Caio Rhian

1.4K posts

Caio Rhian

Caio Rhian

@caiorhian

🇧🇷 Head of Engineering at @rediredi.br

Brasília, Brasil Katılım Ağustos 2009
566 Takip Edilen238 Takipçiler
Caio Rhian retweetledi
Andrej Karpathy
Andrej Karpathy@karpathy·
New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies. More comprehensive article: stepsecurity.io/blog/axios-com…
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
558
1.1K
10.5K
1.5M
Caio Rhian
Caio Rhian@caiorhian·
@liques @liques e a galera de front do time, fica atualizando localmente? ou compartilha com eles por outra maneira?
Português
1
0
0
13
Caio Rhian
Caio Rhian@caiorhian·
Galera de backend, vocês tem documentando API como? Swagger? Postman? Bruno?
Português
1
0
0
27
colinhacks/zod
colinhacks/zod@colinhacks·
whoa. I just found a way to properly infer recursive types in z.object() — no casting, no z.lazy(), no scopes/registries, no special syntax. i've been trying to do this for literally years
colinhacks/zod tweet media
English
51
115
2.2K
157.4K
Caio Rhian retweetledi
RediRedi Brasil
RediRedi Brasil@RediRediBrasil·
O que é a RediRedi? 🔍 Venda produtos online e localmente com o catálogo digital de sua loja. Monte seu catálogo em poucos minutos com ajuda da inteligêcia artificial da RediRedi. Obtenha fotos automáticas dos seus produtos e economize tempo.
RediRedi Brasil tweet media
Português
0
2
0
94
Arvid Kahl
Arvid Kahl@arvidkahl·
Full-text search on 500GB+ of data is keeping me awake at night. MySQL's full-text index just can't handle this. Often takes minutes. And Meilisearch, as fast as it is, is hard to wrangle to get it to get only precise results. Anyone here experienced with search at this size?
English
562
68
1.8K
924K
Jason Bosco
Jason Bosco@jasonbosco·
Just hit 2 BILLION searches per month on @Typesense Cloud. 2,000,000,000 This time last year, we were just about to reach 500M, and that sounded surreal at the time. We're now doing 4 times that volume, with peaks of 425K searches per minute 🤯
Jason Bosco tweet media
English
16
21
502
562K
Caio Rhian
Caio Rhian@caiorhian·
@thdxr That should be fine, I believe dashbird.io works like that. Bundled/minified functions might log huge logs while logging the stack when sourcemap isn’t present. Is that a concern?
English
1
0
1
48
dax
dax@thdxr·
@caiorhian i'm not a huge fan of adding yet another library - we'll likely operate off `console.error` calls where you pass in any JS Error not too hard for us to parse those
English
1
0
0
97
dax
dax@thdxr·
just put out beta2 of the SST Console logs are now more powerful you can page through the most recent invocations or jump to point in time, plus a bunch of other goodies we built exactly what we needed ourselves to debug errors next step - automatic sourcemap support
English
8
1
44
7.5K
Caio Rhian
Caio Rhian@caiorhian·
e lançaram o MacBook Air 15", considerando a perfomance do 13.6", esse novo promete
Português
0
0
0
71
mah
mah@Marcelasmorais·
É tão bom ver amigos entrando na faculdade e no curso que eles queriam!! 🥺🥺
Português
1
0
4
252
Caio Rhian
Caio Rhian@caiorhian·
Rumores de que hoje sai um MacBook novo, será que vem o M2 Pro ai?
Português
0
0
0
92
mah
mah@Marcelasmorais·
Tenho vontade de ser medvloger só pra ser fazer patrocinada pela dr cherie
Português
3
0
5
354
Scott
Scott@akarolscott·
Finalmente vou jogar TLOU
Português
3
0
4
183
Caio Rhian
Caio Rhian@caiorhian·
Não da pra entender porque o macOS ainda não suporta contas Microsoft nativamente igual suporta as do Google
Português
0
0
0
0