
Sign up to save your podcasts
Or


The supply chain attacks on npm continue and this week, Crowdstrike’s npm packages fell victim to the “Shai-Hulud” worm.
To mitigate the potential of downloading these malicious packages, consider pinning specific package versions in JS projects and using 2FA to publish new package versions to npm.
Also this week, WebAssembly Specification (Wasm) released v3.0. This version dramatically expands the memory Wasm apps can use, supports multiple memory usage, and now allows garbage collection.
It’s been a while since we last covered LLM options for folks who want to run their own models locally or in the browser, so Jack gives a quick rundown of some of the best options out today.
There’s WebLLM from MLC, MediaPipe from Google, and ONNX from Microsoft, and although none are easily interchangeable with another, if cost, privacy, or working offline are concerns of your LLM-enabled app, these may be good options to explore.
Chapter Markers:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
Just 5 months ago we covered how Storybook 9 was in beta, and already Storybook 10 is in beta. The biggest change is that Storybook is going all in on ESM and dropping CJS support, which is making for some big performance gains and smaller bundle sizes.
This past week, npm suffered the largest supply chain attack in its history when a prolific OSS maintainer got phished. Luckily, the attack was noticed and reported within the hour and it looks like the hackers got next to nothing for their efforts, but it serves as another reminder to be extra careful before clicking links in emails.
In the same security vein, browser company Brave uncovered a security vulnerability in AI-browser Comet where malicious instructions on a web page could cause the agent to “go rogue” while it was being asked to summarize a page’s contents. Perplexity has since added more guardrails to try and mitigate this sort of thing, but be cognizant of the data and site access you’re giving to AI agents.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
The Google vs. the US anti-trust lawsuit has finally drawn to a close, and (spoiler alert) Google doesn’t have to sell Chrome (or Android, for that matter). Going forward it will have to share certain search data with its rivals, and that’s about it, so this is definitely a big win for Google any way you look at it.
The popular terminal company Warp just unveiled Warp Code - a suite of features for shipping agent-generated code “all the way from prompt to production” via the Warp terminal. Warp Code offers an agent-driven terminal-first approach, with visual code review of agent changes, and a native file editor for minor edits in an attempt to eliminate the context switching devs have to do nowadays between their AI agents, IDEs, and GitHub.
In a twist no one saw coming, SaaS behemoth Atlassian has bought AI-browser Dia (and its maker The Browser Company) for $610 million. Atlassian wants to position Dia as the AI-browser for users at work and time will tell if that bet pays off.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
Last episode, we lamented Claude’s lack of checkpoints to roll back code when it goes off the rails. Other devs feel the same, and this week Checkpoints for Claude Code debuted. It’s an MCP server that follows Claude Code, creating checkpoints when tasks are completed, allowing for easy reverts when needed.
The Bun team quietly pushed some nice new features in Bun v1.2. Highlights include: a unified SQL client with zero dependencies, native YAML file support, OS native credential storage for secrets, and a security scanner API that scans packages for vulnerabilities before installation.
And MCP-UI, a toolkit of interactive UI components for MCP has new features to support resources beyond text like embedded iframes and even raw HTML. Not all agents with MCP support can handle these new resources, but if they can, users can see product photos, data visualizations, and other mini sites right in their AI chat.
In the Lightning News section for this week, the folks at Deno leading the charge to get Oracle to relinquish its trademark for JavaScript need our help. Those legal bills aren’t going to pay themselves and Deno’s pockets aren’t nearly as deep as Oracle’s, so if you care about making JavaScript public domain (which it absolutely should be), please consider donating so they can keep fighting the good fight to free JS. Every little bit helps.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
The latest craze for MCP this week? Instead of multiple MCP servers with different tools, use an MCP server that accepts programming code as tool inputs - a single “ubertool” if you will. AI agents like Claude Code are pretty good at writing code, but letting the agent write and execute code to invoke API functions instead of using a defined MCP server doesn’t seem like the most efficient use of LLM tokens, but it's another approach to consider.
In infrastructure news, there’s a library called Alchemy that lets devs write their Infrastructure as Code in pure TypeScript. No Terraform files, no dependencies, just async functions, stored in plain JSON files, that runs anywhere JS can run. For web devs, the future of IaC has arrived.
Next.js has made their last big release before v16 in the form of 15.5. Highlights of this minor release include: production turbopack builds, stable support for the Node.js runtime in middleware, fully typed routes, and deprecation warnings in preparation for Next.js 16.
Timestamps:
You just can’t keep TanStack out of the news for more than a few weeks before a new product appears. This week, it’s TanStack Devtools, which provides a centralized devtools panel of all the Tanstack libraries for streamlined DX and custom devtools support.
The State of CSS 2025 survey results are in, and highlights include: devs love the new `:has()` feature, Tailwind CSS continues to be the most popular CSS framework, and over 60% of respondents are still using Sass or SCSS in their web apps.
Continuing the CSS topics, Panda CSS, a CSS-in-JS library that debuted in 2023, just hit v1. Panda gained traction by being a CSS-in-JS library built for the server-first era (meaning RSC support), and it adds new features like static analysis, type safety, and support for modern CSS like cascade layers, JSX style props, and a `createStyleContext` API for cross-framework design systems.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
There’s drama brewing between AI-answer engine company Perplexity and hosting platform Cloudflare, which recently declared it would actively block AI bots from crawling websites without the owners’ permission. Cloudflare received complaints, set up its own test sites, and then asked Perplexity pointed questions only - and got answers! Not a great look, Perplexity.
Two years after Vercel launched v1 of its AI SDK, it has dropped v5, and it’s got some major improvements. Rebuilt chat hooks, improved tool calling, more agentic controls, and it works with React, Svelte, Vue, and Angular. That’s just the tip of the iceberg, but it seems like Vercel’s got a winner on its hands.
Never one to rest on its laurels, the team behind the TanStack universe unveils TanStack DB. TanStack DB extends TanStack Query with collections, live queries and optimistic mutations client side for building super fast apps on sync without needing a Firebase subscription
In Lightning News this week, OpenAI released GTP-5. It’s better at all the things: writing, coding, and health questions, but are the improvements going to be so great we’ll actually notice? Time will tell.
Also, in disappointing news, Cognition, the AI company that scooped up the remains of Windsurf, has laid off the Windsurf employees it acquired, or told those who remain to expect 80-hour, six day a week, work weeks: another way to effectively reduce headcount. Let’s hope this doesn’t set a new precedent in Silicon Valley.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
There’s a new utility library in town called es-toolkit, and it’s gunning for Lodash. 2-3x faster, 97% smaller, full TypeScript support, and using modern JavaScript APIs, es-toolkit’s just added a “Lodash compatibility layer” to ensure an identical API and 100% Lodash compatibility.
oRPC is the newest wrinkle in the Remote Procedural Call (RPC) world, and it promotes easy to build APIs that are end-to-end type-safe and adhere to OpenAPI standards.
Stack Overflow’s 15th developer survey results are in, and the learnings are... interesting. Some of the takeaways are expected (React’s still very popular, lots of devs have at least tried AI tools), but some seem willfully wrong (SO claims it’s a new resource for devs that need to solve AI-related issues, but 43% of respondents said they rarely or never visit the site anymore).
Either way, SO’s use has declined dramatically over the last few years due to the rise of AI, and we’ll see how much longer it can hang on as a vital part of the developer ecosystem.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
GitHub is advocating for a European Union Sovereign Tech Fund to help pay the open source software developers building and maintaining software relied upon by economies and societies just like any other necessary infrastructure like roads and bridges.
Apple gets called out by the Open Web Advocacy group saying its technical rules and restrictions are blocking other browser vendors from successfully offering their own search engines to iOS users in the EU.
Last episode we talked about Amazon’s new AI coding editor Kiro, and this week, we learned about a feature called Agent Hooks which let users write automation tools that agents can use within the IDE to do predefined actions like maintaining code quality, checking for security vulnerabilities, standardizing and enforcing team processes, and more. Think of it like pre-commit hooks but with AI behind them!
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
There are so many headlines about AI IDE Windsurf as of late, but we’ll try to catch you up.
First, OpenAI wanted to buy Windsurf for $3B, but the deal fell through due to Microsoft. Next, Google hired Windsurf’s top execs and researchers to work on its AI products, but didn’t buy the Windsurf IDE, for $2.4B. Then, Cognition bought the remainder of Windsurf’s IP (and its staff) to integrate into its own products like Devin. And did we mention this all happened in the span of 72 hours?
Amazon released its own AI-powered IDE called Kiro, and it claims it will bring structure to vibe-coding with "specs" to appeal to the enterprise companies. Kiro transforms prompts into structured specifications, technical designs, and implementation plans complete with testing.
Next.js 15.4 debuted with a few notable highlights like 100% integration test compatibility for its new Turbopack bundler, and an experimental feature flag called `browserDebugInfoInTerminal` that will forward browser console output to the local terminal so CLI coding agents and AI IDEs like Cursor can see (and fix) client side errors. That sounds super useful.
Timestamps:
Links:
Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.
From the publisher's feed
A weekly show that helps you stay up to date on the latest and greatest in the front-end world.

286 Listeners

1,092 Listeners

501 Listeners

622 Listeners

62 Listeners

983 Listeners

8,428 Listeners

205 Listeners

10,183 Listeners

5,554 Listeners

59 Listeners

26 Listeners

211 Listeners

103 Listeners

221 Listeners