Sign in

Haoqun Jiang

@haoqun.dev
456 followers 1.1K following 84 posts

@vuejs.org core team member. @vite.dev core team emeritus. Worked on JS tooling. Learning new things. haoqun.dev

PostsRepliesMedia
Haoqun Jiang @haoqun.dev · 18/09/2026
🚨 ACTIVE SUPPLY CHAIN ATTACK If you haven't removed `actions-cool/issue-helper` from your GitHub actions, it's back. And the latest release still points to the malicious commit, same as 4 months ago. www.stepsecurity.io/blog/actions...
stepsecurity.io
actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials - StepSecurity
The popular GitHub Action actions-cool/issues-helper has been compromised. Every existing tag in the repository has been moved to point to a single imposter commit that does not appear in the action's...
110
Haoqun Jiang @haoqun.dev · 04/09/2026
One benefit of having good physical modeling of the motion system is that you can build delightful visualizations very easily. Much more compelling than function graphs.
0210
Haoqun Jiang @haoqun.dev · 01/09/2026
It's always great to see a years-old issue finally get fixed! This, plus content mappers, I'd say TypeScript 7.1 might even have a bigger impact on the tooling ecosystem than 7.0 github.com/microsoft/Ty...
github.com
Ambient Module Declarations for Import Attributes (formerly known as Import Assertions) · Issue #46135 · microsoft/TypeScript
Suggestion 🔍 Search Terms import attributes, import assertions, ambient module ✅ Viability Checklist My suggestion meets these guidelines: This wouldn't be a breaking change in existing TypeScript/...
2285
Haoqun Jiang @haoqun.dev · 26/08/2026
Finally built a truly native-feeling bottom sheet for the web. Turns out it’s surprisingly hard to get right, even with good reference implementations.
020
Haoqun Jiang @haoqun.dev · 25/08/2026
Negative parallelism, antithetical parallelism, rhetorical padding, aphoristic compression, metaphorical reification, conceptual sloganization, interpretive closure... AI really is a master of rhetorical packaging.
100
Haoqun Jiang @haoqun.dev · 22/06/2026
#TIL iOS users generally see fewer CAPTCHAS when browsing the web.
Screenshot of an iPhone settings screen for "Automatic Verification" feature. A blue icon showing an ID card with a checkmark appears above the heading “Access apps and websites faster and easier.” Supporting text explains that iCloud can automatically and privately verify the user’s device and account to bypass CAPTCHAs in apps and on the web. A “Learn more…” link is shown, and the “Automatic Verification” toggle at the bottom is turned on (green).
110
Haoqun Jiang @haoqun.dev · 19/06/2026
#TIL Cloudflare Pages still runs Node.js 22.16, while many packages now require 22.18+. This can break native packages that ship platform binaries via `optionalDependencies`, because pnpm silently drops those binaries when the Node.js version doesn't meet the requirement.
210
Haoqun Jiang @haoqun.dev · 17/06/2026
Babel 8! After all these years! What a surprise! babeljs.io/blog/2026/06...
babeljs.io
Releasing Babel 8 today: ESM-only, drop ES5 default, and a smooth migration path · Babel
Today we are releasing Babel 8. It's been 8 years since we released Babel 7. And that's not without reason.
05812
Haoqun Jiang @haoqun.dev · 08/06/2026
#TIL iOS Safari limits the frame rate to around 60fps by default, and you can turn it off to enjoy a smoother web browsing experience (Settings -> Safari -> Advanced -> Feature Flags -> Prefer Page Rendering Updates near 60fps)
Screenshot of the iOS Safari WebKit Feature Flags settings page showing the option “Prefer Page Rendering Updates near 60fps” with the toggle switched off.
130
Haoqun Jiang @haoqun.dev · 14/05/2026
docs.zizmor.sh/audits/ It's always interesting to read the rules in an auditing/linting tool's documentation. Surprised by how many footguns exist in common GitHub Actions usage patterns.
docs.zizmor.sh
Audit Rules - zizmor
Audit rules, examples, and remediations.
030
Haoqun Jiang @haoqun.dev · 27/04/2026
I spent the last two weeks vibe-coding a port of Vue’s style compiler to LightningCSS, and I’m seeing ~2.4–5× speedups in most cases: npmx.dev/package/@lig... Pretty happy with where the architecture and performance have landed.
npmx.dev
@lightning-vue/compiler - npmx
Vue SFC compiler module with a Lightning CSS-backed style compiler
120
Haoqun Jiang @haoqun.dev · 31/03/2026
One more reason to use @pnpm.io and @npmx.dev: trust policy downgrade becomes visible and preventable
Multiple warnings shown on https://npmx.dev/package/axios

1. Trust downgrade
This version was published without trusted publishing. Install commands are pinned to 1.14.0, the last version with trusted publishing.

