Bret Comnes
@bret.io
170 followers 190 following 180 posts
bret.io @socket.dev @breadcrum.net
Posts Media Videos Starter Packs
Reposted by Bret Comnes
socket.dev
Maintainer compromises used to be rare. Now they’re happening at an alarming rate, as seen in recent attacks. Today we’re giving developers a new layer of defense with Socket Firewall, a free tool that blocks malicious dependencies at install time.
Reposted by Bret Comnes
feross.bsky.social
🚨 Open source supply chain attacks are exploding.

Starting today, that ends.

We’re releasing Socket Firewall — FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI.

Just run:

npm i -g sfw
sfw npm install lodash

Works for: npm, yarn, pnpm, pip, uv, and cargo.
bret.io
Anyone know a good leader election library that either uses pg or redis on the backed? Basically, in a horizontally deployed service, I need one instance to do something unique, and something else to take over when it disappears.
bret.io
Or like multisignature publish flow where two accounts need to sign off on it.
bret.io
Bret Comnes @bret.io · Aug 28
Gigantic OOOOOF on this one.
socket.dev
Socket @socket.dev · Aug 27
🚨 Supply chain attack on Nx npm packages (4.6M weekly downloads)

Malware abused AI CLI tools (Claude, Gemini, Q) to steal creds + wallets, then exfiltrated to GitHub repos (s1ngularity-repository*).

More than 1,000 victim accounts confirmed.
🔗 socket.dev/blog/nx-pack... #nodejs
Nx npm Packages Compromised in Supply Chain Attack Leveragin...
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malwa...
socket.dev
Reposted by Bret Comnes
voxpelli.com
Reminder that the major thing that made GitHub succeed over Google Code, Sourceforge etc is to be found in its initial tagline:

“Social coding”

GitHub added a social network on top of the code – highlighting the people rather than just the lines

Any successor to it needs to solve the social layer
bret.io
Bret Comnes @bret.io · Aug 12
Lost its spark
bret.io
Bret Comnes @bret.io · Aug 12
Actually a good model. Meeting people at the movie store is a core memory.
bret.io
Bret Comnes @bret.io · Aug 12
They were supposed to be the valve software of open source.
bret.io
Bret Comnes @bret.io · Aug 12
Bad omen
bret.io
Didn't know @pfrazee.com was moonlighting at openai
Reposted by Bret Comnes
breadcrum.net
You can now view and edit your auth tokens in your account page. More auth token features like a CRUID ui and old token cleanup coming soon. Sorry for the slow pace of development lately, just trying to get core features implemented correctly.
Reposted by Bret Comnes
lirantal.com
Y'all don't sleep on ls-mcp

It's a quick access CLI to detect and list all MCP servers across your AI tools stack
bret.io
Bret Comnes @bret.io · Jul 18
Worked!
bret.io
Bret Comnes @bret.io · Jul 18
Just saw this yes! Will try
bret.io
Bret Comnes @bret.io · Jul 10
Does it support zed?
bret.io
Bret Comnes @bret.io · Jun 30
I ported the Tron Legacy theme to @zed.dev
bret.io
Bret Comnes @bret.io · Jun 20
Homebrew bundle lets you install everything in one go
bret.io
Bret Comnes @bret.io · Jun 20
what is c2pa ?
bret.io
Bret Comnes @bret.io · Jun 14
Is there such a thing as a userQueryState hook? Basically use state but reactive in and out of the query string.
bret.io
Oh you mean bsky feeds. Might work but it’s just generic jwt