Skip to content
Robert Stowe
Photo Blog
LinkedIn
Security and Supply Chain
Node.js 26.10 adds debounce and throttle to the runtime
October 2026
The new accessibility draft reports by impact, not by level
September 2026
Passkeys are a settled standard, the rest is product work
August 2026
One maintainer account reached 515 million weekly downloads
August 2026
AsyncAPI compromise ran its payload at import time
July 2026
Node.js June patches reach into hostname checks
July 2026
Third parties were involved in nearly half of breaches
June 2026
The TanStack packages were published by the real pipeline
May 2026
pnpm 11 waits a day before installing a new version
May 2026
Questions I think a team should ask before an AI tool trial
May 2026
React 19.2.5 is another Server Components hardening patch
April 2026
What I think engineers should understand about compliance
April 2026
Node.js patches nine issues, two of them old-fix bypasses
March 2026
Why I treat security as part of the pipeline
March 2026
A native HTML sanitizer arrives in Firefox and Chrome
February 2026
Node.js security releases, 8 fixes across every active line
January 2026