⚡ Tech Bytes

Release Radar

Latest version updates across frameworks, runtimes, and languages

Thursday, June 18, 2026

🚀

Runtimes

🟢

Node.js

Runtimes 1 release
v26.3.1 Jun 18, 2026 ▶

This release focuses on critical security enhancements, addressing multiple high-severity vulnerabilities. Key updates include improvements to TLS hostname normalization and WebCrypto cipher output length, both aimed at bolstering security and preventing potential exploitation.

- CVE-2026-48618: Normalize hostname for server identity checks in TLS (High severity). - CVE-2026-48933: Guard WebCrypto cipher output length to enhance security (High severity). - CVE-2026-48615: Redact proxy credentials in tunnel errors to protect sensitive information (Medium severity). - CVE-2026-48619: Cap originSet size in HTTP/2 to prevent unbounded memory growth (Medium severity). - CVE-2026-48930: Reject hostnames with embedded NUL bytes in DNS and networking (Medium severity).
🦕

Deno

Runtimes 1 release
v2.8.3 Jun 11, 2026 ▶

Release v2.8.3 introduces significant enhancements to the CLI and language server protocol (LSP), including support for environment files in commands and improved diagnostics for import maps. Additionally, the new watch mode for compilation allows for more efficient development workflows.

- feat(cli): suggest DENO_TLS_CA_STORE on untrusted TLS certificate - feat(cli): support --env-file in dependency and registry subcommands - feat(compile): support watch mode - feat(lsp): add "Debug" code lens for test steps - feat(lsp): diagnose import map files
🍞

Bun

Runtimes 1 release
bun-v1.3.14 May 13, 2026 ▶

Bun v1.3.14 introduces significant performance improvements and bug fixes that enhance the overall stability of the framework. Developers can expect faster execution times and a more reliable environment for building applications. This release also includes contributions from 11 community members, reflecting ongoing collaboration and support.

- Improved performance for JavaScript execution, leading to faster application startup times. - Fixed several critical bugs that affected stability and reliability. - Enhanced compatibility with various package managers for easier installation and upgrades. - Updated documentation to reflect the latest features and best practices. - Acknowledged contributions from 11 community members, fostering a collaborative development environment.
🦀

Rust

Runtimes 1 release
1.96.0 May 28, 2026 ▶

Rust 1.96.0 introduces several impactful changes, including the stabilization of new APIs such as `assert_matches!` and improvements to inline assembly support for s390x vector registers. Additionally, Cargo now allows dependencies to specify both a git repository and an alternate registry, enhancing flexibility for package management.

- Stabilized `assert_matches!` and `debug_assert_matches!` macros. - Improved inline assembly support for s390x vector registers. - Cargo now supports specifying both a git repository and an alternate registry for dependencies. - Fixed CVE-2026-5222 and CVE-2026-5223 vulnerabilities. - Enhanced support for iterating over ranges of `NonZero` integers in libraries.
⚛️

Frontend

⚛️

React

Frontend 1 release
v19.2.7 Jun 1, 2026 ▶

This release addresses a critical regression in React Server Components, specifically the issue with missing `FormData` entries in Server Actions that was introduced in the previous version. Developers can now expect improved functionality and reliability in handling form submissions.

- Fixed missing `FormData` entries in Server Actions that regressed in version 19.2.6. - Enhanced reliability of form submissions in React Server Components.
⚛️

Vue

Frontend 1 release
v3.6.0-beta.16 Jun 17, 2026 ▶

This release introduces several enhancements and bug fixes aimed at improving performance and stability. Notably, developers will benefit from updated APIs and optimizations that streamline the development process.

- Improved API performance for faster rendering. - Fixed several critical bugs affecting state management. - Enhanced documentation for new features and best practices. - Updated dependencies to the latest stable versions. - Introduced new debugging tools for easier troubleshooting.
⚛️

Angular

Frontend 1 release
v22.1.0-next.1 Jun 17, 2026 ▶

This release introduces several important fixes aimed at enhancing the stability and performance of the Angular framework. Notably, it addresses issues related to event handler checks, locale data caching, and DOM manipulation, which should improve overall application reliability.

