bartosjiri ⚡️
534 posts

bartosjiri ⚡️
@bartosjiri_
Full-stack software engineer | Svelte code pusher
Prague, Czech Republic Katılım Nisan 2014
367 Takip Edilen218 Takipçiler

vibecoded a site called Base Ice Rink that visualizes basic data on @base chain !! made with @viedotgame, each chib sliding is a tx, updated every 2 seconds
link to try here: baseicerink.vie.live
lmk how to improv it :DD
English


@ttyl5h @sohey_eth We're not using any of the affected libraries 😉
English

BM builders!
If you deployed a Next.js 15 or 16 app with App Router, your server might be vulnerable to remote code execution.
That means someone can send a single request to your app and your server will run whatever code they want. Steal env vars, drain your hot wallet, access your database.
One command to fix: npx fix-react2shell-next
So what actually happened?
React Server Components use something called the Flight protocol to send data between your server and the browser. Think of it like a special format for streaming UI data.
The problem was React wasn't properly checking if incoming data was safe. Attackers could send a payload disguised as normal data, but it actually contained instructions to run code.
Why does this work? JavaScript is very flexible.
If an object has a .then method, JS treats it like a Promise.
The exploit abuses this by crafting an object that "looks" like React internals but actually tricks the system into executing attacker code.
It's like handing someone a package that looks like mail but it's actually a bomb.
Run this - it checks your version and upgrades you to the patched release:
npx fix-react2shell-next
Full advisory: nextjs.org/blog/CVE-2025-…
Exploits are already circulating. Takes 30 seconds to fix. Do it now.
English

DeSci NG founder, @mofasasi, giving a talk on how we’re making African research endure to move the world forward at the 2025 NASA SpaceApps Challenge hosted by @SpaceBarAfrica


English

Our first Mini App just hit #1 in productivity on @baseapp !
Super excited to keep building, lots of cool features on the way!
smolfridge studio@smolfridgestu
Y’all need to chill, we haven’t even dropped the best features yet 😭
English
bartosjiri ⚡️ retweetledi

Great article by @stew_loren about front-end frameworks and innovation in this field. Give it a read! lorenstew.art/blog/react-won…

English

Mini Apps @buildonbase dev tip:
Want to keep dev tools available even in the production version of your app? Use the Mini Apps SDK to check the user's FID and enable them only for devs!

English
bartosjiri ⚡️ retweetledi

Careful: Popular packages like debug (a dependency of vite-plugin-svelte) were compromised, versions with a crypto wallet stealer were on npm for a short amount of time.
More info: socket.dev/blog/npm-autho…
English

Mini Apps @buildonbase dev tip:
Made updates to your manifest media but not seeing changes? Add a random query param to your URLs. Plus, it works for regular web2 head meta tags too!

English
bartosjiri ⚡️ retweetledi

Our @baseapp/@farcaster_xyz pomodoro Mini App is now out!
Come try the MVP and get your first taste! And don't forget, we’ve got special things in store for our early supporters!
Secretpika (replyguy era)@ttyl5h
GW universe ! OG (@bartosjiri_) and pika cooked up a @farcaster_xyz mini app for frens who liek to be productiv online together !! Currently 4 players per POMODORO seshon It called "Time to Fish" <3 Try it out farcaster.xyz/miniapps/YCfij…
English
bartosjiri ⚡️ retweetledi

GW universe !
OG (@bartosjiri_) and pika cooked up a @farcaster_xyz mini app for frens who liek to be productiv online together !! Currently 4 players per POMODORO seshon
It called "Time to Fish" <3 Try it out
farcaster.xyz/miniapps/YCfij…

English

You can easily onboard people onchain with @baseapp Mini Apps:
- Build a web version of the app that works even without extra web3 features
- Make it fun to use while keeping some parts exclusive to Mini App users
- Provide a simple onboarding guide
- Bring everyone onchain! 🚀
English

As a creative dev, @farcaster_xyz /@baseapp Mini Apps are a dream.
@zora took an early step with HTML assets, but without wallet integration, external services or mobile, possibilities were limited.
With Mini Apps bringing all of that, there’s never been a better time to build!
English

@ttyl5h can you pls let me know beforehand so I can buy some before the pump? thx
English

Phewww! Just realized it's been over a year since I made the OP. Uncertain decision, but I took the leap. 🧗♂️
What have I been up to? Here's a quick unplanned overview:
1. Had the opportunity to contribute to @WTFAcademy_ open source educational libraries, my first exposure to web3 development. Check out their website to get started too, highly recommended!
2. Helping (i) above to reach talent in Africa at @wtf_academy_a , one pop-up at a time.
3. Co-building @multisightapp with @bartosjiri_ on @safe for individuals and teams using multisignature wallets. Happy to chat with teams on this.
4. Accelerating access to knowledge @SciHubFans and coalescing the effort locally @DeSci_NG to increase our collective knowledge bank, enable a culture of research and to proffer custom made solutions for our landscape.
5. Currently cooking and getting cooked @Web3Bridge virtually. Looking forward to meeting folks onsite before Cohort XII ends. By the way, Cohort XIII registration opens in a few days. Take that leap!
Just getting started, it's still day 1! 🧗♂️
"Stay hungry, stay foolish".
Mosa@mofasasi
I've been shuffling web2 and web3 over the last 2 years but this is the year I focus on web3. As someone who's had this shift @Harri_obi , any word of advice for me?
English

who's building @base wrapped for 2024?
would love to give a retro grant to someone who builds something beautiful, shareable, and onchain.
English

@jessepollak @base Grateful for @ttyl5h for onboarding me to the Superchain, creating opportunities for collabs, and always being such a pleasure to work with! 🙌
English

it's thanksgiving week, so I want to try something new — would love everyone to join in.
what's one thing or person in the @base ecosystem that you are grateful for you?
rules: can't be me, share a quick why, tag in whoever it is, stay based.
English

