Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 3 days ago

NextJS Security Vulnerability

https://nextjs.org/blog/CVE-2025-66478

#HackerNews #NextJS #Security #Vulnerability #NextJS #Security #Vulnerability #Cybersecurity #WebDevelopment #SoftwareSecurity #CVE2025

  • Copy link
  • Flag this post
  • Block
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 4 days ago

Critical RCE Vulnerabilities in React and Next.js

https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182

#HackerNews #CriticalRCE #Vulnerabilities #React #Nextjs #Cybersecurity #Vulnerabilities #CVE-2025-55182

wiz.io

Critical RCE Vulnerabilities Discovered in React & Next.js | Wiz Blog

React and Next.js are exposed to critical unauthenticated RCE via CVE-2025-55182 and CVE-2025-66478. Learn which versions are impacted and how to mitigate.
  • Copy link
  • Flag this post
  • Block
Vincent Tunru
@VincentTunru@fosstodon.org  ·  activity timestamp 2 weeks ago

@danabra.mov What I haven't read much about is what bounds the cache size, or more importantly: can I be confident that a process won't crash with an out of memory error caused by using Cache Components?

#React #NextJS

  • Copy link
  • Flag this post
  • Block
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 weeks ago

Okta's NextJS-0auth troubles

https://joshua.hu/ai-slop-okta-nextjs-0auth-security-vulnerability

#HackerNews #Okta #NextJS #0auth #troubles #security #vulnerability #OAuth #NextJS

Joshua.Hu Joshua Rogers’ Scribbles

AI slop security engineering: Okta’s nextjs-0auth troubles

In October, I reported two security issues to Okta’s auth0/nextjs-auth0 project, here and here. The latter bug, an oauth parameter injection, allows for a range of types of abuse, like scoping tokens for unintended services, setting redirect_uri and scope to arbitrary values to leak tokens, and so on.
  • Copy link
  • Flag this post
  • Block
omi fan :miyagi: 🐟⁂ and 2 others boosted
Chris Hayes
@chris@nutmeg.social  ·  activity timestamp 3 weeks ago

It's alive! 🧟

After a bit of trial-error, got fediverse comments showing on a #nextjs site running #fedify. My personal fediverse-connected youtube mirror is now mostly feature complete.
(The video post in the screenshot is over here: https://watch.hayes.software/video/16)
#fediverse

Screenshot of a website with a big video player playing a video titled, "Citadel blasting Caramelldansen" Below it is a comment section. The comment field says you can comment on videos by connecting your Mastodon account. The comment section has a single comment, "This is a test comment." Which is a comment I made from mastodon.social that now automagically shows on my video site. Yay!
Screenshot of a website with a big video player playing a video titled, "Citadel blasting Caramelldansen" Below it is a comment section. The comment field says you can comment on videos by connecting your Mastodon account. The comment section has a single comment, "This is a test comment." Which is a comment I made from mastodon.social that now automagically shows on my video site. Yay!
Screenshot of a website with a big video player playing a video titled, "Citadel blasting Caramelldansen" Below it is a comment section. The comment field says you can comment on videos by connecting your Mastodon account. The comment section has a single comment, "This is a test comment." Which is a comment I made from mastodon.social that now automagically shows on my video site. Yay!
  • Copy link
  • Flag this post
  • Block
Chris Hayes
@chris@nutmeg.social  ·  activity timestamp 3 weeks ago

It's alive! 🧟

After a bit of trial-error, got fediverse comments showing on a #nextjs site running #fedify. My personal fediverse-connected youtube mirror is now mostly feature complete.
(The video post in the screenshot is over here: https://watch.hayes.software/video/16)
#fediverse

Screenshot of a website with a big video player playing a video titled, "Citadel blasting Caramelldansen" Below it is a comment section. The comment field says you can comment on videos by connecting your Mastodon account. The comment section has a single comment, "This is a test comment." Which is a comment I made from mastodon.social that now automagically shows on my video site. Yay!
Screenshot of a website with a big video player playing a video titled, "Citadel blasting Caramelldansen" Below it is a comment section. The comment field says you can comment on videos by connecting your Mastodon account. The comment section has a single comment, "This is a test comment." Which is a comment I made from mastodon.social that now automagically shows on my video site. Yay!
Screenshot of a website with a big video player playing a video titled, "Citadel blasting Caramelldansen" Below it is a comment section. The comment field says you can comment on videos by connecting your Mastodon account. The comment section has a single comment, "This is a test comment." Which is a comment I made from mastodon.social that now automagically shows on my video site. Yay!
  • Copy link
  • Flag this post
  • Block
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp last month

