@ivanburazin Pay the price trying to learn it perfectly first (e.g. college, classes etc.) or start your business now and pay that price while building. The difference is one takes longer to get your business going than the other. Just start!
@ThePrimeagen No package manager is immune to supply chain attacks but considering a pure Deno/JSR ecosystem...
fewer would succeed silently
credential theft would be much harder
developer machines would likely be less compromised
CI environments would still remain high risk
@traversymedia Great video Brad. I started following you about 8 years ago. I started my coding journey with you! I'm launching my SaaS soon. I can't believe my dream is going to become a reality. Keep on keeping on brother!
IMO there is a lot you can build yourself especially small stuff. For example a UUIDv7 function is like a couple lines of JS. Why use a package from NPM to do it only to expose your attack surface. Whereas something like Valibot might be more worth it. Building a module yourself isn't that hard and will be specific for your app and it lowers your attack surface. My $0.02
@i549@tan_stack The md files are the easy part. The navigation is the dynamic part. Try building a right floating TOC or the side expanding doc nav with Astro...you can't. Astro won't do it. You need JavaScript or a framework like Svelte
I built my latest project using Astro. The docs section was an issue for Astro. I used vanilla and Svelte to fill in the gaps. Because of this I'll never use Astro again. Every sire will eventually have a Docs section and Astro falls short hard. I was going to go with Svelte kit moving forward but might have to look at Tanstack now
@ivanburazin That's been my experience as well. I baby sit them because I'm paranoid and they will destroy your codebase with slop if you don't. Facts.
We are investigating unauthorized access to GitHubβs internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHubβs internal repositories (such as our customersβ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.