Sign in

Bret Comnes

@bret.io
202 followers 213 following 223 posts

bret.io @socket.dev @breadcrum.net

PostsRepliesMedia
Bret Comnes @bret.io · 29/09/2026
Quentin Dupieux Movies You Should Watch bret.io/blog/2026/qu...
bret.io
Quentin Dupieux Movies You Should Watch
A running log of announcements, projects and accomplishments.
000
Bret Comnes @bret.io · 20/08/2026
Sup
000
Bret Comnes @bret.io · 20/07/2026
Vouch for me on tangled.org/bret.io
tangled.org
bret.io
bret.io on Tangled
120
Reposted by Bret Comnes
Pelle Wessman @voxpelli.com · 12/07/2026
Trying out fetchrss.com to get RSS for sites that lack native RSS because especially in these AI-times it’s baffling how many sites are lacking RSS (and goes to show that vibe-coding is no replacement for knowing _what_ to do, it’s just a way to write out the code that _does_ it)
fetchrss.com
RSS Generator - FetchRSS
Online RSS feed generator. Create RSS for any website. Pick a content you are interested in. Get RSS generated by your rules.
011
Reposted by Bret Comnes
Pierre-Loup Griffais @plagman.bsky.social · 24/06/2026
We've just updated the SteamOS installation image to 3.8. This update improves compatibility with certain modern systems and includes a first-time setup. help.steampowered.com/en/faqs/view... If you have an AMD GPU, you can build your own Steam Machine now! More GPU support being worked on.
21471117
Reposted by Bret Comnes
Pelle Wessman @voxpelli.com · 08/06/2026
Very well done and scarily eye opening!
122
Reposted by Bret Comnes
Joyee Cheung @joyeecheung.bsky.social · 11/06/2026
Today I gave a talk JSNation about the life cycle of ESM in Node.js, how it differs in other environments and the new features that will affect these stages. Slides: github.com/joyeecheung/...
github.com
13812
Reposted by Bret Comnes
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Reposted by Bret Comnes
Feross @feross.bsky.social · 14/05/2026
🚨 node-ipc is compromised again. Three malicious versions (9.1.6, 9.2.3, 12.0.1) published via expired-domain account takeover. Payload steals credentials, SSH keys, cloud tokens, .env files and exfils over DNS. Socket flagged them as malware within 3 min. Details: socket.dev/blog/node-ip...
socket.dev
Popular node-ipc npm Package Infected with Credential Steale...
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.
1225
Reposted by Bret Comnes
Feross @feross.bsky.social · 28/04/2026
. @socket.dev just acquired @secureannex.com, the extension security company built by @johntuckner.me. John is joining Socket. John built Secure Annex as a solo founder into a product that security teams at Reddit, Brave, Torq, and Movable Ink depend on.
2143
Bret Comnes @bret.io · 28/04/2026
I tried this out again recently. It’s a cool feature but it requires EVERY dep to be exceeding well behaved and defined. It also relies on NODE_PATH and has weird issues with esm. Unfortunately something like this needs a runtime solution to work generally.
020
Reposted by Bret Comnes
Pelle Wessman @voxpelli.com · 22/04/2026
Anyone publishing rel-alternate type-text/markdown link tags to their sites? `<link rel=”alternate” type=”text/markdown” href=”foo.md” />` Would enable discovery of a #markdown representation of the same content. /cc @bret.io
151
Reposted by Bret Comnes
patak @patak.cat · 10/04/2026
@pnpm.io's experimental global virtual store is brilliant. The install performance gains are a game-changer for git flows. You get near-zero per-worktree overhead and instant installs for new worktrees as packages are already in the global store. @kochan.io can't stop making pnpm better 🤌
pnpm's experimental global virtual store

