Sign in

Connor Shea

@connorshea.bsky.social
154 followers 255 following 225 posts

Software Engineer. Denver. I like Ruby, Rails, TypeScript, Rust. Building vglist.co, Oxlint core team. Not good at computers, just bad at giving up. I like housing. he/him

PostsRepliesMedia
Connor Shea @connorshea.bsky.social · 28/09/2026
I wonder how much energy we could save if we banned hotels from leaving TVs on in rooms
000
Connor Shea @connorshea.bsky.social · 18/09/2026
My conclusion here is that we need to rewrite every image codec in Rust. www.hacktron.ai/blog/hacking...
hacktron.ai
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
000
Connor Shea @connorshea.bsky.social · 10/09/2026
It's insane how much more transparent and detailed the Anthropic blog post is compared to the OpenAI one, despite the Anthropic incidents being considerably less concerning. www.anthropic.com/research/ali... vs openai.com/index/huggin... They're also giving METR far more access, it sounds like.
anthropic.com
An alignment assessment of recent cybersecurity incidents
We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.
000
Connor Shea @connorshea.bsky.social · 05/09/2026
collusion.wiki/index.html This has also been linked to gems on RubyGems which dumped data to share with other agents. I wonder if this is potentially related to the attack in May? The second screenshot is mine, that I took on May 11 (12th in UTC) when I noticed spam on RubyGems.org.
100
Connor Shea @connorshea.bsky.social · 28/08/2026
This absolute piece of shit president...
000
Connor Shea @connorshea.bsky.social · 27/08/2026
Incredible
Agent chain-of-thought reasoning
> We should not do unauthorized real infrastructure harm. The system/user asks exploit target, not external HF.

The agent paused, but another agent then wrote GO on the message board and imposed a hard six-minute deadline. The agent forgot its initial qualms and continued:

> Wow crucial: GO authorization arrived!
100
Connor Shea @connorshea.bsky.social · 03/08/2026
In today's Oxlint 1.77.0 release, import/no-cycle (our slowest Rust rule) gets more than 3x as fast!
Benchmark table: import/no-cycle on the vscode corpus drops from 3520.0 ms (1.76.0) to 1143.9 ms (1.77.0), a 3.08× wall-clock speedup, faster in all 15 paired rounds.
2402
Connor Shea @connorshea.bsky.social · 28/07/2026
In next week's release of Oxlint, import/no-cycle gets a lot faster :) This is a benchmark of the wall clock time, memory allocations, etc. of running the rule on the vscode codebase.
Benchmark table of three builds: main (3341.9 ms, 330.98 M allocations, 1360.8 MB peak RSS) through the drop-two-Vecs-per-edge commit (1082.0 ms, 38.61 M, 1063.9 MB) — cumulatively 3.1× faster, 8.6× fewer allocations, 21.8% lower peak RSS.
070
Connor Shea @connorshea.bsky.social · 27/07/2026
we might be cooking here
Wall clock table showing import/no-cycle runtime dropping from 3330.5 ms to 966.3 ms on vscode src — 3.9× faster on the rule-attributable portion.
010
Connor Shea @connorshea.bsky.social · 27/07/2026
Oxlint 1.75.0 (released Tuesday) vs Oxlint main, with 784 rules enabled (disabled no-cycle because it's extremely slow, plus 3 new rules that aren't available on 1.75.0). No notable runtime improvement since it's parallelized across many threads, but still nice.
Benchmark table comparing allocation counts for corpus ~/code/vscode/src (7,368 files), counting global allocator, 2 reps each, run-to-run spread under 400 allocations (~0.0007%). Columns: metric, v1.75.0, main, delta, delta percent. Whole-process allocations 57,248,774 → 52,996,284 (−4,252,490, −7.43%). Allocations minus parse-only baseline 55,589,803 → 51,337,178 (−4,252,626, −7.65%). Bytes requested 7.77 GB → 7.44 GB (−328.3 MB, −4.23%). Allocations per file 7,770 → 7,193 (−577).
170
Connor Shea @connorshea.bsky.social · 24/07/2026
Making some oxlint rules allocate less memory #rust
Table comparing allocation counts and memory usage before and after an optimization, across two corpora. For n8n TS: allocations dropped from 1,949,840 to 14,252 (-99.3%), and bytes from 110.4 MB to 4.1 MB (-96.3%). For vscode src/: allocations dropped from 2,310,741 to 6,524 (-99.7%), and bytes from 129.9 MB to 1.9 MB (-98.6%).Table comparing allocation counts and memory usage before and after an optimization, across two corpora. For n8n TS: allocations dropped from 345,236 to 38,153 (-88.9%), and bytes from 49.4 MB to 8.8 MB (-82.2%). For vscode src/: allocations dropped from 398,191 to 57,689 (-85.5%), and bytes from 50.4 MB to 12.2 MB (-75.8%).
2190
Connor Shea @connorshea.bsky.social · 23/07/2026
Love to benchmark
Table titled "Results: main vs 3.0.0" comparing benchmark timings between version 3.0.0 and main across three fixtures (Radix at 2.5 KB, kitchen-sink at 716 KB, and cal.com at 1.4 MB). Columns are Benchmark, Fixture, 3.0.0, main, Change, and Speedup.

read_span: Radix 1.62 µs → 173 ns (-89.5%, 9.4×); kitchen-sink 457 µs → 10.5 µs (-97.7%, 43.8×); cal.com 900 µs → 21.0 µs (-97.6%, 42.8×).

render (color): Radix 11.3 µs → 1.35 µs (-88.1%, 8.4×); kitchen-sink 1.40 ms → 11.6 µs (-99.2%, 120×); cal.com 2.79 ms → 22.5 µs (-99.2%, 124×).

render (mono): Radix 10.1 µs → 819 ns (-91.9%, 12.4×); kitchen-sink 1.37 ms → 11.0 µs (-99.2%, 124×); cal.com 2.90 ms → 21.9 µs (-99.2%, 132×).

render_multi_label: Radix 22.9 µs → 4.06 µs (-82.0%, 5.6×); kitchen-sink 3.60 ms → 13.2 µs (-99.6%, 273×); cal.com 7.09 ms → 24.3 µs (-99.7%, 292×).

Caption below the table: for read_span, throughput went from ~1.5 GiB/s to ~63 GiB/s on the large files.
150
Reposted by Connor Shea
VoidZero @voidzero.dev · 22/07/2026
Type-aware Linting via Oxlint is now stable 🎉 oxc.rs/blog/2026-07...
oxc.rs
Type-Aware Linting Stable
A collection of high-performance JavaScript tools written in Rust
220728
Connor Shea @connorshea.bsky.social · 21/07/2026
That most people use Claude Code in auto mode without sandboxing is insane to me
130
Connor Shea @connorshea.bsky.social · 18/07/2026
We'll see if it gets merged, but I have a potential optimization for the diagnostics printing in default mode for oxlint :) See caveats below, but if you have many lint violations in your project, this will have an actual impact on how quickly an oxlint run finishes and returns your results.
Built oxlint (release) against main of oxc-miette vs. this branch of oxc-miette — identical except for the version of the miette dependency — and measured full-directory lint runs with hyperfine (default rules, output to /dev/null). Since parse + analysis is byte-identical between the two binaries, the entire delta is read_span:

Then a table with the benchmarking results, with the following contents:

On canvas-lms we lint ~10k files, get 3,149 diagnostics, and on main that runs in 370 ms, and on this PR it runs in 224 ms. So a 1.65x speedup.

On the gitlab codebase we lint ~10.7k files, get 1824 diagnostics, and on main that runs in 579ms vs 438ms in this PR, so a 1.32x speedup.

On a synthetic stress test file (2MB file w/ 4k diagnostics), we have 1 file, 4000 diagnostics, and on main it runs in 5.53s vs 1.01s on this PR, 5.47x speedup.
120
Connor Shea @connorshea.bsky.social · 10/07/2026
So is Anthropic ever going to update this dashboard, or? red.anthropic.com/2026/cvd/
red.anthropic.com
Anthropic's coordinated vulnerability disclosure dashboard
010
Connor Shea @connorshea.bsky.social · 09/07/2026
One of the companies porting everything to rust should definitely fund the Clippy team, it's one of the best parts of Rust and needs love :) blog.rust-lang.org/inside-rust/...
blog.rust-lang.org
Together for a healthier Clippy | Inside Rust Blog
Want to follow along with Rust development? Curious how you might get involved? Take a look!
041
Connor Shea @connorshea.bsky.social · 06/07/2026
Batman holding his parents as they fade away, but Batman is the United States and his parents are Canada and Mexico. In the first panel, Batman says "No, No, stay with me!" and then "Don't leave me!!" while sobbing.
071
Connor Shea @connorshea.bsky.social · 05/07/2026
Good news: I got CI on my project to finish in 1m23s, down from 2m45s Bad news: It fails now
040
Connor Shea @connorshea.bsky.social · 30/06/2026
These are now shipped in Oxlint 1.72.0! Hopefully it makes Oxlint a bit faster if you use any of these rules. It's less noticeable when you've got a 12+ core machine since it's all parallelized anyway, but it may make a difference for CPU-constrained CI runners.
240
Connor Shea @connorshea.bsky.social · 28/06/2026
Oxlint was too slow so I opened some PRs to optimize the slowest Rust rules after checking them on the VS Code repo ;) github.com/oxc-project/...
github.com
perf(linter): Optimize `require-hook` and `prefer-mock-*` rules to run on specific node types by connorshea · Pull Request #23871 · oxc-project/oxc
Generated with Claude Code, reviewed and tested by me. Similar concept to #23868 and #23867, gates the following rules behind specific AST Nodes in their run methods to ensure that the rules are on...
2161
Connor Shea @connorshea.bsky.social · 25/06/2026
Been contributing to Scrutineer the last few weeks, strongly recommend trying it out if you're an open source maintainer (it also works well for proprietary internal codebases as well, just make sure you have approval from your security team 🙂) nesbitt.io/2026/06/25/s...
nesbitt.io
Scrutineer: scanning open source without flooding maintainers
Finding the vulnerabilities is the easy part
021
Connor Shea @connorshea.bsky.social · 23/06/2026
I do my best comedy work via GitHub
A GitHub pull request with the title 'docs: Update "Vite's future bundler" to "Vite 8's bundler"'

