1 October 2026
What are code reviews even for?
We’ve always known this:
Keep changes small. Write a meaningful description of what changed and why
And that doesn’t change. But if we were doing it wrong before, then AI inherited it, and then amplified it.
It goes on to describe Meta’s Risk Aware Diff Auto Review (RADAR) system where scarce human attention should be reserved for changes where human judgment and accountability matter most.
And how code review isn’t just about finding defects - it’s also about sharing knowledge.
Maybe We Shouldn’t Be Reviewing All This Code
A counter-article to the one above. She’s suggesting that we shouldn’t do code reviews at all, except in exceptional circumstances. Instead we should be doing pair programming and other things to achieve the same goal.
I think I lean more on the previous article - fix the PR process, regardless of AI.
The broken windows theory of coding agents
About how lowering your standards quickly accelerates. Fewer (proper) code reviews lead to poorer code (because if it works, who cares, or just no-one noticed) and then AI starts replicating that because it’s following the standards of the codebase.
I don’t want the details
After an incident, you shouldn’t ask how it happened - you should ask what you’re going to change.
We can trust that the people involved understand what happened and did their best to solve it, and we can even talk about how to prevent it in future. But unless something changes, we’ll have forgotten that next time it happens.
Turn your REST APIs into MCP tools with Google Cloud API Gateway
Google can turn an API with an OpenAPI spec into an MCP. Just like that.
How Fast is .NET 11 Runtime Async?
You probably know that async/await generates a state machine at compile-time, which adds quite an overhead.
That overhead is often not needed because async methods complete synchronously more often than you’d expect,
especially in deep call chains and distributed systems built around asynchronous APIs.
Runtime Async moves async handling from the C# compiler’s state machines into the runtime, so the JIT can optimise it. This is around 20x faster with zero allocations when an async method completes synchronously.
Less Known LINQ Methods
Lots of LINQ methods that seem useful but we don’t think about,
including Aggregate/AggregateBy, Append/Prepend, Chunk, Index, SkipWhile/TakeWhile.
If It Quacks - Part 2
Interesting idea - you can define parameters to be an interface, and then pass in objects that match that interface, even if they don’t actually implement it.
This is the interface:
1
2
3
4
public interface INamed
{
string Name { get; }
}
This is a method that accepts the interface as parameters:
1
2
3
[DuckTyped]
public string Greet(INamed first, INamed second, string greeting = "Hello") =>
$"{greeting}, {first.Name} and {second.Name}!";
Here are two classes that don’t explicitly implement the interface, but match it:
1
2
public class Person { public string Name => "Steven"; }
public class Mallard { public string Name => "Donald"; }
And you can call the method as if they did implement it:
1
new Greeter().Greet(new Person(), new Mallard()); // Hello, Steven and Donald!
It also works with anonymous objects:
1
new Greeter().Greet(new { Name = "Steven" }, new { Name = "Donald" });
Faster blob copying in Azure Blob Storage
First of all, you shouldn’t need to copy blobs, but if you do, don’t download and upload - for several reasons - copy server side instead.
There’s the simple way:
1
2
var copy = await target.StartCopyFromUriAsync(sourceSasUri);
await copy.WaitForCompletionAsync(); // poll until Azure finishes
If both blobs are in the same storage account, that’s almost instant.
If you want to copy a large blob to a different storage account, he describes how to parallelize it.
A faster way to convert a timestamp to Hour, Min, Sec
Calculating minutes and hours in parallel instead of one after the other makes it up to 50% faster, as low as five CPU cycles.
Understanding Device Bound Session Credentials (DBSC)
A bearer token can be used by anyone in possession of it, which leads to a risk of cookie theft and session hijacking. DBSC uses a refresh token that requires a server to verify it is being used on the same machine it was issued to. The short-lived cookies expire shortly, and the refresh token would not be valid if someone managed to steal them.
This is a non-breaking, opt-in header.
The article goes on to explain how and why to implement it, but a bit short on practical details.
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Using invisible Unicode characters has been a common way to do prompt injection. Now it’s also being used to evade spam filters and AI guardrails.
