Profile avatar
naugtur.pl
Working on supply chain security for JS. LavaMoat and Endo contributor. meet.js Poland organizer. Node.js user since v0.8. Addicted to teaching. https://naugtur.pl
1,650 posts 1,106 followers 224 following
Regular Contributor
Active Commenter

Just want to reiterate how much of a problem this is. Check out how simple this exploit is. Basically, this means when you click a malicious link, anyone can SILENTLY download and execute ANYTHING as admin on your PC. Click a link, that's it, nothing else. And you can't stop Asus bloatware.

Yesterday I presented about #Temporal at #JSNation. In case you missed it, here are my slides! (with clickable links on the "learning more" page!) ptomato.name/talks/jsnati...

New blog post: Construction Lines I turned 39 today. My career turns 20 this summer. Prompted by a recent career shift, I paused to reflect; and ask myself “What has brought me the most joy — and why?” lea.verou.me/blog/2025/co...

fitness tamagotchi where it eats steps and heartbeats and stuff and dies if you dont workout

Issue #597 of Gamedev.js Weekly newsletter about AI Diplomacy, countdown to js13kGames 2025, and Living Canvas is out - go check it! gamedevjsweekly.com/597 #HTML5 #JavaScript #gamedevjs #gamedev #weekly #newsletter #AI #js13k #Canvas

Many teams struggle with Node.js as they scale. They face roadblocks that slow progress and frustrate developers. Here’s your guide to overcoming ALL of those challenges: ↓↓↓

AI agents are a security nightmare in every way. I've seen people put llm injection in resumes and this is a nice spin on that. Why train your employees against phishing when Copilot will click every link in every email for you :P www.aim.security/lp/aim-labs-...

.@therealptomatoon the #JSNation stage😍

Just as surprised as anyone that Mashable or MSN seem to no longer be reliable: they publish fake stuff quoting influencers making things up, and never bother to correct. Like this Builder .ai story about “devs pretending to be AI” Their incentive is views/ads not correctness

Yes, Node.js has a Pride logo 🏳️‍🌈. And yes, anyone is welcome in our community. nodejs.org/en

“Cursor […] tried to delete some old files, didn’t work at the first time and it decided to end up deleting everything on my computer, including itself.” 😶‍🌫️ forum.cursor.com/t/cursor-yol...

In case anyone out there is looking for a good-first Chromium bug, issues.chromium.org/issues/42421... is one I'd be happy to mentor someone through..

I told you we’d be back

The 1 billionth GitHub repository has been created and it’s absolutely perfect.

A browser that's created for you is always going to put you in charge.

This is not loud enough. Spread the word. I've never installed any app owned by Meta and never will.

Remembering Mikeal Rogers blog.izs.me/2025/06/mike...

GitHub blocked GitHub Actions on all my repositories, this is very frustrating... Do I know anybody that could help? It says that it's because "recent account payments have failed or your spending limit needs to be increased", but neither is true.

ok chat, where's everyone hanging out today? ... also, anyone up for bouldering later? 👀 cc: @naugtur.pl @erikras.com @nicr.dev @acemarke.dev @jpsc.dev @foxy-proxy.bsky.social @tazsingh.com @ayco.io @goede.dev @matteogabriele.bsky.social @marcoippolito.dev @43081j.com (+ open invite)

Chatting with an old friend, or, how I spent the entire day but was finally able to restore the podcast episode I recorded with Mikeal back in 2016. jonkuperman.com/chatting-wit...

Sad to hear about Mikeal Rogers’ passing. He was a big part of the node community and participated actively in the decentralized web movement. Thinking of his friends and family tonight and wishing them peace in this difficult time b.h4x.zip/mikeal/

What is happening right now? ChatGPT/OpenAI outage for 3 hours Heroku down for 4 hours (even their status page is down!) NVIDIA dev docs as well (runs on Heroku) Pipedrive (CRM) issues for 4 hours What else is down… and are these connected? Something started 4 hours ago…