BLOGSEM Devs
Articles on software development, web and technology
Cyber Resilience Act: under three weeks to 11 September
In July we explained why the CRA's first binding deadline is 11 September 2026, not 2027. Now time is up: from 11 September the 24 and 72-hour clocks for exploited vulnerabilities start. The final checklist, no theory.
Next.js flags a critical patch for 26 August: get ready now
Vercel did something rare and right: it gave advance notice that a patch for a critical Next.js vulnerability lands on 26 August, in versions 16.3.3 and 15.5.24. The details come that day. What to do in the days before so you do not eat the exploitation window.
The LLM price floor just dropped: time to redesign your tiering
In two weeks of August, Anthropic made Sonnet 5's price permanent at 2 and 10 dollars per million tokens, updated Opus 5, OpenAI restructured its lineup into durable tiers and Google shipped Gemini 3.7 Flash. If you run an AI feature in production, your cost tiering is already stale.
RAMpocalypse: the memory price spike was never about Hetzner
In July we framed Hetzner's rise as one provider's choice. By August it is clearly the symptom: OVHcloud confirms 5-10%, the hyperscalers will follow in the second half, and DRAM costs are up to 500% higher than September 2025. What to do when the problem is silicon, not a price list.
The worm that infected keyv: inside August's npm supply chain attack
On 4 August the GitHub account of the keyv maintainer was compromised, 127 million weekly downloads, and within two days a self-propagating worm poisoned over 1,300 package versions. You do not need to use keyv to be hit. What we checked across client pipelines.
The AI Act's Article 50 is live: what actually changed on 2 August
In July it was a deadline to prepare for, now it is applicable law: from 2 August chatbots, generated content and deepfakes must be disclosed, and on 31 July the Commission confirmed enforcement would begin. What we fixed across client projects in half a day.
Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026
The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.
Your AI vendor can be switched off by a government you do not vote for
On 12 June a US export-control order switched off a frontier model for everyone, everywhere, for eighteen days. What that means for a European SME with a feature in production, and how you actually defend against it.
The AI Act omnibus is law: what slipped and what starts on 2 August
The Digital Omnibus took effect on 27 July and pushes the high-risk rules out to December 2027. Article 50 did not move: from 2 August 2026 chatbots, generated content and deepfakes must be disclosed, and in Italy ACN does the enforcing.
WP2Shell: the WordPress flaw that needs no login
On 17 July WordPress closed WP2Shell, a two-CVE chain giving unauthenticated code execution on a clean install, and the first attempts landed within hours. What we checked across the sites we maintain, and why patched does not mean clean.
Behind the scenes at Kappa FuturFestival 2026: 80 TB in three days and an all-flash storage
Twelve editors, one storage, more than 80 TB of footage in three days. At Kappa FuturFestival 2026 in Turin SEM Devs ran the media crew's data management on an all-flash NVMe hot storage at 40 Gbit over fiber, mirrored onto dual NAS.
TypeScript 7.0: the Go compiler and the end of slow builds
The Go native compiler landed on 8 July: full builds 8 to 12 times faster and the first error in the editor after 1.3 seconds instead of 17.5. The benchmarks, the breaking changes, and how to schedule the migration.
Hetzner doubles CCX and CPX prices: what to do when cheap hosting stops being cheap
The fourth pricing move in a year: Hetzner's CCX and CPX lines rise up to 2.75x, and a single rescale moves your instance onto the new list. What we changed on our own and our clients' infrastructure, and why switching provider does not fix it.
Observability without an enterprise budget: a stack for small teams
Logs, metrics and traces aren't a big-company luxury. Here's the cheap, lightweight stack we use to understand what happens in production.
EU AI Act for SMEs: what kicks in during 2026 and what to do now
The EU AI regulation phases in over time. Many SMEs assume it doesn't touch them. Often it does. Here's what matters if you build AI features.
