Vladimir
@erus.dev
📤 2131
📥 158
📝 254
Team member of
@vite.dev
and
@vitest.dev
📍 Berlin, Germany
https://github.com/sheremet-va
reposted by
Vladimir
patak
3 days ago
what are we even doing?
add a skeleton here at some point
3
62
6
reposted by
Vladimir
Vite
3 days ago
We've published two Windows-related security advisories: ◇ If Vite runs with `--host`, denied files may have been reachable over the network. ◇ launch-editor with NTLM enabled may leak NTLMv2 hashes via a malicious page. Update to Vite 8.0.16/7.3.5/6.4.3, Vite+ 0.1.24, and launch-editor 2.14.1.
1
29
5
reposted by
Vladimir
Vitest
3 days ago
We've published a Browser Mode security advisory. CDP-capable providers like Playwright Chromium with the browser API exposed to the network allowed attackers to run code on the host. Update vitest/browser to 5.0.0-beta.4, 4.1.8, or 3.2.6. Vite+ users: Upgrade to 0.1.24
github.com/vitest-dev/v...
loading . . .
Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
## Summary Vitest Browser Mode exposes a `cdp()` API that forwards raw Chrome DevTools Protocol (CDP) methods over the Vitest browser WebSocket RPC. CDP is not gated by `browser.api.allowWrite`,...
https://github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhm
0
26
6
reposted by
Vladimir
Vue Fes Japan
3 days ago
/ 📢 Vue Fes Japan 2026 CFP is now open‼️ \ The Call for Proposals for Vue Fes Japan 2026 is now open. Submit here 👇
docs.google.com/forms/d/e/1F...
Full details in this article ✨
note.com/tutti2612/n/...
We can't wait to see your proposals!
#vuefes
loading . . .
https://docs.google.com/forms/d/e/1FAIpQLSfpEFc6XHAgaA_-1dOMZhYoFCthBQ9DYmE3wukJAO-TR6VJpA/viewform
0
8
3
reposted by
Vladimir
AriPerkkio
3 days ago
Building this integration has been amazing opportunity to dogfood all APIs we've added into
@vitest.dev
in past years. It's using features like new Reporter APIs, Vitest plugin hooks, browser commands, CDP, test tags and much more! Vitest is definitely one of the most extensible JS tools out there.
add a skeleton here at some point
1
22
7
reposted by
Vladimir
Willow (GHOST)
3 days ago
happy pride month 🎉
0
163
28
reposted by
Vladimir
Willow (GHOST)
3 days ago
Rumor has it... if SvelteKit reaches #2... we'll rewrite npmx in it 👀
add a skeleton here at some point
3
25
2
reposted by
Vladimir
Dominik 🇳🇴 React Norway
4 days ago
“Opened 296 other pull requests in 27 repositories”
loading . . .
Eric Kofi Abrefa: I'm Just Tired
Alt: Eric Kofi Abrefa: I'm Just Tired
https://static.klipy.com/ii/925f17378dd1893b674a723c07535afe/04/0f/vfrmWvuS.gif?hh=498&ww=498&mp4=Co39FkjO&webm=DXIqEOjgEyAKjX
1
45
1
reposted by
Vladimir
Rebane
10 days ago
i made a new game called js crossword where you have to solve it by literally writing javascript code that eval()'s into the correct values! check it out if you're into ctfs or wanna challenge your javascript skills
lyra.horse/fun/jscrossw...
<3
23
211
69
reposted by
Vladimir
Matteo Gabriele
5 days ago
If you're feeling burned out because your motivation is fading due to today's tech news or your job, join communities like
@npmx.dev
,
@e18e.dev
, and other OSS projects to get your drive back. Stay away from AI agents and interact with real people. It's one of the best things that happened to me.
4
116
18
reposted by
Vladimir
Ursula von der Leyen
6 days ago
Dear Peter Magyar, it has only been a few weeks. But we can feel a strong wind of change across Hungary. Fight corruption. To kickstart economic recovery. And restore the rule of law. Today we share the progress made ↓
link.europa.eu/9PH3Dh
9
421
60
reposted by
Vladimir
Chromatic
7 days ago
We’re launching early access for Vitest visual testing with Chromatic! ⚡️ Built with
@vitest.dev
core maintainer
ariperkkio.dev
, Chromatic adds visual testing to the browser tests you already write. 🧵 (1/4)
3
53
11
reposted by
Vladimir
npmx
8 days ago
console.log("happy birthday,
@nodejs.org
!")
4
121
13
reposted by
Vladimir
☀️ Jon Schwarz ☀️
8 days ago
This is the most incredible triumph of propaganda in my lifetime. The idea that Hitler was "left" and/or a "socialist" once was correctly seen as self-evidently insane. But here we have the richest & most powerful man on earth blithely repeating it.
