Peter van der Zee
banner
pvdz.ee
Peter van der Zee
@pvdz.ee
tafka @kuvos

eng @socket.dev

- 15yr js/ts
- rust
- ex vercel
- ex fb
- js1k-guy
Pinned
Today is my first day at @socket.dev ! 😱

Perfectly aligns with what I want. Stoked to get started 🧐
Maybe github should add an AI review phase to PR's where you get to duke it out with the code assist of your choice, before opening the actual PR. It could hide the usually rather noisy messages from the bot while you work to resolve issues.

I mean, I don't expect them to change anything, but yknow
November 14, 2025 at 4:53 PM
Ah yes, the unknown category is legendary. Its effectiveness is un-de-fined.

🤦‍♂️
November 11, 2025 at 5:25 PM
Ok, Inscription has some depth. I love it. Hope there's even more depth after act 2.

Also, jetlag is a pita. Didn't have much of it two weeks ago in Washington but now in NY I'm waking up at 4 am and can't sleep anymore. Ugh.
November 5, 2025 at 12:29 PM
I guess screw you, Google play, and I'll never leave a review again. So not my problem.
And screw any random games demanding sign up to play without reasons.
November 1, 2025 at 7:45 PM
> The real value of your AI-first language isn't the constraints - it's that you're co-designing the language WITH the LLM's feedback, which might reveal insights about what makes code "LLM-friendly." But so far, the answer seems to be: TS is already LLM-friendly enough.

I need my yesman back...
October 20, 2025 at 11:18 PM
Trying to define an AI-first language with Claude.

Ironically, you can't just ask an LLM what works best for it. It's not "conscious" (in any sense of the word) and can't reflect on that. It doesn't "like" anything. Any response comes from training data/resources.

Also, I need less of a yes-man.
October 19, 2025 at 10:08 PM
@areinet.bsky.social im doing pizza before rar so don't wait for me at the bar, see you there
October 16, 2025 at 10:41 PM
Recognition for Sarah! So deserved! @sarahgooding.bsky.social
October 16, 2025 at 2:50 PM
Good story bro, nay, Great story 😁 @voodootikigod.bsky.social
October 16, 2025 at 1:15 PM
Ahw. Tenko didnt make the cut, nor any of my other stuff. Im a failure.
October 14, 2025 at 2:24 PM
So who's gonna be at jsconf! Hoping to see some old friends and acquaintances again :)

Let's hope border queues are not too bad with the shutdown and all :/ I'm sure it'll be fine. Long day tomorrow, either way.
October 12, 2025 at 8:41 PM
15 years later and there's finally a wikipedia page for JS1k! 🥲

en.wikipedia.org/wiki/Js1k
Js1k - Wikipedia
en.wikipedia.org
October 10, 2025 at 3:47 PM
LLM tools should leverage a difference in content and actual conversation better. For example, when I paste a glob of debug text or have it run tests and check the output, that sort of blob should not become part of the message conversation.
October 10, 2025 at 8:55 AM
Shit :/

> Google Is Ending Gmailify and POP Support
October 4, 2025 at 6:22 AM
Reposted by Peter van der Zee
🚨 Open source supply chain attacks are exploding.

Starting today, that ends.

We’re releasing Socket Firewall — FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI.

Just run:

npm i -g sfw
sfw npm install lodash

Works for: npm, yarn, pnpm, pip, uv, and cargo.
September 30, 2025 at 6:06 PM
I mean. wtf
September 30, 2025 at 12:52 PM
I'm actually looking forward to the LLM-first framework talk at JSConf.

I've been thinking about this too. Theres no real framework for AI yet. I suspect theres a lot of room for improvement to cater for LLMs. Both in language and in web framework.

What would an LLM-friendly language look like?
September 27, 2025 at 2:29 PM
Reposted by Peter van der Zee
While we haven't seen major supply chain attacks hitting any of the major open-source ecosystems, the Socket Threat Research Team uncovered some fascinating and creative attack techniques worth sharing:
pypi-mirror.org
September 26, 2025 at 10:44 PM
Seriously. I don't know who worked on that Skoda Enyaq UX, or how this passed QA, but holy shit it's so bad

Half the physical buttons are USELESS, inc steering wheel, it's dangerous to change the fan speed while driving, and no separate speed between driver/passenger. Software mostly sucks. etc etc
September 21, 2025 at 11:19 PM
We learned that the Skoda Enyaq, which has a terrible UX on almost all accounts, also doesn't have a darkmode. It just doesn't have one. wtf. Screen is so bright at night :(

Best you can do is turn down the control lights, then open version page. It's darker because it is JACK SHIT EMPTY anyways.
September 21, 2025 at 11:14 PM
Who needs enemies when cant even beat a 1700 elo bot in chess.

Ugh.
September 20, 2025 at 3:30 PM
I looked at our detected threats this morning and had a bit of a :wow: moment.

socket.dev/blog/ongoing...
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages...
Socket.dev found compromised various CrowdStrike npm packages, continuing the "Shai-Halud" supply-chain attack that previously hit `tinycolor`.
socket.dev
September 16, 2025 at 10:04 AM
Third major npm supply chain attack in like two weeks? One week? Yikes.

socket.dev/blog/tinycol...
Popular Tinycolor npm Package Compromised in Supply Chain At...
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
socket.dev
September 15, 2025 at 11:37 PM
I like anthropic's claude CLI better than Cursor's CLI.

For one it seems slightly better overall (cursor sometimes goes brain zombie once it goes over input token limit) but more importantly: cursor downgrades the model underwater once you go over 20$ plan. And the downgrade is so observably worse.
September 15, 2025 at 11:40 AM
@gothamchess.bsky.social Heya. Some feedback;

- you hate it when chess .com spoils games due to the bug, but spoil your videos by putting results in titles. :feelsbadman:

And since you, I think, like to pronounce langs proper:

- Foreest, ee like a in ace
- stroopwafels, oo like oa in oatmeal
September 14, 2025 at 10:08 PM