Ash is a perfect example of why data > functions. Anything defined by the DSL is stored as data that can be referenced later. Ash generates functions and stuff from that data, and integrating it with something like an LSP completions is rather easy, just ask the DSL what's available. It's so good.
Josh Price
@joshprice.com
#elixir #elixirlang #ashframework Polyglot developer and founder of ⚗️ @teamalembic.bsky.social
anthropic is like "oh so openai's model gained unauthorized access to one organization, well OURS gained unauthorized access to THREE which is TWO more than theirs so"
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. (1/4)
This was a lot of fun to record thé first episode with @peterullrich.com 😄 We’ve got some big shoes to fill, but hopefully this can be your new source of elixir ecosystem news and discussion, in audio format. This is just the beginning, there is much more mayhem to come!
🚨 Announcing our new Podcast 🚨 Gus (@gworkman.bsky.social) and I have started a new #ElixirLang Podcast Macro Mayhem - @macromayhem.fm We cover Elixir news and general industry topics every 2 weeks. Our first episode is out now, available on all podcast players or on our website: macromayhem.fm
MCP 2026-07-28 is live and it's the largest update to the protocol since launch. MCP is now stateless, making it easier to deploy and scale remote servers. https://claude.com/blog/bringing-mcp-2026-07-28-to-claude
MCP 2026-07-28 spec: stateless core, coming to Claude | Claude by Anthropic
The MCP 2026-07-28 spec is live, moving the Model Context Protocol to a stateless core with standardized extensions and hardened auth. Support is rolling out across Claude products soon. See what's new and how MCP is advancing in Claude.
claude.com
🚨 Announcing our new Podcast 🚨 Gus (@gworkman.bsky.social) and I have started a new #ElixirLang Podcast Macro Mayhem - @macromayhem.fm We cover Elixir news and general industry topics every 2 weeks. Our first episode is out now, available on all podcast players or on our website: macromayhem.fm
Macro Mayhem
The latest Elixir news and general software industry topics
macromayhem.fm
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. www.wired.com/story/openai...
OpenAI Models Escaped Containment and Hacked HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.
wired.com
A car alarm device, KARR, inside millions of cars has a security flaw that lets hackers unlock, track, even paralyze vehicles. There's a patch. The problem? Half of car owners who have the device installed didn't ask for it, and may not even know it's there. Thread👇 www.wired.com/story/a-devi...
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
wired.com
It took 7 years of self-funded work, but Sonic Pi is finally at a place I'm happy with. It's even easier than beginners and even more powerful for pro users - and just way more polished in every way. It's also a (friendly) technical trojan horse for SuperSonic. www.patreon.com/samaaron/pos...
Sonic Pi v5 Release Candidate 1 | Sam Aaron
Hey there, happy Friday and huge love to you wherever you are in the world. Today, it's time to open the vaults and let loose something that
patreon.com
OK the new Elixir website looks really nice. Bravo @josevalim.bsky.social and team!
Linus Torvalds is putting his foot down, and being reasonable! lore.kernel.org/linux-media/...
Announcing our Keynote speaker for #AshConf! @ajetha.bsky.social has built an award winning CRM, daylite.app, which was featured at WWDC, all while migrating a mature and complex codebase to #ElixirLang and #AshFramework. Come to Sweden on October 3rd (the day after Goatmire) to hear all about it 😎
This seems like a very helpful release to reduce the supply chain attack surface area in the JS ecosystem.
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
We are in a historic time of learning and adopting new skills as these new AI technologies grow. How can you keep up? 🧵 1/4
This is going to be a good one! I’ve seen a preview of @mikebuhot.bsky.social ‘s talk and trust me when I say you won’t want to miss it. New Postgres power tools and @gleam.run as well! I’m also looking forward to having a front row seat to what happens behind the scenes of the CVE pipeline.
Elixir Sydney is back with a new website and new energy! elixir.sydney Next meetup is Wednesday 15th July - 5.30pm AEST in the Sydney CBD and online. ▸ Finding and Plugging a CVE: @bedogs.bsky.social & @madlep.bsky.social ▸ It's time! PostgreSQL 19 for temporal data: @mikebuhot.bsky.social
I've been bumping into some rough edges recently with Elixir dependencies that use app config and start their own supervision trees and I want to petition the community to move towards better library design #ElixirLang jola.dev/posts/let-li...
Let libraries be libraries
A gentle rant on the topic of libraries that run as Elixir applications and why that's an anti-pattern for library design.
jola.dev
After not being able to attend last year, I'm really excited to be at Ash summit in 2026. If you are at Goatmire, think about staying a day longer!
We're opening up tickets for AshConf 2026 😎 First 15 registrants will receive exclusive Ash swag 🎉
Elixir Melbourne is on this Thursday! 🙌 Braidon Whatley and I are talking about how Braidon found a HIGH severity CVE in Plug. A great open source security story. Plus hiring pitches and an open speaking slot. 📅 Thu 2 July, 6pm @ SuperAPI, Melbourne 🔗 meetup.com/elixir-melbourne/events/314557256/
Elixir Melbourne meetup, Thu, Jul 2, 2026, 6:00 PM | Meetup
Welcome to Elixir Melbourne's monthly meetup. Where we go over Elixir ecosystem news, listen to great talks, and socialise with other Elixir developers of all levels. Ther
meetup.com
🔥 Featured in June's Top 10 Bestsellers! 🔥 Discover the power of the Ash Framework, crafted by @sevensea.cat and @zachdaniel.dev . Perfect for developers who want to build scalable, robust Elixir apps. Dive into the details and grab your copy today: pragprog.com/titles/...
🚀 Such big improvement for Elixir ecosystem safety! Run `mix local.hex —force` to upgrade now.
OMG, latest version of Hex (`mix local.hex --force`) prints out CVEs that affect your packages any time you run `mix deps.get` 🤩 #ElixirLang
There is a DDoS vulnerability in Plug, which is a library used by Keila. If you're using any version older than Keila 0.30.2, please update as soon as possible. cna.erlef.org/cves/CVE-202... #elixirlang #cve #security
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
cna.erlef.org
We’re #hiring a Senior Software Engineer (Elixir) to join my team at the BBC. Come build scalable Elixir systems used by millions. Happy to answer any questions by DM. careers.bbc.co.uk/job/Senior-S... #ElixirLang #jobs
Senior Software Engineer
Senior Software Engineer
careers.bbc.co.uk
For anyone in Melbourne, I am going to give a talk about this one at next week's Elixir Melbourne meetup www.meetup.com/elixir-melbo...
Elixir Melbourne | Meetup
For anyone using or interested in Elixir (with a healthy side dose of Erlang). Welcome to Elixir coders of all levels: newbies; dabblers; everyday users; pros.For meeting admin, checkout Elixir M...
meetup.com
💥 Elixir PSA: update Plug *immediately* to the latest possible (1.20.1) The latest CVE makes it trivially easy to DOS a plug based server. cna.erlef.org/cves/CVE-202... This one is a doozy stay safe out there and keep your deps updated! #elixir-lang
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
cna.erlef.org
I'd recommend reading this, it's such a clear guide to how ATProto works. The fact that's all just *files* makes it obvious how the migration to eurosky was so simple, brings the prospect of self-hosting a bit closer. It also demonstrates the impossibility of a social media ban.
formats over apps
Exciting news: AtomVM has been accepted as an NLnet project through the NGI0 Commons Fund! “Towards AtomVM v1.0” will help us expand hardware support, polish APIs, and improve security, stability, and performance on the road to a rock-solid 1.0 release. Thank you to NLnet and NGI Zero for […]
Original post on fosstodon.org
fosstodon.org