Sign in

rich harris

@rich-harris.dev
21K followers 749 following 2K posts

my life is derp and i do derp shit

PostsRepliesMedia
rich harris @rich-harris.dev · 24/09/2026
Don't mean to harp on this but delaying fixes and creating the appearance that everything is insecure and there's nothing you can do about it almost certainly makes us collectively _less_ safe than the occasional false positive. if it's good enough for systems like dependabot/npm audit/whatever...
100
rich harris @rich-harris.dev · 24/09/2026
At the very least, linking to the GHSA (or equivalent) would make it easier for people to judge for themselves. "Single-source report" makes it sound like some rando is guessing, rather than "the people who published the advisory also published a fix and you can check that for yourself right here"
100
Reposted by rich harris
pngwn @pngwn.at · 22/09/2026
After about a year, on and off, I am veeeery happy to release TWINKLEPLOP, a syntax highlighter of tremendous power! The speed of prism with the customisation of Shiki. twinkleplop.pngwn.at
519233
rich harris @rich-harris.dev · 24/09/2026
Oops sorry missed this reply and replied to the other thread - understand not manually patching but I'm surprised that the metadata isn't immediately available given GHSA is the source of truth? bsky.app/profile/rich...
100
rich harris @rich-harris.dev · 24/09/2026
The patched version was included _in the advisory_. What more verification do you need? What more information can an independent source provide?
000
rich harris @rich-harris.dev · 23/09/2026
correction, this is patched in 5.9.3. here's the advisory: github.com/sveltejs/dev... please update your site accordingly
github.com
`stringify`/`uneval` serialize shared memory
### Impact `stringify` and `uneval` serialize a typed array by emitting its backing `ArrayBuffer`, not just the view. In the case of a Node `Buffer` object, the backing buffer is a process-wide ...
140
rich harris @rich-harris.dev · 19/09/2026
If it's easy to repro please raise an issue! Definitely not supposed to happen
110
Reposted by rich harris
The Guardian @theguardian.com · 14/09/2026
Zuckerberg says the science isn’t settled. But the harms of short-form video on the brain are starting to show | Caty Enders
theguardian.com
Zuckerberg says the science isn’t settled. But the harms of short-form video on the brain are starting to show | Caty Enders
Recent social media lawsuits have addressed concerns about mental health. But what about its cognitive effects?
119641
Reposted by rich harris
Erlend Sogge Heggen @erlend.sh · 14/09/2026
PSA: universal basic income / guaranteed minimum income is a form of systemic relief, not systemic change. The former makes room for the latter, but there’s no theory of change in UBI, it’s just a patch fix to avert violent collapse. The steady erosion of agency continues until we OWN STUFF again.
4378
Reposted by rich harris
Laurie Voss @seldo.com · 13/09/2026
I have been writing this post about the economics of open source, on and off, for 13 years. I wasn't expecting to end up at "Microsoft should send corporations a huge bill" but nothing else we've tried has worked. seldo.com/posts/nobody-pays-for-ope…
seldo.com
Nobody pays for open source. We can force them to. | Seldo.com
Thirty years of voluntary funding schemes haven't paid open source maintainers because asking doesn't scale. The real money already flows — to JFrog, Docker, Sonatype — at the registry layer. The fix: registries charge companies for supply (they already do), then route a slice automatically to the maintainers who make that supply worth having.
2016655
rich harris @rich-harris.dev · 12/09/2026
This short story (by the "there is no anti-memetics division" guy) is fantastic and horrifying and you should all read it
2353
Reposted by rich harris
Elle Cordova @ellecordova.bsky.social · 08/09/2026
I am the very model of a modern day typographer I know the type tonalities from elegant to jocular I am a master tracker and my kerning is harmonical I know the sacred swatches and can name the hues Pantonical (Full version of Modern Day Typographer now on my YouTube channel)
youtu.be
Modern Day Typographer - Elle Cordova
YouTube video by Elle Cordova
701850415
Reposted by rich harris
michael h keller @mhkeller.bsky.social · 08/09/2026
Some @layercake.graphics news: with @openclimatedata.net's help and @techniq.dev's insights, v11 of the library is out and has fully converted into runes instead of the @svelte.dev Store API. tldr; many fewer dollar-signs!
