Jacob Bolda

@jacobbolda.com

Board and Core Team @tauri.app Senior Software Engineer @frontside.bsky.social | Consulting for Fortune 100 | frontside.com 📺 watch | youtube.com/@JacobBolda 📖 read | www.jacobbolda.com 🧑‍💻 code | github.com/jbolda

clack 1.6.0 is out. keyboard hints on select menus, cleaner note() output, and a handful of fixes that make multiline + password prompts behave the way you'd expect. big thanks to @florian-lefebvre.dev for helping ship this 💣

Release @clack/prompts@1.6.0 · bombshell-dev/clack

Minor Changes #568 f87933f Thanks @florian-lefebvre! - Updates default formatter of note() to note dim lines anymore If you want the old behavior, provide a format() function: import { note } fro...

github.com

Given the feedback, we decided to move forward and start verifying maintainers and projects in the npm ecosystem. Later on, large ecosystem projects could also become verifiers for their communities. Reach out if you're interested in these conversations! Here are the first 100+ verifications 🩷

app.bsky.graph.verification - @npmx.dev

Browse @npmx.dev's app.bsky.graph.verification collection on Taproot

atproto.at

npmx@npmx.dev · 2mo ago

We've started by verifying npmx maintainers. Log in to mu.social to see the verified badges! We'd like to discuss the best strategy for our communities with OSS maintainers. Should all large enough OSS projects be verifiers? Or would it be better for a few orgs/foundations to take on the task?

… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog

A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.

wiz.io

Added "line" mode to clayterm to support nice interactions in normal scrolling CLIs. The trick: 1. render frame continuously into the region at the bottom. 2. "commit" the final frame to scroll history. Non-terminal pipes like CI logs see the last frame only, so look nice github.com/thefrontside...

🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile. socket.dev/blog/axios-n...

Supply Chain Attack on Axios Pulls Malicious Dependency from...

A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...

socket.dev

Heartbreaking. Take the time to read this post. We're doing such a terrible job as a society in distributing resources. Emelia's work is so valuable. We need her focused on open networks. She would be fully funded in any sane universe. Hire her. Or donate to help her thrive so she can help us.

Emelia@thisismissem.social · 6mo ago

So here's a short write up explaining what happened today and what I'm going through, at a high level. It does include some history too, but I tried to keep it brief.

With Elon enabling and profiting of the production of CSAM (Child sexual abuse material), I finally think of Twitter as X now

ECMAScript excitement 😉 The Temporal API ships in Chrome 144 Beta today 🎉 developer.chrome.com/blog/chrome-... Right on time. Arriving in the Chrome Stable release in approximately one month!

Chrome 144 beta  |  Blog  |  Chrome for Developers

Learn about the latest features shipping in Chrome.

developer.chrome.com

Rob Palmer@robpalmer.bsky.social · 9mo ago

ECMAScript excitement 😉 Congrats to @manishearth.bsky.social on unflagging TC39 Stage 3 Temporal in V8 today. Heading for Chrome 144 🎉 By many metrics this new date-time API is the single biggest change to JS ever 🔥 V8 uses Boa's temporal_rs by @jason-williams.co.uk Kevin Ness & Manish 👍

I've turned on automatic tab closing on my new phone, in part, because my previous phone still has 300 tabs open. It's jarring but... I think I might like the forced cleansing? Helps to force me to immediately shift something to a long term location if I really care.

One of those days where I found a werewolf shaped problem for a client. Wasn't specifically looking for that type of problem, but glad I had that silver bullet ready.