@jviide.iki.fi
📤 348
📥 29
📝 160
https://jviide.iki.fi
Playing the classics!
add a skeleton here at some point
about 10 hours ago
0
9
0
Why be knowledgeable when you can be Kyeswledgeable?
4 days ago
0
0
0
4 days ago
3
6
0
Is it just me, or do LLMs seem to love the word "shape"? "Shape of the problem." "Shape of the solution." Program architecture and data flow? "Code shape." Bug report structure? "Issue shape." One of those "once you see it, you can't unsee it" sort of shapes in life, I shappose.
8 days ago
2
10
1
reposted by
Joe Dator
11 days ago
Today's Daily Cartoon for
@newyorker.com
by Kevin Maher and me.
40
6985
1738
Daniel added a very cool detail that many other actions could also adopt: The usage examples in the README pin the action to the specific commit SHA of the latest release.
add a skeleton here at some point
11 days ago
2
14
2
Instead of doing more, let’s do better.
12 days ago
0
35
11
Whee! Published @badrap/valita v0.5.2 using both trusted & staged publishing just now insert party emoji here
add a skeleton here at some point
12 days ago
0
23
3
reposted by
Marvin Hagemeister
16 days ago
Speeding up the JS ecosystem OXC edition 🚀 We made both oxfmt and oxlint 50% faster on projects with >50k directories.
marvinh.dev/blog/speedin...
loading . . .
Speeding up the JavaScript ecosystem - oxlint and oxfmt
Future versions of oxlint and oxfmt will be ~50% faster on projecs with many (>=20k) directories.
https://marvinh.dev/blog/speeding-up-javascript-ecosystem-part-13/
7
180
29
the trubo is vulnerable
13 days ago
1
2
0
The recent wave of vulnerabilites, found in part with AI, has laid bare just how load-bearing ”scarcity of human attention” has been for the cybersecurity house of cards.
19 days ago
1
7
0
Deno’s FormData, URLSearchParams + Headers show O(n²) behavior in .set()/.delete() when many repeated keys are present. Example: FormData.delete("_") on ~1MB of _=&_=&_=&... Node: ~4ms Deno: ~74s Could turn otherwise reasonable cleanup of untrusted request data into a potential DoS vector. 1/3
21 days ago
2
12
0
reposted by
Daniel Ahmad
21 days ago
7 months to go
27
10383
2144
More companies, governmental organizations and community projects should adopt the security.txt convention/proposal:
securitytxt.org
Making security contact discovery as easy as possible is good for everyone. Yes, even within the context of the recent AI vulnerability report slopocalypse.
22 days ago
0
22
5
reposted by
patak
22 days ago
We will see a huge wave of security vulnerability reports. But this influx shows we should have spent more time on security tooling and research in our projects, rather than treating it as a new paradigm that requires us to change the way we collaborate.
1
21
3
Huge fan of Christopher Nolan’s film trilogy Batman Begins, Batman Continues, and Batman Ends.
23 days ago
2
8
0
Quadratic blowups are like the sun: stare at one long enough and you start seeing them everywhere. I’m very good at similes.
24 days ago
0
3
0
reposted by
The C Programming Language
about 2 months ago
What if there was a man in the middle attack but the man in the middle was like, really chill. What if he was basically a chill guy who didn't mind if you sent a secret or whatever
3
150
28
This started as an off-hand joke, but it made more sense the more we thought about it 😅
add a skeleton here at some point
26 days ago
2
16
2
reposted by
Mayday Trippe
about 1 month ago
me when i get shot
57
4435
1258
Switched @badrap/valita to ESM-only, pretty cool how
@npmx.dev
celebrates the package size reduction 🎉
npmx.dev/package/@bad...
27 days ago
0
54
7
reposted by
npmx
30 days ago
A free press makes openness possible for everyone.
1
91
14
Gonna adopt this practice at the workplace. - So that's it for the status meeting. See you next week! - And hey, everyone, don't mention the goblins. - ...What? - Or the pigeons.
add a skeleton here at some point
about 1 month ago
0
16
1
Some personal news:
about 1 month ago
0
12
1
Announcing the general availability of Schrödinger's Pull Requests
about 1 month ago
2
39
6
There's highly personalized phishing, and then there's this.
about 1 month ago
1
15
0
Sometimes notifications can be delightful.
about 2 months ago
0
32
2
Should
@preactjs.com
implement this new IETF draft?
www.ietf.org/archive/id/d...
loading . . .
