From Mexico: Anthropic’s models found 29,000+ possible bugs in open source, but people could only review about 6,000. Its new OSS Scanner lets maintainers skip that line and get raw AI reports fast. Here’s what that trade really means.
From Mexico: GitHub’s new data says leaked secrets aren’t rising per push. There’s just way more pushing, a lot of it by agents. Here’s what that means for my repos, and the tiny model GitHub put right at the push to catch passwords.
From Mexico: JetBrains Research and Lund University say reviewing what a coding agent wrote isn’t about seeing what changed. It’s about knowing where to look hard. Here’s their three-level review idea and what I’d steal from it today.
From Mexico: GitHub’s Oct 6 engineering post says agent fleets are breaking the old trade-off in its Git storage, so it’s splitting durable storage from compute and coordinating only the ref update. Here’s what the numbers mean for small teams.
From Mexico: GitLab published its Security Standard v1.0 on Oct 6, a five-stage ladder that coding agents climb before they can merge on their own, on the same day Transcend pushed /goal flows that stop waiting for a human.
From Mexico: Obelisk 0.42 (Oct 4) stores coding-agent workflow progress in a database, wraps generated code in nested server/app/deployment grants, and ships a workflow-agent prototype that can deploy and inspect apps after the process dies.
From Mexico: Cloudflare’s Oct 2 post puts web search on AI Gateway, so an agent can ask Ceramic, Exa, or Linkup instead of guessing a URL and curling a 404. Native server tools are still coming soon. The docs call it an open beta.
From Mexico: Supabase’s Oct 2 post moves schema and project config into the repo, runs a local stack without Docker, and lets an app ship its own MCP server. Compute, for long jobs, is still a private alpha.
From Mexico: Earendil shipped Pi 1.0 on Oct 1, a minimal coding-agent harness that adds MCP through Codemode, deferred tool loading, and virtual models. They kept the terminal agent small and put long runs in a separate experiment.
On September 29, Sentry’s Seer Agent can create dashboards, alerts, and triage inside a project, and it can read Datadog or Google Cloud while it diagnoses. The write permission does not outlive the chat.