vhyrro @vhyrro.neorg.org · 27/09/2026vhyrro.neorg.org/posts/critic... It's live :)vhyrro.neorg.orgConquering the Moon (luarocks.org remote code execution exploit) | Vhyrro's Digital GardenHow I found an incredibly dangerous vulnerability in Lua's infrastructure. 041
vhyrro @vhyrro.neorg.org · 27/09/2026During my work on Lux, I noticed an oddity in luarocks and launched a month-long investigation. luarocks.org had a critical RCE allowing anyone to gain root access to the site with a package upload. I will launch a blog post describing how the exploit works soon. luarocks.org/security-inc...luarocks.orgLuaRocks - The Lua package managerA website for submitting and distributing Lua rocks 131
vhyrro @vhyrro.neorg.org · 13/07/2026Tired of CLI tools having difficult to understand errors? Me too! That's why Lux is getting a huge overhaul of its error system to make it as friendly as possible. System is a work in progress - by the end I want any newbie to be able to try the CLI and immediately be guided towards best practices. 020
vhyrro @vhyrro.neorg.org · 12/07/2026If I had to teach the accumulated best practices of AI to a person from 2019 this is how I'd do it: vhyrro.neorg.org/posts/a-hitc...vhyrro.neorg.orgA Hitchhiker's Guide to AI | Vhyrro's Digital GardenHow not to make total slop :) 0101
Reposted by vhyrroMarc @mrcjkb.bsky.social · 08/07/2026Progress update on Lux: You can now distribute your Lua projects as archives or standalone binaries. mrcjkb.dev/posts/2026-0...mrcjkb.devmrcjkb.dev - lx dist - distribute your Lua projects as archives or standalone binaries 021
vhyrro @vhyrro.neorg.org · 02/07/2026Huge updates for Lux! The recently implemented 2FA will prevent a class of API key hijacking attacks present throughout programming today. vhyrro.neorg.org/posts/rocks-...vhyrro.neorg.orgLux v0.34.2 | Vhyrro's Digital GardenTwo Factor Authentication is here! 022
vhyrro @vhyrro.neorg.org · 02/07/2026This was one fun side project to devise and create, opinions welcome! vhyrro.neorg.org/posts/calend...vhyrro.neorg.orgOur Calendar Sucks | Vhyrro's Digital GardenIt's the 20th March, 4:02.09.1 CET. Wait, that doesn't sound right. 000
vhyrro @vhyrro.neorg.org · 25/06/2026I'm about to finalize sensible rate limiting for Luanox APIs to prevent spam or excessive server load. There are many great features coming up, including 2FA for tokens and full backwards compatibility with the luarocks.org APIs 🚀🚀luarocks.orgLuaRocks - The Lua package managerA website for submitting and distributing Lua rocks 010
vhyrro @vhyrro.neorg.org · 25/06/2026the Lux Lua bridge wiil soon get support for full type annotation generation. You'll soon be able to get hints from the lua language server when interacting with the Lux API :) github.com/lumen-oss/lu... 020
vhyrro @vhyrro.neorg.org · 29/03/2026Shoutout to the Neovim devs for 0.12.0, it's all good steps towards making the editor even better for beginner users and for me who can now run :restart 500 times a day 020
vhyrro @vhyrro.neorg.org · 29/03/2026now THIS is a rant I can get behind I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN I HATE MARKDOWN 010
vhyrro @vhyrro.neorg.org · 25/03/2026Moved my bsky account from bsky.social to vhyrro.neorg.org, it's nice that all you need is a DNS entry! I love it. 070
vhyrro @vhyrro.neorg.org · 24/03/2026My Rust bindings for the fantastic Janet language are the first repo of mine to be hosted on tangled.org! tangled.org/vhyrro.neorg... 030
vhyrro @vhyrro.neorg.org · 12/03/2026Lux now prevents privilege escalation and malicious Lua scripts from doing any damage to your host system. After thousands of changes and hours of debugging, say hello to sandboxing! 🚀🔥 opencollective.com/lumen-labs/u...opencollective.com🚀 Lua Sandboxing - Lumen LabsI have spent the last two weeks working on integrating https://github.com/kyren/piccolo into Lux as our VM for executing untrusted Lua scripts. Today that PR was merged! 🎉🎉 With constant atta... 051
vhyrro @vhyrro.neorg.org · 06/03/2026I've finally done it. The sandboxing refactor for Lux is done, after a lot of long winded planning and rewiring the codebase. Now for the tedious cleanup phase 🔥 050
vhyrro @vhyrro.neorg.org · 21/02/2026The sandboxing refactor for Lux is much larger than I had anticipated! The PR will be large but the upside is that packaging the project will become much easier as we will be able to ditch mlua as a dependency 🔥🔥 040
vhyrro @vhyrro.neorg.org · 15/02/2026Additionally, Luanox support in Lux will further enhance security by using a service with stronger API keys and no manifest files. Ideally, we will one day incrementally upgrade to TOML rockspecs instead of dynamic Lua files (which bring nothing useful other than security issues). 020
vhyrro @vhyrro.neorg.org · 15/02/2026If all goes well, Lux will be hardened against an attack like this by limiting execution time and restricting access to I/O and the capacity to load dynamic libraries at runtime. 110
vhyrro @vhyrro.neorg.org · 15/02/2026I am currently making a serious attempt at implementing sandboxing in Lux. Due to the way the ecosystem is structured, rockspecs (instructions on how to build a Lua project) are themselves Lua files. This means that they can run unbounded and arbitrary code. 110
vhyrro @vhyrro.neorg.org · 09/01/2026Video about Lazy Loading should be ready by the end of today 🔥🔥 020
vhyrro @vhyrro.neorg.org · 05/01/2026youtu.be/vZtL_Er4QpQ?... Here it is! Latest Neovim video 🔥youtu.beUnderstanding Neovim #11 - KeybindsYouTube video by Vhyrro 072
vhyrro @vhyrro.neorg.org · 04/01/2026There may or may not be a new YouTube video coming out very soon 👀 010
vhyrro @vhyrro.neorg.org · 31/12/2025github.com/neovim/neovi... Dont mind me eagerly checking this PR daily hoping for some progress. The Neovim terminal could really do with some QoL for end users :)github.comreplace libvterm with libghostty / libvaxis / ghostty-vt · Issue #33155 · neovim/neovimProblem libvterm is missing some features and moving too slowly. Expected behavior Evaluate if libghostty or libvaxis can replace libvterm. full support (including scrollback) for reflow. #30117 li... 021
vhyrro @vhyrro.neorg.org · 20/12/2025Elixir's tooling is severely underrated for just how good it is 🙏 010
Reposted by vhyrroZach Daniel @zachdaniel.dev · 25/09/2025www.postgresql.org/about/news/p... PostgreSQL 18 is hype.postgresql.orgPostgreSQL 18 Released!The [PostgreSQL Global Development Group](https://www.postgresql.org) today announced the release of [PostgreSQL 18](https://www.postgresql.org/docs/18/release-18.html), the latest version of the worl... 1155
vhyrro @vhyrro.neorg.org · 15/09/2025Thanks to generous donations from our OpenCollective supporters we've now moved Luanox to a dedicated domain (beta.luanox.org)! For reasons to support us be sure to check out beta.luanox.org/donate :Dbeta.luanox.orgLuanoxDiscover the most popular and well-maintained packages in our ecosystem 020
Reposted by vhyrroRust Language @rust-lang.org · 12/09/2025We received reports of a phishing campaign targeting crates.io users. Do not click on links asking to authenticate to protect your account. More information: blog.rust-lang.org/2025/09/12/c...blog.rust-lang.orgcrates.io phishing campaign | Rust BlogEmpowering everyone to build reliable and efficient software. 011256
Reposted by vhyrroNTBBloodbath @amartin.beer · 10/09/2025Designing for mobile-first in frontend development is fun... Until you come across mobile devices that for some reason have a viewport width less than 365 pixels. In some cases, they completely break CSS and you have to deal with edge cases. Why don't companies make phones with a viewport standard? 131
vhyrro @vhyrro.neorg.org · 10/09/2025With the growth of luarocks maybe we should start advocating for internationalization in larger Neovim plugins? I think it'd be quite amazing. You could throw a lua lib like github.com/kikito/i18n.... in your project and make a more accessible plugin than ever before 🎉github.com 030
vhyrro @vhyrro.neorg.org · 10/09/2025if you're already on emacs then I personally wouldn't bother :) 110
vhyrro @vhyrro.neorg.org · 08/09/2025I'll never stop yapping out the jujutsu VCS. It's such a good tool and has entirely replaced Git for me, tbh. Even for the most simple of operations I find jj to be much more ergonomic. You also get the op log for free! :D 021
vhyrro @vhyrro.neorg.org · 08/09/2025I'd like to take a moment to appreciate FOSS. For all the craziness that goes on in communities every day the fact that we can all reap the benefits of freedom in both senses of the word is really remarkable. After using FOSS for several years I've really forgotten this simple fact. 010
vhyrro @vhyrro.neorg.org · 07/09/2025I'm complaining that people should wait it out and let other developers write wrappers around vim.pack before starting to use it full-time. Let people integrate lazy-loading, auto-configuration and more. If they're going this far they might as well just use git clone/git pull while they're at it :p 100
vhyrro @vhyrro.neorg.org · 07/09/2025Oh no, don't get me wrong, I don't think vim.pack should change. It's got a good minimal feature set as it is. But people have a tendency to flock to the latest thing and then complain that something's missing features, despite it being the core design of vim.pack 100
vhyrro @vhyrro.neorg.org · 07/09/2025I get that wanting to make a minimal config is a tempting idea, I love myself some minimalism, but in the case of a git-based plugin manager you're only losing quality of life features without much in return. Hoping to see some cool wrapper plugins around vim.pack soon. 100
vhyrro @vhyrro.neorg.org · 07/09/2025I personally find the #neovim 0.12 plugin manager to be severely overhyped. It's great to have a standard interface for more sophisticated wrappers to step in, but it's still very basic. Users will end up on a wrapper plugin anyway. The best thing vim.pack is good for is bootstrapping other code. 100
vhyrro @vhyrro.neorg.org · 07/09/2025Github OAuth is amazing. In the oauth data, username is called "nickname", and the nickname is called "name". definitely did not cause any headaches :p 000
vhyrro @vhyrro.neorg.org · 06/09/2025Starting work on native support in Lux for Luanox's API. It's so much more efficient than luarocks.org's, allowing you to do package search server-side, pull metadata about individual packages (instead of pulling a massive manifest file) and no weird stuttering or delays on the server. Excited!luarocks.orgLuaRocks - The Lua package managerA website for submitting and distributing Lua rocks 000
vhyrro @vhyrro.neorg.org · 06/09/2025Give the luanox site a quick test run over on our beta: luanox-beta.neorg.org 🚀 🚀luanox-beta.neorg.orgLuanoxA Lua module host for the Lux package manager, fully compatible with the rockspec format. 011
vhyrro @vhyrro.neorg.org · 05/09/2025Hooked up all the logic to the page for API keys. I'll be releasing the page for beta testing to the public soon. It'll be a big test for the OAuth flow and key generation code :D 020
vhyrro @vhyrro.neorg.org · 05/09/2025Alright, settings page is fully designed and ready to roll 🔥 This one will definitely need further touch-ups before the final release, but I'm happy with it as is for now :) Next up, the page that generates API keys 🚀 030
vhyrro @vhyrro.neorg.org · 02/09/2025Huge win! Neovim now has a dedicated documentation page for plugin best practices 🎉 github.com/neovim/neovi...github.comdocs: add guide for developing Lua plugins by mrcjkb · Pull Request #29073 · neovim/neovimAs requested by @justinmk in nvim-neorocks/nvim-best-practices#5 Using upstream to :help lua-guide nvim-neorocks/nvim-best-practices#5 (comment) as a guideline Reworded a to have a less "opin... 070
vhyrro @vhyrro.neorg.org · 01/09/2025Alright, the MVP package page is ready 🚀 I'm already done with the backend endpoints, which are much more convenient to use over luarocks.org, and they sure as hell don't encode the API key in the URL itself ☠️ I guess the next natural step is to create a "legacy" API which is luarocks-compatible 030
vhyrro @vhyrro.neorg.org · 31/08/2025Putting in my full effort into finishing Luanox so it can finally hit production. First off, I revamped the landing page! Things left: - Ask the user for email if OAuth didn't provide it - Search functionality - Package view page - Plenty of touchups and more API endpoints Exciting stuff ahead 🚀 051
vhyrro @vhyrro.neorg.org · 29/08/2025Amidst all the projects I'm working on I decided to dedicate some time to Luanox - a more modern alternative to luarocks.org We've had quite a few run-ins with the site misbehaving (as well as being slow) and so we're working on a sister site that will work in tandem with the main luarocks site :)luarocks.orgLuaRocks - The Lua package managerA website for submitting and distributing Lua rocks 031