Richard Feldman

2.5K posts

Richard Feldman banner
Richard Feldman

Richard Feldman

@rtfeldman

Let’s go with the ambitious approach.

Philadelphia, PA Katılım Eylül 2008
675 Takip Edilen16.7K Takipçiler
Richard Feldman retweetledi
Loris Cro ⚡
Loris Cro ⚡@croloris·
My take on the bun stuff #c_kvngy9" target="_blank" rel="nofollow noopener">lobste.rs/s/lapqbz/bun_s…
English
8
16
158
15.6K
Richard Feldman retweetledi
Zed
Zed@zeddotdev·
Big diff go brrrrr
English
116
142
3.9K
260.5K
Richard Feldman retweetledi
Joseph Lyons
Joseph Lyons@MyDeathMachine·
It's wild to think Nathan and I were chatting about Zed before the pandemic. Really puts into perspective the sheer amount of time and effort behind this tool.
Joseph Lyons tweet media
English
0
1
3
999
Richard Feldman retweetledi
RWX
RWX@rwx_cloud·
We're excited to roll out RWX sandboxes today, giving coding agents (and humans) one platform for the inner loop of running individual tests, and the outer loop of running all of CI. rwx.com/blog/rwx-sandb…
English
1
2
6
656
Richard Feldman
Richard Feldman@rtfeldman·
Weird how it's always companies with financial problems that are suddenly doing layoffs "for AI reasons."
English
2
2
56
2.2K
Richard Feldman retweetledi
Datastar Cult Leader
Datastar Cult Leader@DelaneyGillilan·
Just a daily reminder. Datastar has no dependencies, no NPM, private dev repo. In fact we use Go to compile our builds. Hypermedia first is about state in the right place and simple security across the whole process. Be safe y'all
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
2
6
61
5.6K
Richard Feldman retweetledi
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
Published via OIDC trusted publishing btw. I hope this ends this absurd idea that OIDC is the silver bullet to supply chain issues.
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
15
41
574
69.5K
Richard Feldman retweetledi
Filip Jerzy Pizło
Filip Jerzy Pizło@filpizlo·
Want to know more about Fil-C? I'll be giving a talk about it at Software Should Work this July! Lots of cool folks will be there. Join us! softwareshould.work
English
1
5
60
3K
Richard Feldman retweetledi
Software Unscripted
Software Unscripted@sw_unscripted·
Episode 118: AI & Software Quality with @swyx! 🎉
Italiano
1
2
6
1.2K
Richard Feldman retweetledi
Ben Dicken
Ben Dicken@BenjDicken·
FYI physics is still physics. NVMe is fast. Felt like a good day to update you all on this
English
110
144
3.3K
683.2K
Richard Feldman retweetledi
Jonathan Blow
Jonathan Blow@Jonathan_Blow·
It's been 3 months since the 100x vibers started 100x vibin'! So, post your 25-years-of-work-equivalent project here, so we can signal boost and everyone can celebrate the Life's Work that you did in 3 months. Looking forward to it, Let's Go!!!
English
232
252
5.2K
386.3K
Richard Feldman retweetledi
Brian Cardarella
Brian Cardarella@bcardarella·
Earlier in my career I worked at a company that built the backend call center software for a large industrial company. They intentionally tried to encourage people to hang up and considered it part of their success metrics. Customer support used to be seen as part of customer retention but has long since been viewed as a cost most companies would prefer to avoid.
English
0
1
3
1.1K
Richard Feldman
Richard Feldman@rtfeldman·
Back in the 1990s, if I called a customer service phone line, I'd typically wait 5-45 minutes before any interaction with a human. Today, as soon as the call connects, I'm instantly interacting with an automated phone tree. Waiting on hold was ASTRONOMICALLY less infuriating.
English
7
1
26
3.3K