Sign in

Jovi 🐨

@jovidecroock.com
1.5K followers 346 following 1.4K posts

🇧🇪 | Software Engineer @Shopify | Building drydock.org | Preact core team | passionate about DX & web perf | opinions are my own

PostsRepliesMedia
Jovi 🐨 @jovidecroock.com · 19m
The RTS release is on my list today so should be available in a few hours
000
Jovi 🐨 @jovidecroock.com · 6h
This is the way
110
Jovi 🐨 @jovidecroock.com · 10h
It’s been a real piece of work getting Preact 11 to a shape worthy of a major and worthy of our awesome community, I hope y’all enjoy it. Thank you for taking a bet on an ambitious junior
150
Jovi 🐨 @jovidecroock.com · 10h
I’m not that unexperienced person just coming out of school anymore. I know what I want and I’ve helped shape the philosophy of Preact. Seeing the evolution of Preact has been an honor, when I joined we had 300k weekly downloads and now we have over 30 million weekly downloads.
160
Jovi 🐨 @jovidecroock.com · 10h
As of a certain minor in Preact X and for almost everything in Preact 11 I was the guiding maintainer and it’s been such a surprise realising how I’ve grown over the past years.
140
Jovi 🐨 @jovidecroock.com · 10h
I started eagerly converting our codebase but bumped into act missing from the Preact X alpha at the time, that was my first PR github.com/preactjs/pre... - I’ve done several after that and ultimately became a maintainer. I learned so much working with the wider team.
github.com
(Test) - testutils package with act for hooks by JoviDeCroock · Pull Request #1371 · preactjs/preact
Please don't mind where it's located now, I've been trying to make it work. Tests are still a success but the updates aren't synchronous yet, I feel like I am missing something extr...
150
Jovi 🐨 @jovidecroock.com · 10h
I’ve maintained Preact for a bit over 7 years, I was just getting started in tech and we had this application with horrible performance. I looked around to see what we could do and switching React to Preact was an option. The extensible nature would allow me to tweak rendering.
2191
Jovi 🐨 @jovidecroock.com · 11h
github.com/preactjs/pre...
github.com
preact/src/diff/children.js at main · preactjs/preact
⚛️ Fast 3kB React alternative with the same modern API. Components & Virtual DOM. - preactjs/preact
020
Jovi 🐨 @jovidecroock.com · 13h
Can’t wait to see!
030
Jovi 🐨 @jovidecroock.com · 13h
Thank you everyone for the feedback, pull requests and issues we've gotten over the years, it has enabled this release! preactjs.com/blog/preact-...
preactjs.com
Preact 11 – Preact
The wait is finally over: Preact 11 is here!
061
Jovi 🐨 @jovidecroock.com · 13h
Hydration 2.0: hydrating while lazy chunks are still loading makes 0 DOM mutations, and lazy components can return a Fragment or null. Returning 0 or more than 1 DOM node in Preact X would introduce hydration mismatches for resumed hydration before all of this.
190
Jovi 🐨 @jovidecroock.com · 13h
Child reconciliation goes through Element.moveBefore() where supported. Reverse a list of 10 iframes: Preact 10 reloads 9, Preact 11 reloads 0, and the focused input stays focused.
Diagram comparing keyed list reordering behavior in Preact 10.29.8 and Preact 11.0.0. In Preact 11, keyed DOM moves use Element.moveBefore() where supported, preserving iframe state and input focus during reordering. Moving one row, reversing the list, and shuffling the list all reload 0 of 10 iframes and keep focus in Preact 11. In Preact 10, the same operations reload 1, 9, and 6 of 10 iframes respectively, and focus is lost in each case.
2131
Jovi 🐨 @jovidecroock.com · 13h
preact/compat is now tree-shakeable per feature. A library that only imports memo or forwardRef pulls in ~1.3–1.4 kB of compat instead of ~2.2 kB (−35–40% for single APIs).
Bar chart comparing Preact 10.29.8 and Preact 11.0.0 bundle sizes for preact/compat features. Preact 11 reduces compat code for individual React APIs by roughly 35–40%: memo drops from 2,215 B to 1,418 B, forwardRef from 2,218 B to 1,326 B, useSyncExternalStore from 2,275 B to 1,468 B, Children from 2,190 B to 1,334 B, and createRoot from 2,183 B to 1,316 B. Suspense + lazy drops 13%, from 2,215 B to 1,917 B, while importing everything drops 5.5%, from 3,752 B to 3,547 B. The chart highlights that Preact 11 makes preact/compat tree-shakeable per feature.
1100
Jovi 🐨 @jovidecroock.com · 13h
Core is 4.5 kB brotli, +75 B over 10.29, while adding Hydration 2.0, minimal-move keyed diffing, moveBefore and createPortal.
Four comparison bars showing Preact 10 vs 11 in terms of published bundle size.

preact +75b at 4459b
hooks +41b at 1419b
compat -177b at 3556b
1100
Jovi 🐨 @jovidecroock.com · 13h
The npm package went from 1.56 MB to 609 kB (−61%). v11 ships ES modules only, so the CommonJS, UMD and duplicate builds, and most source maps, are gone. The runtime you ship is the same ~40 kB of ESM.
2 bars showing the total package size of Preact, in 10.29.8 it's at 1.56MB and at 11.0.0 609KB which is 61% reduction in size.
1212
Jovi 🐨 @jovidecroock.com · 13h
Preact 11 is out 🎉 We’ve been hard at work at making our diffing use modern features like moveBefore , leveraging ESM for tree-shaking Preact Compat and ensuring you have a great experience with resumed hydration.
59220
Jovi 🐨 @jovidecroock.com · 29/09/2026
You know what, I'll take a lot less as well
130
Reposted by Jovi 🐨
nate moore @natemoo.re · 29/09/2026
we have no choice but to give the preact team billions of dollars 😌
3486
Reposted by Jovi 🐨
jviide.iki.fi @jviide.iki.fi · 29/09/2026
I didn't want to be the one to say it, but someone has to. Preact 11 will kill all of us.
2545
Jovi 🐨 @jovidecroock.com · 28/09/2026
Seeing drydock badges pop up like in mockhttp, docula and fumanchu really makes my day! github.com/jaredwray/mo...
github.com
GitHub - jaredwray/mockhttp: A simple HTTP server that can be used to mock HTTP responses for testing purposes. Inspired by httpbin and built using nodejs and fastify with the idea of running it via h...
A simple HTTP server that can be used to mock HTTP responses for testing purposes. Inspired by httpbin and built using nodejs and fastify with the idea of running it via https://mockhttp.org, via d...
020
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 26/09/2026
Putting up the PR to move Preact 11 from release candidate to stable feels like something that was a long time coming for me. I've worked on Preact X for the last 7 years, during which we had a different Preact 11 which was based on long-lived vnodes preactjs.com/blog/preact-x
preactjs.com
Preact X, a story of stability – Preact
2224
Jovi 🐨 @jovidecroock.com · 26/09/2026
No codegen needed, you can import the type into your client and use it. See the example
000
Jovi 🐨 @jovidecroock.com · 26/09/2026
For fans of gql.tada, I've put up a little experiment of creating a server-runtime where the output can just be used in gql.tada to have a typed client. This is inspired by the tRPC experience github.com/0no-co/gql.t...
github.com
feat: add gql.tada/server schema builder and schema contract by JoviDeCroock · Pull Request #594 · 0no-co/gql.tada
Resolves #10 · Stacked on #595 (input objects' inputFields keyed by field name) Adds gql.tada/server, so a schema defined in TypeScript types gql.tada documents directly, with no introspection ...
390
Jovi 🐨 @jovidecroock.com · 26/09/2026
It's also quite something to see these AI firms hit record revenue with a lot of the knowledge OSS has put in the world (issues, PR's, source code, ...)
030
Jovi 🐨 @jovidecroock.com · 26/09/2026
Thank you! I can relate to that, not sure how much of that I'll still work on. If work needs something I can look at it, I've been just building stuff I like like drydock.org but it's all feeling a bit empty lately
drydock.org
Drydock Package Review: read the artifact before you publish
Your pull request got reviewed; the published tarball did not. Drydock diffs the exact npm, PyPI, or VS Code artifact and pins supply-chain findings to changed lines.
140
Jovi 🐨 @jovidecroock.com · 26/09/2026
OSS has been feeling a bit empty for the past year so I am going to be taking it easy for a bit, especially now that my days are really full with a newborn, drydock and work
1120
Jovi 🐨 @jovidecroock.com · 26/09/2026
Releasing Preact 11 with better hydration, moveBefore support and some reshuffling may sound like a boring release but to me it feels like completing something I've thought about for a while, I want to thank everyone for supporting Preact and enabling my journey
1131
Jovi 🐨 @jovidecroock.com · 26/09/2026
I've often referred to Preact X as finished software especially in these last minors... We've published 29 (!!) of them and admittedly, some of it has been a very lonely journey for me
140
Jovi 🐨 @jovidecroock.com · 26/09/2026
Putting up the PR to move Preact 11 from release candidate to stable feels like something that was a long time coming for me. I've worked on Preact X for the last 7 years, during which we had a different Preact 11 which was based on long-lived vnodes preactjs.com/blog/preact-x
preactjs.com
Preact X, a story of stability – Preact
2224
Jovi 🐨 @jovidecroock.com · 26/09/2026
Makes me happy that folks are hyped about my Made in Belgium website. Been receiving submissions and it has expanded a lot, go take a look! madeinbe.dev/en/recent
madeinbe.dev
Recently added
The newest cards in the directory, most recent first: 154 on file, the latest added 26 September 2026. Follow along with the Atom feed.
081
Jovi 🐨 @jovidecroock.com · 25/09/2026
The way we are currently going, 100% - it's a weird time
010
Jovi 🐨 @jovidecroock.com · 24/09/2026
It's a very hard balance to strike currently given that the role is transforming into a very product-y one when it's viewed by folks in more managerial positions
111
Reposted by Jovi 🐨
Jovi 🐨 @jovidecroock.com · 20/09/2026
It really pains me to lookup GraphQL in search, the technology has gotten a really negative co-notation generally. It was sold the wrong way "solving over-/underfetching" was never the selling point... A product-centric API for all your clients was...
2121
Jovi 🐨 @jovidecroock.com · 21/09/2026
Lvl 31, what a journey
020
Jovi 🐨 @jovidecroock.com · 20/09/2026
persisted operations solve a lot of the DDos concern as caching and rate limiting becomes easier
011
Jovi 🐨 @jovidecroock.com · 20/09/2026
There's also a lot of misinformation, you don't have to lose out on caching. It's however all under developed, if tinkerers would come back to the tech and make it easy to use persisted-operations, ... it would be far less of a problem I think
030
Jovi 🐨 @jovidecroock.com · 20/09/2026
This also isn't for everyone nor is it for every use case but it really has good use cases and it enables discoverable API's, great generic caches, ...
140
Jovi 🐨 @jovidecroock.com · 20/09/2026
It really pains me to lookup GraphQL in search, the technology has gotten a really negative co-notation generally. It was sold the wrong way "solving over-/underfetching" was never the selling point... A product-centric API for all your clients was...
2121
Jovi 🐨 @jovidecroock.com · 20/09/2026
I was thinking of adding some kind of dependency intelligence to drydock where closed repositories can also log on and see what they depend on, which repositories publish in what way, ... Could also be a good way for OSS maintainers to become aware what orgs use their code
010
Jovi 🐨 @jovidecroock.com · 20/09/2026
I refrain so often from posting to reddit/hackernews due to the amount of negativity it has most of the time. Might be one of the things making the marketing game weaker for mcp-tada, drydock, pracht and preact
050
Jovi 🐨 @jovidecroock.com · 20/09/2026
Agents are really good at diagnosing problems, however next time you are inclined to type "fix it" - read it, look at the source and come up with a fix yourself. Collaborate with your agent, don't trust it for opinions, 9 times out of 10 the solution it would bring is bloated
161
Jovi 🐨 @jovidecroock.com · 19/09/2026
It should yes, all though I wonder whether this increase in min release age will slow down compromise detection. Most detection is reactive, drydock was my attempt at making it proactive but… npm does not give us much to work with.
110
Jovi 🐨 @jovidecroock.com · 19/09/2026
One thing I find dangerous in the current MCP ecosystem is the tendency to advertise npx -y <mcp> which will always get the latest version, compromised dependencies,... included
220
Jovi 🐨 @jovidecroock.com · 19/09/2026
Drydock now has release memory, it will demote unchanged context risk when the package has been reviewed before. I noticed that a lot of deterministic findings would keep surfacing, when they've been checked already, they should not resurface! github.com/JoviDeCroock...
github.com
GitHub - JoviDeCroock/drydock: Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines
Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines - JoviDeCroock/drydock
000
Jovi 🐨 @jovidecroock.com · 18/09/2026
One final tip for folks using OIDC publishing, turn on "Use immutable subject claim" in your OIDC GH repo settings
000
Jovi 🐨 @jovidecroock.com · 18/09/2026
Finally, cache poisoning issues can be prevented by not leveraging caches inside of your publishing workflow. I hope this can help some people out, I have also added this as a skill at github.com/JoviDeCroock...
github.com
110
Jovi 🐨 @jovidecroock.com · 18/09/2026
A compromised action can be prevented by always pinning the action by SHA or ensuring the repository uses immutable releases and pinning to a release. Tip: enable "Require actions to be pinned to a full-length commit SHA" on your repositories
100
Jovi 🐨 @jovidecroock.com · 18/09/2026
A malicious actor pushes code to the repository which can result in a direct publish or some hidden code that gets later published by the author. With stage publish we can prevent this, we can leverage a tool like drydock.org to verify before it hits the registry
drydock.org
Drydock Package Review: pre-publish package security
Review the exact npm, PyPI, or VS Code artifact before publication. Drydock diffs built package bytes and pins supply-chain risks to changed lines.
100
Jovi 🐨 @jovidecroock.com · 18/09/2026
Direct publishes by a malicious actor can get verified, with current provenance we can prove that a publish comes from a verified source (repository, ci-run, ...) We sadly can't tell npm to disallow direct publishing and only allow i.e. stage publish with multiple approvals
100
Jovi 🐨 @jovidecroock.com · 18/09/2026
The ways OSS code gets compromised - A malicious actor publishes malicious code to the registry - A malicious actor pushes code to the repository - An action gets compromised and injects malicious code during publish - A cache is poisoned and that is bundled in/...
110