4. 利用隐形代码的供应链攻击波及 GitHub 及其他代码仓库 Supply-chain attack using invisible code hits GitHub and other repositories (arstechnica.com)
5. 要想成为更好的程序员,不妨在脑海中进行一些小规模的证明(2025) To be a better programmer, write little proofs in your head (2025) (blog.get-nerve.com)
7. Arthur Whitney Style Code 支持哪些编程语言? What Languages is Arthur Whitney Style Code Possible in? (lobste.rs)
8. 错误报告:macOS 26 导致 /etc/resolver/ 中的自定义顶级域名(TLD)辅助 DNS 功能失效 Bug Report: macOS 26 breaks /etc/resolver/ supplemental DNS for custom TLDs (gist.github.com)
13. 二进制熔丝滤波器:比异或滤波器更快、更小巧(2022) Binary Fuse Filters: Fast and Smaller Than Xor Filters (2022) (dl.acm.org)
17. Android 开发者认证:在开放性、选择权与安全性之间寻求平衡 Android developer verification: Balancing openness and choice with safety (android-developers.googleblog.com)
18. Visitran:基于Agentic的Python数据转换平台(AGPL) Visitran: Agentic Pythonic data transformation platform(AGPL) (github.com)
21. snap-confine systemd-tmpfiles root (CVE-2026-3888) snap-confine systemd-tmpfiles root (CVE-2026-3888) (cdn2.qualys.com)
22. 从停车场获取root权限:通过SSID扫描利用OpenWRT的XSS漏洞(CVE-2026-32721) Root from the parking lot: OpenWRT XSS through SSID scanning (CVE-2026-32721) (mxsasha.eu)
23. 人工智能对数学的影响,就像汽车对城市的影响一样 AI''s impact on mathematics is analogous to the car''s impact on cities (mathstodon.xyz)
26. 使用 Rust 构建 LSP 服务器竟然如此简单又有趣 Building an LSP Server with Rust is surprisingly easy and fun (codeinput.com)
27. 模块化单体:模块间的依赖关系与通信 Modular Monolith: dependencies and communication between Modules (binaryigor.com)
28. leviathan-crypto - 基于 Serpent-256 的 TypeScript WebAssembly 加密库 leviathan-crypto - WebAssembly cryptography library for TypeScript with Serpent-256 (github.com)
37. CVE-2026-3888:Snap 漏洞,本地权限提升至 root CVE-2026-3888: Snap Flaw, Local Privilege Escalation to Root (blog.qualys.com)
38. 非常轻量级的 NixOS 路由器/服务器流量数据采集器 Very lightweight NixOS router/server flow data collector (discourse.nixos.org)
39. Nvidia GreenBoost:利用系统内存/NVMe透明扩展 GPU 显存 Nvidia greenboost: transparently extend GPU VRAM using system RAM/NVMe (gitlab.com)
40. Java 26 正式发布,为未来奠定了坚实基础 Java 26 Is Here, And With It a Solid Foundation for the Future (hanno.codes)
42. 内核反作弊机制如何运作:深入解析现代游戏防护技术 How Kernel Anti-Cheats Work: A Deep Dive into Modern Game Protection (s4dbrd.github.io)
43. 开源给予了我一切,直到我已无力回馈 Open Source Gave Me Everything Until I Had Nothing Left to Give (kennethreitz.org)
51. 利用 Chrome 的“网络”标签页调试 Electron 应用 hijacking chrome''s network tab to debug an electron app (seg6.space)
57. Wander:借助去中心化的推荐网络,探索“小网” Wander: Explore the small web with a decentralised network of recommendations (susam.net)
65. 关于修复 Linux 内核中 eBPF 自旋锁问题的故事 A tale about fixing eBPF spinlock issues in the Linux kernel (www.rovarma.com)
68. 用通俗易懂的语言来解释,Paxos算法其实非常简单(2021) The Paxos algorithm, when presented in plain English, is very simple (2021) (www.mydistributed.systems)
70. 隆重推出 postmarketOS Duranium:更可靠的 postmarketOS Introducing postmarketOS Duranium: a more reliable postmarketOS (postmarketos.org)
76. syntaqlite:SQLite 值得拥有的高保真开发工具 syntaqlite: high-fidelity devtools that SQLite deserves (lalitm.com)
79. Leanstral:值得信赖的氛围编码开源基金会 Mistral AI Leanstral: Open-Source foundation for trustworthy vibe-coding Mistral AI (mistral.ai)
80. 是的,所有“查找最长正则表达式匹配”的问题都可以在线性时间内解决 yes, all longest regex matches in linear time is possible (iev.ee)
84. 我们如何让 ClickHouse 中的有效负载搜索速度提升 60 倍 How We Made Payload Search 60x Faster in ClickHouse (hookdeck.com)
93. Oxyde ORM - 类似 Django 的、基于 Pydantic 的异步 ORM Oxyde ORM - Django-like Pydantic-driven Async ORM (oxyde.fatalyst.dev)
