
1,342 articles published in 2023.


Find out what PostgreSQL v16 has to offer, what the top new features will be and why the new postgres is so cool and useful.

After two months of open beta, we’ve shipped more than 200 of the most-wanted updates to our Dev Mode workspace.

Summary In recent years, cellular architectures have become increasingly popular for large online services as a way to increase redundancy and limit the blast radius of site failures. In pursuit of these goals, we have migrated the most critical user-facing services at Slack from a monolithic to a cell-based architecture over the last 1.5 years.…

Here is a reading list with 2023 trends, what you need to know about attacks, and a guide on how to stay protected using Cloudflare

We are back with a quarterly update of our Application Security report. Read on to learn about new attack trends and insights visible from Cloudflare’s global network

Another new release of Git is here! Take a look at some of our highlights on what’s new in Git 2.42.

Discover how to improve the user experience of nested menus and tackle a minor yet common issue with them when the user’s pointer leaves the menu item for a moment, and the nested menu goes away, requiring the user to re-hover and try again. A well-known concept called the “safe triangle” solves this problem.

Brian Chesky saved Airbnb by leading through design, and he thinks this is just the beginning of the revolution. Five industry experts weigh in.

In this post, we’ll deep dive into some interesting attacks on mTLS authentication. We’ll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information leakages.

You can now configure payment method settings from the Dashboard—no code required. We call this integration path dynamic payment methods.


The 2023 Phishing Threats Report analyzes millions of malicious emails, brand impersonation examples, identity deception and other key attack trends based on email security data from a 12-month period

How to index LIKE conditions in PostgreSQL and Oracle. Answers the question: Why is LIKE indexing simpler in Oracle? Is it better?

This week I’ve been reading through the recent judgment from the Swedish FSA on the Swedbank outage. If you’re unfamiliar with this story, Swedbank had a major outage in April 2022 that was caused by an unapproved change to their IT systems. It temporarily left nearly a million customers with incorrect balances, many of whom were unable to meet payments. After investigation, the regulator found th

When Zuul was designed and developed, there was an inherent assumption that connections were effectively free, given we weren’t using mutual TLS (mTLS). It’s built on top of Netty, using event loops…

Get tickets to our global developer and customer event for 30% off during our Super-Early Bird special, only for a limited time.

After the last Release Radar, I promised the next one wouldn’t be far away, so here it is. This is the low down on some of the best open source…

Some best practices and important defenses to prevent common attacks against GitHub Actions that are enabled by stolen personal access tokens, compromised accounts, or compromised GitHub sessions.

Instagram has introduced Immortal Objects – PEP-683 – to Python. Now, objects can bypass reference count checks and live throughout the entire execution of the runtime, unlocking exciting avenues for true parallelism. At Meta, we use Python (Django) for our frontend server within Instagram. To handle parallelism, we rely on a multi-process architecture along with […]

The background image used in the hero component, which is slow to load, is a very common problem with any component that uses a large image file as a background image. In this article, Mike Herchel walks you through how to tackle this common performance issue using modern techniques.


Debugging Rust and Wasm with Cloudflare Workers involves a lot of the good old time-consuming and nerve-wracking printf'ing strategy. What if there’s a better way? This blog is about enabling and using Wasm core dumps and how you can easily debug Rust in Cloudflare Workers

It was another record year for our Security Bug Bounty program! We’re excited to highlight some achievements we’ve made together with the bounty community in 2022!

[…]

Most of the projects have at least a few unused files, exports, and dependencies lying around, often because it’s difficult knowing when one thing relies on another and scary removing something you’re not sure is in use. Lars Kappert shares a tool he’s been working on that offers a solution.

Easily manage storage with scheduled deletion for Cloudflare Stream, available for live recordings and on-demand video

Today, we are thrilled to share that customers can now debug their Queues directly from the Cloudflare dashboard. This new feature allows customers to send, list, and acknowledge messages in their Queues from the Cloudflare dashboard, enabling a more user-friendly way to interact with their Queues

Notes on using a single-person Mastodon server

In part 2 of the series, Hannah Milan reviews various accessible text over images techniques for designing your content, including framing the image, soft-colored gradients technique, text styles and text position, solid color shapes, and use of colored backgrounds.

Airbnb’s Brian Chesky talks about design’s catalytic potential for business and the central role it played in Airbnb’s post-IPO growth story.

What does your performance “stack” look like? There are all kinds of tools available for measuring page speed, but what data and assumptions do they use to measure performance? And speaking of *measuring* performance, there’s quite a difference between that and *monitoring* performance. Let’s dig in!

Starting today, customers that use Cloudflare’s Advanced Certificate Manager can configure TLS settings on individual hostnames within a domain

Introducing two new secret scanning push protection features that will enable individual developers to protect all their pushes and organizations to gain insights and trends across their repositories.

In July, we experienced one incident that resulted in degraded performance across GitHub services.

Researchers from Purdue and NCSU have found a large number of command injection vulnerabilities in the workflows of projects on GitHub. Follow these four tips to keep your GitHub Actions workflows secure.

Explore is one of the largest recommendation systems on Instagram. We leverage machine learning to make sure people are always seeing content that is the most interesting and relevant to them. Using more advanced machine learning models, like Two Towers neural networks, we’ve been able to make the Explore recommendation system even more scalable and […]

Announced as part of the Back to School Safely: K-12 Cybersecurity Summit at the White House on Aug 7, Proj Cybersafe Schools will support eligible K-12 public school districts with Zero Trust

GitHub’s design experts share 10 tips and lessons for designing magical user experiences for AI applications and AI coding tools.

What helps people get comfortable on the command line?

Meta is developing new privacy-enhancing technologies (PETs) to innovate and solve problems with less data. These technologies enable teams to build and launch privacy-enhanced products in a way that’s verifiable and safeguards user data. Using state-of-the-art cryptographic techniques, we have developed Private Data Lookup (PDL) that allows users to privately query a server-side data set. […] Rea

Some tactics for writing in public

Fixit is dead! Long live Fixit 2 – the latest version of our open-source auto-fixing linter. Fixit 2 allows developers to efficiently build custom lint rules and perform auto-fixes for their codebases. Fixit 2 is available today on PyPI. Python is one of the most popular languages in use at Meta. Meta’s production engineers (PEs) […]

Short-lived certificates (SLCs) are part of our latest efforts to further secure our Transport Layer Security (TLS) private keys on our edge networks. SLCs have a very short exposure compared to traditional certificates and lower the chances of a compromised private key being abused. Implementing SLCs has required us to address tradeoffs between operability and […]

Friction often has a negative connotation in user experience design, but it actually has many benefits. Its best-known use case is mitigating unintended consequences in high-risk scenarios, yet it has a new place in the age of artificial intelligence. Adding strategic friction to interfaces can lead to profound efficiency gains in machine learning algorithms.

A high-performance ecommerce template, including support for BigCommerce, Medusa, Saleor, Shopify, and Swell.

The Cybersecurity and Infrastructure Security Agency (CISA) just released a report highlighting the most commonly exploited vulnerabilities of 2022.

Product Research Intern Jacky Huang and Software Engineer Willy Wu discuss their FigJam widget that matches up your work style with the stars, and how fun is the future of collaborative work.

In the world of software development, collaboration can make the difference between a brittle last-minute release and a reliable, maintainable, pain-free project. Whether you’ve been coding for a day or a decade, your colleagues are there to help strengthen your work. But they can only help if you’ve given them the tools to do so.

In this two-part series of articles, Hannah Milan covers the best practices when using various accessible text over images techniques for designing your web and mobile app content.

Today, we are very excited to announce the general availability of Cloudflare Zero Trust Integration with Datadog

Today, we’re announcing a private beta of GitHub Copilot with code referencing that includes a filter to detect code suggestions matching public code on GitHub.

Behind "Hello World" on Linux

Liran Cohen and the team at Bookaway, a travel booking service, dramatically improved their site’s performance by auditing Core Web Vitals. In this article, Liran shares his team’s process for auditing and monitoring Web Vitals and the effort it took to dramatically improve Bookaway’s performance — and the benefits that came with it.

A deep dive into the recent incidents relating to Workers KV, and how we’re going to fix them

Announcing the new Upstash database integrations for Workers. Now it is easier to use Upstash Redis, Kafka and QStash inside your Worker

Learn how you can structure your enterprise to get the most value out of GitHub and provide the best experience for your developers!

Learn about how we build containerized services that power microservices on the GitHub.com platform and many internal tools.

Compare the performance of bulk load methods in PostgreSQL. Get recommendations for parameter settings to improve performance even more.

John Maeda shares takeaways from this year’s Design In Tech Report, and why we should embrace uphill thinking in a world optimized for shortcuts.