OpenJS Foundation
@openjsf
Followers
320K
Following
3K
Media
681
Statuses
7K
A home for those who love JavaScript.
Joined April 2008
Working on some shorts for you to round out 2025 and we're feelin' festive 👀 You can catch all of the past videos for our JavaScript Security Snapshot on our YouTube: https://t.co/T0aiOvbcDS
0
0
5
npm has revoked classic tokens for publishing, pushing maintainers toward OIDC trusted publishing or granular tokens. But @openjsf warns OIDC trusted publishing still has risky gaps for critical projects. https://t.co/DLJh46TV3o
#NodeJS #JavaScript
socket.dev
GitHub has revoked npm classic tokens for publishing; maintainers must migrate, but OpenJS warns OIDC trusted publishing still has risky gaps for crit...
0
5
4
JavaScript is 30. Still running the web & still our favorite. 💛✨ The OpenJS Foundation is grateful for every contributor who has shaped its path, and we look forward to the continued growth of this community.
9
42
225
Life runs in seconds, not minutes, hours, weeks, or years. Anything can change at a moments notice. So try to do it right the first time if you're able because you might not get a second chance at it again.
0
1
44
The JavaScriptLandia individual contributor program will end on Friday, Dec 5, 2025. Thank you to everyone who earned badges and celebrated the amazing work across the JS ecosystem. The community awards will continue, and we’re exploring new ways to highlight community
openjsf.org
Phasing out the JavaScriptLandia Individual Contributor Program
0
0
6
Tis the season ✨ Level up your skills this holiday with 65% off Training and Certification from our friends at the Linux Foundation. Ends December 9. Details here: https://t.co/eewm5gzm2B
1
0
5
SEMVER MAJORS ARE BORING 🚨 Major releases mostly bring breaking changes, not shiny new features. The fun stuff? That’s hiding in the minors. @_rafaelgss talks about why you should follow the minor releases in our latest JavaScript Security Snapshot. Want to dive in further?
0
4
9
ICYMI: We wrote some concrete npm security suggestions for JavaScript maintainers to help guard against Shai-Hulud style attacks. 👇 https://t.co/FiLnEIQeHg
openjsf.org
The OpenJS Security Collaboration Space has been working closely with GitHub’s npm team to understand how new security features affect projects and maintainers, especially as threats and tools keep...
0
6
10
Before automated workflows, releasing @nodejs meant 20 manual steps. Now it’s one command. 👀 @kom_256 and @_rafaelgss share how the Node.js build team went from a rack of Raspberry Pis in someone’s garage to full release automation. Check out the Build Team Working Group on
1
6
25
See what JSConf 2025 was all about in @hackmdio's recap 😎
@jsconf @matteocollina @jarredsumner @LizzParody @voodootikigod @openjsf @JavaScript explore more and see the fun that was had in our latest blog:
0
0
3
Security incident? Don’t panic. Have a plan. 🤝 @kom_256 explains how a clear incident response plan keeps open source projects steady when things go wrong in the latest JavaScript Security Snapshot. Check out the Incident Response Plan here on GitHub: https://t.co/v2Rz4stNMf
1
4
18
With npm supply chain attacks on the rise, secure publishing practices are becoming a pressing concern for anyone maintaining npm packages. ⚠️ The OpenJS Security Collaboration Space has released updated guidance to help maintainers reduce exposure, strengthen release processes,
0
10
27
October’s security check‑in is here! 🚨 📌 Highlights: stronger threat modelling, npm Trusted Publishing risks tackled, new runtime features for secure‑by‑default apps. https://t.co/Xhwd1yjcp2
0
2
6