home.social

#lodash — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lodash, aggregated by home.social.

  1. 🔖 The latest issue of my is live, issue 013.

    March recap: 12 CVEs across , , & , a state-actor supply chain attack on , and the security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  2. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  3. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  4. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  5. 🔐 7 out of 10 of reports for and are invalid.

    The current spike is LLM-generated noise eating volunteers' time that should go to releases, features, and real bugs.

    Our tooling wasn't designed for this volume. Every report still needs to be read, cross-referenced, and responded to. We need better tooling and support to sustain this.

  6. 🔖 The latest issue of my is out, issue 010.

    Stories from reviving & reimagining , secure publishing on , why doesn’t fail because of code, backlog updates &

    blog.ulisesgascon.com/newslett

  7. 🚀 Recent updates focus on stronger & posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via

    📝 Docs now have dedicated CI

    🔒 Added escalation policy

    📊 Reporting

    🧯 New Incident Response Plan ()

    🧠 Threat Model inspired by &

    More details: blog.ulisesgascon.com/the-futu

  8. 🚀 Recent #Lodash updates focus on stronger #CI & #security posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via #Playwright

    📝 Docs now have dedicated CI

    🔒 Added #OpenJS #CNA escalation policy

    📊 Reporting #OSSF #Scorecard

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by #Express & #Webpack

    More details: blog.ulisesgascon.com/the-futu

  9. 🚀 Recent #Lodash updates focus on stronger #CI & #security posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via #Playwright

    📝 Docs now have dedicated CI

    🔒 Added #OpenJS #CNA escalation policy

    📊 Reporting #OSSF #Scorecard

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by #Express & #Webpack

    More details: blog.ulisesgascon.com/the-futu

  10. 🚀 Recent #Lodash updates focus on stronger #CI & #security posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via #Playwright

    📝 Docs now have dedicated CI

    🔒 Added #OpenJS #CNA escalation policy

    📊 Reporting #OSSF #Scorecard

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by #Express & #Webpack

    More details: blog.ulisesgascon.com/the-futu

  11. Вам не нужен Lodash. Хватит! Пожалуйста

    На State Of JS 2023 Lodash занял первое место в топе библиотек - что меня сильно огорчило. Я топлю за его отказ последние годы - и хотел бы рассказать, почему я считаю его вредным и не особо вам нужным. Ну давай!

    habr.com/ru/articles/823484/

    #lodash #unjs #javascript #esm #es #typescript