Node.js 22.23.2 security release patches ten CVEs
The Node.js project has published Node.js 22.23.2 (LTS 'Jod'), a security release fixing ten CVEs — three rated high — affecting HTTP/2, the permissio… ▶ D2
Independent. Nonpartisan. Untested in production.
Vercel Labs' scriptc compiles TypeScript straight to native binaries ▶ D2
GitHub Opens Public Preview of Stacked Pull Requests ▶ D2
VS Code 1.131 Adds Built-In Dictation and Deeper Subagent Insights ▶ D2
TypeScript 7, released July 8, 2026, replaces the compiler with a Go-based implementation and delivers real build speed gains.
MEDIUM · SOFTWARE ENGINEERING — The piece warns that the upgrade path comes with three common breaking issues most teams will encounter during migration.
curated by Sönke
The Node.js project has published Node.js 22.23.2 (LTS 'Jod'), a security release fixing ten CVEs — three rated high — affecting HTTP/2, the permissio… ▶ D2
JetBrains has patched CVE-2026-63077, a critical 9.8 CVSS vulnerability in TeamCity's agent polling protocol affecting all on-premises versions. Attac… ▶ D3
Vercel Labs has published scriptc, an open-source compiler that turns ordinary TypeScript into small native executables without embedding Node, V8 or … ▶ D4
Claude Code, Cursor, Codex and the newly open-sourced Grok Build all write software fast now. A July preprint testing 86 Python developers found we're bad at catching the… ▶ D4
Security: Decade-Old Linux Kernel Code Turns Into Instant Root Exploit
Security: CrowdStrike Finds Self-Hiding Worm Targeting AI Coding Toolchains
Reads: The Case Against Storing Secrets in Environment Variables
Reads: SQLite's Confusing Defaults Spark Debate Over Rust-Style 'Editions'
Reads: Reddit Reacts to Unpatched Cursor IDE 0-Day That Runs Any Renamed Executable as Git
Reads: Engineering Deep Dive: Scaling a Notification System to Millions of Fanouts
Reads: Building encrypted secret sharing in the browser with the Web Crypto API
Reads: Cloudflare Identifies Race Condition in hyper's HTTP/1 Implementation
Reads: GhostLock: A 15-Year-Old Stack Use-After-Free Vulnerability in Linux
Reads: Here are all my chairs
News: CNIL Mandates Consent for Email Tracking Pixels
Reads: Announcing TypeScript 7.0
Reads: Postgres Is Enough for More Than We Admit
Reads: How to Achieve Pruning When Querying by Non-Partitioned Columns in PostgreSQL
News: China recovers its first reusable rocket using a sea-based net
Reads: Self-hosting Umami analytics on Cloudflare, Fly, and Supabase
News: Won’t fix! – Teil 4: Warum sich Codequalität nicht in eine Zahl pressen lässt
News: Flock License Plate Readers Escalate Over Data-Entry Typo
News: Apple sues OpenAI over alleged trade secret theft
Tooling: Vite+ reaches beta with 180+ fixes
Security: Ransomware Negotiator Sentenced for Colluding with BlackCat Attackers
News: Microsoft formalizes heavy use of AI for vulnerability discovery
All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy