Sign in

Richard Lau

@rwklau.bsky.social
396 followers 30 following 39 posts

Software Engineer at IBM. Node.js Build Infrastructure, Releaser & Technical Steering Committee.

PostsRepliesMedia
Reposted by Richard Lau
James Snell @jasnell.me · 25/09/2026
If you're not able to join us in person at @nodeconf.eu in Bologna, Italy next week, please do try to join us remotely here live.nodeconf.eu ... every talk will be broadcast live with downloadable recordings available after.
live.nodeconf.eu
NodeConf EU 2026 Live | Bologna, Italy
Watch NodeConf EU 2026 live from Bologna on 29-30 September.
0136
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 24/09/2026
One of the most exciting things I've seen in my seven years at IBM is how much open source software originally developed for cloud-native environments is coming to IBM z/OS. Ansible! Apache Kafka! And OpenTelemetry! SHARE has posted a nice intro article about it here: blog.share.org/Article/what...
blog.share.org
What Is OpenTelemetry for IBM z/OS? — Intro to the Mainframe Series
This article is part of SHARE’s intro to the mainframe series. Read the articles on CICS, Automation, Catalogs, COBOL, and HSLAM. If you would like to contribute to this series, please reach out to ed...
011
Reposted by Richard Lau
npm @npmjs.com · 21/09/2026
Learn more recent improvements and what’s next. Tell us what would make publishing and consuming packages safer and easier.
github.com
npm’s roadmap: safer publishing, smoother workflows, and what’s next · community · Discussion #208130
Hi everyone, Leo here, npm's PM. I want to share what we’ve shipped since May, where we’re focusing for the rest of 2026, and what we’re considering for 2027. I also want your feedback: what would ...
061
Reposted by Richard Lau
James Snell @jasnell.me · 17/09/2026
Node.js now has (or in the next release will soon have) an improved range of performance diagnostic analysis features built in. New APIs have been added to the Histogram class: * h.burnRate(slowTarget) * h.ccdf(value) * h.cliffsD(other) * h.cohensD(other) * h.ewmaMean * h.ewmaErrorRate ...
2193
Reposted by Richard Lau
OpenJS Foundation @openjsf.org · 17/09/2026
Last chance to share your feedback in the 2026 Node.js User Survey! If you use Node.js, take a few minutes to tell us about your experience, priorities, and what matters most to you. Take the survey: linuxfoundation.surveymonkey.com/r/nodejs-use... #NodeJS #OpenSource
linuxfoundation.surveymonkey.com
Node.js User Survey 2026
Take this survey powered by surveymonkey.com. Create your own surveys for free.
052
Reposted by Richard Lau
James Snell @jasnell.me · 18/09/2026
100% true. And, honestly, one of the secrets to @nodejs.org's longevity is that we exactly built resilience to this into the governance. No single company can represent more than 1/3 of the TSC for instance. It's never perfect but with effort companies can participate rather than dominate.
1146
Reposted by Richard Lau
Antoine du Hamel @aduh95.bsky.social · 16/09/2026
Node.js 26.9.0 is out, it enables by default node:ffi and adds support for Web Worker API (behind a flag). Full changelog and download links at nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.9.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
1227
Reposted by Richard Lau
Ulises Gascón @ulisesgascon.com · 12/09/2026
🫶 As part of the @openjsf.org #CNA, we also want to encourage #maintainers, in our projects and beyond, to give themselves permission to take a break. #Burnout is real for #maintainers, especially in #security work. openjsf.org/blog/the-ope...
openjsf.org
The OpenJS Foundation CNA is taking a coordinated break: September 17 to October 6, 2026 | OpenJS Foundation
To combat volunteer burnout driven by a surge in AI-generated vulnerability reports, the OpenJS Foundation CNA will temporarily pause all security operations from September 17 to October 6, 2026. This...
