Effection 4.1 is out: ⚡️ faster runtime, package half the size 🤝 support for JavaScript's explicit resource management 🧬 New `experimental` entry: Contextual APIs, our take on algebraic effects frontside.com/effection/bl...
frontside.com
Jacob Bolda
@jacobbolda.com
Board and Core Team @tauri.app Senior Software Engineer @frontside.bsky.social | Consulting for Fortune 100 | frontside.com 📺 watch | youtube.com/@JacobBolda 📖 read | www.jacobbolda.com 🧑💻 code | github.com/jbolda
Effection 4.1 is out: ⚡️ faster runtime, package half the size 🤝 support for JavaScript's explicit resource management 🧬 New `experimental` entry: Contextual APIs, our take on algebraic effects frontside.com/effection/bl...
frontside.com
omg, how did I not notice that dependabot can exclude folders now?
When you don't touch a project for a bit and all your deps are behind...
more coming soon. exciting stuff that's gonna bring new life to the javascript ecosystem & tty envs 💣
cannot express how geeked i am about what we've been building for @bomb.sh
Real excited for more of this. Just need to figure out how to buy more time to play with it!
glyph coverage for borders/curves is particularly poor, so subcell precision for those does require fancy kitty graphics support but we'll use the highest fidelity we can—the second row in the fill demo below renders in any terminal because eighth-blocks provide subcell precision using only glyphs
clack 1.6.0 is out. keyboard hints on select menus, cleaner note() output, and a handful of fixes that make multiline + password prompts behave the way you'd expect. big thanks to @florian-lefebvre.dev for helping ship this 💣
Release @clack/prompts@1.6.0 · bombshell-dev/clack
Minor Changes #568 f87933f Thanks @florian-lefebvre! - Updates default formatter of note() to note dim lines anymore If you want the old behavior, provide a format() function: import { note } fro...
github.com
Given the feedback, we decided to move forward and start verifying maintainers and projects in the npm ecosystem. Later on, large ecosystem projects could also become verifiers for their communities. Reach out if you're interested in these conversations! Here are the first 100+ verifications 🩷
app.bsky.graph.verification - @npmx.dev
Browse @npmx.dev's app.bsky.graph.verification collection on Taproot
atproto.at
We've started by verifying npmx maintainers. Log in to mu.social to see the verified badges! We'd like to discuss the best strategy for our communities with OSS maintainers. Should all large enough OSS projects be verifiers? Or would it be better for a few orgs/foundations to take on the task?
What's the landscape for local-first in vue? Seems like everything defaults to React these days (at least at first).
… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
wiz.io
Getting real excited to use this to build utility CLIs in TS that just weren't really possible before.
Just put together an initial implementation of transitions for clayterm. Yes, these are just terminal apps.
Added "line" mode to clayterm to support nice interactions in normal scrolling CLIs. The trick: 1. render frame continuously into the region at the bottom. 2. "commit" the final frame to scroll history. Non-terminal pipes like CI logs see the last frame only, so look nice github.com/thefrontside...
🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile. socket.dev/blog/axios-n...
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...
socket.dev
To celebrate the launch of the @npmx.dev alpha, I wrote up a guide on how to make your first contribution to an open-source project. Let me know if this helps you make your first contribution (and it doesn't have to be code)!
How to make your first contribution to an open source project
Getting involved in open source doesn't have to be scary! Understand how to find a great project and make your first contribution in this ten-step guide.
whitep4nth3r.com
Lovely to see this evolve over the past weeks. Cheers to all the effort and care folks have put into this!
this is open source
Heartbreaking. Take the time to read this post. We're doing such a terrible job as a society in distributing resources. Emelia's work is so valuable. We need her focused on open networks. She would be fully funded in any sane universe. Hire her. Or donate to help her thrive so she can help us.
So here's a short write up explaining what happened today and what I'm going through, at a high level. It does include some history too, but I tried to keep it brief.
Protests happen, but most of what is happening in Minneapolis isn’t protesting. More accurate terms: - observers - witnesses - volunteers - neighbors - residents - people
One thing that irks me: people keep calling the folks on the streets in Minneapolis protestors. They are not generally there to protest, they are there to observe and document. This is the product of organizing and mutual aid. It is telling that these acts of citizenship are seen as protest!
wonder how the “our ICE contract was only $200,000” githubbers feel these days
Spending some night brain cycles thinking about open source sustainability. 😮💨
With Elon enabling and profiting of the production of CSAM (Child sexual abuse material), I finally think of Twitter as X now
Interop is brilliant. Aligning the efforts of all browsers around crucial focus areas every year is doing wonders for interoperability, and its effect is compounding.
Switch to the “experimental” tab (which is not about experimenting, but about what is definitely coming soon) and you can see that every browser reached at least 98. Once all this engineering work ships in browsers, the overall interoperability for these 19 Focus Areas is 96%! wpt.fyi/interop-2025
ECMAScript excitement 😉 The Temporal API ships in Chrome 144 Beta today 🎉 developer.chrome.com/blog/chrome-... Right on time. Arriving in the Chrome Stable release in approximately one month!
Chrome 144 beta | Blog | Chrome for Developers
Learn about the latest features shipping in Chrome.
developer.chrome.com
ECMAScript excitement 😉 Congrats to @manishearth.bsky.social on unflagging TC39 Stage 3 Temporal in V8 today. Heading for Chrome 144 🎉 By many metrics this new date-time API is the single biggest change to JS ever 🔥 V8 uses Boa's temporal_rs by @jason-williams.co.uk Kevin Ness & Manish 👍
I've turned on automatic tab closing on my new phone, in part, because my previous phone still has 300 tabs open. It's jarring but... I think I might like the forced cleansing? Helps to force me to immediately shift something to a long term location if I really care.
One of those days where I found a werewolf shaped problem for a client. Wasn't specifically looking for that type of problem, but glad I had that silver bullet ready.
Excited to talk about local dev and testing through "simulating" data for your APIs on the @github.com OSS live stream today. We are diving into a project that I have been using with clients for years to quickly stand up APIs to test your apps. Starts in 2 hours! www.youtube.com/watch?v=Uw8k...
Open Source Friday with Simulacrum - Simulate the GitHub API Like a Pro
YouTube video by GitHub
youtube.com
Has anyone happened across a plugin or extension or something that hides private GitHub repos, etc, for use when pairing/sharing/streaming?
That urge to stack up projects to freely swap between and never be bored, but then invariably way over extend myself. 🫠
Our youngest kiddo wants to watch Cake Pop Demon Hunters. Worth the watch?
This initiative looks like a lovely way to help the ecosystem shift forward!
Want to see what we've accomplished with the node.js ‘userland-migrations’ initiative? Check out these awesome codemods codemod.link/nodejs-offic... I hope your depreciation is already supported. If not, go to git.new/userland-mig...
A commonly proposed alternative to structured concurrency in JavaScript is "why not use async/await + AbortController" But strangely enough, nobody actually ever does this in practice 🤔 Here's why it's not a real solution frontside.com/blog/2025-0...