Skip to content
Frontend Feeds
  • Today
  • Archive
  • Sources
  • Categories
    • The Giants6 Sources
    • Multi Author Blogs18 Sources
    • Top Front-end Bloggers25 Sources
    • More Front-end Bloggers77 Sources
    • Browsers, engines, etc.11 Sources
    • Libraries, Frameworks, etc.12 Sources
    • Company/Startup Blogs12 Sources
    • Developer/Designer News4 Sources
    • YouTube Channels13 Sources
    • Podcasts7 Sources

Today

Front-end, in one read.

The latest from the sources worth following, newest first.

Saturday, 10 October 2026

  • DEV CommunityThe Giantsread at source

    57 Findings Across 12 AWS Services. Zero False Positives. No Credentials Required.

    ✓ Human-authored analysis; AI used for formatting and proofreading. NCC Group built SadCloud to test cloud security tools. It deploys intentionally vulnerable AWS infrastructure with 84 misconfigurations across 22 services so you can measure exactly what your scanner catches and what it misses. We pointed a static analyzer at a SadCloud deployment. It does not use credentials or make API calls against the live environment. Just a JSON snapshot of the AWS account state, evaluated on a laptop. 57 findings. 12 services. 1 compound risk chain. Zero false positives. This post walks through the results, including what we missed and why. The setup SadCloud deploys resources via Terraform. Each service module has flags that enable specific misconfigurations. These are things like CloudTrail with no log validation, KMS keys with no rotation, IAM roles with wildcard trust policies, security groups open to the internet. We enabled everything: CloudTrail, IAM, KMS, EC2, EBS, ELBv2, CloudWatch, AWS Config, CloudFormation, OpenSearch, S3, and SES. Terraform created the resources in a dedicated AWS account. We captured the state using standard AWS CLI calls ( describe-trails , list-users , list-keys , describe-instances , etc.), saved the output as JSON files, and destroyed the infrastructure. Total time infrastructure was live: under 2 hours. Total cost: under $10. The analysis ran against the JSON files after the infrastructure was already gone. The progression We got to 57 in four iterations, each one exposing a gap that we fixed before the next run. Iteration Services Assets Findings What changed 1 3 9 12 CloudTrail + KMS + IAM baseline 2 3 11 19 Fixed Terraform flag conflict, authored 3 new controls 3 7 21 26 Added S3, EBS, EC2 security groups 4 12 35 57 Fixed property path mismatches, added remaining services Every iteration followed the same cycle: run the analyzer, read the gaps, determine whether the gap is a missing observation, a missing control, or a property path mismatch, fix it, re-run. What fired 57 findings across 28 controls. Here's the breakdown by service and severity: Critical (3 findings) The three highest-severity findings represent the most dangerous misconfigurations in the deployment: An IAM role with Principal: * in its trust policy. Any AWS account in the world can assume it. A group with full administrator access attached. And a CloudTrail configuration that's single-region only, meaning activity in other regions goes unlogged. High (22 findings) CloudTrail with no log file validation and no S3 data event logging. A KMS key with an open key policy ( Principal: * ). An EC2 instance with a public IP, IMDSv2 not enforced, and secrets in user data. An ALB with an HTTP listener (no TLS). An OpenSearch domain with an open access policy. Security groups with high ports and restricted ports open to 0.0.0.0/0 . S3 buckets with public prefixes and no object ownership controls. Shadow IAM policies (inline policies that duplicate or conflict with managed policies). Each of these maps to a SadCloud misconfiguration flag. The analyzer identified the correct asset, the correct property, and produced a remediation specific to the finding. Medium (24 findings) Password policy weaknesses (short minimum length, no complexity requirements, no reuse prevention). KMS key rotation disabled. S3 with no versioning and no access logging. Inline IAM policies on users and groups. CloudFormation stack with termination protection disabled. ALB with no deletion protection and no access logging. OpenSearch with no logging. Seven security groups with 0.0.0.0/0 CIDR blocks and seven with overly broad CIDR ranges. Low and Info (8 findings) Empty IAM groups (members assigned to a group that has a policy, but the group has no members or vice versa). Incomplete CloudTrail and CloudFormation configurations. S3 governance gaps. The compound chain The most important finding: [critical] Chain: cloudwatch_detection_broken Detection pipeline broken at the metric-filter, alarm, or alarm-action layer. The alarm exists in the console with the expected name, but the path from log event to operator notification is severed. Failing: CTL.CLOUDWATCH.ALARM.NOACTION.001 Fix any of: CTL.CLOUDWATCH.GHOST.METRICFILTER.LOGGROUP.001, CTL.CLOUDWATCH.ALARM.DISABLED.001 Score: 75.0 Stages: detection_evasion SadCloud deploys a CloudWatch alarm with no actions configured. On its own, that's a medium-severity finding with an alarm that doesn't notify anyone. Every scanner catches it. The compound chain links this to the detection pipeline: CloudTrail logs → CloudWatch metric filters → CloudWatch alarms → notification actions. If any stage in that pipeline is broken, the entire detection path is severed. The team believes monitoring is in place because the alarms exist in the console with the expected names. The reality is that an attacker's activity flows through CloudTrail, hits the metric filter, triggers the alarm and nothing happens. No page, Slack message or incident. This is the class of finding that individual-check scanners structurally cannot produce. The alarm-without-actions check exists in every tool. The insight that this specific alarm is the only detection path for a specific class of attacker activity, and that its failure creates a detection blind spot that requires evaluating the composition, not the setting. What we missed S3 public bucket policies (3 misconfigs): The AWS account has BucketOwnerEnforced and BlockPublicPolicy enabled at the account level. SadCloud's S3 module was written for older AWS defaults that allowed public bucket ACLs and policies. The module's public-bucket resources fail to deploy. This isn't a Stave gap. The misconfigurations don't exist in the deployed infrastructure because AWS prevents them. We'll revisit when SadCloud updates its S3 module for current AWS defaults. 9 services with no deployed resources: ACM, ECR, EKS, ELB classic, Lightsail, RDS, Redshift, SNS, and SQS modules either don't create resources by default or were blocked by sandbox restrictions. Nothing to scan means nothing to find. These services have controls in the catalog. They'll be validated when infrastructure exists. SES (2 misconfigs): Domain identity and DKIM are deployed but no matching controls exist in the catalog yet. Noted as a gap for future work. 4 Prowler parity checks: The coverage posture shows 44 of 47 Prowler IAM checks and 20 of 21 S3 checks covered. The 4 uncovered checks are prescriptive presence-checks (does a specific named role exist, is a root account feature enabled, are S3 event notifications turned on). These are compliance checkbox items, not risk-based invariants. The numbers Infrastructure deployed: Full SadCloud (all_findings = true) Services with resources: 12 of 22 Total misconfigurations: ~60 deployable (of 84 catalog) Findings produced: 57 False positives: 0 Compound chains: 1 Controls fired: 28 Assets evaluated: 35 Attack surface: 28 Analysis time: 4.7 seconds Credentials required: 0 Network access required: none What this validates SadCloud exists to test security tools. NCC Group uses it to benchmark ScoutSuite, Prowler, CloudMapper, CloudSploit, and tfsec. The published sample reports show what each tool finds against the same corpus. Running a static analyzer against the same corpus and getting 57 findings with zero false positives from a JSON snapshot validates three things: First, the observation contract works. Raw AWS CLI output transforms into a structured format that the analyzer's controls can evaluate. The property paths match what the controls expect. When they didn't match (iterations 2 and 3), fixing the paths immediately produced the missing findings. Second, the control catalog covers real misconfigurations. Every finding maps to an actual SadCloud flag. The controls weren't written for SadCloud. They were written from incident reports, compliance frameworks, and AWS security best practices. They fired against SadCloud because the misconfigurations are real patterns that appear in production environments. Third, compound chain detection works on third-party infrastructure. The cloudwatch_detection_broken chain wasn't authored for SadCloud. It was authored from the observation that detection pipelines fail silently when any stage is broken. SadCloud happened to deploy that failure mode with an alarm with no actions and the chain caught it. What's next This is the third vendor lab completed. Datadog Pathfinding Labs validated IAM privilege escalation detection. Bishop Fox IAM Vulnerable validated 30 escalation paths. NCC Group SadCloud validated broad CSPM coverage across 12 services. The hardest test is still ahead: Rhino Security's CloudGoat, which deploys multi-service compound attack chains where the vulnerability isn't in any single resource but in the path between them. That's where compound chain detection either proves out at scale or doesn't. The tool is Stave . Static analysis. No credentials. No agents. Files in, findings out.

