
Jerónimo López
45.5K posts

Jerónimo López
@jerolba
Picador de código en @ClarityAIEng






We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby

Atención al alemán Andreas Schwab, presidente de Control Presupuestario en la Eurocámara y miembro de la CDU: "Es inaceptable que España use fondos europeos para encubrir falta de presupuestos" elmundo.es/economia/2026/…


We’ve also agreed to acquire Tomoro, which will bring 150 experienced Forward Deployed Engineers and Deployment Specialists to the OpenAI Deployment Company from day one.



Buen artículo 👇👇 larsfaye.com/articles/agent…

🚨 How the TanStack npm attack actually happened: 1. Attacker opened a normal-looking pull request (#7378) on the TanStack repo. 2. GitHub automatically ran CI tests on that PR. 3. Code inside the PR stole the workflow's GitHub Actions Cache write token during the test run. 4. The attacker used that token to plant poisoned files in the shared build cache. The PR could be closed afterwards. The poisoned cache stays. 5. The official release workflow later pulled from the cache, baked the malicious files into the build, and signed and published 84 malicious package versions to npm.

«El joven conoce las reglas, pero el anciano conoce las excepciones.» -Oliver Wendell Holmes


Otro día más. De verdad que me voy a plantear seriamente hacer un uptime monitor para la pasarela cl@ve.




