







Summary Implements a Deno-compatible permissions model for Bun, providing granular control over system resource access. This PR introduces a security sandbox that can restrict file system, network,...
Introducing Deno Sandbox | Deno
Instant Linux microVMs with defense-in-depth security for running untrusted code.


Node.js Cryptography Overhaul: Migrating from SHA-256 to Post-Quantum Algorithms | Markaicode
Learn how to upgrade your Node.js applications from SHA-256 to quantum-resistant cryptographic algorithms with practical code examples and migration strategies.

Composing capability security and conflict-free replicated data types — Spritely Institute
In August, I attended the DWeb Seminar where a small group of builders gathered to discuss the state-of-the-art and open problems in the distributed web space. Some in the group are primarily concerned with distributed data and focus on sync algorithms and local-first use cases. I am mainly concerned with distributed behavior and focus on the object capability security model. Both areas of study are steeped in their own lore and research papers, which makes it difficult for the two camps to communicate effectively with each other.
Fresh 2.3: Zero JS by default, View Transitions, and Temporal support | Deno
Fresh 2.3 ships true zero-JS pages, View Transitions, CSP nonce support, IP filtering, and Temporal API support in islands.

How do you secure API secrets in local development without exposing them to devs?
20 votes, 25 comments. Hey everyone! I’m a tech-lead managing a development team, and we’re currently using .env files shared among developers to…
Lume, the static site generator for Deno
Support for multiple file formats like Markdown, YAML, JavaScript, TypeScript, JSX, Nunjucks etc.

FOSDEM 2025 - Goblins: The framework for your next project!
Building peer-to-peer decentralised applications remains difficult and error-prone. Most attempts at this either abandon collaborative features entirely or fall back on centralised architectures. The Spritely Institute is working on this challenge by creating (among other things) Goblins, a Guile framework that makes secure, fault-tolerant peer-to-peer applications accessible to developers. These tools are especially valuable for developers building secure collaborative applications that aim to foster healthy online communities. This talk walks you through Goblins’ most powerful features, including the actor model, object capability security, networking, time travel debugging, and persistence.

I am worried about Bun
Bun is excellent software. Anthropic owns it now, Bun sits under Claude Code, and Claude Code getting worse makes me worried Bun could follow the same enshittification path.
Next.js / React Server Components vulnerability identified. Apps deployed on Deno Deploy infrastructure are already protected by a runtime-level patch applied by our team. See this post for more information on how to protect your projects. deno.com/blog/react-server-functions-r…
React Server Functions / Next.js Vulnerability: Deno Deploy users protected | Deno
deno.comas a little pre-show surprise, here's an early draft of the permissioned data proposal! github.com/bluesky-social/proposals/pull…
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
github.comAT Protocol Developers
Don't forget, @dholms.at is joining us for the livestream TOMORROW for a permissioned data AMA.
as a little pre-show surprise, here's an early draft of the permissioned data proposal! github.com/bluesky-social/proposals/pull…
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
github.comAT Protocol Developers
Don't forget, @dholms.at is joining us for the livestream TOMORROW for a permissioned data AMA.
🙋♂️ so ... for reasons: I would love to know people's frustrations with: - the current npmjs.com - admin user flows on npm web ui (and cli, locally) 🙏