An unknown person joined the core team of a popular library where the author burned out and then inserted a backdoor.
And large corporations continue to ignore the problem of burnout of library maintainers, on whom their business depends.
The xz situation is absolutely insane and almost certainly state sponsored.
This is an excellent example of a widely used software being maintained by basically one person.
Read this web article and then frown and become sad.
boehs.org/node/everything-i-…
Don’t think that xz case is a case when you just need to downgrade your dependency.
It is a case when your company should start supporting open source libraries your business relies on.
Talk to your manager, use this case as an example “why it is important for the business”.
The xz situation is absolutely insane and almost certainly state sponsored.
This is an excellent example of a widely used software being maintained by basically one person.
Read this web article and then frown and become sad.
boehs.org/node/everything-i-…
I love micro-optimizations (especially as onboarding challenges).
@Konfuze wrote a custom PostCSS plugin for the reader that merge :root rules. We often use them in components.
Also, I love custom @PostCSS plugins for project specific tasks.
github.com/hplush/slowreader…
Autoprefixer 10.4.19 was released.
We finally removed `end value has mixed support, consider using flex-end` warning since now `end`/`start` now have good support.
github.com/postcss/autoprefi…
Release’s knight by Paolo Uccello.
PostCSS 8.4.38 was released.
@romainmenke fixed error/warnings location on `endIndex: 0`. For instance, it will fix some @Stylelint reports.
github.com/postcss/postcss/p…
Release’s alchemist by Hans Asper.
PostCSS 8.4.36 was released.
We fixed `original.line and original.column are not numbers` error when previous source map was broken.
Release’s alchemist is Ekaterina Shulman by Olga Mentzar.
With postcss-html you can parse CSS-in-JS in Vue, Svelte, or React.
I worte a small script for my RSS reader which check that all CSS classes match my BEM system and filename (I use BEM, so users can override styles).
github.com/hplush/slowreader…
Autoprefixer 10.4.18 was released.
@Goodwine added extra check to keep -webkit-box-orient when rule has -webkit-line-clamp (a popular hack for multiline ellipsis).
github.com/postcss/autoprefi…
Release’s knight is a Navalny by @BadFoxLab.
I’m updating slides for the "How to Make Popular Open Source Project" talk for the #OSDAY24 in Florence.
I love to put references that nobody will understand.
postcss-dark-theme-class now supports light-dark(), a new way to specify the color for light and dark theme in one line. Thanks to @VladBrok99.
github.com/postcss/postcss-d…
With this @PostCSS plugin you can write regular CSS and switch theme manually by putting the class on <body>.
In recent PostCSS 8.4.34 we add `undefined` to `atrule.nodes`. It broke types in some project.
In new 8.4.35 release we made types smarter to avoid node.nodes! in TypeScript in some cases.
github.com/postcss/postcss/i…
Release’s alchemist is Ramon Llull.
And in terms of downloads, @PostCSS is larger than React. I'm super proud every time to say that it is was built by a Martian, the visionary @sitnikcode