2. You might not need this dependency.
The community has flagged this package as having more performant alternatives. Learn more at https://e18e.dev/docs/replacements/fetch.htmlPNPM documentation:

trustPolicy
Added in: v10.21.0

Default: off
Type: no-downgrade | off
When set to no-downgrade, pnpm will fail if a package's trust level has decreased compared to previous releases. For example, if a package was previously published by a trusted publisher but now only has provenance or no trust evidence, installation will fail. This helps prevent installing potentially compromised versions. Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Starting in v10.24.0, prerelease versions are ignored when evaluating trust evidence for a non-prerelease install, so a trusted prerelease cannot block a stable release that lacks trust evidence.
39514
Haoqun Jiang @haoqun.dev · 30/01/2026
Moltbook is fascinating.
020
Haoqun Jiang @haoqun.dev · 30/11/2025
TIL that IPv4 over IPv6 is a mainstream home internet setup in Japan to avoid old PPPoE limits. It took me back to my college years in China, when I was playing with IPv6 over IPv4 because native IPv6 wasn’t widely available. It’s really interesting to see how differently things evolved here.
120
Reposted by Haoqun Jiang
Emanuele (Ema) @ematipico.xyz · 10/11/2025
@pnpm.io getting better by the day pnpm.io/blog/release... I still can't believe that a one-person package manager is doing better than npm CLI, owned by a corporate, where the resources of the two projects are incomparable. Draw your own conclusions.
pnpm.io
pnpm 10.21 | pnpm
Added support for Node.js runtime installation for dependencies and a setting for configuring trust policy.
2374
Haoqun Jiang @haoqun.dev · 04/11/2025
Apple forgot to turn off sourcemaps when shipping their new App Store website lol github.com/rxliuli/apps...
github.com
060
Haoqun Jiang @haoqun.dev · 20/10/2025
lmao 🤣
040
Reposted by Haoqun Jiang
pnpm @pnpm.io · 16/09/2025
Published an article about mitigating supply chain attacks with pnpm pnpm.io/supply-chain...
pnpm.io
Mitigating supply chain attacks | pnpm
Sometimes npm packages are compromised and published with malware. Luckily, there are companies like [Socket], [Snyk], and [Aikido] that detect these compromised packages early. The npm registry usually removes the affected versions within hours. However, there is always a window of time between when the malware is published and when it is detected, during which you could be exposed. Fortunately, there are some things you can do with pnpm to minimize the risks.
05711
Reposted by Haoqun Jiang
James @43081j.com · 09/09/2025
some thoughts about the bloat introduced by edge-case first libraries
43081j.com
The bloat of edge-case first libraries
How building edge-case first led to bloated, overly-granular libraries and what we can do about it
1213044
Reposted by Haoqun Jiang
Kevin Deng @sxzz.dev · 15/08/2025
We encourage everyone to migrate from using npm publish tokens to trusted publisher! github.com/e18e/ecosyst...
github.com
Promote npm trusted publisher · Issue #201 · e18e/ecosystem-issues
Motivation npm Trusted Publishing is now generally available, allowing package owners to publish npm packages via CI without manually generating npm tokens. This method greatly reduces the risk of ...
1275
Haoqun Jiang @haoqun.dev · 04/08/2025
Finally, finally! SALVATION HAS ARRIVED! Time to refactor every GitHub Actions workflow! 🎉
030
Haoqun Jiang @haoqun.dev · 08/07/2025
Wow, this was unexpected. I've got mixed feelings, but huge congrats to the team!
271
Haoqun Jiang @haoqun.dev · 20/03/2025
Finally. I wish the community could migrate from the `packageManager` field to `devEngines` following this - always pinning versions is good in theory but way too cumbersome in practice.
070
Reposted by Haoqun Jiang
James @43081j.com · 14/03/2025
This thing is so useful. Especially for security - ensuring the published package is actually what exists in the source
0145
Haoqun Jiang @haoqun.dev · 24/02/2025
😮‍💨 Still paying down the tech debt that accumulated during the transition from non-scoped packages to scoped ones… I’m lucky to have subscribed to @lirantal.com’s Node.js security newsletter. It’s always informative! - www.alxndrsn.com/2024-08-01-n... - www.nodejs-security.com/newsletter/n...
GitHub commit message:

docs: add --no flag to npx command to avoid downloading the incorrect package from npm
Thanks to @alxndrsn for finding this issue and the insightful blog post.
https://www.alxndrsn.com/2024-08-01-npx-binary-confusion/

