DeepSeek-V4-Flash means LLM steering is interesting again https://lobste.rs/s/wycfiy #vibecoding
https://www.seangoedecke.com/steering-vectors/

seangoedecke.com


@hongminhee@hollo.social
1,074 following1,882 followers
An intersectionalist, feminist, and socialist living in Seoul (UTC+09:00). @tokolovesme's spouse. Who's behind @fedify, @hollo, and @botkit. Write some free software in #TypeScript, #Haskell, #Rust, & #Python. They/them.
서울에 사는 交叉女性主義者이자 社會主義者. 金剛兔(@tokolovesme)의 配偶者. @fedify, @hollo, @botkit 메인테이너. #TypeScript, #Haskell, #Rust, #Python 等으로 自由 소프트웨어 만듦.
DeepSeek-V4-Flash means LLM steering is interesting again https://lobste.rs/s/wycfiy #vibecoding
https://www.seangoedecke.com/steering-vectors/

seangoedecke.com
I'm getting closer to something showable on my side project, a recipe and baking app, #federated with #ActivityPub, https://cookifed.dev.
I'm not ready to accept new users yet, but @dmathieu@cuisine.social is the first ever #cookifed federated account!
cookifed.dev
We are still getting started. But if the promise sounds interesting to you, feel free to get in touch
Thank you @hongminhee@hollo.social for sponsoring me on github. You can join them at my sponsors profile: https://github.com/sponsors/SJang1?o=nsm&sc=t
github.com
Support SJang1's open source work
갑자기 @siliconsjang 님이 서울 올라오셔서 같이 又來屋 왔음…!
We just released Bonfire Social 1.0.3 🔥
Blog post with all the details: bonfirenetworks.org/posts/bo...
It comes with dozens of bug fixes and UX improvements, plus:
#CalmEmpowerment: a new design pattern that starts with a few sensible defaults, offers a middle layer of common adjustments, and reveals the full options only when you need them. Boundaries and post permissions got this treatment first, more to follow...
Modular community rules: a first step in bringing research and co-design with students and researchers at @hci@micro.blogs.princeton.edu into Bonfire, so governance becomes something communities can better define and share, and that others can fork and adapt.
bonfire.cafe
A space for Bonfire maintainers and contributors to communicate
Hollo 0.8.0 shipped less than a month ago, and 0.9.0 is already shaping up to be a bigger release than I expected. New frontend design, Passkey support, WebFinger domain separation, a media proxy, full FEP-044f (Mastodon-style quote posts) compliance, and Traditional Chinese docs. More details when it's out.
w3id.org
Hollo 0.8.0 shipped less than a month ago, and 0.9.0 is already shaping up to be a bigger release than I expected. New frontend design, Passkey support, WebFinger domain separation, a media proxy, full FEP-044f (Mastodon-style quote posts) compliance, and Traditional Chinese docs. More details when it's out.
w3id.org
Hollo 0.8.0 shipped less than a month ago, and 0.9.0 is already shaping up to be a bigger release than I expected. New frontend design, Passkey support, WebFinger domain separation, a media proxy, full FEP-044f (Mastodon-style quote posts) compliance, and Traditional Chinese docs. More details when it's out.
w3id.org
@cheeaun Is there any particular reason you're using vanilla npm instead of pnpm? I use pnpm, and I didn't have any issues at all in the same situation.
@liaizon Yeah, it's so-called Misskey-style quotes, and as far as I know, Pleroma/Akkoma also implements this style of quotes!
@liaizon That's probably because Hackers' Pub doesn't implement FEP-044f (Mastodon-style quotes) yet… I'll implement it soon!
w3id.org
知り合いの @siliconsjang さんが今日、SiliconBeest v1.0.0 を公開しました。Cloudflare Workers、D1、R2、Queuesだけで動くフェディバースサーバーで、Fedifyを使ってくれています。
個人的に面白いと思ったのは出発点で、Cloudflare障害のたびにフェディバースのサーバーがまとめて落ちるのを見て、「それならいっそCloudflareの上で動かせばよいのでは」と思ったのが始まりだそうです。
小規模なインスタンスならCloudflareの無料プランで、少し大きくなっても月5ドルくらいで運営できることを目指しているとのこと。まだ初期バージョンなので未実装の部分も多く、MastodonやMisskey APIとの互換性は未だ先の目標みたいです。
Fedifyを使ってくれているのもあって、個人的に嬉しいです。気になったので共有します。
ソースコードはAGPL 3.0でGitHubで公開されています。
github.com
Fediverse in Cloudflare Workers + live serverless code - SJang1/siliconbeest
안녕하세요! Hello everyone!
마스토돈 API 호환을 목표로 하는 Cloudflare 엣지 컴퓨팅 기반 서버리스 연합우주 소프트웨어, SiliconBeest v1.0.0을 공개하게 되어 기쁩니다.
I'm pleased to announce SiliconBeest v1.0.0, a serverless fediverse software project built on Cloudflare edge computing, aiming for Mastodon API compatibility.

