When an AI Company Buys the Runtime, Governance Stops Being Boring
Anthropic bought Bun because Claude Code ships on it, and the deal will probably make Bun better. Kai argues the real lesson sits elsewhere: single-ve… ▶ D2
Independent. Nonpartisan. Untested in production.
Chrome 153 ships with two-week release cycle and 230 security fixes ▶ D2
Microsoft fixes record 972 vulnerabilities in September, 112 rated cri… ▶ D2
Node.js 26.8.2 (Current), released 9 September 2026 by Antoine du Hamel, updates Undici to 8.10.2, OpenSSL to 3.5.8, npm to 11.19.1 and corepack to 0.36.0.
NODE.JS RELEASES (DIST) — The release also deprecates the internal Server.prototype._listen2 API in node:net and refines the security posture for experimental features.
curated by Sönke
Anthropic bought Bun because Claude Code ships on it, and the deal will probably make Bun better. Kai argues the real lesson sits elsewhere: single-ve… ▶ D2
CVE-2026-85046, a V8 type confusion bug exploited in the wild, is being filed under 'browser news'. Wrong drawer. If your PHP app renders PDFs with Br… ▶ D3
CVE-2026-85046, a type confusion bug in Chrome's V8 engine, is being exploited in the wild via a single crafted HTML page. Google patched it in Chrome… ▶ D4
Zod 4.5 introduces z.compile(schema), letting developers precompile validation schemas ahead of time to cut parsing overhead. The runtime validation library also slashes … ▶ D4
Security: BGP Hijack of Softaculous IPs Pushed Malicious Updates to Virtualizor Servers
Releases: pnpm 12 in Rust: Fast Start, npm Packages and No SSH
Reads: Why One Engineer Blames File-System Design for the Hugging Face Breach
The Editorial: Your CI Runner Executes Strangers' Code, So Defend It Like Production
News: How a Mismatched PostgreSQL Index Turned a 40ms Query Into 4 Seconds
Reads: Zod 4.5 ships schema compilation, but zod-compiler still leads in benchmarks
Reads: htmx 4.0.0 Released
Security: Critical Next.js flaws allow remote code execution, Windows servers affected
Reads: New paper details how mold achieves its linker speedups
Releases: Node.js 24.20.0 LTS 'Krypton' lands with AsyncLocalStorage scopes and package maps
The Editorial: SELinuxMount is the right call, and the pods it breaks were on borrowed time
Releases: Node.js 26.8.0 released
The Editorial: Go 1.27 Settles a Fight PHP Finished Years Ago: Someone Must Carry the Weight
News: GitHub blames seven-hour August 17 outage on capacity limits amid AI-driven traffic surge
Reads: Supply Chain Attack on Rust Crate Sparks Debate Over Dependency Culture
Releases: TypeScript 7.0.2 Released as Patch Update
Releases: Bun 1.4 ships with Rust rewrite, big Node.js compatibility gains
Security: Critical GitLab GraphQL flaw already under attack, watchTowr reports
Security: Critical GitLab Flaw Lets Attackers Delete Projects
Reads: What to Expect From DuckDB's Upcoming 2.0 Release
Security: PostgreSQL patches 28 security flaws, two allow code execution
All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy