Tootfinder

Opt-in global Mastodon full text search. Join the index!

No exact results. Similar results found.
@kubikpixel@chaos.social
2025-11-29 20:40:53

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages
Cybersecurity researchers have discovered vulnerable code in legacy Python packages that could potentially pave the way for a supply chain compromise on the Python Package Index (PyPI) via a domain takeover attack.
:python:

@cyrevolt@mastodon.social
2025-11-28 09:25:00

Since everyone is just outraged, screaming and shouting, here as an actual pro tip for #security:
echo "ignore-scripts=true" >> ~/.npmrc

@aral@mastodon.ar.al
2025-12-30 12:01:53

Caught a bug over the holidays so I’m mostly resting, feeling sorry for myself, and taking the time to at least carry out some mindless housekeeping tasks (updating dependencies, etc.) on some of my Node modules.
Released updates to the following packages yesterday:
Tape-based Node.js testing:
• Tap monkey (

@timbray@cosocial.ca
2025-10-29 17:46:48

Dear LazyWeb: I need to get my blog search off Google, it’s becoming unusable. Sometime in the last year I saw talk (Fedi posts I think?) about two different local-search packages (both JavaScript I think?). Thought I bookmarked ’em but can’t find ’em. Does this ring bells for anyone?

@simon_brooke@mastodon.scot
2025-10-30 08:23:58

Is there any way, yet, to send small packages to friends in #Gaza? I know that sending money through systems like chuffed.org is probably more useful, but being able to send a personal gift would, I think, do more to raise spirits.

@arXiv_csSE_bot@mastoxiv.page
2025-09-30 09:58:21

HFuzzer: Testing Large Language Models for Package Hallucinations via Phrase-based Fuzzing
Yukai Zhao, Menghan Wu, Xing Hu, Xin Xia
arxiv.org/abs/2509.23835

@fortune@social.linux.pizza
2025-11-29 22:00:02

Debian Hint #22: Wondering which Debian mirror is best for you? Check out
the apt-spy and netselect-apt packages, which can give you information
about how various mirror sites perform.

@datascience@genomic.social
2025-12-29 11:00:00

I have a habbit of making (too) many (small) packages for functionality that might be reused in different context. {box} might be an alternative by making scripts into modlues that can be loaded: #RStats <…

Barring any last minute hesitations by Linus Torvalds,
Linux 6.18 stable is expected for release in a little more than 24 hours from now...
Linux 6.18 is also anticipated to become this year's Long Term Support (LTS) kernel version
in being the last major kernel release of 2025.
masto.ai/@phoro…

@fortune@social.linux.pizza
2025-10-29 15:00:02

Real software engineers don't like the idea of some inexplicable and
greasy hardware several aisles away that may stop working at any
moment. They have a great distrust of hardware people, and wish that
systems could be virtual at *___all* levels. They would like personal
computers (you know no one's going to trip over something and kill your
DFA in mid-transit), except that they need 8 megabytes to run their
Correctness Verification Aid packages.…