Sign in

Wes

@notwes.bsky.social
3K followers 716 following 5.7K posts

ATX - he/him - 🥂Humans are more important than code - I work at an entertainment company and volunteer my time making art on github github.com/wesleytodd

PostsRepliesMedia
Reposted by Wes
NodeConf.eu @nodeconf.eu · 3h
Thank you everyone for joining us at #NodeConfEU 2026! 💚 We hope you enjoyed it as much as we did, and we can’t wait to see you again next year! 📅👩‍💻 #TechCommunity #NodeCommunity
0104
Wes @notwes.bsky.social · 3h
@nodeconf.eu was a great success. Incredible talks and conversations. Now we drink wine, eat pizza, and collaborate on @nodejs.org things tomorrow.
051
Reposted by Wes
Ruy Adorno @ruyadorno.com · 9h
Starting the second day of @nodeconf.eu in the hallway track with @pipobscure.com @notwes.bsky.social and @joesepi.com #NodeConfEU
picture with friends at NodeConfEU
072
Reposted by Wes
James Snell @jasnell.me · 29/09/2026
If you're having some FOMO for @nodeconf.eu ... You can watch online! live.nodeconf.eu
live.nodeconf.eu
NodeConf EU 2026 Live | Bologna, Italy
Watch NodeConf EU 2026 live from Bologna on 29-30 September.
275
Reposted by Wes
Nico Kaiser @nico.kaiser.me · 29/09/2026
📸 #NodeConfEU Robert Nagy: NodeJS Performance Tips & Tricks
072
Reposted by Wes
Ruy Adorno @ruyadorno.com · 29/09/2026
Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev
082
Reposted by Wes
Nico Kaiser @nico.kaiser.me · 29/09/2026
📸 #NodeConfEU @nodeland.dev kicking off NodeConf EU 2026, Bologna, Italy.
0227
Wes @notwes.bsky.social · 29/09/2026
This!! The web apis are often designed for browsers and are not great for server and tooling use cases.
Where node.js’ approach is better, it’s ok to ignore web api
270
Wes @notwes.bsky.social · 29/09/2026
@sheplu.bsky.social, our pic with @naugtur.pl the napkin hats made an appearance. I couldn’t get my phone out in time to get a picture of the slide. Wish you were here.
150
Wes @notwes.bsky.social · 29/09/2026
@nodeconf.eu today!!
1123
Wes @notwes.bsky.social · 27/09/2026
Hey Vienna, what’s happening tonight?
120
Wes @notwes.bsky.social · 22/09/2026
www.npmjs.com/package/engl... 200k weekly downloads starting earlier this year. Who knew an array of the english days of the week would be so popular?
npmjs.com
150
Wes @notwes.bsky.social · 16/09/2026
Sad that I will have to be suspicious of the people who tell me I look just like Ed Sheeran and how the love him. No I don’t have red hair. Yes this has happened to me more than a few times.
030
Reposted by Wes
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚨 High-severity security fix in compression@1.8.2 just released! Patches CVE-2026-87776: compression vulnerable to Denial of Service via memory leak on premature response close github.com/expressjs/co...
github.com
compression vulnerable to Denial of Service via memory leak on premature response close
### Impact A vulnerability in compression `< 1.8.2` allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the...
021
Reposted by Wes
James Snell @jasnell.me · 10/09/2026
... Open source communities have been built on the assumption that contribution is personal and difficult. That there's a high bar that limits volume. We don't have the tools in place for anything other than that...
141
Reposted by Wes
Kamil Dzieniszewski @dzienisz.bsky.social · 03/09/2026
meet.js x Netflix Poland Warsaw thank you for hosting our event @naugtur.pl @notwes.bsky.social @dominykas.social
042
Wes @notwes.bsky.social · 24/08/2026
Pretty sure the folks who need to hear this are not in the audience, but in case you have a special someone who needs to hear it: sophiebits.com/2026/06/25/t... Particularly of interest is: "Writing is thinking." Don't get caught showing how thoughtless you are by posting slop.
sophiebits.com
There are no lossless transformations of natural-language text
160
Wes @notwes.bsky.social · 24/08/2026
Got my ticket last week, now I need to figure out how I am getting there 🤣
340
Wes @notwes.bsky.social · 24/08/2026
I'll be speaking about Supply Chain Security with @naugtur.pl at the meet.js x Netflix meetup on September 3rd! Excited to meet the JavaScript community at our Warsaw office.
See you soon, meet.js Warsaw! Wes Todd - Software Engineer 5. Netflix.
2101
Wes @notwes.bsky.social · 20/08/2026
