
@npmjs @GHSecurityLab there is an active supply chain attack on axios@1.14.1 which pulls in a malicious package published today - plain-crypto-js@4.2.1 - someone took over a maintainer account for Axios
Jason Swartz
15.4K posts

@swartzrock
Let's talk dev productivity & side projects. Enjoys DX, UX, 2D graphics, writing, public speaking, Scala. Alumni of Twitch & Netflix & Broderbund.

@npmjs @GHSecurityLab there is an active supply chain attack on axios@1.14.1 which pulls in a malicious package published today - plain-crypto-js@4.2.1 - someone took over a maintainer account for Axios


My son Max deadlifting 160KG easy






🆕 How to Kill The Code Review latent.space/p/reviews-dead the volume and size of PRs is skyrocketing. @simonw called out StrongDM’s “Dark Factory” last month: no human code, but *also* no human review (!?) in this week’s guest post, @ankitxg makes a 5 step layered playbook for how this can come true.



Cant get enough of these LA skyline + snowy mountain photos.




"San Francisco is so beautiful." 90% of San Francisco:

we're launching the new Sentry CLI. it's made for developers and agents, by developers and agents, with a focus on dev workflows. It's has things backed in like: