Sign in

Haoqun Jiang

@haoqun.dev
456 followers 1.1K following 84 posts

@vuejs.org core team member. @vite.dev core team emeritus. Worked on JS tooling. Learning new things. haoqun.dev

PostsRepliesMedia
Haoqun Jiang @haoqun.dev · 18/09/2026
If I remember correctly, the repository was gone almost exactly 4 months ago today after the community became aware of the attack. I don't if it was suspended by GitHub for 4 months, or the attacker closed the account themselves and then reopened it. Anyway, it's a new pattern.
000
Haoqun Jiang @haoqun.dev · 18/09/2026
github.com/actions-cool...
github.com
Release v3.8.0 · actions-cool/issues-helper
2026.03.20 🛠 chore: up node24. #229
100
Haoqun Jiang @haoqun.dev · 18/09/2026
🚨 ACTIVE SUPPLY CHAIN ATTACK If you haven't removed `actions-cool/issue-helper` from your GitHub actions, it's back. And the latest release still points to the malicious commit, same as 4 months ago. www.stepsecurity.io/blog/actions...
stepsecurity.io
actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials - StepSecurity
The popular GitHub Action actions-cool/issues-helper has been compromised. Every existing tag in the repository has been moved to point to a single imposter commit that does not appear in the action's...
110
Haoqun Jiang @haoqun.dev · 04/09/2026
One benefit of having good physical modeling of the motion system is that you can build delightful visualizations very easily. Much more compelling than function graphs.
0210
Haoqun Jiang @haoqun.dev · 01/09/2026
It's always great to see a years-old issue finally get fixed! This, plus content mappers, I'd say TypeScript 7.1 might even have a bigger impact on the tooling ecosystem than 7.0 github.com/microsoft/Ty...
github.com
Ambient Module Declarations for Import Attributes (formerly known as Import Assertions) · Issue #46135 · microsoft/TypeScript
Suggestion 🔍 Search Terms import attributes, import assertions, ambient module ✅ Viability Checklist My suggestion meets these guidelines: This wouldn't be a breaking change in existing TypeScript/...
2285
Haoqun Jiang @haoqun.dev · 26/08/2026
Finally built a truly native-feeling bottom sheet for the web. Turns out it’s surprisingly hard to get right, even with good reference implementations.
020
Haoqun Jiang @haoqun.dev · 25/08/2026
I learned so much about English rhetoric in trying to get rid of the AI feel in my writing. The techniques I once wanted to learn to improve my English writing are now things I have to avoid to improve my English writing...
020
Haoqun Jiang @haoqun.dev · 25/08/2026
Negative parallelism, antithetical parallelism, rhetorical padding, aphoristic compression, metaphorical reification, conceptual sloganization, interpretive closure... AI really is a master of rhetorical packaging.
100
Haoqun Jiang @haoqun.dev · 28/07/2026
Hi! it looks like the Bluesky link on your YouTube channel points to the wrong account: bsky.app/profile/nuno... 😅
bsky.app
001
Haoqun Jiang @haoqun.dev · 22/06/2026
The technology behind this: blog.cloudflare.com/eliminating-...
blog.cloudflare.com
Private Access Tokens: eliminating CAPTCHAs on iPhones and Macs with open standards
