Grilled Cheese

ExploreLog inSign up

Matteo Collina

@nodeland.dev

374 Following4.6k Followers

Platformatic.dev Co-Founder & CTO, Node.js TSC member, Lead maintainer Fastify, Board OpenJS, Conference Speaker, Ph.D. Views are my own.

PostsRepliesMedia
@nodeland.devOct 9, 2026, 5:19 AM

no software is well defined

@nodeland.devOct 8, 2026, 7:23 PM

Still stand to what I wrote. But if you read the full series, there is essentially a path forward for the tinkerers!

adventures.nodeland.dev/archive/soft...

@nodeland.devOct 8, 2026, 10:55 AM

Indeed they are. And they will get even more unfortunately, as all tech is becoming more and more expensive to join. Sadly.

@nodeland.devOct 7, 2026, 8:08 PM

we are doing it again next year!

@nodeland.devOct 7, 2026, 8:08 PM

Maybe I should see if I can get custom bags for next year!

@bengl.devOct 7, 2026, 7:27 PMReposted by @nodeland.dev

I have sampled the @nodeconf.eu speaker gift (a bag of coffee) and I can confirm that it's pretty tasty!

Thanks @nodeland.dev et al!

(For the curious: I did 383ml to 23g, steeped for 2 min in a Clever Dripper, stir, another 30s, then release.)

@nodeland.devOct 7, 2026, 3:59 PM

In the era of AI, our network is what makes us valuable, and the work more enjoyable. (The work is mysterious and important). Go to more conferences.

@nodeland.devOct 6, 2026, 3:59 PM

As a maintainer who lives in these flows, this is a huge quality-of-life boost. Trying to triage vulnerability reports with a single free-text box and no way to share private context was painful. GitHub heard us. 👏

@nodeland.devOct 6, 2026, 3:59 PM

5. New SecurityAdvisory fields in the GraphQL API.
cveId, sourceCodeLocation, githubReviewedAt, nvdPublishedAt, repositoryAdvisoryUrl, plus severities and isWithdrawn filters. One auth path, one rate limit budget, fewer round trips.

github.blog/changelog/20...

@nodeland.devOct 6, 2026, 3:59 PM

Announcement: github.blog/changelog/20...

@nodeland.devOct 6, 2026, 3:59 PM

4. Repository security advisory comments API (public preview). Until now, the triage discussion lived only in the web UI. Now you can list, get, add, and edit comments via the REST API, and get comment counts in responses. I can now fully automate this via my custom Pi configuration.

@nodeland.devOct 6, 2026, 3:59 PM

3. Confidential comments on repository security advisories.
Post comments visible only to maintainers. No more moving your abuse/investigation notes to Slack when a reporter can see everything. Clearly marked, permission-aware, and audit-logged.

github.blog/changelog/20...

@nodeland.devOct 6, 2026, 3:59 PM

2. Rate limits for private vulnerability reports.
Bulk and automated reports were burying the real ones. Now there's a daily per-user cap, you can set a custom repo limit, and add trusted reporters to an allow list. Legit researchers get through, spam doesn't.

github.blog/changelog/20...

@nodeland.devOct 6, 2026, 3:59 PM

Announcement: github.blog/changelog/20...

@nodeland.devOct 6, 2026, 3:59 PM

1. Structured forms for private vulnerability reports. No more single free-text box. Now reporters fill in a summary, details, PoC (min 150 chars), and impact. You can even customize the form via .github/VULNERABILITY_REPORT.yml and require a CWE. Reporters can also disclose whether they used AI. 🎯

@nodeland.devOct 6, 2026, 3:59 PM

Big shoutout to @GitHub this week. In two days, they shipped a stack of security advisory updates that maintainers have been asking for for a long time. 🛡️

@nodeland.devOct 5, 2026, 3:59 PM

So do I still read code written by AI? Every single line. The human in the loop isn't a bug to be optimized away. It's the feature to protect.

See you next wednesday for the full conversation 👇
streamyard.com/watch/PDmxZD...

@nodeland.devOct 5, 2026, 3:59 PM

An academic paper just confirmed what I've been arguing: the bottleneck is judgment, and it's getting more valuable. Not prompting. Not "agentic infrastructure." Judgment.

adventures.nodeland.dev/archive/the-...

@nodeland.devOct 5, 2026, 3:59 PM

My worry isn't that software development is dying. It's that "I didn't review it, the AI wrote it" becomes an acceptable excuse. At AI speed, the scale of damage when you ship code you don't understand is enormous.

@nodeland.devOct 5, 2026, 3:59 PM

The moment I stop reviewing is the moment I stop being responsible for what I ship. AI is just another contributor now. I review its PRs like I review anyone else's, and I decide if it's good enough.

Older posts
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT