Sign in

jonchurch

@jonchurch.com
125 followers 150 following 204 posts

maintaining express, lodash / ex-msft

PostsRepliesMedia
Reposted by jonchurch
npm @npmjs.com · 13/08/2026
npm Granular Access Tokens that bypass 2FA can no longer manage your account, org, or packages—those actions now require an interactive 2FA challenge, closing a major credential-based attack surface. github.blog/changelog/20...
github.blog
Restricting npm bypass-2FA granular access tokens - GitHub Changelog
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of…
1254
Reposted by jonchurch
Sam Rose @samwho.dev · 13/08/2026
This might be the most beautiful thing I've read in my life. What a privilege to be alive in 2026. ordinaryabundance.com
ordinaryabundance.com
Ordinary Abundance
A walk through a modern apartment, through the eyes of the people for whom everything in it was new.
13590221
jonchurch @jonchurch.com · 13/08/2026
“Linux ISOs of unusually cinematic provenance” is the funniest thing an llm has said to me in a while
030
jonchurch @jonchurch.com · 12/08/2026
My first time ever building a stack and it seems yours is uhm, different im structural integrity than mine I still have a little less than half from last winter
Shoddily stacked firewoodCat enjoying the wood fired stove
030
jonchurch @jonchurch.com · 12/08/2026
How long will what is stacked here last? And is it heating for your home? This Floridian wants to understand more. I have a high efficiency wood burning stove in my home in north central florida, but it is mostly for fun as we get like a few nights a year below freezing (also have central gas heat)
240
jonchurch @jonchurch.com · 11/08/2026
This was a really cool read ngrok.com/blog/compres...
ngrok.com
Compression is prediction | ngrok blog
Compression and LLMs are trying to solve the exact same problem: predicting what comes next. Learn the fundamentals of compression and how better prediction leads to better shrinkage.
030
jonchurch @jonchurch.com · 11/08/2026
I need to do a closer read of Fetch, as I sort of assumed this kind of backcompat for legacy HTTP quirks didn't hold as much weight there. But I suppose what is an HTTP spec except a best effort to accomodate decades of choices already made for us
020
jonchurch @jonchurch.com · 11/08/2026
@annevk.nl's logic of not breaking the existing web is familiar, and always a tough spot. But yeah, I didn't realize this was a spec stance
120
jonchurch @jonchurch.com · 11/08/2026
I didn't know this which sent me on a rabbit hole. We're not the only ones who are surprised here, PATCH coming up as far as 11 years ago in this issue github.com/whatwg/fetch... And as recently as 2026 in regards to QUERY github.com/whatwg/fetch...
github.com
PATCH verb · Issue #50 · whatwg/fetch
Should the patch verb be included in the spec? (https://tools.ietf.org/html/rfc5789) here - https://fetch.spec.whatwg.org/#concept-method-normalize and https://fetch.spec.whatwg.org/#http-network-o...
130
jonchurch @jonchurch.com · 09/06/2026
Detection logic is messy and easy to miss all cases, hence I went to peek hehe I opened a different but similarly spirited PR to npmx a couple months ago for their logic too Really should be a standard package for this. Or maybe dotenv is just wrong idk ¯\_(ツ)_/¯
020
jonchurch @jonchurch.com · 09/06/2026
Theres a very small bug that yields some extra duals in the crawl.js code Consider that dotenv is reported as dual while it is CJS The analyzer treats the presence of “default” when “import” or “require” are present in the export map as signaling dual. I think it drops the dual count by a few %
120
jonchurch @jonchurch.com · 09/06/2026
This is analyzing the latest version for every package in the dataset? Any interest in share of npm downloads by module type? That would be where the real impact/meaningful change is tracked IMO, is that tangential to the work you are interested in? I wonder what year we will see it flip to ESM
100
jonchurch @jonchurch.com · 05/06/2026
The saddest part about the npm worms for me is watching an opt in security feature be used as the delivery vector to the registry.
120
jonchurch @jonchurch.com · 03/06/2026
My PR didnt get taken but I showed them how to reduce the 4.x size by dropping sourcemaps for the cdn files
060
jonchurch @jonchurch.com · 03/06/2026
Aw someone beat me, but I was gonna ask if it’s cheating if I knew the package bc I helped 😂
170
jonchurch @jonchurch.com · 03/06/2026
May was another record breaking month for total downloads on the npm registry overall. 661 billion total monthly downloads, up 4.8% from last month. The insane March +35% increase hasn’t yet meaningfully regressed jonchurch.com/npm-global-t...
jonchurch.com
npm Registry Download Trends
Total downloads across all packages on the npm registry, charted over time.
000
jonchurch @jonchurch.com · 31/05/2026
Looks like 1 dep is equivalent to to ~100kb in the ranking? Based on “once” being where it is, 1 dep 0.00kb
100
jonchurch @jonchurch.com · 31/05/2026
Love lists like these though, ty!
000
jonchurch @jonchurch.com · 31/05/2026
How does weighting work? Im surprised by how small most of these are by install size! Lodash on there with zero deps and 1.3mb, higher than I expected
200
Reposted by jonchurch
Daniel Martí @mvdan.cc · 31/05/2026
It just dawned on me that "firm"ware is someplace between software and hardware.
814713
jonchurch @jonchurch.com · 31/05/2026
Underlying tech aside, I dont like how spot on you are about marketing
static.klipy.com
Simpsons Old Man Yells at Cloud
Alt: Simpsons Old Man Yells at Cloud
000
jonchurch @jonchurch.com · 31/05/2026
Its since been ported to ts (and for some reason moved into astro org, to reduce the bus factor?), but the repo was always known github.com/withastro/ro...
github.com
GitHub - withastro/rosie: Agent package manager
Agent package manager. Contribute to withastro/rosie development by creating an account on GitHub.
020
jonchurch @jonchurch.com · 31/05/2026
The thing that gets me is a maintainer answered “the package itself is something we have trust in” and the reporter came back saying basically okay but why. I can see how that’s valid, but is also entitled. The relationship btwn project and user is meant to be trusted, im sad thats breaking down
130
jonchurch @jonchurch.com · 31/05/2026
github.com/cloudflare/w...
github.com
~600kb WASM binary dependency in wrangler@>=4.94.0 · Issue #14110 · cloudflare/workers-sdk
👋 A new dependency, rosie-skills, was introduced in wrangler@4.94.0. This package appears to be brand new to the npm registry, and ships a large ~600kb WASM binary as part of its functionality. I a...
110
jonchurch @jonchurch.com · 31/05/2026
This was such a weird issue report. Dude opened an issue worried about a supply chain attack for a dep added to the repo by a maintainer like 2 weeks earlier. It is truly a sign of the times that someone opens an issue bc they got scared that a dep was added in the normal way
120
jonchurch @jonchurch.com · 30/05/2026
oh I see "prev babel" in bio, so maybe he's passed the torch
030
jonchurch @jonchurch.com · 30/05/2026
github.com/danielroe/nu...
github.com
fix: add nofollow to outbound links to sites by jonchurch · Pull Request #4 · danielroe/nuxt.fyi
Law of the internet, no feet pics for free, no link juice for free There's other places to make this fix, like site wide or robot.txt to not crawl, but this is the most targetted and should lik...
110
jonchurch @jonchurch.com · 30/05/2026
like www.rawchili.com is definitely some placeholder? Or spam site? or something idk, but what a funny and specific domain name
rawchili.com
RAW CHILI - RAWCHILI.COM | MLB FANBASE | NFL FANBASE | NBA FANBASE | NHL FANBASE
RAWCHILI.COM | MLB FANBASE | NFL FANBASE | NBA FANBASE | NHL FANBASE
110
jonchurch @jonchurch.com · 30/05/2026
woooaahhhh! The nuxt.fyi/recent page is very cool! Idk why a firehose of links is so interesting, but this is now my favorite page on this site
210
jonchurch @jonchurch.com · 30/05/2026
This sort of is user generated content if you squint every so slightly, so best to put in the typical protections
110
jonchurch @jonchurch.com · 30/05/2026
Make sure to add nofollow to the outbound links at the least, lest the spammers discover your automated backlink generating device 👍
210
jonchurch @jonchurch.com · 30/05/2026
Only met @henryzoo.com (once, in Berlin w/ @notwes.bsky.social ), but can confirm he is the best
120
jonchurch @jonchurch.com · 26/05/2026
The readme makes it into the tarball, but doesn't show up on the website
100
jonchurch @jonchurch.com · 26/05/2026
I have a toy package Im using for publish testing, and I cannot get it to update the readme? www.npmjs.com/package/semv... Has anyone else run into this? I've seen some old threads about this, but idk if it's related to new OIDC/staged publishing or something silly im not seeing
npmjs.com
100
jonchurch @jonchurch.com · 24/05/2026
Its just so wild to see everyone I know with deep experience on the topics e18e cares about be so completely on the other side of most of yalls core position statements Hence me assuming lack of those voices in the process (I know jordan’s in the discord, but he’s like a match in a rainstorm)
010
jonchurch @jonchurch.com · 24/05/2026
Ill have to go back and check the discord to learn the history then e18e is a self selected group though where I dont expect there to be a diversity of opinion which goes against the group Ofc thats an oversimplification 🙇 I still am down to be one of yalls internal dissenters to represent
310
jonchurch @jonchurch.com · 24/05/2026
Often the justification for many things is “trends are going this way”, but e18e is the one organizing and forcing that trend It becomes a circular justification, and that feels risky to me. The ecosystem moves on trends. I want less Trending in my ecosystem trends and more discussion!
110
jonchurch @jonchurch.com · 24/05/2026
I do think there is use in discussing this. Very often I see people make a move like this where they drop a link to e18e work, invoke your name, and present it as settled facts from the experts Debate isnt the right word, we are not enemies.
210
jonchurch @jonchurch.com · 24/05/2026
It is bc of this that such pnpm settings feel like security theater, and teach people the wrong signals, and worse still overload those partial signals (TP, prov) with more confidence than they deserve. They deserve confidence! Just the appropriate amount.
110
jonchurch @jonchurch.com · 24/05/2026
Its clear IMO to see how that is naive? Scenario: My CI is compromised, my repo is pwned, my contributors turned to ghouls. I must publish the old fashioned way, a pristine clean version from a VM, to fix the situation! “Package security downgraded bc bad version used TP and clean didnt”, blocked
100
jonchurch @jonchurch.com · 24/05/2026
“Tools people considering OIDC more trusted than not”. That is fine, people can make their own choices about their own sec posture. The problematic thing is propagating that preference as if it were fact via features that misrepresent a switch from OIDC to a 2fa local publish as trust “downgrade”
210
jonchurch @jonchurch.com · 24/05/2026
Idk that anyone is saying that information shouldnt be made available about this Provenance is not a signal that I find useful The trust boundary that pwns people is not at the identity attestation level. The call is coming from inside the house as it were. But that is a tangent
110
jonchurch @jonchurch.com · 24/05/2026
I dont think these signs are completely meaningless. But I do believe that most people who opt into the pnpm setting do not understand what protections they are actually getting. IMO they are getting none. They get a sense of safety, and most dont realize what that is all they get, a vibe
130
jonchurch @jonchurch.com · 24/05/2026
Having some fields at the registry level to assert these different qualities is definitely a good idea, so lossy heuristics like this can be dropped
110
jonchurch @jonchurch.com · 24/05/2026
See a counter (now outdated) post that I also contributed to and stand by. This is what the Node project and security experts had to say about TP when we first made the requests to GH which you have seen roll out over the past few months openjsf.org/blog/publish...
openjsf.org
Publishing More Securely on npm: Guidance from the OpenJS Security Collaboration Space | OpenJS Foundation
The OpenJS Security Collaboration Space has been working closely with GitHub’s npm team to understand how new security features affect projects and maintainers, especially as threats and tools keep ev...
130
jonchurch @jonchurch.com · 24/05/2026
On the “agree to disagree”, a lot of maintainers disagree with you for the reasons outlined here. TP is trending all the same. Its worth asking why. With staged publishing now being an option, this is the first moment I would ever recommend it to anyone
130
jonchurch @jonchurch.com · 24/05/2026
Jordan’s points are correct in this thread. No one is saying there’s a silver bullet for security. Unfortunately, when positioning TP as the most secure recommendation without acknowledging the very real tradeoffs in security, the masses do equate it with a silver bullet
140
jonchurch @jonchurch.com · 24/05/2026
Correct me if Im wrong, but this isnt an npm issue but an issue in how pnpm is using heuristics to try and guess these things?
130
jonchurch @jonchurch.com · 24/05/2026
AI is best used to guilt trip your friends into going to Cracker Barrel with you
Ron how impoverished a life do you lead if you cant part with some coin for the pleasure of Campfire Beef with the boys, how poor is your soul when the bonds of wealth restrain you from the sacred smoke of fellowship

What cold province of the heart must a man inhabit to turn away from Fried Onion Petals, those golden little blossoms of friendship, arriving hot and communal to the table

What accountant of the damned taught you to deny yourself Loaded Hashbrown Casserole Tots, as though joy itself must first be itemized and approved
000
jonchurch @jonchurch.com · 23/05/2026
What are you trying to achieve? I think regular thread comments in PRs can use issue: write and reviews/inline comments on the diff require pr: write But theres nothing more granular that resource: read/write
130