Elektrine lite

← Feed

github.com/ghostwriter

ghostwriter@phpc.social

<p>A functional mind hosted in an object oriented brain.
✊🏿🖤 ✊🏻#BlackLivesMatter</p><p>🇵🇸 <a href="https://phpc.social/tags/FreePalestine" class="mention hashtag" rel="tag">#<span>FreePalestine</span></a><br />🇮🇷 <a href="https://phpc.social/tags/StandWithIran" class="mention hashtag" rel="tag">#<span>StandWithIran</span></a><br />🇺🇦 <a href="https://phpc.social/tags/StandWithUkraine" class="mention hashtag" rel="tag">#<span>StandWithUkraine</span></a></p><p>I write reminders to myself here.</p>

Posts

  • Post #3564532

    https://youtu.be/32u5T6lO8qk

  • Post #3561728

    Rentier capitalism Pay more for #AI you never asked for, or pay less for a crippled version of the software you already had.

  • Post #3440073

    The inability to feel shame is a super power that can make you really rich… ∆

  • Post #3110577

    The packages published by the user &amp;quot;spruko&amp;quot; are all executing arbitrary, obfuscated or malicious code… via &amp;quot;autoload.files&amp;quot; entry in composer.json It reads an embedded payload from a fake `index.jpg` file, decodes it through multiple de-obfuscation functions, and executes it via `eval()` in almost ever php file. I have no interest to investigate further, but somebody should look into it and take action. https://packagist.org/users/spruko https://github.com/...

  • Post #2965875

    🚨 A compromise affecting the community-maintained Laravel Lang project introduced remote code execution backdoors across multiple packages, including: - Laravel-Lang/lang - Laravel-Lang/http-statuses - Laravel-Lang/actions - Laravel-Lang/attributes All tags were rewritten pointing to malicious commits https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer https://github.com/Laravel-Lang/lang/issues/8295 https://github.com/Laravel-Lang/common/is...

  • Post #2965874

    ✅ Create PRs to mitigate #npm #SupplyChainAttack via #npmrc file https://github.com/phpactor/vscode-phpactor/pull/220 https://github.com/xdebug/vscode-php-debug/pull/1125 ✅ Disable extension &amp;quot;auto update&amp;quot; and &amp;quot;auto update check&amp;quot; in #VSCode

  • Post #2965873

    Did #AI free up your schedule, or have you just been paying to babysit a chatbot 20 hours a day?

  • Post #2965872

    #arXiv is cracking down on sloppy AI-generated research submissions.👏🏾 If a paper contains obvious AI hallucinations, specially fake citations and references, authors can now get: - a 1-year ban from posting to arXiv, - and afterward may only post papers already accepted by reputable peer-reviewed venues The policy is aimed at stopping “AI slop” from flooding preprint servers. Submitting AI-slop show negligence and threaten trust in science. https://www.nature.com/articles/d41586-026-01595...

  • Post #2965871

    Using AI to polish grammar is one thing, but if you can&amp;#39;t explain your position without outsourcing the thinking to AI, maybe you don&amp;#39;t understand it well enough to present it as a deeply held argument based on facts and experience. #AI #PHP #Internals

  • Post #2965870

    #Composer currently supports locking a branch to a specific commit: `dev-main#a1b2c3d4` However, it does not support combining a semantic version constraint with a specific immutable commit SHA: `^1.2.3#a1b2c3d4` Would Composer consider adding support for dependency constraints that combine a semantic version with an immutable commit SHA? - Protect users from malicious/compromised tag re-targeting - Ensure a tagged release resolves to an expected immutable commit or fail #PHP #ComposerPHP

  • Post #2965869

    They show you how much they used, but not what it costs them. FREE But...You… you will have to pay. rip electricity and water. https://xcancel.com/i/status/2055346265869721905 #AI #CodexOpenAI #OpenAI #TokenEfficiency #TokenSpending #TokenMaxing #Sustainability

  • Post #2965868

    LibrariesIO API Client an event dispatcher feels appropriate…but not caching. #PHP #PSR7 #PSR11 #PSR14 #PSR17 #PSR18 #PSR20

  • Post #2965867

    Would you accept a PR to add &amp;quot;Class&amp;quot; Constraint? Using classes that extend `PHPUnit\Framework\Constraint\Constraint` then adding them to `PHPUnit\Framework\Assert`? If yes, which branch should be target? @phpunit @sebastian

  • Post #2511719

    Much of the web is powered by #PHP PHP’s reputation was shaped over decades through real engineering decisions, ecosystem evolution, and developer experience. Just because #Laravel creates fake hype through aggressive unethical marketing, community manipulation, fake influencers, and vendor lock-in does not mean it has the best marketing. The real challenge is legacy reputation, fragmented ecosystem, and competition from newer languages; not a lack of tweets or vlogs. https://phpc.social/@br...