Today we’re announcing Private Access Tokens, a completely invisible, private way to validate that real users are visiting your site.
010
Haoqun Jiang @haoqun.dev · 22/06/2026
#TIL iOS users generally see fewer CAPTCHAS when browsing the web.
Screenshot of an iPhone settings screen for "Automatic Verification" feature. A blue icon showing an ID card with a checkmark appears above the heading “Access apps and websites faster and easier.” Supporting text explains that iCloud can automatically and privately verify the user’s device and account to bypass CAPTCHAs in apps and on the web. A “Learn more…” link is shown, and the “Automatic Verification” toggle at the bottom is turned on (green).
110
Haoqun Jiang @haoqun.dev · 19/06/2026
* runs Node.js 22.16 _by default_
000
Haoqun Jiang @haoqun.dev · 19/06/2026
So, one more reason to migrate to Workers. * Node.js enables type stripping by default in 22.18
000
Haoqun Jiang @haoqun.dev · 19/06/2026
#TIL Cloudflare Pages still runs Node.js 22.16, while many packages now require 22.18+. This can break native packages that ship platform binaries via `optionalDependencies`, because pnpm silently drops those binaries when the Node.js version doesn't meet the requirement.
210
Haoqun Jiang @haoqun.dev · 17/06/2026
Babel 8! After all these years! What a surprise! babeljs.io/blog/2026/06...
babeljs.io
Releasing Babel 8 today: ESM-only, drop ES5 default, and a smooth migration path · Babel
Today we are releasing Babel 8. It's been 8 years since we released Babel 7. And that's not without reason.
05812
Haoqun Jiang @haoqun.dev · 08/06/2026
#TIL iOS Safari limits the frame rate to around 60fps by default, and you can turn it off to enjoy a smoother web browsing experience (Settings -> Safari -> Advanced -> Feature Flags -> Prefer Page Rendering Updates near 60fps)
Screenshot of the iOS Safari WebKit Feature Flags settings page showing the option “Prefer Page Rendering Updates near 60fps” with the toggle switched off.
130
Haoqun Jiang @haoqun.dev · 14/05/2026
docs.zizmor.sh/audits/ It's always interesting to read the rules in an auditing/linting tool's documentation. Surprised by how many footguns exist in common GitHub Actions usage patterns.
docs.zizmor.sh
Audit Rules - zizmor
Audit rules, examples, and remediations.
030
Haoqun Jiang @haoqun.dev · 27/04/2026
Using coding agents to explore multiple ideas at once has been really fun. But the project has grown to the point where I can’t easily do a full line-by-line review anymore 🥲 I need to find a realistic way to make it production-ready.
030
Haoqun Jiang @haoqun.dev · 27/04/2026
I spent the last two weeks vibe-coding a port of Vue’s style compiler to LightningCSS, and I’m seeing ~2.4–5× speedups in most cases: npmx.dev/package/@lig... Pretty happy with where the architecture and performance have landed.
npmx.dev
@lightning-vue/compiler - npmx
Vue SFC compiler module with a Lightning CSS-backed style compiler
120
Haoqun Jiang @haoqun.dev · 31/03/2026
One more reason to use @pnpm.io and @npmx.dev: trust policy downgrade becomes visible and preventable
Multiple warnings shown on https://npmx.dev/package/axios