  • DEV CommunityThe Giantsread at source

    Conflicting Android beta reports: separating observations from verified bugs

    Two reports from a small Android beta described different behaviour for the same breathing timer: one tester said it restarted after switching apps, while another said it resumed correctly. The second report identified a Pixel 7 running an Android 15 beta. The device and Android version for the first report were still unknown when these notes were prepared. A separate report described a home-screen widget whose money-saved value matched the app only after a manual refresh. These are user-reported observations. They do not establish the cause, prove a general Android problem, or demonstrate that a fix works. The follow-up test plan For the timer, record the device model, Android version, exact steps, time spent outside the app, and the displayed state before and after returning. Repeat the same sequence on the same device before comparing it with another device. For the widget, use fictional input values. Record the app value and widget value, then check them after reopening the app and after a manual widget refresh. Keep those actions separate so the report identifies which action changed the result. For each issue, keep a distinction between: Reported: a tester described it. Reproduced: the same steps produced it during an observed check. Changed: an implementation change was made. Verified: the original steps were repeated on the new build and the expected result was observed. At this stage, these notes cover the reports and proposed follow-up checks. They do not claim an implementation change or a verified fix. Use sample data in screenshots and reports. Device model, OS version and reproduction steps are useful; private journal text, account details and health information are unnecessary for these checks.

  • DEV CommunityThe Giantsread at source

    PDF to Excel in the Browser: Extracting Tables with JavaScript

    Series: Building PdfWord — a free, no-backend PDF tools site (Part 11) "Convert my bank statement PDF to Excel" — one of the most requested features I've gotten, and one of the most technically dishonest-sounding. Here's the dirty secret of PDF-to-Excel: PDFs don't have tables. They have glyphs painted at coordinates. There are no rows, no columns, no cells — just text floating at (x, y) positions on a page. So "extracting tables" really means reconstructing structure from positioned text. Here's how I do it entirely in the browser, with pdf.js and SheetJS, no server involved. Try it: PDF to Excel Step 1: Get positioned text from pdf.js page.getTextContent() returns every text fragment on the page, each with a transform matrix [a, b, c, d, e, f] where e and f are the x/y position. (Note: PDF y-axis points up , so sorting needs care.) You also get the font size from transform[0] and the fragment width. That's your entire raw material. Step 2: Reconstruct lines with groupLines() This is the core algorithm, and it's pleasingly simple: Throw away empty fragments. Sort everything by y descending, then x ascending . Walk the sorted list: start a new line whenever the y-coordinate differs from the current line by more than a tolerance — I use Math.max(2.5, fontSize * 0.32) , so the tolerance scales with the text size. Within each line, sort fragments by x and join them with gap-aware spacing — a wide gap between fragments usually means a column break, so it gets wider spacing in the output. rows . sort (( a , b ) => b . y - a . y || a . x - b . x ); // y down the page, x across const tol = Math . max ( 2.5 , r . size * 0.32 ); // tolerance scales with font size if ( ! cur || Math . abs ( cur . y - r . y ) > tol ) { cur = { y : r . y , parts : [] }; lines . push ( cur ); // new line } The font-size-scaled tolerance is the bit I'm proudest of. A fixed 3px tolerance breaks on large headings; a pure relative tolerance breaks on tiny footnotes. The max() of the two handles both. Step 3: Lines become a spreadsheet with SheetJS Once you have lines of text, the Excel part is almost boring — which is a compliment to SheetJS: const ws = XLSX . utils . aoa_to_sheet ( rows ); // array-of-arrays → worksheet const wb = XLSX . utils . book_new (); XLSX . utils . book_append_sheet ( wb , ws , ' Text ' ); const out = XLSX . write ( wb , { bookType : ' xlsx ' , type : ' array ' }); // → Blob download as .xlsx I insert --- Page N --- separator rows between pages so multi-page PDFs stay navigable, and there's a progress bar since a 50-page statement takes a few seconds. The whole library ( xlsx.full.min.js ) is served locally — no CDN, so it works offline once cached. The honest limitations Text-based PDFs only. A scanned statement is images, not text — the tool says so plainly ("No readable text found — this PDF may be scanned images only") and points you at the OCR tool instead of handing you an empty spreadsheet. A silent empty file is the worst possible output. It's reading order, not real tables. Merged cells, multi-line cells, and rotated text confuse the coordinate heuristic. What you get is clean, readable text in the right order — enough to work with, not a pixel-perfect table clone. Numbers come out as text, deliberately. Auto-detecting number formats sounds smart until it silently turns an account number into scientific notation. I'd rather you format the column yourself than discover corrupted data later. For bank statements, invoices, and reports — the "rows of stuff" PDFs — it does the job. For a beautifully typeset annual report with nested tables... manage your expectations, and mine. Try it: PDF to Excel — upload a statement and see what the coordinate heuristic makes of it. What's the gnarliest PDF table you've ever had to extract? Bonus points if it involved merged cells.

