#👾-core-development

1 messages · Page 120 of 1

oak hull
#

🤝

jagged cloak
#

my plugins arr ususlly all doable with flux dispatcher events thankfully

#

except the patch i stole from somewhere that replaces playing with watching

oak hull
#

was looking at some random js file and it was full of loops with single letter variables

jagged cloak
#

discord minifird code reaction

#

bleh looks jank

#

lol

oak hull
jagged cloak
#

average vr recording

opaque pewter
#

wtf

woeful sable
jagged cloak
woeful sable
#

can you shiggy in vr

jagged cloak
#

if it alllowed images in the body lol

woeful sable
#

make your character shiggy

jagged cloak
#

okay one more time replay and say something silly

woeful sable
#

balls

jagged cloak
#

perfect

woeful sable
#

:3

jagged cloak
#

i believe so

junior olive
#

I can't proxyLazy a memoized component

#

well

#

I want to memoize a discord component for use in one of my modals

verbal pumice
#

there was

junior olive
#

bc when the user is typing text in a field the component rerenders and it causes the pfp to restart animation

#

Ima sleep but i want to memoize findByCode("AvatarDecorationModalPreview")

#

i cba to get error

charred monolithBOT
junior olive
#

i'm getting insane lags that vee was talking about

#

i'm getting insane lags that vee was talking about

#

i'm getting insane lags that vee was talking about

#

i'm getting insane lags that vee was talking about

#

i'm getting insane lags that vee was talking about

woeful sable
#

nice spam

#

vban @junior olive spam

charred monolithBOT
junior olive
#

WHAT

#

I stepped away to piss while waiting for the lag to clear up

#

??????

woeful sable
junior olive
jagged cloak
#

'tis done, review at your own convenience

#

finally got that shit out of 6month git stash purgatory

charred monolithBOT
charred monolithBOT
#

When launching Vesktop in a FreeBSD Linuxjail using a wrapper that usually works for Discord I get the following output:

halley~⇥ vencord
No matching processes belonging to you were found
W: [(null)] caps.c: Normally all extra capabilities would be dropped now, but that's impossible because PulseAudio was built without capabilities support.
executed this shit! (wexp)
[52490:1026/133442.734212:ERROR:file_path_watcher_inotify.cc(822)] Failed to read /proc/sys/fs/inotify/max_user_watch...
austere talon
#

istg if he brings back polyfills im combusting

opaque pewter
#

tsoding ofc xd

#

his poor shitbox

turbid hatch
#

i like tsoding but what

#

why is he running 2 year old currently

#

chromium

oak hull
#

tsoding is cool

charred monolithBOT
lime stone
#

too cool for updates

#

discord could maybe have better error handling

limpid badger
austere talon
#

i think they shouldn't be using Object.hasOwn cause even i hesitated to use it in vencord since its somewhat new

#

but why would they handle errors of js globals potentially not existing

#

at that point they should just polyfill again

lime stone
#

🤷‍♀️ what if you run in internet explorer

verbal pumice
#

i doubt pre change code worked in ie lol

lime stone
#

that's probably a white screen xd

austere talon
#

duh? don't use IE

verbal pumice
#

though yeah hasown is like really new

lime stone
#

it doesn't feel that long ago that you could use modern websites in IE 😭

#

but yeah lmao

verbal pumice
#

you'd at least expect that to be polyfilled for the people with an ancient host still on electron 13

lime stone
#

if you are using Internet Explorer now you are living under a rock

surreal storm
#

still seems there's these two issues in vencord after the fixes:

  • ShowHiddenChannels Plugin doesn’t allow channels in categories to collapse if there are unreads
  • ImageZoom Plugin minimizes/dismisses fullscreen preview of image when magnifying and left mouse button is released
    (just sending here so they can be noted)
austere talon
#

the latter has a tracking issue

surreal storm
#

i do have a question, unrelated to what happened. if i wanted to make a request for two different plugins to be made compatible with each other, where would i do that?
example: currently, with NoReplyMention, you can set specific users to have it default OFF to, but the QuickReply plugin doesn't respect those options.
(genuine question, sorry if it's stupid)

austere talon
#

it should respect them 🤔

#

it specifically has logic to integrate with quick reply

surreal storm
#

since i started using it like a few days ago it doesn't

austere talon
#

can you show what settings you have for quick reply

surreal storm
#

ye will do in a few mins when i get home

lime stone
#

🔥 🔥

#

it's not a typo 😭

austere talon
#

first hacktoberfestf spam pr?

