Sign in

Lovell Fuller

@lovell.info
84 followers 80 following 13 posts

Open source software maintainer, product developer and Internet technologist London, UK lovell.info

PostsRepliesMedia
Lovell Fuller @lovell.info · 09/09/2026
It's been 10 years since British font designer Vernon Adams died aged only 49 He created many fonts that you see every day on the web, in print and on signs above shops fonts.adobe.com/designers/ve... Also one of the few people with a dedicated search result page www.google.com/search?q=ver...
fonts.adobe.com
Vernon Adams | Adobe Fonts
020
Lovell Fuller @lovell.info · 24/08/2026
Luckily OS-level package managers on most Linux distributions provide Position Independent Executables and therefore allow Address Space Layout Randomisation (ASLR). If you're unsure, run "file $(which node)" at the Linux command line and look for a tasty "pie executable" in the output.
010
Lovell Fuller @lovell.info · 24/08/2026
If you're exposing Node.js services running on Linux to the public Internet, you may be surprised to learn that the official binaries and Docker images are *not* Position Independent. This prevents use of OS security features that would otherwise protect against some memory-related exploits.
github.com
ASLR (pie) disabled in v12 Linux amd64 build from nodejs.org · Issue #33425 · nodejs/node
$ pwn checksec ./node/node-v12.16.3-linux-x64/bin/node [*] '/home/pdxjohnny/Downloads/node/node-v12.16.3-linux-x64/bin/node' Arch: amd64-64-little RELRO: Full RELRO Stack: Canary found NX: NX enabl...
110
Lovell Fuller @lovell.info · 30/07/2026
I spoke with one of the maintainers and they are waiting for GitHub to reinstate the org as it has been erroneously suspended.
130
Lovell Fuller @lovell.info · 27/07/2026
All budget airlines I've used auto-assign a seat for under 12s next to an adult on the same booking without extra charge (I think it might even be the law in some countries). But of course they won't tell you that during the ̶u̶p̶s̶e̶l̶l̶ booking process.
010
Lovell Fuller @lovell.info · 24/07/2026
Ouch, right on the line between satire and reality, thank you for labelling it as the former 😅
010
Lovell Fuller @lovell.info · 24/07/2026
Big news for Wordpress users as client-side media processing will be part of the forthcoming 7.1 release. make.wordpress.org/core/2026/07... A huge round of applause is due to @kleisauke.nl and @vanilagy.bsky.social for all their work creating and maintaining wasm-vips and mediabunny respectively.
make.wordpress.org
Client-Side Media Processing in WordPress 7.1
WordPress 7.1 ships client-side media processing – a capability that handles image compression, resizing, format conversion, rotation, and thumbnail generation directly in the user’s br…
032
Lovell Fuller @lovell.info · 22/07/2026
This is my kind of crossover event. Chicago deep house legend @joshuaiz.com of Iz and Diz fame DJing at a tech/atproto meetup in a brewery. London can learn from this.
031
Lovell Fuller @lovell.info · 20/07/2026
If you use Node.js native modules that pass JavaScript strings to C++ or Rust code, which is most of them, then Node.js 26 does this around 4x faster than Node.js 24. github.com/nodejs/node/...
github.com
Investigating a Severe Performance Regression in Node.js v22 and v24 · Issue #60719 · nodejs/node
Investigating a Severe Performance Regression in Node.js v22 and v24 Hello everyone, We (@forwardemail) have been running some benchmarks with better-sqlite3-multiple-ciphers and came across what a...
011
Lovell Fuller @lovell.info · 17/07/2026
We've just published advisories for a number of libvips vulnerabilities that affect the prebuilt binaries provided by versions of sharp <= 0.34.5 If you use sharp with untrusted input, please upgrade to the latest version, currently 0.35.3, which provides libvips 8.18.3 github.com/lovell/sharp...
github.com
Vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
### Impact A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency. Those processing untrusted input with ver...
021
Lovell Fuller @lovell.info · 16/07/2026
Renewed my #DHFC season ticket. Proper football starts again in 3 weeks.
000
Lovell Fuller @lovell.info · 02/07/2026
Yes, @florian-lefebvre.dev has been working on this, please see github.com/lovell/sharp...
github.com
ESM-only · Issue #4539 · lovell/sharp
Feature request What are you trying to achieve? Reduce the package size by switching to ESM-only. When you searched for similar feature requests, what did you find that might be related? Followup t...
031
Lovell Fuller @lovell.info · 02/07/2026
Latest version of sharp (for Node.js image processing): 📦 Faster and safer installation, no more install scripts 🙌 Dual ESM/CJS 🖼️ Improved AVIF output quality and bit depth ☀️ Experimental support for HDR gain maps 👷 Transferable ArrayBuffer output for worker threads www.npmjs.com/package/sharp
npmjs.com
3244