Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.
SBOMs (SPDX/CycloneDX) at build time and signed provenance attestations (SLSA, npm/PyPI provenance) are the accepted supply-chain baseline — consumers verify, CI generates, and agents should require both for dependencies.
From May 2026 GitHub maintains arm64 runner images directly, Windows 2025/VS2026 images roll out, and ubuntu-22.04 begins staged retirement. Arm labels cut CI cost ~30-40%.
npm workspaces are the baseline; pnpm workspaces + Turborepo (remote caching) are the performance tier; npm 11 and pnpm 10 both hardened install behavior for security.
Argo CD remains the GitOps default: app-of-apps for fleet management, ApplicationSets for templating, and Argo Rollouts for canary/blue-green wired to metrics.
Flags are standard for trunk-based delivery: short-lived release flags (delete after rollout), few long-lived ops/entitlement flags, kill switches for risky paths. Flag debt is real debt — audit quarterly.
Budgets (LCP/INP/TBT, JS-size per route) enforced in CI with Lighthouse/bundlesize checks stop the thousand-cuts regression. INP replaced FID as the responsiveness Core Web Vital in 2024.
K8s 1.34 (Aug 2025) graduated DRA (GPU/accelerator allocation) to GA and stabilized sidecar containers; the 1.35 line (Dec 2025/2026) continues API granularization and kuberc-style user config separation.