Sign in

Jovi 🐨

@jovidecroock.com
1.5K followers 346 following 1.4K posts

🇧🇪 | Software Engineer @Shopify | Building drydock.org | Preact core team | passionate about DX & web perf | opinions are my own

PostsRepliesMedia
Jovi 🐨 @jovidecroock.com · 3h
I’ve maintained Preact for a bit over 7 years, I was just getting started in tech and we had this application with horrible performance. I looked around to see what we could do and switching React to Preact was an option. The extensible nature would allow me to tweak rendering.
1140
Jovi 🐨 @jovidecroock.com · 7h
Preact 11 is out 🎉 We’ve been hard at work at making our diffing use modern features like moveBefore , leveraging ESM for tree-shaking Preact Compat and ensuring you have a great experience with resumed hydration.
57818
Reposted by Jovi 🐨
nate moore @natemoo.re · 29/09/2026
we have no choice but to give the preact team billions of dollars 😌
3486
Reposted by Jovi 🐨
jviide.iki.fi @jviide.iki.fi · 29/09/2026
I didn't want to be the one to say it, but someone has to. Preact 11 will kill all of us.
2545
Jovi 🐨 @jovidecroock.com · 28/09/2026
Seeing drydock badges pop up like in mockhttp, docula and fumanchu really makes my day! github.com/jaredwray/mo...
github.com
GitHub - jaredwray/mockhttp: A simple HTTP server that can be used to mock HTTP responses for testing purposes. Inspired by httpbin and built using nodejs and fastify with the idea of running it via h...
A simple HTTP server that can be used to mock HTTP responses for testing purposes. Inspired by httpbin and built using nodejs and fastify with the idea of running it via https://mockhttp.org, via d...
020
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 26/09/2026
Putting up the PR to move Preact 11 from release candidate to stable feels like something that was a long time coming for me. I've worked on Preact X for the last 7 years, during which we had a different Preact 11 which was based on long-lived vnodes preactjs.com/blog/preact-x
preactjs.com
Preact X, a story of stability – Preact
2224
Jovi 🐨 @jovidecroock.com · 26/09/2026
For fans of gql.tada, I've put up a little experiment of creating a server-runtime where the output can just be used in gql.tada to have a typed client. This is inspired by the tRPC experience github.com/0no-co/gql.t...
github.com
feat: add gql.tada/server schema builder and schema contract by JoviDeCroock · Pull Request #594 · 0no-co/gql.tada
Resolves #10 · Stacked on #595 (input objects' inputFields keyed by field name) Adds gql.tada/server, so a schema defined in TypeScript types gql.tada documents directly, with no introspection ...
390
Jovi 🐨 @jovidecroock.com · 26/09/2026
Putting up the PR to move Preact 11 from release candidate to stable feels like something that was a long time coming for me. I've worked on Preact X for the last 7 years, during which we had a different Preact 11 which was based on long-lived vnodes preactjs.com/blog/preact-x
preactjs.com
Preact X, a story of stability – Preact
2224
Jovi 🐨 @jovidecroock.com · 26/09/2026
Makes me happy that folks are hyped about my Made in Belgium website. Been receiving submissions and it has expanded a lot, go take a look! madeinbe.dev/en/recent
madeinbe.dev
Recently added
The newest cards in the directory, most recent first: 154 on file, the latest added 26 September 2026. Follow along with the Atom feed.
081
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 20/09/2026
It really pains me to lookup GraphQL in search, the technology has gotten a really negative co-notation generally. It was sold the wrong way "solving over-/underfetching" was never the selling point... A product-centric API for all your clients was...
2121
Jovi 🐨 @jovidecroock.com · 21/09/2026
Lvl 31, what a journey
020
Jovi 🐨 @jovidecroock.com · 20/09/2026
It really pains me to lookup GraphQL in search, the technology has gotten a really negative co-notation generally. It was sold the wrong way "solving over-/underfetching" was never the selling point... A product-centric API for all your clients was...
2121
Jovi 🐨 @jovidecroock.com · 20/09/2026
I was thinking of adding some kind of dependency intelligence to drydock where closed repositories can also log on and see what they depend on, which repositories publish in what way, ... Could also be a good way for OSS maintainers to become aware what orgs use their code
010
Jovi 🐨 @jovidecroock.com · 20/09/2026
I refrain so often from posting to reddit/hackernews due to the amount of negativity it has most of the time. Might be one of the things making the marketing game weaker for mcp-tada, drydock, pracht and preact
050
Jovi 🐨 @jovidecroock.com · 20/09/2026
Agents are really good at diagnosing problems, however next time you are inclined to type "fix it" - read it, look at the source and come up with a fix yourself. Collaborate with your agent, don't trust it for opinions, 9 times out of 10 the solution it would bring is bloated
161
Jovi 🐨 @jovidecroock.com · 19/09/2026
One thing I find dangerous in the current MCP ecosystem is the tendency to advertise npx -y <mcp> which will always get the latest version, compromised dependencies,... included
220
Jovi 🐨 @jovidecroock.com · 19/09/2026
Drydock now has release memory, it will demote unchanged context risk when the package has been reviewed before. I noticed that a lot of deterministic findings would keep surfacing, when they've been checked already, they should not resurface! github.com/JoviDeCroock...
github.com
GitHub - JoviDeCroock/drydock: Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines
Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines - JoviDeCroock/drydock
000
Jovi 🐨 @jovidecroock.com · 18/09/2026
The ways OSS code gets compromised - A malicious actor publishes malicious code to the registry - A malicious actor pushes code to the repository - An action gets compromised and injects malicious code during publish - A cache is poisoned and that is bundled in/...
110
Jovi 🐨 @jovidecroock.com · 16/09/2026
Oof, this looks so good! www.npmchart.com/p/preact
npmchart.com
preact · npm downloads and repository activity
Download trends, releases, and repository activity for any npm package
171
Jovi 🐨 @jovidecroock.com · 15/09/2026
I am getting really tired of the amount of bot accounts spamming me on BlueSky, I wonder whether X was right all along with making their API payments based 😅
230
Reposted by Jovi 🐨
Patrick Brosset @patrickbrosset.com · 15/09/2026
I'm worried about the web. I don't want to live in a world where most users of internet-connected devices consume their information and accomplish their tasks via a chatbot interface.
patrickbrosset.com
Patrick - I'm worried about the web
I'm worried about the web. I don't want to live in a world where most users of internet-connected devices consume their information and accomplish their tasks via a chat bot interface.
97721
Jovi 🐨 @jovidecroock.com · 14/09/2026
What in the agent dystopia… I’ve received a PR on Preact which looked reasonable but then I looked in my email and saw an email from the authors agent asking for opencollective money 😅
390
Jovi 🐨 @jovidecroock.com · 14/09/2026
Added support for the 2.0 release of the MCP SDK
010
Jovi 🐨 @jovidecroock.com · 13/09/2026
Me: I'd like to sell merch for my OSS projects Belgium: Yes, nah, if your warehouse is hosted in a different country you should be taxed this way oh and also domestic tax this way and cross-border EU tax under 10k this way and over 10k that way and OH NO the US! Nevermind...
160
Jovi 🐨 @jovidecroock.com · 13/09/2026
Instead of giving the model 40 tool definitions, give it one run_code tool and a TypeScript declaration of the server. The declaration can be the .d.ts mcp-tada generated so it has typings of all the connected MCP's. Type-safety in code mode github.com/JoviDeCroock...
github.com
GitHub - JoviDeCroock/mcp-tada: Compile-time typed MCP tool calls for TypeScript
Compile-time typed MCP tool calls for TypeScript. Contribute to JoviDeCroock/mcp-tada development by creating an account on GitHub.
471
Reposted by Jovi 🐨
Laurie Voss @seldo.com · 13/09/2026
I have been writing this post about the economics of open source, on and off, for 13 years. I wasn't expecting to end up at "Microsoft should send corporations a huge bill" but nothing else we've tried has worked. seldo.com/posts/nobody-pays-for-ope…
seldo.com
Nobody pays for open source. We can force them to. | Seldo.com
Thirty years of voluntary funding schemes haven&#x27;t paid open source maintainers because asking doesn&#x27;t scale. The real money already flows — to JFrog, Docker, Sonatype — at the registry layer. The fix: registries charge companies for supply (they already do), then route a slice automatically to the maintainers who make that supply worth having.
2016655
Jovi 🐨 @jovidecroock.com · 12/09/2026
Anyone maintaining/authoring an MCP server want to talk? I'd love to hear from your experiences and issues doing it
230
Jovi 🐨 @jovidecroock.com · 12/09/2026
drydock has been scanning an increasing amount of staged packages, however it can't tell npm that a release is malicious yet while our github action environment can. We can and should do better github.com/community/co...
github.com
Release gates · community · Discussion #207561
🏷️ Discussion Type Product Feedback Body Hey all, I have been maintaining libraries for a bit over 7 years and the whole supply chain attack/GitHub actions injecting compromised code/... has me rea...
010
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 10/09/2026
Introducing mcp-tada: typed MCP tool calls for TypeScript. Snapshot a server's tools/list and every call gets a narrowed tool name, args inferred from inputSchema, and structuredContent typed from outputSchema. github.com/JoviDeCroock...
github.com
GitHub - JoviDeCroock/mcp-tada: Compile-time typed MCP tool calls for TypeScript
Compile-time typed MCP tool calls for TypeScript. Contribute to JoviDeCroock/mcp-tada development by creating an account on GitHub.
3143
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 11/09/2026
Every MCP callTool in TypeScript takes a string and returns unknown, mcp-tada reads the server once and ensures every tool-call has the proper names, input- and output types.
2116
Jovi 🐨 @jovidecroock.com · 11/09/2026
Every MCP callTool in TypeScript takes a string and returns unknown, mcp-tada reads the server once and ensures every tool-call has the proper names, input- and output types.
2116
Jovi 🐨 @jovidecroock.com · 10/09/2026
Introducing mcp-tada: typed MCP tool calls for TypeScript. Snapshot a server's tools/list and every call gets a narrowed tool name, args inferred from inputSchema, and structuredContent typed from outputSchema. github.com/JoviDeCroock...
github.com
GitHub - JoviDeCroock/mcp-tada: Compile-time typed MCP tool calls for TypeScript
Compile-time typed MCP tool calls for TypeScript. Contribute to JoviDeCroock/mcp-tada development by creating an account on GitHub.
3143
Jovi 🐨 @jovidecroock.com · 08/09/2026
Preact 11 will be tree-shakeable, you pay what you use of preact/compat. Soon you won't pay for createElement when using the jsx method. We're continuously trying to give the smallest bundle size, and 600 bytes saved might not seem like a lot but... to us it is
Side-by-side BundleJS comparison showing preact/compat before and after becoming tree-shakeable. The current version bundles render at 7.06 kB gzip with a 1.56 MB publish size, while the release candidate bundles the same import at 6.49 kB gzip with a 601 kB publish size.
1603
Jovi 🐨 @jovidecroock.com · 07/09/2026
Seems like the orange site also likes the EU infra moves, what more things are we missing to make EU builders successful?!
101
Jovi 🐨 @jovidecroock.com · 07/09/2026
I keep making little apps with things that frustrate me but I never publish them so... just putting it out there - an npm proxy that allows forking your deps and having org/app specific changes - a place where you can fund projects with tokens for us that aren't rich and want to crowdfund projects
180
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 05/09/2026
Preact 11 has been long in the making and I'm really proud of what came out the other end. It has quite some history as we first started working on a backing-node (fiber-like) structure for Preact but reversed.
2408
Jovi 🐨 @jovidecroock.com · 05/09/2026
Preact 11 has been long in the making and I'm really proud of what came out the other end. It has quite some history as we first started working on a backing-node (fiber-like) structure for Preact but reversed.
2408
Jovi 🐨 @jovidecroock.com · 03/09/2026
Having spent much of my career focused on DX, I can’t help but feel a little sad seeing these details get overlooked in the age of agents.
1130
Reposted by Jovi 🐨
Vitest @vitest.dev · 03/09/2026
Vitest 5 is here! 🎉 - Big performance improvements (vm pools up to 53% faster, ~18% boost across the board including Browser Mode) - New builtin Trace View in Browser Mode - Nested projects support - New benchmarking API - New `vi.when` API - Better defaults - And a lot of bug fixes!
vitest.dev
Announcing Vitest 5.0
Vitest 5.0 Release Announcement
221744
Jovi 🐨 @jovidecroock.com · 03/09/2026
Something that I am going to try to implement over the next months are dedicated OSS time in my calendar. An hour before and an hour after work will be the only time I reply and probably Sunday off. Sponsors might get an exception on this with a slack connection
030
Jovi 🐨 @jovidecroock.com · 03/09/2026
The hardest part about having a finished thing that I'd like to get out there... Deciding on a domain name, feels bad sending the workers.dev address to folks for opinions
workers.dev
110
Reposted by Jovi 🐨
indexzero @charlie.dev · 29/07/2026
⚰️ The npm registry as I knew it is officially dead. False positive rates for malware scanning are known to be astronomically high. That's because one attacker's malware is another developer's feature github.blog/changelog/20...
github.blog
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
111
Reposted by Jovi 🐨
drk @drk.wtf · 28/08/2026
www.youtube.com/watch?v=Chfj... good stuff
youtube.com
On the merits & limitations of React & single-page apps
YouTube video by Real World React
052
Jovi 🐨 @jovidecroock.com · 31/08/2026
The last few weeks have been intense, in a good way. My daughter was born two weeks ago and, while disrupting my sleep, she has stolen my heart.
4510
Jovi 🐨 @jovidecroock.com · 30/08/2026
While I wasn’t able to finish the fragment arguments specification, I did get it in graphql-js and now graphiql and the LSP tooling github.com/graphql/grap...
github.com
feat(graphql-language-service): support GraphQL 17 fragment arguments by JoviDeCroock · Pull Request #4462 · graphql/graphiql
Revives #3761 now that GraphQL.js 17 ships experimental fragment argument support. What changed parse fragment variable definitions and fragment spread arguments in the online parser enable GraphQ...
151
Jovi 🐨 @jovidecroock.com · 30/08/2026
Every time folks celebrate EU companies I tend to check where they are incorporated and more often than not.... Lovable comes up as a poster child of European startups, however while the founders are - the company is not. The EU can do better www.sovereignmagazine.com/article/swed...
sovereignmagazine.com
Lovable AI Is a Delaware Company, Not Swedish
Lovable Labs is incorporated in Delaware despite operating from Sweden. Why Europe's top AI startups keep choosing US corporate law.
140
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 29/08/2026
Valid provenance but with malware Drydock would have flagged the releases with binding.gyp: high and preinstall: critical. While drydock can't block a release for this particular case npm staged publishing would have created a second surface to approve and have prevented this
aikido.dev
Popular code generator for TanStack Query hit by supply chain worm
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains...
142
Jovi 🐨 @jovidecroock.com · 29/08/2026
Been playing a bit with WebMCP over the past few days and I kind of like where this is going.
152
Jovi 🐨 @jovidecroock.com · 29/08/2026
Valid provenance but with malware Drydock would have flagged the releases with binding.gyp: high and preinstall: critical. While drydock can't block a release for this particular case npm staged publishing would have created a second surface to approve and have prevented this
aikido.dev
Popular code generator for TanStack Query hit by supply chain worm
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains...
142
Jovi 🐨 @jovidecroock.com · 28/08/2026
Great description 10/10 would apply again
040