#typescript — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #typescript, aggregated by home.social.
-
Day 14: MISSION ACCOMPLISHED! 🏁
The #P2P video app is live, tested, and installable as a #PWA. From foundations to a full-mesh conferencing tool in two weeks.
Built with #ReactJS, #TypeScript, #Peerix & #ZedEditor.
Thoughts and takeaways: https://meefik.dev/2026/07/20/peerix-talk/
App: https://talk.peerix.dev
Source: https://github.com/meefik/peerix-talk -
Day 14: MISSION ACCOMPLISHED! 🏁
The #P2P video app is live, tested, and installable as a #PWA. From foundations to a full-mesh conferencing tool in two weeks.
Built with #ReactJS, #TypeScript, #Peerix & #ZedEditor.
Thoughts and takeaways: https://meefik.dev/2026/07/20/peerix-talk/
App: https://talk.peerix.dev
Source: https://github.com/meefik/peerix-talk -
【個人開発】マルチレポでnoteクリエイター向け統計ダッシュボードを作ってみた【React / Hono / Chrome拡張】
https://qiita.com/natsugure/items/e12091867becb931bce0?utm_campaign=popular_items&utm_medium=feed&utm_source=popular_items -
【個人開発】マルチレポでnoteクリエイター向け統計ダッシュボードを作ってみた【React / Hono / Chrome拡張】
https://qiita.com/natsugure/items/e12091867becb931bce0?utm_campaign=popular_items&utm_medium=feed&utm_source=popular_items -
Day 13: Installable everywhere!
Turning the #P2P video app into a full-blown #PWA:
📱 Web App Manifest + icons & themes
🔔 Native install prompts (iOS/Android/Desktop)
⚡ App-like UX, zero store frictionBuilt with #ReactJS, #TypeScript & #Vite inside #ZedEditor.
-
Day 13: Installable everywhere!
Turning the #P2P video app into a full-blown #PWA:
📱 Web App Manifest + icons & themes
🔔 Native install prompts (iOS/Android/Desktop)
⚡ App-like UX, zero store frictionBuilt with #ReactJS, #TypeScript & #Vite inside #ZedEditor.
-
Day 13: Installable everywhere!
Turning the #P2P video app into a full-blown #PWA:
📱 Web App Manifest + icons & themes
🔔 Native install prompts (iOS/Android/Desktop)
⚡ App-like UX, zero store frictionBuilt with #ReactJS, #TypeScript & #Vite inside #ZedEditor.
-
Microsoft Principal Product Manager Daniel Rosenwasser writes an in-depth guide to TypeScript 7.0's July 8th release. As we have discussed here before, 7.0 is mostly about performance and developer experience.
"A 10x Faster TypeScript"
https://mastodon.social/@rperezrosario/114299644066167176"TypeScript 6.0 is your final warning"
https://mastodon.social/@rperezrosario/116331807248668581"Announcing TypeScript 7.0"
https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/
-
Microsoft Principal Product Manager Daniel Rosenwasser writes an in-depth guide to TypeScript 7.0's July 8th release. As we have discussed here before, 7.0 is mostly about performance and developer experience.
"A 10x Faster TypeScript"
https://mastodon.social/@rperezrosario/114299644066167176"TypeScript 6.0 is your final warning"
https://mastodon.social/@rperezrosario/116331807248668581"Announcing TypeScript 7.0"
https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/
-
Microsoft Principal Product Manager Daniel Rosenwasser writes an in-depth guide to TypeScript 7.0's July 8th release. As we have discussed here before, 7.0 is mostly about performance and developer experience.
"A 10x Faster TypeScript"
https://mastodon.social/@rperezrosario/114299644066167176"TypeScript 6.0 is your final warning"
https://mastodon.social/@rperezrosario/116331807248668581"Announcing TypeScript 7.0"
https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/
-
Microsoft Principal Product Manager Daniel Rosenwasser writes an in-depth guide to TypeScript 7.0's July 8th release. As we have discussed here before, 7.0 is mostly about performance and developer experience.
"A 10x Faster TypeScript"
https://mastodon.social/@rperezrosario/114299644066167176"TypeScript 6.0 is your final warning"
https://mastodon.social/@rperezrosario/116331807248668581"Announcing TypeScript 7.0"
https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/
-
Microsoft Principal Product Manager Daniel Rosenwasser writes an in-depth guide to TypeScript 7.0's July 8th release. As we have discussed here before, 7.0 is mostly about performance and developer experience.
