hey if anyone is spinning up an alternative npm registry let me know because this is a major PITA
I trust my own machines, but npm thinks otherwise and requires that I publish through GitHub CI, a service I don't trust
i have a knack for guessing when bluesky does stable releases, probably
not even anything notable, I'm really surprised it hadn't gotten caught much earlier. like sure RSC doesn't have Facebook's oversight (some of the React team members wouldn't have moved to Vercel otherwise) but come on man why aren't there more people scrutinizing the wire format
10.0 CVE on React and it's literally just object prototype pollution that can be used for RCE, what are we doing man
guy yells at cloud(flare)
genuinely thought my isp was down for a sec
i got atcute.dev i just have to figure out what to put on there
kinda overwhelmed trying to set up GoToSocial idk why