Npm Slop & Wonky Software Supply Chains

What's wrong with Electron IPC and how it could be improved

Rust is eating JavaScript (2021, upd. 2026)

Quo now has payload diffing!

Parse, Don't Validate — In a Language That Doesn't Want You To · cekrem.github.io

3 pnpm Settings to Protect Yourself from Supply Chain Attacks

CheerpJ 4.3 - Run unmodified Java applications in the browser

CanvasKit Documentation with interactive examples

Announcing Rspack 2.0

Scratchpad for JavaScript and TypeScript. Open-source alternative to RunJS

Are event handlers scheduled asynchronously on the event loop? MDN says they do - I'm pretty sure that's wrong

diagrams-js - Cloud architecture diagrams as code

TTSC, TypeScript-Go compiler and runner with transformer plugins (10x faster than ts-node)

I Built a Lightweight Headless Browser Because Chrome Was Too Slow

styled-components 6.4 now available

Why did everyone stop using Meteor.js?

What To Know in JavaScript (2026 Edition)

Trustlock: a dependency admission controller that enforces npm trust signals as policy

Release Apache Fory Serialization For JavaScript: Schema Evolution, Shared/Circular Reference and 4X faster than Protobuf

I built an open-source WYSIWYG editor in vanilla JavaScript (no frameworks, CDN-ready)

Preload Google Fonts Before the CSS Waterfall Starts

The Blueprint of a North Korean Attack on Open-Source

Just shipped docmd 0.7.0 : zero-config docs with native i18n

The Axios supply chain attack used individually targeted social engineering

SVG Jar - The best way to use SVGs in your web apps

I don't chain everything in JavaScript anymore

Pushing a Linux shell experience further in a static website

Critical flaw in Protobuf library enables JavaScript code execution

puru - a JavaScript concurrency library for worker threads, channels, and structured concurrency

North Korean threat group published 60+ malicious npm packages over 7 months, specifically designed to fool AI coding agents into installing them (PromptMink)

More →