Maël
11.3K posts

Maël
@arcanis
Lead maintainer for @yarnpkg 🧶, staff FE DevX @mistralai, alumni @datadoghq, @facebook, @sketchfab. Find me on 🦋: https://t.co/UJOKfQdJWa!
Nantes, France شامل ہوئے Ağustos 2009
587 فالونگ4.5K فالوورز
پن کیا گیا ٹویٹ
Maël ری ٹویٹ کیا

It’s happening. Yarn 6 Preview is here 💫
Yes, we rewrote it in Rust 🦀⚡️
I'm incredibly excited for the future of our beloved package manager. See the benchmarks and plans in our latest post: yarn6.netlify.app/blog/2026-01-2…
English

Maël@arcanis
@sebastienlorber @kerematam @jarredsumner @pnpmjs @ZoltanKochan Yes, I initially was worried about decreasing the visibility of new releases (and thus the chances malicious things would get caught) but now there are enough 3rd-party reviewers that this isn't a concern anymore. We'll do that in a future release.
QME

@sebastienlorber @kerematam @jarredsumner @pnpmjs @ZoltanKochan Yes, I initially was worried about decreasing the visibility of new releases (and thus the chances malicious things would get caught) but now there are enough 3rd-party reviewers that this isn't a concern anymore. We'll do that in a future release.
English

@kerematam @jarredsumner Great idea, would definitely use that when upgrading deps or generating a new project!
cc @pnpmjs @ZoltanKochan @arcanis
English

One pattern keeps repeating with supply chain attacks: most of them get caught within hours, or at most within a week; meaning mostly zero-day victims effected.
Some recent picks; the NX attack from last week was caught in just a few hours, and this latest one within a day.
The Hacker News@TheHackersNews
🚨 20 npm packages with 2 BILLION+ weekly downloads (incl. chalk & debug) were hacked. A maintainer was phished into giving up 2FA — attackers slipped in malware that hijacks wallets & steals crypto. Here’s what went down ↓ thehackernews.com/2025/09/20-pop…
English
Maël ری ٹویٹ کیا

@wunderacle @styfle @kvz @satanacchio I, and others, have the feeling the decision was made without a proper understanding of the negative impact it would have.
A "Node.js core" sharing unsupported stats and discarding the official ones doesn't help dismiss this feeling.
English

@arcanis @styfle @kvz @satanacchio That’s not what I intended to say. I have no idea why you are being aggressive with a random you’ve ever met. There’s no need to be passive aggressive.
You’re entitled to your opinions, and I’m to mine, and that’s it. Have a good day.
English

@wunderacle @styfle @kvz @satanacchio "The data we connect aren't representative, I actually prefer to ask my friends to have unbiased data" is a weird argument, but it tracks.
Seriously, I don't understand how you're missing the optics here. Corepack fails, so be it. But to see it fail this way? Doesn't look great.
English

Ive definitely looker at this way before Darcy made this public lol. I never said Yarn adoption is small, I’ve said corepack adoption is small.
The only survey we did is the Next-10 survey which has a very small sample, which is naturally biased as it comes from sources such as X.
The Next-10 survey has small statistical significance and it is only used to get a signal of how adoption of certain pieces of the ecosystem is, knowing that it is biased.
I’m pretty sure that corepack is only used by a minor % (probably less than 10% of Node.js devs) around the world. Do I have large data sources to prove that? Not really, just what I observe around all the communities and companies Ive worked with.
But pretty please do not take my words as any sort of truth, or that they have any value. Take them with salt. They’re just my personal views and might be quite wrong.
English

@wunderacle @kvz @styfle @satanacchio 30% of respondents stated they use Corepack a year ago, despite the experimental tag, despite having to explicitly enable it, despite the FUD. I don't know where your "extremely small" comes from. Citation needed?
English

I get that, I am not defending npm being bundled or not; Just saying I understand why it is a way easier decision to unbundle corepack which is user by an extremely small % of the user-base compared to npm, than unbundling npm. Is that enough of a reason? I do think so. Node is an enterprise-first runtime. It focusses a lot on stability and backwards compatibility.
But this is how I perceive the technical direction of Node. We don’t have the luxury to make radical decisions. Still I believe we are on the right path and doing right for our users.
English

@cursor_ai Bluesky mirroring please 🙏🦋 I only accidentally saw this thread thanks to it being shared in Slack.
English

@bloushed_2 @Mimthegamer @SpeeDonsFR Pour info ta réponse n'apparaît pas dans mes notifs. Faire un don à Speedons ou se faire scam par Twitter Blue, aïe aïe aïe dilemme 😬
Français

@arcanis @Mimthegamer @SpeeDonsFR En effet, vous voulez qu'on sombre tous dans le même bateau, top votre solidarité
Français

@Mimthegamer @SpeeDonsFR Non, rappelons au contraire que chaque élan de solidarité a toujours été propulsé par la gauche. Peut-être qu'à un moment l'électorat de droite verra le pattern et pigera qu'ils se font scammer.
Français

@SpeeDonsFR Le seul bémol de cette année : trop de politique. On nous emmerdes avec ça tous les jours, pas besoin d en rajouter une couche... Laissons l humain, le jeu vidéo et la générosité être le coeur de l'événement et rassemblons les foules au lieu de vouloir les séparer...
Français

@PabloTM27 @ArcanisYT Wrong Arcanis 🙂 especially since I'm mostly on Bluesky these days anyway.
English

@ArcanisYT @arcanis toca video polemico donde hables si Switch 2 se convertirá en la consola Main de muchos, seria interesante
Español
Maël ری ٹویٹ کیا

@TomlinsonCJ @gasmonkey You owe 107,000 USD per person in federal debt. We owe close to nothing and have a huge surplus on both our trade balance and our government budget. Our standard of living is better in almost every way. We have no idea why you think that the US is so attractive for everybody.
English

@SamuelEtienne @boulanger @Frederic_Molas My bad alors ! La résolution de l'image m'avais fait douter
Français

@SensCritique Par curiosité, comment les backups raw SQL ont-elles été corrompues?
Français

Comme promis, on fait le point sur la maintenance du site en détails sur SensCritique ! 🗞
L'article complet : bit.ly/4hiNCWV.

Français
Maël ری ٹویٹ کیا

@JulienVerlaguet @Vjeux Makes sense! What about performances? If I do updates that trigger other updates in a hot loop, would that be an issue?
English

Soooo excited about Skip - The Reactive Framework. I’ve always wanted something like React for the backend and I feel like this is it! If you want to hack on something during the winter break, go at it ;) skiplabs.io
English














