Please stop this Pretext madness!

PSA: axios 1.14.1 and 0.30.4 are compromised — open-source scanner detects the plain-crypto-js backdoor

Built a lifecycle-first frontend runtime (no VDOM, direct DOM ownership)

I built memscope — a real-time memory profiler for Node.js + browser. Zero config, live dashboard, 605 downloads in its first few months

Environment Variables You're Leaking to the Frontend Without Knowing It

Washi, a pin-based commenting for any iframe-rendered page. Drop Figma-style annotation pins directly on live HTML content

Echo Shift: A Unique Puzzle Game

dead framework theory

I built a zero-dependency CLI that catches source leaks and supply chain attacks across 7 languages

Anthropic accidentally shipped source maps in their NPM package, exposing Claude Code's entire 380k-line TypeScript source

I built an open source npm supply chain monitor with eBPF kernel monitoring after the Axios attack

If you joined the Electron core team tomorrow, what would you fix/improve first?

Axios npm package compromised with RAT malware via hijacked maintainer account — versions 1.14.1 and 0.30.4 affected

Do users struggle with your app's complexity?

State machines feel heavy for UI flows. What are people using?

Building an affordable SEO + AEO + GEO SaaS , Need feedback ?

Lightweight IDE recommendations for JS/TS + React + React Native?

Atlas: a universal self-hosted package registry.

React is overkill for embeddable widgets - Preact + iframe isolation is a better default

Ghost AI Coder: Desktop App for Coding Interviews Using TypeScript, React & Electron - Looking for Feedback

Has anyone else noticed malicious npm packages targeting AI coding tools? My scanner found 21 in 24 hours with 4 undocumented attack vectors

Temporal: The 9-year journey to fix time in JavaScript

The three pillars of JavaScript bloat

axios 1.14.1 and 0.30.4 on npm are compromised - dependency injection via stolen maintainer account

We Added a Console Notice to Internationalizationext – and Why We Removed It

Debounce is not enough: handling stale responses with AbortController and retries

Supply Chain Attack on Axios

Vite 8.0 Is Out

Basic physics engine in about 100 lines of pure JavaScript

Prerelease of Ky 2.0

More →