Passkeys in 2026: can we really retire the password?
Synced across devices, pushed by Apple, Google and Microsoft. Are passkeys ready for serious login? What we learned shipping them.
Coding with AI agents in 2026: how our workflow actually changed
It's no longer autocomplete. Agents read the repo, open PRs, fix tests. But the bottleneck moved, it didn't vanish.
Tailwind CSS v4 in production: is the new engine worth the migration?
The Oxide engine, CSS-first config, faster builds. We migrated three real projects. What we gained and where it hurt.
Behind the scenes at Nameless 2026: data management and IT for the media crew
Behind the clips you scroll online there's a problem the crowd never sees: the data. At Nameless Music Festival 2026 SEM Devs handled ingest, redundant dual-NAS storage and the network that let the whole crew edit straight off the storage.
INP one year on: how we keep interaction under 200ms
Interaction to Next Paint replaced FID as the responsiveness metric. A year later we know what actually moves the needle and what is theater.
European sovereign cloud in 2026: realism, not ideology
Hetzner, OVH, Aruba and new EU players grow quietly. Between Cloud Act, GDPR and real pricing, the choice gets pragmatic.
PostgreSQL 17 in production: the features we actually use
Since 17 hit LTS we ran it on our largest projects. What the upgrade was worth and what stayed on paper.
AI agents for SMEs in mid-2026: what really works and what doesn't
A year after the autonomous-agents season, the operational level has risen. But winning use cases are few and well-defined.
Next.js 16 and React 19 six months in: what we actually used
Server Actions taking center stage, partial prerendering finally stable, and a build pipeline making less noise. Verdict in May 2026.
EAA eleven months in: what really changed on Italian sites
The European Accessibility Act has been in force since June 28, 2025. In May 2026 the picture is clearer: few fines, many audits, a few surprises.
Web performance in 2026: INP has grown, LCP has not
Early 2026 Chrome UX Report data is clear: INP is the metric separating fast sites from slow ones. What it takes to stay under 200ms.
Kubernetes for SMEs in 2026: still a sensible choice?
After five years of hype, Kubernetes in Italian SMEs is rare. Is that failure or a correct choice?
Web Components: rebirth or slow death?
Lit, Shoelace, micro-frontends. Are Web Components a serious choice in 2026? Our experience on three cases.
Claude Code: The Evolution of a Music Recognition Tool
Discover how Claude Code evolved from a command-line tool to a sophisticated product with a tech stack including TypeScript.
GSD: The Meta-Prompting and Context Engineering System for AI Coding Assistants
Discover how GSD can help you manage context and streamline complex project workflows in software development
OpenClaw, Nanoclaw, Picoclaw: What are the Differences?
Discover the fundamental differences between OpenClaw, Nanoclaw, and Picoclaw, and how these technologies can impact your software development
How OpenAI Codex Works: A Technical Guide
Discover how OpenAI Codex uses artificial intelligence to generate high-quality code and improve developer productivity
PostgreSQL 17 in production: three features we liked
Postgres 17 shipped in September 2024. Six months after upgrading our projects, three things that really matter.
Vercel Marketplace and AI integration: what's nice, what's not
Vercel revamped the Marketplace integrating AI assistants for setup, debug, deploy. What really works.
VS Code built-in AI: do we still need Copilot?
Microsoft built native AI into VS Code. For Copilot subscribers, is it still worth $19/month? Field test.
Edge functions in 2026: who's really winning
Cloudflare Workers, Vercel Edge, Deno Deploy, Bun. Four philosophies. What we pick in 2026 for edge-native projects.
NIS3: what's moving in the EU for the next cybersecurity wave
Informal EU Parliament discussions on NIS3. Nothing official, many signals. What they reveal.
One year of NIS2: what we actually learned implementing it
Twelve months after Italian Decree 138/2024 came into force, we walked seven companies through the path. Five things that make the difference, and three that can be skipped.
AI agents in customer operations: 2026's first reckoning
After a year of agents on tickets, lead routing and qualification, we know where they pay off and where they ruin things. Three patterns that work, three that don't.
2025 in 7 tech trends that touched our projects
Agentic AI, edge native, prompt cache, real NIS2, SBOM, ARM, ESG. What really entered, what stayed noise.
Bun 2.0 stable: what really changes, and why we're trying it in production
Two years after 1.0, Bun reaches 2.0 with Node ≥ 22 parity, native deploy and polished tooling.
pgAdmin alternatives in 2025: TablePlus, Beekeeper, DataGrip
pgAdmin gets the job done. But for those who work with databases daily, much more pleasant alternatives exist.
Custom ERP or off-the-shelf: the right question to ask
Build a custom ERP from scratch or adopt an off-the-shelf one? The answer is not ideological. It is a calculation with three variables too many clients forget.
Dependency security: SBOM, Trivy, Snyk and what we learned
Knowing what's inside your software is now mandatory, not optional. Three tools to start seriously.
TanStack Start: the new Next.js alternative, is it worth it?
Type-safe routing, server functions, full SSR. TanStack Start tries to do to Next.js what Next.js did to Create React App.
Claude 4.5 and prompt caching savings: real numbers in production
Anthropic shipped Claude 4.5 with more efficient prompt caching. For teams running AI assistants in production, savings are real.
Zero-trust for SMEs: how it really gets done, without snake oil
Zero-trust is the most overused term in cybersecurity. For an SME, what does it actually mean, where do you start, and what does it cost.
AI video generation in business: Sora, Veo, and what's actually useful
Mature AI video models in 2025. For marketing, training or product: where they pay off and where not yet.
Inngest vs BullMQ: which queue for Italian projects in 2025
Serverless job processing or self-hosted Redis: two philosophies. When we pick which, and why.
Ransomware-safe backups: what we changed after the 2024-25 wave
Mutated snapshots, deleted online copies, backup heirs. Three lessons that reshaped our standard setup.
WCAG 2.2 AA: real audits on 6 Italian e-commerces, the 7 things always failing
The European Accessibility Act is live. Across six audits, seven recurring issues that block AA.
Headless WordPress in 2025: still alive? Yes, but differently
Two years ago we were sceptical. Today headless WP is a more mature practice with better tools and a clearer scope. What changed and what did not.
From NextAuth.js to Auth.js v5: the migration explained
Auth.js v5 went stable. What changes, how to migrate, and why we waited.
Hetzner ARM Ampere: field tests, is it worth it?
New ARM instances on Hetzner Cloud. Performance, Node.js compatibility, containers, price: real numbers.
Stripe vs PayPal vs Satispay: pick matrix for Italian e-commerce in 2025
Three players, three audiences. The matrix we use to recommend the right payment mix for our clients.
Synology vs Ugreen NAS: which one for a production studio
Synology is still the reference, Ugreen is the direct new contender. Which to pick today for a video studio, a photo production or a small office.
ESG software for Italian SMEs: what's really needed in 2025
CSRD widens its reach, sustainability demands flow from the supply chain. What we built (and bought) for six clients.
Cursor, Copilot, Claude Code: three philosophies on day-to-day code
Two years of AI assistance in our daily work. Which tool we use for what, where each one shines, and why the future is not single-tool.
WordPress 6.8: zoom out, stronger pattern library, what to fix first
WordPress' latest major polishes the Site Editor. What landed well, what breaks, what to test in staging.
pgvector vs dedicated vector DBs: for Italian cases, is Postgres enough?
Pinecone, Qdrant, Weaviate. Or just pgvector. The real thresholds where dedicated databases win.
React Server Components in production: 18 months later, what we've learned
After a year and a half of Server Components in real projects, we have ten pages of lessons. The four that changed how we think about web apps.
