Public list by ~nodeweekly

Issue 628 - npm install is (finally) getting safer

Upcoming breaking changes for npm v12 - GitHub Changelog

https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/

npm v12 to Stop Running Install Scripts by Default — After a year of supply chain attacks, npm v12 will no longer execute preinstall, install, or postinstall scripts, unless you allow them with a new npm approve-scripts workflow. You can prepare today by upgrading to npm 11.16.0 which prints warnings about anything v12 would block.

2 months ago

POSETTE: An Event for Postgres 2026

https://posetteconf.com/2026/

Come for Great PostgreSQL Talks – Virtual and Free — Attend talks about PostgreSQL backed app development at POSETTE: An Event for Postgres 2026 (16-18 June). Join live and chat directly with PostgreSQL speakers, other developers and users. There is also swag waiting for you. Register for updates.

2 months ago

Node.js is changing its release schedule and version numbers

https://nodejsdesignpatterns.com/blog/nodejs-release-schedule-changes/

Node's New Release Schedule and Version Numbers Explained — Node’s moving to a one major release per year cadence as of Node 27 and adding a new ‘alpha’ channel for testing and experimentation. Luciano goes deep into how it’s happening, when, and why.

#node.js #design patterns #javascript #backend development #software architecture #programming

2 months ago

node_modules/

https://nesbitt.io/heap

Wander Around a Heap of Packages in node_modules — An interactive browser experience where you can navigate around a node_modules folder FPS-style. Which, why, how? I don’t know, but when something is by packaging expert Andrew Nesbitt of ecosyste.ms, I check it out.

2 months ago

Version 5.0 released

https://nodered.org/blog/2026/06/09/version-5-0-released

Node-RED 5.0: The Biggest Editor Overhaul in the Project's History — The Node.js and 'node'-based low-code environment gets "the biggest change to the editor experience in [its] history": updated sidebars, dark theme (above), pausable debug output, and the ability to call Link nodes from Function nodes.

2 months ago

Bonsai — Safe Expressions for Rules, Filters, and Templates

https://danfry1.github.io/bonsai-js/

Bonsai: A Safe Expression Language for User-Defined Rules — A fast, sandboxed expression language for when you need to evaluate user-supplied rules, filters, or templates without reaching for eval. Try the playground.

2 months ago

DepsGuard - Guard your dependencies against supply chain attacks

https://depsguard.com/

DepsGuard: A Tool to Harden npm, pnpm, Yarn and Bun Configs — Can't wait for npm v12's safer defaults? This Rust-based tool audits and rewrites your package manager config, disabling install scripts, enforcing cooldowns, and blocking provenance downgrades.

2 months ago

Try Tiger Cloud Free: $1,000 Credit | Tiger Data

https://www.tigerdata.com/go/trial

Stale API Responses Start with a Stale Data Source — TimescaleDB extends Postgres for analytics on live data. No pipeline, no second database. $1000 credit to start.

3 months ago