
TypeScript.fm - The Friendly Show for TypeScript Developers Anthropic's Bet on Bun, React2Shell, Vite 8 Beta, and Elves Spam npm | News | Ep 47
11 snips
Dec 9, 2025 Exciting updates include Anthropic's acquisition of the Bun JavaScript runtime and the critical vulnerabilities discovered in React2Shell that led to a Cloudflare outage. The discussion also sheds light on the Vite 8 Beta featuring faster development tools, and a surge of 'elf spam' npm packages to avoid. Listeners will learn about new features in Node.js, like project-relative imports, and updates on type-aware linting with Oxlint. Plus, insights on security best practices and must-read architecture books make it a packed session!
AI Snips
Chapters
Books
Transcript
Episode notes
Vite 8 Embraces Rolldown
- Vite 8 beta moves to Rolldown, a Rust rewrite of Rollup that unifies dev and prod bundling.
- This reduces dev/prod parity bugs and brings faster builds with new features like full bundle mode.
Prepare For Node.js Security Patch
- Prepare for a Node.js security release scheduled for December 15th and update test pipelines.
- Ensure CI, setup-node actions, and developer environments are ready to upgrade quickly.
Act Fast On React2Shell RCE
- If you use React 19 with server components, upgrade immediately to patched releases.
- Audit whether your app uses server components or bundler plugins that enable them and patch or disable accordingly.



