Thursday, October 8, 2026ArchiveSearchAsk the paper

The Computomatix Times

All the posts fit to save — curated from @computomatix's bookmarks & likes on X

Search

Latest stories — use the filters to narrow by keyword, section or date.

Vercel Releases Deepsec, an Agent-Based Full-Repository Security Scanner

deepsec: Full-Repository Security Review - Vercel

Malte Ubl of Vercel announces deepsec, an open-source tool that uses coding agents to scan an entire repository for vulnerabilities and revalidate each finding before reporting it. The linked page describes the tool.

Original post · 1 min read
New vercel.com/oss/deepsec – the only must-run software
vercel.comdeepsec: Full-Repository Security Review - Verceldeepsec uses coding agents to find vulnerabilities across your entire repository, then revalidates every finding before it reaches your team.
♥ 190 · ⟲ 5 · 👁 34.5KView on X ↗
AI7/10

Google Unveils Gemini 3.5 Transcribe Speech-to-Text Model

Google Unveils Gemini 3.5 Transcribe Speech-to-Text Model▶

Ammaar Reshi announces Gemini 3.5 Transcribe, a speech-to-text model supporting over 85 languages with smart correction and custom vocabulary. He says he built a Wispr Flow-style app on the model and is open-sourcing it, with a demo in the attached video.

Original post · 1 min read
Introducing Gemini 3.5 Transcribe 🚀

Our most precise speech to text model, that can handle over 85+ languages, has smart correction, and custom vocabulary.

I vibe coded a Wispr Flow like app powered by the model.

Demo + open sourcing below!
♥ 1.0K · ⟲ 72 · 👁 220.1KView on X ↗

Grok Bot Vault Keeps Agent Credentials Away From the Model

Grok Bot Vault Keeps Agent Credentials Away From the Model

Eric Zakariasson describes a Grok Bot feature that stores credentials in a vault and injects them at the host when a tool call is executed, so the model never sees the plain-text key. He gives a Linear bug-filing example and shares a diagram of the flow.

Original post · 1 min read
this card allows grok bot to store credentials securely in a vault! when the credential is needed, it goes through a special access path where its never exposed to the model in plain text

later when you say "file a bug that login is broken", the bot turns that into a linear call with just the title (no token). the host knows that tool call is linear's, looks up this agent's linear api key, and builds the real http request. linear creates it, and the bot gets back "sent it, we're good". the host where the final tool call is constructed is also the only place the credential shows up

here's roughly how it works
Chris Maconi @chrismaconi
I don't see anyone pointing out this Grok Bot innovation, but I think it is actually a big deal for mass adoption.

How much time have you spent trying to figure out how to securely give your keys to your agent?

Most people give up before they figure out how to build and store an .env file for their agent to access and use.

Grok Bot's solution is simple, and most important of all, easy!
♥ 239 · ⟲ 13 · 👁 38.6KView on X ↗
AI8/10

Patrick O'Shaughnessy Interviews Neil Movva of Sail Research on Inference

Patrick O'Shaughnessy Interviews Neil Movva of Sail Research on Inference▶

Patrick O'Shaughnessy promotes a long podcast with Neil Movva, founder of Sail Research and former Nvidia GPU and kernel engineer. Topics include latency versus throughput, Nvidia's GPU stack, chip scarcity, data centers, power, and open versus closed AI.

Original post · 1 min read
Neil Movva (@neilmovva) started his career at Nvidia, working on GPUs and kernels, and has an unusually deep understanding of inference, from software to chips to power.

We spend a lot of time on each of those layers, how they connect, and where the important tradeoffs are.

What makes this conversation special is how detailed it is (like a 401-level class), yet Neil makes it remarkably clear and easy to follow.

Today he runs Sail Research, a company building infrastructure for agents to make tokens as cheap as possible.

We discuss:
- Latency versus throughput
- Why there are no bad chips, only bad pricing
- The end of kernel engineering
- Buying chips and power no one else wants
- New chip architectures
- Nvidia lore + his contrarian view of the company
- Open source and the frontier labs

I learned a ton. Enjoy!

TIMESTAMPS
0:00 Intro
0:38 Building a “Token Factory”
4:21 The Future of Background Agents
13:09 Nvidia and the GPU Stack
23:27 Chips, Memory, and Transformers
36:14 The Future of AI Training Data
44:32 Chip Scarcity and Compute Arbitrage
52:44 Reinventing the AI Data Center
59:01 Power and the “Scavenger Strategy”
1:10:10 Open vs. Closed AI
♥ 10.4K · ⟲ 1.2K · 👁 4.6MView on X ↗

Paul Solt Shares Skills He Uses for Building iOS Apps With Agents

Paul Solt recommends a set of skills that help coding agents build iOS apps and says he uses the last one daily. He links to a post on installing these skills before Codex works on an Xcode project.

Original post · 1 min read
These SKILLS help me build iOS Apps.

I use the last one daily.
Paul Solt @PaulSolt
Install These Skills Before Codex Touches Your Xcode Project — I've been building iOS and macOS apps with Codex and Claude Code since last year. One thing I've learned: agents need simple systems that produce reliable results.
Without the right skills, agents
♥ 521 · ⟲ 37 · 👁 109.7KView on X ↗

Ex-Cursor SpaceXAI Engineer Runs 10-20 Grok Bot Agents Daily

Ex-Cursor SpaceXAI Engineer Runs 10-20 Grok Bot Agents Daily▶

Codez relays that a SpaceXAI engineer, formerly at Cursor, runs 10-20 Grok Bot agents to automate routine work, including a Chief of Staff agent that manages the others. Codez promotes a podcast and a Substack tutorial on building a Grok agent team.

Original post · 1 min read
SpaceXAI engineer (ex-Cursor):

"right now I'm running 10-20 GrokBot agents that automate 90% of my routine

i have a Chief of Staff agent. He knows about all my other bots and manages everything"

in a 50-minutes podcast, a SpaceXAI engineer showed how to build a team of agents that will work for you 24/7

worth more than a $500 course on agentic engineering

watch today, then read how to build a Grok agents team from scratch in the article below
Codez @0xCodez
Grok Bot Agents: how to automate your life in 10 Steps (Full-tutorial) — Every AI tool you have used so far waits for you. You open it, you ask, it answers, you close it. The work still happens in your hands - the model just talks you through it.
Follow my Substack to get
♥ 16.6K · ⟲ 1.4K · 👁 5.2MView on X ↗

Ethan Evans Explains Barriers Highly Skilled Immigrants Face in US Leadership

Ethan Evans writes that highly skilled immigrants often struggle to be promoted into US leadership, as traits respected abroad can backfire domestically. He says he has helped many immigrant leaders become SVPs or higher.

Original post · 1 min read
Highly skilled immigrants often struggle to get promoted into leadership in the US despite their talents. Traits that earn respect in other countries sometimes backfire here. I've helped many immigrant leaders overcome this and become SVPs or higher.
♥ 478 · ⟲ 24 · 👁 92.9KView on X ↗

Sophia Dominguez Warns Against Following AI Advice on Apple Developer Account Switch

Sophia Dominguez advises against following Codex, ChatGPT, or Claude when moving an Apple personal developer account to a company account, saying those tools gave wrong guidance in her experience. She promises alternative steps, which the post does not include.

Original post · 1 min read
if you’re planning to switch your apple personal developer account -> company developer account

DO NOT listen to codex. chatgpt, or claude - in my personal (and humbling experience), they’re wrong! follow these steps instead:
♥ 335 · ⟲ 13 · 👁 49.6KView on X ↗

Software Mansion Releases Argent Agentic Toolkit for iOS and Android

GitHub - software-mansion/argent: An agentic toolkit to control, debug, and profile iOS and Android apps. Made by Software Mansion.

Kacper Kapuściak recommends Argent, an agentic toolkit from Software Mansion for controlling, debugging, and profiling iOS and Android apps, and says he will open-source his own related project later. The linked GitHub repository describes the toolkit.

Original post · 1 min read
I need a little more time to open-source it but in the meantime you should def check out Argent 👇

github.com/software-mansion/argent
github.comGitHub - software-mansion/argent: An agentic toolkit to control, debug, and profile iOS and Android apps. Made by Software Mansion.An agentic toolkit to control, debug, and profile iOS and Android apps. Made by Software Mansion. - software-mansion/argent
♥ 43 · ⟲ 2 · 👁 4.1KView on X ↗

Fayaz Ahmed Launches Headless Tools for AI Agents on Cloudflare

Fayaz Ahmed Launches Headless Tools for AI Agents on Cloudflare▶

Fayaz Ahmed presents hdls.tools, open-source headless SaaS utilities for agents including a URL shortener, pastebin, email client, self-reminder, and file sharing, built on Cloudflare. He says a related MCP v2 project launches the next day.

