Sign in

Haoqun Jiang

@haoqun.dev
456 followers 1.1K following 84 posts

@vuejs.org core team member. @vite.dev core team emeritus. Worked on JS tooling. Learning new things. haoqun.dev

PostsRepliesMedia
Haoqun Jiang @haoqun.dev · 04/09/2026
One benefit of having good physical modeling of the motion system is that you can build delightful visualizations very easily. Much more compelling than function graphs.
0210
Haoqun Jiang @haoqun.dev · 26/08/2026
Finally built a truly native-feeling bottom sheet for the web. Turns out it’s surprisingly hard to get right, even with good reference implementations.
020
Haoqun Jiang @haoqun.dev · 22/06/2026
#TIL iOS users generally see fewer CAPTCHAS when browsing the web.
Screenshot of an iPhone settings screen for "Automatic Verification" feature. A blue icon showing an ID card with a checkmark appears above the heading “Access apps and websites faster and easier.” Supporting text explains that iCloud can automatically and privately verify the user’s device and account to bypass CAPTCHAs in apps and on the web. A “Learn more…” link is shown, and the “Automatic Verification” toggle at the bottom is turned on (green).
110
Haoqun Jiang @haoqun.dev · 08/06/2026
#TIL iOS Safari limits the frame rate to around 60fps by default, and you can turn it off to enjoy a smoother web browsing experience (Settings -> Safari -> Advanced -> Feature Flags -> Prefer Page Rendering Updates near 60fps)
Screenshot of the iOS Safari WebKit Feature Flags settings page showing the option “Prefer Page Rendering Updates near 60fps” with the toggle switched off.
130
Haoqun Jiang @haoqun.dev · 31/03/2026
One more reason to use @pnpm.io and @npmx.dev: trust policy downgrade becomes visible and preventable
Multiple warnings shown on https://npmx.dev/package/axios

1. Trust downgrade
This version was published without trusted publishing. Install commands are pinned to 1.14.0, the last version with trusted publishing.

2. You might not need this dependency.
The community has flagged this package as having more performant alternatives. Learn more at https://e18e.dev/docs/replacements/fetch.htmlPNPM documentation:

trustPolicy
Added in: v10.21.0

Default: off
Type: no-downgrade | off
When set to no-downgrade, pnpm will fail if a package's trust level has decreased compared to previous releases. For example, if a package was previously published by a trusted publisher but now only has provenance or no trust evidence, installation will fail. This helps prevent installing potentially compromised versions. Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Starting in v10.24.0, prerelease versions are ignored when evaluating trust evidence for a non-prerelease install, so a trusted prerelease cannot block a stable release that lacks trust evidence.
39514
Haoqun Jiang @haoqun.dev · 24/02/2025
😮‍💨 Still paying down the tech debt that accumulated during the transition from non-scoped packages to scoped ones… I’m lucky to have subscribed to @lirantal.com’s Node.js security newsletter. It’s always informative! - www.alxndrsn.com/2024-08-01-n... - www.nodejs-security.com/newsletter/n...
GitHub commit message:

docs: add --no flag to npx command to avoid downloading the incorrect package from npm
Thanks to @alxndrsn for finding this issue and the insightful blog post.
https://www.alxndrsn.com/2024-08-01-npx-binary-confusion/

Also thanks to @lirantal for his newsletter that brought this issue to
my attention.
https://www.nodejs-security.com/newsletter/npm-supply-chain-security-prisma-orm-security-fun-nodejs-security-challenges

Git Diff:

- npx vue-cli-service serve
+ npx --no vue-cli-service serve
261
Haoqun Jiang @haoqun.dev · 16/02/2025
#TIL So this is the fastest way to import an ES module in the Node.js REPL… How did I never know about the `_` (underscore) auto-assignment in the REPL?! nodejs.org/api/repl.htm... So many wasted keystrokes over the years!
Screenshot of Node.js REPL with the following text:

› await import ("./index.js")
[Module: null prototype] { oneTrueDate: [Function: oneTrueDate] }
_.oneTrueDate(new Date())
'2024-03-01'
081
Haoqun Jiang @haoqun.dev · 21/11/2024
I only got to know Lucide recently because I found out that @bolt.new's system prompt suggests using icons from `lucide-react` for logos, which turns out to be a good choice.
A screenshot of a code snippet:

```
".bolt/prompt": "For all designs I ask you to make, have them be beautiful, not cookie cutter. Make webpages that are fully featured and worthy for production.\n\nBy default, this template supports JSX syntax with Tailwind CSS classes, React hooks, and Lucide React for icons. Do not install other packages for UI themes, icons, etc unless absolutely necessary or I request them.\n\nUse icons from lucide-react for logos.\n\nUse stock photos from unsplash where appropriate, only valid URLs you know exist. Do not download the images, only link to them in image tags.\n\n"
```

"Use icons from lucide-react for logos" is highlighted.
1112
Haoqun Jiang @haoqun.dev · 15/11/2024
I was reminded of why I didn’t use Bluesky last year… The old logo was a big turnoff for me 😅 Great redesign!
A screenshot of the original Bluesky Social app on the iOS App Store. The original logo was a photorealistic cloudy blue sky, literally.
010
Haoqun Jiang @haoqun.dev · 30/10/2024
I recently shipped several minor improvements to `create-vue`, some of which required considerable effort. However, one small feature stands out as the most gratifying to me: a default file nesting configuration for all new projects.
A screenshot of the VS Code sidebar for a project called “visual-clutter”, with many config files under the root directory, but now most of them are collapsible.
110