Sign in

Jordan Harband

@jordan.har.band
3.7K followers 494 following 642 posts

github.com/ljharb software engineer/nerd/teacher/will try anything once; surgeon with git rebase. @TC39.es @Socket.dev ex @Coinbase/@Airbnb/@Twitter/@MobBase. Fav punctuation ⸮, scent petrichor

PostsRepliesMedia
Reposted by Jordan Harband
harbor.ist @harbor.ist · 29/09/2026
Two new CVEs published today (as well as the fixed releases for them): `shell-quote`: www.cve.org/CVERecord?id... `pbkdf2`: www.cve.org/CVERecord?id...
011
Jordan Harband @jordan.har.band · 27/09/2026
i wish I’d discovered both scuba diving and Japan in my 20s rather than in my 40s. the last two decades would have been quite different.
390
Reposted by Jordan Harband
Leah McElrath @leahmcelrath.bsky.social · 24/09/2026
AP Stylebook warns against anthropomorphizing AI systems: “Avoid language that gives them human characteristics… Instead, explain what a system does, how well it performs, who built it and who could be affected by it.”
APStylebook @APStylebook
X.com
Artificial intelligence systems do not think, feel, want or understand. Avoid language that gives them human characteristics. This is called anthropomorphizing, when we ascribe human traits, emotions or behaviors to non-human things, such as animals or inanimate objects.
Instead, explain what a system does, how well it performs, who built it and who could be affected by it.
1970102257
Jordan Harband @jordan.har.band · 21/09/2026
nvm.sh v0.40.8 is out, fixing a path traversal vuln and a number of bugs - cve.org/CVERecord?id... - github.com/nvm-sh/nvm/r...
github.com
Release v0.40.8 · nvm-sh/nvm
Bug Fixes nvm_alias, nvm_version_path: reject .. path components nvm_get_make_jobs: count cores on platforms the case does not name nvm-exec: improve the no-version failure message nvm use: do not...
042
Reposted by Jordan Harband
Starfire’s Deranged Neocon Foreign Policy Podcast @irhottakes.bsky.social · 18/09/2026
It’s very simple. A reality TV host became dictator because he turned down a role for Sharknado 4 and that’s why the king of outer space, who cheats at Diablo, got to kill Africa. Now the economy is controlled by a sex cult that has something to do with Harry Potter fanfic because of robots.
15786372553
Reposted by Jordan Harband
Demigirlboss @demigirlboss.win · 18/09/2026
DO SOMETHING YOU LOVE AND YOU'LL NEVER WORK A DAY IN YOUR LIFE. COROLLARY. DO SOMETHING YOU LOVE AND YOU NEVER TAKE DAYS OFF EITHER. THIS IS A POST ABOUT BEING AN ENGINEER.
41174
Reposted by Jordan Harband
danielroe @danielroe.dev · 19/09/2026
don't be nice.
roe.dev
Don't be nice
Sometimes, it's more important to be good than it is to be nice.
41734246
Reposted by Jordan Harband
bryan english @bengl.dev · 19/09/2026
Joel Spolsky, 2002
The law of leaky abstractions means that whenever somebody comes up with a wizzy new code-generation tool that is supposed to make us all ever-so-efficient, you hear a lot of people saying “learn how to do it manually first, then use the wizzy tool to save time.” Code generation tools which pretend to abstract out something, like all abstractions, leak, and the only way to deal with the leaks competently is to learn about how the abstractions work and what they are abstracting. So the abstractions save us time working, but they don’t save us time learning.
041
Jordan Harband @jordan.har.band · 03/09/2026
tfw you and your cat successfully hunt a bug
static.klipy.com
Cat High Five
ALT: Cat High Five
0100
Jordan Harband @jordan.har.band · 26/08/2026
Oh, right. The daybed. The daybed for Kuzco, the daybed chosen especially to relax Kuzco, Kuzco’s daybed. That daybed?
Sign for “Daybed 7” that says “Cronk Party”
010
Jordan Harband @jordan.har.band · 14/08/2026
Your friendly reminder that a thing developed in isolation, absent sufficient stakeholders, has to be insanely, extremely, staggeringly good to be able to outweigh the aforementioned badness. (spoiler alert: it probably isn’t)
240
Jordan Harband @jordan.har.band · 12/07/2026
lol why would Glendale Community College have any info about me whatsoever??? I've never attended, applied, lived near it, or been to Glendale. this is the most confusing @haveibeenpwned.com email i've gotten yet
110
Reposted by Jordan Harband
npm @npmjs.com · 08/07/2026
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
26024
Reposted by Jordan Harband
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026
You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss
01510
Jordan Harband @jordan.har.band · 06/07/2026
can someone please tell *every bank* that if a "secure messaging system" goes to my email address, then it's basically not possible for it to be more secure than my email account itself?
000
Reposted by Jordan Harband
Coach Finstock @coachfinstock.bsky.social · 22/03/2026
Aesop: I TOLD YOU
10278892412
Jordan Harband @jordan.har.band · 03/07/2026
please be student patient driver
bumper sticker trying to say “please be patient, student driver”data/lore meme
161
Jordan Harband @jordan.har.band · 30/06/2026
@tantek.com.web.brid.gy (ง’̀-‘́)ง
120
Jordan Harband @jordan.har.band · 19/06/2026
I got really tired of having to manually track down whether a package ships its own types, or has a DefinitelyTyped package, or how that changes over time. so, I made npmjs.com/dt-clean - `npx dt-clean -u` and you'll have the right version of the right DT packages!
npmjs.com
0152
Jordan Harband @jordan.har.band · 11/06/2026
ok i know i'm a couple months late, but wtaf is this new "Marathon" game? it seems like it has precisely nothing to do with actual Marathon lore, and is just a (potentially fun but) entirely unrelated game with the title slapped on top.
220
Jordan Harband @jordan.har.band · 11/06/2026
it is oddly satisfying watching ferrier content on the reels
000
Jordan Harband @jordan.har.band · 04/06/2026
nvm.sh v0.40.5 is out, with some CVE fixes: github.com/nvm-sh/nvm/r... Be sure to update!
github.com
Release v0.40.5 · nvm-sh/nvm
New Stuff nvm install --offline: install from cache without network access Bug Fixes nvm_download_artifact: reject version strings with disallowed characters nvm_get_checksum: pass the tarball n...
052
Jordan Harband @jordan.har.band · 26/05/2026
what happened to the kiki bouba labeler??
010
Reposted by Jordan Harband
Mike Cook @mtrc.bsky.social · 21/05/2026
oh no, i don't use the ai for <thing that i am paid to do> it's terrible at that. it's great for <thing you are paid to do> though.
its amazing how chatgpt knows everything about subjects I know nothing about, but is wrong like 40% of the time about things im an expert on. not going to think about this any further
41131306
Reposted by Jordan Harband
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Jordan Harband @jordan.har.band · 30/04/2026
Clutching pearls about how many PURLs are in your application is just FUD and nonsense. The only thing that matters is, how many humans can put code into it. (ie all your engineers + every linux dev + every OSS maintainer etc)
031
Jordan Harband @jordan.har.band · 22/04/2026
PSA: add `export GH_TELEMETRY=false` and `export DO_NOT_TRACK=true` to your shell profile files to opt out of @github.com's on-by-default `gh` telemetry.
0141
Jordan Harband @jordan.har.band · 22/04/2026
oof, who do i complain to about the name of git 2.54's "history" command? git does not have a history, it has a changelog, and the conceptual difference is very important for having the proper mental model :-(
200
Jordan Harband @jordan.har.band · 04/04/2026
I was pretty happy with my surroundings while discussing supply chain security today.
Tahoe and snow from Palisades.
0160
Reposted by Jordan Harband
Wes @notwes.bsky.social · 03/04/2026
The thing people may not realize is that the best way to secure the supply chain is to secure the maintainers. And the best way to secure the maintainers is to pay them and give them a laptop, health insurance, and maybe even a desk to sit at.
1105
Reposted by Jordan Harband
eliza🌻 @elizas.website · 03/04/2026
so what i am learning from github.com/axios/axios/... is that you should simply never join a Microsoft Teams call for any reason --- because of security
github.com
Post Mortem: axios npm supply chain compromise · Issue #10636 · axios/axios
Post Mortem: axios npm supply chain compromise Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were...
413834
Reposted by Jordan Harband
Socket @socket.dev · 03/04/2026
🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week. socket.dev/blog/attacke...
socket.dev
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
12814
Reposted by Jordan Harband
Darcy Clarke @darcyclarke.me · 01/04/2026
tldr; if you used @vlt.sh as your package manager, then you were protected the minute @socket.dev flagged the malicious packages in the `axios` attack yesterday. The best time to switch your package manager was 48hrs ago, the next best time is right now. More below: blog.vlt.sh/blog/vlt-build
blog.vlt.sh
Introducing Phased Package Installations
When you run vlt install, packages are downloaded and extracted to node_modules, but no lifecycle scripts execute.
1137
Reposted by Jordan Harband
Socket @socket.dev · 01/04/2026
🧨 Axios only needed to be resolved somewhere in your dependency graph to affect you. Semver + transitive deps + runtime installs = hidden blast radius. If you only checked your project’s lockfile, you may still not know. socket.dev/blog/hidden-... #nodejs #javascript
socket.dev
The Hidden Blast Radius of the Axios Compromise - Socket
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
01613
Reposted by Jordan Harband
TC39 @tc39.es · 11/03/2026
ECMAScript Euphoria! 🎉 We don't always post when a single proposal advances, but when we do, it's Temporal -> Stage 4. Just days shy of 9 years from Stage 1, a herculean effort on the part of many champions, delegates, invited experts, and contributors, past and present. Thank you all! 🙌
220948
Reposted by Jordan Harband
Rob Palmer @robpalmer.bsky.social · 10/03/2026
ECMAScript excitement 😉 Congrats to @jordan.har.band on advancing Error.prototype.stack to Stage 2.7 at TC39 today 🎉 This proposal seeks to standardize the existence of the accessor in the JS spec. github.com/tc39/proposa...
github.com
Path to Stage 4! · Issue #9 · tc39/proposal-error-stack-accessor
Stage 4 committee approval two implementations v8 (node / Chrome) node (for DOMException) spidermonkey (Firefox) jsc (Webkit / Safari) Deno (for DOMException) Porffor es-shims polyfill keisel Boa s...
1211
Jordan Harband @jordan.har.band · 10/03/2026
did you know claude code has _weekly_ usage limits? i didn't
130
Jordan Harband @jordan.har.band · 09/03/2026
Finally found a plane with a device holder that can fit an iPad Pro
The back of a plane seat, holding an iPad Pro
1110
Jordan Harband @jordan.har.band · 06/03/2026
i hadn’t hit Claude’s limits once since upgrading to the 10x max plan, but it took me less than 24 hours to hit the limits on the free open source 20x max plan (-‸ლ)
media.tenor.com
a cartoon character is sitting in front of an orange emergency exit sign
ALT: a cartoon character is sitting in front of an orange emergency exit sign
1130
Jordan Harband @jordan.har.band · 03/03/2026
Your mission, should you choose to accept it
An open briefcase filled with office supplies
110
Reposted by Jordan Harband
Socket @socket.dev · 28/02/2026
minimatch patched 3 high-severity ReDoS vulnerabilities that can stall the Node.js event loop. Because it's pulled into nearly every corner of the #NodeJS ecosystem (~472M weekly downloads), we're releasing free Certified Patches for all three. socket.dev/blog/minimat... #JavaScript
socket.dev
minimatch Patches 3 High-Severity ReDoS Vulnerabilities - So...
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.
054
Reposted by Jordan Harband
Socket @socket.dev · 19/02/2026
We're excited to announce that Socket is joining the @openjsf.org! Proud to support the #JavaScript ecosystem alongside so many great projects and contributors. socket.dev/blog/socket-...
socket.dev
Socket Joins the OpenJS Foundation - Socket
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecos...
0175
Reposted by Jordan Harband
OpenJS Foundation @openjsf.org · 19/02/2026
🎉 We’re thrilled to welcome @socket.dev as our newest Silver member. Socket is doing critical work to secure the JavaScript ecosystem by helping developers identify and prevent supply chain risks. We're excited to collaborate and make open source safer for everyone! 🛡️💻 openjsf.org/blog/socket-...
0236
Jordan Harband @jordan.har.band · 12/02/2026
when you're publishing a CVE, please think about the good actor/bad actor cohorts (especially governments) that will be awake and responsive to deal with it to be clear, evening pacific time is a very poor choice.
040
Jordan Harband @jordan.har.band · 01/02/2026
here’s a fun fact - the vast majority of the conspiracy theorists are still very wrong even when they get it right that said, they should probably be buying lottery tickets, because wtaf
030
Reposted by Jordan Harband
Citizen Platano 🇵🇷 @daniloc.xyz · 31/01/2026
me at 17: a secret conspiracy of billionaires shapes global events me at 35: class interest creates emergent outcomes and aligned behavior, but there’s no smoky room where plutocrats plot to shape global events me at 41: a secret conspiracy of billionaire perverts shapes global events
214130
Reposted by Jordan Harband
Kate Compton @galaxykate.bsky.social · 31/01/2026
You can test new tech ideas using the Seinfeld Test Would the product eliminate the plot of an episode? (Google maps, cell phones, paypal, battery packs) Good tech. Would the product inspire new Seinfeld plots? (NFTs, AI chatbots, crypto currency, blindboxes, metaverse land sales) Bad tech.
7688072844
Reposted by Jordan Harband
Sarah Gooding @sarahgooding.bsky.social · 31/01/2026
"Security work is emotionally expensive and invisible, and sharing it makes it sustainable." - @ulisesgascon.com Many thanks to @jddalton.bsky.social, @jordan.har.band, and @ulisesgascon.com for their insights on maintaining Lodash and all the hard work put into reviving the project. 💚
0127
Reposted by Jordan Harband
Thomas Fuchs 🫯 @thomasfuchs.at · 30/01/2026
2006: Less is more, don’t repeat yourself 2016: Beautiful code prevents technical debt 2026: trillions of lines of generated spaghetti code that generate other spaghetti code will save us
212930
Jordan Harband @jordan.har.band · 29/01/2026
nvm.sh users: please upgrade to github.com/nvm-sh/nvm/r... if you're using `wget` on your system, to fix a medium vulnerability (github.com/nvm-sh/nvm/s...).
github.com
Release v0.40.4 · nvm-sh/nvm
Bug Fixes sanitize NVM_AUTH_HEADER in wget path nvm_has_colors: also check if stdout is a terminal nvm_strip_path: avoid gawk-specific RT variable for mawk compatibility nvm_get_default_packages: ...
164