning Distributed Representations of Eye Movement for Program Comprehension Analysis
Haruhiko Yoshioka, Kazumasa Shimari, Hidetake Uwano, Kenichi Matsumoto
https://arxiv.org/abs/2510.11722 …
Cursor says it has crossed $1B in annualized revenue, has 300 employees, and its in-house models "generate more code than almost any other LLMs in the world" (Ashley Capoot/CNBC)
https://www.cnbc.com/2025/11/13/cursor-ai-startup-funding-round-valuati…
OpenAI releases GPT-5.1 in the API, featuring a "no-reasoning" mode and extended prompt caching with up to 24-hour retention to generate faster responses (OpenAI)
https://openai.com/index/gpt-5-1-for-developers
(R)evolution of Programming: Vibe Coding as a Post-Coding Paradigm
Kevin Krings, Nino S. Bohn, Thomas Ludwig
https://arxiv.org/abs/2510.12364 https://arxiv…
Please don't upload my code on GitHub
This is a call to free/libre and open source software developers to not upload the work of others to GitHub.
🚫 #NoGitHub
This week, I received an interesting task: dusting off a legacy #Java application. The application analyzes specific #XML files in proprietary format. I know XML doesn’t sound sexy to junior developers, but it has an amazing benefit. One can validate a file against a grammar. Such grammar is called an
How developers are using Apple's local AI models in iOS 26: Lil Artist story generation, MoneyCoach's spending insights, F1 race summaries in Lights Out, more (Ivan Mehta/TechCrunch)
https://techcrunch.com/2025/09/26/how-developers-are-u…
OpenAI launches AgentKit, a toolkit for building and deploying AI agents, including Agent Builder, which Sam Altman described as like Canva for building agents (Rebecca Bellan/TechCrunch)
https://techcrunch.com/2025/10/06/openai-launche…
2025 In Review: What’s New In Web Performance?
Slow websites continue to be a problem and a lot of work is being done so developers can measure performance more effectively and fix performance issues.
🧑💻 https://www.debugbear.com/blog/2025-in-web-performance
Google adds a new command-line interface and public API to its AI coding agent Jules, allowing it to plug into terminals, CI/CD systems, and tools like Slack (Jagmeet Singh/TechCrunch)
https://techcrunch.com/2025/10/02/goog
AI Where It Matters: Where, Why, and How Developers Want AI Support in Daily Work
Rudrajit Choudhuri, Carmen Badea, Christian Bird, Jenna Butler, Rob DeLine, Brian Houck
https://arxiv.org/abs/2510.00762
Prompting in Practice: Investigating Software Developers' Use of Generative AI Tools
Daniel Otten, Trevor Stalnaker, Nathan Wintersgill, Oscar Chaparro, Denys Poshyvanyk
https://arxiv.org/abs/2510.06000
Swift releases Swift SDK preview for Android, allowing developers to build Android apps in Swift and making it easier to share code across iOS and Android (Hartley Charlton/MacRumors)
https://www.macrumors.com/2025/10/26/developers-can-make-android-apps-with…
Google says Gemini 3 Pro sets new vision AI benchmark records, including in complex visual reasoning, beating Claude Opus 4.5 and GPT-5.1 in some categories (Rohan Doshi/The Keyword)
https://blog.google/technology/developers/gemini-3-pro-vision/
OFP-Repair: Repairing Floating-point Errors via Original-Precision Arithmetic
Youshuai Tan, Zishuo Ding, Jinfu Chen, Weiyi Shang
https://arxiv.org/abs/2510.09938 https://…
[Thread] GPT-5.2 is now available in the API, priced at $1.75/1M input and $14/1M output tokens; GPT-5.2 Pro is priced at $21/1M input and $168/1M output tokens (@openaidevs)
https://x.com/openaidevs/status/1999184802755354954
Developers' Perspectives on Software Licensing: Current Practices, Challenges, and Tools
Nathan Wintersgill, Trevor Stalnaker, Daniel Otten, Laura A. Heymann, Oscar Chaparro, Massimiliano Di Penta, Daniel M. German, Denys Poshyvanyk
https://arxiv.org/abs/2510.01096
Sam Altman says ChatGPT has reached 800M weekly active users, 4M developers "have built with OpenAI", and OpenAI processes over 6B tokens per minute on its API (Rebecca Bellan/TechCrunch)
https://techcrunch.com/2025/10/06/sam-altman-says-…
Search and browser startup Brave says it has passed $100M in annualized revenue in Q1, and had 100M MAUs as of September, up from 77M at the end of 2024 (Stephanie Palazzolo/The Information)
https://www.theinformation.com/articles/li
Modeling Developer Burnout with GenAI Adoption
Zixuan Feng, Sadia Afroz, Anita Sarma
https://arxiv.org/abs/2510.07435 https://arxiv.org/pdf/2510.07435
Repository-Aware File Path Retrieval via Fine-Tuned LLMs
Vasudha Yanuganti, Ishaan Puri, Swapnil Chhatre, Mantinder Singh, Ashok Jallepalli, Hritvik Shrivastava, Pradeep Kumar Sharma
https://arxiv.org/abs/2510.08850
Google releases fully managed, remote MCP servers to help developers connect AI agents to services such as Maps, BigQuery, Compute Engine, and Kubernetes Engine (Rebecca Bellan/TechCrunch)
https://techcrunch.com/2025/12/10/google-is-going-all-in…
PyMigTool: a tool for end-to-end Python library migration
Mohayeminul Islam, Ajay Kumar Jha, May Mahmoud, Sarah Nadi
https://arxiv.org/abs/2510.08810 https://
Fal, which hosts generative AI models for developers, raised a $140M Series D led by Sequoia, a source says at a $4.5B valuation, up from $1.5B in July (Paayal Zaveri/Bloomberg)
https://www.bloomberg.com/news/articles/2025…
What Types of Code Review Comments Do Developers Most Frequently Resolve?
Saul Goldman, Hong Yi Lin, Jirat Pasuksmit, Patanamon Thongtanunam, Kla Tantithamthavorn, Zhe Wang, Ray Zhang, Ali Behnaz, Fan Jiang, Michael Siers, Ryan Jiang, Mike Buller, Minwoo Jeong, Ming Wu
https://arxiv.org/abs/2510.05450
Saving SWE-Bench: A Benchmark Mutation Approach for Realistic Agent Evaluation
Spandan Garg, Ben Steenhoek, Yufan Huang
https://arxiv.org/abs/2510.08996 https://
SEER: Sustainability Enhanced Engineering of Software Requirements
Mandira Roy, Novarun Deb, Nabendu Chaki, Agostino Cortesi
https://arxiv.org/abs/2510.08981 https://
Data from 300K pull requests shows OpenAI is catching up to Anthropic in AI coding: Codex has a 74.3% success rate vs. Claude Code's 73.7% in code approvals (Stephanie Palazzolo/The Information)
https://www.theinformation.com/articles/openai-catching-anthropi…
AI browsers, still far from making legacy browsers obsolete, are forcing web developers to rethink whether they are designing websites for humans or for robots (Natalie Lung/Bloomberg)
Identifying Video Game Debugging Bottlenecks: An Industry Perspective
Carlos Pinto Gomez, Fabio Petrillo
https://arxiv.org/abs/2510.08834 https://arxiv.org…
Over 200 prominent figures, including senior staffers at AI companies, call for international action to create "red lines" for AI development by the end of 2026 (Shakeel Hashim/Transformer)
https://www.transformernews.ai/p/nobel-laureate…
OpenAI's recent deals with Oracle, Nvidia, Samsung, AMD, SK Hynix, and others, plus its DevDay announcements, show it is making a play to be the Windows of AI (Ben Thompson/Stratechery)
https://stratechery.com/2025/openais-windows-play/
The Linux Foundation will launch the React Foundation, a new home for Meta's React and React Native; founding members include Amazon, Meta, Microsoft, others (Engineering at Meta)
https://engineering.fb.com/2025/10/07/
Cloudflare combines a new Email Sending feature with Routing into a unified Email Service to let developers send emails from Cloudflare Workers, in private beta (Cloudflare)
https://blog.cloudflare.com/email-service/
Docs: Oracle generated ~$900M from its Nvidia cloud server rental business, with a $125M gross profit, or a 14% margin, vs. its ~70% overall gross profit margin (The Information)
https://www.theinformation.com/articles/internal-oracl…
A live blog of OpenAI DevDay 2025, where the company is expected to announce a visual agent builder and other developer updates (Ashley Capoot/CNBC)
https://www.cnbc.com/2025/10/06/open-ai-devday-live-updates-altman-jony-ive.html