Claude sourcecode leaked, Axios hacked, GitHub auto-opting users to AI training and can you survive 100 jumps? ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  

WeAreDevelopers Dev Digest

View in browser

Issue 214: Claude is leaking, GitHub is listening & Axios hacked!

Your article on the WeAreDevelopers Magazine? - Submit your proposal

08-10/07/26: WeAreDevelopers World Congress Europe

25-26/11/26: WeAreDevelopers Conference India - CFP India

23-25/09/2026: WeAreDevelopers World Congress North America - CFP US

Get 15% off your tickets with code "devdigest" for Europe, North America

Hello fellow developer, what a week! A misconfigured source map leaked the whole Claude source code and GitHub caused turmoil by auto-opting people into offering their code for AI training and accidentally showing ads in pull requests. And in the code world, pretext hints at new ways of performantly rendering text in browsers. Want to learn more?

How to defend against data manipulation attacks

Bozidar Spirovski and Wekoslav Stefanovski are seasoned security researchers and developers who proposed a workshop for the WeAreDevelopers World Congress in July in Berlin. We sat down with them to learn how to defend against data manipulation attacks.

Google Cloud Summit "DACH for Developers" - June 9-10 Frankfurt

Two days to move beyond the hype: Expect hands-on labs, live builds, and tech breakouts. Bring your team, build together, and level up your stack!

What's happening in AI

  • A deep dive analysis of the accidentally leaked Claude Code source
  • How to Do AI-Assisted Engineering 
  • How to Attract AI Bots to Your Open Source Project
  • Will AI Kill Open Source or will AI Agents Make Free Software Matter Again?
  • Building shared coding guidelines for AI (and people too)

Security and Privacy

  • Supply Chain Attack on Axios Pulls Malicious Dependency from npm
  • Dangerous by Default: What OpenClaw CVE Record Tells Us About Agentic AI
  • Securing our codebase with autonomous agents
  • Nvidia’s version of OpenClaw could solve its biggest problem: security
  • Your AI Copilot Is the Newest Attack Surface

Software Development

  • Pretext - a library for multiline text measurement, what it means for rendering, teaches us about reinforced AI Loops and why we're looking at the wrong demos.
  • Abusing Customizable Selects for fun
  • A gentle intro to npm workspaces, with visuals
  • Small Programming Tricks
  • Shell Tricks That Actually Make Life Easier (And Save Your Sanity)

Tips, Tricks and Tools

  • Run and train AI models locally with Unsloth Studio.
  • The complete registry of OpenClaw clones, forks, derivatives, and inspired projects
  • AI agents proving work with video recording, error logs, and proof artifacts
  • Caterpillar Security scanner for AI agent skills
  • fetch-network-simulator

Procrastination corner and Wonderful Weird Web

  • 100 jumps - simple, but addictive
  • The Dunning-Kruger Effect Is Probably Not Real
  • Hostile volume - how not to UX

Career and Culture:

  • GitHub Copilot “Ads” Controversy Explained: Bug or Warning Sign for Developers?
  • Petition to Node.js TSC: No AI code in Node.js Core
  • I Created My First AI-assisted Pull Request and I Feel Like a Fraud
  • The Sudden Fall of OpenAI’s Most Hyped Product Since ChatGPT

  • We analyzed 1,140 devtools funding rounds—here's who's writing checks and why

Are you looking for opportunities or fancy a change?

Companies to check:

  • Software Architect at Dennemeyer Group
  • Software Engineer, Java (Trade Hub) at Bitpanda
  • Backend Software Engineer at fulfillmenttools
  • Product Owner at procilon Group
  • Data & AI Analyst at ZEISS Group
  • ROSEN Technology
  • SD Worx
  • Technoly
  • SMG
  • Vertical Horizon B.V.

More jobs here: Remote positions - Germany - Austria

WeAreDevelopers, Schottenfeldgasse 23, Vienna, Vienna 1070, Austria

Unsubscribe Manage preferences