"A 10x Faster TypeScript"
https://mastodon.social/@rperezrosario/114299644066167176"TypeScript 6.0 is your final warning"
https://mastodon.social/@rperezrosario/116331807248668581"Announcing TypeScript 7.0"
https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/
-
PlayStation is hiring Software Engineer I
🔧 #golang #java #javascript #python #typescript #react #node #aws #azure #cicd #docker #gcp #kubernetes
🌎 San Mateo, California, United States
⏰ Full-time
🏢 PlayStationJob details https://jobsfordevelopers.com/jobs/software-engineer-i-at-playstation-com-may-22-2026-8f23a6?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
PlayStation is hiring Software Engineer I
🔧 #golang #java #javascript #python #typescript #react #node #aws #azure #cicd #docker #gcp #kubernetes
🌎 San Mateo, California, United States
⏰ Full-time
🏢 PlayStationJob details https://jobsfordevelopers.com/jobs/software-engineer-i-at-playstation-com-may-22-2026-8f23a6?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
PlayStation is hiring Software Engineer I
🔧 #golang #java #javascript #python #typescript #react #node #aws #azure #cicd #docker #gcp #kubernetes
🌎 San Mateo, California, United States
⏰ Full-time
🏢 PlayStationJob details https://jobsfordevelopers.com/jobs/software-engineer-i-at-playstation-com-may-22-2026-8f23a6?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
PlayStation is hiring Software Engineer I
🔧 #golang #java #javascript #python #typescript #react #node #aws #azure #cicd #docker #gcp #kubernetes
🌎 San Mateo, California, United States
⏰ Full-time
🏢 PlayStationJob details https://jobsfordevelopers.com/jobs/software-engineer-i-at-playstation-com-may-22-2026-8f23a6?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
PlayStation is hiring Software Engineer I
🔧 #golang #java #javascript #python #typescript #react #node #aws #azure #cicd #docker #gcp #kubernetes
🌎 San Mateo, California, United States
⏰ Full-time
🏢 PlayStationJob details https://jobsfordevelopers.com/jobs/software-engineer-i-at-playstation-com-may-22-2026-8f23a6?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
so uh hi #askfedi, do you know any project NOT tainted from (or preferablly banning) ai/llm for webdev with #javascript ..
for years i usually make my private websites with preact and express both in #typescript, but lately happened to find both of the libraries were slop polluted, i wanna leave them 😞
i know ts also is and even if it weren't it's still maxxoslop's, but as it's a language and almost the only (kinda-)static typed alternative, it's way harder to ditch 😞
any input welcome 🥺 !
-
so uh hi #askfedi, do you know any project NOT tainted from (or preferablly banning) #ai/#llm for webdev with #javascript ..
for years i usually make my private websites with preact and express both in #typescript, but lately happened to find both of the libraries were slop polluted, i wanna leave them 😞
i know ts also is and even if it weren't it's still maxxoslop's, but as it's a language and almost the only (kinda-)static typed alternative, it's way harder to ditch 😞
any input welcome 🥺 !
-
so uh hi #askfedi, do you know any project NOT tainted from (or preferablly banning) #ai/#llm for webdev with #javascript ..
for years i usually make my private websites with preact and express both in #typescript, but lately happened to find both of the libraries were slop polluted, i wanna leave them 😞
i know ts also is and even if it weren't it's still maxxoslop's, but as it's a language and almost the only (kinda-)static typed alternative, it's way harder to ditch 😞
any input welcome 🥺 !
-
so uh hi #askfedi, do you know any project NOT tainted from (or preferablly banning) #ai/#llm for webdev with #javascript ..
for years i usually make my private websites with preact and express both in #typescript, but lately happened to find both of the libraries were slop polluted, i wanna leave them 😞
i know ts also is and even if it weren't it's still maxxoslop's, but as it's a language and almost the only (kinda-)static typed alternative, it's way harder to ditch 😞
any input welcome 🥺 !
-
FSD, Clean или modular? Шесть вариантов React-магазина под четырьмя изменениями
Мы вынесли компактную карточку банковской карты в entities/card/ui : маска номера, баланс и статус — решение казалось очевидным. Через два спринта в карточке появились действия «заблокировать карту» и «изменить лимит». В итоге entity начала импортировать features/block-card , features/change-card-limit и проверку прав доступа мимо public API. Когда ту же карточку понадобилось показать в выборе счёта списания, вместе с ней приехали ненужные зависимости и проверки ролей. Пользовательских инцидентов не случилось, но исправление отняло время. В entity оставили чистый CardPreview , сценарии подключили выше, композицию дашборда перенесли в widgets/card-summary , затем заново прогнали ролевые тесты. После этого на ревью мы стали обсуждать имя папки ближе к концу разговора. Сначала отвечали на другой вопрос: Какие будущие изменения выбранная граница позволит оставить локальными? В FSD 2.1 для подобных ситуаций рекомендуют начинать со страниц и извлекать код ниже по мере появления переиспользования. Это хороший вариант по умолчанию, хотя самостоятельный сценарий с близким вторым потребителем иногда оправдывает границу раньше.
https://habr.com/ru/articles/1060256/
#React #TypeScript #архитектура_фронтенда #FeatureSliced_Design #FSD #Clean_Architecture #модульная_архитектура #масштабирование_приложений #границы_модулей #рефакторинг
-
FSD, Clean или modular? Шесть вариантов React-магазина под четырьмя изменениями
Мы вынесли компактную карточку банковской карты в entities/card/ui : маска номера, баланс и статус — решение казалось очевидным. Через два спринта в карточке появились действия «заблокировать карту» и «изменить лимит». В итоге entity начала импортировать features/block-card , features/change-card-limit и проверку прав доступа мимо public API. Когда ту же карточку понадобилось показать в выборе счёта списания, вместе с ней приехали ненужные зависимости и проверки ролей. Пользовательских инцидентов не случилось, но исправление отняло время. В entity оставили чистый CardPreview , сценарии подключили выше, композицию дашборда перенесли в widgets/card-summary , затем заново прогнали ролевые тесты. После этого на ревью мы стали обсуждать имя папки ближе к концу разговора. Сначала отвечали на другой вопрос: Какие будущие изменения выбранная граница позволит оставить локальными? В FSD 2.1 для подобных ситуаций рекомендуют начинать со страниц и извлекать код ниже по мере появления переиспользования. Это хороший вариант по умолчанию, хотя самостоятельный сценарий с близким вторым потребителем иногда оправдывает границу раньше.
https://habr.com/ru/articles/1060256/
#React #TypeScript #архитектура_фронтенда #FeatureSliced_Design #FSD #Clean_Architecture #модульная_архитектура #масштабирование_приложений #границы_модулей #рефакторинг
-
FSD, Clean или modular? Шесть вариантов React-магазина под четырьмя изменениями
Мы вынесли компактную карточку банковской карты в entities/card/ui : маска номера, баланс и статус — решение казалось очевидным. Через два спринта в карточке появились действия «заблокировать карту» и «изменить лимит». В итоге entity начала импортировать features/block-card , features/change-card-limit и проверку прав доступа мимо public API. Когда ту же карточку понадобилось показать в выборе счёта списания, вместе с ней приехали ненужные зависимости и проверки ролей. Пользовательских инцидентов не случилось, но исправление отняло время. В entity оставили чистый CardPreview , сценарии подключили выше, композицию дашборда перенесли в widgets/card-summary , затем заново прогнали ролевые тесты. После этого на ревью мы стали обсуждать имя папки ближе к концу разговора. Сначала отвечали на другой вопрос: Какие будущие изменения выбранная граница позволит оставить локальными? В FSD 2.1 для подобных ситуаций рекомендуют начинать со страниц и извлекать код ниже по мере появления переиспользования. Это хороший вариант по умолчанию, хотя самостоятельный сценарий с близким вторым потребителем иногда оправдывает границу раньше.
https://habr.com/ru/articles/1060256/
#React #TypeScript #архитектура_фронтенда #FeatureSliced_Design #FSD #Clean_Architecture #модульная_архитектура #масштабирование_приложений #границы_модулей #рефакторинг
-
Es ist wieder eine Woche rum und beide bringen einen bunten Blumenstrauß an Themen mit. Sie freuen sich, dass das Thema pnpm gut angekommen ist, und tauchen dann ab in Themen wie #tuxedo #typescript #bun
Hört selbst rein:
👉 https://ready-for-review.dev/2026/07/17/rfr108-die-query-boys/
-
Es ist wieder eine Woche rum und beide bringen einen bunten Blumenstrauß an Themen mit. Sie freuen sich, dass das Thema pnpm gut angekommen ist, und tauchen dann ab in Themen wie #tuxedo #typescript #bun
Hört selbst rein:
👉 https://ready-for-review.dev/2026/07/17/rfr108-die-query-boys/
-
Es ist wieder eine Woche rum und beide bringen einen bunten Blumenstrauß an Themen mit. Sie freuen sich, dass das Thema pnpm gut angekommen ist, und tauchen dann ab in Themen wie #tuxedo #typescript #bun
Hört selbst rein:
👉 https://ready-for-review.dev/2026/07/17/rfr108-die-query-boys/
-
Es ist wieder eine Woche rum und beide bringen einen bunten Blumenstrauß an Themen mit. Sie freuen sich, dass das Thema pnpm gut angekommen ist, und tauchen dann ab in Themen wie #tuxedo #typescript #bun
Hört selbst rein:
👉 https://ready-for-review.dev/2026/07/17/rfr108-die-query-boys/
-
Es ist wieder eine Woche rum und beide bringen einen bunten Blumenstrauß an Themen mit. Sie freuen sich, dass das Thema pnpm gut angekommen ist, und tauchen dann ab in Themen wie #tuxedo #typescript #bun
Hört selbst rein:
👉 https://ready-for-review.dev/2026/07/17/rfr108-die-query-boys/
-
Chainlink Labs is hiring Senior Rust Software Engineer
🔧 #rust #golang #solidity #swift #typescript #blockchain #defi #web3 #aws #postgresql #terraform #seniorengineer
🌎 Remote; Toronto, Canada
⏰ Full-time
🏢 Chainlink LabsJob details https://jobsfordevelopers.com/jobs/senior-rust-software-engineer-at-chainlinklabs-com-jul-17-2024-393192?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
Chainlink Labs is hiring Senior Rust Software Engineer
🔧 #rust #golang #solidity #swift #typescript #blockchain #defi #web3 #aws #postgresql #terraform #seniorengineer
🌎 Remote; Toronto, Canada
⏰ Full-time
🏢 Chainlink LabsJob details https://jobsfordevelopers.com/jobs/senior-rust-software-engineer-at-chainlinklabs-com-jul-17-2024-393192?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
Chainlink Labs is hiring Senior Rust Software Engineer
🔧 #rust #golang #solidity #swift #typescript #blockchain #defi #web3 #aws #postgresql #terraform #seniorengineer
🌎 Remote; Toronto, Canada
⏰ Full-time
🏢 Chainlink LabsJob details https://jobsfordevelopers.com/jobs/senior-rust-software-engineer-at-chainlinklabs-com-jul-17-2024-393192?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
Chainlink Labs is hiring Senior Rust Software Engineer
🔧 #rust #golang #solidity #swift #typescript #blockchain #defi #web3 #aws #postgresql #terraform #seniorengineer
🌎 Remote; Toronto, Canada
⏰ Full-time
🏢 Chainlink LabsJob details https://jobsfordevelopers.com/jobs/senior-rust-software-engineer-at-chainlinklabs-com-jul-17-2024-393192?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
Chainlink Labs is hiring Senior Rust Software Engineer
🔧 #rust #golang #solidity #swift #typescript #blockchain #defi #web3 #aws #postgresql #terraform #seniorengineer
🌎 Remote; Toronto, Canada
⏰ Full-time
🏢 Chainlink LabsJob details https://jobsfordevelopers.com/jobs/senior-rust-software-engineer-at-chainlinklabs-com-jul-17-2024-393192?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring -
UnitTesterJS: Lightweight Unit Test Runner for Javascript
Runs test functions while keeping track of failures, logging them and to provide a summary. No dependencies, runs in the browser too. Works well with chai.
new in 2.1.0:
- Adds small PromiseStatus helper to inspect the state of promises and avoid some try/catch when testing for rejected promises.features: https://docs.miamao.de/@main/unittesterjs/?#features-and-configuration
-
UnitTesterJS: Lightweight Unit Test Runner for Javascript
Runs test functions while keeping track of failures, logging them and to provide a summary. No dependencies, runs in the browser too. Works well with chai.
new in 2.1.0:
- Adds small PromiseStatus helper to inspect the state of promises and avoid some try/catch when testing for rejected promises.features: https://docs.miamao.de/@main/unittesterjs/?#features-and-configuration
-
IntelliJ IDEA 2026.2 integriert Copilot und bietet Support für TypeScript 7.0
Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.
#Entwicklungsumgebung #IDE #IntelliJIDEA #IT #Java #JetBrains #TypeScript #news
-
IntelliJ IDEA 2026.2 integriert Copilot und bietet Support für TypeScript 7.0
Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.
#Entwicklungsumgebung #IDE #IntelliJIDEA #IT #Java #JetBrains #TypeScript #news
-
IntelliJ IDEA 2026.2 integriert Copilot und bietet Support für TypeScript 7.0
Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.
