Sign in

Philippe Serhal

@philippeserhal.com
888 followers 1.3K following 470 posts

💼 Staff Engineer @netlify.com, integrating all the frameworks 🔨 Open source maintainer @npmx.dev 🏡 philippeserhal.com

PostsRepliesMedia
Reposted by Philippe Serhal
Mohammad Bagher 👾 @aslemammad.bsky.social · 22h
renewing the bolt open source fund for 2026. $1,700/month in new sponsorships, $11,333/month total. @bolt.new and webcontainers are built on other people's open source. here's who we fund. bolt.new/blog/bolt-op...
bolt.new
Bolt Open Source Fund 2026
StackBlitz is renewing the Bolt Open Source Fund in 2026, adding $1,700/month in new sponsorships for a total run-rate of $11,333/month.
2164
Reposted by Philippe Serhal
Eduardo Bouças @eduardoboucas.com · 28/09/2026
After exactly zero people asked, I wrote something a bit more personal about my journey at Netlify and how I think about my work. eduardoboucas.com/posts/2026-0...
eduardoboucas.com
I ___ Netlify
A coffee mug with a missing heart, and what it says about my complicated relationship with work.
091
Reposted by Philippe Serhal
VoidZero @voidzero.dev · 28/09/2026
Vite+ 1.0 is here 🚀 A single `vp` CLI for managing your Node.js runtime, package manager, and frontend toolchain. Built on top of Vite, Vitest, Rolldown, Oxc, and tsdown. All with a single config. Free and open source under the MIT license. Start with `vp create` or migrate with `vp migrate`.
voidzero.dev
Announcing Vite+ 1.0
Vite+ 1.0 is here. One CLI manages your runtime, package manager, and frontend toolchain.
213532
Philippe Serhal @philippeserhal.com · 27/09/2026
Touching grασσ this week
Photo of a partially sunlit sea view with islands, mountains, and blue sky with a few clouds
1310
Reposted by Philippe Serhal
James Snell @jasnell.me · 25/09/2026
Way overdue but Node.js is finally getting a `--process-timeout=N` cli flag that will force the process to exit with an explanation of why it was open. github.com/nodejs/node/...
2406
Reposted by Philippe Serhal
MDN Web Docs @developer.mozilla.org · 25/09/2026
🆕 Customize MDN's browser compat tables! Press ⚙️ Settings on any compat table to choose which browsers and engines you see, and hide the ones you don't need. Your picks are saved in your browser. Try it 👇 developer.mozilla.org/en-US/docs/W...
MDN's browser compatibility table for the HTML popover attribute. Its columns cover desktop and mobile browsers, showing which versions support the attribute and its "hint" value. A "Settings" button sits above the table.The Browser compatibility settings dialog on MDN. Browsers appear as chips grouped under Desktop, Mobile, Server and XR, and each one can be added to or removed from the table.
27724
Reposted by Philippe Serhal
Julian @fettstorch.dev · 25/09/2026
Wanted to play around with Jev and did a little atproto account search tool. Originally made for our social-media team that wanted to be able to tag @thealexlichter.com in our 🦋-posts knowing only: "alex, dev that does something with void" 🤷‍♂️ Whats his @? -> whatstheir.at 😊
4133
Reposted by Philippe Serhal
Jens Rømer @jensroemer.com · 25/09/2026
There's an overview here tangled.org/jensroemer.c... there's a small section with repos/workflows that can convert nicely today @philippeserhal.com you have a few repos for example that are ready ;-) @oppi.li not sure if this is interesting to you folks
tangled.org
jensroemer.com/tangleflow-coverage
Small repo for scanning Tangled for repos with github workflows, but no tangled workflows, and whether the workflows currently can be converted with https://github.com/43081j/tangleflow or not.
051
Reposted by Philippe Serhal
James @43081j.com · 24/09/2026
Today we're launching ai-policy.dev! A collaboration of me, @danielroe.dev and @matteogabriele.npmx.social - this provides a few human curated AI contribution policies you can choose from. Our hope is that this will help you better define your stance and what kind of contributions you accept 🙏
ai-policy.dev
AI Contribution Policies
Ready-to-use AI contribution policies for open source projects.
1313540
Philippe Serhal @philippeserhal.com · 23/09/2026
@willow.sh your "Blog" has been quiet since 22 Aug 2024 — go write something! willow.sh Friendly spying provided by standard-incite.bisks.net
willow.sh
Willow (GHOST)
Hey, I am Willow (GHOST)! Welcome to my website, mostly junk propped up with a healthy amount of open source work and events :p
3120
Philippe Serhal @philippeserhal.com · 23/09/2026
@zeu.dev your "from:zeu" has been quiet since 14 Sept 2025 — go write something! from.zeu.dev Sleuthed via standard-incite.bisks.net
from.zeu.dev
from:zeu
080
Philippe Serhal @philippeserhal.com · 22/09/2026
Excited to finally share this project I worked on! @netlify.com is not immune to the... Cambrian explosion: millions of projects are now created each month. But 93% aren't on GitHub, or GitLab, or any forge(!) Turns out git is really useful. So, we hosted our own: www.netlify.com/blog/how-we-....
netlify.com
How we built Git storage for millions of Netlify projects
A technical look at how Netlify built Netlify Source: durable Git storage on S3, scalable caching, push consistency, and support for millions of projects.
1445
Reposted by Philippe Serhal
Next.js @nextjs.org · 22/09/2026
The September 22 out-of-band Next.js security update is now available. It addresses a critical upstream issue affecting Next.js 16. Next.js 15 is not affected, but 15.5.26 adds hardening. ▲ ~/ npm install next@16.3.6 ▲ ~/ npm install next@15.5.26 nextjs.org/blog/nextjs...
nextjs.org
Next.js Security Update for a Critical Upstream Issue
The September 22, 2026 out-of-band security update for Next.js is now available
1125
Reposted by Philippe Serhal
Artem Zakharchenko @kettanaito.com · 22/09/2026
I am losing roughly $800 a month by working on MSW full-time while it's one of the most used projects in the ecosystem. Please, if MSW provides you any value, consider becoming a sponsor. I mean it when I say every contribution counts. Thank you ❤️ github.com/sponsors/mswjs
github.com
Sponsor @mswjs on GitHub Sponsors
Mock Service Worker is an API mocking library for browser and Node.js.
23012
Reposted by Philippe Serhal
Vladimir @vladimir.berlin · 21/09/2026
If you are in Amsterdam this Thursday, come to the @vitest.dev x @npmx.dev meetup! guild.host/events/vites...
guild.host
vitest x npmx | Guild
Sep 24th 6:00PM: Join us in Amsterdam for a joint event with the Vitest and npmx communities! A huge thank you to Biscuit for hosting us Schedule: 18:00 - 19:00 -> Socialising & Food 19:00 - 19:15 ...
34511
Reposted by Philippe Serhal
npm @npmjs.com · 21/09/2026
The latest updates on npm 🧵⬇️
1196
Reposted by Philippe Serhal
Next.js @nextjs.org · 21/09/2026
An out-of-band Next.js security update is planned for September 22, 2026. It addresses a critical issue in an upstream dependency. Upgrade to Next.js 16.3.6 or 15.5.26 as soon as they are available. nextjs.org/blog/upcomi...
nextjs.org
Upcoming Next.js Security Update for a Critical Upstream Issue
Next.js 16.3.6 and 15.5.26 are planned for a critical out-of-band security update on September 22, 2026.
2182
Philippe Serhal @philippeserhal.com · 19/09/2026
Let the psychoanalysis begin
Screenshot of a dark-themed “Frequently used” emoji/sticker panel showing three rows of reaction images, including dogs, cats, eyes, thinking and smiling emojis, prayer hands, thumbs-up, Shrek, Fry from Futurama, a “DONE” stamp, and several custom GitHub- or Netlify-themed icons.
2230
Reposted by Philippe Serhal
danielroe @danielroe.dev · 19/09/2026
don't be nice.
roe.dev
Don't be nice
Sometimes, it's more important to be good than it is to be nice.
41734243
Reposted by Philippe Serhal
Evil Martians @evilmartians.com · 17/09/2026
Not all heroes wear capes... at least the @e18e.dev team doesn't. They’re on a mission to make the JS ecosystem lighter and faster. So we’re donating to them as part of our OSS donation program. They've already reduced node_modules size and made Node.js tooling much faster, and we appreciate it!
2518
Philippe Serhal @philippeserhal.com · 17/09/2026
WHO DID IT? @43081j.com? @thealexlichter.com!?
static.klipy.com
Gif
Alt: Sgt. Doakes from the show Dexter staring suspiciously at a man
0170
Reposted by Philippe Serhal
OpenSSF @openssf.org · 16/09/2026
AI moves fast. Critical infrastructure needs support. The OpenSSF Governing Board backs sustainable funding for public package registries: stronger security, reliable services, and continued free access for developers. We’re in. Join us: openssf.org/blog/2026/09...
Graphic titled "We’re In: Enterprise Commitment to Sustainable Package Registries" featuring the OpenSSF (Open Source Security Foundation) logo on a dark background. A grid on the right displays logos for supporting organizations: Arm, Datadog, Dell Technologies, Ericsson, GitHub, Google, IBM, Kusari, Microsoft, Red Hat, Rust Foundation, and Sonatype.
0104
Reposted by Philippe Serhal
Anthony Fu @antfu.me · 16/09/2026
It's been a while... Introducing Devframe v1.0 🚀 The framework for building DevTools that can run everywhere, for any meta-framework, for both humans and agents. Check out the announcement post and join our Discord 👇
devfra.me
Pluggable, Extensible, and Playful DevTools
Introduction to Devframe, a framework for building pluggable, extensible, and playful DevTools.
614630
Philippe Serhal @philippeserhal.com · 16/09/2026
Am I tripping or did npmjs.com remove package size (I believe it was "Unpacked size")?
Screenshot of the npmjs.com react package page side bar, showing the install command, the repository, the homepage, weekly downloads, version, license, last publish, and collaborators.
230
Reposted by Philippe Serhal
danielroe @danielroe.dev · 14/09/2026
🙋‍♂️ ever wanted to build something without needing to configure a db, auth, file storage or a cms? it turns out you already have all four if you have a bluesky account 👉 airspace is a typed client for it
getair.space
airspace
The database you already have.
1950789
Philippe Serhal @philippeserhal.com · 14/09/2026
In prose, would you use Git or git?
350
Reposted by Philippe Serhal
Alex @alexdln.com · 14/09/2026
11 years ago, Node.js and io.js merged back into one project
A screenshot of the npmx.dev homepage with an updated logo dedicated to the io.js and node.js merge
813219
Reposted by Philippe Serhal
atprotoalternatives @atprotoalternatives.com · 13/09/2026
npmx (@npmx.dev) is a fast, modern browser for the npm registry with instant search, package pages, and a package compare feature, built on the AT Protocol. Now listed on ATproto Alternatives! atprotoalternatives.com/product/npmx/
atprotoalternatives.com
npmx — AT Protocol | at://alternatives
npmx – Fast, modern browser for the npm registry with instant search, package pages, and a package compare feature, built on the AT Protocol.
0305
Philippe Serhal @philippeserhal.com · 09/09/2026
And I'm off to @zurichjs.com Conf too! See you all soon!
1221
Reposted by Philippe Serhal
James @43081j.com · 09/09/2026
Big win! Migrated the whole @netlify.com build repo to @vitest.dev 🎉🎉 Also made heavy use of my snapshot diff tool since ava has binary snapshots (accounting for most of the 40k+ PR 😅)
2365
Philippe Serhal @philippeserhal.com · 07/09/2026
is this anything: test coverage but instead of during test execution it's during actual (like, production) runtime and it reports to a remote endpoint or stdout or something like logs or traces. so you can see a report that shows irl foo.js:137 executes 38m times/day and bar.js:34-96 is dead code.
4100
Philippe Serhal @philippeserhal.com · 05/09/2026
it ain't much but it's honest work
Line chart showing the dependencies of the netlify-cli package, from version 17.38.0 to 27.4.2. The dependencies in version 17.38.0 is 848, in version 27.4.2 is 806 (-5% overall). Key changes: version 17.38.1: 11 dependencies added; version 18.0.2: 15 dependencies removed; version 20.0.1: 7 dependencies added; version 22.1.4: 6 dependencies removed; version 22.3.0: 11 dependencies removed; version 24.0.0: 24 dependencies added; version 24.1.0: 15 dependencies added; version 24.3.0: 47 dependencies removed. At the bottom, a watermark reads "./npmx a fast, modern browser for the npm registry".
5422
Philippe Serhal @philippeserhal.com · 05/09/2026
Saturday 8am, time to finally start preparing my two first ever public talks, the first of which is in... *checks notes*... six days (half of which is work and travel). wish me luck and don't tell @farisaziz.com 🤫
3270
Reposted by Philippe Serhal
Matteo Gabriele @matteogabriele.npmx.social · 05/09/2026
Oh yeah, it's GIF day today, and I finally made my first Noodles for @npmx.dev npmx.dev
67612
Philippe Serhal @philippeserhal.com · 04/09/2026
using frontier models to spark joy in 2026: > claude, fix this markdown table syntax 😌
2240
Reposted by Philippe Serhal
Corbin Crutchley @crutchcorn.dev · 03/09/2026
I still cannot believe that PNPM can interactively upgrade GitHub actions the same way it upgrades other NPM deps. SO good! pnpm.io/cli/update#u...
pnpm.io
pnpm update | pnpm
Aliases: up, upgrade
3506
Reposted by Philippe Serhal
Matteo Gabriele @matteogabriele.npmx.social · 01/09/2026
GitHub doesn't show how many projects use your GitHub Action or GitHub App, so I wrote a custom script to retrieve that information for AgentScan. I didn't expect this many projects ❤️ I'm stoked on one end and sad on the other for the mess AI spam is causing. Stay positive 💪
agentscan.tools
Used by | AgentScan
Public repositories running AgentScan on their CI
3499
Reposted by Philippe Serhal
Remix @remix.run · 31/08/2026
Today we published the first release candidate for Remix 3! - 350+ commits since beta - Full-stack HMR - Database tooling - Safer routing - Improved assets serving - More components - SPA support - One remix package Try it: npx remix@next new my-app
remix.run
Remix 3 Release Candidate
Remix 3 RC is available now. A full-stack JavaScript framework built on web primitives and shipped as a single dependency.
2357
Philippe Serhal @philippeserhal.com · 31/08/2026
I do framework things at @netlify.com and I am easily nerd-sniped, so naturally I painstakingly spelled out some messages with framework logos: viteconf.org/tickets/t/aE... ... oh, right, and I'll be speaking about stuff, be sure to tune in, etc. etc.
viteconf.org
Philippe Serhal's ViteConf 2026 mission credential
Philippe Serhal is on a connect mission for ViteConf 2026. Create your own credential.
0151
Reposted by Philippe Serhal
Netlify @netlify.com · 28/08/2026
Stacks let you merge a large change in sequence instead of landing it all at once. The catch was that only the first pull request had a preview to check against. That is fixed, and each layer is now reviewable on its own URL. www.netlify.com/changelog/20...
121
Reposted by Philippe Serhal
Lars @webpro.nl · 28/08/2026
I don't know who needs to hear this, but the @npmx.dev dependencies list is simply 🧑‍🍳's 💋 Example: npmx.dev/package/knip
List of dependencies for Knip package, highlighting those that have a new version available.
27310
Reposted by Philippe Serhal
Matija Marohnić @silvenon.com · 28/08/2026
Wow, every time I discover something new. Overall it's a perfect and inspiring product. I especially love the compare feature 💯 It was very useful for comparing XML & HTML parsers. It's so easy to pick optimal dependencies with such an efficient tool. npmx.dev simply won over the official one.
091
Philippe Serhal @philippeserhal.com · 27/08/2026
Had you noticed the new @github.com Stacked PRs didn't quite work with @netlify.com deploy previews? ✔️ Fixed: www.netlify.com/changelog/20... Fun fact: this was a ~2-line change. GH PR events have a new `stack.base`: docs.github.com/en/webhooks/.... We now treat this as the base when present. Fin.
netlify.com
Deploy Previews for GitHub stacked pull requests
Every pull request in a GitHub stack can now get its own Netlify Deploy Preview when the stack targets your production branch.
071
Philippe Serhal @philippeserhal.com · 25/08/2026
The Next.js team has just published two Critical remote code execution vulnerabilities. As usual, @netlify.com engineers received early disclosure. We were able to quickly determine that Netlify projects are NOT vulnerable to either vulnerability. Details 👉🏼 www.netlify.com/changelog/20...
netlify.com
Next.js security release (August 2026): what to know
Two critical Next.js RCE advisories: one Windows-only, one in image optimization. What this means for Netlify sites. Upgrade to 15.5.24 or 16.3.3.
1120
Philippe Serhal @philippeserhal.com · 25/08/2026
👀 Is the fact that 28 of the top 30 are on @netlify.com largely selection bias of some sort or should we be patting ourselves on the back here?
140
Philippe Serhal @philippeserhal.com · 24/08/2026
I did the thing! 👉 bsky.app/profile/phil...
0100
Philippe Serhal @philippeserhal.com · 24/08/2026
Introducing: 🛜 npm.report Want to start setting up trusted or staged publishing for your org but aren't sure where to start? 🤹 Trouble keeping track of your migration status? 🕵️ Curious how the ecosystem's migration is going? 📈 Want the satisfaction of a chart going up and to the right?
npm.report
npm.report: supply-chain trust audits for npm orgs
Audit, visualize, share, and track your npm org's trust signals.
44513
Reposted by Philippe Serhal
ZurichJS @zurichjs.com · 24/08/2026
It’s easy to complain about what could be better in the JS ecosystem. James takes a different approach: he sees something that could be improved and gets to work. Through @e18e.dev & many other projects, he’s helping make our shared OSS infrastructure better. So happy to have him at ZurichJS Conf.
2466
Reposted by Philippe Serhal
tierney cyren @bnb.im · 23/08/2026
a reminder that I’m still looking for full-time developer relations roles and I’m open to full-time software engineering roles
24522
Philippe Serhal @philippeserhal.com · 23/08/2026
I'm actually finishing another side project today. I'm doing it. It's happening. I will *not* start a new one. I *will* finish this one and share it tomorrow. I will. Hold me to it, bluesky.
7490