Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

Mitchell Hashimoto's trust management system for open source, Nicholas Carlini has a team of Claudes build a C compiler, Stephan Schwab recounts the history of attempted developer replacement, NanClaw is an alternative to OpenClaw, and Sophie Koonin can't wrap her head around so many people going so hard on LLM-generated code.

Chapters

Tap a chapter to play from there.

  1. Link
  2. Link
  3. Link
  4. Link
  5. Link
  6. Link
  7. Link
  8. Link

Transcript

Read the transcript · about 1,190 words

Jerod Santo:What up, nerds? I'm Jerod and this is Changelog News for the week of Monday, February 9th, 2026. So the folks at ai.com apparently spent $70 million on the domain, then another $15 million on a Super Bowl ad, then failed to prepare for the resulting flood. The end result: one of the most expensive, self-inflicted DDoS attacks in tech history *and* free advertising for Cloudflare's standard Gateway time-out page. ([src](https://x.com/aquariusacquah/status/2020694326247100621)) Ok, let's get into this week's news.

Jerod Santo:[Vouch for an open source web of trust](https://github.com/mitchellh/vouch) Ghostty creator, Mitchell Hashimoto: > AI eliminated the natural barrier to entry that let OSS projects trust by default. People told me to do something rather than just complain. So I did. Introducing Vouch: explicit trust management for open source. Trusted people vouch for others. The idea is simple and mimics real life social constructs, so I think it has a chance of succeeding. > Unvouched users can't contribute to your projects. Very bad users can be explicitly "denounced", effectively blocked. Users are vouched or denounced by contributors via GitHub issue or discussion comments or via the CLI. Mitchell is rolling out this vouching process in Ghostty immediately.

Jerod Santo:[Claudes build a C compiler](https://www.anthropic.com/engineering/building-c-compiler) Alongside the launch of Opus 4.6, the Anthropic team published the results of Nicholas Carlini's experiment with "agent teams": > I tasked 16 agents with writing a Rust-based C compiler, from scratch, capable of compiling the Linux kernel. Over nearly 2,000 Claude Code sessions and $20,000 in API costs, the agent team produced a 100,000-line compiler that can build Linux 6.9 on x86, ARM, and RISC-V. It was a fascinating journey, which produced some new techniques in designing harnesses for long-running autonomous agent teams. The resulting [compiler](https://github.com/anthropics/claudes-c-compiler) can build Linux 6.9, but isn't a fully functional C compiler. In fact, it fails to compile the most basic ['Hello, world'](https://github.com/anthropics/claudes-c-compiler/issues/1) program, which gave the general public all it needed to [torch](https://github.com/anthropics/claudes-c-compiler/issues/1#issuecomment-3856153640) the entire effort.

Jerod Santo:[We've tried to replace devs every decade since 1969](https://www.caimito.net/en/blog/2025/12/07/the-recurring-dream-of-replacing-developers.html) Stephan Schwab recounts the history of the sentiment that, "this time, we'll finally make software development simple enough that we won't need so many developers." According to Stephan: > Understanding why this cycle persists for fifty years reveals what both sides need to know about the nature of software work. In brief, the history looks like this: - 1969: The dream was born during the Apollo program - 1970s: COBOL: business people will write their own programs - 1980s: CASE tools will generate everything - 1990s: Visual Basic and Delphi: drag, drop, done - 2000s+: Web frameworks, low-code, and no-code - Today: AI: the latest chapter in a long story So far, every advancement has not reduced the need for developers, but increased it. Stephan says AI will do the same. > The pattern continues because the dream reflects a legitimate need. We genuinely require faster, more efficient ways to create software. We just keep discovering that the constraint isn’t the tool—it’s the complexity of the problems we’re trying to solve. > > Understanding this doesn’t mean rejecting new tools. It means using them with clear expectations about what they can provide and what will always require human judgment.

Jerod Santo:It's now time for sponsored news! [Did your AI just recommend a vulnerable package?](https://fandf.co/4ahP5MZ) Here's a fun experiment: ask your coding agent to recommend a logging library for your next project. Now check when that recommendation was last updated. Feeling lucky? AI coding agents are trained on data with a knowledge cutoff. That package they just confidently suggested could have three CVEs disclosed since the model learned about it. Your code runs. Your security audit does not. That's why Sonatype built [Guide](https://fandf.co/4ahP5MZ). **No signup. No credit card.** Just go to [guide.sonatype.com]([https://guide.sonatype.com](https://fandf.co/4ahP5MZ)) and start querying. Sonatype Guide is an MCP server that plugs directly into Claude, Cursor, and other AI assistants. Instead of your agent pulling from stale training data, it pulls from Sonatype's live component intelligence. These are the folks behind Maven Central, trusted by over 15 million developers. They know which packages are safe and which ones you should avoid. Here's a challenge: go to [guide.sonatype.com](https://fandf.co/4ahP5MZ), search for a dependency your AI recently recommended, and see what Sonatype knows that your model doesn't.

Jerod Santo:[A lightweight, containered alternative to OpenClaw](https://github.com/gavrielc/nanoclaw) > [OpenClaw](https://github.com/openclaw/openclaw) is an impressive project with a great vision. But I can't sleep well running software I don't understand with access to my life. OpenClaw has 52+ modules, 8 config management files, 45+ dependencies, and abstractions for 15 channel providers. Security is application-level (allowlists, pairing codes) rather than OS isolation. Everything runs in one Node process with shared memory. > > NanoClaw gives you the same core functionality in a codebase you can understand in 8 minutes. One process. A handful of files. Agents run in actual Linux containers with filesystem isolation, not behind permission checks. OpenClaw's success is undeniable, but that doesn't mean it fits everyone perfectly. NanoClaw looks like a great alternative for the security and/or simplicity conscious. It also has an interesting approach to feature additions and configuration: [nope](https://github.com/gavrielc/nanoclaw?tab=readme-ov-file#contributing). Fork the codebase and add skills to adapt it to your needs instead. *See also: [nanobot](https://github.com/HKUDS/nanobot)*

Jerod Santo:[Stop generating, start thinking](https://localghost.dev/blog/stop-generating-start-thinking/) Sophie Koonin explains why she's unsettled by so many people "going so hard" on LLM-generated code in a way that she can't wrap her head around: > I find it hard to justify the value of investing so much of my time perfecting the art of asking a machine to write what I could do perfectly well in less time than it takes to hone the prompt. > > You’ve got to give it enough context - but not too much or it gets overloaded. You’re supposed to craft lengthy prompts that massage the AI assistant’s apparently fragile ego by telling it “you are an expert in distributed systems” as if it were an insecure, mediocre software developer. > > Or I could just write the damn code in less time than all of this takes to get working. I shared this position with her until recently, but I don't do any of the fancy prompting / massaging that other devs talk about and I've been getting excellent results the last few months. Back to Sophie: > My worry is more around people thinking they can “vibe code” their way to production-ready software, or hand off the actual thinking behind the coding. I'm 100% with her on that last bit. We cannot *hand off the actual thinking* and produce anything of lasting value. I'd love to say we won't do that, but I repeatedly underestimate the extent to which humans are, above all else, lazy...

Jerod Santo:That's the news for now, but go and subscribe to the Changelog Newsletter for the full scoop of links worth clicking on. Such as: - [The Anthropic Hive Mind](https://steve-yegge.medium.com/the-anthropic-hive-mind-d01f768f3d7b) - [Saying "No" in an age of abundance](https://blog.jim-nielsen.com/2026/saying-no/) - [Why Elixir is the best language for AI](https://dashbit.co/blog/why-elixir-best-language-for-ai) Get in on the newsletter at changelog.news Have a great week! Like, subscribe, and leave us a 5-star review if you dig the show, and I'll talk to you again real soon.

Transcript supplied by the publisher with the episode.

The Changelog: Software Development, Open Source

by Changelog Media · English · Tech & Science

Software's best weekly news brief, deep technical interviews & talk show.

More from The Changelog: Software Development, Open Source

  1. 16 Feb 2026 · 6 min

    All the Claw things (News)

    Peter Steinberger joins OpenAI, ZeroClaw is "claw done right", MimiClaw runs on a $5 chip, Steve Yegge on managing the AI Vampire, and the day the telnet died.

  2. 13 Feb 2026 · 2 hr

    Han shot first (Friends)

    Our ol' friend, Brett Cannon, is back to talk all things Python. But first! Star Wars, Machete Order, Lost, Babylon 5, Game of Thrones, Murderbot, Ted Lasso, Project Hail Mary, David Attenborough, perpetual voice rights, and the AI uncanny valley.

  3. 11 Feb 2026 · 1 hr 37 min

    Building the machine that builds the machine (Interview)

    Paul Dix joins us to discuss the InfluxDB co-founder's journey adapting to an agentic world. Paul sent his AI coding agents on various real-world side quests and shares all his findings: what's going to prod, what's not, and why he's (at least for a bit) back to coding by hand. Update: He's back to letting the AIs write code, but with a lot more oversight. For now…

  4. 6 Feb 2026 · 1 hr 43 min

    It's a renaissance woman's world (Friends)

    Amal Hussein returns to tell us all about her new role at Istari, what life is like outside the web browser, how she's helping ambitious orgs in aerospace, what the SDLC looks like in 2026, and a whole lot more. Wait, moon vacuums?!

  5. 4 Feb 2026 · 1 hr 17 min

    Setting Docker Hardened Images free (Interview)

    In May of 2025, Docker launched Hardened Images, a secure, minimal, production-ready set of images. In December, they made DHI freely available and open source to everyone who builds software. On this episode, we're joined by Tushar Jain, EVP of Engineering at Docker to learn all about it.

  6. 2 Feb 2026 · 9 min

    The tech monoculture is finally breaking (News)

    Jason Willems believes the tech monoculture is finally breaking, Don Ho shares some bad Notepad++ news, Tailscale's Avery Pennarun pens a great downtime apology, Milan Milanović explains why you can only code 4 hours per day, and Addy Osmani on managing comprehension debt when leaning on AI to code.

  7. 9 Oct 2026 · 2 hr 43 minNew

    From zero to NanoClaw (Interview)

    Gavriel Cohen, creator of NanoClaw and co-founder of NanoCo, joins Adam to explain how a 40-hour weekend project became a viral open source hit and the foundation of an enterprise AI company. Gavriel describes the security concerns that led him to build a small, container-isolated alternative to OpenClaw, why he released it under the MIT license, and why the project's community and credibility are more valuable than keeping its code private. They explore the shift from writing code to architecting the environments in which agents work, NanoClaw's "skills over features" approach, the approval…

  8. 3 Sep 2026 · 1 hr 55 min

    Forking Cal.com to closed source (Interview)

    This week I'm joined by Peer Richelsen, co-founder of Cal.com. What if the majority of open source repositories are already compromised and we just don't know it yet? That's the theory Peer brings to the table this week. We dig into how AI has flattened the knowledge graph to the point that a 16-year-old can vibe hack a power station just as easily as their mom can vibe code an iOS app, why the reporting culture that has kept open source safe all these years is collapsing under AI generated noise, Cal.com's move to fork its own codebase and take the sensitive parts private, and the eye…

  9. 25 Aug 2026 · 1 hr 42 min

    Postgres at PlanetScale (Interview)

    Sam Lambert is back after 4 years and he does not hold back! We cover $5 PlanetScale Postgres, the Neki "do-over" of Vitess, agents shipping schema changes through deploy requests, rolling back a 500TB table in seconds, and the very real question of whether to open source any of it. Plus: why he thinks the sleeping, lazy giants should be broken up.

  10. 21 Jul 2026 · 2 hr 7 min

    Canary tokens and digital tripwires (Interview)

    Haroon Meer is back! Haroon is the Founder of Thinkst, the ~50-person bootstrapped company behind Canary and Canarytokens — honeypots and tripwires you sprinkle inside your network and forget about until an attacker touches one. We talk about the AWS API key token attackers just can't resist trying, the real credit card token backed by an actual bank partnership, Breadcrumbs (their brand-new feature that leads intruders straight to your canaries), a live demo where a hardware Canary becomes a Synology NAS in one click, and how a company with zero outbound sales and no price increase in ten…

Every episode of The Changelog: Software Development, Open Source →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play