TypeScript.fm - The Friendly Show for TypeScript Developers

Anthropic's Bet on Bun, React2Shell, Vite 8 Beta, and Elves Spam npm | News | Ep 47

11 snips
Dec 9, 2025
Exciting updates include Anthropic's acquisition of the Bun JavaScript runtime and the critical vulnerabilities discovered in React2Shell that led to a Cloudflare outage. The discussion also sheds light on the Vite 8 Beta featuring faster development tools, and a surge of 'elf spam' npm packages to avoid. Listeners will learn about new features in Node.js, like project-relative imports, and updates on type-aware linting with Oxlint. Plus, insights on security best practices and must-read architecture books make it a packed session!
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Vite 8 Embraces Rolldown

  • Vite 8 beta moves to Rolldown, a Rust rewrite of Rollup that unifies dev and prod bundling.
  • This reduces dev/prod parity bugs and brings faster builds with new features like full bundle mode.
ADVICE

Prepare For Node.js Security Patch

  • Prepare for a Node.js security release scheduled for December 15th and update test pipelines.
  • Ensure CI, setup-node actions, and developer environments are ready to upgrade quickly.
ADVICE

Act Fast On React2Shell RCE

  • If you use React 19 with server components, upgrade immediately to patched releases.
  • Audit whether your app uses server components or bundler plugins that enable them and patch or disable accordingly.
Get the Snipd Podcast app to discover more snips from this episode
Get the app