Gavin Anderegg

@gavinanderegg
345 Followers
501 Following
1.5K Posts
Freelance developer, data nerd, Apple fan, gaming geek, CMS critic. Halifax, Nova Scotia. He/him. 🏳️‍🌈
Websitehttps://anderegg.ca
GitHubhttps://github.com/gavinanderegg

NPM and other package repositories must learn from Linux distributions.

It is ridiculous that every week we are now reading about vulnerability that already ended up in the NPM package repository.

Linux distributions have mitigated this with for example having testing and stable branches. Packages stay few weeks at least in testing, before they go stable. This would have prevented many of the compromises alone.

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

#NPM #Linux #NodeJS

axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity

Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.

Liquid Glass updates in 26.4

Apple recently updated all their OSs to 26.4, and there were plenty of Liquid Glass updates. Most of them of the better! Here are some of the changes that stood out to me, as well as a bit more grumbling about Liquid Glass in general (sorry).

anderegg.ca
Liquid Glass updates in 26.4

Apple recently updated all their OSs to 26.4, and there were plenty of Liquid Glass updates. Most of them of the better! Here are some of the changes that stood out to me, as well as a bit more grumbling about Liquid Glass in general (sorry).

anderegg.ca

NVIDIA’s #DLSS5 is crazy yo!

#macOS #macOSTahoe

Gamers react with overwhelming disgust to DLSS 5's generative AI glow-ups
Nvidia's next frame-gen tech goes way beyond upscaling, and not in a good way
https://arstechnica.com/gaming/2026/03/gamers-react-with-overwhelming-disgust-to-dlss-5s-generative-ai-glow-ups/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
Happy π day eve, everyone!
Periodic reminder that the cloud is just some else’s (often shared, expensive, and slow to spin up) computer. The MacBook Neo does a surprisingly good job in this big data benchmark. https://duckdb.org/2026/03/11/big-data-on-the-cheapest-macbook
Big Data on the Cheapest MacBook

How does the latest entry-level MacBook perform on database workloads? We benchmarked it using ClickBench and TPC-DS SF300. We found that it could complete both workloads, sometimes with surprisingly good results.

DuckDB
To be clear, I don't have a leg to stand on here as my signature is a weird scribble. This just struck me as funny.
Nice letter from Jin Coole on Apple's 50th. https://www.apple.com/50-years-of-thinking-different/