Self-hosted analytics in 2025: Plausible, Umami, Pirsch
Three GDPR-friendly alternatives to Google Analytics. Which we pick for clients, and what self-hosting actually costs.
GitHub Copilot Workspace: is it worth $39/month? Yes and no.
Built to handle whole tasks, not single lines. After a month on real projects, where it shines and where it doesn't.
Cloudflare Workers: the real 10ms CPU limit and how to live with it
Workers are powerful but strict. 10ms CPU per request — not wall time — disciplines how you write code.
Tailwind CSS v4: Oxide engine, CSS-first and no more JavaScript config
On January 22 Tailwind v4 went stable. Faster builds, CSS configuration, native container queries. Here is why we are migrating our projects.
Postgres zero-downtime migrations: the patterns we actually use
Adding columns, renaming, changing types: all without service interruption. Four techniques we apply.
React 19 in production: first two months, three things we liked
Stable in December 2024, in production by January. useActionState, native form actions, useOptimistic: what really changes.
The 2024 tech year in five things: the ones we actually used
No top 100 list. The five innovations that entered our real projects this year and stayed.
MCP, the protocol that changes how we use AI inside IDEs
In November Anthropic announced the Model Context Protocol. It looks like a technical detail; it is a paradigm shift for anyone coding with AI assistants.
PWA on iOS in EU after the DMA: where we landed
From February's block to Apple's reversal. State of PWAs on iPhone in Europe, with what works and what does not.
AI Act: what the first general-purpose model compliance looks like
The first rules on foundation models kick in May 2025. What providers, integrators and end-customers must do.
Next.js 15 and React 19: what changes (and what breaks) in real projects
Async Request APIs, less aggressive caching, React Compiler in beta. Next.js 15 is the most impactful release since 13. What to adopt and what to delay.
Drizzle ORM vs Prisma: the choice we make on new projects
Prisma stays the default, Drizzle has gained ground. When we pick which in 2024.
NIS2 in Italy: October 17 is here, and Decree 138/2024 is reality
Italian Decree 138/2024 is now in the Official Gazette. What it operationally means for companies in the NIS2 scope, and what to do in the next 90 days.
Astro 5 and the Content Layer: content becomes data
Astro 5 unifies content collections, external CMSes and APIs. For content-heavy sites, the missing leap.
WCAG 2.2: AA is not optional (and not hard, either)
WCAG 2.2 has been official since October 2023. With the European Accessibility Act landing in June 2025, AA is a baseline, not a target. Here is what changes.
Headless commerce 2024: Shopify Hydrogen, WooCommerce or Medusa?
Three different philosophies for decoupling e-commerce frontend and backend. When each one fits, and for whom.
AWS S3 + EventBridge: event-driven pipelines without Lambda spaghetti
Reacting to S3 file arrivals without piling up 30 Lambda triggers. EventBridge is the answer — if you can model it.
Tailscale: the VPN that actually works for distributed teams
No OpenVPN, no manual WireGuard. Tailscale puts you on a private mesh in 90 seconds. What changed after we adopted it.
WordPress 6.6: mature block themes and what changes for site builders
Section styles, overrides in synced patterns, view transitions: WordPress 6.6 is the most solid block editor release to date. Here is what is worth adopting.
GitHub Actions: seven patterns for genuinely fast pipelines
Clean cache, parallel jobs, smart matrix. From 14 minutes down to 3 on a real build of ours.
On-site data management at festivals: what it is, why it matters
Dozens of photographers, hours of video to ingest, social teams posting live. How to keep a major festival's media pipeline running without losing a single frame.
WordPress 6.5: the Block Bindings API is the missing piece
Connect blocks to custom fields without writing PHP. For editorial site builders, a small revolution.
WooCommerce and ERP: integrating e-commerce and back-office without losing your mind
Catalogue, orders, warehouse, invoicing: the sore spot of every Italian e-commerce. The integration patterns we actually use in production.
pgvector and RAG: our first client project with AI on internal data
Semantic document search across 8,000 internal documents. Postgres + pgvector + embeddings: lessons learned.
