Your Dependencies Are Someone Else's Keys to Your Serversecurity dependencies consulting javascript The Axios supply chain attack reminded me of a dependency audit I ran at a client last year. What I found was worse than any vulnerability scanner could flag.Published OnApril 6, 2026Read more →
The Canary That Didn't Sing — What Our Deployment Strategy Misseddevops deployment observability consulting We built a canary deployment pipeline with automated rollbacks. It still let a bad release through to 100% of users. Here's what went wrong.Published OnApril 5, 2026Read more →
We Let AI Review Every Pull Request for Three Months. Here's What It Actually Caught.ai code-review developer-experience consulting code-quality AI code review tools are everywhere now. After rolling one out on a real project, I learned more about our team than about the tool itself.Published OnApril 4, 2026Read more →
The E2E Test Suite That Cried Wolftesting developer-experience consulting ci-cd How a 45-minute end-to-end test suite trained an entire team to ignore test failures — and what we did about it.Published OnApril 3, 2026Read more →
The Feature Flag Graveyard We Built Over Two Yearstechnical-debt feature-flags code-quality consulting How 340 feature flags turned a codebase into a minefield — and the boring process that dug us out.Published OnApril 2, 2026Read more →