MikeTrendsTrends right now

search

JavaScript

Trends

  1. 1

    Developer Dietrich Gebert released Ponytail, an open-source JavaScript tool hosted on GitHub that instructs AI coding agents to behave like 'the laziest senior dev in the room' โ€” writing as little code as possible. Its stated philosophy is that 'the best code is the code you never wrote', pushing assistants to prefer reuse and deletion over generating new code.

  2. 2
    Blockchain.com hiring Senior React Native Engineer in Buenos Airesโ—Blockchain.com is hiring Senior React Native Engineer ๐Ÿ”ง # react # reactnative # java # javascript # kotlin # swift # typMmastodonTechnologyMobile1536 min ago

    Blockchain.com has opened a full-time position for a Senior React Native Engineer based in Buenos Aires, Argentina. The role calls for experience with React, React Native, JavaScript, TypeScript, Kotlin and Swift, plus Android and iOS development and CI/CD practices. It is circulating among developers tracking tech job openings.

  3. 3

    Developer Paul Bakaus has released Impeccable, an open-source JavaScript project described as a design language that helps AI coding assistants produce better visual and interface design. The repository provides guidelines that developers can feed to AI harnesses so generated UI looks more polished, and it is gaining early attention in the developer community.

  4. 4
    Six Currency Mistakes Developers Make When Handling Moneyโ–ผFloats, decimal places, symbols, base vs quote, and stale rates. Practical JavaScript and Python examples for handling mMmastodonBusinessBanking244 min ago

    A guide covering six common currency mistakes developers make is drawing attention. It covers the pitfalls of using floating-point numbers for money, incorrect decimal place handling, currency symbol confusion, mixing up base and quote currencies in exchange rates, and relying on stale rates. Practical code examples in JavaScript and Python show how to handle money correctly in software, a topic of recurring interest in fintech and web development circles.

  5. 5
    The death of web development educationโ—The death of web development education https:// lobste.rs/s/td9dxd # education # vibecoding # web https:// molily.de/webMmastodonLifeEducation22 h ago

    A German web developer argues that structured web development education is dying out, with 'vibe coding' and AI-assisted shortcuts replacing systematic learning of HTML, CSS and JavaScript fundamentals. The piece is being discussed on developer forums, where commenters are debating whether formal teaching of the web platform is still relevant or worth saving.

  6. 6
    Critical unpatched flaw reported in gray-matter parserโ—CVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patchMmastodonTechnologyCybersecurity02 h ago

    A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.

  7. 7
    Low-severity vm2 sandbox flaw disclosed under EUVD-2026-81594โ—๐Ÿšจ EUVD-2026-81594 ๐Ÿ“Š Score: 2.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2: ExternalMmastodonTechnologyCybersecurity04 h ago

    A new vulnerability entry, EUVD-2026-81594, has been published for the vm2 JavaScript sandbox library maintained by patriksimek. The flaw carries a low CVSS v3.1 score of 2.3 out of 10 and stems from the external module allowlist using a raw prefix test, meaning a sibling package sharing a name prefix is incorrectly treated as allowlisted. The entry was updated on 1 October 2026.

  8. 8
    Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ—๐Ÿšจ EUVD-2026-81591 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 NodeVM cMmastodonTechnologyCybersecurity04 h ago

    A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.

  9. 9
    Critical vm2 sandbox escape vulnerability flagged in Node.jsโ—๐Ÿšจ EUVD-2026-81593 ๐Ÿ“Š Score: 9.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 sandbox eMmastodonTechnologyCybersecurity04 h ago

    A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.

  10. 10
    Critical 9.4-severity vulnerability disclosed in vm2 sandbox libraryโ—๐Ÿšจ EUVD-2026-81589 ๐Ÿ“Š Score: 9.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 crypto buMmastodonTechnologyCybersecurity04 h ago

    A high-severity vulnerability, EUVD-2026-81589, has been catalogued in vm2, the JavaScript sandbox library maintained by Patrik Simek. Scored 9.4 out of 10 under CVSS v3.1, the flaw involves vm2's crypto builtin loading attacker-supplied native code through the setEngine function, a path that could allow sandbox escapes or arbitrary code execution. The advisory was updated on October 1, 2026, and security teams are being urged to review any systems relying on vm2 for isolating untrusted JavaScript.

  11. 11
    Veteran software engineer documents mid-career switch into AIโ—I'm a software engineer with 16 years behind me, now halfway through a double MSc in AI (EPITA ร— EM... # ai # claude # cMmastodonTechnologyAI218 h ago

    A software engineer with 16 years of experience is halfway through a double MSc in artificial intelligence with EPITA and EM, and has been sharing the transition openly. They describe asking an AI tool to produce a video about their career switch, saying it took nine versions to get right. The posts touch on coding, JavaScript, career change and inclusive tech communities, drawing attention from developers weighing similar moves.

  12. 12
    Critical stored XSS flaw reported in Kiteworks Coreโ—๐Ÿšจ CVE-2026-102147 โ€” CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauMmastodonTechnologyCybersecurity022 h ago

    Security researchers are flagging CVE-2026-102147, a critical vulnerability in Kiteworks Core carrying a CVSS score of 9.3. The flaw is a stored cross-site scripting weakness that could let an unauthenticated attacker plant crafted content which then executes arbitrary JavaScript in the session of an administrator who views it, potentially giving attackers privileged access. Organizations running Kiteworks are urged to review the advisory and apply patches.

  13. 13
    Open-source pay-gap cost calculator promises zero network callsโ—I maintain a small open-source calculator that prices what it costs to close an unexplained gender... # opensource # javMmastodonTechnologySoftware31 d ago

    A developer maintains a small open-source calculator that estimates the cost of closing an unexplained gender pay gap. The tool is built in JavaScript and is designed to make zero network calls, so salary data entered by employers or analysts never leaves the user's browser. The privacy-first approach is drawing attention in open-source and HR communities.

  14. 14
    Browser piano reference highlights clashing note numbering systemsโ—When I built a piano reference for the browser, I found it easy to put three different numbers into... # javascript # weMmastodonCultureMusic21 d ago

    A developer who built a piano reference tool for the browser found it simple to mix up three different numbering systems: piano key numbers, MIDI note numbers, and frequencies. The JavaScript-based reference clarifies the differences for programmers and musicians working on web audio projects, and it is drawing attention in coding and music communities.

  15. 15
    New cozy browser MMO Evorin launched on itch.ioโ—Evorin a cozy challenging MMO! https:// coa-100.itch.io/evorin # gaming # pcgaming # videogames # javascript # wow # phpMmastodonCultureGaming12 d ago

    A small indie developer known as coa-100 is promoting Evorin, a self-described 'cozy but challenging' massively multiplayer online game, available through the itch.io game marketplace. The game is built with web technologies including JavaScript and PHP, suggesting it runs directly in a browser. Coverage so far is limited, with little independent reaction or detail about gameplay yet.

  16. 16
    Critical CVE-2026-102829 flaw reported in simple-gitโ—๐Ÿšจ CVE-2026-102829 โ€” CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enabMmastodonTechnologyCybersecurity02 d ago

    A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.

  17. 17
    Critical vulnerability CVE-2026-102828 found in simple-git libraryโ—๐Ÿšจ CVE-2026-102828 โ€” CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enabMmastodonTechnologyCybersecurity02 d ago

    A critical vulnerability, CVE-2026-102828 with a CVSS score of 9.2, has been disclosed in simple-git, a widely used Node.js library for running Git commands from JavaScript. Versions 3.15.0 through 4.0.1 are affected because the default blockUnsafeOperationsPlugin fails to classify certain trailer .cmd values, potentially allowing unsafe Git operations. Developers are being urged to check their dependency versions and update promptly.

  18. 18
    AegisLink 1.0.8 shifts crypto to native codeโ—AegisLog โ€” what's in AegisLink 1.0.8, the next release. It's the biggest one so far under the hood, so here's the full lMmastodonTechnologyCybersecurity11 d ago

    The developers behind AegisLink have detailed version 1.0.8, described as the biggest under-the-hood update so far. Cryptography moves out of JavaScript into native code, private keys are stored in a vault that application code cannot read, and Android gains wake capabilities. The changelog is being shared with users ahead of the release.

  19. 19
    Indie game developers praise thinking smallโ—think small sized wow # gamedev # indiegames # javascript # gamingMmastodonCultureGaming02 d ago

    Independent game developers are encouraging each other to think small when building games, with the message circulating in gamedev and indie game communities alongside tags for JavaScript and gaming. The idea reflects a common theme in indie development circles: that small, focused projects are easier to finish and can still impress players.

  20. 20
    Displaying Calculation Results With HTML Outputโ—Showing Calculation Results With HTML output https:// ronaldsvilcins.com/2026/09/20/ showing-calculation-results-with-htMmastodonTechnologySoftware12 d ago

    A developer blog post walks through showing calculation results using HTML output, covering CSS, HTML and JavaScript techniques for rendering computed values in a web page. The piece is being shared among web development communities, with readers flagging it for its practical front-end coding examples.

  21. 21
    DirtyBlanket Linux Worm Spreads Through Malicious npm Packagesโ—(safedep.io) DirtyBlanket: Self-Spreading Linux Worm Distributed via Malicious npm Packages Targeting Developers In brieMmastodonTechnologyCybersecurity12 d ago

    Security researchers at SafeDep report a self-spreading Linux worm, dubbed DirtyBlanket, distributed through nine malicious npm packages impersonating popular libraries such as Express and React. Once installed, the malware targets developers' Linux machines and propagates further, making supply-chain attacks on the JavaScript ecosystem a renewed concern for developers reviewing dependencies.

  22. 22
    GitLab patches high-severity stored XSS flaw CVE-2026-84739โ—๐ŸŸ  CVE-2026-84739 - High (8.7) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19MmastodonTechnologyCybersecurity02 d ago

    GitLab has released fixes for CVE-2026-84739, a high-severity vulnerability (CVSS 8.7) affecting all versions of GitLab CE/EE from 13.11 onwards. Under certain conditions, the flaw could have let an authenticated user execute arbitrary JavaScript in another user's browser. Patches are available in versions 19.2.7, 19.3.3 and 19.4.1, and self-hosted installations are urged to upgrade promptly.

Repos