  • Post #2490250

    a blog and art gallery where users can purchase a license to use the art. Modules /App /Blog /Gallery /License /Checkout /User /Admin Original image storage (private) - Automatic thumbnails - Watermarked previews - Metadata extraction - Download via signed URLs Purchase Flow - User selects artwork - Chooses license tier - Pays - Receives: * Invoice * License * Download access /blog /blog/{slug} /gallery/{id} /license/{id} /checkout /account /purchases /admin Phase 1/8: Blog and User

  • Post #2490249

    https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised #CyberSecurity #InfoSec #SupplyChainSecurity #SoftwareSupplyChain #NPM #OpenSourceSecurity #AppSec #DevSecOps #ThreatIntel #Malware #JavaScript #NodeJS #CICD #GitHubActions #CloudSecurity #TypeScript #ReactJS #WebDev #OpenSource #DevTools #SoftwareEngineering #DeveloperSecurity #SecureCoding #GitHub #SupplyChainAttack #Programming #TechNews #DevOps #ApplicationSecurity #ThreatResearch #SecurityEngineerin...

  • Post #2490246

    🚨 Heads up, Chrome users! Google’s browser is quietly downloading a 4GB AI model without permission. https://www.pcmag.com/news/chrome-is-quietly-downloading-4gb-ai-model-without-your-permission #MachineLearning #TechNews #Chrome #Google #Privacy #CyberSecurity #DataSecurity #OnlineSafety #DigitalRights #TechUpdate #TechAlert #AIModel #BigData #UserPrivacy

  • Post #2490245

    unsafe is abused a lot. you&amp;#39;re supposed to use it for small abstractions that you can prove are safe, but the compiler can&amp;#39;t. not as a way to silence borrow checker errors until the code compiles. #rust #rustlang

  • Post #2490244

    &amp;gt; After we were told about the problem and then denied it and then realized we are wrong, we deployed a fix in hours. *cringe* https://xcancel.com/zackkorman/status/2048767688411959573 #Vercel #Lovable

  • Post #2490243

    🚨 Critical Composer Update: 2.9.8 &amp;amp; 2.2.28 fix a GitHub Actions token disclosure! ⚠️ Update NOW or disable GitHub Actions immediately! https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/ #PHP #Composer #ComposerPHP #OpenSource #WebDevelopment #GitHubActions #DevSecOps #CyberSecurity #SoftwareUpdate #PatchRelease #DependencyManagement #SecurityFix #Programming #Packagist #PHPDev #ComposerUpdate #OpenSourceSoftware #WebDevLife #Info...

  • Post #2490241

    Installed my new favorite PHP package by @samsonasik, Turn PHP architecture decisions into enforceable rules you can test with PHPUnit. https://github.com/boundwize/structarmed (Automated dependency installs, validation, updates, CI/CD, and workflow orchestration entirely through GhostCI) #PHP

  • Post #2353620

    Happy Mother&amp;#39;s Day #PHP #PHPWomen

  • Post #1672068

    switched to revolt/event-loop

  • Post #1672067

    I love working with events. https://github.com/php-tui/php-tui

  • Post #1672066

    Console application Server mode Worker (FrankenPHP) mode 1 index.php 1 entry point 0 duplication

  • Post #1672065

    testing a new event &amp;amp; listener naming convention.

  • Post #1672064

    Vendor lock-in, makes a customer dependent on a vendor for a product or service, unable to use another vendor without substantial switching costs. &amp;quot;Premium&amp;quot; suggests higher quality, but in practice it often just a higher price tier that may or may not reflect real improvements.

  • Post #1672063

    ideas and such

  • Post #1672062

    https://techcrunch.com/2026/04/22/france-confirms-data-breach-at-government-agency-that-manages-citizens-ids/

  • Post #1672061

    draft is a deterministic PHP code generation tool using symfony/yaml to parse the YAML and nikic/php-parser to generate PHP programmatically. `vendor/bin/draft draft/UserRegistrationTest.yaml` I bet your AI can’t read the same YAML file and produce the same exact PHP code across multiple sessions… without requiring a subscription or depleting Earth’s energy resources.😜