Royalaid

466 posts

Royalaid banner
Royalaid

Royalaid

@royalaid

Web Dev

Farcaster 가입일 Şubat 2009
689 팔로잉221 팔로워
Royalaid 리트윗함
TANSTACK
TANSTACK@tan_stack·
SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.
English
113
874
3.3K
2.9M
Yining Karl Li
Yining Karl Li@yiningkarlli·
Here's a super hot take of mine. If you've been in graphics long enough, you know I'm right though.
Yining Karl Li tweet media
English
36
172
2.8K
66.6K
Royalaid
Royalaid@royalaid·
@lucashjin When I first read your post I thought "I hope he read the ASCII rendering post that hit the HN front page months ago". Lo and Behold, actually gud tek inside. Definitely gonna check this out!
English
0
0
0
18
Lucas Jin
Lucas Jin@lucashjin·
the solution: > match characters based on shape instead of brightness > sample different parts of characters and treat them as vectors (you can compare with nearest-neighbor search) > preserves overall image quality much better + much less visual clutter > inspiration: alexharri.com/blog/ascii-ren…
English
4
0
38
4K
Lucas Jin
Lucas Jin@lucashjin·
existing video to ascii components suck. so i built one that doesn't.
English
79
151
2.6K
154.9K
Royalaid
Royalaid@royalaid·
@EntireHQ Entire CLI 0.6.0 (0ec0d032) Go version: go1.26.2 OS/Arch: darwin/arm64
English
0
0
0
24
Entire
Entire@EntireHQ·
@royalaid hey, sorry to hear that the experience is slow! Can I ask ..what version are you on?
English
1
0
0
14
Royalaid
Royalaid@royalaid·
@EntireHQ I love the idea of your product but sadly I can't really use it, it takes a long time for even one turn of claude to work with the hooks enabled and turning what should be a quick 3 minute session into 15 minutes+ Happy to help you guys debug it tho!
English
2
0
1
37
Royalaid
Royalaid@royalaid·
@EntireHQ Here is, what I am sure is a flawed, analysis of my current set of issues
Royalaid tweet media
English
1
0
0
24
Royalaid
Royalaid@royalaid·
Hello world
English
0
0
2
29