<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: vldszn</title><link>https://news.ycombinator.com/user?id=vldszn</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 21 May 2026 01:26:55 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=vldszn" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by vldszn in "Nx Console VS Code extension was the initial access vector in the GitHub breach"]]></title><description><![CDATA[
<p>Per security advisory on GitHub:<p>Root Cause<p>One of our developers was compromised by a recent supply-chain compromise on Tanstack, which leaked their GitHub credentials through the GitHub CLI (gh). This allowed the attacker to run workflows on our GitHub repository as a contributor.<p>More links:<p><a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w" rel="nofollow">https://github.com/nrwl/nx-console/security/advisories/GHSA-...</a><p><a href="https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised" rel="nofollow">https://www.stepsecurity.io/blog/nx-console-vs-code-extensio...</a></p>
]]></description><pubDate>Thu, 21 May 2026 01:20:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48216615</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48216615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48216615</guid></item><item><title><![CDATA[Nx Console VS Code extension was the initial access vector in the GitHub breach]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/jeffbcross/status/2057236396658811020">https://twitter.com/jeffbcross/status/2057236396658811020</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48216614">https://news.ycombinator.com/item?id=48216614</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 21 May 2026 01:20:20 +0000</pubDate><link>https://twitter.com/jeffbcross/status/2057236396658811020</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48216614</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48216614</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub confirms breach of 3,800 repos via malicious VSCode extension"]]></title><description><![CDATA[
<p>UPD: it’s confirmed now by the CEO of Nx <a href="https://x.com/jeffbcross/status/2057236396658811020?s=46&t=_RN2fQnPTv5buAq00Oxwaw" rel="nofollow">https://x.com/jeffbcross/status/2057236396658811020?s=46&t=_...</a></p>
]]></description><pubDate>Thu, 21 May 2026 01:11:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48216533</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48216533</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48216533</guid></item><item><title><![CDATA[New comment by vldszn in "DOS Zone"]]></title><description><![CDATA[
<p>so cool!</p>
]]></description><pubDate>Wed, 20 May 2026 23:41:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48215892</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48215892</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48215892</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub confirms breach of 3,800 repos via malicious VSCode extension"]]></title><description><![CDATA[
<p>=)</p>
]]></description><pubDate>Wed, 20 May 2026 22:36:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48215241</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48215241</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48215241</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>UPD: disable auto-updates for extensions in VS Code/Cursor!</p>
]]></description><pubDate>Wed, 20 May 2026 20:34:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48213729</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48213729</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48213729</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub confirms breach of 3,800 repos via malicious VSCode extension"]]></title><description><![CDATA[
<p>friendly reminder:<p>- disable auto-updates for extensions in VS Code/Cursor<p>- use static analysis for GitHub Actions to catch security issues in pre-commit hook and on ci: <a href="https://github.com/zizmorcore/zizmor" rel="nofollow">https://github.com/zizmorcore/zizmor</a><p>- set locally: pnpm config set minimum-release-age 4320 # 3 days in minutes <a href="https://pnpm.io/supply-chain-security" rel="nofollow">https://pnpm.io/supply-chain-security</a><p>- for other package managers check: <a href="https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e93104" rel="nofollow">https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...</a><p>- add Socket Free Firewall when installing npm packages on CI to catch malware <a href="https://docs.socket.dev/docs/socket-firewall-free#github-actions" rel="nofollow">https://docs.socket.dev/docs/socket-firewall-free#github-act...</a></p>
]]></description><pubDate>Wed, 20 May 2026 20:32:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48213698</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48213698</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48213698</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub confirms breach of 3,800 repos via malicious VSCode extension"]]></title><description><![CDATA[
<p>There are rumours that was NX Console VS code extension<p><a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w" rel="nofollow">https://github.com/nrwl/nx-console/security/advisories/GHSA-...</a><p><a href="https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised" rel="nofollow">https://www.stepsecurity.io/blog/nx-console-vs-code-extensio...</a></p>
]]></description><pubDate>Wed, 20 May 2026 19:35:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48212942</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48212942</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48212942</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>fair point</p>
]]></description><pubDate>Wed, 20 May 2026 12:28:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48206612</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48206612</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48206612</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>Disabling vscode/cursor extensions auto-updates also makes sense</p>
]]></description><pubDate>Wed, 20 May 2026 04:21:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48203049</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48203049</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48203049</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>Nice</p>
]]></description><pubDate>Wed, 20 May 2026 03:06:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48202635</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48202635</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48202635</guid></item><item><title><![CDATA[New comment by vldszn in "Gemini Omni"]]></title><description><![CDATA[
<p>When I click the link, the website crashes on my iPhone 13 iOS Chrome lol</p>
]]></description><pubDate>Wed, 20 May 2026 03:04:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48202626</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48202626</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48202626</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>You are welcome! Recently discovered it and found it genuinely useful. Fixed a bunch of issues in my workflows too :)</p>
]]></description><pubDate>Wed, 20 May 2026 02:25:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48202358</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48202358</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48202358</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>Exactly =)</p>
]]></description><pubDate>Wed, 20 May 2026 02:10:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48202256</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48202256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48202256</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>Makes sense tbh :)</p>
]]></description><pubDate>Wed, 20 May 2026 02:09:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48202251</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48202251</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48202251</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>GitHub: "We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity."</p>
]]></description><pubDate>Wed, 20 May 2026 00:56:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48201712</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48201712</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48201712</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>Maybe zizmor could catch this <a href="https://github.com/zizmorcore/zizmor" rel="nofollow">https://github.com/zizmorcore/zizmor</a> but not sure 100%</p>
]]></description><pubDate>Wed, 20 May 2026 00:43:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48201618</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48201618</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48201618</guid></item><item><title><![CDATA[New comment by vldszn in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>- Use Static analysis for GHA to catch security issues: <a href="https://github.com/zizmorcore/zizmor" rel="nofollow">https://github.com/zizmorcore/zizmor</a><p>- set locally: pnpm config set minimum-release-age 4320 # 3 days in minutes <a href="https://pnpm.io/supply-chain-security" rel="nofollow">https://pnpm.io/supply-chain-security</a> for other package managers check: <a href="https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e93104" rel="nofollow">https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...</a><p>- add Socket Free Firewall when installing npm packages on CI <a href="https://docs.socket.dev/docs/socket-firewall-free#github-actions" rel="nofollow">https://docs.socket.dev/docs/socket-firewall-free#github-act...</a></p>
]]></description><pubDate>Wed, 20 May 2026 00:34:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48201562</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48201562</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48201562</guid></item><item><title><![CDATA[New comment by vldszn in "Postmortem: TanStack npm supply-chain compromise"]]></title><description><![CDATA[
<p>Recommend adding this globally:<p>pnpm config set minimum-release-age 10080 # 7 days in minutes<p><a href="https://pnpm.io/supply-chain-security#delay-dependency-updates" rel="nofollow">https://pnpm.io/supply-chain-security#delay-dependency-updat...</a></p>
]]></description><pubDate>Tue, 12 May 2026 01:47:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48103221</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=48103221</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48103221</guid></item><item><title><![CDATA[New comment by vldszn in "Show HN: Tolaria – Open-source macOS app to manage Markdown knowledge bases"]]></title><description><![CDATA[
<p>looks very good! love this</p>
]]></description><pubDate>Fri, 24 Apr 2026 13:37:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=47890113</link><dc:creator>vldszn</dc:creator><comments>https://news.ycombinator.com/item?id=47890113</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47890113</guid></item></channel></rss>