SShortSingh.
0
WorldBBC World ·

Over 300 Russians still unaccounted for after Ukraine's 2024 Kursk incursion

More than 300 Russian individuals are reported missing following Ukraine's military incursion into the Kursk region in 2024. Russian officials have acknowledged the figure, though the true number of missing persons remains uncertain. Families of the missing are seeking answers as the full scale of the losses is yet to be determined. The Kursk offensive marked a significant cross-border military operation by Ukrainian forces into Russian territory.

0
ProgrammingHacker News ·

AgentsDock Launches IDE Built Specifically for Agentic AI Research

AgentsDock is a newly introduced integrated development environment designed specifically for agentic AI research. The platform aims to provide researchers and developers with specialized tools tailored to building and experimenting with autonomous AI agents. It was shared on Hacker News, where it garnered initial community attention. The project is accessible via its official website at agentsdock.net. Details about its full feature set and development team remain limited at this stage.

0
ProgrammingHacker News ·

Atlantic hurricane season hits 60-year low with no storms by September 12

The 2025 Atlantic hurricane season has set an unusual record by producing no hurricanes through September 12, breaking a streak that dates back over 60 years. This marks one of the quietest starts to a hurricane season in modern meteorological records. The absence of storms is particularly notable given that September is historically the most active month of the Atlantic hurricane season. Meteorologists and weather trackers have flagged the anomaly as statistically significant, though the season still has weeks remaining. AccuWeather reported the milestone, noting it defies earlier forecasts that had predicted an active season.

0
ProgrammingHacker News ·

TailTalk Brings AppleTalk Networking Back via Rust and Tokio

A developer has released TailTalk, an open-source project that reimplements the classic AppleTalk networking protocol as a modern asynchronous stack. The project is built using Rust and the Tokio asynchronous runtime, running entirely in user space rather than at the kernel level. TailTalk is hosted on GitHub under the FeralFirmware account and appears to be in early stages, having attracted modest attention on Hacker News. The project aims to modernize a protocol originally developed by Apple in the 1980s for local area networking between Apple devices.

0
ProgrammingDEV Community ·

Adding LLM Descriptions to 1,245 Database Tables Made Search Retrieval Worse

A developer catalogued a 1,245-object database schema by generating LLM descriptions for every table, expecting improved search retrieval, but instead saw recall drop significantly. The problem stemmed from BM25 scoring mechanics: when a term like 'contact' appears in over 1,000 of 1,245 documents, its inverse document frequency collapses to near zero, stripping it of ranking power. Compounding this, BM25's length normalisation penalised the most important tables — which naturally have the most columns — pushing them further down rankings. Attempts to fix this by down-weighting prose fields helped marginally but sacrificed retrieval of rare, valuable terms like obscure view names. The author's solution was to maintain three separate BM25 indexes — one for identifiers, one for prose descriptions, and one combined — then fuse their rankings using reciprocal rank fusion.

0
ProgrammingDEV Community ·

Study finds all major text-to-SQL benchmarks ignore role-based access control

A new research paper titled 'Benchmarking Text-to-SQL under Role-Based Access Control' by Yang Fei and colleagues reveals that widely used benchmarks like Spider, BIRD, and LiveSQLBench evaluate AI systems without any user permission constraints. The researchers built a dataset spanning 53 databases, 399 tables, and over 21,500 role-annotated query instances with access policies defined at the individual column level. Testing existing text-to-SQL systems against this dataset showed significant performance degradation, with many generating SQL queries that are technically correct but violate access control rules — a category the paper terms 'RBAC-rejected' queries. The core problem identified is that standard AI pipelines apply database access controls only at query execution, meaning restricted tables and columns are still visible to the model during SQL generation. The paper argues that access control must be enforced earlier, at the schema-selection stage, so that restricted objects are never presented to the model at all.

0
ProgrammingDEV Community ·

How to Audit CLAUDE.md Files Using Evidence-Based Classification

Developers using Claude Code often let their CLAUDE.md project instruction files grow cluttered with outdated, temporary, or unverified rules, which can mislead AI-assisted coding workflows. A structured audit method recommends classifying every line in the file under one of six labels — such as stable fact, verified command, boundary, or obsolete — based on actual repository evidence. Each instruction should pass a two-part test: it must remain true across different tasks and be independently verifiable by another contributor. Vague directives should be replaced with specific, path-linked, and prerequisite-aware guidance that has a clear failure mode if something changes. The goal is a leaner, testable file that separates permanent project knowledge from task-specific context, which belongs in a separate task brief.

0
ProgrammingDEV Community ·

YINI Syntax Highlighting Extension Hits v1.0.0 on VS Code Marketplace

The official YINI Syntax Highlighting extension for Visual Studio Code has reached version 1.0.0 and is now publicly available on the Visual Studio Marketplace. Published by yini-lang, the extension targets YINI Specification 1.0.0 RC 6 and brings syntax highlighting support for .yini configuration files within VS Code. It covers a range of syntax elements including sections, keys, values, strings, numbers, comments, lists, objects, and directives. Developers can install it directly from VS Code by searching for 'YINI Syntax Highlighting' in the extensions panel. The release is described as one part of the broader YINI ecosystem, aimed at making .yini files easier to read and work with during everyday development.

0
ProgrammingDEV Community ·

Decorator Pattern: How to Add Features to Objects Without Subclass Sprawl

The Decorator is a structural design pattern from the Gang of Four (GoF) catalog that lets developers add behavior to individual objects dynamically without modifying their source code or creating excessive subclasses. It works by wrapping the original object in additional layers that each contribute a single, focused responsibility, keeping code clean and modular. A DEV Community article explains the pattern using a Java example involving graphical components like buttons, borders, and shadows. The abstract decorator holds a reference to a base Component interface and calls the original behavior before appending new functionality, enabling runtime composition of behaviors. The pattern is recommended when inheritance feels too rigid and when multiple behavior combinations would otherwise require an unmanageable number of subclasses.

0
ProgrammingDEV Community ·

JQuickCurl XML Mode Lets Developers Manage API Configs Without Touching Java Code

JQuickCurl's XML configuration mode allows developers to store all API definitions in a separate XML file, keeping business logic free of annotations or HTTP-related imports. Each API request is declared in the XML catalog with a name and return type, and a factory class binds these entries to matching Java interface methods at runtime. Dynamic values can be injected into curl commands using #{...} placeholder syntax, with method parameters mapped via the @Param annotation from the XML module. Crucially, endpoint behavior can be changed — such as adding headers or switching providers — by editing only the XML file, with no need to recompile or modify Java code. This declarative separation of contract and implementation is the core design goal of JQuickCurl's XML mode.

0
ProgrammingDEV Community ·

Missing Row-Level Security Quietly Became One of the Biggest Database Breach Causes

Failing to enable Row-Level Security (RLS) on database tables has emerged as a leading cause of data breaches in 2025-2026, with encryption receiving far more attention than this more critical access-control gap. A May 2025 vulnerability (CVE-2025-48757) exposed data from 303 endpoints across 170 apps built with the AI tool Lovable, because Supabase RLS was never switched on. Security researchers have also identified hundreds to thousands of Supabase instances globally that can be queried using only a public anonymous key and a basic curl request. The problem is not new or platform-specific — a similar Firebase misconfiguration previously leaked sensitive data belonging to over 1.8 million users across more than 900 apps in health, finance, and education. Supabase has since enabled RLS by default on new tables, but experts warn the risk remains highest during database migrations, when access-control logic must be manually rebuilt from scratch under time pressure.

← NewerPage 1166 of 5254Older →