Intro ååã¯ãNx ã®äºä¾ããã¼ã¹ã«ãããã±ã¼ã¸ãå ¬éããå´ãã®å¯¾çã«ã¤ãã¦è§£èª¬ããã ä»åã¯ããããã±ã¼ã¸ã使ãå´ãããã£ã¨è¨ãã°ãOSS ã使ãä¸ã§éçºè ãèããã¹ããã¨ãã«ã¤ãã¦èå¯ããã OSS ã®å±éºæ§ npm èµ·å ã®ãµãã©ã¤ãã§ã¼ã³æ»æã確èªããããã¨ã§ãnpm ã¯å±éºã ãã¨ãã話ã«ãªãã¨ããnpm ãç¦æ¢ãã¹ããã¨ãã£ã極端ãªè©±ã«ãªã£ããããã ååã®ããã°ã§ç´¹ä»ãããããªå¯¾çãè¡ããªããå¤å°ã¯è¯ããªããããããªãããããããããã¯å ¨ã¦ããã±ã¼ã¸å ¬éè ã«å§ãããããèªåãå ¬éè ã¨ãã¦å®æ½ãããªããèªåãåå ã§æ»æãçºçãããã¨ã¯é²ããã ããã 䏿¹ãæ»æã«å¿ è¦ãªçªç ´å£ã¯ 1 ã¤ããã°è¯ããnpm ã«ããå ¨ã¦ã®ããã±ã¼ã¸ã対çãããªãéããnpm ã主èªã¨ããå®å ¨ãæ ä¿ãããæ¥ã¯æ¥ãªãã ãã®åºå¤§ãªä¾åé¢ä¿ã®ä¸ã«ã¯ãéè½ã¡ããéçºè ããããã¾ã§ã®åè¯ãªã³ã¼ãããèªåã®æå¿
èªåã®2025å¹´ã¯ãViteã®èå¼±æ§ã®å¯¾å¿ãããã¨ã³ã·ã¹ãã å ã®ä»ã®ãã¼ã«ã«ãããå ±åãããã¨ããå§ã¾ãã¾ããããã®ããã°è¨äºã¯ããã®çµé¨ã«ã¤ãã¦ã®æ¯ãè¿ãã§ãããã®è¨äºã¯ä¸»ã«éæè¡çãªå´é¢ã«ç¦ç¹ãå½ã¦ã¦ãã¾ããæè¡çãªå´é¢ã«èå³ãããå ´åã¯ãæ¬¡ã«æ¸ãäºå®ã®è¨äºãåç §ãã¦ãã ããã Viteã¸ã®å ±å æ°å¹´ã®ä¼ã¿ãéãã¦ããã®1æ9æ¥ãããèå¼±æ§ã¬ãã¼ããViteã«å ±åããã¾ããï¼GHSA-vg6x-rcgg-rjx6 / CVE-2025-24010ï¼ã ãã®å 容ã¯Viteã®WebSocketãµã¼ãã¼ãCross Site WebSocket Hijacking (CSWSH) attackã«å¯¾ãã¦èå¼±ï¼CWE-1385ï¼ã§ãããã½ã¼ã¹ã³ã¼ããå¤é¨ããåå¾ã§ãã¦ãã¾ãã¨ãããã®ã§ããï¼æ³¨: ã¬ãã¼ãã®å 容ã¯å ±åæã®ãã®ãã夿´ããã¦ãã¾ãï¼ã Viteã®WebSocketãµã¼ãã¼ãCSWS
TSKaigi 2025 ã§ã®çºè¡¨è³æã§ã - ã¹ãã¼ã«ã¼ãã¼ã ãªãã¸ããªâ¦
é åï¼Arrayï¼ã¨ã®æ¯è¼ JavaScriptã«ã¯TypedArrayã¨ã¯å¥ã«é åï¼Arrayï¼ã®éãã説æãã¾ãã Arrayã¯TypedArrayã¨æ¯ã¹ãã¨æè»ã§æ±ç¨æ§ãé«ãã§ããããããArrayã¯å é¨ã§åçãªã¡ã¢ãªã¼ç®¡çãè¡ãããããã¼ã¿å¦çã転éãé«ãé »åº¦ã§è¡ãå ´åã«ã¯ãªã¼ãã¼ããããçºçããå¯è½æ§ãããã¾ãã