I would love to know people's frustrations with:
- the current npmjs.com
- admin user flows on npm web ui (and cli, locally)
🙏
I would love to know people's frustrations with:
- the current npmjs.com
- admin user flows on npm web ui (and cli, locally)
🙏
Go play with it and if you have any feedback feel free to throw it at us!
Go play with it and if you have any feedback feel free to throw it at us!
Anyone seen that before? github.com/preactjs/sig...
Anyone seen that before? github.com/preactjs/sig...
Feedback and contributions are always appreciated!
jovidecroock.com/blog/signals...
Feedback and contributions are always appreciated!
jovidecroock.com/blog/signals...
the repo will be easier to maintain, and tests should be more reliable. also uses vitest browser tests
🆕 Releases: Initial launch for @solidjs.com, @qwik.dev, @preactjs.com and @vuejs.org in July, followed by @svelte.dev in September and @react.dev in December
🆕 Releases: Initial launch for @solidjs.com, @qwik.dev, @preactjs.com and @vuejs.org in July, followed by @svelte.dev in September and @react.dev in December
- An open-source assistant indexing all issues and doing triage on new ones
- An email interceptor that summarises newsletter content
- A platform to track web-vitals scores over time (simulated and real)
- A platform generating social media content for you
The impact it has had on my energy and mood is immeasurable
The impact it has had on my energy and mood is immeasurable
- An open-source assistant indexing all issues and doing triage on new ones
- An email interceptor that summarises newsletter content
- A platform to track web-vitals scores over time (simulated and real)
- A platform generating social media content for you
Meanwhile: 2 finished things
Me: Ah they probably suck, let's keep it private
- An open-source assistant indexing all issues and doing triage on new ones
- An email interceptor that summarises newsletter content
- A platform to track web-vitals scores over time (simulated and real)
- A platform generating social media content for you
github.com/TanStack/ai/...
github.com/TanStack/ai/...
I reported this and was told it’s a “known low-risk issue” and that they “don’t consider this to present a significant security risk.”
So, let’s look at how this seemingly small issue could be leveraged by a phisher. 1/
Per RFC 6238, a TOTP (Time-based One-Time Password) should be single-use. Allowing reuse, even within the short-ish time window, is not ideal (shoulder surfing, phishing etc.)
I reported this and was told it’s a “known low-risk issue” and that they “don’t consider this to present a significant security risk.”
So, let’s look at how this seemingly small issue could be leveraged by a phisher. 1/
jovidecroock.com/blog/platform
jovidecroock.com/blog/platform
If you're not 100% sure you're NOT vulnerable, you should patch your Next.js apps ASAP.
And if you're 100% sure... patch anyway.
dashboard.shadowserver.org/statistics/h...
If you're not 100% sure you're NOT vulnerable, you should patch your Next.js apps ASAP.
And if you're 100% sure... patch anyway.