tutorials
LiteLLM Vulnerability: 6 CVEs, a Supply Chain Attack, and the Fixes
LiteLLM has been hit by RCE, SQL injection, privilege escalation, and a PyPI supply chain attack in 2026. Here's every CVE, who's affected, and how to fix it.
tutorials
LiteLLM has been hit by RCE, SQL injection, privilege escalation, and a PyPI supply chain attack in 2026. Here's every CVE, who's affected, and how to fix it.
Rust vs Go compared with real benchmarks, salary data, and production use cases. Go for 80% of backends, Rust for the 20% where latency and memory matter.
Go 1.26 ships Green Tea GC by default (10-40% less overhead), experimental SIMD, runtime/secret, and a rewritten go fix. Hands-on code for each feature.
Gemini 3.5 Flash vs Claude Haiku 4.5 vs MAI-Code-1-Flash โ SWE-bench scores, token costs, and which flash model actually writes better code in 2026.
OpenCode (free, 75+ models) vs Claude Code ($20/mo, best SWE-bench) vs Cursor ($20/mo, IDE-native). Real pricing, benchmarks, and which one wins for your stack.
Long-form posts in your inbox roughly once a week โ research breakdowns, tutorials, comparisons, the occasional review. No tracking pixels, no growth-hacked subject lines.
Or grab the RSS feed โ same posts, no email needed.
I'm Maksim. By day I lead an engineering team at inDrive. After hours I ship side projects (PageBloom, NotesPilot, MyDevKit, startgaze) and write things up here when I learn something worth keeping.
The blog itself runs on an agentic publishing pipeline I built and rebuilt โ a slow-moving experiment in how much of a writer's workflow can be automated without losing the voice. It writes, fact-checks, and refreshes; I edit, decide, and publish.