https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
npm v12 to Stop Running Install Scripts by Default — After a year of supply chain attacks, npm v12 will no longer execute preinstall, install, or postinstall scripts, unless you allow them with a new npm approve-scripts workflow. You can prepare today by upgrading to npm 11.16.0 which prints warnings about anything v12 would block.
2 months ago
https://posetteconf.com/2026/
Come for Great PostgreSQL Talks – Virtual and Free — Attend talks about PostgreSQL backed app development at POSETTE: An Event for Postgres 2026 (16-18 June). Join live and chat directly with PostgreSQL speakers, other developers and users. There is also swag waiting for you. Register for updates.
2 months ago
https://nodejsdesignpatterns.com/blog/nodejs-release-schedule-changes/
Node's New Release Schedule and Version Numbers Explained — Node’s moving to a one major release per year cadence as of Node 27 and adding a new ‘alpha’ channel for testing and experimentation. Luciano goes deep into how it’s happening, when, and why.
#node.js
#design patterns
#javascript
#backend development
#software architecture
#programming
2 months ago
https://github.com/wooorm/npm-esm-vs-cjs#data
📊 ESM Provision by Popular npm Packages Sees a Big Jump — Titus’s twice-yearly look at what popular packages ship finds 38% now expose ESM (and 16% are ESM only), up from 33.4% six months ago.
2 months ago
https://nesbitt.io/heap
Wander Around a Heap of Packages in node_modules — An interactive browser experience where you can navigate around a node_modules folder FPS-style. Which, why, how? I don’t know, but when something is by packaging expert Andrew Nesbitt of ecosyste.ms, I check it out.
2 months ago
https://nodered.org/blog/2026/06/09/version-5-0-released
Node-RED 5.0: The Biggest Editor Overhaul in the Project's History — The Node.js and 'node'-based low-code environment gets "the biggest change to the editor experience in [its] history": updated sidebars, dark theme (above), pausable debug output, and the ability to call Link nodes from Function nodes.
2 months ago
https://danfry1.github.io/bonsai-js/
Bonsai: A Safe Expression Language for User-Defined Rules — A fast, sandboxed expression language for when you need to evaluate user-supplied rules, filters, or templates without reaching for eval. Try the playground.
2 months ago
https://depsguard.com/
DepsGuard: A Tool to Harden npm, pnpm, Yarn and Bun Configs — Can't wait for npm v12's safer defaults? This Rust-based tool audits and rewrites your package manager config, disabling install scripts, enforcing cooldowns, and blocking provenance downgrades.
2 months ago
https://www.tigerdata.com/go/trial
Stale API Responses Start with a Stale Data Source — TimescaleDB extends Postgres for analytics on live data. No pipeline, no second database. $1000 credit to start.
3 months ago