Karl Horky @karlhorky.com · 18hwhat I was doing (using TS for security) was not common at the time, so it was understandably not so much of an easy sell but AI agent guardrails use this now successfully to prevent these types of security holes 010
Karl Horky @karlhorky.com · 18h@lirantal.com @notwes.bsky.social circling back around to this after a while in the AI agentic era, there have been new tools that also follow a similar pattern to using TS as a security tool if you ask your agent, i'm sure you'll find a lot more precedent of this eg github.com/rauchg/gdp-ts 110
Karl Horky @karlhorky.com · 26/08/2026introducing the `code-comments` skill: clearer, more deterministic code comments why: AI mostly writes in horrible, unclear, twisted ways (esp Claude) and that slop is saved in your codebase code comments, w. human + AI comprehension costs npx skills add karlhorky/agent-skills 220
Karl Horky @karlhorky.com · 20/08/2026Seems like the Node.js cookbook still mentions Corepack with pnpm, PR open github.com/jdx/mise/pul... cc @jdx.devgithub.comSwitch Corepack to Idiomatic Version Files for pnpm by karlhorky · Pull Request #12213 · jdx/miseCorepack is now recommended against for pnpm: "Invalid package manager specification in package.json (pnpm@^11.1.3); expected a semver version" with corepack pnpm/pnpm#11732 (comment) ht... 020
Karl Horky @karlhorky.com · 20/08/2026but I understand that Netlify may want something like Mise to also manage other package manager versions like npm, Bun, Deno, vlt, etc looks like it supports devEngines.packageManager (and the older packageManager) mise.jdx.dev/configuratio....mise.jdx.devConfiguration | mise-en-placemise-en-place documentation 100
Karl Horky @karlhorky.com · 20/08/2026Yarn 6+ also manages its own versions with Yarn Switch: yarn6.netlify.app/concepts/swi...yarn6.netlify.appYarn SwitchA description of Yarn Switch, the official way to manage Yarn binaries across projects. 100
Karl Horky @karlhorky.com · 20/08/2026now that pnpm manages its own versions since v10, I think Mise isn't strictly necessary for it github.com/pnpm/pnpm/pu...github.comRelease pnpm 10 · pnpm/pnpmMajor Changes Lifecycle scripts of dependencies are not executed during installation by default! This is a breaking change aimed at increasing security. In order to allow lifecycle scripts of spe... 110
Karl Horky @karlhorky.com · 20/08/2026nice, thanks! seems to have a lot of great AI writing tells (although I actually prefer dense writing with fewer characters, so I won't apply this skill wholesale) but I've bookmarked it - maybe I'll grab some things next time I make some edits to my agents.md or try adding a skill 010
Karl Horky @karlhorky.com · 20/08/2026Also asked @eduardoboucas.com over here: x.com/karlhorky/st...x.comKarl Horky (@karlhorky) on X@zkochan @imjcmartin @pnpmjs @theoklitosBam7 @eduardoboucas would @Netlify switch off Corepack for pnpm now that it's officially recommended against? https://t.co/ryETEOhSc2 010
Karl Horky @karlhorky.com · 20/08/2026@philippeserhal.com would @netlify.com switch off Corepack for pnpm now that it's officially recommended against? x.com/karlhorky/st...x.comKarl Horky (@karlhorky) on XOfficial recommendation from the pnpm team to avoid Corepack 220
Karl Horky @karlhorky.com · 19/08/2026still trying to get Claude Code (Opus 5, but all Anthropic models are like this) to be more grounded in reality and less persuasive / rhetoric-heavy the responses are by default so unstructured and void of proof / verification push a little bit against the rhetoric and "You're absolutely right!" 131
Karl Horky @karlhorky.com · 18/08/2026TypeScript overlays in MDX files 😍 Using TS 7.x Content Mappers by @andrewbran.ch 🙌 0180
Karl Horky @karlhorky.com · 16/08/2026Community feedback worked! GitHub is pausing the deprecation github.com/orgs/communi...github.comNotification subscriptions cannot be customised anymore. · community · Discussion #204563🏷️ Discussion Type Bug 💬 Feature/Topic Area Issues Body This is a recurrence of what discussions/132506#discussioncomment-11294250 resolved: To summarise, I am unable to utilise the "Custom" featur... 010
Karl Horky @karlhorky.com · 12/08/2026blog post github.blog/changelog/20...github.blogCustom thread subscriptions are being deprecated - GitHub ChangelogYou’ll no longer be able to configure custom thread subscriptions for GitHub notifications. What’s changing As part of this rollout, GitHub will remove support for custom thread subscription settings.... 000
Karl Horky @karlhorky.com · 12/08/2026ahh @github.com is removing "Close" notifications?? 😬 notifications are already bad enough, making them worse? submit your feedback here: github.com/orgs/communi... 300
Karl Horky @karlhorky.com · 12/08/2026I also created a Next.js issue to possibly get this into a 1st-party CLI github.com/vercel/next....github.comNext.js TypeScript plugin diagnostics not reported by CLI / CI type checking with `tsc` or `next` subcommand · Issue #97229 · vercel/next.jsLink to the code that reproduces this issue https://github.com/karlhorky/repro-next-js-typescript-plugin-diagnostics-no-cli To Reproduce Open the reproduction sandbox at https://codesandbox.io/p/de... 010
Karl Horky @karlhorky.com · 12/08/2026new proof of concept script: diagnostics from Next.js TypeScript language service plugin on the command line 😍 (also in CI) like `astro check` or `vue-tsc` or `mdx-tsc` 220
Karl Horky @karlhorky.com · 10/08/2026another of my weird code review habits check PR changes (even for your PRs) - if not self-explanatory in PR context, make line comments on what/why benefits: 1. finds many logic errors + overengineering 2. returning to PRs later offers extra context both for AI and people 110
Karl Horky @karlhorky.com · 07/08/2026that kind of day ... where a React key warning in your app leads you to discover a bug in React 🤯 github.com/react/react/... 020
Karl Horky @karlhorky.com · 07/08/2026hmm, maybe someone has already explored first-party semantic diff drivers for Git? (per language and framework) has anyone seen anything like this? 010
Karl Horky @karlhorky.com · 07/08/2026I can follow, that they are different ASTs what do you mean to say with that? or did you not mean to draw any deeper conclusion? 100
Karl Horky @karlhorky.com · 07/08/2026Kind of related: Michael Montalbo has a recent Git RFC for external "hunk providers", eg. for tools like Difftastic 👀 This isn't about built-in 1st-party semantic diff drivers though lore.kernel.org/git/pull.212...lore.kernel.orgMaking sure you're not a bot! 110
Karl Horky @karlhorky.com · 07/08/2026Reported to Difftastic too github.com/Wilfred/diff...github.comTreat equivalent JSX whitespace expressions as unchanged · Issue #1026 · Wilfred/difftasticSomewhat related to #72 First of all, thanks for Difftastic! These foundational tools which reduce unnecessary work are invaluable, especially now with the high number of PRs created by AI agents. ... 110
Karl Horky @karlhorky.com · 07/08/2026Even with all of these new code review tools lately, we still have diffs like this on GitHub (even SemanticDiff can't ignore the {' '} diff) Wonder if these belong in Git as semantic diff drivers per language/framework 👀 so diffs everywhere can ignore these 🤔 450
Karl Horky @karlhorky.com · 05/08/2026Naming is hard So try to avoid naming things as much as possible - use existing names, from the language, framework, external APIs, etc One of my latest additions to AGENTS . md github.com/karlhorky/do... 000
Karl Horky @karlhorky.com · 03/08/2026Not yet, but we're a small team so it's easy to communicate this process Other things that can also help: - keep the PR as draft until there are real implementation commits and it's ready for review - organize your work so that you can quickly push a real commit (ideally amending the empty commit) 110
Karl Horky @karlhorky.com · 30/07/2026Example PR: github.com/upleveled/yo...github.comAdd endpoint sync with OpenAPI contract by karlhorky · Pull Request #2 · upleveled/youtube-private-invitationsDepends on PR #1 Manual sync in PR #1 lets channel owners paste add/remove invitees in YouTube Studio, so it works without a backend. Some teams already decide private-video invite changes outside ... 000
Karl Horky @karlhorky.com · 30/07/20263. AI and humans can quickly look up the spec / plan details in PRs and see them in the context of the repository history 100
Karl Horky @karlhorky.com · 30/07/2026Benefits: 1. Avoids the double work of creating the spec / plan and also the PR title and description (since you need the PR details anyway) 2. Keeps the spec / plan close to the proposed change (the PR), rather than in separate, disconnected specs/plans folder 100
Karl Horky @karlhorky.com · 30/07/2026Lightweight AI planning (avoiding a "plan" or "spec" which easily gets out of date): Start PRs with an empty commit + include all of the planned tasks in PR title and description (using checkboxes) Then keep this up to date and check off the points as you / AI implement github.com/karlhorky/do... 231
Reposted by Karl HorkyTypeScript @typescriptlang.org · 08/07/2026📣 The moment is here. 📣 TypeScript 7 is officially released! 7️⃣ devblogs.microsoft.com/typescript/a...devblogs.microsoft.comAnnouncing TypeScript 7.0 - TypeScriptToday we are proud to announce the availability of TypeScript 7, a 10x faster native port of TypeScript! Since its early days, TypeScript has promised to 15617157
Reposted by Karl HorkyNode.js @nodejs.org · 18/06/2026⚠️ Updates are now available for the 26.x, 24.x, 22.x Node.js release lines for the following issues. More information here: nodejs.org/en/blog/vulnerability/ju…nodejs.orgNode.js — Thursday, June 18, 2026 Security ReleasesNode.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts. 03710
Karl Horky @karlhorky.com · 17/06/2026My VS Code feature issue github.com/microsoft/vs...github.comSecurity: minimumReleaseAge setting for mitigating supply chain attacks on extensions · Issue #316867 · microsoft/vscodeIn the last years, supply chain attacks have increased dramatically. A few examples in the VS Code extension ecosystem: AI-Slop ransomware test sneaks on to VS Code marketplace - BleepingComputer M... 010
Karl Horky @karlhorky.com · 17/06/2026Security: VS Code 1.125 finally has a delay for auto-updates of extensions 👍 // Delay extension updates for 7 days "extensions.autoUpdateDelay": 168, Prompted by the recent security breaches and over 300 upvotes on my feature suggestion code.visualstudio.com/updates/v1_1... 111
Karl Horky @karlhorky.com · 17/06/2026And thanks to my co-MCs @jessiebellehooks.bsky.social @tolin.ski @w3cj.com for helping entertain 🙌 000
Karl Horky @karlhorky.com · 17/06/2026Thanks for letting me intro and grill you afterwards with questions too 😃 Noah Yamamoto, @paolo.ricciuti.me, @joyeecheung.bsky.social, @erickwendel.bsky.social, @tkdodo.eu, David Mark Clements 220
Karl Horky @karlhorky.com · 17/06/2026Had a great time MCing at @jsnation.gitnation.org 2026 in Amsterdam! Great to see all the friends and make new connections Thanks to the organizers at @gitnation.bsky.social , and everyone else who helped organize, spoke and otherwise joined the event! #JSNation 100
Reposted by Karl HorkyVite @vite.dev · 04/06/2026Today, VoidZero joins Cloudflare. Vite remains MIT, vendor-neutral, and stewarded by the same wider team. The same goes for Vitest, Rolldown, and Oxc. Cloudflare is also committing $1M to an OSS fund to support independent development in the Vite ecosystem.vite.devCloudflare supports Vite's missionThe VoidZero team is joining Cloudflare. Vite remains MIT, vendor-neutral and stewarded by the same wider team. 521238
Karl Horky @karlhorky.com · 02/06/2026Looking forward to MCing at JSNation Conf 2026 in Amsterdam next week 🚀 As a preview, here's multiple badly-generated AI photos of me on stage, which don't look like me at all hint: I like talking about AI slop / AI fails ✨ and how we can do better See you all there! 120
Reposted by Karl HorkyJiahan Chen @chenjiahan.bsky.social · 26/05/2026Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks? It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts. This is what happened in the recent Nx supply-chain compromise, which led to GitHub’s source code being leaked. 2347
Karl Horky @karlhorky.com · 19/05/2026Come and join us at Jetbrains for the next AmsterdamJS, with some TC39 members 🙌 080
Karl Horky @karlhorky.com · 17/05/2026VS Code extension Security: I proposed a setting in VS Code to limit extension installs to versions older than X days This is to mitigate supply chain attacks, similar to pnpm's minimumReleaseAge github.com/microsoft/vs... 1291
Karl Horky @karlhorky.com · 27/04/2026Great research into the changing team dynamics of AI, and how a lot of tools and processes are built for: 1. slow, pre-AI ways of collaboration 2. multiplying singular AI users and siloing the AI interactions, instead of making it team-first 040
Karl Horky @karlhorky.com · 16/04/2026VS Code: I suggested an "edit mode" for the integrated browser, for WYSWYG-style workflows of changing text copy If you also want this: it is a backlog candidate now, needs 20 👍 reactions to move it to backlog github.com/microsoft/vs... 140
Karl Horky @karlhorky.com · 06/04/2026Tomorrow: React Amsterdam ⚛️ April edition, at Picnic - Kirill Voloshin and Masoud Alali: Evolving the Picnic Page Platform with React Server Components - Leon Liefting: Building Flexible Breadcrumbs in Next.js With the App Router Hope to see you there! guild.host/events/react...guild.hostReact Amsterdam Meetup: React Server Components & more! | GuildApr 7th 6:30PM: Hey, React Amsterdam Community! We’re excited to kick off our next React meetup on April 7! Join us for an evening of practical insights, great conversations, and community vibes — fr... 020
Karl Horky @karlhorky.com · 31/03/2026To bundle all of your security settings, use "configurational dependencies": pnpm.io/config-depen... Also, you can set these globally for defense in depth of unconfigured projects: pnpm config set minimumReleaseAge 10080 --globalpnpm.ioConfig Dependencies | pnpmConfig dependencies allow you to share and centralize configuration files, settings, and hooks across multiple projects. They are installed before all regular dependencies ("dependencies", "devDepende... 010
Karl Horky @karlhorky.com · 31/03/2026Example pnpm-workspace.yaml config github.com/upleveled/es...github.com 130
Karl Horky @karlhorky.com · 31/03/2026The axios breach is a good opportunity to review your package manager settings I recommend pnpm @pnpm.io Default: postinstall scripts are blocked, protects against axios vector Also try: - minimumReleaseAge: 10080 (pkgs must be min 7 days old) - trustPolicy - blockExoticSubdeps 3100
Karl Horky @karlhorky.com · 21/01/2026Feb 5: Come and join our next React Amsterdam meetup 🚀 at Albert Heijn's AH Technology office in Zandaam Talks: - Releasing 20 Micro-Frontends in 1 Week With Module Federation by Gonzalo Beviglia - The Design System Journey by Gabriel Cardoso guild.host/events/react...guild.hostReact Amsterdam Meetup: The Design System Journey & more! | GuildFeb 5th 6:00PM: Hey, React Amsterdam Community! We’re kicking off 2026 with our first meetup on February 5. Join us to explore how to scale 010