Skip to content
Frontend Feeds
  • Today
  • Archive
  • Sources
  • Categories
    • The Giants6 Sources
    • Multi Author Blogs18 Sources
    • Top Front-end Bloggers25 Sources
    • More Front-end Bloggers77 Sources
    • Browsers, engines, etc.11 Sources
    • Libraries, Frameworks, etc.12 Sources
    • Company/Startup Blogs12 Sources
    • Developer/Designer News4 Sources
    • YouTube Channels13 Sources
    • Podcasts7 Sources

Today

Front-end, in one read.

The latest from the sources worth following, newest first.

Monday, 5 October 2026

  • DEV CommunityThe Giantsread at source

    Claude Code mods: but does it run Doom?

    Yes ... Yes it does. The Minesweeper was the warm-up. A pane that can draw pixels and take the keyboard raises the only question the internet ever asks of a new screen, so the second game in the arcade is Doom: Freedoom on the doomgeneric engine, in a pane beside the transcript, while Claude works. /doom opens the pane and starts the game. In kitty the screen is a real picture at Doom's own 320×200 (Ghostty speaks the same protocol, but I haven't tried it); in any other terminal it is drawn in quadrant block characters, four pixels a cell. Walk with w and s , turn with a and d or by dragging sideways on the game, fire with space or the right mouse button. Getting a picture on screen took an afternoon. The controls took the rest of the week, because a terminal never tells you that a key was let go. Doom runs in a process of its own A mod's hooks run in a sandbox: no Node, no DOM, no require , and deliberately no WebAssembly . The typings say what to do instead: run the heavy thing as a program of its own. So the game is doomgeneric compiled to a native binary, and the mod starts it with $.process.spawn : const child = $ . process . spawn ({ argv : engineArgs ( binary , root , placement ), env : token !== null ? { DOOM_CLAUDE_TOKEN : token } : {} }) A spawned child lives as long as the mod reads its output and ends when the mod unloads, so there is no daemon to clean up. The engine prints doom-claude listening once it is ready, and from then on the mod talks to it with $.http.fetch : over a Unix socket on Linux and macOS ( socketPath ), and over 127.0.0.1 with a random 64-digit token on Windows, where every request without the token gets a 403. There is no compiler on the player's machine to count on, so the arcade ships six prebuilt engines, cross-compiled with zig cc from one Linux box: Linux, macOS and Windows, each on x86_64 and arm64. Honest status: only the Linux x86_64 one has run. The macOS and Windows builds are compiled and checked ( file says Mach-O and PE32+, the arm64 Mach-O carries its ad-hoc signature), and nobody has started one yet. Pixels that never pass through Claude Code In kitty and Ghostty, Claude Code's Image element can take a file instead of bytes. The engine writes each frame as raw RGB to a file beside its socket (written aside, then renamed over the old one, so it is never read half-written), and the mod points the Image at it: export function imageSource ( path : string , generation : number ): ImageSource { return { file : path , format : ' rgb ' , width : IMAGE . width , height : IMAGE . height , generation } } Claude Code hands kitty the path ( a=T,…,t=f in the graphics protocol), kitty reads the pixels itself, and a new generation makes it read the file again. Not one pixel goes through Claude Code. Every other terminal gets a Raster , and a Raster has opinions. It rounds every colour to 4 bits a channel. It paints at most 1024 colour pairs and snaps the rest, which speckles a photo-like picture. And it leaves blank cells at the end of a row undrawn, so a dark corridor came out with black holes in it. The engine pre-encodes each frame into cells: a 32-colour palette per scene (32 × 32 is 1024), each cell the quadrant glyph and the two colours that fit its four pixels best, a cell reusing its left neighbour's colours when they fit nearly as well, and no blank cells at all. Claude Code stops drawing when nothing moves The first live run froze for 300 ms at a time. $.ui.blit repaints a Raster at Claude Code's next frame, and with nothing else on screen moving, Claude Code draws only about three frames a second. The game was sending 30. The fix is a heartbeat: the red strip under the game is a Client , and it redraws itself every 30 ms, swapping one blank character for another. That keeps Claude Code drawing, and it costs far less than redrawing the whole pane from the hooks module. One more trap on the way: a blit resolves when it has been painted, not when it has been taken, so the frame loop must not await it before fetching the next frame. On a machine with other work running (load 5–6 on 8 cores), the picture changed 35–40 times a second in a plain terminal and 31–32 times a second in kitty. The block picture costs Claude Code about a full core; the kitty picture about a third of one. The keyboard that never lets go Doom wants to know when a key goes down and when it comes up. A terminal reports the press, then, after its repeat delay, the same press again every 30 ms or so, and never the release. Claude Code turns on kitty's keyboard protocol with flags 5 only, so a mod gets no release events and can't even tell a repeat from a new press. The terminal also repeats only the newest key: hold w , press a , and w goes quiet whether your finger is still on it or not. So every terminal Doom fakes the release, and my first attempt was a guess. A turn key held for 220 ms, so a tap would be a small turn. Then the terminal's first repeat came at 500 ms, and a held turn key stopped dead for 308 ms before it started turning for real. I measured it by reading the player's facing out of the engine every 10 ms. Then I patched it, and patched the patch. What fixed it was reading how the others do it: port fakes the release how doom-cli learns the terminal's repeat delay and rate per key; a fresh press holds until the first repeat is due, a repeat until the next is due intermission 550 ms after a fresh press, 120 ms while repeating; turning is mouse-only claude-doom a 160 ms pulse per press doom-braille released after 100 ms with no bytes doom-cli's model is the one that holds up, so the engine now does the same. A movement key holds until its next repeat is due. The repeat delay is learnt from the gap between a press and its first repeat (the median of the last five, capped at 600 ms), so it fits GNOME's 500 ms as well as anyone's faster setting: static uint32_t freshHold ( int key ) { return isMovement ( key ) ? s_RepeatDelay + DELAY_MARGIN_MS : OTHER_HOLD_MS ; } That has a cost doom-cli's own source admits in a TODO: a tap now lasts as long as the repeat delay, so one tap of d turned 61.5°. The TODO also names the fix: "just turn more slowly outside of state repeat? so it's still possible to do some precision aiming" . So a turn key in play doesn't press Doom's arrow key at all. It turns through Doom's mouse, slowly until the terminal starts repeating it, then at the arrow keys' full speed, with the same half-speed first six tics Doom gives a held key: if ( ! k -> isRepeating ) { s_KeyTurnTics = 0 ; return sign * TAP_TURN ; } return sign * ( s_KeyTurnTics ++ SLOW_TURN_TICS ? KEY_TURN / 2 : KEY_TURN ); A tap of d now turns 10.5°, about what a quick tap gives in Doom with a real keyboard, and a held d never stops for longer than 28 ms. In a menu, a pause or the title demo, the arrows stay arrow keys, because menu sliders want them. The mouse is the only exact hold A pointer is the one input that does report its release. So dragging sideways on the game turns, and letting go stops at once. It only turns: walking stays on w and s , and the keys and the mouse work together, so you can walk and turn at the same time, which the keyboard alone can't do. The first version of the stick walked too, and turned up to 2.5 times faster than the keys the further you dragged. Now any sideways drag past a small dead zone turns exactly as fast as a and d : export function stickOf ( pad : Pad | null ): Stick { if ( ! pad ) return { turn : 0 , forward : 0 , buttons : 0 } const dx = pad . isHeld ? pad . dx : 0 const turn = Math . abs ( dx ) > STICK . dead ? Math . sign ( dx ) * STICK . turn : 0 const buttons = ( pad . isFiring ? STICK . fire : 0 ) | ( pad . isHeld && pad . isStrafing ? STICK . strafe : 0 ) return { turn , forward : 0 , buttons } } 80 is Doom's mouse turning at 640 units a tic, the same as a held arrow key, and the engine gives a drag the same half-speed start. A drag and a held d stayed within a tic of each other at every point I measured: 51.0° against 52.8° at half a second, 114.3° against 112.5° at one. Escape belongs to the prompt A Client gets the keyboard only after a click, and Escape always hands it back to Claude Code's prompt. No mod and no keybinding can take Escape: it never reaches the mod at all. So the menu is m or backspace. Before the first click, space and the digits land in the prompt too. While you play, then, the prompt is Doom's. A prompt.edit hook takes game keys out of the prompt and hands them to the game, and drops the rest: state . isPromptOurs = true const keys = e . key ? [ e . key ] : Array . from ( String ( e . inputText ?? '' )). map (( ch ) => ({ key : ch })) const codes = keys . map ( doomKeyOf ). filter (( code ) => code !== null ) if ( codes . length > 0 ) { state . gameInputAt = now state . queuedKeys . push (... codes ) } state . promptCheckAt = now + PROMPT_CHECK_MS return { text : '' , cursor : 0 } Answering { text, cursor } without calling next consumes the key. The hook decides without a single $ call, because Claude Code sometimes lets the key through anyway when the hook is slow. Type / and the prompt is yours again at once, ten seconds without a game key gives it back too, and a draft you had typed before is never touched. This makes Doom different from the Minesweeper in one way that matters: it hooks the prompt. claude plugin validate lists it before any of the mod's code runs: ❯ ./register.ts hooks: session.start, command.run{command=doom}, ui.render{component=Pane}, ui.message, prompt.edit, ui.close, session.end ❯ ./register.ts calls: $.clock.after (via fitPane, focusSoon, watchEngine), $.clock.every (via startPulling), $.command.register, $.env.get (via readEnv), $.fs.exists (via findEngine), $.fs.write (via watchEngine), $.http.fetch (via pullFrame, sendKeys, sendStick, stopEngine), $.process.run (via findEngine, startEngine), $.process.spawn (via startEngine), $.prompt.fill (via clearLeakedPrompt), $.prompt.read (via clearLeakedPrompt), $.session.surfaces, $.ui.blit (via paint), $.ui.close, $.ui.invalidate, $.ui.open (via fitPane, openPane), $.ui.resolve It reads nothing the model sees and adds nothing to it, and its only network traffic is to its own engine on your machine. What the test kit missed this time The mod has 20 tests under claude plugin test , typechecked under the same strict config as the code. A review still found two bugs in them that a player would have hit in the first minute: A held drag stopped after 1.5 s. The engine lets go of a stick it hasn't heard about for 1.5 s, in case the mod died mid-drag. The strip re-sends a held stick on its heartbeat, but the layer over the game, where you actually drag, had no heartbeat. Hold still while turning or firing, and you stopped. A restarted engine replayed old keys. Each pane numbers its keys so a post that replaces an undelivered one loses nothing. Quit Doom from its own menu and run /doom again, and the hooks module forgot the numbers while the pane kept counting: the new engine got the last 24 keys again, menu and quit included. The first one is a lesson about the kit. The new test for it failed with the bug in place only once it stepped the frame clock one frame at a time: the kit delivers one post per ui.advance , so a two-second advance collapsed six re-sends into one and passed anyway. Play it In a Claude Code session: /plugin marketplace add reporails/arcade /plugin install doom@reporails-arcade Then start Claude Code in the fullscreen layout, which the mouse needs, and run /doom : CLAUDE_CODE_NO_FLICKER = 1 claude Mods load by default from Claude Code 2.1.287; on 2.1.285 and 2.1.286, add CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1 . Run it in kitty for the real picture (Ghostty should work the same, untested); every other terminal gets the blocks, and so does Windows, where no terminal the mod detects speaks kitty's picture protocol. It has been played on Linux. If you run it on a Mac or on Windows, tell me how it went. The mod's code is MIT, in reporails/arcade on GitHub. The engine is doomgeneric, GPL-2.0-or-later, and the game data is Freedoom, BSD. "Doom" is id Software's name; this plays Freedoom and contains nothing of id's.

  • DEV CommunityThe Giantsread at source

    Your cloud security tool is sorting by the wrong number

    Every cloud security tool I have used opens on the same screen: a list of findings, sorted by severity, with the criticals at the top in red. It feels like a priority queue. It is not one. Here is the problem with it, using two findings I had in front of me last month. Finding A. A critical CVE, CVSS 9.8, remote code execution, on a container image. The image runs in a private subnet. No ingress, no public load balancer, no NAT gateway on the route table. The task role can read one S3 bucket of build artifacts. Nothing else in the account can reach it. Finding B. A medium misconfiguration, CVSS 5.3. An EC2 instance with IMDSv1 still enabled. The instance sits behind an ALB that is open to the internet and runs an app with a path traversal bug nobody had got round to fixing. Its instance profile can assume a role in the production account, and that role can read the database credentials. Sorted by severity, A is at the top and B is twelve screens down. Sorted by what an attacker can actually do, B is the only one that matters this week. Severity is a property of the vulnerability, not of your environment This is the whole issue in one line. CVSS scores a vulnerability in the abstract. It has no idea whether the affected host is reachable, what the compromised identity can do next, or whether the blast radius is one build artifact or your customer database. That is not a criticism of CVSS. It was never meant to be a work queue. The specification says so. We turned it into one because it was the only number every tool agreed on, and because sorting by it is easy to implement. EPSS helps, because it estimates the probability a vulnerability gets exploited in the wild in the next thirty days. KEV helps more, because it is a list of things that definitely are being exploited right now. Both are still properties of the vulnerability. Neither one knows anything about your network. What actually makes something urgent Three things, and none of them are in the CVE record: Reachability. Can anything an attacker controls get to this asset? That means route tables, security groups, NACLs, load balancers, peering, and whatever your service mesh is doing. In practice most critical findings in a well segmented account are not reachable from anywhere an attacker starts. Identity. If this asset is compromised, what can the attacker do next? An instance profile that can call sts:AssumeRole into another account is worth more to an attacker than a dozen RCEs on isolated hosts. Over permissioned roles are the real lateral movement path in cloud, not kernel exploits. Blast radius. What is on the other side of that movement? There is a difference between reaching a staging bucket and reaching the production database, and no severity score captures it. Put those three together and findings stop being a list. They become a graph, and the question changes from "what is the highest score" to "which of these chain together into a route to something that matters". Doing it yourself You can get a surprising distance with the APIs you already have. Roughly: Pull your inventory. ec2:DescribeInstances , ecs:ListTasks , rds:DescribeDBInstances , the equivalents on Azure and GCP. Pull network configuration. Route tables, security groups, NACLs, load balancer listeners and target groups. Build the reachability edges from that rather than from tags, because tags lie. Pull IAM. Roles, attached and inline policies, trust policies, instance profiles. The trust policy is the edge you care about, because it is what makes cross account movement possible. Pull your vulnerability data from wherever it already lives, and join it onto the inventory by instance id or image digest. Mark your crown jewels by hand. Nothing automatic gets this right, and it is a short list. Walk the graph from every internet reachable node and see which crown jewels you can reach, and what you had to exploit on the way. Step 6 is where it gets interesting and where it gets slow. The graph is not large by graph standards, but the path search is not a simple shortest path, because each edge has a precondition: you only traverse the IAM edge if you first got code execution on the node that holds the role. I built this twice by hand before deciding it was a product. If you want to see what it looks like when it is finished, that is what we do at Secorvia : a live graph across AWS, Azure, Google Cloud and DigitalOcean, with findings ranked by exploitability and blast radius instead of by CVSS. The scanning is read only, and the free tier does not expire. Build it yourself if you have the time, though. You will understand your own environment far better than any tool will explain it to you. The thing I got wrong for a long time I used to think the goal was to get the critical count to zero. It is not, and chasing it actively hurts, because you spend your week on unreachable criticals and the reachable mediums stay open. A better target: zero findings that sit on a path from the internet to anything you would be sad to lose. That number is usually small enough to actually fix, which is the entire point. If you do this differently, I would genuinely like to hear it, particularly how you handle reachability through service meshes. That is the part I am least happy with.

  • DEV CommunityThe Giantsread at source

    The Pre-Migration Server Audit: What to Document Before You Touch Anything

    Migrating a VPS goes sideways in the same places every time — and it's never the part you expect. It's the queue worker left on the old box. The certbot renewal in root's crontab. The rsync that died on permissions. Before you move anything, audit the old server. Here's the checklist. Running services systemctl list-units --type = service --state = running ss -tlnp Write down everything. That random Python process on port 8000? That's serving something. Find out what before you migrate. Cron jobs (all four places) crontab -l # your user sudo crontab -l # root ls /etc/cron.d/ /etc/cron.daily/ /etc/cron.hourly/ systemctl list-timers # systemd timers (the new cron) Miss one and something silently stops working a week after migration. Disk and databases df -h du -sh /var/www/ * /home/ * mysql -e "SHOW DATABASES;" # or psql -l for Postgres Know what you're moving before you start moving it. SSL certificates certbot certificates ls /etc/letsencrypt/live/ Note expiry dates and renewal method. If certbot auto-renewal is configured, that config needs to move too. Config files Document every customized config: nginx/apache vhosts, PHP settings, systemd units, environment files. diff against defaults if you're not sure what you changed. This audit is Zone 1 of my VPS Migration Checklist & Runbook — 38 checkpoints across 8 zones, from this audit through cutover and the 24-hour watch afterward. The full runbook covers rsync flags, database moves, the hosts-file testing trick, and the rollback plan you write before you need it.

  • DEV CommunityThe Giantsread at source

    Who Changed My Site Property? The OutSystems Service Center Trick You Should Know

    Something changed in Production. The application is still running, but the behavior is different. You check the code. Everything looks fine. Then you check the configuration and discover: `MaximumTransactionLimit = 50,000 But you know it wasn’t always 50,000.` So the real question becomes: Who changed the Site Property, when did they change it, and what was the previous value? This is where OutSystems Service Center becomes surprisingly powerful. Where to Look Go to: Service Center → Monitoring → General Log Press enter or click to view image in full size Then search or filter for entries related to Site Properties. For non-secret Site Properties, the log can provide useful information about the change, including the user who performed it and the previous and new values. For example: Site Property: MaximumTransactionLimit Old Value: 25,000 New Value: 50,000 Changed By: admin@company.com Now you have a much clearer picture of what happened. Become a Medium member Instead of: “The configuration changed, but nobody knows why.” You can investigate the change directly from Service Center. Why This Matters Configuration issues are often difficult to troubleshoot because the application code may be perfectly fine. The problem might simply be a value that changed in the environment. That’s why being able to investigate Site Property changes can be extremely useful, especially in Production. One Important Detail The Site Property itself is not a permanent version history. The change information comes from the General Log, which has a limited retention period. So very old changes may no longer be available. For Secret Site Properties, sensitive values are not exposed in the log. The Takeaway When troubleshooting an OutSystems application, don’t only ask: “What changed in the code?” Sometimes the better question is: “What changed in the configuration?” And Service Center gives you a powerful place to start looking. Check the value. Investigate the change. Find out who made it. That’s the power of Service Center.

  • DEV CommunityThe Giantsread at source

    Woodpecker CI at 1,831 Titles and 2 Application Fingerprints: What a Narrow Signature Gap Means

    Woodpecker CI at 1,831 Titles and 2 Application Fingerprints: What a Narrow Signature Gap Means Continuous integration systems are among the more consequential self-hosted services, because the pipeline they run holds the credentials to deploy. Measuring their reachability is therefore worth doing carefully, and Woodpecker CI is a useful case for a signature comparison that does not behave as a title count would suggest. What was measured Collected from ZoomEye AI on 2026-10-02: title="Woodpecker" with sub_type="all" : 1,831 matches. app="Woodpecker" with sub_type="all" : 2 matches. title="Woodpecker CI" with sub_type="all" : 0 matches. Counts are indexed-service observations at collection time and describe reachable assets, not vulnerabilities. Two problems in the same set The first problem is a name collision. "Woodpecker" is a common English word and the name of unrelated software and organisations, so an HTML title containing it is not evidence of the CI product. The 1,831 title matches almost certainly include a large share of pages that have nothing to do with continuous integration. The second problem is the opposite of the one seen with several other products in this series. Here the application fingerprint does exist, but it matches only two services, while the title matches 1,831. A signature that matches two hosts against a title count of nearly two thousand is a signature that is either narrow or new. Neither field produces a usable population estimate on its own. The third query shows why refining the name does not help: the more specific string "Woodpecker CI" produces nothing, because the product's own pages do not use that exact title. Refinement that assumes the product name matches its marketing name will fail. What a reachable CI system carries The reason to care is the payload. A CI system holds or can obtain: Source code for every repository it builds. Deployment credentials for every target it deploys to, often in the form of tokens or keys stored as repository secrets. The ability to run arbitrary code as part of a build, which is the mechanism by which a pipeline compromise becomes a supply-chain event. That combination is why CI is a high-value target independent of what other services an organisation runs. The relevant exposure question is not whether the web interface is reachable, but whether an unauthenticated actor can influence what the pipeline runs. Measuring a product without a reliable name The practical lesson from these three numbers concerns method. When a product's name is a common word and its signature set is thin, a public measurement cannot produce a trustworthy instance count, and the correct output is a statement of that limitation rather than a number. What can still be done is a format-based query. CI systems typically expose distinctive paths and response structures: a health endpoint, a build status badge, an API route with a known prefix. A query built on one of those is far more specific than a title string, and it is the technique that produces a defensible count. For the operator, the more reliable route is direct. A pipeline system should be reachable from a known network, by a known set of users, and by webhook sources from the code host. Comparing the intended set against observed traffic is a better measurement than any public query. What operators should check Is the CI web interface reachable from outside the organisation's network, and if so, is it authenticated at the edge? Are repository secrets scoped to the repositories and environments that need them, rather than shared across a project? Do builds run in ephemeral runners rather than on a long-lived host that also holds deployment credentials? Is the webhook path restricted to the expected source, so that a forged webhook cannot trigger a build? Where ZoomEye fits ZoomEye is a legitimate part of this workflow in two ways that do not depend on the name query being reliable. Running the format-based query over time shows whether the population is changing, and running it against a known address range answers the operator's direct question. Both uses require the query to be specific enough to trust, which is exactly what the title query demonstrates it is not. What to take away 1,831 titles, 2 fingerprints and 0 for the more specific product string. The first is inflated by a name collision, the second is suspiciously narrow, and the third shows that adding a qualifier does not help. When the numbers disagree this way, the honest output is a limitation statement plus a better query, not a population estimate built from the largest figure. References ZoomEye AI, cyberspace search - counts collected 2026-10-02 with the queries stated above Woodpecker CI, Woodpecker documentation ZoomEye, search syntax reference

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: DevBoard – a simpler ClickUp for small dev teams, native apps and MCP

    Comments

  • Hacker News Front PageThe Giantsread at source

    "I'm Embarrassed on Behalf of the Tech Industry"

  • Go Make ThingsMulti Author Blogs1 min read

    No human is illegal

    I just ordered a bunch of leftist patches to put on my backpack, because virtue signaling is good, actually. One patch I kept seeing over and over again is… No human is illegal on stolen land. I get it. It’s supposed to point out the hypocrisy of complaining about illegal immigration in a country that was founded by stealing it from and genociding the people who already lived here.