167
2556
566
reposted by
Vladimir
Zoltan Kochan
9 days ago
Check this out
3
50
3
reposted by
Vladimir
Armin Ronacher
9 days ago
More musings after some people got upset about the word clanker.
lucumr.pocoo.org/2026/5/26/cl...
loading . . .
Clanker: A Word For The Machine
Why I like the word clanker and why machines are not people.
https://lucumr.pocoo.org/2026/5/26/clankers/
14
66
15
reposted by
Vladimir
Wilco
9 days ago
In
@npmx.dev
you can now view a package's changelogs currently only package's that use Github to host their releases or
changelog.md
are supported but support for others are planned
loading . . .
4
94
22
reposted by
Vladimir
James
9 days ago
the
@e18e.dev
npm publishing guide has been updated to recommend the new `npm stage` feature! this guide and the templates it offers are a good way to get setup quickly in a secure way
loading . . .
e18e (Ecosystem Performance) - Best Practices on Publishing npm Packages
Best practices on publishing npm packages securely using GitHub Actions.
https://e18e.dev/docs/publishing.html
1
41
12
reposted by
Vladimir
Bjorn Lu
10 days ago
We’ve been working on a new site for Changesets with a lot of new docs! If changesets has been confusing before, hopefully some of these will help, or let us know what else could be improved. Check it out 👉
changesets.dev
loading . . .
Changesets
A tool to manage versioning and changelogs with a focus on monorepos
https://changesets.dev
5
90
18
reposted by
Vladimir
Filippo Valsorda
12 days ago
This might be what vexes me most of the unforced GitHub Actions minefield. Commenting on PRs is PUBLIC. Any registered account can do it without permissions!! And yet if you want an automation to comment, you’re encouraged to run it as a privileged, dangerous pull_request_target job.
add a skeleton here at some point
4
153
14
reposted by
Vladimir
danielroe in london 🏴
12 days ago
🙋♂️ do I know any oss friends who are facing unwelcome LLM-generated PRs or comments? .... want to fight back?
27
124
18
reposted by
Vladimir
Deno
13 days ago
`import defer` is the new ES2025 syntax for lazy module loading. Deno is the first runtime to ship it and with TypeScript support. Big win for CLI startup and conditionally-loaded code.
2
27
6
reposted by
Vladimir
James
14 days ago
Woooo yeaaah! The missing piece 🎉 everything is about to get a lot more secure
loading . . .
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
https://docs.npmjs.com/staged-publishing
5
127
33
reposted by
Vladimir
Willow (GHOST)
14 days ago
Oh, we know
add a skeleton here at some point
2
34
1
reposted by
Vladimir
Vlad-Stefan Harbuz
14 days ago
OSS burnout claims another project. On 2 Apr, an entitled user angrily asked the burned-out maintainer of nvim-treesitter to “go switch to something that doesn't require interacting with people”. The maintainer replied “OK” — and archived the repo, stopping development of nvim-treesitter.
loading . . .
Open Source Burnout Claims Another Project
Yet another OSS maintainer quits because of burnout. To fix this, we need better mental health resources for maintainers.
https://vlad.website/nvim-treesitter-burnout/
6
192
66
reposted by
Vladimir
Marvin Hagemeister
15 days ago
Module mocking in test runners is the devil. Prevents so many performance opportunities.
5
28
1
reposted by
Vladimir
Yann Braga
15 days ago
What do you think of a dev tool that helps you inspect components in your live app and then save that snapshot as a story in Storybook? 🤔 Backed by the incredible Vite devtools of course
@antfu.me
<3
loading . . .
3
43
9
reposted by
Vladimir
danielroe in london 🏴
15 days ago
I can't believe I asked
@rich-harris.dev
for an opinion
0
19
1
reposted by
Vladimir
danielroe in london 🏴
15 days ago
it's just possible I may have been killed. 💀
19
117
2
reposted by
Vladimir
James
15 days ago
GitHub is not having a good time recently 😬 I hope the teams over there can figure this stuff out
4
31
2
reposted by
Vladimir
Matteo Gabriele
15 days ago
Winter is coming.
1
9
2
reposted by
Vladimir
Roman
15 days ago
GitHub actions publishers, please use immutable releases!
loading . . .
e18e (Ecosystem Performance) - Best Practices on Publishing npm Packages
Best practices on publishing npm packages securely using GitHub Actions.
https://e18e.dev/docs/publishing.html#use-immutable-releases
0
31
10
reposted by
Vladimir
Alexander Lichter
15 days ago
A well-written bug report is worth so much more than a drive-by PR with a "solution". Showing us maintainers how to reproduce it is often the real work and improves debugging your skills!