031
Reposted by Richard Lau
Antoine du Hamel @aduh95.bsky.social · 09/09/2026
Node.js 24.21.0 and 26.8.2 are available, with security updates from OpenSSL and Undici. Full changelog and download links available at nodejs.org/en/blog/rele... and nodejs.org/en/blog/rele...
nodejs.org
085
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 08/09/2026
Here we are, the Linux on IBM Z and LinuxONE Open Source Software Report for August 2026! 🐧 The team worked on Bazel, Consul, and Zabbix, along with 30 other projects. In the community we saw binaries released and/or CI enabled for another 7 🎉 Full report: community.ibm.com/community/us...
community.ibm.com
Linux on IBM Z and LinuxONE Open Source Software Report: August 2026
021
Richard Lau @rwklau.bsky.social · 03/09/2026
25 years at #IBM today (including a five year stint at #RedHat). 🎉
020
Reposted by Richard Lau
npm @npmjs.com · 13/08/2026
Coming next: bypass-2FA tokens will also lose direct publish (~Jan 2027). Move automated publishing to trusted publishing (OIDC) or staged publishing.
131
Reposted by Richard Lau
npm @npmjs.com · 13/08/2026
npm Granular Access Tokens that bypass 2FA can no longer manage your account, org, or packages—those actions now require an interactive 2FA challenge, closing a major credential-based attack surface. github.blog/changelog/20...
github.blog
Restricting npm bypass-2FA granular access tokens - GitHub Changelog
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of…
1254
Reposted by Richard Lau
Matteo Collina @nodeland.dev · 11/08/2026
I triage 20-40 security vulnerability reports a week. Almost all of them are now AI-written. And we usually get 3-5 duplicates of each one. That's the new reality of being a maintainer. 🧵
2112
Richard Lau @rwklau.bsky.social · 10/08/2026
This is really sad news: www.hampshirechronicle.co.uk/news/2644920... Thankfully nobody was injured. The clubhouse was one of the perks of working at #IBM Hursley Park office, even if getting to it in a wheelchair onsite was difficult due to the gravel paths and steps.
hampshirechronicle.co.uk
Huge fire which destroyed clubhouse was visible for miles, says witness
A huge fire that engulfed an industrial building could be seen from miles away, with a witness describing feeling the heat on their faces as…
010
Reposted by Richard Lau
Joyee Cheung @joyeecheung.bsky.social · 08/08/2026
Added some new commands to the GDB & LLDB plugin for V8.. `v8 source`: shows the JS source of the selected frame `v8 isolate`: find the isolate address in the current thread, works from the coredump too (implementing that in LLDB was quite a bit of challenge!)
Screenshot showing v8 isolate and v8 source
0153
Reposted by Richard Lau
James Snell @jasnell.me · 10/08/2026
A word of advice to young developers: Stop spamming open source projects with AI "contributions". Opening dozens of PRs in a matter of hours is just going to piss people off and get you blocked regardless of whether the changes are legitimate or not.
2639
Reposted by Richard Lau
Matteo Collina @nodeland.dev · 10/08/2026
Who is still using the domain module? We are planning to runtime deprecate it in @nodejs.org v27.
github.com
domain: runtime-deprecate the module by mcollina · Pull Request #65074 · nodejs/node
Promote DEP0032 (node:domain module) from a documentation-only deprecation to a runtime deprecation. Fixes #10843
4135
Reposted by Richard Lau
Antoine du Hamel @aduh95.bsky.social · 05/08/2026
📣 New Node.js release 📣 Node.js 26.7.0 is out with Perfetto tracing support, STORE loaders for private keys, and `module.register()` hooks are now disposable, plus many patches. Full changelog and download links available at nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.7.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0265
Reposted by Richard Lau
npm @npmjs.com · 04/08/2026
npm is rotating write-scoped npm Granular Access Tokens that bypass 2FA as a precaution following a now-contained security incident. This doesn't affect GitHub personal access tokens. Maintainers should upgrade the npm CLI to v12+ and consider Trusted Publishing. docs.npmjs.com/trusted-publ...
