keninvc
140 posts


@suryanox7 because it starts with {"alg" which encoded in b64 translates to eyJ...
English

@keninvc dep bumps and lint drift are the easy wins, any agent clears those week one. the one that survives past the novelty is flaky test fixes, because the cause moves every run. that is the task worth keeping the agent on. assrt.ai/r/cr48cjps written with ai
English

Monocle 3.5 is out
heyiam.dk/monocle
Btw, I hid an easter egg on the website for 50% OFF on the license
English
keninvc nag-retweet

@Black_Mage01 @sysadafterdark That’s… exactly what I said. What do you think the 😉 was for?
English

@keninvc @sysadafterdark Right but if you used Bitwarden CLI you would still have been infected...
English

Well, this isn’t good. How can I trust a company with my passwords if they don’t invest and protect in their own systems? Might be time to roll my own server.
mpgn@mpgn_x64
Looks like the npm package bitwarden cli was compromised, you can see version 2026.4.0 was not published from a trusted publisher (green checkmark) 😬 @bitwarden/cli/v/2026.4.0" target="_blank" rel="nofollow noopener">npmjs.com/package/@bitwa…
English

@keninvc @sysadafterdark But the client is what was breached, or a version of that client (only CLI is being reported as compromised.) Even if you self hosted, if you use the bitwarden client - this attack still affected you unless you forked and audited or built from a stable older version.
English