  • DEV CommunityThe Giantsread at source

    I built an AI pet dance app: one photo, one generator

    I built CatDance , a small web app that turns a pet photo into an AI dance video. The idea is playful: take a cat, dog or plush photo and make it the star of a short dance clip. The interesting engineering problem was making the workflow feel simple even though preview and full generation have different costs and capabilities. One upload, two choices My first approach separated the free preview and full video too much. That made people repeat work. The current generator lets you upload the photo once and choose the free preview or full version in the same place. A Google account can try one free 5-second preview. The full version produces approximately 19 seconds at 720p, supports an optional second pet and preset scenes, and starts at $9.90 as a one-time purchase. There is no subscription. The preview and full version use different models, so the preview is a way to try the workflow rather than a promise of identical final output. Generation is only half the job The frontend uses React and TanStack Start, with the application running on Cloudflare Workers. Generated files are delivered through object storage. One practical lesson: a provider reporting “completed” is not the same as a customer having a downloadable video. The application still has to retrieve the output, assemble the full clip when necessary, attach template audio and persist the final file. I now treat delivery as an explicit part of the job lifecycle. Errors record which stage failed, retries have a limit, and failed orders return the generation credit. An ambiguous submission should also be investigated before automatically submitting the same paid model request again. Show the output before asking for a purchase The homepage includes real input-photo and video examples. For a creative tool, those pairs explain the product better than a long feature list: people can judge whether the result is something they would want to share. Photo quality and subject identity still matter. A clear image with one visible subject is a better starting point than a crowded or heavily cropped photo. Two-pet replacement is a more demanding task than replacing a single pet, and AI results can vary. Try it You can see the examples and use the generator at catdance.app . I am the maker of the product; this is a launch note, not an independent review. I would be interested in feedback on the upload flow and whether the examples make the free/full choice clear.

  • DEV CommunityThe Giantsread at source

    How I Made PdfWord Work Fully Offline as a PWA

    Series: Building PdfWord — a free, no-backend PDF tools site (Part 10) Most "free PDF tools" die the moment your Wi-Fi does. That's weird when you think about it — the actual work (merging, compressing, converting) happens on your CPU, not on their server. So when I built PdfWord with zero backend — every tool is static HTML + JavaScript running entirely in your browser — making it work fully offline wasn't a feature request. It was the obvious consequence of the architecture. Here's how I did it, including the two mistakes that cost me the most time. Try it: PdfWord — install it, then turn on airplane mode. It still works. The architecture made it easy (the details made it hard) A PWA is really two things: a manifest.json (name, icons, colors, how it launches) and a service worker (a script that intercepts network requests and serves cached files). Because there's no server to reach, the service worker just needs to make the files available offline. The manifest was the fun part. Beyond the basics (name, 192/512 icons, display: standalone , theme color #4f46e5 ), I added two things users actually feel: App shortcuts — long-press the icon and jump straight to Merge PDF or Compress PDF. Skips the homepage entirely. Share target — share a PDF from WhatsApp, and PdfWord appears in the share sheet. The service worker catches the shared file via a POST to /share.html , stashes it in a cache, and opens the app with the file ready. This one felt like magic the first time it worked. The precache mistake My first service worker precached everything : pdf-lib, pdf.js, SheetJS, Tesseract — over 2MB of libraries on install. The installed app opened noticeably slowly, especially on low-end Android phones (which is most of my audience). The fix was a rule I now apply everywhere: precache only the true app shell (~120KB) — the homepage, the shared JS/CSS, the icons, the manifest. The heavy libraries cache on demand : the first time you open the PDF-to-Excel tool, its SheetJS library downloads and gets cached; after that it works offline too. Nobody should wait for libraries they haven't used yet. The caching strategy: two rules, no exceptions // HTML pages: network-first (always fresh), offline falls back to cache if ( isPage ) { e . respondWith ( fetch ( e . request ). then ( res => { // stash a fresh copy, then serve it const copy = res . clone (); caches . open ( CACHE ). then ( c => c . put ( e . request , copy )); return res ; }). catch (() => caches . match ( e . request ))); } // Static assets (JS/CSS): cache-first — they change rarely Pages are network-first because a stale tool page is worse than a slow one. Assets are cache-first because they're fingerprinted by the cache version anyway. Simple, predictable, debuggable. The version-bump discipline (learned the hard way) Here's the thing nobody tells you about service workers: the worker only updates when sw.js bytes change. I once shipped a deploy where I bumped the cache version ( pdfword-v7 → v9 ) only in the staging folder and forgot the source file. The source drifted, and installed apps kept serving stale files essentially forever — the update mechanism never triggered because the served sw.js was byte-identical. Now it's a ritual: bump the version in the source sw.js , copy every file to its exact staged path, grep-verify the staged copy, then deploy. And on the UX side, there's a one-tap "New version available!" banner — users click Refresh once instead of ever needing a hard reload. Related war story: Ctrl+Shift+R does NOT bypass the service worker. I once "verified" a bug fix for a full hour while unknowingly testing the old cached code. My QA rule now: if the banner appears, refresh until it's gone, then trust the test. The honest limitations The first visit needs internet (obviously — the files have to come from somewhere). A tool's heavy library downloads on first use, so "offline" for a tool you never opened means a one-time download first. On iOS it's "Add to Home Screen," not a store install — Apple being Apple. None of these are dealbreakers for a tools site. The win is real: open the app in airplane mode, merge two PDFs, get your file. No server was ever involved, so no server is missed. Try it: PdfWord — install it to your home screen, go offline, and merge a PDF. That's the whole demo. What's the smallest useful thing you've ever made work offline? I'm collecting ideas for what deserves the offline treatment next.

