GitHub's engineering team ran secret scanning across 15,000+ repos, surfaced 20,000+ exposed secrets, and got to zero open alerts in nine months. The post focuses on the process: classifying real risks, assigning ownership, and building safe remediation workflows.
programmingTuesday, July 7, 2026
GitHub's secret scanning hits inbox zero
Today's programming news is about practical engineering at scale: GitHub's own secret scanning initiative offers a playbook for managing secrets across thousands of repos, while a critical look at mobile-first CSS questions a long-held best practice. AI coding tools get a mixed review, and a new benchmark challenges agents on scientific quantum programming.
Secrets and scale
GitHub's own secret scanning story is the standout today, offering a real-world case study in reducing alert noise.
CSS and AI debates
Two pieces question current assumptions: mobile-first CSS and AI coding assistants.
Patrick Clancey argues that mobile-first CSS, while philosophically sound, can lead to bloated stylesheets and unnecessary complexity when applied rigidly. It's a practical critique of a widely accepted practice.
eWeek rounds up research on AI coding tools: they boost productivity on bounded tasks but introduce security risks and increase review burdens on complex codebases. The takeaway is about tiered controls, not blanket adoption.
Hardware and benchmarks
Open-source hardware and new benchmarks round out the day.
The z386, an open-source FPGA re-implementation of the Intel 80386, now has a key missing feature implemented: early start memory access. A niche but interesting bit of retro hardware hacking.
ORBIT-Q is a new benchmark for autonomous coding agents in quantum programming. It tests physical fidelity and framework-native semantics, going beyond typical code-generation metrics.
Also today2
More roundups that day
Galaxy Watch problems and creative reflections

Herb Alpert returns, regional rap gets reviewed
Gen Z's American Dream slipping away
Xbox restructure dominates gaming news
