Will Velida πŸ‡ΊπŸ‡¦
banner
willvelida.com
Will Velida πŸ‡ΊπŸ‡¦
@willvelida.com
Senior Software Engineer at Microsoft πŸ§‘β€πŸ’»
@Arsenal fan
Posts are mine
Blog: https://www.willvelida.com/
YouTube: https://www.youtube.com/@willvelida
Linktree: https://linktr.ee/willvelida
Reposted by Will Velida πŸ‡ΊπŸ‡¦
> I think we need to focus on our overall approach to software engineering and treat AI as a tool. A powerful tool, a new kind of tool, but still a tool.

Hard to pick what to quote from Russ Cox on how the Golang team should think about AI contributions (and more broadly).
February 13, 2026 at 9:35 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
I do not fear the rise of superintelligence.

I do, however, fear the rise of billionaires, organizations, and world powers who seek to use computing to maximize their power, influence, and control.
February 13, 2026 at 9:37 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
Personally, I find the usage of AI in a corporate setting regularly enables the worst behaviors to be amplified and rewarded.

A lot of people care about output vs quality or correctness. And at scale, producing incorrect things is disastrous network effects.
February 12, 2026 at 3:30 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
too many kids today have never destroyed the family PC with sketchy downloads

you must learn to fear Computer before you can properly wield Computer
folks today don't know the abject fear of inadvertently downloading, for the first (and only lol) time, a .exe file from kazaa or limewire and it shows

def one of those "it only takes one time to learn" but oooo boy at what cost for that single instance
February 12, 2026 at 2:08 AM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks
GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks
A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers to crash servers, steal data, or hijack user sessions. Security experts urge administrators of self-managed instances to upgrade immediately, noting that GitLab.com has already been patched.​ The most severe vulnerability, tracked asΒ CVE-2025-7659Β (CVSS 8.0), lies in the Web IDE. This flaw involves β€œincomplete validation,” meaning the system fails to verify who is accessing certain data properly. An unauthenticated attacker, someone without a username or password, could exploit this to steal access tokens and view private software repositories.​ CVE ID Severity Type Description CVE-2025-7659 High (8.0) Token Theft Unauthenticated access to private tokens via Web IDE. CVE-2025-8099 High (7.5) DoS Service crash via repeated GraphQL queries. CVE-2026-0958 High (7.5) DoS Resource exhaustion via JSON validation bypass. CVE-2025-14560 High (7.3) XSS malicious script injection in Code Flow. The update also resolves two dangerous Denial-of-Service (DoS) issues . In a DoS attack, a hacker tries to overwhelm a system to knock it offline. CVE-2025-8099Β (CVSS 7.5) allows attackers to crash the service by sending repeated, complex queries to the GraphQL interface. CVE-2026-0958Β (CVSS 7.5) exploits the JSON validation middleware, letting attackers exhaust the server’s memory or CPU.​ Another major fix addressesΒ CVE-2025-14560Β (CVSS 7.3), a Cross-Site Scripting (XSS) vulnerability in the β€œCode Flow” feature. XSS flaws allow attackers to inject malicious scripts into trusted websites. In this case, an attacker could hide code that executes when another user views it, potentially allowing them to perform actions on behalf of that victim.​ GitLab strongly recommends that all customers running affected versions upgrade to the latest patch immediately. While the update fixes these critical issues, it also addresses several medium-severity bugs, including Server-Side Request Forgery (SSRF) and HTML injection flaws. Administrators should be aware that upgrading single-node instances may require brief downtime for database migrations. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks appeared first on Cyber Security News .
cybersecuritynews.com
February 11, 2026 at 6:06 AM
Found out yesterday that I'll be speaking at @ndcconferences.com Copenhagen in June! Very excited to be getting the opportunity to visit Denmark for the first time! ndccopenhagen.com/agenda/platf...
Platform Engineering in the age of Generative AI | NDC Copenhagen 2026
Establishing a platform that serves the needs of your developers is a challenge for teams of all sizes. But with Generative AI tools like GitHub Copilot, surely this is now all easy, and all we need i...
ndccopenhagen.com
February 11, 2026 at 8:28 AM
Why was this hidden as abuse? This is right
February 10, 2026 at 11:35 PM
I am once again asking you not to blindly trust AI and THINK FOR YOURSELVES! The maintainers anger here is justified in the face of this AI slop: github.com/starfederati...
feedback from Claude 4.6 Β· Issue #1131 Β· starfederation/datastar
Feature Request I didn't post this to bugs because it may not be a bug, but this is based on realworld experience. I'm not here to complain, I'm just providng some feedback so that it may help the ...
github.com
February 10, 2026 at 11:35 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
When I started Puppet, execs always exclaimed, β€œGreat, so you can fire sysadmins!”

But I always said, no, so you can increase quality and velocity without increasing cost.

In Puppet’s case, people who did not adapt saw lower salaries, but people who did got paid much better and had more impact.
We are asking developers to do more with less, including less pay. Either we have managed to cut cost without reducing output, or we have increased output, but have very little to show for it.

I'm sure there is another narrative around creating new opportunities, but I'm not hearing about those.
The average developer salary is my new GenAI signal. If it's really about developers leveraging AI and unlocking new value, then I expect salaries to increase.

If GenAI is about increasing profit margins, then I expect the average developer salary, and headcount, to decrease over time.
February 10, 2026 at 10:05 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
I'm convinced AI is our generation's radium - a discovery with genuinely useful applications in specific, controlled circumstances that we stupidly put in everything from kid's toys to toothpaste until we realised the harm far too late where future generations will ask if we were out of our minds.
VC, founder, dumbass
February 8, 2026 at 10:23 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
I never thought people would be this excited about talking to a computer.
February 8, 2026 at 10:27 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
VC, founder, dumbass
February 8, 2026 at 9:37 PM
Today might be the day....
a close up of a bald eagle 's face with yellow eyes and the words `` go birds '' below it .
ALT: a close up of a bald eagle 's face with yellow eyes and the words `` go birds '' below it .
media.tenor.com
February 8, 2026 at 11:13 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
"TDD slows me down"

Good
February 8, 2026 at 12:39 PM
I finding that agent skills is lightweight and fits my developer flow. You could change your .gitignore, but I'm trying to be more intentional and force myself to write code myself, and not pollute the repo with markdown. Yeah I'll be slower, but at least it will be MY code πŸ™‚
February 8, 2026 at 8:05 AM
After using SpecKit to implement some features for my side project, I've decided to get rid of it. Getting rid of 33k lines of useless crap is therapeutic, and I never should have committed them to the repository in the first place: github.com/willvelida/b...
FUCK SPEC KIT by willvelida Β· Pull Request #155 Β· willvelida/biotrackr
I'm removing SpecKit from this repo. It produces far too much crap that I don't care about. I use AI for my coding work. And yes, I do think that it makes me more productive. I don't kn...
github.com
February 8, 2026 at 7:41 AM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
Mr. Hightower also posted this on Linkedin, and its absolutely maddening seeing all the so called "practitioners" completely miss his point and fill the comment section with cope, rather than being humble and taking a moment to reflect on his words.
I'm still writing code the hard way. I'm slow. I like to think critically about every line of code and fiddle with variable names until everything looks right. I treat code as a liability and try to ship only what's necessary.

It's hard to imagine writing code any other way.
February 3, 2026 at 7:53 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
I think it's best for everyone to understand that the unified class project of billionaires right now is to do to white collar workers what globalization and neoliberalism did to blue collar workers.
February 4, 2026 at 7:41 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
It’s a terrible time to be someone who pays attention or cares about other people.
February 6, 2026 at 1:32 PM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
I'm still writing code the hard way. I'm slow. I like to think critically about every line of code and fiddle with variable names until everything looks right. I treat code as a liability and try to ship only what's necessary.

It's hard to imagine writing code any other way.
February 1, 2026 at 2:52 AM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
We’re excited to announce a new partnership between the @owasp.org foundation and NDC Conferences, bringing an all-new OWASP Track to this year’s NDC Security conference! Check out the OWASP track in Room 6 on Thursday πŸ‘‰ ndcsecurity.com/agenda?day=2...
February 6, 2026 at 9:38 AM
Agent Skills are impressive, but I'm still encountering subtle hallucinations and errors here from time-to-time. I have a skill for git commits, and I require all commits to be signed. Even though this is explicitly defined in multiple MD files, GHCP will still try to create unsigned commits πŸ™„
February 6, 2026 at 9:53 AM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
We've built AI that can write code, pass bar exams, and diagnose diseases. Impressive right? Turns out it's also racist, sexist, and a bit dangerous. Our keynote speaker Sreyna Rath is going to show how to teach AI some basic human decency. πŸ˜˜πŸ€–

Grab your DDD ticket now: www.dddmelbourne.com/tickets
February 6, 2026 at 1:08 AM
Calling it now. This guy doesnt have the temperament to do the job: www.bbc.co.uk/sport/footba...
Arsenal lack of respect in warm-up behind outburst - Chelsea boss Liam Rosenior
Chelsea boss Liam Rosenior says Arsenal were affecting his side's warm-up prior to the second leg of their Carabao Cup semi-final at Emirates Stadium.
www.bbc.co.uk
February 6, 2026 at 12:12 AM
Reposted by Will Velida πŸ‡ΊπŸ‡¦
This is why people *hate* AI. It found a "security issue" that isn't actually an issue, and then when I tell it it's wrong, it tries to tell me it is an issue and I'm like no, it's not. I don't use the affected product.
February 5, 2026 at 10:22 PM