Original post · 1 min read
I made some headless tools for your agents

hdls.tools are little saas apps with no UI

1. URL Shortener
2. Pastebin
3. An email client (grab your handle now)
4. Self reminder (email yourself)
5. File sharing - upload and get a URL

Sign up or host it yourself - its open source and runs on @CloudflareDev
Fayaz Ahmed @fayazara
Read this article by @mattzcarey

blog.cloudflare.com/mcp-v2/

Experimented something with MCP v2

I am so excited to launch it tomorrow (when everyones back at their desks) because its all on Cloudflare

Scheduled it with a social media scheduler tool I've made for myself - built on top of Durable Objects Alarms
hdls.toolsheadlesstoolsMCP-first SaaS tools for AI agents. URL shortener, pastebin, and a real send/receive mailbox.
♥ 359 · ⟲ 9 · 👁 33.5KView on X ↗

How the Confidential NASA Aviation Safety Reporting System Began After Fatal 1974 Crash

Aakash Gupta recounts how a 1974 near miss at United went unshared before the TWA 727 crash on Mount Weather killed 92 people, and how NASA's confidential reporting system, launched in 1976, was created to share such incidents. He says the system has taken over 2 million reports without leaking an identity.

Original post · 2 min read
Six weeks before a TWA 727 flew into a Virginia mountain and killed all 92 people on board, a United crew made the exact same mistake on the exact same approach and missed the ridge by a few hundred feet. United wrote it up internally. Nobody outside United ever saw the memo.

The crash was December 1, 1974. The controller said "cleared for the approach." The TWA crew took that as permission to descend to 1,800 feet. The controller assumed they knew to stay high until the published approach began. Pilots and controllers across the country were using the same words to mean different things, and the plane hit Mount Weather at 1,670 feet.

When the NTSB found the United near miss sitting in a company file, the question wrote itself. Why did the second crew have to die to learn what the first crew already knew?

Incentives. A pilot who admitted a mistake to the FAA was handing the regulator evidence against his own license. So nobody admitted anything. Every airline kept its own quiet incident folder, and none of them talked to each other.

The fix, launched in April 1976, is the strangest institution in American transportation. The FAA handed the confession box to NASA, a completely different agency, because pilots would never trust the cop. File a report within 10 days of screwing up and the FAA cannot use it against you. No fine, no suspension. NASA strips your name before anyone at the FAA reads a word.

Fifty years in, the system has taken more than 2 million reports and never leaked a single identity. Close to 100,000 arrive every year. Wrong altitudes, missed clearances, two planes nearly sharing a runway, fatigue nobody wants on their record. NASA reads all of it, spots the patterns, and pushes alerts back out to every carrier before the pattern kills anyone.

That is the machine behind the chart. 6,581 deaths per billion passengers in 1970. 42 in 2023. At the 1970 rate, 2023's passengers would have produced around 29,000 funerals. The actual number was under 200.

Every industry says it wants people to report their mistakes. Aviation is the one that made confessing cheaper than hiding.
Colin McCarthy @US_Stormwatch
Perhaps one of the greatest modern miracles of society is how safe flying has become.
♥ 2.8K · ⟲ 389 · 👁 346.2KView on X ↗

Developer Publishes Reconstructed Source of Grok Bot 0.18.0

GitHub - b-nnett/grok-bot-0.18-reconstructed: Unofficial source-oriented reconstruction and extension of Grok Bot 0.18.0 for macOS

Bennett reports that Cursor's Grok bot 0.18.0 shipped with runtime source maps enabled, and links to an unofficial reconstruction and extension of the macOS app's source code.

Original post · 1 min read
The Cursor team shipped Grok bot (0.18.0) with runtime source maps enabled. Surprised nobody noticed until now.

Source code reconstructed (and downloads) here: github.com/b-nnett/grok-bot-0.18-reconstructed
github.comGitHub - b-nnett/grok-bot-0.18-reconstructed: Unofficial source-oriented reconstruction and extension of Grok Bot 0.18.0 for macOSUnofficial source-oriented reconstruction and extension of Grok Bot 0.18.0 for macOS - b-nnett/grok-bot-0.18-reconstructed
♥ 2.0K · ⟲ 129 · 👁 1.1MView on X ↗

Kevin Xu Argues Compounding Makes Wealth Targets Grow Fast

Kevin Xu makes a short argument that a $1 million nest egg from 1990 would be worth about $4 million now and could reach $16 million by retirement, framing it as a lesson about compounding.

Original post · 1 min read
$1M was rich in 1990

now it’s $4M

by the time you retire, it’ll be $16M

this is incredibly important to understand
♥ 4.5K · ⟲ 369 · 👁 719.9KView on X ↗

Developer Open-Sources iMessage Shopping Agent Built on Shopify

Developer Open-Sources iMessage Shopping Agent Built on Shopify▶

Gil describes an open-source shopping agent that works inside iMessage, searching Shopify's catalog, building per-merchant carts and checking out with budget controls via Shopify's Universal Commerce Protocol, without exposing card details.

