Skip to content
yceffort
PostsSeriesTagsAbout🧪 Research
KO

Tweaks

theme
accent palette
film grain
minimal mode
05 POSTS

Npm 1

  • #bundler#web-performance#debugging

    Tearing Apart a Third-Party SDK and Rebuilding It My Way: Without Touching a Single Line of Logic

    I imported one constant and 97.7% of the bundle came along with it. The vendor had no timeline for a fix, so I pried open the published source maps, recovered over 400 TypeScript files, and rewrote the build, the entry points, and the dependencies however I wanted. Everything except the logic. That got /send to -77.5% raw. The hard part came after. All 1,932 tests passed, and a few of them were watching nothing at all.

    2026-08-31·41 min read
  • #typescript#blogging#npm

    What Happens When You Install typescript@7: A Blog Monorepo Migration Log

    I dropped typescript 7.0.2 into a monorepo where pnpm lint took 12 minutes 32 seconds. Type checking passed quietly, but next build broke and lint crashed. A record of the chain reaction from one day of swapping eslint and prettier for oxlint and oxfmt, with before-and-after measurements. To say it up front, the build did not get any faster.

    2026-08-10·11 min read
  • #security#ci-cd#npm

    The TanStack npm Supply Chain Attack: Why pull_request_target Is Dangerous

    Analysis of the @tanstack/* supply chain incident. The risks of pull_request_target, GitHub Actions cache, and OIDC trusted publishers, and how to defend against them.

    2026-05-16·24 min read
  • #npm#essay#oss

    What makes a package you can keep using for years different

    A good package has to be user-friendly not just in features, but in dependencies, version bumps, compatibility, and release policy.

    2026-05-09·20 min read
  • #security#nextjs#react

    It's a React vulnerability, so why do I have to upgrade Next.js?

    CVE-2025-55182, CVE-2025-55184, CVE-2025-55183, and the React hidden inside Next.js

    2025-12-12·19 min read
mailMail icongithubtwitter
yceffort
•
© 2026
•
https://yceffort.kr