| ▲ | fnoef 2 hours ago | ||||||||||||||||||||||
I’m honestly at a point where I’m afraid to update any of my project’s dependencies, and I’m also afraid to run the locally without some locked down VM | |||||||||||||||||||||||
| ▲ | darkwi11ow a minute ago | parent | next [-] | ||||||||||||||||||||||
I use Tanstack in my projects. Last week when Tanstack got compromised, it was only my laziness that saved me -- was thinking about doing pnpm upgrade but got lazy and played some dota... Finished game was just going to pnpm upgrade, opened hacker news and boom! news hit. Since then, I had set up libvirt/qemu based VM with another Linux running in it specifically for development. Now I run all of docker, kubernetes, IDE, pnpm, uv, etc in that VM and removed them from host. The only write capable secret VM has access to, is my passphrase protected ssh key, which I can quickly revoke from my Github account in case of compromise. Feels much safer now. | |||||||||||||||||||||||
| ▲ | exiguus an hour ago | parent | prev [-] | ||||||||||||||||||||||
I also was at this point, and I decided to add cooldowns to every project. | |||||||||||||||||||||||
| |||||||||||||||||||||||