Sign in

Dominykas Blyžė

@dominykas.social
703 followers 232 following 376 posts

Full of stack

PostsRepliesMedia
Reposted by Dominykas Blyžė
Yo @yoyoyoyo.bsky.social · 03/10/2026
You’ll end up doing the hard part while they can go to their bosses and claim they mostly did it (and convince other dunces of that) and then if it falls over or takes a while to clean up, they’ll blame you. Just be prepared for this and make sure to coordinate with coworkers. You aren’t alone. 2/
221
Dominykas Blyžė @dominykas.social · 27/09/2026
Why are there LLMbots that can "answer your emails"? Like, who still receives emails that need answering at scale? Sure, last week my car broke down, so I was corresponding with the garage and insurance, but before that, I think the last email exchange I had was like 6 weeks ago? Is my life sad?
000
Dominykas Blyžė @dominykas.social · 26/09/2026
social.treehouse.systems/@pndc/117325...
social.treehouse.systems
@pndc (@pndc@treehouse.systems)
Q: How many Open Source maintainers does it take to change a lightbulb? A: None. Being burnt-out is the new normal.
030
Reposted by Dominykas Blyžė
James Snell @jasnell.me · 25/09/2026
Way overdue but Node.js is finally getting a `--process-timeout=N` cli flag that will force the process to exit with an explanation of why it was open. github.com/nodejs/node/...
2406
Dominykas Blyžė @dominykas.social · 13/09/2026
Going forward, given that a disclosure of an undici vuln is effectively a disclosure of a Node.js vuln - should the announcements/releases be synced? I haven't looked at the current batch in detail, maybe they're not applicable under typical uses inside Node.js?
001
Reposted by Dominykas Blyžė
Antoine du Hamel @aduh95.bsky.social · 09/09/2026
Node.js 24.21.0 and 26.8.2 are available, with security updates from OpenSSL and Undici. Full changelog and download links available at nodejs.org/en/blog/rele... and nodejs.org/en/blog/rele...
nodejs.org
085
Reposted by Dominykas Blyžė
dax @thdxr.com · 07/09/2026
looking at all the stuff programmers have been building since AI unleashed them is a great reminder of why product people exist
2931
Dominykas Blyžė @dominykas.social · 04/09/2026
I assume we'll need to expect the corresponding Node.js releases for these? How come these are not synchronized in terms of disclosure? Or am I missing/imagining something?
100
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 03/09/2026
🎟️ NodeConf EU 2026 is in Bologna in 3 weeks, and tickets are running low. Sep 29-30. The Savoia Regency, an 18th-century villa set in a 10,000m² park, 5km from the city center. Pool between sessions, Emilia-Romagna food, and two days of real Node.js depth.
1103
Dominykas Blyžė @dominykas.social · 04/09/2026
Ok, fine, yes, I didn't realize how much I missed going to geeky meetups (it's a luxury for me these days, with family and other commitments). Had a great time yesterday, @naugtur.pl @notwes.bsky.social! See you in Vilnius sometime?
231
Dominykas Blyžė @dominykas.social · 03/09/2026
Ohai, Warsaw! You've grown 😱
010
Dominykas Blyžė @dominykas.social · 24/08/2026
See you there 😁
110
Dominykas Blyžė @dominykas.social · 21/08/2026
The train from Vilnius takes ~7h - that's a perfect working day I could spend on it 😁 I wonder if I could bribe @naugtur.pl to open up an extra slot in the meetup 😁
120
Dominykas Blyžė @dominykas.social · 21/08/2026
But I was considering a short trip to Warsaw, until I saw that the meetup is full anyways...
110
Dominykas Blyžė @dominykas.social · 21/08/2026
No...
110
Dominykas Blyžė @dominykas.social · 20/08/2026
Are you doing it in person or remotely?
000
Reposted by Dominykas Blyžė
Wes @notwes.bsky.social · 20/08/2026
Two dudes, one talk: Warsaw on September 3rd where @naugtur.pl and I will be (very professionally, I swear) talking about supply chain security at @meetjs.bsky.social.
331
Dominykas Blyžė @dominykas.social · 20/08/2026
A Thursday 😭
111
Dominykas Blyžė @dominykas.social · 12/08/2026
An incredible experience. Worth the travel, the money, the heat, even if it only lasted 90s.
030
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 11/08/2026
I triage 20-40 security vulnerability reports a week. Almost all of them are now AI-written. And we usually get 3-5 duplicates of each one. That's the new reality of being a maintainer. 🧵
2112
Dominykas Blyžė @dominykas.social · 11/08/2026
Make sure you download the literature from that lady's archive. What a nice lady she is, Anna. Check if the author has a Patreon or smth like that too.
020
Reposted by Dominykas Blyžė
Filippo Valsorda @filippo.abyssdomain.expert · 09/08/2026
I'm watching this, and sure sure the agents coordinating is neat, but once again, WHY ARE WE CHILL WITH Artifactory HAVING SEVERAL RCEs, SSRFs, and unauthorized writes. Why are we chill with Hugging Face having RCEs. Why are we chill with GitHub having RCEs (unrelated, from April).
817417
Dominykas Blyžė @dominykas.social · 09/08/2026
I was once sleeping in a tent with kids next to my home. A dragon at 7am sounded scary, so I stepped out to find one of these beasts.
110
Dominykas Blyžė @dominykas.social · 09/08/2026
This bothers me. Nx v1 was released in 2018, yet nx.dev/blog/cve-202... (CREEP) was only discovered in 2025 (and is, disingenuously, described as a "race condition", which it is not - it's just inappropriate use of shared resources without trust boundaries).
nx.dev
CVE-2025-36852: Critical Cache Poisoning Vulnerability Affects Multiple Build Systems | Nx Blog
A critical security vulnerability called CREEP (Cache Race-condition Exploit Enables Poisoning) has been published as CVE-2025-36852. This vulnerability affects remote cache plugins across numerous bu...
020
Reposted by Dominykas Blyžė
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
Dominykas Blyžė @dominykas.social · 31/07/2026
If you do your job well, you only need to do it once.
000
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 29/07/2026
What do you all think of NPM adding scanning of all packages during publish- a 15-minute delay during peak times? What concerns me the most is: 1. false positives 2. the SLA for the "appeal process" Anyway, good step! github.blog/changelog/20...
github.blog
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
12224
Dominykas Blyžė @dominykas.social · 29/07/2026
FINALLY!
000
Dominykas Blyžė @dominykas.social · 28/07/2026
They tout this as a security improvement, which it is, but it still assumes that an actor with a write permission is not an adversary. Which is true for most humans, esp. in the work setting. But humans are no longer the only entities opening PRs!
000
Dominykas Blyžė @dominykas.social · 28/07/2026
Yet another example of how Github is hopelessly unprepared for the agentic world: github.blog/changelog/20...
github.blog
Read-only Actions cache for untrusted triggers - GitHub Changelog
GitHub Actions now issues read-only cache tokens to the default branch for workflow events that can be triggered without write permissions to the repository. This applies least privilege to the…
110
Dominykas Blyžė @dominykas.social · 27/07/2026
Should be easy enough to vibecode a something that generates an svg with all the avatars?
110
Dominykas Blyžė @dominykas.social · 26/07/2026
The M in MIT license stands for Mechanical. A well known fact.
120
Dominykas Blyžė @dominykas.social · 24/07/2026
Oh, and this is all observable from the outside. You can probably imagine how it all looks from the inside. Pity, I saw an email from them yesterday about something something HackerOne. I didn't read it, but I'm guessing it's not worth hunting for the bounty anymore.
