James's feed digest https://github.com/jameslevine/feed-digest Tue, 06 Oct 2026 06:21:15 +0000 Digest for 2026-10-06 https://github.com/jameslevine/feed-digest/blob/main/digests/2026-10-06.html Digest for 2026-10-06 Tue, 06 Oct 2026 06:21:15 +0000 Digest for 2026-10-06

Your stack

Python 3.14

Amazon Bedrock

AWS Organizations and Control Tower

MCP

Claude

React

  • TanStack Charts hit 1.0, a new headless charting library meant to pair with the team's existing table and query tooling.

Java

IaC and DevOps

AWS

AI and agents

Security

Engineering practice

Feeds that failed

CISA advisories (HTTP 403 Forbidden).

]]>
Digest for 2026-10-05 https://github.com/jameslevine/feed-digest/blob/main/digests/2026-10-05.html Digest for 2026-10-05 Mon, 05 Oct 2026 06:12:53 +0000 Digest for 2026-10-05

Your stack

Python 3.14

uv

boto3

EventBridge

Amazon Bedrock

MCP

Claude

Security (AI and cloud)

Rust

Go

Java

IaC and DevOps

AWS

AI and agents

Security

Engineering practice

Feeds that failed

CISA advisories (HTTP 403 Forbidden).

]]>
Digest for 2026-10-02 https://github.com/jameslevine/feed-digest/blob/main/digests/2026-10-02.html Digest for 2026-10-02 Fri, 02 Oct 2026 06:14:38 +0000 Your stack

Amazon Bedrock

  • Building ambient agents with Bedrock AgentCore shows a framework-agnostic pattern for event-driven agents (SQS, Lambda, DynamoDB) with a human-in-the-loop ask_human tool — a solid reference if you're wiring agents to react to events instead of chat prompts.
  • AWS Professional Services used AgentCore to automate enterprise cloud migrations end to end, including IaC generation — a bigger data point for agentic IaC workflows.

Claude

MCP

  • CVE-2026-97662: argument injection in AWS's own security-agent-mcp-server diff scan — worth checking if you run that tool, and a reminder to treat MCP server inputs as untrusted.

Powertools for AWS Lambda

  • CVE-2026-104002: the data masking utility in Powertools for AWS Lambda (Python) fails open on errors instead of masking — update if you rely on it for PII redaction in logs.

DynamoDB

GitHub Actions

AWS Organizations and Control Tower

boto3

Security (AI and cloud)

Python

  • PEP 818 (Pyodide FFI core for Python) is back up for discussion after a round of trims and renames.

IaC and DevOps

AWS

Security

  • A self-healing WordPress backdoor persists across files, the database and shared memory, re-infecting the site after cleanup.
  • This week's tl;dr sec roundup covers Google's PageBreak web app scanner and Perplexity's agent-security tooling.

AI security

Engineering practice

Feeds that failed

CISA advisories (malformed XML).

]]>
Digest for 2026-10-01 https://github.com/jameslevine/feed-digest/blob/main/digests/2026-10-01.html Digest for 2026-10-01 Thu, 01 Oct 2026 14:07:45 +0000 Your stack

boto3

  • boto3 1.43.106 is out on PyPI — routine SDK update, worth a bump if you pin exact versions.

Amazon Bedrock

GitHub Actions

MCP

  • Agent Helidon: License to Scale — a look at scaling virtual-thread-based MCP servers on the JVM, useful context on MCP server performance outside the Python world.

Claude

Security (AI and cloud)

React

Rust

  • Rust 1.99.0 is out — check the release notes for breaking changes before bumping toolchains.

Java

IaC and DevOps

AWS

AI and agents

  • Google rolled out Gemini 4 Argon to trusted cyber defenders, with a guardrail-free version planned — a notable competitive move in security-focused agent workflows.

Security

Engineering practice

Feeds that failed

TanStack blog, Tokio blog, Oracle Java Magazine, 2ality, Platform Engineering, Anthropic engineering blog, CISA advisories, Lakera blog, Anthropic research, Protect AI blog, tl;dr sec, HiddenLayer research, Invariant Labs, Microsoft Security Response Center.

]]>