Newslurp

<< Stories

Visual Studio 2026 Insiders πŸ†•, Malicious NPM Package πŸ₯·, Cloudflare Feature Availability ☁️

TLDR DevOps <dan@tldrnewsletter.com>

September 29, 11:23 am

TLDR DevOps
Visual Studio 2026 Insiders introduces deeply integrated AI, making code reviews, documentation, and debugging more seamless β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ  β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ β€Œ 

TLDR

Together With The Linux Foundation

TLDR DevOps 2025-09-29

If Your Search Isn't AI-Ready, You're Already Behind (Sponsor)
  • AI-ready from day one – Built-in vector search that scales with your innovation
  • Any use case – Power RAG, semantic search, and recommendations
  • Full control – Open ML architecture, no license fees
  • Your tools, your way – Works with Faiss, Lucene & more
  • Enterprise scale – Proven open source alternative to proprietary databases

Future-proof your AI stack now with OpenSearch. Before your competition does.

πŸ“±

News & Trends

Every Cloudflare feature, available to everyone (5 minute read)

Nearly all of Cloudflare's features, previously limited to enterprise customers, will become available for purchase by anyone on any plan without contracts or sales involvement. The rollout will begin with dashboard Single Sign-On and will expand over the next year to include other advanced capabilities, reinforcing Cloudflare's mission to make powerful Internet security and performance tools accessible to all users.
Safe in the sandbox: security hardening for Cloudflare Workers (13 minute read)

Cloudflare has strengthened the security of Workers by modifying the V8 runtime to use memory protection keys and a software-based sandbox, preventing cross-isolate data access and containing memory corruption attacks. These improvements create layered defenses that block escalation attempts, ensuring user code runs safely on Cloudflare's globally distributed infrastructure without requiring customer intervention.
Visual Studio 2026 Insiders is here! (5 minute read)

Visual Studio 2026 Insiders introduces deeply integrated AI, making code reviews, documentation, and debugging more seamless while reducing developer overhead. The release also delivers major performance boosts, a modernized Fluent UI design, and a new Insiders Channel for early feature access, all aimed at keeping developers in flow and accelerating productivity.
πŸš€

Opinions & Tutorials

Code Mode: the better way to use MCP (10 minute read)

AI agents can handle more tools and more complex tools by converting Model Context Protocol (MCP) tools into a TypeScript API and having LLMs write code to call that API. This approach uses the Cloudflare Workers platform and its new Worker Loader API, which loads Worker code on-demand with a secure sandbox that prohibits internet access. It isolates access to MCP servers through bindings and prevents the AI from leaking API keys.
Priorities (3 minute read)

Focusing only on urgent tasks in software engineering leaves bugs and technical debt unresolved, eventually slowing development and frustrating users. Teams can avoid this by reserving capacity for lower-priority but important work through strategies like time allocation, dedicated ownership, or zero-tolerance policies.
What is "good taste" in software engineering? (7 minute read)

Good taste in software engineering isn't about raw skill but about choosing the right engineering valuesβ€”like readability, scalability, or resiliencyβ€”for the problem at hand. Engineers with good taste stay flexible, avoid rigid β€œbest practices,” and make tradeoffs that fit their project's context, leading to more successful outcomes over time.
πŸ§‘β€πŸ’»

Resources & Tools

AI writes code in seconds. mirrord tackles the new bottleneck: testing. (Sponsor)

AI agents can generate new code instantly, but testing it against cloud resources such as other microservices, databases, and queues still takes too long. mirrord lets AI-generated code run locally with seamless access to your live staging environment. No mocks, no waiting, just instant integration testing. Try mirrord for free
Coze Studio (GitHub Repo)

Coze Studio, an all-in-one AI agent development tool derived from the "Coze Development Platform," has been released as open source. The platform simplifies AI agent creation, debugging, and deployment with visual tools, no-code or low-code approaches, and a microservices architecture built on Golang, React, and Typescript.
Claude Code Router (GitHub Repo)

Claude Code Router version v1.0.50 is now available. Users can now route Claude Code requests through models like GLM-4.5 and DeepSeek v3.1 for free via the iFlow Platform.
🎁

Miscellaneous

CNCF Expands Infrastructure Support for Project Maintainers via Docker Partnership (4 minute read)

The Cloud Native Computing Foundation partnered with Docker to provide all CNCF projects with access to Docker's Sponsored Open Source program, delivering premium registry, security, and support services. Maintainers gain scalable infrastructure with tools like Docker Scout, automated builds, and usage insights, while users benefit from more secure and reliable access to cloud native projects.
Malicious NPM packages: Are you exposed? (5 minute read)

A newly discovered NPM worm called Shai-Hulud spread rapidly by stealing credentials and self-propagating across hundreds of packages, highlighting the escalating risks of open source supply chain attacks. Sysdig's Threat Intelligence Feed provides real-time visibility into malicious NPM packages, enabling security teams to quickly verify exposure, investigate threats, and respond with precision.
⚑

Quick Links

Find CVEs that deserve your attention with this free tool (Sponsor)

Tired of doomscrolling to figure out if the latest vuln is the next Log4j? cvemon (by Intruder) tracks CVE hype with expert commentary - completely free. See what's trending β†’
Migrating from AWS CodeDeploy to Amazon ECS for blue/green deployments (7 minute read)

Amazon ECS now supports native blue/green deployments, providing an alternative to AWS CodeDeploy.
Announcing H1 2026 KCDs (2 minute read)

The Cloud Native Computing Foundation (CNCF) announced the first wave of Kubernetes Community Days (KCDs) for 2026 and introduced three tiers of KCDs to support communities of all sizes.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them!

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR DevOps isn't for you, please unsubscribe.