Sign in

Tobias Bieniek

@tobias.bieniek.cloud
301 followers 117 following 189 posts

✈️ glider pilot 🦀 crates.io team & Rust Foundation engineer 🐹 Ember CLI team emeritus

PostsRepliesMedia
Reposted by Tobias Bieniek
Mainmatter @mainmatter.com · 28/09/2026
We're hiring a Rust Engineering Consultant. We're looking for strong expertise in C-to-Rust migrations or Rust web backends, ideally both, plus experience leading projects and using AI to accelerate development. Learn more and apply 👇 #rustlang
mainmatter.notion.site
Rust Engineering Consultant 2026 | Notion
Please email jobs+rust@mainmatter.com with your résumé and availability.
012
Reposted by Tobias Bieniek
Jonas Kruckenberg @jonaskruckenberg.de · 28/09/2026
come work with me! work with dome of the biggest companies on some of the hardest problems! mainmatter.notion.site/Rust-Enginee...
mainmatter.notion.site
Rust Engineering Consultant 2026 | Notion
Please email jobs+rust@mainmatter.com with your résumé and availability.
2104
Reposted by Tobias Bieniek
Raph Levien @raphlinus.bsky.social · 23/09/2026
A huge milestone: Fearless SIMD 1.0 is published: linebender.org/blog/fearles.... This was a real collaboration, thanks especially to Sergey Davidoff for pushing this over the line, Laurenz Stampfl, Andrew Jakubowicz, valadaptive, Benjamin Saunders, and Daniel McNab.
linebender.org
Fearless SIMD v1.0 is here
Fearless SIMD v1.0 is here
27715
Reposted by Tobias Bieniek
Dion Dokter @diondokter.nl · 19/09/2026
"We don't want to use Rust because we don't want hundreds of dependencies" Ok, then just don't add dependencies? You're in control of your own destiny here! sudo-rs has only 2 which they deemed better than 0
4441
Reposted by Tobias Bieniek
Rust Language @rust-lang.org · 17/09/2026
⚠️ We believe that there is an ongoing campaign targeting owners of popular crates and rust-lang team members that is attempting to compromise devices and accounts in order to use them to publish malware. See our blog post for details: blog.rust-lang.org/2026/09/17/t...
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
121990
Tobias Bieniek @tobias.bieniek.cloud · 17/09/2026
🦀 or you can go to github.com/sponsors/rus... and sponsor the #rustlang project directly through the @rustfoundation.org maintainers fund 😉 more info at rust-lang.org/funding/ including links to all the people you can sponsor individually 😊
github.com
Sponsor @rustfoundation on GitHub Sponsors
The Rust Foundation is an independent non-profit organization dedicated to a more secure, performant, and versatile future through the use of the Rust programming language. Our work supports Rust's...
010
Reposted by Tobias Bieniek
Michael Gattozzi @mgattozzi.dev · 04/09/2026
Unfortunately a job offer I had fell through due to head count elimination so I am currently on the market for a new job! If you need someone with 11+ years of Rust, backend, and distributed systems experience I am your guy. Contact Email: michael@ductile.systems. Boosting appreciated!
26733
Reposted by Tobias Bieniek
Dirkjan Ochtman @djc.ochtman.nl · 03/09/2026
PSA: if you depend on Hickory DNS, upgrade now: github.com/hickory-dns/... DNS implementations (not just Hickory) have been hit pretty hard by LLM-assisted vulnerability research.
github.com
Release v0.26.2 · hickory-dns/hickory-dns
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in pars...
23311
Reposted by Tobias Bieniek
Marco Otte-Witte @marcoow.bsky.social · 01/09/2026
.@mainmatter.com has an all-star Rust team available immediately. After some budget hiccups at one of our clients, we happen to have a well-established team of Rust experts around that's ready to go immediately. 1/🧵
173
Reposted by Tobias Bieniek
Andrew Lilley Brinker @alilleybrinker.com · 31/08/2026
Hey @1password.bsky.social, time to change course.
alilleybrinker.com
1Password Supports the Ethnic Cleansing of Europe — Andrew Lilley Brinker
1Password has committed $300,000 to Omarchy. This is unacceptable and must be rescinded.
541519622
Reposted by Tobias Bieniek
Josh Bressers @josh.bressers.name · 31/08/2026
I had a chat with Erik Möller from @sovereign.tech about what they're doing in the universe of funding open source Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU
opensourcesecurity.io
Sovereign Tech Agency with Erik Möller
Episode Links Erik’s LinkedIn Sovereign Tech Agency Meet the First Sovereign Tech Standards Cohort Incident Report: unsanctioned agent behaviour during cyber testing STA on Mastodon This episode is al...
022
Reposted by Tobias Bieniek
Andrew Lilley Brinker @alilleybrinker.com · 31/08/2026
Hey @1password.bsky.social, longtime customer here: stop giving your money to fascists.
19457131
Reposted by Tobias Bieniek
Artem Zakharchenko @kettanaito.com · 25/08/2026
Please help me make MSW sustainable. It helps hundreds of thousands of engineers, countless companies from startups to enterprise to government institutions build better software. Consider becoming a GitHub sponsor: github.com/sponsors/mswjs
github.com
Sponsor @mswjs on GitHub Sponsors
Mock Service Worker is an API mocking library for browser and Node.js.
1134
Reposted by Tobias Bieniek
Rust Language @rust-lang.org · 20/08/2026
⚠️ A few hours ago, a malicious crate was discovered on crates.​io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted. For details and how to see if you are impacted, see: blog.rust-lang.org/2026/08/20/s...
blog.rust-lang.org
Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.
119481
Reposted by Tobias Bieniek
Dirkjan Ochtman @djc.ochtman.nl · 13/08/2026
Happy to announce a new project: OxiSH, a modern, memory-safe SSH server. dirkjan.ochtman.nl/writing/2026... Prossimo has three criteria for suggesting memory-safe rewrites: (1) widely used, (2) on a security boundary and (3) performing a critical function. This is clearly true for SSH servers.
dirkjan.ochtman.nl
OxiSH: a modern, memory-safe SSH server – Dirkjan Ochtman
26714
Reposted by Tobias Bieniek
jberanek.bsky.social @jberanek.bsky.social · 03/08/2026
Blogged about what I have been up to lately in upstream Rust.
kobzol.github.io
Sovereign Tech Fellowship for Rust maintenance (June-July 2026 report)
For the past few years, I was sponsored by Futurewei to work on upstream Rust. It was great to have the freedom to work on anything I wanted in Rust, be it new features, performance optimizations, bot...
0102
Tobias Bieniek @tobias.bieniek.cloud · 13/07/2026
🦀 in case you're wondering what the crates.io team has been up to for the past 6 months: blog.rust-lang.org/2026/07/13/c... - Source Code Viewer - Untangling crates.io Accounts from GitHub - Advisories and Suggestions - Cuter Error Pages - Svelte Frontend Migration Completed #rustlang
blog.rust-lang.org
crates.io: development update | Rust Blog
Empowering everyone to build reliable and efficient software.
1309
Reposted by Tobias Bieniek
pnpm @pnpm.io · 10/07/2026
If you are on the latest pnpm v11.10.0 (or v10.34.5), you can try out the pnpm v12 alpha via: pnpm self-update 12.0.0-alpha.5 It is fully in Rust! 🦀
3688
Reposted by Tobias Bieniek
Josh Bressers @josh.bressers.name · 06/07/2026
I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve #OpenSourceSecurity #rust #RustFoundation
opensourcesecurity.io
Rust Foundation Maintainers Fund with Lori and Niko
Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It’s a great discussion w...
173
Reposted by Tobias Bieniek
EuroRust @eurorust.eu · 02/07/2026
🦀 Are you feeling lucky? Amos (@fasterthanli.me) and Tris (from No Boilerplate) are hosting a Rust game show at #EuroRust26! Two teams of expert panelists navigate bug-filled code in a spooky game show of pedantic corrections 🎲👻 Learn more 👉 eurorust.eu/talks/game-s... #RustLangNo
0212
Reposted by Tobias Bieniek
Mainmatter @mainmatter.com · 01/07/2026
Chapter 1 of our "C to Rust Migration Book", written by @jonaskruckenberg.de, is out now. We distilled our experience modernizing critical software into this self-paced course: FFI fundamentals, safe mixed codebases, best practices. Read it for free now 👉 mainmatter.com/c-to-rust-mi... #RustLang
mainmatter.com
The C to Rust Migration Book - Mainmatter
Learn how to migrate production C codebases to safe, idiomatic Rust one module at a time.
