Justin Bennett

7.8K posts

Justin Bennett banner
Justin Bennett

Justin Bennett

@just_be_dev

Open-source enthusiast; maker. Co-host of @DevtoolsFM. @recursecenter Alum. Prev at @ValDotTown, @oxidecomputer, @ArtsyOpenSource.

Brooklyn, NY Katılım Haziran 2010
3.1K Takip Edilen2.3K Takipçiler
Sabitlenmiş Tweet
Justin Bennett
Justin Bennett@just_be_dev·
Alrighty folks, I've renamed my twitter account from @zephraph to @just_be_dev. Got a placeholder for the old one.
English
0
0
7
1.9K
Justin Bennett retweetledi
Feross
Feross@feross·
🚨 Breaking: Trivy GitHub Actions supply chain attack – 75 out of 76 version tags compromised. If your CI/CD pipelines reference “aquasecurity/trivy-action” by version tag, you’re likely running malware right now. At Socket, we identified that an attacker force-pushed nearly every version tag in the official aquasecurity/trivy-action repository. That’s @​0.0.1 all the way through @​0.34.2. Over 10,000 GitHub workflow files reference this action. The malicious payload runs silently before the legitimate Trivy scan, so nothing looks broken. Meanwhile it’s: - Dumping runner process memory to extract secrets - Harvesting SSH keys - Exfiltrating AWS, GCP, and Azure credentials - Stealing Kubernetes service account tokens The only unaffected tag right now appears to be @​0.35.0. Socket independently detected this at 19:15 UTC and generated 182 threat feed entries tied to this campaign – all correctly classified as Backdoor, Infostealer, or Reconnaissance malware. This is the second Trivy compromise this month. Earlier in March, attackers injected code into the Aqua Trivy VS Code extension on OpenVSX to abuse local AI coding agents. The compromised tags are still active. Pin to @​0.35.0 or use a SHA reference until this is fully remediated. Full write-up: socket.dev/blog/trivy-und…
English
12
103
347
194.7K
Justin Bennett retweetledi
Chris Tate
Chris Tate@ctatedev·
Introducing a new experiment: 𝚎𝚖𝚞𝚕𝚊𝚝𝚎 Local API emulation for CI and no-network sandboxes → No mocks → Fully stateful → Full OAuth flows → Register apps and seed data → Production-fidelity API emulation → Emulates Vercel, GitHub, Google APIs
Chris Tate tweet media
English
30
40
686
53K
Justin Bennett retweetledi
Shu
Shu@shuding·
COBE v2 is here: markers, arcs, attach any HTML elements, Infinite ideas. cobe.vercel.app
English
52
162
2.3K
132.7K
Justin Bennett retweetledi
Nathan Flurry 🔩
Nathan Flurry 🔩@NathanFlurry·
🤘 Securely execute AI-generated Node.js code without a sandbox - 17.9ms coldstarts p99 - 3.4 MB RAM - 56x cheaper than sandboxes - Built on the same tech as Cloudflare Workers - Just a library, no external vendor - Our most metal website yet
Nathan Flurry 🔩 tweet media
Rivet@rivet_dev

Introducing the Secure Exec SDK Secure Node.js execution without a sandbox ⚡ 17.9 ms coldstart, 3.4 MB mem, 56x cheaper 📦 Just a library – supports Node.js, Bun, & browsers 🔐 Powered by the same tech as Cloudflare Workers $ 𝚗𝚙𝚖 𝚒𝚗𝚜𝚝𝚊𝚕𝚕 𝚜𝚎𝚌𝚞𝚛𝚎-𝚎𝚡𝚎𝚌

