Sign in

Kevin Deng

@sxzz.dev
1.6K followers 310 following 307 posts

github.com/sxzz • 🏳️‍🌈 Gen Z • indie OSS developer sponsored by @voidzero.dev @vuejs.org @vite.dev @vue-macros.dev @vueuse.org @unjs.io @rolldown.rs elk.zone More at sxzz.dev

PostsRepliesMedia
Reposted by Kevin Deng
Anthony Fu @antfu.me · 16/09/2026
It's been a while... Introducing Devframe v1.0 🚀 The framework for building DevTools that can run everywhere, for any meta-framework, for both humans and agents. Check out the announcement post and join our Discord 👇
devfra.me
Pluggable, Extensible, and Playful DevTools
Introduction to Devframe, a framework for building pluggable, extensible, and playful DevTools.
614630
Reposted by Kevin Deng
Rick Viscomi @rviscomi.dev · 08/09/2026
I wrote this one! 🙋‍♂️ In CJK languages, hitting Enter to confirm an IME candidate can accidentally submit the form in chat textareas The guide shows how to safely implement "Enter to submit" including how to work around a Safari event-ordering bug with isComposing github.com/GoogleChrome...
github.com
modern-web-guidance/skills/modern-web-guidance/guides/forms/ime-safe-enter-submit.md at v0.0.186 · GoogleChrome/modern-web-guidance
Keep your coding agent up to date with the latest web best practices - GoogleChrome/modern-web-guidance
0162
Reposted by Kevin Deng
Roman @rman.dev · 01/09/2026
I just sponsored sxzz. Go sponsor your open source dependencies!
github.com
Sponsor @sxzz on GitHub Sponsors
An open sourceror. Working on Vue, Vite, VueUse, and their ecosystems.
1141
Reposted by Kevin Deng
Andrew Branch @andrewbran.ch · 15/08/2026
If you’re not stalking TypeScript PRs, you might be surprised how much you can do with the API in nightlies (and even in 7.0 stable), so here’s a tiny demo that I think hits some of the highlights. 🧵
A package.json in VS Code after npm installing typescript@next
412720
Kevin Deng @sxzz.dev · 13/08/2026
Changesets is using tsdown
091
Kevin Deng @sxzz.dev · 06/08/2026
Just like this is Johnson’s project, he can do whatever he wants. After using such disrespectful language toward someone (regardless of where), I thought you knew you could always directly fork an OSS project instead of impotently raging like an asshole. No community welcomes you.
040
Kevin Deng @sxzz.dev · 05/08/2026
TIL: Domains like .dev, .app are required to use HTTPS.
181
Kevin Deng @sxzz.dev · 26/07/2026
❯ pnpm run release && claude --dangerously-skip-permissions /review-npm-stage github.com/sxzz/review-...
github.com
GitHub - sxzz/review-npm-stage
Contribute to sxzz/review-npm-stage development by creating an account on GitHub.
170
Kevin Deng @sxzz.dev · 23/07/2026
Glad to help move the ecosystem toward: - ESM-only - TypeScript - OIDC + staged publishing - Runtime-agnostic design wherever possible - No bundled deps unless needed - Like-minded dependencies I’ve replaced `debug` and `semver` with `obug` and `verkit`. What’s next? 🤔
3472
Kevin Deng @sxzz.dev · 21/07/2026
The tsdown ecosystem, visualized ✨ Each circle = a project owner using tsdown, sized by GitHub stars. 873 projects over 100 stars and counting. Grateful to everyone shipping with it.
1252
Reposted by Kevin Deng
Antoine @antleth.fr · 16/07/2026
magic-string got more than half smaller btw!
Package size dropping from ~600kB to 305kB, making it 56% smaller
2302
Kevin Deng @sxzz.dev · 16/07/2026
Volar now has first-class support in tsdown and rolldown-plugin-dts. It can generate `.d.ts` files for all file types supported by Volar, including Vue and Astro. github.com/sxzz/rolldow...
github.com
feat: support multiple volar plugins · sxzz/rolldown-plugin-dts@7cb4ee8
090
Reposted by Kevin Deng
Anthony Fu @antfu.me · 16/07/2026
magic-string v1.0.0 gets released with pure-ESM, thanks to @sxzz.dev!
github.com
Release v1.0.0 · Rich-Harris/magic-string
In magic-string v1.0.0, it's now pure ESM, and the type declarations are built from the TypeScript source. This means the previous CJS, UMD, and IIFE builds are now dropped as we believe the ecosys...
1664
Kevin Deng @sxzz.dev · 16/07/2026
🎉 magic-string is now fully migrated to pure ESM and TypeScript, and its long-awaited v1.0 release is finally here! github.com/Rich-Harris/...
github.com
feat!: migrate build to pure ESM and TypeScript by sxzz · Pull Request #310 · Rich-Harris/magic-string
closes #309, closes #301
2315
Kevin Deng @sxzz.dev · 12/07/2026
⚡ After `rolldown-plugin-dts` migrated Babel toolchain to yuku, tsdown has cut ~5 MB from its install size and is now smaller than tsup. ❤️ Huge thanks to arshad-yaseen for the help!
0230
Kevin Deng @sxzz.dev · 08/07/2026
i am cool
190
Kevin Deng @sxzz.dev · 06/07/2026
tsdown #1000 issue github.com/rolldown/tsd...
github.com
@tsdown/css should reuse sass-embedded AsyncCompiler instead of spawning a compiler per SCSS transform · Issue #1000 · rolldown/tsdown
Clear and concise description of the problem @tsdown/css currently loads Sass via loadSass() and compiles SCSS with the module-level API: const sass = await loadSass(); const result = await sass.co...
110
Reposted by Kevin Deng
npmx @npmx.dev · 11/06/2026
We've started by verifying npmx maintainers. Log in to mu.social to see the verified badges! We'd like to discuss the best strategy for our communities with OSS maintainers. Should all large enough OSS projects be verifiers? Or would it be better for a few orgs/foundations to take on the task?
48015
Reposted by Kevin Deng
Kevin Deng @sxzz.dev · 11/06/2026
Open-sourced now! github.com/regesta-dev/...
github.com
GitHub - regesta-dev/draft: Universal Package Registry Kernel
Universal Package Registry Kernel. Contribute to regesta-dev/draft development by creating an account on GitHub.
032
Kevin Deng @sxzz.dev · 10/06/2026
I deployed an instance at registry.regesta.dev If anyone is interested, I can invite you to the GitHub repo!
100
Reposted by Kevin Deng
Titus 🇵🇸 @wooorm.com · 08/06/2026
Hello friends and welcome to another “how’s ESM vs CJS doing?!” A big win this time, at a year of `require(esm)` available! 38.0% of the popular npm packages now have ESM, up from 33.4% half a year ago. ESM-only is up from 12.6% to 16.0%. Particularly this non-dual, “vanilla” growth is very big!
Graph showing the status, in raw CSV:

```csv
date,total,esm,dual,faux,cjs
2021-08-24,5617,341,95,832,4349
2021-11-09,5647,411,119,809,4308
2022-08-01,5734,496,207,791,4240
2022-11-04,5747,518,216,785,4228
2023-05-29,6240,630,417,783,4410
2023-11-22,6818,734,510,881,4693
2024-05-27,7042,819,736,826,4661
2024-11-27,8087,942,1152,843,5150
2025-06-05,8677,995,1573,859,5250
2025-12-04,14159,1779,2947,1522,7911
2026-06-08,16231,2590,3574,1689,8378
```
911123
Kevin Deng @sxzz.dev · 09/06/2026
I’m designing a transparent, ecosystem-neutral package registry. Content-addressed releases, append-only events, mirrorable state, and projections for npm/PyPI/Cargo/Go/OCI. Feedback welcome: regesta.dev
regesta.dev
Regesta
A transparent, secure, modern, scalable universal package registry.
1193
Reposted by Kevin Deng
Socket @socket.dev · 04/06/2026
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
socket.dev
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
03810
Kevin Deng @sxzz.dev · 04/06/2026
I now own VoidZero.
070
Kevin Deng @sxzz.dev · 04/06/2026
I'm designing and creating a new registry
2122
Reposted by Kevin Deng
Willow (GHOST) @willow.sh · 01/06/2026
happy pride month 🎉
npmx homepage with a pride themed npmx logo (noodle)
016525
Reposted by Kevin Deng
Rebane @rebane2001.bsky.social · 25/05/2026
i made a new game called js crossword where you have to solve it by literally writing javascript code that eval()'s into the correct values! check it out if you're into ctfs or wanna challenge your javascript skills lyra.horse/fun/jscrossw... <3
JS Crossword
a crossword where the clue = eval(answer)

Welcome to JS Crossword! Every clue is a JS eval of its answer - for example, 7 could be solved with 3+4 and [object Object] could be solved with []+{}. This crossword uses some lesser-known and cursed JS features, so I'd recommend it for people already somewhat familiar with JavaScript.

You're allowed to use the following characters: A-Za-z0-9!"()*+-./<=>[]`{}. This means that no spaces (empty squares), commas, or semicolons are allowed to be used. The crossword is case-sensitive. The final answer consists only of english words, so it must match A-Za-z.

Your answers will be evaluated within an eval() sandbox, you can try it out at the playground below. You're of course also allowed to use other resources, such as DevTools, MDN, searching etc. This crossword is human-made, so if you solve it with AI you're lame, learn to have fun.

You can change the writing direction by clicking a square or pressing ctrl. Your progress is savedbanner image - JS Crossword, a crossword where the clue = eval(answer)

a mini-crossword is pictured underneath as a visual examplegameplay screenshot showing the crossword partially filled in

the status at the bottom can be seen saying:
across (green)
expect: cw==
actual: cw==
down (red)
expect: -Infinity
error: SyntaxError: Unexpected end of input
2322358
Kevin Deng @sxzz.dev · 29/05/2026
It’s been really encouraging to see tsdown adopted by companies like @vercel.com and @cloudflare.social, as well as open-source projects like OpenClaw and LobeHub. If tsdown has been useful to you or your project, please consider sponsoring my work ❤️ github.com/rolldown/tsd...
github.com
Who's using tsdown? · rolldown tsdown · Discussion #143
Which Projects Are Using tsdown? Share Your Insights! Hey everyone! 🚀 We're curious to know which projects or teams are currently using tsdown. Whether it's a personal side project, a startup, or a...
0231
Kevin Deng @sxzz.dev · 26/05/2026
npm increasingly feels like a zombie org under GitHub. As someone who's been around the JS ecosystem and part of multiple OSS orgs for years, what I'm seeing isn't just "big co moves slow." It's quiet neglect of critical infrastructure the entire JS world runs on. A short thread 🧵
25610
Kevin Deng @sxzz.dev · 24/05/2026
PSA: the safest way to publish an npm package today is staged publish + OIDC + provenance. "But it can't stop every attack." Sure, and seatbelts don't prevent every injury either. We still wear them. Security is layers, not silver bullets.
3558
Kevin Deng @sxzz.dev · 24/05/2026
Heads up: npm's stage publish still has an unresolved issue. Toolchains can't tell if a package was published via trusted publishing once it's staged, so tools like pnpm end up showing false security downgrade warnings. github.com/pnpm/pnpm/is...
github.com
no-downgrade false positive with staged publishing · Issue #11887 · pnpm/pnpm
Verify latest release I verified that the issue exists in the latest pnpm release pnpm version 11.x Which area(s) of pnpm are affected? (leave empty if unsure) No response Link to the code that rep...
3262
Kevin Deng @sxzz.dev · 23/05/2026
The first high-impact package for staged publishing has arrived: tinyexec! @43081j.com
090
Kevin Deng @sxzz.dev · 23/05/2026
Tracking npm provenance adoption across the top ~15k high-impact packages. Now with daily trend data 📈 Since Aug 2025: • Trusted Publisher: 0.55% → 16.69% • Provenance: 6.96% → 3.14% • Untrusted: 92.49% → 80.17% Trusted Publisher adoption is climbing fast! github.com/sxzz/npm-top...
1110
Kevin Deng @sxzz.dev · 20/05/2026
The actions-cool/issues-helper compromise showed a nasty edge case: Even pinned SHAs can still break if the action repo gets disabled. I built actionspack to inline actions/workflows where possible, pin what remains, and make dependency updates visible in git diff.
050
Kevin Deng @sxzz.dev · 20/05/2026
Recent supply-chain poisoning incidents made one thing obvious: CI should not blindly trust floating @main refs. actionspack brings a pnpm-like lockfile to GitHub Actions: author in .github/workflows/src, inline safe workflows/actions, pin the rest to SHAs, and review updates with git diff.
github.com
GitHub - sxzz/actionspack: Lockfile-first GitHub Actions workflow packer
Lockfile-first GitHub Actions workflow packer. Contribute to sxzz/actionspack development by creating an account on GitHub.
3114
Kevin Deng @sxzz.dev · 07/05/2026
🚀 tsdown v0.22 is out, now powered by Rolldown 1.0.0! What’s new: ✦ Upgraded to Rolldown v1.0.0 ✦ Reduced install size by 1.33 MB ✦ Auto-detects the `bin` field ✦ Dropped support for Node.js 20, 21, and 23 ✦ `dts` is now inferred from `compilerOptions.declaration` github.com/rolldown/tsd...
github.com
Release v0.22.0 · rolldown/tsdown
🚨 Breaking Changes Drop Node.js < 22.18.0 support, make unrun optional, add tsx config loader  -  by @sxzz (a1042) dts: Auto-enable dts when tsconfig declaration is true  -  by @sxzz in #872 (0...
15511
Reposted by Kevin Deng
VoidZero @voidzero.dev · 07/05/2026
🚀Rolldown 1.0 is here!🚀 Rust-based high-performance JavaScript bundler. 🏎️ Runs at native speed that’s up 30x faster than Rollup 🤝 Compatible with existing Rollup & Vite plugins ⚡The underlying bunder for Vite After 2 years, Rolldown is officially stable and has 20+M weekly downloads.
535168
Kevin Deng @sxzz.dev · 03/05/2026
👀 tangled.org/sxzz.dev
tangled.org
sxzz.dev
sxzz.dev on Tangled
050
Kevin Deng @sxzz.dev · 01/05/2026
Node.js 20 is EOL. Say goodbye to: - tinyglobby: use `fs.glob` instead - picomatch: use `path.matchesGlob` instead - tsx: run TS files directly with type stripping only
1142
Reposted by Kevin Deng
Anthony Fu @antfu.me · 10/04/2026
`tsnapi` - a snapshot testing utility for the public API for library maintainers. Snapshots for both JavaScript and TypeScript declarations. It would help prevent unintended breaking changes on public API signatures. Thanks @sxzz.dev for the initial idea and implementation. github.com/antfu/tsnapi
github.com
GitHub - antfu/tsnapi: Library public API snapshot testing for runtime exports and type declarations.
Library public API snapshot testing for runtime exports and type declarations. - antfu/tsnapi
48312
Kevin Deng @sxzz.dev · 16/03/2026
🚀 tsdown 0.21.4 just dropped. CSS Modules are now supported. Also, the `tsdown-migrate` skill lets your agent auto-migrate from tsup to tsdown. ❯ npx skills add rolldown/tsdown --skill tsdown-migrate tsdown.dev/guide/skills
tsdown.dev
tsdown
The Elegant Bundler for Libraries
2192
Kevin Deng @sxzz.dev · 09/03/2026
I've always wanted to rewrite the `semver` package on npm — until I found that the Deno team already rewrote it in TypeScript on JSR. So I ported it to npm instead. No more excuses not to use Deno's std library in the npm ecosystem. npmx.dev/package/std-...
npmx.dev
6330
Kevin Deng @sxzz.dev · 05/03/2026
👀 Turborepo is using tsdown! github.com/vercel/turbo...
github.com
feat: Migrate from tsup to tsdown by anthonyshew · Pull Request #11649 · vercel/turborepo
Summary Migrates all TypeScript package bundling from tsup to tsdown. tsdown is built on Rolldown and provides faster builds while maintaining compatibility with tsup&#39;s configuration patterns. ...
1210
Kevin Deng @sxzz.dev · 05/03/2026
🚀 tsdown v0.21 is released now! github.com/rolldown/tsd...
github.com
Release v0.21.0 · rolldown/tsdown
v0.21.0 - Notable Changes Breaking Changes Dependency options renamed to deps namespace The dependency-related options have been moved under a new deps namespace with clearer names: external -> de...
0120
Kevin Deng @sxzz.dev · 03/03/2026
tsdown v0.21 is going to be a big one 🚀 What's new: ✦ Full CSS pipeline (Sass/Less/Stylus + Lightning CSS) ✦ Cross-platform executable builds via @tsdown/exe ✦ Dep options moved to deps namespace ✦ Node.js < 22.18.0 deprecated Try the beta: npm add tsdown@beta -D github.com/rolldown/tsd...
github.com
Release v0.21.0-beta.3 · rolldown/tsdown
v0.21.0 - Notable Changes Breaking Changes Dependency options renamed to deps namespace The dependency-related options have been moved under a new deps namespace with clearer names: external -> de...
1370
Kevin Deng @sxzz.dev · 28/02/2026
Wrote a RFC for @npmx.dev The idea: surface packages that are silently bundled inside other packages' tarballs — and show their "implied downloads". Would love feedback 👇 github.com/npmx-dev/npm... Also applied to @e18e.dev
github.com
[RFC] Surface Inline Bundled Dependencies in Package Pages · Issue #1736 · npmx-dev/npmx.dev
Summary Add first-class UI support for packages that physically inline their dependencies into their published tarball — making it possible for developers and consumers to understand what packages ...
3618
Kevin Deng @sxzz.dev · 27/02/2026
🎉 cac v7 just dropped — after 3.5 years! ✦ CJS build gone. Now pure ESM! ✦ No more Node.js APIs — runs in any JS runtime, even browsers ✦ Deno? It's on JSR now ✦ Repo refreshed with Vitest / tsdown / npmx Thanks @egoist.dev for passing the torch 🙌 npmx.dev/package/cac
npmx.dev
cac - npmx
Simple yet powerful framework for building command-line apps.
2381
Kevin Deng @sxzz.dev · 26/02/2026
🚀 Coming in the next version of tsdown: built-in Node.js SEA (Single Executable Applications) support! Now you can bundle your JS apps into a standalone executable with a single command: tsdown --exe
48813
Reposted by Kevin Deng
npmx @npmx.dev · 13/02/2026
see y'all in a week 👋
npmx.dev
on vacation - npmx
The npmx team is recharging. Discord reopens in a week.
415016
Kevin Deng @sxzz.dev · 08/02/2026
ESLint v10 ships with a Node.js version requirement that necessitates `require(esm)`, yet the package remains CJS only. Why?
2232