RFC: It’s Time for npm to Make Install Scripts Opt-In — npm is the only major package manager that runs dependency install scripts (e.g. postinstall) by default, and they’ve become too much of a security weakness, says Jamie, who works for GitHub (maintainers of npm). This RFC features further discussion of the idea and the tradeoffs involved. Jamie Magee |
💡 npq is a tool that makes npm installs safer. It stands in front of npm and audits packages before installing them, including the presence of pre/post install scripts. |
How Depot Built a CI Orchestrator on AWS Lambda — Long-running CI orchestration without long-lived servers. Depot rebuilt their CI engine using AWS Lambda durable functions — stateful, callback-driven, and crash-recoverable. A deep dive into the run-workflow-job hierarchy powering Depot CI. Depot |
IN BRIEF:
😱 Dr. Axel Rauschmayer (JavaScript legend and former JS Weekly editor) has taken his blog and JavaScript books off the Web due to being overwhelmed by AI crawlers. You can, however, still purchase his fantastic books here.
The Bun saga continues. Despite once playing down its significance, the Rust-based rewrite of Bun has been merged, though there are questions over the quality of the AI-ported code. Much discussion ensued on Hacker News.
The Deno team is teasing Deno 2.8, due to be released this week. Significant Node.js compatibility improvements, import defer, and TypeScript 6.0.3 support await.
The Chrome and Edge teams are working on a new <install> HTML element for browsers to render a 'trusted install button' for PWAs.
The Express.js project has an all new look, including a new site, logo, and improved docs.
|
🤖 Mark Erikson's Agent Setup, Workflow, and Tools — Mark, well known for maintaining Redux and creating Redux Toolkit, goes deep into his daily development workflow, including his use of OpenCode (an open source JavaScript-powered coding agent), how he manages his knowledge base, tasks, and more. Mark Erikson |
📄 Hardening TanStack After the npm Compromise – What TanStack is doing to improve supply chain security after an attacker published malicious versions of TanStack packages last week. The TanStack Team 📺 The TanStack Start Story: Tanner Linsley on Competing with Next.js – A candid 40-minute interview with TanStack’s founder. Nuno Maduro 📄 Cross-Document View Transitions: The Gotchas Nobody Mentions Durgesh Rajubhai Pawar (CSS Tricks) |
💡 Schedule-X is another great option in this space and v4.6 just landed. |
Alien Signals: 'The Lightest Signal Library' — Boils the best of Vue, Preact and Svelte’s approaches down into the lightest signal library going. A push-pull reactivity core so well-tuned it got merged back into Vue. Johnson Chu |
HyperFormula: The headless spreadsheet engine with 400+ Excel-compatible formulas. Run complex calculations at high speed.
Flaky tests slowing down dev? Meticulous gives engineers confidence to ship faster by autonomously testing every edge case of your web app.
⚙️ Middleware, but for AI agents. Compose Claude Code, Codex & Gemini as one TypeScript harness — 100+ agent recipes. agentfield.ai/github. |
|
📢 Elsewhere in the ecosystem |
|
Комментарии
Отправить комментарий