아직은 초기 버전이라 구현되지 않은 부분도 많지만, Cloudflare Workers, D1, R2, Queues 등 Cloudflare의 서버리스 인프라 위에서 연합우주 소프트웨어를 얼마나 가볍고 저렴하게 운영할 수 있는지 실험하고 있습니다.
This is still an early version, and many parts are not implemented yet. However, SiliconBeest is an experiment in how lightweight and affordable fediverse software can be when built on top of Cloudflare’s serverless infrastructure, such as Workers, D1, R2, and Queues.
현재 v1.0.0에서는 기본적인 구조와 핵심 기능을 먼저 정리하는 데 집중했으며, 앞으로 Mastodon API 호환성, federation 안정성, 관리 도구, 문서화 등을 점진적으로 개선해나갈 예정입니다.
In v1.0.0, I focused on organizing the basic architecture and core functionality first. Going forward, I plan to gradually improve Mastodon API compatibility, federation stability, admin tooling, and documentation.
관심 있으신 분들은 GitHub 저장소를 확인해주시고, 이슈나 피드백도 언제든 환영합니다.
If you’re interested, please check out the GitHub repository. Issues, feedback, and suggestions are always welcome.
https://github.com/SJang1/siliconbeest
SiliconBeest는 GitHub 템플릿과 Cloudflare를 이용해 비교적 간단하게 배포할 수 있습니다.
아직 설치 과정은 계속 다듬고 있으며, 개선사항이 많음을 알고 있습니다. 추후 보강해 나갈 예정이며, 이에 대한 PR도 환영입니다.
SiliconBeest can be deployed relatively easily using a GitHub template and Cloudflare.
The installation process is still being refined, and I’m aware that there is plenty of room for improvement. I plan to keep improving the documentation and deployment flow over time, and related PRs are always welcome.
知人인 @siliconsjang 님이 오늘 SiliconBeest v1.0.0을 公開했습니다. Fedify와 Cloudflare를 基盤으로 만든 #聯合宇宙 소프트웨어인데, Workers, D1, R2, Queues 등 #Cloudflare 서버리스 스택 위에서 全部 돌아갑니다.
發想의 出發點이 재밌습니다. Cloudflare 障礙 때 聯合宇宙 서버들이 덩달아 다운되는 걸 보고, 「그럼 아예 Cloudflare 위에서 돌리면 되지 않나?」라는 생각에서 始作했다고 하네요.
費用 面에서는 小規模 인스턴스는 Cloudflare 無料 플랜, 조금 더 큰 規模는 月 $5 플랜으로 堪當할 수 있도록 하는 게 目標라고 합니다. 아직 初期 버전이라 未具顯 機能이 많고, Mastodon 및 Misskey API 互換은 長期 目標로 보고 있다네요.
Fedify를 써주시는 분이라 반갑기도 하고, 應援하고 싶어 紹介합니다.
소스 코드는 AGPL 3.0으로 GitHub에 공개되어 있습니다.
github.com
Fediverse in Cloudflare Workers + live serverless code - SJang1/siliconbeest
안녕하세요! Hello everyone!
마스토돈 API 호환을 목표로 하는 Cloudflare 엣지 컴퓨팅 기반 서버리스 연합우주 소프트웨어, SiliconBeest v1.0.0을 공개하게 되어 기쁩니다.
I'm pleased to announce SiliconBeest v1.0.0, a serverless fediverse software project built on Cloudflare edge computing, aiming for Mastodon API compatibility.