1. Trust downgrade
This version was published without trusted publishing. Install commands are pinned to 1.14.0, the last version with trusted publishing.

2. You might not need this dependency.
The community has flagged this package as having more performant alternatives. Learn more at https://e18e.dev/docs/replacements/fetch.htmlPNPM documentation:

trustPolicy
Added in: v10.21.0

Default: off
Type: no-downgrade | off
When set to no-downgrade, pnpm will fail if a package's trust level has decreased compared to previous releases. For example, if a package was previously published by a trusted publisher but now only has provenance or no trust evidence, installation will fail. This helps prevent installing potentially compromised versions. Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Starting in v10.24.0, prerelease versions are ignored when evaluating trust evidence for a non-prerelease install, so a trusted prerelease cannot block a stable release that lacks trust evidence.
39514
Haoqun Jiang @haoqun.dev · 30/01/2026
Moltbook is fascinating.
020
Haoqun Jiang @haoqun.dev · 30/11/2025
TIL that IPv4 over IPv6 is a mainstream home internet setup in Japan to avoid old PPPoE limits. It took me back to my college years in China, when I was playing with IPv6 over IPv4 because native IPv6 wasn’t widely available. It’s really interesting to see how differently things evolved here.
120
Reposted by Haoqun Jiang
Emanuele (Ema) @ematipico.xyz · 10/11/2025
@pnpm.io getting better by the day pnpm.io/blog/release... I still can't believe that a one-person package manager is doing better than npm CLI, owned by a corporate, where the resources of the two projects are incomparable. Draw your own conclusions.
pnpm.io
pnpm 10.21 | pnpm
Added support for Node.js runtime installation for dependencies and a setting for configuring trust policy.
2374
Haoqun Jiang @haoqun.dev · 04/11/2025
Apple forgot to turn off sourcemaps when shipping their new App Store website lol github.com/rxliuli/apps...
github.com
060
Haoqun Jiang @haoqun.dev · 20/10/2025
lmao 🤣
040
Reposted by Haoqun Jiang
pnpm @pnpm.io · 16/09/2025
Published an article about mitigating supply chain attacks with pnpm pnpm.io/supply-chain...
pnpm.io
Mitigating supply chain attacks | pnpm
Sometimes npm packages are compromised and published with malware. Luckily, there are companies like [Socket], [Snyk], and [Aikido] that detect these compromised packages early. The npm registry usually removes the affected versions within hours. However, there is always a window of time between when the malware is published and when it is detected, during which you could be exposed. Fortunately, there are some things you can do with pnpm to minimize the risks.
05711
Reposted by Haoqun Jiang
James @43081j.com · 09/09/2025
some thoughts about the bloat introduced by edge-case first libraries
43081j.com
The bloat of edge-case first libraries
How building edge-case first led to bloated, overly-granular libraries and what we can do about it
1213044
Reposted by Haoqun Jiang
Kevin Deng @sxzz.dev · 15/08/2025
We encourage everyone to migrate from using npm publish tokens to trusted publisher! github.com/e18e/ecosyst...
github.com
Promote npm trusted publisher · Issue #201 · e18e/ecosystem-issues
Motivation npm Trusted Publishing is now generally available, allowing package owners to publish npm packages via CI without manually generating npm tokens. This method greatly reduces the risk of ...
1275
Haoqun Jiang @haoqun.dev · 04/08/2025
Finally, finally! SALVATION HAS ARRIVED! Time to refactor every GitHub Actions workflow! 🎉
030
Haoqun Jiang @haoqun.dev · 08/07/2025
Wow, this was unexpected. I've got mixed feelings, but huge congrats to the team!
271
Haoqun Jiang @haoqun.dev · 18/06/2025
But there is a language switcher at the bottom of the GoDaddy homepage? And you can use root paths like www.godaddy.com/en to go directly to the English homepage.
000
Haoqun Jiang @haoqun.dev · 01/04/2025
Bought. The interactive debugger looks cool!
230
Haoqun Jiang @haoqun.dev · 27/03/2025
I rarely feel that the Vue ecosystem is lacking anything, but this time, I truly wish we had a Vue version of this library. Impressive work!
140
Haoqun Jiang @haoqun.dev · 24/03/2025
You won't have to worry even without corepack - pnpm reads from `packageManager` too: pnpm.io/npmrc#manage... And you can prevent npm from being used with `devEngines`: github.com/npm/cli/pull...
130
Haoqun Jiang @haoqun.dev · 20/03/2025
Finally. I wish the community could migrate from the `packageManager` field to `devEngines` following this - always pinning versions is good in theory but way too cumbersome in practice.
070
Haoqun Jiang @haoqun.dev · 15/03/2025
There’s an RFC for this: github.com/vitejs/vite/...
github.com
[RFC] Proper Import Attributes support · vitejs vite · Discussion #18534
Context: Import Attributes is now stage 4: https://github.com/tc39/proposal-import-attributes Related PR / issues: #17485 rollup/rollup#5694 There are few different aspects regarding properly impor...
000
Reposted by Haoqun Jiang
James @43081j.com · 14/03/2025
This thing is so useful. Especially for security - ensuring the published package is actually what exists in the source
0145
Haoqun Jiang @haoqun.dev · 24/02/2025
Can't believe scoped packages wasn't a free feature of npm until 2017-03-22 blog.npmjs.org/post/1587182...
blog.npmjs.org
npm Blog Archive: announcing free Orgs
npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog
040
Haoqun Jiang @haoqun.dev · 24/02/2025
😮‍💨 Still paying down the tech debt that accumulated during the transition from non-scoped packages to scoped ones… I’m lucky to have subscribed to @lirantal.com’s Node.js security newsletter. It’s always informative! - www.alxndrsn.com/2024-08-01-n... - www.nodejs-security.com/newsletter/n...
GitHub commit message:

docs: add --no flag to npx command to avoid downloading the incorrect package from npm
Thanks to @alxndrsn for finding this issue and the insightful blog post.
https://www.alxndrsn.com/2024-08-01-npx-binary-confusion/

Also thanks to @lirantal for his newsletter that brought this issue to
my attention.
https://www.nodejs-security.com/newsletter/npm-supply-chain-security-prisma-orm-security-fun-nodejs-security-challenges

Git Diff:

- npx vue-cli-service serve
+ npx --no vue-cli-service serve
261
Reposted by Haoqun Jiang
Marvin Hagemeister @marvinh.dev · 23/02/2025
Speeding up the JavaScript ecosystem part 11 is here! This time we're looking at: Extending Rust tools with JavaScript plugins marvinh.dev/blog/speedin...
marvinh.dev
Speeding up the JavaScript ecosystem - Rust and JavaScript Plugins
Up until recently, supporting JavaScript in Rust based tools has been deemed not worth it. The main concern is the overhead of the de-/serialization cost when sending data back and forth. But there is...
914339
Haoqun Jiang @haoqun.dev · 23/02/2025
Have you tried `v-memo`?
000
Haoqun Jiang @haoqun.dev · 21/02/2025
Looks like Reka UI, the rebranded Radix Vue component library, has just got officially released 👀 It's such a cool name. Can't wait to try it out!
reka-ui.com
Reka
An open-source library with unstyled, primitive components, accompanied by a variety of examples & use cases ready to be integrated into your projects.
3877
Haoqun Jiang @haoqun.dev · 16/02/2025
#TIL So this is the fastest way to import an ES module in the Node.js REPL… How did I never know about the `_` (underscore) auto-assignment in the REPL?! nodejs.org/api/repl.htm... So many wasted keystrokes over the years!
Screenshot of Node.js REPL with the following text:

› await import ("./index.js")
[Module: null prototype] { oneTrueDate: [Function: oneTrueDate] }
_.oneTrueDate(new Date())
'2024-03-01'
081
Haoqun Jiang @haoqun.dev · 08/02/2025
@rspack/core does not have a postinstall script, so it won’t be in the list in the first place. If the attacker adds one, it won’t be executed by default. This feature mitigates risks like this, and that’s it, it’s not designed to prevent all possible attacks.
120
Haoqun Jiang @haoqun.dev · 05/02/2025
Note it's not about their Node APIs (so Vite isn't affected), just when executing the binaries (i.e. `pnpm exec esbuild`) there will be a performance hit.
020
Haoqun Jiang @haoqun.dev · 05/02/2025
In my experience this new default doesn't break many projects. But it might slow down some native packages a bit. For example, packages like esbuild, lightningcss-cli try to optimize their binaries in the postinstall scripts; these will no longer be executed by default: github.com/evanw/esbuil...
110
Haoqun Jiang @haoqun.dev · 05/02/2025
Resurfacing this post now that pnpm 10 is tagged as latest.
131
Haoqun Jiang @haoqun.dev · 30/01/2025
?? The link preview is still available even though I deleted the link? Interesting feature/bug…
010
Haoqun Jiang @haoqun.dev · 30/01/2025
And in case you still want that username, you can temporarily change your handle back and forth to reserve it. This feature was introduced about a month ago: bsky.app/profile/bsky...
000
Haoqun Jiang @haoqun.dev · 30/01/2025
@acemarke.dev Hi Mark, I just noticed that the Bluesky link on your GitHub profile is invalid since you changed your handle. Just wanted to give you a heads-up in case you'd like to update it
230