freenode

← digests

LLVM merge outages, Python None PEPs, Go and Bun HTTP/2 CVEs

Languages & Toolchains2026-10-08

LLVM hit project-wide GitHub merge failures while Python debated a pair of None-related operator PEPs and Go disclosed an HTTP/2 content-length smuggling risk. Security fixes, hash-migration RFCs, and build-cache proposals rounded out the day across major toolchains.

LLVM reports persistent GitHub PR merge failures

LLVM engineers describe a project-wide problem in which merging pull requests through the GitHub UI fails after roughly ten-second timeouts. Contributors are sharing REST and script-based workarounds while GitHub investigates. The outage disrupts routine review and landing workflows across LLVM and related projects.

PEP 823 proposes None-aware access operators

PEP 823 introduces None-aware ?. and ?[] operators for Python and has drawn a large technical thread with Guido van Rossum participating. Discussion centers on operator design and how None should propagate through chained expressions. Language users and library authors should watch whether the syntax is accepted and in what exact form.

Go HTTP/2 transport accepts multiple Content-Length headers

Go's net/http HTTP/2 transport accepts multiple conflicting Content-Length headers, creating a response-smuggling path when reverse proxies forward responses to HTTP/1 clients. The flaw is tracked as CVE-2026-78660. Deployments that terminate HTTP/2 in Go and then speak HTTP/1 downstream need to assess exposure and apply the fix.

Git RFC adds optional SHA-256 tree digests to signed commits

An RFC patch series proposes optionally embedding a SHA-256 digest of the tree inside signed commits and tags as an alternative to Git 3.0's default hash transition. The thread turned heated over migration readiness and whether an optional digest is enough. Distributors and security-sensitive users evaluating hash plans now have a concrete counter-proposal to weigh.

LLVM RFC would forbid AI-generated communication

An LLVM RFC proposes banning AI-generated text from pull-request and RFC descriptions to reduce low-quality verbose submissions and keep clear contributor ownership. Participants debate enforcement practicality and where assistance ends and substitution begins. Other large projects facing AI-generated review noise may find the framing relevant.

Bun missing Node http2 originSet size limit

A Bun report notes that its http2 client still lacks the maxOriginSetSize cap added in Node.js 26.4.0, allowing the originSet to grow without bound under CVE-2026-48619. The gap leaves a memory-growth exposure that upstream Node has already closed. Bun HTTP/2 client users should track a corresponding fix.

PEP 824 adds None-coalescing operators

PEP 824, sponsored by Guido van Rossum, proposes ?? and ??= None-coalescing operators and is under active discussion independently of PEP 823. Debate focuses on readability and whether the two PEPs should stay separate. Together the proposals would change everyday None handling if both advance.

SwiftPM compilation caching enters evolution review

SE-0547 has opened Swift evolution review to add compilation caching support to SwiftPM. The feature reuses prior compilation artifacts to shorten incremental builds. Package authors and CI operators stand to gain faster feedback loops if the proposal is accepted.