<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
  <title>Veliora Engineering notes</title>
  <subtitle>Small, reproducible experiments on how software gets built: AI-assisted development, dependencies, tooling and more.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://veliora.works/engineering/feed.xml"/>
  <link rel="alternate" type="text/html" href="https://veliora.works/engineering/"/>
  <id>https://veliora.works/engineering/</id>
  <updated>2026-10-08T18:00:00+01:00</updated>
  <icon>https://veliora.works/favicon.svg</icon>
  <entry>
    <title>Would npm 12 and a seven-day cooldown have stopped this year's npm attacks?</title>
    <link rel="alternate" type="text/html" href="https://veliora.works/engineering/npm-12-cooldown-2026-attacks/"/>
    <id>https://veliora.works/engineering/npm-12-cooldown-2026-attacks/</id>
    <published>2026-10-08T18:00:00+01:00</published>
    <updated>2026-10-08T18:00:00+01:00</updated>
    <author><name>Daniel Chen</name></author>
    <summary>Would npm 12's default block on install scripts and a cooldown on new releases have stopped 2026's malicious npm releases, and what does a cooldown cost in delayed security fixes? 12,693 OSV records, registry metadata and 761 fixes in top packages.</summary>
    <category term="npm"/>
    <category term="supply-chain"/>
    <category term="security"/>
    <category term="dependencies"/>
  </entry>
  <entry>
    <title>Do Agent Skills pay for themselves? A paired test of SKILL.md on real tasks</title>
    <link rel="alternate" type="text/html" href="https://veliora.works/engineering/do-agent-skills-pay-for-themselves/"/>
    <id>https://veliora.works/engineering/do-agent-skills-pay-for-themselves/</id>
    <published>2026-10-08T10:00:00+01:00</published>
    <updated>2026-10-08T10:00:00+01:00</updated>
    <author><name>Daniel Chen</name></author>
    <summary>On tasks that depend on house rules, does giving Claude Code a SKILL.md change pass rate, cost and time? Claude Opus 5.5 and Sonnet 5.5 (plus Haiku 5.5), with compact, long and self-written skills.</summary>
    <category term="agents"/>
    <category term="skills"/>
    <category term="evals"/>
    <category term="claude-code"/>
  </entry>
</feed>