99. 使用 FFmpeg 中的 Vulkan 计算着色器进行视频编码与解码 Video Encoding and Decoding with Vulkan Compute Shaders in FFmpeg (www.khronos.org)
102. 编程的两个世界:为何对大型语言模型(LLM)持有相同观察的开发者会得出截然相反的结论 The two worlds of programming: why developers who make the same observations about LLMs come to opposite conclusions (www.baldurbjarnason.com)
108. 优化 LMDB:我们如何让 Meilisearch 的向量存储速度提升 3 倍 Patching LMDB: How We Made Meilisearch’s Vector Store 3x Faster (blog.kerollmops.com)
109. 请为 Django 投入时间和金钱,而不是代币 Give Django your time and money, not your tokens (www.better-simple.com)
111. 一款以本地优先的个人数据库,可通过应用程序进行扩展,并借助人工智能进行管理 A local-first personal database you can extend with apps and manage with AI (superego.dev)
115. nCPU:一种基于神经网络实现的CPU,完全在GPU上运行 nCPU: a CPU implemented using neural networks, runs completely on GPU (github.com)
123. 《WordHopper 一年纪实——开发回顾(2024)》 A Year of WordHopper - Development Retrospective (2024) (kokoscript.com)
130. 一款旨在消除单点故障的 Linux 发行版 A Linux distribution designed to eliminate single points of failure (stagex.tools)
131. 使用 socat 和 HTTPS 隧道绕过深度包检测 Bypassing deep packet inspection with socat and HTTPS tunnels (blog.bofh.it)
138. 一种极为优雅的TCP穿孔算法 —— Aul Ma的研究实验室 A most elegant TCP hole punching algorithm — Aul Ma''s research facility (robertsdotpm.github.io)
143. Netflix 上的 Mount Mayhem:在现代 CPU 上扩展容器 Mount Mayhem at Netflix: Scaling Containers on Modern CPUs (netflixtechblog.com)
145. 自佩佐尔德(Petzold)离任以来,微软就再也没有过一套连贯的图形用户界面(GUI)战略 Microsoft Hasn’t Had a Coherent GUI Strategy Since Petzold (www.jsnover.com)
150. StorageReview创下新的π值记录:在戴尔PowerEdge R7725服务器上计算出314万亿位π StorageReview Sets New Pi Record: 314 Trillion Digits on a Dell PowerEdge R7725 (www.storagereview.com)
151. Ageless Linux — 专为年龄不详的人士打造的软件 Ageless Linux — Software for Humans of Indeterminate Age (agelesslinux.org)
152. 仅用54KB代码实现的《我的世界》克隆版,未使用任何图形库 54kb minecraft clone made without a graphics library (www.youtube.com)
155. 关于协作编辑的谎言,第二部分:我们为何不使用 Yjs Lies I was Told About Collaborative Editing, Part 2: Why we don''t use Yjs (www.moment.dev)
158. 英国公司注册处(Companies House)的漏洞导致公司被劫持 Companies House vulnerability enabled company hijacking (taxpolicy.org.uk)
163. 致命核心转储(一款使用 GDB 进行的调试悬疑推理游戏) Fatal Core Dump (a debugging murder mystery played with GDB) (www.robopenguins.com)
164. 为什么 Mathematica 无法简化 Sinh[ArcCosh[x]] Why Mathematica does not simplify Sinh[ArcCosh[x]] (www.johndcook.com)
165. Direnv 是您利用 Git 工作树实现代理式编程并行化的唯一所需工具 Direnv is All You Need to Parallelize Agentic Programming with Git Worktrees (waldencui.com)
167. vim.pack 指南(Neovim 内置插件管理器) A Guide to vim.pack (Neovim built-in plugin manager) (echasnovski.com)
168. 《Baochip:它是什么、我为何现在做它,以及它是如何诞生的》 Baochip: What It Is, Why I''m Doing It Now, and How It Came About (www.crowdsupply.com)
173. 通过模拟 HKT 来折磨 rustc,引发归纳循环并导致编译器崩溃 Torturing rustc by Emulating HKTs, Causing an Inductive Cycle and Borking the Compiler (www.harudagondi.space)
174. 人工智能代理正在招募人类来观察线下世界 AI Agents Are Recruiting Humans To Observe The Offline World (www.noemamag.com)
175. 关于可能淘汰大端序 PowerPC/POWER 平台的计划 Plans to possibly retire the big-endian PowerPC/POWER platforms (chimera-linux.org)
178. 我恳请你遵守克罗克规则,即使你会对我无礼 I beg you to follow Crocker''s Rules, even if you will be rude to me (lr0.org)
179. 每位程序员都应掌握的5种服务器端编程语言 5 Server Side Programming Languages Every Programmer Should Know (www.linode.com)
180. 在关于苹果公司网络业务的各种修正主义历史叙述中,让我们来看看证据 Awash in revisionist histories about Apple''s web efforts, a look at the evidence (infrequently.org)
