AI Weekly Malaysia

Back to items Summaries

Friendship ended with Deno, now Node is my best friend

ID
32365
Status
summarized
Published
06 Oct 2026, 6:30 AM
Fetched
06 Oct 2026, 11:41 PM
Provider
Hacker News
Category
dev-community
Original URL
https://dbushell.com/2026/10/03/deno-to-node/
Source URL
https://hnrss.org/best

Summary

Score
7.5
Created
06 Oct 2026, 11:42 PM
Tags
Audience
developersvibe_coderssaas_startup_founders

What happened

After using Node heavily this month on a SvelteKit client project, David Bushell writes that he is moving back from Deno to Node because modern ECMAScript support and APIs mean he no longer sees require(). He uses FNM for Node version switching and PNPM with npm/npx aliases, plus pnpm-workspace.yaml settings minimumReleaseAge: 1440 and trustPolicy: no-downgrade to delay malicious releases and avoid downgrades. Node can now run TypeScript, but Node.js v26.10.0 docs say type stripping is unsupported for files under node_modules, so TypeScript packages cannot be published to NPM under this restriction.

Why it matters

For JS/TS teams, the actionable part is package-manager defaults: PNPM's minimumReleaseAge: 1440 (one day) and trustPolicy: no-downgrade are concrete supply-chain mitigations, while npm's post-install script behavior remains a risk to verify. Also, do not assume Node's native TypeScript support covers dependencies or published packages—node_modules TS files are still unsupported per Node v26.10.0 docs. No direct Malaysia-specific angle appears in the text.

Discussion angle

Given Node's node_modules TypeScript restriction and PNPM's malware-delay settings, what should a TypeScript monorepo use for package publishing and dependency safety?

Top