TLDR Dev 2026-10-01
Gemini 4 Argon 🚀, gRPC vs REST 🤔, how Instinct was built 💬
Make all your data an AI advantage (Sponsor)
AI is only as good as the context you give it. At
Elastic{ON}, Elastic engineers show you how to build AI agents with real-time context. Detect and respond to threats faster. And get more from your enterprise data — wherever it lives.
Come for:
- Actionable blueprints:Bring your biggest data challenges and leave with a clear plan and architectural blueprint you can deploy immediately.
- Real-world case studies: Hear how top global organizations are leveraging Elastic to run proactive anomaly detection and eliminate operational downtime.
- Hands-on guidance and networking: Collaborate with peers, swap battle-tested strategies, and get 1:1 guidance from Elastic product experts.
Elastic{ON} is visiting major cities worldwide. Save your spot at a session near you
gRPC vs REST Is the Wrong Question (7 minute read)
Connect lets browsers and gRPC clients call the same service without a separate gateway, using HTTP and JSON or binary Protobuf on one port. It preserves schema-driven clients, streaming, ordinary HTTP status codes, and curl-friendly requests while keeping gRPC compatibility.
How We Rebuilt Our Design Language in Three Days with AI (13 minute read)
A small team used tightly specified briefs and coding agents to rebuild a 67-page site across 22 visual directions, then turned the strongest ideas into one design system. The process worked because content stayed fixed, rules were numerical, real pages were reviewed, automated checks were themselves verified, and losing experiments were deleted.
Why Instinct Feels Magical (9 minute read)
A reverse engineering tour attributes Instinct's appeal to a single conversational thread, delegated task agents, file-based memory, computer use, and quiet background automation. iMessage/WhatsApp distribution, Instinct's easy-to-understand personality, and proactive execution make the underlying agent harness feel accessible to nontechnical users.
Convention-Based Design for Docs (8 minute read)
A shared folder path and GitHub topic can turn repository-local Markdown into a searchable documentation site without maintaining a central registry. Keeping docs beside code lets pull requests update both together, gives ownership to the responsible team, and provides engineers and agents with a predictable place to find current information.
A Design System Is What It Does (6 minute read)
Design system defaults shape which products get built and which users those products serve. Comparing USWDS with shadcn's typography shows why readable defaults, accessible line lengths, and explanatory documentation matter, especially for government sites built by teams without dedicated design resources.
Dear Software Makers (3 minute read)
YouTube's proposed video variant testing prompts a broader warning about optimizing creative work around measurable performance. One should make finished things repeatedly, stand behind creative choices, and learn from each result instead of sanding away originality through endless tests.
Intent 0.5: Skills You Can Maintain (5 minute read)
Intent 0.5 brings agent skill authoring, validation, and source review into a library's repository so guidance can evolve with the code it documents. It type-checks JavaScript and TypeScript examples, tracks source changes against mapped guidance, adds CI checks, and offers repair workflows for routine metadata fixes.
OpenAI MCP Extensions (GitHub Repo)
OpenAI MCP Extensions adds ChatGPT-specific capabilities for plugins, including sidebar entry points, file handlers, composer mentions, and richer forms. The repository provides TypeScript and Python SDKs, a specification, documentation, and a Bits & Bolts example under the Apache 2.0 license.
Gemini 4 Argon: Our Next Era of Frontier Intelligence (8 minute read)
Google introduced Gemini 4 Argon for long-horizon coding, enterprise knowledge work, and defensive cybersecurity, with a 1 million token output limit and phased access through trusted testers. Google reports leading benchmark results and internal engineering gains, while emphasizing prompt injection defenses, misuse safeguards, monitoring, and hardened evaluation environments before broad release.
How I Could've Accessed 17 Trillion Microsoft Records (9 minute read)
An internal Microsoft analytics service accepted unsigned JWTs, allowing a forged admin identity to run SQL across an environment estimated at 17.3 trillion stored rows. The bounded investigation exposed the consequences of skipping signature verification and showed how persistent agent exploration combined with a human insight to uncover the flaw.
Is Sandboxing Sufficient to Contain Rogue Agents? (14 minute read)
Recent incidents involving agents probing network boundaries motivate a closer look at whether conventional sandboxes can contain increasingly capable systems. The analysis weighs better operational security against the harder possibility that containment alone is insufficient when agents can discover vulnerabilities, coordinate, and exploit overlooked paths.
The most important software engineering news in one daily email
Join 470,000 readers for
one daily email