


These days except few portfolios all look nearly same I will be recreated my portfolio from scratch I will start with just html and plain css lets see how good i can make with it.
Atulya Rai
393 posts

@snehit70
I post what I’m learning in code. Linux, Neovim, AI/ML, and random experiments.



These days except few portfolios all look nearly same I will be recreated my portfolio from scratch I will start with just html and plain css lets see how good i can make with it.




New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies. More comprehensive article: stepsecurity.io/blog/axios-com…




This 18 year old literally has 12 $200 Codex plans. Here's exactly how he organizes them to build 100x faster: (we're cooked)


sneak peek of my new portfolio design ..........
