The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Wednesday, September 30, 2026 Vol. I — No. 679 · Page D1 € 0,00*  *as always

Nine npm lookalikes carried a self-spreading Linux worm ▶ D2

TypeScript publishes vscode-typescript 1.0.0 ▶ D2

Citrix ships NetScaler fixes after two flaws are exploited ▶ D2

Releases!
Extra!read all about it

TypeScript ships vscode-typescript 1.0.1

TypeScript has published vscode-typescript 1.0.1 on GitHub.

TYPESCRIPT RELEASES — The tag points to commit b6eaace and was created by typescript-automation on 29 Sep at 19:31. GitHub lists two release assets. The supplied release page contains no change notes or compatibility information, so the update’s practical impact cannot be assessed from the available data.

▶ continued: summary & source

curated by Sönke

Node.js publishes version 26.10.0

Node.js has published version 26.10.0, according to the project’s release page. The available announcement identifies the release and its version but provides no addition… ▶ D4

News: Google tracked TeamPCP from inside its supply-chain campaign

Reads: Mojo 1.1 opens compiler to community contributions

News: AWS Reports Irrecoverable Customer Data After Gulf Strikes

Reads: Rust community warns of targeted attacks

Releases: Node.js 26.9.0 expands crypto APIs and Web Workers

Reads: Java discussion highlights modern features and legacy runtimes

The Editorial: Python 3.15's Lazy Imports Ship Without the Discipline That Made Ours Work

Reads: Homebrew 7.0.0 Adds Native macOS App and Built-In Vulnerability Scanning

Releases: VS Code 1.137 Adds Scheduled Agent Task Automations

Tooling: PlanetScale launches Neki, a sharded Postgres platform

Security: BlueMoon exploit kit hits Chrome and Windows across four threat groups

Releases: Node.js 26.8.2 updates Undici, OpenSSL and npm

Security: Chrome 153 ships with two-week release cycle and 230 security fixes

Security: Microsoft fixes record 972 vulnerabilities in September, 112 rated critical

Releases: Node.js 24.21.0 Arrives as LTS Krypton

The Editorial: When an AI Company Buys the Runtime, Governance Stops Being Boring

The Editorial: Headless Chromium Is a Production Dependency. Patch It Like One

Security: Actively Exploited V8 Flaw Puts Every Chromium App and Electron Tool at Risk

Releases: Zod 4.5 speeds up validation with precompiled schemas

Security: BGP Hijack of Softaculous IPs Pushed Malicious Updates to Virtualizor Servers

Releases: pnpm 12 in Rust: Fast Start, npm Packages and No SSH

Reads: Why One Engineer Blames File-System Design for the Hugging Face Breach

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy