What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
1
0
1
0

https://nextjs.org/blog/security-update-2025-12-11

Next.js의 추가 보안 업데이트가 있습니다.

지난주에 CVE-2025-66478 보안취약점때문에 부랴부랴 패키지 업데이트한 기억이 있는데, 이번에도 몇개 패치되었네요.

Next.js를 App Router 방식으로 쓰는 개발자분들은 잊지 말고 업데이트하셔요.

fix-react2shell-next 패키지로 검사 및 업데이트 가능합니다.

❯ npx fix-react2shell-next

fix-react2shell-next - Next.js vulnerability scanner

Checking for 4 known vulnerabilities:

  - CVE-2025-66478 (critical): Remote code execution via crafted RSC payload
  - CVE-2025-55184 (high): DoS via malicious HTTP request causing server to hang and consume CPU
  - CVE-2025-55183 (medium): Compiled Server Action source code can be exposed via malicious request
  - CVE-2025-67779 (high): Incomplete fix for CVE-2025-55184 DoS via malicious RSC payload causing infinite loop

...
3

Hard to believe this gorgeous 27" iMac, with a 6 core i5-8500, 16 gigs of ram and a solid state drive was on its way to the dump.

Apparently, it's not "good enough" to run the new MacOS, so it was discarded.

Thankfully, is here to save the day and make this a perfect computer for someone that will last YEARS into the future.

27" iMac running the Nixbook installer
0
0
0
1
1
0
0

原本第一次搭 Skyliner 很興奮,結果誤點了 20 分鐘,特急都不特急了。

列車來了後,我很怕坐錯車次,問了三次工作人員才敢肯定;結果我的位置坐了一位中國口音的大哥,問他,他只拿車票給我看,座號相同,但肯定是他坐錯車,因為我前面確認好幾次了 😂
還好車裡還有空位,我就另外找位子坐,懶得釐清了。
(後來車掌有來確認座位,但語言不通,也是拿那個人沒輒,車掌回來問我說坐這邊OK嗎?我說OK)

0
0

Servo Report for Week 49 2025

Highlights from last week:

- Implemented basic support of custom protocol handlers
- Added webdriver touch support for all platforms
- Finished adding ChaCha20-Poly1305 support to WebCrypto API
- Servo can now use a http proxy without authentication

You can help support Servo, an independent web rendering engine, and the health of the web ecosystem by donating:

github.com/sponsors/servo
opencollective.com/servo

Decorative report cover with the Servo logo that reads "Servo Report Week 49 2025”
0
2
0

Last week, we hosted an event to mark the inaugural cohort. It was an opportunity to reflect on the program’s impact, share insights from its evaluation report, and celebrate the vital contributions of these maintainers of critical digital infrastructure.

In our latest blog post, we take you inside the event with a recap of the highlights ➡️ 

sovereign.tech/news/who-will-m

@icingStefan Eissing @hugovkHugo van Kemenade @matkMatthias Klumpp

five people lined up in black "Sovereign Tech Fellowship" Hoodies, in front of a screen
0
2
0
0
0
1
1
0
1
1
0
0

내맘대로 올해의 앨범 5개 (기준: 2025년 발매)

北園みなみ - Meridian
長瀬有花 - Mofu Mohu
Ninajirachi - I Love My Computer
蓮ノ空女学院スクールアイドルクラブ - Dream Believers (105期Ver.)
椎乃味醂 - 解釈系

0
0
0
0
1
0
1
1
0
1

虚無

昔むかし(およそ8925年前)、おじいさんとおばあさんと​:takasi:がいました

おじいさんは山へ芝刈りに おばあさんは川へ洗濯に
:takasi:​は​:ogoride_sushi:に行きました

すると
:takasi:​の行った​:ogoride_sushi:​屋さんのレーンから ​:5000t_kakuteisinkoku:​ ​:5000t_kakuteisinkoku:​と​:harrypottertoniranomisoshiru:が流れてきました

:takasi:​は​:fuwa_tententen:と空を飛び そして 人類で始めて火星に降り立ったのでした

:you_are_winner:

:real_hato_kokekokko:

1
1
0
0
0
1
1
0

so there isn’t really a protocol “reader” or a “writer” that isn’t the same thing as RSC itself. unless you introduce some intermediate format or runtime representation which would hurt performance

0
1