
Acha
10.4K posts

Acha
@Acha_for_CS
⚠︎フォロー感謝DM等不要不急のDM&メンション🙅 ⚠︎情報リテラシーが低過ぎる人はリム/ブロックするよ❗ 東京藝大大学院→CG制作&デザイナー→40代でIT系英日翻訳者→50代でエンジニアデビュー。RecursionCSとcreative codingは休止中。C言語を親だと思っている(得意とは言ってない)







🚨 Security advisory: Composer 2.9.8 and 2.2.28 are out and fix a vulnerability leaking GitHub Actions new format GITHUB_TOKENs into job logs via error messages. Update now (composer self-update) or disable affected Actions workflows. #composerphp #phpc #php



「黒田先生の言っていることは本当なのか?」 自画像で黒を使ったことを黒田清輝に酷評された学生、藤田嗣治(レオナール・フジタ)。 彼はその後、自分を認めない日本を飛び出して、芸術の本場フランスへ渡りました。 そこで見たのは 「なんだこれは!?全然違うじゃないか、






SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.