0103
Tobias Bieniek @tobias.bieniek.cloud · 27/06/2026
🦀 first basic prototype for the diff viewer on crates.io seems to work as planned 😍 and the regular code viewer is now publicly released :) #rustlang
41088
Tobias Bieniek @tobias.bieniek.cloud · 25/06/2026
🦀 It's open for "public" beta testing now! Example: crates.io/crates/base6... The code viewer is not linked anywhere yet while we test it. Just append `/code` to the crate URLs 😉 #rustlang
0252
Tobias Bieniek @tobias.bieniek.cloud · 20/06/2026
🦀 I did another thing... what do you think? 😄 Code viewer right inside of crates.io that shows the uploaded files ✨ It's still a prototype, but once I've cleaned it up I'll open a PR. Diff viewer next? 🙀 #rustlang
8822
Reposted by Tobias Bieniek
dan @danabra.mov · 19/06/2026
"but where are all the bluesky instances?" i've heard this so many times that i wrote an explainer
overreacted.io
There Are No Instances in atproto — overreacted
Like RSS and Google Reader.
42677202
Reposted by Tobias Bieniek
Kevin Cunningham @dolearning.dev · 19/06/2026
TIL you can ignore files in git globally. Never again will a .DS_Store slip into a repo because I forgot to add it to the .gitignore! nelson.cloud/.gitignore-i...
nelson.cloud
.gitignore Isn’t the Only Way To Ignore Files in Git
You can ignore files in .gitignore, .git/info/exclude, and ~/.config/git/ignore
0375
Tobias Bieniek @tobias.bieniek.cloud · 15/06/2026
🦀 I've now extracted the dataset to github.com/rust-lang/st... This should make it easier to other tools to make use of the data. The combined dataset is available as rust-lang.github.io/std-replacem... :) Contributions welcome! ✨ #rustlang
github.com
GitHub - rust-lang/std-replacement-data: Curated dataset of standard-library replacements for crates, surfaced on crates.io
Curated dataset of standard-library replacements for crates, surfaced on crates.io - rust-lang/std-replacement-data
1152
Reposted by Tobias Bieniek
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 10/06/2026
A human in control. In #curl development. daniel.haxx.se/blog/2026/06/10/a-hu…
daniel.haxx.se
A human in control
There seems to be a fair amount of people in either extremes in the current AI landscape. At one side we see the “vibe coders” who use agents and allow them to merge code without any person even looking at the source, while on the other side of the field there are people who are against everything and anything even remotely associated with AI. My personal stance is somewhere in between, as I suppose shouldn’t be too surprising to readers of this blog. ## A work of love and pride The core team behind curl, and that is more people than just me, consists of individuals to whom code quality and source code excellence is important. We do software development because it is a craft we love and we are proud of what we have accomplished this far. We do not hand over our responsibilities to any machines. _We stand for ever bit of code we merge – as humans._ ## AIs do mistakes Blindly accepting code written by AI means that you merge a certain amount of errors, but this is certainly true for human written code as well, so this is not in itself special. Some data suggests that AI generated code might even contain more mistakes than the human versions. We invented test cases and code review a long time ago as a means to help us combat and reduce mistakes to get merged. The particular way code was written does not take away the benefits from code review and getting additional checks and eyes on pending changes. A good code review helps spotting mistakes, omissions or slip-ups. It also helps reinforce the architecture and established design choices. This is true however the code was created. This far, code reviews done by automatic AI bots and the likes have not yet managed to replace the humans. They are simply not good enough. Human reviews are much better. They catch other things and they help make sure proposed changes stay on track. Not to mention how I want to know how curl works, even if I don’t keep 100% intimate knowledge of every single angle and corner, I know most of it. I think it helps me make better decisions, debug better, help users better and keep the architecture sound. Getting the initial code written is not the big deal. For curl, maintaining and polishing the landed code _through decades_ is the real task. _Everything we merge in curl is determined fine and fitting by humans._ ## Humans do mistakes In all living software projects we get bugs reported and we fix them. We do new releases and continue to iterate. We have done this since software was invented and we still do, as humans are quite fallible and easily make mistakes. We try to reduce the error density and frequency by adding tests and by adding more human eyes on the code before we green-light it. It helps, but is not perfect. To help us do better code we invent, introduce and enforce a wide variety of different tools. With tools that look at code and identify problems in the early stages, they help avoid landing bad code in the first place. They make us do better code. They reduce the bug frequency. Some of the best tools for detecting coding mistakes today use AI. These tools might work on existing source code in a git repository or they might look at proposed changes in pull-requests. Above I mentioned that human code reviews are better; but the opposite is also true. In a somewhat complicated change request, it is now common that after the humans can’t spot any more problems, the AI PR review bots can still find an issue or two to remark on. Sure, sometimes they are wrong and then the comment is easily dismissed, but more often than not the findings they point out are actually something worth addressing before merge. _curl is developed and driven by humans, assisted by tools._ ## Communication is for humans Open Source is about sharing code and is a development model where we do things in the open. The _communication_ part of this model is key. Share your ideas, your visions, your problems or maybe just your ideas for what to do this afternoon. Express what you want or what the problem is, and the team can respond and we can work together on fixing and improving whatever needs to be done. Effective communication, a condition for good Open Source, implies _human-to-human_ interaction. Inserting a large AI generated tone-deaf large wall-of-text into such a flow _can_ still work, but only in the same way humans can learn to work with difficult individuals as well. It is not ideal and it is not a smooth way of working. It introduces sand in the machine. Don’t do that. It is rude. _Effective Open Source work means we communicate as humans, even if parts of the work and the code is made with the help of AI._ ## The combination Humans and machines excel at different things. We can complement each other in software development. Everyone is free to act to their own will, but in the curl project we don’t hand over responsibility to machines. We stand for our product. We make it as good as we possibly can; using all the tools that are available to us. I claim that in order to do this, humans need to remain in control.
