Jordan Harband

@jordan.har.band

https://github.com/ljharb software engineer/nerd/teacher/will try anything once; surgeon with git rebase. @TC39.es @Socket.dev ex @Coinbase/@Airbnb/@Twitter/@MobBase. Fav punctuation ⸮, scent petrichor

npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...

npm install-time security and GAT bypass2fa deprecation - GitHub Changelog

npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…

github.blog

can someone please tell *every bank* that if a "secure messaging system" goes to my email address, then it's basically not possible for it to be more secure than my email account itself?

ok i know i'm a couple months late, but wtaf is this new "Marathon" game? it seems like it has precisely nothing to do with actual Marathon lore, and is just a (potentially fun but) entirely unrelated game with the title slapped on top.

Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.

Bild

Clutching pearls about how many PURLs are in your application is just FUD and nonsense. The only thing that matters is, how many humans can put code into it. (ie all your engineers + every linux dev + every OSS maintainer etc)

oof, who do i complain to about the name of git 2.54's "history" command? git does not have a history, it has a changelog, and the conceptual difference is very important for having the proper mental model :-(

The thing people may not realize is that the best way to secure the supply chain is to secure the maintainers. And the best way to secure the maintainers is to pay them and give them a laptop, health insurance, and maybe even a desk to sit at.

ECMAScript Euphoria! 🎉 We don't always post when a single proposal advances, but when we do, it's Temporal -> Stage 4. Just days shy of 9 years from Stage 1, a herculean effort on the part of many champions, delegates, invited experts, and contributors, past and present. Thank you all! 🙌

minimatch patched 3 high-severity ReDoS vulnerabilities that can stall the Node.js event loop. Because it's pulled into nearly every corner of the #NodeJS ecosystem (~472M weekly downloads), we're releasing free Certified Patches for all three. socket.dev/blog/minimat... #JavaScript

minimatch Patches 3 High-Severity ReDoS Vulnerabilities - So...

minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.

socket.dev