Also thanks to @lirantal for his newsletter that brought this issue to
my attention.
https://www.nodejs-security.com/newsletter/npm-supply-chain-security-prisma-orm-security-fun-nodejs-security-challenges

Git Diff:

- npx vue-cli-service serve
+ npx --no vue-cli-service serve
261
Reposted by Haoqun Jiang
Marvin Hagemeister @marvinh.dev · 23/02/2025
Speeding up the JavaScript ecosystem part 11 is here! This time we're looking at: Extending Rust tools with JavaScript plugins marvinh.dev/blog/speedin...
marvinh.dev
Speeding up the JavaScript ecosystem - Rust and JavaScript Plugins
Up until recently, supporting JavaScript in Rust based tools has been deemed not worth it. The main concern is the overhead of the de-/serialization cost when sending data back and forth. But there is...
914339
Haoqun Jiang @haoqun.dev · 21/02/2025
Looks like Reka UI, the rebranded Radix Vue component library, has just got officially released 👀 It's such a cool name. Can't wait to try it out!
reka-ui.com
Reka
An open-source library with unstyled, primitive components, accompanied by a variety of examples & use cases ready to be integrated into your projects.
3877
Haoqun Jiang @haoqun.dev · 16/02/2025
#TIL So this is the fastest way to import an ES module in the Node.js REPL… How did I never know about the `_` (underscore) auto-assignment in the REPL?! nodejs.org/api/repl.htm... So many wasted keystrokes over the years!
Screenshot of Node.js REPL with the following text:

› await import ("./index.js")
[Module: null prototype] { oneTrueDate: [Function: oneTrueDate] }
_.oneTrueDate(new Date())
'2024-03-01'
081
Haoqun Jiang @haoqun.dev · 05/02/2025
Resurfacing this post now that pnpm 10 is tagged as latest.
131
Haoqun Jiang @haoqun.dev · 30/01/2025
@acemarke.dev Hi Mark, I just noticed that the Bluesky link on your GitHub profile is invalid since you changed your handle. Just wanted to give you a heads-up in case you'd like to update it
230
Haoqun Jiang @haoqun.dev · 29/01/2025
The discoveries are really cool, though
000
Reposted by Haoqun Jiang
sapphi_red @sapphi.red · 20/01/2025
Vite 6.0.9 / 5.4.12 / 4.5.6 has been released with *breaking changes* due to security issues. I recommend upgrading it. Some users may need to update the config options. Please check github.com/vitejs/vite/... if you encountered any errors.
github.com
Any websites were able to send any requests to the development server and read the response
### Summary Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket co...
16418
Haoqun Jiang @haoqun.dev · 16/01/2025
I forked Bun's internal allowlist for those who need the protection from this new default but don't want to bother reviewing every dependency one-by-one: github.com/haoqunjiang/...
github.com
GitHub - haoqunjiang/build-scripts-allowlist: An up-to-date list of common NPM packages that need to run lifecycle scripts during installation.
An up-to-date list of common NPM packages that need to run lifecycle scripts during installation. - haoqunjiang/build-scripts-allowlist
151
Haoqun Jiang @haoqun.dev · 12/01/2025
Trying to make configuring ESLint + Vue + TypeScript a bit easier with a few helper functions, but I'm afraid it might be too intrusive: github.com/vuejs/eslint... What's your opinion about this API?
github.com
130
Reposted by Haoqun Jiang
pnpm @pnpm.io · 28/12/2024
pnpm can block lifecycle scripts of dependencies during installation. This is an opt-in feature though. Should we block them by default? github.com/orgs/pnpm/di...
github.com
Should we block lifecycle script of dependencies during installation? · pnpm · Discussion #8918
There was recently an incident with rspack, where it was published with a postinstall script that contained malware. Such incidents happen from time to time, so it could be a good idea to stop runn...
63810
Haoqun Jiang @haoqun.dev · 11/12/2024
SCOTUSblog IS HERE!!! I’ve been missing them since they left X. As I don’t use TikTok, I’ve had no easy way to follow them (well, I don’t feel like checking websites regularly for updates). So glad to see this account again on a social network!
010
Haoqun Jiang @haoqun.dev · 09/12/2024
Generated a report for vuejs/core too: triagster.com/app/report/p... Many of the duplicated issues already identified by team members, but the report itself is very interesting - it shows some recurring issues, some we'd forgot to add tests for when fixing them the first time…
triagster.com
Triagster
291
Reposted by Haoqun Jiang
Vue School @vueschool.io · 28/11/2024
All things Vue this Black Friday 💚 Get The Ultimate Vue Bundle or Build Your Own to access courses & certificates you need at a great price. Enjoy exclusive savings from @vueschool.io, @masteringnuxt.com, @masteringpinia.com, and @certificates.dev - all in one place. 👉 Get it now vuebundle.com
vuebundle.com
The Ultimate Vue Bundle
Course bundles with all you will need to master the full Vue.js Ecosystem and the official Vue.js certification to prove it! Enjoy big savings the more you buy.
0125
Haoqun Jiang @haoqun.dev · 28/11/2024
Wow, this looks polished!
000
Reposted by Haoqun Jiang
Vite @vite.dev · 26/11/2024
Vite 6.0 is out ⚡️ vite.dev/blog/announc...
vite.dev
Announcing Vite 6
Vite 6 Release Announcement
331462324
Haoqun Jiang @haoqun.dev · 23/11/2024
I too may have followed too many people. But what I like about Bluesky is that it has many unique features to help with such issues. Instead of taking Following feed as the main feed, use Mutuals, Popular With Friends, Quiet Posters, PinPost-random, etc.. Even better, invent your own feed algorithm…
270
Haoqun Jiang @haoqun.dev · 21/11/2024
I only got to know Lucide recently because I found out that @bolt.new's system prompt suggests using icons from `lucide-react` for logos, which turns out to be a good choice.
A screenshot of a code snippet:

```
".bolt/prompt": "For all designs I ask you to make, have them be beautiful, not cookie cutter. Make webpages that are fully featured and worthy for production.\n\nBy default, this template supports JSX syntax with Tailwind CSS classes, React hooks, and Lucide React for icons. Do not install other packages for UI themes, icons, etc unless absolutely necessary or I request them.\n\nUse icons from lucide-react for logos.\n\nUse stock photos from unsplash where appropriate, only valid URLs you know exist. Do not download the images, only link to them in image tags.\n\n"
```