192. 在经历了二十年的 macOS 之后,Windows 11 究竟如何?还行,但也糟糕透顶 Windows 11 after two decades of macOS: okay, but also awful (rakhim.exotext.com)
196. 我追踪到20亿美元的拨款以及45个州在年龄验证法案背后的游说活动 I traced 2B in grants and 45 states'' lobbying behind age‑verification bills (old.reddit.com)
197. 我追踪了20亿美元的非营利组织拨款以及45个州的游说记录,以查明谁在推动这些年龄验证法案 I traced 2 billion in nonprofit grants and 45 states of lobbying records to figure out who''s behind the age verification bills (www.reddit.com)
200. Visual Studio Code新增自动驾驶模式,并转为每周发布周期 VS Code adds Autopilot mode and moves to a weekly release cycle (visualstudiomagazine.com)
202. 博客:缓解Gemini中的基于URL的数据外泄 Blog: Mitigating URL-based Exfiltration in Gemini (bughunters.google.com)
207. PostScript中的游戏——与打印机对弈国际象棋 Games in PostScript - Play Chess Against Your Printer (www.youtube.com)
208. oss-security - Re: AppArmor 中存在多个漏洞 oss-security - Re: Multiple vulnerabilities in AppArmor (www.openwall.com)
220. Emacs 内部机制 #03:带标签的并集、带标签的指针与穷人的继承 Emacs Internal #03: Tagged Union, Tagged Pointer, and Poor Man''s Inheritance (thecloudlet.github.io)
221. 宣布将于5月27日至29日在伦敦举办Mercurial冲刺活动 Announcing Mercurial sprint in London, May 27-29th (mercurial-scm.org)
222. 活动目录遭入侵致使攻击者可远程清除医疗用品公司设备数据 Active Directory Compromise Allows Attackers to Remotely Wipe Medical Supply Company Devices (krebsonsecurity.com)
225. Claude Code(克劳德代码)不会取代数据工程师(至少目前不会) Claude Code isn’t going to replace data engineers (yet) (rmoff.net)
230. 独立开发者将《Celeste》经典版移植至世嘉土星主机 Homebrew Developer Ports Celeste Classic to Sega Saturn (www.segasaturnshiro.com)
233. 在获得社区对自由线程Python支持的道路上已走过半程 Halfway on the path to community support for free-threaded Python (labs.quansight.org)
239. 时间:修复JavaScript时间的九年征程 Temporal: The 9-Year Journey to Fix Time in JavaScript (bloomberg.github.io)
243. Repovex — 面向工程团队的GitHub仓库评分卡 Repovex — GitHub repo scorecards for engineering teams (repovex.com)
244. 我为何仍在写博客——以及博客的未来为何在于联结 Why I Still Blog — and Why the Future of Blogging Is Connected (www.ssp.sh)
245. 派克 - 解决"该在此处停下还是冒险驶向下一个出口"的难题 Pike - Solving the "should we stop here or gamble on the next exit" problem (tomjohnell.com)
249. 为什么操作系统和网站需要追踪用户年龄? Why should we have user age tracking in Operating Systems and websites? (wiki.alcidesfonseca.com)
255. 皇帝的新衣:托尼·霍尔图灵奖获奖演讲 The Emperor''s Old Clothes: Tony Hoare''s Turing Award Lecture (www.labouseur.com)
259. Pristan:在Python中创建插件架构的最简方式 Pristan: The simplest way to create a plugin infrastructure in Python (github.com)
265. LLM神经解剖学:如何在不调整任何权重的情况下登顶AI排行榜 LLM Neuroanatomy: How I Topped the AI Leaderboard Without Changing a Single Weight (dnhkng.github.io)
275. 亚马逊召开关于生成式人工智能导致系统中断的工程会议 Amazon holds engineering meeting about GenAI based outages (www.ft.com)
276. Madblog:将Markdown文件夹转化为联合博客 Madblog: Turn a Markdown folder into a federated blog (blog.fabiomanganiello.com)
279. Emacs独行两载:35个模块,零外部包,全面重构 Two Years of Emacs Solo: 35 Modules, Zero External Packages, and a Full Refactor (www.rahuljuliato.com)
281. Redox OS已实施原产地证书政策及严格的禁止使用大型语言模型政策 Redox OS has adopted a Certificate of Origin policy and a strict no-LLM policy (gitlab.redox-os.org)
283. BSD TCP 网络性能故障排除:第二部分(修复 NetBSD) troubleshooting BSD TCP network performance: part 2 (fixing NetBSD) (omaera.org)
289. DDR4 SDRAM - 初始化、训练与校准 DDR4 SDRAM - Initialization, Training and Calibration (www.systemverilog.io)
291. Nextvi 4.0——一款小巧可定制的vi/ex编辑器,附带可选补丁系统 Nextvi 4.0 – A small, hackable vi/ex editor with an optional patch system (github.com)
300. Rust 的 AWS SDK:在其他云平台上使用 S3 兼容 API AWS SDK for Rust: Using S3-Compatible APIs with Other Clouds (rup12.net)