Lost my ~260 day streak on chess.com today. Silly things like “work” cost me my dream of playing one game a day for a year and not getting any better.
Wes
@notwes.bsky.social
ATX - he/him - 🥂Humans are more important than code - I work at an entertainment company and volunteer my time making art on github https://github.com/wesleytodd
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
While I have spent the past 5 years doing the RV each summer, this was the first one that actually felt like a "summer vacation". - 2w off, sailing on Monterey Bay, campfires, Big Sur - 1w in the office - 1w at a work offsite - Golf trip with friends in MI - 1w doing RV repairs/clean & getting home
There is CSS... but what if I told you there is such a thing as DSS? Dependency Selector Syntax is an expressive DSL written as a homage to CSS. Use it to inspect malicious dependencies in your repo docs.vlt.io/cli/selector...
it is incredibly stupid to generate blog posts with llms anyone can output the same thing with the same prompts. If they’re interested in reading that, let them write the prompts. if it’s a writing skill issue on your end… failing at writing is how you get better at writing.
it's time
Had a great time sailing on Monterey Bay this morning. First time sailing on the open ocean, it was awesome. Highly recommend.
I’m in a Waymo right now, my second of the week, Waymo’s have the exact same problem that AI does. It means I don’t get to interact with any other humans. It’s isolating and lonely and worse for humanity.
So far the the benefits touted from this shift in the way we work is *entirely* to the benefit of value extractors or things that detract from community. "I am so much more productive at work..." and "it lets me become a full company by myself".
I mean it was last year when I last saw you @pfrazee.com, but I did not expect that amazingly beautiful beard in such a short time 🤣
@pfrazee.com and @dholms.at of @bsky.app are coming to DWeb Camp with “Start From Scale: Building an Open Network for the Real World” https://talx.dod.ngo/dwebcamp-2026/talk/ENYZUU/ 👉 Check out their other talks and the full schedule here: https://dwebcamp.org/schedule
I bought two computers last year because I was nearly positive this would happen. A mac and a razer. Glad but not happy I was right.
‘The company briefly took down its Apple Online Store early this morning as it typically does when announcing new products. When it came back online, the price tags for Mac computers rose roughly 15% to 20% and iPad prices rose 15% to 25%.’ (gift) www.wsj.com/tech/apple-r...
📢 CFP EXTENDED: NodeConf EU 2026 — Bologna, Italy We pushed the Call for Papers deadline to **June 30th**. One more week to send your talk. Node.js maintainers, production engineers, runtime nerds, tooling builders => we want your session.
It's Monday, I am very busy, but.... All I want to know when the final patch for @factorio.com comes out. I should focus on the stuff I am supposed to be doing, but its supposed to be some time this week so.....when is it?
Always glad to see folks talk about the main reason I find this new world we have created so distasteful. Call me crazy, but I think we *can* care about the human impact and also have new technologies.
Suraj has a point.
🔐 A thing many people miss: Node.js trusts the code you install by default. So blocking npm install scripts closes one door and leaves another wide open, the one that opens when you require() the package. nodesource.com/blog/npm-v12...
Blocking Install Scripts Is Not a Silver Bullet
npm v12 blocks install scripts by default, but supply chain attacks won't disappear. Learn why runtime execution, the Node.js permission model, and sandboxing still matter.
nodesource.com
Upcoming npm v12 will disable preinstall, install, and postinstall scripts from dependencies unless allow-listed. You can prepare for this change using npm v11 now: github.com/orgs/communi...
Preparing for npm v12: install scripts and non-registry sources become opt-in · community · Discussion #198547
Hi everyone — sharing this so maintainers, application developers, and CI operators have time to prepare for behavioral changes landing in npm v12 (estimated July 2026). Everything below is already...
github.com
explain your @ I am (not) Wes. Wes is really my middle name. And somehow despite being an elder and getting my invite directly from @pfrazee.com, there is an inactive but more elder @wes.bsky.social. Such a waste of the @.
explain your @ I know a decent bit about the PDS and atmosphere account migration process. @jimray.bsky.team dubbed me “The PDS Dad.” It stuck.
RE: https://mastodon.social/@campuscodi/116756737024675823 I’m not surprised that SBOM adoption is so low, almost all the efforts around SBOMs have been compliance theatre, not actually tackling the hard work of working out which software is being packaged. There’s also zero incentives for […]
Original post on mastodon.social
mastodon.social
🚨 High-severity security fix in undici (7.28.0, 8.5.0) just released! Patches CVE-2026-9697. undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent. github.com/nodejs/undic...
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
## Impact undici's `ProxyAgent` silently drops the `requestTls` option when configured with a SOCKS5 proxy URI (`socks5://` or `socks://`). The target HTTPS connection through the SOCKS5 tunnel ...
github.com
I usually don’t relate to tiktok relationship memes. But I just saw this compilation where all these guys let their GFs order ice cream first then said “that’s all, I’m not getting anything” and that got me. 🤣🫡
I feel bad because I probably came across as ungrateful or snarky, but I just had to tell a maintainer reviewing a PR I opened that I just don't have time to deal with their toolchain.
This is how you do it. Great to hear this from @cloudflare.social. 🎉
We've been working with folks from Cloudflare for a long time, and I've seen how important Vite is to them. It's telling that their first move is a $1M fund for maintainers in the ecosystem. Together with Vite's OC funds, this is a ton of support for independent devs. Massive waves ahead.
More musings after some people got upset about the word clanker. lucumr.pocoo.org/2026/5/26/cl...
Clanker: A Word For The Machine
Why I like the word clanker and why machines are not people.
lucumr.pocoo.org
Looks like support for staged publishing is coming to pnpm already thanks to @jovidecroock.com & @kochan.io 🎉
feat: add pnpm stage command by JoviDeCroock · Pull Request #11863 · pnpm/pnpm
NoteThis is largely authored by GPT5.5 based on the npm/cli PR's, afterwards it needed some guidance to better adhere to the repository standards. Resolves #11796 Summary Implements npm's ...
github.com
When your repository reaches 1,000 stars or so on GitHub, it warns you about having more admin-level contributors in case of a bus factor. What it should do is mail you two yubikeys for free.
There is a person in disguise (fake mustache, sunglasses, hair cap, etc) who just sat down next to me with a laptop and pretended to type on the login screen then closed their laptop. I love my local coffee shop.