Sign in

jonchurch

@jonchurch.com
125 followers 150 following 204 posts

maintaining express, lodash / ex-msft

PostsRepliesMedia
Reposted by jonchurch
npm @npmjs.com · 13/08/2026
npm Granular Access Tokens that bypass 2FA can no longer manage your account, org, or packages—those actions now require an interactive 2FA challenge, closing a major credential-based attack surface. github.blog/changelog/20...
github.blog
Restricting npm bypass-2FA granular access tokens - GitHub Changelog
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of…
1254
Reposted by jonchurch
Sam Rose @samwho.dev · 13/08/2026
This might be the most beautiful thing I've read in my life. What a privilege to be alive in 2026. ordinaryabundance.com
ordinaryabundance.com
Ordinary Abundance
A walk through a modern apartment, through the eyes of the people for whom everything in it was new.
13590221
jonchurch @jonchurch.com · 13/08/2026
“Linux ISOs of unusually cinematic provenance” is the funniest thing an llm has said to me in a while
030
jonchurch @jonchurch.com · 11/08/2026
This was a really cool read ngrok.com/blog/compres...
ngrok.com
Compression is prediction | ngrok blog
Compression and LLMs are trying to solve the exact same problem: predicting what comes next. Learn the fundamentals of compression and how better prediction leads to better shrinkage.
030
jonchurch @jonchurch.com · 05/06/2026
The saddest part about the npm worms for me is watching an opt in security feature be used as the delivery vector to the registry.
120
jonchurch @jonchurch.com · 03/06/2026
May was another record breaking month for total downloads on the npm registry overall. 661 billion total monthly downloads, up 4.8% from last month. The insane March +35% increase hasn’t yet meaningfully regressed jonchurch.com/npm-global-t...
jonchurch.com
npm Registry Download Trends
Total downloads across all packages on the npm registry, charted over time.
000
Reposted by jonchurch
Daniel Martí @handle.invalid · 31/05/2026
It just dawned on me that "firm"ware is someplace between software and hardware.
814713
jonchurch @jonchurch.com · 26/05/2026
I have a toy package Im using for publish testing, and I cannot get it to update the readme? www.npmjs.com/package/semv... Has anyone else run into this? I've seen some old threads about this, but idk if it's related to new OIDC/staged publishing or something silly im not seeing
npmjs.com
100
jonchurch @jonchurch.com · 24/05/2026
AI is best used to guilt trip your friends into going to Cracker Barrel with you
Ron how impoverished a life do you lead if you cant part with some coin for the pleasure of Campfire Beef with the boys, how poor is your soul when the bonds of wealth restrain you from the sacred smoke of fellowship

What cold province of the heart must a man inhabit to turn away from Fried Onion Petals, those golden little blossoms of friendship, arriving hot and communal to the table

What accountant of the damned taught you to deny yourself Loaded Hashbrown Casserole Tots, as though joy itself must first be itemized and approved
000
jonchurch @jonchurch.com · 23/05/2026
Tortoises Without Bordoises #WorldTurtleDay
000
Reposted by jonchurch
Wes @notwes.bsky.social · 20/05/2026
A little history lesson on the new @npmjs.bsky.social "Staged Publishing": github.com/npm/rfcs/pul... We had this mostly designed back in 2020 on the RFC calls. You cannot believe how happy I am to see this come to fruition. Great work team!
github.com
RFC: Add staging workflow for CI and human interoperability by djsauble · Pull Request #92 · npm/rfcs
See the RFC
2144
jonchurch @jonchurch.com · 21/05/2026
LETS FUCKING GOOOO!!! docs.npmjs.com/staged-publi...
docs.npmjs.com
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
170
jonchurch @jonchurch.com · 20/05/2026
Btw, you can give gh cli a readonly token instead of the normal gh auth method which will have write. Drastically reduces blast radius if you are concerned about your gh cli token being stolen (which you should be) gh auth login —with-token hit enter Then paste the token, it will persist for you
1110
jonchurch @jonchurch.com · 16/05/2026
In summary, what I learned is that the poisoned cache caused trojan versions of the checkout and cache GH actions to be restored over the their true versions within the release job. This is known as Cacheract, the vuln discovered by @adnanthekhan.bsky.social github.com/AdnaneKhan/C...
github.com
GitHub - AdnaneKhan/Cacheract: GitHub Actions Cache Native Malware - for Educational and Research Purposes only.
GitHub Actions Cache Native Malware - for Educational and Research Purposes only. - AdnaneKhan/Cacheract
000
jonchurch @jonchurch.com · 15/05/2026
Does anyone have a link to an in depth write up of the tanstack attack, the CI compromise bit? I ask bc I am doing my own analysis and the official post mortem doesnt seem to get all the details right. That or I am misunderstanding something, so want to see if a real expert has written this up
100
Reposted by jonchurch
jonchurch @jonchurch.com · 19/02/2026
Okay so adding cache to the list of github actions feature surface to always be terrified of adnanthekhan.com/posts/clinej...
adnanthekhan.com
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager | Adnan Khan - Security Research
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager - Security research by adnanthekhan
022
jonchurch @jonchurch.com · 10/05/2026
tbh I didnt know whoopi was still on The View
100
jonchurch @jonchurch.com · 07/05/2026
There is no Trusted Publishing setup which prevents a compromised repo admin's github PAT from triggering an npm publish, right? I've spent months trying to find something, but deploy envs w/ required reviews, workflow guards, branch protections, signed tags. All of it can be overwritten w/o 2fa
140
Reposted by jonchurch
Wes @notwes.bsky.social · 04/05/2026
devEngines started as @geoffreybooth.bsky.social and I in DMs 2 years ago. It's now supported in @npmjs.bsky.social & @pnpm.io, and later this month will be our recommended way for developers at Netflix to define runtime and package manager versions in their projects. docs.npmjs.com/cli/v11/conf...
docs.npmjs.com
package.json | npm Docs
Specifics of npm's package.json handling
4449
jonchurch @jonchurch.com · 23/04/2026
Rebranding the bullet point fetish of llms "bullet pontification"
000
jonchurch @jonchurch.com · 21/04/2026
added OG image to my little npm reg total download trend site, so here's a reminder to keep an eye on this, hopefully one day we find out why exactly downloads have exploded! No idea if its agents (sandboxes), security scanning companies, or model training ¯\_(ツ)_/¯ jonchurch.com/npm-global-t...
jonchurch.com
npm Registry Download Trends
Total downloads across all packages on the npm registry, charted over time.
111
Reposted by jonchurch
James Snell @jasnell.me · 17/04/2026
So... we've decided to change things up. NodeConf EU 2026 will be hosted in Bologna, Italy this year. The dates are set for September 29th and 30th, 2026.
292
jonchurch @jonchurch.com · 14/04/2026
Theres been an npmx bug that’s bothered me for a few weeks now. User profiles are showing almost random packages. Its a subset of your packages, first I thought it was dropping anything in an npm org dug a little and it was worse. It shows packages _where the gh user is the same as the npm user_
110
Reposted by jonchurch
Socket @socket.dev · 10/04/2026
🪿 There are some wild takes out there right now about open source being “dead” after recent supply chain attacks and rapid advances in AI-driven security. Let’s talk goosenomics for a minute. → socket.dev/blog/dont-ki...
socket.dev
Don't Kill the Goose That Lays the Golden Eggs - Socket
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three dec...
1136
jonchurch @jonchurch.com · 03/04/2026
jokes on them, ignoring my inbox has long been part of my security posture
3363
jonchurch @jonchurch.com · 02/04/2026
We released a lodash patch today, everything went well so havent really thought about it since. A non event. Released a minor yesterday, and it broke stuff and immediately heard about it. Couldnt stop thinking about it until we fixed it EoD today 🫠
010
jonchurch @jonchurch.com · 19/02/2026
Okay so adding cache to the list of github actions feature surface to always be terrified of adnanthekhan.com/posts/clinej...
adnanthekhan.com
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager | Adnan Khan - Security Research
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager - Security research by adnanthekhan
022
jonchurch @jonchurch.com · 17/02/2026
belt-and-suspenders
000
jonchurch @jonchurch.com · 09/02/2026
lodash just had its first ever 100M+ download week on npm that's a 70% YoY increase
110
jonchurch @jonchurch.com · 30/01/2026
its frustrating that the remote claude code env is missing some tools. For me its the missing gh cli that really hurts, for reading issues/PRs or otherwise doing read against GH So I created this StartSession script which ensures it is installed in remote sessions www.npmjs.com/package/@jon...
npmjs.com
000
jonchurch @jonchurch.com · 28/01/2026
i do like the computer
021
jonchurch @jonchurch.com · 07/12/2025
In my OSS archaelogy efforts I keep bumping into the defunct Component.js pre-npm registry and UI framework paradigm Just found this video explainer from their homepage focusing on the ui component runtime system, really capturing a point in time www.youtube.com/watch?v=gtz7...
youtube.com
ComponentJS - 1 - Overview
YouTube video by Dr. Ralf S. Engelschall
100
jonchurch @jonchurch.com · 19/10/2025
I spent almost $3k on Google BigQuery by accident while exploring dependency relationships in the deps.dev dataset WOOF
340
jonchurch @jonchurch.com · 17/09/2025
Our goal is to provide guidance and tooling for perf based decisions to the maintainers under our umbrella. Aligning our philosophy for how/what we monitor and how to interpret the results lets us be consistent across our 50+ packages. Ive been learning a lot so far, and big ty to @rafaelgss.dev
022
jonchurch @jonchurch.com · 17/05/2025
There are 39 ads on a given article from for my town’s local paper beyond cooked www.gainesville.com/story/news/l...
gainesville.com
Shepherd: 'The people's representative'
Gainesville City Commission meetings in recent years have had three constant features: Lively debate among elected officials, passionate public comments about the city’s utility, and a few words from…
000
jonchurch @jonchurch.com · 02/05/2025
The Pitt: every week Brad Pitt unveils a new pit full of bullshit and throws people into it. Everyone loves the pit
000
jonchurch @jonchurch.com · 18/04/2025
I just learned that setting process.noDeprecation = true Silences dep notifications from node, its what —no-deprecation flag ends up setting I know its hacky, but how hacky?
110
Reposted by jonchurch
Express @expressjs.bsky.social · 31/03/2025
🚀 Exciting Announcement today! Express v5 is officially "latest" and we have started the maintenance period for v4. Read more about the release and our LTS plans in our blog post: expressjs.com/2025/03/31/v...
expressjs.com
Express@5.1.0: Now the Default on npm with LTS Timeline
Express 5.1.0 is now the default on npm, and we're introducing an official LTS schedule for the v4 and v5 release lines.
2458
Reposted by jonchurch
Wes @notwes.bsky.social · 05/03/2025
Not sure this is the one, but pretty sure it is. @bjohansebas.bsky.social has been doing such great work it is awesome to see this kind of recognition! Well deserved.
github.com
feat: support for brotli by bjohansebas · Pull Request #194 · expressjs/compression
The changes from #172 are brought in, with the exception of using the accept negotiation logic.
162
jonchurch @jonchurch.com · 05/03/2025
I love getting nerdsniped on HTTP spec related stuff, and am glad I quit my job to have space in my life for this was fun to figure out what probably happened with content-disposition having in incomplete regex for parsing extended filename parameters: github.com/jshttp/conte...
github.com
Certain languages can't be matched correctly by the Regular Expression EXT_VALUE_REGEXP like en-US or zh_cn · Issue #47 · jshttp/content-disposition
Create and parse HTTP Content-Disposition header. Contribute to jshttp/content-disposition development by creating an account on GitHub.
032
jonchurch @jonchurch.com · 04/01/2025
Whats the purpose here of exfil to oastify vs requestbin? Does oastify enrich the exfil or is it just a convenient and innocuous endpoint?
010
jonchurch @jonchurch.com · 06/12/2024
top tier scam message
100
jonchurch @jonchurch.com · 05/12/2024
Approach open source as an infinite, open game. Prioritize purpose over goals, collaboration over competition, and legacy over ownership
020
jonchurch @jonchurch.com · 13/11/2024
Woah I didnt realize you can create your own algorithmic feeds! But also like hey @bsky.app which one of you is the Alf freak? 👀 docs.bsky.app/docs/starter...
docs.bsky.app
Custom Feeds | Bluesky
Custom feeds, or feed generators, are services that provide custom algorithms to users through the AT Protocol. This allows users to choose their own timelines, whether it's an algorithmic For You pag...
000
jonchurch @jonchurch.com · 12/11/2024
So what are github action threats for public repos? Talking about allowing CI on PRs from forks Assume that im using “pull_request” trigger and have the default perms for actions GH defaults you to having to approve runs. In the above scenario, is it really a risk to let all of them run?
341
jonchurch @jonchurch.com · 10/11/2024
Still extremely enjoying the wipeout soundtrack from @coldstorage.bsky.social open.spotify.com/artist/1TvIL...
open.spotify.com
CoLD SToRAGE
041