charred monolithBOT
cunning canyon
lime stone
#

a repo i maintain had a pr to add a full stop

#

😭

#

first time they put it after badges

limpid badger
lime stone
#

then they realised that a series of badges is not a sentence

limpid badger
#

Prs*

lime stone
#

actually we got two prs

limpid badger
#

Hmm

surreal storm
lime stone
austere talon
#

GITMUSLIM

#

HAHAHAHAHA

charred monolithBOT
cunning canyon
little wing
#

gitmuslim 😭

limpid badger
lime stone
#

i probably should have blurred their name

#

there was also this

#

it changed a single word 😭

little wing
#

where are the add typo prs

lime stone
surreal storm
#

interesting typo

lime stone
#

it removes all the charm of the repo

#

hel low guys thsi his my gihtruhb reop

surreal storm
#

it's giving nerd_glasses

teal halo
#

🤨

surreal storm
#

hmm

limpid badger
#

Is that star repo armies

limpid badger
#

Bro what

#

Yeah it is

surreal storm
verbal pumice
#

what happened

#

new ntts video confirmed

limpid badger
#

Mhmm

lament cedar
#

where i report bug ? in github ?

verbal pumice
lament cedar
#

thx

limpid badger
#

Is that the cursed photo thing

#

It seems as if getting banned on discord is becoming easier

lime stone
#

maybe this should be implemented in vesktop

#

not sure if i mentioned it but i'm pretty sure it's new

#

...so i probably didn't mention it because it didn't exist 😭

#

déjà vu

charred monolithBOT
lime stone
#

i think i just talked about something similar

austere talon
#

the opening channel links?

austere talon
lime stone
#

i don't know

#

my memory is bad 😭

austere talon
#

but arrpc likely needs to implement it

#

this is how invite launch works

charred monolithBOT
austere talon
#

but i doubt arrpc supports message links

lime stone
#

i think i talked about implementing it before discord did with a custom extension (but that would be a pain)

#

but now discord has implemented this feature

lime stone
livid heath
#

updated my plugin pr to fix new changes JihyoPray

livid heath
feral burrow
#

how do i know if openasar is working

limpid badger
#

Why so many stars

lime stone
#

i like the way discord's official app's rpc doesn't work but vesktop's does

lime stone
#

i'm confused

#

i'll try removing vencord

pale anvil
#

wait when could we talk here?

limber skiff
#

hmm so many people starring

charred monolithBOT
obsidian dragon
#

that was me just now lol

limber skiff
obsidian dragon
#

myself lol

lime stone
#

how 😭

#

that's impressive

austere talon
#

i think we're the only functional mod

obsidian dragon
#

no like

austere talon
#

BD is badly broken

limber skiff
limpid badger
#

I assume a lot of people basically switched as bd died

obsidian dragon
#

I found it from a youtube vid about client mods

limpid badger
#

So this is a storm of new Vencord users coming from various mods

obsidian dragon
#

Ive been using vencord for a while now

limpid badger
charred monolithBOT
limber skiff
#

Still broken: EmoteCloner, petpet

obsidian dragon
#

I think I’ve been using it since 5 months ago

lime stone
#

aw no

#

sadface

obsidian dragon
#

I don’t remember exactly

austere talon
lime stone
#

shigsmash << emoji

austere talon
#

and message logger has a small bug if you edit a message with a link with embed

turbid hatch
#

i will take a look at automating this

#

and then we can just forget about it

#

similar to winget

limber skiff
#

we should have a way to test finds using the reporter

lime stone
limber skiff
#

maybe we load all chunks and then test the finds

lime stone
#

another one of these

limber skiff
#

we could have a special mode where find calls add to an array so we can test all later

verbal pumice
#

so many modules have names and can be findbyprops'd now ❤️

lime stone
#

what if they end up unnamed and proxy functions in the future

charred monolithBOT
lime stone
#

nvm, am i misunderstanding it derp

charred monolithBOT
austere talon
turbid hatch
#

flatpak is weird

limber skiff
#

yeah it is possible

lime stone
#

i think i've fixed EmoteCloner lol. it was pretty easy.

austere talon
limber skiff
#

we just have to execute the finds after we load every chunk

#

yep

#

I will do it today

#

it's a very good idea

austere talon
#

ill fix the webpack patch issues soon

limber skiff
#

nice nice

turbid hatch
#

oh wait

#

we can get electron-builder to make a flatpak bundle @austere talon

austere talon
#

no

turbid hatch
#

it just wont publish to flathub though

#

wdym no it's in their documentation :P

austere talon
#

i already tried it literally just errors lmao

#

it's broken

turbid hatch
#

hm

austere talon
#

it gave some really weird error

turbid hatch
#

in which case this is going to be annoying as shit

austere talon
#

like meaningless error

#

if you can figure it out, nice

turbid hatch
#

flatpak is the most horrible system

austere talon
#

but we should likely just write the initial flatpak manually for the best experience

#

then we can automate updating it

turbid hatch
#

that's what im trying to work out

austere talon
#

updating it just means updating hashes, links and version

turbid hatch
#

im trying to work out how to even make a flatpak

#

their documentation is crap

austere talon
#

should be easy with a script

#

there's probably some tool out there already

turbid hatch
#

maybe

austere talon
lime stone
#

hm, i wonder if you could get RPC to work

turbid hatch
#

definitely not a github action though that's sane, might have to write my own fear

austere talon
#

check out armcord and discord flatpaks

#

and copy paste

#

ive been meaning to work on flatpak for ages, just been preoccupied with other stuff

charred monolithBOT
lime stone
#

it goes to /run/user/1000/app/app.id.here/discord-ipc-0 iirc

austere talon
#

discord flatpak has a workaround

turbid hatch
austere talon
lime stone
turbid hatch
#

yeah just taking a look now

lime stone
#

yeah^^

turbid hatch
#

this feels like a massive hack fear

lime stone
#

the chat is moving too fast for my brain

slender helm
#

Just wanna give all you devs props for fixing Vencord so fast yesterday ❤️

charred monolithBOT
slender helm
#

I was watching this channel a bit and saw you guys zoomin' 3dsunglasses

turbid hatch
#

i can probably just use sed

#

to autofill in some manifest stuff

#

it'll be good enough

charred monolithBOT
austere talon
#

SED

turbid hatch
#

THEIR OFFICIAL FLATPAK

#

USES SED

#

LOL

#

THIS IS AMAZING

#

"sed -e 's/Icon=discord/Icon=com.discordapp.Discord/' -e 's|Exec=/usr/share/discord/Discord|Exec=discord|' /app/discord/discord.desktop > /app/share/applications/${FLATPAK_ID}.desktop",

#

I LOVE

austere talon
#

i mean makes sense

#

patching the official discord stuff to work

charred monolithBOT
dusk hill
#

does vencord really installs the installer to just inject?

pale anvil
#

wait when could we talk in here?

pale anvil
#

Am I even allowed in here?

turbid hatch
#

yes

scenic raft
#

re: this. sorry about the necroing a pr. i'm dumb and didn't realize i was on a pr and not an open issue. but i'm curious what version of glibc I should have for vencord, and if you happen to know what version of ubuntu i should be on to get it?

austere talon
charred monolithBOT
pale anvil
#

i mean hey I anit complaining

austere talon
#

in any case it might work on latest ubuntu (not lts)

turbid hatch
#

i'll probably just do a detached fork of the armcord manifest and change it

austere talon
#

you should just switch to the flatpak eventually, that will fix the glibc++ issues

pale anvil
#

ive been thinkabout getting vesktop. is it really all that worth it?

dusk hill
austere talon
#

it sucks that C++ is like that

charred monolithBOT
turbid hatch
# dusk hill

yes we use the installer to inject your dev version

#

its convenient

scenic raft
#

yeah but i have a jackbox event i'm streaming for this saturday so i need a fix before then 😭

austere talon
turbid hatch
#

run the app from terminal and see what it comlpains about

dusk hill
#

let see

austere talon
austere talon
charred monolithBOT
charred monolithBOT
scenic raft
#

okay it needs 3.4.32.... now to figure out which version of ubuntu has that

austere talon
scenic raft
#

yeah thanks, i'm getting there uwu

turbid hatch
#

according to StackOverflow™️

#
sudo add-apt-repository ppa:ubuntu-toolchain-r/test
sudo apt-get update
sudo apt-get install --only-upgrade libstdc++6
#

try that

#

but yeah it does say gcc 13 so either or

#

ven you will merge vencord.dev#two9 NOW

austere talon
#

son

#

soon

#

cool hair btw peach

charred monolithBOT
turbid hatch
#

reminds me i need to dye my hair pink again

scenic raft
#

it works!!!! thanks vee ❤️ you're my hero

austere talon
#

it kinda reminds me of google chrome chan in a way

scenic raft
#

haha i wish it still looked like that

#

it's all faded out now

dusk hill
austere talon
turbid hatch
#

doing that will be difficult depending on the error

austere talon
#

well surely you can check what glibcxx versions are available

turbid hatch
#

yes, easily, but are we loading before glibc++ is?

#

well

#

i guess we can shell script it

#

cant we

charred monolithBOT
turbid hatch
#
if [ glibc we want is not available ]; then
cry
exit -1
fi

run vesktop
scenic raft
#

it drives me nuts that discord hasn't figured out basic features of their app for linux users. 😦

#

thank you so much for making it usable

charred monolithBOT
turbid hatch
#

oh fuck it

#

how much is the apple dev account

#

is it $100

austere talon
#

yes

turbid hatch
#

okay

gentle spruce
#

it is not worth it

turbid hatch
#

i know

austere talon
#

it is not worth it

turbid hatch
#

i know

austere talon
#

don't do it lewi...

turbid hatch
#

i'm pissed off with the amount of issues we have because of that fucking gatekeeper

#

and i know this is exactly what they want people to do

gentle spruce
#

shrimply do not support mac

turbid hatch
#

they want people to cave in and buy the account

gentle spruce
turbid hatch
#

but we have a lot of people who actually use mac and i want to at least give them a good first time user experience

charred monolithBOT
austere talon
#

apple is just evil, it's now 2023 can we already stop buying their products

scenic raft
#

<Billionaires> $100 is reasonable right? that's like, a whole minute of work!

turbid hatch
gentle spruce
#

i use it

#

is good

austere talon
turbid hatch
#

userscript is literally a last resort option fear

austere talon
#

it's really whatever

gentle spruce
austere talon
#

also, someone said universal binaries don't need signature

#

does electron support this?

gentle spruce
#

i will bet: no

charred monolithBOT
austere talon
turbid hatch
austere talon
#

we could give this a shot

turbid hatch
#

the universal binary itself does not need signing

#

the subbinaries do

austere talon
#

it just combines multiple .app

turbid hatch
#

yeah

#

those .apps need to be signed

#

for it to work

gentle spruce
#

funny mac moment

austere talon
#

wait electron builder literally supports universal

turbid hatch
#

holy shit

#

the fucking bars

#

are emailing me now

charred monolithBOT
turbid hatch
#

asking me to come back

gentle spruce
turbid hatch
#

contrary to popular belief i am not a crippling alcoholic

gentle spruce
#

whyd you give them your email

turbid hatch
#

i didnt

#

they scraped it

#

oh wait no i did give them this one

charred monolithBOT
gentle spruce
#

how'd they know you were there

turbid hatch
#

oh right i needed an account on there to order

#

💀

austere talon
#

WHAT THE HELL

turbid hatch
#

i have notifications on for the stuff i work on

#

:P

austere talon
#

oh are you saying they're two different emails

turbid hatch
#

yeah

austere talon
#

i thought that was the subject of the spam mail 😭

turbid hatch
#

oh no lmfao

austere talon
#

ofc i have email notifs too

turbid hatch
#

i use *@lewisakura.moe

austere talon
#

i got at least 200 emails from github yesterday

turbid hatch
#

so i just put the company name as the email

#

its so i know who sold my data

austere talon
#

bro I use this stupid hamster emote too much but I love it

turbid hatch
#

and for sorting

charred monolithBOT
turbid hatch
#

apple

#

buddy

#

i just gave you this shit

limpid badger
charred monolithBOT
turbid hatch
charred monolithBOT
austere talon
#

LEWI DONT DO IT

turbid hatch
#

wait its cheaper now?

#

its only $80

charred monolithBOT
turbid hatch
#

for me

#

oh because gbp

austere talon
#

"only" agony

charred monolithBOT
turbid hatch
#

our money is worth more than the US dollar

#

💪

rustic sigil
turbid hatch
#

if i sign it we're saving $5

#

oh wait i just realised

#

it'll say "Vesktop by Lewis Crichton" on it

silent ingot
#

crazy that the usd is so cheap now a days

turbid hatch
#

because we arent a company so i cant put a custom name there

#

that's SHITE

#

fuck it

#

ven, want to establish an LLC?

nimble plaza
#

searchreply webpack find kaboom

austere talon
austere talon
turbid hatch
#

literally just a "create a delaware tax haven company"

austere talon
turbid hatch
#

VEN

#

THINK ABOUT IT

#

THINK ABOUT THE VEN STOCK

charred monolithBOT
turbid hatch
#

PEOPLE WILL BUY SHARES OF VENCORD

charred monolithBOT
turbid hatch
#

wait a minute

#

wait holy shit we would actually have stock in this theoretical company

#

that's fucking hilarious

#

i want to have vencord llc stock

azure jay
turbid hatch
#

Vencord Apple Signatory LLC

charred monolithBOT
austere talon
#

LEWI WTF

turbid hatch
#

for the small price of

austere talon
#

vencord stock

turbid hatch
#

500 DOLLARS

austere talon
turbid hatch
#

HOLY SHIT

austere talon
#

worth

turbid hatch
#

actually that's not a lot of money

#

for establsihing a company half way across the world

#

in a tax haven

#

owned by stripe

#

where you dont have to do any of the legal shit

austere talon
#

lewi you don't seem too good with financial decisions

turbid hatch
#

and you get an IP assignment

turbid hatch
#

sometimes

austere talon
#

first the license purchasing now you want to establish an llc fear

turbid hatch
#

think about it ven

steep burrow
turbid hatch
#

Vencord IP assignment

#

we'll have to issue our own IP to ourselves

charred monolithBOT
turbid hatch
#

we'll even have a Delaware Company Agent™️

charred monolithBOT
austere talon
#

unironically vencord breaking is good for us

crude hearth
austere talon
#

vencord breaking = we gain popularity

charred monolithBOT
austere talon
#

deliberately breaking vencord again soon so we get more users

steep burrow
steep burrow
turbid hatch
#

oh i see

#

so an LLC is where we pay tax

#

a C Corp is where the company pays tax

crude hearth
#

I wonder how many days it will take devilbro to fix his plugins

austere talon
charred monolithBOT
turbid hatch
#

it's just moving the legal part of tax payment between a person and the company itself

#

interesting

charred monolithBOT
austere talon
#

the fact that he's doing all these terrible things to twitter makes it the talk everywhere

crude hearth
#

STOP STARRING

austere talon
#

negative attention is still attention

charred monolithBOT
crude hearth
#

"there is no such a thing called bad adveristment"

scenic raft
#

OMG it's full of stars

charred monolithBOT
marsh herald
limpid badger
austere talon
#

but i also don't really want to ruin our relations with BD lmao

scenic raft
#

That's a mood

crude hearth
#

other betterdiscord is meh

austere talon
#

i think this already happens enough without us doing it

like one guy going "omg bd so broken" and then some other person telling them to hop on vencord

charred monolithBOT
scenic raft
#

I was using discord screen audio before

turbid hatch
#

we even get a vencord bank account

limpid badger
austere talon
charred monolithBOT
austere talon
#

vesktop is in a really good state now and id like for more people to know if its existence

limpid badger
#

Yk

scenic raft
#

I'd offer to help but I'm waist deep in my own projects 😭

turbid hatch
#

christ okay so i can either pay $100 a year for a personal apple licence or spend like $600/yr for a delaware corporation, then an apple dev licence

austere talon
turbid hatch
charred monolithBOT
turbid hatch
#

somehow

#

this seems too easy

charred monolithBOT
turbid hatch
#

i love the "pay taxes" button

austere talon
#

it has never really been that big of a deal, everyone just makes do

silent ingot
nimble plaza
#

i have a dev account if needed but its under a weird name

turbid hatch
#

because i have a strong belief that if we did that more people would actually use the desktop app

#

also it means i can do tax writeoffs on whatever i buy as long as i use it for vencord development

#

:^)

#

/s

silent ingot
#

i mean not really unlimited but it goes back on taxes as a write off

nimble plaza
crude hearth
#

is there even much mac users

turbid hatch
#

also i dont want a random vietnamese person signing our product

charred monolithBOT
nimble plaza
#

yeah fair

turbid hatch
#

i wish apple did open source discounts or something

limpid badger
crude hearth
#

I only seen like 3 mac users on discord

#

and doubt they care about certificate name

scenic raft
#

I use a Mac for work

turbid hatch
#

you know what would be really useful to determine the viability of an apple developer licence?

#

Telemetry!

scenic raft
#

I hate it

turbid hatch
#

With Vencord Telemetry we will be-

#

if i go any further ven will probably hire a sniper

austere talon
scenic raft
#

Hopefully telemetry is what I'm doing for my job right now

#

I feel so dirty

austere talon
#

i swear if i ever get into an accident and can't come online for a few weeks i will come back to lewi having created a telemetry empire

turbid hatch
#

yes.

scenic raft
#

Daddy IBM pays the bills though

turbid hatch
#

I WILL HAVE MY NUMBERS

pearl sundial
#

vecord with ads when

turbid hatch
#

I WILL HAVE EVERYTHING

#

I WILL MICROOPTIMIZE THE SHIT OUT OF THIS PRODUCT

#

WITH NUMBERS

nimble plaza
austere talon
turbid hatch
scenic raft
#

The enshittification of vencord

#

Lol

turbid hatch
#

if you buy something personally you can write it off if it ends up getting used by a company

limpid badger
turbid hatch
#

a lot of people establish companies just to do tax writeoffs because their projects are under it

pearl sundial
charred monolithBOT
austere talon
crude hearth
#

"guys it was a joke"

#

"we made 4000$ out of it but it was a joke"

turbid hatch
#

it's basically ordering stuff under the company to 'use' by the company, and as long as you actually end up using it for something you're perfectly legal

lime stone
#

and replugged

crude hearth
#

github default pfp people

#

that guy has java app

lime stone
#

hey i used to have the default pfp

pearl sundial
#

ven botting stars?!?!?

#

!!

teal halo
scenic raft
#

I need to update my GitHub pfp

#

It old and far less gay

lime stone
#

LOL

crude hearth
#

I never thought default pfp people had repos

charred monolithBOT
lime stone
#

it is impossible for a pfp to be too gay

austere talon
charred monolithBOT
scenic raft
charred monolithBOT
austere talon
#

uh what

crude hearth
#

looooovely

woeful sable
#

ven is blonde, i can sense the nordic blood in their body

limpid badger
teal halo
charred monolithBOT
teal halo
#

just report on github lol

limpid badger
#

What the fuck was that

lime stone
charred monolithBOT
lime stone
#

reporting vulerabilities publicly isn't the greatest idea

crude hearth
#

well yes

charred monolithBOT
crude hearth
#

BUT THIS IS A INSTALLER

charred monolithBOT
limpid badger
#

I mean, it’s still not safe even if it was a installer…?

teal halo
#

bet it ain’t a real vuln

crude hearth
#

guys I found RCE

#

in vencord installer

charred monolithBOT
lime stone
charred monolithBOT
crude hearth
#

I want to watch this

lime stone
#

yes LOL

charred monolithBOT
limpid badger
#

Lemme just prepare my popcorn

charred monolithBOT
austere talon
#

NOT SIGNING

#

what is wrong with my head

crude hearth
#

ven loves signing emails

lime stone
#

need to verify that ven sent the email to ven

austere talon
#

im too used to using gpg to sign my commits

crude hearth
#

@austere talon please tell if its some dumb thing

#

I really want to know

turbid hatch
#

i wonder what the junior penetration tester from algeria found in our product installer

#

i wonder if it drops files

limpid badger
#

Let’s see lol

charred monolithBOT
#

Basically this is #177 but not fixed by doing what that person did.
Things i tried:

  1. Nuke Vencord in ~/.config/Vencord
  2. Update from tray icon
    Both options don't do anything. Also launching vencorddekstop from terminal does not output any logs in the terminal.

Distro: NixOS
Kernel: 6.5.7-xanmod1
Gpu: AMD (mesa 23.1.7)

teal halo
#

"fun fact if you execute the installer it installs" cta_wtf_shock

charred monolithBOT
turbid hatch
#

although to be fair, we should actually have a properly stated security policy

#

that would be a good idea

#

oh it's a nixos user

austere talon
crude hearth
#

he has tryhackme account

austere talon
#

I love that we noticed that at the same time

#

it's always nixos that has these issues

turbid hatch
#

lmfao

charred monolithBOT
crude hearth
#

god I hate tryhackme everything is paid

charred monolithBOT
crude hearth
#

why nixos users exist

turbid hatch
#

oh yeah ven

#

wailsinstaller™️ is basically done i think

#

we just need to test it further to make sure it works

scenic raft
turbid hatch
#

but i think we can release it

charred monolithBOT
crude hearth
#

just google

charred monolithBOT
limpid badger
#

Could just use some simple distro

charred monolithBOT
crude hearth
#

I would want answer to both questions

austere talon
#

yeah, idk why it's always nixos (and also arch) users doing that. you never get issues like that from gentoo users

#

gentoo users learned to cope with their broken setups I think

scenic raft
#

Aww b- booo

austere talon
#

B-

rigid rock
#

oof

#

im lucky

turbid hatch
#

havent touched wails since sep 5

#

👀

austere talon
rigid rock
#

sheeesh

turbid hatch
#

actually couldnt we technically roll it out

#

and see what happens

austere talon
#

mm

turbid hatch
#

cause we did finish it

austere talon
#

i want to fully review it before that

turbid hatch
#

alright

rigid rock
#

idk about that stat though. just a c?

turbid hatch
#

it is done though from what i remember

austere talon
#

ill check it out soon, i have some more important things to still do rn

turbid hatch
#

yipyip

austere talon
turbid hatch
#

lmao

topaz thistle
lime stone
#

idk why it doesn't count the 200 stars i got on a repo lol

#

ig i archived it

oak hull
#

do i count as a programmer

shut dome
crude hearth
#

how does it calculate score

austere talon
oak hull
charred monolithBOT
austere talon
#

im blonde, blue eyes. but not tall

rigid rock
#

i mean i basically beat my stats from last year. 200ish contributions last year and this year 1300 contributions

cunning canyon
topaz thistle
topaz thistle
charred monolithBOT
limpid badger
#

Got B- lmao

charred monolithBOT
topaz thistle
#

The Github Readme Stats spam is real holy

lime stone
#

i'm A teawiesmug

charred monolithBOT
crude hearth
#

this thing is definiletly racist

#

I am sure

#

how am I A-

#

negative point to turkish people

oak hull
#

i am C, fair enough

#

only learnt to properly use github this year husk

crude hearth
#

ven is A+ which means its made by german people

oak hull
#

correct

lime stone
#

yes

crude hearth
#

extra point to germans

topaz thistle
#

Maybe over all commits count?

#

The logic is explained in the repo of the guy that made these btw

lime stone
#

i don't think it counts stars in orgs

topaz thistle
#

Not sure where though

lime stone
#

because i should have 200+ stars

topaz thistle
lime stone
#

another german dude

#

it's rigged

#

but should say 4000 stars

charred monolithBOT
lime stone
#

scwumplex

crude hearth
austere talon
#

about that guy who opened a BSD issue on vesktop yesterday

#

I wonder how vesktop would even work on bsd

crude hearth
#

isnt scrumlex turkish

#

but live in germany

austere talon
#

our code switches over process platform and expects it to be either of the three

crude hearth
#

yes

charred monolithBOT
crude hearth
#

sefa eyeoğlu is turkish name

austere talon
crude hearth
#

do

lime stone
#

is the starboard alive

#

vendicated@riseup.adwkuhdsjk

#

or something

crude hearth
#

ven when will you give me riseup email

turbid hatch
#

im going to start planning telemetry trolley

lime stone
#

do not harrass the vending machine

charred monolithBOT
turbid hatch
#

im not gonna write code

#

just plan

#

:^)

oak hull
charred monolithBOT
turbid hatch
#

well i lied im going to write code

crude hearth
#

power poisoning

turbid hatch
#

but it'll be pseudocode

austere talon
crude hearth
#

if vencord ever reaches 10k stars lewi would fill it with adveristment

austere talon
#

have been for like a year now

turbid hatch
crude hearth
turbid hatch
#

i wouldnt fill the mod with ads

charred monolithBOT
oak hull
#

wrong

crude hearth
#

not fill it with ads

oak hull
#

vencord 1.7.0 ads and telemetry update

austere talon
limpid badger
misty heart
#

hi

lime stone
charred monolithBOT
frozen mango
#

it's still erorr?

nimble plaza
#

vns

nimble pendantBOT
rigid rock
#

lol

charred monolithBOT
solid crown
charred monolithBOT
solid crown
#

sounds like a minecraft update

oak hull
#

yes jt is

charred monolithBOT
oak hull
#

LOL

charred monolithBOT
austere talon
# charred monolith

The Vencord Installer codebase allows for user input from command-line arguments, specifically the locationFlag and branchFlag, without proper validation or sanitization. This lack of input validation exposes the application to the risk of command-line injection attacks.

turbid hatch
#

what

charred monolithBOT
austere talon
#

nonsense, like expected

lime stone
#

is this ai generated

austere talon
crude hearth
charred monolithBOT
limpid badger
#

Probably

turbid hatch
#

you tell it where to install...

