Dominykas Blyžė
@dominykas.social
📤 688
📥 219
📝 273
Full of stack
I wrote a thread about my home and IoT network setup, but it's on the non-corporate network:
fosstodon.org/@dominykas/1...
loading . . .
Dominykas Blyžė (@
[email protected]
)
OK so some of you were interested in my home network (incl. IoT) setup. As luck may have it, my old router (Linksys WRT3200ACM) started having random connectivity problems (no change in config/update...
https://fosstodon.org/@dominykas/115232767918218397
7 days ago
0
2
0
There's a Lithuanian band who like to sing Killing in the Name during protests which is all nice, but really - where's the Know Your Rights of 2026? Any Bob Dylans still exist?
8 days ago
0
0
0
reposted by
Dominykas Blyžė
isaacs
10 days ago
bsky.app/profile/isaa...
add a skeleton here at some point
0
0
1
Wtf
@isaacs.bsky.social
?
add a skeleton here at some point
10 days ago
1
0
0
reposted by
Dominykas Blyžė
13 days ago
Today's news is all Trump and no Epstein files, how's that happening?
0
1
1
I wonder how much of the world's pain could have been avoided had Obama been a liiiiiitle bit less peaceful (and not received that Nobel...)
13 days ago
0
0
0
It's enough to copy/paste your code styleguide into an
AGENTS.md
to make the news these days. I mean I really like that documentation is having it's 15 minutes of fame, but really - I don't get it.
15 days ago
1
1
0
reposted by
Dominykas Blyžė
Lionella
15 days ago
aspirational
6
590
165
I want to produce some code 😭
15 days ago
1
0
0
Good thing I never stopped.
add a skeleton here at some point
17 days ago
0
1
0
reposted by
Dominykas Blyžė
Nicolò Ribaudo
26 days ago
Thinking about the fact that most EU leaders still have an account on the American non-consensual child pornography website...
1
5
1
Well that will look great in the spreadsheet column called "Copilot sales" 🤭
26 days ago
1
0
0
So I built this over holidays:
github.com/owhelm/helm-...
It allows you to embed Kustomizations in your (wrapper) Helm charts to make changes to things that your dependencies don't expose the controls for. It still has work remaining, but it should be usable as is, at the very least as a PoC.
loading . . .
GitHub - owhelm/helm-kustomize: A Helm post-renderer plugin to process kustomizations embedded inside a chart.
A Helm post-renderer plugin to process kustomizations embedded inside a chart. - owhelm/helm-kustomize
https://github.com/owhelm/helm-kustomize
28 days ago
0
0
0
How come it's so hard to get 100% coverage in Go? Testing the error conditions is (unpopular opinion) more important than testing success cases (which generally just work and immediately give you like 50% coverage, depending on language).
28 days ago
1
0
0
Go's os#Root is nice. We should have it in Node.js.
28 days ago
0
0
0
The Claude Code integration in IntelliJ IDEA feels like it was built with Claude Code. The Copilot integration feels like it was built with Copilot. Make of it what you will.
28 days ago
0
0
0
So are you having your "oh shit" moment with LLMs today, or are you leaving that for tomorrow?
about 1 month ago
0
0
0
All the LLM tooling building their own chat interfaces with utter rubbish editors is deeply frustrating. I already have years of experience using chat interfaces. Make your chat interface work the way I expect. Give me all the features I have in Slack. Vibe code this if you have to.
about 1 month ago
0
0
0
No way this is actually happening 🥹
github.blog/security/sup...
about 1 month ago
4
23
6
It looks like
@economist.com
spent all the moneys on trying to make their mp3s not available, yet it took me all of 15 minutes to circumvent all of that. Look, folks, I pay you to make my life easier. You could have just not spent all that engineering effort and produced more content instead.
about 1 month ago
1
1
0
Every time I need to step out of the npm ecosystem, I immediately "you live like this?"
about 1 month ago
1
3
1
reposted by
Dominykas Blyžė
Marco Ippolito
about 2 months ago
❗️Node.js Security release pre-alert ❗️ We will release new versions of v20, v22, v24, v25 release lines on or shortly after the 15th of December 2025 in order to address: * 3 high severity issues. * 1 low severity issue. * 1 medium severity issue.
nodejs.org/en/blog/vuln...
loading . . .
Node.js — Monday, December 15, 2025 Security Releases
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
https://nodejs.org/en/blog/vulnerability/december-2025-security-releases
0
18
8
reposted by
Dominykas Blyžė
naugtur
about 2 months ago
Hey
@react.dev
or
@nextjs.org
I did a unique Defensive Coding workshop at DEFCON and NodeConfEU that's exploring techniques to avoid prototype pollution attacks, no matter how powerful. I'd be willing to run it for free for the teams around RSC. Do I know anybody who could help arrange that?
1
7
3
Am I getting it right: your so called president is pardoning a person convicted for drug trafficking, while blowing other alleged drug traffickers out of the water? And he will get away with it?
2 months ago
1
1
0
Can't get over the fact that external security vendors are able to block malicious npm packages faster than Github.
2 months ago
0
0
0
reposted by
Dominykas Blyžė
Dale Bustad
2 months ago
Folks would have seen a warning in sfw within minutes of the original publish, when automated scanning detected the potential malware and it was marked as “potential malware”. Further along in the malware campaign, human review was roughly happening in realtime, so sfw was blocking more quickly.
1
3
1
reposted by
Dominykas Blyžė
Jordan Harband
2 months ago
every option, including "no 2FA at all", *can* be made secure. The problem is that it shouldn't even be POSSIBLE to publish insecurely - and either way, defaults matter. OIDC and token-based publishing are default insecure, full stop.
0
3
2
reposted by
Dominykas Blyžė
Wes
2 months ago
We need them to enforce it on OIDC publish or turn OIDC publish off until it can be enforced, and to treat this with the urgency it needs. I want to be able to stop having this discussion every other week and go into the new year without more supply chain incidents over the holidays.
1
3
1
Hello? Microsoft? Any humans still there?
2 months ago
1
2
0
@socket.dev
hey folks, it is a bit unclear from your post, but which of the recent attacks was sfw able to catch in practice?
2 months ago
1
3
0
reposted by
Dominykas Blyžė
Wes
2 months ago
> as in its current state it wouldn’t prevent attacks such as Shai-Hulud and other recent ones. From our blog, almost like we knew. 🔮
openjsf.org/blog/publish...
loading . . .
Publishing More Securely on npm: Guidance from the OpenJS Security Collaboration Space | OpenJS Foundation
The OpenJS Security Collaboration Space has been working closely with GitHub’s npm team to understand how new security features affect projects and maintainers, especially as threats and tools keep ev...
https://openjsf.org/blog/publishing-securely-on-npm
1
6
3
"grok". He friggin ruined the perfectly great word "grok". What an asshole.
3 months ago
0
0
0
A lot of repos already have this information. Why are they being forced to put it in a different format in a different location for robots? Or did the robots get trained on human behavior to not read existing documentation?
github.blog/ai-and-ml/un...
loading . . .
Unlocking the full power of Copilot code review: Master your instructions files
Ready to make your code reviews smarter and easier? Learn how to structure your instructions files for better results, avoid common pitfalls, and see real-world examples to get started. 🚀
https://github.blog/ai-and-ml/unlocking-the-full-power-of-copilot-code-review-master-your-instructions-files/
3 months ago
1
0
0
Node.js is actually good now. Opened a repo that has code that's probably some 7-8 years old, because it had a renovate PR for a while. Closed the renovate PR and instead removed 6 dependencies, replacing them with built-ins.
3 months ago
0
4
0
reposted by
Dominykas Blyžė
Matt Blaze
3 months ago
Not that anyone here needs to hear this, but for the record, in a democracy "people voted differently from the way I expected or hoped" does not constitute evidence of fraud, no matter how many pretty charts and graphs of "voting patterns" you make.
22
832
161
reposted by
Dominykas Blyžė
joschi
3 months ago
I see a lot of people here being smug about AWS having a major outage. 😞 What happened to
#hugops
?
1
0
2
I was going to say that staying in your neighborhood on a Saturday is not a protest, but a picnic. However that video 😲
3 months ago
0
0
0
words.filippo.io/compromise-s...
loading . . .
A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises
Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.
https://words.filippo.io/compromise-survey/
4 months ago
1
1
0
reposted by
Dominykas Blyžė
Wes
4 months ago
To give some credit (I don’t mean to be so harsh) it is a series of *really deep* paper cuts. But the real ailment is internal bleeding, and neither bandaids (the right paper cut treatment) not the cast fix the problem. We need forced 2FA supported from CI.
0
3
1
reposted by
Dominykas Blyžė
Le Roux Bodenstein
4 months ago
Someone should make one of these giant frog style costumes that looks like an Irish Mammy. Then you can protest as Aunt Aoife.
0
2
1
reposted by
Dominykas Blyžė
naugtur
4 months ago
Get a permanent access to publishing with a single factor as long as you publish from github but no 2fa totp for your setup that can't be stolen at scale.
0
3
1
reposted by
Dominykas Blyžė
Darcy Clarke
4 months ago
Why are
@github.com
tokens allowed to have no expiry but
@npmjs.bsky.social
are about to make every IT team's lives a living hell? This is just more security theatre. Think harder
@microsoft.com
.
1
15
4
reposted by
Dominykas Blyžė
Tom MacWright
4 months ago
copilot is smarter than ever (we no longer have accurate counts of pull requests on the pull requests tab)
0
8
1
reposted by
Dominykas Blyžė
Matteo Collina
4 months ago
🚀 BIG NEWS: We just shipped @platformatic/python - run Python ASGI apps INSIDE your Node.js process! This changes everything for AI/ML + Node.js apps 🧵
youtu.be/8eAAP9IF4xA
loading . . .
Launching @platformatic/python: Bring Python ASGI to Your Node.js Applications
Today we are excited to ship @platformatic/python, a new capability for Watt, the Application Server for Node.js, that lets you run Python ASGI applications alongside your existing Node.js workloads.…
https://youtu.be/8eAAP9IF4xA
1
21
11
Wha?! How is this even possible? Almost 1 GiB per day? I don't even watch the videos or anything.
4 months ago
0
0
0
Just received an SMS from an unknown number. Moments after, Google changed that to show me the first and last name of the person. How is this legal?
4 months ago
1
2
0
reposted by
Dominykas Blyžė
Matt Harrison
4 months ago
What are people using to track their reading these days? Goodreads, Storygraph?
#reading
1
0
1
reposted by
Dominykas Blyžė
🇺🇦 Ingvar Stepanyan
6 months ago
Will Github ever take spam detection seriously? Aka at all? They don't have even at the most basic blatant spam detection that any self-respecting email provider had 15 years ago, and now that we have AI you'd think it would be useful at least for this. Why do I have to keep doing this manually?
3
26
2
My assessment is that they're forcing people into Github Actions while not solving any of the recent problems?
github.blog/security/sup...
loading . . .
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/
4 months ago
1
6
0
How come verdaccio does not have a way to quarantine packages for a number of hours? Anyone tried building a plugin for that?
5 months ago
0
0
0
Load more
feeds!
log in