Warp is open-source now | Build or Be Replaced
AI news and automation insights for 2026-04-29. Episode date: 2026-04-29.
Download MP3 →
Build or Replaced
AI news and automation insights for 2026-04-29. Episode date: 2026-04-29.
Download MP3 →JOSH: It's Wednesday, April 29. This is Build or Be Replaced powered by ScanBrief.dev. I'm Josh, here with Erik Anderson. ERIK: Default platforms get lazy. Builders shouldn't. JOSH: Stick around. Erik's got an AI pro tip at the end about when to stop using one big model for everything. [pause] JOSH: Three quick signals this morning. First up, Warp is open-source now. Does that matter, or is that just terminal nerd news? ERIK: It matters. Dev tools earn trust when the code is visible, especially if they're sitting in your shell, your keys, your commands, your whole day. [beat] JOSH: GitHub also had a nasty RCE bug tied to `git push`. That's the kind of sentence people hate hearing. ERIK: Yeah. If a normal authenticated push can turn into backend command execution, that's not a bug, that's a siren. Everybody building on GitHub infrastructure just got reminded that convenience has a blast radius. [beat] JOSH: And LocalSend is getting a lot of love as an AirDrop alternative. Why are people so into that? ERIK: Because simple software that does one thing well still wins. Cross-platform file transfer with no cloud weirdness, no account circus, no vendor tax. People miss software that minds its business. [pause] JOSH: The first deep dive is Ghostty leaving GitHub. On the surface that sounds small. One project changes where it lives. Why did that blow up? ERIK: Because it's not one random repo. Ghostty's maintainer is a serious GitHub power user. When somebody like that says, "I'm out," people pay attention. They're not leaving because buttons moved around. They're leaving because GitHub stopped feeling like neutral ground. [beat] JOSH: Neutral ground for what? ERIK: Open source coordination. Code, sure. But also issues, trust, reputation, discovery, docs, release notes, bug reports, random drive-by fixes from somebody in Poland at 2 AM. GitHub became the town square and the filing cabinet at the same time. That's why this matters. JOSH: So the story isn't "terminal app moves." It's "people are tired of the town square." ERIK: Exactly. And once builders start feeling that, migration pressure builds fast. Not because every alternative is better. Most aren't. But once the default stops feeling safe, people tolerate rough edges somewhere else. [beat] JOSH: What's actually driving the frustration? ERIK: A few things. Platform lock-in. AI features people didn't ask for. Corporate gravity. The sense that the product is serving executives and telemetry before it's serving maintainers. Open source people can smell that stuff quick. JOSH: That's wild, because GitHub still feels unavoidable. ERIK: Right now, yeah. Same way VMware felt unavoidable. Same way Stack Overflow felt unavoidable. Then one day you realize the traffic's still there, but the energy left. Those are different things. [beat] JOSH: How do you think about that in your own stack? You've got a lot of moving parts tied together. ERIK: I don't let one vendor become my nervous system. That's the lesson. PrimeBus is NATS-based. Claude writes code in a bunch of workflows. ScanBrief pulls from 56 sources. InkEngine has its own app flow. I try real hard not to make any single company the one throat my whole lab has to breathe through. JOSH: And that's because you've seen what happens when people do. ERIK: Yep. A platform becomes identity, hosting, issue tracking, CI, package trust, release automation, discussion, auth. Then the vendor changes terms, breaks the UX, gets breached, or decides your use case isn't strategic. Now your whole shop gets dragged around by the ankle. [beat] JOSH: How much of your own stuff would break if GitHub had a really bad week? ERIK: Some things would get annoying. Nothing important should die. That's the standard. I've got 64 projects running across two servers in the lab, 229 cron jobs, three Claude instances on the PrimeBus mesh, and the goal is always the same: graceful degradation. If one thing goes weird, I want inconvenience, not paralysis. JOSH: That's a good line. ERIK: It's a billing line too. Companies pay a lot of money to turn paralysis into inconvenience. [beat] JOSH: For teams listening, what's the practical takeaway? Not the philosophy. The actual move. ERIK: Separate your social layer from your build layer. People smash those together and regret it later. Mirror your repos. Own your CI definitions. Export your issues. Keep release artifacts somewhere you control. Don't build your company on screenshots of green checkmarks from one platform. JOSH: You're saying reduce dependence before you're angry enough to need it. ERIK: Exactly. You do not start building the lifeboat after the ship lists. That's fake planning. [beat] JOSH: Does leaving GitHub actually help a project, though? Doesn't it also make contribution harder? ERIK: It can. That's the trade. You lose some default visibility. Some drive-by contributors won't follow. But serious users will. And sometimes the point isn't growth. Sometimes the point is control. Builders need to remember that. More users on worse terms isn't always a win. JOSH: So this is less rebellion and more boundary-setting. ERIK: Yeah. And it's a signal that the center of gravity can move. Slowly at first, then all at once. Open source communities don't need permission to relocate. They just need a reason. [pause] JOSH: Next one. Rust. Everybody treats Rust like a force field, and then Ubuntu audits Rust-based coreutils and finds 44 CVEs. Wait, really? ERIK: Really. This is the part people don't like hearing. Memory safety is huge. It is not magic. Rust can stop whole classes of bugs. It cannot stop you from making bad system decisions with perfect memory safety. [beat] JOSH: Put that in plain English. ERIK: If your privileged file utility has a race condition with symlinks, Rust doesn't save you. If you check a path and then use it later and the world changed in between, Rust doesn't save you. If your logic is bad, your logic is bad in any language. JOSH: So the headline isn't "Rust failed." It's "people oversold what it solves." ERIK: That's exactly it. Rust is a seatbelt. A seatbelt is good. Still a bad idea to drive into a lake. [beat] JOSH: Why does this matter beyond language wars? ERIK: Because teams make budget decisions and staffing decisions on myths. They hear "we rewrote it in Rust" and think security problem solved, hiring problem solved, compliance box checked. No. You changed one layer of risk. Good move. Now go do the boring part too. JOSH: The boring part being audits and threat models and all the stuff nobody wants to fund. ERIK: Yep. Filesystem semantics. Privilege boundaries. Integration testing. Abuse cases. SAST. Dynamic tests. Running the weird edge cases. You still need paranoid engineers. The compiler is not your security team. [beat] JOSH: How do you handle that in your own automation work? Because you've got a lot of code touching real systems. ERIK: I assume every automation can hurt me if I let it. That's the posture. In PrimeBus, when an agent sees an error and tries a fix, that fix doesn't get a free pass because Claude wrote it neatly. I wrap guardrails around the action path. Diff checks. Retry limits. Scope restrictions. Logging. HumanRail if confidence is low. JOSH: How often do those guardrails actually matter? ERIK: Constantly. PrimeBus has done 214 auto-fixes with a 78 percent success rate. Everybody hears that and thinks, "nice." What they should hear is 22 percent didn't make it. That's exactly why the rails matter. Success without rails is a delayed outage. [beat] JOSH: That's a good point. People only market the win rate. ERIK: Of course. Nobody makes a landing page that says, "Our agent confidently did the wrong thing on Friday." But that's real life. Good builders plan around wrongness. JOSH: Does this Rust story change anything for AI-written code too? ERIK: A lot. AI tends to produce code that looks clean before it's truly safe. That's dangerous. Humans get tricked by polished syntax. You see nice tests, nice comments, nice structure, and your brain assumes the edge cases got handled. They didn't necessarily. [beat] JOSH: So if a model writes Rust, that doesn't mean the code is safe either. ERIK: Correct. If anything, it can make the false confidence worse. "Rust plus AI" sounds like two layers of smart. Could still be a symlink race with nicer formatting. JOSH: Dry, but fair. ERIK: That's most postmortems. Fancy technology, boring root cause. [beat] JOSH: If you're running an engineering team and somebody says, "We're moving this service to Rust," what's the right response? ERIK: Good. Why? What risk are we removing? What risk remains? What tests change? What operational assumptions change? If they can't answer that, they're doing religion, not engineering. JOSH: And if they can answer it? ERIK: Then fund it. Rust is useful. I've got no interest in clown takes on either side. But use it like an adult. Memory safety is one control in a stack, not a final state. [beat] JOSH: You've been around network automation forever. Any comparison from that world? ERIK: Yeah. People used to think if they had NSO or Terraform, then change risk disappeared. No. You got consistency. That's valuable. You did not get wisdom. You can automate a bad intent beautifully. JOSH: That's the line. ERIK: Happens every day. Clean YAML. Terrible idea. Still takes prod down. [pause] JOSH: Third deep dive. OpenAI models coming to Amazon Bedrock. Why is that a big shift? ERIK: Because it breaks the feeling that serious OpenAI usage had to orbit Azure. Enterprises don't like being herded onto one cloud just because the model is good. Bedrock changes the buying conversation fast. [beat] JOSH: Is this mostly a procurement story? ERIK: Procurement, compliance, architecture, politics. All the fun stuff. Plenty of companies already have AWS baked into security review, billing, network patterns, data handling, vendor approval. If they can buy OpenAI there, a bunch of internal friction disappears overnight. JOSH: And that matters more than model benchmarks sometimes. ERIK: Way more. The best model on the wrong procurement path loses. I've seen this forever in enterprise infra. Better tool, wrong approval lane, dead on arrival. [beat] JOSH: What does it mean for Microsoft? ERIK: Less differentiation. They had gravity from hosting and relationship structure. If OpenAI shows up in Bedrock too, the moat gets shallower. Microsoft still matters a lot, but the exclusivity story gets weaker. JOSH: Does that change how builders like you work day to day? ERIK: It gives me options. Options are speed. If I want one workflow on Claude, another on OpenAI, maybe route something through Bedrock because the client's already in AWS, that reduces friction. I'm building systems, not joining fan clubs. [beat] JOSH: You actually mix models already. ERIK: Constantly. Three Claude instances are on my PrimeBus mesh right now. Bob on Neo, Bill on the Mac M3, Homer on Morpheus. Then I use other models where they fit better. ScanBrief cares about ranking and summary quality. InkEngine cares about long-form structure and revision flow. PrimeTrader cares about fast classification and signal handling. Same hammer for all of that would be lazy. JOSH: People still want the one-model answer, though. ERIK: Because it's simpler to explain. Not simpler to run. In the lab I care about throughput, cost, confidence, retry behavior, context limits, and whether the model follows the shape of the task. That's way more important than tribal brand arguments. [beat] JOSH: What kind of tasks get routed differently for you? ERIK: High-risk code fixes get stronger review paths. Commodity summarization can use cheaper models. Classification can go tiny and fast. If a workflow has low confidence, HumanRail can send it to a human. If it's repetitive and bounded, let the agents eat. JOSH: That's a very different frame from "which model is best." ERIK: "Best" is a toy question. Best at what, under what cost, with what failure mode, inside which system. Builders need to ask system questions. [beat] JOSH: Does Bedrock make multi-model setups easier for normal teams, or is this mostly enterprise theater? ERIK: Both. Big companies care first because they're stuck in approval labyrinths. But smaller teams benefit too because the market keeps loosening. More distribution means more pricing pressure, more deployment patterns, more room to avoid single-vendor traps. JOSH: Back to the GitHub theme, basically. ERIK: Yep. Same lesson again. Don't hand one company the keys to your whole future if you don't have to. [beat] JOSH: If you're listening and building internal tools right now, what's the smart move? ERIK: Build an abstraction layer early. Not a giant science project. Just enough to swap model providers without surgery. Standardize prompts, outputs, retries, logs, and evals. Then you can move where the economics or risk picture makes sense. JOSH: Because the market won't sit still. ERIK: It never does. That's why I ship daily. The guy waiting for the perfect stable stack gets lapped by the guy with adapters and guardrails. [pause] ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com [pause] JOSH: Alright, what's the AI pro tip today? ERIK: Stop using one giant model for every task. That's the tip. People throw the expensive brain at everything because it's easy, and then they wonder why cost goes up and latency gets stupid. [beat] ERIK: Split the work. Use a cheap fast model for classification, routing, and cleanup. Use the stronger model only where judgment matters. Code review. tricky edits. ambiguous prompts. Stuff that can actually hurt you. [beat] ERIK: In my stack, I think in lanes. One lane scores signals. One lane summarizes. One lane checks confidence. One lane asks for a human if the output smells off. That pattern matters more than whatever model won Twitter this week. [beat] ERIK: If you do one thing today, add a confidence check before expensive generation. If confidence is high, stay cheap. If it's low, escalate. That one move saves money and catches dumb mistakes early. That's your tip. Use it. [pause] ERIK: If you're building toward financial independence through automation, my first book walks through the whole path. Free chapter at erikandersonbook.com. [pause] JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev. ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff. [pause] ERIK: Build or be replaced. JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.