Jax 🧑🏽‍💻

57 posts

Jax 🧑🏽‍💻 banner
Jax 🧑🏽‍💻

Jax 🧑🏽‍💻

@jax_gitdoctor

here for people who ship fast and don’t want to find out the hard way what they missed.

Katılım Temmuz 2021
8 Takip Edilen5 Takipçiler
Sabitlenmiş Tweet
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
We scanned 500+ GitHub repos with AI. The results were bad, really bad. Hardcoded API keys. No rate limiting. Missing auth. Wildcard CORS. So we built GitDoctor: Paste your repo URL to get an instant security & readiness audit in ~50 seconds. Try Free: gitdoctor.io
English
0
0
1
68
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
kept telling myself "it's just a side project no one's looking at this" and then a recruiter mentioned something from my code in an interview. it's public. people look. more people than you think
English
0
0
0
1
Kelvin Celso
Kelvin Celso@kelvinbuildss·
@jax_gitdoctor You start by engaging with people, as much as you can! that's the best way to start getting some visibility
English
1
0
1
7
Kelvin Celso
Kelvin Celso@kelvinbuildss·
So close to 2k followers My fellow founders, can we get there today?🥹
Kelvin Celso tweet media
English
8
0
15
673
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
spent 3 hours confused why my app was broken for users but fine for me. turns out my computer and the actual internet don't run things the exact same way. wish someone told me this earlier
English
0
0
1
2
GenZDev
GenZDev@dev_gen88926·
I'm a vibe coder, scare me with one word.
GenZDev tweet media
English
212
6
275
40.7K
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
your frontend hides the delete button unless you're logged in. nice but did you check if the API route itself checks who's calling it, or does it just... run whatever request hits it if you can hit your own delete/update endpoint directly with curl and no auth token and it still works, that's the actual security boundary. the button was never it ask your AI tool to add auth checks server-side, not just hide UI
English
0
0
0
3
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
@edinsoncode Fully agreed with the take but for the ones the know how to ship it properly, the ceiling just got 100x higher
English
0
0
0
56
Edinson Carranza
Edinson Carranza@edinsoncode·
Vibe coding isn't making developers faster, it's just making bad code ship quicker.
English
55
2
55
4.6K
Kritika
Kritika@kritikakodes·
I need a cool startup name that sounds like it just raised $100M.🤔
English
121
1
90
8K
Kelvin Celso
Kelvin Celso@kelvinbuildss·
What’s the biggest mistake all first-time founders make?
English
40
0
24
2K
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
deleted your .env file and pushed a new commit? cool, doesn't matter the old commit is still in your git history. anyone can go back and find it run this: git log --all --full-history -- .env if that returns anything, your key is sitting in history even though the file's gone fix is rotating the key, not deleting the file. deleting it just stops new leaks, not the old one
English
0
0
0
4
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
if you're using firebase or supabase, go check your security rules right now if they still say "allow read, write: if true" (the default when you're just trying to get it working), literally anyone can read or wipe your entire database. no login needed this is one of the most common vibe-coded mistakes because the default rules are wide open and most tutorials never tell you to lock them down before shipping two minute fix, ask your AI tool to write proper rules based on your actual auth setup check it today
English
0
0
0
6
Mason
Mason@nosam2006·
Very fast yeah. I've built a whole product with AI with no prior coding experience. The landscape is changing very v fast and you don't actually need to know anything now. The AI can kinda just.. teach you if you need it to. If you have great taste and consistency you can build anything!
English
1
0
1
36
Omkar
Omkar@omkarships·
vibe coding only works well if you already know how to code.
English
233
34
563
37.6K
CHEAF
CHEAF@cheaf25master·
you're starting web development in 2026... Which should you learn first? • Frontend • Backend
English
40
1
29
1.8K
Ethan Mollick
Ethan Mollick@emollick·
“Generate a fake, but believable, witty Churchill insult at a party and explain the context. It should be very clever and original” This time, I think GPT 5.6 Sol Pro wins, but Fable is good too, and you could argue for it taking the prize. Kimi & Gemini miss by a mile.
Ethan Mollick tweet mediaEthan Mollick tweet mediaEthan Mollick tweet mediaEthan Mollick tweet media
Ethan Mollick@emollick

“Generate a fake, but believable, witty Churchill insult at a party and explain the context. It should be very clever and original” I think this is a Claude victory. (Also the weights apparently favor the hypothetical existence of an annoying Sir Reginald)

English
21
10
208
47.2K
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
@kelvinbuildss linux server behaves the same whether it's my laptop or prod. no "works on my machine" surprises from mac-specific quirks
English
1
0
3
61
Kelvin Celso
Kelvin Celso@kelvinbuildss·
Founders, Give me one reason to pick windows/linux over Mac
English
19
1
10
1.6K
Kelvin Celso
Kelvin Celso@kelvinbuildss·
Hey programmers, how much RAM do you actually need? -8 GB -16 GB -24 GB -32 GB -64 GB+
English
88
2
52
12.7K
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
quick vibe check for your vibe-coded app: open dev tools → network tab → refresh → click any request to openai/anthropic/whatever see your API key just... sitting there in the headers? that's bad. anyone who opens dev tools on your live site can grab it and run up your bill fix: move that call to a backend route. tell your AI tool "put this behind a backend endpoint so the key isn't exposed to the browser" — it knows how, it just doesn't do it unless asked two minute check. do it now if you have anything live
English
0
0
1
15
Jax 🧑🏽‍💻
Jax 🧑🏽‍💻@jax_gitdoctor·
Quick check most people never run: hit yoursite.com/.git/config directly in a browser. If it loads, you haven't just left a stray file exposed. You've left your entire git history publicly downloadable. Every commit, every branch, every "temporary" hardcoded key you committed and later "removed" is still sitting in there, because deleting a file in a new commit doesn't erase it from history. This happens more than people think. It's almost always the same root cause: the build process serves the project's root directory as static files, and .git was never explicitly excluded. Frameworks and static hosts vary on whether this is blocked by default, so don't assume yours handles it for you. How to actually check: Visit yoursite.com/.git/config in a browser. If you see plaintext config instead of a 403/404, you're exposed. If it's exposed, anyone can clone your entire history with a tool like git-dumper in under a minute. No login required. The fix: Add a server/CDN-level rule blocking any path starting with /.git/ (most hosts support this in a few lines of config). Don't rely on .gitignore. That only stops new files from being committed, it does nothing for what's already exposed. If you find secrets in your history after checking, rotate them immediately. Removing the file going forward isn't enough, the leaked value already exists in old commits. Takes five minutes to check, five minutes to fix. Worth doing today if you haven't.
English
0
0
0
29
Barchart
Barchart@Barchart·
U.S. Dollar jumps to highest level in over a year 📈💵🇺🇸
Barchart tweet media
English
41
151
916
96.8K