A worm spread an identical credential stealer through nine unrelated npm organisations within roughly 30 minutes, hitting keyv and cacheable packages among others. Affected packages include authentication libraries, and …
Node.js has published two new releases: v26.6.0 in the current release line and v24.19.0, the latest update to the LTS Krypton branch. Both versions are available via the official Node.js release channels and distributio…
RFC 10008 finally gives us an HTTP method that carries a body and is still safe and idempotent. The spec is sound and short. But whether QUERY becomes real depends on nginx configs, CDN method allowlists, WAF defaults an…
TypeScript 7, released July 8, 2026, replaces the compiler with a Go-based implementation and delivers real build speed gains. The piece warns that the upgrade path comes with three common breaking issues most teams will…
Vercel Labs has released scriptc, an open-source compiler that turns TypeScript directly into native executables without a JavaScript runtime. Early benchmarks show drastically faster startup, smaller binaries and lower …
GitHub has launched stacked pull requests in public preview. The feature splits large changes into an ordered series of small, focused pull requests, making reviews easier. Developers can create and manage dependent PR c…
Visual Studio Code 1.131 introduces an experimental built-in dictation service for chat, editor and terminal, powered by the offline Nemotron model, removing the need for the separate Speech extension. The update also sh…
The Node.js project has published Node.js 22.23.2 (LTS 'Jod'), a security release fixing ten CVEs — three rated high — affecting HTTP/2, the permission model, HTTPS, DNS and zlib. Immediate upgrades are recommended.
JetBrains has patched CVE-2026-63077, a critical 9.8 CVSS vulnerability in TeamCity's agent polling protocol affecting all on-premises versions. Attackers can bypass authentication and execute arbitrary OS commands. Upda…
Vercel Labs has published scriptc, an open-source compiler that turns ordinary TypeScript into small native executables without embedding Node, V8 or any JavaScript engine. Static binaries start in about 2.4 ms at 170-20…
Claude Code, Cursor, Codex and the newly open-sourced Grok Build all write software fast now. A July preprint testing 86 Python developers found we're bad at catching the wrong ones while feeling just as confident. My ta…
A report describes a flaw present in the Linux kernel since version 2.6.39, released in 2011, and shipped by default in most mainstream distributions ever since. The dormant code can reportedly be leveraged to gain root …
CrowdStrike researchers discovered a worm that infiltrates AI-driven development pipelines, harvesting npm tokens, cryptographic keys and access credentials while mimicking legitimate automation to evade detection. The m…
A developer explains why they load secrets through application code instead of environment variables, citing a unified config format, an AWS ECS incident where env vars leaked in the console, disk-encryption safeguards, …
A Reddit discussion around a blog post proposes that SQLite adopt Rust-style 'editions' — versioned bundles of safer defaults for foreign keys, journal_mode and busy_timeout. Many developers say they've been burned by SQ…
A Reddit thread reacts to a disclosure from security firm Mindgard showing Cursor's Windows client executes any file named git.exe found in a repository's root folder, even in restricted workspace mode. Demonstrated by r…
This piece walks through the architectural challenges of rebuilding a notification platform to reliably fan out millions of messages without timing out. It covers personalization, priority handling, consent checks, traff…
The article explains how to implement end-to-end encrypted secret sharing in the browser using the Web Crypto API. It also warns against common salt mistakes—stressing that salts should be unique, not secret—and argues t…
Cloudflare discovered a race condition vulnerability in the hyper Rust HTTP library's HTTP/1 handling. The flaw affects concurrent request processing and warrants attention from teams using hyper in production systems. D…
GhostLock is a use-after-free (UAF) vulnerability affecting the kernel's I/O handling stack that persisted across all major Linux distributions for approximately 15 years. The flaw, detailed in security research, represe…
A humorous take on poor software architecture through the lens of furniture organization. The post examines common design mistakes and over-engineering pitfalls that developers encounter when structuring their codebase, …
The French data protection authority, CNIL, is enforcing a new regulatory framework requiring online services to obtain user consent before using tracking pixels in emails. This move, aligning email marketing with cookie…
This Reddit submission points to the official announcement for TypeScript version 7.0. Professional developers using TypeScript in web projects should read it to learn about the latest additions, potential breaking chang…
This short piece argues that many teams add extra databases, queues, caches, and services before they actually need them. It is worth reading for its practical framing of when Postgres can stay the center of a stack, and…
The post examines techniques for enabling partition pruning in PostgreSQL when queries filter on columns outside the partitioning key. It covers practical approaches to preserve performance gains from table partitioning …
China’s Long March 10B completed its first flight and recovered its booster in the South China Sea using a net mounted on an offshore vessel. The test marks China’s first controlled rocket recovery and validates reusable…
Guide to deploying Umami, a privacy-focused analytics platform, across serverless and edge infrastructure. Covers practical setup on Cloudflare Workers, Fly.io, and Supabase, appealing to developers seeking vendor-indepe…
The article examines why code quality resists reduction to single metrics such as Lines of Code, cyclomatic complexity, Halstead metrics, Maintainability Index or code coverage. It references Goodhart’s Law and Weyuker’s…
A reporter testing a Range Rover was surrounded by armed police after Flock's ALPR system flagged it as stolen—caused by a clerical error 2,000 miles away. An LA fleet entry typo ("34 DTM" instead of "34 03 DTM") led to …
Apple has filed a lawsuit accusing OpenAI of stealing hardware trade secrets and breaching contracts, alleging that former Apple employees retained access to confidential material after joining the company. The complaint…