🧵 …gut gibt es bezüglich axios positive Nachrichten. Es ist nun anscheinend nicht mehr in der aktueller Version gehackt:

«Fake-Teams-Update — So haben Angreifer den axios-Maintainer ausgetrickst:
Der axios-Maintainer beschreibt, wie Cyberkriminelle den HTTP-Client mit Schadcode verseuchen konnten. Derweil gibt es ähnliche Attacken auf weitere Maintainer.»

💥 https://www.heise.de/news/Fake-Teams-Update-So-haben-Angreifer-den-axios-Maintainer-ausgetrickst-11246273.html

#javascript #axios #webdev #faketeam #http #httpclient #npm #web #dev #js #malware #jslibary #maintainer

Fake-Teams-Update: So haben Angreifer den axios-Maintainer ausgetrickst

Der axios-Maintainer beschreibt, wie Cyberkriminelle den HTTP-Client mit Schadcode verseuchen konnten. Derweil gibt es ähnliche Attacken auf weitere Maintainer.

heise online

May is #maintainermonth

https://maintainermonth.github.com/

A month for open source maintainers to gather, share, and be celebrated.

Are you a maintainer? You can submit your idea!

#maintainer #foss #event #community

Maintainer Month 2026

A month for open source maintainers to gather, share, and be celebrated.

Nothing against #French people, but literally the only people that reach out to me in a foreign #language (besides English and German as it's obvious I'm located in Germany) are French.

If you open an #issue, you want sth from me, so make sure I understand it.

Do you think it's harsh to ignore these issues or ask for an English translation?

#opensource #github #maintainer #development

@mrmasterkeyboard @xinit if you refuse to acknowledge #ahitposters and their hate as legitimate but just respond calmly (if at all) you'll make their blood boil, heads implode and frustrate them the most.

  • Besides the "optics" of being a level-headed #maintainer who doesn't waste time trying to argue against those that already made up their minds is just professional.

I genuinely want evi to succeed, because this is an important stance to take:

  • If we allow the #Enshittification of fundamental tools in #tech we'll run the risk of being unable to maintain even the core functionality of ibfrastructure and systems.
    • Because the longterm ramifications of using #vommits of #AIslop / #SlopCode are not just unknown, but already happening incidents based around "#AI" / "#VibeCoding" show that this is at best extremely fragile

In fact, I want simple and auditable systems - espechally in critical infrastructure - and it needs to be reproduceable and maintainable.

  • With human-written code one usually gets comments or can reason things out easily.
    • Worst-case even ask the original author "Why did you do that?" because an "AI" cannot take or face #Accountability or #Consequences per design!

#EVi

#OpenSourceEconomy allows a #maintainer of #opensource software to market their services to #companies which depend on #software or could benefit from #coaching.

https://www.open-source-economy.com/

#funding

Open Source Economy

I really liked this notice that the @biomejs maintainers put in one of their discussions on GitHub. Hopefully folks read it, sadly I suspect the abusers won't

#OpenSource #Maintainer #Sustainability

Respecting maintainer time should be in security policies

Generative AI tools becoming more common means that vulnerability reports these days are loooong. If you're an open source maintainer, you unfortunately know what I'm talking about. Markdown-format...

sethmlarson.dev
Autonomer KI-Agent startet Diffamierung gegen Matplotlib-Maintainer

Ein abgelehnter Pull Request endet in einer persönlichen Attacke auf einen Maintainer. Risiken autonomer KI werden sichtbar.

TARNKAPPE.INFO
An #AIagent autonomously wrote and published a #personalizedattack article about a Matplotlib #maintainer after he #rejected its #codecontribution. The agent researched the developer's background and constructed a 'hypocrisy' narrative, marking a new frontier in AI safety risks. https://the-decoder.com/an-ai-agent-got-its-code-rejected-so-it-wrote-a-hit-piece-about-the-developer/?eicker.news #tech #media #news
An AI agent got its code rejected so it wrote a hit piece about the developer

After a volunteer developer rejected its code, an autonomous AI agent independently researched his background and published a hit piece attacking his character. The incident at Matplotlib shows how theoretical AI safety risks are becoming real.

The Decoder
Debian überarbeitet seine Infrastruktur

Die Debian-Infrastruktur ist in die Jahre gekommen und bedarf an einigen Stellen der Erneuerung. Die Auflösung de FTP-Masters-Delegation in zwei effektivere…

LinuxNews.de