boxersb

6.9K posts

boxersb banner
boxersb

boxersb

@boxersb

Just programmer. Terran or Zerg

Katılım Temmuz 2009
560 Takip Edilen594 Takipçiler
boxersb retweetledi
GeekNews
GeekNews@GeekNewsHada·
시니어 개발자가 전문성을 전달하지 못하는 이유 - 시니어 개발자와 비개발자는 AI 에이전트가 개발자를 대체한다는 같은 문장을, 안정성과 시장 학습이라는 서로 다른 기준으로 받아들임 - 비즈니스 조직은 빠르게 출시해 피드백을 얻고 불확실성을 줄이려 하지만, 시니어… news.hada.io/topic?id=29459
한국어
0
10
36
4.4K
boxersb retweetledi
Theo - t3.gg
Theo - t3.gg@theo·
Security things from the last few days: - CopyFail (linux pwn'd) - CopyFail 2/Dirty Frag - 13 advisories in Next.js - Over 70 CVEs addressed in MacOS 26.5 - ~50 CVEs addressed in iOS 26.5 - YellowKey (Windows Bitlocker pwn'd entirely) - GreenPlasma (Windows privilege escalation) - CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE - CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access - Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning) - Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too" - Canvas (popular LMS used in most schools) pwn'd entirely - PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300 Are you scared yet?
English
348
985
6.8K
738.2K
boxersb
boxersb@boxersb·
CAVEMAN 스킬 쓰다보니 내 말투도 rocky 나 군 선임 처럼 변해버림.
boxersb tweet media
한국어
0
0
0
15
boxersb retweetledi
Neverland
Neverland@jait_chen·
Supply-chain attacks through GitHub Actions are becoming increasingly difficult to prevent. Attackers can now use agents to discover new attack paths and automate exploitation at a scale we haven’t seen before. Huge respect to the TanStack team for reacting so quickly and communicating clearly. For users, upgrading to pnpm 11 is probably one of the safest choices right now, since it ships with minimum-release-age enabled by default, plus several other protections against malicious packages.
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
4
8
67
9.6K
boxersb
boxersb@boxersb·
여러모로 커리어의 종말을 기다리고 있는듯한,, AI로 다 하니까 재미가 없다,, ㅎㅎ
한국어
0
0
1
25
boxersb retweetledi
dalgom.bami
dalgom.bami@dalgom_bami·
"영어 미팅할 때 그냥 한국어로 말해도 내가 영어로 말하는 것 처럼 해주세요" 처음에 이런 피드백을 받았을 때 제 엔지니어 자아가 아 그건 조금 어려운데.. 구글도 아직 완벽하게는 못하고 있는데.. 라고 생각했었습니다. 근데 정말 많은 분들이 계속 같은 요청을 주시고, 애초에 그걸 기대하면서 설치하시는 걸 보면서 이건 꼭 만들어야겠다라고 생각하게 되었습니다. 정말 수많은 AI모델간의 조합을 테스트해보면서 직접 학습도 돌려보고 튜닝도 해보면서 단순 데모가 아닌 실제 미팅에서 쓸만한 퀄리티가 될 때 까지 오래 연구했고, 이제는 제가 들어도 제 목소리로 진짜 영어로 하는 것처럼 들립니다. 이 기능을 켜면 구글밋, 줌, 팀즈에 봇이 따라 들어와 내가 한국어로 말하면 내 목소리로 유창한 영어를 하기 시작합니다. 이 기능이 필요하신 분들은 댓글의 신청 폼을 통해 얼리억세스에 신청해주세요! 곧 제품에 탑재할 예정인데 장시간 미팅, 실제 유저 테스트를 충분히 진행하고 출시할 계획입니다.
한국어
5
34
200
18.4K
boxersb retweetledi
Yoonho
Yoonho@youknow04·
이거지. 옛날부터 기술부채 관리하며 개발 하던 사람들은 AI 코딩 하면서도 어차피 기술부채 관리 하고 있을거다. 기술부채를 지나치게 당겨쓰는 사람들은 AI 코딩 전이나 후나 원래 있었는데, AI 코딩으로 그 속력만 높이면 늪으로 가는 하이패스가 되는거고.
GeekNews@GeekNewsHada

코드 작성에 쓰는 AI 코딩 에이전트는 반드시 유지보수 비용을 줄여야 함 - AI 코딩 에이전트가 코드 작성 속도를 높이더라도 유지보수 비용을 같은 비율로 줄이지 못하면, 일시적 생산성 향상 후 오히려 영구적인 생산성 저하로 이어짐 - 모든 코드는 작성 후 버그 수… news.hada.io/topic?id=29399

한국어
2
69
187
22.4K
boxersb retweetledi
Outsider
Outsider@Outsideris·
microsoft.github.io/waza/ MS에서 만든 AI 에이전트 스킬을 벤치마크로 평가하는 Go CLI. 스킬이 고도화될수록 이런 도구들로 환경을 구성할 필요성이 커질것 같다.
한국어
0
5
21
1.8K
boxersb retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 How the TanStack npm attack actually happened: 1. Attacker opened a normal-looking pull request (#7378) on the TanStack repo. 2. GitHub automatically ran CI tests on that PR. 3. Code inside the PR stole the workflow's GitHub Actions Cache write token during the test run. 4. The attacker used that token to plant poisoned files in the shared build cache. The PR could be closed afterwards. The poisoned cache stays. 5. The official release workflow later pulled from the cache, baked the malicious files into the build, and signed and published 84 malicious package versions to npm.
Adnan Khan@adnanthekhan

This attack leveraged GitHub Actions Cache Poisoning. Payload deployed here: github.com/TanStack/route… It looks like it detonated here: #step:26:2" target="_blank" rel="nofollow noopener">github.com/TanStack/route…

English
61
574
4.7K
798.5K
boxersb retweetledi
Claude
Claude@claudeai·
New in Claude Code: agent view. One list of all your sessions, available today as a research preview.
English
988
2.2K
28.8K
5.7M
boxersb retweetledi
Outsider
Outsider@Outsideris·
mise를 만들 Jeff Dickey가 Figma를 퇴사하고 en.dev 라는 1인 오픈소스 개발 회사를 만들어서 오픈소스 풀타임 개발을 한다고 한다. 후원으로 수입을 만들고 장기적으로는 mise로 유료 서비스를 만들 생각인거 같은데 좋은 사례가 되었으면 좋겠다. jdx.dev/posts/2026-04-… en.dev
한국어
0
14
54
3.1K
boxersb retweetledi
Paul Bohm
Paul Bohm@paulbohm·
If your startup does not have a UUID microservice you’re ngmi
Paul Bohm tweet media
English
189
274
6.8K
687.8K
boxersb retweetledi
ClaudeDevs
ClaudeDevs@ClaudeDevs·
/radio
Español
329
877
14.7K
1M
boxersb retweetledi
AYi
AYi@AYi_AInotes·
Claude团队的工程师,已经彻底抛弃Markdown了。 不是Markdown不好用, 是AI变得太快,它已经跟不上了。 以前AI写10行笔记,Markdown刚刚好, 现在AI能一次性输出1000行计划、复杂流程图、完整代码审查, 密密麻麻的纯文字墙谁有耐心看得完? 作者自己都说,他从来没完整读完过100行以上的AI生成MD文件。 更要命的是:现在都是AI写,我们只看不改。 Markdown最大的优点“易手动编辑”,现在已经彻底没用了。 而HTML,才是AI时代真正的沟通语言, 它能做到的事,Markdown想都不敢想: • 直接生成带颜色的表格、SVG流程图、可点击的原型 • 加滑块调参数、拖拽排序任务、实时预览Prompt效果 • 改完一键导出成代码或Prompt,喂回给AI继续迭代 • 发个链接别人点开就能看,不用下载任何工具 作者直接放出了20个现成示例: 从代码审查的彩色diff, 到可拖拽的任务看板, 从动画参数调试器, 到一键生成的幻灯片。 每一个都是能直接用的生产力工具。 最爽的三个用法,现在就能抄: 1. 代码审查:让AI把PR生成带注释的彩色diff+模块调用图 2. 做计划:生成带时间线、风险表、流程图的交互式项目页 3. 临时工具:让AI写一个Prompt调参器,改完直接复制结果 当然它也有缺点: 多花一点token,生成时间长2-4倍,版本控制不如MD干净。 但作者说:体验提升了10倍,这些代价完全值得。 本质上不是格式之争,而是人机协作方式的升级。 因为Markdown是给人写给人看的, 而HTML是给AI写给人用的。 随着当AI越来越聪明,我们需要的不再是文字墙,而是能互动、能操作、能思考的界面。 现在打开Claude,输入“帮我做一个HTML文件……”,你会打开一个全新的世界。
Thariq@trq212

x.com/i/article/2052…

中文
197
601
4.4K
1.4M
boxersb
boxersb@boxersb·
ㅋㅋㅋ 이것이 AX다!
Brian Armstrong@brian_armstrong