1
36
6
reposted by
Vladimir
Vitest
16 days ago
🚨 We are publishing Vitest 4.1.6 and Vitest 5.0.0-beta.3 to resolve recent vulnerabilities: - `--api` and `--ui` exposed arbitrary files to the network - `--api` allowed arbitrary execution - `?otelCarrier` XSS Check
github.com/vitest-dev/v...
for more information
loading . . .
Build software better, together
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
https://github.com/vitest-dev/vitest/security
0
43
10
reposted by
Vladimir
{🧪} +paoloricciuti.svelte
17 days ago
Proof that
@danielroe.dev
will definitely pass if it doesn't use svelte
5
28
2
reposted by
Vladimir
Firefox for Web Developers
17 days ago
Chrome shipped an LLM Prompt API to the web platform. At Mozilla, we oppose this API. Here's why:
loading . . .
18
417
139
reposted by
Vladimir
Marvin Hagemeister
17 days ago
Speeding up the JS ecosystem OXC edition 🚀 We made both oxfmt and oxlint 50% faster on projects with >50k directories.
marvinh.dev/blog/speedin...
loading . . .
Speeding up the JavaScript ecosystem - oxlint and oxfmt
Future versions of oxlint and oxfmt will be ~50% faster on projecs with many (>=20k) directories.
https://marvinh.dev/blog/speeding-up-javascript-ecosystem-part-13/
7
181
29
reposted by
Vladimir
nate moore
21 days ago
many such cases
14
479
52
reposted by
Vladimir
VoidZero
19 days ago
Couldn't keep up with all the news? We got some selected highlight from last month to recap! 🌀 → Vite Plus lazyPlugins API →
@vitest.dev
5 sneak peak → Oxlint: RFC for linting Svelte/Vue/Angular templates → Module Federation in
@vite.dev
via plugin →
@npmx.dev
vp option
youtu.be/zwY4UZr-qjc
0
49
11
reposted by
Vladimir
Antoine
20 days ago
> *open Twitter* > Bun’s controversial rewrite, Next.js/Tanstack CVEs, ragebait for money, new terrible AI photo processing… > *close Twitter* > *open Bluesky* > just patak literally cooking What a peaceful world, how do you survive in the warzone that’s the other app
add a skeleton here at some point
8
139
7
reposted by
Vladimir
patak
21 days ago
I'll go against the discourse. 280 contributors to
repo.npmx.dev
in 100 days. We only used bluesky for social comms. We asked while welcoming folks, and most of them got involved after reading our bsky posts. Thanks for building and running bluesky. This network is a great place to do open source 💙
add a skeleton here at some point
4
183
21
reposted by
Vladimir
patak
21 days ago
Wild to see that
@npmx.dev
was the fastest-growing emerging open source organization by number of contributors in Q1 2026 according to
osscar.dev
. What is even more interesting: it was the only non-AI tool in the top 10.
2
128
15
reposted by
Vladimir
Andras Bacsai
22 days ago
We made a fake repo with fake bounties, and the bots are applying fake PRs, so we know who is fake, and we can ban them from the Coolify repo. IQ over 1000
42
2016
387
reposted by
Vladimir
Cult.Repo
23 days ago
Have you ever written the words "Hello, World"? Did you ever wonder who typed it first? And why? Brian Kernighan, co-author of the book that defined the C language, has the answer. Find out in this outtake from our upcoming C++ documentary.
youtu.be/vLer3fRwwxE
loading . . .
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
https://youtu.be/vLer3fRwwxE
0
2
1
reposted by
Vladimir
Alec Lloyd Probert
24 days ago
New feature on
@npmx.dev
🎉 The timeline tab now comes with a chart, so it is easier to see the evolution of the package size and its dependencies. The positive and warning events queried from
@e18e.dev
are great to check the package health ❤️
loading . . .
7
126
19
reposted by
Vladimir
patak
24 days ago
Mythos' underwhelming results for curl are a great example of why Open Source is even more important now that we have access to these tools. curl is more secure because everyone can tinker with it. We should be doubling down on Open Source rather than closing projects in panic.
add a skeleton here at some point
6
198
44
reposted by
Vladimir
Smosh Out of Context
25 days ago
loading . . .
1
62
32
reposted by
Vladimir
marissa walmart dog
3 months ago
loading . . .
2
71
13
reposted by
Vladimir
Josh Goldberg
27 days ago
This 100%. My approachability and willingness to help have gone down across the board. It's not joyous anymore.
add a skeleton here at some point
0
52
2
Load more
feeds!
log in