One year with Next.js App Router and why we're moving on

https://paperclover.net/blog/webdev/one-year-next-app-router

#HackerNews #NextJS #AppRouter #movingOn #webDevelopment #techTrends #developerJourney

One Year with Next.js App Router — Why We're Moving On
One Year with Next.js App Router — Why We're Moving On
One Year with Next.js App Router — Why We're Moving On
  • Copy link
  • Flag this post
  • Block
omi fan :miyagi: 🐟⁂ boosted
The New Oil
@thenewoil@mastodon.thenewoil.org  ·  activity timestamp 2 months ago

#Filen: We’re #hiring: #Frontend Developer – Web Platform ( #React + #Nextjs) (m/f/d)

https://filen.io/hub/were-hiring-frontend-developer-web-platform-react-next-js-m-f-d/

#GetFediHired #privacy #cybersecurity #FOSS

Filen Hub

We’re hiring: Frontend Developer – Web Platform (React + Next.js) (m/f/d)

(20 hrs per week preferred · up to 40 hrs possible · 0-100% remote · flexible hours) Hi there, At Filen, we’re steadily expanding to keep up with our product’s growth. After welcoming a new developer for our mobile app, our next step is to strengthen the web platform. We’re
  • Copy link
  • Flag this post
  • Block
The New Oil
@thenewoil@mastodon.thenewoil.org  ·  activity timestamp 2 months ago

#Filen: We’re #hiring: #Frontend Developer – Web Platform ( #React + #Nextjs) (m/f/d)

https://filen.io/hub/were-hiring-frontend-developer-web-platform-react-next-js-m-f-d/

#GetFediHired #privacy #cybersecurity #FOSS

Filen Hub

We’re hiring: Frontend Developer – Web Platform (React + Next.js) (m/f/d)

(20 hrs per week preferred · up to 40 hrs possible · 0-100% remote · flexible hours) Hi there, At Filen, we’re steadily expanding to keep up with our product’s growth. After welcoming a new developer for our mobile app, our next step is to strengthen the web platform. We’re
  • Copy link
  • Flag this post
  • Block
wakest ⁂ boosted
scy
@scy@chaos.social  ·  activity timestamp last year

The CEO of #Vercel welcomes President Trump.

https://x.com/rauchg/status/1854206133776388461 (Twitter link)

Vercel also maintains #NextJS.

X (formerly Twitter)
View
  • Copy link
  • Flag this post
  • Block
jbz boosted
jbz
@jbz@indieweb.social  ·  activity timestamp 2 months ago

no_nazi Just in case you still liked Rauch despite being a serial grifter

#nextjs #vercel #genocide #israel

Tweet from Rauchg, with a selfie taken next to war criminal Netanyahu: 

Enjoyed my discussion with PM Netanyahu on how AI education and literacy will keep our free societies ahead.

We spoke about AI empowering everyone to build software and the importance of ensuring it serves quality and progress.

Optimistic for peace, safety, and greatness for Israel and its neighbors.
Tweet from Rauchg, with a selfie taken next to war criminal Netanyahu: Enjoyed my discussion with PM Netanyahu on how AI education and literacy will keep our free societies ahead. We spoke about AI empowering everyone to build software and the importance of ensuring it serves quality and progress. Optimistic for peace, safety, and greatness for Israel and its neighbors.
Tweet from Rauchg, with a selfie taken next to war criminal Netanyahu: Enjoyed my discussion with PM Netanyahu on how AI education and literacy will keep our free societies ahead. We spoke about AI empowering everyone to build software and the importance of ensuring it serves quality and progress. Optimistic for peace, safety, and greatness for Israel and its neighbors.
  • Copy link
  • Flag this post
  • Block
Hostvix
@stacksize@mastodon.social  ·  activity timestamp 2 months ago

👀 Vercel + Next.js are in the hot seat.

CEO Guillermo Rauch posted about meeting Netanyahu → dev backlash, boycott calls, Paul Graham weighing in, and rivals like Replit offering migration paths.

