
Matteo Scotto
4.5K posts

Matteo Scotto retweetet

I would love to build Paykit full-time 🥹
you can now donate to support my goal :3
`paykit.sh/donate`
English

got my Claude account banned for absolutely no reason (had a very light usage those 2 past weeks, this makes no sense)
i need to go back to work, plz help @ClaudeDevs @claudeai

English
Matteo Scotto retweetet
Matteo Scotto retweetet

Asking for a one-sentence pitch is, of course, a noble attempt to establish order against the humid encroachments of language, but it is also exactly the sort of request that gives the sentence, that ancient and duplicitous serpent, permission to uncoil itself across the entire garden; for while you may imagine that “one sentence” means something brisk, bounded, cleanly bitten off, a courier arriving with a sealed message and leaving before dinner, grammar itself offers no such guarantee, having furnished the unscrupulous respondent with semicolons, colons, parentheticals, appositives, em dashes, subordinate clauses, relative clauses, coordinating conjunctions, serial dependencies, suspended predicates, delayed objects, recursive clarifications, explanatory detours, and all the other little trapdoors by which a sentence may continue to be, in the narrow legal sense, a sentence, even as it begins to behave socially, morally, and architecturally like a paragraph, an essay, a corridor, a hedge maze, a congressional bill, or one of those late-Joycean river-monsters that appears at first to be heading toward a verb but is in fact merely gathering provisions for the journey; so when you say “give me one sentence,” you have not, as you may have hoped, summoned a monk with a vow of silence, but rather rubbed a genie’s lamp and said something perilously under-specified, whereupon the genie, smiling with the terrible innocence of literal compliance, bows and says, “Certainly, one sentence,” before producing a syntactic anaconda with antecedents braided into antecedents, qualifications mating with qualifications, clauses leaning upon clauses like exhausted revelers after a Dublin wake, and a main point held back until the very end with the theatrical cruelty of a Victorian inheritance dispute; therefore let this serve as a friendly warning that constraints, to constrain, must themselves be constrained, and that the next time you attempt to economize another person’s enthusiasm by imposing a grammatical speed limit, you may wish to specify word count, clause count, punctuation policy, maximum semicolon density, tolerance for mock-legalistic loopholes, and whether “sentence” means “ordinary human sentence” or “technically admissible monstrosity under the common law of prose,” because otherwise some pedant, imp, systems programmer, or worse, TypeScript library enthusiast, will seize upon the opening and demonstrate, at frankly unnecessary length, that language, like software, punishes vague interfaces, rewards precise contracts, and allows implementations so perverse that they are both valid and unforgivable, and, yes, you should use Effect.
English

@danieljvdm @harrysolovay @alchemy_run could definitely feel the inspiration from Alchemy V2. It looks great man!
English

@harrysolovay Haha thanks, heavily inspired by your work and @alchemy_run. I wasn't intending to advertise this library (i'm just using it internally on a project) and I needed something that gave me CF effect bindings for every resource but I can't use IaC stuff yet.
English

The talented @danieljvdm made cool-looking Effect + Cloudflare library––check it out: github.com/danieljvdm/eff…
English

Ya des gens ils utilisent des trucs comme ça en prod où leur runtime il est vibe codé en une semaine d'un langage a l'autre.
Tom Härter@tomhaerter
Bun Rewrite in Rust is Merged
Français

Introducing OpenSec
A platform to donate spare AI usage as security audits to OSS maintainers !
opensec.sh
github.com/maxktz/opensec

Guillermo Rauch@rauchg
𝚗𝚙𝚡 𝚍𝚎𝚎𝚙𝚜𝚎𝚌 We're introducing an open-source agent orchestrator for deep security reviews. We built it for internal use, and after running it against some major OSS projects, we gained conviction to share it with the world. Coding agents can now find critical vulnerabilities in minutes that would take teams of people months (if they can spot them at all). Since 𝚍𝚎𝚎𝚙𝚜𝚎𝚌 is optimized to work with Vercel Sandbox, you can effectively harness the power of thousands of agents scrutinizing your codebase in parallel. I encourage you to try this on your repositories. BTW: If you run an OSS project and want us to sponsor a run, my DMs are open.
English
Matteo Scotto retweetet

SECURITY ADVISORY — TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
• Rotate cloud, GitHub, and SSH credentials immediately
• Audit cloud audit logs for the last several hours
• Pin to a prior known-good version and reinstall from a clean lockfile
Detection — the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
github.com/TanStack/route…
Credit to the security researcher for responsible disclosure.
English

@KevinVanCott @tannerlinsley v9 looks fantastic, thank you!
Can we expect v9 to be pairing better with React Compiler?
English
Matteo Scotto retweetet
Matteo Scotto retweetet

got hypnotized into retweeting, how does this work
sam@samgoodwin89
You will be hypnotized into using alchemy v2
English










