Sign in

Sebastian Markbåge

@sebmarkbage.calyptus.eu
8.9K followers 24 following 70 posts

Formerly: React · Next.js · Vercel

PostsRepliesMedia
Reposted by Sebastian Markbåge
React @react.dev · 03/12/2025
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12...
react.dev
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
714691
Reposted by Sebastian Markbåge
Next.js @nextjs.org · 03/12/2025
A critical vulnerability in React Server Components (CVE-2025-55182) affects React 19 and frameworks, including Next.js (CVE-2025-66478). All users should upgrade to the latest patched version in their release line. nextjs.org/blog/CVE-20...
nextjs.org
Security Advisory: CVE-2025-66478
A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately.
22612
Sebastian Markbåge @sebmarkbage.calyptus.eu · 24/04/2025
I moved to Bluesky for higher quality content that I’m more aligned with which is true to some extent. However I realized what I really like about it is *less* content and that I like zero even better. So I think I’m getting off of Bluesky as well. I didn’t need better social media but none.
8922
Sebastian Markbåge @sebmarkbage.calyptus.eu · 03/04/2025
Tbh, I like the AI DJ voice on Spotify trained on Xavier Jernigan. It adds value over just randomly playing tracks.
270
Reposted by Sebastian Markbåge
Devon Govett @devongovett.me · 29/03/2025
React 19.1 enables Server Components in Parcel with React Stable (not only canary)! Just released Parcel v2.14.3 with the corresponding update. 🥳
413312
Sebastian Markbåge @sebmarkbage.calyptus.eu · 21/03/2025
You can pass sub-classed Promises to React such as in use() with the fields status and value or reason. This allows React synchronously read the value without waiting on a microtask. This is much faster but it also ensures compat when someone needs flushSync(). Microtasks are bad, mkay.
3717
Sebastian Markbåge @sebmarkbage.calyptus.eu · 14/03/2025
New York, New York, New York so good they named it thrice+. New York County is Manhattan. New York City is larger than the county and includes the five boroughs. New York State includes all of them. The city is Manhattan, i.e. New York County. The Tri-State area is the New York metropolitan area.
160
Sebastian Markbåge @sebmarkbage.calyptus.eu · 08/03/2025
Man, I love mainstream health science so much. It’s just so simple when you ignore all the made up stuff from influencers.
0200
Sebastian Markbåge @sebmarkbage.calyptus.eu · 07/03/2025
I've been working through a lot of browser bugs lately but tbh I wouldn't trade it for less ambitious work from browser vendors. I can do a lot more with a buggy API than no API at all.
0360
Sebastian Markbåge @sebmarkbage.calyptus.eu · 28/02/2025
Asking an AI "Are you sure?" to get a better result is this generation's "Millennial pause".
2290
Sebastian Markbåge @sebmarkbage.calyptus.eu · 24/02/2025
The new iOS 18.4 Beta is the first on-device build that has working Scroll-Driven Animations on iPhone. It's not on by default there yet. Unfortunately, it feels a little jittery. Like the frame-rate isn't quite right or something it getting rounded to integers. bsky.app/profile/bram...
1170
Sebastian Markbåge @sebmarkbage.calyptus.eu · 15/01/2025
Chrome DevTools is now going to ignore list `node:` by default. github.com/ChromeDevToo... This is great news for using Chrome Inspector to inspect servers (like the Next.js server). If you've added custom rules and moved away from the default. I recommend adding ^node: to your ignore list.
github.com
Ignore node internals by default, remove bower_components · ChromeDevTools/devtools-frontend@326c069
Bug: 382453615 Change-Id: Ib1625fb44e25ab32a09080276edabe6cb951389e Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/6175018 Commit-Queue: Eric Leese <leese@c...
3293
Sebastian Markbåge @sebmarkbage.calyptus.eu · 09/01/2025
View Transitions are basically magic. Not in the sense that it just works. It's trying to model showmanship in a way that breaks the physics of the rendering engine. It's like semi-transparent ghosts walking through walls. That's why it has to break out of the normal layout and painting flow. 🪄
3663
Sebastian Markbåge @sebmarkbage.calyptus.eu · 13/12/2024
Now that the dust has settled on the funny naming of the experimental Taint APIs. Have you tried them? Did you find them useful? Did they help protect against any mistakes? react.dev/reference/re... react.dev/reference/re... en.wikipedia.org/wiki/Taint_c...
// next.config.js
module.exports = {
  experimental: {
    taint: true
  }
}
7452
Sebastian Markbåge @sebmarkbage.calyptus.eu · 12/12/2024
I'm working on built-in profiling of both Client and Server Components in Chrome DevTools Performance tab. Thanks to the new performance.measure() extensions. h/t Andrés Olivares This works in any RSC environment. In fact, this screenshot is running RSC for Parcel. h/t @devongovett.bsky.social
Screenshot showing the Chrome DevTools Performance tab with RSC integration.
318923
Sebastian Markbåge @sebmarkbage.calyptus.eu · 10/11/2024
If you use auth with refresh tokens that have automatic reuse detection. I.e. if an auth token is expired, you can request a new one using the refresh token only once. How do YOU on your site deal with the race condition where opening multiple tabs/requests at once logs the user out? Not at all?
15997
Sebastian Markbåge @sebmarkbage.calyptus.eu · 01/11/2024
Catch the gotcha? This cache entry is specific to only a specific user because it uses the current user to compute its output. It means the current user must be part of the cache key otherwise this cache entry could leak between users. "use cache" handles this automatically for closures.
export default async function Posts({ posts }) {
  const user = await getUser((await cookies()).token)
  const getPost = async (postID) => {
    "use cache"
    const post = await loadPost(postID)
    return <div>
      {post.title}
      {post.author.id === user.id ? <Edit id={post.id} /> : ' by ' + post.author.name}
    </div>
  }
  return posts.map(getPost)
}
51392
Sebastian Markbåge @sebmarkbage.calyptus.eu · 01/11/2024
Don't sleep on this. While we do have some static parameterization for storage location. We don't actually want dynamic parameterization in the cache directive. That would be too early. It should be able to parameterize it using the content of the function and only that. nextjs.org/blog/our-jou...
Since this API can be called after data loading, you can now use data to tag your cache entries.
2352
Sebastian Markbåge @sebmarkbage.calyptus.eu · 31/10/2024
I missed having 90% @danabra.mov in my feed.
61813
Sebastian Markbåge @sebmarkbage.calyptus.eu · 31/10/2024
👋
131873