Reminder: Next.js is MIT, you don’t need Vercel hosting. Options exist.

https://dropletdrift.com/vercel-and-next-js-facing-pushback-after-ceo-cozies-up-to-netanyahu/

#nextjs #vercel #react #webdev #frontend #javascript #opensource #developer #coding #tech #software #devcommunity #startup #framework #programming #cloud #hosting #migration #remix #sveltekit #astro

  • Copy link
  • Flag this post
  • Block
jbz
@jbz@indieweb.social  ·  activity timestamp 2 months ago

no_nazi Just in case you still liked Rauch despite being a serial grifter

#nextjs #vercel #genocide #israel

Tweet from Rauchg, with a selfie taken next to war criminal Netanyahu: 

Enjoyed my discussion with PM Netanyahu on how AI education and literacy will keep our free societies ahead.

We spoke about AI empowering everyone to build software and the importance of ensuring it serves quality and progress.

Optimistic for peace, safety, and greatness for Israel and its neighbors.
Tweet from Rauchg, with a selfie taken next to war criminal Netanyahu: Enjoyed my discussion with PM Netanyahu on how AI education and literacy will keep our free societies ahead. We spoke about AI empowering everyone to build software and the importance of ensuring it serves quality and progress. Optimistic for peace, safety, and greatness for Israel and its neighbors.
Tweet from Rauchg, with a selfie taken next to war criminal Netanyahu: Enjoyed my discussion with PM Netanyahu on how AI education and literacy will keep our free societies ahead. We spoke about AI empowering everyone to build software and the importance of ensuring it serves quality and progress. Optimistic for peace, safety, and greatness for Israel and its neighbors.
  • Copy link
  • Flag this post
  • Block
Hostvix
@stacksize@mastodon.social  ·  activity timestamp 2 months ago

Thinking about moving off Vercel? 🚀

I wrote a deep-dive guide on the best hosting alternatives for web devs in 2025 — costs, trade-offs, and my real migration lessons.

👉 https://dropletdrift.com/the-best-vercel-hosting-alternatives-for-web-developers/

#webdev #developer #coding #programming #javascript #nextjs #react #frontend #backend #fullstack #hosting #cloud #serverless #opensource #startup #software #tech #devlife #digitalocean #netlify #vercel #render #flyio #aws #gcp #azure #paas #saas #infrastructure #deployment #docker

  • Copy link
  • Flag this post
  • Block
Michael Downey 🧢 boosted
thegrumpyenby
@thegrumpyenby@tenforward.social  ·  activity timestamp 4 months ago

♻️ Please boost! ♻️

Looking for frontend devs for volunteer open-source team at a humanitarian aid org! As a Frontend Developer at Distribute Aid (https://distributeaid.org), you’ll create new pages for our website and update/maintain existing ones, often working closely with our designers and other devs. Looking for mid/long-term commitment. Main goal is to finally get our website relaunched. Volunteer commitment is ~5h/week.

Stack: NextJS, TypeScript, Strapi, Radix UI

We’re looking for experienced devs who are reliable, organised, and can communicate well. You do not need to know the full stack you’ll be working with. You just need to know how to learn and ask for help if you need it. Previous open source experience is nice but not strictly necessary. If you learn quickly and willingly, we can help you get started

It would be good if you have some availability overlapping with Central European Time and can make it to at least 1x tech hang per month and 1x sprint meeting per quarter (that’s ~4 meetings a month)

Our tech hangs are every Wednesday and Thursday from 6 to 8 pm CET/CEST and sprint meetings are during tech hang on the first Wednesday of each month

Our tech team is international and diverse—most of our team members are in some way marginalised—and leadership is fully queer/trans.

If you’re interested, please get in touch via tech@distributeaid.org. That comes directly to me as the Technical Program Manager. If you have any questions, you can ask me here too :)

#Developers #frontendDevs #frontend#OSS#FOSS #volunteering#NextJS #typescript#Strapi

Join Distribute Aid’s Open-Source Tech Team

Volunteer your time & skills to work on our new website

We’re looking for experienced frontend devs who want to work in a distributed & diverse open-source tech team!