아직은 초기 버전이라 구현되지 않은 부분도 많지만, Cloudflare Workers, D1, R2, Queues 등 Cloudflare의 서버리스 인프라 위에서 연합우주 소프트웨어를 얼마나 가볍고 저렴하게 운영할 수 있는지 실험하고 있습니다.
This is still an early version, and many parts are not implemented yet. However, SiliconBeest is an experiment in how lightweight and affordable fediverse software can be when built on top of Cloudflare’s serverless infrastructure, such as Workers, D1, R2, and Queues.
현재 v1.0.0에서는 기본적인 구조와 핵심 기능을 먼저 정리하는 데 집중했으며, 앞으로 Mastodon API 호환성, federation 안정성, 관리 도구, 문서화 등을 점진적으로 개선해나갈 예정입니다.
In v1.0.0, I focused on organizing the basic architecture and core functionality first. Going forward, I plan to gradually improve Mastodon API compatibility, federation stability, admin tooling, and documentation.
관심 있으신 분들은 GitHub 저장소를 확인해주시고, 이슈나 피드백도 언제든 환영합니다.
If you’re interested, please check out the GitHub repository. Issues, feedback, and suggestions are always welcome.
https://github.com/SJang1/siliconbeest
SiliconBeest는 GitHub 템플릿과 Cloudflare를 이용해 비교적 간단하게 배포할 수 있습니다.
아직 설치 과정은 계속 다듬고 있으며, 개선사항이 많음을 알고 있습니다. 추후 보강해 나갈 예정이며, 이에 대한 PR도 환영입니다.
SiliconBeest can be deployed relatively easily using a GitHub template and Cloudflare.
The installation process is still being refined, and I’m aware that there is plenty of room for improvement. I plan to keep improving the documentation and deployment flow over time, and related PRs are always welcome.
A friend of mine, @siliconsjang, released SiliconBeest v1.0.0 today. It's a #fediverse server built on #Cloudflare Workers, D1, R2, and Queues, using Fedify.
I like the starting point: after watching fediverse servers go down together during Cloudflare outages, they thought, why not just run on Cloudflare directly?
They're aiming for something cheap enough that a small instance can stay on Cloudflare's free plan, and a somewhat bigger one can fit in the $5/month tier. It's still early; a lot is missing, and Mastodon/Misskey API compatibility is more of a long-term goal.
I'm glad to see Fedify put to use for something like this. Worth checking out.
The source code is on GitHub under AGPL 3.0.
github.com
Fediverse in Cloudflare Workers + live serverless code - SJang1/siliconbeest
안녕하세요! Hello everyone!
마스토돈 API 호환을 목표로 하는 Cloudflare 엣지 컴퓨팅 기반 서버리스 연합우주 소프트웨어, SiliconBeest v1.0.0을 공개하게 되어 기쁩니다.
I'm pleased to announce SiliconBeest v1.0.0, a serverless fediverse software project built on Cloudflare edge computing, aiming for Mastodon API compatibility.

아직은 초기 버전이라 구현되지 않은 부분도 많지만, Cloudflare Workers, D1, R2, Queues 등 Cloudflare의 서버리스 인프라 위에서 연합우주 소프트웨어를 얼마나 가볍고 저렴하게 운영할 수 있는지 실험하고 있습니다.
This is still an early version, and many parts are not implemented yet. However, SiliconBeest is an experiment in how lightweight and affordable fediverse software can be when built on top of Cloudflare’s serverless infrastructure, such as Workers, D1, R2, and Queues.
현재 v1.0.0에서는 기본적인 구조와 핵심 기능을 먼저 정리하는 데 집중했으며, 앞으로 Mastodon API 호환성, federation 안정성, 관리 도구, 문서화 등을 점진적으로 개선해나갈 예정입니다.
In v1.0.0, I focused on organizing the basic architecture and core functionality first. Going forward, I plan to gradually improve Mastodon API compatibility, federation stability, admin tooling, and documentation.
관심 있으신 분들은 GitHub 저장소를 확인해주시고, 이슈나 피드백도 언제든 환영합니다.
If you’re interested, please check out the GitHub repository. Issues, feedback, and suggestions are always welcome.
https://github.com/SJang1/siliconbeest
SiliconBeest는 GitHub 템플릿과 Cloudflare를 이용해 비교적 간단하게 배포할 수 있습니다.
아직 설치 과정은 계속 다듬고 있으며, 개선사항이 많음을 알고 있습니다. 추후 보강해 나갈 예정이며, 이에 대한 PR도 환영입니다.
SiliconBeest can be deployed relatively easily using a GitHub template and Cloudflare.
The installation process is still being refined, and I’m aware that there is plenty of room for improvement. I plan to keep improving the documentation and deployment flow over time, and related PRs are always welcome.
안녕하세요! Hello everyone!
마스토돈 API 호환을 목표로 하는 Cloudflare 엣지 컴퓨팅 기반 서버리스 연합우주 소프트웨어, SiliconBeest v1.0.0을 공개하게 되어 기쁩니다.
I'm pleased to announce SiliconBeest v1.0.0, a serverless fediverse software project built on Cloudflare edge computing, aiming for Mastodon API compatibility.

아직은 초기 버전이라 구현되지 않은 부분도 많지만, Cloudflare Workers, D1, R2, Queues 등 Cloudflare의 서버리스 인프라 위에서 연합우주 소프트웨어를 얼마나 가볍고 저렴하게 운영할 수 있는지 실험하고 있습니다.
This is still an early version, and many parts are not implemented yet. However, SiliconBeest is an experiment in how lightweight and affordable fediverse software can be when built on top of Cloudflare’s serverless infrastructure, such as Workers, D1, R2, and Queues.
현재 v1.0.0에서는 기본적인 구조와 핵심 기능을 먼저 정리하는 데 집중했으며, 앞으로 Mastodon API 호환성, federation 안정성, 관리 도구, 문서화 등을 점진적으로 개선해나갈 예정입니다.
In v1.0.0, I focused on organizing the basic architecture and core functionality first. Going forward, I plan to gradually improve Mastodon API compatibility, federation stability, admin tooling, and documentation.
관심 있으신 분들은 GitHub 저장소를 확인해주시고, 이슈나 피드백도 언제든 환영합니다.
If you’re interested, please check out the GitHub repository. Issues, feedback, and suggestions are always welcome.
https://github.com/SJang1/siliconbeest
SiliconBeest는 GitHub 템플릿과 Cloudflare를 이용해 비교적 간단하게 배포할 수 있습니다.
아직 설치 과정은 계속 다듬고 있으며, 개선사항이 많음을 알고 있습니다. 추후 보강해 나갈 예정이며, 이에 대한 PR도 환영입니다.
SiliconBeest can be deployed relatively easily using a GitHub template and Cloudflare.
The installation process is still being refined, and I’m aware that there is plenty of room for improvement. I plan to keep improving the documentation and deployment flow over time, and related PRs are always welcome.
Today I gave a guest lecture at KAIST CS350 Introduction to Software Engineering. Slides are up.
Nobody's job, everybody's problem: F/OSS in the age of AI: F/OSS basics, the commons problem, how maintainers get funded, and how projects like Zig, Ghostty, and Fedify are handling AI contributions differently.

