Andrey Sitnik

@en.sitnik.es

The creator of PostCSS. I write about Barcelona, Local-First, kinky events, languages, and crazy facts from Wikipedia. https://sitnik.es Russian: @ru.sitnik.es Ex-life: https://twitter.com/andreysitnik https://twitter.com/sitnikcode

Almost full Russian Cyrillic alphabet but with the most strange-looking letter forms from the Old Novgorodian birch-bark letters. By Maxim Persikov.

Bild

Popular npm packages keyv and cacheable were hijacked, and malicious versions containing a malware were released to steal users’ access tokens. Protect your packages from the same fate with my guide, based on maintaining PostCSS and 100+ other projects: evilmartians.com/chronicles/t...

@sitnik_en@mastodon.social (@sitnikcode) on X

Popular npm packages Keyv and Cacheable were hijacked, and malicious versions containing a malware were released to steal users’ access tokens. Protect your packages from the same fate with my guide,...

x.com

Watched the Chinese animated film Nobody with my family, and we loved it. The filmmakers found a fresh take on Journey to the West, a classic that’s been adapted countless times. Gorgeous backgrounds, a distinctive story, and no attempt to imitate Hollywood.

Bild

Буквы Q, W и X были запрещены в Турции. Например, в 2006 мэра суди за то что поздравил людей с Newroz вместо Nevroz. Это начали ради нового стандарта турецкого, где ушли от этих букв. Но по факту, это было подавлением курдского языка, где есть эти буквы. en.wikipedia.org/wiki/Prohibi...

Bild

The SCREEN Act is not just another age-verification bill — it goes much further than anything passed at the state-level or in other countries. 1. The bill doesn't just target porn sites. It goes after *any* site that allows material "harmful" to minors. You'd have to scan your face to use Google.

(3) COVERED PLATFORM.— The term "covered platform" -
(A) means an entity -
(i) that is an interactive computer service;
(ii) that-
(I) is engaged in interstate or foreign commerce;
or
(Il) purposefully avails itself of the United States
market or a portion thereof; and
(iïi) for which it is in the regular course of the trade or
business of the entity to create, host, or make available content that meets the definition of harmful to minors under paragraph (4) and that is provided by the entity, a user, or other intration conten provider, with

Deforestation isn’t a modern phenomenon. Humans have been clearing forests for thousands of years. Reforestation is. Once countries reach a certain level of economic development, forest cover often starts to recover.

Bild

Reminder: Spain’s total solar eclipse is coming on August 12. If you live here, don’t miss it. Use an AI to plan your trip, but double-check the viewing spot (the Sun will be very low on the horizon) and buy certified eclipse glasses. It’s unforgettable.

About 25,000 migrants (50% of those who entered Ceuta) already have returned to Morocco after realizing they would not be able to legalize their status in Spain. Around 150 people per minute are now crossing back. www.ultimahora.es/noticias/nac...

El Gobierno estima en 25.000 los inmigrantes que han retornado a Marruecos desde Ceuta hasta este mediodía

Interior calcula que cerca de la mitad de las personas llegadas durante la crisis migratoria ya han regresado al país vecino

ultimahora.es

While some people laughed about the number of dependencies in the JS world, others worked to improve the ecosystem (like @e18e.dev). Now many of my open source projects have around 20 packages in node_modules, including transitive dependencies.

Bild

Supply chain attacks stealing npm packages are a real threat, with new attacks monthly. But an npm package doesn’t need to be famous to become a target. Check this new post from @en.sitnik.es on the secure release setup made from our experience with 100+ open-source projects. Agent skill inside.

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog

How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

evilmartians.com

My new article is out! A systematic guide to releasing npm packages as safely as possible in 2026 (with a Skill to quickly apply the practices to your open source projects). Not just “do X”: I cover real supply chain attacks and explain how each defense helps. evilmartians.com/chronicles/t...

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog

How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

evilmartians.com