home.social

#lodash — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lodash, aggregated by home.social.

fetched live
  1. 🫠 El 95% de los reportes de vulnerabilidades que recibimos en se rechazan: una prueba de concepto que funciona no es lo mismo que una vulnerabilidad en la librería.

    blog.ulisesgascon.com/por-que-

  2. 🫠 El 95% de los reportes de vulnerabilidades que recibimos en #Lodash se rechazan: una prueba de concepto que funciona no es lo mismo que una vulnerabilidad en la librería.

    blog.ulisesgascon.com/por-que-

  3. 🫠 Around 95% of the vulnerability reports we get for are rejected: a working proof of concept isn't the same as a library vulnerability.

    blog.ulisesgascon.com/why-most

  4. 🫠 Around 95% of the vulnerability reports we get for #Lodash are rejected: a working proof of concept isn't the same as a library vulnerability.

    blog.ulisesgascon.com/why-most

  5. 😱 Oh no! The #creator of #Lodash is tired! 🥱 Who could have guessed maintaining one of the most popular #JavaScript libraries in the world would be exhausting? 🙄 But don't worry, he's on a "personal journey" to find "sustainability."✨ #GroundbreakingNews
    openjsf.org/blog/burnout-is-re #Exhaustion #Sustainability #PersonalJourney #HackerNews #ngated

  6. 😱 Oh no! The #creator of #Lodash is tired! 🥱 Who could have guessed maintaining one of the most popular #JavaScript libraries in the world would be exhausting? 🙄 But don't worry, he's on a "personal journey" to find "sustainability."✨ #GroundbreakingNews
    openjsf.org/blog/burnout-is-re #Exhaustion #Sustainability #PersonalJourney #HackerNews #ngated

  7. 🔖 The latest issue of my is live, issue 013.

    March recap: 12 CVEs across , , & , a state-actor supply chain attack on , and the security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  8. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  9. 🔐 7 out of 10 of reports for and are invalid.

    The current spike is LLM-generated noise eating volunteers' time that should go to releases, features, and real bugs.

    Our tooling wasn't designed for this volume. Every report still needs to be read, cross-referenced, and responded to. We need better tooling and support to sustain this.

  10. 🔐 7 out of 10 of #security reports for #Lodash and #Express are invalid.

    The current spike is LLM-generated noise eating volunteers' time that should go to releases, features, and real bugs.

    Our tooling wasn't designed for this volume. Every report still needs to be read, cross-referenced, and responded to. We need better tooling and support to sustain this.

  11. 🔖 The latest issue of my is live, issue 011.

    Secure publishing on in 2026, major security overhaul, updated security best practices, fresh release backlog & ecosystem insights from talks, CVEs & community work ✨

    blog.ulisesgascon.com/newslett

  12. 🔖 The latest issue of my #newsletter is live, issue 011.

    Secure publishing on #npm in 2026, major #Lodash security overhaul, updated security best practices, fresh #Express release backlog & ecosystem insights from talks, CVEs & community work ✨

    blog.ulisesgascon.com/newslett

  13. Just shipped a new newsletter to Sponsors! 🎁

    Includes the hard truths of security, updates, and the overhaul that put my code in space 🚀.

    Get early access & support my OSS work here: github.com/sponsors/UlisesGasc

  14. Just shipped a new newsletter to Sponsors! 🎁

    Includes the hard truths of #npm security, #Expressjs updates, and the #Lodash overhaul that put my code in space 🚀.

    Get early access & support my OSS work here: github.com/sponsors/UlisesGasc

  15. 🛠️ Análisis en profundidad del parche de para CVE-2025-13465 en : causa raíz, mecánica de prototype pollution en _.unset/_.omit y detalles del parche.

    orbitant.com/prototype-polluti

  16. 🛠️ Análisis en profundidad del parche de #seguridad para CVE-2025-13465 en #Lodash: causa raíz, mecánica de prototype pollution en _.unset/_.omit y detalles del parche.

    orbitant.com/prototype-polluti

  17. 🛠️ In-depth breakdown of the fix for CVE-2025-13465 in : root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch.

    orbitant.com/en/prototype-poll

  18. 🛠️ In-depth breakdown of the #security fix for CVE-2025-13465 in #Lodash: root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch.

    orbitant.com/en/prototype-poll

  19. 🥹 Proud to have contributed to the security overhaul. Strengthening governance, security processes, and infrastructure to keep the project healthy for the community 🛡️

    openjsf.org/blog/lodash-securi

  20. 🥹 Proud to have contributed to the #Lodash security overhaul. Strengthening governance, security processes, and infrastructure to keep the project healthy for the community 🛡️

    openjsf.org/blog/lodash-securi

  21. Big news 🚀! is now on Open Collective!

    Support the project and be among the first backers or sponsors 🙌

    opencollective.com/lodash

  22. Big news 🚀! #Lodash is now on Open Collective!

    Support the project and be among the first backers or sponsors 🙌

    opencollective.com/lodash

  23. 🔖 The latest issue of my is out, issue 010.

    Stories from reviving & reimagining , secure publishing on , why doesn’t fail because of code, backlog updates &

    blog.ulisesgascon.com/newslett

  24. 🔖 The latest issue of my #newsletter is out, issue 010.

    Stories from reviving #Expressjs & reimagining #Lodash, secure publishing on #npm, why #OSS doesn’t fail because of code, backlog updates & #OpenSSF #Scorecard

    blog.ulisesgascon.com/newslett

  25. ✍️ El open source no falla por el código.
    Falla por problemas de gobernanza, burnout y trabajo invisible.

    He escrito sobre lo que aprendí trabajando en y :

    blog.ulisesgascon.com/el-open-

  26. ✍️ El open source no falla por el código.
    Falla por problemas de gobernanza, burnout y trabajo invisible.

    He escrito sobre lo que aprendí trabajando en #Expressjs y #Lodash:

    blog.ulisesgascon.com/el-open-

  27. ✍️ Open source doesn’t fail because of code.
    It fails because of governance gaps, burnout, and invisible work.

    I wrote down what I learned working on and

    blog.ulisesgascon.com/open-sou

  28. ✍️ Open source doesn’t fail because of code.
    It fails because of governance gaps, burnout, and invisible work.

    I wrote down what I learned working on #Expressjs and #Lodash

    blog.ulisesgascon.com/open-sou

  29. 📺 ¿Qué viene después del caos?

    Lecciones de revivir y reimaginar .

    youtube.com/watch?v=NHsIxEy0_Qw

  30. 🍕 The slides for my talk “What Comes After Chaos?” are now available

    Stories and lessons from reviving and reimagining .

    ✨ Thanks to for the invitation!

    slides.ulisesgascon.com/what-c

  31. 🍕 The slides for my talk “What Comes After Chaos?” are now available

    Stories and lessons from reviving #ExpressJS and reimagining #Lodash.

    ✨ Thanks to #Orbitant for the invitation!

    slides.ulisesgascon.com/what-c

  32. ¿Qué viene después del caos?

    Lecciones de revivir y reimaginar .

    🎙️ Charla (en español) organizada por Orbitant
    🗓️ 19 nov, 5 PM CET
    🔑 El enlace se enviará el día del evento
    🎟️ Gratis → docs.google.com/forms/d/e/1FAI

  33. ¿Qué viene después del caos?

    Lecciones de revivir #Expressjs y reimaginar #Lodash.

    🎙️ Charla (en español) organizada por Orbitant
    🗓️ 19 nov, 5 PM CET
    🔑 El enlace se enviará el día del evento
    🎟️ Gratis → docs.google.com/forms/d/e/1FAI

  34. ¿Qué viene después del caos?

    Lecciones de revivir y reimaginar .

    🎙️ Charla (en español) organizada por Orbitant
    🗓️ 19 nov, 5 PM CET
    🔑 El enlace se enviará el día del evento
    🎟️ Gratis → docs.google.com/forms/d/e/1FAI

  35. ¿Qué viene después del caos?

    Lecciones de revivir #Expressjs y reimaginar #Lodash.

    🎙️ Charla (en español) organizada por Orbitant
    🗓️ 19 nov, 5 PM CET
    🔑 El enlace se enviará el día del evento
    🎟️ Gratis → docs.google.com/forms/d/e/1FAI

  36. 🔧 The latest issue of my is out, number 009.

    It dives into the new governance and era, the cleanup and reboot, the 6 modernization journey… and much more 🔥

    blog.ulisesgascon.com/newslett

  37. 🔧 The latest issue of my #newsletter is out, number 009.