- Stack: NextJS, TypeScript, Strapi, Radix UI
- Volunteer commitment: ~5h/week
- Work in a team: Collaborate at our weekly tech hangs
- Monthly sprint meetings: join at least 1x/quarter
- Some availability overlapping with Central European Time is ideal
- Previous OSS experience helpful but not strictly necessary

Reach out to tech@distributaid.org (with your GitHub handle) if you’re interested!
Join Distribute Aid’s Open-Source Tech Team Volunteer your time & skills to work on our new website We’re looking for experienced frontend devs who want to work in a distributed & diverse open-source tech team! - Stack: NextJS, TypeScript, Strapi, Radix UI - Volunteer commitment: ~5h/week - Work in a team: Collaborate at our weekly tech hangs - Monthly sprint meetings: join at least 1x/quarter - Some availability overlapping with Central European Time is ideal - Previous OSS experience helpful but not strictly necessary Reach out to tech@distributaid.org (with your GitHub handle) if you’re interested!
Join Distribute Aid’s Open-Source Tech Team Volunteer your time & skills to work on our new website We’re looking for experienced frontend devs who want to work in a distributed & diverse open-source tech team! - Stack: NextJS, TypeScript, Strapi, Radix UI - Volunteer commitment: ~5h/week - Work in a team: Collaborate at our weekly tech hangs - Monthly sprint meetings: join at least 1x/quarter - Some availability overlapping with Central European Time is ideal - Previous OSS experience helpful but not strictly necessary Reach out to tech@distributaid.org (with your GitHub handle) if you’re interested!
  • Copy link
  • Flag this post
  • Block
thegrumpyenby
@thegrumpyenby@tenforward.social  ·  activity timestamp 4 months ago

♻️ Please boost! ♻️

Looking for frontend devs for volunteer open-source team at a humanitarian aid org! As a Frontend Developer at Distribute Aid (https://distributeaid.org), you’ll create new pages for our website and update/maintain existing ones, often working closely with our designers and other devs. Looking for mid/long-term commitment. Main goal is to finally get our website relaunched. Volunteer commitment is ~5h/week.

Stack: NextJS, TypeScript, Strapi, Radix UI

We’re looking for experienced devs who are reliable, organised, and can communicate well. You do not need to know the full stack you’ll be working with. You just need to know how to learn and ask for help if you need it. Previous open source experience is nice but not strictly necessary. If you learn quickly and willingly, we can help you get started

It would be good if you have some availability overlapping with Central European Time and can make it to at least 1x tech hang per month and 1x sprint meeting per quarter (that’s ~4 meetings a month)

Our tech hangs are every Wednesday and Thursday from 6 to 8 pm CET/CEST and sprint meetings are during tech hang on the first Wednesday of each month

Our tech team is international and diverse—most of our team members are in some way marginalised—and leadership is fully queer/trans.

If you’re interested, please get in touch via tech@distributeaid.org. That comes directly to me as the Technical Program Manager. If you have any questions, you can ask me here too :)

#Developers #frontendDevs #frontend#OSS#FOSS #volunteering#NextJS #typescript#Strapi

Join Distribute Aid’s Open-Source Tech Team

Volunteer your time & skills to work on our new website

We’re looking for experienced frontend devs who want to work in a distributed & diverse open-source tech team!

- Stack: NextJS, TypeScript, Strapi, Radix UI
- Volunteer commitment: ~5h/week
- Work in a team: Collaborate at our weekly tech hangs
- Monthly sprint meetings: join at least 1x/quarter
- Some availability overlapping with Central European Time is ideal
- Previous OSS experience helpful but not strictly necessary

Reach out to tech@distributaid.org (with your GitHub handle) if you’re interested!
Join Distribute Aid’s Open-Source Tech Team Volunteer your time & skills to work on our new website We’re looking for experienced frontend devs who want to work in a distributed & diverse open-source tech team! - Stack: NextJS, TypeScript, Strapi, Radix UI - Volunteer commitment: ~5h/week - Work in a team: Collaborate at our weekly tech hangs - Monthly sprint meetings: join at least 1x/quarter - Some availability overlapping with Central European Time is ideal - Previous OSS experience helpful but not strictly necessary Reach out to tech@distributaid.org (with your GitHub handle) if you’re interested!
Join Distribute Aid’s Open-Source Tech Team Volunteer your time & skills to work on our new website We’re looking for experienced frontend devs who want to work in a distributed & diverse open-source tech team! - Stack: NextJS, TypeScript, Strapi, Radix UI - Volunteer commitment: ~5h/week - Work in a team: Collaborate at our weekly tech hangs - Monthly sprint meetings: join at least 1x/quarter - Some availability overlapping with Central European Time is ideal - Previous OSS experience helpful but not strictly necessary Reach out to tech@distributaid.org (with your GitHub handle) if you’re interested!
  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login