TypedArrayã¯é·ããåºå®ã§ããããã¤ãåä½ã®ãã¼ã¿æ ¼ç´ãå¯è½ãªãããã¡ã¢ãªã¼ã¢ã¯ã»ã¹ãå¹ççã«è¡ããã¾ããæ°å¤è¨ç®ã«ããã¦ããã¤ããªãã¼ã¿ãç´æ¥æä½ã§ããã®ã§ãé«ãããã©ã¼ãã³ã¹ãæå¾ ã§ãã¾ããã¾ããã¡ã¢ãªã¼é åãé£ç¶ãã¦ããã®ã§é«éãªãã¼ã¿ã®è»¢éãå¯è½ã§ãã 大éã®ãã¼ã¿ãå¦çããæ°å¤è¨ç®ã®å ´åã«ã¯TypedArrayã§ç®¡çããã¨ãã¼ã¿ã®ã¾ã¨ããåãåããæ¥½ã«ãªãã¾ããéã«ãã¼ã¿ã®è¦æ¨¡ãå°ããæã¯æ±ç¨çãªArrayãè¯ãã§ãããã TypedArrayã¯æ±ºã¾ã£
ããã«ã¡ã¯ãè¤å¾éï¼gfxï¼ã¨ç³ãã¾ããStarleyã¨ããä¼ç¤¾ã§ãããã¹ãAIã¢ããªãCotomoããéçºãã¦ãã¾ããTypeScriptæ´ã¯10å¹´ãããã§ãã ã¯ããã« - TypeScriptãå½ããåã«ãªã£ãä¸çä»å¹´ï¼2025å¹´ï¼ã¯TypeScriptããªãªã¼ã¹ããã¦13å¹´ãESã¢ã¸ã¥ã¼ã«ãå°å ¥ãããES2015ã®ãªãªã¼ã¹ãã10å¹´ãçµã¡ã¾ããä»ãJavaScriptããã¸ã§ã¯ãã«ããã¦ã¯ãTypeScriptãå½ããåã®ä¸çã«ãªã£ã¦ãã¾ãããã¤ã¾ããJavaScriptããã¸ã§ã¯ãã®å®è£ è¨èªã®ããã©ã«ãã¯TypeScriptãã¨ããç¶æ³ã«ããªãè¿ã¥ãã¦ãã¾ãã TypeScriptãå½ããåã®ä¸çã¨ã¯ãJavaScriptå¦çç³»ãããã©ã«ãã§TypeScriptããµãã¼ããã¦ããä¸çã®ãã¨ã§ããNode.jsã§TypeScriptãµãã¼ããå§ã¾ããBunãDenoã®ããã«æåãã
æ°ããCookieã«"__HttpOnly-"ãã¬ãã£ãã¯ã¹ã追å ãããHttpOnly cookie prefixãã¨ããææ¡ä»æ§ãåºããã¦ãã¾ãã åæ: Cookie Name Prefixes ã«ã¤ã㦠Cookieã«ã¯ãCookie Name Prefixesãã¨ãã仿§ãããã¾ã(ããããããRFCã«ãªãã¾ã)ããªãããã§ã«ãã©ã¦ã¶ã«å®è£ ããã¦ãã¾ãã Cookieåã«ãã¬ãã£ãã¯ã¹ãã¤ãããã¨ã§ãç¹å®ã®å±æ§ãä»ä¸ããã¦ããäºãä¿è¨¼ããã¾ãã ä¾ãã°Cookieåã« "__Secure-" ãã¤ãããã¨ã§ãsecure屿§ãä»ä¸ããã¦ããäºãä¿è¨¼ããã¾ããjavascriptãå ±æå ã®ãµã¤ãã«ããåæã«å±æ§å¤ãå¤ããããã¨ã¯ããã¾ããã ç¾å¨ã¯æ¬¡ã®ï¼ã¤ã®ãã¬ãã£ãã¯ã¹ãå®ç¾©ããã¦ãã¾ã __Secure- __Host- googleã®ãµã¤ãããã§ã«ãããããã¤ããCookie
ãµã㪠ISO-2022-JPã¨ããæåã¨ã³ã³ã¼ãã£ã³ã°ã®èªåå¤å®ãæªç¨ããã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)æ»æã«ã¤ãã¦èª¬æãããããã¯ãæåã¨ã³ã³ã¼ãã£ã³ã°ãé©åã«æå®ãã¦ããªãã¦ã§ãã³ã³ãã³ãã«å¯¾ãã¦ãæåã¨ã³ã³ã¼ãã£ã³ã°ãISO-2022-JPã¨èª¤èªããããã¨ã§ããã¯ã¹ã©ãã·ã¥ãåè¨å·ã¨è§£éããããã¨ã«ããã¨ã¹ã±ã¼ãå¦çãåé¿ããæ»æã§ãããæ¬ç¨¿ã§ç´¹ä»ããæ»æã¯ã徿¥ããã®ã»ãã¥ãªãã£ãã¹ããã©ã¯ãã£ã¹ã§ãããæåã¨ã³ã³ã¼ãã£ã³ã°ã®æç¤ºãã«å¾ã£ã¦ããã°å½±é¿ãåãããã¨ã¯ãªãã ã¯ããã« ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°å¯¾çã¨ãã¦ãè¨å·æåã®ã¨ã¹ã±ã¼ãå¦çã«å ãã¦ãã³ã³ãã³ãã®æåã¨ã³ã³ã¼ãã£ã³ã°ãã¬ã¹ãã³ã¹ããããmetaã¿ã°ã§æç¤ºãã¾ãããã¨è¨ããã¦ãã¾ããï¼åç §ï¼ããã®èæ¯ã¨ãã¦ãUTF-7ã¨ããæåã¨ã³ã³ã¼ãã£ã³ã°ãæªç¨ããXSSã®åå¨ãããã¾ããããã®æ»æã«ã¤ãã¦ã¯ä»¥ä¸
ããªã·ã¼: ãã®ä¸çã§ã¯å¸¸ã«ææ°çã使ãã¨ããæ°æã¡ã§çãã¦ãã Node.js ã¯æ¯ããã¨ããæ¦å¿µããªãã常ã«å¤ããã¨ã¯ãªã¹ã¯ ã¨ããèªèãLTS ãçã(3å¹´) å¤ãAPIã®ããã¥ã¡ã³ãã¯å¸¸ã«æ¶å¤±ãã ã¢ãã³ãªãã¼ã«ã¯ãã¢ãã³ãªåæãè¦æ±ãã ~2020: CJS/ESM é¢é£ã§æçµ¶ããã(jestãåããªããªãã¤ã¤ãã) ~2019: ããã©ã¼ãã³ã¹æèãä½ãæä»£ã®å®è£ ãå¤ã ~2015: Node.js ã®ã¿ã§ããåããªããã®ãå¤ããpeerDeps ã®æèãä½ã ãã®è¾ºã§ç®è¦ã§ãããããã npm: npm-check-updates - npm yarn upgrade-iteractive pnpm upgrade -i ãµã¼ãã¼ã©ã³ã¿ã¤ã ã«ã¯å®å®ãããã¼ã«ãã§ã¤ã³ã«ã¯ããã©ã¼ãã³ã¹ã ãµã¼ãã¼ã©ã³ã¿ã¤ã (Node.js) Node æ¬ä½ã¯ Stable LTS ããä¸ã¤åã®
ãTypeScriptã§ã¯ãããåã·ã¹ãã ãã¨ããè¨äºãnæåã©ã ããã¼ãã«å¯ç¨¿ãã¾ããã æ°åãçºå£²ãã¾ãã "ãnæåã©ã ããã¼ããVol.4 No.3ï¼2024ï¼çºè¡ã®ãç¥ãã https://t.co/PGppk1aRRAâ lambdanote (@lambdanote) 2024å¹´10æ4æ¥ ã©ããªå å®¹ï¼ TypeScriptã®æ¥µå°ãµãã»ããã«å¯¾ãã忤æ»å¨ãæ¸ãããããéãã¦åã·ã¹ãã ã使ãã¦ã¿ãããã¨ããå 容ã§ãã 詳ããè¨ãã¨ãbooleanåã¨numberåã¨é¢æ°åãããªãTypeScriptãµãã»ããè¨èªãã¿ã¼ã²ããã§ãã 忤æ»å¨ã®å®è£ è¨èªã«ãTypeScriptï¼å¦çç³»ã¯Denoï¼ã使ãã¾ãã TypeScriptã¥ããã®ä¸åã§ãã ããã人åãã«è¨ãã¨ããåã·ã¹ãã å ¥éãã¨ããæ¬ï¼éç§°TAPLï¼ã®åç´åä»ãã©ã ãè¨ç®ã«ç¸å½ããå 容ãTypeScriptã§èª¬æã
Naming things neednât be hard Find inspiration for naming things â be that HTML classes, CSS properties or JavaScript functions â using these lists of useful words. Word lists Action Describe the behaviour or operation of things. ðï¸ Architecture Terms from architecture can describe the space in and around things. ð¨ Art Terms from art can describe the composition of things. Collection Describe th
2020-07-15 OWASP Sendai Node.js ã®è²ã OWASP Kansai board member ã¯ããããããã é·è°·å·é½ä» (ã¯ããããããã) (æ ª)ã»ãã¥ã¢ã¹ã«ã¤ã»ãã¯ããã¸ã¼ åç· å½¹CTO [email protected] https://utf-8/jp/ åèå¤§å¦ é常å¤è¬å¸« OWASP Kansai ãã¼ãã¡ã³ãã¼ OWASP Japan ãã¼ãã¡ã³ãã¼ CODE BLUEã«ã³ãã¡ã¬ã³ã¹ ã¬ãã¥ã¼ãã¼ãã¡ã³ãã¼ OWASP Kansai Chapter èªåãã¡ã®ç´é¢ããWebã»ãã¥ãªãã£ã®åé¡ã èªåãã¡ã®æã§è§£æ±ºãããï¼ ï½ æ¥æ¬ã§2çªç®ã® OWASP Local Chapter ï½ Webã»ãã¥ãªãã£ã®æ©ã¿äºãæ°æ¥½ã«ç¸è«ãæ å ±å ±æã§ããå ´ ï½ ã¹ãã«ãå½¹è·ãæ¥ç¨®ãå½ç±ãæ§å¥ãå¹´é½¢ã«é¢ä¿ãªã vol.16 OWASP Kansai æ£®ç° æºå½¦
ã¯ããã«link æè¿åããNode.js + TypeScriptç°å¢ã®ç¸è«ã®ä¸ã§ãCommonJSãECMAScript Modulesã®ãããã§è½ã¨ãç©´ã«ã¯ã¾ã£ã¦ãã人ãå¤ãã¨ããäºã«æ°ã¥ããã Node.jsã¯æ´å²çã«CommonJSã¨ECMAScript Modulesï¼ä»¥å¾ESMã¨è¡¨è¨ï¼ãã©ããã¦ãå ¥ãä¹±ããç°å¢ã«ãããããã«TypeScriptã®ã¢ã¸ã¥ã¼ã«ãå ããã¨çµã¿åããã§ããã«è¤é度ãå¢ãã®ãç¾ç¶ã§ããã 