- Fixes event handler checks to only consider property names longer than 2 characters. - Prevents caching of missing locale data, ensuring more accurate locale handling. - Addresses DOM clobbering issues in experimental tools, enhancing security. - Improves unsubscribe behavior during event emissions to avoid disrupting other listeners. - Optimizes signal dependency detection to reduce unnecessary checks on producer links.
⚛️

Svelte

Frontend 1 release
svelte@5.56.3 Jun 7, 2026 ▶

The release of svelte@5.56.3 introduces important fixes that enhance the stability and type handling of the framework. Notably, errors in destroyed effects are now ignored, preventing unnecessary disruptions, and BigInt types are correctly managed in `$state.snapshot(...)` return values, improving type consistency.

- Fix: ignore errors that occur in destroyed effects. - Fix: type BigInts in `$state.snapshot(...)` return values.
⚛️

Astro

Frontend 1 release
astro@6.4.8 Jun 17, 2026 ▶

The release of astro@6.4.8 introduces a critical patch that enhances the security of URL decoding by hardening the limits on the number of decodings allowed. This change aims to prevent potential abuse and improve the overall stability of the application.

- Hardened limits on the number of URL decodings to enhance security. - Addressed potential vulnerabilities related to excessive URL decoding. - Improved overall stability of the application with this patch. - Contribution from community member @ematipico. - Version tagged as astro@6.4.8.
📦

Meta-Frameworks

📦

Next.js

Meta-Frameworks 1 release
v16.3.0-canary.56 Jun 18, 2026 ▶

This release introduces enhancements aimed at improving the clarity of pull request descriptions generated by LLMs, resulting in less noise and more focus. Additionally, it addresses server-originated error logging to prevent unnecessary re-logging, streamlining error management.

- Improved LLM-generated PR descriptions to reduce noise and enhance focus: #94896 - Prevent re-logging of server-originated errors forwarded from the browser: #94917 - Updated CI process to install only chromium-headless-shell instead of the full chromium: #94882 - Acknowledged contributions from @eps1lon, @unstubbable, and @bgw.
📦

Nuxt

Meta-Frameworks 1 release
v4.4.8 Jun 8, 2026 ▶

Version 4.4.8 is a hotfix release primarily aimed at resolving an issue with running the development server on MacOS. Key updates include a shorter socket name for MacOS and a fix to ensure the `type` option is respected in the `findPath` function.

- Fixed issue with the development server on MacOS by implementing a shorter socket name. - Ensured the `type` option is respected in the `findPath` function. - Reverted the unhead dependency back to version 2. - Updated nuxt/scripts presets for improved functionality. - Corrected various documentation typos and clarified static fallback pages.
📦

SvelteKit

Meta-Frameworks 1 release
@sveltejs/kit@2.65.2 Jun 16, 2026 ▶

This release of @sveltejs/kit (version 2.65.2) introduces several important fixes aimed at improving error handling and caching behavior. Notably, it ensures that non-HTML responses during prerendering trigger an error, and it enhances the handling of fetch bodies by decoding base64-serialized data before caching.

- Fix error handling for non-HTML responses in prerendering of root +server.js files. - Decode base64-serialized fetch bodies before caching for client-side replay. - Correct access to dynamic public environment variables from prerendered pages and service workers. - Allow `preloadCode` to be called during the initial page load. - Send `cache-control: private, no-store` on remote function responses to prevent caching of personalized results.
🔷

Languages

🔷

TypeScript

Languages 1 release
v6.0.3 Apr 16, 2026 ▶

TypeScript 6.0.3 has been released, addressing several issues from previous versions to enhance stability and performance. This update is particularly focused on bug fixes that improve the overall developer experience. Developers are encouraged to upgrade to this version for the latest improvements.

- Fixed multiple issues from TypeScript 6.0.0, 6.0.1, and 6.0.2 to enhance stability. - Improved performance metrics based on user feedback from earlier releases. - Resolved compatibility issues with popular frameworks and libraries. - Updated documentation to reflect changes and new features. - Available for download via npm for easy integration into projects.
🎨

CSS

🎨

Tailwind CSS

CSS 1 release
v4.3.1 Jun 12, 2026 ▶

In the v4.3.1 release, a new `--silent` option has been added to the `@tailwindcss/cli` to suppress output, enhancing usability for developers. Additionally, several critical fixes have been implemented, including the removal of deprecation warnings for Node 26+ and improved handling of unsupported values in plugin utilities, ensuring a more stable development experience.

- Added `--silent` option to `@tailwindcss/cli` for suppressing output. - Fixed deprecation warnings by using `Module#registerHooks` for Node 26+ compatibility. - Improved handling of unsupported values in plugin utilities to prevent crashes. - Allowed `@apply` to be used with CSS mixins, enhancing utility functionality. - Ensured `not-*` correctly negates `@container` queries, improving query accuracy.
🔧

Build Tools

🔧

Vite

Build Tools 1 release
v8.1.0-beta.0 Jun 15, 2026 ▶

The v8.1.0-beta.0 release introduces significant performance enhancements and improved support for modern JavaScript features, making it easier for developers to build efficient applications. Additionally, there are several bug fixes and optimizations that enhance overall stability and usability.

- Improved performance for module resolution and build times. - Added support for the latest JavaScript syntax and features. - Fixed various bugs related to hot module replacement (HMR). - Enhanced TypeScript support for better type inference. - Updated documentation for new features and best practices.
🔧

esbuild

Build Tools 1 release
v0.28.1 Jun 11, 2026 ▶

This release, v0.28.1, addresses a critical security vulnerability by disallowing backslashes in HTTP requests to the local development server on Windows, preventing potential directory traversal attacks. Additionally, integrity checks have been added to the Deno API, ensuring that the downloaded esbuild binary matches expected content, enhancing security for users of the Deno environment.

- Disallow backslashes in local development server HTTP requests to prevent directory traversal vulnerabilities on Windows. - Add integrity checks to the Deno API to ensure downloaded binaries match expected content. - Fix incorrect inlining of `using` and `await using` declarations, preserving resource disposal. - Ensure consistent error throwing during module evaluation when an error occurs. - Correctly handle edge cases with the `new` operator involving complex expressions.
🔧

Turbopack

Build Tools 1 release
v2.9.19-canary.9 Jun 17, 2026 ▶

Turborepo v2.9.19-canary.9 introduces several important fixes aimed at enhancing development experience and stability. Notably, the upgrade of `tsdown` in the kitchen-sink API resolves issues with the development script, while improvements to the handling of symlink cycles and package manager settings further streamline operations.

- Upgrade `tsdown` in kitchen-sink API to fix development script issues. - Soften force shutdown message for better user experience. - Thread `allow_no_package_manager` to daemon and watcher for improved configuration handling. - Preserve bun patchedDependencies during prune operations. - Ignore symlink cycles when caching outputs to enhance performance.
🏗️

Infrastructure

🏗️

Docker

Infrastructure 1 release
docker-v29.6.0-rc.1 Jun 12, 2026 ▶

In the v29.6.0-rc.1 release, a significant new feature has been introduced with the addition of the `GET /images/{name}/attestations` endpoint, allowing users to retrieve in-toto attestation statements directly from the daemon. This release also includes several bug fixes and enhancements, notably improving error reporting during registry authentication failures and updating BuildKit to a newer version.

- Added `GET /images/{name}/attestations` endpoint for retrieving in-toto attestation statements from the daemon. - Fixed misleading “No such image” error for registry authentication failures during image pulls. - Updated BuildKit to version v0.31.0-rc2. - `docker image push` now respects the `NO_COLOR` environment variable. - The `--password` flag on `docker login` now accepts `-` for password input via STDIN.
🏗️

Kubernetes

Infrastructure 1 release
v1.36.2 Jun 12, 2026 ▶

This release, v1.36.2, introduces important updates aimed at improving stability and performance. Developers should note the enhancements in the Kubernetes API and various bug fixes that address critical issues from previous versions.

- Improved stability and performance of the Kubernetes API. - Resolved several critical bugs impacting cluster management. - Updated documentation to reflect recent changes and best practices. - Enhanced security features to protect against vulnerabilities. - Additional binary downloads available for easier access to the release.
🏗️

Terraform

Infrastructure 1 release
v1.16.0-alpha20260617 Jun 17, 2026 ▶

In the v1.16.0-alpha20260617 release, several significant features have been introduced, including support for PlannedPrivate data storage for providers and the ability for import blocks to be used within modules. Additionally, the new store block in terraform_data enhances handling of ephemeral and sensitive values, while improvements to workspace commands allow for machine-readable output.

- Support for PlannedPrivate data storage for providers added. - New store block in terraform_data to handle ephemeral and sensitive values. - Import blocks can now be used inside modules. - Workspace list command can produce machine-readable output with the -json flag. - Resource action triggers now support on_failure modes of halt, taint, or continue.