//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
ProfilePosts









Loading...
I'm here! Come by for a chat.
Are you still hiding if no one is looking? People aren't reading the code at all—they'd see the weird decoder+eval—and machines can see that and also the private use code points. Also, it's been public since May 2025 and GitHub/NPM/Microsoft have done nothing. www.aikido.dev/blog/glasswo...
2/ Proposal: User-Provided Functions and Validators github.com/cue-lang/cue... A simple Go API for wrapping Go functions as CUE-callable functions and validators — extending CUE's evaluation with custom logic. #cuelang
2mo
2mo
2mo
The Glassworm supply chain attack is back. Researchers uncovered malware hidden in invisible Unicode characters across 150+ GitHub repositories, plus npm packages and VS Code extensions.
www.aikido.dev
Glassworm Returns: Invisible Unicode Malware Found in 150+ GitHub Repositories
📋 Proposal Details: File: designs/4293-user-functions-and-validators.md Status: Draft This proposal introduces a Go API for wrapping ordinary Go functions as CUE-callable functions and validators. ...
github.com
Proposal: User-Provided Functions and Validators · cue-lang cue · Discussion #4293
I'm officially looking around, if anybody needs a Go software engineer with a very strong background in web security lmk. I also know a fair share of frontend dev and was a SWE/SE for Google and Microsoft. I'm looking for security-sensitive dev projects and security reviews.
5/ Note: there's more to come — in particular some way to automatically include injected values without building a Go binary, but these should provide a foundation for that.