Search results

I will never understand the urge the use a library designed to provide reactive DOM updates as a server framework. Here I am, wasting time parametrising my queries while some are shipping unprotected “eval()” in what looks like a very abstracted gRPC service.

github.com/vercel/next.js/secu

0

Reactのサーバーコンポーネント(RSC)に脆弱性(CVE-2025-55182)が発見されたらしいので記事を書きました。

(高く見積もられがちではありますが)CVSS10と極めて危険ですので、速やかなアップデートが必要となります。
19.0.019.1.019.1.119.2.0の4バージョンに影響があるとされていますので、確認を行うことをおすすめします。

また、Next.js等のReactに依存しているフレームワークにも影響があります。
Akamaiによればこの脆弱性による攻撃はまだ確認されていないようですが、いつこの脆弱性をついた攻撃が始まるかは不明です。早めの対策をおすすめします。

ReactにCVSS10の脆弱性、サーバーサイドでのデシリアライズに欠陥が存在し攻撃者はHTTPリクエストのみで任意のコードを実行可能 - osumiakari.jp
www.osumiakari.jp/articles/20251204-react2shell-cvss10/

0

Reactのサーバーコンポーネント(RSC)に脆弱性(CVE-2025-55182)が発見されたらしいので記事を書きました。

(高く見積もられがちではありますが)CVSS10と極めて危険ですので、速やかなアップデートが必要となります。
19.0.019.1.019.1.119.2.0の4バージョンに影響があるとされていますので、確認を行うことをおすすめします。

また、Next.js等のReactに依存しているフレームワークにも影響があります。
Akamaiによればこの脆弱性による攻撃はまだ確認されていないようですが、いつこの脆弱性をついた攻撃が始まるかは不明です。早めの対策をおすすめします。

ReactにCVSS10の脆弱性、サーバーサイドでのデシリアライズに欠陥が存在し攻撃者はHTTPリクエストのみで任意のコードを実行可能 - osumiakari.jp
www.osumiakari.jp/articles/20251204-react2shell-cvss10/

0
0

I finally wrote and deployed my first app this week.

I have played with and for the past few decades, but I haven’t dug hard into django as every app i have worked on or overseen would not benefit much from the admin interface.

I am the only one working on this app, and it's for me only, and I didn't care if the admin interface adhered to a very specific design spec. In fact, i am the only one wjho will probably ever see the admin interface.

More attached…

0
0

#introduction

I am a (non-tenure track, uni) interested in every single thing about , esp ones, & Side gig in ( lol). I love and will ask you too many questions about your etc . Proud fan. Love 👋

0
0
0

I have been using web frameworks for decades, but have not had the opportunity to use . I am working on a small personal project, with one dev, me! I picked Django for the admin interface. But had trouble getting through the tutorials because they were huge.

I found a perfect tutorial for someone in my headspace.

Thanks, @ehmatthesEric Matthes for a SUPER useful tutorial. I have gone half way through, and this is perfect. More detail in the responses in this toot.

link: mostlypython.com/django-from-f

0

😅 So I did not fully appreciate the power of hashtags on this place when I wrote my , so I'm giving it a second go.

• I'm a front-end web developer in Spokane, WA. I work for Red Hat on Ansible Controller using , , . I don't write so much here as I have at previous gigs, but, I'm okay at that too…

• I'm the author of CSS in Depth 📘 manning.com/books/css-in-depth

• I enjoy mixing and have my recipes available in a : sidecar.us

0
0
0
0

TypeScript와 React에 File-based App 서버를 부착하여 단순하지만 완결성있는 풀 스택 개발 환경을 구축할 수 있습니다. 여기에 AGENTS.md 파일이나 mcp.json을 추가한다면 풀 스택 프로젝트에 바이브코딩까지 얹을 수 있겠습니다.

https://forum.dotnetdev.kr/t/typescript-react-file-based-app-c-api/13812

2

👋 Heading to Plone Conference 2025 in Jyväskylä this October?

🍂 October can be crisp and colorful in Finland! 🇫🇮

🧥 Pack a jacket, gloves & comfortable shoes – mornings & evenings can be chilly (or not, it will be a surprise!)

☕ Inside it’s cozy, outside stay comfy & enjoy the autumn colors (like pitch black 😜 )!

🎟️ To get your tickets at: 2025.ploneconf.org/tickets

0

🚀 The Plone Conference 2025 in Jyväskylä on October 13–19, 2025 – hosted by the University of Jyväskylä, Finland 🇫🇮

👉 A week full of learning, networking & inspiration

👉 International and Finnish IT professionals from experienced to new

👉 Talks & workshops on Plone, Python, web development & open source innovation 🤯

👉 Special one-day event: PyCon Finland on Oct 17, dedicated to Python 🐍

🎟️ Tickets: 2025.ploneconf.org/tickets

0

PyCon Finland 2025 Schedule Published! 🎉
Join us on Friday, October 17th in Jyväskylä for a full day of Python talks and networking.

Featured talks include:
- Keynote: "Muuttolintujen Kevät - Automatic Bird Sound Classifier" by Patrik Lauha
- "Building RAG AI Applications with MariaDB Vector and Python" by Robert Silén
- "Using Python with Satellites, Lessons from a Staff Engineer" by Jeremy Mayeres

2025.ploneconf.org/schedule/py

0

React - useCallback & useMemo Misuse

Shahar Amir @shaharamir@hackers.pub

The `useCallback` and `useMemo` hooks in React are designed to optimize performance by memoizing functions and values, but using them indiscriminately can lead to unnecessary overhead. These hooks are beneficial when dealing with expensive calculations or when passing stable references to deeply nested child components. However, for simple operations like basic arithmetic or simple function declarations, the memoization provided by these hooks adds complexity without any performance gain. Overusing `useMemo` and `useCallback` introduces extra CPU cycles and can confuse developers, making the code harder to maintain. It's more efficient to apply these hooks selectively, focusing only on the parts of your application where they provide a tangible benefit, ensuring that React remains fast and your code stays clean.

Read more →
5
0

Just moved over from mastodon.design, so it's time for another !

I'm Toni 👋

I’m a software , though I’m spending more and more time writing code, mostly in and

When I'm not heads down at work, you'll catch me , eating my weight in oranges, walking with my dog Xenon, or just getting lost in a new , , or .

I’m also a passionate collector, fan and I play occasionally.

More🍊 → toni.li/about

0

Since I've moved to a new instance - one I'm running myself - I though I might re-introduce myself.

I'm Jeff Markel (see profile for pronunciation) - he/him. I'm kinda old, kinda not - born on the cusp of Baby Boom I and Baby Boom 2, aka Generation Jones (1955).

I can schmooze, but am basically very shy - f2f, anyway - and very introverted. More than a few hours of f2f interaction are exhausting.

I had one sibling - a sister - who died of pancreatic cancer in 1997, at 45. I lost my dad to bladder cancer in 1991 (age 67), and my mom to breast cancer in 2006 (age 80). So the big-C is ever-looming; my odds aren't so good. But I've lived longer than my sister and my father. Hopefully the string will continue.

My wife and I have been married to each other since 1982. We have 3 "children" (in quotes only because they're long-past childhood), and 4 grandchildren. Two are in NYC and one is in LA. The oldest of the grands is 15 and in full-fledged teenager mode.

I'm Jewish, but also an atheist - if that makes sense. The ethnicity does mean a lot to me. I have always felt a sense of 'other'ness and, although I know that I benefit from white privilege, I no longer really think of myself as "white" because the people for whom that matters most do not - and that's perfectly fine with me.

I get obsessed with things. I bake sourdough. I make cocktails. I walk long distances. I develop websites - using Drupal mostly, though I'm now learning React and a few other Javascript frameworks like Sveltekit and Astro - and of course those all have adjacent, and necessary, technologies that I also want to learn. As I used to say in my Twitter profile, when I was still there, I try to learn something new every day.

I've been a software person since the late 1970's. I started out on mainframes - but that's become a distinction without a difference. I've written code in many languages, from Algol to YAML (I tried to think of one starting with Z but Zend is all I could come up with, but that's a company, not a language 🤷‍♂️). Still working, but I do plan to "retire" in the next 18 months or so - in quotes because I will certainly need to do something after that besides sleeping in.

0

청개구리 스택 찬가

洪 民憙 (Hong Minhee) @hongminhee@hackers.pub

이 글은 저자가 기술 스택을 선택할 때 주류를 따르지 않고 대안적인 기술을 선택하는 경향, 즉 "청개구리 스택"을 추구하는 경험을 공유합니다. 청개구리 스택은 사용자가 적어 문제 해결에 어려움이 있을 수 있지만, 기술에 대한 깊이 있는 이해와 오픈 소스 기여 기회를 제공합니다. 또한, 후발주자로서 대안적인 설계를 통해 정석 스택보다 나은 이해를 제공할 수 있습니다. 여러 부품을 직접 조립하는 과정은 번거롭지만 각 기술에 대한 깊은 이해를 얻을 수 있게 합니다. 저자는 오늘의 정석 스택도 과거에는 청개구리 스택이었을 수 있음을 지적하며, LLM 시대에도 청개구리 스택이 주는 배움의 기회는 여전할 것이라고 주장합니다. Stack Overflow에 답이 없는 길을 걸으며 얻는 깨달음은 온전히 자신의 것이 될 것이라는 메시지를 전달하며, 독자들에게도 주체적인 기술 선택과 도전을 권장합니다.

Read more →
29
1
3
0