Clara Leigh

@clara42.bsky.social

Laravel, VueJS, Cyber Security 🌈

"There were metal shavings found in bread products … products that were supposed to be dairy-free, that were not dairy-free, [which] were only caught by accident because somebody happened to put it together after their child or they themselves got sick, not because the company had worked it out."

Horse meat has been sold as minced beef or lamb in Australia, documents show

Government documents show hundreds of businesses operating in Australia have breached food safety laws, with one politician warning "you could be eating a minced horse".

abc.net.au

Anyone else's PHP github actions suddenly taking an insane time to complete? Mine are taking 20mins-1hr and I cannot replicate any problem on local or even brand new machines setup

We have another giveaway: a ticket to Laracon India 🎉. Since this is a last-minute giveaway, it is only open to people already basedin Ahmedabad, India, and it's only open until January 17th, 2026. Retweet/share for reach, and enter via our website, link below ⬇️.

There should be a “same product, same features” law If a country forces a company to have better privacy options or allow third party app stores or whatever it might be, you should be forced to offer that same feature here in Australia

Reminder folks, chatgpt is designed to agree with you and "solve" issues so it rarely tells you that you're misunderstanding things. It will absolutely mislead you or say its found the issue when really it's just giving its best guess Getting tired of seeing low quality github issues hey

Once upon a time, USBs and CDs could auto run. That’s how worms like stuxnet and Agent.BTZ spread everywhere We learned the hard way and killed autorun Now we `npm install` 1,000 different dependencies from the internet and consider it “safe”, forgetting that it does the exact same thing

Is username enumeration (UE) a real vulnerability? Yes, and it matters more today than it did a few years ago. As phishing attacks look more legitimate, even smart people are getting tricked This week I saw a UE+phish lead to an account take over, and the URL in the Phish was a legitimate url

If there is one thing I've learned in the last year, it's never use a property named "type" I have lost so many hours debugging this exact bug but alas I am a goldfish just did it again, for the third time this week 😭

“Think like a hacker” is one of my favourite phrases It leads to the zero trust mindset. Assume a breach will happen and brainstorm what you can do to reduce that risk Short liven tokens are just one thing that can help. I encourage you to research OIDC tokens, it might just save you one day

Clara Leigh@clara42.bsky.social · last yr.

Today I leaned about OIDC tokens and how you can use them to prevent GitHub actions from having access to long lived secrets (like AWS) While its not yet supported by my main provider, I can certainly clean up my AWS actions and hope others add it to their roadmap 🙏 docs.github.com/en/enterpris...

🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc