color npm package compromised
On September 8 2025, around 13:00 UTC, someone compromised Josh Junon’s npm account (qix) and started publishing backdoored versions of his package. Someone noticed and let Josh know: Josh confirme...fasterthanli.me
On September 8 2025, around 13:00 UTC, someone compromised Josh Junon’s npm account (qix) and started publishing backdoored versions of his package. Someone noticed and let Josh know: Josh confirme...fasterthanli.me
I have been pushing for #Inkscape to remove/decommission it's Twitter account. But I didn't want to do it unilaterally, bossing people about, but through reasoned policy that can be applied to other captured banana-pants social media platforms.
So I've drafted a policy, which I'm interested in having more people look at as it's going to be one of those gnarly things that's important to get right:
lists.inkscape.org/hyperkitty/…
What do you think? Worth while approach for a #foss project?
Until now, if you lost or broke your phone, your Signal message history was gone, a real challenge for everyone whose most important conversations happen in Signal. So, with careful design & development, we’re rolling out opt-in secure backups.
Secure backups will let you save an archive of your Signal messages remotely in privacy-preserving form, refreshed daily.
Now available in the latest Android beta release, rolling out to iOS & Desktop soon
signal.org/blog/introducing-se…
In the past, if you broke or lost your phone, your Signal message history was gone. This has been a challenge for people whose most important conversations happen on Signal.Signal Messenger
would that our local police were as committed to arresting asshole pickup truck drivers as the Prince George RCMP was to arresting this guy driving a toy Barbie jeep
New Privacy Guides article :2001: ⛔
by me:
Chat Control is one of the
most terrifying proposal for dystopian authoritarianism the Western world has seen in years.
We need your help to fight it ✊🇪🇺
For democracy,
For privacy,
And for all other human rights,
We cannot afford to lose this battle.
📩 If you are European (EU):
Contact your MEPs and local media this week to tell them to oppose Chat Control (more information in the linked article).
🗣️ If you are outside of the EU:
Spread the word! Tell your friends and family in the EU about it! Make noise on social media! This will affect you too.
privacyguides.org/articles/202…
#PrivacyGuides #ChatControl #StopScanningMe #Privacy #HumanRights #Democracy #EUpol
Chat Control is back to undermine everyone's privacy. There's an important deadline this Friday on September 12th. We must act now to stop it!Privacy Guides
reshared this
Strasbourg, Blick von der Kathedrale Notre Dame
#Strasbourg #France #photographie #photography #urban_photography #architecture #europe
To me, the worst part of what is being called the "largest supply chain attack in history" is the fact that there are over "2.6 billion weekly downloads of those NPM packages"
What the actual fuck?! [says a guy who used to curate SQL queries because the results took too long to deliver over 9600bd]
I maintain the Debian package/repo for Helm here https://helm.sh/docs/intro/install/#from-apt-debianubuntu . The bandwidth has gotten to be enough that it's no longer feasible to host it myself (~7...mattfox (GitHub)
Sensitive content
A Cli package for the public Radio browser API, built to be lightweight , accessible and easy to use from the ground up. - GitHub - tgeczy/radio-browser-whiptail-cli: A Cli package for the public ...GitHub
France’s parliament voted to topple the government of Prime Minister François Bayrou on Monday after the PM surprised even his own allies by calling a confidence vote to resolve a months-long deadlock over his austerity budget.FRANCE 24
Love LibreOffice development? Want to turn your passion into a paid job? We are The Document Foundation (TDF), the non-profit entity behind LibreOffice.Open Source JobHub
Just became aware of this from @thecarpentries — they had to say no to a huge grant from the US government because of their commitment to diversifying the software industry. I donated and hope you’ll think about it too.
