InfoQ Homepage Web Development Content on InfoQ
-
Axios npm Package Compromised in Supply Chain Attack
On March 31, 2026, two versions of the Axios library were compromised and found to contain a Remote Access Trojan. The malicious packages were published through a hijacked maintainer account. The Axios team is investigating how the breach occurred and has deprecated the affected versions. Security experts emphasize the need for better dependency management.
-
ESLint v10: Flat Config Completion and JSX Tracking
ESLint version 10 has removed the legacy eslintrc configuration system, finalizing a long transition to flat config. The update enhances developer experience, especially for plugin authors and monorepo teams, by changing configuration file location and improving JSX reference tracking. Node.js support has been tightened, and new assertion options have been added to the RuleTester API.
-
TanStack Start Introduces Import Protection to Enforce Server and Client Boundaries
TanStack Start has introduced a import protection, which aims to prevent server and client code from being mixed in full-stack React applications. This Vite plugin automatically checks imports during development and build processes. It blocks harmful imports by file naming conventions or explicit markers, enhancing security and reducing bugs without requiring additional developer input.
-
FOSDEM 2026: Intro to WebTransport - the Next WebSocket?!
Max Inden recently explored in a talk at FOSDEM 2026 how the upcoming WebTransport protocol and Web API enhance WebSocket capabilities. WebTransport seeks to provide, among other things, lower latency and transparent network switching for key use cases such as high-frequency financial data streaming, cloud gaming, live streaming, and collaborative editing.
-
Nuxt Test Utils v4: Vitest v4 Requirement, Mocking Overhaul and Stricter Environment Setup
Nuxt Test Utils has released version 4.0.0, which primarily integrates Vitest v4. This update changes the test environment setup to beforeAll, resolving issues with module-level mocks. It also improves mockNuxtImport for cleaner partial mocking and enhances state management for registered endpoints. The library remains vital for testing in the Nuxt framework, bridging unit and end-to-end testing.
-
Experimental Web Install API Seeks to Improve Application Discovery and Distribution
The new, experimental Web Install API is now in Origin Trial in Microsoft Edge and Chrome. The API allows developers to programmatically trigger a PWA installation prompt from in-app user interactions. The API aims to simplify software discovery and distribution, particularly for users who are unaware of the install icon in the browser’s address bar or do not typically use app stores.
-
Vercel Releases JSON-Render: a Generative UI Framework for AI-Driven Interface Composition
Vercel has open-sourced json-render, a framework that enables AI models to create structured user interfaces from natural language prompts. Released under the Apache 2.0 license, it supports multiple frontend frameworks and features a catalog of components defined by developers. Community feedback includes both support and skepticism, highlighting its differences from existing standards.
-
QCon London 2026: Tools That Enable the Next 1B Developers
At QCon London 2026, Ivan Zarea, director of platform engineering at Netlify, discussed the impact of AI on web development, noting a surge in non-traditional developers among the 11 million users on the platform. He presented three pillars for developer tools: developing expertise, honing taste, and practicing clairvoyance, emphasizing the need for thoughtful architecture in a evolving landscape.
-
QCon London 2026: Running AI at the Edge - Running Real Workloads Directly in the Browser
At QCon London 2026, James Hall discussed running AI workloads directly in browsers, highlighting local processing benefits such as enhanced privacy, reduced latency and cost. He examined technologies like Transformers.js and WebGPU, illustrated practical applications, and provided guidelines for browser-based AI implementation, emphasizing appropriate use cases and evaluation principles.
-
State of JavaScript 2025: Survey Reveals a Maturing Ecosystem with TypeScript Cementing Dominance
The 2025 State of JavaScript survey reveals a maturing ecosystem with TypeScript's dominance solidified—40% of developers use it exclusively. Vite surges in build tools with a 98% satisfaction rate, while React remains the top framework amidst mixed feedback. AI-assisted development grows notably, and Node.js stays dominant. Overall, developer satisfaction stabilizes at 3.8/5.
-
QCon London 2026: from DVDs to Global Streaming How Netflix’s Commerce Architecture Actually Evolved
Dynamic principal engineer at Netflix, Kasia Trapszo, expertly navigates the evolution of the company’s commerce architecture from a DVD rental service to a global streaming giant. Her insights on pragmatic adaptations to billing systems reveal invaluable lessons on agility, localization, and the complexity of modern payment landscapes.
-
Webpack Publishes 2026 Roadmap with Native CSS Support, Universal Target, and Path to Version 6
Webpack's 2026 roadmap, led by Even Stensberg, unveils substantial enhancements aimed at modernizing the bundler. Key features include native CSS module support, universal compilation for various environments, built-in TypeScript support, and a focus on performance optimization. As competitors rise, webpack strives to enhance user experience while preserving its core strengths.
-
Rspress 2.0: AI-Native Documentation, Faster Startup and a Redesigned Theme
Rspress 2.0 has launched with a revamped theme, boosted performance, and innovative AI features, transforming developer documentation. With enhanced build speeds and a new Static Site Generation to Markdown (SSG-MD) capability, Rspress empowers developers with customizable styling options while simplifying content management. Experience superior documentation with lightning-fast efficiency!
-
Vue Router 5: File-Based Routing into Core with No Breaking Changes
Vue Router 5.0 has integrated unplugin-vue-router into its core, enhancing file-based routing and TypeScript support. This transition release boasts no breaking changes, simplifies dependencies, and introduces experimental features like data loaders and improved editor tooling. Ideal for Vue.js developers, it positions itself as a bridge to the upcoming ESM-only version 6.
-
Vercel Releases React Best Practices Skill with 40+ Performance Rules for AI Agents
Vercel has launched "react-best-practices," an open-source repository featuring 40+ performance optimization rules for React and Next.js apps. Tailored for AI coding agents yet valuable for developers, it categorizes rules based on impact, assisting in enhancing performance, bundle size, and architectural decisions.