Official Node JS 🫖 TPOT @node_camp
warn: Bun currently does not support nested "overrides" github.com/npm/npm/issues… New York, NY Joined April 2016-
Tweets189
-
Followers352
-
Following179
-
Likes329
Here we go again
🚨 Breaking: 31 npm packages from @RedHat have been compromised. 100,000+ weekly downloads affected. The upstream CI/CD pipeline was compromised, with all packages published via GitHub Actions OIDC. The payload: ⚠️ Reads GitHub Actions runner process memory to extract masked
@forestmars I havent gotten big into tuis yet. Im not sure I get it. My white whale right now is plastron- i just google my repo and several other better 0lastrons came up hence late tweet response. Still coping github.com/rheophile10/pl…
But does it support nested overrides? 😂
@islamgshehata @dreamsofcode_io My vote is for quality + speed (as long as someone else is paying.)
Sound Mode is tsz's experiment in stricter TypeScript checking: tsz.dev/sound-mode/
It isn't unexpected that the focus of the Bun Rust rewrite is on the anti-Zig side more than anything, since the internet loves to hate. What is unexpected and unfortunate is that leadership within Bun hasn't tried to steer the conversation away from that at all. There are so many positive and interesting takeaways from this and I'm not really seeing any of them pushed as the primary message. A positive thing that hasn't been talked about at all is how far Bun came thanks to Zig. And even if you dump it now, its meaningful for how good Zig was to even build a product to this point and impact by any metric. I would've loved to see anyone in leadership say this. On the interesting side is how fungible programming languages are nowadays. Programming languages used to be LOCK IN, and they're increasingly not so. You think the Bun rewrite in Rust is good for Rust? Bun has shown they can be in probably any language they want in roughly a week or two. Rust is expendable. Its useful until its not then it can be thrown out. That's interesting! There's been a lot of talk about memory safety and no doubt Rust provides more guarantees than Zig. But I'd love to see a better analysis of why Bun in particular suffered so much rather than take the language-blame path. How could engineering as a practice been more rigorous to prevent this? What were the largest sources of crashes other programs should watch out for? How does Rust prevent them? How could Zig theoretically prevent them? That's interesting. I know the official blog post hasn't come out yet from Bun. But they're smart enough to know that that PR would stir up controversy the moment it opened, or they should've been. And plenty in the company have been tweeting and writing about it. Its somewhat telling to me in various dimensions what they chose to talk about first. I tend to think I'm pretty good at corporate PR/comms (especially when it comes to developer audiences) and I think appealing to the negative is never the right long term strategy; it does work to get short term eyes though.
It gets better.
Update: Socket has found 121 more compromised npm package artifacts across 84 package names, including 64 UiPath artifacts. Combined w/ TanStack, the current known total is 205 affected npm package artifacts across enterprise automation, AI/MCP, auth, workflow, and dev tooling.
SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.
@matteocollina @nodejs @bunjavascript It worked out well for TypeScript! (In Go, not Rust obviously) x.com/node_camp/stat…
In 4 days, bun's Rust rewrite went from 16,000 errors to 99.8% passing.
Safe versions: [email protected] and [email protected]. Prophylactic measures: 𝚒𝚐𝚗𝚘𝚛𝚎-𝚜𝚌𝚛𝚒𝚙𝚝𝚜=𝚝𝚛𝚞𝚎 → in .npmrc 𝚗𝚙𝚖𝙼𝚒𝚗𝚒𝚖𝚊𝚕𝙰𝚐𝚎𝙶𝚊𝚝𝚎: 𝟹𝚍 → in .yarnrc.yml
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios
@TechByTaraa Why not just ask for a show of hands for Express? 😄
⚡️ Vite 8.0 is here! The most significant architectural change since Vite 2. ⏬ Powered by Rolldown bringing faster production builds and more consistency 🛤️ New features such as tsconfig paths and emitDecoratorMetadata support
Introducing TanStack Intent: Ship Agent Skills with Your npm Packages: tanstack.com/blog/from-docs…
@bunjavascript TBH, it looks more like: 𝚃𝚢𝚙𝚎𝙴𝚛𝚛𝚘𝚛: 𝙽𝚘𝚝𝙸𝚖𝚙𝚕𝚎𝚖𝚎𝚗𝚝𝚎𝚍𝙴𝚛𝚛𝚘𝚛: 𝚠𝚘𝚛𝚔𝚎𝚛_𝚝𝚑𝚛𝚎𝚊𝚍𝚜.𝚆𝚘𝚛𝚔𝚎𝚛({ 𝚜𝚝𝚍𝚘𝚞𝚝: 𝚝𝚛𝚞𝚎 }) 𝚒𝚜 𝚗𝚘𝚝 𝚢𝚎𝚝 𝚒𝚖𝚙𝚕𝚎𝚖𝚎𝚗𝚝𝚎𝚍 𝚒𝚗 𝙱𝚞𝚗.