  • Hacker News Front PageThe Giantsread at source

    Lobbying Is Corruption

  • HTML All The ThingsPodcastsAudioListen

    Is the AI Bubble Starting to Pop?

    Is the AI bubble finally starting to pop? In this edition of the Web News, Matt and Mike discuss OpenAI reducing usage on its $200 Pro plan, the enormous cost of AI infrastructure, and growing questions around whether businesses are actually seeing enough financial return from…

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: OpenWants – A Simulated City Where AI Agents Handle Residents Needs

    Comments

  • Hacker News Front PageThe Giantsread at source

    LLMs Aren't Inevitable

  • Hacker News Front PageThe Giantsread at source

    Apple/macOS silently removed from official Unix registry

  • Hacker News Front PageThe Giantsread at source

    Talorys – A self-hosted personal AI agent on Cloudflare's free tier

  • AdactioTop Front-end Bloggersread at source

    Going to Florida. brb

  • Hacker News Front PageThe Giantsread at source

    `123456' password used in Danish CPR data breach

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: Open Components – UI Components standard for people, devs and AI agents

    Comments

  • Flavio CopesMore Front-end Bloggersread at source

    How to create an Apple TV app

    Build a tvOS app with SwiftUI, share code with your Mac app, design it for the Siri Remote, make its layered icon, and install it on your own Apple TV.

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: The safe-choice tax – what the vendor nobody gets fired for costs

    Comments

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: Rutter – shared decision memory across AI tools

    Comments

  • Hacker News: Show HNLibraries, Frameworks, etc.read at source

    Show HN: Iimos – an AI app that ships as one chat box and rewrites itself

    Comments

  • Zell LiewMore Front-end Bloggers2 min read

    Redefining My Relationship With You

    I no longer knew how to define my relationship with the people who read my work. Not teacher and student, not leads and customers. Here's where I eventually settled: fellow wayfarers.

  • Google for DevelopersYouTube ChannelsVideoWatch on YouTube

    Order in any language with Gemini 3.5 Live Translate

Friday, 9 October 2026

  • AbduzeedoMulti Author Blogsread at source

    Not Yoga: Brand Brothers Explores Visual Identity

    Brand Brothers designed a hypnotic visual identity for Paris studio Not Yoga, pairing a kinetic monogram with undulating graphic waves. Located at 13 rue des Tournelles in Paris, Not Yoga strips away ...

  • DigitalOcean BlogMulti Author Blogs5 min read

    DigitalOcean MicroVMs: Fast, isolated compute for your AI agent infrastructure

    Coding-agent platforms, sandbox products, and code-execution services all need the same thing: isolated machines that start up fast, retain their state between bursts of work, and don’t consume compute when idle. If you build it yourself, you’ll have to lease compute capacity…

  • AbduzeedoMulti Author Blogsread at source

    Masthead Zine Is a Masterclass in Typography by Duttweiler

    Masthead Zine reprints logos from 1960s and 70s Chicano newspapers as a red-ink zine by Alexandria Canchola and Joshua Duttweiler. The first thing you notice is restraint. One vermilion red on warm cr...

  • AbduzeedoMulti Author Blogsread at source

    Web Design: Atlas for Mac by Alexey Sekachov

    Alexey Sekachov designed the web design for Atlas for Mac, combining stark typographic hierarchy with minimal, native product storytelling. Digital software marketing often falls into the trap of visu...

