Hailing from the Philippines, Yasmine will rush you down with her skills in Eskrima on August 3! 🗡️
Pay close attention to her movement lest you be on the wrong side of her karambit.
It's 2026 and your CEO just sent you a 2,400 line pull request.
You get a cup of coffee and sit down to review it.
It's a disaster. A dozen unrelated refactors. Unused methods with names like `convertFromBase10` and `normalizeBeforeSerialization`.
You catch a few hardcoded API keys, but that's ok. It's part of the dance. They didn't consider that someone might look at this diff. Here's a comment buddy.
They respond in an hour (after Copilot, qodo, CodeRabbit and Greptile finish their reviews) saying we shouldn't worry about "implementation details" anymore, those are relics of the past. Hey let's jump into a room and figure it out. We can't just agree to disagree, this is probably my last job in tech and I can't watch this fucker burn the place to the ground.
The PR merges and goes to prod. You feel a shared sense of apathy and dread with Hannah the intern (she has to review his AI generated social media posts ever since Grok got too imaginative).
That night you go to sleep and have nightmares of that code. You can still see the shapes of it on the backs of your eyelids.
You go to work the next day ready to quit. You no longer understand the system. There is no foundation. Time to use those savings and an SBA loan to buy a liquor store and never login to GitHub again.
Effective immediately, we are making the vite-plus repository private.
The source will be distributed exclusively through our production sourcemaps.
We believe this is the only logical path forward given the recent events.
This does not change our stance on Open Source!
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Just released heerich.js, a tiny voxel engine that renders 3D scenes to SVG 🎨
╬ Boolean ops
◮ Oblique & perspective
𝑥 Zero dependencies
◌ Pure vector output, infinite scaling
Named after Erwin Heerich's geometric cardboard sculptures.
since markdown files are becoming more and more present in my day-to-day, decided to make a cli markdown previewer (with media, mermaid, and latex support)
built on unifiedjs & opentui; inspired by glow
tech used to feel awesome because you could be from some random ass high school and make cool things
now it feels like people care about what college / accelerator / VC ppl just raised from. i hate that
Lewis Hamilton via Instagram:
“Today is an important day. The first step of a deal has been agreed to bring hostages home and to return peace to Palestine.”
“Now, for the first time in a long time, Palestinians can allow themselves hope again. (…) Now, more than ever, they need our support. The eyes of the world must stay on Gaza.”
really respect lewis hamilton for taking care of his dog. i feel like a lot of celebrities treat animals as playthings or accessories. or they buy an expensive breed and treat it as a status symbol. but he seemingly cared about his dog like a member of his family.