  • Hacker News Front PageThe Giantsread at source

    Making a GTK application in Haskell, part 1

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: Vibivibi – End-to-end encrypted sharing of Coding Agent sessions

    Comments

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: EtherPK – an Obsidian and Logseq alternative with prose and blocks

    Comments

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: Approvegate – Deploy approvals enforced in your pipeline, not in Jira

    Comments

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: Native Port of Super Smash Bros. Melee

    Comments

  • Frontend Masters BlogMore Front-end Bloggers10 min read

    Transferring sibling-count() to a Parent Element

    You can tell a parent element how many children it has with... scroll-driven animations??

  • AbduzeedoMulti Author Blogsread at source

    Brand Identity: Papier by Ragged Edge

    Ragged Edge crafted a tactile brand identity for Papier, centering on the blank page with expressive serifs and bespoke stationery. Papier began as an online stationery brand. It soon grew into a life...

  • Hacker News Front PageThe Giantsread at source

    Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped

  • Flavio CopesMore Front-end Bloggersread at source

    I built Blips, 6,000 8-bit sound effects for my apps

    Blips is my free, open source Mac app and command line tool with about 6,000 8-bit sound effects made with jsfxr. Click a sound to hear it, drag it into your app.

  • Hacker News Front PageThe Giantsread at source

    Gitframes

  • Hacker News Front PageThe Giantsread at source

    Tell HN: Uceprotect is extorting website owners

  • Flavio CopesMore Front-end Bloggersread at source

    I built Snake, the classic phone game for the Apple TV

    Snake is my free, open source Apple TV game: the classic snake game from old mobile phones, full screen on a green LCD board, steered by swiping on the Siri Remote.

  • SitePointThe Giantsread at source

    8 Ways to Turn a Marketing Brief into a Testable Website

    null Continue reading 8 Ways to Turn a Marketing Brief into a Testable Website on SitePoint .

  • Flavio CopesMore Front-end Bloggersread at source

    How to use cf, the new Cloudflare CLI

    Learn cf, the new Cloudflare CLI: find commands with cf cli search, configure Workers in cloudflare.config.ts, deploy, and migrate from Wrangler.

  • SyntaxPodcastsAudioListen

    1044: Ruby on Rails is Dead

    Scott, Wes, and CJ ask whether Ruby on Rails is really dead (and whether Rust is just Rails you don't have to read), then dig into Meta's new Muse agent, which is free, comes with its own VM, and is already reading messages nobody asked it to. Plus: upm, a tiny TypeScript npm…

  • Flavio CopesMore Front-end Bloggersread at source

    Hosting picker: find where to host your app

    Answer four questions and get three hosts that fit your project, with a monthly price and the main catch. 21 providers, prices checked October 1, 2026.

  • Flavio CopesMore Front-end Bloggersread at source

    Payment picker: find how to get paid for your app

    Find a payment provider for your product, compare fees on your own numbers, and see who handles tax and disputes. Merchant of Record and direct providers.

  • Level AccessCompany/Startup Blogs9 min read

    AI vs. Closed Captioning: Understanding Audio Accessibility Compliance

    Captions are written text meant to account for audio content such as spoken dialogue, important sounds, and other audio information. They may also The post AI vs. Closed Captioning: Understanding Audio Accessibility Compliance appeared first on Level Access .

  • Flavio CopesMore Front-end Bloggersread at source

    A deep dive into cron

    Learn cron on Linux and macOS: crontab syntax, schedules, the cron environment, logs, overlapping runs, time zones, launchd and systemd timers.

  • SitePointThe Giantsread at source

    How to Build Smarter Marketplace Search with Vanilla JavaScript

    null Continue reading How to Build Smarter Marketplace Search with Vanilla JavaScript on SitePoint .

  • Flavio CopesMore Front-end Bloggersread at source

    I built Blueprint, a Mac app that shows how my apps are built

    Blueprint is my free, open source Mac app that draws how your apps are built, their workflows and the data they store, from maps your coding agents write.

  • Flavio CopesMore Front-end Bloggersread at source

    How to sync a Mac app with its iPhone app

    How to sync a Mac app and its iPhone companion: CloudKit, what the Apple Developer Program unlocks, iCloud for apps outside the App Store, and alternatives.

  • SitePointThe Giantsread at source

    7 Features Every Creator Marketplace Should Build Before Launch

    null Continue reading 7 Features Every Creator Marketplace Should Build Before Launch on SitePoint .

  • HeyDesignerDeveloper/Designer Newsread at source

    Timeless type family

    Training AI to paint with code, Design is a nice-to-have, Google Fonts superfamilies, A flame needs three sine waves.