This is an email I sent earlier today to all employees at Coinbase: Team, Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future. Why now Two forces are converging at the same time. We need to be front footed to respond to both. First, the market. Coinbase is well-capitalized, has diversified revenue streams, and is well-positioned to weather any storm. Crypto is also on the verge of the next wave of adoption, with stablecoins, prediction markets, tokenization, and more taking off. However, our business is still volatile from quarter to quarter. While we've managed through that cyclicality many times before and come out stronger on the other side, we’re currently in a down market and need to adjust our cost structure now so that we emerge from this period leaner, faster, and more efficient for our next phase of growth. Second, AI is changing how we work. Over the past year, I’ve watched engineers use AI to ship in days what used to take a team weeks. Non-technical teams are now shipping production code and many of our workflows are being automated. The pace of what's possible with a small, focused team has changed dramatically, and it's accelerating every day. All of this has led us to an inflection point, not just for Coinbase, but for every company. The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core. What this means To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it. What does this mean in practice? - Fewer layers, faster decisions: We are flattening our org structure to 5 layers max below CEO/COO. Layers slow things down and create coordination tax. The future is small, high context teams that can move quickly. Leaders will own much more, with as many as 15+ direct reports. Fewer layers also means a leaner cost structure that is built to perform through all market cycles. - No pure managers: Every leader at Coinbase must also be a strong and active individual contributor. Managers should be like player-coaches, getting their hands dirty alongside their teams. - AI-native pods: We’ll be concentrating around AI-native talent who can manage fleets of agents to drive outsized impact. We’ll also be experimenting with reduced pod sizes, including “one person teams” with engineers, designers, and product managers all in one role. In short: AI is bringing a profound shift in how companies operate, and we’re reshaping Coinbase to lead in this new era. This is a new way of working, and we need to leverage AI across every facet of our jobs. To those who are affected I know there are real people behind these decisions — talented colleagues who have poured themselves into this company and our mission. To those of you who will be leaving: thank you. You’ve helped build Coinbase into what it is today, and I am sincerely grateful for everything you've done. All impacted team members will receive an email to their personal account in the next hour with more information, and an invitation to meet with an HRBP and a senior leader in your organization. Coinbase system access has been removed today. I know this feels sudden and harsh, but it is the only responsible choice given our duty to protect customer information. To those affected, we will be providing a comprehensive package to support you through this transition. US employees will receive a minimum of 16 weeks base pay (plus 2 weeks per year worked), their next equity vest, and 6 months of COBRA. Employees on a work visa will get extra transition support. Those outside of the US will receive similar support, based on local factors and subject to any consultation requirements. Coinbase prides itself on talent density. Our employees are among the most talented people in the world, and I have no doubt that your skills and experience will be highly sought after as you pursue your next chapters. How we move forward To the team that is staying, I know this is a difficult day. We’re saying goodbye to colleagues and friends you've been in the trenches with. But here’s what I want you to know as we move forward together: Over the past 13 years, we have weathered four crypto winters, gone public, and built the most trusted platform in our industry. We’ve made it this far by making hard decisions and by always staying focused on our mission. This time will be no different – nothing has changed about the long term outlook of our company or industry. And most importantly, our mission has never been more important for the world. Increasing economic freedom requires a new financial system, and we’re building it. The Coinbase that emerges from this will be more capable than ever to achieve our mission. Brian

한국어
0
0
0
40
boxersb retweetledi
빅웨이브
빅웨이브@travis20260121·
호갱노노 앱을 개발한 심상민 대표도 인상적인 케이스. 1. 네이버, 카카오 개발자 출신 2. 카카오 재직 시절부터 천재 개발자로 명성 떨침 3. 동료들과 함께 창업해 ‘호갱노노’ 개발 4. 직방에 ‘호갱노노’ 200억대에 팔고 CEO 직위는 유지 5. 현재는 직방도 떠나서 ‘카페노노’라는 스타트업 창업 6. 압도적으로 자신을 증명한 사람이기에 새 사업을 할 때 투자 유치 수월. 7. 한 번의 큰 성공은 어렵지만, 그걸 이뤄낸 사람은 그 다음 뭔가를 시작할 때 비교적 수월해짐. 8. ‘호갱노노’라는 앱을 만든 이유는 결국 많은 사람이 ‘무엇에 불편해하는지’ 이해하고 그것을 해결하려고 했기 때문. 9. 이 세상의 비즈니스의 본질은 결국 ‘내가 어떻게 저 사람을 도와줄 수 있을까’
한국어
18
102
704
128.5K
boxersb retweetledi
りゅう@Obsidianガチ勢
りゅう@Obsidianガチ勢@obsidianstudio9·
【速報】 Obsidian公式がAIエージェント用スキルを正式リリース😳 CEOのkepano自らが作ったobsidian-skillsが公開された。 Claude CodeにObsidianの使い方を教えるスキル集👇 ・Markdown構文の正しい扱い方 ・Bases(データベース機能)の操作 ・JSON Canvasの生成と編集 ・CLIでのvault操作 ・Webコンテンツの取り込み 5つのスキルが1セットになってる。 つまりObsidian公式が「AIエージェントにvaultを任せる」前提で設計し始めた。 この流れは確実に加速する🔥 github.com/kepano/obsidia…
日本語
12
215
1.7K
101.8K