Sign in

vhyrro

@vhyrro.neorg.org
64 followers 10 following 80 posts

A programmer. Can someone build me a hut in the woods pls. Lead dev of: - github.com/nvim-neorocks/rocks - github.com/nvim-neorg/neorg

PostsRepliesMedia
vhyrro @vhyrro.neorg.org · 27/09/2026
vhyrro.neorg.org/posts/critic... It's live :)
vhyrro.neorg.org
Conquering the Moon (luarocks.org remote code execution exploit) | Vhyrro's Digital Garden
How I found an incredibly dangerous vulnerability in Lua's infrastructure.
041
vhyrro @vhyrro.neorg.org · 27/09/2026
During my work on Lux, I noticed an oddity in luarocks and launched a month-long investigation. luarocks.org had a critical RCE allowing anyone to gain root access to the site with a package upload. I will launch a blog post describing how the exploit works soon. luarocks.org/security-inc...
luarocks.org
LuaRocks - The Lua package manager
A website for submitting and distributing Lua rocks
131
vhyrro @vhyrro.neorg.org · 13/07/2026
Tired of CLI tools having difficult to understand errors? Me too! That's why Lux is getting a huge overhaul of its error system to make it as friendly as possible. System is a work in progress - by the end I want any newbie to be able to try the CLI and immediately be guided towards best practices.
020
vhyrro @vhyrro.neorg.org · 12/07/2026
If I had to teach the accumulated best practices of AI to a person from 2019 this is how I'd do it: vhyrro.neorg.org/posts/a-hitc...
vhyrro.neorg.org
A Hitchhiker's Guide to AI | Vhyrro's Digital Garden
How not to make total slop :)
0101
Reposted by vhyrro
Marc @mrcjkb.bsky.social · 08/07/2026
Progress update on Lux: You can now distribute your Lua projects as archives or standalone binaries. mrcjkb.dev/posts/2026-0...
mrcjkb.dev
mrcjkb.dev - lx dist - distribute your Lua projects as archives or standalone binaries
021
vhyrro @vhyrro.neorg.org · 02/07/2026
Huge updates for Lux! The recently implemented 2FA will prevent a class of API key hijacking attacks present throughout programming today. vhyrro.neorg.org/posts/rocks-...
vhyrro.neorg.org
Lux v0.34.2 | Vhyrro's Digital Garden
Two Factor Authentication is here!
022
vhyrro @vhyrro.neorg.org · 02/07/2026
This was one fun side project to devise and create, opinions welcome! vhyrro.neorg.org/posts/calend...
vhyrro.neorg.org
Our Calendar Sucks | Vhyrro's Digital Garden
It's the 20th March, 4:02.09.1 CET. Wait, that doesn't sound right.
000
vhyrro @vhyrro.neorg.org · 25/06/2026
I'm about to finalize sensible rate limiting for Luanox APIs to prevent spam or excessive server load. There are many great features coming up, including 2FA for tokens and full backwards compatibility with the luarocks.org APIs 🚀🚀
luarocks.org
LuaRocks - The Lua package manager
A website for submitting and distributing Lua rocks
010
vhyrro @vhyrro.neorg.org · 25/06/2026
the Lux Lua bridge wiil soon get support for full type annotation generation. You'll soon be able to get hints from the lua language server when interacting with the Lux API :) github.com/lumen-oss/lu...
020
vhyrro @vhyrro.neorg.org · 29/03/2026
Shoutout to the Neovim devs for 0.12.0, it's all good steps towards making the editor even better for beginner users and for me who can now run :restart 500 times a day
020
vhyrro @vhyrro.neorg.org · 29/03/2026
now THIS is a rant I can get behind I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN
010
vhyrro @vhyrro.neorg.org · 25/03/2026
Moved my bsky account from bsky.social to vhyrro.neorg.org, it's nice that all you need is a DNS entry! I love it.
070
vhyrro @vhyrro.neorg.org · 24/03/2026
My Rust bindings for the fantastic Janet language are the first repo of mine to be hosted on tangled.org! tangled.org/vhyrro.neorg...
030
vhyrro @vhyrro.neorg.org · 12/03/2026
Lux now prevents privilege escalation and malicious Lua scripts from doing any damage to your host system. After thousands of changes and hours of debugging, say hello to sandboxing! 🚀🔥 opencollective.com/lumen-labs/u...
opencollective.com
🚀 Lua Sandboxing - Lumen Labs
I have spent the last two weeks working on integrating https://github.com/kyren/piccolo into Lux as our VM for executing untrusted Lua scripts. Today that PR was merged! 🎉🎉 With constant atta...