#Entwicklungsumgebung #IDE #IntelliJIDEA #IT #Java #JetBrains #TypeScript #news
-
IntelliJ IDEA 2026.2 integriert Copilot und bietet Support für TypeScript 7.0
Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.
#Entwicklungsumgebung #IDE #IntelliJIDEA #IT #Java #JetBrains #TypeScript #news
-
IntelliJ IDEA 2026.2 integriert Copilot und bietet Support für TypeScript 7.0
Die IDE ermöglicht die direkte Verwendung von GitHub Copilot und kann mit neuen Versionen der Programmiersprachen Java, Kotlin und TypeScript umgehen.
#Entwicklungsumgebung #IDE #IntelliJIDEA #IT #Java #JetBrains #TypeScript #news
-
Dew Drop - July 17, 2026 (#4714)
https://fed.brid.gy/r/https://alvinashcraft.com/2026/07/17/dew-drop-july-17-2026-4714/
-
So the upcoming NPM publish token changes are a potential lock-out scenario for people who're not using CI-based "Trusted Publishing" (TP) and cannot switch to "Staged Publishing" (SP) for reasons of practicality or feasibility.
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
The first approach (TP) requires a compatible CI platform (currently only Github, Gitlab or CircleCI supported), the latter requires manual approvals by a human, for each single publishing attempt... Both approaches are seemingly per-package solutions only, meaning for a full release of my https://thi.ng/umbrella monorepo I'd either have to use one of the three CI platforms above and manually fill out 216 forms (one per package) to register each package for TP. Alternatively, for SP I'd have to manually approve (with 2FA) each staged package (also up to 200+ times). No batch process/approval workflows mentioned or envisioned! Just who are these people making plans like this?!
If this proposal doesn't change, then it means I (and others in similar situations) won't be able to publish my projects anymore after January 2027, when this all is planned to come into force. End of the road! Open source enclosed at the point of publishing by monopolistic infrastructure...
I understand security is important, but these problems should (MUST!) be approached & solved differently. It's simply unreasonable to force developers to figure out how to re-adapt their release tooling every few months toward ever tighter and increasingly hostile decision-making on NPM's end, without any choice in the matter...
If you can, please contribute your views to the discussion on Github:
https://github.com/orgs/community/discussions/201329#NPM #OpenSource #Release #InfoSec #2FA #TypeScript #JavaScript
-
So the upcoming NPM publish token changes are a potential lock-out scenario for people who're not using CI-based "Trusted Publishing" (TP) and cannot switch to "Staged Publishing" (SP) for reasons of practicality or feasibility.
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
The first approach (TP) requires a compatible CI platform (currently only Github, Gitlab or CircleCI supported), the latter requires manual approvals by a human, for each single publishing attempt... Both approaches are seemingly per-package solutions only, meaning for a full release of my https://thi.ng/umbrella monorepo I'd either have to use one of the three CI platforms above and manually fill out 216 forms (one per package) to register each package for TP. Alternatively, for SP I'd have to manually approve (with 2FA) each staged package (also up to 200+ times). No batch process/approval workflows mentioned or envisioned! Just who are these people making plans like this?!
If this proposal doesn't change, then it means I (and others in similar situations) won't be able to publish my projects anymore after January 2027, when this all is planned to come into force. End of the road! Open source enclosed at the point of publishing by monopolistic infrastructure...
I understand security is important, but these problems should (MUST!) be approached & solved differently. It's simply unreasonable to force developers to figure out how to re-adapt their release tooling every few months toward ever tighter and increasingly hostile decision-making on NPM's end, without any choice in the matter...
If you can, please contribute your views to the discussion on Github:
https://github.com/orgs/community/discussions/201329#NPM #OpenSource #Release #InfoSec #2FA #TypeScript #JavaScript
-
So the upcoming NPM publish token changes are a potential lock-out scenario for people who're not using CI-based "Trusted Publishing" (TP) and cannot switch to "Staged Publishing" (SP) for reasons of practicality or feasibility.
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
The first approach (TP) requires a compatible CI platform (currently only Github, Gitlab or CircleCI supported), the latter requires manual approvals by a human, for each single publishing attempt... Both approaches are seemingly per-package solutions only, meaning for a full release of my https://thi.ng/umbrella monorepo I'd either have to use one of the three CI platforms above and manually fill out 216 forms (one per package) to register each package for TP. Alternatively, for SP I'd have to manually approve (with 2FA) each staged package (also up to 200+ times). No batch process/approval workflows mentioned or envisioned! Just who are these people making plans like this?!
