Technical notes you can poke
Every post here comes with something you can drag, break, and rebuild — because the fastest way to understand something is to poke it until it misbehaves.

Writing
See all 13 →
Security
bcrypt Stops Reading at 72 Bytes and Does Not Tell You
Two passwords that look nothing alike can be the same password. The cut is measured in bytes, not characters, so it lands mid-character — and 24 Chinese characters is already the whole budget.

JavaScript
The Two ESM/CommonJS Errors Everyone Quotes Are Gone. One Nobody Mentions Is Not.
require() of an ESM module works now, and TypeScript no longer complains either. What still breaks is the dual package hazard — and it fails as instanceof returning false, not as an error.

Data tools
The pandas 3 Change That Will Break Your Code Does Not Warn You
Everyone is fixing SettingWithCopyWarning. That one never worked anyway. The write that works today and silently stops working under Copy-on-Write does not emit a warning in either version.