hongminhee.codeberg.page
"A guest lecture for KAIST CS350 Introduction to Software Engineering.\n\nMost CS students use free/open source software every day. Fewer have seen\nwhat happens after a project has users, bug reports, security expectations,\nand downstreams.\n\nThe first half looks at why engineers choose free/open source software, why\nshared infrastructure often has no clear owner, and how maintainers pay for\nthe work. The second half turns to AI-generated code, using contribution\npolicies from Zig, Ghostty, and Fedify to show how maintainers are\nresponding.\n"
I finally deleted #Threads recently because their algorithm is annoying, they gave up on #fediverse support, and their app is loaded with UX dark patterns.
I still use #Instagram because the people I meet in person do, and organizing https://photostroll.nyc kinda requires it.
Fedi is the only place I really feel good about posting on, because I know where data lives and how it's distributed, it's community-run, and usually it's by the type of people I'd want running my virtual social space.

photostroll.nyc
A meetup for and by the NYC-area photography community.
과학기술정보통신부 및 정보통신산업진흥원(NIPA)에서 주최하는 오픈 소스 컨트리뷰션 아카데미 (OSSCA) 참여형 프로그램 멘티를 모집합니다. OSSCA는 평소 오픈 소스에 관심은 있었지만 어떻게 참여해야 할 지 막막하셨던 분들께 몇 개월에 걸쳐 구체적으로 참여하는 요령을 알려드리는 프로그램입니다. 실제로 이 과정을 계기로 오픈 소스 프로젝트의 메인테이너들과 교류하게 되고, 본격적으로 오픈 소스 기여를 시작하게 되는 분들도 많습니다.
저희 Fedify 프로젝트도 작년에 이어 올해도 OSSCA에서 만나보실 수 있는데요, 작년에 멘티셨던 권지원 님(@z9mb1), 이재열 님(@kodingwarrior), 이찬행 님(@2chanhaeng)이 저와 함께 멘토로 참여하게 되었습니다. 세 분 모두 작년 OSSCA를 통해 Fedify에 본격적으로 참여하게 된 케이스입니다. 여러분도 이런 식으로 평소 관심만 있던 오픈 소스에 실제로 기여도 하고, 아예 본격적으로 참여하실 수도 있습니다.
제가 멘토라서 하는 얘기가 아니라, 정말 좋은 기회라고 생각합니다. 학생·직장인 무관하게 지원 가능하니, 관심 있는 분들의 많은 참여 부탁드립니다! → 참가 신청
open-up-kr.typeform.com
접수기간: ~2026.06.14(일) 까지
So, Fedify returns a string and delegates the decision to the user?
Yes, more accurately, it returns a URL object which is a scalar value.

developer.mozilla.org
The URL interface is used to parse, construct, normalize, and encode URLs. It works by providing properties which allow you to easily read and modify the components of a URL.
If you use BotKit, update to a patched release now. A private network protection bypass affects Fedify's remote document loading code, and it also affects BotKit which depends on Fedify.
The validatePublicUrl() function in Fedify, which ensures resources aren't fetched from private or loopback addresses, failed to correctly identify certain IPv6 literals. Specifically, URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals (e.g., http://[::ffff:127.0.0.1]/) could bypass the check.
This vulnerability could allow an attacker to provide a malicious URL that bypasses security checks, potentially allowing them to make the bot fetch internal resources or interact with services on the private network that should not be accessible from the public internet.
All versions of BotKit up to 0.3.1 (in the 0.3.x branch) and 0.4.0 (in the 0.4.x branch) are affected. Patched releases are 0.3.2 and 0.4.1.
For BotKit 0.4.x, update @fedify/botkit:
npm update @fedify/botkit
yarn upgrade @fedify/botkit
pnpm update @fedify/botkit
bun update @fedify/botkit
deno update @fedify/botkitFor BotKit 0.3.x, update @fedify/botkit:
npm update @fedify/botkit@0.3.2
yarn upgrade @fedify/botkit@0.3.2
pnpm update @fedify/botkit@0.3.2
bun update @fedify/botkit@0.3.2
deno update @fedify/botkit@0.3.2If you use other BotKit-related packages (e.g., @fedify/botkit-sqlite), update them as well. After updating, redeploy.
Thanks to Changkyun Kim (@me) for the report and responsible disclosure.
If anything is unclear, feel free to ask on GitHub Discussions or Matrix.
matrix.to
You're invited to talk on Matrix
the 90 day disclosure policy is dead https://lobste.rs/s/qxkdgl #security
https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/
blog.himanshuanand.com
TLDR The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyone else paying attention. This post lays out why the old model is broken, with real stories, and makes one ask to the industry: treat every critical security issue as P0 and patch it immediately.
Mythos finds a curl vulnerability via @andrewnez https://lobste.rs/s/am7evd #ai #security
https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

daniel.haxx.se
yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →
If you run Hollo, update to a patched release now. A private network protection bypass in Fedify, the ActivityPub framework Hollo depends on, affects remote document loading. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such as http://[::ffff:7f00:1]/, could pass URL validation even though they refer to private or loopback addresses.
Hollo uses Fedify to fetch remote ActivityPub documents and related resources. An attacker who can make your Hollo instance fetch an attacker-controlled URL may be able to bypass the private address checks that are intended to reduce SSRF (Server-Side Request Forgery) risk.
All Hollo versions up to and including 0.7.14 and 0.8.2 are affected. Patched releases are 0.7.15 for the 0.7.x series and 0.8.3 for the 0.8.x series. For full technical details of the underlying vulnerability, see the Fedify security announcement.
For 0.7.x deployments, update to 0.7.15:
docker pull ghcr.io/fedify-dev/hollo:0.7.15For 0.8.x deployments, update to 0.8.3:
docker pull ghcr.io/fedify-dev/hollo:0.8.3After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart.
Thanks to Changkyun Kim (@me) for the report and responsible disclosure to the Fedify project.
If anything is unclear, ask below.
Released on May 10, 2026. Upgraded Fedify to 2.1.12 to fix a critical SSRF (Server-Side Request Forgery) vulnerability where private IPv4 addresses encoded as IPv6 literals could bypass security c...
If you use Fedify, update to a patched release now. A private network protection bypass affects Fedify's remote document loading code. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such as http://[::ffff:7f00:1]/, could pass validatePublicUrl() even though they refer to private or loopback addresses.
Fedify uses validatePublicUrl() when fetching remote ActivityPub documents and related resources. An attacker who can make a Fedify server fetch an attacker-controlled URL may be able to bypass the private address checks that are intended to reduce SSRF risk.
All versions up to and including 2.2.0 are affected. Patched releases are 1.9.10, 1.10.9, 2.0.16, 2.1.12, and 2.2.1.
For Fedify 1.x, update @fedify/fedify:
npm update @fedify/fedify
yarn upgrade @fedify/fedify
pnpm update @fedify/fedify
bun update @fedify/fedify
deno update @fedify/fedify
For Fedify 2.x, update both @fedify/fedify and @fedify/vocab-runtime:
npm update @fedify/fedify @fedify/vocab-runtime
yarn upgrade @fedify/fedify @fedify/vocab-runtime
pnpm update @fedify/fedify @fedify/vocab-runtime
bun update @fedify/fedify @fedify/vocab-runtime
deno update @fedify/fedify @fedify/vocab-runtime
After updating, redeploy. If you run other Fedify-based servers, update those too.
Thanks to Changkyun Kim (@me) for the report and responsible disclosure.
If anything is unclear, ask below.
Released on May 10, 2026. @fedify/vocab-runtime Fixed validatePublicUrl() allowing private IPv4 addresses encoded as IPv4-mapped IPv6 URL literals, such as http://[::ffff:7f00:1]/, which could byp...
@kodingwarrior 떡볶이를 또 드셨다고요…!?
I'm here at PyCon Busan 2026! I'm manning the Hackers' Pub community booth with @kodingwarrior and @2chanhaeng. Stop by and we'll give you some Hackers' Pub stickers!
파이콘 부산 2026에 왔습니다! @kodingwarrior 님, @2chanhaeng 님과 함께 Hackers' Pub 커뮤니티 부스 자리를 지키고 있습니다. 방문해 주시면 Hackers' Pub 스티커를 나눠드립니다!