Mauricio Lauffer

@mauriciolauffer.bsky.social

Into SAP tech, nodejs and web dev stuff...

That said, there’s still some friction for people to start benefiting from agents, and the cost can be a barrier. If you’re actively contributing to OSS and want to use agents to help with your work, DM me with your contributions or plans. I’d be happy to sponsor your agent bills for a few months.

Anthony Fu@antfu.me · 2mo ago

I want to say thanks to @hyf0.bsky.social, who wrote me a long email back then explaining the benefit of using agents, with a $100 sponsorship for me to try them. It has significantly changed my attitude and workflow (still exploring the best practices tho, hopefully to be able to share soon).

How did the "Mini Shai-Hulud" attack compromise 170+ packages while maintaining valid SLSA Build L3 attestations? Read the full blog to see where SLSA’s boundaries fall and how to secure your pipeline with defense in depth. 🔗: openssf.org/blog/2026/06...

Bild

✨ Introducing @GoogleGemma 4 12B, a unified open model bringing high-performance agentic multimodal intelligence directly to your laptop. Bridging the gap between edge efficiency and advanced reasoning, nearing 26B MoE at <50% the memory footprint.

Bild

"Cognitive debt and burnout aren’t new, alas. With or without AI, we’ve all stayed up to 4AM working on a bug that won’t go away or pursuing an interesting idea to its end. Sometimes that’s heroic, but AI threatens to turn it into a lifestyle." Check out new #Radar article: bit.ly/4uPmJ3N

Burnout and Cognitive Debt

Steve Yegge’s article about programmer burnout (“The AI Vampire”) along with Margaret Storey’s article about Cognitive Debt started an ongoing conversation

bit.ly

🚨 Supply chain attack: SAP CAP and Cloud MTA npm packages compromised to download and execute unverified binaries. Affected versions: → mbt@1.2.48 → @cap-js/db-service@2.10.1 → @cap-js/postgres@2.2.2 → @cap-js/sqlite@2.2.2 Details: socket.dev/blog/sap-cap...

SAP CAP npm Packages Hit by Supply Chain Attack - Socket

Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...

socket.dev

avoid the next malicious package disaster with pnpm security hardening: github.com/lirantal/npm... Security Best Practice: Set trustPolicy: no-downgrade so that pnpm refuses to install any package version whose trust evidence is weaker than a previously published version of that package

Bild

AI agents are executing code, calling APIs, writing to databases, and most deployments have almost no controls around what they can do. @microsoft.com just open-sourced a runtime governance toolkit built around @owasp.org's Top 10 for Agentic Applications. Details → socket.dev/blog/microso...

Microsoft Releases Open Source Toolkit for AI Agent Runtime ...

Microsoft has released an open source toolkit for enforcing runtime security policies on AI agents as adoption accelerates faster than governance cont...

socket.dev

TypeScript 6.0 is now available! This release brings better type-checking for methods, new standard library features, new module features for Node.js, and more! But most important, this release brings us one step closer to the upcoming native-speed 7.0! devblogs.microsoft.com/typescript/a...

Announcing TypeScript 6.0 - TypeScript

TypeScript 6.0 is now available! TypeScript 6 is a stepping-stone release, aligning with the upcoming native-speed 7.0 release.

devblogs.microsoft.com