就在最近,ECMAScript 2026(ES2026)规范正式获批,这是 JavaScript 最新一代语言标准。这意味着:未来几年,浏览器、Node.js、Deno、Bun……都会逐步全面进入 ES2026 时代。 过去几年每次 ECMAScript 发布新版本。 评论区都会出现一句话:JavaScript 又更新了,但我每天还是在写 const。 很多开发者甚至觉得:ES6 之后,JavaS ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
过去 TypeScript 一直依赖 JavaScript Runtime。写完代码,需要经过浏览器、Node.js 或 Electron 才能运行。但现在有人开始尝试:让 TypeScript 直接变成 Native。 过去 TypeScript 一直依赖 JavaScript Runtime。 写完代码,需要经过浏览器、Node.js 或 Electron 才能运行。 但现在有人开始 ...
Significantly lower memory consumption, faster page transitions, Rust-based React compiler: Next.js 16.3 offers comprehensive ...
那个11岁的熊孩子并不需要真的从零写一个浏览器内核,谷歌养了几千人,花了十几年的时间,已经替她写好了。她只需要让AI帮她用Electron给Chromium套一层壳,让系统认不出来她就足够了。
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Go beyond HTML with practical workflows to uncover rendering issues, weak site structure, and other obstacles to AI ...
A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
This week’s ThreatsDay Bulletin covers malicious packages, AI agent risks, phishing chains, exposed systems, router flaws, ...