AnimeJS v4 has landed. Boy oh boy, it’s probably the sickest JavaScript library for animations.

AnimeJS v4 has landed. Boy oh boy, it’s probably the sickest JavaScript library for animations.
Anyone else seeing #npm package installation failures? I can see https://status.npmjs.org/incidents/hdtkrsqp134s, but the "scoped to certain keywords" is both weasel-wording and confusing ... #npmjs #javascript #devops
hah, npm issue right now, which https://status.npmjs.org/ was quite tardy in reporting
@cwebber What do you think of JS packages, ten years later (same day, what a coincidence)?
Package Manager for Markdown
I'm working on a project that is intended to encourage folk to make markdown text files which can be bundled together in different bundles of text files using a package manager.
Question for coders; Which package manager would you suggest I use?
Main criterias (in order) are:
1. Easy for someone with basic command line skills to edit the file and update version numbers and add additional packages.
2. All being equal, more commonly and easy to setup is preferred.
#Markdown #CommonMark #PackageManager #Programming #Dev
#NPM #RubyGems #Cargo #PickingAMastodonInstance
#Ruby #Python #Rust #Javascript #NodeJs #Lisp #CommonGuide
#Infostealer campaign compromises 10 #npm packages, targets devs
@henry Having (almost fully) switched to #NodeJS in 2012, I quickly recognized the danger of relying to _anything_ (#npm included, this one gave me a lot of pain for several times over the years).
Ended up with a monstrous monorepo. Forked (and improved) just 2 other people's repos, one abandoned and one that took months to finally get it right regarding garbage collection, but I had no time to wait.
Thereby I never got to a situation to hate a programming language because of the hype around it, but it surely got me coding a ton of #javascript.
The experience helped me a lot in JS5=>ECMAScript and ECMAScript=>TypeScript switching in the last year or so.
New #npm attack poisons local packages with backdoors
https://www.bleepingcomputer.com/news/security/new-npm-attack-poisons-local-packages-with-backdoors/
#security vulnerability on #npm packages
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
Malware found on NPM infecting local package with reverse shell
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
@BleepingComputer Do we think something like this is enough to find if this garbage is present on a Linux system? `sudo find / -iregex '.*ethers-.*`
#node #npm #malware
#WebDev #JavaScript #TypeScript #frontend #npm
Meet dd<el> — JS lib for building #reactiveUIs with syntax close to native DOM!
See https://fosstodon.org/@jaandrle/114216488004115032 or https://github.com/jaandrle/deka-dom-el … share or use star if u like it
Out of pure curiosity, and because I'm on that #webdev #framework discovery tip. Heck, this project even made me download an IDE for Android lol
Just to read `install.bin` - which is an sh script.
Excuse me, but why are you bundling #nodejs and #npm? Is it to facilitate a setup process for containers, or is it merely to make the process easy?
I'm a bit sceptical to that sort of thing, especially when fetching from a vendors domain directly.
Any plans to build packages via CI?
We made an MCP Server so that Cursor can build anything from API Docs
“Vanilla JavaScript for flavouring, a full-fledged feast for large projects.”
Meet dd<el> – the Vanilla JavaScript library for building reactive UIs with syntax close to native DOM! No build step required, just native DOM with superpowers. #ReactiveUI based on signals and events.
- NPM: https://www.npmjs.com/package/deka-dom-el
- GitHub: https://github.com/jaandrle/deka-dom-el (use star if u like it)
- Docs & examples: https://jaandrle.github.io/deka-dom-el
Last week's most downloaded npm packages:
1. semver
2. ansi-styles
3. debug
4. supports-color
5. chalk
6. minimatch
7. ms
8. tslib
9. strip-ansi
10. has-flag