Posts 386 entriesPage 1 of 39

Posts

DevOps

Connect every public surface to the new canonical

An evergreen earns the slot when home and About link to it. Search visitors land without knowing the company; the canonical must reach them on the first read.

Read
DevOps

Require the Phone at Intake, Not When Staff Call Back

now-lms /request-access added a required, server-validated phone field at intake (PR #123), stored as a labeled line of the existing body.

Read
Technical Deep-Dive

Team-Page Ordering Is a Release Decision

Team-page ordering is a release decision. Legal Counsel landed seventh; same-day hotfix; a 79-line CI gate keeps the roster authoritative across eight footers.

Read
Development Journey

Use the Primitive, Not the Patch: Closing a CodeQL Backlog by Class

When CodeQL keeps flagging js/file-system-race, the fix is one canonical primitive routed through one shared module. Eleven TOCTOU sites closed.

Read
Development Journey

One Folder Was Behind Every Critical Dependabot Alert

When the only two manifests in your Dependabot queue belong to a folder your plugin never ships, the fix is to delete the folder, not patch it.

Read
Technical Deep-Dive

Tailscale Federated Trust: Scope to Auth Keys, Not All

Tailscale's federated trust lets a GitHub Actions OIDC subject do anything on your tailnet by default. A deploy only needs to create an auth key.

Read
Technical Deep-Dive

Pin the Installer and Add a Renewer

A CI tool that floats is a gate whose behaviour changes without a commit. Pin the installer, then add a renewer so the pin is refreshed by review.

Read
DevOps

Move Deterministic Math Out of the LLM Prompt

Move date windows, site lists, and per-site totals out of the LLM prompt and into a Python file the wrapper reads before the prompt is built.

Read
DevOps

Refuse to Substitute a Weaker Token in Scheduled CI

A scheduled CI workflow that falls back to a weaker token opens PRs that re-trigger no required checks. PR #1563 closes that fallback in update-npm-stats.yml.

Read
Technical Deep-Dive

Git Plumbing for an Unattended Cron on a Shared Checkout

When an unattended cron has to commit to a shared, often-dirty checkout, git plumbing beats porcelain: hash-object + commit-tree + push survives concurrent sessions, behind-branch state, and push races.

Read