Original post · 1 min read
I built a shopping agent inside iMessage. Open sourcing the code: github.com/gil--/ucp-agent-imessage

1. Send a msg or photo.
2. It searches Shopify’s global catalog.
3. Builds one cart per merchant.
4. Connects Shop identity w/ budget.
5. No cc details exposed.

Why Shopify? Shop identity already covers hundreds of millions of buyers.
One protocol (UCP), every merchant. Millions of products. No scraping or “computer use”is necessary. 💚
Gil @gilgNYC
Instinct shows how far LLM computer use has come but it’s still awfully slow 😴 and no one wants to share payment (or address) credentials with a 3p. 😱

Here’s a short demo of my agent, Concierge using Shopify’s UCP tools and our Shop identity tokens to directly checkout with spend controls.

👋 If you’re building in this space, let’s work together to enable seamless agentic commerce.
github.comGitHub - gil--/ucp-agent-imessage: Agentic commerce chat built on Shopify UCP + iMessageAgentic commerce chat built on Shopify UCP + iMessage - gil--/ucp-agent-imessage
♥ 30 · ⟲ 4 · 👁 6.5KView on X ↗

App Store Connect CLI Releases Version 4.9.0

GitHub - rorkai/App-Store-Connect-CLI: Fast, scriptable CLI for the App Store Connect API. Automate TestFlight, builds, submissions, signing, analytics, screenshots, subscriptions, and more

Rudrank Riyam announces version 4.9.0 of the App Store Connect command-line tool and promises a detailed breakdown of its changes, linking to the project's GitHub repository.

Original post · 1 min read
App Store Connect CLI 4.9.0 is out!! 🤩

There are many great changes in this release, so I am listing them all one by one in detail 👇🏽

github.com/rorkai/App-Store-Connect-CLI
github.comGitHub - rorkai/App-Store-Connect-CLI: Fast, scriptable CLI for the App Store Connect API. Automate TestFlight, builds, submissions, signing, analytics, screenshots, subscriptions, and moreFast, scriptable CLI for the App Store Connect API. Automate TestFlight, builds, submissions, signing, analytics, screenshots, subscriptions, and more - rorkai/
♥ 651 · ⟲ 48 · 👁 70.7KView on X ↗

Trump Disclosure Shows 1,051 Trades; Critics Allege Insider Timing

Jim Stewartson criticizes Donald Trump's June financial disclosure, which reports 1,051 trades, and alleges organized insider trading, citing a MeidasTouch post highlighting Boeing and SpaceX purchases made near contract awards.

Original post · 1 min read
Holy shit. A THOUSAND TRADES A MONTH.
50 trades per day. This is a TEAM.

He hired professional traders to use inside information to make money for him on the stock market while he uses every lever in the federal toolkit to pump up equity prices.

Staggering organized crime.
MeidasTouch @MeidasTouch
Trump reported a staggering 1,051 trades in his June financial disclosure. Here are two of the more curious ones:

— June 18: Bought $250K–$500K in Boeing, the same day the Navy awarded Boeing an $880 million contract for P-8A training systems.

— June 23: Bought $15K–$50K in SpaceX, the same day NASA recorded a $425.6 million award to SpaceX.
♥ 23.5K · ⟲ 7.9K · 👁 729.1KView on X ↗

Gil Demos Concierge Agent Using Shopify Checkout With Spend Controls

Gil Demos Concierge Agent Using Shopify Checkout With Spend Controls▶

Gil promotes a demo of his agent Concierge, which uses Shopify's UCP tools and Shop identity tokens to check out directly with spend controls, and comments on the slowness of LLM computer use. A quoted post surveys personal agent products including Instinct, Grok Bots and ChatGPT Work.

Original post · 1 min read
Instinct shows how far LLM computer use has come but it’s still awfully slow 😴 and no one wants to share payment (or address) credentials with a 3p. 😱

Here’s a short demo of my agent, Concierge using Shopify’s UCP tools and our Shop identity tokens to directly checkout with spend controls.

👋 If you’re building in this space, let’s work together to enable seamless agentic commerce.
Anish Acharya @illscience
Personal Agents Notes (Instinct / Grok Bots / ChatGPT Work):
- The three products to look at are Instinct, Grok Bots and ChatGPT Work. All three feel like the distillation of patterns established by OpenClaw earlier this year: persistent agents with cloud(ish) computers, browser access, cached credentials and recurring loops—plus a top-level orchestration agent with visibility into every other agent/thread that can report across them and dispatch work on the user’s behalf.
- Browser use is now good enough to do most web-based work, modulo CAPTCHAs / 2FA / occasional brittle flows. The interest…
♥ 38 · ⟲ 0 · 👁 23.5KView on X ↗

Wayne Sutton Argues Critical Thinking Matters Most With Bots

Just call me BOO. Bot Orchestration Officer.

Wayne Sutton describes a Grok Bot founder event with SpaceXAI and Harper Insure and argues that the valuable skill is orchestrating bots while keeping human judgment. The article also promotes Convex as a backend for agents.

Original post · 3 min read
X ArticleJust call me BOO. Bot Orchestration Officer.
Earlier this week, I was at @SpaceXAI for a Grok @Bot Founder Build Night featuring Harper Insure. The SpaceXAI and Harper team
demoed Grok Bot and various workflows of how Harper uses Cursor agents
This is the core idea.
Bots running operations. Not a bot thinking for you.
The skills that matter today are critical thinking, problem-solving, and orchestration. Not just using a tool, but becoming someone who thrives while tools evolve.
You will hear a different story. About learning how to use Grok Bot and trusting the bot to think for you.
That’s how the idea dies.
The bot gives you an answer. You take it without questioning or adding your own original thought.
AI is not here to think for you. It’s here to brainstorm with you so you, the human, land on better options.
We’ve seen this wave before
San Francisco rewired daily life with new products that changed entire industries.
Twitter made news and media real-time
Instagram changed photography, venues, and tourism
Lyft and Uber disrupted ride-sharing and taxis
Airbnb transformed hospitality
Each one looked like just a product, but changed the way people move, share, and connect. All while creating new categories and opportunities for people to build on and launch businesses.
Bots are the next wave
Bots and agents are next.
They’ll run small business ops, internal processes in big companies, software dev, coaching, media, and automation everywhere. Agents today need a modern backend and infrastructure to run at scale. (hint convex.ai)
Grok Bot is not a pile of scripts. It’s a desk you talk to. Focused on human-led work.
Orchestration is the big-picture skill
You see an organization and spot what bots can automate. Then you have bots run and manage operations alongside you.
Harper’s CRM plus Grok Bot shows this in a GTM shop. It’s not trivia from prompts.
Critical thinking happens next to the bot. You don’t just accept answers. You question, add your own view, and improve. Or you build the app to enhance your workflow and day-to-day tasks, with convex.dev as your backend, of course.
The better option remains yours.
The bigger loop
This isn’t a skill frozen in time.
It’s about continuous learning tied to who you are becoming.
The skill is critical thinking and problem-solving, orchestrated by human identity. Bots and agents guide but do not replace.
This is how you thrive as agents change software and AI impacts every business on earth.
In other words, just call me BOO (Bot Orchestration Officer).

This article was originally sent by me (human) using Grok Bot, with the AgentMail plugin, and published through APIs on waynesutton.ai a @Convex-hosted app.
♥ 111 · ⟲ 4 · 👁 7.9KView on X ↗

Thread Lists Ten Free Open-Source GitHub Tools for Creators

Thread Lists Ten Free Open-Source GitHub Tools for Creators

A thread lists ten free open-source GitHub projects, including Recordly, Stirling PDF, PhotoGIMP, Open Notebook, Odysseus, FreeDomain, HyperFrames and Web-to-App, with brief descriptions and licenses.

Original post · 2 min read
10 GITHUB REPOS THAT SHOULD BE ILLEGAL TO HAVE.

all free. all open-source. bookmark this for later.

1. Recordly — the free screen studio.
Open-source screen recorder with auto-zoom, smooth cursor, webcam overlay, styled backgrounds, and polished demos without a video editor. (AGPL-3.0)
github.com/webadderallorg/Recordly

2. Stirling PDF — your entire PDF toolkit.
Self-hosted. Merge, split, sign, redact, OCR, convert, compress, 50+ tools. Runs locally, so nothing leaves your machine. (MIT)
github.com/Stirling-Tools/Stirling-PDF

3. PhotoGIMP — turns GIMP into Photoshop.
Photoshop shortcuts, layout, and splash screen patched on top of GIMP 3+.
github.com/Diolinux/PhotoGIMP

4. Open Notebook — self-hosted NotebookLM.
Drop in PDFs, URLs, and YouTube links. Chat with them, summarize them, and even generate podcasts. Supports 18+ AI providers. (MIT)
github.com/lfnovo/open-notebook

5. Odysseus — PewDiePie's self-hosted AI workspace.
Chat, agents, deep research, docs, email, memory, and more. Local-first, your hardware, your data. (MIT)
github.com/odysseus-dev/odysseus

6. FreeDomain — free domain names for everyone.
Register a domain, point it to Cloudflare or any DNS provider, and launch your site without paying for the domain. (AGPL-3.0)
github.com/DigitalPlatDev/FreeDomain

7. HyperFrames — write HTML, render videos.
HeyGen's open-source engine that converts HTML/CSS animations into deterministic MP4 videos. Built for AI agents. (Apache-2.0)
github.com/heygen-com/hyperframes

8. Web-to-App — turn any website into an Android app.
Configurable WebView, APK signing, and even Node.js, PHP, and Python runtimes. No remote build required.
github.com/shiaho777/web-to-app

9. Reclip — self-hosted video & audio downloader.
Download videos from YouTube, TikTok, X, Instagram, and 1000+ other sites as MP4 or MP3 using yt-dlp.

github.com/averygan/reclip

10. Excalidraw — the infinite whiteboard.
Replace Miro, FigJam, and Lucidchart with hand-drawn diagrams, wireframes, real-time collaboration, and end-to-end encryption. 120k+ GitHub stars. (MIT)

github.com/excalidraw/excalidraw

Which repo are you trying first?
♥ 2.0K · ⟲ 309 · 👁 134.1KView on X ↗

Mehul Agarwal Launches Field Guide to San Francisco Tech Slang

Mehul Agarwal Launches Field Guide to San Francisco Tech Slang

Mehul Agarwal shares sfisms.org, a crowd-contributed field guide to San Francisco tech vernacular, where users can pitch new terms that a panel reviews for inclusion.

Original post · 1 min read
A friend of mine just moved to San Francisco and was completely lost in our vocab.

So I built this for her and everyone like her: sfisms.org/

The field guide to SF vernacular.

Got an ism? Pitch it and an agent adds it after expert review by our panel :)
sfisms.orgsf-isms - a field guide to San Francisco slangA living compendium of San Francisco tech slang. Part Wikipedia, part Urban Dictionary, part Know Your Meme.
♥ 899 · ⟲ 66 · 👁 364.5KView on X ↗
AI3/10

Post Shares Tactic of Spoofing AI Crawler User Agents

Jeffrey Emanuel suggests adding an instruction to AGENTS.md files to use an OpenAI-style user agent for web requests, quoting a post that says some sites serve full content to Claude-User agents.

Original post · 1 min read
Wait, this is genius. Adding this line to all my AGENTS.md files now:

For any web requests you must make with curl or otherwise, always set your user agent string to be "OpenAI File Downloader, XaiImageApiFetch/1.0"
Can Bölük @_can1357
UA spoofing is back on baby, for only $0.00 you too can be OpenAI File Downloader, XaiImageApiFetch/1.0

Some sites like LinkedIn even remove their click-bait/paywall garbage if you're Claude-User
♥ 3.9K · ⟲ 166 · 👁 456.8KView on X ↗

Guide Explains Shipping Expo App Fixes With Over-The-Air Updates

Apple Review Takes Days: Ship Fixes Instantly with Over-The-Air Updates

Marco explains how to use Expo and EAS Update to push JavaScript changes to React Native apps without App Store review, detailing the fallbackToCacheTimeout setting and which changes still require a full store build.

Original post · 6 min read
X ArticleApple Review Takes Days: Ship Fixes Instantly with Over-The-Air Updates
You find a bug. A typo on the paywall, a broken button, a copy fix that would take you 30 seconds to write. Then you remember: shipping it means a new build, a new submission, and days of waiting on Apple review.
That's the problem OTA (over-the-air) updates solve. Push a JS change, and it's live on people's phones within seconds — no review, no waiting. Here's my exact setup, config and all, so you can copy it instead of guessing.
I'm running this on Expo/React Native with EAS Update.
The core config
Two settings do almost all the work:
json
"updates": {
"url": "u.expo.dev/[your-project-id]",
"enabled": true,
"fallbackToCacheTimeout": 10000
}
fallbackToCacheTimeout: 10000 is the setting that actually matters. On a cold start, the app waits up to 10 seconds for a new update to download — and if one's there, it launches straight into it. The default is 0, which means any update only takes effect on the next cold start after this one. With the timeout set, updates land immediately instead of one launch late.
The trade-off is honest: on a slow connection, app start can take up to those 10 seconds longer. I've decided that's worth it — instant fixes over a slightly slower worst-case launch.
Remind the 10 seconds is a ceiling, not the norm. That's just the timeout if the download stalls. On a normal connection the update usually finishes in 1–3 seconds, so in practice you rarely feel any delay at all.
One thing to know: this only fires on a genuine cold start. Reopening the app from the background doesn't trigger a new check. Realistically though, barely anyone goes weeks or months without ever fully closing the app at least once — so in practice this basically never becomes a problem.
What actually goes over OTA — and what doesn't
OTA-able: anything in JS/TS. Screens, business logic, copy, navigation, images and other assets. If you can write it in your app code, it can ship instantly.
Needs a full store build: new native modules, version upgrades of native dependencies that touch native code, any app.json field that compiles into the native project (permissions, icons, splash screen — even the fallbackToCacheTimeout setting itself), and SDK upgrades.
One nuance worth knowing: sometimes a feature looks JS-only but only works because the native side already shipped support for it in an earlier build. A config or variable change can go out via OTA — but only because the native plumbing for it was already sitting in a build people already have installed.
The actual workflow
bash
npx eas-cli@latest update --branch production --message "description" --non-interactive
Then commit and push. One easy-to-miss detail: EAS Update publishes whatever's in your working directory right now — not your last commit. Uncommitted changes go out with the update whether you meant them to or not. So commit immediately after publishing, to keep git and what's actually live in sync.
Three more levers worth knowing about
Rollback. eas update:rollback reverts to a previous update, or all the way back to the bundle embedded in the original build. Your emergency lever if an OTA update breaks something in production.
Staged rollout. Updates can ship to a percentage of users first (--rollout-percentage) instead of going straight to 100%. I currently push straight to everyone — a staged rollout is the safer move for anything you're not fully sure about.
Code signing. Updates can be cryptographically signed so only bundles you authorized can install. Not essential for most solo setups, but worth knowing it exists.
Is this actually allowed by Apple?
Yes — with real limits, not a loophole.
Apple's guidelines technically say apps shouldn't download code that changes their features or functionality. But there's an explicit carve-out: code interpreted by JavaScriptCore or Hermes is fine, as long as it doesn't add native capabilities that bypass review. That's exactly what a React Native JS bundle is. The native layer never changes — your JS only calls into native functions that were already reviewed and approved when you submitted the build. This isn't a gray area workaround; it's the sanctioned case, and it's been standard practice since 2017.
What's inside the lines: bug fixes, copy changes, layout tweaks, feature flags toggling things that were already part of what Apple reviewed. What's not: hiding a genuinely new feature behind a remote flag and quietly switching it on later. That's the same interpreted-code mechanism, but it's used to ship something Apple never saw — and apps have been flagged for exactly that.
One honest caveat: review is policy plus judgment, not just the text of the guideline. No tool — not Expo, not any other OTA provider — can promise "Apple-approved" updates, because that certification doesn't exist. What does exist is a clear, long-standing precedent for this exact use case. Stay inside it (fixes and tweaks, not disguised new features) and you're on solid ground.
The short version
Set fallbackToCacheTimeo… continue on X ↗
♥ 204 · ⟲ 14 · 👁 154.6KView on X ↗

Engineer Says Subtle Vulnerability Was Patched in an Hour

Engineer Says Subtle Vulnerability Was Patched in an Hour

Oren Yomtov reports that a critical, subtle vulnerability was found by AI-augmented researchers and patched within an hour, with no known attack. He argues well-designed software can still hide such issues that demand deep security experience.

Original post · 1 min read
i just won $200k using this one prompt
Anicet @AniC_dev
a new critical vuln was found by AI augmented researchers, patched by us 1hr later

this time it was quite twisted, took me a good amount of time to grasp

it was never used to attack us, as far as we can dig

I'm now convinced that even well designed/written software can have so many such small, twisted issues

it takes good experience with vulnerabilities and long chains of actions to suspect, find and exploit them

10yoe+ and solid CS knowledge is not enough

beyond the classic security footguns, that we, software engineers, know about and try hard to prevent

some class of issues, often mo…
♥ 2.3K · ⟲ 121 · 👁 330.3KView on X ↗

Skydive Launches Omnichannel, Cloud-Native AI Teammates

Skydive Launches Omnichannel, Cloud-Native AI Teammates▶

Dhruv introduces Skydive by Anything, a platform for always-on AI teammates reachable via Slack, email, iMessage and CLI. It is model-agnostic, supporting models such as Fable, GPT and Deepseek, with full access granted from day one.

Original post · 1 min read
what if AI teammates (Grok Bot, Hermes, etc.) lived everywhere?

Introducing Skydive by Anything.

- omnichannel (Slack, email, iMessage, CLI)
- cloud native (always on, works while you sleep)
- model agnostic (Fable, GPT, Deepseek, more)

everyone gets full access from day one

let's fly. 🪂
♥ 773 · ⟲ 126 · 👁 1.2MView on X ↗

Salesforce Launches Slack Code for Humans and Agents

Salesforce Launches Slack Code for Humans and Agents▶

Marc Benioff announces Slack Code, a coding environment where humans and agents collaborate in the same channel. It launches with agents from Anthropic, GitHub, Cognition and Vercel, and was unveiled at Dreamforce.

