Philippe Serhal

@philippeserhal.com

💼 Staff Engineer @netlify.com, integrating all the frameworks 🔨 Open source maintainer @npmx.dev 🏡 https://philippeserhal.com

Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying

🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all affected packages/versions.

Socket@socket.dev · yesterday

🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

🧾 Introducing npm.tax Estimate the probability of being impacted by a breach in your npm supply chain. Adjust the knobs to see how slimming your node_modules lowers your risk. Look up a package to see its own risk profile, then share the report, e.g. npm.tax?direct=59&tr.... What's your npm tax?

npm.tax: npm supply-chain risk explorer

Explore how your code, npm dependency count, breach probability, and time horizon combine into cumulative supply-chain risk.

npm.tax

ANNOUNCEMENT: I’ve been working on putting together something between a retreat and a hackathon for #atproto builders for the past several weeks. I’ve been in discussion with potential funders and some funding has become available to make this a reality. now, I need your help!! KEEP READING 👇🏽

the bsky design team is working on communities and looking for feedback. one core idea we have is builders should be able to create apps and websites for their communities. they shouldn't only show up on bsky. community builders: would you want to create a separate custom app/site?

this year i've carved a big chunk of my time out to officially work on OSS. if you like what I do, or use the things I work on, sponsorships go a long way. these help me keep the balance I have, and allow me to dedicate a lot more time to open source. thank you to those who already sponsor me 💙

Sponsor @43081j on GitHub Sponsors

Maintainer of clack, chai, parse5, unjs, vueuse, tinylibs, & more. One of the e18e.dev leads. Core contributor to lit and modernweb.

github.com

Worry no more about your colleagues accidentally publishing a wide-open internal financial report microsite to the internet from ChatGPT. Hypothetically, right? 🔒 New sites are now private by default. Opt in to make it public with one click.

Netlify@netlify.com · last wk.

For most of Netlify's history, every new project deployed straight to a public URL. That made sense when going live took real effort. Now a deploy is often a work in progress: prototypes, internal tools, early client work, agent builds. So new projects can start private. ntl.fyi/4yF4LU9

diagnose me: ❯ vite dev Port 3000 is in use, trying another one... Port 3001 is in use, trying another one... Port 3002 is in use, trying another one... Port 3003 is in use, trying another one... VITE v8.1.5 ready in 3134 ms ➜ Local: localhost:3004