The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Wednesday, September 30, 2026 Vol. I — No. 679 · Page D3 € 0,00*  *as always

Node.js v26.6.0 and v24.19.0 (LTS Krypton) released ▶ D2

QUERY Is the Easy Part. The Plumbing Is Where It Gets Decided ▶ D2

TypeScript 7 Ships With Go-Based Compiler and Big Build Gains ▶ D2

Reads!
Extra!read all about it

Worm Compromises npm's keyv Package and Eight Other Organisations

A worm spread an identical credential stealer through nine unrelated npm organisations within roughly 30 minutes, hitting keyv and cacheable packages among others.

R/PROGRAMMING (TOP) — Affected packages include authentication libraries, and a dead-man switch fires when stolen GitHub tokens are revoked, making credential rotation risky without prior cleanup.

▶ continued: summary & source

curated by Sönke

Node.js 22.23.2 security release patches ten CVEs

The Node.js project has published Node.js 22.23.2 (LTS 'Jod'), a security release fixing ten CVEs — three rated high — affecting HTTP/2, the permission model, HTTPS, DNS … ▶ D4

Security: Critical TeamCity flaw lets attackers bypass authentication and run commands

Tooling: Vercel Labs unveils scriptc, a TypeScript-to-native compiler with no JS engine in the binary

The Editorial: Judgment Was Always the Bottleneck. AI Just Made It Visible

Security: Decade-Old Linux Kernel Code Turns Into Instant Root Exploit

Security: CrowdStrike Finds Self-Hiding Worm Targeting AI Coding Toolchains

Reads: The Case Against Storing Secrets in Environment Variables

Reads: SQLite's Confusing Defaults Spark Debate Over Rust-Style 'Editions'

Reads: Reddit Reacts to Unpatched Cursor IDE 0-Day That Runs Any Renamed Executable as Git

Reads: Engineering Deep Dive: Scaling a Notification System to Millions of Fanouts

Reads: Building encrypted secret sharing in the browser with the Web Crypto API

Reads: Cloudflare Identifies Race Condition in hyper's HTTP/1 Implementation

Reads: GhostLock: A 15-Year-Old Stack Use-After-Free Vulnerability in Linux

Reads: Here are all my chairs

News: CNIL Mandates Consent for Email Tracking Pixels

Reads: Announcing TypeScript 7.0

Reads: Postgres Is Enough for More Than We Admit

Reads: How to Achieve Pruning When Querying by Non-Partitioned Columns in PostgreSQL

News: China recovers its first reusable rocket using a sea-based net

Reads: Self-hosting Umami analytics on Cloudflare, Fly, and Supabase

News: Won’t fix! – Teil 4: Warum sich Codequalität nicht in eine Zahl pressen lässt

News: Flock License Plate Readers Escalate Over Data-Entry Typo

News: Apple sues OpenAI over alleged trade secret theft

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy