November 28, 2023
Turn on loading images 😉- Logo ECMAScript News

The “State of JavaScript 2023” survey is open

stateofjs.com @sachagreif@hachyderm.io

Quoting the frequently asked questions:
  • When will the results be released?
    The survey will run from November 22 to December 12, and the survey results will be released shortly after that.
  • How long will answering the survey take?
    Depending on how many questions you answer (all questions are optional), filling out the survey should take around 15-20 minutes.

Welcome to QuickJS-ng [friendly fork of JavaScript engine QuickJS]

github.com @s@social.saghul.net github.com/bnoordhuis github.com/bellard

Saúl Ibarra Corretgé on Mastodon: “Introducing QuickJS-ng! My buddy Ben [Noordhuis] and I have been working on reingniting the QuickJS project. We just released a new version with top-level await and many more ECMAScript features, check it out!”

  • Implemented in C
  • Can be installed via jsvu: “jsvu makes it easy to install recent versions of various JavaScript engines without having to compile them from source.”

esbuild 0.19.7

github.com @evanw@hachyderm.io

Highlight of esbuild 0.19.7:
  • Add support for bundling code that uses import attributes
Highlight of esbuild 0.19.6:
  • Allow package subpath imports to map to node built-ins

package-majors: How often were the major versions of a given npm package downloaded during the past week?

majors.nullvoxpopuli.com @nullvoxpopuli@mastodon.coffee

The diagram tells you which old versions are still popular. You can then investigate why people aren’t upgrading.

How Socket combats insidious typosquatting supply chain attacks

socket.dev @sarahgooding@fosstodon.org @SocketSecurity@fosstodon.org

“Socket’s free GitHub app was created to detect malicious packages and is your first line of defense against typosquatting, among other supply chain risks […]. It offers real-time scanning of incoming dependencies with every pull request. When a potential typosquatted package is detected, the app instantly alerts the developer who submitted the PR (or the one reviewing it) through a GitHub comment.”

This email was sent to {{ email | default }}. You can unsubscribe from this list here or update your preferences.