jonchurch

@jonchurch.com

maintaining express, lodash / ex-msft

Btw, you can give gh cli a readonly token instead of the normal gh auth method which will have write. Drastically reduces blast radius if you are concerned about your gh cli token being stolen (which you should be) gh auth login —with-token hit enter Then paste the token, it will persist for you

Does anyone have a link to an in depth write up of the tanstack attack, the CI compromise bit? I ask bc I am doing my own analysis and the official post mortem doesnt seem to get all the details right. That or I am misunderstanding something, so want to see if a real expert has written this up

There is no Trusted Publishing setup which prevents a compromised repo admin's github PAT from triggering an npm publish, right? I've spent months trying to find something, but deploy envs w/ required reviews, workflow guards, branch protections, signed tags. All of it can be overwritten w/o 2fa

So... we've decided to change things up. NodeConf EU 2026 will be hosted in Bologna, Italy this year. The dates are set for September 29th and 30th, 2026.

Theres been an npmx bug that’s bothered me for a few weeks now. User profiles are showing almost random packages. Its a subset of your packages, first I thought it was dropping anything in an npm org dug a little and it was worse. It shows packages _where the gh user is the same as the npm user_

We released a lodash patch today, everything went well so havent really thought about it since. A non event. Released a minor yesterday, and it broke stuff and immediately heard about it. Couldnt stop thinking about it until we fixed it EoD today 🫠