説æããéã«å£é ããæ´çããæç« ãæ¬²ããã¨æã£ãã®ã§è¨äºã«ããã 以ä¸ã®ãªãã¸ããªã§æ¤è¨¼ã³ã¼ãã管çãã¦ããã https://github.com/koh110/module_test Node.jsã¢ã¸ã¥ã¼ã«ãã§ãã¯ã·ã¼ãlink ã¾ãæåã«Node.jsã«ãããCommonJSã¨ESMã®æåã«ã¤ãã¦æ´çããã ãããªãæ¸ããã¦ãææ¡ã§ããªããããããªããã䏿¦ã
2024.03.15 ç¦å²¡ããã³ãã¨ã³ãåå¼·ä¼ #1
html5ã®æä»£ã«ãªã£ã¦jsã§ãã¤ããªãã¼ã¿ãæ±ããã¨ãå¢ãã¦ãã¦ãã. ãããªãªãã§è¦ãã¦ããã¹ããã¨ãããã¤ãã¡ã¢ãã¦ãã. Cè¨èªã«ãããintãshortãªã©ã®åã¤ãã¦ç¥ã£ã¦ããã¨æ¥½ã«ãªã. å ·ä½çãªãã¨ã¯ãã¾ãæ¸ãã¦ãªãã®ã§å®éã«ãããã£ãããã°ã©ã ãä½ãã«ã¯, åºã¦ããåèªãããã£ã¦æ¬²ãã. ãããããã¤ããªãã¼ã¿ãã©ããã£ã¦æ±ã? jsã§ã¯ä¸»ã«Uint8Arrayã¨ããé åã使ã£ã¦æ±ããã¨ãå¤ãã ãã. ãã®Uint8Arrayã¨ããã®ã¯æ°å¤ããè¨é²ã§ãã,å¤ã0ãã255ã¾ã§ã®åæåæã«é·ããæ±ºã¾ãé åã§ãã. Uint8Arrayã¨ããã®ã¯ã¤ã¾ã,è² ã®æ°ãªã(Unsigned)ã®æ´æ°(int)ã§,è¦ç´ ä¸ã¤ããã1ãã¤ã(8bit = 1byte)ã®é å(Array)ã¨ãããã¨ã§ãã. Cè¨èªã«ãããunsigned char[]ã«ç¸å½ãã. ãã®é åã¯é£æ³é åã§ã¯ãªãç´ç²
JavaScript ã®éåæå¦çã¯é常ã«é£ããããã®é£ããã®åå ã¯ãå¶å¾¡ã®æµãããæ´ã¿ã¥ãããã¨ã«ããã¾ãã ãã®æ¬ã§ã¯éåæå¦çãçè§£ããããã«å¿ è¦ãªæ¦å¿µã§ãããä»çµã¿ã§ãããã¤ãã³ãã«ã¼ãã§ãããã¹ãã§ã¼ã³ã®å¦çãã©ã®ããã«è¡ãããããã¯ã¤ãºå½¢å¼ã§å¦ã¶ãã¨ã«ãã£ã¦ãéåæå¦çã®ãå¶å¾¡ã®æµãããæ´ããããã«è¨ç·´ãã¾ãã ç¥èé¢ã«ã¤ãã¦ã¯ä¸æ¢ã¨ãªãã¤ãã³ãã«ã¼ãã®æ©æ§ãããå®è¡ç°å¢ã¨ APIãasync/await ã Promise.all ãªã©ã®ä¸éãã®ç¯å²ãå¦ç¿ããæçµçã«ã¯ä¸¦ååãé åºã¥ãã¦å復å¦çãè¡ãããã®å¶å¾¡æ¹æ³ã¨ TypeScript ã§ã®å注éã¾ã§ãç¶²ç¾ ãã¾ãã
Security.Tokyo #3ã®çºè¡¨è³æã§ãã ã¯ã©ã¤ã¢ã³ããµã¤ãã®ãã¹ãã©ãã¼ãµã«ã¨ãpostMessageçµç±ã®èå¼±æ§ãåãä¸ãã¾ããã
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}