  • SitePointThe Giantsread at source

    How to Improve Website Performance Without Rewriting Your Front End

    null Continue reading How to Improve Website Performance Without Rewriting Your Front End on SitePoint .

  • AbduzeedoMulti Author Blogsread at source

    tubik studio Unveils Crezco UI/UX Design

    tubik studio crafts an accessible ui/ux design system for Crezco, pairing Aeonik typography with clear API architecture and responsive grids. Design studio tubik first paired with Crezco in 2019 to sh...

  • Google for DevelopersYouTube ChannelsVideoWatch on YouTube

    🤖 Operating real hardware with Gemini AI

  • freeCodeCamp.orgYouTube ChannelsVideoWatch on YouTube

    n8n Full Course – Architect Scalable AI Automations from Scratch

  • AbduzeedoMulti Author Blogsread at source

    FAUVE: Palantis Crafts an Architectural Brand Identity in Paris

    Palantis designs a sharp, modular brand identity with earthy palette for FAUVE, a contemporary tea room and specialty coffee shop in Vincennes. If you have spent any time roaming third-wave cafes over...

  • Adrian RoselliMore Front-end Bloggers4 min read

    Decorative Images…

    …aren’t a thing. Three hand-drawn lines curling together like an S or three skinny snakes trying to spoon. At least not as far as people are concerned. Yes, this is an absolutist take, but sometimes it’s necessary to take the absolutist position to force someone to justify their own reasoning.…

  • Google for DevelopersYouTube ChannelsVideoWatch on YouTube

    Building low-latency remote robotics with Gemini

  • SitePointThe Giantsread at source

    Vue 3 Composition API: Stop Watcher Memory Leaks in Composables

    How to manage watcher lifecycles and cleanup in Vue 3 composables, preventing memory leaks when watchers are created outside synchronous setup. Continue reading Vue 3 Composition API: Stop Watcher Memory Leaks in Composables on SitePoint .

  • SitePointThe Giantsread at source

    JavaScript Event Loop Explained: How to Trace Queues and Debug Async Code

    Predict async execution order, identify microtask starvation, and compare browser and Node.js event loop behavior using step-by-step queue trace tables and annotated code snippets. Continue reading JavaScript Event Loop Explained: How to Trace Queues and Debug Async Code on SitePoint .

  • SitePointThe Giantsread at source

    Express React Refresh Token Setup: Diagnosing Missing Cookies and 401s

    Fix missing HTTP-only refresh cookies in Express 5 and React, configure CORS and cookie options, and implement silent token rotation with single-flight retry on 401s. Continue reading Express React Refresh Token Setup: Diagnosing Missing Cookies and 401s on SitePoint .

  • SitePointThe Giantsread at source

    How to Review AI-Generated Pull Requests and Catch Duplicate Types

    Catch duplicate types, reimplemented utilities, and weakened CI checks in agent-authored PRs using targeted review checklists, ESLint, and diff-based CI heuristics. Continue reading How to Review AI-Generated Pull Requests and Catch Duplicate Types on SitePoint .

  • Frontend Masters BlogMore Front-end Bloggers7 min read

    5 Good Choices for HTML Containers

    Divs and spans are fine, but purposefully meaningless. Often the meaning actually matters, so let's look at some of those situations.

  • AbduzeedoMulti Author Blogsread at source

    Intuit Rebrand: Inside JKR's New Identity System

    JKR built the Intuit rebrand around one idea: the letter i. A new lowercase wordmark detaches into an animated symbol for Intuit Intelligence. The whole system reads like it wants to start a conversat...

  • DequeMulti Author Blogs4 min read

    Deque named a Leader in the 2026 Gartner® Magic Quadrant™ for Digital Accessibility

    Deque has been recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Digital Accessibility! The post Deque named a Leader in the 2026 Gartner® Magic Quadrant™ for Digital Accessibility appeared first on Deque .

  • Level AccessCompany/Startup Blogs5 min read

    Accessibility Needs an Authority. Why Gartner Named Us a Leader

    Level Access has been named a Leader in the inaugural Gartner® Magic Quadrant™ for Digital Accessibility Platforms, published October 5, 2026. This is The post Accessibility Needs an Authority. Why Gartner Named Us a Leader appeared first on Level Access .

  • Christian HeilmannTop Front-end Bloggersread at source

    Returning to Bengaluru in November, see you there.

    After rocking San Jose with our World Congress, WeAreDevelopers’ next port of call is Bengaluru in India. See you there on the 25th of November for two days of excellent talks and workshops !