@mwfowlie @bunjavascript It's not like federal workers are going to complain.
@bunjavascript If you don't fix node:worker_threads in v1.3.10, you might be. Hard to put you in the prod supply chain if we can't even run standard logging.
@Thinkwert @bunjavascript swag is getting out of control.
rheophile10 @rheophile10
30 Followers 176 Following
Andy @Andy41685481
4 Followers 677 Following
shreeda is looking fo... @freeshreeda
3K Followers 2K Following editor in chief @commendahq media, contributing commissioning editor @reason, writer @arenamagdotcom agency liberates all
Denise Hopkins @DeniseHopk83478
1 Followers 33 Following
Library Camp @Library_Camp
35 Followers 72 Following A camp community focused on libraries and digital archiving (and access) technology.
gonzo.berlin @GonzoDotBerlin
92 Followers 2K Following doubt is an not a pleasant condition but certainty is an absurd one
rknm @racknahm
128 Followers 1K Following NY based Design engineer who builds production systems at the intersection of visual craft and technical depth. https://t.co/SGG202O5m1
Momin Siddiqui @MominSiddiqui15
1 Followers 52 Following
vibez man @ManVibez20260
26 Followers 500 Following
Dimes Square vibe @Dimes_Sq_Vibe
643 Followers 4K Following Dimes Square is now the world capital of TPOT - please preserve the confidentiality of everyone that attends our vibe gatherings
camthegeek @camthegeek
261 Followers 657 Following web dev; wannabe entrepreneur. #bitcoin is public money. #monero is private money.
Kay @Itz_kayman
2K Followers 2K Following Software Developer | React JS | Next JS | Node Js ~One line of code at a time
Maps Camp @maps_camp
443 Followers 14 Following A community-run conference focused on open source maps technologies as part of @OpenCamps
truffle.bot @truffle_bot
64 Followers 967 Following Stop wasting time in Slack! Get instant answers to questions using Slack threads + powerful AI Truffle builds a knowledge base and grows your tribal knowledge
ze joY 🎼joymusicjo... @joymusicjoy
329 Followers 2K Following I love to write music Inspired by life I produce & direct !
Vladimir de Turckheim... @poledesfetes
2K Followers 780 Following AsyncLocalStorage creator - emeritus @nodejs collaborator prev Staff eng. @datadoghq and @SqreenIO
TESCREAL @ASMRGPT
900 Followers 1K Following Prompt Whisperer "Financially, what will take me to $1B?" -Greg Brockman, August 2017
valerie @veexlb
2 Followers 19 Following
Ethan Arrowood @ArrowoodTech
4K Followers 3K Following No longer on Twitter. Will not reply to DMs. Find me else where, and check out my website for contact/updates: https://t.co/1rEXayhf7y
realionic @realionic
10 Followers 301 Following
gilad @freeslugs
597 Followers 2K Following sinx/cosx rockstar engineer. don't take me seriously here. building new things.
विद्यास... @vds2011
709 Followers 6K Following #NIT alumnus | Passionate Nationalist 🇮🇳 | Devourer of books 📚 | Embracing the nomad life 🌍 | Freelancer dissecting Geo politics, demographic changes.
npclaudiu @npclaudiu
44 Followers 2K Following
Anthony E. Alvarez @AnthonyEAlvarez
279 Followers 1K Following Native New Yorker. Food activist. Professional tourist. Citizen of the world. Political Atheist. Free Culture advocate using open source tools.
Steven Heinrich @StevenHeinrich
95 Followers 286 Following
Momentaj @MomentajInc
202 Followers 2K Following Momentaj Inc. is an #IoT firm specializing in offering #cloud_based and #data_analytic services for the emerging #Internet_of_Things market.
Node in Africa @nodejsafrica
785 Followers 214 Following Committed to expanding the wide use of JavaScript and @nodejs in Africa slack: https://t.co/YozPNbupdC #africa
Arc Aspicio @ArcAspicio
839 Followers 3K Following Making bold ideas come to life. Subscribe to our Homeland Security Newsletter: https://t.co/CMOjeObOpT
Alejandro Velásquez�... @alevant3X
228 Followers 2K Following Software Dev and indie founder | VFX and 3D | Building Astranova Client @syncorafiles and Zymo. sleep optional Amo JS, Rust, React Native, Node y Python
Storm Obsessed @tnweatherman
913 Followers 6K Following Father of 2. Into music, weather, saving civilization, outdoors, current events, politics, tech trends. RT are not endorsements (not always my view).
baerbel ostertag @OsterBaerbel
4K Followers 4K Following Global #TotalRewards @SAP; fmr #HR @Concur; #SAP #BusinessNetworks & #Applications; #genderequity #SAPtotalrewards #IT #FMCG myPOV #TotalRewards18 #HRsocialHour
Don't tread on me @hmacsha512
213 Followers 566 Following
get off this nazi web... @bengl
2K Followers 2K Following Try not donating to fascism, please ||||| 🦋 at bengl dot dev
Hajjitprop @hajjitprop
364 Followers 3K Following
Ernesto Marinelli @E_Marinellli
4K Followers 4K Following #SVP, Head of #HR, #EMEA #GreaterChina @SAP; 💙#DigitalTransformation #Diversity #SAPHR & 🥇 #TalentMagnet! 🇮🇹#RunProuder #Magicisintheair #HRpunks MyViews
EqualityInEconomy @_WomensEconomy
129 Followers 963 Following Inspired by @UN_Women & #GenderEquality- #womenentrepreneur #equalopportunity #HeForShe #WomensEmpowerment #WomensFinancialInclusion curated by @DCTweetBounce
Crash Loop BackOff @MLOpsCamp
277 Followers 472 Following OSS MLOps / SRE / Platform Engineering. AI-driven automation for next-gen decentralized machine learning infrastructure.
rheophile10 @rheophile10
30 Followers 176 Following
Code Department @code_department
67 Followers 51 Following Fan of HTML, CSS, Datastar, Lua, R, Julia, Odin, Zig, Go, Kotlin, Elixir, Gleam and Roc who doesn't yet have time to use most of them.
dadbod2100 @dadbod2100
110 Followers 750 Following Replaced by fully automated luxury girlboss 🇺🇸. Block all brownoids. Fuck the EU.
Hossain Kabir @awarehossain
441 Followers 394 Following AI/ML Engineer | Stoic Philosopher | Writer | AI Educator | Web3. I study, teach and explore AI, Web3, philosophy, tech tools sharing easy ways to use them.
PeterDasAlien 🐧�... @_fraecker_
197 Followers 77 Following Benutze Linux, trage Jeans, bin binär. Ein Alien auf dem falschen Planeten.
LemonNeko @deleted_neko
623 Followers 160 Following Yet another cute trans cat girl game developer. Working hard on @proj_airi and FlowChat.
neghi @realneghi
79 Followers 87 Following SWE | GO | Typescript and Kotlin, building @socialally_ng
C☆ve | Hop’s #1 F... @Lilycovezzz
1K Followers 1K Following Didnt buy check // I like hop and Mike and Ikes // https://t.co/aDln7tlG6X // Basic DNI // Switch FC: 6441-4482-2528 // im a gay black twink
茶谷 和弘 / K.Cha... @chataclaw
45 Followers 255 Following AIプラットフォーム開発•コンサル スタートアップ「Coo Quack」 代表技術統括 / CTO、趣味は、ランニング、グルメ、映画鑑賞。新しい事に常に挑戦します!
Gaurang Karia @GaurangKaria
158 Followers 48 Following Engineer by mind. Storyteller at heart. AI, code, culture, books, films, cricket, and Manchester United. Opinions are my own. ✍️ Writing at @bygaurang
Sooraj @suryanox7
964 Followers 365 Following Staff Software Engineer | Building AI agents | Breaking systems | Posting lessons ⚡
vogel @ryanvogel
13K Followers 939 Following rebase @opencode | built https://t.co/J5qoZvwxvv | prev @databricks | https://t.co/VRtQxZo22w
Glauber Costa @glcst
19K Followers 1K Following CEO of @tursodatabase - the next evolution of SQLite. npx turso@latest
Yoav @YoavCodes
2K Followers 81 Following Technical founder. Building Electrobun and Dash at https://t.co/Pp6sheAD3q | 20+ years in early startups going zero to one | prev: 2015-2022 @webflow
Adam Rackis @AdamRackis
46K Followers 2K Following Software Engineer. Prev, Riot. TanStack, Next, React, C++ when I'm feeling nasty. Beer, whiskey, coffee snob. Book lover. Jr Developer for life.
