Front-End Fire

Front-End Fire

By TJ VanToll, Paige Niedringhaus, Jack HerringtonTechnology
Download on the App Store

Front-End Fire episodes

  • npm Under Siege: The “Shai-Hulud” Worm Attack

    The supply chain attacks on npm continue and this week, Crowdstrike’s npm packages fell victim to the “Shai-Hulud” worm. 

    To mitigate the potential of downloading these malicious packages, consider pinning specific package versions in JS projects and using 2FA to publish new package versions to npm.

    Also this week, WebAssembly Specification (Wasm) released v3.0. This version dramatically expands the memory Wasm apps can use, supports multiple memory usage, and now allows garbage collection.

    It’s been a while since we last covered LLM options for folks who want to run their own models locally or in the browser, so Jack gives a quick rundown of some of the best options out today. 

    There’s WebLLM from MLC, MediaPipe from Google, and ONNX from Microsoft, and although none are easily interchangeable with another, if cost, privacy, or working offline are concerns of your LLM-enabled app, these may be good options to explore.

    Chapter Markers:

    • 00:58 - npm supply chain attack
    • 16:28 - Wasm 3.0
    • 23:34 - LLM options in the browser
    • 34:41 - Jack’s experience at CascadiaJS and a discussion on the value of in-person conferences in 2025
    • 41:54 - GitHub’s new MCP registry
    • 43:26 - Microsoft Paint is getting project files
    • 46:54 - What’s making us happy

    Links:

    • Paige - “Shai-Hulud” supply chain attack on npm continues against Crowdstrike npm packages and pnpm 10.16 minimumReleaseAge setting
    • Jack - LLM options in the browser: WebLLM, MediaPipe, ONNX
    • TJ - Wasm 3.0
    • GitHub’s new MCP registry
    • Microsoft Paint is getting its own Photoshop-like project files
    • Paige - Great British Bake Off season 16 is back!
    • Jack - Yoyos
    • TJ - phishyurl.com

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    57 min
  • npm’s Biggest Supply Chain Attack (and What We Learned)

    Just 5 months ago we covered how Storybook 9 was in beta, and already Storybook 10 is in beta. The biggest change is that Storybook is going all in on ESM and dropping CJS support, which is making for some big performance gains and smaller bundle sizes.

    This past week, npm suffered the largest supply chain attack in its history when a prolific OSS maintainer got phished. Luckily, the attack was noticed and reported within the hour and it looks like the hackers got next to nothing for their efforts, but it serves as another reminder to be extra careful before clicking links in emails.

    In the same security vein, browser company Brave uncovered a security vulnerability in AI-browser Comet where malicious instructions on a web page could cause the agent to “go rogue” while it was being asked to summarize a page’s contents. Perplexity has since added more guardrails to try and mitigate this sort of thing, but be cognizant of the data and site access you’re giving to AI agents.

    Timestamps:

    • 1:12 - Storybook 10
    • 7:53 - npm’s supply chain attack
    • 17:24 - Brave discloses a security vulnerability in Comet
    • 26:38 - You’re absolutely right!
    • 35:26 - What’s making us happy

    Links:

    • Paige - Storybook 10 beta and Storybook 9 features
    • Jack - npm just suffered the largest supply chain attack in its history
    • TJ - Brave discloses a security vulnerability in Comet
    • Someone made a customizable website to count how many times Claude Code says “You’re absolutely right!” in a day
    • Paige - Silicon Valley TV show
    • Jack - Shokz OpenComm2 bone conduction headphones
    • TJ - macOS text message forwarding

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    51 min
  • Warp Code and the Future of Agent-Driven Dev

    The Google vs. the US anti-trust lawsuit has finally drawn to a close, and (spoiler alert) Google doesn’t have to sell Chrome (or Android, for that matter). Going forward it will have to share certain search data with its rivals, and that’s about it, so this is definitely a big win for Google any way you look at it.

    The popular terminal company Warp just unveiled Warp Code - a suite of features for shipping agent-generated code “all the way from prompt to production” via the Warp terminal. Warp Code offers an agent-driven terminal-first approach, with visual code review of agent changes, and a native file editor for minor edits in an attempt to eliminate the context switching devs have to do nowadays between their AI agents, IDEs, and GitHub. 

    In a twist no one saw coming, SaaS behemoth Atlassian has bought AI-browser Dia (and its maker The Browser Company) for $610 million. Atlassian wants to position Dia as the AI-browser for users at work and time will tell if that bet pays off.

