1004: TanHacked
Scott and Wes break down the “Mini Shai-Hulud” supply chain attack that compromised TanStack and other popular npm packages through a clever GitHub Actions cache poisoning exploit; a self-propagating worm that stole credentials and persisted through Claude Code hooks and VS Code tasks. They also cover how developers can protect themselves using pnpm’s security defaults, dev containers, and other practical defenses. Show Notes 00:00 Welcome to Syntax! 00:25 Understanding the Shai-Hulud Worm Post Mortem of Shai Hulud Attack 02:47 Mechanics of the Attack: GitHub Actions and Cache How the attack happened Who Was Involved in the Attack Several npm latest releases are compromised Socket.dev Step Security 05:44 Brought to you by Sentry.io 06:09 Propagation and Impact of the Worm 09:30 Preventative Measures for Developers Dead Man’s Switch 12:33 The Role of Package Managers in Security Block Exotic Subdeps 18:39 Using Dev Containers Why You Should Use Dev Containers Scott Tolinski’s Security Review 20:57 Conclusion and Final Thoughts Sentry has Skills! Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott: X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(1032)

1032: Stripe Buys OpenRouter for $7B

1032: Stripe Buys OpenRouter for $7B

Scott and CJ break down Stripe's $7B acquisition of OpenRouter, the SvelteKit 3 release candidate, and their first look at TanStack Charts. Plus Zed's new Delta editor, stealing reasoning traces from ...

24 Aug 1h 7min

1031: My Coding Skills Are Atrophying

1031: My Coding Skills Are Atrophying

Scott and Wes answer your questions about coding in the AI era, atrophying skills from too much autocomplete, whether it’s finally time to leave VS Code, chasing flow state with agents, and which sing...

19 Aug 57min

1030: AI Assistant Hacks Gym

1030: AI Assistant Hacks Gym

An AI assistant goes rogue and hacks a gym website, a $9k surprise Cloudflare bill lands in someone’s inbox, and AI subscriptions start promising unlimited usage. Plus Meta’s Muse Glimmer, Agent Plugi...

17 Aug 1h 24min

1029: The Workflow of the Future With Zed

1029: The Workflow of the Future With Zed

Nathan Sobo joins Scott and Wes to explain why Zed was built in Rust, how GPUI works, and what happens to editors once agents write most of the code. They also talk about DeltaDB, Zed’s new Git-compat...

12 Aug 59min

1028: Cloudflare Wallets

1028: Cloudflare Wallets

Cloudflare is rolling out crypto wallets with claimable handles as identity, and a real React compiler finally landed for regular hooks-based code. Plus: OpenAI's pricing war, Vue Vapor benchmarks, Gi...

10 Aug 1h 18min

1027: The Rise of the Design Engineer

1027: The Rise of the Design Engineer

Scott and Wes tackle your questions on the rise of the design engineer, why AI still lacks “taste” (and why it’s about more than just looks), and how to actually write tests in the age of AI-assisted ...

5 Aug 1h 3min

1026: OpenAI Agent Hacks Hugging Face

1026: OpenAI Agent Hacks Hugging Face

A rogue OpenAI agent allegedly hacks Hugging Face, the React Compiler lands in Rust, and a fresh Rust full-stack framework ships. Scott, Wes, and CJ also dig into Anthropic’s $1.5B copyright settlemen...

3 Aug 1h 36min

1025: The Open Web's second chance (w/ Dan Abramov)

1025: The Open Web's second chance (w/ Dan Abramov)

Dan Abramov joins Scott and Wes to explain AT Protocol, the open standard quietly rebuilding the social web. They get into how it actually works, why it’s way bigger than just Bluesky, and why Dan cal...

29 Juli 1h

Populärt inom Politik & nyheter

aftonbladet-krim
p3-krim
aftonbladet-daily
rss-expressen-dok
flashback-forever
svenska-fall
rss-vad-fan-hande
rss-krimreportrarna
rss-sanning-konsekvens
motiv
rss-krimstad
svd-ledarredaktionen
spar
rss-frandfors-horna
politiken
rss-flodet
krimmagasinet
fordomspodden
grans
rss-aftonbladet-krim