Sign in

Dominykas Blyžė

@dominykas.social
699 followers 230 following 376 posts

Full of stack

PostsRepliesMedia
Dominykas Blyžė @dominykas.social · 27/09/2026
Why are there LLMbots that can "answer your emails"? Like, who still receives emails that need answering at scale? Sure, last week my car broke down, so I was corresponding with the garage and insurance, but before that, I think the last email exchange I had was like 6 weeks ago? Is my life sad?
000
Dominykas Blyžė @dominykas.social · 26/09/2026
social.treehouse.systems/@pndc/117325...
social.treehouse.systems
@pndc (@pndc@treehouse.systems)
Q: How many Open Source maintainers does it take to change a lightbulb? A: None. Being burnt-out is the new normal.
020
Reposted by Dominykas Blyžė
James Snell @jasnell.me · 25/09/2026
Way overdue but Node.js is finally getting a `--process-timeout=N` cli flag that will force the process to exit with an explanation of why it was open. github.com/nodejs/node/...
2406
Reposted by Dominykas Blyžė
Antoine du Hamel @aduh95.bsky.social · 09/09/2026
Node.js 24.21.0 and 26.8.2 are available, with security updates from OpenSSL and Undici. Full changelog and download links available at nodejs.org/en/blog/rele... and nodejs.org/en/blog/rele...
nodejs.org
085
Reposted by Dominykas Blyžė
dax @thdxr.com · 07/09/2026
looking at all the stuff programmers have been building since AI unleashed them is a great reminder of why product people exist
2931
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 03/09/2026
🎟️ NodeConf EU 2026 is in Bologna in 3 weeks, and tickets are running low. Sep 29-30. The Savoia Regency, an 18th-century villa set in a 10,000m² park, 5km from the city center. Pool between sessions, Emilia-Romagna food, and two days of real Node.js depth.
1103
Dominykas Blyžė @dominykas.social · 04/09/2026
Ok, fine, yes, I didn't realize how much I missed going to geeky meetups (it's a luxury for me these days, with family and other commitments). Had a great time yesterday, @naugtur.pl @notwes.bsky.social! See you in Vilnius sometime?
231
Dominykas Blyžė @dominykas.social · 03/09/2026
Ohai, Warsaw! You've grown 😱
010
Reposted by Dominykas Blyžė
Wes @notwes.bsky.social · 20/08/2026
Two dudes, one talk: Warsaw on September 3rd where @naugtur.pl and I will be (very professionally, I swear) talking about supply chain security at @meetjs.bsky.social.
331
Dominykas Blyžė @dominykas.social · 12/08/2026
An incredible experience. Worth the travel, the money, the heat, even if it only lasted 90s.
030
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 11/08/2026
I triage 20-40 security vulnerability reports a week. Almost all of them are now AI-written. And we usually get 3-5 duplicates of each one. That's the new reality of being a maintainer. 🧵
2112
Dominykas Blyžė @dominykas.social · 11/08/2026
Make sure you download the literature from that lady's archive. What a nice lady she is, Anna. Check if the author has a Patreon or smth like that too.
020
Reposted by Dominykas Blyžė
Filippo Valsorda @filippo.abyssdomain.expert · 09/08/2026
I'm watching this, and sure sure the agents coordinating is neat, but once again, WHY ARE WE CHILL WITH Artifactory HAVING SEVERAL RCEs, SSRFs, and unauthorized writes. Why are we chill with Hugging Face having RCEs. Why are we chill with GitHub having RCEs (unrelated, from April).
817417
Dominykas Blyžė @dominykas.social · 09/08/2026
This bothers me. Nx v1 was released in 2018, yet nx.dev/blog/cve-202... (CREEP) was only discovered in 2025 (and is, disingenuously, described as a "race condition", which it is not - it's just inappropriate use of shared resources without trust boundaries).
nx.dev
CVE-2025-36852: Critical Cache Poisoning Vulnerability Affects Multiple Build Systems | Nx Blog
A critical security vulnerability called CREEP (Cache Race-condition Exploit Enables Poisoning) has been published as CVE-2025-36852. This vulnerability affects remote cache plugins across numerous bu...