Meow
Meow meow meow meow Meow Meow Meow (MEOW). MEOW meow meow meow meow-meow meow meow meow Meow meow meow, meow meow meow meow meow meow meow meow meow meow meow meow meow...
https://www.ietf.org/archive/id/draft-meow-mrrp-00.html
about 2 months ago
2
9
0
reposted by
Telephone Friend
about 2 months ago
This is what going on the internet used to feel like
23
1646
394
A career highlight for sure!
about 2 months ago
0
12
0
"Days of arguing about exploitability can save minutes of fixing the bug." -- Socrates, on vulnerability disclosure
about 2 months ago
1
6
1
A gentle reminder that while `pnpm install` (or `bun install`) doesn't run the lifecycle scripts of the dependencies by default, it *does* run them from the repo's own package.json. Let's be mindful when cloning and exploring all those new & exciting projects on our local machines.
about 2 months ago
2
25
6
What a demo! Razor 1911 celebrating their 40 years of activity on the scene.
www.youtube.com/watch?v=2Anb...
loading . . .
Razor1911
YouTube video by Dubmood
https://www.youtube.com/watch?v=2AnbYNudAyM
about 2 months ago
0
1
0
”FATHER WHY MUST I EXIST”
about 2 months ago
0
9
0
reposted by
badrap.io
2 months ago
Badrap is happy to support
@npmx.dev
in an advisory role. A better developer experience can be a boon to security. Easier access to trust signals and tips for avoiding unnecessary dependencies, among other things, help make stronger supply chain choices. Read their intro:
npmx.dev/blog/alpha-r...
loading . . .
Announcing npmx: a fast, modern browser for the npm registry
Today we're releasing the alpha of npmx.dev – a fast, modern browser for the npm registry, built in the open by a growing community.
https://npmx.dev/blog/alpha-release
10
18
3
reposted by
GitHub's auto-suggest using the display names instead of the account names isn't really doing us any favors. The latter "Dependabot" here is our beloved, and very fake, depenbadot.
2 months ago
1
5
2
brb gonna update some actoins
github.com/acticns/setu...
add a skeleton here at some point
2 months ago
2
8
0
Update: depenbadot just now got its first invite to collaborate on a repository 😟
add a skeleton here at some point
2 months ago
2
48
3
Worry not, Coplllot is on the case.
add a skeleton here at some point
2 months ago
1
11
1
It's, uh, less than ideal that I'm allowed to claim a GitHub username like this.
2 months ago
7
52
6
Okay, so it turns this is really, really slow. Which led to CVE-2026-30226:
github.com/sveltejs/dev...
Thanks to
@ell.iott.dev
and the rest of the
@svelte.dev
team for a well-handled vuln process, a pleasure as always 🫡
3 months ago
1
17
0
reposted by
Rav
3 months ago
Wise words
159
8025
2058
New
@react.dev
patches released today for CVE-2026-23864. Fixes for DoS issues reported by several people, including Yours Truly 🙂 The blog post at
react.dev/blog/2025/12...
has been updated with the new info.
loading . . .
Denial of Service and Source Code Exposure in React Server Components – React
The library for web and native user interfaces
https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
4 months ago
0
12
4
O(n²) works great until n+1.
4 months ago
0
8
0
me: move fast and break things my dentist: what
4 months ago
0
5
0
reposted by
lauren
4 months ago
scoreboard
add a skeleton here at some point
118
5913
988
Huge props to the
@svelte.dev
team for an exceptionally well-handled vulnerability process, despite my terrible timing of reporting the devalue issues just before New Year’s Eve 🙂
add a skeleton here at some point
5 months ago
0
25
3
OPEN YOU'RE EYES 👁️👄👁️
5 months ago
1
68
7
reposted by
Li Chen
7 months ago
◉‿◉
4
513
67
Pretty cool that you have to create a Facebook account to file a vulnerability report to Meta.
5 months ago
0
5
0
Load more
feeds!
log in