In short
Weekly developer news (Apr 27, 2026): Warp becoming open source; Bitwarden CLI supply-chain compromise; TypeScript 7.0 beta; Ubuntu 26.04 LTS; plus sponsored and other tooling updates (Coder, Spinal, PG Backrest).
Guests
None mentioned as interview guests. Named individuals: Zach (Warp open-sourcing advocate), Daniel Rosenwasser (Microsoft TypeScript PM), Matt (Spinal author), David Steele (PG Backrest maintainer).
Key claims/examples
Bitwarden CLI (published maliciously on NPM) scraped GitHub tokens, AWS/Azure/GCP creds, NPM config, SSH keys, shell profiles, and cloud/MCP config via spoofed audit.checkmarks.cx; incident response, not a patch cycle. TypeScript 7.0 beta: ~10x faster vs 6.0; stable in ~2 months. Ubuntu 26.04 LTS runs to Apr 2036; Rust coreutils swap paused. Spinal compiles Ruby to native binaries; benchmarks ~11.6x faster, Conway’s Game of Life up to 86x. PG Backrest archived after 13 years; no future CVE patches—act now.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOWarp Open Source Announcement
0:45 to 1:59
Discussing the release of Warp as an open source project.
“Yes, Bitwarden's official command line tool got hit last Thursday.”
Bitwarden CLI Compromise
1:59 to 3:47
Details on the Bitwarden CLI being compromised and its implications.
“And they say stable is within the next two months.”
TypeScript 7.0 Beta Release
3:47 to 4:59
Overview of the TypeScript 7.0 beta release and its performance improvements.
“And if you're not really controlling how they get out there, that's where you get this.”
Ubuntu 26.04 LTS Release
4:59 to 6:21
Announcing the release of Ubuntu 26.04 LTS and its significance.
“Now, does this stop everything like Shai Halud?”
PG Backrest Maintenance Update
8:20 to 8:31
Update on the maintenance status of PG Backrest and its implications.
Transcript
Automatic transcript. May contain errors.0:03What's up friends, Adam here. This is changed all news for the week of April 27th, 2026. fresh off the press literally hours old at this point warp is now open source yes your favorite terminal and mine too besides ghosty of course is now open source years ago we had zach on the pod and pressured him highly suggested i should say that warp be open source and the day is finally here they are now open source the primary reason is quote that we think we can ship a better warp more quickly if we open source and work with our community. End quote. Big congrats, Zach. I'm excited. Are you excited? Okay, let's get into the news.
0:47Bitwarden CLI has been compromised. Yes, Bitwarden's official command line tool got hit last Thursday. Our friends at Socket are on the beat. They flagged a malicious CLI published to NPM as part of the same checkmarks-themed supply chain campaign that's been going through developer tooling this past few weeks. Here's what matters. The CLI is now the tool by definition that sits next to our secrets. And the compromised build was scraping GitHub tokens, AWS, Azure and GCP credentials, NPM config, SSH keys, the good stuff, right? Shell profiles and even your cloud and MCP config files out of the spoofed audit.checkmarks.cx endpoint.
1:31So if you ran Bitwarden or BW, the command on a dev machine or a CI runner in the past few weeks, this is an incident response. This is not a patch cycle. And our friends at Socket say, quote, the compromise follows the same GitHub action supply chain vector identified in the broader checkmarks campaign. End quote. So this is a strategic attack and our dev tools are in the crosshairs. TypeScript 7.0 beta. typescript 7.0 hit beta last tuesday after more than a year of porting from a javascript-based bootstrap compiler to a go rewrite the team is shipping it with one headline number about 10x faster than 6.0 the big picture this is the most ambitious thing typescript has done since the language shipped microsoft didn't add features they rewrote the core in a different language to break a performance ceiling that JavaScript bootstrap TSC was never going to clear.
2:33And they say stable is within the next two months. Daniel Rosenwasser, TypeScript program manager from Microsoft says this, quote, it is highly stable, highly compatible and ready to put to the test in your daily workflows and CI pipelines today. So you got your marching orders, use it in your workflows today, use it in your pipelines today and enjoy TypeScript 7.0. Ubuntu 26.04 LTS is here. Okay, so Resolute Raccoon shipped on Thursday. Fantastic news for our home labbers out there who are on the edge of Ubuntu. I know that's what I use in my VMs and containers, so I'm excited to finally get my templates updated to Ubuntu 26.04 up from 24.04.
