Kwonjae Lee

Kwonjae Lee

SRE, Observability

Weekly - March 20, 2026

- 13 mins

๐Ÿ“š ์ด๋ฒˆ ์ฃผ ์ถ”์ฒœ ์•„ํ‹ฐํด

1. Supply-chain attack using invisible code hits GitHub and other repositories

์ถœ์ฒ˜: lobsters | ๋‚ ์งœ: 2026-03-20

GitHub ๋“ฑ ์ฝ”๋“œ ์ €์žฅ์†Œ์—์„œ โ€˜๋ณด์ด์ง€ ์•Š๋Š”(invisible) ์ฝ”๋“œโ€™ ๊ธฐ๋ฒ•์„ ์ด์šฉํ•œ ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๋ฆฌ๋ทฐยท๋ Œ๋”๋ง ํ™”๋ฉด์—์„œ๋Š” ์ •์ƒ์ฒ˜๋Ÿผ ๋ณด์ด์ง€๋งŒ ์‹ค์ œ๋กœ๋Š” ์•…์„ฑ ๋™์ž‘์„ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ์ ์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ์†Œ์Šค ํ‘œ์‹œ/๋ฆฌ๋ทฐ UI๋งŒ ์‹ ๋ขฐํ•˜์ง€ ๋ง๊ณ , ๋นŒ๋“œยท๋ฐฐํฌ ํŒŒ์ดํ”„๋ผ์ธ์—์„œ ์‹ค์ œ ์‹คํ–‰๋˜๋Š” ๋ฐ”์ดํŠธ(ํŒŒ์ผ ๋‚ด์šฉ)๋ฅผ ๊ธฐ์ค€์œผ๋กœ ๊ฒ€์ฆํ•˜๋Š” ์Šต๊ด€๊ณผ ๋ฐฉ์–ด ์ฒด๊ณ„๋ฅผ ๋ฐฐ์šธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

2. ์ผ์ƒ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” Claude Code ํŒ๊ณผ ๋ชจ๋ฒ” ์‚ฌ๋ก€ 50๊ฐ€์ง€

์ถœ์ฒ˜: geeknews | ๋‚ ์งœ: 2026-03-20

์ด ๊ธ€์€ Claude Code๋ฅผ ์ด๋ฏธ ์“ฐ๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ์ƒ์‚ฐ์„ฑ์„ ๋” ๋Œ์–ด์˜ฌ๋ฆด ์ˆ˜ ์žˆ๋„๋ก, ์„ธ์…˜ ์šด์˜ ๋‹จ์ถ•ํ‚ค(cc alias, ! ์ ‘๋‘์‚ฌ, Esc ๋˜๊ฐ๊ธฐ ๋“ฑ)๋ถ€ํ„ฐ ํ”„๋กฌํ”„ํŠธ/์›Œํฌํ”Œ๋กœ์šฐ ๋ชจ๋ฒ” ์‚ฌ๋ก€๊นŒ์ง€ 50๊ฐ€์ง€ ์‹ค์ „ ํŒ์„ ์ •๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ๊ณต์‹ ๋ฌธ์„œ, ์ปค๋ฎค๋‹ˆํ‹ฐ ๊ฒฝํ—˜, ์žฅ๊ธฐ๊ฐ„ ์‹ค์‚ฌ์šฉ ๋…ธํ•˜์šฐ๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ โ€˜๋” ๋น ๋ฅด๊ฒŒ ํƒ์ƒ‰ํ•˜๊ณ , ๋” ์•ˆ์ „ํ•˜๊ฒŒ ๋ณ€๊ฒฝํ•˜๋ฉฐ, ๋ฐ˜๋ณต ์ž‘์—…์„ ์ค„์ด๋Š”โ€™ ๋ฐฉ๋ฒ•์„ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

3. Beat Paxos

์ถœ์ฒ˜: lobsters | ๋‚ ์งœ: 2026-03-20

โ€˜Beat Paxosโ€™(lobsters ๋Œ“๊ธ€)์€ Paxos ๊ฐ™์€ ํ•ฉ์˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ โ€˜์ด๊ฒจ์•ผโ€™ ํ•˜๋Š” ์ƒํ™ฉ์ด ์‹ค์ œ๋กœ ๋ฌด์—‡์ธ์ง€(์ง€์—ฐ, ์šด์˜ ๋ณต์žก๋„, ์žฅ์•  ๋ชจ๋“œ, ์š”๊ตฌ์‚ฌํ•ญ ๋ถˆ์ผ์น˜)์™€, ๋งŽ์€ ์‹œ์Šคํ…œ์—์„œ ๋” ๋‹จ์ˆœํ•œ ๋Œ€์•ˆ์ด ์ถฉ๋ถ„ํ•œ ์ด์œ ๋ฅผ ๊ฐœ๋ฐœ์ž ๊ด€์ ์—์„œ ์ ๊ฒ€ํ•˜๊ฒŒ ํ•ด์ค๋‹ˆ๋‹ค. ๋ถ„์‚ฐ ํ•ฉ์˜๊ฐ€ ํ•„์š”ํ•œ ๊ฒฝ์šฐ์™€ ๊ทธ๋ ‡์ง€ ์•Š์€ ๊ฒฝ์šฐ๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ณ , ์„ค๊ณ„ ๋ชฉํ‘œ(์ผ๊ด€์„ฑ/๊ฐ€์šฉ์„ฑ/์ง€์—ฐ/์šด์˜์„ฑ)์— ๋งž์ถฐ Raft/etcd, ๋‹จ์ผ ๋ฆฌ๋”, DB ํŠธ๋žœ์žญ์…˜, ์ด๋ฒคํŠธ ๊ธฐ๋ฐ˜ ํŒจํ„ด ๋“ฑ ํ˜„์‹ค์ ์ธ ์„ ํƒ์ง€๋ฅผ ๋น„๊ตํ•˜๋Š” ๊ด€์ ์„ ์–ป์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

4. Video Conferencing with Durable Streams

์ถœ์ฒ˜: lobsters | ๋‚ ์งœ: 2026-03-20

์ด ๊ธ€์€ ํ™”์ƒํšŒ์˜ ๊ฐ™์€ ์‹ค์‹œ๊ฐ„ ๋ฏธ๋””์–ด ์ „์†ก์„ โ€œDurable Streams(๋‚ด๊ตฌ์„ฑ ์žˆ๋Š” ์ŠคํŠธ๋ฆผ)โ€ ๊ด€์ ์—์„œ ์„ค๊ณ„ํ•ด, ์ผ์‹œ์  ๋„คํŠธ์›Œํฌ ์žฅ์• ๋‚˜ ์žฌ์ ‘์† ์ƒํ™ฉ์—์„œ๋„ ๋ฐ์ดํ„ฐ ์œ ์‹คยท๋Š๊น€์„ ์ค„์ด๋Š” ๋ฐฉ๋ฒ•์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ์ŠคํŠธ๋ฆผ์„ ๋‹จ์ˆœํ•œ ์†Œ์ผ“/์„ธ์…˜์ด ์•„๋‹ˆ๋ผ ์žฌ์ „์†กยท์žฌ์ƒยท์ •ํ•ฉ์„ฑ์„ ๊ฐ–์ถ˜ ๋กœ๊ทธ/์ŠคํŠธ๋ฆผ์œผ๋กœ ์ทจ๊ธ‰ํ•  ๋•Œ ์–ป๋Š” ์•„ํ‚คํ…์ฒ˜์  ์ด์ ๊ณผ ์šด์˜(๊ด€์ธกยท๋ณต๊ตฌ) ์ „๋žต์„ ๋ฐฐ์šธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

5. Show HN: Sonar โ€“ A tiny CLI to see and kill whateverโ€™s running on localhost

์ถœ์ฒ˜: hackernews | ๋‚ ์งœ: 2026-03-20

Sonar๋Š” ๋กœ์ปฌํ˜ธ์ŠคํŠธ์—์„œ ์–ด๋–ค ํ”„๋กœ์„ธ์Šค๊ฐ€ ์–ด๋–ค ํฌํŠธ๋ฅผ ์ ์œ ํ•˜๊ณ  ์žˆ๋Š”์ง€ ๋น ๋ฅด๊ฒŒ ํ™•์ธํ•˜๊ณ , ํ•„์š”ํ•˜๋ฉด ์ฆ‰์‹œ ์ข…๋ฃŒ(kill)ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ์ดˆ์†Œํ˜• CLI ๋„๊ตฌ๋ฅผ ์†Œ๊ฐœํ•ฉ๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ํฌํŠธ ์ถฉ๋Œ๋กœ ์ธํ•ด ์„œ๋ฒ„/ํ”„๋ก ํŠธ์—”๋“œ/DB๊ฐ€ ์•ˆ ๋œจ๋Š” ๋ฌธ์ œ๋ฅผ ๋” ๋นจ๋ฆฌ ์ง„๋‹จํ•˜๊ณ , ๋ฐ˜๋ณต์ ์ธ lsof/netstat/ps ์กฐํ•ฉ ์ž‘์—…์„ ์ค„์—ฌ ๋กœ์ปฌ ๊ฐœ๋ฐœ ๋ฃจํ”„๋ฅผ ๋‹จ์ถ•ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

6. Atuin v18.13 โ€“ better search, a PTY proxy, and AI for your shell

์ถœ์ฒ˜: lobsters | ๋‚ ์งœ: 2026-03-20

Atuin v18.13์€ ์…ธ ํžˆ์Šคํ† ๋ฆฌ ํ™œ์šฉ์„ ๊ฐ•ํ™”ํ•ด ๋” ๋‚˜์€ ๊ฒ€์ƒ‰ ๊ฒฝํ—˜์„ ์ œ๊ณตํ•˜๊ณ , PTY ํ”„๋ก์‹œ ๋ฐ ์…ธ์šฉ AI ๊ธฐ๋Šฅ์„ ํ†ตํ•ด ํ„ฐ๋ฏธ๋„ ์ž‘์—… ํ๋ฆ„์„ ํ™•์žฅํ•ฉ๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ๋ช…๋ น ์‹คํ–‰ ๋งฅ๋ฝ(๋””๋ ‰ํ„ฐ๋ฆฌ, ์‹œ๊ฐ„, ํ˜ธ์ŠคํŠธ ๋“ฑ)์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์žฌํ˜„ ๊ฐ€๋Šฅํ•œ ์ปค๋งจ๋“œ ํƒ์ƒ‰/์žฌ์‚ฌ์šฉ์„ ๊ฐœ์„ ํ•˜๊ณ , ์ธํ„ฐ๋ž™ํ‹ฐ๋ธŒ ํ”„๋กœ๊ทธ๋žจ๊นŒ์ง€ ํฌํ•จํ•œ ๊ธฐ๋กยท๊ณต์œ ยท์ž๋™ํ™”๋ฅผ ๊ฒ€ํ† ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

7. Unified Modules For Your Nixfiles

์ถœ์ฒ˜: lobsters | ๋‚ ์งœ: 2026-03-20

์ด ๊ธ€(๋ฐ ๋Œ“๊ธ€)์€ Nix ์„ค์ •(Nixfiles)์„ โ€œํ†ตํ•ฉ ๋ชจ๋“ˆ(unified modules)โ€ ํ˜•ํƒœ๋กœ ๊ตฌ์กฐํ™”ํ•ด, ํ˜ธ์ŠคํŠธ/ํ™˜๊ฒฝ๋ณ„๋กœ ์ค‘๋ณต์„ ์ค„์ด๊ณ  ์žฌ์‚ฌ์šฉ์„ฑ์„ ๋†’์ด๋Š” ๋ฐฉ๋ฒ•์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ์„ค์ •์„ ์ž‘์€ ๋ชจ๋“ˆ ๋‹จ์œ„๋กœ ์ชผ๊ฐœ ์กฐํ•ฉํ•˜๊ณ , ๊ณตํ†ต ๊ทœ์น™๊ณผ ์˜ค๋ฒ„๋ผ์ด๋“œ๋ฅผ ์ผ๊ด€๋˜๊ฒŒ ์ ์šฉํ•ด ์œ ์ง€๋ณด์ˆ˜์„ฑ๊ณผ ํ™•์žฅ์„ฑ์„ ์–ป๋Š” ํฌ์ธํŠธ๋ฅผ ๋ฐฐ์šธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:

8. To be a better programmer, write little proofs in your head (2025)

์ถœ์ฒ˜: lobsters | ๋‚ ์งœ: 2026-03-20

์ด ๊ธ€(๋Œ“๊ธ€ ์Šค๋ ˆ๋“œ)์€ โ€˜์ฝ”๋“œ๋ฅผ ์“ฐ๊ธฐ ์ „์— ๋จธ๋ฆฟ์†์—์„œ ์ž‘์€ ์ฆ๋ช…(proof)์„ ํ•ด๋ณด๋ผโ€™๋Š” ์Šต๊ด€์ด ๋ฒ„๊ทธ๋ฅผ ์ค„์ด๊ณ  ์„ค๊ณ„๋ฅผ ๋” ๋ช…ํ™•ํ•˜๊ฒŒ ๋งŒ๋“ ๋‹ค๋Š” ์ ์„ ๊ฐ•์กฐํ•ฉ๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ํ•จ์ˆ˜/๋ชจ๋“ˆ์˜ ์ „์ œ์กฐ๊ฑด๊ณผ ๊ฒฐ๊ณผ, ๋ถˆ๋ณ€์‹, ์˜ˆ์™ธ ์ผ€์ด์Šค๋ฅผ ๊ฐ„๋‹จํ•œ ๋…ผ๋ฆฌ๋กœ ์ ๊ฒ€ํ•ด โ€œ์ด ์ฝ”๋“œ๊ฐ€ ์™œ ๋งž๋Š”์ง€โ€๋ฅผ ์„ค๋ช…ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๋ฉฐ, ๊ทธ ๊ณผ์ •์—์„œ ํ…Œ์ŠคํŠธ์™€ ๋ฆฌ๋ทฐ๋„ ๋” ๋‚ ์นด๋กœ์›Œ์ง‘๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ํฌ์ธํŠธ:


๐Ÿ“š This Weekโ€™s Picks

1. Supply-chain attack using invisible code hits GitHub and other repositories

Source: lobsters | Date: 2026-03-20

This discusses a supply-chain attack technique using โ€œinvisible codeโ€ in GitHub and other repositories, where code can look harmless in diff/review views but behave maliciously when executed. Developers learn to avoid trusting UI-rendered source alone and instead validate the exact bytes that are built and shipped, adding pipeline-level checks and hardening.

Key Points:

2. ์ผ์ƒ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” Claude Code ํŒ๊ณผ ๋ชจ๋ฒ” ์‚ฌ๋ก€ 50๊ฐ€์ง€

Source: geeknews | Date: 2026-03-20

This article compiles 50 practical tips for developers already using Claude Code, covering session/navigation shortcuts (e.g., cc aliases, the ! prefix, Esc rewind) as well as prompt and workflow best practices. Drawing from official docs and long-term real-world usage, it helps you move faster, make safer code changes, and reduce repetitive work.

Key Points:

3. Beat Paxos

Source: lobsters | Date: 2026-03-20

โ€œBeat Paxosโ€ (Lobsters comments) helps developers clarify what it really means to โ€œbeatโ€ Paxos in practiceโ€”latency, operational complexity, failure modes, and mismatched requirementsโ€”and why simpler alternatives often suffice. It encourages you to distinguish when distributed consensus is truly necessary and to choose pragmatic options (Raft/etcd, single-leader designs, DB transactions, event-driven patterns) aligned with your systemโ€™s goals around consistency, availability, latency, and operability.

Key Points:

4. Video Conferencing with Durable Streams

Source: lobsters | Date: 2026-03-20

The piece frames video conferencing as a โ€œdurable streamsโ€ problem: design real-time media transport so brief network failures and reconnects donโ€™t translate into data loss or broken sessions. Developers can learn the architectural and operational benefits of treating media as a replayable, consistent stream/log with recovery and observability built in.

Key Points:

5. Show HN: Sonar โ€“ A tiny CLI to see and kill whateverโ€™s running on localhost

Source: hackernews | Date: 2026-03-20

Sonar is a tiny CLI that helps you quickly see which processes are bound to localhost ports and kill them when needed. Developers can diagnose port conflicts faster and reduce the repetitive lsof/netstat/ps workflow, speeding up local development iterations.

Key Points:

6. Atuin v18.13 โ€“ better search, a PTY proxy, and AI for your shell

Source: lobsters | Date: 2026-03-20

Atuin v18.13 upgrades shell history workflows with improved search, adds a PTY proxy, and introduces AI features for the shell. Developers can better discover and reuse commands with richer context (directory/time/host, etc.), and evaluate recording/sharing/automation options that may extend even to interactive terminal programs via PTY handling.

Key Points:

7. Unified Modules For Your Nixfiles

Source: lobsters | Date: 2026-03-20

This post (and its comments) discusses structuring Nix configuration (โ€œNixfilesโ€) as unified, composable modules to reduce duplication across hosts/environments and improve reuse. Developers will learn how to split configuration into small modules, compose them consistently, and apply shared defaults and overrides to make Nix setups easier to maintain and scale.

Key Points:

8. To be a better programmer, write little proofs in your head (2025)

Source: lobsters | Date: 2026-03-20

This comment thread argues that doing small โ€œproofs in your headโ€ before and while coding helps reduce bugs and clarifies design. By explicitly checking preconditions, postconditions, invariants, and edge cases, developers become better at explaining why code is correctโ€”leading to sharper tests and more effective code reviews.

Key Points:


๐Ÿ”— Sources

Articles curated from Hacker News, GeekNews, Lobsters, TLDR Tech, Pragmatic Engineer, GitHub Blog, Meta Engineering, Anthropic, Martin Fowler, and more.


์•„ํ‹ฐํด ์ œ์•ˆ์ด ์žˆ์œผ์‹œ๋ฉด ์ด๋ฉ”์ผ๋กœ ์—ฐ๋ฝ์ฃผ์‹œ๊ฑฐ๋‚˜ ๋Œ“๊ธ€์„ ๋‚จ๊ฒจ์ฃผ์„ธ์š”!

Have an article suggestion? Feel free to reach out via email or leave a comment below!

Kwonjae Lee

Kwonjae Lee

SRE, Observability

comments powered by Disqus