harsh
1K posts

harsh
@harshwarez
GenAI Eng @ CTS, Ex @ransahai, Ex @codedamncom || Building meaningful stuff.

New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies. More comprehensive article: stepsecurity.io/blog/axios-com…

unpopular opinion: 16GB is plenty if software engineers actually cared about memory efficiency. chrome eating 4GB for 12 tabs is not a hardware problem its a software disgrace. docker consuming 2GB idle is not a feature its laziness. we live in an era where people optimize every single token to save $0.001 on API costs but happily ship electron apps that eat 500MB to display a todo list. if the industry treated RAM the way we treat inference compute - obsessively measuring every byte - 16GB would feel luxurious. the hardware isnt the problem, the software is @adxtyahq

BREAKING: NVIDIA CEO announces “we’ve achieved AGI”


With AI, the gap between capability and judgment is growing fast. You are capable of building literally anything you want and adding every damn feature to your product - but should you? That question is more important than ever. Just because you can, doesn't mean you should.



Just got GitHub Copilot pro for absolutely free for next 2 years 😋🎉


what’s a material thing under $1000 you’ve bought that actually changed your life?