docs.npmjs.com
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
13014
Reposted by Richard Lau
Node.js @nodejs.org · 03/08/2026
Node.js 26.6.0 and 24.19.0 are out 💚 - nodejs.org/blog/release/v24.19.0 - nodejs.org/blog/release/v26.6.0
nodejs.org
Node.js — Node.js 24.19.0 (LTS)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
1285
Reposted by Richard Lau
Node.js @nodejs.org · 29/07/2026
⚠️ Node.js Security Update: Updates are now available for the 26.x, 24.x, 22.x release lines. Details: nodejs.org/en/blog/vulnerability/ju…
nodejs.org
Node.js — Wednesday, July 29, 2026 Security Releases
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0368
Richard Lau @rwklau.bsky.social · 03/08/2026
Back at work after a week off to help look after some young relatives. - Inbox 1, 116 unread emails. - Inbox 2, 336 unread emails. - Over 1000 GitHub notifications, which appears to break the notifications counter.
github.com
Unread notification display won't display over 1,000 · community · Discussion #139148
Select Topic Area Bug Body The number gets generated as "1" not showing the true count. If I mark some as read, anything under 1,000 works fine Firefox 130
010
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 22/07/2026
Welcome to the Open Source Software report for IBM Z and LinuxONE for June 2026 🐧 Validation was maintained for over 2 dozen projects, including the Apache HTTP Server, pgvector, & RabbitMQ + 6 projects and ecosystems added s390x binaries, CI, and/or containers! 📦 community.ibm.com/community/us...
community.ibm.com
Linux on IBM Z and LinuxONE Open Source Software Report: June 2026
021
Reposted by Richard Lau
Node.js @nodejs.org · 21/07/2026
⚠️ The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026. Details: nodejs.org/en/blog/vulnerability/ju…
nodejs.org
Node.js — Monday, July 27, 2026 Security Releases
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0263
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 15/07/2026
My talk at PLUG went well last night 🐧 🎉 Answered lots of interesting mainframe questions, got to show off zopen's port of DNF5, and folks were interested in both the IBM LinuxONE Community Cloud and learning more via IBM Z Xplore. Slides here: princessleia.com/presentation... (1.3M pdf)
Opening presentation slide on a large television that has a starfield background and says "The Source Awakens: Open Source on IBM Z in a Multi-Architecture World" followed by pleia2's contact information.
021
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 14/07/2026
This evening at 7PM I'm speaking at the Philadelphia Linux Users Group about the latest in the open source mainframe world, from the Mainframe Software Hub for Linux to the development around rpm and dnf5 for IBM z/OS Unix System Services (yes, really!) Info: lists.netisland.net/archives/plu...
lists.netisland.net
[PLUG] [plug-announce] Tue Jul 14 - PLUG North - "The Source Awakens: Op
031
Reposted by Richard Lau
Joyee Cheung @joyeecheung.bsky.social · 14/07/2026
TIL `git history split`!! 😍 lalitm.com/post/git-his...
lalitm.com
The git history command deserves more attention
Working with lots of changes in parallel on git can be painful. You end up juggling branches and commits, and running scary rebase -i commands that can leave your tree in a half-broken state if you so...
4446
Reposted by Richard Lau
Joyee Cheung @joyeecheung.bsky.social · 10/07/2026
Anyone using --use-largepages in real-world deployments? Just opened an issue about possibly deprecating it (if nobody is using it) to reduce the maintenance churn github.com/nodejs/node/...
github.com
Future of `--use-largepages=on` · Issue #64408 · nodejs/node
This was added back in 2018, some background can be found in this issue #16198 - from what I can tell we opted into a user-land relocation to work around the fact that for most kernels in the wild,...
