Reposted by John-David DaltonJames Snell @jasnell.me · 25/09/2026Way overdue but Node.js is finally getting a `--process-timeout=N` cli flag that will force the process to exit with an explanation of why it was open. github.com/nodejs/node/... 2406
Reposted by John-David DaltonSteve Klabnik @steveklabnik.com · 21/09/2026Arguing about arguments steveklabnik.com/writing/argu...steveklabnik.comArguing about argumentsHere’s some Rust code: // define a function fn foo (x : i32 , y : i32 ) -> i32 { // body elided } // call it let z = foo ( 5 , 6 ); In programming language jargon, we call x and y parameters and 5 and 6 arguments . Rust does not have many fancy features related to parameters and… 21928
Reposted by John-David DaltonCrow @abbyjane.cloverdalelane.com · 14/08/2026I think about this a lot. 7895082494
Reposted by John-David DaltonLea Verou, PhD @lea.verou.me · 06/08/2026🔥 New blog post: Dark mode toggles that expose three states (system, light, dark) seem like the best option. Until you think about user goals, that is. Before rushing to disagree, hear me out. lea.verou.me/blog/2026/da... PS: As a data point, @jakearchibald.com was converted after reading this 😅lea.verou.meDark mode toggles: two states are enough • Lea VerouYes, the underlying model must have three states, but one is always irrelevant to the actual user goal. Users do not seek out solutions to problems they don’t currently have. A lot of the hate towards... 3118935
Reposted by John-David DaltonBrian LeRoux @brianleroux.bsky.social · 17/07/2026The Internet vs me reading this post 061
Reposted by John-David Daltonpatak @patak.cat · 11/07/2026i'm sorry npm, but you need to fix this. it has been more than 3 months now. users need to be able to read deprecation warnings. 61095
Reposted by John-David Daltonvlt /vōlt/ @vlt.io · 08/07/2026Once upon a time, the internet was a village where people built things for each other. It's exciting seeing folks explore developer-centered spaces like tangled.org 🍿tangled.orgTangled · The next-generation social coding platformThe next-generation social coding platform. 072
Reposted by John-David Daltonvlt /vōlt/ @vlt.io · 08/07/2026Typosquat attacks uncovered yesterday on payment services: Paysafe, Skrill, and Neteller. Check your dependencies! Pin the compromised versions, stay safe. socket.dev/blog/npm-pyp...socket.devCoordinated npm and PyPI Campaign Typosquats Popular Secure ...Socket uncovered 17 malicious npm and PyPI packages typosquatting Paysafe, Skrill, and Neteller SDKs to steal developer secrets. 041
Reposted by John-David Daltonvlt /vōlt/ @vlt.io · 09/07/2026Have you ever tried to POST with a GET? 😜 Or query with a POST? We're just glad the new HTTP Query method is herehttp.devQUERYHTTP QUERY sends safe, idempotent queries with a request body. Overcome URI length limits for complex searches, GraphQL, and structured filter operations. 041
Reposted by John-David DaltonOliver Medhurst @honk.foo · 08/07/2026Porffor is now self-hosted, meaning it compiles itself with itself! This is made possible by Porffor's new rewrite, reducing its lines of code by >50% and making C output up to 5x more efficient! Here you can see the stats before and after the rewrite for Porffor itself: 48910
Reposted by John-David DaltonSocket @socket.dev · 08/07/2026🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow them, and 2FA-bypass tokens are starting to be phased out. Details → socket.dev/blog/npm-12 #nodejssocket.devnpm v12 Ships With Install Scripts Off by Default, Begins De...npm v12 is generally available, turning install scripts off by default and beginning the deprecation of 2FA-bypass publishing tokens. 03913
Reposted by John-David Daltonnpm @npmjs.com · 08/07/2026npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...github.blognpm install-time security and GAT bypass2fa deprecation - GitHub Changelognpm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation… 26024
Reposted by John-David DaltonSocket @socket.dev · 08/07/2026pnpm 11.10 adds a new _auth setting that ties each registry credential to its host, so a malicious or compromised repo file can't redirect your token to a different server. The release also hardens pnpm deploy, pack-app, and more. socket.dev/blog/pnpm-11...socket.devpnpm 11.10 Hardens Registry Authentication to Block Token Re...pnpm 11.10 hardens registry auth to block token redirection, tightens pack-app and deploy, and makes the Rust port (v12) installable. 0204
Reposted by John-David DaltonJiahan Chen @chenjiahan.bsky.social · 08/07/2026OMG, @jddalton.bsky.social has a wild proposal for Rspack's native binding: - size: 38.4 MiB -> 13.8 MiB (-64%) - first load: 853ms -> 615ms (-28%) 3285
Reposted by John-David DaltonJoyee Cheung @joyeecheung.bsky.social · 07/07/2026Landed a few improvements to the error reporting for require(esm) with top-level await (behind --experimental-print-required-tla for now): - No longer need to run the code to collect the TLA locations, so it can be enabled by default soon - Added require stack and location metadata to the error 1378
Reposted by John-David DaltonJake Archibald @jakearchibald.com · 08/07/2026Right now, if you import something from JS, and the result is a 404 (or other not-ok status code), it fails the load & gives you nothing. I wonder with json imports, and maybe even text/byte imports, if that's the right pattern github.com/whatwg/html/...github.comShould modules really be 'null' if the HTTP status code is not-ok? · Issue #12657 · whatwg/htmlWhat is the issue with the HTML Standard? https://html.spec.whatwg.org/multipage/webappapis.html#fetch-a-single-module-script:~:text=response%27s%20status%20is%20not%20an%20ok%20status%2C,-then%20s... 5164
Reposted by John-David Daltonnpmx @npmx.dev · 03/07/2026npmx 0.16 rainbow comet is out! 🌈💫npmx.devnpmx rainbow cometnpmx 0.16 is out! This period was especially full of good news. And it’s particularly great that, amid the constant search for vulnerabilities and risks, we’ve started celebrating more and taking joy ... 25916
Reposted by John-David DaltonNicholas C. Zakas @humanwhocodes.com · 29/06/202613 years ago today I made the first commit to the ESLint Git repo. It’s hard to believe that this project I cobbled together in my spare time over a couple of weeks is still going strong. I’ve been doing a lot of reflecting over these years and the journey it’s been. A thread. 3899
Reposted by John-David DaltonJames @43081j.com · 28/06/2026here's an @e18e.dev tool to summarise and visualise v8 deoptimisations. with `npx @e18e/deopt your_script.js`, you basically get a UI served up locally which shows where v8 deoptimised your code. you can also use `npx @e18e/deopt --md your_script.js` to get a markdown summarygithub.comGitHub - e18e/deopt: A tool for analyzing Node.js/v8 (de)optimizations.A tool for analyzing Node.js/v8 (de)optimizations. - e18e/deopt 2719
Reposted by John-David DaltonBabel @babel.dev · 27/06/2026📢 We released Babel 8 last week! Babel now targets modern browsers by default, is now ESM-only, and ships TypeScript types for all of its packages. We waited a week before announcing it to catch any last minute regressions, but now it's time for you to update your Babel version 😄babeljs.ioReleasing Babel 8 today: ESM-only, drop ES5 default, and a smooth migration path · BabelToday we are releasing Babel 8. It's been 8 years since we released Babel 7. And that's not without reason. 18612
Reposted by John-David Daltonpnpm @pnpm.io · 24/06/2026Very early sneak peek to pnpr - the pnpm registry: pnpm.io/pnpr/pnpm.ioIntroduction | pnpmpnpr is a pnpm-compatible npm registry server, written in Rust. It speaks the 410515
Reposted by John-David DaltonJames Snell @jasnell.me · 21/06/2026Could npm be rebuilt on atproto? www.jasnell.me/posts/what-i...jasnell.meWhat If npm Ran on AT Protocol?A thought experiment about what a package registry would look like if built on atproto. 148016
Reposted by John-David Daltonaustin (eeek!/ackkk! 👻) @thebadcode.com · 20/06/2026continuing to share stupid bullshit i had nano banana make for my slide deck 418920
Reposted by John-David Daltonboneskull @boneskull.dev · 20/06/2026tf is a zizmor anyway. nobody asks these questions and it’s important 001
Reposted by John-David DaltonZach Leatherman @zachleat.com · 17/06/2026Upcoming npm v12 will disable preinstall, install, and postinstall scripts from dependencies unless allow-listed. You can prepare for this change using npm v11 now: github.com/orgs/communi...github.comPreparing for npm v12: install scripts and non-registry sources become opt-in · community · Discussion #198547Hi everyone — sharing this so maintainers, application developers, and CI operators have time to prepare for behavioral changes landing in npm v12 (estimated July 2026). Everything below is already... 1198
Reposted by John-David DaltonRob Palmer @robpalmer.bsky.social · 18/06/2026Nub is a new frontend for Node by @colinhacks.com ✨ 🦀 A Rust CLI 🧱 Bundler-style JS/TS/JSX transpilation ⚡️ Fast script execution 📦 A new package manager based on Aube 🔢 Node version management The name is similar to Bun. github.com/nubjs/nub 2525
Reposted by John-David DaltonBrian Kardell @bkardell.com · 17/06/2026WHATWG Stage 1! bsky.app/profile/mari... 1132
Reposted by John-David DaltonSocket @socket.dev · 15/06/2026🚀 We're kicking off another Socket Launch Week, introducing one new feature every day this week! Day 1 is a big one: Socket for Linear is now available. Turn Socket alerts into Linear issues automatically, with two-way sync that keeps both sides current as things change.socket.devSocket for Linear Is Now Available - SocketCreate and manage Linear issues directly from Socket alerts, with manual creation and automated ticketing rules. 121
Reposted by John-David DaltonJames Snell @jasnell.me · 14/06/2026Oh. After many long years... HTTP now officially has a standard QUERY method. Think: cacheable, idempotent GET that can carry a meaningful payload. We can now all stop bastardizing POST. auth48-transition.rfc-editor.org/authors/rfc1...auth48-transition.rfc-editor.org 37114
Reposted by John-David Daltonnpmx @npmx.dev · 12/06/2026Given the feedback, we decided to move forward and start verifying maintainers and projects in the npm ecosystem. Later on, large ecosystem projects could also become verifiers for their communities. Reach out if you're interested in these conversations! Here are the first 100+ verifications 🩷atproto.atapp.bsky.graph.verification - @npmx.devBrowse @npmx.dev's app.bsky.graph.verification collection on Taproot 2847
Reposted by John-David DaltonFeross @feross.bsky.social · 11/06/2026Andrew Becherer is joining Socket as our first CISO. He was Datadog's first security hire and led security there through its IPO. Socket protects 27,000+ orgs. Andrew will own how we protect ourselves and how we show up for the security teams we serve. socket.dev/blog/andrew-...socket.devAndrew Becherer Joins Socket as Chief Information Security O...Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate. 061
Reposted by John-David DaltonJoyee Cheung @joyeecheung.bsky.social · 11/06/2026Today I gave a talk JSNation about the life cycle of ESM in Node.js, how it differs in other environments and the new features that will affect these stages. Slides: github.com/joyeecheung/...github.com 13812
Reposted by John-David DaltonSocket @socket.dev · 10/06/2026🔥 Socket Firewall is now built into Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced. socket.dev/blog/socket-...socket.devSocket Partners with Replit to Block Malicious Packages in A...Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages. 062
Reposted by John-David DaltonSocket @socket.dev · 09/06/2026npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...socket.devnpm Tooling Bug Incorrectly Marks One-Character Packages as ...npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback. 063
Reposted by John-David DaltonFrancisco Tolmasky @tolmasky.bsky.social · 08/06/2026Rich, native experiences, now *enhanced* with a floating black bubble vomiting 300 lines of tiny white text right in your face, not *replaced* by it. #WWDC26 011
Reposted by John-David Daltonmadeline gurriarán @superchupu.dev · 07/06/2026after about two years of the package existing, tinyglobby has surpassed both globby and fast-glob. it's been an insane journey that wouldn't have been possible without @e18e.dev and help from people like @benmccann.com or @43081j.com. i'm infinitely grateful for what e18e has done to the ecosystem 💙 3609
Reposted by John-David DaltonZoltan Kochan @kochan.io · 07/06/2026I have some early benchmark results with my custom @pnpm.io registry. In different scenarios, overall install times are 2 to 7 times faster than even the already very fast pnpm in Rust. Looks promising. 2636
Reposted by John-David DaltonGreg Whitworth @gregwhitworth.bsky.social · 06/06/2026I'm joining the Web Platform team at Microsoft! We are at a pivotal moment that raises a lot of interesting questions for the web and how it should evolve. I'm looking forward to working with this great team and the broader industry during this exciting era! 1492
Reposted by John-David DaltonRyan Cavanaugh @searyanc.dev · 05/06/2026We're changing how single-character inference in template literals works in TypeScript 7.0 TL;DR 3444
Reposted by John-David DaltonRob Palmer @robpalmer.bsky.social · 05/06/2026Type-stripping (used in Node's *.ts support) continues to pay dividends 👍 Masaki Hara found some type syntax that was unexpectedly not erasable: adding type assertions changed the precedence of the underlying JS code 😮 Anders on the TypeScript team universally fixed it in TS 7.0 via new errors 🎉 1753
Reposted by John-David Daltonnatemoore on elm street 👻 @natemoo.re · 25/05/2026👀 pnpm registry you say?? 0421
John-David Dalton @jddalton.bsky.social · 22/05/2026The profits argument is weakened when a company is so massive and has many levers to fund a variety of things. It’s like a government that chooses to spend on endless wars instead of investing in social programs. It’s a deliberate choice. 0110
Reposted by John-David DaltonJordan Harband @jordan.har.band · 21/05/2026thank @leobalter.bsky.social - he's the hero we (and microsoft) doesn't deserve if staging had shipped in 2020, shai hulud would never have happened. 1142
Reposted by John-David Daltonpatak @patak.cat · 21/05/2026to whoever moved mountains to ship staged publishing in npm, thank you. 31159
Reposted by John-David DaltonJames @43081j.com · 20/05/2026Woooo yeaaah! The missing piece 🎉 everything is about to get a lot more securedocs.npmjs.comStaged publishing for npm packages | npm DocsDocumentation for the npm registry, website, and command-line interface 512628
Reposted by John-David DaltonFeross @feross.bsky.social · 20/05/2026💥 Read our full official announcement: socket.dev/blog/series-csocket.devSocket raises $60M Series C at a $1B valuation to secure sof...Socket is scaling to defend open source against supply chain attacks as AI accelerates software development. 1182
Reposted by John-David DaltonFeross @feross.bsky.social · 20/05/2026Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started. 118514
Reposted by John-David DaltonAntoine du Hamel @aduh95.bsky.social · 20/05/2026Node.js 26.2.0 is out! `stream.compose` is now stable, `node:fs` integrates with the new `Temporal` API, and a fair load of bug fixes. Full changelog and download links at nodejs.org/en/blog/rele...nodejs.orgNode.js — Node.js 26.2.0 (Current)Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 03910
Reposted by John-David DaltonKaylyn Saucedo - MarzGhoul @marzgurl.com · 12/05/2026Games Industry plant 527136
John-David Dalton @jddalton.bsky.social · 08/05/2026As a multimedia major, without a formal CS education, I feel this. AI gets the artistic flow and imagination running 020