npm still recommends a trusted publishing workflow that allows any jobs and steps to publish, instead of limiting to just one step or publish flow (which is easily possible with tokens before). amazing.
Bjorn Lu
@bluwy.me
🇲🇾 Web dev. Building tools for fun. @vite.dev core team member. Something something opinions.
npm still recommends a trusted publishing workflow that allows any jobs and steps to publish, instead of limiting to just one step or publish flow (which is easily possible with tokens before). amazing.
I re-watched last year Joyee's @webengineshackfest.org talk. I can't recommend it enough. There are many lessons on the require(esm) story. If you want adoption, meet developers where they are, build bridges for them to move to the future you want.
Joyee Cheung - Bridging CommonJS and ESM in Node.js
YouTube video by Web Engines Hackfest
m.youtube.com
Among the big corpos in web dev lately, I’m happy it was Cloudflare. The smart folks from VZ deserve it too.
VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone. https://cfl.re/4dR0LYA
VoidZero is joining Cloudflare
VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone.
blog.cloudflare.com
Today, VoidZero joins Cloudflare. Vite remains MIT, vendor-neutral, and stewarded by the same wider team. The same goes for Vitest, Rolldown, and Oxc. Cloudflare is also committing $1M to an OSS fund to support independent development in the Vite ecosystem.
Cloudflare supports Vite's mission
The VoidZero team is joining Cloudflare. Vite remains MIT, vendor-neutral and stewarded by the same wider team.
vite.dev
You now do not need the Changesets bot for automatic PR comments. Use GitHub Actions instead! With two new sub-actions: - `changesets/action/pr-status` - `changesets/action/pr-comment` Set up a workflow like below to automate it yourself. Or check out the action docs: github.com/changesets/a...
We’ve been working on a new site for Changesets with a lot of new docs! If changesets has been confusing before, hopefully some of these will help, or let us know what else could be improved. Check it out 👉 changesets.dev
Changesets
A tool to manage versioning and changelogs with a focus on monorepos
changesets.dev
Two less extensions to install for me. Pretty nice!
The new @code release adds Mermaid diagram rendering directly in the Markdown preview. The Integrated Browser also now supports HTML file previews and drag-to-select for pulling multiple page elements into chat context.
In node-modules-inspector@2.1.0, we added a new report page "Maintainer Actions", which lists actionable changes for package maintainers to move the ecosystem forward. With pre-constructed prompts to copy if you want agents to do that for you. github.com/antfu/node-m...
The latest npm security incident has a slightly different shape but would still have been mitigated by what I suggested back in January. humanwhocodes.com/blog/2026/01...
How GitHub could secure npm - Human Who Codes
Why doesn't npm detect compromised packages the way credit card companies detect fraud?
humanwhocodes.com
Just released a new version of github.com/bluwy/npm-us... to fix the dark mode syntax highlighting issues. Apparently it's using the GitHub Light theme in dark mode, now swapped to GitHub Dark. Before / After:
FYI if you use pnpm and upgraded from Vite 7 -> 8, you might still have esbuild installed but unused. You can purge it out by: 1. Set `autoInstallPeers: false` in `pnpm-workspace.yaml` 2. `pnpm i` 3. Undo no1 4. `pnpm i`
The little things! This should help me clear my backlogs better
New Sort by control added to Notifications - GitHub Changelog
A new “Sort by” control appears on the Notifications page, with two options: Newest to oldest (which matches the previous behavior) and Oldest to newest. The selected sort order applies…
github.blog
Just published a new version of `create-vite-extra` matching the new designs and setup from `create-vite`!
GitHub - bluwy/create-vite-extra: Extra Vite templates
Extra Vite templates. Contribute to bluwy/create-vite-extra development by creating an account on GitHub.
github.com
Made a site to compare projects on Open Collective. Some are managing funds really well while others are burning through quite a bit. octrends.bjornlu.com
Join the Vite ecosystem tomorrow to celebrate the Vite Team 5th Anniversary by rewatching together the Vite Documentary! Let's remember the stories of the people who connected to extend together our shared commons. And stay at 3:45 PM UTC to participate in the live stage after the movie 💜
5th anniversary of the Vite Team Creation
Vite: The Documentary re-premiere. Join the ecosystem this March 19th at 3 PM UTC to remember the story we wrote together. And participate in the live stage to discuss our past, present, and future. W...
vite.dev
⚡️ Vite 8.0 is here! The most significant architectural change since Vite 2. ⏬ Powered by @rolldown.rs bringing faster production builds and more consistency 🛤️ New features such as tsconfig paths and emitDecoratorMetadata support vite.dev/blog/announc...
Vite 8.0 is out!
Vite 8 Release Announcement
vite.dev
We're joining with the Vite team to re-premiere our Vite documentary!⚡️ 📅 Happening 19th March at 4pm CET | 10am CST 📺 Screening on the Vite website 💬 Followed by a live stage on Discord with Vite devs from the film Come hang out!
5th anniversary of the Vite Team Creation
Vite: The Documentary re-premiere. Join the ecosystem this March 19th at 3 PM UTC to remember the story we wrote together. And participate in the live stage to discuss our past, present, and future. W...
vite.dev
Just as I was about to go on vacation too, npmx knows me well
see y'all in a week 👋