    Timestamps:

    • 02:34 - Google doesn't have to sell Chrome
    • 10:17 - Warp Code
    • 22:56 - Atlassian buys The Browser Company
    • 31:48 - Anthropic raises $13 billion
    • 34:54 - OpenAI is building an AI-powered hiring platform
    • 39:42 - What’s making us happy 

    Links:

    • Paige - Atlassian buys The Browser Company for $610 million
    • Jack - Warp terminal unveils Warp Code
    • TJ - Google doesn’t have to sell Chrome after all
    • TJ - Addy Osmani’s blog post on the history of Chrome
    • Anthropic raises $13 billion Series F
    • OpenAI is building an AI-powered hiring platform
    • Paige - BenQ RD280U programming monitor
    • Jack - Alien: Earth TV series
    • TJ - Severance TV series

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    52 min
  • Bun v1.2: SQL, YAML & Security Scans

    Last episode, we lamented Claude’s lack of checkpoints to roll back code when it goes off the rails. Other devs feel the same, and this week Checkpoints for Claude Code debuted. It’s an MCP server that follows Claude Code, creating checkpoints when tasks are completed, allowing for easy reverts when needed.

    The Bun team quietly pushed some nice new features in Bun v1.2. Highlights include: a unified SQL client with zero dependencies, native YAML file support, OS native credential storage for secrets, and a security scanner API that scans packages for vulnerabilities before installation.

    And MCP-UI, a toolkit of interactive UI components for MCP has new features to support resources beyond text like embedded iframes and even raw HTML. Not all agents with MCP support can handle these new resources, but if they can, users can see product photos, data visualizations, and other mini sites right in their AI chat.

    In the Lightning News section for this week, the folks at Deno leading the charge to get Oracle to relinquish its trademark for JavaScript need our help. Those legal bills aren’t going to pay themselves and Deno’s pockets aren’t nearly as deep as Oracle’s, so if you care about making JavaScript public domain (which it absolutely should be), please consider donating so they can keep fighting the good fight to free JS. Every little bit helps.

    Timestamps:

    • 00:48 - Claude Code thinking modes & checkpoints
    • 10:33 - Bun v1.2
    • 17:04 - MCP-UI updates
    • 23:06 - Claude for Chrome
    • 28:12 - Donate to help Deno fight Oracle
    • 30:24 - What’s making us happy

    Links:

    • Paige - Bun v1.2
    • Jack - MCP-UI updates
    • TJ - Claude Code Thinking Modes & Claude Code Checkpoints
    • Claude for Chrome
    • Donate to help Deno keep fighting Oracle in court
    • Paige - Zima Dental Pod
    • Jack - Foundation TV series
    • TJ - Babe Ruth commits fraud

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    42 min
  • Alchemy: IaC Without Terraform

    The latest craze for MCP this week? Instead of multiple MCP servers with different tools, use an MCP server that accepts programming code as tool inputs - a single “ubertool” if you will. AI agents like Claude Code are pretty good at writing code, but letting the agent write and execute code to invoke API functions instead of using a defined MCP server doesn’t seem like the most efficient use of LLM tokens, but it's another approach to consider.

    In infrastructure news, there’s a library called Alchemy that lets devs write their Infrastructure as Code in pure TypeScript. No Terraform files, no dependencies, just async functions, stored in plain JSON files, that runs anywhere JS can run. For web devs, the future of IaC has arrived.

    Next.js has made their last big release before v16 in the form of 15.5. Highlights of this minor release include: production turbopack builds, stable support for the Node.js runtime in middleware, fully typed routes, and deprecation warnings in preparation for Next.js 16.

    Timestamps:

    • 00:57 - Dangers of the “ubertool”
    • 09:54 - Alchemy Infrastructure as Code (IaC)
    • 15:27 - Next.js 15.5
    • 24:57 - How CodeRabbit AI got hacked
    • 27:48 -
    55 min
  • TanStack Devtools: One Panel to Rule Them All

    You just can’t keep TanStack out of the news for more than a few weeks before a new product appears. This week, it’s TanStack Devtools, which provides a centralized devtools panel of all the Tanstack libraries for streamlined DX and custom devtools support.

    The State of CSS 2025 survey results are in, and highlights include: devs love the new `:has()` feature, Tailwind CSS continues to be the most popular CSS framework, and over 60% of respondents are still using Sass or SCSS in their web apps.

    Continuing the CSS topics, Panda CSS, a CSS-in-JS library that debuted in 2023, just hit v1. Panda gained traction by being a CSS-in-JS library built for the server-first era (meaning RSC support), and it adds new features like static analysis, type safety, and support for modern CSS like cascade layers, JSX style props, and a `createStyleContext` API for cross-framework design systems.

    Timestamps:

    • 0:56 - TanStack Devtools
    • 6:28 - State of CSS 2025 survey results
    • 15:23 - Panda CSS v1
    • 23:19 - Perplexity wants to buy Chrome from Google
    • 25:52 - Google Gemini is having a mental breakdown
    • 30:50 - Bolt.new unveils Bolt Cloud
    • 35:14 - The dialog element’s closedby attribute
    • 39:20 - What’s making us happy

    Links:

    • Paige - Panda CSS v1 
    • Jack - TanStack Devtools
    • TJ - State of CSS 2025 survey results
    • Perplexity wants to buy Chrome from Google
    • Google Gemini’s having a mental breakdown
    • Bolt.new unveils Bolt Cloud
    • The dialog element’s `closedby` attribute
    • Paige - Express VPN
    • Jack - A Psalm for the Wild Built book
    • TJ - The Retrievals podcast and The Savannah Bananas baseball team

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    51 min
  • TanStack DB: Reactive Apps Without Firebase

    There’s drama brewing between AI-answer engine company Perplexity and hosting platform Cloudflare, which recently declared it would actively block AI bots from crawling websites without the owners’ permission. Cloudflare received complaints, set up its own test sites, and then asked Perplexity pointed questions only - and got answers! Not a great look, Perplexity.

    Two years after Vercel launched v1 of its AI SDK, it has dropped v5, and it’s got some major improvements. Rebuilt chat hooks, improved tool calling, more agentic controls, and it works with React, Svelte, Vue, and Angular. That’s just the tip of the iceberg, but it seems like Vercel’s got a winner on its hands.

    Never one to rest on its laurels, the team behind the TanStack universe unveils TanStack DB. TanStack DB extends TanStack Query with collections, live queries and optimistic mutations client side for building super fast apps on sync without needing a Firebase subscription

    In Lightning News this week, OpenAI released GTP-5. It’s better at all the things: writing, coding, and health questions, but are the improvements going to be so great we’ll actually notice? Time will tell. 

    Also, in disappointing news, Cognition, the AI company that scooped up the remains of Windsurf, has laid off the Windsurf employees it acquired, or told those who remain to expect 80-hour, six day a week, work weeks: another way to effectively reduce headcount. Let’s hope this doesn’t set a new precedent in Silicon Valley.

    Timestamps:

    • 00:53 - Drama between Cloudflare and Perplexity
    • 09:15 - Vercel AI SDK 5
    • 15:23 - TanStack DB update
    • 19:28 - GPT-5
    • 25:23 - A not-so-great Windsurf & Cognition update
    • 30:51 - What’s making us happy

    Links:

    • Paige - Vercel AI SDK 5
    • Jack - TanStack DB
    • TJ - Drama between Cloudflare and Perplexity
    • OpenAI GPT-5 arrives
    • A not-great Windsurf & Cognition update
    • Illinois blocks AI from being your therapist
    • A Guide To Hover And Pointer Media Queries (Smashing Magazine)
    • Paige - The Retrievals podcast
    • Jack - Creality CR-Scan Otter 3D Scanner
    • TJ - People I (Mostly) Admine

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    46 min
  • Is es-toolkit the Lodash Killer?

    There’s a new utility library in town called es-toolkit, and it’s gunning for Lodash. 2-3x faster, 97% smaller, full TypeScript support, and using modern JavaScript APIs, es-toolkit’s just added a “Lodash compatibility layer” to ensure an identical API and 100% Lodash compatibility.

    oRPC is the newest wrinkle in the Remote Procedural Call (RPC) world, and it promotes easy to build APIs that are end-to-end type-safe and adhere to OpenAPI standards. 

    Stack Overflow’s 15th developer survey results are in, and the learnings are... interesting. Some of the takeaways are expected (React’s still very popular, lots of devs have at least tried AI tools), but some seem willfully wrong (SO claims it’s a new resource for devs that need to solve AI-related issues, but 43% of respondents said they rarely or never visit the site anymore). 

    Either way, SO’s use has declined dramatically over the last few years due to the rise of AI, and we’ll see how much longer it can hang on as a vital part of the developer ecosystem.

    Timestamps:

    • 0:57 - es-toolkit update
    • 7:46 - oRPC
    • 17:13 - Stack Overflow Developer Survey
    • 31:43 - Bolt hackathon winners
    • 34:11 - Microsoft Edge Copilot Mode
    • 38:46 - State of HTML survey
    • 39:30 - What’s making us happy

    Links:

    • Paige - es-toolkit is coming for Lodash
    • Jack - oRPC
    • TJ - Stack Overflow 2025 survey results
    • Bolt hackathon winners
    • Microsoft Edge Copilot Mode
    • State of HTML survey
    • Paige - Monopoly Deal card game
    • Jack - Gridfinity 3D printed grid storage system
    • TJ - NY Times Games App

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    48 min
  • Is Open Source Software Infrastructure?

    GitHub is advocating for a European Union Sovereign Tech Fund to help pay the open source software developers building and maintaining software relied upon by economies and societies just like any other necessary infrastructure like roads and bridges.

    Apple gets called out by the Open Web Advocacy group saying its technical rules and restrictions are blocking other browser vendors from successfully offering their own search engines to iOS users in the EU.

    Last episode we talked about Amazon’s new AI coding editor Kiro, and this week, we learned about a feature called Agent Hooks which let users write automation tools that agents can use within the IDE to do predefined actions like maintaining code quality, checking for security vulnerabilities, standardizing and enforcing team processes, and more. Think of it like pre-commit hooks but with AI behind them!

    Timestamps:

    • 0:51 - GitHub is advocating for an EU tech fund
    • 9:21 - An update on non-WebKit browsers on iOS
    • 15:30 - Kiro’s agent hooks
    • 26:28 - Kilo Code
    • 28:35 - eslint-config-prettier got hacked
    • 33:15 - @media(hover: hover)
    • 36:05 - What’s making us happy

    Links:

    • Paige - GitHub is advocating for an EU Sovereign Tech Fund
    • Jack - Kiro’s Agent Hooks
    • TJ - An update on non-WebKit browsers on iOS
    • Kilo Code - open source AI agent VS Code extension (not to be confused with the Kiro fork)
    • Popular npm package eslint-config-prettier got hacked
    • @media(hover:hover)
    • Paige - Relax Meditation app
    • Jack - Physical books like the Annihilation series
    • TJ - Apple Watch series 10

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    46 min
  • Windsurf’s 72-Hour Power Shuffle

    There are so many headlines about AI IDE Windsurf as of late, but we’ll try to catch you up. 

    First, OpenAI wanted to buy Windsurf for $3B, but the deal fell through due to Microsoft. Next, Google hired Windsurf’s top execs and researchers to work on its AI products, but didn’t buy the Windsurf IDE, for $2.4B. Then, Cognition bought the remainder of Windsurf’s IP (and its staff) to integrate into its own products like Devin. And did we mention this all happened in the span of 72 hours?

    Amazon released its own AI-powered IDE called Kiro, and it claims it will bring structure to vibe-coding with "specs" to appeal to the enterprise companies. Kiro transforms prompts into structured specifications, technical designs, and implementation plans complete with testing.

    Next.js 15.4 debuted with a few notable highlights like 100% integration test compatibility for its new Turbopack bundler, and an experimental feature flag called `browserDebugInfoInTerminal` that will forward browser console output to the local terminal so CLI coding agents and AI IDEs like Cursor can see (and fix) client side errors. That sounds super useful.

    Timestamps:

    • 1:07 - Windsurf drama explained
    • 11:28 - Amazon’s new Kiro editor
    • 26:29 - Next 15.4
    • 33:33 - Figma’s new glass effect
    • 39:19 - Lee Robinson leaves Vercel
    • 41:09 - What’s making us happy

    Links:

    • Paige - Next.js 15.4, including `browserDebugInfoInTerminal` flag for AI agents
    • Jack - Kiro AI IDE for spec-driven development
    • TJ - OpenAI’s Windsurf deal falls through - and Windsurf’s CEO is going to Google
    • Lee Robinson leaves Vercel after 5 years
    • Figma has Glass Effect
    • Paige - The Will of the Many novel
    • Jack - Ninja Single Serve coffee maker and SF Bay Coffee compostable K-cups
    • TJ - Tabletop shuffleboard

    Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

    • Front-end Fire website
    • Blue Collar Coder on YouTube
    • Blue Collar Coder on Discord
    • Reach out via email
    • Tweet at us on X @front_end_fire
    • Follow us on Bluesky @front-end-fire.com
    • Subscribe to our YouTube channel @Front-EndFirePodcast
    52 min

About Front-End Fire

From the publisher's feed

A weekly show that helps you stay up to date on the latest and greatest in the front-end world.

More shows like Front-End Fire

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,092 Listeners

ShopTalk by Chris Coyier & Dave Rupert

ShopTalk

501 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

622 Listeners

JavaScript Jabber by Charles M Wood

JavaScript Jabber

62 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

983 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,428 Listeners

Practical AI by Daniel Whitenack and Chris Benson

Practical AI

205 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

10,183 Listeners

Hard Fork by The New York Times

Hard Fork

5,554 Listeners

PodRocket by LogRocket

PodRocket

59 Listeners

devtools.fm: Developer Tools, Open Source, Software Development by Andrew Lisowski, Justin Bennett

devtools.fm: Developer Tools, Open Source, Software Development

26 Listeners

The Startup Ideas Podcast by Greg Isenberg

The Startup Ideas Podcast

211 Listeners

Latent Space: The AI Engineer Podcast by Latent.Space

Latent Space: The AI Engineer Podcast

103 Listeners

This Day in AI Podcast by Michael Sharkey, Chris Sharkey

This Day in AI Podcast

221 Listeners