  • AbduzeedoMulti Author Blogsread at source

    Packaging Design: Iron Coin Whisky by Opera Prima

    Opera Prima crafted a tactile packaging design for Iron Coin Whisky, pairing heavy faceted flint glass with minted metallic coin talismans. Most luxury spirits rely on decorative filigree or loud neck...

  • HeyDesignerDeveloper/Designer Newsread at source

    Tesler’s Law: Complexity moved to a different part of the journey

    Designing Michelangelus, Critique in the AI era, The web needs interactive lists.

  • SitePointThe Giantsread at source

    How to Humanize AI-Written Technical Documentation

    null Continue reading How to Humanize AI-Written Technical Documentation on SitePoint .

  • SitePointThe Giantsread at source

    Designing Apps for AI Agent Phones: 6 Checks Developers Should Make Before Granting Access

    null Continue reading Designing Apps for AI Agent Phones: 6 Checks Developers Should Make Before Granting Access on SitePoint .

  • Flavio CopesMore Front-end Bloggersread at source

    How to install your own apps on your iPhone with Xcode

    Put the apps you build on your iPhone without the App Store: turn on Developer Mode, install from Xcode, update over Wi-Fi from the terminal, and renew them.

  • SitePointThe Giantsread at source

    What Is a Managed SOC Service and Who Needs It?

    null Continue reading What Is a Managed SOC Service and Who Needs It? on SitePoint .

  • PiccalilliMore Front-end Bloggersread at source

    The Index: Issue #201

    2027 web platform feature ranking This is the second year we're doing this, and last year's 1900+ rankings not only helped us push the right proposals in the Interop process, it was also used to prioritize web platform feature development in Firefox. Certainly beats thumbs up in GitHub issues! Make your voice heard. This hue shall pass A fabulous colour contrast tool from the great folks over at Clearleft. Dark forestry Not only an outstanding and important piece of writing, but the design and effects are lovely. Destroy any website This is very fun! Destroy your least favourite websites (like the pre-loaded example) for a vibe boost. css.earth Explore earth, other planets and even other galaxies, all rendered with HTML and CSS, via PolyCSS . The box model and box sizing Here's one from the Piccalilli archives that you might have missed to wrap up this issue. P.S. this is a good website from personalsit.es . Sponsor message Has your organisation gone too deep with frameworks or [gasp] LLMs and feel like you're stuck? We're helping clients get away from that noise and instead, focusing their efforts and budgets on actually doing stuff that will help them reach their goals. We do all of that while running this publisher, Piccalilli too! Our availability opens up again in late 2026 into 2027, so check out what we're about. Maybe we can be the key that unlocks your success in 2027 onwards. Check out our work

  • W3C BlogBrowsers, engines, etc.5 min read

    What’s new in the W3C Website Design System

    A significant update to the W3C Website Design System was published at the end of September 2026. Here’s what changed and why.

  • Robin WieruchMore Front-end Bloggersread at source

    Toward a Self-Improving Agentic Code Review Loop

    An agentic code review loop where each developer fires their own AI review skill at pull requests, the author's agent answers, and a scorecard rates each skill.

  • AbduzeedoMulti Author Blogsread at source

    Montreal Architecture Brand Identity by Mariane Farias

    Mariane Farias crafts a minimalist brand identity for Montreal Architecture, translating circular window facades into tactile yellow stationery. Montreal Arquitetura is an architecture studio based in...

  • Frontend Masters BlogMore Front-end Bloggersread at source

    How an accessibility designer adds keyboard shortcuts to a web app

    Eric Bailey explains the thinking and research that go into adding just a few custom keyboard shortcuts to a web app. There’s an absolute ton to consider and test, and plenty of challenges can come from your own team.

  • Auth0 BlogCompany/Startup Blogsread at source

    Multi-Tenant SaaS Apps with Auth0 Organizations — Part One

    If you are building a B2B SaaS product multi-tenancy is a foundational requirement. Your customers are companies, and each company expects its own isolated space. Getting this right early saves enormous pain later.

  • Google for DevelopersYouTube ChannelsVideoWatch on YouTube

    Building with Gemma 4

Thursday, 8 October 2026

  • Bram.usMore Front-end Bloggers4 min read

    <​calc-input>, a custom input element that accepts mathematical formulas

    Continuing my streak of small form-related Custom Elements (like ) , I built . It’s a custom input element that accepts mathematical formulas — such as 2 + 3 or (2 + 3) * 4 — and automatically toggles between showing the formula on focus and the calculated result on blur.

  • Bram.usMore Front-end Bloggers2 min read

    caniname: CLI tool to check project name availability across Netlify and NPM (and other sources)

    Whenever I build a new tool or custom element (like or ), I always end up doing the same manual dance: checking if the package name is still free on NPM and if the matching .netlify.app subdomain is still unclaimed on Netlify. To automate that check, I built caniname .

  • Jim Nielsen’s BlogMore Front-end Bloggersread at source

    “Getting off the Modernization Treadmill”

    My notes from this talk by Alexander Petros at Big Sky DevCon 2026 . Alex starts by noting how “modernize” used to mean something along the lines of “update this thing that was made before I was born”. But now “modernize” means something more like “update this thing from 5-10 years ago” (hence the framing of the talk, the “modernization treadmill”). Using a real-world example of an incredibly slow website that was required to access state-sponsored programs for welfare, Alex points out the disparity in conditions between those of us who make software and those who have to use them: The people who develop these websites are usually doing so on high-powered internet connections and high-powered devices, but they're not using them in the conditions that the people who most need those benefits are going to be. Then he shows a Reddit thread where somebody essentially posted, “I’m having problems with this website. I’ve been waiting for months for my application to go through. Any suggestions?” And one Reddit user responded, “The best thing you can do is go into the physical office, get a case worker, and your problems will be solved within the hour.” The irony. I guess we've come full circle now. It used to be: “Don’t talk to anybody. It’s faster and more convenient to use the website!” But now it’s: “Don’t use the website. It’s faster and more convenient to talk to somebody!” Have we failed at making websites? And is our failure, at least in part, rooted in the fact that we don’t leverage the basic tools for making websites: HTML, CSS, and (in a distant third) JavaScript? Alex goes on to argue that the technologies of the web have an ideological bent and, if used as designed, can solve so many of the performance, accessibility, and usability issues that plague so many websites. The grain of the web’s technologies are rooted in these values: User-friendly Backwards- and forwards-compatibility Long-term viability Universal accessibility Which means if you use them as intended, they are optimized to deliver outcomes rooted in those same values. So if you like those values and you want those outcomes, use the platform. Take HTML, for example. Here’s Alex: HTML does [performance improvements] for you for free. If you've coded your website in a proper, semantical, structure HTML style, it will just get better over time at zero cost to the people who built that website HTML is your friend. HTML won’t give you up or let you down . HTML will make it difficult for you to make a bad website. Write it in to the requirements of the project you’re doing that it work without JavaScript. Not necessarily that it doesn’t have any JavaScript, but just that the core functionality of the website can happen without JavaScript. If you do this […] you will find that it’s very hard to deliver a bad web page because the structure that HTML requires is one that fundamentally is good for the user, performant, and cost effective. Technologies are imbued with culture, which influences what you do and how you do it. If you can align your ideological beliefs with your technological choices, you might end up with an outcome that aligns with your values — who would’ve thought, eh? A lot of modern software developers come from websites like Facebook, they come from big tech companies [who] fundamentally have a different set of priorities. Their job is to keep you on the website as long as possible so that you consume more ads. But that’s the opposite set of requirements and priorities that the government needs to be doing, which is to build something that is clean, quick, efficient, and gets you in and out as fast as possible. So [I tell people] that the technology they use comes from [an] ideological place. But there are different ideological places that produce different technological results and if we start from those through lines then we can produce services that help people who need them. The ideological principles of the web are well established : users over everything else. If you use HTML as much as possible, you’ll make something that’s as user-friendly as possible on the web. Reply via: Email · Mastodon · Bluesky

  • Next.js BlogLibraries, Frameworks, etc.read at source

    Upcoming Next.js Security Update for Upstream Vulnerabilities

    Next.js plans to publish an out-of-band security update next Wednesday, October 14, 2026, addressing two Critical and one High severity vulnerabilities in upstream dependencies.

  • Google for DevelopersYouTube ChannelsVideoWatch on YouTube

    📷 Searching for images from text with EmbeddingGemma 2

  • Web Tools WeeklyMulti Author Blogsread at source

    Web Tools Weekly Issue #690

    Media Tools, JS Plugins, Git/CLI Tools

  • AdactioTop Front-end Bloggersread at source

    The people holding up the internet | Data Drop

    Bringing receipts for xkcd.com/2347 . adactio.com/links/22794

See everything from the last 30 days →

Articles belong to their publishers. This site only collects what their feeds provide.

Updated 10 October 2026 at 14:29