omg....claude just suggested the title "Two Doors, One Supply Chain" for an upcoming talk and I am dying.
3110
Reposted by Wes
vlt /vōlt/ @vlt.io · 19/08/2026
vlt v1.03 dropped with faster installs at every layer. 158x faster packument generation. A warm cache that skips the network entirely on your second install. Tarball extraction, parallelized. github.com/vltpkg/vltpk...
022
Wes @notwes.bsky.social · 14/08/2026
I am a big fan of building *on* existing systems over *replacing* them. I am still processing some of the stuff on semver.xyz, but I am a HUGE fan of the @vlt.io team's *approach* to engineering the future of package management.
semver.xyz
semver.xyz — Semantic Versions
A modern versioning spec: restores build precedence and formally defines sets, ranges and comparators. Test the range grammar in your browser.
163
Reposted by Wes
Socket @socket.dev · 07/08/2026
Maintaining critical software now comes with a security burden that has outgrown what any volunteer can reasonably carry. That's why we're upgrading our open source program from the Team plan to the Business plan, full protection for maintainers at no cost. socket.dev/blog/free-bu...
socket.dev
Free Business Plan Upgrades for Open Source Maintainers - So...
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
04711
Wes @notwes.bsky.social · 13/08/2026
Glad to see 2FA being a requirement on more and more of these critical workflows. If you were in any of these conversations you know that was my *highest priority ask*.
000
Reposted by Wes
Philipp Dunkel @pipobscure.com · 10/08/2026
I have made a starter pack with all (the ones in the atmosphere) the people bringing you NodeConf.eu go.bsky.app/CFiVdYA
083
Reposted by Wes
Matteo Collina @nodeland.dev · 10/08/2026
Who is still using the domain module? We are planning to runtime deprecate it in @nodejs.org v27.
github.com
domain: runtime-deprecate the module by mcollina · Pull Request #65074 · nodejs/node
Promote DEP0032 (node:domain module) from a documentation-only deprecation to a runtime deprecation. Fixes #10843
4135
Reposted by Wes
Ethan Arrowood @arrowood.dev · 10/08/2026
@harper.fast is hosting the @renderatl.com @openjsf.org @nodejs.org Code and Learn workshop on 8/13 from 2-5pm. Learn how to make your first contribution to Node.js, no prior experience required! Join the "nodejs-interactive-code-and-learn" channel in the Render discord for more info. 🚀🐢
"Node.js Interactive Code and Learn"
"RenderATL - August 12-13, 2026 - Atlanta, Georgia"
Logos: Node.js, OpenJS Foundation, Harper, RenderATL
062
Wes @notwes.bsky.social · 07/08/2026
Am I the only one who walks right in front of Waymo’s when it is unclear if I really had to ight of way (pretty sure I always do as a reasonable pedestrian)? They pretty much have to stop, and if they don’t…maybe I win a big lawsuit 🤣
220
Wes @notwes.bsky.social · 06/08/2026
I have regularly thought about this as a millennial. I feel like our gen is heavily impacted by the "we know what we lost" mentality and it makes sense that GenZ would feel like they missed even that last sliver of "before".
110
Reposted by Wes
vlt /vōlt/ @vlt.io · 06/08/2026
You can't improve what you don't measure. And measure, we do. 😉 A clean install runs up to 38% faster than npm, no change to your tooling required.
131
Wes @notwes.bsky.social · 04/08/2026
Lost my ~260 day streak on chess.com today. Silly things like “work” cost me my dream of playing one game a day for a year and not getting any better.
3160
Reposted by Wes
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
Wes @notwes.bsky.social · 03/08/2026
While I have spent the past 5 years doing the RV each summer, this was the first one that actually felt like a "summer vacation". - 2w off, sailing on Monterey Bay, campfires, Big Sur - 1w in the office - 1w at a work offsite - Golf trip with friends in MI - 1w doing RV repairs/clean & getting home
110
Reposted by Wes
vlt /vōlt/ @vlt.io · 16/07/2026
There is CSS... but what if I told you there is such a thing as DSS? Dependency Selector Syntax is an expressive DSL written as a homage to CSS. Use it to inspect malicious dependencies in your repo docs.vlt.io/cli/selector...
1103
Reposted by Wes
danielroe @danielroe.dev · 03/07/2026
it's time
a screenshot of a bluesky moderation list

title: people (I like) who write with Ilms

description:

for people who use Ilms to write articles or post on bluesky

this list exists so I can mute them + use an Ilm to summarise their writing instead

please let me know if you ever stop 🙏

> I'm so tired of being expected to read things that no one has bothered to write.
> https://bsky.app/profile/cassiecodes.bsky.social/post/3mmradnzj2s2n
1117511
Reposted by Wes
tierney cyren @bnb.im · 04/07/2026
it is incredibly stupid to generate blog posts with llms anyone can output the same thing with the same prompts. If they’re interested in reading that, let them write the prompts. if it’s a writing skill issue on your end… failing at writing is how you get better at writing.
2524
Wes @notwes.bsky.social · 02/07/2026
Summer vacation in full swing. Wine, fire, and a show.
Wine in a green cup with “ex”, a campfire, and a show.
1110
Wes @notwes.bsky.social · 30/06/2026
Had a great time sailing on Monterey Bay this morning. First time sailing on the open ocean, it was awesome. Highly recommend.
090
Wes @notwes.bsky.social · 27/06/2026
I’m in a Waymo right now, my second of the week, Waymo’s have the exact same problem that AI does. It means I don’t get to interact with any other humans. It’s isolating and lonely and worse for humanity.
3201
Wes @notwes.bsky.social · 26/06/2026
I mean it was last year when I last saw you @pfrazee.com, but I did not expect that amazingly beautiful beard in such a short time 🤣
010
Wes @notwes.bsky.social · 25/06/2026
I bought two computers last year because I was nearly positive this would happen. A mac and a razer. Glad but not happy I was right.
131
Reposted by Wes
Matteo Collina @nodeland.dev · 23/06/2026
📢 CFP EXTENDED: NodeConf EU 2026 — Bologna, Italy We pushed the Call for Papers deadline to **June 30th**. One more week to send your talk. Node.js maintainers, production engineers, runtime nerds, tooling builders => we want your session.
1117
Wes @notwes.bsky.social · 22/06/2026
It's Monday, I am very busy, but.... All I want to know when the final patch for @factorio.com comes out. I should focus on the stuff I am supposed to be doing, but its supposed to be some time this week so.....when is it?
110
Wes @notwes.bsky.social · 22/06/2026
Always glad to see folks talk about the main reason I find this new world we have created so distasteful. Call me crazy, but I think we *can* care about the human impact and also have new technologies.
1401
Reposted by Wes
Ulises Gascón @ulisesgascon.com · 20/06/2026
🔐 A thing many people miss: Node.js trusts the code you install by default. So blocking npm install scripts closes one door and leaves another wide open, the one that opens when you require() the package. nodesource.com/blog/npm-v12...
nodesource.com
Blocking Install Scripts Is Not a Silver Bullet
npm v12 blocks install scripts by default, but supply chain attacks won't disappear. Learn why runtime execution, the Node.js permission model, and sandboxing still matter.
3165
Wes @notwes.bsky.social · 18/06/2026
Heat index of 113f today. Not ideal.
010
Reposted by Wes
Zach Leatherman @zachleat.com · 17/06/2026
Upcoming npm v12 will disable preinstall, install, and postinstall scripts from dependencies unless allow-listed. You can prepare for this change using npm v11 now: github.com/orgs/communi...
github.com
Preparing for npm v12: install scripts and non-registry sources become opt-in · community · Discussion #198547
Hi everyone — sharing this so maintainers, application developers, and CI operators have time to prepare for behavioral changes landing in npm v12 (estimated July 2026). Everything below is already...
1198
Wes @notwes.bsky.social · 18/06/2026
Another good read from @andrewnez.mastodon.social.ap.brid.gy
000
Wes @notwes.bsky.social · 17/06/2026
explain your @ I am (not) Wes. Wes is really my middle name. And somehow despite being an elder and getting my invite directly from @pfrazee.com, there is an inactive but more elder @wes.bsky.social. Such a waste of the @.
2110
Reposted by Wes
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 17/06/2026
RE: mastodon.social/@campuscodi/1167567… I’m not surprised that SBOM adoption is so low, almost all the efforts around SBOMs have been compliance theatre, not actually tackling the hard work of working out which software is being packaged. There’s also zero incentives for […]
mastodon.social
Original post on mastodon.social
217