<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HTML + CSS + JavaScript</title>
	<atom:link href="https://htmlcssjavascript.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://htmlcssjavascript.com</link>
	<description>Let&#039;s Build the Web We Want</description>
	<lastBuildDate>Thu, 08 Oct 2026 15:04:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>
	<item>
		<title>The Superset Trap: Why Node’s Native TypeScript is Going to Break Enterprise Brains</title>
		<link>https://htmlcssjavascript.com/web/the-superset-trap-why-nodes-native-typescript-is-going-to-break-enterprise-brains/</link>
					<comments>https://htmlcssjavascript.com/web/the-superset-trap-why-nodes-native-typescript-is-going-to-break-enterprise-brains/#respond</comments>
		
		<dc:creator><![CDATA[Rob Larsen]]></dc:creator>
		<pubDate>Thu, 08 Oct 2026 15:04:42 +0000</pubDate>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[typescript]]></category>
		<guid isPermaLink="false">https://htmlcssjavascript.com/?p=11516</guid>

					<description><![CDATA[If you spend your time in open-source mailing lists or arguing about AST transformations on social media, the recent push toward &#8220;erasable syntax&#8221; makes total sense. I’ve been a proponent of TypeScript for a long time. In the early days, whenever someone brought up enum, for example, I remember having conversations along the lines of: [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h1 class="wp-block-heading"></h1>



<p class="wp-block-paragraph">If you spend your time in open-source mailing lists or arguing about AST transformations on social media, the recent push toward &#8220;erasable syntax&#8221; makes total sense.</p>



<p class="wp-block-paragraph">I’ve been a proponent of TypeScript for a long time. In the early days, whenever someone brought up <code>enum</code>, for example, I remember having conversations along the lines of: <em>&#8220;Oh, enum? That’s not real. That gets magically transformed into real JavaScript behind your back.&#8221;</em></p>



<p class="wp-block-paragraph">And then I’d get a sparkle in wondering what IIFE monstrosity the compiler invented just to make it work. (I have to shout out Ben Alman, who was right here in our ridiculous Boston front-end scene when he popularized the term &#8220;IIFE&#8221; back in 2010. Little did Ben know the TypeScript compiler would end up weaponizing his naming contribution to haunt us sixteen years later.)</p>



<p class="wp-block-paragraph">Back then, we loved pulling back the curtain. Do people even know what a polyfill is anymore? I have my doubts.</p>



<p class="wp-block-paragraph">The thing is, most developers writing code for a living don&#8217;t live in that world.</p>



<p class="wp-block-paragraph"><em>&#8220;AST what?&#8221;</em></p>



<p class="wp-block-paragraph">In the enterprise trenches, where teams were dragged out of desktop software and backend services into the chaotic swamp of modern web development, TypeScript wasn&#8217;t viewed as a lightweight annotation layer. It was viewed as a sanctuary.</p>



<p class="wp-block-paragraph">Anders Hejlsberg designed C#, and then he designed TypeScript. To millions of backend engineers, TypeScript felt like fruit from the very same design tree. The mental model was simple: TypeScript was the bigger circle in the Venn diagram—the &#8220;typed superset&#8221; Microsoft explicitly sold us. You wrote <code>enum</code>, you wrote <code>namespace</code>, you wrote constructor parameter properties, and you trusted the compiler magic to handle the messy JavaScript plumbing underneath.</p>



<p class="wp-block-paragraph">And for a decade, that compact worked fine. The build toolchain absorbed the weirdness, emitted runtime IIFEs, and everyone went about their day.</p>



<p class="wp-block-paragraph">Then the enterprise joined the chorus asking for the holy grail: <em>“Can Node please just run TypeScript natively?”</em></p>



<p class="wp-block-paragraph">We got what we asked for. Node will execute your <code>.ts</code> files. But it does so with a massive asterisk that is going to bewilder anyone who learned TypeScript as &#8220;C# for the browser&#8221;: <strong>Node only strips types. It does not compile your bespoke runtime features.</strong></p>



<p class="wp-block-paragraph">The moment you run a raw TypeScript file in Node without a build step, that comfortable superset abstraction collapses. You have an <code>enum</code> sitting in an enterprise shared-utility file? Crash. A clever <code>namespace</code>? Crash.</p>



<p class="wp-block-paragraph">Nobody in a corporate sprint planning meeting thought about the distinction between <em>type-stripping</em> and <em>transpilation</em>. They just assumed native TypeScript meant the engine would run their TypeScript code. Period.</p>



<p class="wp-block-paragraph">Which brings us to <code>erasableSyntaxOnly: true</code>.</p>



<p class="wp-block-paragraph">JSON</p>



<pre class="wp-block-code"><code>{
  "compilerOptions": {
    "erasableSyntaxOnly": true
  }
}
</code></pre>



<p class="wp-block-paragraph">This flag is essentially the antidote to a decade of superset marketing. It forces the compiler to yell at you the second you write syntax that can&#8217;t be deleted with an eraser. Try to write an <code>enum</code>? It breaks in your editor before it can blow up your server.</p>



<p class="wp-block-paragraph">It is a fascinating full-circle moment. For ten years, teams embraced TypeScript precisely because it felt like a richer, more familiar programming language than JavaScript. Now, if we want the dream of zero-build native execution, we have to teach those same teams that the extra features they loved were actually technical debt in disguise.</p>



<p class="wp-block-paragraph">Fun times.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://htmlcssjavascript.com/web/the-superset-trap-why-nodes-native-typescript-is-going-to-break-enterprise-brains/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Governing the Generative Drift: Why We Need the Assumptions &#038; Constraints Manifest (ACM)</title>
		<link>https://htmlcssjavascript.com/web/why-we-need-the-acm/</link>
					<comments>https://htmlcssjavascript.com/web/why-we-need-the-acm/#respond</comments>
		
		<dc:creator><![CDATA[Rob Larsen]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 16:45:18 +0000</pubDate>
				<category><![CDATA[Web]]></category>
		<guid isPermaLink="false">https://htmlcssjavascript.com/?p=11510</guid>

					<description><![CDATA[A couple of weeks ago, I talked about the &#8220;Happy Path Trap&#8221;—how LLMs create massive Day 1 velocity while burying teams in silent Day 2 architectural debt. During that discussion, I pitched an idea: What if we required an Assumptions &#38; Constraints Manifest (ACM) in every AI-assisted PR to make hidden trade-offs visible? Since I’m [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe title="Launching ACM v1.1 (Assumptions and Constraints Manifest)" width="500" height="375" src="https://www.youtube.com/embed/klsM_6d-G2s?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div></figure>



<p class="wp-block-paragraph">A couple of weeks ago, I talked about the &#8220;Happy Path Trap&#8221;—how LLMs create massive Day 1 velocity while burying teams in silent Day 2 architectural debt.</p>



<p class="wp-block-paragraph">During that discussion, I pitched an idea: What if we required an Assumptions &amp; Constraints Manifest (ACM) in every AI-assisted PR to make hidden trade-offs visible?</p>



<p class="wp-block-paragraph">Since I’m not one to wait around for someone else to build tooling I want to use, I spent the last few days building it out.</p>



<p class="wp-block-paragraph">Today, I’m open-sourcing ACM v1.1—a formal spec and developer toolkit designed to audit architectural boundaries, not just syntax.</p>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> What’s in the toolkit:<br>Typed Contracts &amp; Proof Obligations: Requires the PR to explicitly state guarantees around concurrency, idempotency, and scaling—citing exact line numbers and locking mechanisms.</p>



<p class="wp-block-paragraph">Automated Generation: Drop-in .cursorrules and PR templates that prompt Cursor, Claude, and Copilot to generate manifests automatically during code creation.</p>



<p class="wp-block-paragraph">CI/CD Linter: An open-source CLI linter (@roblarsen/acm-cli) and GitHub Action to validate manifests and gate PRs automatically in your pipeline.</p>



<p class="wp-block-paragraph">Instead of spending 45 minutes playing digital archaeology on AI-generated diffs, reviewers can audit explicit boundaries in 30 seconds.</p>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f517.png" alt="🔗" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Get Started<br>GitHub: <a href="https://github.com/roblarsen/ACM">github.com/roblarsen/ACM</a></p>



<p class="wp-block-paragraph">CLI: npx @roblarsen/acm-cli</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://htmlcssjavascript.com/web/why-we-need-the-acm/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Weekly Web Dev Quick Hits</title>
		<link>https://htmlcssjavascript.com/web/weekly-web-dev-quick-hits/</link>
					<comments>https://htmlcssjavascript.com/web/weekly-web-dev-quick-hits/#respond</comments>
		
		<dc:creator><![CDATA[Rob Larsen]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 17:37:45 +0000</pubDate>
				<category><![CDATA[Web]]></category>
		<guid isPermaLink="false">https://htmlcssjavascript.com/?p=11492</guid>

