Reposted by Jordan Harbandharbor.ist @harbor.ist · 29/09/2026Two new CVEs published today (as well as the fixed releases for them): `shell-quote`: www.cve.org/CVERecord?id... `pbkdf2`: www.cve.org/CVERecord?id... 011
Jordan Harband @jordan.har.band · 27/09/2026i wish I’d discovered both scuba diving and Japan in my 20s rather than in my 40s. the last two decades would have been quite different. 390
Reposted by Jordan HarbandLeah McElrath @leahmcelrath.bsky.social · 24/09/2026AP Stylebook warns against anthropomorphizing AI systems: “Avoid language that gives them human characteristics… Instead, explain what a system does, how well it performs, who built it and who could be affected by it.” 1970102257
Jordan Harband @jordan.har.band · 21/09/2026nvm.sh v0.40.8 is out, fixing a path traversal vuln and a number of bugs - cve.org/CVERecord?id... - github.com/nvm-sh/nvm/r...github.comRelease v0.40.8 · nvm-sh/nvmBug Fixes nvm_alias, nvm_version_path: reject .. path components nvm_get_make_jobs: count cores on platforms the case does not name nvm-exec: improve the no-version failure message nvm use: do not... 042
Reposted by Jordan HarbandStarfire’s Deranged Neocon Foreign Policy Podcast @irhottakes.bsky.social · 18/09/2026It’s very simple. A reality TV host became dictator because he turned down a role for Sharknado 4 and that’s why the king of outer space, who cheats at Diablo, got to kill Africa. Now the economy is controlled by a sex cult that has something to do with Harry Potter fanfic because of robots. 15786372553
Reposted by Jordan HarbandDemigirlboss @demigirlboss.win · 18/09/2026DO SOMETHING YOU LOVE AND YOU'LL NEVER WORK A DAY IN YOUR LIFE. COROLLARY. DO SOMETHING YOU LOVE AND YOU NEVER TAKE DAYS OFF EITHER. THIS IS A POST ABOUT BEING AN ENGINEER. 41174
Reposted by Jordan Harbanddanielroe @danielroe.dev · 19/09/2026don't be nice.roe.devDon't be niceSometimes, it's more important to be good than it is to be nice. 41734246
Jordan Harband @jordan.har.band · 03/09/2026tfw you and your cat successfully hunt a bugstatic.klipy.comCat High FiveALT: Cat High Five 0100
Jordan Harband @jordan.har.band · 26/08/2026Oh, right. The daybed. The daybed for Kuzco, the daybed chosen especially to relax Kuzco, Kuzco’s daybed. That daybed? 010
Jordan Harband @jordan.har.band · 14/08/2026Your friendly reminder that a thing developed in isolation, absent sufficient stakeholders, has to be insanely, extremely, staggeringly good to be able to outweigh the aforementioned badness. (spoiler alert: it probably isn’t) 240
Jordan Harband @jordan.har.band · 12/07/2026lol why would Glendale Community College have any info about me whatsoever??? I've never attended, applied, lived near it, or been to Glendale. this is the most confusing @haveibeenpwned.com email i've gotten yet 110
Reposted by Jordan Harbandnpm @npmjs.com · 08/07/2026npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...github.blognpm install-time security and GAT bypass2fa deprecation - GitHub Changelognpm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation… 26024
Reposted by Jordan HarbandWilliam Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss 01510
Jordan Harband @jordan.har.band · 06/07/2026can someone please tell *every bank* that if a "secure messaging system" goes to my email address, then it's basically not possible for it to be more secure than my email account itself? 000
Reposted by Jordan HarbandCoach Finstock @coachfinstock.bsky.social · 22/03/2026Aesop: I TOLD YOU 10278892412
Jordan Harband @jordan.har.band · 19/06/2026I got really tired of having to manually track down whether a package ships its own types, or has a DefinitelyTyped package, or how that changes over time. so, I made npmjs.com/dt-clean - `npx dt-clean -u` and you'll have the right version of the right DT packages!npmjs.com 0152
Jordan Harband @jordan.har.band · 11/06/2026ok i know i'm a couple months late, but wtaf is this new "Marathon" game? it seems like it has precisely nothing to do with actual Marathon lore, and is just a (potentially fun but) entirely unrelated game with the title slapped on top. 220
Jordan Harband @jordan.har.band · 11/06/2026it is oddly satisfying watching ferrier content on the reels 000
