<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>DVNC Dev</title>
    <link>https://dvnc.dev</link>
    <description>Agentic engineering — build logs, agentic engineering decisions, agent failures, evals, observability, and what survives real users.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 16 Aug 2026 07:00:37 GMT</lastBuildDate>
    <atom:link href="https://dvnc.dev/feed.xml" rel="self" type="application/rss+xml"/>
    <generator>Next.js</generator>
    <managingEditor>hi@dvnc.dev (DVNC Dev)</managingEditor>
    <webMaster>hi@dvnc.dev (DVNC Dev)</webMaster>
    <copyright>Copyright 2026 DVNC Dev</copyright>
    <ttl>60</ttl>
    
    <item>
      <title><![CDATA[A Repository Readiness Score Is Not a Coding-Agent Release Gate]]></title>
      <link>https://dvnc.dev/blog/repository-readiness-score-coding-agent-release-gate</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/repository-readiness-score-coding-agent-release-gate</guid>
      <description><![CDATA[Use readiness scores for inventory. Gate coding-agent rollout on pinned runtime behavior, denied actions, merge controls, and full-tuple rollback.]]></description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[Repository Instructions Need a Release Process]]></title>
      <link>https://dvnc.dev/blog/repository-instructions-release-process</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/repository-instructions-release-process</guid>
      <description><![CDATA[Release AGENTS.md, CLAUDE.md, Copilot, and Gemini instructions through deterministic integrity and real-client compatibility gates.]]></description>
      <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[Your AGENTS.md Is Not a Policy Boundary]]></title>
      <link>https://dvnc.dev/blog/agents-md-not-policy-boundary</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/agents-md-not-policy-boundary</guid>
      <description><![CDATA[Repository instructions are context, not control. Test discovery, scope, compliance, and independent enforcement across five pinned coding-agent surfaces.]]></description>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[Treat AGENTS.md Like Code: A CI Regression Harness for Repository Instructions]]></title>
      <link>https://dvnc.dev/blog/agents-md-ci-regression-harness</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/agents-md-ci-regression-harness</guid>
      <description><![CDATA[Build a repo-specific CI harness for AGENTS.md and CLAUDE.md diffs with paired tasks, hard policy gates, repeated runs, and safe GitHub Actions.]]></description>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[Secure MCP for Coding Agents Across Laptops and CI]]></title>
      <link>https://dvnc.dev/blog/secure-mcp-coding-agents-laptops-ci</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/secure-mcp-coding-agents-laptops-ci</guid>
      <description><![CDATA[A concrete identity, tool-policy, approval, secret, and audit design for MCP servers used by coding agents on laptops and in CI.]]></description>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>mcp</category>
    </item>
    <item>
      <title><![CDATA[Shipment Exception Commander build log]]></title>
      <link>https://dvnc.dev/blog/shipment-exception-commander-build-log</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/shipment-exception-commander-build-log</guid>
      <description><![CDATA[A Claude Managed Agents workflow that scores synthetic shipment recoveries deterministically, challenges the recommendation, requires native human approval, and leaves one replay-safe receipt.]]></description>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>agents</category>
    </item>
    <item>
      <title><![CDATA[Put a Cost Fuse on Every Copilot CLI Run]]></title>
      <link>https://dvnc.dev/blog/copilot-cli-ai-credit-session-limits</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/copilot-cli-ai-credit-session-limits</guid>
      <description><![CDATA[Per-session AI credit limits cap one Copilot CLI or SDK run. Wire the soft stop, SDK events, and monthly budget layers without hiding failures.]]></description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[MCP Security Scanner Alerts Are Leads, Not Verdicts]]></title>
      <link>https://dvnc.dev/blog/mcp-security-scanner-alerts-leads-not-verdicts</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/mcp-security-scanner-alerts-leads-not-verdicts</guid>
      <description><![CDATA[A scanner cannot admit an MCP server. Pair alert triage with sandboxed runtime tests, capability policy, and drift checks.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>mcp</category>
    </item>
    <item>
      <title><![CDATA[A Two-Stage Upgrade Plan for Cloudflare Agents SDK and AI SDK 7]]></title>
      <link>https://dvnc.dev/blog/cloudflare-agents-sdk-ai-sdk-7-migration</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/cloudflare-agents-sdk-ai-sdk-7-migration</guid>
      <description><![CDATA[Cloudflare now supports AI SDK 6 and 7 side by side. This migration plan separates framework risk from SDK risk and keeps rollback clean.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>stack</category>
    </item>
    <item>
      <title><![CDATA[MCP Drops the Session: What Stateless Servers Change]]></title>
      <link>https://dvnc.dev/blog/mcp-stateless-servers-2026-07-28</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/mcp-stateless-servers-2026-07-28</guid>
      <description><![CDATA[MCP 2026-07-28 removes protocol sessions. Redesign routing, state, caching, tasks, identity, and traces without breaking legacy clients.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>mcp</category>
    </item>
    <item>
      <title><![CDATA[A Sandbox Is Not a Security Model for AI Coding Agents]]></title>
      <link>https://dvnc.dev/blog/ai-coding-agent-sandbox-security-model</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/ai-coding-agent-sandbox-security-model</guid>
      <description><![CDATA[The Hugging Face incident exposed the missing layers around agent sandboxes. Ship default-deny egress, brokered identity, and external control.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[OpenAI Agents SDK Sandbox Agents: The Production Isolation Playbook]]></title>
      <link>https://dvnc.dev/blog/openai-agents-sdk-sandbox-agents-production</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/openai-agents-sdk-sandbox-agents-production</guid>
      <description><![CDATA[Use OpenAI Agents SDK Sandbox Agents safely: choose the execution boundary, protect secrets, persist state, log runs, and gate production rollout.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>agents</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-52869: Patch the MCP Python SDK Session Boundary]]></title>
      <link>https://dvnc.dev/blog/mcp-python-sdk-cve-2026-52869-patch-guide</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/mcp-python-sdk-cve-2026-52869-patch-guide</guid>
      <description><![CDATA[Patch CVE-2026-52869 in the MCP Python SDK, identify affected HTTP transports, bind sessions to principals, and verify the fix before rollout.]]></description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>mcp</category>
    </item>
    <item>
      <title><![CDATA[GitHub Code Quality Review: The Production Rollout Rule]]></title>
      <link>https://dvnc.dev/blog/github-code-quality-production-review</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/github-code-quality-production-review</guid>
      <description><![CDATA[GitHub Code Quality costs $10 per active committer plus AI and compute. This review shows what it gates, what it misses, and how to pilot it safely.]]></description>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[Repo Gardener build log]]></title>
      <link>https://dvnc.dev/blog/repo-gardener-build-log</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/repo-gardener-build-log</guid>
      <description><![CDATA[A weekly Claude Managed Agents workflow that reproduces reported bugs, derives issue hygiene mechanically, remembers verified rulings, and never posts without maintainer approval.]]></description>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>agents</category>
    </item>
    <item>
      <title><![CDATA[Agent Evaluation Frameworks: How to Test AI Agents in Production]]></title>
      <link>https://dvnc.dev/blog/agent-evaluation-frameworks-production</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/agent-evaluation-frameworks-production</guid>
      <description><![CDATA[What an agent eval actually measures, which framework fits your stack (DeepEval, LangSmith, Braintrust, Phoenix), and the decision rule.]]></description>
      <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>evals-observability</category>
    </item>
    <item>
      <title><![CDATA[GitHub Copilot Code Review Custom Instructions for Production]]></title>
      <link>https://dvnc.dev/blog/github-copilot-code-review-custom-instructions</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/github-copilot-code-review-custom-instructions</guid>
      <description><![CDATA[Configure GitHub Copilot code review instructions for production with secure head-branch trust boundaries, evals, merge controls, and cost telemetry.]]></description>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[GitHub Copilot Security Review vs CodeQL: What Can Block a Merge?]]></title>
      <link>https://dvnc.dev/blog/github-copilot-security-review-vs-codeql</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/github-copilot-security-review-vs-codeql</guid>
      <description><![CDATA[Use Copilot /security-review for local triage and CodeQL rulesets for merge enforcement. Compare coverage, cost, evidence, and rollout controls.]]></description>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
    <item>
      <title><![CDATA[Upgrade Steward build log]]></title>
      <link>https://dvnc.dev/blog/upgrade-steward-build-log</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/upgrade-steward-build-log</guid>
      <description><![CDATA[An eve agent that researches breaking dependency changes, proves migrations in a sandbox, and binds pull request publication to human-approved evidence.]]></description>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>agents</category>
    </item>
    <item>
      <title><![CDATA[Claude Code Agent Teams Review: When Parallel Agents Pay Off]]></title>
      <link>https://dvnc.dev/blog/claude-code-agent-teams-production-review</link>
      <guid isPermaLink="true">https://dvnc.dev/blog/claude-code-agent-teams-production-review</guid>
      <description><![CDATA[Use Claude Code agent teams only for independent work. Set file ownership, plan review, hook gates, spend limits, and teardown before parallel runs.]]></description>
      <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
      <author>hi@dvnc.dev (Dev)</author>
      <category>coding</category>
    </item>
  </channel>
</rss>