21712
Tobias Bieniek @tobias.bieniek.cloud · 09/06/2026
🦀 🙄 😆 #rustlang
1231
Tobias Bieniek @tobias.bieniek.cloud · 04/06/2026
🦀 I did a thing... what do you think? github.com/rust-lang/cr... #rustlang
3976
Reposted by Tobias Bieniek
Andrew Gallant @burntsushi.net · 03/06/2026
I was recently diagnosed with a rare autoimmune disorder called anti-NMDA receptor encephalitis. It's a "disease of chaos" that completely upturned my life for a couple months. I wrote a blog about it that goes into more detail and discusses prognosis. :-) burntsushi.net/encephalitis/
burntsushi.net
Encephalitis - Andrew Gallant's Blog
1312443
Reposted by Tobias Bieniek
The Rust Foundation @rustfoundation.org · 02/06/2026
🌱 Donate to our Maintainers Fund on GitHub: github.com/sponsors/rustfoundation The software powering the world's critical infrastructure runs on humans. The RFMF provides support to those who keep #rustlang evolving. Read more: rustfoundation.org/media/help-fund-the-people-who-build-rust/
0104
Reposted by Tobias Bieniek
Frenck | Home Assistant & Smart Home @frenck.social · 31/05/2026
AI did not create the maintainer burden problem in open source. It accelerated it. Contributors are being amplified. Maintainers are still the verification bottleneck. New post: frenck.dev/open-source-...
0151
Reposted by Tobias Bieniek
Jonathan Pallant @thejpster.org.uk · 27/05/2026
eurorust.eu/talks/tales-... Lots of great talks at EuroRust. And this aging idiot banging on about ancient processors or something.
eurorust.eu
EuroRust 2026, Barcelona & online
EuroRust 2026 is a conference for the European Rust community – Barcelona & online, 14.10-17.10.2026
0102
Reposted by Tobias Bieniek
EuroRust @eurorust.eu · 27/05/2026
The full schedule for EuroRust 2026 is here! ✨ We have great speakers and talks, fun side activities, workshops and of course the impl day. If you haven’t already, now is the time to get your ticket! 🦀 See the full schedule and get your ticket 👇 eurorust.eu/schedule/ #RustLang #EuroRust
032
Reposted by Tobias Bieniek
Frenck | Home Assistant & Smart Home @frenck.social · 26/05/2026
Developer machines are not production, but they often hold keys to production-shaped doors. Editors, extensions, CLIs, and local credentials are part of the supply chain now. That is uncomfortable. Also true. frenck.dev/your-editor-...
1124
Reposted by Tobias Bieniek
Adam Chalmers @adamchalmers.com · 26/05/2026
You can use LLMs to help you write quality code, instead of writing (low quality) code for you. nolanlawson.com/2026/05/25/u...
nolanlawson.com
Using AI to write better code more slowly
A lot of people seem convinced that the point of AI coding is to write low-quality code as fast as possible. Spew out barely-passable slop, open massive PRs, and merge them unvetted. Ship it! But t…
2335
Tobias Bieniek @tobias.bieniek.cloud · 21/05/2026
🦀 OMG, github.com/renovatebot/... is finally merged and released! 🎉 from now on renovatebot will automatically keep your `rust-toolchain.toml` files up-to-date with support for stable and nightly versions :) #rustlang
github.com
feat(rust-toolchain): Add `rust-toolchain` manager by Turbo87 · Pull Request #38554 · renovatebot/renovate
New package manager questionnaire Did you read our documentation on adding a package manager? I've read the adding a package manager documentation. Basics What's the name of the package ...
