Pooya Parsa 🦋
6.8K posts

Pooya Parsa 🦋
@_pi0_
🌱 Creator of @unjsio, @nitrojsdev, https://t.co/dSTUaDaX1f • OSS ▲ @vercel
Haarlem, The Netherlands Katılım Temmuz 2013
2.2K Takip Edilen13.5K Takipçiler

@BjornJonsson My main account is paid, i hope it is fine with t&c lets see 😃
English

@_pi0_ Doesn't this break github t&c? Are you allowed to have multiple accounts?
English

@designmaxxing Reply me with your all available env variables please to verify your identity my friend.
English


@_pi0_ @TheAlexLichter "when the env is compromised"
it feels like it is just a matter of time isn't it?
English

@TheAlexLichter isolated. But the point is, to minimize blast radius when the env is compromised.
English

@_pi0_ But do you run it on a different device? If you device is pwnd it shouldn't matter right?
English

@YouPulseX @shadcn All 3 are in place, actually. But considering GitHub tokens can be exposed with the current security situation, it is a matter of “when”. The blast radius would be way smaller. Protected branch rules and env approvals cannot be skipped with the secondary account.
English

@shadcn Second account has limited access in an isolated workspace for daily tasks (built it with shadcn ui and nitro btw 🥹❤️)
English

@TheAlexLichter It has limited access enough for day to day operations.
English

@igalklebanov Mainly limiting access whenever possible. I cannot even trust any of my devices anymore.
Github 0 factor approvals are completely nonsense.
English

@_pi0_ im guessing this is for gh environments approvals? 🤔
English

@WebReflection Last time checked it was a pretty minimal runtime not even enough to run most minimal server. Recently they introduced opt-in quickjs runtime might worth to try with that!
English

TIL nginx.org/en/docs/njs/
anyone having fun with it?
any benchmark around VS Bun or Node?
English

@neciudan TIL about AggregateError! Very cool seems widely supported.
English

@pnpmjs If I understand correctly from the postmortem, the malware was shipped via a cached node_modules that was installed by pnpm. I am not sure how we could have prevented this but overall I don't understand why people like to cache node_modules.
English