3:19This is the LTS release your servers will run for the next five years. On through April 2036. So that's a long time. The most interesting call on the release isn't the kernel or the desktop. It's canonical pumping the brakes on the Rust Core Util swap. It's kind of the judgment that makes the LTS worth trusting. Plan your fleet upgrade window now. I know I am. If Rust Everywhere lands by 26.10 as targeted, this LTS is the on-ramp. and now time for some sponsored news well i'm here with nicky pike from coder.com secure environments where devs and agents work in parallel nicky the thing on my mind this week is the laptop how secure how at risk are we the laptop is the is the trap here and not only because the fact that it could be stolen you could lose it it breaks and you're out of work while you're waiting for a new one but there's also just the consistency you got there we all know developers developers are going to be looking for some of the latest and greatest.
4:17And if you're not really controlling how they get out there, that's where you get this. It works on my machine. It doesn't work on in production. It doesn't work anywhere else because you don't have that consistency. You don't have that ability to really standardize what that environment looks like. But there's also the security and the supply chain aspect of this. When you have local machines out there, look at like the Shai Halud, you know, that virus that went out not long ago. This was a compromise of the NPM public repositories. They went and downloaded things. NPM did what it did. Next thing you know, you're compromised.
4:46But when you use something like what we're doing with cloud development environments, then you can mandate and you can put restrictions on there to say, hey, you can only go get your packages from our private repo. Those packages are expected to have been thoroughly vetted. We know that they're clean. Now, does this stop everything like Shai Halud? No. If that compromised package gets into your private repo, you can still have that, But it really reduces the surface area of the attack. And it also reduces the blast area of the compromise should it happen. Because if your laptop gets compromised and you have to kill the laptop for whatever reason, that's weeks out of work while you're either fixing that or you're getting a new laptop in.
5:24The cloud development environments allows you to kill that, start back up fresh, and you're back and running in five minutes. You don't have to wait all that time. All right, friends, go to coder.com. Give your developers room to build and run parallel agents inside Secure, self-hosted environments. Again, Coder.com. Spinal compiles Ruby to native binaries. Our favorite programmer, Matt, dropped Spinal on Friday. Thank you, Matt, of course, for Ruby. It is an ahead-of-time compiler that takes Ruby's source, emits standalone C, and runs it through GCC or CLang to produce a native binary. And the benchmarks say it's about 11.6x faster and on compute-heavy workloads, Conway's Game of Life is the canonical example, and it tops 86X.
6:09And if you ask me, this changes the framing for what Ruby can be used for. The immediate obvious win is small CLIs, Lambda functions, and short-lived processes. Basically, anywhere CRuby's startup cost was a tax to you and pushed you to Go or Rust, now Ruby is an option. And here's the cool thing, Ruby on more serious infrastructure. The cleanest read of this is that Matt is signaling Ruby's future has a typed, pre-compiled lane next to his dynamic one. The crystal community has been making this case for years, but the difference is this one's coming from Matt himself. It's not a fork, it's a direction.
6:46PG backrest is no longer being maintained. After 13 years, David Steele has stepped away from PG backrest. The repository is archived. The REB leads with, quote, notice of obsolescence, end quote. The standard backup tool for production postcard deployments has lost its maintainer and won't be patched going forward. This is not a hobby crate gone dormant. PG backrest is a tool a lot of operations teams have woven into the fabric of what they do, their run books, their backup automation, their disaster recovery plans. And when the next CVE hits and this maintainer is gone, it's not getting patched.
7:25Not eventually, just not at all. The sentiment can be read directly from David Steele, Rather than do the work poorly and or sporadically, I think it makes sense to have a hard stop. David, good for you to call the ball, draw the line, and step away as you need to. So if you run PG Backrest in production, this is a this week task. Don't delay it. And who knows what's to come for PG Backrest. Next week, we may have a new headline about it. We shall see. alright friends this show's done tons of links in the newsletter check that out as well also tune in to changelog680 talking to Amelia Wattenberger exploring with agents, designer jataviz veteran, ex-githubnext and now designing intent at Augment Code once again changelog680 and again thank you to Coder for sponsoring this episode, that's it we're done we'll see you soon
8:30I'll see you next time.
From the publisher
Bitwarden's CLI got hit by the Checkmarx supply-chain campaign, TypeScript 7.0 beta lands with the Go-rewritten compiler running ~10x faster than 6.0, and pgBackRest lost its maintainer of thirteen years leaving anyone running production Postgres with a real dependency-trust task this week. We've also got Ubuntu 26.04 LTS shipping with TPM-backed full-disk encryption, and Matz dropping Spinel as an AOT path that takes Ruby to native binaries. This week was a good reminder that the tools we depend on are all moving at once. Security, performance, and maintenance aren't isolated threads.

