Sign in

Ayu

@ayuhito.com
89 followers 78 following 33 posts

fontsource.org and medama.io creator • open-source enthusiast building tools to simplify the web • ayuhito.com • github.com/ayuhito

PostsRepliesMedia
Reposted by Ayu
Filippo Valsorda @filippo.abyssdomain.expert · 21/07/2026
Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!
words.filippo.io
Opaque, Interoperable Passkey Records (and a Go API)
Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.
519741
Reposted by Ayu
warpfork @warpfork.bsky.social · 29/06/2026
1000x this. This is the way. When I've done perf quests in Golang, this is pretty much how: I wrote scripts to grep the assembler phase for any occurrences of allocations. It's correct and it's powerful. Something like borrow checkers is actually weaker: nothing stops you from tossing in a clone.
5224
Reposted by Ayu
rich harris @rich-harris.dev · 30/04/2026
the kindest possible thing i could say about chrome's proposal is that it is extremely premature. the least kind would be a violation of this site's terms and conditions
31148
Reposted by Ayu
Ethan Mollick @emollick.bsky.social · 28/04/2026
This is an actual line that was added to the official system prompt for Codex for GPT-5.5 by OpenAI. Usually the system prompt is as minimal as possible, so I assume it would otherwise mention goblins a lot. AIs are weird.
571323266
Reposted by Ayu
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.
wiz.io
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
735099
Reposted by Ayu
Brandon Dail @brandondail.com · 27/01/2026
Here's your friendly reminder that CSS selectors are global and evaluated RTL, so if you have selectors that are very broad like `.container > div` you might be impacting performance in a measurable way 🙈 Before and after profile of server switching after some selector optimizations in @discord.com
Two screenshots from Chrome DevTools side-by-side. On the left it says "Before" and shows that rendering took 1518 milliseconds. On the right it says "After" and shows that rendering took 610 milliseconds.
1316518
Reposted by Ayu
Jay Conrod @jayconrod.com · 15/01/2026
New blog post, with a perhaps mildly unpopular opinion: jayconrod.com/posts/133/in...
jayconrod.com
Integration tests are best tests
Itegration tests are the most important kind of tests. You should strive for excellent integration test coverage and invest relatively little time in unit tests. I've believed this since I worked on c...
4317
Ayu @ayuhito.com · 12/01/2026
I don’t hate it. But I’d still probably stick to UUIDs because it’s standardised which lets random services work together without much thinking e.g. Postgres UUID type at least gives me free validation and storage optimizations regardless of what app generates the ID and so on…
010
Ayu @ayuhito.com · 12/01/2026
What are better alternatives that people should switch to?
100
Reposted by Ayu
TypeScript @typescriptlang.org · 02/12/2025
We've got some updates on TypeScript 7! The new native port - can type-check any project - supports --build and --incremental - has rich editor features implemented - is still 10x faster and is ready for you to try today! devblogs.microsoft.com/typescript/p...
devblogs.microsoft.com
Progress on TypeScript 7 - December 2025 - TypeScript
Earlier this year, the TypeScript team announced that we’ve been porting the compiler and language service to native code to take advantage of better raw performance, memory usage, and parallelism. Th...
525355
Ayu @ayuhito.com · 19/11/2025
Just cut another release for modern-tar. I’ve been benchmarking it a bunch and it seems like we’re the fastest Node.js tar library on all benchmarks. Especially in a big way for many small files which are typical for node_modules like directories 🚀
github.com
GitHub - ayuhito/modern-tar: 🗄 Zero dependency streaming tar parser and writer for every JavaScript runtime.