Hetzner, Vercel, AWS: where to host your web app in 2024
Three different philosophies, three different price brackets. Which one we pick for our clients, how we move between them and what each really costs.
TanStack Query 5 vs SWR vs RTK Query: which for what in 2024
Three data-fetching libraries, three philosophies. When we pick what, and why TanStack Query is almost always our default.
Business networks with Ubiquiti UniFi: a formula that works for SMEs
Managed switches, Wi-Fi 6/7 APs, centralised controller. Why we keep picking UniFi for offices, studios and production sites with under 200 devices.
Sanity CMS in production: 6 months in, what we would redo and what not
Customizable Studio, GROQ, real-time collaboration. What sold us and the three places we sweated.
Prisma 5.10 and relationLoadStrategy: a join in the right place
Prisma 5.10 brings relationLoadStrategy, a preview flag that lets you pick between subquery and join for relations. For anyone fighting hidden N+1, it is fresh air.
Synology DSM 7.2 and Docker: what really works (and what does not)
Container Manager replaced Docker. What we learned running 12 stacks on DSM across our clients.
NIS2: the new EU cybersecurity directive (and why it hits SMEs too)
The NIS2 directive lands in Italy in 2024. The scope is far wider than NIS1: who is affected, what to do, and where to start.
EU AI Act: what the December deal actually contains
After 38 hours of trilogue, on December 8 2023 the political deal landed. What changes for AI builders and users in Europe.
Cookie banners and the Italian DPA: what to fix before 2024
The Italian DPA is again going after non-compliant cookie banners. Between dark patterns, scroll-as-consent and Google Analytics, here are the rules we apply to every client site.
Bun 1.0 in dev: is it ready to replace Node? Almost.
Test runner, package manager, runtime: Bun 1.0 is already faster than Node at everything. Is that enough to ship it?
The 3-2-1 backup rule: from theory to practice in SMEs
Three copies, two different media, one offsite. A thirty-year-old rule still ignored by too many Italian businesses. Here is how we actually deploy it on site.
Cloudflare R2 vs AWS S3: the bill, the benchmarks, and when the jump makes sense
R2 promises zero egress fees. For anyone running S3 + CDN, is the jump worth it? Real numbers from a client.
Next.js 14: stable Server Actions and Partial Prerendering on the horizon
Vercel shipped Next.js 14 at Next.js Conf in San Francisco: no new APIs but Server Actions go stable and Partial Prerendering lands in preview.
Tailwind: how many megabytes of JavaScript do we really save?
Tailwind kills CSS-in-JS and a chunk of JS runtime with it. Let us quantify the saving on three real projects.
TypeScript 5.2: the `using` keyword and the end of endless try/finally
TypeScript 5.2 brings `using` and `await using`, mirroring the ECMAScript Explicit Resource Management proposal. A small revolution for anyone juggling files, connections and locks.
Lighthouse 11 and the new Core Web Vitals: what changes for optimisers
PWA score gone, INP replacing FID, accessibility tightened. A small revolution in our audit reports.
Headless WordPress: pros, cons and when it actually makes sense
Decoupling WordPress from the frontend is trendy, but it is not the universal answer. Here is when it pays off, when it does not, and what we have learned on the job.
Astro 3.0 and View Transitions: SPA-feel without the SPA weight
Smooth navigations like a real app, but with a static site. Astro 3.0 makes a big step and rewires how we think content-heavy sites.
PostgreSQL 15 in production: the verdict after six months
MERGE, faster logical decoding, better sort performance. What we actually used and what stayed on paper.
Next.js 13.4 and the stable App Router: what really changes
Vercel marked the App Router stable in 13.4. Between Server Components, nested layouts and new routing conventions, here is what to adopt now and what to let mature.