051
vhyrro @vhyrro.neorg.org · 06/03/2026
I've finally done it. The sandboxing refactor for Lux is done, after a lot of long winded planning and rewiring the codebase. Now for the tedious cleanup phase 🔥
050
vhyrro @vhyrro.neorg.org · 21/02/2026
The sandboxing refactor for Lux is much larger than I had anticipated! The PR will be large but the upside is that packaging the project will become much easier as we will be able to ditch mlua as a dependency 🔥🔥
040
vhyrro @vhyrro.neorg.org · 15/02/2026
Additionally, Luanox support in Lux will further enhance security by using a service with stronger API keys and no manifest files. Ideally, we will one day incrementally upgrade to TOML rockspecs instead of dynamic Lua files (which bring nothing useful other than security issues).
020
vhyrro @vhyrro.neorg.org · 15/02/2026
If all goes well, Lux will be hardened against an attack like this by limiting execution time and restricting access to I/O and the capacity to load dynamic libraries at runtime.
110
vhyrro @vhyrro.neorg.org · 15/02/2026
I am currently making a serious attempt at implementing sandboxing in Lux. Due to the way the ecosystem is structured, rockspecs (instructions on how to build a Lua project) are themselves Lua files. This means that they can run unbounded and arbitrary code.
110
vhyrro @vhyrro.neorg.org · 04/02/2026
Amazing work :)
010
vhyrro @vhyrro.neorg.org · 09/01/2026
Video about Lazy Loading should be ready by the end of today 🔥🔥
020
vhyrro @vhyrro.neorg.org · 05/01/2026
youtu.be/vZtL_Er4QpQ?... Here it is! Latest Neovim video 🔥
youtu.be
Understanding Neovim #11 - Keybinds
YouTube video by Vhyrro
072
vhyrro @vhyrro.neorg.org · 05/01/2026
oh this looks nice 👀
000
vhyrro @vhyrro.neorg.org · 04/01/2026
There may or may not be a new YouTube video coming out very soon 👀
010
vhyrro @vhyrro.neorg.org · 31/12/2025
github.com/neovim/neovi... Dont mind me eagerly checking this PR daily hoping for some progress. The Neovim terminal could really do with some QoL for end users :)
github.com
replace libvterm with libghostty / libvaxis / ghostty-vt · Issue #33155 · neovim/neovim
Problem libvterm is missing some features and moving too slowly. Expected behavior Evaluate if libghostty or libvaxis can replace libvterm. full support (including scrollback) for reflow. #30117 li...
021
vhyrro @vhyrro.neorg.org · 25/12/2025
Merry Christmas to all the real ones 🙏🔥
020
vhyrro @vhyrro.neorg.org · 20/12/2025
based chromium hater
020
vhyrro @vhyrro.neorg.org · 20/12/2025
Elixir's tooling is severely underrated for just how good it is 🙏
010
Reposted by vhyrro
Zach Daniel @zachdaniel.dev · 25/09/2025
www.postgresql.org/about/news/p... PostgreSQL 18 is hype.
postgresql.org
PostgreSQL 18 Released!
The [PostgreSQL Global Development Group](https://www.postgresql.org) today announced the release of [PostgreSQL 18](https://www.postgresql.org/docs/18/release-18.html), the latest version of the worl...
1155
vhyrro @vhyrro.neorg.org · 15/09/2025
Thanks to generous donations from our OpenCollective supporters we've now moved Luanox to a dedicated domain (beta.luanox.org)! For reasons to support us be sure to check out beta.luanox.org/donate :D
beta.luanox.org
Luanox
Discover the most popular and well-maintained packages in our ecosystem
020
Reposted by vhyrro
Rust Language @rust-lang.org · 12/09/2025
We received reports of a phishing campaign targeting crates​.io users. Do not click on links asking to authenticate to protect your account. More information: blog.rust-lang.org/2025/09/12/c...
blog.rust-lang.org
crates.io phishing campaign | Rust Blog
Empowering everyone to build reliable and efficient software.
011256
Reposted by vhyrro
NTBBloodbath @amartin.beer · 10/09/2025
Designing for mobile-first in frontend development is fun... Until you come across mobile devices that for some reason have a viewport width less than 365 pixels. In some cases, they completely break CSS and you have to deal with edge cases. Why don't companies make phones with a viewport standard?
131
vhyrro @vhyrro.neorg.org · 10/09/2025
With the growth of luarocks maybe we should start advocating for internationalization in larger Neovim plugins? I think it'd be quite amazing. You could throw a lua lib like github.com/kikito/i18n.... in your project and make a more accessible plugin than ever before 🎉
github.com
030
vhyrro @vhyrro.neorg.org · 10/09/2025
if you're already on emacs then I personally wouldn't bother :)
110
vhyrro @vhyrro.neorg.org · 08/09/2025
I'll never stop yapping out the jujutsu VCS. It's such a good tool and has entirely replaced Git for me, tbh. Even for the most simple of operations I find jj to be much more ergonomic. You also get the op log for free! :D
021
vhyrro @vhyrro.neorg.org · 08/09/2025
I'd like to take a moment to appreciate FOSS. For all the craziness that goes on in communities every day the fact that we can all reap the benefits of freedom in both senses of the word is really remarkable. After using FOSS for several years I've really forgotten this simple fact.
010
vhyrro @vhyrro.neorg.org · 07/09/2025
I'm complaining that people should wait it out and let other developers write wrappers around vim.pack before starting to use it full-time. Let people integrate lazy-loading, auto-configuration and more. If they're going this far they might as well just use git clone/git pull while they're at it :p
100
vhyrro @vhyrro.neorg.org · 07/09/2025
Oh no, don't get me wrong, I don't think vim.pack should change. It's got a good minimal feature set as it is. But people have a tendency to flock to the latest thing and then complain that something's missing features, despite it being the core design of vim.pack
100
vhyrro @vhyrro.neorg.org · 07/09/2025
I get that wanting to make a minimal config is a tempting idea, I love myself some minimalism, but in the case of a git-based plugin manager you're only losing quality of life features without much in return. Hoping to see some cool wrapper plugins around vim.pack soon.
100
vhyrro @vhyrro.neorg.org · 07/09/2025
I personally find the #neovim 0.12 plugin manager to be severely overhyped. It's great to have a standard interface for more sophisticated wrappers to step in, but it's still very basic. Users will end up on a wrapper plugin anyway. The best thing vim.pack is good for is bootstrapping other code.
100
vhyrro @vhyrro.neorg.org · 07/09/2025
Github OAuth is amazing. In the oauth data, username is called "nickname", and the nickname is called "name". definitely did not cause any headaches :p
000
vhyrro @vhyrro.neorg.org · 06/09/2025
ask the neovim developers for keybind namespaces first :p
020
vhyrro @vhyrro.neorg.org · 06/09/2025
Starting work on native support in Lux for Luanox's API. It's so much more efficient than luarocks.org's, allowing you to do package search server-side, pull metadata about individual packages (instead of pulling a massive manifest file) and no weird stuttering or delays on the server. Excited!
luarocks.org
LuaRocks - The Lua package manager
A website for submitting and distributing Lua rocks
000
vhyrro @vhyrro.neorg.org · 06/09/2025
Give the luanox site a quick test run over on our beta: luanox-beta.neorg.org 🚀 🚀
luanox-beta.neorg.org
Luanox
A Lua module host for the Lux package manager, fully compatible with the rockspec format.
011
vhyrro @vhyrro.neorg.org · 05/09/2025
Hooked up all the logic to the page for API keys. I'll be releasing the page for beta testing to the public soon. It'll be a big test for the OAuth flow and key generation code :D
020
vhyrro @vhyrro.neorg.org · 05/09/2025
Alright, settings page is fully designed and ready to roll 🔥 This one will definitely need further touch-ups before the final release, but I'm happy with it as is for now :) Next up, the page that generates API keys 🚀
030
vhyrro @vhyrro.neorg.org · 02/09/2025
Huge win! Neovim now has a dedicated documentation page for plugin best practices 🎉 github.com/neovim/neovi...
github.com
docs: add guide for developing Lua plugins by mrcjkb · Pull Request #29073 · neovim/neovim
As requested by @justinmk in nvim-neorocks/nvim-best-practices#5 Using upstream to :help lua-guide nvim-neorocks/nvim-best-practices#5 (comment) as a guideline Reworded a to have a less "opin...
070
vhyrro @vhyrro.neorg.org · 01/09/2025
Alright, the MVP package page is ready 🚀 I'm already done with the backend endpoints, which are much more convenient to use over luarocks.org, and they sure as hell don't encode the API key in the URL itself ☠️ I guess the next natural step is to create a "legacy" API which is luarocks-compatible
030
vhyrro @vhyrro.neorg.org · 31/08/2025
Putting in my full effort into finishing Luanox so it can finally hit production. First off, I revamped the landing page! Things left: - Ask the user for email if OAuth didn't provide it - Search functionality - Package view page - Plenty of touchups and more API endpoints Exciting stuff ahead 🚀
051
vhyrro @vhyrro.neorg.org · 29/08/2025
Amidst all the projects I'm working on I decided to dedicate some time to Luanox - a more modern alternative to luarocks.org We've had quite a few run-ins with the site misbehaving (as well as being slow) and so we're working on a sister site that will work in tandem with the main luarocks site :)
luarocks.org
LuaRocks - The Lua package manager
A website for submitting and distributing Lua rocks
031