Tootfinder

Opt-in global Mastodon full text search. Join the index!

@veit@mastodon.social
2026-04-30 14:10:02

Now elementary-data has also been hit: for just under half a day, a malicious version 0.23.3 was available on PyPI, which had stolen credentials such as SSH keys, AWS login details, API tokens and wallet files. The attack was carried out via a script injection vulnerability in one of the GitHub Actions workflows. Cooldown helps protect against such attacks, as we have described here:

@ELLIOTTCABLE@functional.cafe
2026-02-08 22:44:39

Spent the day figuring out how to create macOS "web apps" from the command line (like old-school Fluid site-specific browsers, SSBs - accessed via the "Add to Dock" button in Safari.)
Here, have my shat-out half-AI-written script for this, since I couldn't find anybody else having done this after scouring the internet high and low: