
Yaser Alkayale
1K posts

Yaser Alkayale
@yaseralkayale
Building CivCore, prev @instagram 🚀



Oh my god it scored worse than Composer 2! Not even 2.5! And it cost 4x more to run!!! This might be the worst major lab model drop of all time. Llama 4 tier. Insane.


The Railway dashboard is currently unavailable, and services running on our cloud infrastructure are down. Services running on Railway Metal are not affected. We're working with our upstream provider to restore service. Updates: status.railway.com




Cannot believe you can just ask for things like “can I have a place to stay in Napa?” and someone on this site will just give it to you.

If MongoDB has taught me anything, it's that you can ship horribly unreliable, yet data critical software and still get boatloads of customers as long as it is what customers want. You can always make it more reliable over time.


The eternal debate is over. @raycast


if you dont use cursor: pointer on buttons you should stop writing css


It is time for the United States Postal Service to ban junk mail. Unsolicited spam calls are already prohibited by the FCC. Emails are heavily regulated by the CAN-SPAM Act of 2003. Junk mail is the majority of mail, 100 million trees per year. Enough!

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.




what would github look like if @linear designed it? oh wait a second…