000
Dominykas Blyžė @dominykas.social · 24/07/2026
If I were paranoid, I'd say that is by design. But the reality is that we just have Typical Enterprise Grade Issues here.
100
Dominykas Blyžė @dominykas.social · 24/07/2026
It's incredibly frustrating that this also applies to security features. And since these three things (roles, protections, tokens) are so confusing - you can bet money there's tons of misconfiguration in the wild.
100
Dominykas Blyžė @dominykas.social · 24/07/2026
Since you're a keen eyed reader, you noticed one big symptom here: Github seems to have a tendency to start building New Shiny and to also not finish it.
100
Dominykas Blyžė @dominykas.social · 24/07/2026
Fine grained tokens don't have the option to grant the same permissions that classic tokens can (e.g. you can't use a fine-grained token to access the Github Package Registry, but you can't lock down a classic one to only give access to the registry either).
110
Dominykas Blyžė @dominykas.social · 24/07/2026
Ex 3. They have fancy shiny new "Fine grained tokens" and discourage the use of "Classic tokens". But wait for it, wait for it...
100
Dominykas Blyžė @dominykas.social · 24/07/2026
Ex 2. In the spirit of RBAC, you have "roles" in the repo. You can even construct custom roles. But you can't grant someone "write access to create branches without forks" without also granting them "write access to merge PRs into protected branches".
100
Dominykas Blyžė @dominykas.social · 24/07/2026
But branch protections, of course, don't have the options that rulesets have either (e.g. some of bypasses).
100
Dominykas Blyžė @dominykas.social · 24/07/2026
However, rulesets cannot achieve everything that branch protections can (e.g. you can't create a ruleset, which restricts _who_ can approve things; you can do that via CODEOWNERS checked into the repo, but that is a) not centralizable via API b) not governable by admins alone)
100
Dominykas Blyžė @dominykas.social · 24/07/2026
Ex 1. Go into "Branch protections" - it will tell you "check out the new cool modern way of doing things - Rulesets".
100
Dominykas Blyžė @dominykas.social · 24/07/2026
The more I dig into tightening up our Github permissions, the more I: - want to punch someone - ask where a friend of mine could buy a flamethrower - understand why Github is in the state that it is in terms of supply chain attacks.
100
Dominykas Blyžė @dominykas.social · 21/07/2026
Hidden in the release notes for npm@12: > The default license for npm init has been changed from "ISC" to an empty string. If not set, the license field will be omitted from new packages. Which means a bunch of new packages will be unlicensed, which also means you can't use them in your projects 🎉
000
Reposted by Dominykas Blyžė
Matteo Collina @nodeland.dev · 13/07/2026
Node.js runs under almost every AI product shipping today. The least the industry can do is give its maintainers the tools to keep it secure. Live July 15 👇 streamyard.com/watch/YJ7W3s...
021
Dominykas Blyžė @dominykas.social · 12/07/2026
He was one of the few Republicans who stood for Ukraine. So there's that.
120
Dominykas Blyžė @dominykas.social · 12/07/2026
Such PR campaigns have happened multiple times throughout this war, usually when russia is not doing great. You'd think @economist.com would be smart enough to have learnt to notice that and to not fall for a trap like that.
000
Dominykas Blyžė @dominykas.social · 12/07/2026
This article has only one important phrase - something along the lines of "if sanctions don't ease up and you don't let us pillage Ukraine - russia might use nukes". Which is literally the same PR campaign that's been going the past 3-4 weeks where nukes just get mentioned casually by russians.
200
Reposted by Dominykas Blyžė
rem / Remy Sharp @remysharp.com · 08/07/2026
1996 Novice: I made the forms work 1996 Webbies: fucking copied that from a forum 2006 Novice: I made it interactive 2006 Webbies: you fucking stackoverflow script kiddie 2016 Novice: I made a nice website 2016 Webbies: ugh, fucking bootstrap? 2026 Novice: I made a thing 2026 Webbies: WTF it AI slop
2155