AI News

2

Claude Haiku 5.5

Anthropic released Claude Haiku 5.5, a fast low-cost model matching GPT-6 Luna pricing ($0.10/$0.50 per million tokens) up to 100k tokens; beyond that it jumps 5x to $0.50/$2.50, where Luna remains cheaper. A new tokenizer uses ~1.25x more tokens than Haiku 4.5, a hidden price increase. Reasoning can't be disabled and defaults to medium effort; low-effort pelican SVG cost 0.0936 cents (7s), max effort 3.38 cents (5m9s), with much better output than Haiku 4.5. Anthropic also halved Sonnet 5.5 cache-read prices and added monthly API credits for Max/Team subscribers ($100–$500, non-rolling-over), with optional balance caps to avoid overages.

Quoting Ben Affleck

Simon Willison quotes Ben Affleck describing his film-industry ML background: Affleck says he writes basic Python scripts and explains that VFX pipelines have long used machine learning, using convolutional neural networks on tensors (numerical pixel/frame/color data) for edge detection and feature extraction, e.g., to aid green screen replacement. He contrasts CNNs with transformers, describing transformers as handling much more computation simultaneously.

Blogs

3

The Pulse: Firebase’s global outage & poor response

A Firebase configuration change crashed iOS apps globally on 29 Sep 2026. A stale legacy config flag cleanup produced a malformed payload; the iOS SDK failed to validate a nil flag name and crashed on launch. Time to detect was ~1 hour (acknowledged via GitHub ticket 70 min in); rollback took ~2h11m, but cached bad responses kept apps crashing up to 6 hours total. An external developer identified the root cause on the GitHub issue before Google acknowledged it; only iOS crashed, as the Android SDK was more hardened. Firebase's status page stayed green throughout, since dashboards rely on server-side metrics and can't show client-side SDK outages; a postmortem came four days later. Google committed to integrating SDK outage info into dashboards, but the incident was buried in a Google Ads dashboard, reflecting unclear org ownership. The article contrasts this with the similar 2020 Facebook iOS SDK crash and urges hardening mobile SDKs against malformed backend payloads.

FOSS Weekly #26.41: Open Source Trouble, More Rust in Ubuntu, Adobe Photoshop's Linux Clone, Rich CLI Tool and More

This It's FOSS Weekly #26.41 digest covers open source funding and security news, tools, and tips. DigitalOcean quietly ended infrastructure credits for long-standing open source projects, and Gentoo is seeking new sponsors after backers withdrew. IFPI submitted yt-dlp to the EU piracy watchlist, naming four maintainers; Google paused OSS product vulnerability reports after AI spam, with a revamped program teased for Q1 2027. Siemens deleted OpenRadioss, but its AGPL license enabled a quick fork (OpenCourant) already shipping Linux/Windows binaries; Red Hat's Lightwell backports Java fixes, having cleared 400 vulnerabilities. Ubuntu 26.10 adds Sequoia PGP, a Rust-based OpenPGP tool alongside GnuPG, with plans to phase out GnuPG; Tuta Mail launched a Nextcloud app and plugin. Highlighted tools include an early-stage AI-generated Photoshop clone, S-TUI for terminal CPU monitoring, inxi for system info, and a community fork of GitHub Desktop for Ubuntu. Quick tip: in Nemo file manager, F3 opens an extra pane for side-by-side file management, toggleable via the toolbar preferences.

Gentoo Needs Your Help! Several Sponsors Have Pulled Out

Gentoo announced (Oct 7, 2026) that several long-time infrastructure sponsors have withdrawn, prompting a public call for new sponsors. The source-based distro relies on donated hardware and hosting, maintaining only a few machines itself; existing sponsors include OSU Open Source Lab, CDN77, HP, and Hetzner. Five sponsorship options are offered: donated machines for US hosting, colocation (non-US capacity is the most urgent need), VMs (min 2 vCPUs, 4GB RAM, 25GB storage), fully hosted physical servers with Gentoo getting remote access, or cash donations. Gentoo notes many services are monolithic, so Kubernetes is a poor fit for them; they prefer cloud VMs where possible. Sponsors aligned with Gentoo's open, user-choice philosophy are preferred; contact is [email protected]. The post compares this with LVFS, which successfully attracted major sponsorships (e.g., Lenovo and Dell at $100k/year).

