Budapeşte

316 posts

Budapeşte

Budapeşte

@solpeste

web developer and psychologist

Katılım Şubat 2023
279 Takip Edilen8 Takipçiler
Budapeşte
Budapeşte@solpeste·
once again i'm stuck with nextjs for a project i got hired to do an i'm hating every second of it....... why is it so slow on dev? also what even is the advantage of using turbopack??
English
0
0
1
6
Budapeşte
Budapeşte@solpeste·
@AnaArsonist i like it because the battery is good, i don't care about the enter key's size
English
0
0
0
13
ana howard
ana howard@AnaArsonist·
HOW DO PEOPLE LIKE THIS KEYBOARD LAYOUT WHY WOULD I WANT A THIN ENTER KEY
ana howard tweet media
English
40
1
112
22.7K
Jinjing Liang
Jinjing Liang@JinjingLiang·
Easiest way to protect yourself: 1. Use pnpm 2. Set a minimum-release-age
Jinjing Liang tweet media
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
50
113
1.5K
211.5K
Budapeşte
Budapeşte@solpeste·
@jarredsumner passing tests is great but have you been using the rust port internally already? this feels rushed
English
0
0
0
65
Jarred Sumner
Jarred Sumner@jarredsumner·
Bun v1.3.14 releases tomorrow. If we do merge the Rust rewrite, this would be the last version in Zig
English
188
159
3.2K
594.4K
Ti Girl 💗
Ti Girl 💗@thoniahilary·
I understand useState, but I’m struggling with useEffect. One-sentence explanations could go a long way.
English
44
9
245
23.2K
Budapeşte
Budapeşte@solpeste·
@IroncladDev i like naming files based on the variable name in it, i used to name everything very carefully like "project.get.ts" but your team members aren't looking for feature names they usually search for variable names instead like projectGet etc.
English
0
0
0
156
IroncladDev
IroncladDev@IroncladDev·
an "organized" or "nested" file structure vs a "flat" file structure has the potential to lead to a lot of complexity in a nested structure, you can't see how big everything is becoming in a flat structure, it might make you think twice I haven't tried it, but this might be good for building something lightweight by design
IroncladDev tweet media
English
37
2
120
21K
Budapeşte
Budapeşte@solpeste·
@_newtonjob using assertions instead of a fallbacks is good but what even is this option? most of the time that code will not compile
English
1
0
0
16
Newton Job
Newton Job@_newtonjob·
If you're almost certain something should be defined, then just drop the fallback. I've learnt over the years to avoid excessive defensive programming and just "letting it crash". Too much fallback swallows issues that you should know in time. Teach your agents.
Newton Job tweet media
English
33
10
197
23.7K
Budapeşte
Budapeşte@solpeste·
@StanleyMasinde_ i don't think you should call ignoring headers altogether a small issue
English
0
0
0
129
John Doe
John Doe@StanleyMasinde_·
Today on stream we discovered why this would fail. It is a small issue that a REST die hard can spot.
John Doe tweet media
English
8
9
58
5K