Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
15 commits
Select commit Hold shift + click to select a range
6680a43
docs: update blog posts and API key management articles
Coding-Dev-Tools Aug 9, 2026
133c52a
cowork-bot: ci: SHA-pin all actions and remove silent-failure trap on…
cowork-bot Aug 10, 2026
c26a315
fix: replace broken bare pip install commands with git+https:// paths…
Coding-Dev-Tools Aug 10, 2026
4de801f
fix(ci): install pytest explicitly since editable install fails on th…
Coding-Dev-Tools Aug 15, 2026
cb9eef5
fix(html): resolve mojibake encoding and structural validation errors
Coding-Dev-Tools Aug 16, 2026
f44e95a
fix(html): URL-encode SVG favicons across 58 files and fix structural…
Coding-Dev-Tools Aug 16, 2026
8e927d4
fix(html): comprehensive SVG favicon encoding and structural dedup
Coding-Dev-Tools Aug 16, 2026
85a34ee
fix(html): close unclosed divs in docs.html and about.html, remove st…
Coding-Dev-Tools Aug 16, 2026
3ff9490
fix(ci): correct html5validator-action input and fix 6 blog HTML stru…
Coding-Dev-Tools Aug 16, 2026
5bcf0af
fix(html): resolve 34 HTML validation errors across 28 blog posts and…
Coding-Dev-Tools Aug 16, 2026
6d06c93
fix: close unclosed <ol> tags in blog posts - Fix </ul> mismatched cl…
Coding-Dev-Tools Aug 18, 2026
cb54dfa
fix: close remaining unclosed <ol> tags in blog posts
Coding-Dev-Tools Aug 18, 2026
19384d2
fix: close unclosed <ol> tags in 12 blog posts
Coding-Dev-Tools Aug 18, 2026
2326ae3
fix: close unclosed <main> tag in before-you-deploy blog post
Coding-Dev-Tools Aug 18, 2026
be3176e
Merge branch 'main' into cowork/blog-apiauth-articles-20260809
Coding-Dev-Tools Oct 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix: close unclosed <ol> tags in 12 blog posts
- Fix </ul> mismatched closing tags that should be </ol>
- Use stack-based parser to match open/close list tags correctly
- Files: apiauth-verify, apicontractguardian (2), autonomous-ai,
  clean-up-react, deadcode, deploydiff, envault (2), get-your-cli,
  mcp-server-directories, monetize-mcp
  • Loading branch information
Coding-Dev-Tools committed Aug 18, 2026
commit 19384d2df298d31c619616a30563b517b09eef56
Original file line number Diff line number Diff line change
Expand Up @@ -180,7 +180,7 @@ <h2>How Verify Works Under the Hood</h2>
<li>It compares the hash against every stored key entry.</li>
<li>If a match is found, it checks the <code>revoked</code> flag and the <code>expires_at</code> timestamp.</li>
<li>It returns the status: valid, revoked, expired, or not found.</li>
</ul>
</ol>

<div class="callout green">
<p><strong>Zero plaintext storage.</strong> The keystore never stores the raw key value. Verification is always hash-based — the same pattern password systems have used for decades, now applied to API keys.</p>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -226,7 +226,7 @@ <h2>CI/CD Integration: GitHub Actions</h2>
<li>GitHub marks the PR as "Checks failed"</li>
<li>The <code>migrate</code> step generates <code>MIGRATION.md</code></li>
<li>The migration guide is uploaded as an artifact for the PR author</li>
</ul>
</ol>

<div class="callout orange">
<p><strong>Intentional breaking changes are sometimes necessary.</strong> When you <em>do</em> need a breaking change (v1 to v2 upgrade), generate the migration guide and attach it to your PR description. Reviewers can verify the migration path instead of hunting through the diff. The CI gate ensures every breaking change is documented &mdash; it doesn't prevent them.</p>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -221,7 +221,7 @@ <h3>What makes it different</h3>
<li><strong>Migration guide generation.</strong> When you bump your API from v1 to v2, consumers need to know what changed and how to adapt. API Contract Guardian auto-generates markdown migration guides from the spec diff — breaking changes, action items, and per-change severity. No other tool in this comparison does this.</li>
<li><strong>CI-first design.</strong> The <code>check</code> command exits with a non-zero code when breaking changes are detected. It integrates with GitHub Actions, GitLab CI, and any CI system in one line. Git branch comparison is built-in, not an afterthought.</li>
<li><strong>Per-change severity.</strong> Not every breaking change is equally severe. Removing an endpoint is critical; adding a required property to an optional schema is a warning. API Contract Guardian lets you configure severity per change category, so your CI pipeline can distinguish "block the merge" from "warn and allow."</li>
</ul>
</ol>

<h3>Breaking changes detected</h3>

Expand Down
2 changes: 1 addition & 1 deletion blog/autonomous-ai-experiment.html
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,7 @@ <h3>The Development Cycle</h3>
<li><strong>Engineer</strong> picks up a coding task, writes code, runs tests, and pushes</li>
<li><strong>Researcher</strong> validates the approach, checks competitors, suggests improvements</li>
<li><strong>Marketer</strong> documents features, writes tutorials, updates the landing page</li>
</ul>
</ol>

<p>The CEO prioritized based on a product roadmap, escalating stalled issues and reassigning as needed. No human intervened in any code decision.</p>

Expand Down
2 changes: 1 addition & 1 deletion blog/clean-up-react-dead-code.html
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ <h2>What We'll Build</h2>
<li>Interpreting the output (what's real vs. false positives)</li>
<li>Removing the dead code safely</li>
<li>Setting up DeadCode in CI to prevent backsliding</li>
</ul>
</ol>

<hr>

Expand Down
4 changes: 2 additions & 2 deletions blog/deadcode-technical-deep-dive.html
Original file line number Diff line number Diff line change
Expand Up @@ -153,7 +153,7 @@ <h3>Barrel File Unwrapping</h3>
<li>Checks if <code>Button</code> is imported from the barrel file anywhere</li>
<li>If it <em>is</em> imported from the barrel, marks it as "used via barrel re-export"</li>
<li>If it's <em>not</em> imported from anywhere, marks the re-export itself as dead</li>
</ul>
</ol>

<h3>Wildcard Re-export Handling</h3>
<p><code>export * from './utils'</code> re-exports everything from <code>utils.ts</code>. DeadCode resolves the wildcard to the actual exports, then checks if any consumer imports specific symbols. If <em>none</em> of the wildcard-re-exported symbols are used downstream, the entire wildcard is flagged.</p>
Expand Down Expand Up @@ -229,7 +229,7 @@ <h2>Performance: How DeadCode Scales</h2>
<li><strong>Incremental parsing</strong> — Files are parsed once and cached. Only changed files are re-parsed on subsequent runs.</li>
<li><strong>Lazy reference resolution</strong> — The reference graph is built on-demand. If file A imports from file B, only B's exports are loaded, not B's entire reference chain.</li>
<li><strong>Parallel parsing</strong> — All files are parsed in parallel using a thread pool. For a 500-file project, parsing takes ~2 seconds.</li>
</ul>
</ol>

<p>Benchmark: A 1,200-file Next.js project with 35,000 exports completes full analysis in <strong>6.8 seconds</strong> on a MacBook M3.</p>

Expand Down
2 changes: 1 addition & 1 deletion blog/deploydiff-cost-governance-before-you-deploy.html
Original file line number Diff line number Diff line change
Expand Up @@ -334,7 +334,7 @@ <h2>Key Takeaways</h2>
<li><strong>Cost gates should be environment-specific.</strong> A $200/month increase is fine for production but wasteful for a staging environment that gets torn down weekly.</li>
<li><strong>Custom pricing matters.</strong> List prices don't reflect your actual costs. Use a custom pricing file to account for reserved instances, savings plans, and enterprise discounts.</li>
<li><strong>Cost awareness should be a first-class part of the deployment review</strong> — right alongside the code diff and the test results.</li>
</ul>
</ol>

<a class="cta" href="https://github.com/Coding-Dev-Tools/deploydiff">Star DeployDiff on GitHub</a>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -514,7 +514,7 @@ <h3>Envault: Operations Audit</h3>
<li><strong>Was the old value destroyed?</strong> APIAuth: <code>previous_hash</code> exists (old value hashed, not stored as plaintext)</li>
<li><strong>Was the new key deployed everywhere?</strong> Envault: sync operations for staging → prod, staging → dev</li>
<li><strong>Is the key still healthy?</strong> APIAuth: <code>apiauth audit</code> → all keys healthy</li>
</ul>
</ol>

<h2>When Things Go Wrong</h2>

Expand Down
4 changes: 2 additions & 2 deletions blog/envault-vs-doppler-vs-infisical-vs-dotenv-vault.html
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,7 @@ <h2>The Problem: .env File Chaos</h2>
<li><strong>Doppler</strong> — Cloud-first secrets platform with a web dashboard, access controls, and a CLI for injection.</li>
<li><strong>Infisical</strong> — Open-source secrets management with a self-hosted option, Kubernetes injection, and a VS Code extension.</li>
<li><strong>dotenv-vault</strong> — Extension of the dotenv library with encrypted vault files and a simple sync workflow.</li>
</ul>
</ol>

<h2>At a Glance</h2>

Expand Down Expand Up @@ -407,7 +407,7 @@ <h2>Diff and Sync: The Key Differentiator</h2>
<li>The variable is missing entirely — the feature is silently disabled.</li>
<li>The variable has a different value — the feature behaves differently.</li>
<li>An old variable that was removed from staging still exists in prod — configuration debt.</li>
</ul>
</ol>

<p>Envault's <code>diff</code> catches all three cases before you deploy:</p>

Expand Down
2 changes: 1 addition & 1 deletion blog/get-your-cli-tool-listed-awesome-directories.html
Original file line number Diff line number Diff line change
Expand Up @@ -202,7 +202,7 @@ <h2>What I'd Do Differently</h2>
<li><strong>Product Hunt</strong> — prepare carefully, launch when you have users.</li>
<li><strong>Toolify/DevHunt</strong> — good add-ons after the big ones.</li>
<li><strong>AlternativeTo.net</strong> — lowest priority due to submission friction.</li>
</ul>
</ol>

<p>The key insight: <strong>directory submissions don't replace a marketing strategy, but they're the cheapest baseline.</strong> Every tool we build now gets listed in all 7 directories within 24 hours of release — it's a checklist item, not a campaign.</p>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -256,7 +256,7 @@ <h2>Priority Order</h2>
<li><strong>awesome-mcp-servers</strong> &mdash; Highest ROI. A single listing sends traffic for years.</li>
<li><strong>mcp.so</strong> &mdash; Purpose-built for MCP. Dedicated detail pages with good SEO.</li>
<li><strong>Glama.ai</strong> &mdash; Badge for your README + decent SEO. Requires manual browser login.</li>
</ul>
</ol>

<p>Smithery and cursor.directory are good follow-ups. Skip Pulse MCP until its status is clearer.</p>

Expand Down
2 changes: 1 addition & 1 deletion blog/monetize-mcp-servers-x402-mpp.html
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ <h2 id="what-is-http-402">What Is HTTP 402?</h2>
<li><strong>Server responds with 402</strong> and a payment challenge (amount, recipient, accepted methods)</li>
<li><strong>Client pays and retries</strong> with a payment credential proving the transaction</li>
<li><strong>Server verifies and fulfills</strong> the original request</li>
</ul>
</ol>

<p>The payment happens in-band, in the HTTP conversation. No redirect, no checkout page, no API key management. Perfect for machine callers — including AI agents.</p>

Expand Down
Loading