🗄 Zero dependency streaming tar parser and writer for every JavaScript runtime. - ayuhito/modern-tar
020
Reposted by Ayu
Jake Bailey @jakebailey.dev · 10/07/2025
[DEP0169] DeprecationWarning: `url.parse()` b̶͎͆e̴̛̟͖͠havior is not standardized and̴̃͜ ̷͈̤̿͠p̴͔̉͊rone to errors that hav̶̧̗̄̂e security impl̶̖̗̎͒ï̵̩͈c̸̢̑̍a̶̫̝͝t̴̖̒i̵̛̲͙̓ő̵̩̣̚n̴̰̏s. Use the Ẃ̷̯̬̟̫͉̠̞̬̣̃̀̀̒͒͊̓̍́H̷̙͇͇̞̘̝͍̣͍̲̼̕̕̚͜A̶̺͇͒Ţ̴̠͍̻̯̮̬͇͍̈͐̆͗W̶̪͈̤͊́͑̀͜͜G̷͇͒̋̿̾̔̌̾͊͘͝͝͝ URL API instead. C̸͍̤̥̲̩̣̭̈͒̉̅̓͑͋̋͆̋̾͐̃V̴̦̖͚̥̘̲̦̺̣͌̎̒͌̅̊É̶̼̟̈́͛̋̿̈́͛̕s are not issued for `url.parse()` v̶̘͔͎͚͔̩̻̰̌͋͂͊̕͝ư̷̻͋͗͌̽́̓̂̋̅̓ḽ̶̢̳̥̗̯̻̳̜͉́̇͝͝n̴̬̆̀͂͂͛͘͘͝͝͠ë̴̯̺͎͉͇̝͂̅̍̀͌̽͂͐́̏̚ͅŗ̷̢̥̮͚̩͕̬̳̹̫͎̝̹̑̾͛͐͌̅̂̌͛́͒̚̚͝͝ͅḁ̷̡͇͙͓̺̮̥̠͉̪̤͆̉̽̆̆́͠b̶̢̲̯̼̭͖̖̳̲̘̫̫̳̳͔͂̃̾͐͐̏̔͆̎́̚̕͜͠i̵̹͍͔̟̞̲̫̪͍̽͋̔͑ļ̷̢͔̬̫̫͔̤͇̮̙̌̊̿͋̂͛̉̾͜i̵̢̘̜͚̺̬̊́̽̔̓̈́͊t̵͕̗̲̖̟͕͕͉̞͕̞̜͚͒̿͐͜ͅi̶̤̖̥̥̺͋̎͛͊̐̌͑͐̋̓̚̕͝ͅe̸̪̖͒̈́̾ş̴̨̢̖͓͚͎͇̣̥͓̣̤̪̜͐͗̃̏̓ͅ.
7536
Reposted by Ayu
James @43081j.com · 31/10/2025
here's what the @e18e.dev community has been upto for the last couple of months! huge thanks to everyone involved 🎉 much more to come very soon, and we have a roadmap of some super useful tools in the works
e18e.dev
Community Showcase (Q3 2025)
An update on what the community have been up to in Q3 of 2025
04111
Ayu @ayuhito.com · 31/10/2025
I’ve read your blog posts many on sustaining yourself as a FT OSS developer which was inspiring, but alas you deserve more. Congrats!
120
Ayu @ayuhito.com · 31/10/2025
One of the more awesome blog posts by the Go team that simplified a not so simple topic really well!
000
Reposted by Ayu
oli @olil.bsky.social · 20/10/2025
Edinburgh castle failing to render, likely thanks to the AWS outage
A picture of a foggy street
8490741385
Reposted by Ayu
Cloudflare @cloudflare.social · 14/10/2025
Cloudflare investigated performance benchmark results for Workers, uncovering and fixing issues, making Workers faster for all customers. blog.cloudflare.com/unpacking-cloud…
blog.cloudflare.com
Unpacking Cloudflare Workers CPU Performance Benchmarks
Cloudflare investigated CPU performance benchmark results for Workers, uncovering and fixing issues in infrastructure, V8 garbage collection, and OpenNext optimizations. These improvements have made C...
0244
Reposted by Ayu
Cloudflare @cloudflare.social · 08/10/2025
84 million requests a second means even rare bugs appear often. We'll reveal how we discovered a race condition in the Go arm64 compiler and got it fixed. cfl.re/3WrpKrB
cfl.re
How we found a bug in Go's arm64 compiler
84 million requests a second means even rare bugs appear often. We'll reveal how we discovered a race condition in the Go arm64 compiler and got it fixed.
071
Ayu @ayuhito.com · 08/10/2025
New architecture makes a centralised interface that only accepts Uint8Array chunks which allows us to skip converting between streams entirely 👾
000
Ayu @ayuhito.com · 08/10/2025
Released v0.4.0 of modern-tar today! Huge performance improvements and a new architecture. We originally converted Web Streams into Node Streams to make maintaining cross compatibility manageable… but synchronising those two felt very incomplete and was prone to so so many race conditions 👾
github.com
GitHub - ayuhito/modern-tar: 🗄 Zero dependency streaming tar parser and writer for every JavaScript runtime.
🗄 Zero dependency streaming tar parser and writer for every JavaScript runtime. - ayuhito/modern-tar
110
Reposted by Ayu
VoidZero @voidzero.dev · 06/10/2025
The world depends on Open Source software After joining the @opensourcepledge.com last year, we are increasing our annual commitment to $48,360 for 2025. Take a look at our full 2025 report on which vital projects we're sponsoring and how the money is distributed. voidzero.dev/posts/oss-pl...
voidzero.dev
VoidZero's 2025 Open Source Pledge Report
VoidZero is continuing our commitment to the Open Source Pledge and donating $48,360 or $3,454 per VoidZero developer to external open source projects
0567
Reposted by Ayu
Jake Bailey @jakebailey.dev · 30/09/2025
Fun little Go compiler CL merged today: go.dev/cl/706655 Uninlined generic functions have a "dict" arg, since Go generics are neither erased nor monomorphized, but instead instantiated for each "GC shape" (e.g. T=*int and T=*float64 get the same code, but T=int32 and T=int64 do not).
1204
Ayu @ayuhito.com · 30/09/2025
It’s hard to express how I love working with Go in my day job and wouldn’t want anything else, but could not say the same for JavaScript. But I absolutely enjoy working with JavaScript as a hobby, whilst Go feels a little bit more like a chore. Both communities are 🔥 though
010
Ayu @ayuhito.com · 30/09/2025
I didn’t expect the savings to be that great! Glad it worked out!
010
Reposted by Ayu
Bjorn Lu @bluwy.me · 30/09/2025
`@bluwy/giget-core` is now back to a small 90kB install size thanks to @ayuhito.com's `modern-tar` package! Perf is also slightly faster.
packagephobia.com results for the `@bluwy/giget-core` package, showing a sharp decrease in install size in its latest 0.1.4 version
3143
Reposted by Ayu
Cloudflare @cloudflare.social · 26/09/2025
We reduced Cloudflare Workers cold starts by 10x by optimistically routing to servers with already-loaded Workers. Learn how we did it here. cfl.re/3Kf8PGa #BirthdayWeek
cfl.re
Eliminating Cold Starts 2: shard and conquer
Earlier this month, we finished deploying a new technique intended to keep pushing the boundary on cold start reduction.
0162
Ayu @ayuhito.com · 25/09/2025
I’ll look into it! I don’t expect it to be faster at all as some alternatives use specialised dependencies to replace Node streams entirely. But I also don’t believe the difference is significant.
000
Ayu @ayuhito.com · 25/09/2025
🗄️ modern-tar I just released a new zero dependency streaming tar parser and writer that is built with the browser-native Web Streams API! Please check it out! It's awesome 📼 github.com/ayuhito/mode...
github.com
GitHub - ayuhito/modern-tar: 🗄 Zero dependency streaming tar parser and writer for every JavaScript runtime.
🗄 Zero dependency streaming tar parser and writer for every JavaScript runtime. - ayuhito/modern-tar
1264
Reposted by Ayu
Marc Brooker @marcbrooker.bsky.social · 23/09/2025
New blog post, reflecting on nearly seven years since the Firecracker launch, and how we're using Firecracker to power serverless databases (in Aurora DSQL) and infrastructure for AI agents (in Bedrock AgentCore). Here's the post: brooker.co.za/blog/2025/09...
brooker.co.za
Seven Years of Firecracker - Marc's Blog
12511
Reposted by Ayu
VoidZero @voidzero.dev · 22/09/2025
Rolldown v1.0.0-beta.39 has been released! ⚡ macOS Performance Boost: 10%-30% faster bundling, up to 45% in extreme cases. 🎯 Cross-Chunk Optimization: Support for __NO_SIDE_EFFECTS__ annotation, as well as better tree-shaking across module boundaries and more efficient DCE
1708
Ayu @ayuhito.com · 22/09/2025
one of the most common issues is inconsistencies in builds due to the weaknesses of scraping Google Fonts is incredibly dynamic serving completely different files depending on your useragent, so often there are tradeoffs that lead to worse situations for one type of user over another
000
Ayu @ayuhito.com · 22/09/2025
really excited to merge this PR that enables Fontsource to build fonts from source rather than scraping all of Google Fonts if it works out, it lets us close tons of issues and even makes reaching the fabled zero issues repo a realistic goal!
github.com
feat(core): new package by ayuhito · Pull Request #1079 · fontsource/fontsource
Related: #39, #588, #728, #730, #773, #792, #908, #929, #984, #989, #990, #1036, #1050 and maybe more. This is an initial implementation of an experimental package that will build Google Fonts from...
110
Ayu @ayuhito.com · 20/09/2025
