#lodash — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #lodash, aggregated by home.social.
-
🫠 El 95% de los reportes de vulnerabilidades que recibimos en #Lodash se rechazan: una prueba de concepto que funciona no es lo mismo que una vulnerabilidad en la librería.
-
🫠 El 95% de los reportes de vulnerabilidades que recibimos en #Lodash se rechazan: una prueba de concepto que funciona no es lo mismo que una vulnerabilidad en la librería.
-
🫠 Around 95% of the vulnerability reports we get for #Lodash are rejected: a working proof of concept isn't the same as a library vulnerability.
https://blog.ulisesgascon.com/why-most-lodash-vulnerability-reports-get-rejected
-
🫠 Around 95% of the vulnerability reports we get for #Lodash are rejected: a working proof of concept isn't the same as a library vulnerability.
https://blog.ulisesgascon.com/why-most-lodash-vulnerability-reports-get-rejected
-
😱 Oh no! The #creator of #Lodash is tired! 🥱 Who could have guessed maintaining one of the most popular #JavaScript libraries in the world would be exhausting? 🙄 But don't worry, he's on a "personal journey" to find "sustainability."✨ #GroundbreakingNews
https://openjsf.org/blog/burnout-is-real-for-open-source-maintainers #Exhaustion #Sustainability #PersonalJourney #HackerNews #ngated -
😱 Oh no! The #creator of #Lodash is tired! 🥱 Who could have guessed maintaining one of the most popular #JavaScript libraries in the world would be exhausting? 🙄 But don't worry, he's on a "personal journey" to find "sustainability."✨ #GroundbreakingNews
https://openjsf.org/blog/burnout-is-real-for-open-source-maintainers #Exhaustion #Sustainability #PersonalJourney #HackerNews #ngated -
Burnout Is Real in the OSS World, Says John-David Dalton, Creator of Lodash
https://openjsf.org/blog/burnout-is-real-for-open-source-maintainers
#HackerNews #burnout #open-source #Lodash #OSS #community #mentalhealth
-
Burnout Is Real in the OSS World, Says John-David Dalton, Creator of Lodash
https://openjsf.org/blog/burnout-is-real-for-open-source-maintainers
#HackerNews #burnout #open-source #Lodash #OSS #community #mentalhealth
-
🔖 The latest issue of my #newsletter is live, issue 013.
March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐
-
🔖 The latest issue of my #newsletter is live, issue 013.
March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐
-
🔐 7 out of 10 of #security reports for #Lodash and #Express are invalid.
The current spike is LLM-generated noise eating volunteers' time that should go to releases, features, and real bugs.
Our tooling wasn't designed for this volume. Every report still needs to be read, cross-referenced, and responded to. We need better tooling and support to sustain this.
-
🔐 7 out of 10 of #security reports for #Lodash and #Express are invalid.
The current spike is LLM-generated noise eating volunteers' time that should go to releases, features, and real bugs.
Our tooling wasn't designed for this volume. Every report still needs to be read, cross-referenced, and responded to. We need better tooling and support to sustain this.
-
🔖 The latest issue of my #newsletter is live, issue 011.
Secure publishing on #npm in 2026, major #Lodash security overhaul, updated security best practices, fresh #Express release backlog & ecosystem insights from talks, CVEs & community work ✨
-
🔖 The latest issue of my #newsletter is live, issue 011.
Secure publishing on #npm in 2026, major #Lodash security overhaul, updated security best practices, fresh #Express release backlog & ecosystem insights from talks, CVEs & community work ✨
-
Just shipped a new newsletter to Sponsors! 🎁
Includes the hard truths of #npm security, #Expressjs updates, and the #Lodash overhaul that put my code in space 🚀.
Get early access & support my OSS work here: https://github.com/sponsors/UlisesGascon
-
Just shipped a new newsletter to Sponsors! 🎁
Includes the hard truths of #npm security, #Expressjs updates, and the #Lodash overhaul that put my code in space 🚀.
Get early access & support my OSS work here: https://github.com/sponsors/UlisesGascon
-
🛠️ Análisis en profundidad del parche de #seguridad para CVE-2025-13465 en #Lodash: causa raíz, mecánica de prototype pollution en _.unset/_.omit y detalles del parche.
https://orbitant.com/prototype-pollution-javascript-cve-2025-13465/
-
🛠️ Análisis en profundidad del parche de #seguridad para CVE-2025-13465 en #Lodash: causa raíz, mecánica de prototype pollution en _.unset/_.omit y detalles del parche.
https://orbitant.com/prototype-pollution-javascript-cve-2025-13465/
-
🛠️ In-depth breakdown of the #security fix for CVE-2025-13465 in #Lodash: root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch.
https://orbitant.com/en/prototype-pollution-javascript-cve-2025-13465/
-
🛠️ In-depth breakdown of the #security fix for CVE-2025-13465 in #Lodash: root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch.
https://orbitant.com/en/prototype-pollution-javascript-cve-2025-13465/
-
🥹 Proud to have contributed to the #Lodash security overhaul. Strengthening governance, security processes, and infrastructure to keep the project healthy for the community 🛡️
-
🥹 Proud to have contributed to the #Lodash security overhaul. Strengthening governance, security processes, and infrastructure to keep the project healthy for the community 🛡️
-
Big news 🚀! #Lodash is now on Open Collective!
