Sign in

Maël Nison

@mael.dev
1K followers 149 following 311 posts

Arcanis on GitHub. Lead maintainer for @yarnpkg.dev 🧶 Staff DevX Mistral AI 🇪🇺 previously: Datadog, Meta, Sketchfab My life: my wife, two sons, two cats, and far too many side projects 📦

PostsRepliesMedia
Reposted by Maël Nison
Simon Boudrias @sboudrias.bsky.social · 04/08/2026
We deleted a year of AI context files—and our evals got better. On The AI Native Dev podcast, I share what changed as Datadog scaled AI coding tools to 1,000+ engineers. tessl.co/sb6 #AIagents #DevEx
011
Reposted by Maël Nison
Antoine du Hamel @aduh95.bsky.social · 25/06/2026
Node.js 26.4.0 is out with package map support! Full changelog and download links available at nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.4.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0141
Maël Nison @mael.dev · 12/06/2026
Experimental package map support has been merged ! Now on to implement generation support into both Yarn and pnpm 🚀
1240
Maël Nison @mael.dev · 25/05/2026
I'll be at #jsnation EU in Amsterdam on June 11 to talk about @yarnpkg.dev's Rust rewrite! Met amazing people every year, will anyone be there as well? @acemarke.dev @danielroe.dev @tkdodo.eu @nicr.dev maybe?
180
Reposted by Maël Nison
Yarn @yarnpkg.dev · 19/05/2026
We just released the 4.15 branch 🎊 One important change is that npmMinimalAgeGate will now default to 1d for new projects.
092
Maël Nison @mael.dev · 14/05/2026
Making `npmMinimalAgeGate: 1d` the default github.com/yarnpkg/berr...
github.com
Makes `npmMinimalAgeGate: 1d` the default by arcanis · Pull Request #7135 · yarnpkg/berry
What's the problem this PR addresses? The rate at which supply chain attacks occur is growing, and given that we can't rely on the npm registry for good practices it means we need to beco...
1225
Maël Nison @mael.dev · 13/05/2026
Let me tell you, "sustainability in OSS" is going to become a matter of mental health rather than money more than ever before. I fear the field will get toxic pretty fast as projects start competing entirely on social marketing antics 🫤
270
Reposted by Maël Nison
Yarn @yarnpkg.dev · 12/05/2026
Reminder that Yarn lets you filter out fresh packages with `npmMinimalAgeGate` and it's a good idea to use it on your work repos!
161
Maël Nison @mael.dev · 20/04/2026
I'll be speaking at #JSNation to tell you the story of how we ported Yarn to Rust over the past year, and what we learned doing that (A LOT 😁) Check out my #JSNation badge: gitnation.com/badges/jsnat.... Register via the badge and watch the stream for FREE! See you on June 11 & 15.
gitnation.com
Check out my badge & claim your free JSNation 2026 remote ticket!
Join 10k engineers worldwide at JSNation 2026 and meet 50 top speakers at June 11 - 15, 2026
051
Maël Nison @mael.dev · 17/04/2026
Is *anyone* using "Require branches to be up to date before merging" ? Always saw this setting as pretty harmful (N people update their branch in the hope to merge, only one can, all others wasted their CI time; rinse and repeat).
400
Reposted by Maël Nison
Yarn @yarnpkg.dev · 17/04/2026
We just released the 4.14 branch! 🎊 Two important security changes: - `enableScripts` now defaults to `false` (can be overridden on a per-package basis) - A new `approvedGitRepositories` setting should be used to tell Yarn which git repos are safe to pack.
1275
Maël Nison @mael.dev · 10/04/2026
I'm working on a feature called package maps for Node.js - it's leveraging everything I learned about package resolution these past six years, in a design that's both simple and flexible enough to be backward compatible with existing installs. I'm very excited about this! github.com/nodejs/node/...
github.com
loader: implement package maps by arcanis · Pull Request #62239 · nodejs/node
This PR adds a new --experimental-package-map=<path> flag letting Node.js resolve packages using a static JSON file instead of walking node_modules directories. node --experimental-package-ma...
13428
Maël Nison @mael.dev · 19/03/2026
It should go without saying: Yarn isn't and will never be a company. My vision of sustainable OSS has always been that not only should the tool be free, but its maintainers as well.
6230
Maël Nison @mael.dev · 03/03/2026
I got my kid interested in his first fantasy book! We read one chapter every day 🥰 www.goodreads.com/book/show/21... by @liliwilkinson.bsky.social
goodreads.com
Bravepaw and the Heartstone of Alluria (Bravepaw #1)
An epic Tail of Adventure! Can one gallant mouse find t…
2110
Maël Nison @mael.dev · 26/02/2026
Perhaps a silly question - are multi-tenancy OSes legacy at this point? It feels like every machine nowadays only ever use a single user (perhaps a second for root). As far as I understand it even cloud deployments went away from unix's multi-user towards virtualization.
070
Maël Nison @mael.dev · 24/02/2026
I'm implementing task management primitives into Yarn. I think tools like Turbo having to parse the lockfile is sign enough that they should be native features. Scripts have always been too limiting for local development.
060
Maël Nison @mael.dev · 20/02/2026
The state of GitHub's "Require status checks to pass before merging" section is incredible. Never saw what should be such a simple feature that simply couldn't work in two different companies. I get 500s just by searching for my jobs !
140
Maël Nison @mael.dev · 29/01/2026
I can now say it: Rust is really neat. I'm still on my learning journey, but I like many of its constructs. And I'm in love with pattern matching.
1170
Maël Nison @mael.dev · 28/01/2026
Noticed the amazing website? It's built with @astro.build from the ground up thanks to the help of the fine folks at luckymedia.dev, and the GLSL mad skills of shadertoy.com/user/Kali 😊
1120
Maël Nison @mael.dev · 28/01/2026
It’s happening. Yarn 6 Preview is here 💫 Yes, we rewrote it in Rust 🦀⚡️ I'm incredibly excited for the future of our beloved package manager. See the benchmarks and plans in our latest post:
yarn6.netlify.app
Yarn 6 Preview
Yarn is a modern JavaScript package manager focused on speed, security, and reliability.
712526
Maël Nison @mael.dev · 04/12/2025
Just left the theater - I found Zootopia a little lacking execution-wise, but overall I liked the universe enough that I could get past that and have a good time
030
Maël Nison @mael.dev · 24/11/2025
I joined a middle school that turned out to have a programming club (ie 2-3 pro-linux kids self-learning Dark Basic on the school computers during lunch break).
120
Maël Nison @mael.dev · 14/11/2025
I just realized it's the 10-years anniversary of my Secret Santa planner! I hope you'll find it useful this year as well 🎄☃️ mael.dev/secretsanta/
mael.dev
Secret Santa Planner - by mael.dev
Organize your Secret Santa gift exchange easily and securely. No accounts needed, no emails - just have fun!
351
Reposted by Maël Nison
Josh Goldberg @joshuakgoldberg.com · 30/10/2025
I am looking for a full-time job. Being independent in open source for 3.5+ years has been wonderful. I've gotten done most of the high-level goals I wanted to, and miss having people & structure around me. If you know of a role for a staff-level TypeScript+web developer, let me know! 🙂
1021378
Maël Nison @mael.dev · 27/10/2025
Those discussions about 'use workflow' remind me something!
110
Maël Nison @mael.dev · 18/10/2025
I started a new position at Mistral AI this week, still focused on developer experience. Interesting change of pace, going from a huge IPO'd company to a super fast growing startup on the rise! And a European one at that 🇪🇺🥳
5170
Maël Nison @mael.dev · 15/10/2025
It's baffling that GitHub still doesn't implement a neutral exit code. It used to be there! It was inherited from Azure Pipelines and they just ... removed it, with no replacement.
github.com
Add a way (command or step) to early-exit the job and set check conclusion · community · Discussion #82744
Select Topic Area Product Feedback Body Currently, to skip the rest of the steps during a job, an if condition has to be added to all of the steps or steps have to be moved to another job. It'd be ...
020
Maël Nison @mael.dev · 12/10/2025
Is that a surprise? The same can happen by having the LLM update the eslint configuration to add a malicious plugin. Due to how vscode works it'll be instantly evaluated.
embracethered.com
GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773) · Embrace The Red
An attacker can put GitHub Copilot into YOLO mode by modifying the project's settings.json file on the fly, and then executing commands, all without user approval
020
Maël Nison @mael.dev · 11/10/2025
I heard good things about Zed and Warp so I decided to try them, as I needed to reinstall a laptop anyway. So far they seem nice enough !
100
Reposted by Maël Nison
André Arko @indirect.io · 10/10/2025
Ruby Central said some really concerning things today. I don’t think they’re representing the situation accurately. andre.arko.net/2025/10/09/t...
andre.arko.net
The RubyGems “security incident”
Ruby Central posted an extremely concerning “Incident Response Timeline” today, in which they make a number of exaggerated or purely misleading claims. Here’s my effort to set the record straight. Fir...
719974
Maël Nison @mael.dev · 06/10/2025
An unfortunate oversight
The "Velo fall" meme. Frame 1: "Invent the exports field, block access to undeclared files"; frame 2: "No implicit access to package.json files"; frame 3: "Can't reliably know where packages are on disk anymore"
010
Reposted by Maël Nison
Yarn @yarnpkg.dev · 18/09/2025
Yarn 4.10 is fresh off the press! 💫 It includes a new npmMinimalAgeGate setting, catalog support, and OIDC publishing.
github.com
Release v4.10.0 · yarnpkg/berry
What's Changed Bumps TypeScript to 5.9 by @arcanis in #6889 Updates tests for the merge conflict resolution v5 by @arcanis in #6892 Tweaks tests by @arcanis in #6894 docs: fix typo in enableScript...
0168
Maël Nison @mael.dev · 16/09/2025
A good security aspect of my job lately has been that I spend significantly more time writing package managers than installing packages 😄
000
Maël Nison @mael.dev · 20/08/2025
Non-AI items on my GitHub wishlist: 🔍 GH Pages previews for PRs ⚠️ Status checks for issues 📝 Type hints in the viewer 🔗 GH first-parent iterator in the API Anything else I forget?
230
Reposted by Maël Nison
Jan Martin @hybrist.dev · 17/08/2025
Can’t wait for this to land: drafts.csswg.org/mediaqueries... (API for recording user preferences in a way that just works)
drafts.csswg.org
Media Queries Level 5
033
Maël Nison @mael.dev · 17/08/2025
Why is there no JS API that can flip prefers-color-scheme for the current page? Dark mode switches require adding custom selectors, which doesn't compose with third-party components.
140
Maël Nison @mael.dev · 17/08/2025
Mistral is very good at building interesting narratives; much better than ChatGPT it feels: chat.mistral.ai/chat/5110f7a...
chat.mistral.ai
Le Chat
Chat with Mistral AI's cutting edge language models.
010
Maël Nison @mael.dev · 09/08/2025
React 19 broke "click a component to open its source"; not sure the team is even aware? 😮 github.com/facebook/rea...
github.com
[React 19] Need Bring Back `_debugSource` or Provide an Equivalent for Better Developer Experience · Issue #32574 · facebook/react
Problem React 19 removed the _debugSource property from Fiber nodes (PR #28265), which has broken critical developer tools that enable "click to open the source from browser" functionality. This re...
041
Maël Nison @mael.dev · 08/08/2025
The more I see async iterators, the more I feel like they're a really fancy way to make a frustrating and painful API
051
Maël Nison @mael.dev · 31/07/2025
I've been hoping for this proposal for so long ❤️ github.com/tc39/proposa...
github.com
GitHub - tc39/proposal-import-bytes: A modest proposal for importing bytes in javascript
A modest proposal for importing bytes in javascript - tc39/proposal-import-bytes
000
Reposted by Maël Nison
Bruce Lawson @brucel.bsky.social · 24/07/2025
We need a European Sovereign Tech Fund github.blog/open-source/... "Open source software is critical infrastructure, but it’s underfunded. With a new feasibility study, GitHub’s developer policy team is building a coalition of policymakers and industry to close the maintenance funding gap."
github.blog
We need a European Sovereign Tech Fund
With a new feasibility study, GitHub’s developer policy team is building a coalition of policymakers and industry to close the maintenance funding gap.
086
Maël Nison @mael.dev · 20/07/2025
My opinions about an old license drama are subtly evolving
github.com
❌(REVERTED): Add text to MIT License banning ICE collaborators by jamiebuilds · Pull Request #1616 · lerna/lerna
The Lerna Core team has reverted this PR and revert information and response can be found in #1633 ============================================ In this PR, the following text has been added to the ...
100
Maël Nison @mael.dev · 12/07/2025
My wife gave me a birthday present and the kid inside me is screaming 😱
2130
Maël Nison @mael.dev · 20/06/2025
I'm thinking perhaps we could expose the `pnpapi` module to every install, whether PnP or not, so that 3rd-party tools could easily introspect the dependency tree without parsing the lockfile.
yarnpkg.com
PnP API | Yarn
In-depth documentation of the PnP API.
100
Maël Nison @mael.dev · 20/06/2025
Do you know any blind developers? What do they think about AI in their day-to-day work?
100
Maël Nison @mael.dev · 15/06/2025
Can you imagine the nerve? github.com/viperdavis/f...
github.com
Help needed: Seeking developers to launch a crypto project similar to our token faucet with subsequent deployment on a DEX · Issue #1 · viperdavis/faucet-token-help
Hi there, Hope all is well! Apologies for the unsolicited message, but we’re actively looking for a talented developer to implement a token distribution system similar to what we have on our websit...
140
Maël Nison @mael.dev · 13/06/2025
The GH API is simultaneously great and frustrating. It's mostly complete, but lacks a couple of fields for seemingly no particular reason (here, it's the job summary that's missing).
020
Reposted by Maël Nison
Maël Nison @mael.dev · 12/06/2025
Ah, seems to be because of Cloudflare (www.cloudflarestatus.com), which in turn might be because of GCP
cloudflarestatus.com
Cloudflare Status
Welcome to Cloudflare's home for real-time and historical data on system performance.
001
Maël Nison @mael.dev · 12/06/2025
Package manager summit with @kochan.io at #JSNation !
Me and Zoltan
1213
Maël Nison @mael.dev · 12/06/2025
@kochan.io's talk about configDependencies made me realize we forgot to document remote plugins on the Yarn website 🙈
021