← Home
The Changelog · April 29, 2026 · 8m 33s

Bitwarden CLI compromised (News)

This week's news roundup covers five major stories: the Checkmarx supply‑chain campaign hitting Bitwarden’s CLI, TypeScript 7.0 beta landing with a Go‑rewritten compiler that’s 10x faster, Ubuntu 26.04 LTS shipping with TPM‑backed full‑disk encryption, pgBackRest losing its maintainer of thirteen years, and Matz releasing the Spinel AOT compiler for Ruby native binaries. The episode highlights how security, performance, and open‑source maintenance are deeply intertwined and all in motion at once.

This summary was generated from show notes and public descriptions, not from a full transcript review. Details may contain inaccuracies.

Highlights

Bitwarden CLI Targeted by Checkmarx Supply‑Chain Campaign
Bitwarden’s command‑line tool was compromised as part of the Checkmarx supply‑chain campaign.
TypeScript 7.0 Beta Ships a Go‑Rewritten Compiler
The TypeScript 7.0 beta includes a compiler rewritten in Go that runs about 10x faster than the 6.0 version.
pgBackRest Loses Its 13‑Year Maintainer
The widely used PostgreSQL backup tool pgBackRest lost its sole maintainer after thirteen years.
Ubuntu 26.04 LTS Adds TPM‑Backed Full‑Disk Encryption
Ubuntu 26.04 LTS ships with TPM‑backed full‑disk encryption enabled by default.
Ruby’s Spinel AOT Compiler Targets Native Binaries
Matz introduced Spinel, an ahead‑of‑time compiler that turns Ruby code into standalone native binaries.

Editorial

The Interwoven Nature of Security, Performance, and Maintenance
The week’s news shows that security incidents, performance breakthroughs, and maintenance gaps are not isolated threads but overlapping forces shaping the tools we use.

Misc

TypeScript 7.0’s new Go‑written compiler runs roughly 10x faster than version 6.0.
pgBackRest, a critical PostgreSQL backup tool, lost its sole maintainer of 13 years – a stark reminder of the bus‑factor problem in open‑source infrastructure.
Ubuntu 26.04 LTS introduces TPM‑backed full‑disk encryption out of the box, tying encryption keys directly to the hardware.
Was this useful?