naugtur

@naugtur.pl

Working on supply chain security for JS. LavaMoat and Endo contributor. meet.js Poland organizer. Node.js user since v0.8. TC39 noobie. Addicted to teaching. https://naugtur.pl

No the problem is the entitlment of users. You are not entitled to conscript someone’s labor and then harass him because they disapprove of the tools he used to make Linux support possible. What it shows is that even when you arent paying for a product you can become a fucking Karen.

Resharc@reshar.cc · yesterday

the whole paint.net debacle is an interesting microcosm of a wider problem in software engineering, where developers seem to have no interaction with their users or put any effort into understanding them, and end up being surprised when they piss them off

What if our ears were like our eyes, and only had three (types of) receptors? Interestingly speech is still more or less intelligible, but not much else to me this shows how much more discriminating of frequencies our hearing is than our vision. Of course our vision has much more spatial resolution

I have 27 vulnerabilities to triage and 31 confirmed ones to publish a fix for. This is not really sustainable long-term. How can one fund all of this work?

The Rustification of #JavaScript tooling continues: @pnpm.io 12 has been rewritten in Rust, with installs up to 90% faster in testing. Other highlights: project-aware global bins, registry revisions, and deterministic lockfiles for cyclic dependency graphs. socket.dev/blog/pnpm-12

pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%

pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

socket.dev

The only real signal for whether to trust a package is what the code actually does. Does it hit the network? Read your filesystem? Grab your API keys and env vars? Everything else is a proxy. There's no replacement for reading the code:

4 weeks left until #NodeConf EU 2026. If you touch #Node.js in production, this is the conference where you stop explaining your job and start arguing about it with people who get it. 📍 September 29–30, Bologna, Italy. 🎟️ Grab your tickets now ti.to/apropos/node... #NodeJS #NodeConfEU #JavaScript

NodeConf EU 2026

NodeConf EU is heading to Italy. After years of gathering on a secluded Irish island, Europe’s longest-running Node.js conference finds a new home in Bologna, a city full of history and energy. The…

ti.to

Some of you may remember the halting struggle to establish netiquette: rules of interaction on the internet. I believe it to be a matter of “aitiquette” that we keep bots out of human spaces. We should not impose AI on anyone.

I am genuinely surprised that people don’t know that copyleft exists to facilitate this exact arrangement and that even Stallman thinks that this is the GPL working as designed. Microsoft contributes massively to the Linux kernel and helps pay the salaries of Linus, Greg, and many many more.

jake@yetanotheruseless.com · 6d ago

Copyleft is a waste of time IMO. It was supposed to protect eg Linux from getting co-opted by in particular, MSFT. How well did that work out? MSFT basically ships it with Windows and makes billions off it in Azure. So “protected”. 🙄

Oh cool, I was called a "piece of garbage" from a "vomit-party" by the Neovim developer. I'm glad I started switching to Emacs... This is no way to treat your users. Specially so when they're calling out a literal white supremacist on your front page: github.com/neovim/neovi...

GitHub issue thread DHH #501 (Closed). Comment from aris-mav 19h ago: "#504 has been merged, so I guess the matter is more or less resolved" with 1 reaction. Comment from justinmk (Developer) 19h ago: "You all have embarrassed and shamed yourselves. Most of you aren't Neovim users, but a drive-by mob, swirling from one mindless vomit-party to another, like the pacific garbage patch." Issue closed as completed 19h ago by justinmk. Neovim locked as spam and limited conversation to collaborators 19h ago.

this is pretty crazy, US is designating a small italian tech company as a terrorist org. whats next, declaring Signal a terrorist org for allowing encrypted chats? claiming libraries are terrorist orgs for hosting "violent left wing" books? this is some dark shit man

Robin Berjon@robin.berjon.com · last wk.

The US State Department has designated A/I, a small Italian provider of open source infrastructure for political activists, as a global terrorist group. They will reach into our very homes to grab us — if we let them. www.state.gov/releases/off...