Without the global virtual store, each worktree would have its own .pnpm virtual store inside node_modules, with hardlinks or copies of every package. With enableGlobalVirtualStore: true, pnpm keeps all package contents in a single shared directory (the global store, which you can find by running pnpm store path), and each worktree's node_modules contains symlinks pointing there:

your-monorepo/                      (bare git repo)
> main/                           (worktree: main branch)
>> packages/
>> node_modules/
>>> lodash → <global-store>/links/@/lodash/...
>>> express → <global-store>/links/@/express/...
> feature-auth/                   (worktree: feat/auth branch)
>> node_modules/
>>> lodash → <global-store>/links/@/lodash/...  ← same target
>>> express → <global-store>/links/@/express/...
> fix-api/                        (worktree: fix/api-error branch)
>> node_modules/
>>> lodash → <global-store>/links/@/lodash/...  ← same target
>>> express → <global-store>/links/@/express/...
512110
Reposted by Bret Comnes
Pelle Wessman @voxpelli.com · 02/04/2026
And this is what that app contained. (Thankfully I never ran it)
022
Reposted by Bret Comnes
Socket @socket.dev · 02/04/2026
Axios maintainer confirms the npm compromise was caused by a targeted social engineering attack that led to full access to his GitHub and npm accounts. Open source maintainers continue to be high-value targets in supply chain attacks. socket.dev/blog/axios-m...
socket.dev
Axios Maintainer Confirms Social Engineering Attack Behind n...
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
0115
Reposted by Bret Comnes
Pelle Wessman @voxpelli.com · 02/04/2026
If it’s anything like what they attempted with me then a new modus operandi is to create social credibility and even group pressure, then have a planned video call on a faked version of a real streaming service, then show credible errors and urge to download a native app. This is what I got:
174
Bret Comnes @bret.io · 27/03/2026
Buy my graphics card! www.ebay.com/itm/29816448...
ebay.com
GIGABYTE Radeon RX 7700 XT GAMING OC 12GB GDDR6 Graphics Card | eBay
It has probably less than 100 hours on it. Great 1440 card. It was used in a linux Steam Machine gaming PC build and worked great!
000
Bret Comnes @bret.io · 15/02/2026
Whats your favorite SaaS subscriptions/billing/invoicing reference implementation?
100
Bret Comnes @bret.io · 11/02/2026
Good thing I posted this because a 1st party preact adapter released 3 days later lol
000
Bret Comnes @bret.io · 07/02/2026
Small tutorial post on using @tanstack.com with @preactjs.com bret.io/blog/2026/si...
bret.io
Simple TanStack Query with Preact
Use npm package aliases to get @tanstack/react-query working in Preact without any bundler config.
000
Reposted by Bret Comnes
nichoth @nichoth.com · 06/01/2026
+1 to all this. More-or-less the same experience even. Very open to things. If anyone is hiring.
031
Bret Comnes @bret.io · 11/12/2025
Pulled it off
120
Bret Comnes @bret.io · 08/12/2025
Good reference. Thanks for sorting that out in one place.
020
Bret Comnes @bret.io · 06/12/2025
I mini-racked my network. Next step is to fit the orange case into 1U somehow.
150
Bret Comnes @bret.io · 06/12/2025
Why doesn’t anyone sell a charging cubby optimized for horizontal slots. They are all vertical.
000
Bret Comnes @bret.io · 21/10/2025
020
Bret Comnes @bret.io · 21/10/2025
Anyone have old Mac minis they have sitting around and want to sell me?
010
Reposted by Bret Comnes
Jay 🦋 @jay.bsky.team · 03/10/2025
We’re system architects at core. We built a decentralized network so you could run your own moderation, but beyond that our upcoming healthy discourse project is taking some swings at the interaction model that drives these dynamics on Bluesky. Excited to start seeing it in action.
49194156
Reposted by Bret Comnes
Peter van der Zee @pvdz.ee · 16/10/2025
Recognition for Sarah! So deserved! @sarahgooding.bsky.social
294
Reposted by Bret Comnes
Socket @socket.dev · 30/09/2025
