Sign in

Matteo Collina

@nodeland.dev
4.6K followers 374 following 1.8K posts

Platformatic.dev Co-Founder & CTO, Node.js TSC member, Lead maintainer Fastify, Board OpenJS, Conference Speaker, Ph.D. Views are my own.

PostsRepliesMedia
Reposted by Matteo Collina
Nico Kaiser @nico.kaiser.me · 7h
📸 #NodeConfEU @nodeland.dev: Next-Gen Flame Graphs: Making Node.js Performance Profiling Actually Work
061
Matteo Collina @nodeland.dev · 29/09/2026
booking.com just cut compute costs on their biggest Node.js service by 38%. No new hardware. No code changes in the service. All of it from the platform layer. And the heart of it is @platformatic Watt. 🧵
booking.com
https://Booking.com
3185
Reposted by Matteo Collina
Ruy Adorno @ruyadorno.com · 29/09/2026
Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev
072
Matteo Collina @nodeland.dev · 29/09/2026
I would have never have expected @bengl.dev to put an AI slide on a talk 🤣❤️
030
Reposted by Matteo Collina
Nico Kaiser @nico.kaiser.me · 29/09/2026
📸 #NodeConfEU @nodeland.dev kicking off NodeConf EU 2026, Bologna, Italy.
0227
Matteo Collina @nodeland.dev · 29/09/2026
Do you know you can watch NodeConf live at live.nodeconf.eu ? Join now!
nodeconf.eu
NodeConf EU 2026 | Bologna, Italy
NodeConf EU 2026 returns to Bologna with tickets, venue info, and conference links in one fast single-page experience.
051
Matteo Collina @nodeland.dev · 28/09/2026
Nub's thread-pool PR has good bcrypt numbers for bumping the pool on the tested machines. But I disagree with auto-sizing it from CPU count. Before adding threads, we need to know what else is using the machine. 🧵
120
Matteo Collina @nodeland.dev · 25/09/2026
Durable workflows survive crashes, deploys, and sleep("7d"). But their journal lives in ONE place: a vendor's store, a cloud service, or your own database. Whoever runs that store has the only official copy. We call that role a landlord.
171
Matteo Collina @nodeland.dev · 21/09/2026
I’m starting to feel I need to write a npm client, in TypeScript, and optimize every part of Node.js that slow for it.
3280
Matteo Collina @nodeland.dev · 18/09/2026
Running JavaScript at runtime is everywhere now: AI-generated changes, user automation, plugins, programmable app parts. The problem is that a regular `eval()` inherits all the host's permissions. We built something to help.
2112
Matteo Collina @nodeland.dev · 17/09/2026
Last night I received "5" potential vulnerabilities. How many were actual vulnerabilities? 0. How many were bugs? 5. How many were from the same slop-bot? 5.
2210
Matteo Collina @nodeland.dev · 16/09/2026
I'm starting to wonder whether many of the old commercial models for Open Source are dead, thanks to AI. What's the point of open-sourcing innovation if anyone can copy/integrate it into a competing product in a day? There is no moat left in the implementation.
4192
Matteo Collina @nodeland.dev · 15/09/2026
According to most "AI" security researchers, EVERY bug is a vulnerability and should be assigned a CVE. Sigh.
2130
Matteo Collina @nodeland.dev · 14/09/2026
What if you could execute a @nodejs.org package without ever unzipping it? What if npm had no central server, just a peer-to-peer mesh with cryptographic integrity baked in?
121
Matteo Collina @nodeland.dev · 09/09/2026
Given we don’t write code anymore… why are we still dealing with TypeScript and transpilation? Models can write perfect JS in less tokens.
14121
Matteo Collina @nodeland.dev · 08/09/2026
Publishing a large monorepo of interdepent modules has become impossible with the new change on npm: the new scan thing delays every publishing substantially, and it does not recognize a batch. Maybe one should try doing a staged publishing and then do 15-20 clicks to approve them all?
382
Matteo Collina @nodeland.dev · 07/09/2026
Do you remember the time where we were all on online events? Is there still a point in hosting one (vs just putting videos on YT)?
100
Matteo Collina @nodeland.dev · 04/09/2026
As a coder, you need at least 2 AI providers in case one is offline. Use different models from those providers for different tasks.
121
Matteo Collina @nodeland.dev · 03/09/2026
🎟️ NodeConf EU 2026 is in Bologna in 3 weeks, and tickets are running low. Sep 29-30. The Savoia Regency, an 18th-century villa set in a 10,000m² park, 5km from the city center. Pool between sessions, Emilia-Romagna food, and two days of real Node.js depth.
1103
Reposted by Matteo Collina
snek @snek.dev · 01/09/2026
bit of an update, it's been a few months now since I parted ways with Deno, and I'm starting to actively look for jobs again! I'm pretty good with big systems, compilers, and embedded. especially if rust or elixir are involved :)
33811
Matteo Collina @nodeland.dev · 01/09/2026
I have 27 vulnerabilities to triage and 31 confirmed ones to publish a fix for. This is not really sustainable long-term. How can one fund all of this work?
1181
Matteo Collina @nodeland.dev · 28/08/2026
🔥 NEW BANTER: "Will AI kill the framework?" AI-generated code is fast and cheap. So the argument goes: why keep optimizing for everyone when you can generate code tailored to each workload? Some claim frameworks are outdated. The future is ad-hoc and disposable. @lucamaraschi and I push back 🧵👇
490
Reposted by Matteo Collina
Ryan Carniato @ryansolid.bsky.social · 19/08/2026
I know there has been a lot of talk about AI generated content the last few days. I wrote up my thoughts: dev.to/playfulprogr...
dev.to
My AI Content Journey
I apologize ahead of time, what follows has no tooling applied to it. No grammar checks, no AI, and...
4344
Matteo Collina @nodeland.dev · 20/08/2026
Thanks to AI, @supabase.com Storage hit a billion requests. Thanks to @platformatic.dev Watt they were able to 4x throughput on half the infrastructure. 🧵
1100
Reposted by Matteo Collina
James Sumners @james.sumners.info · 08/04/2026
I have debated releasing this for several days, but have ultimately decided that I'm okay with putting it out there. I have revised it to be a bit tamer, but 🤷‍♂️ Basically: stop treating open source as if it is a private org selling a product with a guarantee of safety. jrfom.com/posts/2026/0...
jrfom.com
Open Source & Security
There is a GitHub user (LLM?) that is reporting a lot of “security vulnerabilities” as open issues. They are mostly trash reports (e.g. “if you pass Object.prototype to the setFooOnObject function, it...
1102
Matteo Collina @nodeland.dev · 19/08/2026
I flipped one flag in node-postgres and simple SELECT 1 went from ~10k to ~25k queries per second. That is 2.35x throughput, and it cost me one line of code.
260
Matteo Collina @nodeland.dev · 13/08/2026
I've just used DeepSeek v4 Flash 0731 running on my DGX Spark to find 4 vulnerabilities. Sigh.
110
Reposted by Matteo Collina
Kate Holterhoff, PhD @kateholterhoff.com · 12/08/2026
Look who’s visiting ATL 🍑 all the way from Italy 🇮🇹!! It’s @nodeland.dev, here at the @nodejs.org Interactive discussing the new release schedule for node #NodeJSInteractive
061
Reposted by Matteo Collina
Faris Aziz @farisaziz.com · 12/08/2026
@nodeland.dev doing his thing
0121
Matteo Collina @nodeland.dev · 12/08/2026
The story of OSS CI is one of a pioneer, an acquisition, and a platform stepping up. It starts with Travis. 🧵
220
Matteo Collina @nodeland.dev · 11/08/2026
I triage 20-40 security vulnerability reports a week. Almost all of them are now AI-written. And we usually get 3-5 duplicates of each one. That's the new reality of being a maintainer. 🧵
2112
Matteo Collina @nodeland.dev · 11/08/2026
On my way to Atlanta for Render..!
1180
Matteo Collina @nodeland.dev · 10/08/2026
Who is still using the domain module? We are planning to runtime deprecate it in @nodejs.org v27.
github.com
domain: runtime-deprecate the module by mcollina · Pull Request #65074 · nodejs/node
Promote DEP0032 (node:domain module) from a documentation-only deprecation to a runtime deprecation. Fixes #10843
4135
Matteo Collina @nodeland.dev · 07/08/2026
The superpower AI gives us is to triage/prepare a spec document and have it challenged until all inconsistencies are found... before actually doing it.
161
Matteo Collina @nodeland.dev · 06/08/2026
Something that puzzles me all the time is how node core collaborators can complain if commits should or should not be squashed during review. You ask two people, and you get two different answer as it really depends on how one’s brain work. Be patient folks!
130
Matteo Collina @nodeland.dev · 05/08/2026
🔥 NEW BANTER: "Should You Block the Event Loop?" Day one of Node.js, you learn one rule: never block the event loop. A customer brought us a compression problem that turned that rule on its head. Async didn't just lose. It took the app down. Luca and I go through it. 📅 Aug 12th
120
Reposted by Matteo Collina
Peter van der Zee @pvdz.ee · 05/08/2026
Must ... refrain... from logging in... during holiday... one more day. Good luck to anyone in/affected 🫂
062
Matteo Collina @nodeland.dev · 04/08/2026
Congratulations for the launch!!! 🚀
081
Matteo Collina @nodeland.dev · 04/08/2026
Every recursive algorithm can be exploited to cause a crash in most languages. Prefer iteration whenever possible.
182
Matteo Collina @nodeland.dev · 03/08/2026
🔥 NEW BANTER: "Nitro Builds the Server. Who Runs the Fleet?" Nitro gives you a clean, portable server. Consistent builds. Familiar routing. Great DX. Then you scale to five instances with a cron job and nobody is in charge. Luca, Paolo and I dig into @platformatic/nitro. 📅 Aug 5th
100
Matteo Collina @nodeland.dev · 31/07/2026
I genuinely hate CSRF vulnerabilities. Fixing them always is at odd with developer experience.
160
Matteo Collina @nodeland.dev · 30/07/2026
I'm relatively surprised by how hard it is to operate HTTP/2 at scale. So many pitfalls for so little benefit. Today I stumbled on a fancy bug. github.com/haproxy/hapr...
github.com
HTTP/2 client streams silently aborted when reused backend connection is closed by server (no access log entry) · Issue #3414 · haproxy/haproxy
Detailed Description of the Problem When a haproxy instance serves clients over HTTP/2 and uses the default http-reuse safe backend connection pool, a fraction of client requests end with the clien...
230
Matteo Collina @nodeland.dev · 29/07/2026
State machines: let's teach LLMs to use state machines. LLMs, like humans, forget the "refactoring" step of TDD.
110
Reposted by Matteo Collina
naugtur @naugtur.pl · 29/07/2026
I wrote this bit on preventing prototype pollution dev.to/naugtur/but-... in response to @nodeland.dev 's recent post where he claimed we can't. It's all about pronouns. 😜
dev.to
But _We_ Can Harden Node.js Against Prototype Pollution
This is a response to a post by Matteo Collina Define We Matteo's post argues that...
052
Matteo Collina @nodeland.dev · 29/07/2026
Undici security release is out: v8.9.0, v7.29.0 and v6.28.0. Five advisories, one high severity and four medium. If you use Undici directly or through fetch() in Node.js, upgrade. npm i undici@^8.9.0 (or ^7.29.0 / ^6.28.0) github.com/nodejs/undic...
132
Matteo Collina @nodeland.dev · 29/07/2026
What do you all think of NPM adding scanning of all packages during publish- a 15-minute delay during peak times? What concerns me the most is: 1. false positives 2. the SLA for the "appeal process" Anyway, good step! github.blog/changelog/20...
github.blog
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
12224
Matteo Collina @nodeland.dev · 28/07/2026
🔥 NEW BANTER: "Your Bug Fix Will Never Reach the Runs That Need It" You find a critical bug. You fix it. You deploy. Meanwhile the 30-day subscription cycles, the compliance timers, the approvals waiting on a signature are all still running the broken workflow version. They never get your fix.
100
Matteo Collina @nodeland.dev · 28/07/2026
I’m developing a new product (more on that later on). I’m doing it pairing it with Fable and GPT-Sol. I made some glorious mistakes in the design. I would never have caught them without a deep code review.
070
Matteo Collina @nodeland.dev · 27/07/2026
An OSS maintainer wakes up knowing they will have more potential security vulnerabilities to triage. The work never ends.
031
Matteo Collina @nodeland.dev · 27/07/2026
I'm in London for the next two weeks! Yay!
130