"Use icons from lucide-react for logos" is highlighted.
1112
Haoqun Jiang @haoqun.dev · 20/11/2024
manifest.build Interesting project. Lots of handy features behind a minimalistic interface. I think it's worth trying out for many small-to-medium-sized personal projects. Maybe even alongside bolt.new?
manifest.build
171
Haoqun Jiang @haoqun.dev · 18/11/2024
#TIL there's an undocumented Twitter query syntax `filter:follows`. So you can go to x.com/search?q=fil... to search for tweets mentioning bluesky by your following accounts. This can complement github.com/kawamataryo/... and help you find more people to follow on Bluesky.
x.com
x.com
130
Haoqun Jiang @haoqun.dev · 15/11/2024
I was reminded of why I didn’t use Bluesky last year… The old logo was a big turnoff for me 😅 Great redesign!
A screenshot of the original Bluesky Social app on the iOS App Store. The original logo was a photorealistic cloudy blue sky, literally.
010
Haoqun Jiang @haoqun.dev · 13/11/2024
I went into a rabbit hole when trying to figure out what monospace font a documentation site should use… 😂 the diff was only one line, but the commit message deserves a blog post on its own: haoqun.blog/en/2024/blog...
haoqun.blog
Blogged Pull Requests: Should Put All Kinds of System Monospace Fonts Before Courier New
I sometimes do a lot of research for a seemingly simple pull request. It's worth writing down all the reasoning behind t...
020
Haoqun Jiang @haoqun.dev · 13/11/2024
#TIL "Courier New" is only readable on Windows because ClearType made a special case for it: learn.microsoft.com/en-us/archiv... One should never use this font with Linux.
learn.microsoft.com
Why is Courier New so Thin?
020
Reposted by Haoqun Jiang
patak @patak.cat · 10/11/2024
wake up babe, new feed just dropped Place this one at the end of your home and check it once a week or so and you can see a high level update of all the folks you're following by skimming through their pins. Feeds. Are. So. Awesome. Thanks for making an english version for us @tomo-x.bsky.social
1314
Haoqun Jiang @haoqun.dev · 09/11/2024
Glad to find the bot here. Even more human touch on this platform. Very timely!
040
Haoqun Jiang @haoqun.dev · 07/11/2024
While pkg.pr.new works great for testing edge releases, package managers' overriding rules diverge. I see many experienced developers get them wrong on their first tries. So, I wrote a tool to handle that in existing projects: github.com/haoqunjiang/... Try it out on any PRs you are interested in!
github.com
GitHub - haoqunjiang/install-vue: Install Vue.js prereleases, done correctly
Install Vue.js prereleases, done correctly. Contribute to haoqunjiang/install-vue development by creating an account on GitHub.
042