Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. No more JavaScript, it's clear y'all can't be trusted with it.

No more JavaScript, it's clear y'all can't be trusted with it.

Scheduled Pinned Locked Moved Uncategorized
21 Posts 16 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

    No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote last edited by
    #2

    @darfplatypus Fuckin FINALLY

    1 Reply Last reply
    0
    • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

      No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

      huronbikes@cyberplace.socialH This user is from outside of this forum
      huronbikes@cyberplace.socialH This user is from outside of this forum
      huronbikes@cyberplace.social
      wrote last edited by
      #3

      @darfplatypus

      Link Preview Image
      sharkfie@infosec.exchangeS lil5@social.last.nlL 2 Replies Last reply
      1
      0
      • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

        No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

        nyanbinary@infosec.exchangeN This user is from outside of this forum
        nyanbinary@infosec.exchangeN This user is from outside of this forum
        nyanbinary@infosec.exchange
        wrote last edited by
        #4

        @darfplatypus eyes https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud don't you dare touch my snek!

        1 Reply Last reply
        0
        • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

          @darfplatypus

          Link Preview Image
          sharkfie@infosec.exchangeS This user is from outside of this forum
          sharkfie@infosec.exchangeS This user is from outside of this forum
          sharkfie@infosec.exchange
          wrote last edited by
          #5

          @huronbikes @darfplatypus perfect, no notes

          1 Reply Last reply
          0
          • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

            @darfplatypus

            Link Preview Image
            lil5@social.last.nlL This user is from outside of this forum
            lil5@social.last.nlL This user is from outside of this forum
            lil5@social.last.nl
            wrote last edited by
            #6

            @huronbikes @darfplatypus The problem lies with npm postinstall, as soon as we all collectively agree to use a package manager that doesn’t run a postinstall script of any dependency you install, this goes away.

            Pnpm bun idk.

            huronbikes@cyberplace.socialH novet@infosec.exchangeN 2 Replies Last reply
            0
            • lil5@social.last.nlL lil5@social.last.nl

              @huronbikes @darfplatypus The problem lies with npm postinstall, as soon as we all collectively agree to use a package manager that doesn’t run a postinstall script of any dependency you install, this goes away.

              Pnpm bun idk.

              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.social
              wrote last edited by
              #7

              @lil5 @darfplatypus *stares in lpad incident from 10 years back from which nothing of value was learned*

              lil5@social.last.nlL 1 Reply Last reply
              0
              • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                @lil5 @darfplatypus *stares in lpad incident from 10 years back from which nothing of value was learned*

                lil5@social.last.nlL This user is from outside of this forum
                lil5@social.last.nlL This user is from outside of this forum
                lil5@social.last.nl
                wrote last edited by
                #8

                @huronbikes @darfplatypus omfg it’s been that long

                Link Preview Image
                npm Blog Archive: Package install scripts vulnerability

                npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog

                favicon

                (blog.npmjs.org)

                Looks at published date: March 25th, 2016 10:16pm

                huronbikes@cyberplace.socialH 1 Reply Last reply
                0
                • lil5@social.last.nlL lil5@social.last.nl

                  @huronbikes @darfplatypus omfg it’s been that long

                  Link Preview Image
                  npm Blog Archive: Package install scripts vulnerability

                  npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog

                  favicon

                  (blog.npmjs.org)

                  Looks at published date: March 25th, 2016 10:16pm

                  huronbikes@cyberplace.socialH This user is from outside of this forum
                  huronbikes@cyberplace.socialH This user is from outside of this forum
                  huronbikes@cyberplace.social
                  wrote last edited by
                  #9

                  @lil5 @darfplatypus

                  Link Preview Image
                  1 Reply Last reply
                  1
                  0
                  • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                    No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                    epic_null@infosec.exchangeE This user is from outside of this forum
                    epic_null@infosec.exchangeE This user is from outside of this forum
                    epic_null@infosec.exchange
                    wrote last edited by
                    #10

                    @darfplatypus Yay!!!!

                    1 Reply Last reply
                    0
                    • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                      No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                      abt1181@ioc.exchangeA This user is from outside of this forum
                      abt1181@ioc.exchangeA This user is from outside of this forum
                      abt1181@ioc.exchange
                      wrote last edited by
                      #11

                      @darfplatypus go screw yourself, AL HAIL SAINT JAVASCRIPT

                      1 Reply Last reply
                      0
                      • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                        No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                        secretsloth@mastodon.artS This user is from outside of this forum
                        secretsloth@mastodon.artS This user is from outside of this forum
                        secretsloth@mastodon.art
                        wrote last edited by
                        #12

                        @darfplatypus (pauses with a spoonful of JavaScript halfway to mouth) (tries to hide the rest of the bowl behind back) it's just lucky charms

                        1 Reply Last reply
                        0
                        • lil5@social.last.nlL lil5@social.last.nl

                          @huronbikes @darfplatypus The problem lies with npm postinstall, as soon as we all collectively agree to use a package manager that doesn’t run a postinstall script of any dependency you install, this goes away.