  • AbduzeedoMulti Author Blogsread at source

    Mother Design Unveils the Realm Brand Identity

    Mother Design turned Serial Box into Realm, and the new Realm brand identity pairs a mascot-eyed wordmark with glowing portals and deep purple. The first thing you meet is the wordmark, and it stares ...

  • Auth0 BlogCompany/Startup Blogsread at source

    Auth0 Metadata Explained: user_metadata vs app_metadata

    user_metadata and app_metadata aren't interchangeable. Users can edit one, not the other. Learn how this distinction becomes a security boundary in your post-login Actions.

Sunday, 4 October 2026

  • SitePointThe Giantsread at source

    Next.js Chunk Load Error: How to Fix Production Failures

    Diagnose and resolve intermittent Next.js App Router ChunkLoadError issues in production, from deploy skew and proxy matchers to CDN caching and error boundaries. Continue reading Next.js Chunk Load Error: How to Fix Production Failures on SitePoint .

  • SitePointThe Giantsread at source

    Node 26 Debounce and Throttle: Practical Guide and Lodash Comparison

    Use Node.js 26.10's built-in util.debounce and util.throttle: options, promise behavior, tested examples, the cancel() gotcha and how they differ from Lodash. Continue reading Node 26 Debounce and Throttle: Practical Guide and Lodash Comparison on SitePoint .

  • Speckyboy Design MagazineDeveloper/Designer News4 min read

    Should Your Agency Charge Less for AI-Assisted Solutions?

    Should clients pay less when agencies use AI? Learn why faster WordPress development still depends on expertise, testing, planning, and clear communication about results. The post Should Your Agency Charge Less for AI-Assisted Solutions? appeared first on Speckyboy Design Magazine .

  • Jim Nielsen’s BlogMore Front-end Bloggersread at source

    “I’m Embarrassed on Behalf of the Tech Industry”

    That’s something Ben Thompson said a recent episode of Dithering . He was referring to how he felt while trying to help his mom get control of her digital life. Everything was just too hard and convoluted and he felt embarrassed as someone who works in tech. That very same evening, I randomly got this text from a family member. I hear this a lot from family and friends who sit outside tech. “Nothing works.” “Everything is hard to use.” “I can’t make sense of this.” And to them I am a representative, a connection, to this pain in their lives. And I, too, am embarrassed on behalf of the tech industry — by our collective failure. Reply via: Email · Mastodon · Bluesky

  • AdactioTop Front-end Bloggersread at source

    Sunday session

  • AbduzeedoMulti Author Blogsread at source

    Mix Interiors Brand Identity Is a Masterclass by Marçal Prats

    Marçal Prats rebuilt the Mix Interiors brand identity on a square grid, then expanded the three-letter MIX logotype into a full display typeface. The MIX mark reads as flat planes that refuse to stay ...

  • Stéphanie WalterMore Front-end Bloggersread at source

    Pixels of the Week – October 4, 2026

    👉🏻 Curated weekly UX Research, Design & Tech resources: building a general-purpose accessibility agent, how to make your design system AI-ready, WCAG 3.3.4 error prevention explained, why you got faster but your company didn't, the AI delegation matrix for your UI, flame painting art on copper, curated branding inspiration, how mechanical watches work, maps of book characters' journeys, free no-login utility tools.

  • Go Make ThingsMulti Author Blogsread at source

    Radical books that aren't a slog

    I’m loving the resurgence of zines! Violet B. Fox just released on on radical books that aren’t a slog, a collection of books for leftists that aren’t super dense theory by old dead white guys. There’s so many good ones to choose from, but I started with The Parable of the Sower by Octavia Butler. For posterity, I’ve saved a local backup, but you should visit Violet’s site instead.

  • AbduzeedoMulti Author Blogsread at source

    Best of the Week: Monograms, Serifs, and Tactile Systems

    Our curated roundup of the best of the week highlights architectural monograms, editorial serif fonts, and tactile apothecary packaging from ISO week 2026-W40. This week’s editorial throughline explor...

  • Christian HeilmannTop Front-end Bloggers7 min read

    AI needs fewer Iron Men and more Smart Hulks

    When I got into machine learning it was all about making the world a better place. I worked for Microsoft and had access to projects and the smart people behind them that all were for the benefit of humans. Batch analysis of MRI scan data to allow doctors to detect cancer growths faster. Analysis of […]

  • phpiedTop Front-end Bloggers2 min read

    Debugging download initiator

    I was recently debugging why an image was being downloaded. In Chrome devtools, in the network panel, the column for "initiator" was pointing to the end of the HTML document. But that wasn't true and I suspect when Chrome gives up on trying to figure out the actual code location, the default is the HTML […]

  • Jens Oliver MeiertTop Front-end Bloggersread at source

    We Need to Protect Muslims

    The West has developed a self-fueling story about Muslims that is used to wage a non-scrutinized forever war on Islam. Both the story and the war need to stop.

