Ulises Gascón
banner
ulisesgascon.com
Ulises Gascón
@ulisesgascon.com
#OpenSource Maintainer (@nodejs.org, @expressjs.bsky.social, Lodash, Yeoman...), #TC39 Delegate and #Maker | He/Him
Pinned
🌍 Hello, BlueSky! 🤠

I'm Ulises Gascón from Spain! Passionate about #Nodejs, #Express, #JavaScript, and the world of #OpenSource.

I spend my days building, maintaining, and improving tools and libraries for our #devCommunity 🫶

👉 Check out my projects and support my work:
github.com/sponsors/Uli...
✨ Want to contribute to @openjsf.org projects but not sure where to start?

Simple trick: connect with the community first 🎯
• Join the community Slack
• Check the shared calendar for meetings & events

www.youtube.com/shorts/4h7P7...
How to Get Involved in OpenJS Projects
YouTube video by OpenJS Foundation
www.youtube.com
December 19, 2025 at 11:12 AM
Reposted by Ulises Gascón
Major update to the CSS Media Queries Analysis Snippet with a Performance Impact Analyzer

It calculates the REAL cost of desktop-only CSS on mobile:

📉 Core Web Vitals Impact
💰 Estimated Conversion Lift

e.g.: Fixing 30KB of unused CSS 180ms faster load and up to 1.8% conversion boost
December 16, 2025 at 9:07 AM
Reposted by Ulises Gascón
How can you ACTUALLY get involved with OpenJS projects??

@ulisesgascon.com gives the download in our latest snapshot.

Join Slack, join our community meetings, or watch recordings.

Come say hi. 👋
December 16, 2025 at 3:16 PM
😏 Want to master #JS & #TS this year?

This Humble Tech Book Bundle features practical guides — including my book Node.js for Beginners.
Plus, your purchase supports charity ♥️

www.humblebundle.com/books/javasc...
Humble Tech Book Bundle: JavaScript and TypeScript Mastery by Packt
Rewrite the script of your career journey with new skills in JavaScript, TypeScript, and more—get our latest Tech Book Bundle today!
www.humblebundle.com
December 16, 2025 at 8:44 AM
🚀 Just released serve-static@1.16.3 📦

🍿 #release details: github.com/expressjs/se...
Release v1.16.3 · expressjs/serve-static
What's Changed deps: send@~0.19.1 by @Phillip9587 in #227 Release: 1.16.3 by @UlisesGascon in #229 Full Changelog: v1.16.2...v1.16.3
github.com
December 15, 2025 at 7:14 PM
Reposted by Ulises Gascón
WinterTC's Minimum Common Web API standard is now officially published as ECMA-429, Edition 1 . To many more editions!

Thanks @jasnell.me, @andreubotella.com, @akiro.se, @littledan.dev and everyone else that was involved in making this happen.

🎉
December 12, 2025 at 3:33 PM
Reposted by Ulises Gascón
🚀 iconv-lite 0.7.1 released 🎉

- Improved type definitions and added missing APIs 🧩

github.com/pillarjs/ico...
Release v0.7.1 · pillarjs/iconv-lite
What's Changed 🚀 Improvements types: improve type definitions and add missing APIs - by @plbstl and @bjohansebas in #330 Other changes Bump actions/setup-node from 4 to 6 by @dependabot[bot] in ...
github.com
December 11, 2025 at 3:59 PM
This was such a fun recording! 🤣
Working on some shorts for you to round out 2025 and we're feelin' festive 👀

You can catch all of the past videos for our JavaScript Security Snapshot on our YouTube: youtube.com/playlist?lis... @rafaelgonzaga.bsky.social @ulisesgascon.com
December 11, 2025 at 7:46 PM
🔖 My PR updating the #Security Best Practices for Your Project guide is now merged!

