A product discussed on AI Engineer.

Building ambitious software — Jonathan Kelley, Dioxus Labs & Cognition
Sep 11, 2026 · 19:14
Jonathan Kelley, founder of Dioxus Labs, whose cross-platform Rust app framework now has nearly 37,000 GitHub stars and an estimated 200 million end users and was acquired by Cognition, argues that AI coding agents have made code cheap but quality remains the scarce resource, so architecture now takes most engineering time. He traces Dioxus's five-year effort building everything from scratch, including the Blitz rendering engine with a browser-grade CSS engine lifted from Firefox and the Subsecond hot reload engine that patches running native code in about 100 milliseconds. When agents got good at Rust, his team maxed out their Claude Code subscriptions and produced tens of thousands of lines that mostly never cleared the merge bar, a failure mode he calls becoming a slop cannon. He credits agents for deeply integrated Kotlin and Swift build plugins shipped in two to three weeks, release checklists, backports, and documentation accuracy, while noting they write tests for any API but rarely the right ones, though they excel at fuzzing harnesses. Rust's learning curve, once fought, is now a feature because agents absorb the borrow checker and edge cases.

Using LLMs to Secure Source Code — Eugene Yan, Anthropic
Jul 17, 2026 · 21:30
Eugene Yan of Anthropic details how frontier LLMs like Claude are reshaping software security, citing Mozilla's 20x surge in monthly fixes (to 400 in April 2025, two-thirds credited to Claude) and Anthropic's own scan of 1,000+ open source repos that uncovered 6,200 high/critical issues, 1,600 reported, and about 100 patched upstream. He argues that finding vulnerabilities is no longer the hard part; the bottleneck has moved to verification, triage, and patching. Yan outlines a six-step workflow: a written threat model (boosts true positive rate to 90%), an isolated sandbox for reproducibility, discovery optimizing for recall, a separate adversarial verification agent that detonates exploits in fresh containers, triage to prioritize engineer attention, and patching that closes the loop so bugs cannot recur. His advice: start this week on open source dependencies, keep hands on the wheel before automating, and recognize that scanning was never the bottleneck.
Powered by PodHood