If this proposal doesn't change, then it means I (and others in similar situations) won't be able to publish my projects anymore after January 2027, when this all is planned to come into force. End of the road! Open source enclosed at the point of publishing by monopolistic infrastructure...
I understand security is important, but these problems should (MUST!) be approached & solved differently. It's simply unreasonable to force developers to figure out how to re-adapt their release tooling every few months toward ever tighter and increasingly hostile decision-making on NPM's end, without any choice in the matter...
If you can, please contribute your views to the discussion on Github:
https://github.com/orgs/community/discussions/201329#NPM #OpenSource #Release #InfoSec #2FA #TypeScript #JavaScript
-
So the upcoming NPM publish token changes are a potential lock-out scenario for people who're not using CI-based "Trusted Publishing" (TP) and cannot switch to "Staged Publishing" (SP) for reasons of practicality or feasibility.
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
The first approach (TP) requires a compatible CI platform (currently only Github, Gitlab or CircleCI supported), the latter requires manual approvals by a human, for each single publishing attempt... Both approaches are seemingly per-package solutions only, meaning for a full release of my https://thi.ng/umbrella monorepo I'd either have to use one of the three CI platforms above and manually fill out 216 forms (one per package) to register each package for TP. Alternatively, for SP I'd have to manually approve (with 2FA) each staged package (also up to 200+ times). No batch process/approval workflows mentioned or envisioned! Just who are these people making plans like this?!
If this proposal doesn't change, then it means I (and others in similar situations) won't be able to publish my projects anymore after January 2027, when this all is planned to come into force. End of the road! Open source enclosed at the point of publishing by monopolistic infrastructure...
I understand security is important, but these problems should (MUST!) be approached & solved differently. It's simply unreasonable to force developers to figure out how to re-adapt their release tooling every few months toward ever tighter and increasingly hostile decision-making on NPM's end, without any choice in the matter...
If you can, please contribute your views to the discussion on Github:
https://github.com/orgs/community/discussions/201329#NPM #OpenSource #Release #InfoSec #2FA #TypeScript #JavaScript
-
So the upcoming NPM publish token changes are a potential lock-out scenario for people who're not using CI-based "Trusted Publishing" (TP) and cannot switch to "Staged Publishing" (SP) for reasons of practicality or feasibility.
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
The first approach (TP) requires a compatible CI platform (currently only Github, Gitlab or CircleCI supported), the latter requires manual approvals by a human, for each single publishing attempt... Both approaches are seemingly per-package solutions only, meaning for a full release of my https://thi.ng/umbrella monorepo I'd either have to use one of the three CI platforms above and manually fill out 216 forms (one per package) to register each package for TP. Alternatively, for SP I'd have to manually approve (with 2FA) each staged package (also up to 200+ times). No batch process/approval workflows mentioned or envisioned! Just who are these people making plans like this?!
If this proposal doesn't change, then it means I (and others in similar situations) won't be able to publish my projects anymore after January 2027, when this all is planned to come into force. End of the road! Open source enclosed at the point of publishing by monopolistic infrastructure...
I understand security is important, but these problems should (MUST!) be approached & solved differently. It's simply unreasonable to force developers to figure out how to re-adapt their release tooling every few months toward ever tighter and increasingly hostile decision-making on NPM's end, without any choice in the matter...
If you can, please contribute your views to the discussion on Github:
https://github.com/orgs/community/discussions/201329#NPM #OpenSource #Release #InfoSec #2FA #TypeScript #JavaScript
-
Another #ThingUmbrella release cycle this AM:
- fixed yesterday's https://thi.ng/geom-io-obj stream parser update to also support #Safari (aka the modern IE6-like browser problem child), which in the release notes for Safari v26.4 claims[1] that
ReadableStreamcan (finally) be iterated viafor await(...)syntax, but then turns out it's still only planned for v27 [2]... 🙄 - added async versions of all timing & benchmarking functions in https://thi.ng/bench to support benchmarking async functions
[1] https://webkit.org/blog/17862/webkit-features-for-safari-26-4/#web-api
[2] https://developer.mozilla.org/en-US/docs/Web/API/ReadableStream#browser_compatibility - fixed yesterday's https://thi.ng/geom-io-obj stream parser update to also support #Safari (aka the modern IE6-like browser problem child), which in the release notes for Safari v26.4 claims[1] that