Saturday, 3 October 2026

  • DXDMore Front-end Bloggersread at source

    Não é Só um Logótipo, literalmente

    A identidade visual do podcast "Não é Só um Logótipo" é um convite à descoberta de um sem fim de curiosidades sobre a disciplina do design. O conteúdo Não é Só um Logótipo, literalmente aparece primeiro em DXD .

  • AbduzeedoMulti Author Blogsread at source

    Inside the Craft of Module: Brand Identity by FAST Studio

    FAST Studio crafts a disciplined brand identity for Riyadh architecture firm Module, balancing geometric order and human-scale engineering. Module approaches architecture as enduring cultural infrastr...

  • Adam ArgyleTop Front-end Bloggersread at source

    Page View Count Regression Fixed

    Page view counts regressed Oct 1 and were fixed just now. Hopefully those historical counts can be retrieved or fixed; working on it.

  • SitePointThe Giantsread at source

    Pi 1.0 Coding Agent Setup: Install, Configure MCP, and Run Codemode

    Install Pi 1.0, add MCP servers with pi mcp add, and use codemode scripts. A setup guide for developers, based on the official Pi docs. Continue reading Pi 1.0 Coding Agent Setup: Install, Configure MCP, and Run Codemode on SitePoint .

  • AbduzeedoMulti Author Blogsread at source

    Sabina Farziyeva Unveils Editorial Illustration for Nargis

    Sabina Farziyeva's editorial illustration series for Nargis Magazine reimagines fashion editors as collage portraits built of clashing patterns. The premise is character, not likeness. Each portrait b...

  • SitePointThe Giantsread at source

    How to Detect Breaking API Changes with TypeScript and OpenAPI

    Build a CI pipeline that catches breaking API changes before runtime with oasdiff spec diffing and openapi-typescript type checks in GitHub Actions. Continue reading How to Detect Breaking API Changes with TypeScript and OpenAPI on SitePoint .

  • AbduzeedoMulti Author Blogsread at source

    Resn Website — A Masterclass in Web Design by Marcus Brown

    Marcus Brown crafts an iconic web design for the Resn portfolio, pairing tactile click-and-hold mechanics with audiovisual surprises. Resn has long held a singular reputation across the global digital...

  • Jeffrey Zeldman PresentsMore Front-end Bloggersread at source

    Another Saturday, Another Song.

    🎧 “Side Two” LP in progress. At 14 songs, it is nearly complete. I expect to release it before the year’s end. The post Another Saturday, Another Song. appeared first on Jeffrey Zeldman Presents .

  • AbduzeedoMulti Author Blogsread at source

    Brand Identity: Lloyds by Wolff Olins

    Wolff Olins' brand identity for Lloyds turns a 330-year-old bank into a living system, starting with the black horse, finally taught to move. The heart of the project is the Cancara Philosophy, named ...

  • David BushellMore Front-end Bloggers4 min read

    Friendship ended with Deno, now Node is my best friend

    It’s finally time I go crawling back to Node! I’ve been using Node heavily this month on a SvelteKit client project. When did Node get so good‽ Deno has been my go-to runtime for so long I forgot how to Node. Now I’m back, I find all the ECMAScript† sugar is supported and the old annoying APIs have […]

  • HTML All The ThingsPodcastsAudioListen

    AI Has Made Skilled Labour Almost Free (And It’s Scary)

    Our world already has an instant gratification problem and AI has somehow made it worse. It's making skilled work faster and cheaper than ever, which in turn makes us more impatient than ever. Why should we spend a week learning a new SEO tool or a new coding method when we can…

  • remy sharp's b:logTop Front-end Bloggersread at source

    Firefox version 157 is very round (and how to make it less round) – creolened.com [link]

    This is very useful. I do like the direction Firefox design is going, but the very round tabs make me think the hit target for tabs - especially when pinned and muted - is much smaller than it actually is. Original link: creolened.com/firefox-version-157-is-very-round

  • Adam ArgyleTop Front-end Bloggersread at source

    Transitioning Field Sizing Content With CSS

    Neat CSS trick: Use anchor to track the size changes in a textarea (or whatever) and transition instead of instantly update 🤘🏻 See on Codepen

Friday, 2 October 2026

  • SitePointThe Giantsread at source

    Building Lead Capture Forms That Convert: A Developer's Guide

    null Continue reading Building Lead Capture Forms That Convert: A Developer's Guide on SitePoint .

See everything from the last 30 days →

Articles belong to their publishers. This site only collects what their feeds provide.

Updated 5 October 2026 at 16:46