					<description><![CDATA[A couple quick hits while I rev the content engine back up over here! CSS Weaponized at Black Hat 2026: Security researcher Gareth Heyes dropped a research paper showing how CSS alone can break out of webmail sanitizers. Without a single line of JavaScript, malicious stylesheets in Gmail and Outlook were manipulated to spoof UI [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>A couple quick hits while I rev the content engine back up over here!</p>
<ul>
<li>
    <strong><a href="https://beeble.com/en/blog/how-a-css-border-escape-compromised-the-world-s-most-trusted-webmail-interfaces" target="_blank" rel="noopener">CSS Weaponized at Black Hat 2026</a>:</strong> Security researcher Gareth Heyes dropped a research paper showing how CSS alone can break out of webmail sanitizers. Without a single line of JavaScript, malicious stylesheets in Gmail and Outlook were manipulated to spoof UI elements, capture keystrokes, and steal tokens. Stripping <code>&lt;script&gt;</code> tags isn&#8217;t cutting it anymore, apparently.
  </li>
<li>
    <strong><a href="https://css-tricks.com/2026-state-of-css-devs-surveys/" target="_blank" rel="noopener">The 2026 State of CSS Results Are In</a>:</strong> The survey numbers show <code>:has()</code> leading as the most used newer feature, while Anchor Positioning holds the crown as the &#8220;favorite feature we wish had better browser support.&#8221; On the workflow front, 80% of developers report using AI for less than half of their CSS work. It turns out layout still needs humans!
  </li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://htmlcssjavascript.com/web/weekly-web-dev-quick-hits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>H5BP As an Open Source Incubator</title>
		<link>https://htmlcssjavascript.com/web/h5bp-as-an-open-source-incubator/</link>
					<comments>https://htmlcssjavascript.com/web/h5bp-as-an-open-source-incubator/#respond</comments>
		
		<dc:creator><![CDATA[Rob Larsen]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 21:21:00 +0000</pubDate>
				<category><![CDATA[Web]]></category>
		<category><![CDATA[h5bp]]></category>
		<guid isPermaLink="false">https://htmlcssjavascript.com/?p=11478</guid>

					<description><![CDATA[I&#8217;m looking at the future of the HTML5 Boilerplate (H5BP) organization and repos right now and, in addition to formulating plans for the existing projects, I&#8217;ve decided to try something new. Maintenance of the existing projects is vital, but passive stewardship isn&#8217;t enough for where I&#8217;m at right now. The web changes too quickly. AI [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>I&#8217;m looking at the future of the HTML5 Boilerplate (H5BP) organization and repos right now and, in addition to formulating plans for the existing projects, I&#8217;ve decided to try something new. </p>
<p>Maintenance of the existing projects is vital, but passive stewardship isn&#8217;t enough for where I&#8217;m at right now. The web changes too quickly. AI is generating incredible volumes of code and that influx of bloated, unoptimized code requires a counterweight of strict engineering discipline.</p>
<p>So this week, I decided to expand the footprint of @h5bp to act as an active open-source incubator for new projects and emerging engineering talent.</p>
<h2>Why an Incubator?</h2>
<p>Throughout my career leading engineering teams, mentoring builders has been the most rewarding work I&#8217;ve done. The open-source world can be incredibly daunting for a developer looking to scale a project from a personal repository to an industry standard.</p>
<p>By incubating projects within H5BP, we aim to provide independent creators with the operational framework, automation experience, and community visibility required to build high-integrity open source software at scale.</p>
<h2>Enforcing Strict Governance</h2>
<p>We have just released our Project Inclusion Guidelines. To be considered for the incubator, a project must demonstrate:</p>
<ul>
<li>Permissive Licensing: Strict MIT alignment.</li>
<li>Lean Architecture: Minimal or zero runtime dependencies to protect performance budgets.</li>
<li>Supply Chain Security: Clean, verifiable dependency graphs to limit organization-level vulnerability.</li>
</ul>
<h2>Submit a Proposal</h2>
<p>If you are engineering modern web utilities, or foundational developer tools under strict architectural constraints, we want to hear from you.</p>
<p>Review our new <a href="https://github.com/h5bp/html5-boilerplate/blob/main/.github/PROPOSAL_GUIDELINES.md">PROPOSAL_GUIDELINES.md</a>, check out the active PR, and submit your Request for Comments (RFC) directly in our meta repository.</p>
<p>Let&#8217;s build the next generation of web infrastructure.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://htmlcssjavascript.com/web/h5bp-as-an-open-source-incubator/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Mastra Poisoning and the Yin/Yang of Ecosystem Velocity</title>
		<link>https://htmlcssjavascript.com/web/the-mastra-poisoning-and-the-yin-yang-of-ecosystem-velocity/</link>
					<comments>https://htmlcssjavascript.com/web/the-mastra-poisoning-and-the-yin-yang-of-ecosystem-velocity/#respond</comments>
		
		<dc:creator><![CDATA[Rob Larsen]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 20:26:18 +0000</pubDate>
				<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Web]]></category>
		<guid isPermaLink="false">https://htmlcssjavascript.com/?p=11475</guid>

					<description><![CDATA[The modern JavaScript ecosystem is incredible. If you need a utility, library or framework for anything it&#8217;s probably out there in the npm registry. Things that used to take us a week are now available as a simple `npm install.` But last week, the ecosystem reminded us of the exact tax we pay for that [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>The modern JavaScript ecosystem is incredible. If you need a utility, library or framework for <em>anything</em> it&#8217;s probably out there in the npm registry. Things that used to take us a week are now available as a simple `npm install.` But last week, the ecosystem reminded us of the exact tax we pay for that blinding speed.</p>
<p>On June 17, 2026, a sophisticated supply chain attack systematically poisoned the @mastra npm organization. Over a tight 88-minute window, a hijacked contributor account mass-published 144 malicious package versions. The target wasn’t random. Mastra is a leading open-source TypeScript framework for building AI agents and retrieval-augmented generation (RAG) pipelines. By definition, its packages run in environments dripping with high-value infrastructure secrets: OpenAI keys, AWS tokens, database connection strings, and production CI/CD access.</p>
<p>The problem here wasn’t a sloppy, front-facing exploit. The framework’s actual source code remained pristine. Instead, the attackers pushed the payload one level down into the dependency tree, injecting a typosquatted package named `easy-day-js` (a clone of the ubiquitous `dayjs` date library). Hidden inside an obfuscated `postinstall` lifecycle hook was a cross-platform Remote Access Trojan (RAT). The second it was pulled down, it disabled TLS validation, established OS-level login persistence across Windows, macOS, and Linux, and silently opened a remote execution tunnel.</p>
<p><em>That&#8217;s not great. </em></p>
<p>Because it executed during the standard `npm install` phase before a single line of application code was even imported, it sidestepped traditional static analysis and CVE-based scanners.</p>
<h2>The Yin/Yang of Modern Tooling</h2>
<p>This debacle isn’t an isolated incident or an &#8220;AI security&#8221; problem. It is a direct symptom of the foundational double-standard that splits the tech community in half.</p>
<p>On one side, you have <em>willful blindness</em>. This is the camp that looks at a massive dependency tree and thinks &#8220;something bad will happen to someone, someday, but it probably won&#8217;t happen to me.&#8221; </p>
<p>I am in this camp and am one of the few people I know who will say the words out loud in polite company. </p>
<p>We lock our production systems behind layers of enterprise security, yet blindly execute unvetted code straight on our local developer laptops every Tuesday afternoon. <em>Because it&#8217;s probably going to be fine. And we nee to fix this stupid bug. </em> </p>
<p>On the other side sits pure ignorance. There are two flavors of ignorance at play. The first are people which might be in IT, writ large, who don&#8217;t really know how npm works and what <em>actually happens</em> when you type `npm install.` The second is the camp that operates under a warm, fuzzy blanket of open-source idealism: &#8220;It&#8217;s open-source, which means thousands of eyes have already vetted the code, right?&#8221;</p>
<p>The reality is that nobody is auditing nested dependency metadata on a random weeknight. Or, really, ever. It all changes so fast. </p>
<p>This is the inescapable Yin and Yang of our modern web architecture. We want velocity. We want to pull down 1,000 dependencies with a single command so we don&#8217;t have to write custom date parsers or whatever. But the price of that convenience is an aggressively expanded attack surface.</p>
<p><em>Yay</em></p>
<p>When we treat software <strong>identity</strong> as a proxy for absolute trust, we don&#8217;t just inherit the library—we inherit the security habits of every human who has ever touched its dependency graph over the last five years. </p>
<p><em>It&#8217;s what we do and what we&#8217;re going to continue to do</em>, but by treating lockfiles like static grocery lists we are simply playing the world&#8217;s worst game of security roulette.</p>
<h2>Where does this land on the Leaderboard?</h2>
<p>In the grand pantheon of npm registry disasters, Mastra ranks highly. It&#8217;s a state actor, which is always fun. It lacks the sweeping, internet-snapping devastation (or the lol-factor) of the 2016 <code>left-pad</code> tantrum, and it didn’t achieve the sheer global blast radius of the September 2025 Phishing Wave that hijacked foundational blocks like <code>chalk</code> and <code>debug</code> to drain crypto wallets globally.</p>
<p>Instead, Mastra is an echo of the infamous 2018 <code>event-stream</code> compromise. It proves that the modern threat matrix has expanded away from noisy, registry-wide vandalism. Today&#8217;s actors are playing a quiet game of social engineering and credential harvest—hiding their payloads exactly where they know developers are too hurried, too comfortable, or too blind to look.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://htmlcssjavascript.com/web/the-mastra-poisoning-and-the-yin-yang-of-ecosystem-velocity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
