Norwich // Software Dev Technical Lead // #React#JavaScript#TypeScript // #NCFC Barclay Lower E Block // @canariestrust board member π‘π’ Thoughts are my own
NEW: Amazon has reportedly scrapped its internal AI leaderboard as costs soared, with a senior executive telling staff: βdonβt use AI just for the sake of using AI.β
@Hi250000@olly_afc@xGPhilosophy To be fair, professional teams staff use these numbers to analyse their games and sides, so I would be hard pressed to say theyβre pointless and mean nothing.
@BethnalYG I actually think itβs incredibly low risk. Great option to have, and in that second year will be the sort of player who will understand he may not get minutes, but will be really good experience to have around the squad.
Time to pack in open source. We need to pivot to ordering packages over the phone, where the source code is then shipped out to us on a USB, this is the only option.
SECURITY ADVISORY β TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE β packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH β payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
β’ Rotate cloud, GitHub, and SSH credentials immediately
β’ Audit cloud audit logs for the last several hours
β’ Pin to a prior known-good version and reinstall from a clean lockfile
Detection β the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
Funny how the same opinions are generally shared across completely different industries. Especially funny with this one though, with trades anticipating fixing replaced humans mistakes. Rather than humans fixing AIβs mistakes like in software.
We're expanding our collaboration with Amazon to secure up to 5 gigawatts of compute for training and deploying Claude. Capacity begins coming online this quarter, with nearly 1 gigawatt expected by the end of 2026.
Whoever uses AI to write code should be responsible for that code (and liable for any potential consequences).
I don't care what model you used, how you used it, or how much it helped you.
You are responsible for the code.
@22Baggie99@Tgarratt10 Maybe, Iβm willing to give it a go. Hopefully adds a bit more competitiveness than there is now for teams that are around the top 10 towards the end of the season
@jordxcix@Tgarratt10 I donβt disagree. Iβm pretty sure looking back that itβs v rare 6th would get promoted, finishing 8th would still mean you have to navigate a quarter final before playing 3rd(?) over two legs.
If it were to happen, I think it says as much about the financial needs of the prem.