jonchurch's Avatar

jonchurch

@jonchurch

maintaining express, lodash / ex-msft

74
Followers
104
Following
69
Posts
30.06.2024
Joined
Posts Following

Latest posts by jonchurch @jonchurch

Thanks! I was hoping someone else had replicated the registry so I didnt have to

06.03.2026 00:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
pure-color dependent packages | npmjs.org | Ecosyste.ms: Packages View the packages that depend on the #<Package:0x00007f6154efc308> package on the npmjs.org package registry, including their kind and latest version.

Yeah I see how the downloads dont seem to add up if you just walk the reported dependents

packages.ecosyste.ms/registries/n...

04.03.2026 22:18 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
ecosyste.ms | Tools and datasets to support, sustain, and secure critical digital infrastructure. Tools and datasets to support, sustain, and secure critical digital infrastructure.

I got replies before from folks suggesting how they have or would do this, I pinged @andrewnez.bsky.social from ecosyste.ms who might know more!

04.03.2026 22:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
ecosyste.ms | Tools and datasets to support, sustain, and secure critical digital infrastructure. Tools and datasets to support, sustain, and secure critical digital infrastructure.

@andrewnez.bsky.social can you help point to the correct way to do with? can ecosyste.ms do it?

04.03.2026 22:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

ooph yeah idk, my query reports it would scan 48 TB, so almost $300 to run it once

04.03.2026 22:06 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

lemme see if I am still set up to pull this info easily without spending money lol

04.03.2026 21:55 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I spent like 3k by accident doing some queries which were similar to these, but not the same.

What’s the package btw?

04.03.2026 21:48 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
GitHub - jonchurch/top-dependents Contribute to jonchurch/top-dependents development by creating an account on GitHub.

Yep, this repo shows the queries I used

Be warned though BigQuery get expensive fast, Id suggest making these queries on an account with no credit card attached lol

Or otherwise restrict the query to processing 1TB of data (which I think is the free usage threshold)

04.03.2026 21:48 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

someone’s gotta monitor the situation

02.03.2026 06:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Kind of brilliant for an agent’s mascot to be a type of bug itself if you mentally squint

23.02.2026 02:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Clinejection β€” Compromising Cline's Production Releases just by Prompting an Issue Triager | Adnan Khan - Security Research Clinejection β€” Compromising Cline's Production Releases just by Prompting an Issue Triager - Security research by adnanthekhan

Okay so adding cache to the list of github actions feature surface to always be terrified of

adnanthekhan.com/posts/clinej...

19.02.2026 02:30 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

belt-and-suspenders

17.02.2026 23:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

It's not just lodash, to be clear, it seems like a lot of packages are having a pretty sharp increase this week

calling out lodash bc of the big number milestone

09.02.2026 22:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

we all know npm stats are a blunt metric, and a rising tide of JS continuing to eat the world lifts all boats

but got damn πŸ‘

does anyone have stats about how npm downloads in general grow YoY?

09.02.2026 22:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

lodash just had its first ever 100M+ download week on npm

that's a 70% YoY increase

09.02.2026 22:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

its frustrating that the remote claude code env is missing some tools.

For me its the missing gh cli that really hurts, for reading issues/PRs or otherwise doing read against GH

So I created this StartSession script which ensures it is installed in remote sessions

www.npmjs.com/package/@jon...

30.01.2026 20:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Some (world is large) people have been getting angry with Anthropic lately and see requesting clawdbot change its name as another user hostile action

Which is wild to me, it is so clearly infringing

Same folks have been mad they prevented 3rd party agent harnesses using claude subscription auth

28.01.2026 01:11 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

i do like the computer

28.01.2026 01:08 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Do you mean domains as orgs ala namespace? Do you have thoughts on how domain takeover risk would playout here (ala expiry, reregister)

I know in ATP domain takeover !== account takeover, just handle. But if you mean domains as namespaces, then I dont know enough about ATP to see past the risk

25.01.2026 01:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

*pre-npm registry as in before it became the defacto place for JS code to be distributed

07.12.2025 23:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
ComponentJS - 1 - Overview
ComponentJS - 1 - Overview YouTube video by Dr. Ralf S. Engelschall

In my OSS archaelogy efforts I keep bumping into the defunct Component.js pre-npm registry and UI framework paradigm

Just found this video explainer from their homepage focusing on the ui component runtime system, really capturing a point in time
www.youtube.com/watch?v=gtz7...

07.12.2025 23:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Maybe it was the aws outage today?

20.10.2025 21:29 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

For sure, Ive tried to recreate the API calls from the site, but the feed it shows is by latest published now it seems

19.10.2025 15:31 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
GitHub - jonchurch/top-dependents Contribute to jonchurch/top-dependents development by creating an account on GitHub.

My use case is here, but my expensive query was a modified version of what is in the readme

github.com/jonchurch/to...

19.10.2025 14:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 3 πŸ“Œ 0

I know @e18e.dev has mirrored some data, what are yall doing to query the ecosystem relationships?

19.10.2025 14:31 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I got most of what I wanted for a specific package, but npm registry data access just doesnt exist anymore and has been lacking for a long time.

This bigquery dataset is still the best way I know to do this, and it still doesnt give me everything I need.

19.10.2025 14:29 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Im asking for a goodwill credit 🀞as I just didnt realize running my simple focused query less than 10 times could spend that

But ultimately there’s no good way to do this research today that Im aware of

19.10.2025 14:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 1

I spent almost $3k on Google BigQuery by accident while exploring dependency relationships in the deps.dev dataset

WOOF

19.10.2025 14:21 πŸ‘ 4 πŸ” 0 πŸ’¬ 3 πŸ“Œ 0

I need to process whatever all I signed up for

18.10.2025 16:12 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Aye, what Ive been working on is a change monitor.

Takes a list of packages to watch, alerts when any changes occur at the registry. Maintainers add/rm, version add/rm, dist tag changes, lifecycle scripts change between versions etc

To solve for knowing if any of your pkgs had a sneaky publish

25.09.2025 17:04 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0