Advertisement Β· 728 Γ— 90

Posts by NicolΓ² Ribaudo

Photos of Daniel and Matias's cat (their respective avatars) on a title card which says the same text.  Soundwaves are visualized eminating from them in the background

Photos of Daniel and Matias's cat (their respective avatars) on a title card which says the same text. Soundwaves are visualized eminating from them in the background

πŸŽ™οΈ New Episode of Igalia Chats -
npmx: The People Powered Package Index

@bkardell.com and @ryzokuken.dev chat with @danielroe.dev and @patak.cat of npmx about the project, the community and Open Source

www.igalia.com/chats/npmxyz

4 hours ago 27 12 0 3

Hello welcome to Amsterdam!

2 days ago 8 0 2 0

I just saw a full article on Fortune about the percentages of likelihood that LLMs think LLMs have of causing inflation or deflation, and then comparing LLMs based on the fake numbers they came up with about themselves???

4 days ago 6 0 1 0

Maybe you should use Linux rather than Windows to go to the moon?

4 days ago 31 2 1 0

If you work on tools that deal with source maps, TC39-TG4 (the source maps working group) has a hackathon in Amsterdam on 18th May 2026 at the JetBrains office.

@nicr.dev is the organizer who can be reached via BSky DMs or Matrix if you wish to register.

6 days ago 4 1 0 0

Santa only brought two trains and only got June 1st πŸ™ƒ

6 days ago 2 0 0 0

Waiting for midnight hoping that in April Renfe will release their full June timetable.

I feel like a child waiting for Santa 🎁

1 week ago 9 0 2 0

Thanks to @wooorm.com I learned that I can change the text selection color in MacOS and now I can make everything pink.

1 week ago 9 0 0 0

They actually do have a "repro" that does not do what the description says.

I ended up blocking the user. I really wish we had a "labeler" shared between trusted maintainers so that we can avoid wasting time to even detect that report is spam.

1 week ago 2 0 0 0

I wish people were like him πŸ˜…

1 week ago 1 0 0 0
Advertisement

They opened issues

1 week ago 1 0 2 0

They didn't even open a PR, which would be impossible to do because there is nothing to fix!

I ended up just blocking them

1 week ago 2 0 1 0

I hate it so much when I have to book a train trip that has multiple trains, and the first one sells out before that the timetable for the last one is even available.

1 week ago 5 0 0 0

We spent *hours* today in total going through their reports:
- one is not classifiable as vulnerability
- the other three are just hallucinated behavior that does not actually happen

1 week ago 1 0 0 0

This is the user: github.com/dfzysmy2tf-c...

They are opening issues in tens of repositories, and none of those are security vulnerabilities (in most case, the behavior they are describing is not even what actually happens!)

If you see an issue from them in your project, go ahead and block.

1 week ago 6 0 1 0

But what if one is an actual vulnerability and I don't notice?

1 week ago 0 0 1 0

No. Three of them I just closed/commented that they are not vulnerabilities based on the description, but the fourth one I actually had to spend time playing with it (to then reach the conclusion that it was also not a vulnerability).

1 week ago 2 0 1 0
Advertisement

There is a GitHub user (LLM?) that is reporting a lot of "security vulnerabilities" as open issues.

They are mostly trash reports (e.g. "if you pass Object.prototype to the setFooOnObject function, it will set Object.prototype.foo so that's prototype pollution"), but what if one is real?

1 week ago 12 1 6 2

This is SO funny

It's a parody of the Italian government websites, and it feels exactly like the originals

pucs.it

1 week ago 13 0 2 0
Preview
npm Dependency Links - Visual Studio Marketplace Extension for Visual Studio Code - Go to npm site of your dependencies

Cool! Apparently the npm Dependency Links VSCode extension has a configuration to specify a custom registry.

Now ctrl clicking a dependency in package.json takes me directly to npmx.dev.

{
"npmDependencyLinks.registryUrlPattern": "https://npmx.dev/package/{{pkg}}"
}

1 week ago 44 6 2 1
2026 Web Engines Hackfest Web Platform community event for people working on the different engines (Chromium/Blink/V8, Safari/WebKit/JSC, Firefox/Gecko/SpiderMonkey, Servo, Ladybird), on the testing side (WPT, Test262), on spe...

We have more than 80 people registered to participate onsite in the Web Engines Hackfest 2026: webengineshackfest.org#attendees
If you want to join us, please fill the form at: forms.gle/7gSwfFebFW7s...

1 week ago 10 8 0 0

No, Vite shows the same downward curve

2 weeks ago 2 0 0 0
Webpack downloads stats from npmx. It shows consistent weekly downloads between 30M/week and 35M/week. In the past 3 weeks, it suddenly dropped to 20M/week.

Webpack downloads stats from npmx. It shows consistent weekly downloads between 30M/week and 35M/week. In the past 3 weeks, it suddenly dropped to 20M/week.

I'm seeing this sudden drop in download counts in most popular npm packages, happening in the last 3 weeks.

Does anybody know what's going on?

2 weeks ago 30 4 10 1

This sounds incredibly fun, I'd love to participate as a "regular traveler" if you'll need it :)

2 weeks ago 1 0 1 0

Thanks for organizing!

2 weeks ago 2 0 1 0
screenshot of the one-pager version of the servo readiness report

screenshot of the one-pager version of the servo readiness report

How do we get to more than just three web engines owned by three US companies?

It's a gargantuan question, with no easy or right answer.

I've put together a draft report, thinking about it through a very specific approach - please enjoy:

Servo Readiness Report

webtransitions.org/servo-readin...

1 month ago 72 30 5 1
Advertisement

Last week we were able to present @robpalmer.bsky.social with his physical Ecma Recognition Award! πŸŽ‰ This was followed by an extensive round of tributes and praise, which Rob endured somewhat uncomfortably, at every opportunity urging us to cease and attend to the waiting celebratory Temporal cake.

2 weeks ago 90 9 6 2

Or too few batteries πŸ˜›

2 weeks ago 2 0 0 0

Did somebody create some controversy around Yarn?

2 weeks ago 0 0 1 0

I wonder whether this would make it easier to implement type-directed linting in tools like oxlint. Yes Flow is different from TypeScript, but in the past years their syntax aligned and the semantics might be similar enough for linting rules.

2 weeks ago 3 0 2 0