Tootfinder

Opt-in global Mastodon full text search. Join the index!

No exact results. Similar results found.
@kubikpixel@chaos.social
2025-09-08 17:35:16

»npm Packages With 2 Billion Weekly Downloads Hacked in Major Attack:
Aikido Security flagged the largest npm attack ever recorded, with 18 packages like chalk, debug, and ansi-styles hacked to hijack crypto wallets via injected code.«
Good heavens! Another example of how "simple" and popular programming languages are misused to exploit users.
😠

@Techmeme@techhub.social
2025-09-08 17:10:44

Aikido Security says attackers injected malware into 18 popular npm packages, including the debug package, with over 2.6B total weekly downloads (Sergiu Gatlan/BleepingComputer)
bleepingcomputer.com/news/secu

@thomasfuchs@hachyderm.io
2025-09-08 18:31:11

It’s almost like programming language monocultures with “best practices“ and paradigms requiring hundreds or thousands of dependencies even for simple apps are harmful bleepingcomputer.com/news/secu

@netzschleuder@social.skewed.de
2025-10-08 05:00:06

python_dependency: Python Dependency Network
Python's package dependency networks. Nodes in the network are Python's packages registered to PyPI and edges are dependencies among packages.
This network has 58743 nodes and 108399 edges.
Tags: Technological, Software, Unweighted
networks.sk…

python_dependency: Python Dependency Network. 58743 nodes, 108399 edges. https://networks.skewed.de/net/python_dependency
@karlauerbach@sfba.social
2025-10-08 14:53:24

I generally like FreeBSD. But when it comes to their system of effectively erasing prior versions of packages at the end of the "supported" period - well then I hate FreeBSD with a purple passion.
Just a few days back the 14.2 version feel out of "support". Until then I could install pre-built packages. Today I cannot.
(They say "build 'em from the ports source" - well that means rebuilding tool chains - which is a hell of infinite regression be…

@grahamperrin@bsd.cafe
2025-12-08 07:50:39

@… thanks, a few observations.
Nine base sets (minimal plus all eight additions) should be rare, not a norm.
The next screenshot shows 311 packages, that's not consistent with the nine base sets. There should be 488 packages, including pkg itself.
The pictured user has not been added to any groups. They'll not benefit from hardware-acc…

@arXiv_csSE_bot@mastoxiv.page
2025-10-08 08:59:09

UnitTenX: Generating Tests for Legacy Packages with AI Agents Powered by Formal Verification
Yiannis Charalambous, Claudionor N. Coelho Jr, Luis Lamb, Lucas C. Cordeiro
arxiv.org/abs/2510.05441

@zachleat@zachleat.com
2025-09-08 17:34:38

@… ah, yeah — for sure. I just mean that packages using provenance aren’t *required* to use provenance to publish (which was an interesting design decision)

@cyrevolt@mastodon.social
2025-09-08 00:39:34

#Go escape, or... //go:noescape
"meaning that the function has an implementation not written in Go"
very mysterious.
pkg.go.dev/cmd/compile
Today I learned a few first things about…

@netzschleuder@social.skewed.de
2025-12-06 18:00:06

python_dependency: Python Dependency Network
Python's package dependency networks. Nodes in the network are Python's packages registered to PyPI and edges are dependencies among packages.
This network has 58743 nodes and 108399 edges.
Tags: Technological, Software, Unweighted
networks.sk…

python_dependency: Python Dependency Network. 58743 nodes, 108399 edges. https://networks.skewed.de/net/python_dependency