Mathis Hofer

@hupf.bsky.social

Irgendwo zwischen technikaffin, weltinteressiert, gesellschaftskritisch und musisch begabt. Fediverse: https://tooting.ch/@hupf

🚀Rolldown 1.0 is here!🚀 Rust-based high-performance JavaScript bundler. 🏎️ Runs at native speed that’s up 30x faster than Rollup 🤝 Compatible with existing Rollup & Vite plugins ⚡The underlying bunder for Vite After 2 years, Rolldown is officially stable and has 20+M weekly downloads.

We at TanStack just had a major attack against our Router packages. We have a postmortem out now explaining what happened and how we mitigated the response: tanstack.com/blog/npm-sup... No other TanStack packages outside of the Router monorepo were impacted

Postmortem: TanStack npm supply-chain compromise | TanStack Blog

On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 mal...

tanstack.com

Oh noooo, the company that extracted our data for their models is having others extracting data for their models

Bild

Yesterday I've replaced the battery and the wonky 3.5 mm audio jack of my 5 year old @fairphone.com with nothing more than a screw driver and a perfect instruction video by the manifacturer. I hope one day such an experience will be normal with all kinds of technical devices... 🌎🔧 #sustainability

pnpm v10.16.0 adds "minimumReleaseAge", a setting for defining how long a version has to have been published before pnpm will install it. A nice countermeasure against accidental installs of short-lived compromised packages before they get taken down. Not a 100% fix, but a great additional step!

Release pnpm 10.16 · pnpm/pnpm

Minor Changes There have been several incidents recently where popular packages were successfully attacked. To reduce the risk of installing a compromised version, we are introducing a new settin...

github.com