Related posts
Kenneth Reitz
x.com
Requests installations via PyPi continue to increase, at over 732.48 downloads / second today.
pypi downloads requests
The the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Sources
All
Writing
x.com GitHub Korrents
Top people
Andrej Karpathy
Guillermo Rauch
Luke Wroblewski
Elio Struyf
Peter Steinberger
Showing
Profile →
Show everything
Hiding
Show them again
Show them again
Further back ↓
Hiding
Show them again
15 September
CEO of Vercel; creator of Next.js and Socket.IO. Writes at rauchg.com.
Excited to formally introduce Vercel Labs. https://t.co/zCNVryaiin is the home for the in-public research and experimentation arm of Vercel. 247 million downloads in, we wanted to, also in public, share what we're supporting, what we're researching, and what experiments didn't pan out. Kudos to @ctatedev and @cramforce for shaping this great initiative and iterating in public. Related
3 September
Product designer and entrepreneur; author of Mobile First and Web Form Design; formerly a product director at Google; now building AI products.
big step forward for sure. but: "Now make it a 3D model in Blender" "Can you go to eBay" "using the arrow keys to move around" "in my downloads folder" is echoing the past not pointing to the future. lukew.com
Quoting @OpenAI This is GPT-6 Astra. Anything you can do on a computer, Astra can do for you. Fast. Related
1 September
Belgian engineering lead, Microsoft MVP and public speaker. Creator of Front Matter, a headless CMS extension for Visual Studio Code.
10 August
Founded PSPDFKit in 2011 and ran it for a decade. Came back from a break to work on AI agents — the OpenClaw project, and OpenAI, joined in February 2026. Writes at steipete.me.
31 March
Founding member of OpenAI and former director of AI at Tesla; creator of nanoGPT and the term "vibe coding".
New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I thin… stepsecurity.io
Quoting @feross 🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downl… Related
24 March
Founding member of OpenAI and former director of AI at Tesla; creator of nanoGPT and the term "vibe coding".
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm… Quoting @hnykda LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below crypto Related
Nothing matches. Show everything
What is a korrent?
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com .
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
Got it
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.
Got it