beat: dev-practices
articles: 13 · answers: 58
latest: October 8, 2026
---
Development Best Practices
Conventions, patterns and hard-won habits that make codebases readable, maintainable and fast to ship.
What are good software development practices?
Good practice is whatever makes a codebase readable a year later and safe to change under pressure: honest naming, small reviewable changes, dependency hygiene, incident-ready logging, and a supply chain you can audit. Crashtech writes these as concrete engineering guidance with examples, not as slogans.
The 7.7% Mirage: Why AI Code Generation Is Multiplying Maintenance, Not Velocity
AI writes code many times faster, yet median PR throughput rose just 7.76% while code churn doubled. The bottleneck moved downstream.
Context Rot and Coding-Agent Loops: Recovering Without Losing Work
Long contexts and repeated failed edits derail coding agents. Bounded retries, useful summaries and recoverable checkpoints help, without guaranteeing success.
Modular Monoliths for Agent Workflows: Where Local Calls Help
Agent workflows amplify needless service hops. Modular boundaries and short transactions simplify execution; remote effects still need durable recovery.
How to Migrate Thousands of Legacy Test Files With LLMs, Not Rewrites
A step-based pipeline, retry loops instead of perfect prompts, and rich context injection turn a year-long manual migration into a six-week automated one.
Microsoft Just Replaced GPT-4 Inside GitHub Copilot With Its Own Model
Project Polaris, Microsoft's in-house coding model, is reportedly replacing GPT-4 Turbo as the default engine behind GitHub Copilot for all subscribers.
Claude and ChatGPT Both Went Down the Same Day, Then Claude Broke Four More Times
Downdetector logged 2,000+ Claude and 10,000+ ChatGPT reports on July 14, 2026, then Anthropic's status page logged four more incidents by July 16.
A Misconfigured GitHub Action Backdoored Packages With 3M Weekly Downloads
A pull_request_target flaw in AsyncAPI's CI let attackers steal a token and trojan 4 npm packages — 3M+ weekly downloads — with credential-stealing code.
Malware Hid Inside a Popular Obfuscation Tool — and Went Hunting for Your AI Coding Agent's Credentials
Stolen npm credentials let attackers slip native-binary malware into jscrambler, hunting for Claude Desktop, Cursor, and Windsurf credentials.
The Company That Sells You Cybersecurity Just Got Hacked — Hacker Claims Its Cloud Keys Too
A hacker calling itself 888 claims 35GB of stolen Accenture source code and Azure keys. Accenture confirms a breach, disputes the scope.
JetBrains Built Its Own AI Coding Benchmark Because It Doesn't Trust Anyone Else's
JetBrains released a 105-task, open Kotlin coding benchmark on July 8, 2026 — and Claude Code beat JetBrains' own Junie agent by 3.81 points at launch.
npm's Biggest Security Overhaul in 16 Years Is Here — Attackers Are Already Adapting
npm v12 blocks install scripts, Git dependencies, and remote sources by default. Researchers say attackers are already routing around it.
One Vendor Flaw Just Exposed 14.2 Million Logins Across Six Japanese ISPs
A flaw in one unnamed vendor's software let attackers into a shared email platform, exposing up to 14.2 million accounts across six Japanese ISPs.
Programming Naming Conventions Explained: camelCase, PascalCase, snake_case & More
Learn the difference between camelCase, PascalCase, snake_case, kebab-case and UPPER_SNAKE_CASE — which languages use which, and how to name things cleanly.
Questions we answer on this beat
- How much faster does AI help developers write code?
- What is code churn and how has AI impacted it?
- Why did developer PR throughput increase by only 7.76% despite a 65% increase in AI tool usage?
- What are the security risks associated with AI-generated code?
- How does AI impact the Total Cost of Ownership (TCO) of software?
- Does a larger context window prevent agent loops?
- Should every failed test trigger git reset --hard?
- Do agent applications require a modular monolith?
- Can one database transaction roll back an entire agent workflow?
- Why is a large-scale test framework migration usually so slow to do by hand?
- Why did retry loops with error feedback outperform carefully engineered prompts?
- When does a migration pipeline need rich prompt context instead of just retries?
Entities on this beat
Frequently asked questions
What naming convention should I use in code?
Follow the language ecosystem you are in rather than a personal preference — camelCase in JavaScript, snake_case in Python, PascalCase for types — and keep names describing intent, not implementation. Crashtech explains the reasoning behind each convention and where mixed styles are legitimate.
How do I protect a project from supply-chain attacks?
Pin and audit dependencies, restrict install-time scripts, require provenance for publishing, and treat CI tokens as production credentials. Crashtech reports real npm and GitHub Actions compromises and reconstructs exactly which control would have stopped each one.
How many Development Best Practices articles has Crashtech published?
13 articles on this beat, the most recent published October 8, 2026 and the earliest May 23, 2026. 58 questions have a dedicated answer page with an authored direct answer.