Matt Travi's Avatar

Matt Travi

@matt.travi.org

DivOps Engineer. OSS Maintainer: semantic-release, repository-settings, form8ion

203 Followers  |  353 Following  |  4 Posts  |  Joined: 18.08.2023  |  1.6397

Latest posts by matt.travi.org on Bluesky

Post image

๐Ÿšจ npm phishing alert!
Attackers are sending emails from spoofed support@npmjs.org addresses linking to a typosquatted clone site (npnjs.com) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links: socket.dev/blog/npm-phi... #nodejs #JavaScript

18.07.2025 20:20 โ€” ๐Ÿ‘ 20    ๐Ÿ” 14    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

For no reason at all, I feel the need to remind folks that Node.js is not in competition with other runtimes like Deno or Bun. Companies compete. For profit entities compete. Private equity competes. Non-profits do not compete. Non-profits just exist. Use Node.js, use Deno, use Bun, use what works..

31.05.2025 03:08 โ€” ๐Ÿ‘ 58    ๐Ÿ” 13    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 2
Preview
Node.js โ€” Node v18.20.8 (LTS) Node.jsยฎ is a JavaScript runtime built on Chrome's V8 JavaScript engine.

New @nodejs.org 18.20.8 release. This is the last planned release of Node.js 18 before it reaches End-of-Life at the end of April 2025. You are recommended to update to Node.js 20 or 22 to continue to receive security updates after that date.
nodejs.org/en/blog/rele...

27.03.2025 13:41 โ€” ๐Ÿ‘ 41    ๐Ÿ” 14    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Post image

๐Ÿ”‘ under-discussed point โ€” why they were on signal:

25.03.2025 11:59 โ€” ๐Ÿ‘ 53229    ๐Ÿ” 21814    ๐Ÿ’ฌ 1485    ๐Ÿ“Œ 1819

We want to get some early feedback on this tool. Is there anyone in my network working in OSS who could be interested to try it out? It will be just a few minutes!

24.03.2025 11:24 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I'm even more afk than usual this week, so I apologize if I'm slow to respond. I saw your semantic-release issue, and it sounds interesting. I'm ok with keeping the conversation in the open there, but my contact form is a good option so we could chat over email too

24.03.2025 11:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I need examples of vulnerabilities reported against npm packages that maintainers of the package or another package depending on it were annoyed by.
Doesn't have to be fresh, last 5 years is ok.

Respond with ghsa link or package+version - I can look it up myself.

(repost for reach a lot please)

21.03.2025 10:53 โ€” ๐Ÿ‘ 9    ๐Ÿ” 5    ๐Ÿ’ฌ 6    ๐Ÿ“Œ 1
Post image

Great sticker ITW

08.03.2025 13:45 โ€” ๐Ÿ‘ 1373    ๐Ÿ” 277    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 10
A Tesla where the owner has put a Buick logo on the center of the trunk, a Buick badge under the left taillight and a LaCrosse CX badge under the right taillight.

A Tesla where the owner has put a Buick logo on the center of the trunk, a Buick badge under the left taillight and a LaCrosse CX badge under the right taillight.

Imagine your car becoming so hated that owners are like "please let them think I'm driving a Buick!"

05.03.2025 17:36 โ€” ๐Ÿ‘ 2767    ๐Ÿ” 401    ๐Ÿ’ฌ 70    ๐Ÿ“Œ 68

> changes the behavior for the obj.toString folks

Major

13.02.2025 22:13 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

All y'all investing your careers in generative AI should be keeping a close eye on cases like this. It's early but so far every judge has ruled in favor of copyright holders and against the idea that LLM outputs fall under fair use. If they ALSO rule that code repos with LLM-produced work in them

11.02.2025 21:47 โ€” ๐Ÿ‘ 31    ๐Ÿ” 11    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
An image highlighting the SHA in the URL after hitting the "Y" key on GitHub

An image highlighting the SHA in the URL after hitting the "Y" key on GitHub

๐ŸšจPSA: When copying GitHub URLs, always hit "Y" first!

Hitting "Y" adds the current SHA to the URL. This ensures your link doesn't break as the repository changes over time.

07.02.2025 15:37 โ€” ๐Ÿ‘ 60    ๐Ÿ” 10    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 1

I'm still very happy with mine from Autonomous

04.01.2025 06:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Want to influence priorities in an OSS project? Here's the secret: demand nothing, be kind, and if possible roll up your sleeves to contribute. OSS thrives on collaboration, not demands. #OpenSource #OSS

28.12.2024 07:45 โ€” ๐Ÿ‘ 35    ๐Ÿ” 10    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Semantic Release Semantic Release has 35 repositories available. Follow their code on GitHub.

Hi, folks ๐Ÿ‘‹

I maintain github.com/semantic-rel... and github.com/repository-s...

24.12.2024 04:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Cucumber is back in Community Ownership | Cucumber Today is a big day for Cucumber.

Itโ€™s a big day for Cucumber: weโ€™re back in community ownership.

cucumber.io/blog/open-so...

20.12.2024 06:42 โ€” ๐Ÿ‘ 28    ๐Ÿ” 13    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
A graphic created by our graphic designer, Clelia Rella. The light background has an a green and blue abstract plant where the leaves are communication bubbles and the top stem a couple rain drops on the right half of the image, our Home Assistant antenna on the left side barely visible. Our Home Assistant logo is in the top left. Text overlay reads:
Understanding our community
The 2024 Home Assistant Survey

A graphic created by our graphic designer, Clelia Rella. The light background has an a green and blue abstract plant where the leaves are communication bubbles and the top stem a couple rain drops on the right half of the image, our Home Assistant antenna on the left side barely visible. Our Home Assistant logo is in the top left. Text overlay reads: Understanding our community The 2024 Home Assistant Survey

As we continue to grow and evolve, so does our commitment to making Home Assistant more inclusive, accessible, and aligned with the diverse needs of our community. To that end, weโ€™re launching an annual surveyโ€”and we hope youโ€™ll take part! ๐Ÿ‘‡๐Ÿผ

home-assistant.typeform.com/communitysur...

16.12.2024 21:59 โ€” ๐Ÿ‘ 31    ๐Ÿ” 13    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0

@matt.travi.org is following 20 prominent accounts