Apple has released Swift 6.3, which includes several key updates to the programming language. One notable change is the stabilization of the Android SDK, which will allow developers to create apps for Android devices using Swift. Additionally, the new version extends C interop, making it easier for developers to integrate Swift code with C code.
Trivy, an open-source security tool, has been hit by a supply chain attack, prompting an urgent response from the industry. The attack, which was discovered on March 22, allowed attackers to inject malicious code into the tool's dependencies. As a result, users who installed Trivy between March 15 and March 22 may have inadvertently downloaded the compromised version.
Module Federation 2.0 has reached stable release, offering wider support outside of Webpack. This update allows developers to use the feature with other bundlers and build tools, expanding its reach and flexibility.
Github has integrated artificial intelligence (AI) to improve the management of accessibility issues and automate the triage of feedback. This move aims to enhance the user experience for developers with disabilities. The AI-powered system will help identify and prioritize accessibility issues, allowing developers to focus on resolving critical problems.
Axios, a popular JavaScript library for making HTTP requests, has been compromised in a supply chain attack. The attack, which was discovered on March 29, 2023, involved a malicious package being uploaded to the npm registry, a central repository for JavaScript packages. The compromised package, which was used by Axios, was designed to steal sensitive information from users who installed it.
Helidon 4.4.0 has been released, aligning with the OpenJDK cadence and introducing support via the Java Verified Portfolio. This release aims to provide a more streamlined and efficient experience for developers.