bradleymeck Profile Banner
Bradley Farias Profile
Bradley Farias

@bradleymeck

Followers
2K
Following
6K
Statuses
27K

Head of Open Source Security at @SocketSecurity 🦋 Thoughts are my own. He/him.

Austin, TX
Joined July 2008
Don't wanna be here? Send us removal request.
@bradleymeck
Bradley Farias
9 hours
@satanacchio SEA needs this
0
0
1
@bradleymeck
Bradley Farias
1 day
@erikras @mattpocockuk @kentcdodds Never? require a bit less typing but make normal JS wierd though (ever Object.entries/keys/values an enum? and how the differ for numeric values vs other). Same kind of wierdness for declarative vs runtime namespaces. Just make an object. Enums don't give special capabilities.
0
0
1
@bradleymeck
Bradley Farias
2 days
@MikolaLysenko @sea3dformat Oi the hole kinda is a cute effect
0
0
0
@bradleymeck
Bradley Farias
2 days
@thdxr @Ffxivmarket need a bunch more checks to stop me
0
0
1
@bradleymeck
Bradley Farias
3 days
RT @samwillis: PGlite, our Postgres in WASM project, has hit 1/2 million downloads a week! 🤯 We (@ElectricSQL) have a lot planned for (nati…
0
18
0
@bradleymeck
Bradley Farias
3 days
@fabiospampinato @CanadaHonk @guybedford to be fair you really should be using 'Accept: application/vnd.npm.install-v1+json' but yea
0
0
2
@bradleymeck
Bradley Farias
4 days
@CanadaHonk @guybedford Not even in the outlier bracket
1
0
3
@bradleymeck
Bradley Farias
7 days
@aidenybai We do T_T
0
0
4
@bradleymeck
Bradley Farias
7 days
RT @matteocollina: @simonesanfradev makes 100% considering how file system works. This is also the reason why readFileSync() is faster than…
0
1
0
@bradleymeck
Bradley Farias
7 days
RT @arstechnica: Backdoored package in Go mirror site went unnoticed for >3 years
0
10
0
@bradleymeck
Bradley Farias
8 days
@Hiteshdotcom @jarredsumner Whatever it is... it seems to be... growing...
0
0
1
@bradleymeck
Bradley Farias
8 days
@SocketSecurity Always remember that what provenance gives is reactive not proactive! Love using it to investigate but several recent things were not helped by it even when existing sadly.
0
0
0
@bradleymeck
Bradley Farias
9 days
RT @burckhap: We uncovered a stealthy Go supply chain attack: a malicious BoltDB typosquat backdoored dev machines while looking clean on G…
0
2
0
@bradleymeck
Bradley Farias
15 days
@robpalmer2 @dested ... Something something... JSSugar
0
0
2
@bradleymeck
Bradley Farias
17 days
@matteocollina @rauchg @RhysSullivan I'm curious honestly on if we could even get Staff/Principal to agree on A pattern; once you move away from this the solutions seem to just explode with too many options. Some effort/work by 1pass has been nice but still not seen in the wild too much.
0
0
1
@bradleymeck
Bradley Farias
20 days
@shvr93 @im_the_knarf @mattpocockuk @seif_sweilam Yep but all the old implementations of them had to port code just the same as if JS spec differs from legacy TS enums. Few people wrote decorator implants lots of people using enums
0
0
1
@bradleymeck
Bradley Farias
20 days
@AClotfelter @michael_timbs @mattpocockuk TS enums are basically a way to declare an object literal and type mapping not an avenue for rust/php enums
0
0
0
@bradleymeck
Bradley Farias
20 days
@matteocollina A toxic trait of threat feed that we try to avoid but certainly is engrained in them is creating alerts that maintainers don't get to verify.
0
0
0
@bradleymeck
Bradley Farias
20 days
@matteocollina I think there is some way to let the people who get these vulns etc to pay for it to be verified by maintainers as certainly our customers don't want to get anything and when they do they want it gone.
0
0
0