Maintainer compromises used to be rare. Now they’re happening at an alarming rate, as seen in recent attacks. Today we’re giving developers a new layer of defense with Socket Firewall, a free tool that blocks malicious dependencies at install time.
192
Reposted by Bret Comnes
Feross @feross.bsky.social · 30/09/2025
🚨 Open source supply chain attacks are exploding. Starting today, that ends. We’re releasing Socket Firewall — FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI. Just run: npm i -g sfw sfw npm install lodash Works for: npm, yarn, pnpm, pip, uv, and cargo.
74512
Bret Comnes @bret.io · 24/09/2025
Anyone know a good leader election library that either uses pg or redis on the backed? Basically, in a horizontally deployed service, I need one instance to do something unique, and something else to take over when it disappears.
000
Bret Comnes @bret.io · 28/08/2025
Gigantic OOOOOF on this one.
020
Reposted by Bret Comnes
Pelle Wessman @voxpelli.com · 11/08/2025
Reminder that the major thing that made GitHub succeed over Google Code, Sourceforge etc is to be found in its initial tagline: “Social coding” GitHub added a social network on top of the code – highlighting the people rather than just the lines Any successor to it needs to solve the social layer
182
Bret Comnes @bret.io · 07/08/2025
Didn't know @pfrazee.com was moonlighting at openai
1120
Reposted by Bret Comnes
🥖 Breadcrum.net @breadcrum.net · 28/07/2025
You can now view and edit your auth tokens in your account page. More auth token features like a CRUID ui and old token cleanup coming soon. Sorry for the slow pace of development lately, just trying to get core features implemented correctly.
042
Reposted by Bret Comnes
Liran Tal @lirantal.com · 22/07/2025
Y'all don't sleep on ls-mcp It's a quick access CLI to detect and list all MCP servers across your AI tools stack
011
Bret Comnes @bret.io · 30/06/2025
I ported the Tron Legacy theme to @zed.dev
110
Bret Comnes @bret.io · 14/06/2025
Is there such a thing as a userQueryState hook? Basically use state but reactive in and out of the query string.
000
Reposted by Bret Comnes
Neocities @neocities.org · 10/02/2025
One million sites 🎉
Screenshot of Neocities showing one million sites
21825184
Bret Comnes @bret.io · 27/05/2025
deploy-to-neocities helping deploy 1k personal websites! Glad to see it!
062
Bret Comnes @bret.io · 25/05/2025
Is there any good domain registrar left? (Independently run, well made, decent prices?) seems iwantmyname sold out recently.
100
Bret Comnes @bret.io · 22/05/2025
I think it may finally be time to drop .io domains. These stupid things cost $100/yr!
130
Bret Comnes @bret.io · 20/05/2025
This is just going to get worse with AI, when people finally realize the only things these create are derivative ripoffs of original work. Goes for code too!
030
Bret Comnes @bret.io · 15/05/2025
Looking for prior art: dissecting GitHub repos into sub-projects, specifically in monorepos.
010
Bret Comnes @bret.io · 09/05/2025
I finally posted my writeup on my Steam Machine project bret.io/blog/2025/yo...
bret.io
You can just build a Steam Machine
I built a Steam Machine and so can you!
020
Bret Comnes @bret.io · 02/05/2025
Technology is a fractal for which we are stuck in an ever narrowing corridor
020
Reposted by Bret Comnes
Matteo Collina @nodeland.dev · 30/04/2025
Why we built a new Kafka client for Node.js The Node.js world needs better tools. Here’s what you need to know: Apache Kafka is vital for real-time data. It powers many businesses, especially in Fintech and Media. These fields see heavy data usage and need reliable solutions.
13810
Bret Comnes @bret.io · 29/04/2025
Anyone recommend a good image viewer component? Doesn't need to be react
000
Bret Comnes @bret.io · 27/04/2025
goversion/v2 is out. Turns out maybe people were right: major versioning in go is a super big headache. Not only do you have to update the go.mod file, but also every self reference in every .go file. AND pkg.go.dev and docs. goversion updates go.mod and .go now too github.com/bcomnes/gove...
github.com
Release v2.0.2 · bcomnes/goversion
Full Changelog: v2.0.1...v2.0.2
020