#

and it.. installs there?

#

that's the vulnerability?

nimble plaza
#

chatgpt

crude hearth
#

there is no way that guy wrote this himself

limpid badger
lime stone
#

it just looks ai generated

turbid hatch
#

it does

oak hull
#

ai gen alright

turbid hatch
#

especially because we do have validation

crude hearth
#

its ai generated

turbid hatch
#

like

crude hearth
#

100%

charred monolithBOT
oak hull
#

yop

#

🔥

charred monolithBOT
turbid hatch
#

you cant just point it to system32 and it overwrites the entire directory

#

thats not how it works

limpid badger
#

This is just ridiculous

turbid hatch
#

ugh

crude hearth
#

it is nonsensical

#

you cant do anything by providing cli arguments

lime stone
#

chatgpt often generates nonsense

crude hearth
#

actually yeah

#

its normal

#
  1. The development team should immediately address this vulnerability by implementing the suggested mitigation steps.
  2. The code should be reviewed for other potential security vulnerabilities, and a comprehensive security review should be conducted to identify and remediate any further issues.
  3. The development team should establish security best practices and integrate them into the development process to prevent future vulnerabilities.
#

do this

austere talon
#

why would you even use command line injection when you already have the ability to execute binaries on the host

turbid hatch
#

what the fuck is

#

command line injection

#

like i understand what it is

#

but not in the context they're using it

#

is passing command line arguments injection?

austere talon
#

apps like vencord installer inherently cannot have vulnerabilities unless we messed up something like the github downloading and somehow you could abuse that to download malicious files

turbid hatch
#

my understanding is that injection is where you have a shit shell script

austere talon
#

or rather, they can have vulnerabilities but they cannot have any impact

crude hearth
#

chatgpt would think rm command has vulnerability because it can delete files

oak hull
#

hroror

austere talon
oak hull
charred monolithBOT
crude hearth
#

I wonder what tool even is that

cunning canyon
crude hearth
#

there was some guy doing the same thing

charred monolithBOT
lime stone
#

:youtried:

oak hull
crude hearth
#

it should be some website that scans github repos and creates a report

limpid badger
shut dome
tidal cloud
#

I saw vitepress being used for docs and vitepress is awesome

nimble plaza
#

show

tidal cloud
#

does this still work

tidal cloud
#

alright thanks good friend

lime stone
#

🐸

charred monolithBOT
nimble plaza
#

i should clone the "bettervencord" fork and see how bad it is

#

actually no i shouldnt

heavy lotus
#

the storm has settled :v

lime stone
#

ToadMod

nimble plaza
#

it uses browserfs husk

crude hearth
nimble plaza
#

itll kill my indexeddb

nimble plaza
#

its vencord with bdapi

charred monolithBOT
austere talon
#

horror

charred monolithBOT
crude hearth
#

why is this starred

austere talon
#

omg i forgot about that person

crude hearth
#

bencord is mine

lime stone
crude hearth
#

its named vencordplus now

austere talon
lime stone
#

because there's another star

nimble plaza
charred monolithBOT
nimble plaza
#

that

austere talon
#

So it's really just slightly out of date

nimble plaza
#

hell

crude hearth
nimble plaza
#

yeah

crude hearth
#

I was considering to do same thing in vencord plus but was too lazy

nimble plaza
#

i would clone but itll kill my indexeddb and i dont wanna clear it

crude hearth
#

and didnt want to touch internal code

#

because then merge conflicts

lime stone
#

he

nimble plaza
#

yeah

lime stone
#

frog

#

oh it was actually made by a frog

nimble plaza
charred monolithBOT
nimble plaza
#

ill do it next class

charred monolithBOT
teal halo
#

what even was that false installer vuln lmao

limpid badger
lime stone
teal halo
crude hearth
#

"it's called Vencord because it's made by ven,
it's called BetterVencord because it's bettter than Vencord"

  • Davilarek
charred monolithBOT
#

Code Vulnerability Report

Project: Vencord Installer

Prepared by: Rafik Saifi

Executive Summary

This vulnerability report aims to address a critical security concern identified within the Vencord Installer codebase. The vulnerability pertains to the potential for command-line injection, which could allow malicious actors to execute arbitrary commands on the system where the application is running.

Vulnerability Description

The Vencord Installer codebase al...

crude hearth
#

I fear this