Łukasz Kliś

@lkl.is

Product Engineer. I help product teams ship reliable software with speed and craft. 15+ years in SaaS, fintech & e-commerce. Move fast. Build right. https://lukaszklis.com

Every time I visit my company's website, I find hidden gems crafted by my incredibly talented colleague Arek (arkadiuszpalki.com). Here's a great example — a delightfully simple way to copy Surfer's logo or symbol.

This kind of attack is getting more and more common. Early in my career I used to update dependencies blindly — not anymore. For a few years now I’ve been locking packages to specific versions, reading changelogs carefully, and setting a `cooldown` in Dependabot (link in thread).

Socket@socket.dev · 5mo ago

🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile. socket.dev/blog/axios-n...

I accidentally set “in-app” as the default browser for opening links in Bluesky on iOS. I can’t find any way to revert this setting. Is reinstalling the app the only way to fix it?​​​​​​​​​​​​​​​​