This Week In React

736 posts

This Week In React banner
This Week In React

This Week In React

@ThisWeekInReact

• ⚛️ Stay up-to-date with React • 📡 High signal, no drama • 🔥 Join 42k React devs - 1 email/week • 📨 https://t.co/ymeDmOmnYt • By @sebastienlorber

📨 For React Experts 👇 Katılım Ocak 2024
472 Takip Edilen3.7K Takipçiler
This Week In React
This Week In React@ThisWeekInReact·
These orgs have been compromised because of pull_request_target: - TanStack - PostHog - Nx - LiteLLM Any many more... As safe as you think it is, it's not and hackers are searching for repos using that workflow, easy target!
Seb ⚛️ ThisWeekInReact.com@sebastienlorber

TL;DR for open-source maintainers 🚫 NEVER use "pull_request_target" workflows 🚫 NEVER use shared caches in your publish pipeline Combining these 2 in particular is extremely dangerous I've repeated this countless times over the years, but another reminder is always useful

English
0
1
4
754
This Week In React retweetledi
Seb ⚛️ ThisWeekInReact.com
Seb ⚛️ ThisWeekInReact.com@sebastienlorber·
TL;DR for open-source maintainers 🚫 NEVER use "pull_request_target" workflows 🚫 NEVER use shared caches in your publish pipeline Combining these 2 in particular is extremely dangerous I've repeated this countless times over the years, but another reminder is always useful
Seb ⚛️ ThisWeekInReact.com tweet media
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
25
221
1.7K
203.5K
This Week In React retweetledi
Remotion
Remotion@Remotion·
HTML-in-canvas is now a first-class primitive in Remotion! It enables new types of effects that were impossible before.
English
63
208
2.8K
564.9K
This Week In React retweetledi
Seb ⚛️ ThisWeekInReact.com
Seb ⚛️ ThisWeekInReact.com@sebastienlorber·
This Week In React 276 ⚛️ - Boneyard - Ink - MUI - React Router - Next.js - shadcn - Docusaurus - Comark - Forms - Shaders 📱 - RN 0.85 - ViewTransition - Skia - Windows - CRNL - Maestro - Nitro Player - RNGH 🍿 Read/subscribe: thisweekinreact.com/newsletter/276 ✍️ @jaworek3211 & I
Seb ⚛️ ThisWeekInReact.com tweet media
English
1
5
31
8.6K
This Week In React retweetledi
Seb ⚛️ ThisWeekInReact.com
Seb ⚛️ ThisWeekInReact.com@sebastienlorber·
👀 React <ViewTransition> support for React Native 🎉 Behind a flag, doesn't seem ready for prime time But nonetheless quite exciting to see it being actively worked on! You'll find various PRs showing activity in the RN reconcilier and the Fabric renderer
Seb ⚛️ ThisWeekInReact.com tweet media
English
3
18
162
8.8K
This Week In React retweetledi
Seb ⚛️ ThisWeekInReact.com
Seb ⚛️ ThisWeekInReact.com@sebastienlorber·
This Week In React 275: ⚛️ - Next.js Adapter API - TanStack Start RSC preview - React Compiler in Rust - React XSS - Signals - Inertia - Astro 📱 - ExecuTorch - Unistyles - RN run - Preflight - Confetti - AI/Skills 🍿 Read/subscribe: thisweekinreact.com/newsletter/275 ✍️ @jaworek3211
English
1
7
63
9K
This Week In React retweetledi
Seb ⚛️ ThisWeekInReact.com
Seb ⚛️ ThisWeekInReact.com@sebastienlorber·
This Week In React 274 ⚛️ - Next.js - React Router - Storybook - HeroUI - Remotion - Lucide Icons - useEffect 📱 - Worklets / Reanimated - Nitro Fetch - React Navigation - Rozenite - MMKV - Windows - Swift 🍿 Read/subscribe: thisweekinreact.com/newsletter/274 Enjoy 👋
Seb ⚛️ ThisWeekInReact.com tweet media
English
0
6
38
8.1K