Sign in

Kevin Deng

@sxzz.dev
1.6K followers 310 following 307 posts

github.com/sxzz • 🏳️‍🌈 Gen Z • indie OSS developer sponsored by @voidzero.dev @vuejs.org @vite.dev @vue-macros.dev @vueuse.org @unjs.io @rolldown.rs elk.zone More at sxzz.dev

PostsRepliesMedia
Reposted by Kevin Deng
Anthony Fu @antfu.me · 16/09/2026
It's been a while... Introducing Devframe v1.0 🚀 The framework for building DevTools that can run everywhere, for any meta-framework, for both humans and agents. Check out the announcement post and join our Discord 👇
devfra.me
Pluggable, Extensible, and Playful DevTools
Introduction to Devframe, a framework for building pluggable, extensible, and playful DevTools.
614630
Reposted by Kevin Deng
Rick Viscomi @rviscomi.dev · 08/09/2026
I wrote this one! 🙋‍♂️ In CJK languages, hitting Enter to confirm an IME candidate can accidentally submit the form in chat textareas The guide shows how to safely implement "Enter to submit" including how to work around a Safari event-ordering bug with isComposing github.com/GoogleChrome...
github.com
modern-web-guidance/skills/modern-web-guidance/guides/forms/ime-safe-enter-submit.md at v0.0.186 · GoogleChrome/modern-web-guidance
Keep your coding agent up to date with the latest web best practices - GoogleChrome/modern-web-guidance
0162
Kevin Deng @sxzz.dev · 04/09/2026
I guess it should work with tsdown after this PR github.com/sxzz/rolldow...
github.com
feat!: add tsgo API and VFS support by sxzz · Pull Request #290 · sxzz/rolldown-plugin-dts
Summary replace the tsgo CLI implementation with the asynchronous declaration emit API add tsgo.moduleUrl, defaulting to import.meta.resolve("typescript"), with capability-based API dete...
130
Kevin Deng @sxzz.dev · 01/09/2026
❤️
020
Reposted by Kevin Deng
Roman @rman.dev · 01/09/2026
I just sponsored sxzz. Go sponsor your open source dependencies!
github.com
Sponsor @sxzz on GitHub Sponsors
An open sourceror. Working on Vue, Vite, VueUse, and their ecosystems.
1141
Kevin Deng @sxzz.dev · 30/08/2026
This has nothing to do with CJS-ESM interoperability. The performance overhead exists even in pure ESM packages. See x.com/_pi0_/status...
x.com
Pooya Parsa 🦋 (@_pi0_) on X
🏎️ perf tip of the day: If your ESM package uses "type": "module" and ships .js files, Node.js must find, read, and parse package.json to determine their format. Shipping .mjs avoids all this runtim...
110
Reposted by Kevin Deng
Andrew Branch @andrewbran.ch · 15/08/2026
If you’re not stalking TypeScript PRs, you might be surprised how much you can do with the API in nightlies (and even in 7.0 stable), so here’s a tiny demo that I think hits some of the highlights. 🧵
A package.json in VS Code after npm installing typescript@next
412720
Kevin Deng @sxzz.dev · 13/08/2026
Changesets is using tsdown
091
Kevin Deng @sxzz.dev · 06/08/2026
Just like this is Johnson’s project, he can do whatever he wants. After using such disrespectful language toward someone (regardless of where), I thought you knew you could always directly fork an OSS project instead of impotently raging like an asshole. No community welcomes you.
040
Kevin Deng @sxzz.dev · 05/08/2026
I think that’s mostly a browser concern. IoT clients generally don’t implement HSTS (or preload lists), so they can still talk over plain HTTP even if a browser would automatically upgrade the same hostname to HTTPS.
120
Kevin Deng @sxzz.dev · 05/08/2026
I was reading about the HSTS preload list today, and one thing that caught me by surprise is that whether HTTPS is enforced seems to depend on the TLD.
120
Kevin Deng @sxzz.dev · 05/08/2026
TIL: Domains like .dev, .app are required to use HTTPS.
181
Kevin Deng @sxzz.dev · 27/07/2026
There is always a trade-off for safety and convenience.
100
Kevin Deng @sxzz.dev · 26/07/2026
❯ pnpm run release && claude --dangerously-skip-permissions /review-npm-stage github.com/sxzz/review-...
github.com
GitHub - sxzz/review-npm-stage
Contribute to sxzz/review-npm-stage development by creating an account on GitHub.
170
Kevin Deng @sxzz.dev · 23/07/2026
> test fixtures are derived from node-semver under the ISC license If you find any inconsistencies, please feel free to open an issue.
120
Kevin Deng @sxzz.dev · 23/07/2026
Glad to help move the ecosystem toward: - ESM-only - TypeScript - OIDC + staged publishing - Runtime-agnostic design wherever possible - No bundled deps unless needed - Like-minded dependencies I’ve replaced `debug` and `semver` with `obug` and `verkit`. What’s next? 🤔
3472
Kevin Deng @sxzz.dev · 21/07/2026
original image: github.com/sxzz/tsdown-...
030
Kevin Deng @sxzz.dev · 21/07/2026
The tsdown ecosystem, visualized ✨ Each circle = a project owner using tsdown, sized by GitHub stars. 873 projects over 100 stars and counting. Grateful to everyone shipping with it.
1252
Reposted by Kevin Deng
Antoine @antleth.fr · 16/07/2026
magic-string got more than half smaller btw!
Package size dropping from ~600kB to 305kB, making it 56% smaller
2302
Kevin Deng @sxzz.dev · 16/07/2026
Volar now has first-class support in tsdown and rolldown-plugin-dts. It can generate `.d.ts` files for all file types supported by Volar, including Vue and Astro. github.com/sxzz/rolldow...
github.com
feat: support multiple volar plugins · sxzz/rolldown-plugin-dts@7cb4ee8
090
Reposted by Kevin Deng
Anthony Fu @antfu.me · 16/07/2026
magic-string v1.0.0 gets released with pure-ESM, thanks to @sxzz.dev!
github.com
Release v1.0.0 · Rich-Harris/magic-string
In magic-string v1.0.0, it's now pure ESM, and the type declarations are built from the TypeScript source. This means the previous CJS, UMD, and IIFE builds are now dropped as we believe the ecosys...
1664
Kevin Deng @sxzz.dev · 16/07/2026
🎉 magic-string is now fully migrated to pure ESM and TypeScript, and its long-awaited v1.0 release is finally here! github.com/Rich-Harris/...
github.com
feat!: migrate build to pure ESM and TypeScript by sxzz · Pull Request #310 · Rich-Harris/magic-string
closes #309, closes #301
2315
Kevin Deng @sxzz.dev · 12/07/2026
⚡ After `rolldown-plugin-dts` migrated Babel toolchain to yuku, tsdown has cut ~5 MB from its install size and is now smaller than tsup. ❤️ Huge thanks to arshad-yaseen for the help!
0230
Kevin Deng @sxzz.dev · 08/07/2026
i am cool
190
Kevin Deng @sxzz.dev · 06/07/2026
tsdown #1000 issue github.com/rolldown/tsd...
github.com
@tsdown/css should reuse sass-embedded AsyncCompiler instead of spawning a compiler per SCSS transform · Issue #1000 · rolldown/tsdown
Clear and concise description of the problem @tsdown/css currently loads Sass via loadSass() and compiles SCSS with the module-level API: const sass = await loadSass(); const result = await sass.co...
110
Reposted by Kevin Deng
npmx @npmx.dev · 11/06/2026
We've started by verifying npmx maintainers. Log in to mu.social to see the verified badges! We'd like to discuss the best strategy for our communities with OSS maintainers. Should all large enough OSS projects be verifiers? Or would it be better for a few orgs/foundations to take on the task?
48015
Reposted by Kevin Deng
Kevin Deng @sxzz.dev · 11/06/2026
Open-sourced now! github.com/regesta-dev/...
github.com
GitHub - regesta-dev/draft: Universal Package Registry Kernel
Universal Package Registry Kernel. Contribute to regesta-dev/draft development by creating an account on GitHub.
032
Kevin Deng @sxzz.dev · 11/06/2026
Open-sourced now! github.com/regesta-dev/...
github.com
GitHub - regesta-dev/draft: Universal Package Registry Kernel
Universal Package Registry Kernel. Contribute to regesta-dev/draft development by creating an account on GitHub.
032
Kevin Deng @sxzz.dev · 10/06/2026
Try it via: pnpm i @sxzz.dev/hello-regesta --registry=https://npm.regesta.dev
110
Kevin Deng @sxzz.dev · 10/06/2026
I deployed an instance at registry.regesta.dev If anyone is interested, I can invite you to the GitHub repo!
100
Reposted by Kevin Deng
Titus 🇵🇸 @wooorm.com · 08/06/2026
Hello friends and welcome to another “how’s ESM vs CJS doing?!” A big win this time, at a year of `require(esm)` available! 38.0% of the popular npm packages now have ESM, up from 33.4% half a year ago. ESM-only is up from 12.6% to 16.0%. Particularly this non-dual, “vanilla” growth is very big!
Graph showing the status, in raw CSV:

```csv
date,total,esm,dual,faux,cjs
2021-08-24,5617,341,95,832,4349
2021-11-09,5647,411,119,809,4308
2022-08-01,5734,496,207,791,4240
2022-11-04,5747,518,216,785,4228
2023-05-29,6240,630,417,783,4410
2023-11-22,6818,734,510,881,4693
2024-05-27,7042,819,736,826,4661
2024-11-27,8087,942,1152,843,5150
2025-06-05,8677,995,1573,859,5250
2025-12-04,14159,1779,2947,1522,7911
2026-06-08,16231,2590,3574,1689,8378
```
911123
Kevin Deng @sxzz.dev · 09/06/2026
I’m designing a transparent, ecosystem-neutral package registry. Content-addressed releases, append-only events, mirrorable state, and projections for npm/PyPI/Cargo/Go/OCI. Feedback welcome: regesta.dev
regesta.dev
Regesta
A transparent, secure, modern, scalable universal package registry.
1193
Kevin Deng @sxzz.dev · 08/06/2026
TIL
010
Kevin Deng @sxzz.dev · 04/06/2026
What I’m designing isn’t exactly a decentralized registry. The goal is to make it more transparent and easier to oversee. ATM, I only have a very rough prototype, and that was even partly written with AI's help, so I probably still need more time to think it through properly.
120
Reposted by Kevin Deng
Socket @socket.dev · 04/06/2026
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
socket.dev
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
03810
Kevin Deng @sxzz.dev · 04/06/2026
I hope so, but for now, it is just my own personal exploration.
040
Kevin Deng @sxzz.dev · 04/06/2026
I now own VoidZero.
070
Kevin Deng @sxzz.dev · 04/06/2026
I'm designing and creating a new registry
2122
Kevin Deng @sxzz.dev · 01/06/2026
XD
010
Reposted by Kevin Deng
Willow (GHOST) @willow.sh · 01/06/2026
happy pride month 🎉
npmx homepage with a pride themed npmx logo (noodle)
016525
Reposted by Kevin Deng
Rebane @rebane2001.bsky.social · 25/05/2026
i made a new game called js crossword where you have to solve it by literally writing javascript code that eval()'s into the correct values! check it out if you're into ctfs or wanna challenge your javascript skills lyra.horse/fun/jscrossw... <3
JS Crossword
a crossword where the clue = eval(answer)

Welcome to JS Crossword! Every clue is a JS eval of its answer - for example, 7 could be solved with 3+4 and [object Object] could be solved with []+{}. This crossword uses some lesser-known and cursed JS features, so I'd recommend it for people already somewhat familiar with JavaScript.

You're allowed to use the following characters: A-Za-z0-9!"()*+-./<=>[]`{}. This means that no spaces (empty squares), commas, or semicolons are allowed to be used. The crossword is case-sensitive. The final answer consists only of english words, so it must match A-Za-z.

Your answers will be evaluated within an eval() sandbox, you can try it out at the playground below. You're of course also allowed to use other resources, such as DevTools, MDN, searching etc. This crossword is human-made, so if you solve it with AI you're lame, learn to have fun.

You can change the writing direction by clicking a square or pressing ctrl. Your progress is savedbanner image - JS Crossword, a crossword where the clue = eval(answer)

a mini-crossword is pictured underneath as a visual examplegameplay screenshot showing the crossword partially filled in

the status at the bottom can be seen saying:
across (green)
expect: cw==
actual: cw==
down (red)
expect: -Infinity
error: SyntaxError: Unexpected end of input
2322358
Kevin Deng @sxzz.dev · 29/05/2026
It’s been really encouraging to see tsdown adopted by companies like @vercel.com and @cloudflare.social, as well as open-source projects like OpenClaw and LobeHub. If tsdown has been useful to you or your project, please consider sponsoring my work ❤️ github.com/rolldown/tsd...
github.com
Who's using tsdown? · rolldown tsdown · Discussion #143
Which Projects Are Using tsdown? Share Your Insights! Hey everyone! 🚀 We're curious to know which projects or teams are currently using tsdown. Whether it's a personal side project, a startup, or a...
0231
Kevin Deng @sxzz.dev · 26/05/2026
I created an issue on JSR, but unfortunately, nine months have passed and I still haven't received any official response. Maybe I should go to the Deno main repo and open an issue instead. github.com/jsr-io/jsr-n...
github.com
Support Resolve pnpm catalogs · Issue #132 · jsr-io/jsr-npm
Reproduction repo: https://github.com/rolldown/tsdown See pnpm catalogs ❯ pnpx jsr publish Checking for slow types in the public API... Ignoring failed to resolve package.json dependency. Invalid v...
110
Kevin Deng @sxzz.dev · 26/05/2026
Yeah, I think it's still too early to publish this article. We should wait until npm is ready before we post it.
130
Kevin Deng @sxzz.dev · 26/05/2026
Of course, none of this works unless someone's still home to merge PRs and ship releases. Open sourcing without staffing maintainers is just dumping a tarball over the wall. The community side and the maintainer side have to land together.
010
Kevin Deng @sxzz.dev · 26/05/2026
That's what issues, PRs and discussions actually mean. When you hit a bug, you can submit a PR and fix it yourself, instead of waiting in the dark for some unknown release date. Right now, the npm feedback loop is broken. You report, you wait, you give up.
110
Kevin Deng @sxzz.dev · 26/05/2026
Agreed, just open sourcing the code isn't the answer on its own. The way I see it, open sourcing isn't really about the code being public. It's about activating a community. The community is the point. The repo is just the entry door.
130
Kevin Deng @sxzz.dev · 26/05/2026
`npx jsr publish` literally downloads a Deno binary under the hood. The actual publish logic lives in Deno, not the JSR CLI. So when "JSR CLI" misbehaves, the fix often has to land in the Deno repo. That's not what a neutral, ecosystem wide registry should look like to me.
150
Kevin Deng @sxzz.dev · 26/05/2026
I've actually tried publishing to JSR, and a few real issues stopped me. Looks like JSR packages don't work with pnpm catalog. But the bigger problem: JSR is too tightly coupled to Deno. A registry should be runtime neutral.
130
Kevin Deng @sxzz.dev · 26/05/2026
One last thing, more personal. Going through pages of broken links from the old npm community, the thought that keeps hitting me: this community is dead. Not slow. Not neglected. Dead. @github.com, @microsoft.com, @npmjs.bsky.social team: open the registry. Staff the trackers. Show up. /end
1130