Łukasz Kliś

@lukaszklis.com

Product Engineer. I help product teams ship reliable software with speed and craft. 15+ years in SaaS, fintech & e-commerce. Move fast. Build right. https://lukaszklis.com

This kind of attack is getting more and more common. Early in my career I used to update dependencies blindly — not anymore. For a few years now I’ve been locking packages to specific versions, reading changelogs carefully, and setting a `cooldown` in Dependabot (link in thread).

Socket@socket.dev · 4mo ago

🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile. socket.dev/blog/axios-n...

I accidentally set “in-app” as the default browser for opening links in Bluesky on iOS. I can’t find any way to revert this setting. Is reinstalling the app the only way to fix it?​​​​​​​​​​​​​​​​