- 1 hour 54 minutesForking Cal.com to closed source (Interview)
This week I’m joined by Peer Richelsen, co-founder of Cal.com. What if the majority of open source repositories are already compromised and we just don’t know it yet? That’s the theory Peer brings to the table this week. We dig into how AI has flattened the knowledge graph to the point that a 16-year-old can vibe hack a power station just as easily as their mom can vibe code an iOS app, why the reporting culture that has kept open source safe all these years is collapsing under AI generated noise, Cal.com’s move to fork its own codebase and take the sensitive parts private, and the eye opening reality that shipping “$1 of AI tokens for pennies on the dollar” is now a common startup business model.
Changelog++ members save 10 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default.
- Buildkite – You deserve better CI. Buildkite is engineered for frontier scale and trusted by the teams setting the pace.
- WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
- Peer Richelsen – Website, GitHub, LinkedIn, X
- Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
Editorial disclosure: Adam states in the episode that he is a small seed investor in Cal.com.
Cal.com and Cal.diy
- Cal.com is going closed source — here’s why
- Moving to closed-source: the technical changes
- Cal.diy on GitHub
- Cal.diy contributing guide
- Cal.com
Open source, agents, and contribution workflows
- Swamp Club
- OpenClaw
- Mitchell Hashimoto: Vibing a Non-Trivial Ghostty Feature
- GitHub Agentic Workflows
- GitHub issue-intent, rationale, confidence, and approvals
AI-assisted security
- Mozilla: Hardening Firefox with Anthropic’s Red Team
- Mozilla: The zero-days are numbered
- Anthropic and Mozilla’s Firefox security collaboration
- Next.js security advisories
- LiteLLM issue: malicious package and credential stealer
Something missing or broken? PRs welcome!
3 September 2026, 8:00 pm - 1 hour 42 minutesPostgres at PlanetScale (Interview)
Sam Lambert is back after 4 years and he does not hold back! We cover $5 PlanetScale Postgres, the Neki “do-over” of Vitess, agents shipping schema changes through deploy requests, rolling back a 500TB table in seconds, and the very real question of whether to open source any of it. Plus: why he thinks the sleeping, lazy giants should be broken up.
Changelog++ members save 9 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Buildkite – You deserve better CI. Buildkite is engineered for frontier scale and trusted by the teams setting the pace.
- WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com
- Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default.
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
Show Notes:
PlanetScale products and features
- PlanetScale Postgres
- PlanetScale Metal
- Neki
- Vitess
- Database branching
- Non-blocking schema changes
- Deploy requests
- Schema reverts
- Database Traffic Control
- Query Insights
- PlanetScale MCP server
- PlanetScale Skills
- Benchmarking Postgres
Databases and infrastructure
- PostgreSQL
- MySQL
- NVM Express (NVMe)
- Amazon Aurora PostgreSQL Limitless Database
- Amazon Web Services
- Google Cloud
Companies and tools
Talks and prior episodes
- Sam Lambert: Agents and Infrastructure — Cursor Compile 2026
- Making the last database you’ll ever need — Founders Talk #85
- Bringing Vitess to Postgres — Changelog Interviews #651
Something missing or broken? PRs welcome!
25 August 2026, 7:00 pm - 2 hours 6 minutesCanary tokens and digital tripwires (Interview)
Haroon Meer is back! Haroon is the Founder of Thinkst, the ~50-person bootstrapped company behind Canary and Canarytokens — honeypots and tripwires you sprinkle inside your network and forget about until an attacker touches one. We talk about the AWS API key token attackers just can’t resist trying, the real credit card token backed by an actual bank partnership, Breadcrumbs (their brand-new feature that leads intruders straight to your canaries), a live demo where a hardware Canary becomes a Synology NAS in one click, and how a company with zero outbound sales and no price increase in ten years quietly passed $22.5 million in ARR.
Changelog++ members get a bonus 4 minutes at the end of this episode and zero ads. Join today!
Sponsors:
- Buildkite – You deserve better CI. Buildkite is engineered for frontier scale and trusted by the teams setting the pace.
- WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com
Featuring:
Show Notes:
- Thinkst
- Thinkst Canary
- Thinkst Canary Security
- Canary Tokens
- Canary Tokens Docs
- Canary Tokens on GitHub
- OpenCanary on GitHub
- OpenCanary Docs
- TechCrunch: A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding
- Grafana Labs: Canary Tokens, the unsung heroes of security
- Canary Love
Something missing or broken? PRs welcome!
21 July 2026, 7:00 pm - 1 hour 46 minutesFrom open source hits to OpenAI (Interview)
This week I’m talking with Max Stoiber, currently working on ChatGPT’s plugin directory and app platform at OpenAI. We discuss the hundreds of open source projects nobody remembers alongside the big ones like react-boilerplate and styled-components, how Spectrum became part of GitHub and eventually helped shape GitHub Discussions, the founder growth that came from building Stellate, the GraphQL cache that turned into a dual acquisition by Shopify and The Guild, and why ChatGPT apps feel like a new surface for software.
Changelog++ members save 9 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default.
- WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com
- Notion – Custom Agents that automate the busywork so your team can focus on real work. Try them free at notion.com/changelog
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
Show Notes:
Featured
- Max Stoiber
- Max Stoiber on GitHub
- OpenAI
- ChatGPT
- Developers can now submit apps to ChatGPT
- ChatGPT Developer mode
- OpenAI Apps SDK examples
- OpenAI Apps SDK UI
- Model Context Protocol
Max’s open source and community path
- styled-components
- styled-components on GitHub
- react-boilerplate
- Max’s open source projects
- Spec.fm
- GitHub acquires Spectrum
- GitHub Discussions
- Slack
- Circle
GraphQL and Stellate
- Stellate
- Announcing Stellate, the CDN for GraphQL APIs
- GraphCDN is now Stellate and we’ve raised $30M
- The Guild acquires Stellate
- GraphQL
- GraphQL Hive
- GraphQL Yoga
- GraphiQL
- Firebase
- Vercel
- RethinkDB
- Apollo Client
- urql
- DataLoader
Shopify and storefronts
- Shopify
- Shopify Liquid reference
- Shopify themes
- Horizon: 10 new free themes by Shopify
- Horizon documentation
- Shopify Agentic Storefronts
ChatGPT apps and MCP
- Building MCP servers for ChatGPT and API integrations
- Build with the Apps SDK
- Apps in ChatGPT
- MCP Apps overview
- Zillow
- Expedia
Leadership and founder references
Tools, platforms, and companies mentioned
Something missing or broken? PRs welcome!
5 June 2026, 7:00 pm - 1 hour 54 minutesMCP on Code Mode (Interview)
This week I’m talking with Matt Carey about Code Mode and how most of us have been thinking about MCP all wrong. Matt works on the Agents SDK and MCP at Cloudflare — we discuss how server-side Code Mode lets one MCP server expose all ~2,500 Cloudflare API endpoints in about 1,000 tokens of context, the dynamic Worker loader that runs model-written code safely in a V8 isolate, Matt’s own workflow with Claude, where memory fits into the future of agents, and his Zaggy git wrapper that keeps agents from force-pushing his repos.
Changelog++ members save 9 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default.
- Tailscale – Adam loves Tailscale! Easy, secure, identity-based access to anything. Tailscale deploys quickly and enables Zero Trust access to any resource on your network. From CI/CD runners across multi-cloud environments, to SaaS tools and infrastructure, Tailscale connects it all, seamlessly.
- RWX – CI/CD platform for high velocity teams. When agents help developers write code in minutes, validation becomes your bottleneck. RWX gives agents programmatic control, sub-second cached builds, and semantic outputs they can act on. No commit required. Just iterate until CI passes, then push.
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
Show Notes:
Featured
- Matt Carey on the Cloudflare blog
- You’ve Been a Bad Agent
- Cloudflare
- Code Mode: give agents an entire API in 1,000 tokens
- Code Mode: the better way to use MCP
- Cloudflare MCP Server
- Cloudflare Agents SDK
- Cloudflare Agents SDK on GitHub
Cloudflare platform
MCP and code-mode references
- Model Context Protocol
- Introducing the Model Context Protocol
- Code execution with MCP
- CodeAct paper
- GitHub MCP Server
- Datadog MCP Server
- Pydantic Monty
Coding agents and tools
Agent memory and personal AI
Homelab and infrastructure
Something missing or broken? PRs welcome!
