Sign in

John-David Dalton

@jddalton.bsky.social
1.2K followers 142 following 71 posts

Lodash creator • sometimes TC39 delegate • protecting supply chains at Socket.dev • Ex (Bun, Salesforce, Node core, Electron WG, Microsoft)

PostsRepliesMedia
Reposted by John-David Dalton
James Snell @jasnell.me · 25/09/2026
Way overdue but Node.js is finally getting a `--process-timeout=N` cli flag that will force the process to exit with an explanation of why it was open. github.com/nodejs/node/...
2406
Reposted by John-David Dalton
Steve Klabnik @steveklabnik.com · 21/09/2026
Arguing about arguments steveklabnik.com/writing/argu...
steveklabnik.com
Arguing about arguments
Here’s some Rust code: // define a function fn foo (x : i32 , y : i32 ) -> i32 { // body elided } // call it let z = foo ( 5 , 6 ); In programming language jargon, we call x and y parameters and 5 and 6 arguments . Rust does not have many fancy features related to parameters and…
21928
Reposted by John-David Dalton
Crow @abbyjane.cloverdalelane.com · 14/08/2026
I think about this a lot.
Tim Henke
@TimHenke9
eat shit, René Magritte
Translate Tweet
Mauv @ThatsMauvelous • 1d the machine refused to recognize my humanity until i professed to believe that a sign painted to look like a traffic light is indeed a traffic light.
Show this thread
Select all squares with traffic lights
7895082494
Reposted by John-David Dalton
Lea Verou, PhD @lea.verou.me · 06/08/2026
🔥 New blog post: Dark mode toggles that expose three states (system, light, dark) seem like the best option. Until you think about user goals, that is. Before rushing to disagree, hear me out. lea.verou.me/blog/2026/da... PS: As a data point, @jakearchibald.com was converted after reading this 😅
lea.verou.me
Dark mode toggles: two states are enough • Lea Verou
Yes, the underlying model must have three states, but one is always irrelevant to the actual user goal. Users do not seek out solutions to problems they don’t currently have. A lot of the hate towards...
3118935
Reposted by John-David Dalton
Brian LeRoux @brianleroux.bsky.social · 17/07/2026
The Internet vs me reading this post
061
Reposted by John-David Dalton
patak @patak.cat · 11/07/2026
i'm sorry npm, but you need to fix this. it has been more than 3 months now. users need to be able to read deprecation warnings.
a screenshot from npm, the deprecation warning message is unreadable, "has been deprecated" is highlighted so it can be seen
61095
Reposted by John-David Dalton
vlt /vōlt/ @vlt.io · 08/07/2026
Once upon a time, the internet was a village where people built things for each other. It's exciting seeing folks explore developer-centered spaces like tangled.org 🍿
tangled.org
Tangled · The next-generation social coding platform
The next-generation social coding platform.
072
Reposted by John-David Dalton
vlt /vōlt/ @vlt.io · 08/07/2026
Typosquat attacks uncovered yesterday on payment services: Paysafe, Skrill, and Neteller. Check your dependencies! Pin the compromised versions, stay safe. socket.dev/blog/npm-pyp...
socket.dev
Coordinated npm and PyPI Campaign Typosquats Popular Secure ...
Socket uncovered 17 malicious npm and PyPI packages typosquatting Paysafe, Skrill, and Neteller SDKs to steal developer secrets.
041
Reposted by John-David Dalton
vlt /vōlt/ @vlt.io · 09/07/2026
Have you ever tried to POST with a GET? 😜 Or query with a POST? We're just glad the new HTTP Query method is here
http.dev
QUERY
HTTP QUERY sends safe, idempotent queries with a request body. Overcome URI length limits for complex searches, GraphQL, and structured filter operations.
041
Reposted by John-David Dalton
Oliver Medhurst @honk.foo · 08/07/2026
Porffor is now self-hosted, meaning it compiles itself with itself! This is made possible by Porffor's new rewrite, reducing its lines of code by >50% and making C output up to 5x more efficient! Here you can see the stats before and after the rewrite for Porffor itself:
Porffor selfhost rewrite graphs, before vs after.

bundle lines 40.4K→24.7K (1.6x smaller)
bundle size 2.4MB→2.0MB (1.2x smaller)

C lines 1.6M→289.0K (5.5x smaller)
C size 70.4MB→12.3MB (5.7x smaller)

debug compile time 5.0s→1.2s (4.1x faster)
release compile time 143.2s→37.1s (3.9x faster)

debug binary size 52.4MB→13.6MB (3.8x smaller)
release binary size 14.1MB→4.6MB (3.1x smaller).
48910
Reposted by John-David Dalton
Socket @socket.dev · 08/07/2026
🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow them, and 2FA-bypass tokens are starting to be phased out. Details → socket.dev/blog/npm-12 #nodejs
socket.dev
npm v12 Ships With Install Scripts Off by Default, Begins De...
npm v12 is generally available, turning install scripts off by default and beginning the deprecation of 2FA-bypass publishing tokens.
03913
Reposted by John-David Dalton
npm @npmjs.com · 08/07/2026
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
26024
Reposted by John-David Dalton
Socket @socket.dev · 08/07/2026
pnpm 11.10 adds a new _auth setting that ties each registry credential to its host, so a malicious or compromised repo file can't redirect your token to a different server. The release also hardens pnpm deploy, pack-app, and more. socket.dev/blog/pnpm-11...
socket.dev
pnpm 11.10 Hardens Registry Authentication to Block Token Re...
pnpm 11.10 hardens registry auth to block token redirection, tightens pack-app and deploy, and makes the Rust port (v12) installable.
0204
Reposted by John-David Dalton
Jiahan Chen @chenjiahan.bsky.social · 08/07/2026
OMG, @jddalton.bsky.social has a wild proposal for Rspack's native binding: - size: 38.4 MiB -> 13.8 MiB (-64%) - first load: 853ms -> 615ms (-28%)
3285
Reposted by John-David Dalton
Joyee Cheung @joyeecheung.bsky.social · 07/07/2026
Landed a few improvements to the error reporting for require(esm) with top-level await (behind --experimental-print-required-tla for now): - No longer need to run the code to collect the TLA locations, so it can be enabled by default soon - Added require stack and location metadata to the error
Before: extra noisy arrow pointing to internals, no require stack, needs to run the code to find the top-level await location
After: no more noisy arrows, added require stacks to the output, finds location without running the codeNew ERR_REQUIRE_ASYNC_MODULE includes error.requireStack and error.topLevelAwaitLocations metadata properties
1378
Reposted by John-David Dalton
Jake Archibald @jakearchibald.com · 08/07/2026
Right now, if you import something from JS, and the result is a 404 (or other not-ok status code), it fails the load & gives you nothing. I wonder with json imports, and maybe even text/byte imports, if that's the right pattern github.com/whatwg/html/...
github.com
Should modules really be 'null' if the HTTP status code is not-ok? · Issue #12657 · whatwg/html
What is the issue with the HTML Standard? https://html.spec.whatwg.org/multipage/webappapis.html#fetch-a-single-module-script:~:text=response%27s%20status%20is%20not%20an%20ok%20status%2C,-then%20s...
5164
Reposted by John-David Dalton
npmx @npmx.dev · 03/07/2026
npmx 0.16 rainbow comet is out! 🌈💫
npmx.dev
npmx rainbow comet
npmx 0.16 is out! This period was especially full of good news. And it’s particularly great that, amid the constant search for vulnerabilities and risks, we’ve started celebrating more and taking joy ...
25916
Reposted by John-David Dalton
Nicholas C. Zakas @humanwhocodes.com · 29/06/2026
13 years ago today I made the first commit to the ESLint Git repo. It’s hard to believe that this project I cobbled together in my spare time over a couple of weeks is still going strong. I’ve been doing a lot of reflecting over these years and the journey it’s been. A thread.
A birthday cake for ESLint, with candles of 1 and 3 at the top for 13 and the ESLint logo with "Happy birthday" on the side.
3899
Reposted by John-David Dalton
James @43081j.com · 28/06/2026
here's an @e18e.dev tool to summarise and visualise v8 deoptimisations. with `npx @e18e/deopt your_script.js`, you basically get a UI served up locally which shows where v8 deoptimised your code. you can also use `npx @e18e/deopt --md your_script.js` to get a markdown summary
github.com
GitHub - e18e/deopt: A tool for analyzing Node.js/v8 (de)optimizations.
A tool for analyzing Node.js/v8 (de)optimizations. - e18e/deopt
2719
Reposted by John-David Dalton
Babel @babel.dev · 27/06/2026
📢 We released Babel 8 last week! Babel now targets modern browsers by default, is now ESM-only, and ships TypeScript types for all of its packages. We waited a week before announcing it to catch any last minute regressions, but now it's time for you to update your Babel version 😄
babeljs.io
Releasing Babel 8 today: ESM-only, drop ES5 default, and a smooth migration path · Babel
Today we are releasing Babel 8. It's been 8 years since we released Babel 7. And that's not without reason.
18612
Reposted by John-David Dalton
pnpm @pnpm.io · 24/06/2026
Very early sneak peek to pnpr - the pnpm registry: pnpm.io/pnpr/
pnpm.io
Introduction | pnpm
pnpr is a pnpm-compatible npm registry server, written in Rust. It speaks the
410515
Reposted by John-David Dalton
James Snell @jasnell.me · 21/06/2026
Could npm be rebuilt on atproto? www.jasnell.me/posts/what-i...
jasnell.me
What If npm Ran on AT Protocol?
A thought experiment about what a package registry would look like if built on atproto.
148016
Reposted by John-David Dalton
austin (eeek!/ackkk! 👻) @thebadcode.com · 20/06/2026
continuing to share stupid bullshit i had nano banana make for my slide deck
418920
Reposted by John-David Dalton
boneskull @boneskull.dev · 20/06/2026
tf is a zizmor anyway. nobody asks these questions and it’s important
001
Reposted by John-David Dalton
Zach Leatherman @zachleat.com · 17/06/2026
Upcoming npm v12 will disable preinstall, install, and postinstall scripts from dependencies unless allow-listed. You can prepare for this change using npm v11 now: github.com/orgs/communi...
github.com
Preparing for npm v12: install scripts and non-registry sources become opt-in · community · Discussion #198547
Hi everyone — sharing this so maintainers, application developers, and CI operators have time to prepare for behavioral changes landing in npm v12 (estimated July 2026). Everything below is already...
1198
Reposted by John-David Dalton
Rob Palmer @robpalmer.bsky.social · 18/06/2026
Nub is a new frontend for Node by @colinhacks.com ✨ 🦀 A Rust CLI 🧱 Bundler-style JS/TS/JSX transpilation ⚡️ Fast script execution 📦 A new package manager based on Aube 🔢 Node version management The name is similar to Bun. github.com/nubjs/nub
nub.
$ nub index.ts
# TypeScript-first Node.js runtime
$ nub run dev
# 24x faster pnpm run
$
nubx prisma
generate
# 19× faster npx
$ nub install
# 3x faster pnpm install
$ nub watch sic/server.ts
非
native watch
mode
$ nub pm shim
# built-in Corepack-style shims
$
nub node install
26
# Node version
manager
2525
Reposted by John-David Dalton
Brian Kardell @bkardell.com · 17/06/2026
WHATWG Stage 1! bsky.app/profile/mari...
1132
Reposted by John-David Dalton
Socket @socket.dev · 15/06/2026
🚀 We're kicking off another Socket Launch Week, introducing one new feature every day this week! Day 1 is a big one: Socket for Linear is now available. Turn Socket alerts into Linear issues automatically, with two-way sync that keeps both sides current as things change.
socket.dev
Socket for Linear Is Now Available - Socket
Create and manage Linear issues directly from Socket alerts, with manual creation and automated ticketing rules.
121
Reposted by John-David Dalton
James Snell @jasnell.me · 14/06/2026
Oh. After many long years... HTTP now officially has a standard QUERY method. Think: cacheable, idempotent GET that can carry a meaningful payload. We can now all stop bastardizing POST. auth48-transition.rfc-editor.org/authors/rfc1...
auth48-transition.rfc-editor.org
37114
Reposted by John-David Dalton
npmx @npmx.dev · 12/06/2026
Given the feedback, we decided to move forward and start verifying maintainers and projects in the npm ecosystem. Later on, large ecosystem projects could also become verifiers for their communities. Reach out if you're interested in these conversations! Here are the first 100+ verifications 🩷
atproto.at
app.bsky.graph.verification - @npmx.dev
Browse @npmx.dev's app.bsky.graph.verification collection on Taproot
2847
Reposted by John-David Dalton
Feross @feross.bsky.social · 11/06/2026
Andrew Becherer is joining Socket as our first CISO. He was Datadog's first security hire and led security there through its IPO. Socket protects 27,000+ orgs. Andrew will own how we protect ourselves and how we show up for the security teams we serve. socket.dev/blog/andrew-...
socket.dev
Andrew Becherer Joins Socket as Chief Information Security O...
Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.
061
Reposted by John-David Dalton
Joyee Cheung @joyeecheung.bsky.social · 11/06/2026
Today I gave a talk JSNation about the life cycle of ESM in Node.js, how it differs in other environments and the new features that will affect these stages. Slides: github.com/joyeecheung/...
github.com
13812
Reposted by John-David Dalton
Socket @socket.dev · 10/06/2026
🔥 Socket Firewall is now built into Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced. socket.dev/blog/socket-...
socket.dev
Socket Partners with Replit to Block Malicious Packages in A...
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.
062
Reposted by John-David Dalton
Socket @socket.dev · 09/06/2026
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...
socket.dev
npm Tooling Bug Incorrectly Marks One-Character Packages as ...
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
063
Reposted by John-David Dalton
Francisco Tolmasky @tolmasky.bsky.social · 08/06/2026
Rich, native experiences, now *enhanced* with a floating black bubble vomiting 300 lines of tiny white text right in your face, not *replaced* by it. #WWDC26
011
Reposted by John-David Dalton
madeline gurriarán @superchupu.dev · 07/06/2026
after about two years of the package existing, tinyglobby has surpassed both globby and fast-glob. it's been an insane journey that wouldn't have been possible without @e18e.dev and help from people like @benmccann.com or @43081j.com. i'm infinitely grateful for what e18e has done to the ecosystem 💙
weekly downloads chart
tinyglobby: 120.6 million weekly downloads
fast-glob: 117.7 million weekly downloads
globby: 54.6 million weekly downloads
3609
Reposted by John-David Dalton
Zoltan Kochan @kochan.io · 07/06/2026
I have some early benchmark results with my custom @pnpm.io registry. In different scenarios, overall install times are 2 to 7 times faster than even the already very fast pnpm in Rust. Looks promising.
2636
Reposted by John-David Dalton
Greg Whitworth @gregwhitworth.bsky.social · 06/06/2026
I'm joining the Web Platform team at Microsoft! We are at a pivotal moment that raises a lot of interesting questions for the web and how it should evolve. I'm looking forward to working with this great team and the broader industry during this exciting era!
Microsoft sign in front of a building at the Redmond campus
1492
Reposted by John-David Dalton
Ryan Cavanaugh @searyanc.dev · 05/06/2026
We're changing how single-character inference in template literals works in TypeScript 7.0 TL;DR
"you wouldn't split a surrogate pair" in the style of "you wouldn't download a car"
3444
Reposted by John-David Dalton
Rob Palmer @robpalmer.bsky.social · 05/06/2026
Type-stripping (used in Node's *.ts support) continues to pay dividends 👍 Masaki Hara found some type syntax that was unexpectedly not erasable: adding type assertions changed the precedence of the underlying JS code 😮 Anders on the TypeScript team universally fixed it in TS 7.0 via new errors 🎉
as/satisfies precedence and erasableSyntaxOnly

Issue: #63527

- Problem: 1 + 2 as number / 3 parses as ((1 + 2) as number) / 3
- This can't be emitted without parenthesizing 1 + 2, since 1 + 2 / 3 has different meaning
1753
Reposted by John-David Dalton
natemoore on elm street 👻 @natemoo.re · 25/05/2026
👀 pnpm registry you say??
0421
John-David Dalton @jddalton.bsky.social · 22/05/2026
The profits argument is weakened when a company is so massive and has many levers to fund a variety of things. It’s like a government that chooses to spend on endless wars instead of investing in social programs. It’s a deliberate choice.
0110
Reposted by John-David Dalton
Jordan Harband @jordan.har.band · 21/05/2026
thank @leobalter.bsky.social - he's the hero we (and microsoft) doesn't deserve if staging had shipped in 2020, shai hulud would never have happened.
1142
Reposted by John-David Dalton
patak @patak.cat · 21/05/2026
to whoever moved mountains to ship staged publishing in npm, thank you.
31159
Reposted by John-David Dalton
James @43081j.com · 20/05/2026
Woooo yeaaah! The missing piece 🎉 everything is about to get a lot more secure
docs.npmjs.com
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
512628
Reposted by John-David Dalton
Feross @feross.bsky.social · 20/05/2026
💥 Read our full official announcement: socket.dev/blog/series-c
socket.dev
Socket raises $60M Series C at a $1B valuation to secure sof...
Socket is scaling to defend open source against supply chain attacks as AI accelerates software development.
1182
Reposted by John-David Dalton
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Reposted by John-David Dalton
Antoine du Hamel @aduh95.bsky.social · 20/05/2026
Node.js 26.2.0 is out! `stream.compose` is now stable, `node:fs` integrates with the new `Temporal` API, and a fair load of bug fixes. Full changelog and download links at nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.2.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
03910
Reposted by John-David Dalton
Kaylyn Saucedo - MarzGhoul @marzgurl.com · 12/05/2026
Games Industry plant
Soulcage, boss inside the Iifa Tree in Final Fantasy IX.
527136
John-David Dalton @jddalton.bsky.social · 08/05/2026
As a multimedia major, without a formal CS education, I feel this. AI gets the artistic flow and imagination running
020