🐍 Beware the mighty "Mini Shai-Hulud," devouring npm packages like a snack! 🍿 Apparently, "314" is the new "317," but who’s counting in the world of open-source chaos? đŸ€·â€â™‚ïž Just another day in the life of developers pretending they can control the uncontrollable. 🙃
https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/ #MiniShaiHulud #npmChaos #openSourceDev #packageManagement #developerLife #HackerNews #ngated
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security

I might have to explore C++ RAAI concept sooner or later for #GitRaven.

It is getting difficult manually free-ing memory used via libgit2. I am having to think about and write if checks for all the edge cases across my GitManager class.

ChatGPT suggested this after I mentioned this issue and it sounds like it's useful.

#diary #opensourcedev #cppdev

composer-unused 0.9.6 is out!

🚀 Adds official support for PHP 8.5 and Symfony 8
🔧 Improved symbol scanning with SymfonyConfigurationSet realpath
🧰 Dev dependency bumps & CI tweaks

https://github.com/composer-unused/composer-unused/releases/tag/0.9.6

#php #symfony #composer #phpcommunity #opensourcedev

In recent months my YouTube channel’s average likes vs dislikes improved by 10% — a sign the extra time and care are paying off. If you enjoy the content, please like & subscribe. Feedback is welcome, and if you’d like to support me, you can buy me a coffee — it really helps. Thank you!
#OpenSource #FreeSoftware #FOSS #FOSSCommunity #Libre #Productivity #ProductivityTips #OpenSourceDev #DevTools
https://buymeacoffee.com/seve
sevetech is moving to Substack

This marks my final coffee on Buy Me a Coffee. Sevetech is moving to Substack, where I’ll be publishing all new posts, deep‑dives, and updates. If you’ve enjoyed my work, please consider subscrib

Buy Me a Coffee

So, because I'm probably going to have to sort this out in the near future, what CI/CD setups do people use for open-source projects?

Hosted seems to be the thing these days; what do people use?

#OSS #OpenSource #OSSDev #OpenSourceDev

Wir haben gerade den bisher grĂ¶ĂŸten branch von #FOSSWarn gemergt. Ganze 2327 eingefĂŒgt Zeilen und 2786 gelöschte Zeilen Code. Seit Februar haben wir daran gearbeitet, den Code von FOSSWarn aufzurĂ€umen, jetzt ist es endlich gemergt. 😅 Jetzt mit einer etwas besseren Datenstruktur. Das war ganz schön viel Arbeit, aber optisch sieht man einfach keinen Unterschied zu vorher. Naja, jetzt können wir uns bald aber auch wieder anderen Problemen widmen. #opensourcedev

This month we have iconography updates, symbols-view improvements, CI upgrades and bunch of upgrades to our package backend and website.

Check out the latest community update on the Pulsar Blog!
https://pulsar-edit.dev/blog/20230501-Daeraxa-MayUpdate.html

#opensource #opensourcedev #CommunityDevelopment #CI #packagedevelopment #communitypackages #website #pulsar #pulsaredit

Community Update |

A Community-led Hyper-Hackable Text Editor

Check out the first in what we hope will be our regular updates on the Pulsar Blog!
This will hopefully give you some insight as to what we have been up to in the background and what you can expect expect to see in the near future.
In this update we have info on tree-sitter upgrades, a new donation platform, backend improvements and an upcoming Matrix space.

https://pulsar-edit.dev/blog/20230201-Daeraxa-FebUpdate.html

#opensource #opensourcedev #backend #matrix #pulsar #pulsaredit #community #treesitter

Community Update |

A Community-led Hyper-Hackable Text Editor

@bonoky @lgeurts Hopefully soon this won't be required but that's next beta(I think, don't quote me on this). It's something weird about trying to get things updated and patched, from what I recall, and I know we've been fighting the build tools a bit as well. Hopefully soon we're in package managers in some way sooner or later, esp flatpak/snap. Though we could use all the help getting to that point we can get.

- @kaosine

#opensource #pulsar #pulsaredit #pulsar-edit #opensourcedev #discord

Mit dem nĂ€chsten Update von #FOSSWarn, muss man seine Orte neu hinzufĂŒgen, weil sich ein paar grundlegende Dinge geĂ€ndert haben. Wie sage ich das den Nutzern am besten? đŸ€”

#opensourcedev