15 May 2026, 9:00 pm - 2 hours 26 minutesAutomation at the speed of Swamp (Friends)
This week I’m talking with Adam Jacob, founder of System Initiative and creator of Swamp, about what happens when AI agents change the entire shape of software development. We discuss how he went from an 18-person team down to five and shipped Swamp 900 times in four weeks, why he brought User Acceptance Testing (UAT) testing back from the 90s, why software architecture (and domain-driven design) suddenly matters more than knowing how to write code, the live demo where I pointed Swamp at my Proxmox box and watched it write its own automation (blew my mind!!), and why he’ll never accept a pull request to Swamp, ever.
Changelog++ members save 9 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default.
- Tailscale – Adam loves Tailscale! Easy, secure, identity-based access to anything. Tailscale deploys quickly and enables Zero Trust access to any resource on your network. From CI/CD runners across multi-cloud environments, to SaaS tools and infrastructure, Tailscale connects it all, seamlessly.
- RWX – CI/CD platform for high velocity teams. When agents help developers write code in minutes, validation becomes your bottleneck. RWX gives agents programmatic control, sub-second cached builds, and semantic outputs they can act on. No commit required. Just iterate until CI passes, then push.
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
Show Notes:
Featured
- Swamp Club
- Swamp manual
- Swamp extensions
- Swamp leaderboard
- Swamp on GitHub
- Swamp extensions on GitHub
- System Initiative
- System Initiative on GitHub
AI coding tools
Infrastructure and automation
- Chef Infra
- Proxmox VE
- QEMU
- Grafana
- Honeycomb
- Better Auth
- TypeScript
- Talos Linux
- Ubiquiti
- DigitalOcean
- Hetzner Cloud
- Amazon S3
- Incus
- Kubernetes
Developer platforms and companies
Related Changelog episodes
- Rebuilding DevOps from the ground up
- From Chef to System Initiative
- From Chef to System Initiative (remastered)
- The war for the soul of open source
- OSCON
Something missing or broken? PRs welcome!
13 May 2026, 9:00 pm - 8 minutes 33 secondsBitwarden CLI compromised (News)
Bitwarden’s CLI got hit by the Checkmarx supply-chain campaign, TypeScript 7.0 beta lands with the Go-rewritten compiler running ~10x faster than 6.0, and pgBackRest lost its maintainer of thirteen years leaving anyone running production Postgres with a real dependency-trust task this week. We’ve also got Ubuntu 26.04 LTS shipping with TPM-backed full-disk encryption, and Matz dropping Spinel as an AOT path that takes Ruby to native binaries. This week was a good reminder that the tools we depend on are all moving at once. Security, performance, and maintenance aren’t isolated threads.
Changelog++ members save 2 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Coder.com – Secure environments where devs and agents work in parallel. Open by design. Secure by default.
Featuring:
29 April 2026, 3:00 pm - 1 hour 36 minutesExploring with agents (Interview)
Today on the show I’m talking with Amelia Wattenberger — designer, data-viz veteran, ex-GitHub Next, and now designing Intent at Augment Code. What if the last 30% of any software project is about to become the hardest part you’ve ever done? That’s the argument Amelia is making today. We discuss the identity crisis developers are having as agents take over the keyboard, the epic redesign of developer tooling in this agent-first world, the arc from autocomplete to chat to CLI back to UI, why Intent treats a workspace as their core primitive not a chat thread, the tradeoffs between one-worktree-per-agent vs. one-worktree-per-task, and why she thinks prototyping just got easier but finishing got harder.
Changelog++ members save 8 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com
- NordLayer – Toggle-ready network security for modern businesses. Get an exclusive offer: up to 22% off NordLayer yearly plans plus 10% on top with the coupon code changelog-10-NORDLAYER. Try it risk-free with a 14-day money-back guarantee at nordlayer.com/thechangelog
- RWX – CI/CD platform for high velocity teams. When agents help developers write code in minutes, validation becomes your bottleneck. RWX gives agents programmatic control, sub-second cached builds, and semantic outputs they can act on. No commit required. Just iterate until CI passes, then push.
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
Show Notes:
- GitHub Copilot — the launch that kicked off this era (mentioned ~12×)
- GitHub Next — GitHub’s R&D team; where Amelia worked
- GitHub Actions
- Intent — Augment Code’s new workspace-first agent app that Amelia is building (the core product discussion)
- Augie — Augment’s agent
- Claude Code
- Codex
- Notion AI
- VS Code
- Incus — system-level containers/VMs; the Canonical LXD fork
- Proxmox — Adam’s hypervisor platform for the sandbox
- ZFS — storage layer Incus is built on
- Bun — JavaScript runtime
- Rust
- Go
- Ruby on Rails
- SvelteKit
- Svelte
- TypeScript
- TanStack Start
Something missing or broken? PRs welcome!
24 April 2026, 8:00 pm - 10 minutes 48 secondsAstral has been acquired by OpenAI (News)
Astral is joining OpenAI, which says a lot about where the center of gravity is moving for developer tools, LiteLLM got hit by a nasty supply-chain attack, and OpenCode blew up as the latest serious open source swing at the coding-agent stack. We’ve also got Rust doing a very public reality check on its own pain points, WorkOS pushing AuthKit into CLI auth, Ryan Lizza using AI to build an open source TurboTax alternative, and a fresh httpx fork that turns open source maintenance drama into a real dependency story. If nothing else, this week was a good reminder that tools, trust, and control all move together.
Changelog++ members save 1 minute on this episode because they made the ads disappear. Join today!
Sponsors:
- WorkOS – Auth for CLI with AuthKit from WorkOS — Bring secure browser-based login to your terminal apps using the OAuth Device Flow, with the same polished AuthKit experience plus SSO, MFA, and passkeys. Learn more at WorkOS.com and AuthKit.com
Featuring:
27 March 2026, 8:00 pm - 1 hour 42 minutesFrom Tailnet to platform (Interview)
Adam talks with Tailscale co-founder and Chief Strategy Officer David Carney about where Tailscale is headed next: TSIDP, TSNet, multiple tailnets, and Aperture. They get into clickless auth (via TSIDP), TSNet apps, multiple tailnets for isolation and control, and Aperture, Tailscale’s private AI gateway for API key management, observability, and agent security.
Changelog++ members save 8 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Augment Code – Adam loves “Auggie” – Augment Code’s CLI that brings Augment’s context engine and powerful AI reasoning anywhere your code goes. From building alongside you in the terminal to any part of your development workflow.
- NordLayer – Toggle-ready network security for modern businesses. Get an exclusive offer: up to 22% off NordLayer yearly plans plus 10% on top with the coupon code changelog-10-NORDLAYER. Try it risk-free with a 14-day money-back guarantee at nordlayer.com/thechangelog
- Squarespace – Turn your expertise into a business with the all-in-one platform for websites, services, and getting paid. Use code CHANGELOG to save 10% on your first website purchase.
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
Featuring:
Show Notes:
Send an email to David ~> [email protected]
Mentioned in this episode
- Tailscale
- Aperture by Tailscale
- TSIDP
- TSNet
- Multiple tailnets
- Tailnet policy file syntax
- Model Context Protocol (MCP)
- MCP specification
- Proxmox VE
- Incus
- OIDC / OpenID Connect
- OAuth 2.0
- Okta
- Microsoft Entra ID
- Google Workspace
- Keycloak
- Salesforce
- Anthropic
- Amazon Bedrock
- Oso
- Cerbos
- Go
- GopherCon
- Simon Willison
Something missing or broken? PRs welcome!
11 March 2026, 8:00 pm - 5 minutes 10 secondsBig change brings big change (News)
This week’s been wild — Iran bombed AWS data centers to take down Claude, OpenAI dropped GPT-5.4 (and it’s seriously good for coding), and living brain cells are literally playing DOOM. We’ve also got a heartfelt take on what it feels like to be a 10x engineer in the age of AI, plus some cool new tools like Handy for speech-to-text and web haptics. Oh, and new MacBook Pros with M5 Pro and M5 Max are up for pre-order. Try not to impulse buy (or do).
Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!
Sponsors:
- Sonatype – Develop software fearlessly. Find out how at sonatype.com.
Featuring:
10 March 2026, 8:00 pm - More Episodes? Get the App