Original post · 1 min read
Don’t code alone. Slack Code is live.
Humans and agents. Same channel. Same work.
Launching today with agents from @AnthropicAI, @github, @Cognition, and @vercel. This is real multiplayer coding. See it at @Dreamforce #DF26
♥ 4.3K · ⟲ 402 · 👁 2.3MView on X ↗

Fortell Builds AI Hearing Aid With Custom Chip, Raises $740M

Patrick OShaughnessy praises a documentary on Fortell, a startup valued at $740M whose custom chip helps users hear where they look. The company is expanding across America and is backed by notable investors.

Original post · 1 min read
Sachin and Adam are making my favorite short documentaries about technology companies.

This one, about Fortell (I’m an investor), is especially interesting.

This is the sort of company that I hope AI enables in as many industries as possible.

Fortell has combined AI technology (a custom chip and software) with good old-fashioned extraordinary customer service to make living with hearing loss much easier. Many people I’ve seen try the demo have cried at the impact and quality. So cool.

Check out Sachin and Adam’s other videos too. All excellent.
Sachin and Adam @Sachin_and_Adam
Exclusive: Inside Fortell (@fortellresearch)

The $740M startup that had to waitlist billionaires and celebrities for its AI hearing aid.

Their custom chip helps you "hear where you look", distinguishing voices in noisy environments - which solved a problem no hearing aid had cracked in 70 years. Now they're expanding across America to start reaching the 1.5 billion people globally who need it.

Founded by four wildly impressive co-founders. Plus, backed from top VC's led by @JoshuaKushner @AntonioGracias @traestephens @wolfejosh @GavinSBaker @patrick_oshag @RobertIger @jaltma @aplusk @hbarr…
♥ 411 · ⟲ 27 · 👁 143.0KView on X ↗

Vox Examines Grok Bot's Design and Trust Tradeoffs

Vox reviews Grok Bot after several days of heavy use, praising its chat-first interface, thin client and persistent always-on computers. The post questions whether users should trust a fully managed provider with their files and accounts.

Original post · 1 min read
After using Grok Bot heavily for a few days, I think I understand why it feels so smooth. The product is built around a few simple decisions.

→ Chat is almost the entire UI. You don't need to understand sessions, VMs, skills, or context windows before getting started. Just send a message.

→ The client stays thin. The desktop and mobile apps mostly pass messages back and forth, while the coding agent, tools, and task execution stay on the server. Even the beta feels quick.

→ Each Bot has an always-on computer. A new conversation doesn't give it a fresh, empty VM. Its files and workspace stay on its own filesystem.

→ Code and the browser share the same computer. It can write a script, open a logged-in website, and click through the UI. You can also have it record you doing a task and turn that into a repeatable workflow.

Using it also made the basic unit of an AI employee feel pretty clear to me: one identity, one computer, a set of accounts and permissions, and persistent memory.

The next question is who controls all of it. Grok Bot is fully managed, which removes a lot of setup. That also puts the machine, files, and access to connected accounts in the provider's cloud.

As model capabilities converge, which one I stick with may come down to who I'm willing to trust with those four things.
Vox @Voxyz_ai
I can’t quite explain how Grok Bot makes me feel.

It’s pretty bare-bones, and may not match Codex or Claude Code on complex tasks. The Linux computer, memory, skills, plugins, and automations are all familiar from Hermes, OpenClaw, ChatGPT, and Claude.

Taken apart, a Bot also looks a lot like a renamed session: a name, a job description, and a few scheduled tasks.

Codex and Claude Code can keep files and use a built-in browser too. When a login, verification code, or payment requires me, I can take over the computer and hand it back to the agent afterward.

What feels different is how the p…
♥ 238 · ⟲ 15 · 👁 60.3KView on X ↗

Patrick OShaughnessy Praises Investors Who Explain Markets Deeply

Patrick OShaughnessy thanks Ben Thompson, Gavin Baker and other analysts for detailed explanations of market developments. He argues such analysis is a strong positive force in financial markets.

Original post · 1 min read
We are all lucky that people like @benthompson, @GavinSBaker, @altcap, @dsundheim and others so often take the time to explain what’s happening in a detailed and deep way.

I think it’s a huge force for good in markets.
Patrick OShaughnessy @patrick_oshag
My conversation with @benthompson. Ben has been writing Stratechery for over a decade and remains one of my favorite business thinkers.

We covered a lot. Every important company in the industry and the forces acting on all of them.

- Why he thinks it would be problematic for the US to win the AI race
- Will we run out of money to fund AI
- Google becoming Berkshire Hathaway
- Why ads are amazing
- TSMC, Intel, and Samsung
- Nvidia's invisible price cuts + biggest competitors
- Microsoft, Amazon, Apple, and Meta

I love talking to Ben about everything happening in markets and technology. Enjo…
♥ 501 · ⟲ 24 · 👁 66.6KView on X ↗