020
Reposted by Dominykas Blyžė
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 29/07/2026
What do you all think of NPM adding scanning of all packages during publish- a 15-minute delay during peak times? What concerns me the most is: 1. false positives 2. the SLA for the "appeal process" Anyway, good step! github.blog/changelog/20...
github.blog
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
12224
Dominykas Blyžė @dominykas.social · 28/07/2026
Yet another example of how Github is hopelessly unprepared for the agentic world: github.blog/changelog/20...
github.blog
Read-only Actions cache for untrusted triggers - GitHub Changelog
GitHub Actions now issues read-only cache tokens to the default branch for workflow events that can be triggered without write permissions to the repository. This applies least privilege to the…
110
Dominykas Blyžė @dominykas.social · 24/07/2026
The more I dig into tightening up our Github permissions, the more I: - want to punch someone - ask where a friend of mine could buy a flamethrower - understand why Github is in the state that it is in terms of supply chain attacks.
100
Dominykas Blyžė @dominykas.social · 21/07/2026
Hidden in the release notes for npm@12: > The default license for npm init has been changed from "ISC" to an empty string. If not set, the license field will be omitted from new packages. Which means a bunch of new packages will be unlicensed, which also means you can't use them in your projects 🎉
000
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 13/07/2026
Node.js runs under almost every AI product shipping today. The least the industry can do is give its maintainers the tools to keep it secure. Live July 15 👇 streamyard.com/watch/YJ7W3s...
021
Dominykas Blyžė @dominykas.social · 12/07/2026
This article has only one important phrase - something along the lines of "if sanctions don't ease up and you don't let us pillage Ukraine - russia might use nukes". Which is literally the same PR campaign that's been going the past 3-4 weeks where nukes just get mentioned casually by russians.
200
Reposted by Dominykas Blyžė
rem / Remy Sharp @remysharp.com · 08/07/2026
1996 Novice: I made the forms work 1996 Webbies: fucking copied that from a forum 2006 Novice: I made it interactive 2006 Webbies: you fucking stackoverflow script kiddie 2016 Novice: I made a nice website 2016 Webbies: ugh, fucking bootstrap? 2026 Novice: I made a thing 2026 Webbies: WTF it AI slop
2155
Dominykas Blyžė @dominykas.social · 07/07/2026
I know I could log in and unsubscribe or add a filter, but I want to go viral with shaming this bullshit.
010
Dominykas Blyžė @dominykas.social · 07/07/2026
I sometimes have so much stress at work that I want to do some work at work to relax.
000
Dominykas Blyžė @dominykas.social · 04/07/2026
I do catch myself thinking "did I use to talk like this before AI?" several times every week...
120
Dominykas Blyžė @dominykas.social · 24/06/2026
"ai" "agents" don't exist. I have a massive problem (it's a me problem...) with "have an agent do it". All the "doing" happens by the harness (it's making API calls to LLMs and tools and composes the results).
110
Dominykas Blyžė @dominykas.social · 23/06/2026
What are the companies building multiplayer experiences on top of agents/llms?
010
Reposted by Dominykas Blyžė
naugtur @naugtur.pl · 19/06/2026
Ive been hearing claims of JSON handling being a decent chunk of compute so much I'm thinking we should get a hardware module for that already 🤣
131
Dominykas Blyžė @dominykas.social · 13/06/2026
A drinking game where you drink when Claude says "load-bearing" would be super dangerous.
020
Reposted by Dominykas Blyžė
NodeConf.eu @nodeconf.eu · 10/06/2026
#NodeConf EU is back! If you've been working on something worth sharing about #Node.js internals, performance, #developer experience, or anything in between, this is the stage for you! nodeconf.eu See you in Bologna! 🇮🇹
02210
Dominykas Blyžė @dominykas.social · 08/06/2026
I don't know how this little story from, supposedly, 2009 ended up in my Instapaper. Maybe it's a virus. I had fun reading it. www.teamten.com/lawrence/wri...
teamten.com
Coding Machines
000
Dominykas Blyžė @dominykas.social · 06/06/2026
Is there an existing way to do a coverage report per-test? To start with - in any language? As in, I click on a test and it immediately shows me which lines are covered by it specifically (and lines which are only covered by that test, and if there are no such lines - some overlap analysis or smth)?
100
Dominykas Blyžė @dominykas.social · 05/06/2026
It's 2026. Markdown is executable. It's prone to injections. It can do eval().
020
Dominykas Blyžė @dominykas.social · 03/06/2026
Staring at 28 High SAST findings for "Disclosure of Error Details and Stack Traces". I mean, if I have to go and ask the teams to justify and fill out a form for every use of `console.error(err)`, then maybe the AI can just go and take my job already.
000
Dominykas Blyžė @dominykas.social · 29/05/2026
Has anyone invented strongly typed documentation yet? With the primary use being "find usages of this documentation concept across codebase" and "find all documentation mentions of this piece of code"?
000
Dominykas Blyžė @dominykas.social · 28/05/2026
I won't have a chance to experiment myself in the near future, but with npm's staged publishing, what does the packument return as the publishing date?
000
Dominykas Blyžė @dominykas.social · 26/05/2026
Aren't the odds the same as for every other camera in the world?
000
Reposted by Dominykas Blyžė
naugtur @naugtur.pl · 21/05/2026
I said this and npm delivered staged publishing right away. Coincidence? 🤔 What else should I demand for everyone's sake? 😁
8321
Dominykas Blyžė @dominykas.social · 15/05/2026
Smutphone. I mean. Obviously.
010
Dominykas Blyžė @dominykas.social · 15/05/2026
Google Sheets/Docs (the concept; I know Google bought them) revolutionized content work by adding multiplayer. And yet, we're doing TUI with Claude Code et al. Developers are so dull.
000
Reposted by Dominykas Blyžė
Wes @notwes.bsky.social · 13/05/2026
Yeah, pay me as well. Pay @dominykas.social first, but then me 🤣
011
Dominykas Blyžė @dominykas.social · 13/05/2026
- Monitor your vulnerabilities - Alert on new ones in a timely fashion - Have allow lists in your cooldown system thing, which, I hope, is centralized in your org and does not rely on individual devs following best practices on their own - Pay me, I can tell you more (because why not)
152
Reposted by Dominykas Blyžė
Wes @notwes.bsky.social · 12/05/2026
It’s almost as if we said securing GitHub actions is really difficult and maybe it shouldn’t be at the heart of our security model for publishing.
1223
Dominykas Blyžė @dominykas.social · 12/05/2026
Who would have thought OIDC is not a replacement for 2FA publishing? 🤔
020
Dominykas Blyžė @dominykas.social · 11/05/2026
I actually said "Have you tried NOT asking Claude?" today.
121
Reposted by Dominykas Blyžė
Filippo Valsorda @filippo.abyssdomain.expert · 11/05/2026
I truly can’t get over the fact that we chose YAML-interpolated shell scripts as the default CI programming language. It’s so bad that we forgot how to handle untrusted inputs! (pull_request_target and issue_comment triggers should not be that unsafe! It’s just attacker controlled input.)
1919717
Reposted by Dominykas Blyžė
Gal Dagon @mostlygormless.bsky.social · 10/05/2026
This is why we need a ballroom.
51948
Dominykas Blyžė @dominykas.social · 24/04/2026
Basically, for a long time already, in a large enough system, a proper vulnerability review is not possible (unless you're using super small containers, but e.g. ElasticSearch official containers are RedHat and you know what that means). And of course with the new LLM based tooling this gets worse.
100
Dominykas Blyžė @dominykas.social · 23/04/2026
No way to prevent this, says the only package registry, where this keeps on happening...
120