

Simon
10.8K posts










📢 Starting today, Channel Points, emotes, subs, Bits, and badges are available to all streamers on Twitch - no Affiliate status required! These tools help you build a community from day one 💜 Enroll and complete your setup in your dashboard today: 🔗 dashboard.twitch.tv/monetization/r…

Party Animals AI Video Contest is about to begin! What wild ideas have you had for Party Animals? Join the "Golden Paw Awards" now — Party Animals 1st AI Video Contest! A short film you've been dreaming of making, a story that breaks all the rules, a character tribute to your favorite beast... In the past, ideas like these could only exist in your head. Now, with AI, they finally have a chance to become reality. So we're inviting you to bring your ideas to life with AI. During 9:00 AM May 14 — 8:59 AM August 31, 2026(PT), post your video with the hashtags #PartyAnimalsAIVideoContest and #PartyAnimals for a chance to win a share of $75,000 in cash prizes! Get those paws moving and start creating! For more details, check: forum.partyanimals.com/d/12604

Le está lloviendo durísimo a los devs de TanStack. Tenía pensado usarlo en lugar de Nextjs pero con todo esto mejor me espero.



SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.



In the next version of Bun `Bun.Image` - fast builtin multi-format image processing library









Oh, let's break it down... 🤝 📍@Aspen_OW's Overwatch Showdown presented by @Honda on Twitch Rivals. 🗓️ Apr 17-18, 2pm PT 📺 /TwitchRivals