some npm folks might be looking into scope based solutions
github.com
🚀 Coming Soon: OpenID Connect (OIDC) Support for npm Registry · community · Discussion #161015
Hello npm community! 👋 We're excited to announce that we're bringing OpenID Connect (OIDC) authentication to the npm registry! This new feature will enable more secure, token-less authentication fo...
120
Reposted by Ayu
A. H. Zakai @kripken.com · 17/09/2025
The WebAssembly 3.0 spec is complete! webassembly.org/news/2025-09... This includes major features like GC, 64-bit memories, exceptions, and tail calls.
webassembly.org
Wasm 3.0 Completed - WebAssembly
WebAssembly (abbreviated Wasm) is a binary instruction format for a stack-based virtual machine. Wasm is designed as a portable compilation target for programming languages, enabling deployment on the...
59837
Ayu @ayuhito.com · 17/08/2025
Midnight shower thought - I wonder if we could leverage the AST in tsgo and transpile the code into an equivalent Go AST? With a ready to use GC and a packed standard library for I/O, I wonder if JS->Go native could be a thing. (There’s definitely limitations, but it could be worth it)
000
Ayu @ayuhito.com · 19/07/2025
TIL Word and Excel documents are just zip files stuffed with XML
000
Reposted by Ayu
Sarah Drasner @sarahedo.bsky.social · 12/07/2025
One of the great failures of the human mind is to not value security until something breaks
910310
Ayu @ayuhito.com · 13/07/2025
It’s “subtle coloring” where you still have to poison functions with a special parameter. Which is similar to Go and its context parameter, that you also should pass everywhere. Imo, still a better approach since you’re more explicit about it.
000
Ayu @ayuhito.com · 09/07/2025
When you have the urge to run a CT log but can’t justify to your company why they should fund it :p
010
Reposted by Ayu
The New Stack @thenewstack.io · 21/06/2025
@vite.dev and @vuejs.org creator @evanyou.me is tired of JavaScript's fragmented tooling ecosystem. He provides insight into his team's efforts to fix it. By @lorainelawson.bsky.social
bit.ly
Vite’s Creator on a Unified JavaScript Toolchain and Vite+
Vite and Vue creator Evan You is tired of JavaScript's fragmented tooling ecosystem. He provides insight into his team's efforts to fix it.
1306
Reposted by Ayu
DuckDB @duckdb.org · 12/06/2025
We released DuckDB 1.0.0 a little over a year ago with a small easter egg. Since then, no one reported finding it, so we're revealing it: the hash of the DuckDB 1.0.0 binary starts with the duck emoji: 0x1f986 = 🦆.
512315
Reposted by Ayu
VoidZero @voidzero.dev · 10/06/2025
We're thrilled to announce the first stable release of Oxlint - version 1.0! Our Rust-powered JavaScript/TypeScript linter delivers 50~100x faster performance than ESLint with 500+ rules and zero configuration required. Time to give it a try! voidzero.dev/posts/announ...
voidzero.dev
Announcing Oxlint 1.0
The first stable version of Oxlint, a fast & easy-to-use Rust-powered linter for JavaScript and TypeScript, is out. Learn about its 50~100x speed advantage over ESLint, support for 500+ rules, real-wo...
1030161
Reposted by Ayu
Rob Palmer @robpalmer.bsky.social · 22/05/2025
TypeScript excitement 😉 The "tsgo" native Go port is now available on npm as an early preview 🎉 🔷 Checker: Most projects will see error parity with v5.8 🔷 Now supports JS and JSX 🔷 LSP: Auto-completions work 🔷 Perf: 10x win persists 🔷 API: Sync access via a Node addon
29116
Reposted by Ayu
Jake Bailey @jakebailey.dev · 20/05/2025
Happy to say that I'll be speaking at @gophercon.com 2025 about TypeScript's port to Go! There's a lot of interesting stuff to talk about, from the effort's inception, the actual process of porting, and all of the Go stuff we learned along the way (gotchas, perf). www.gophercon.com/agenda/sessi...
Screenshot of the GopherCon agenda

Wed Aug 27, 5:00 PM - 5:45 PM EDT / 2:00 PM - 2:45 PM Your local time   (45 min)
Porting the TypeScript Compiler to Go for a 10x Speedup
The Overview, Room TBD, Level 5, North Javits
From the beginning, the TypeScript compiler has been self-hosted, evolving alongside a growing ecosystem of millions of developers. As time went on, we faced challenges with the compiler's performance, largely inherent to the implementation language itself. Through experimentation and testing, we found Go to be an excellent language for our specific needs; a perfect porting language. In this talk, we will explore the process of porting the 150,000+ line TypeScript compiler and its 90,000+ tests to Go, the challenges we faced, lessons we learned, all leading to an overall 10x performance improvement over our previous implementation.

Talk/Attendee Level: Intermediate

Picture of me, with:

Jake Bailey
Senior Software Engineer
Microsoft
1688
Ayu @ayuhito.com · 22/04/2025
TIL you can just send two requests to object storage in parallel and drop your tail latencies 📉
010
Reposted by Ayu
Phil Eaton @eatonphil.bsky.social · 18/04/2025
This is a fantastic post, categorizing transaction schemes transactional.blog/blog/2025-de...
0171
Ayu @ayuhito.com · 06/04/2025
I've been finding more time to work on OSS these days! Was able to ship out a couple new releases for my Go projects: ⭐ github.com/medama-io/me... - Added an optional tool to automatically provision SSL certificates ⭐ github.com/medama-io/go... - Added many more convenience constants and helpers
github.com
GitHub - medama-io/medama: Self-hostable, privacy-focused website analytics.
Self-hostable, privacy-focused website analytics. Contribute to medama-io/medama development by creating an account on GitHub.
010
Reposted by Ayu
Go @golang.org · 01/04/2025
🎉 Go 1.24.2 and 1.23.8 are released! 🔒 Security: Includes a security fix for net/http (CVE-2025-22871). 🔈 Announcement: groups.google.com/g/golang-ann... 📦 Download: go.dev/dl/#go1.24.2
Go 1.24.2 and 1.23.8 are released!
07720
Ayu @ayuhito.com · 29/03/2025
honestly now I want to do this too 😂
010
Reposted by Ayu
danielroe @danielroe.dev · 28/03/2025
inspired by @harlanzw.com's cool meetup page, I added what is possibly a terrible feature to my site. - location auto-updates daily using apple shortcuts - bigdatacloud.com reverse geocodes it - stores it in @sanity.io - displays it as an emoji in header + in a line of text privacy? what privacy?
A contact me section of a website with the text highlighted: "I'm planning to be in Edinburgh, Scotland today."

The full section reads:

contact me

I'd love to connect on social media (Bluesky, LinkedIn, Mastodon, Instagram) or you can view an aggregated feed on this site. You can also get in touch by email — and I have an open diary if you want to book a meeting.

Drop me a line if you'd like to meet up in person! I'm planning to be in Edinburgh, Scotland today.
10342