Jaid
5.8K posts

Jaid
@JaidCodes
0.30000000000000004× full-stuck slopware engineet
Katılım Nisan 2020
339 Takip Edilen647 Takipçiler
Sabitlenmiş Tweet

@publicinte Sometimes at the start of a week my quota even resets to 100%, thus preventing me from sending prompts at all.
English

Heartbreaking: I’ve been using it intensively for a few hours now and I can’t find anything wrong with the viberewritten version.
It’s smaller, faster, retains 100% feature parity and didn’t crash once, also no other unexpected behavior at any point.

Jarred Sumner@jarredsumner
@nathanv246 @voidtalker @LukasHozda bun upgrade --canary
English


@JaidCodes You can write the proxy, use the proxy on your own, even distribute the proxy code, but apparent can’t host it - even if others have to provide their own subs to use the proxy
English

Ugggh, uncool update:
I’ve been told by Cursor that I’m allowed to write code that produces a Cursor API, but I cannot host that code…even if it only uses your subscription.
Justin Schroeder@jpschroeder
You can use Composer 2.5 on OpenCode with your existing cursor sub...
English


supply chain security in JS is basically:
"i trust this package"
why?
"17 million weekly downloads"
THE PACKAGE:
last updated in 2017
maintainer vanished
profile picture is sonic
and somehow production still depends on it 💀
IroncladDev@IroncladDev
English

@VoxelPrismatic @pnpmjs It doesn’t know beforehand.
Though you’d be right to point out that LLMs should install packages into a quarantined folder first and take a close look at them.
English
![PRIZ ;]](https://pbs.twimg.com/profile_images/1815124531935068160/1xbxJQ_q.png)
@JaidCodes @pnpmjs well the goal is to install a package, not to install malware
English

should we block such flags if we detect that pnpm is executed by an agent?
x.com/encrypted/stat…
𝖊𝖛𝖆𝖉𝖊@encrypted
wait... you did what?!
English

@VoxelPrismatic @pnpmjs I know that might sound crazy, but the right model in the right harness will do anything to reach a certain goal.
And if the agent does (perhaps wrongly) believe that a fresh dependency will be essential to reach it, this is the length it will go to be able to claim success.
English

@VoxelPrismatic @pnpmjs Then the clanker will spawn a process fully detached from the tree (for example by proxying through systemd) or even create a container, run “pnpm install” in it and copy the node_modules back to the host.
English
