                          Pnpm bun idk.

                          novet@infosec.exchangeN This user is from outside of this forum
                          novet@infosec.exchangeN This user is from outside of this forum
                          novet@infosec.exchange
                          wrote last edited by
                          #13

                          @lil5 @huronbikes @darfplatypus what's great is that afaik you can turn off postinstall on most of these package managers

                          hell, most even introduced options to set a window where it won't update to the latest package if a release is within the time window.

                          lil5@social.last.nlL 1 Reply Last reply
                          0
                          • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                            No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                            tkissing@mastodon.socialT This user is from outside of this forum
                            tkissing@mastodon.socialT This user is from outside of this forum
                            tkissing@mastodon.social
                            wrote last edited by
                            #14

                            @darfplatypus From my cold dead SSDs

                            1 Reply Last reply
                            0
                            • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                              No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                              aanee@mastodon.onlineA This user is from outside of this forum
                              aanee@mastodon.onlineA This user is from outside of this forum
                              aanee@mastodon.online
                              wrote last edited by
                              #15

                              @darfplatypus

                              1 Reply Last reply
                              0
                              • novet@infosec.exchangeN novet@infosec.exchange

                                @lil5 @huronbikes @darfplatypus what's great is that afaik you can turn off postinstall on most of these package managers

                                hell, most even introduced options to set a window where it won't update to the latest package if a release is within the time window.

                                lil5@social.last.nlL This user is from outside of this forum
                                lil5@social.last.nlL This user is from outside of this forum
                                lil5@social.last.nl
                                wrote last edited by
                                #16

                                @novet @huronbikes @darfplatypus

                                I’ve really enjoyed pnpm and deno they’re both great indeed

                                novet@infosec.exchangeN 1 Reply Last reply
                                0
                                • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                                • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                                  No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                                  linkplay@biplus.socialL This user is from outside of this forum
                                  linkplay@biplus.socialL This user is from outside of this forum
                                  linkplay@biplus.social
                                  wrote last edited by
                                  #17

                                  @darfplatypus can you turn ai off while you are at it?

                                  1 Reply Last reply
                                  0
                                  • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                                    No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                                    sleet01@fosstodon.orgS This user is from outside of this forum
                                    sleet01@fosstodon.orgS This user is from outside of this forum
                                    sleet01@fosstodon.org
                                    wrote last edited by
                                    #18

                                    @darfplatypus

                                    Link Preview Image
                                    1 Reply Last reply
                                    0
                                    • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                                      No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                                      glitchcake@tech.lgbtG This user is from outside of this forum
                                      glitchcake@tech.lgbtG This user is from outside of this forum
                                      glitchcake@tech.lgbt
                                      wrote last edited by
                                      #19

                                      @darfplatypus better be safe and cut the plug off

                                      1 Reply Last reply
                                      0
                                      • darfplatypus@infosec.exchangeD darfplatypus@infosec.exchange

                                        No more JavaScript, it's clear y'all can't be trusted with it. I'm turning it off.

                                        jkdelauney@tech.lgbtJ This user is from outside of this forum
                                        jkdelauney@tech.lgbtJ This user is from outside of this forum
                                        jkdelauney@tech.lgbt
                                        wrote last edited by
                                        #20

                                        @darfplatypus This is long overdue and I applaud your willingness to take this needful corrective action.

                                        1 Reply Last reply
                                        0
                                        • lil5@social.last.nlL lil5@social.last.nl

                                          @novet @huronbikes @darfplatypus

                                          I’ve really enjoyed pnpm and deno they’re both great indeed

                                          novet@infosec.exchangeN This user is from outside of this forum
                                          novet@infosec.exchangeN This user is from outside of this forum
                                          novet@infosec.exchange
                                          wrote last edited by
                                          #21

                                          @lil5 @huronbikes @darfplatypus a group im part of are just starting a migration from bun to deno. am not really involved but it seems like the best option currently.

                                          1 Reply Last reply
                                          0
                                          • R relay@relay.infosec.exchange shared this topic
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups