The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Thursday, August 20, 2026 Vol. I — No. 373 · Page D1 € 0,00*  *as always

TypeScript 7.0.2 Released as Patch Update ▶ D2

Bun 1.4 ships with Rust rewrite, big Node.js compatibility gains ▶ D2

Critical GitLab GraphQL flaw already under attack, watchTowr reports ▶ D2

Reads!
Extra!read all about it

Supply Chain Attack on Rust Crate Sparks Debate Over Dependency Culture

A supply chain attack on a Rust crate has reignited debate about dependency culture.

R/PROGRAMMING (TOP) — A widely discussed Reddit post argues that Rust shares the npm mindset of pulling in many small packages, and that languages with larger standard libraries face lower attack exposure. The author says Rust needs a broader official ecosystem, not just language work.

▶ continued: summary & source

curated by Sönke

Buf ships language server support for Protobuf

Buf has released LSP support for Protocol Buffers, bringing IDE features like completion, navigation and diagnostics to .proto files. The announcement, discussed on r/pro… ▶ D4

Security: GitLab 19.2.2, 19.1.4 and 19.0.6 patch serious XSS flaws

Reads: Node.js Creator Open-Sources Durable Objects Beyond Cloudflare

Security: LiteLLM Supply-Chain Attack Exposes Credentials at 2,500 Organizations

Security: PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.6 Released with Major Security Fixes

Reads: Tailscale Engineering Uncovers 16-Year-Old SQLite Write-Ahead Log Race Condition

Security: AI-Assisted Bug Hunt Uncovers Zoom Screen-Sharing Flaw Enabling Device Takeover

The Editorial: No ALTER TABLE in Production Without a Lock Budget

Security: New research finds BMC flaws leave tens of thousands of servers open to backdoors

Releases: Node.js v26.7.0 Released

Releases: Next.js 16.3 Ships with up to 90% Lower Memory Usage and Instant Navigations

Reads: JEP 401 brings value objects as a preview feature to the JDK

Reads: Worm Compromises npm's keyv Package and Eight Other Organisations

Releases: Node.js v26.6.0 and v24.19.0 (LTS Krypton) released

The Editorial: QUERY Is the Easy Part. The Plumbing Is Where It Gets Decided

Releases: TypeScript 7 Ships With Go-Based Compiler and Big Build Gains

Tooling: Vercel Labs' scriptc compiles TypeScript straight to native binaries

Reads: GitHub Opens Public Preview of Stacked Pull Requests

Releases: VS Code 1.131 Adds Built-In Dictation and Deeper Subagent Insights

Security: Node.js 22.23.2 security release patches ten CVEs

Security: Critical TeamCity flaw lets attackers bypass authentication and run commands

Tooling: Vercel Labs unveils scriptc, a TypeScript-to-native compiler with no JS engine in the binary

The Editorial: Judgment Was Always the Bottleneck. AI Just Made It Visible

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy