Peter Kellner

10.6K posts

Peter Kellner banner
Peter Kellner

Peter Kellner

@pkellner

Software Developer, Architect, Pluralsight Author, React, .net and forever Learner. https://t.co/nQkNf5PUdz

Pre: 37.3034548,-121.95834 Katılım Eylül 2007
1.2K Takip Edilen2.1K Takipçiler
Peter Kellner
Peter Kellner@pkellner·
@jeffwhelpley My worst enemy is feeling like I want it to finish some feature. Slow and steady wins. Really slow, lots of tests including end to end. For an iOS app I have hundreds os test that literally run the sim. I launch it before bed every day
English
0
0
1
24
Jeff Whelpley
Jeff Whelpley@jeffwhelpley·
The more I get Claude Code to walk me through nearly every planned change, the more I am annoyed at myself that I ever allowed CC to just do a bunch of changes without careful review. The issue isn't necessarily that coding agents get things wrong per se (but the obviously do sometimes). The bigger issue is that we almost never give coding agents enough context up front no matter how hard we try. And...I would argue that it's a fool's errand trying to do everything up front anyways because you don't know up front how much the underlying model will actually be able to figure out on their own. So, IMO the winning approach is to do a decent job of up front context and direction before you ask the agent to come up with an implementation plan. Then have the agent walk you through the plan in detail one thing at a time. If you use agentic code reviewers have them at the plan and again have your main agent walk you through each suggested change one by one in detail. This approach does take longer than accept all YOLO, but this is the way to get the best end result. Otherwise, the actual implementation will not be exactly what you really want and will be rife with bugs/issues that are hard to fix and get worse over time.
English
2
0
1
111
Chris Tate
Chris Tate@ctatedev·
As a follow-up to this I'm considering disabling PR creation from outside contributors on repos I maintain until we have better answers for the constant stream of supply chain and security incidents hitting the ecosystem Instead, I want to invest in automation that properly credits issue authors whose work leads to merged changes Keeping the people and companies who depend on these projects safe is my P0
Chris Tate@ctatedev

Dear GitHub, AI is changing the contribution graph. Issues are often the real contribution now. They define the problem, shape the solution and guide the PR. If a GitHub Issue leads to a merged PR, the issue author should get contributor credit. Signed, ctate

English
24
8
284
31.7K
Peter Kellner
Peter Kellner@pkellner·
@tan_stack @rickyfm If @tan_stack with all that engineering talent was vulnerable, how many other sites are exposed to the same attack? And could AI help an unsophisticated attacker build it? The postmortem almost reads like a blueprint. I support transparency, but this one gives me pause.
English
1
0
0
322
TANSTACK
TANSTACK@tan_stack·
Our official post mortem on the security issue earlier today: tanstack.com/blog/npm-suppl…
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
27
104
498
94.9K
Peter Pistorius
Peter Pistorius@appfactory·
one expensive agent for thinking, another cheap agent for doing.
English
6
0
6
696
Peter Kellner
Peter Kellner@pkellner·
@appfactory Will there be a video of your presentation? Love to see you presenting your stuff
English
1
0
0
29
Peter Pistorius
Peter Pistorius@appfactory·
Made it to SF, jetlagged af.
English
5
0
12
679
Peter Kellner
Peter Kellner@pkellner·
@JoeMayo I’ve found that if I just say build, the ui is ok and great. If I say use your design skills it’s a little better but also not great. I need to be better at promps for great ui
English
0
0
1
60
Joe Mayo
Joe Mayo@JoeMayo·
Still wondering if it's possible or delusional to generate a great UI with AI...if I just write better prompts.
English
1
0
2
336
David K 🎹
David K 🎹@DavidKPiano·
@thekitze Fun fact: this is either $300,000 in some city you don't want to live in or $2 million in some city that you do
English
6
0
48
3.2K
kitze
kitze@thekitze·
american households be like
kitze tweet media
English
48
1
152
21.7K
Peter Kellner
Peter Kellner@pkellner·
I need 12 android testers to get my photo sharing app through the google playstore. Do I have friends that would help? connectionroad.com shares photos from dropbox and onedrive. HELP please!
English
3
0
1
61
Tanner Linsley
Tanner Linsley@tannerlinsley·
Pretty sure @X quietly nerfed the max length of search queries. 3 of my @Pro columns died a few days ago and can only be fixed by cutting them down to half of the tokens. Not cool.
English
8
0
78
13.2K
Peter Kellner
Peter Kellner@pkellner·
@jherr Depends who you want as your audience. It’s not personal. Old like me likes your style, much younger likes compressed, choppy, flashy. Not good or bad.
English
0
0
0
31
Jack Herrington
Jack Herrington@jherr·
I get a lot of negative feedback on my video editing by potential editors. I understand that it's a negotiating thing, but it's annoying none the less. But I do want to say that my minimalist editing style is an intentional choice. In every video I'm trying to present new information and new ideas. And after being presented with new information most people brains (myself included) need a beat to properly process that. That's why I'm not doing pop zooms or chopping the hell out of stuff. That would distract your mind from trying to understand what it just saw. And that's why I occasionally leave in a beat where nothing or not much happens. My vibe is more nature documentary and less "24". And you know what? That's ok. lt's ok that my videos are paced differently than others on YouTube.
English
20
0
137
10K
Peter Kellner
Peter Kellner@pkellner·
@kskrygan Would it scale with processing power? Faster and/or smarter?
English
0
0
0
26
Kirill Skrygan
Kirill Skrygan@kskrygan·
Would you be interested if JetBrains releases a totally local AI agent, working 100% on your laptop, using our code insight engine and deeply integrated into the IDE? Yes, it will be probably 1 month behind the very recent frontier models, but no token blood bath anymore WDYT?
English
805
234
7.1K
489.2K
Peter Kellner
Peter Kellner@pkellner·
@toddanglin IMHO, it’s inevitable that the hybrid approach will be best. I’m sure there is a ton of “easy” stuff the big models can delegate and QA.
English
1
0
1
17
Peter Kellner
Peter Kellner@pkellner·
@appfactory @_maxscn I’m not giving any of these agents access to anything like email. I don’t care how convenient it will make things.
English
1
0
1
28
Peter Pistorius
Peter Pistorius@appfactory·
@_maxscn it's gotta take some courage to give a service access to your email!
English
2
0
0
44
Peter Pistorius
Peter Pistorius@appfactory·
blows my mind that a single oauth token can comprise an entire company, this isn't blame/ I'm sure it can happen to any of us, but something is wrong with how our industry is doing things
English
5
4
27
2.5K
Peter Kellner
Peter Kellner@pkellner·
@theo Are unhappy with opus? Anthropic, or the Claude code agents?
English
0
0
0
36
Theo - t3.gg
Theo - t3.gg@theo·
"Clearly Claude Code isn't that bad, millions of people use it!" This mindset is how we got stuck with Internet Explorer. I'm gonna keep pushing for us to do better as an industry.
English
154
72
2.5K
139.3K
Joe Mayo
Joe Mayo@JoeMayo·
Creating a PDF or converting any document format into a PDF is easy - the other way around - not so.
English
2
0
4
535
Peter Kellner
Peter Kellner@pkellner·
@tannerlinsley @tan_stack One big benefit of a PWA with React Server Components is that I can push browser concerns like caching, background sync, retries, and offline behavior into the service worker thread, which keeps my RSC layer much simpler and focused on rendering and composing server data.
English
0
0
1
37
Peter Pistorius
Peter Pistorius@appfactory·
seems claude is down... which isn't a problem since I have local AI inference
English
3
0
4
1.2K