1279
Reposted by rich harris
ryan cooper @ryanlcooper.com · 08/09/2026
hell of a piece. wooooof harpers.org/archive/2026...
harpers.org
Child’s Play, by Sam Kriss
Tech’s new generation and the end of thinking
1837166
rich harris @rich-harris.dev · 08/09/2026
tag yourself
An exhibit at the Designmuseum Danmark, with hundreds of bottles labeled 'bruised ego coping', 'fear of commitment dissolver' and so on
371
Reposted by rich harris
Robin Berjon @robin.berjon.com · 08/09/2026
The authoritarians are winning, we can all see that. Maybe, just maybe, it wouldn't be the worst thing if pro-democracy people stopped being ridiculously naive about social media. berjon.com/media-media/
berjon.com
Media Media
The authoritarians are winning, we can all see that. It wouldn't be the worst thing if the pro-democracy camp stopped being naive about social media.
615158
rich harris @rich-harris.dev · 07/09/2026
yeah effect_in_unowned_derived is really just effect_orphan. if you can't put an effect inside a derived, it's because you wouldn't have been able to put an effect there _outside_ a derived. it would be like calling useState in an onClick handler, to put it in React terms
010
rich harris @rich-harris.dev · 07/09/2026
'oh right fair enough i guess that makes sense'. beyond things magically working in the way you want them to in that moment (which isn't possible, because that will change from t1 to t2 in ways that can't be resolved) what could be better DX than a link to docs that help refine the mental model?
110
rich harris @rich-harris.dev · 07/09/2026
> the only lead you get is a stacktrace that links to the missing piece is that most of those messages don't have more detailed explanations of what went wrong. like, if svelte.dev/docs/svelte/... had the (ahem) context I gave above, your reaction would likely have been less 'this sucks' and more
svelte.dev
Runtime errors • Svelte Docs
Runtime errors • Svelte documentation
100
rich harris @rich-harris.dev · 07/09/2026
> stores can only be referenced at the topmost <script>, which especially sucks well yes that's why we're getting rid of them > if that effect ends up inside a $derived then it suddenly does not work say more? effects _do_ work in deriveds (svelte.dev/playground/h...)
svelte.dev
Hello world • Playground • Svelte
Web development for the rest of us
200
rich harris @rich-harris.dev · 07/09/2026
yep, exactly — <p>{thing}</p> won't update otherwise, by design. of course, in some cases you _know_ it can never update, and in that case it's equally appropriate to silence it with a `svelte-ignore` comment. this is also valid: const { thing } = untrack(() => data.deeply.nested);
150
rich harris @rich-harris.dev · 07/09/2026
("here's how to create a <ContextProvider> component") or if we should just ship that component or something like it, and b) if there's a better API you envisage
110
rich harris @rich-harris.dev · 07/09/2026
can you elaborate on what you're using context for? re "opt-in into that tradeoff", you can always do this — <ContextProvider key={blah} value={await whatever()}> <MyStuff /> </ContextProvider> — so I'm curious if a) that's insufficiently discoverable, and if so if it's a documentation issue
100
Reposted by rich harris
Erlend Sogge Heggen @erlend.sh · 07/09/2026
Seeing a lot of dev-on-dev harassment has got me thinking about what open software development feels like nowadays.
notes.erlend.sh
Making software hurts now
and hurt people hurt people
511527
rich harris @rich-harris.dev · 05/09/2026
because that would make it impossible for child components to safely start rendering (kicking off any async work _they_ need to do) immediately, instead of waiting for the parent to finish which would cause waterfalls. it's a trade-off, of course. i would strongly argue it's the right one
110
rich harris @rich-harris.dev · 04/09/2026
damn!
010
rich harris @rich-harris.dev · 04/09/2026
this is a fascinating (and sobering) read
0131
Reposted by rich harris
Elle Cordova @ellecordova.bsky.social · 03/09/2026
Rough Draft vs Final Draft
253116673306
Reposted by rich harris
Vale @vale.rocks · 02/09/2026
Respected friends and acquaintances, initial-scale is dead! We are freed of its tyranny. You no longer need to include it in your HTML head. It is an obsolete part of your head's meta viewport declaration. The details: vale.rocks/micros/20260... #WebDev #HTML
vale.rocks
You Don't Need Initial-Scale In Your HTML - 2 Sept 2026 13:50 UTC
410620
Reposted by rich harris
Hendrik Mans @hmans.dev · 31/08/2026
If you run Omarchy I will judge you
1217627
Reposted by rich harris
Carlo Zottmann @zottmann.dev · 29/08/2026
💯 > Blaming #GDPR for the cookie banner is like blaming the health inspector for the roaches. The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the #surveillance apparatus humming behind the "OK." matduggan.com/you-know-gdp... #privacy
matduggan.com
You Know GDPR Is Good Based on Who Hates It
FDR has always been one of my favorite presidents, second maybe to Lincoln. Both were men the establishment assumed were one of them until, to their horror, they governed like they weren't. Both could...
15313
rich harris @rich-harris.dev · 28/08/2026
back atcha! yeah the team is the best. absolute pros and lovely people
020
rich harris @rich-harris.dev · 27/08/2026
a few weeks ago I recorded an updated Svelte(Kit) workshop with @frontendmasters.com. i'm proud of it and you should check it out! master.dev/courses/svel...
master.dev
Build high-performance, accessible full-stack apps with Svelte
Learn Svelte and SvelteKit and build resilient, accessible, high-performance web apps. Ship delightful user experiences with reactive UIs, auth, and server rendering, all with less code.
1899
Reposted by rich harris
Svelte @svelte.dev · 27/08/2026
Last few days for early bird pricing for Svelte Summit! If you're quick you can snag another 10% off 👇
063
Reposted by rich harris
Kimbia @kimbia.app · 22/08/2026
It's time to try kimbia.app All feedback welcome, we are early and we are listening.
The journal (private by default)Session analysis with a lot of data / trendsConnected to bluesky DIRECTLY. You can share stuff. Here an example of post from an activityAdventure mode example with multiple activities on ONE map
46215
Reposted by rich harris
Aram Zucker-Scharff @chronotope.aramzs.xyz · 20/08/2026
The more I think about it the more it seems the Discourse is missing an essential ingredient. We must bring the context that Machines Work For Us, We Don't Work For Machines. This is the core leftist argument that is least clearly articulated, but that all else flows from. Solutions start there.
3557
Reposted by rich harris
Simon H @dummdidumm.bsky.social · 18/08/2026
"Content creator" spamming blog posts on X about topics I do find interesting but can't get myself to read because of the so-obvious AI slop. Framework authors discussing about trade-offs with "here's what my AI said in response to your AI". Something broke inside me today.
4312
rich harris @rich-harris.dev · 17/08/2026
If you're anything like me you will eventually reach the point of never opening unread channels because you've trained yourself to think there's actually nothing new there
060
rich harris @rich-harris.dev · 15/08/2026
Surely one of the most quotable movies ever made. The number of times I've said 'I've only had a few ales officer' when asked how my evening was, or thought to myself "what absolute twaddle"
140
rich harris @rich-harris.dev · 15/08/2026
subpath imports are better! no sense in configuring sveltekit so that it can configure vite and typescript when there's a universally respected standard
1100
rich harris @rich-harris.dev · 14/08/2026
stable release coming soon! get yer bug reports in while you can the post contains a summary of what's changed. there's also a migration guide: next.svelte.dev/docs/kit/mig.... both were written by humans
28611
Reposted by rich harris
Svelte Society @sveltesociety.dev · 14/08/2026
Last chance to submit a CFP for Svelte Summit! 🚨 sveltesummit.com/cfp
0106
rich harris @rich-harris.dev · 13/08/2026
touché
020
rich harris @rich-harris.dev · 12/08/2026
there's no `svelte/motion` without it
060
rich harris @rich-harris.dev · 12/08/2026
and Time Slicing. they were early to discover the importance of being non-blocking
180
rich harris @rich-harris.dev · 12/08/2026
tick tock!
050
rich harris @rich-harris.dev · 12/08/2026
nice transitions you got there, would be a shame if...
140
rich harris @rich-harris.dev · 12/08/2026
you should come to Ljubljana even if you already know!
180
rich harris @rich-harris.dev · 12/08/2026
160
rich harris @rich-harris.dev · 12/08/2026
the repo isn't public, but i just put the markdown for the slides in a gist: gist.github.com/Rich-Harris/...
gist.github.com
Reclaiming AI
Reclaiming AI. GitHub Gist: instantly share code, notes, and snippets.
130