AI coding agents are changing the plumbing as much as the code: Kondasamy's survey maps how agents patch files, while Linear found CI—not code generation—had become the bottleneck and rebuilt it around faster runners, lighter gates, and less repeated setup. Security brought less cheerful news: Ars Technica's TeamPCP investigation follows the poisoning of hundreds of packages and breaches at over a thousand companies; GitHub Actions cache-mode narrows cache access to help prevent another cache-poisoning surprise, and Next.js patched a critical next/og RCE.
On the systems side, DuckDB-Wasm with OPFS makes persistent browser SQL practical, while a Postgres row-lock deep dive shows how locking writes to the heap page itself. Anthropic also got claude.ai 3x faster in two weeks with measured bottleneck hunts and CI ratchets.
And the agent tooling gets its own reality check: self-improving harnesses can overfit, Gortex gives agents a local code graph with search and impact analysis, and secure-eval-worker runs untrusted JavaScript behind time, memory, and permission limits. Helpful agents, now with a sensible amount of adult supervision.
Enjoy!
Signup here for the newsletter to get the weekly digest right into your inbox.
Find the 11 highlighted links of weeklyfoo #156:
How coding agents edit files
by Kondasamy
Survey of search-and-replace blocks, fallback matchers, snapshot hashes, AST codemods and neural fast-apply models across Aider, Claude Code, OpenCode and Cursor
📰 Good to know, ai,agents,tooling
AI coding has made CI a bottleneck, so we reworked ours to keep up
by Linear
Linear cut average PR wait time while its test suite nearly quadrupled, through faster runners, lighter gating jobs and less repeated setup
📰 Good to know, ci,testing,performance
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
by Ars Technica
How a researcher went inside TeamPCP, the group that poisoned hundreds of open source packages and breached over a thousand companies
📰 Good to know, security,supply-chain,oss
Persistent databases in the browser with DuckDB-Wasm and OPFS
by DuckDB
Run DuckDB in the browser with a database file that survives reloads via the Origin Private File System
📰 Good to know, databases,wasm,browser
GitHub Actions adds cache-mode to limit cache access
by Socket
Restrict cache access per workflow or job to defend against cache poisoning like the one that hit TanStack's npm packages
📰 Good to know, github,ci,security
Where Postgres stores row locks
by Radim Marek
pageinspect reveals that every row lock ends up as a write to the heap page
📰 Good to know, postgres,internals
How we made claude.ai 3x faster in two weeks
by Anthropic
Deterministic benchmarks, parallel bottleneck hunts and CI ratchets cut fresh-load time from 3.1s to 0.55s
📰 Good to know, performance,frontend,ai
Self-improving agent harnesses overfit, how Google fixes it
by Stacksweep
Sparsity and magnitude penalties plus noise-aware acceptance keep evolved harnesses from memorizing their eval set
📰 Good to know, ai,agents,evals
Next.js security update, September 2026
by Vercel
Next.js 16.3.6 fixes a critical RCE in next/og ImageResponse affecting v16.2+, with nine more fixes scheduled
📰 Good to know, nextjs,security,react
Gortex
by zzet
Indexes code into a local graph and exposes cross-repo search, references, call chains and impact analysis via CLI, MCP server and API
🧰 Tools, ai,agents,mcp,code-search
secure-eval-worker
by Matteo Collina
Run untrusted or AI-generated JavaScript in a locked-down worker with timeouts, memory caps and only the host functions you allow, built on the Node 26 permission model
🧰 Tools, nodejs,security,ai
Want to read more? Check out the full article here.
To sign up for the weekly newsletter, visit weeklyfoo.com.
Top comments (0)