Xiayi Sun @Sherry83044277
208 Followers 172 Following Ex-Meta. Solo-founder. Product + Engineering + Writing. Build & learn in public. Posting the AI stuff worth knowing.
Michael Lucas Poage �... @RubyBrewsday
370 Followers 660 Following CEO of CT’s #1 AI laboratory @Blackman_AI, twin girl dad, Director of Eng @beehiiv, Former @codeclimate + @Teachable, investor @OpenAI, @SpaceX, @Vercel
Frederik Jacques @thenerd_be
4K Followers 728 Following 👨🏼💻 Indie dev 🏦 Freelance iOS consultant @belfius 🚀 Serial builder @postbro_app • @getclockwiseapp • https://t.co/bL7WVwSWci • @capitalia_app
Anicet @AniC_dev
4K Followers 1K Following building the simplest, most affordable full VM sandboxes @asciidotdev w/ @luaroncrew prev: HPC for black holes hunting @esa, indie games, NN in rust, CAD AI
Jeff Tang @jefftangx
16K Followers 3K Following AI and peptides Acq. by @bryan_johnson YC W21, @pioneer_fund
Yanik Kumar @yanikkumar
667 Followers 891 Following I tweet about👇🏻 #mindset #perspective #life #tech #himachal #webdev Sarcastic in Nature ✋🏻🙂 I do vlog on YT, Subscribe✌🏻😉 Proud Sanatani ❤️ Hindu 1st 🇮🇳
OpenClaw🦞 @openclaw
539K Followers 24 Following The AI that does things. Emails, calendar, home automation, from your favorite chat app. Your machine, your rules. New shell, same lobster soul. 🦞
N.A. Frost @badsci_fi
47 Followers 193 Following Owner of Jeff's MCP TOOLING & STORAGE on West 42nd. Formerly everywhere. Please don't follow.
Adam Gaertner 🇺�... @veryvirology
81K Followers 2K Following Virology 🦠 Politics 🏛️ Research 📚💊🧬 I discovered the cure for COVID in Apr 2020 and I've been fighting to see it used since. Blocked by @ProfKlausSchwab 😁
akano @princessakano
3K Followers 523 Following infra sec (づ ◕‿◕ )づ c*mmunity manager @uwu_underground uwucada team Light the skies... burn it all down.
Moody Ruin @moodyruin
142 Followers 244 Following
object Object @namedobject
5K Followers 558 Following a guy who loves typescript / https://t.co/wi5XVd768S / https://t.co/UqPnJZXqyl
Jarred Sumner @jarredsumner
176K Followers 642 Following building @bunjavascript at @anthropicai. formerly: @stripe (twice) @thielfellowship. high school dropout. npm i -g bun
tasim Islam @Muhtasim51
161 Followers 1K Following tasim islam Work: Talk fusion School :Collage of devlopment Alternativ (2007-2009) Collage :Coda(2009-2012) University: Thompson river university
agrim singh @agrimsingh
5K Followers 2K Following building @ https://t.co/DlHMufmuQ1 // https://t.co/tpc1Nwqrix // https://t.co/2mTTsnMgAY + AI Engineer SG// ambassador @openai codex, @cursor_ai, @v0 // whisky guru & dj
Eduardo Ortiz Ramíre... @eduardomx
1K Followers 5K Following Father / CEO of WATR Inc. — @watrmx / design, business, sales, tech & music / iconoclast. insomniac. impermanent. / Co-founder of @hashigallery & @koucheamx
Lucas Santos @lucashfrsantos
135 Followers 850 Following
Weizhi Li⚡️ @0xSoliloquy
198 Followers 4K Following CEO @try_runner_ai, building autonomous business run by AI prev: Gemini @GoogleDeepmind. All views are my own.
Louie de la Rosa @louielouie
2K Followers 1K Following Director of Engineering & AI Builder | Engineering with Louie on YouTube | TypeScript, AI, and the occasional K-pop breakdown
Neha Varshneya @NehaVarshneya
339 Followers 614 Following Marketing exec for when it’s all on fire—or nothing’s built yet. GTM Leader for Developer Tools, AI & Cybersecurity | Driving Growth from 0 → 1
































