// writing
Posts tagged #tooling
A mix of technical deep-dives, career reflections, and dispatches from the road.
tag: #tooling

developmentSep 28, 2026· 3 min
Node.js Type Stripping: Run TypeScript Without a Build Step
Node.js now runs .ts files out of the box by erasing types, not compiling them. Here's what that buys you, what it refuses to do, and the tsconfig that keeps you honest.
read more →

developmentSep 27, 2026· 4 min
Compression Dictionaries: Ship Only the Diff When Your Bundle Changes
Compression Dictionary Transport (RFC 9842) lets the browser tell your server which cached file it already has, so a redeployed bundle can arrive as a few-kilobyte delta instead of a full download.
read more →

developmentSep 21, 2026· 3 min
import defer: Lazy Modules Without Going Async
ES2026's import defer evaluates a module the first time you touch its namespace, not at startup, so you can move heavy work off the cold path without turning half your call stack async.
read more →

developmentSep 20, 2026· 4 min
Turbopack's Persistent Build Cache Only Helps If Your CI Keeps It
Next.js 16.3 turned on Turbopack's persistent build cache by default and published numbers as high as 5.5x. Most CI pipelines will see exactly zero of that, because the cache is a directory and containers start empty.
read more →

developmentSep 13, 2026· 3 min
GraphQL @oneOf: Exactly One Input, Enforced by the Schema
OneOf Input Objects landed in the September 2025 GraphQL spec, which means the exactly-one-of-these-arguments rule you've been enforcing in resolver code is…
read more →

developmentSep 10, 2026· 3 min
node --test: The Test Runner You Already Have Installed
Node's built-in test runner has been stable since v20 and now handles mocking, coverage, watch mode, and TypeScript files.
read more →

developmentAug 10, 2026· 3 min
Trusted Types Is Baseline: DOM XSS Is Now a Type Error
Firefox 148 shipped Trusted Types in February 2026, making it Baseline. Here's how to turn every dangerous innerHTML assignment in your app into a TypeError…
read more →

developmentAug 6, 2026· 4 min
GraphQL Trusted Documents: Stop Letting Strangers Write Your Queries
Disabling introspection is not security. Trusted documents let your server execute only the operations your own developers wrote, and you probably already…
read more →

developmentAug 2, 2026· 3 min
The Sanitizer API: Safe HTML Injection Without DOMPurify
The browser can now strip XSS from an HTML string during parsing. Here's how setHTML works, why its config can only narrow the allowlist, and how to ship it…
read more →

developmentJul 30, 2026· 3 min
Laravel 13 PHP Attributes: Config That Lives With Your Code
Laravel 13 expands first-party PHP attributes across controllers, authorization, and queued jobs. Here is what actually changed, and where attributes are…
read more →
// the newsletter