063
Reposted by Richard Lau
James Snell @jasnell.me · 10/07/2026
Fetch is not enough... a blog post on server-side HTTP API standardization www.jasnell.me/posts/fetch-...
jasnell.me
Fetch Is Not Enough
The Fetch API gave JavaScript runtimes a shared vocabulary for HTTP. But HTTP has capabilities that Fetch can't express, and every runtime has diverged trying to work around the gaps.
5285
Reposted by Richard Lau
Ulises Gascón @ulisesgascon.com · 09/07/2026
✨ Keep up to date with @nodejs.org by watching the #Nodejs #Security Working Group's last meeting on YouTube! We discussed around the @openjsf.org #CNA #API initiative and the next steps for the final adoption👌 www.youtube.com/watch?v=p1wR...
youtube.com
2026-07-09 - Node.js Security Working Group Monthly Meeting
YouTube video by node.js
041
Reposted by Richard Lau
npm @npmjs.com · 08/07/2026
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
26024
Reposted by Richard Lau
Joyee Cheung @joyeecheung.bsky.social · 08/07/2026
Made the new debug helper plugins work for Node.js + bleeding edge V8 🌟 Verified it works in LLDB (Linux, macOS) & GDB (Linux), both in live and coredump debugging Going to backport the patches to Node.js when the object inspection is more polished and it stablizes bit more..
Using the plugin, bt in gdb shows the JS source info of JIT-compiled frames, mostly from the CJS loader (without plugin gdb only shows ???)In the plugin's `v8 inspect` command, it shows the this argument of the first frame is a function named "Module" (the CJS loader class i.e. require('module').Module)
0113
Reposted by Richard Lau
Ruy Adorno @ruyadorno.com · 08/07/2026
I noticed npm is finally pushing out some of the breaking changes that I wanted to push 5 years ago, so I decided to write something about it, mostly to report and raise awareness that these changes are coming 😊 www.vlt.io/blog/npm-12-...
vlt.io
Beyond disabling postinstalls: how npm install will change in npm 12 | vlt /vōlt/
As part of its planned 12th release, the npm CLI drops automatically running lifecycle scripts on installs as part of multiple planned breaking changes
0165
Richard Lau @rwklau.bsky.social · 08/07/2026
New @nodejs.org 26.5.0 release nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.5.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0214
Richard Lau @rwklau.bsky.social · 08/07/2026
Waiting for the website CI to complete so I can announce the @nodejs.org 26.5.0 release ⌛
000
Reposted by Richard Lau
Joyee Cheung @joyeecheung.bsky.social · 07/07/2026
Landed a few improvements to the error reporting for require(esm) with top-level await (behind --experimental-print-required-tla for now): - No longer need to run the code to collect the TLA locations, so it can be enabled by default soon - Added require stack and location metadata to the error
Before: extra noisy arrow pointing to internals, no require stack, needs to run the code to find the top-level await location
After: no more noisy arrows, added require stacks to the output, finds location without running the codeNew ERR_REQUIRE_ASYNC_MODULE includes error.requireStack and error.topLevelAwaitLocations metadata properties
1378
Reposted by Richard Lau
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026
You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss
01510
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 07/07/2026
It wasn't just IBM opening the NYSE this morning, it was ✨ IBM Z ✨ Why is it such a big day? We just announced our new Single frame and rack mount z17 and LinuxONE 5! newsroom.ibm.com/z17-linuxone...
IBM Z and team ringing the opening bell at the New York Stock Exchange on July 7th 2026, background in blue and "IBM" logo.IBM z17 rack-mount server image, background in white.
241
Reposted by Richard Lau
The Linux Foundation @linuxfoundation.org · 01/07/2026
🧭 What should your IT career path be? Find out with our Career Roadmap Quiz: bit.ly/4uXuMv4
0103
Reposted by Richard Lau
Node.js @nodejs.org · 01/07/2026
New to open source, or wondering how to get your first Node.js contribution landed and released? Check out our new first-time contributors guide, with practical tips and answers to FAQs about working with our volunteer-driven model. bit.ly/4avNtP2
github.com
node/doc/contributing/first-contributions.md at main · nodejs/node
Node.js JavaScript runtime ✨🐢🚀✨. Contribute to nodejs/node development by creating an account on GitHub.
1377
Reposted by Richard Lau
Antoine du Hamel @aduh95.bsky.social · 25/06/2026
Node.js 26.4.0 is out with a new `node:vfs` built-in module (behind `--experimental-vfs` flag). It also adds support for package maps, and many bug fixes, including a fix for a regression shipped with last week security release. Full changelog and download links at nodejs.org/en/blog/rele...
nodejs.org
Node.js — Node.js 26.4.0 (Current)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
03212
Reposted by Richard Lau
Stewart X Addison @sxa.fosstodon.org.ap.brid.gy · 24/06/2026
New #NodeJS v24.18.0 release is now out. See nodejs.org/en/blog/release/v24.18.0 for a full list of changes. This release fixes two regressions which were recently introduced: - github.com/nodejs/node/issues/63487 (Hang when using extract-zip module) - […]
fosstodon.org
Original post on fosstodon.org
041
Richard Lau @rwklau.bsky.social · 24/06/2026
New @nodejs.org 24.18.0 release is now out. nodejs.org/en/blog/rele... This fixes a couple of regressions: - github.com/nodejs/node/... - github.com/nodejs/node/...
nodejs.org
Node.js — Node.js 24.18.0 (LTS)
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
0154
Reposted by Richard Lau
Ulises Gascón @ulisesgascon.com · 20/06/2026
🔐 A thing many people miss: Node.js trusts the code you install by default. So blocking npm install scripts closes one door and leaves another wide open, the one that opens when you require() the package. nodesource.com/blog/npm-v12...
nodesource.com
Blocking Install Scripts Is Not a Silver Bullet
npm v12 blocks install scripts by default, but supply chain attacks won't disappear. Learn why runtime execution, the Node.js permission model, and sandboxing still matter.
3165
Reposted by Richard Lau
Matteo Collina @nodeland.dev · 18/06/2026
🔒 Security release for undici (the HTTP client powering Node.js fetch). We've shipped fixes for 8 advisories across all supported lines. Please upgrade: • v8 → 8.5.0 • v7 → 7.28.0 • v6 → 6.27.0 npm i undici@latest Details 🧵👇
1153
Reposted by Richard Lau
Elizabeth K. Joseph @pleia2.bsky.social · 18/06/2026
Time for the Open Source Software report for IBM Z and LinuxONE for May 2026 🐧 Validation was maintained for over 2 dozen projects, including Apache Ignite, Calico, and OpenResty. And over 10 projects added s390x binaries, CI, and/or containers to their projects! community.ibm.com/community/us...
community.ibm.com
Linux on IBM Z and LinuxONE Open Source Software Report: May 2026
001
Reposted by Richard Lau
Node.js @nodejs.org · 18/06/2026
⚠️ Updates are now available for the 26.x, 24.x, 22.x Node.js release lines for the following issues. More information here: nodejs.org/en/blog/vulnerability/ju…
nodejs.org
Node.js — Thursday, June 18, 2026 Security Releases
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
03710
Richard Lau @rwklau.bsky.social · 16/06/2026
Happy 115th birthday #IBM (nee Computing-Tabulating-Recording Company). www.ibm.com/history/ctr-...
ibm.com
The origins of IBM | IBM
IBM's core values, philosophies and culture date back to the merger of three obscure companies at the turn of the 20th century
120
Reposted by Richard Lau
Joyee Cheung @joyeecheung.bsky.social · 11/06/2026
Today I gave a talk JSNation about the life cycle of ESM in Node.js, how it differs in other environments and the new features that will affect these stages. Slides: github.com/joyeecheung/...
github.com
13812