Vercel
TURBOPACK TELEMETRY NOW SHIPPING, NODE LAMBDA STREAMING BUG SEALED
Vercel's build system fixed a silent streaming flip that could break custom AWS handlers, while Turbopack finally starts reporting what it's actually building.
read --wire →
$ tail -f topics/javascript.log
Daily updates from the JavaScript and TypeScript world - Node.js, React, Vue, Next.js, Vercel, and the platform layers built on them.
41 updates across 6 projects this week.
One calm review of what shipped across JavaScript - the commits, releases, and security advisories that matter. Every Monday, with security advisories same-day. Free, unsubscribe in one click.
We'll start you on the top JavaScript projects - refine anytime. · Read a sample issue →
Vercel
Vercel's build system fixed a silent streaming flip that could break custom AWS handlers, while Turbopack finally starts reporting what it's actually building.
read --wire →
Meta
Jest's e2e test directories got a routine Babel plugin update — not urgent, but worth noting if you're running the latest from main.
read --wire →
Node.js
James Snell landed cleanup commits across QUIC internals as the team tightens the codebase, while undici patches a sneaky MockAgent bug that corrupts multipart form boundaries.
read --wire →
Vue.js
Vue's language server just picked up an upstream fix that improves developer experience across the entire tooling ecosystem.
read --wire →
Vercel
Vercel/Chat pulled the Slack direct WebClient access feature after discovering it silently dropped custom API URLs, while Next.js canary lands 41-second CI wins across test workflows.
read --wire →
Shopify
Shopify CLI's process killer contains a command injection vulnerability on Windows that lets attackers execute arbitrary commands through a malicious PID string.
read --wire →
Meta
Jest shipped three critical fixes for CommonJS-to-ESM module interop that align behavior with Node.js, while React Native re-enabled a flaky VirtualizedList test and fixed out-of-order events on Android Fabric.
read --wire →
Supabase
createClient crashed in restricted-storage environments (sandboxed iframes, in-app webviews, privacy modes) due to unsafe sessionStorage access in the realtime layer [ref:8].
read --wire →
Node.js
Node is locking down its cryptographic guts while simultaneously overhauling how streams handle iterables — two foundational changes shipping together that affect everything downstream.
read --wire →
Vue.js
Both Router and Pinia are consolidating their release tooling around @clack/prompts, dropping a sprawl of legacy dependencies in the process.
read --wire →
Vercel
Meta Messenger is now a first-class chat platform with full webhook support and message caching [ref:1], while a critical workflow regression that broke deployments on cold starts is resolved [ref:6].
read --wire →
Shopify
Shopify/cli shipped a critical security fix for stdin memory exhaustion and eliminated false-positive breaking change detection that was blocking legitimate PRs.
read --wire →
Meta
React's Fiber engine now correctly tracks explicitly preloaded stylesheets, eliminating unnecessary commit suspensions that plagued stylesheet-heavy apps, while Jest's massive 30.4 release stabilizes ESM support and adds Temporal API mocking for Node 26.
read --wire →
Supabase
Supabase's ETL engine plugged a critical coordination bug that could corrupt table ownership when workers restart mid-sync.
read --wire →
Node.js
Node.js v26.1.0 is live, and the release documentation is already published to the main site.
read --wire →
Vue.js
Vue DevTools locked down Trusted Types CSP injection while expanding to support Vapor apps in the latest release.
read --wire →
Vercel
Next.js just halved JsValue's footprint across millions of analyzer instances, the AI SDK now threads context through multi-step workflows, and Turborepo is enforcing hard filesystem boundaries on cached outputs.
read --wire →
Shopify
Long URLs embedded in CLI error messages now parse correctly with opt-in CommonMark link rendering, fixing the broken output that split URLs across terminal borders.
read --wire →
Meta
React shipped type hardening and performance improvements to Server Functions across 19.0.6, 19.1.7, and 19.2.6, closing security vulnerabilities in FlightReply.
read --wire →
Supabase
The platform ditched an archived MDX library and bumped vulnerable dependencies to unblock React 19 adoption across the entire dashboard.
read --wire →