naugtur
banner
naugtur.pl
naugtur
@naugtur.pl
Working on supply chain security for JS. LavaMoat and Endo contributor. meet.js Poland organizer. Node.js user since v0.8.
Addicted to teaching.

https://naugtur.pl
I realized there's a pun opportunity.

Instead of NG Meetup they should be called Angular Circles
November 15, 2025 at 9:48 AM
Barely related but there's a crisis in the UX community because most of them got to a point where they're tired of getting pressured to add one more dark pattern to capture more attention or sales and still remember the early spirit of making things better for thr users and advocating for them.
November 15, 2025 at 9:43 AM
[⚠️ I'm a troll]

Weird term for polygons.

Here's a stackoverflow on unions of polygons
stackoverflow.com/questions/26...
How do I combine complex polygons?
Given two polygons: POLYGON((1 0, 1 8, 6 4, 1 0)) POLYGON((4 1, 3 5, 4 9, 9 5, 4 1),(4 5, 5 7, 6 7, 4 4, 4 5)) How can I calculate the union (combined polygon)? Dave's example uses SQL server to p...
stackoverflow.com
November 15, 2025 at 9:39 AM
As my annoyance grew, I started just pasting the error without explanation, especially if its something stupid. It trained on plenty of stupid errors.
November 15, 2025 at 9:36 AM
Slam dunk.
November 15, 2025 at 9:30 AM
I once left a pumpkin in the oven for 2 days (it turned off after the preset time passed but I already forgot)
November 15, 2025 at 9:18 AM
It's still happening on CI side, so if someone gets somewhere in the dependencies of your project or actions you use or their dependencies, they could steal a credential sufficient to publish to npm without going through the step.
November 13, 2025 at 5:44 PM
That's nice for a large GH org, or if you're doing complex things. It doesn't prevent malware being published when your CI or one of the maintainer gets its/their access leaked.
November 13, 2025 at 3:06 PM
For larger projects - N approvals required within X hours or 1 veto within 30 minutes to block.
November 13, 2025 at 3:03 PM
It does do something like that behind the scenes, but regardless, what I'd want is:
1. CI or anywhere - sends a package to registry with existing security
2. The package doesn't become public, instead - maintainers get notified.
3. Maintainers use strong 2fa to approve making the version public
November 13, 2025 at 3:03 PM
Do treat it like a flow with a token tho. If someone controls your workflow code they can extract that auth too.
November 13, 2025 at 2:26 PM
The darker shape in that slice on the right, while not healthy for the tree, should make a good looking coffee table if you took a slice and processed it
November 13, 2025 at 1:30 PM
Reposted by naugtur
oh my god
November 10, 2025 at 6:16 PM
Wow. Glad it ended up mostly slapstick and not harm.

The build looks fun tho.
November 9, 2025 at 10:18 PM