Maxime Richard retweetledi
Maxime Richard
7.3K posts

Maxime Richard
@rmaximedev
Staff Engineer @getqonto, 📝 @obsdmd nerd, 🥐 Meetup @AperoWebNancy
Nancy, France 🇫🇷 Katılım Nisan 2011
1.1K Takip Edilen438 Takipçiler
Maxime Richard retweetledi

🚀 React Hook Form v7.74.0 is out
🪇 New: setValues for flexible updates
🐞 Fixes:
• preserve value when useController name changes
• handle null parent on nested unregister
• treat NaN as empty with valueAsNumber
Small release, solid improvements 👌
github.com/react-hook-for…

English
Maxime Richard retweetledi
Maxime Richard retweetledi

Bitwarden identified and contained a malicious package briefly distributed through the npm delivery path for the Bitwarden CLI in connection with the broader Checkmarx supply chain incident. No user vault data or production systems were compromised or at-risk. Additional details and updates are available here: community.bitwarden.com/t/bitwarden-st…
English
Maxime Richard retweetledi

The planet can spell your name – literally. 🔤🌍
This Earth Day, see your name written in landscapes captured by Landsat: go.nasa.gov/4ak4Cdu

English
Maxime Richard retweetledi

Heads up! Bitwarden CLI v2026.4.0 was compromised in the ongoing Checkmarx supply chain campaign.
Attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline to ship malicious code.
We'll update this post as more details are confirmed.
socket.dev/blog/bitwarden…

English
Maxime Richard retweetledi

Today, we’re open-sourcing the draft specification for DESIGN.md, so it can be used across any tool or platform. We’re also adding new capabilities.
DESIGN.md lets you easily export and import your design rules from project to project. Instead of guessing intent, agents know exactly what a color is for and can even validate their choices against WCAG accessibility rules.
Watch David East break down this shared visual language in action👇. New capabilities and links in 🧵
English
Maxime Richard retweetledi

Git 2.54 is here with features like config-based hooks, new ways to rewrite history, and much more. ✨
Check out the highlights from this release. 👇
github.blog/open-source/gi…
English
Maxime Richard retweetledi
Maxime Richard retweetledi

The full story of the extension @davebcn87 & @tobi open-sourced is on our Eng Blog:
shopify.engineering/autoresearch
English
Maxime Richard retweetledi
Maxime Richard retweetledi

Finally, @Tan_Stack Start now supports React Server Components!
Start's RSCs are a truly fetchable, cacheable and composable primitive that work with your favorite tools instead of dictating your entire architecture.
Oh, and one more thing... "Composite Components" 😉
🔗⬇️🧵

English
Maxime Richard retweetledi

Build your own HTTP client with fetch-extras
Take only what you need. Tree-shakeable.
Built on Fetch. Works in the browser, Node.js, etc.
github.com/sindresorhus/f…

English
Maxime Richard retweetledi
Maxime Richard retweetledi

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
Maxime Richard retweetledi
Maxime Richard retweetledi

Next.js 16.2 introduces a stable Adapter API, built with Netlify, Cloudflare, OpenNext, AWS, and Google Cloud. But the API is only part of the story.
Next.js is used by millions of developers across every major cloud, and making it work well everywhere is on us. Here are our commitments.
nextjs.org/nextjs-across-…
English
Maxime Richard retweetledi

TypeScript 6.0 is now available!
This release brings better type-checking for methods, new standard library features, new module features for Node.js, and more!
But most important, this release brings us one step closer to the upcoming native-speed 7.0!
devblogs.microsoft.com/typescript/ann…
English
Maxime Richard retweetledi

Maxime Richard retweetledi









