> but the commit was not documented as a security fix and received no CVE.
There must be an entire class of open source commits that unknowingly fixed security bugs without being tagged as security fixes that one could look for missed backports. Scary.
"quick" tunnels you can make by installing cloudflare software and running a command, without a cloudflare account, using a fixed "trycloudflare.com" domain and not your own domain.
existing (slow) tunnels you can create once you've set up your own domain for cloudflare to manage its DNS, installing cloudflare software, logging in to your account, and running a similar command.
The things in the 'what should be self-driving' section are the exact things i give to juniors so they can build their mental model of the codebase.
Now, I agree it'd be fantastic to have that automated, but how do we then share that context with the humans that will drive the non-self-driving actions?
> the Tanstack compromise is very likely to have been the leak vector
....appears to have been backdoored to extract an API key with authorization to read the private codebase.
...
> immediately rotated all required tokens & credentials to prevent further incidents.
Rotating the API key doesn't quite put them in a position to "prevent further incidents" does it? The next PyPI/npm supply chain issue will just get the new key?
I suppose whatever they use that key for should be reviewed and re-scoped if possible?
Does github let you restrict where you can originate requests using a given API key? or are we just not there yet?
https://arcprize.org/results/anthropic-claude-opus-5-5
reply