    It dives into the new #Lodash governance and #security era, the #Yeoman cleanup and reboot, the #Expressjs 6 modernization journey… and much more 🔥

    blog.ulisesgascon.com/newslett

  38. I just sent my new Open Source Treats 🎃 newsletter to sponsors — packed with updates on , & !

    It’ll be public on my blog in a few days, but if you’d like early access and want to support my open source work:

    👉 github.com/sponsors/UlisesGasc

  39. I just sent my new Open Source Treats 🎃 newsletter to sponsors — packed with updates on #Lodash, #Yeoman & #Expressjs!

    It’ll be public on my blog in a few days, but if you’d like early access and want to support my open source work:

    👉 github.com/sponsors/UlisesGasc

  40. 🚀 Recent updates focus on stronger & posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via

    📝 Docs now have dedicated CI

    🔒 Added escalation policy

    📊 Reporting

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by &

    More details: blog.ulisesgascon.com/the-futu

  41. 🚀 Recent #Lodash updates focus on stronger #CI & #security posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via #Playwright

    📝 Docs now have dedicated CI

    🔒 Added #OpenJS #CNA escalation policy

    📊 Reporting #OSSF #Scorecard

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by #Express & #Webpack

    More details: blog.ulisesgascon.com/the-futu

  42. is evolving at OpenJS Foundation — shifting from BDFL to shared stewardship. The focus now is maintenance: stability, security & sustainability over new features. A great reminder that mature open source projects thrive when we share responsibility.

    blog.ulisesgascon.com/the-futu

  43. #Lodash is evolving at OpenJS Foundation — shifting from BDFL to shared stewardship. The focus now is maintenance: stability, security & sustainability over new features. A great reminder that mature open source projects thrive when we share responsibility. #OpenSource

    blog.ulisesgascon.com/the-futu

  44. ha prosperado durante años gracias a la increíble dedicación de John-David Dalton, cuyo trabajo mantuvo la librería fuerte y confiable.

    Juntos estamos construyendo sobre esa base, ampliando la , la y la para que continúe impulsando la web durante muchos años más.

    blog.ulisesgascon.com/el-futur

  45. #Lodash ha prosperado durante años gracias a la increíble dedicación de John-David Dalton, cuyo trabajo mantuvo la librería fuerte y confiable.

    Juntos estamos construyendo sobre esa base, ampliando la #colaboración, la #gobernanza y la #seguridad para que #Lodash continúe impulsando la web durante muchos años más.

    blog.ulisesgascon.com/el-futur

  46. has thrived for years thanks to the incredible dedication of John-David Dalton, whose work kept the library strong and reliable.

    Together we’re building on that foundation, expanding , , and so can continue powering the web for years to come:

    blog.ulisesgascon.com/the-futu

  47. #Lodash has thrived for years thanks to the incredible dedication of John-David Dalton, whose work kept the library strong and reliable.

    Together we’re building on that foundation, expanding #collaboration, #governance, and #security so #Lodash can continue powering the web for years to come:

    blog.ulisesgascon.com/the-futu

  48. Чем заменить Lodash. Реальные примеры

    Используете Lodash в вашем проекте? При первом приближении - это удобная, знакомая всем библиотека, но если посмотреть внимательнее, то релиз мажорной версии был в 2016-м году, а последнее обновление в 2021-м. Библиотека имеет критические уязвимости и во многом дублирует нативные методы Javascript. В статье я расскажу о реальных кейсах замены использования библиотеки Lodash на нативные методы и приведу примеры замен, где мы написали собственную реализацию.

    habr.com/ru/articles/934298/

    #lodash #javascript

  49. @zkat @slightlyoff well no, you can forget IE7 anyway (I actually think even #lodash likely dropped support for it by now), but it is "baseline available" in all major browsers… caniuse.com/?search=forEach

  50. @zkat @slightlyoff well no, you can forget IE7 anyway (I actually think even #lodash likely dropped support for it by now), but it is "baseline available" in all major browsers… caniuse.com/?search=forEach

  51. Ah yes, "SuperUtilsPlus"—because what the world desperately needed was yet another #JavaScript #utility library, as if #Lodash isn't already the multi-tool everyone's tripping over. 🤡 GitHub's latest attempt at transforming every keystroke into a 12-step program is like watching someone reinvent the wheel and then declare it a cube for extra efficiency. 🚀
    github.com/dhaxor/super-utils- #Libraries #Innovation #GitHub #SuperUtilsPlus #HackerNews #ngated