I built a tiny JS framework to keep business logic clean — would love feedback

Ember.js 7.0

Rewrite Bun in Rust has been merged

Show r/javascript: I’m working on a fork of Mozilla’s PDF.js focused on exploring native PDF editing in the browser.

Mass NPM Supply Chain Attack Hits TanStack, Mistral AI, and 170 Packages

5 Years and $5M Later: Inventing a New Programming Language for Web Development Was a Mistake

I built a JavaScript execution visualizer — call stack, heap memory, and event loop in real time

From 81s to 2.5s by migrating to Oxlint & Oxfmt

You might not need… the repository pattern

BlueJS - Compile JavaScript to 1.2MB native binaries (no V8)

How I made $350K from an open-source JavaScript library using dual licensing

Stop Using Yarn Classic

The Bun CVE Gap: When Your Package Manager Can't Do Surgical Updates

Node.js worker threads are problematic, but they work great for us

Postmortem: TanStack NPM supply-chain compromise

kysely 0.29 is out btw.

A Linux-like kernel in a browser tab - deep dive in the BrowserPod architecture

HYML Sanitizer API

I built StreamShield: A Twitch/Kick ad-blocker using a custom stream-recovery engine (Manifest V3)

Make install scripts opt-in · npm/rfcs

The Unreasonable Effectiveness of ProseMirror Model in Rich Text Transformation

9 Times the Web Platform was Influenced by Libraries

Mini Shai-Hulud npm worm compromises 160+ packages, including TanStack-related packages

TravelsJS v1.3 - Patch-based undo/redo optimized for large state, small updates, long history, and persistence.

Saying goodbye to asm.js

turned my website’s procedural backgrounds into a standalone vanilla js engine. here's how to use it in yours, if you fancy this.

TrapDoor supply-chain campaign targeted npm, PyPI, and Crates.io packages

CSS vs. JavaScript

How I patched Firefox to bypass fingerprinting anti-bot

MikroORM 7.1: LazyRef, per-parent collection limiting, PGlite driver, query cancellation, database triggers, stored procedures, and more

More →