English
19
6
186
18.6K
Justin Bennett retweetledi
Rivet
Rivet@rivet_dev·
Introducing the Secure Exec SDK Secure Node.js execution without a sandbox ⚡ 17.9 ms coldstart, 3.4 MB mem, 56x cheaper 📦 Just a library – supports Node.js, Bun, & browsers 🔐 Powered by the same tech as Cloudflare Workers $ 𝚗𝚙𝚖 𝚒𝚗𝚜𝚝𝚊𝚕𝚕 𝚜𝚎𝚌𝚞𝚛𝚎-𝚎𝚡𝚎𝚌
English
45
63
829
239K
Jarred Sumner
Jarred Sumner@jarredsumner·
it’s a real WKWebView on macOS haven’t implemented it yet on Linux or Windows. It’ll be Chrome for those, but not exactly sure how it’ll be done yet. The obvious way is CDP, but then it’s not really a WebView.
English
19
0
263
23.9K
Justin Bennett retweetledi
Jarred Sumner
Jarred Sumner@jarredsumner·
In the next version of Bun `Bun.WebView` programmatically controls a headless web browser in Bun
Jarred Sumner tweet media
English
125
149
2.7K
243K
Justin Bennett retweetledi
Kevin A. K.
Kevin A. K.@kevmodrome·
Soft-launching a lil' side project I've been working on! Say hello to Tablinum - a local-first database with built-in sync, collaboration and data persistence! 👇
English
3
3
10
976
Justin Bennett
Justin Bennett@just_be_dev·
@SlackHQ you broke my shortcut keys yo. When someone presses control you ignore all other meta keys. Please don't do that. I use ctrl+option to move windows around and now I can't do that with slack.
English
0
0
0
195
Justin Bennett retweetledi
Ron Mokady
Ron Mokady@MokadyRon·
We're obsessed with background removal so we built another model for it. Introducing **Fibo-Edit-RMBG**: our image editing model, fine-tuned specifically for removing backgrounds. It's open. It's powerful. And it's yours to use. This is exactly why open-source matters - you can take a great model and make it exceptional for YOUR use case. [Link in comments]
Ron Mokady tweet mediaRon Mokady tweet media
English
10
50
673
36.7K
Justin Bennett retweetledi
Lydia Hallie ✨
Lydia Hallie ✨@lydiahallie·
Btw you can add `context: fork` to run a skill in an isolated subagent. The main context only sees the final result, not the intermediate tool calls It gets a fresh context window with CLAUDE.md + your skill as the prompt. The `agent` field even lets you set the subagent type!
Lydia Hallie ✨ tweet media
English
57
81
1.2K
131K
Justin Bennett retweetledi
Daniel Griesser
Daniel Griesser@DanielGri·
Built a slim lib that can be used by your agent to spawn a native web view to interact with you. github.com/hazat/glimpse Starts in <300ms and is fully js hackable. Comes with Pi extension that follows your cursor around for your agents working in the background while you surf.
English
5
17
223
31.2K
Justin Bennett retweetledi
Evan You
Evan You@youyuxi·
Introducing Void, the Vite-native deployment platform: 🚀 Full-stack SDK ⚙️ Auto-provisioned infra (db, kv, storage, AI, crons, queues...) 🔒 End-to-end type safety 🧩 React/Vue/Svelte/Solid + Vite meta-frameworks 🌐 SSR, SSG, ISR, islands + Markdown 🤖 AI-native tooling ☁️ One-command deploys void.cloud
Evan You tweet media
English
224
530
4.3K
711.5K
Justin Bennett retweetledi
Chris Tate
Chris Tate@ctatedev·
json-render now supports YAML as a wire format JSONL needs a full element before rendering YAML is valid at every prefix, going from element-level to property-level 💨 YAML looks like source code to LLMs And we use 3 standards they know: JSON Patch, Merge Patch, Unified diff
English
67
103
1.8K
172.2K
Justin Bennett retweetledi
Chris Tate
Chris Tate@ctatedev·
Introducing @𝚓𝚜𝚘𝚗-𝚛𝚎𝚗𝚍𝚎𝚛/𝚛𝚎𝚊𝚌𝚝-𝚝𝚑𝚛𝚎𝚎-𝚏𝚒𝚋𝚎𝚛 A new renderer that turns JSON specs into interactive R3F scenes Same catalog-driven approach, now for meshes, lights, models, environments, cameras, controls 19 built-in components and 12 demo scenes
English
27
51
824
41K
Justin Bennett retweetledi
kian bazza
kian bazza@kianbazza·
Introducing 𝚑𝚒𝚝-𝚊𝚛𝚎𝚊—a collection of @tailwindcss utility classes for expanding the hit area of interactive elements. Small hit areas are a silent UX killer. One class fixes it. Distributed via @shadcn registry - see link below.
English
58
150
2.5K
127.5K
Justin Bennett retweetledi
Thariq
Thariq@trq212·
We just added /btw to Claude Code! Use it to have side chain conversations while Claude is working.
English
1.2K
1.6K
26K
2.7M