
MJ
43.3K posts

MJ
@mjackson
Building @remix_run at @Shopify. God hath not given us the spirit of fear; but of power, and of love, and of a sound mind – 2 Tim 1:7


@simonklee > this is bad news Most of the feedback from OpenCode users to Bun has been crash reports. Many of these crash reports would not have happened with a borrow checker and lifetimes and automatic cleanup Rust provides. Please file issues if you run into any and we will fix.

There are basically 5 ways to accumulate a billion dollars: 1) Profiting from a monopoly 2) Insider-trading 3) Political payoffs 4) Fraud 5) Inheritance Don’t believe the self-made myth.


SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.


This is hard, kids. Real hard. Can you appreciate the touch on the controls necessary to be this smooth, this close?


Multiple security vulnerabilities affecting React Server Components and Next.js have been disclosed. We strongly recommend updating your applications immediately. Cloudflare WAF managed rules already mitigate the disclosed denial-of-service vulnerabilities, and we are investigating additional coverage for several other CVEs. developers.cloudflare.com/changelog/post…



A peak behind the scenes of our brand update and how we built the new Remix homepage



I don't remember where I found this, but its spot on.










