👀 React Compiler in Rust - Exciting update from @rickyfm
TLDR:
- Rust compiler ➡️ 99.9% the same output as the original
- Confident ➡️ merge the PR within the next weeks
- Can be tested locally
The Oxc team is already working on an integration (draft PR)
This Week In React 283
⚛️
- TanStack Query / Router / Virtual
- RSC + composition
- Perf: GitHub & Linear
- Liquid DOM
- Apollo
- i18n
📱
- Expo SDK 56
- Reanimated
- Worklets
- NativeScript
- Strict DOM
- Standard Nav
🍿 Read: https://t.co/1TB0sNT7Uz
✍️ @jaworek3211 & I
These orgs have been compromised because of pull_request_target:
- TanStack
- PostHog
- Nx
- LiteLLM
Any many more...
As safe as you think it is, it's not and hackers are searching for repos using that workflow, easy target!
TL;DR for open-source maintainers
🚫 NEVER use "pull_request_target" workflows
🚫 NEVER use shared caches in your publish pipeline
Combining these 2 in particular is extremely dangerous
I've repeated this countless times over the years, but another reminder is always useful
TL;DR for open-source maintainers
🚫 NEVER use "pull_request_target" workflows
🚫 NEVER use shared caches in your publish pipeline
Combining these 2 in particular is extremely dangerous
I've repeated this countless times over the years, but another reminder is always useful
We are always happy to receive a positive newsletter feedback!
Please send us more and tell us what you think!
Also tell us what we could do better, we are here to serve you.
I rarely get any replies to my newsletter emails
Once in a while, I get one that really makes me happy 😊
If you like something, please be loud about it!
Authors will appreciate it more than you think