bartosjiri ⚡️

534 posts

bartosjiri ⚡️ banner
bartosjiri ⚡️

bartosjiri ⚡️

@bartosjiri_

Full-stack software engineer | Svelte code pusher

Prague, Czech Republic Katılım Nisan 2014
367 Takip Edilen218 Takipçiler
Secretpika (replyguy era)
Biggest thanks to my Superchibs collectible patrons! Here's pika's pilot episode for you all <3 still a lot more chibs in d wild, link to adopt in pinned tweet 👀 See u in the next video!
English
7
12
37
1.6K
sohey.eth
sohey.eth@sohey_eth·
BM builders! If you deployed a Next.js 15 or 16 app with App Router, your server might be vulnerable to remote code execution. That means someone can send a single request to your app and your server will run whatever code they want. Steal env vars, drain your hot wallet, access your database. One command to fix: npx fix-react2shell-next So what actually happened? React Server Components use something called the Flight protocol to send data between your server and the browser. Think of it like a special format for streaming UI data. The problem was React wasn't properly checking if incoming data was safe. Attackers could send a payload disguised as normal data, but it actually contained instructions to run code. Why does this work? JavaScript is very flexible. If an object has a .then method, JS treats it like a Promise. The exploit abuses this by crafting an object that "looks" like React internals but actually tricks the system into executing attacker code. It's like handing someone a package that looks like mail but it's actually a bomb. Run this - it checks your version and upgrades you to the patched release: npx fix-react2shell-next Full advisory: nextjs.org/blog/CVE-2025-… Exploits are already circulating. Takes 30 seconds to fix. Do it now.
English
46
41
174
23.9K
bartosjiri ⚡️
bartosjiri ⚡️@bartosjiri_·
Mini Apps @buildonbase dev tip: Want to keep dev tools available even in the production version of your app? Use the Mini Apps SDK to check the user's FID and enable them only for devs!
bartosjiri ⚡️ tweet media
English
0
0
1
96
bartosjiri ⚡️ retweetledi
Simon H
Simon H@dummdidumm_·
Careful: Popular packages like debug (a dependency of vite-plugin-svelte) were compromised, versions with a crypto wallet stealer were on npm for a short amount of time. More info: socket.dev/blog/npm-autho…
English
1
7
36
2.7K
bartosjiri ⚡️
bartosjiri ⚡️@bartosjiri_·
Mini Apps @buildonbase dev tip: Made updates to your manifest media but not seeing changes? Add a random query param to your URLs. Plus, it works for regular web2 head meta tags too!
bartosjiri ⚡️ tweet media
English
0
0
1
69
bartosjiri ⚡️ retweetledi
smolfridge studio
smolfridge studio@smolfridgestu·
Our @baseapp/@farcaster_xyz pomodoro Mini App is now out! Come try the MVP and get your first taste! And don't forget, we’ve got special things in store for our early supporters!
Secretpika (replyguy era)@ttyl5h

GW universe ! OG (@bartosjiri_) and pika cooked up a @farcaster_xyz mini app for frens who liek to be productiv online together !! Currently 4 players per POMODORO seshon It called "Time to Fish" <3 Try it out farcaster.xyz/miniapps/YCfij…

English
0
4
6
347
bartosjiri ⚡️
bartosjiri ⚡️@bartosjiri_·
You can easily onboard people onchain with @baseapp Mini Apps: - Build a web version of the app that works even without extra web3 features - Make it fun to use while keeping some parts exclusive to Mini App users - Provide a simple onboarding guide - Bring everyone onchain! 🚀
English
0
0
1
64
bartosjiri ⚡️
bartosjiri ⚡️@bartosjiri_·
As a creative dev, @farcaster_xyz /@baseapp Mini Apps are a dream. @zora took an early step with HTML assets, but without wallet integration, external services or mobile, possibilities were limited. With Mini Apps bringing all of that, there’s never been a better time to build!
English
1
1
13
811
bartosjiri ⚡️
bartosjiri ⚡️@bartosjiri_·
@ttyl5h can you pls let me know beforehand so I can buy some before the pump? thx
English
1
0
1
20
Mosa
Mosa@mofasasi·
Phewww! Just realized it's been over a year since I made the OP. Uncertain decision, but I took the leap. 🧗‍♂️ What have I been up to? Here's a quick unplanned overview: 1. Had the opportunity to contribute to @WTFAcademy_ open source educational libraries, my first exposure to web3 development. Check out their website to get started too, highly recommended! 2. Helping (i) above to reach talent in Africa at @wtf_academy_a , one pop-up at a time. 3. Co-building @multisightapp with @bartosjiri_ on @safe for individuals and teams using multisignature wallets. Happy to chat with teams on this. 4. Accelerating access to knowledge @SciHubFans and coalescing the effort locally @DeSci_NG to increase our collective knowledge bank, enable a culture of research and to proffer custom made solutions for our landscape. 5. Currently cooking and getting cooked @Web3Bridge virtually. Looking forward to meeting folks onsite before Cohort XII ends. By the way, Cohort XIII registration opens in a few days. Take that leap! Just getting started, it's still day 1! 🧗‍♂️ "Stay hungry, stay foolish".
Mosa@mofasasi

I've been shuffling web2 and web3 over the last 2 years but this is the year I focus on web3. As someone who's had this shift @Harri_obi , any word of advice for me?

English
4
2
17
4.8K
jesse.base.eth
jesse.base.eth@jessepollak·
who's building @base wrapped for 2024? would love to give a retro grant to someone who builds something beautiful, shareable, and onchain.
English
198
51
729
77.9K
bartosjiri ⚡️
bartosjiri ⚡️@bartosjiri_·
@jessepollak @base Grateful for @ttyl5h for onboarding me to the Superchain, creating opportunities for collabs, and always being such a pleasure to work with! 🙌
English
0
2
7
154
jesse.base.eth
jesse.base.eth@jessepollak·
it's thanksgiving week, so I want to try something new — would love everyone to join in. what's one thing or person in the @base ecosystem that you are grateful for you? rules: can't be me, share a quick why, tag in whoever it is, stay based.
English
636
103
1.1K
233.2K