Sign in

DaloyJS

@daloyjs.dev
12 followers 43 following 21 posts

daloyjs.dev is the first TypeScript REST API framework built for secure AI-assisted services.

PostsRepliesMedia
DaloyJS @daloyjs.dev · 05/08/2026
Tanya Janca's DevSecStation episode on secure defaults matches why we built DaloyJS the way we did. Security on by default, insecure paths explicit and effortful. Login with JWT is not enough, and telling an AI to build an API does not make the easy path safe. daloyjs.dev/blog/secure-...
daloyjs.dev
Willpower Is Not a Security Control: Secure Defaults Beat Training, and AI Does Not Fix That · DaloyJS
Tanya Janca's DevSecStation episode on secure defaults matches why I built DaloyJS the way I did: security on by default, insecure paths explicit and effortful. Login with JWT is not enough, and telli...
130
DaloyJS @daloyjs.dev · 04/08/2026
The global average hit $4.99 million USD, AI-driven attacks are up 56%, and 92% of AI-related breaches lacked basic access controls. Here is a quick summary of the IBM Cost of a Data Breach 2026 report. daloyjs.dev/blog/ibm-cos...
daloyjs.dev
IBM Cost of a Data Breach 2026: $5M Average, AI on Both Sides, and What Your Backend Still Controls · DaloyJS
Ponemon interviewed 3,500 people across 602 breached organizations. The global average hit $4.99M, AI-driven attacks are up 56%, and 92% of AI-related breaches lacked basic access controls. Here is th...
000
DaloyJS @daloyjs.dev · 03/08/2026
The DaloyJS 1.0.0 stable version is here 🎉🎉🍻🍻. Secure-by-default HTTP routes matter more now because APIs get scaffolded and shipped faster than people configure them. If the framework doesn't block the dumb stuff first, production often ships without it. daloyjs.dev/blog/daloyjs...
daloyjs.dev
DaloyJS 1.0.0 Is Out, and Almost Every Late Bug Was in the Wiring · DaloyJS
The API is frozen and semver starts now. The interesting part of getting here: nine release candidates of live pentesting, where the findings were almost never inside a middleware. They were between t...
031
DaloyJS @daloyjs.dev · 03/07/2026
DaloyJS 1.0.0-rc.0 is out: the first release candidate. The API is frozen. Only bug fixes and docs from here to 1.0.0 GA. The beta run added a dependency-free MCP server and a faster Node hot path along the way. Come build on it and tell me what broke. daloyjs.dev/blog/daloyjs...
daloyjs.dev
DaloyJS 1.0.0-rc.0: The First Release Candidate · DaloyJS
The beta said 'nothing changed, on purpose.' The release candidate says 'the door is now locked.' Here is what the RC means, what actually landed across the beta train (spoiler: MCP), and the short ho...
030
DaloyJS @daloyjs.dev · 30/06/2026
AI now writes ~24% of production code, and 1 in 5 teams report a serious AI-code incident. Our take on what Aikido Security + Sapio Research's State of AI in Security & Development 2026 means for backend teams: stricter contracts, CI gates, less tool noise. daloyjs.dev/blog/state-o...
daloyjs.dev
The State of AI in Security 2026: 450 Teams, One Uncomfortable Pattern, and What Your Backend Can Do About It · DaloyJS
Aikido and Sapio Research surveyed 450 developers, CISOs, and AppSec engineers across Europe and the US. The headline: AI now writes a quarter of production code, 1 in 5 teams had a serious incident b...
020
DaloyJS @daloyjs.dev · 21/06/2026
DaloyJS 1.0.0-beta.0 is live 🎉 After a long 0.x run, the API is feature-complete and stable for 1.0. Same secure-by-default framework, braver version number. daloyjs.dev/blog/daloyjs...
daloyjs.dev
DaloyJS 1.0.0-beta.0 Is Here (and Nothing Broke, On Purpose) · DaloyJS
After a long 0.x preview line, DaloyJS enters its 1.0.0 beta. The funny part: the most important line in this changelog is that nothing changed. Here is what the beta means, how to install it, and wha...
010
DaloyJS @daloyjs.dev · 06/06/2026
Why DaloyJS Is the Framework to Bet On in 2027 open.substack.com/pub/daloyjs/...
open.substack.com
Why DaloyJS Is the Framework to Bet On in 2027
Part 4: The Full Picture
000
DaloyJS @daloyjs.dev · 06/06/2026
Writing APIs That Don't Make You Sad open.substack.com/pub/daloyjs/...
open.substack.com
Writing APIs That Don't Make You Sad
Part 3: The Developer Experience of DaloyJS
000
DaloyJS @daloyjs.dev · 06/06/2026
Your npm install is an Attack Surface open.substack.com/pub/daloyjs/...
open.substack.com
Your npm install Is an Attack Surface
Part 2: How DaloyJS Protects You from Supply-Chain Attacks
000
DaloyJS @daloyjs.dev · 06/06/2026
Why DaloyJS Is the Best Framework for Your Modern Web App open.substack.com/pub/daloyjs/...
open.substack.com
Why DaloyJS Is the Best Framework for Your Modern Web App
Part 1: Built-in Security That Actually Ships
000
DaloyJS @daloyjs.dev · 01/06/2026
RFC 9457 application/problem+json out of the box. HttpError, ValidationError, UnauthorizedError, TooManyRequestsError, all with automatic 5xx redaction in production. daloyjs.dev/docs/errors
daloyjs.dev
Errors & problem+json · DaloyJS
Throw typed errors in DaloyJS and have them serialized as RFC 9457 problem+json responses by default. Customize, extend, and document errors in OpenAPI.
000
DaloyJS @daloyjs.dev · 28/05/2026
Current status: squeezing every millisecond out of Daloy 🏎️ We’re in a full performance pass across the entire framework, no feature work, just making things fast. Benchmarks incoming. 👉 daloyjs.dev
daloyjs.dev
The runtime-portable TypeScript framework with supply-chain-aware defaults · DaloyJS
DaloyJS is a secure-by-default TypeScript/JavaScript web framework with portable runtime guardrails and package provenance you can verify on any CI host. It combines FastAPI-grade docs, Hono-style por...
000
DaloyJS @daloyjs.dev · 28/05/2026
If you're building public APIs, want security without a checklist, or have LLMs scaffolding your code, you need secure defaults baked in from the start, not bolted on later. DaloyJS gets this right. daloyjs.dev
000
DaloyJS @daloyjs.dev · 28/05/2026
Most JS frameworks being insecure by default isn’t wisdom, it’s a historical accident of “stay minimal and unopinionated.” DaloyJS is the correction. Secure defaults shouldn’t be a checklist. They should be the starting line. daloyjs.dev
100
DaloyJS @daloyjs.dev · 23/05/2026
Hono: smallest portable router. Fastify: mature Node ecosystem. Elysia: Bun-first TypeScript magic. Daloy: API contracts, docs, generated clients, tests, runtime portability, and secure defaults from one source of truth.
010
DaloyJS @daloyjs.dev · 22/05/2026
Using @nextjs.org and deploying to @vercel.com automatically results in a 100 Lighthouse score without doing anything. 🤯
010
DaloyJS @daloyjs.dev · 22/05/2026
Ten years of shipping fullstack apps, one Filipino dev in Norway, and the framework I kept wishing existed at 2 am. The honest origin story of DaloyJS. daloyjs.dev/blog/the-flo...
daloyjs.dev
The flow I wished I had: why we built DaloyJS · DaloyJS
Ten years of shipping fullstack apps, one Filipino dev in Norway, and the framework I kept wishing existed at 2am.
020
DaloyJS @daloyjs.dev · 21/05/2026
Just as you wouldn't drink from a contaminated stream, you shouldn't build on a contaminated supply chain. DaloyJS is the "filtration system" for modern JS development.
000
DaloyJS @daloyjs.dev · 16/05/2026
Our new documentation is built using @nextjs.org, @shadcn.com, and @tailwindcss.com. daloyjs.dev
000
DaloyJS @daloyjs.dev · 16/05/2026
contract-first + typed client codegen + security-by-default 🙌 daloyjs.dev on public preview.
030