Bun security, Swift once-calls, CSV.jl 1.0
Security work on Bun archive extraction led the day, alongside a major CSV.jl release and design pitches spanning Swift, Haskell builds, Python stdlib boundaries, Git worktrees, and glibc process debates.
Bun hardens archive extract against symlink traversal
A pull request in oven-sh/bun hardens Bun.Archive.extract so extracted entries do not follow symlinks that would write outside the destination directory. The change closes a path-traversal class of issue in archive handling. Tooling authors who unpack untrusted archives should treat the fix as relevant to sandboxing and install safety.
Swift pitch for at-most-once function annotation
A Swift Evolution pitch on forums.swift.org proposes a @called(once) attribute to mark functions that execute at most once. Discussion covers modeling with non-escaping closures and dependency injection. The attribute would give the type system and optimizers a clearer contract for one-shot callbacks and initialization paths.
CSV.jl reaches 1.0 with parser rewrite
CSV.jl 1.0 was announced on discourse.julialang.org with a SIMD parser rewrite, parallel indexing, a lazy reader, and DataString storage. The release targets large speedups for common tabular workloads. Julia data pipeline maintainers gain a stable major version and faster ingest options.
Buck2 integration experimented for Cabal projects
Simon Marlow shared an experiment wiring the Buck2 build system into Cabal projects on discourse.haskell.org. Thread participants weighed build performance, modularity, and paths to upstreaming. Haskell developers tracking alternate build graphs may find the comparison useful against Cabal-centric workflows.
Glibc dispute over CTI infrastructure transition
Meeting minutes from Office Hours for CTI sparked heated argument on libc-alpha about whether Linux Foundation and CTI infrastructure moves had libc-alpha consensus. Developers contested the legitimacy of the decision process. Readers who track glibc governance should note the split over process and authority.
Python explores stdlib boundary enforcement after PEP 842
A postmortem thread on discuss.python.org asks how to protect the standard library after PEP 842. Ideas include documentation-driven linters and hub-module patterns that keep public APIs within intended boundaries. Stdlib maintainers and linter authors gain concrete directions for reducing accidental surface growth.
Git proposes post-worktree lifecycle hooks
A patch series on the Git mailing list adds post-worktree-add, post-worktree-remove, and related hooks so tooling can react when worktrees appear or disappear. The hooks would let scripts and IDEs track worktree lifecycle without polling. Teams that automate multi-worktree setups are the primary audience.
Glibc proposal to require known-key GPG commit signatures
A libc-alpha thread proposes requiring GPG commit signatures from known keys on glibc pushes, with debate on key management, developer workflow, and alternatives such as SSH signing or gittuf. The goal is stronger provenance on the mainline history. Contributors and distributors concerned with supply-chain integrity should follow the outcome.