Co-founder of App and Up Srl 👨‍💼 - I work and have fun on web, mobile and anything that involves code

Joined July 2017
124 Photos and videos
Pinned Tweet
I’ve been working successfully with my extensions and widgets experiments for the past few weeks. So I thought I share it with you and get new ideas and suggestions to improve it. 👉 Say hello to Xtended! pub.dev/packages/xtended
2
4
36
3,975
Daniele Cambi retweeted
🚨 How the TanStack npm attack actually happened: 1. Attacker opened a normal-looking pull request (#7378) on the TanStack repo. 2. GitHub automatically ran CI tests on that PR. 3. Code inside the PR stole the workflow's GitHub Actions Cache write token during the test run. 4. The attacker used that token to plant poisoned files in the shared build cache. The PR could be closed afterwards. The poisoned cache stays. 5. The official release workflow later pulled from the cache, baked the malicious files into the build, and signed and published 84 malicious package versions to npm.
This attack leveraged GitHub Actions Cache Poisoning. Payload deployed here: github.com/TanStack/router/p… It looks like it detonated here: github.com/TanStack/router/a…
61
571
4,713
809,130
Daniele Cambi retweeted
Drizzle v1.0.0-rc.1 is out 🚀 ▪︎ Effect v4 native support ▪︎ JIT row mappers to reduce ORM overhead to ~0 ▪︎ Reworked casing API (breaking change) ▪︎ Drizzle for LLM agents (preview) Drizzle is now as fast as using raw driver and mapping(or not mapping) results by hand 🙃
99
173
2,037
375,790
Daniele Cambi retweeted
Apr 19
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin: vercel.com/kb/bulletin/verce…
695
2,360
8,762
10,618,328
Daniele Cambi retweeted
19 Dec 2025
🛡️ React Native Security Rule #6 : AsyncStorage is NOT secure storage. If you save tokens, passwords, or credentials there, you’re storing them in plaintext. On rooted/jailbroken devices, attackers can dump it in seconds. AsyncStorage is fully readable. Treat it as public, not private. Never store: • auth tokens • passwords • API secrets Use instead: • expo-secure-store • react-native-keychain • native Keychain / Keystore
19
47
461
24,976
This is one of the perks that made me switch to expo from flutter to begin with. It’s amazing they now support flutter as well!
1 Nov 2025
Or like... Launch it.. with launch.expo.dev Happy Halloween! 🎃👻
2
1
142
Am I the only one having issues with @supabase right now? Their dashboard comes through with a 404
5
1
233
@Docker is down as well, registry, hub, what is happening? 🫣
320
Looks like the issue is with @vercel since our website is down as well and supabase dashboard is running on it
310
Their status page says it’s all right though status.supabase.com/

67
Daniele Cambi retweeted
16 Oct 2025
To write a blog post, you must first redesign your blog
210
93
2,309
163,579
Daniele Cambi retweeted
i love how software was trending towards being more secure. more sanitizers shipping with clang. more software being written with memory safety in mind. then: vibe coding enters the arena
114
269
5,427
226,405
Daniele Cambi retweeted
15 Aug 2025
Vibe coding is a consequence of inexperienced engineers attempting to overcome their imposter syndrome complexes. AI is a tool that you simply have to use to get the job done. We'll be fine once s*** hits the fan and we have to start doing things the right way again.
i love how software was trending towards being more secure. more sanitizers shipping with clang. more software being written with memory safety in mind. then: vibe coding enters the arena
1
5
367
I’ve been craving this!
Drizzle Studio Gateway is now FREE 🆓 yes, it's free now, free Studio
2
191
Daniele Cambi retweeted
asking chatgpt for 30 minutes just saved me 3 minutes of reading the docs
213
416
6,867
207,982
Daniele Cambi retweeted
29 Jun 2025
This is the tweet that convinced me. MCP is just web3 all over again
once you understand MCP, you never see the internet the same way
231
147
5,422
584,595
Daniele Cambi retweeted
9 Jun 2025
I can't believe is a real image shared by Apple. It's worst implementation of glass UI I've ever seen.
6
2
80
5,190
I don’t love it either, will we get used to it?
this goes in the worst designs hall of fame the more you look at it the more your eyes hurt ...
115
I’m super skeptical about readability. The clear icons are especially bad at that from what we’ve seen at #WWDC25
1
80
Well… they made iOS 18 look old in a few minutes. #WWDC25
1
123
People working on the Cupertino package in #flutter are NOT gonna love this 🙃
34