Jordan Harband @jordan.har.band · 04/06/2026nvm.sh v0.40.5 is out, with some CVE fixes: github.com/nvm-sh/nvm/r... Be sure to update!github.comRelease v0.40.5 · nvm-sh/nvmNew Stuff nvm install --offline: install from cache without network access Bug Fixes nvm_download_artifact: reject version strings with disallowed characters nvm_get_checksum: pass the tarball n... 052
Reposted by Jordan HarbandMike Cook @mtrc.bsky.social · 21/05/2026oh no, i don't use the ai for <thing that i am paid to do> it's terrible at that. it's great for <thing you are paid to do> though. 41131306
Reposted by Jordan HarbandFeross @feross.bsky.social · 20/05/2026Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started. 118514
Jordan Harband @jordan.har.band · 30/04/2026Clutching pearls about how many PURLs are in your application is just FUD and nonsense. The only thing that matters is, how many humans can put code into it. (ie all your engineers + every linux dev + every OSS maintainer etc) 031
Jordan Harband @jordan.har.band · 22/04/2026PSA: add `export GH_TELEMETRY=false` and `export DO_NOT_TRACK=true` to your shell profile files to opt out of @github.com's on-by-default `gh` telemetry. 0141
Jordan Harband @jordan.har.band · 22/04/2026oof, who do i complain to about the name of git 2.54's "history" command? git does not have a history, it has a changelog, and the conceptual difference is very important for having the proper mental model :-( 200
Jordan Harband @jordan.har.band · 04/04/2026I was pretty happy with my surroundings while discussing supply chain security today. 0160
Reposted by Jordan HarbandWes @notwes.bsky.social · 03/04/2026The thing people may not realize is that the best way to secure the supply chain is to secure the maintainers. And the best way to secure the maintainers is to pay them and give them a laptop, health insurance, and maybe even a desk to sit at. 1105
Reposted by Jordan Harbandeliza🌻 @elizas.website · 03/04/2026so what i am learning from github.com/axios/axios/... is that you should simply never join a Microsoft Teams call for any reason --- because of securitygithub.comPost Mortem: axios npm supply chain compromise · Issue #10636 · axios/axiosPost Mortem: axios npm supply chain compromise Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were... 413834
Reposted by Jordan HarbandSocket @socket.dev · 03/04/2026🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week. socket.dev/blog/attacke...socket.devAttackers Are Hunting High-Impact Node.js Maintainers in a C...Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios. 12814
Reposted by Jordan HarbandDarcy Clarke @darcyclarke.me · 01/04/2026tldr; if you used @vlt.sh as your package manager, then you were protected the minute @socket.dev flagged the malicious packages in the `axios` attack yesterday. The best time to switch your package manager was 48hrs ago, the next best time is right now. More below: blog.vlt.sh/blog/vlt-buildblog.vlt.shIntroducing Phased Package InstallationsWhen you run vlt install, packages are downloaded and extracted to node_modules, but no lifecycle scripts execute. 1137
Reposted by Jordan HarbandSocket @socket.dev · 01/04/2026🧨 Axios only needed to be resolved somewhere in your dependency graph to affect you. Semver + transitive deps + runtime installs = hidden blast radius. If you only checked your project’s lockfile, you may still not know. socket.dev/blog/hidden-... #nodejs #javascriptsocket.devThe Hidden Blast Radius of the Axios Compromise - SocketThe Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain. 01613
Reposted by Jordan HarbandTC39 @tc39.es · 11/03/2026ECMAScript Euphoria! 🎉 We don't always post when a single proposal advances, but when we do, it's Temporal -> Stage 4. Just days shy of 9 years from Stage 1, a herculean effort on the part of many champions, delegates, invited experts, and contributors, past and present. Thank you all! 🙌 220948
Reposted by Jordan HarbandRob Palmer @robpalmer.bsky.social · 10/03/2026ECMAScript excitement 😉 Congrats to @jordan.har.band on advancing Error.prototype.stack to Stage 2.7 at TC39 today 🎉 This proposal seeks to standardize the existence of the accessor in the JS spec. github.com/tc39/proposa...github.comPath to Stage 4! · Issue #9 · tc39/proposal-error-stack-accessorStage 4 committee approval two implementations v8 (node / Chrome) node (for DOMException) spidermonkey (Firefox) jsc (Webkit / Safari) Deno (for DOMException) Porffor es-shims polyfill keisel Boa s... 1211
Jordan Harband @jordan.har.band · 10/03/2026did you know claude code has _weekly_ usage limits? i didn't 130
Jordan Harband @jordan.har.band · 09/03/2026Finally found a plane with a device holder that can fit an iPad Pro 1110
Jordan Harband @jordan.har.band · 06/03/2026i hadn’t hit Claude’s limits once since upgrading to the 10x max plan, but it took me less than 24 hours to hit the limits on the free open source 20x max plan (-‸ლ)media.tenor.coma cartoon character is sitting in front of an orange emergency exit signALT: a cartoon character is sitting in front of an orange emergency exit sign 1130
Reposted by Jordan HarbandSocket @socket.dev · 28/02/2026minimatch patched 3 high-severity ReDoS vulnerabilities that can stall the Node.js event loop. Because it's pulled into nearly every corner of the #NodeJS ecosystem (~472M weekly downloads), we're releasing free Certified Patches for all three. socket.dev/blog/minimat... #JavaScriptsocket.devminimatch Patches 3 High-Severity ReDoS Vulnerabilities - So...minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches. 054
Reposted by Jordan HarbandSocket @socket.dev · 19/02/2026We're excited to announce that Socket is joining the @openjsf.org! Proud to support the #JavaScript ecosystem alongside so many great projects and contributors. socket.dev/blog/socket-...socket.devSocket Joins the OpenJS Foundation - SocketSocket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecos... 0175
Reposted by Jordan HarbandOpenJS Foundation @openjsf.org · 19/02/2026🎉 We’re thrilled to welcome @socket.dev as our newest Silver member. Socket is doing critical work to secure the JavaScript ecosystem by helping developers identify and prevent supply chain risks. We're excited to collaborate and make open source safer for everyone! 🛡️💻 openjsf.org/blog/socket-... 0236
Jordan Harband @jordan.har.band · 12/02/2026when you're publishing a CVE, please think about the good actor/bad actor cohorts (especially governments) that will be awake and responsive to deal with it to be clear, evening pacific time is a very poor choice. 040
Jordan Harband @jordan.har.band · 01/02/2026here’s a fun fact - the vast majority of the conspiracy theorists are still very wrong even when they get it right that said, they should probably be buying lottery tickets, because wtaf 030
Reposted by Jordan HarbandCitizen Platano 🇵🇷 @daniloc.xyz · 31/01/2026me at 17: a secret conspiracy of billionaires shapes global events me at 35: class interest creates emergent outcomes and aligned behavior, but there’s no smoky room where plutocrats plot to shape global events me at 41: a secret conspiracy of billionaire perverts shapes global events 214130
Reposted by Jordan HarbandKate Compton @galaxykate.bsky.social · 31/01/2026You can test new tech ideas using the Seinfeld Test Would the product eliminate the plot of an episode? (Google maps, cell phones, paypal, battery packs) Good tech. Would the product inspire new Seinfeld plots? (NFTs, AI chatbots, crypto currency, blindboxes, metaverse land sales) Bad tech. 7688072844
Reposted by Jordan HarbandSarah Gooding @sarahgooding.bsky.social · 31/01/2026"Security work is emotionally expensive and invisible, and sharing it makes it sustainable." - @ulisesgascon.com Many thanks to @jddalton.bsky.social, @jordan.har.band, and @ulisesgascon.com for their insights on maintaining Lodash and all the hard work put into reviving the project. 💚 0127
Reposted by Jordan HarbandThomas Fuchs @thomasfuchs.at · 30/01/20262006: Less is more, don’t repeat yourself 2016: Beautiful code prevents technical debt 2026: trillions of lines of generated spaghetti code that generate other spaghetti code will save us 212930
Jordan Harband @jordan.har.band · 29/01/2026nvm.sh users: please upgrade to github.com/nvm-sh/nvm/r... if you're using `wget` on your system, to fix a medium vulnerability (github.com/nvm-sh/nvm/s...).github.comRelease v0.40.4 · nvm-sh/nvmBug Fixes sanitize NVM_AUTH_HEADER in wget path nvm_has_colors: also check if stdout is a terminal nvm_strip_path: avoid gawk-specific RT variable for mawk compatibility nvm_get_default_packages: ... 164