
Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails
Across 409,000 approve-or-deny decisions, human reviewers missed a third of malicious AI agent commands — and the credential-stealing ones slipped through three times as often as the obviously destructive ones. The numbers argue for sandboxes, scoped credentials, and policy engines ahead of the approve button.

Lint the Dockerfile Before You Build It: What hadolint, dockle, and Docker Scout Catch That a Green Build Never Will
A green docker build waves through unpinned base tags, root users, baked-in secrets, and known CVEs. How hadolint at PR time, dockle at build time, and Docker Scout at deploy time each catch a failure class the others cannot see — with gate configs you can copy.

The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted
Between March and June 2026, Axios, node-ipc, Red Hat's npm namespace, and the Mastra framework were all compromised — each defeating a different defense. A concrete accounting of all four attacks and the five build-layer controls that survive them: frozen lockfiles, disabled install scripts, DNS-aware egress sandboxing, honest provenance, and per-build SBOMs.

Preview Databases Are the Part of Preview Environments Nobody Demos
Northflank's Railway-alternatives matrix concedes the awkward half of preview environments: Coolify and Fly.io need custom configuration for per-PR databases, and only teardown automation keeps forgotten previews from compounding. How seed time, snapshot restore, and per-PR isolation decide whether previews are shippable — and the self-hosted recipe that closes the gap.

When Railpack Detects Wrong: What an Angular SSR App Served as a Static Caddy Site Teaches About Builder Autodetect
Railway's Railpack builder classified an Angular SSR app as a static site and served it through Caddy — a green deploy of the wrong architecture. The before-and-after Dockerfile fix, why fail-open autodetect keeps causing outages, and the five detect-time log lines a self-hosted PaaS should emit.

Render Shipped Official Python and TypeScript SDKs: SDK Parity Is Now the Render-Compatibility Bar
Render's September 10 release of official Python and TypeScript SDKs moves the Render-compatibility bar from matching REST endpoints to matching the full client surface: typed methods, per-item cursor pagination, and machine-readable error codes.

Spotify Portal for Backstage Is GA: The Build-vs-Buy Math for Your Golden Path Just Changed
Spotify Portal for Backstage is GA: onboarding wizards, bundled premium plugins, and an AI assistant in one box. What the DIY cost numbers say, who already switched, and a build-buy-skip verdict for self-hosted platform teams.

A2A Hit 150 Organizations in a Year: The Agent-to-Agent Protocol MCP Was Never Meant to Be
A2A grew from a Google proposal to 150+ organizations and a stable v1.0 in twelve months. What the agent-to-agent protocol covers that MCP deliberately doesn't — plus the precise triggers for when a deploy-from-chat roadmap needs both.

Argo CD 3.3 PreDelete Hooks: Stop Tenant Teardowns From Leaving Orphaned Wrecks
Deleting an app-of-apps tree can orphan PVCs, DNS records, and whole namespaces — or deadlock for 45 minutes. Argo CD 3.3's PreDelete hooks gate teardown on a Job that must succeed first. Tabled here: the three failure modes, a working hook, four gotchas, and a Flux fit check.