Sign in

literat

@literat.dev
20 followers 32 following 21 posts

FullStack Pirate 🏴‍☠️ ❯ JS ⚛️ Node 🐘 ❯ Building Frontend Community @ almacareer.com ❯ Whitewater Kayaker ❯ Scout member ⚜️ 🏕️ ❯ ♥️ 📸 ❯ 📝 literat.dev

PostsRepliesMedia
literat @literat.dev · 30/09/2026
You can get rid of some popular dependencies like chalk, dotenv, axios, or nodemon, and more, because the functionality is already shipped in Node.js. More in the article 👇 flaviocopes.com/node-builtins/
flaviocopes.com
Node.js built-ins that replaced npm packages
Twelve Node.js built-ins that replace axios, nodemon, dotenv, jest, chalk, glob and more, with their stability in Node 24 and one gotcha each.
001
literat @literat.dev · 31/08/2026
While everyone at tech conferences is talking about AI, I'll be talking about... sandworms. 🪱 On Oct 6 at @frontkon, I'm diving into DevSecOps, Supply-Chain attacks, and Dune. What hides beneath your node_modules? Let’s talk security. 🎟️ Info & tickets below!👇 #devsecops #frontkon
100
literat @literat.dev · 19/08/2026
Repeating the basics is gold. So, creating prop exclusivity in TypeScript, e.g., `aria-label` vs `aria-labeledby` using a discriminated union type or with the use of `never`. www.nickyt.co/blog/typescr...
nickyt.co
TypeScript and React: Enforcing Props for Accessibility | Nick Taylor
Recently, I added a small accessibility win to our code base. fix:...
010
literat @literat.dev · 04/06/2026
@webexpo.bsky.social is the one conference where I come for the people and stay for the talks. Design systems, accessibility, AI, architecture, and yes, a drone controlled by a banana. Took notes on what was worth sharing. 👇 literat.dev/blog/2026-05...
literat.dev
Notes from WebExpo 2026 conference
WebExpo 2026 wrapped up and I survived with a notebook full of opinions. Most confirmed what we already know, a few challenged it. Here is what was worth the trip.
230
literat @literat.dev · 20/05/2026
🎤 Spoke at #CodeCon in Bratislava about npm supply chain security - a topic close to me after going through an attack firsthand. Most of these attacks are preventable: 🔒 Disable postinstall scripts ⏳ Use cooldown periods 🤖 Automate dependency updates 📊 talk-npm-security-best-practice.netlify.app
000
literat @literat.dev · 25/02/2026
Already on stage 6. Hands management fails on stage 7. Trying to get to stage 8 soon :D justin.abrah.ms/blog/2026-01... #ai #agents #conding #development
justin.abrah.ms
Yegge's Developer-Agent Evolution Model
An 8-stage model describing how developers evolve from skeptical AI-assisted coding to orchestrating fleets of autonomous agents.
000
literat @literat.dev · 20/02/2026
TIL 💡 You can display an uploaded file (like the one from the input type="file") using blob URLs, even before submitting the form. No need for base64. Just a simple blob. 👉 developer.mozilla.org/en-US/docs/W... 👉 developer.mozilla.org/en-US/docs/W... And yeah, it is 10 years old API 🤦‍♂️ #developers
developer.mozilla.org
blob: URLs - URIs | MDN
Blob (or object) URLs, URLs prefixed with the blob: scheme, enable integration of Blobs and MediaSources with other APIs that are only designed to be used with URLs, such as the <img> element. Blob UR...
000
literat @literat.dev · 13/02/2026
AI conversations are loud. “Let models build everything.” In Spirit Design System we focus on practical AI: 👉 Figma → production code 👉 outputs → real components 👉 less repetitive work Figma Code Connect + MCP + Agent Skills = faster frontend workflows #AI #DesignSystem #Frontend
120
literat @literat.dev · 02/12/2025
🔐 npm supply chain attacks hit 180+ packages this year. Here's what works to protect your projects: Quick wins: ✓ Disable postinstall scripts ✓ Use cooldown period ✓ Immutable lockfiles ✓ 2FA on npm Full security guide with code examples 👇 literat.dev/blog/2025-12... #DevSec #JavaScript #npm
literat.dev
Safe navigation through upgrades in npm package minefield
Learn essential security practices to protect your projects from npm supply chain attacks. Discover how to safely manage dependencies, prevent malicious code execution, and strengthen your development...
020
literat @literat.dev · 14/11/2025
Gave a talk at Frontendisti meetup in Prague (Café Lajka) on recent npm supply chain attacks — how they work and how to defend against them. You can check the slides here: talk-npm-security-best-practice.netlify.app #JavaScript #Security #npm #WebDev #SupplyChainSecurity
120
literat @literat.dev · 05/11/2025
#TIL The “You Don’t Need” series is a great reminder of how far JavaScript has come. Example: you don’t need Lodash anymore. Modern JS has built-ins for most of it, and es-toolkit.dev gives you the rest - smaller, faster, typed, maintained. 📚 github.com/you-dont-need #JavaScript #WebDev #Frontend
github.com
You Don't Need
People choose popular projects, often not because it applies to their problems. - You Don't Need
010
literat @literat.dev · 04/11/2025
The Design Tokens spec just went stable 🎉 A huge step for design systems: • real theming support • modern color spaces (Display P3, OKLCH) • cross-tool + cross-platform format Feels like the “CSS moment” for tokens. 👉 www.w3.org/community/de... #DesignTokens #DesignSystems #WebDev #UXEngineering
w3.org
Design Tokens specification reaches first stable version | Design Tokens Community Group
010
literat @literat.dev · 29/07/2025
Hey, want to discover bright new HTML features in one place? Just fill out the recently opened State of HTML 2025 survey. 👉 survey.devographics.com/en-US/survey... What have I discovered? 🧵 #html #web #development #survey
survey.devographics.com
State of HTML 2025
Take the State of HTML survey
100
literat @literat.dev · 20/07/2025
#eslint and #prettier users, beware! There has been a phishing attack on a few packages. 👇 👉 socket.dev/blog/npm-phi... 👉 thehackernews.com/2025/07/malw... 👉 github.com/advisories/G... #javascript #npm #developers #web
socket.dev
020
literat @literat.dev · 07/07/2025
💡 TIL: Using `tsc --traceResolution` is very handy to get information about why the heck TypeScript is raising an error about the file that should not be part of the library, but it is included during the type check 😅 #typescript #error #web #dev #todayilearn #til
020
literat @literat.dev · 23/04/2025
www.youtube.com/watch?v=duty...
youtube.com
VS Code Agent Mode Just Changed Everything
YouTube video by Visual Studio Code
000
literat @literat.dev · 25/02/2025
Interested in future results of the new State of AI in web development. In spite of using AI tooling for my day-to-day job, I think it will take a long journey to help me with all the obstacles during #design #development #deployment 🤔 So take the survey :-) survey.devographics.com/en-US/survey...
survey.devographics.com
State of AI 2025
Take the State of AI survey
000
Reposted by literat
Deno @deno.land · 04/02/2025
Oracle justified its JavaScript trademark by claiming Node.js — now it wants that ignored #FreeJavaScript deno.com/blog/deno-v-...
deno.com
Oracle justified its JavaScript trademark with Node.js—now it wants that ignored
Oracle filed a motion to dismiss in response to Deno’s petition to cancel its “JavaScript” trademark. But instead of addressing the real issue—that JavaScript is an open standard with multiple indepen...
16308121
Reposted by literat
Wes Bos @wesbos.com · 28/01/2025
This is SUCH a good video from CJ, and the most impressive part is that he made all these video graphics in the browser 🤯 www.youtube.com/watch?v=NBDn...
3775
literat @literat.dev · 06/01/2025
Dive into my latest article and take control of your npm scripts! Master best practices: 🛠️ consistent naming 🛠️ organized namespaces 🛠️ tools like npm-run-all 🛠️ clear lifecycle hooks #webdev #coding #bestpractice #npm #javascript literat.dev/blog/2024-12...
literat.dev
Mastering npm scripts: Best practices in sustainable naming and organizing of your scripts
The chaotic organization of npm scripts can slow down project development considerably. I will present a system for efficient naming and organization of npm scripts. You will learn how to use naming c...
010
Reposted by literat
Sunil Pai @threepointone.bsky.social · 06/12/2024
my favourite and most underrated javascript feature is the void operator new killer usecase: using it for react 19 refs to prevent returning a non-function <div ref={current => void (instance = current)} /> (re: react.dev/blog/2024/12...) developer.mozilla.org/en-US/docs/W...
developer.mozilla.org
void operator - JavaScript | MDN
The void operator evaluates the given expression and then returns undefined.
10643