Evil Martians

@evilmartians
382 Followers
23 Following
239 Posts
Loved this episode with @jayroh on maintainability & predictability.
And yes — it’s imgproxy, not ImageProxy 😉
Great example of how to migrate safely with adapters + feature flags instead of risky rewrites: https://buff.ly/oisS8Ng
Joel Oliveira: Predictability Is a Maintainability Feature

Predictability might be the most underrated feature of maintainable software. Joel Oliveira joins Robby to explore how thoughtful patterns, small refactors, and a bit of stubborn persistence can keep systems healthy long after their first release.

Maintainable Software Podcast

Nano Stores seems to be my fastest-growing open source project right now.

10x growth over the past year!

https://github.com/nanostores/nanostores

@sitnik_en is our frontend principal and the creator of PostCSS, Nano Stores, and Autoprefixer.

His interview with Dan Nicu is now live on YouTube. They chatted about Andrey's career, the story of how he created popular open source tools, and his thoughts on AI and open source.

Watch it here: https://evilmartians.com/events/senor-developer-sitnik

CSS Tooling, Plugin Ecosystems & Open Source Values at Scale with Andrey Sitnik (Author of PostCSS) by Evil Martians

What happens when one developer's tools account for 0.7% of all NPM downloads? In this episode, Andrey Sitnik, creator of PostCSS, Autoprefixer, and Browserlist, and lead engineer at Evil Martians, shares the full story behind the CSS tools that millions of developers depend on every day.

evilmartians.com
imgproxy v4 is almost here.
We’re looking for teams ready to test v4 before the public release and share feedback. So we’re opening early access for the Pro version.
https://imgproxy.net/v4-early-access/
v4 Early Access | imgproxy: fast and secure on-the-fly image processing

Join the early access program for imgproxy Pro v4 and be the first to experience our latest features and improvements

We're still looking for a frontend engineer to work on @sitnik_en's team.

We're a fully remote team with 20 years of async work experience that offers:

- 34-39 days off
- The possibility of relocating to Lisbon (not mandatory)
- $80K – $113K gross annual salary

You don’t need tens of years of experience. We'd love to chat, if you:

- Know JS and CSS
- Have worked in English
- Have experience working in startups or as a consultant

Requirements and how to apply here: https://evilmartians.com/careers/frontend-engineer

How to Favicon in 2026: Three files that fit most needs—Martian Chronicles, Evil Martians’ team blog

Prefer SVG over PNG, trust browsers to downscale, drop obscure formats—the ultimate, exhaustive guide to favicons for modern web. Includes steps for static HTML and Webpack.

evilmartians.com

Every year we review @sitnik_en’s post on favicons to make sure we have the best, most straightforward guide out there on the topic. 2026 is no exception.

Turns out, you don’t need dozens of icons. You need five handcrafted ones and a single JSON file. This guide shows you exactly how to do it. https://evilmartians.com/chronicles/how-to-favicon-in-2021-six-files-that-fit-most-needs

How to Favicon in 2026: Three files that fit most needs—Martian Chronicles, Evil Martians’ team blog

Prefer SVG over PNG, trust browsers to downscale, drop obscure formats—the ultimate, exhaustive guide to favicons for modern web. Includes steps for static HTML and Webpack.

evilmartians.com

Calling all frontend engineers. It's a perfect time to become a Martian.

We’re looking for a JS dev who respects CSS, UX, and design and can work independently on a fully remote team.

Join the team behind PostCSS, Nano Stores, and OKLCH. Apply here: https://evilmartians.com/careers/frontend-engineer

RE: https://mastodon.social/@sitnik_en/115730334234115554

At Evil Martians, we take supply chain attacks seriously. Postinstall scripts are the weakest link in npm security, and the fix is almost embarrassingly simple.

Here's a guide to increase JS app security from one of @sitnik_en's recent projects:

If you’re a JS dev, here’s one simple change to improve your security: disable postinstall scripts in your npm package manager.

postinstall is the main vector for supply chain attacks from node_modules, but most packages don’t need it.

↓ Thread