Zach Leatherman
🫣 Go to https://www.zachleat.com/
🎈 Creator/Maintainer of Build Awesome/
@11ty@neighborhood.11ty.dev https://www.11ty.dev/
🎉 Professional Hobbyist at
Font Awesome
🌾 A random person from Nebraska maintaining software
🏳️⚧️ Listen to Trans Folks
🧞 he/him/they
🐟 out of 🌊🌊
🕸️ Front of the front-end web developer
🔎 #searchable
💨 Web Performance: https://www.speedlify.dev/
Cloudflare stock down 23.83% after announcing layoffs yesterday.
do you want to keep daylight saving time or double it and give it to the next person
RE: @jonikorpi@mastodon.gamedev.place
any measure of web performance moving forward must include “Are you a human?” checks in metrics
LinkedIn’s API is absolutely wild — how many hoops do I gotta jump through to get an API key that posts to my LinkedIn page?
A follow up here on action items (assuming you’re already using trusted publishers OIDC to scope releases to a single GitHub Action workflow):
- Look for any
pull_request_targetGitHub Actions workflows! (this allows external forks/code to run your actions with write access ☠️☠️☠️☠️☠️) - Look for use of
cachein your GitHub Actions release workflow (cache was poisoned/compromised bypull_request_targettrigger)
Learn more about pull_request_target: https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/
is there a compound word more tragically ambiguous than lunchmeat
Marginally annoyed that Intl.RelativeTimeFormat#format doesn’t support "millisecond" as a unit.
I get it: why would anyone want to show milliseconds??
Importantly, pull_request_target IGNORES this GitHub security setting: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#controlling-changes-from-forks-to-workflows-in-public-repositories
This was very surprising to me.
*hops on the smallest of miniature horses*
so how high does this horse go
An Awesome Theming Demo with Dave Gandy (and more Build Awesome AMA)
Going to be SUPER CASUALLY hanging out here live in a few, discussing Build Awesome (11ty) Pro and the Kickstarter campaign.
Come hang out! AMA (sure — anything, what could go wrong?)
Build Awesome Pro Kickstarter AMA
@ardouglass one counterexample is that the parseInt() second argument default was changed years and years ago 😅
@jgarber@social.lol luckily I don’t use pull_request_target anywhere but WOOOOOOOFFFFF