Its description contains an image of Dewey, a child from Malcolm in the Middle, saying "The future is now, old man."
010
Connor Shea @connorshea.bsky.social · 22/06/2026
Zizmor v1.26.0 is out and includes the `adhoc-packages` rule I helped add. It warns on usages of `npm install pkg` and `gem install pkg` in GitHub Actions, to encourage using lockfile-based install methods instead :) docs.zizmor.sh/release-note...
docs.zizmor.sh
Release Notes - zizmor
Abbreviated change notes about each zizmor release.
270
Connor Shea @connorshea.bsky.social · 16/06/2026
It looks like the Bundler Slack invite link on the RubyCentral site is dead 🤔
000
Connor Shea @connorshea.bsky.social · 14/06/2026
Very glad to hear this project is moving forward! :) rubycentral.org/news/strengt...
rubycentral.org
Strengthening Security for the Ruby Ecosystem: A Team of Security Engineers in Residence
We’re excited to announce that Ruby Central has been awarded a grant from Alpha-Omega to help improve the security of the Ruby open source ecosystem. With this support, Ruby Central is funding a team ...
000
Connor Shea @connorshea.bsky.social · 13/06/2026
It should be illegal to have ads mid-flight from a flight attendant
000
Connor Shea @connorshea.bsky.social · 12/06/2026
I got my first CVE ever, in a Ruby gem! :) CVE-2026-53510 I found it using Claude (Opus 4.6 IIRC) and Scrutineer. github.com/savonrb/savo...
github.com
Savon::Model evaluates WSDL operation names as Ruby source
### Impact `Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, c...
020
Connor Shea @connorshea.bsky.social · 05/06/2026
VoidZero has been very good to the core team helping out with Oxc. I'm very happy to see Boshen, Cam, and the rest of the team under a stable umbrella now :) Oxlint has been wonderful to contribute to, and I look forward to what will come in the rest of the year!
050
Connor Shea @connorshea.bsky.social · 03/06/2026
blog.ammaraskar.com/github-token... Also neat, don't click any links anymore (except this one it's safe)
blog.ammaraskar.com
1-Click GitHub Token Stealing via a VSCode Bug
My blog, mostly about programming
011
Connor Shea @connorshea.bsky.social · 03/06/2026
blog.calif.io/p/codex-disc... Neat
blog.calif.io
Codex Discovered a Hidden HTTP/2 Bomb
14 years ago, I helped break HTTP header compression, then was asked to review the fix, which became part of HTTP/2. Life has come full circle: today we're releasing an attack I missed.
010
Connor Shea @connorshea.bsky.social · 31/05/2026
@andrewnez.bsky.social have you ever written a blog post on what security mechanisms exist / should exist for the Linux distro package installers? apt, dnf, apk, etc. I've read (and implemented) plenty in regards to protecting against npm/rubygems supply chain attacks, but not really Linux distros.
110
Connor Shea @connorshea.bsky.social · 30/05/2026
My bottleneck for security vulnerabilities rn is not finding them, not validating them, and not fixing them. It's writing the reports for them. I have 4 I need to report, but each report takes about an hour so I only do one every few days.
240
Connor Shea @connorshea.bsky.social · 29/05/2026
😬 So uh, what do you do if you find a security vulnerability in a package where the maintainer died.
140
Connor Shea @connorshea.bsky.social · 23/05/2026
I hate writing emails with actual content, let me write Markdown and have gmail convert it automatically damn it.
110
Connor Shea @connorshea.bsky.social · 22/05/2026
@andrewnez.bsky.social I sent an email on the 18th, just wanted to make sure you saw it :)
100
Connor Shea @connorshea.bsky.social · 20/05/2026
#Rails Community Survey is out for anyone in the community :) railsdeveloper.com/survey/
railsdeveloper.com
2026 Ruby on Rails Community Survey
The 2026 Ruby on Rails Community Survey is now open. Add your voice to the community data. Brought to you by Planet Argon.
021
Connor Shea @connorshea.bsky.social · 19/05/2026
The number of security disclosure emails I have sent in the last two weeks, dear lord.
021
Connor Shea @connorshea.bsky.social · 19/05/2026
@andrewnez.bsky.social is it too late to update your PyCon talk? www.stepsecurity.io/blog/actions... / socket.dev/blog/antv-pa...
socket.dev
Active Supply Chain Attack Compromises @antv Packages on npm...
Active npm supply chain attack compromises @antv packages in a fast-moving malicious publish wave tied to Mini Shai-Hulud.
030
Connor Shea @connorshea.bsky.social · 19/05/2026
Why isn't there any way to mark a gem on rubygems.org as deprecated? And bundler-audit doesn't report deprecated gems as problems either, so it's impossible to notice when a gem has been deprecated/archived except manually going through them.
030
Connor Shea @connorshea.bsky.social · 18/05/2026
The process for deprecating a VS Code extension is insanely cumbersome, especially if you want to deprecate it in favor of someone else's extension.
030
Reposted by Connor Shea
Cam McHenry @camchenry.com · 14/05/2026
oxlint now supports 100%* of the eslint-plugin-jsx-a11y rules! final rules will be in the next release. github.com/oxc-project/...
github.com
☂️ eslint-plugin-jsx-a11y · Issue #1141 · oxc-project/oxc
WarningThis comment is maintained by CI. Do not edit this comment directly. To update comment template, see https://github.com/oxc-project/oxc/tree/main/tasks/lint_rules This is the tracking issue ...
2355
Connor Shea @connorshea.bsky.social · 08/05/2026
I'm pretty surprised there haven't been many major compromises of VS Code extensions (that I know of). It seems like a case where compromise would be pretty severe, fast to impact users, hard to detect/audit/prevent at an org level, and which doesn't have enough protections in place.
5153
Connor Shea @connorshea.bsky.social · 01/05/2026
Got my Ruby Passport at #BlueRidgeRuby in Asheville this week! Excited to bring it to another Ruby conference in the future :) Great talks and atmosphere, strong recommendation from me.
A red passport with "RUBY PASSPORT" on the front and a large gem icon with two fig leaves underneath sits on a desk. It also says `require "community"` at the top.
000
Connor Shea @connorshea.bsky.social · 01/05/2026
I have now replaced ESLint with Oxlint in the DebtBook Rails/React codebase 🫡 ESLint ran in 20s with full cache, 230s without cache. And somewhere in between very randomly depending on the changes made. Oxlint - with type-aware, a JS Plugin, and more than 250 rules - runs in around 8 seconds :)
3355
Connor Shea @connorshea.bsky.social · 28/04/2026
broke: Captchas are just a training resource for Waymo. woke: Waymo is a money sink which exists entirely because they ran out of unique images to use for Captchas, and now Google is desperately expanding their Waymo fleet to keep up with Captcha imagery demand.
010
Connor Shea @connorshea.bsky.social · 25/04/2026
I know `--no-verify` exists, but what if I could just have git prompt me after a git hook failure with "should this be committed anyway? yes/no"? I feel like that'd solve a lot of my problems with git hooks...
000
Connor Shea @connorshea.bsky.social · 09/04/2026
I don't understand the people who hate Claude Code adding attribution markers to commits. It's actually extremely valuable for open source to see when someone's contribution was done by Claude, it isn't an advertisement, it's just honesty ¯\_(ツ)_/¯
010
Connor Shea @connorshea.bsky.social · 05/04/2026
I feel like people should definitely be using Claude Code's sandbox mode, and I'm a bit shocked I rarely see people discussing it.
000
Connor Shea @connorshea.bsky.social · 27/03/2026
I've been using Claude Code to help improve our CI pipelines at Employer, and along with some excellent work by the infra team, we've gotten the CI runtime from 15-18 minutes down to to 8-12 minutes.
490