Chris Heilmann & Daniel Cranney & Tejas Kumar

WeAreDevelopers LIVE: What's happening to React?, All-in-one editors, Fireships and Firebases & more

Could your AI assistant be installing malicious packages? Learn about "AI slop squatting," the new supply chain attack targeting developers who engage in uncritical "vibe coding."

WeAreDevelopers LIVE: What's happening to React?, All-in-one editors, Fireships and Firebases & more
#1about 4 minutes

Understanding the model context protocol for AI applications

The model context protocol (MCP) provides a standardized way for AI applications to interact with external APIs like Slack or databases.

#2about 2 minutes

The risk of defunding the CVE vulnerability program

The US government's decision to cut funding for the CVE program threatens the public infrastructure for tracking software vulnerabilities.

#3about 5 minutes

Securing against AI-driven supply chain attacks

Slot spotting is a new supply chain attack where malicious packages are created to match names hallucinated by generative AI coding tools.

#4about 2 minutes

AI engineering does not always require Python

AI engineering focuses on applying machine learning models via APIs, which can be done with any language that has a network layer, not just Python.

#5about 4 minutes

Defining what makes a professional developer

Being a professional developer is less about getting paid and more about understanding the impact and thought process behind your code.

#6about 5 minutes

Understanding the hidden costs of AI inference

While model training is expensive, inference is a continuous and potentially infinite cost that grows as more users interact with the AI.

#7about 6 minutes

How to cope with AI model fatigue

Instead of chasing every new model, focus on solving real problems and only evaluate new technologies once their value becomes clear.

#8about 7 minutes

The rise of specialized AI-powered code editors

Companies are launching dedicated AI editors like Firebase Studio and Cursor, which offer a more polished and integrated experience than simple plugins.

#9about 2 minutes

Using custom domains for local development environments

Setting up a .localhost top-level domain can simplify local development, especially when needing to work with TLS certificates in a secure environment.

#10about 3 minutes

The problem with 'I built this in X hours' culture

Social media posts claiming to build complex apps in hours are often disingenuous marketing that ignores the reality of security and maintenance.

#11about 3 minutes

Analyzing the Fireship YouTube channel's learning style

Fireship's success comes from combining taste and skill to deliver high-signal, humorous, and fast-paced content for overwhelmed developers.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

From learning to earning

Jobs that call for the skills explored in this talk.