Hey Folks,
Introducing CollabSpace✨: your new collaborative workspace for teams that want to work smarter, not harder. CollabSpace brings together real-time chat, flexible workspaces, and easy project management in one place.
Laws are a joke in India.
GRAP 4 is supposedly implemented in Delhi, construction is banned, yet I woke up to the sound of marble cutting that has been going on for two hours.
And then we talk about AQI going down. Utter nonsense.
i am convinced that software devs have a speed problem
they think the #1 issues is writing code faster... its not. its fixing the code that is already there to stop being utter garbage (as a garbage code connoisseur)
quality is really lacking these days, yet quantity has never been higher
@arpit_bhayani Absolutely. Having worked in two early-stage startups, I completely resonate with this. With the current AI wave, we need a much faster shift in mindset to match the speed at which results are now expected.
if you’re an intern or just joined a company:
for the first 3 to 4 months, don’t work to your personal projects.
spend time for understanding.
- learn the company’s codebase
- learn how work actually gets done
- learn how the business makes money
- learn why decisions are made the way they are
one of the most underrated advantages early in your career:
spend time with the smartest people around you, especially the founder or cto.
- ask “stupid” questions.
- ask how things work.
- ask why they work that way.
early on, curiosity compounds faster than side projects.
To every student choosing discipline over distractions right now:
It may feel lonely today, but one day, you’ll look back and be proud you stayed consistent.
What should you do?
> Upgrade to the latest patched versions immediately.
The React team has fixed the issue but only if you update.
Takeaway:
> Dependency updates aren’t “maintenance”.
They’re a security requirement. 🙌
🚨 React Critical Vulnerability (CVSS 10.0)
A Remote Code Execution (RCE) flaw was found in React Server Functions.
Severity: 10.0 / 10 (maximum)
Under specific conditions,
unauthenticated attackers can execute arbitrary code
directly on the server runtime.
There's a new vulnerability with React Server Components that you should know about and fix.
It happens because of the complex way React handles serialization (and an overly lax "flight" protocol).
In this guide, Arunachalam explains how to protect yourself from the "React2Shell" vulnerability and what to do if your app's already in trouble.
https://t.co/oQC8zB3GIF
Who’s affected?
React Server Components–related packages:
• react-server-dom-webpack
• react-server-dom-parcel
• react-server-dom-turbopack
Apps using React / Next.js may be impacted.
As engineers, you will always be tempted to go down the rabbit hole while reading anything dense, be it a paper, blog, or book. Comprehending a few sections well gives you an adrenaline rush to understand it all and explore all the concepts in depth.
But this is unnecessary almost always. When you are reading a paper, you need to know why you are reading it, what the goal is, and what outcome you are seeking.
If you want to understand it end-to-end, then sure, go down the rabbit hole. If you want to just build an idea about the approach, then stop when you think you have built a decent understanding.
Remember, when you are digging deeper, you are putting your time, energy, and mental bandwidth. So, this should be the most urgent and the most important thing for you at the moment. If it is, sure, continue to put in the effort, but if not, come out of the rabbit hole and switch to something that is more critical.
it is okay to not completely understand a paper.
it is okay to not complete a book.
it is okay to not finish the project.
You should always analyze what's urgent, important, and best use of your time and prioritize it. Apply the same principle to decide how deep you want to go when you are reading anything dense, and it is always okay to pause.
Hope this helps.
Anthropic just snapped up Bun, the super-fast JavaScript runtime that bundles a runtime, package manager, test runner, and bundler all in one tight little engine. Basically if Node is the old reliable truck, Bun’s the electric sports car that somehow carries the same cargo faster
Anthropic is acquiring @bunjavascript to further accelerate Claude Code’s growth.
We're delighted that Bun—which has dramatically improved the JavaScript and TypeScript developer experience—is joining us to make Claude Code even better.
Read more: https://t.co/aQd3XRdUfR
Why does this matter? Well… companies don’t spend millions “just because.”
My guess? Anthropic wants tighter control over the tooling behind Claude Code so they can ship faster, bundle everything cleanly, and run AI-generated code anywhere without friction.
I think organizations should realize that people don't quit great companies- they quit chaotic bosses. They quit the confusion, and they quit the unclear priorities.
Toxic managers hate confident people. Confident people are harder to control, they speak up, they are not going to say "yes," and they challenge poor decisions. This makes such managers feel insecure and exposed, so they often try to silence or push out someone who outshines them or calls them out.
As Niranjan Hiranandani rightly said, "People recognize the difference between a boss and a leader. The boss bullies, and the leader leads. People look up to the leader, people tolerate the boss."