carpentries.org/blog/2025/06/a…
In September 2024, The Carpentries submitted a proposal to the U.S. National Science Foundation (NSF) Pathways to Enable Open-Source Ecosystems (POSE) Program.The Carpentries
Ice Cube is still dropping incredibly catchy tracks. No idea how I missed this last year
youtube.com/watch?v=vvvQwYXPV-…
Don’t miss the first track from Ice Cube’s upcoming album Man Down! "It's My Ego" brings the heat with bold lyrics and hard-hitting visuals, setting the stag...YouTube
though this version with Killer Mike and Busta Rhymes is better because Killer Mike is so good, but Ice Cube has better verses on the original
youtube.com/watch?v=ADvIfLH2qs…
Subscribe to CUBEVISION to get everything the Ice Cube lifestyle has to offer. Stay tuned for new videos and exclusive content coming soon.Official Ice Cube...YouTube
Canada's National Observor: Whistleblower exposes how AI fuels Big Oil growth
nationalobserver.com/2025/09/0…
#AI #climateemergency #microsoft
"We realized we were basically working for an oil company," said Holly Alpine, a former Microsoft employee who quit her dream job on the company's sustainability team when she realized the company, like most tech companies, is helping fossil fuel com…Canada's National Observer
@vincentgrahamwildlife shared the text and video below
I found a new newborn Hedgehog and then
#babyanimals #animals #hibernators #funnyvideos
Sarah Michelle Gellar posts masked selfie on set of Buffy
thecanary.co/global/world-anal…
'I will wear a mask in my shower if that means I don't get this again' said Sarah Michelle Gellar after recovering from COVID-19Christopher McDonald (The Canary)
A short tl;dr is that Hollywood and adjacent industry (music) still have strong COVID protocols in effect, but none speak publicly because the fascist have made COVID protection perceived as something bad.
Maybe Hollywood should show the power they have and actually make this a thing. Show the example.
Imagine the lives that could be changed with this much money? If they spent just a fraction of that on education of women and girls, it would have an impact many times greater.
Imagine how much renewable energy could be installed?
Even simple things like providing concrete floors to those whose homes have a dirt floor would have a massive impact.
Instead, it'll trash the environment, waste water, and make people's lives worse.
Fucking criminal.
mastodon.cloud/@slashdot/11516…
OpenAI Says Its Business Will Burn $115 Billion Through 2029 https://news.slashdot.org/story/25/09/08/1426211/openai-says-its-business-will-burn-115-billion-through-2029?utm_source=rss1.0mainlinkanonmastodon.cloud
This isn't my sub-field of astronomy, but someone needs to give this conference 1000 internet bonus points for the best, most geographically relevant acronym, plus their logo is ADORABLE
uwaterloo.ca/astrophysics-cent…
GEESE-ON: Galaxy Evolution and Environment in Southern and Eastern Ontario
An upcoming workshop for Ontario-based astronomers to discuss ongoing and future research in galaxy evolution, hosted by the Waterloo Centre for Astrophysics.uwaterloo.ca
I'm writing this post here today in hopes to bring some attention to something that is near and dear to my heart, and that's an update to the current situation with Nova Launcher, that I worked for and with for nine years up until August of 2024.
For those that haven't seen the news, Kevin Barry, the founder and developer of Nova has left Branch which in turn means he's now no longer involved with Nova Launcher in any way going forward.
teslacoilapps.com/nova/solong.…
For the past year or so Kevin has stated that he was working on the open source version of Nova Launcher so that if/when this time came, it would be out in the open and the community could take it over and contribute to it and have it continue being developed.
However, it seems that Harish Thimmappa and others at Branch had told him to stop working on that effort as they didn't want him to continue doing that for unknown reasons. This is sad news because this was something that former CEO, Alex Austin, had promised both via a contract and publicly that if Kevin were to ever leave Branch, Nova Launcher would become open source. You can find that quote here:
reddit.com/r/Android/comments/…
and another very similar quote with similar conversation here:
reddit.com/r/Android/comments/…
The reason for this post is to try and draw some attention to the folks at Branch, specifically folks like Harish Thimmappa to do the right thing and honor these promises and any writings in the contracts from 2022 and to fully focus on releasing Nova Launcher as an open source app.
The community deserves this more than anything, since that was something that Kevin was very adamant about when he allowed Branch to acquire Nova Launcher back in 2022. Plus, this is just something that Branch should do since it is something that has been promised.
There is currently a petition on Change.org to try and get Branch to do this as well. After only 3 days of it being posted to Change.org, it sits at almost 1,500 signatures, and that's with very little to no press coverage at this time, which is something that would be super useful to bring full attention to this situation. You can find the petition here:
change.org/p/make-nova-launche…
I ask that everyone who sees this post can share it with their followers as I would love to see Branch do the right thing and follow through with their promises that were made back in 2022 when they acquired Nova Launcher and release it fully as an open source app now that Kevin is no longer working for Branch and not involved in Nova Launcher.
I'm going to tag some folks below that I worked with at Branch in hopes of getting this post seen by as many folks there as possible.
#NovaLauncher #Nova #Branch #BranchMetrics #OpenSource #OpenSourceNova #Petition #Android #Apps #Google
Meta hires far-right influencer to help end 'Woke AI'
mashable.com/article/meta-ai-h…
Starbuck has built his reputation by going after companies and individuals embracing inclusivity.Chase DiBenedetto (Mashable)
Kyberpunková swingers party přináší čtyři delší povídky a v nich očekávatelný děj, jaký si kterýkoli čtenář série s doktorem Koskem nejspíš umí dobře představit.marek (Audiolibrix s.r.o.)
JEWS, PLEASE READ THIS
NON-JEWS, PLEASE READ THIS!
Harvard experts warn Diaspora Jews are suffering from ‘traumatic invalidation’ after Oct. 7
"They call it traumatic invalidation, a condition first studied a decade ago for victims of other traumas such as sexual assault who are told it's their fault or they should get over it. For Jews, the same label should apply, the authors found, because it involves what they describe as a stunning mix of silence, denial, blame, gaslighting, whataboutism, and exclusion, such as documenting many cases of Jews being told their grief does not matter because of what's happening in Gaza"
youtube.com/watch?v=JX4dFaIEEw…
Transcript here:
thecjn.ca/news/harvard-experts…
#Podcast #Antisemitism #MentalHealth #Jews #Abuse
The two therapists' worrying study was published in an academic publication in May 2025.North Star (The Canadian Jewish News)
Ik zat vanochtend net een halve poging te doen om dochterlief naar Linux te helpen. Haar leptop is stuk dus dit is een mooi moment voor verandering.
Maar eigenlijk weet ik niks van Linux. Net zo min als de dochter heb ik veel zin in systeembeheren.
Ik zou wel tips willen welke tweedehands laptop geschikt zou zijn voor een verse Linux-installatie waar een eh, normaal mens ook mee kan werken.
Ik draai al jaren Ubuntu op mijn desktop, en mijn ervaring is dat de hoeveelheid systeembeheren ongeveer net zo veel is als bij Windows. Met als voordeel bij Ubuntu dat iemand het al voor je heeft uitgezocht en je een paar commando's in de commandline plakt die het in orde maken.
Grootste issue zal de software zijn -- als je Windows-only programma's gebruikt dan is het wel echt pielen geblazen. Maar Firefox (en dus ook alles wat via een browser kan) gaat prima.
A new version of MapComplete is out on mapcomplete.org
It has:
- a brand new theme was created by @RLin about infrastructure. If you like power lines, pipelines, street cabinets, then this map will be for you: mapcomplete.org/infrastructure
- More support for offline use (and even more is in the pipeline)
- various bugfixes
MapComplete is a platform to visualize OpenStreetMap on a specific topic and to easily contribute data back to it.mapcomplete.org
1 October @oscl examines open source and data as the foundation for Digital Sovereignty. A great opportunity to engage with the open source community in Luxembourg!
Register here: conference.opensource.lu/
View the agenda here: conference.opensource.lu/agend…
Watch the official music video for Boulevard Of Broken Dreams by Green Day from the album American Idiot.🔔 Subscribe to the channel: https://www.youtube.com...YouTube
amos
in reply to amos • • •amos
in reply to amos • • •try {
args = JSON.parse(JSON.stringify(argsIn));
} catch (e) {
args = [...argsIn];
}
Ah see? I'm not the only one who didn't know about structuredClone
amos
in reply to amos • • •Here's the NPM supply chain attack payload deobfuscated & cleaned up by hand as best I could: github.com/fasterthanlime/0x11…
...I'm not sure it would ever work in its current form, tbh
GitHub - fasterthanlime/0x112: De-obfuscated payload from the September 8 2025 npm supply chain attack
GitHub