Issue #53: Bridge Over Troubled Water


🎵 When darkness comes and pain is all around, like a bridge over troubled water I will lay me down… 🎵

So Metaframeworks Records are back with the first issue since the cadence switch I announced recently. The list of news is unexpectedly short but hopegivingly interesting. The main agenda today is that people are tired of ubiquitous unsolicited AI discourse and have come back to talking about frameworks and metaframeworks.

Did 2 YouTube videos on web frameworks, 30+ comments

Did 1 video on AI w/Jev, 0 comments

I guess some people still want to talk about the web 🤔

(Brandon Roberts)

Frameworks and metaframeworks are probably the bridges over troubled AI degradation waters — the harness to keep our creations robust (yeah, it’s not all just about a couple of markdown files as someone thinks). If the open-source tools won’t give up and won’t altogether get absorbed by huge monsters of the enterprise world, which we’ll touch on a bit today too, there’s still huge hope that full-stack web development is in the good hands of metaframeworks. Let’s dive right in.

The Good

Ryan Carniato does just that (dives right into the ocean of modern versatile web development tools) in his latest piece called (not without a certain pathos, as usual) “The Grand Unifying Architecture of Frontend” and the accompanying 6-hour livestream on this and adjacent topics. He comes up with a matrix of the main approaches in the ecosystem based on tool responsibilities and mechanics. Not surprisingly, most modern innovation over the last few years has been collapsing toward the center of this matrix as individual frameworks expand their capabilities to cover multiple quadrants simultaneously.

From Ryan’s livestream I learned the sad news about his namesake Ryan Florence’s (the exceptionally clever guy who co-created Remix and React Router alongside Michael Jackson) recent personal departure from working on Remix at Shopify. The ongoing development of the metaframework (whose revamp was recently announced to be almost ready for public release) remains in the hands of the Remix and React Router (which got its new 8.4 release just recently too) engineering teams at Shopify. And the latter is moving quite fast with its CEO’s hysterical stance on AI development and new eager acquisitions, the most recent of which was Tailwind, the extremely popular tool most full-stack developers prefer to use for consuming CSS esotericism.

Arguably, acquisitions are never good for the community and actual product development, though there are definitely some exceptions. For instance, VoidZero slowed down the hype train after being acquired and at first sight it looks bad, but at second glance — metaframework authors got some time to actually work instead of never-ending chains of Vite migrations. With that, the team keeps delivering cool stuff too. Vite+ got its first major version (which means proper stability) and Vitest got version 5 with performance improvements I’ve personally been waiting for so long. Moreover, Nuxt dev tools are actively being combined with Vue dev tools, which makes Nuxt developers’ lives so much easier.

React also got its (quite rare these days) 19.3 update, bringing some polish to the language of the main modern web UIs. Its ubiquity and robustness allow some stories, like Evil Martians’ smooth migration from Gatsby to Astro, to exist and finish with a happy ending, which is due in no small part to Astro itself whose team did accomplish a lot of cool stuff in both August and September (and not just for Cloudflare).

The Bad

But you know who can also brag about its accomplishments lately? September’s birthday-celebrating “person” known as Shai Hulud. Its terror has spanned 12 months in a row already.

A year after the first compromise, Shai-Hulud belongs to no one and everyone with a GitHub account.

The ecosystem still gets surprised by ever new attacks regularly. Even the attempts to protect against that on a regular basis get compromised themselves, and here we are — Next.js publishes its urgent security release and prepares for the next one right away. Is it AI to blame for this and similar issues? No one knows, but these problems affect many tools, like the recent vulnerability findings in Hono.

The community persistently tries to stand up for web safety with new initiatives though, like the recent OpenJS Foundation’s Security Stewardship Program for OSS. Any help like that brings good hope for the future of web development in the context of modern open-source tools like metaframeworks.

The JavaScript ecosystem processes more npm package downloads per week than any other package registry. The surface area for vulnerabilities is enormous, and the maintainer population doing the hardest security work is small and largely volunteer. […] AI is driving a sharp rise in vulnerability reports, pushing many open source projects to shut down their bug bounty programs. The bottleneck is now remediation. […] Finding vulnerabilities is only part of the job. Someone still has to triage them, fix them, and get secure releases into the hands of developers. […] Open source powers the world’s software, and the people maintaining it deserve more than goodwill.

The Noteworthy

On the side of more positive celebrations in the web world, Angular (or rather its latest incarnation of Angular 2+) celebrates its 10-year anniversary which is my party too, as I’ve been living in this ecosystem for longer than that (our friendship started in the AngularJS 1+ era) and have seen it become a literal metaframework of its own.

These days I’m becoming more and more of a tooling generalist though, and on this side of things I wanted to share that I started to work on an open-source security linter utility for TypeScript metaframework applications based on (and accompanying to) the Top 10 Metaframework Security Risks registry I announced here some time ago. If you’re interested in contributing, just let me know in a reply, as usual.

So as you can see, the robust metaframeworks bridge over the troubled water of modern software development still stands, and so do our hopes and dreams about the bright future of full-stack web development with metaframeworks and their ecosystems — safe and sound. I also hope this newsletter will help everyone on this journey too, and I promise to deliver more awesome helper goodies along the way, as I mentioned, but that’s a separate story.

đź‘‹

Found it useful? Consider subscribing to the newsletter.No hidden catch, no strings attached.