✨ New: license-risk checks + SBOMs, threat modeling, incident-response basics, and stronger security roles & culture.

opensource.guide/security-bes...
Security Best Practices for your Project
Strengthen your project’s future by building trust through essential security practices — from MFA and code scanning to safe dependency management and private vulnerability reporting.
opensource.guide
December 10, 2025 at 9:23 PM
Reposted by Ulises Gascón
ECMAScript excitement 😉

A highly comprehensive article on what will (and might!) land in ES2026 by @marypcbuk.bsky.social 🎉

Includes coverage on Temporal by Boa creator @jason-williams.co.uk who leads the Rust-based temporal_rs library, as used by Google's V8 engine, amongst others.
December 9, 2025 at 11:57 PM
Reposted by Ulises Gascón
Node excitement 😉

Congrats to @hybrist.dev on landing support for Package Imports that start with #/ 🎉

Previously this prefix was special-cased and would error. It's convenient to use it as an internal absolute path to the package root.

import foo from "#/src/file.ts"
December 8, 2025 at 12:44 PM
🔖 The latest issue of my #newsletter is out, issue 010.

Stories from reviving #Expressjs & reimagining #Lodash, secure publishing on #npm, why #OSS doesn’t fail because of code, backlog updates & #OpenSSF #Scorecard

blog.ulisesgascon.com/newsletter-i...
Newsletter #010: Wrapping Up the Year with Talks, Security Work and Big Releases 🎁
This month brought a new talk, a deep dive into secure publishing, key Express releases, OSSF Scorecard updates, and several ecosystem improvements around security and governance.
blog.ulisesgascon.com
December 8, 2025 at 2:46 PM
🔖 Kode Dot: The ultimate all-in-one device for makers, hackers and geeks.

www.kode.diy
Kode Dot: The ultimate all-in-one device for makers, hackers and geeks.
Kode Dot is a pocket-size device with built-in sensors, a display, external I/Os and more, ready to use in your daily routine to build DIY electronics, explore ethical hacking tools and develop powerf...
www.kode.diy
December 6, 2025 at 10:47 AM
For moments like this, I’m so proud to be part of this amazing team ❤️

github.com/expressjs/ex...
Release: 5.2.1 by UlisesGascon · Pull Request #6933 · expressjs/express
ImportantThe prior release (5.2.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-5199...
github.com
December 5, 2025 at 9:51 AM
🔖 Love how Orbitant shares learnings with the community even under pressure. Great read on handling a critical #CVE as a team:

orbitant.com/en/critical-...
Critical React Server Components Vulnerability: what we did
Critical React Server Components Vulnerability: how a team responded with fast communication, automation, and coordinated updates for the CVE.
orbitant.com
December 4, 2025 at 2:38 PM
Just shipped a new newsletter to my GitHub Sponsors! 🎁

This one includes my latest talk, secure publishing research, #Expressjs and #OSSF #Scorecard updates, and a bunch of ecosystem news.

It will be public soon, but you can read it early and support my OSS work here: github.com/sponsors/Uli...
December 3, 2025 at 3:43 PM
Security incident? Don’t panic. Have a plan. 🤝

A clear incident response plan keeps open source projects steady when things go wrong 😏

www.youtube.com/shorts/mqPlC...
Incident Response Plan
YouTube video by OpenJS Foundation
www.youtube.com
December 2, 2025 at 9:03 PM
Reposted by Ulises Gascón
Woah. String.prototype.startsWith() supports two arguments:

"my string".startsWith("string", 3) => true

I had no idea this was possible.
developer.mozilla.org/en-US/docs/W...
a man with glasses is surrounded by a glowing circle and the website pmitf.com is displayed below him
ALT: a man with glasses is surrounded by a glowing circle and the website pmitf.com is displayed below him
media.tenor.com
December 2, 2025 at 1:51 PM
🚀 Just released finalhandler@1.3.2 📦

🍿 #release details: github.com/pillarjs/fin...
Release v1.3.2 · pillarjs/finalhandler
What's Changed deps: use tilde notation and update certain dependencies by @Phillip9587 in #118 Release: 1.3.2 by @UlisesGascon in #121 Full Changelog: v1.3.1...v1.3.2
github.com
December 1, 2025 at 4:00 PM
🚨 We’ve published our Nov security update, including moderate fix for body-parser.

expressjs.com/2025/12/01/s...
November 2025 Security Releases
Security release for body-parser has been published. We recommend that all users upgrade as soon as possible.
expressjs.com
December 1, 2025 at 3:37 PM