Vercel
TWO CRITICAL SECURITY PATCHES LAND IN WORKFLOW AND EVE OVERNIGHT
Next 16.2.11 and PostCSS 8.5.12 patches ship across workflow to seal CVE vulnerabilities, while Eve locks down workflow failure visibility.
read --wire →
$ tail -f topics/javascript.log
Daily updates from the JavaScript and TypeScript world - Node.js, React, Vue, Next.js, Vercel, and the platform layers built on them.
41 updates across 6 projects this week.
One calm review of what shipped across JavaScript - the commits, releases, and security advisories that matter. Every Monday, with security advisories same-day. Free, unsubscribe in one click.
We'll start you on the top JavaScript projects - refine anytime. · Read a sample issue →
Vercel
Next 16.2.11 and PostCSS 8.5.12 patches ship across workflow to seal CVE vulnerabilities, while Eve locks down workflow failure visibility.
read --wire →
Meta
React's Turbopack integration now supports an experimental array format that lets you dynamically merge or unmerge chunks based on what's already loaded in the browser.
read --wire →
Supabase
Supabase shipped a critical fix that prevents ClickHouse from destroying newer columns during CDC replay restarts, then propagated the same safety logic across Pulumi and Terraform tooling.
read --wire →
Node.js
Antoine du Hamel landed two critical cleanups in core this cycle, removing deprecated function calls and custom DOM polyfills while the FFI layer gets a precision fix that restores uint8 semantics.
read --wire →
Vue.js
Vue core pushes toward 3.6 stable while the tooling ecosystem upgrades its type foundation.
read --wire →
Vercel
Workflow shipped its most ambitious beta yet with experimental token retention, while the AI SDK shipped five critical fixes across Gemini, Bedrock, and dynamic tool validation in a single push.
read --wire →
Meta
React shipped performance wins across 19.0.8 and 19.1.9 while React Native patched a critical timeout bug that broke requestIdleCallback tasks.
read --wire →
Supabase
Supabase Pipelines moves out of private alpha with full schema change support, while the realtime stack hardens against clustering edge cases.
read --wire →
Node.js
Node's crypto layer just got faster and safer, while undici plugged a CRLF injection hole that only matters if your app trusts untrusted function objects as headers.
read --wire →
Vue.js
Vue's scaffolding tool flipped the switch on TypeScript adoption, making strict typing the path of least resistance for new projects.
read --wire →
Vercel
Five security advisories dropped across Next.js in the last 24 hours, ranging from origin validation on internal redirects to fetch cache key collisions that could leak cached responses between requests.
read --wire →
Shopify
Shopify CLI just implemented a seven-day cooldown on npm dependency updates, blocking Dependabot from proposing fresh packages before the ecosystem has time to validate them.
read --wire →
Meta
React shipped a critical fix for useSyncExternalStore mutations being missed when subtrees toggle visibility, while React-Native plugged an Android keyboard that won't close on unmount.
read --wire →
Supabase
Supabase shipped a coordinated push across Studio UI polish, accessibility compliance, and Realtime observability tooling overnight.
read --wire →
Node.js
A circular symlink crash in recursive directory traversal just got patched, and permission audit mode finally stops throwing errors when it should only warn.
read --wire →
Vue.js
Create-vue and its templates ship v3.23.0 in sync, while VitePress now logs Vite version on startup to cut troubleshooting friction.
read --wire →
Vercel
The hook.resume() breakdown that tanked workflow@5.0.0-beta.26 has regression coverage in place [ref:1], and your performance dashboards just got a major readability upgrade [ref:2].
read --wire →
Meta
React's server renderer now supports nested View Transition animations during Suspense reveals, closing a gap that forced SSR apps to choose between progressive enhancement and smooth animations.
read --wire →
Supabase
ClickHouse is now a first-class replication destination in Studio, gated behind a private alpha flag and built with client-side validation that blocks insecure and internal URLs.
read --wire →
Node.js
Node's garbage collector was holding onto timer references it shouldn't have, and a critical FFI vulnerability let native functions receive different signatures than JavaScript thought it was passing.
read --wire →