Support the project and be among the first backers or sponsors 🙌
-
Big news 🚀! #Lodash is now on Open Collective!
Support the project and be among the first backers or sponsors 🙌
-
🔖 The latest issue of my #newsletter is out, issue 010.
Stories from reviving #Expressjs & reimagining #Lodash, secure publishing on #npm, why #OSS doesn’t fail because of code, backlog updates & #OpenSSF #Scorecard ✨
-
🔖 The latest issue of my #newsletter is out, issue 010.
Stories from reviving #Expressjs & reimagining #Lodash, secure publishing on #npm, why #OSS doesn’t fail because of code, backlog updates & #OpenSSF #Scorecard ✨
-
✍️ El open source no falla por el código.
Falla por problemas de gobernanza, burnout y trabajo invisible.He escrito sobre lo que aprendí trabajando en #Expressjs y #Lodash:
https://blog.ulisesgascon.com/el-open-source-no-falla-por-el-codigo
-
✍️ El open source no falla por el código.
Falla por problemas de gobernanza, burnout y trabajo invisible.He escrito sobre lo que aprendí trabajando en #Expressjs y #Lodash:
https://blog.ulisesgascon.com/el-open-source-no-falla-por-el-codigo
-
✍️ Open source doesn’t fail because of code.
It fails because of governance gaps, burnout, and invisible work.I wrote down what I learned working on #Expressjs and #Lodash
https://blog.ulisesgascon.com/open-source-doesnt-fail-because-of-code
-
✍️ Open source doesn’t fail because of code.
It fails because of governance gaps, burnout, and invisible work.I wrote down what I learned working on #Expressjs and #Lodash
https://blog.ulisesgascon.com/open-source-doesnt-fail-because-of-code
-
📺 ¿Qué viene después del caos?
Lecciones de revivir #Expressjs y reimaginar #Lodash.
-
📺 ¿Qué viene después del caos?
Lecciones de revivir #Expressjs y reimaginar #Lodash.
-
🍕 The slides for my talk “What Comes After Chaos?” are now available
Stories and lessons from reviving #ExpressJS and reimagining #Lodash.
✨ Thanks to #Orbitant for the invitation!
-
🍕 The slides for my talk “What Comes After Chaos?” are now available
Stories and lessons from reviving #ExpressJS and reimagining #Lodash.
✨ Thanks to #Orbitant for the invitation!
-
¿Qué viene después del caos?
Lecciones de revivir #Expressjs y reimaginar #Lodash.
🎙️ Charla (en español) organizada por Orbitant
🗓️ 19 nov, 5 PM CET
🔑 El enlace se enviará el día del evento
🎟️ Gratis → https://docs.google.com/forms/d/e/1FAIpQLSeCxburP5WLkqCZIyteG6JHGoQIL6oI7lu3qwjXTdJ8uNamtA/viewform -
¿Qué viene después del caos?
Lecciones de revivir #Expressjs y reimaginar #Lodash.
🎙️ Charla (en español) organizada por Orbitant
🗓️ 19 nov, 5 PM CET
🔑 El enlace se enviará el día del evento
🎟️ Gratis → https://docs.google.com/forms/d/e/1FAIpQLSeCxburP5WLkqCZIyteG6JHGoQIL6oI7lu3qwjXTdJ8uNamtA/viewform -
¿Qué viene después del caos?
Lecciones de revivir #Expressjs y reimaginar #Lodash.
🎙️ Charla (en español) organizada por Orbitant
🗓️ 19 nov, 5 PM CET
🔑 El enlace se enviará el día del evento
🎟️ Gratis → https://docs.google.com/forms/d/e/1FAIpQLSeCxburP5WLkqCZIyteG6JHGoQIL6oI7lu3qwjXTdJ8uNamtA/viewform -
¿Qué viene después del caos?
Lecciones de revivir #Expressjs y reimaginar #Lodash.
🎙️ Charla (en español) organizada por Orbitant
🗓️ 19 nov, 5 PM CET
🔑 El enlace se enviará el día del evento
🎟️ Gratis → https://docs.google.com/forms/d/e/1FAIpQLSeCxburP5WLkqCZIyteG6JHGoQIL6oI7lu3qwjXTdJ8uNamtA/viewform -
🔧 The latest issue of my #newsletter is out, number 009.
It dives into the new #Lodash governance and #security era, the #Yeoman cleanup and reboot, the #Expressjs 6 modernization journey… and much more 🔥
-
🔧 The latest issue of my #newsletter is out, number 009.
It dives into the new #Lodash governance and #security era, the #Yeoman cleanup and reboot, the #Expressjs 6 modernization journey… and much more 🔥
-
I just sent my new Open Source Treats 🎃 newsletter to sponsors — packed with updates on #Lodash, #Yeoman & #Expressjs!
It’ll be public on my blog in a few days, but if you’d like early access and want to support my open source work:
-
I just sent my new Open Source Treats 🎃 newsletter to sponsors — packed with updates on #Lodash, #Yeoman & #Expressjs!
It’ll be public on my blog in a few days, but if you’d like early access and want to support my open source work:
-
🚀 Recent #Lodash updates focus on stronger #CI & #security posture!
✅ CI support expanded (Node 4 → 25)
🌐 New browser tests via #Playwright
📝 Docs now have dedicated CI
🔒 Added #OpenJS #CNA escalation policy
📊 Reporting #OSSF #Scorecard
🧯 New Incident Response Plan (#IRP)
🧠 Threat Model inspired by #Express & #Webpack
More details: https://blog.ulisesgascon.com/the-future-of-lodash
-
🚀 Recent #Lodash updates focus on stronger #CI & #security posture!
✅ CI support expanded (Node 4 → 25)
🌐 New browser tests via #Playwright
📝 Docs now have dedicated CI
🔒 Added #OpenJS #CNA escalation policy
📊 Reporting #OSSF #Scorecard
🧯 New Incident Response Plan (#IRP)
🧠 Threat Model inspired by #Express & #Webpack
More details: https://blog.ulisesgascon.com/the-future-of-lodash
-
#Lodash is evolving at OpenJS Foundation — shifting from BDFL to shared stewardship. The focus now is maintenance: stability, security & sustainability over new features. A great reminder that mature open source projects thrive when we share responsibility. #OpenSource
-
#Lodash is evolving at OpenJS Foundation — shifting from BDFL to shared stewardship. The focus now is maintenance: stability, security & sustainability over new features. A great reminder that mature open source projects thrive when we share responsibility. #OpenSource
-
✨ #Lodash ha prosperado durante años gracias a la increíble dedicación de John-David Dalton, cuyo trabajo mantuvo la librería fuerte y confiable.
Juntos estamos construyendo sobre esa base, ampliando la #colaboración, la #gobernanza y la #seguridad para que #Lodash continúe impulsando la web durante muchos años más.
-
✨ #Lodash ha prosperado durante años gracias a la increíble dedicación de John-David Dalton, cuyo trabajo mantuvo la librería fuerte y confiable.
Juntos estamos construyendo sobre esa base, ampliando la #colaboración, la #gobernanza y la #seguridad para que #Lodash continúe impulsando la web durante muchos años más.
-
✨ #Lodash has thrived for years thanks to the incredible dedication of John-David Dalton, whose work kept the library strong and reliable.
Together we’re building on that foundation, expanding #collaboration, #governance, and #security so #Lodash can continue powering the web for years to come:
-
✨ #Lodash has thrived for years thanks to the incredible dedication of John-David Dalton, whose work kept the library strong and reliable.
Together we’re building on that foundation, expanding #collaboration, #governance, and #security so #Lodash can continue powering the web for years to come:
-
Чем заменить Lodash. Реальные примеры
Используете Lodash в вашем проекте? При первом приближении - это удобная, знакомая всем библиотека, но если посмотреть внимательнее, то релиз мажорной версии был в 2016-м году, а последнее обновление в 2021-м. Библиотека имеет критические уязвимости и во многом дублирует нативные методы Javascript. В статье я расскажу о реальных кейсах замены использования библиотеки Lodash на нативные методы и приведу примеры замен, где мы написали собственную реализацию.
-
#Development #Utilities
es-toolkit · A cutting-edge and fast JavaScript utility library https://ilo.im/165pb3_____
#EsToolkit #Lodash #JavaScript #TypeScript #OpenSource #Library #WebDev #Frontend #Backend -
#Development #Utilities
es-toolkit · A cutting-edge and fast JavaScript utility library https://ilo.im/165pb3_____
#EsToolkit #Lodash #JavaScript #TypeScript #OpenSource #Library #WebDev #Frontend #Backend -
@zkat @slightlyoff well no, you can forget IE7 anyway (I actually think even #lodash likely dropped support for it by now), but it is "baseline available" in all major browsers… https://caniuse.com/?search=forEach
-
@zkat @slightlyoff well no, you can forget IE7 anyway (I actually think even #lodash likely dropped support for it by now), but it is "baseline available" in all major browsers… https://caniuse.com/?search=forEach
-
Ah yes, "SuperUtilsPlus"—because what the world desperately needed was yet another #JavaScript #utility library, as if #Lodash isn't already the multi-tool everyone's tripping over. 🤡 GitHub's latest attempt at transforming every keystroke into a 12-step program is like watching someone reinvent the wheel and then declare it a cube for extra efficiency. 🚀
https://github.com/dhaxor/super-utils-plus #Libraries #Innovation #GitHub #SuperUtilsPlus #HackerNews #ngated -
SuperUtilsPlus - A Modern Alternative to Lodash
https://github.com/dhaxor/super-utils-plus
#HackerNews #SuperUtilsPlus #Lodash #JavaScript #Development #OpenSource #GitHub