zeb

2.6K posts

zeb

zeb

@zebassembly

eng @cloudflare he/him

Katılım Eylül 2019
636 Takip Edilen3.5K Takipçiler
zeb
zeb@zebassembly·
@acoyfellow if this isn't screaming XAB idk what is
English
1
0
3
150
Jordan Coeyman
Jordan Coeyman@acoyfellow·
"capa" Turn OpenAPI specs into Cloudflare service bindings - Stripe, GitHub, GitLab, Jira, Slack, Twilio, Kubernetes, Box, Discord, Zoom + more - 13 capabilities so far, lmk what else to add - 5,852 generated methods you can bind to today capa.coey.dev
Jordan Coeyman tweet media
English
12
8
110
12.5K
zeb
zeb@zebassembly·
I wonder what Matt I'm going to work with today
English
3
2
39
2.7K
zeb retweetledi
Matt Simpson
Matt Simpson@msmps_·
point → annotate → ship any opentui renderable, to any agent. clipboard or mcp.
English
10
10
159
22.5K
zeb
zeb@zebassembly·
A very important part of onboarding to cloudflare as an engineer is seeing your first PR ship and it's at millions of requests per second scale, and then realizing this is the norm.
vaish@wishee0

@zebassembly I KEEP TELLING PEOPLE ABOUT THIS. NO CLUE HOW PEOPLE ARE DESENSITISED TO THIS, THE SCALE HERE IS INSANE

English
2
3
86
10.8K
zeb
zeb@zebassembly·
@thegenioo @ashtonasidhu These are subsidized plans though, if anything this will make them more profitable since the cost to serve the subscription is higher than what they get through the subscription revenue.
English
3
0
2
65
Hamza
Hamza@thegenioo·
went through this Claude Sub cancellation thread from Theo 500+ replies, ~70% actual cancellations = 350 people gone (can actually be higher than this) rough math (assumptions): - 210 Pro @ $20 = $4,200/mo - 84 Max $100 = $8,400/mo - 56 Max $200 = $11,200/mo $23,800/month. $285K/year. From one tweet. and this is just the people who replied 💀
Theo - t3.gg@theo

For every person who replies with a screenshot of their cancelled Claude Code plan, I will donate $10 to open source.

English
77
33
1.2K
172.4K
zeb
zeb@zebassembly·
The world if you could memory map Uint8Arrays into WebAssembly memory I'm sick of the memcpys boss
zeb tweet media
English
4
3
58
3.8K
zeb retweetledi
Walshy
Walshy@WalshyDev·
I've been working on a registry-gateway built on @CloudflareDev Workers due to previous compromises like this. This is reenforcing my belief that every company will need to have this in the future. The gateway will: * Enforce a cooldown period for new versions (similar to how pnpm does it but at a gateway level this enforces it globally and supports ALL package managers) * Allows blocking packages or package prefixes * Logs all downloads * Clone all packages into R2 - this is to avoid any package being replaced and compromised that way. We know byte for byte this will not change (while I don't believe any registries allow this anymore, it's defence in depth) My gateway currently works for npm and Golang is mostly done now too. Rust is next up. I truly believe the future is Enterprises all having their own registry gateways and enforcing security that way.
Walshy tweet media
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
7
7
108
20.3K
zeb
zeb@zebassembly·
@strat0manc3r Did it? I thought Optane still had much better latencies I can't find any recent benchmarks comparing the two
English
1
0
0
31
Stratomancer
Stratomancer@strat0manc3r·
@zebassembly You’re looking for “storage class memory”. Optane died because SLC flash hit the same performance numbers cheaper. Weirdly only available in drive format, not dimms, despite the name.
English
1
0
0
38
zeb
zeb@zebassembly·
@confusedqubit @CloudflareDev I actually prototyped exactly this last year, I think it'd be really cool. Never found time to implement it unfortunately.
English
0
0
0
74
Shivansh Vij
Shivansh Vij@confusedqubit·
Who do I know @CloudflareDev for a feature request in workers? Please make it possible for me to trigger a worker from your dashboard - not just fetch requests 🙏 Just like how Github CI runs have a "manual dispatch" option!
English
5
0
5
2.5K
zeb retweetledi
Nevi Shah
Nevi Shah@nevikashah·
🤸‍♀️You can now get a single unified trace of your Worker across service bindings and Durable Object calls 🤸‍♀️ no more manually piecing together multiple traces to see what’s happening within a request
Nevi Shah tweet media
English
5
13
71
6K
zeb
zeb@zebassembly·
@dillon_mulroy @mattpocockuk Do you have some internal PRs I can look at 👀 I've been wanting to try the skill but haven't found time
English
2
0
23
13.8K
Dillon Mulroy
Dillon Mulroy@dillon_mulroy·
i've been trying to merge at least one PR a day using @mattpocockuk's improve-codebase-architecture skill, and it has turned into my favorite work each day.
English
36
51
2.4K
173K
zeb
zeb@zebassembly·
@worztm The day I put in enough effort into twitter to check for typos is the day I die
English
0
0
1
88