Viewing profile — jonchurch_
jonchurch_
HN member- Joined
- Wed, Sep 26, 2018, 2:29 PM UTC
- HN karma
- 657
- Public activity
- 98 items
- HN profile
- View on Hacker News ↗
About jonchurch_
maintaing express, lodash, cors, body-parser, etc etc
Recent public activity
-
comment
Comment #49171612
npm v12 released last month also defaults into blocking them by default
-
comment
Comment #49145611
Im curious OP, what was the specific callsite (not overall category) that made you write this library? What did the code look like before/after you used this library? And in that c…
-
comment
Comment #48900496
Came to say this, ICANN says: “This status code is set by your domain's Registry Operator. Your domain is not activated in the DNS.” Also the serverDeleteProhibited status is activ…
-
comment
Comment #48530280
Edit: I didnt even notice until someone pointed out this was on the Nex-n2 repo not the rio one, now I understand the OP’s confusion! It wasnt framed as an issue which is the norm …
-
comment
Comment #48497456
(2021)
-
comment
Comment #48215671
I am so incredibly stoked to see this! It is the piece which can FINALLY make it so Trusted Publishing can be safely used. This releases a lot of pressure on maintainers, who until…
- story
-
comment
Comment #48102883
The compromised action here was using pnpm. They poisoned the github action cache, which was caching the pnpm store. The chain required pull_request_target on the job to check bund…
-
comment
Comment #48102687
Not to beat the dead horse, but ths floored me when I realized it so I keep trying to shout it at the top of my lungs. There is no gate you can put on a Trusted Publisher setup in …
-
comment
Comment #48102416
I agree with you that TP is an improvement over long lived npm tokens in CI. However, the threat Im most afraid of still does involve dev environment compromise. Because if your re…
-
comment
Comment #48101513
I tested approving a deployment via API last week w/ my gh cli token (well, had claude do it while I watched). Again, I really want to be wrong about this, but my testing showed th…
-
comment
Comment #48101401
I have not read that blog post. But unfortunately (and I'd love to be wrong!) it doesn't matter for if a repo admin's token gets exfiled, because if you put your gates within Githu…
-
comment
Comment #48101347
its so wild to have seen this advice reverse course over the past year. it used to be that projects that pinned deps were called out as being less secure due to not being able to r…
-
comment
Comment #48101308
It is unfortunate, but this is evidence (IMO) that Trusted Publishing is still ~~not secure~~ not enough by itself to securely publish from CI, as an attacker inside your CI pipeli…
-
comment
Comment #47992116
> So when Becker asked ChatGPT (at the time of writing his book, it has been updated since)
-
comment
Comment #47265075
Instead HN has human moderators, who often make changes in response to these kinds of things being pointed out. Which is quite a luxury these days!
-
comment
Comment #47264969
Thats what the second chance pool is for The guidelines talk about primary sources and story about a story submisisons https://news.ycombinator.com/newsguidelines.html Creating a n…
-
comment
Comment #47264821
This article only rehashes primary sources that have already been submitted to HN (including the original researcher’s). The story itself is almost a month old now, and this articl…
-
comment
Comment #47202048
Hey, thank you kind strangers who sent me some money. I appreciate it! <3
-
comment
Comment #47188127
> How many total developers does that cover? 100? I love these questions bc they both can be answered with some slight heuristics, and they are quite surprising! As of January 2026…
-
comment
Comment #47187625
ETH address 0x60F9CC1b97C78D8E8337Ef991a34bd8D9e600420 ¯\_(ツ)_/¯
-
comment
Comment #47187620
I currently pay them $200/month out of my own pocket for this already, so for me it is not a free trial but subsizing my usage. Agreed that $200 USD would be preferable (credits do…
-
comment
Comment #47185623
I dont want to misrepresent, I am not the original author of any of these projects. I am not JDD of lodash (who is still involved and part of the TC) nor TJ Holowaychuk of express.…
-
comment
Comment #47185117
Folks saying this offer is in bad faith or not generous enough dont seem to understand how low the bar is here for rewarding maintainers. I maintain Express.js and Lodash, as well …
-
comment
Comment #45815696
Wow very cool, theyve now closed 150 bugs identified via ai assistance/static analysis! For ref, here is the post from Joshua Rogers about their investigation into the tooling land…