Sidebar
Resources I use:
- Liberation Toolbox by YK Hong (paywalled site)
- Where's Your Ed At by Ed Zitron
- Pluralistic by Cory Doctorow
- Addie LaMarr on Instagram and YouTube
- Good Work by Dan Toomey and Morning Brew
- 404 Media
- Casual Finance on YouTube and Instagram
- Simon Willison's Weblog
Posts tagged with "security"
Mitigating supply chain attacks with package cooldowns
2026-08-25 / tags: guides, quick reads, security, technical
Software developers and the libraries and applications they write are prime targets for attackers seeking to grab all sorts of valuable prizes: cloud service credentials, downstream users, cryptocurrency wallet keys, networks of all kinds... the list goes on and on. As such, software supply chain attacks have been ramping up for the past several years, and they're now reaching a fever pitch. I can't recall a month of this year I didn't read about a popular software library getting compromised, leading to downstream libraries and applications being accessed by the attacker in turn.
Fear not, though! Waiting to use new versions of software packages for a time after they are published can help avoid getting pwned by a supply chain attack. Updates to dependency management tools for a variety of programming languages allow this to happen automatically as part of regular dependency updates, meaning this protection doesn't come at the expense of a smooth workflow.
Cooldowns.dev is a cool[1] reference website that details how to configure various package managers to include cooldowns. As of writing, it's got instructions for over a dozen package managers supporting six language ecosystems, and because its source is hosted on GitHub and open to pull requests, it can get updates for new functionality quickly.
That's all for this post. Check out Cooldowns.dev when you want to add a quick, easy, and effective mitigation to protect yourself and your projects from supply chain attacks!
-
I will never apologize. Never! ↩
Out, damned WordPress!
2026-08-10 / tags: ai, housekeeping, projects, quick reads, security, sidebar updates
Scenes from my inbox over the past month:
July 10th: [Constance Bello's Blog] Your site has been updated to WordPress 7.0.1
July 17th: [Constance Bello's Blog] Your site has been updated to WordPress 7.0.2
August 6th: [Constance Bello's Blog] Your site has been updated to WordPress 7.0.3
I had my blog running on a managed WordPress site run by May First, a technology cooperative I'm a member of – and their staff have been busy. I'm far from the only person having to deal with frequent updates for my software of late. And WordPress is far from the only affected software. Though 7.0.1 was a maintenance release to follow up on non-security bugs from 7.0 a month and a half prior, 7.0.2 and 7.0.3 fixed critical- and high-severity security bugs that are being discovered at a rapid clip thanks to advances in frontier LLM capability combined with more and more researchers pointing them at software projects, intentionally or not[1]. You may have noticed that your operating system, web browser, or other important software has been needing updates more than usual lately – this is why.
The most secure code is the code that never runs, so I've decided to switch to a static site generator-based website. Instead of a WordPress process running on a server at all times to give you access to my posts, this setup spits out a folder that contains static files that make up the website, which can be served by a variety of service providers and HTTP servers with ease. This trades off a bit of functionality for users (like the ability to comment on posts and subscribe to a mailing list without going to another website) with lots of upside for all parties (better security and a more privacy-respecting posture for users, and the same for me, plus less maintenance overhead and more customizability). If you're interested in all the gory details, I might put out a technical writeup at some point, but for now feel free to look at a mirror of the code.
Personally, my life has been a hot mess the past couple months, between moving (twice... ask me about my Airbnb experience when I was between apartments) and continuing to look for work. I've only recently had time to settle back into projects and getting back to the blog was on top of the proverbial priority queue. I'm bundling that with an update to my #branding; that logo in the top left of the screen[2] is also in my wallet now!

I'm looking forward to giving some of these out at the New Yorker Hotel, where I'll be next weekend for HOPE!
And, as per usual, sidebar additions:
- The Casual Finance YouTube channel tackles the AI bubble from an economics perspective, explaining how fucked everything is in the ✨capital markets✨ that allocate resources in the systems we exist within.
- Simon Willison's Weblog has lots of insights on the day-to-day use of LLMs for software engineering. I resisted for a long time, but I finally bit the bullet and started using LLMs in a very limited way for my projects, with Zed's built-in AI features hooked up to Ollama running models locally. This way, I won't need to worry about what might happen to my model access when the bottom falls out from under OpenAI and Anthropic, since I'm not using any of their tech anyway, and by using open weight models I'm not propping up their business model predicated on extraction.
Until next time, friends...
-
OpenAI was training a model for an internal-only research prototype when it popped open Hugging Face, a platform where users share AI models and datasets, by finding and exploiting multiple zero-day vulnerabilities in software OpenAI's systems use. They held a last-minute talk at Black Hat USA this past Wednesday to disclose some juicy new details (YouTube link) that I haven't had a chance to review yet. ↩
-
It's a bit shy on mobile so the layout can work better. Sorry! ↩