1111
Reposted by Tobias Bieniek
Corbin Crutchley @crutchcorn.dev · 12/05/2026
We at TanStack just had a major attack against our Router packages. We have a postmortem out now explaining what happened and how we mitigated the response: tanstack.com/blog/npm-sup... No other TanStack packages outside of the Router monorepo were impacted
tanstack.com
Postmortem: TanStack npm supply-chain compromise | TanStack Blog
On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 mal...
912440
Reposted by Tobias Bieniek
Mark Erikson @acemarke.dev · 07/05/2026
I wrote about everything I've felt, feared, and experienced about using AI for code over the last few years, and my opinions on where we stand. It's the most personal thing I've ever written. And I'm putting it out there to share with all of you. blog.isquaredsoftware.com/2026/05/ai-t...
blog.isquaredsoftware.com
My Thoughts on AI, Part 1: Fears, Opinions, and Mental Journey
My own personal thoughts and opinions on AI effects and usage, and how those have evolved over time
1211418
Reposted by Tobias Bieniek
Steven ⬢ @styfle.dev · 07/05/2026
GitHub Actions is working on a feature to generate a lockfile to properly pin the version of the actions in your workflow yaml github.com/orgs/communi...
github.com
Help Shape Workflow Dependency Locking 👋 🔒 · community · Discussion #194494
Actions / Workflow Dependency Locking TLDR; This discussion is focused on feedback for: the new dependencies: workflow contract naming and shape of the lock data resolution and enforcement behavior...
0217
Reposted by Tobias Bieniek
Conrad Irwin @cirw.in · 05/05/2026
zed.dev/blog/not-bui...
zed.dev
We're Not Building AI Features for the Money - Zed Blog
From the Zed Blog: Why Zed invests in AI, and the future we're building toward.
161
Reposted by Tobias Bieniek
Andrew Nesbitt @andrewnez.bsky.social · 05/05/2026
Package Manager Threat Models, a follow up from yesterdays CWEs post: nesbitt.io/2026/05/05/p...
nesbitt.io
Package Manager Threat Models
The non-CVE half of package manager security
051
Reposted by Tobias Bieniek
pnpm @pnpm.io · 27/04/2026
Added pnpm Pacquet to the benchmarks github.com/pnpm/pacquet
1685
Reposted by Tobias Bieniek
RustConf @rustconf.com · 09/04/2026
🦀 BIG NEWS, Rustaceans! Tickets are on sale and our speakers & schedule are live for #rustconf 2026! 📅 September 8–11 | Montreal + Online A thread on what to expect... rustconf.com/register?utm...
145
Reposted by Tobias Bieniek
Rust Language @rust-lang.org · 08/04/2026
⚠️ An active phishing attack is targeting crate owners by asking them to "confirm that your email address is still active". These messages are not from crates.io, and should be ignored. (We will never ask you to confirm that your e-mail address is still active.) ⚠️
215563
Tobias Bieniek @tobias.bieniek.cloud · 25/03/2026
first #gliding vacation with the JS3. amazing performance so far 😍
1413
Reposted by Tobias Bieniek
Frenck | Home Assistant & Smart Home @frenck.social · 06/03/2026
🚀 I've just opened 2 new roles at the Open Home Foundation to work full-time on @home-assistant.io! 🖥️ Frontend Engineer 🔐 Security Engineer Fully remote. Full-time. Open source every day. Best job in the world. It changed my life. This is your chance to change yours. 🔗 openhomefoundation.org/jobs
openhomefoundation.org
Open Home Foundation Jobs
Open Home Foundation Jobs
3197
Reposted by Tobias Bieniek
Josh Bressers @josh.bressers.name · 02/03/2026
I had a chat on #OpenSourceSecurity with @sylvestreledru.bsky.social about his Rust coreutils work Replacing coreutils with Rust is one of those things that I love as a way to improve security but also keep a project fresh in the modern age I learned a ton from this disucssion
opensourcesecurity.io
Rust coreutils with Sylvestre Ledru
Josh talks to Sylvestre Ledru about the Rust coreutils project. We’ve been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason...
021
Reposted by Tobias Bieniek
Pete 🙆‍♂️ @petelevasseur.com · 02/03/2026
in ~23 hours see the work that Daniel Silverstone from @codethink.co.uk has done in C <=> Rust gap analysis at the @sdv.eclipse.org Rust SIG meeting :D
screenshot showing upcoming Eclipse SDV Rust SIG talks

in particular, tomorrow's / March 3rd 2026's is highlighed: "Measuring the gap between C and Rust" by Daniel Silverstone  of Codethink
221