Company Blogs

4

Reducing Android scope-sync overhead in Sentry Flutter

Sentry Flutter's Android scope-sync pipeline now normalizes scope data once (in the calling isolate) instead of twice, and encodes JSON directly to UTF-8 bytes via JsonUtf8Encoder, removing an extra Uint8List copy before JByteArray.from. Combined changes cut processing time 27–30% (e.g., 1.2 KB breadcrumb: 41.0→29.9 µs; 238 KB context: 8.24→5.95 ms), measured on a Pixel 4 in release mode, medians of 7 runs. The worker isolate (shipped in 9.21.0) keeps encoding and JNI calls off the UI isolate; the fixes shipped in sentry_flutter 9.26.0. Measurements exclude isolate round-trip latency, network delivery, and worker-isolate responsiveness benefits.

Solving Regional Consistency of Delivery ETA with a Deep Probabilistic Framework

Swiggy replaced point-estimate ETA prediction (MAE-trained) with a deep probabilistic model predicting Lognormal distribution parameters (mu, log-sigma) to fix inconsistent regional compliance. EDA showed delivery times are positive and right-skewed; a single Lognormal outperformed Gamma, Gaussian, and Gaussian MDNs (up to 10 components). Unlike multi-task quantile/city heads, the distribution output decouples training (NLL loss) from business metrics — any percentile can be extracted post-hoc per region/cohort without retraining. Training issues (NaN losses and sigma-inflation via a steeper "escape route" gradient) were fixed with EDA-backed sigma capping, chosen over regularization and two-stage MAE→NLL training. Offline evaluation used calibration curves and PIT plots, plus a Compliance vs Difference-of-Means trade-off curve where the new model strictly dominates the legacy baseline; segments meeting compliance targets rose 13% relatively. Because user-level A/B tests violate SUTVA in courier marketplaces, the model was validated in shadow production mode, then deployed pan-India with the legacy model kept in reverse shadow for continuous counterfactual monitoring. Key limitation: the approach relies on a single parametric Lognormal assumption, though it fit all tested micro-cohorts best.

TIN v1.0.6: 2-3x faster, with support for stemming

TIN v1.0.6 adds Snowball stemming via the rust_stemmers crate, supporting 18 languages; using it requires updating to v1.0.4+ and rebuilding indexes with WITH (stemmer = 'en'). Top-k queries with tiebreaker ORDER BY columns (e.g., score DESC, created_at DESC, id) now use the same block-max plan as plain ranked queries, instead of scoring all matching documents. After ParadeDB briefly beat TIN on BM25 top-10 read-only queries, optimizations restored TIN's lead: default-config TIN achieves 3.1-5.0x higher throughput and 2.7-4.4x lower p99 latency than ParadeDB 0.26.0 on x86-64, and 3.1-4.2x / 2.1-3.0x on ARM64. Benchmarks used 150M Stack Exchange documents (85 GB), 1,254 synthetic queries as disjunction/conjunction/phrase, an i7i.8xlarge EC2 host, and CPU pinning; x86-64 with AVX-512 outperformed Graviton4 for text search. TIN's default scoring omits terms appearing in >10% of documents from BM25 scores (matching logic unaffected); tin.full_score or tin.score(ctid, dense_ratio => F) restores full or tunable scoring. TIN's index format is unchanged and drop-in compatible, while ParadeDB 0.26.0's speedup grows its index 29% and requires a rebuild.

Track organization-wide security risk in one dashboard

GitLab 19.4 (beta, GitLab.com Ultimate) adds an organization-level security dashboard aggregating risk across all top-level groups. A risk score weighs open vulnerabilities by severity, age, KEV-list presence, and EPSS score, replacing raw counts. Charts show vulnerabilities over time (30/60/90 days), by age, by severity, and top-10 CWEs, with filtering by project or report type (e.g., SAST, dependency scanning). Third-party scanners emitting SARIF reports are ingested as vulnerability records and roll into the same score and views. Prerequisites: an Organization with multiple top-level groups, Owner role, active advanced search and advanced vulnerability management, and completed default-branch scans from at least one scanner per project.

Hacker News

4

Vitalik Buterin backs crypto ‘bunker mode’ amid rapid AI math advances

A Cointelegraph article reports that Vitalik Buterin endorsed a crypto "bunker mode" proposal amid rapid AI-driven advances in mathematics. Ethereum researcher Justin Drake warned AI could break current wallet security within months. The linked source text contains only metadata (title and URL); no technical details of the proposal or threat model are provided. Points and comment counts from the aggregator are metadata, not article content.

Vitalik Buterin backs crypto ‘bunker mode’ amid rapid AI math advances

Ethereum's Vitalik Buterin endorsed a crypto "bunker mode" proposal by Justin Drake, amid rapid advances in AI-driven mathematics. The concern is that AI progress could accelerate cryptanalytic breakthroughs threatening wallet security, potentially within months. Drake urged the crypto community to adopt defensive postures in response to these risks. Source material is limited to a headline and link metadata; no technical details of the proposal are provided.

The value of not getting to the point (2015)

A 2015 essay by Ken Arneson, re-discussed on Hacker News with 136 points and 43 comments. It argues for the value of digression — not getting straight to the point. The provided metadata contains no article body, so specific arguments or examples are unavailable. Comment discussion and precise technical claims cannot be verified from the supplied text alone.

Infra

4

Initial Triage Guide for VMware Cloud Foundation Private AI Services

VMware published an initial triage guide for VCF Private AI Services to quickly isolate whether issues stem from infrastructure or the service itself. Setup: workstations need vCenter/NSX/Supervisor access plus kubectl and VCF CLI; authenticate to the Supervisor, switch namespace context, then extract the VKS guest cluster kubeconfig from a secret named -kubeconfig. Confirm the deployed PAIS version via vSphere Client (Services > Manage Service) or kubectl jsonpath on paisconfiguration. Part 1 rules out infrastructure: blast-radius check across namespaces/clusters, ESXi and NVIDIA GPU driver/ECC/license health via nvidia-smi, vSAN Skyline Health, backing PostgreSQL database connectivity on port 5432, NSX/VPC realization and IP block usage, and certificate validity across vCenter/Supervisor/SSO. Part 2 inspects the service: check PAISConfiguration conditions (Ready, ModelEndpointPrerequisitesMet, PrometheusReady), then clusters/machines and pods readiness. Most pod-startup failures trace to CPU/memory under-reservation or missing VM/storage classes; stuck nodes (10+ minutes) or pending pods usually indicate infrastructure capacity or provisioning issues. If unresolved, collect a support bundle per Broadcom KB 408731 before escalating to GSS.

The audit log says my name: what an agent inherits when you hand it your credentials

An author gave a coding agent their own Azure credentials via the Azure CLI and measured what the agent inherited. Database sessions recorded the human's login, workstation, and tool name, so agent and human actions are indistinguishable and no downstream control can key on the agent. The token's scope was user_impersonation with an mfa attestation, and the CLI auto-refreshes past the 84-minute token lifetime. Authorization flowed from 37 group memberships invisible to standard role checks; two production stores one hour apart exposed 2 vs 107 permissions, with the analytics endpoint contradicting the agent's "read-only" instruction file. Audit coverage was inverse to privilege: the unmonitored environment was the one where the agent could delete from a secure database, and database-level audit specs misleadingly reported "enabled." Even a properly scoped managed-identity setup failed at the data path, authenticating to SQL via a shared login. Remedies proposed: delegation tokens distinguishing actor from subject, intersecting effective permissions, action-scoped grants, privilege-based auditing, and independent revocation.

Coding Agents Broke Git’s Scaling Math. GitHub Is Rebuilding to Keep Up

Agentic coding is overwhelming GitHub’s Git backend: commits hit 7.38B in Sept 2026 (5x YoY), pushes 3.35B/month, and one repo took ~1B requests. The current Spokes system keeps five local replicas synced via a three-phase commit, so every replica joins every write and adding read replicas slows pushes. Agents break this: sustained concurrent writes, trunk-based merges, clone storms from CI, and background GC on the serving path. The new design coordinates only on branch-pointer updates, offloads object checks/secret scanning, and moves maintenance to background workers. Storage is separated from compute: authoritative data in Azure Blob Storage with stateless read workers caching in front, so read scaling no longer slows writes and worker failure is just a cache miss. Internal benchmarks show up to 35x higher write throughput; no rollout timeline or customer-facing changes disclosed. GitHub preserves existing workflows, protections, and auditability; analysts note review bandwidth—running at human speed—becomes the next bottleneck, and teams must rethink CI cadence per checkpoint.

Upgrade to VMware Cloud Foundation 9.1 and Express Patching Webinar Top 10 Questions Answered

VCF 9.1 upgrade guidance covers security audits, image management, capacity requirements and Live Patching. STIG audits use the STIG Automation Appliance or VCF Security and Hardening Guidelines scripts. Vulnerability scanning should combine authenticated configuration checks and unauthenticated network scans, with least-privilege credentials. vLCM images combine ESX, OEM add-ons and firmware plugins; vendor components can be added before custom ISOs arrive. Grayed-out SDDC Manager controls are expected while an upgrade step is pending or after a workflow error clears. Two-node upgrades require single-host capacity and verified vSAN policies; convergence imports all clusters from a vCenter. ESX Live Patching avoids reboot and VM evacuation for eligible Express Patches; others require standard maintenance mode. Terraform support currently covers VCF 9.0, not 9.1.

Tech Publications

4

Anthropic bans ‘abusive or cruel behavior’ toward Claude

Anthropic updated its usage policy for the first time in over a year, targeting misuse like election interference, weapons development, surveillance, and high-risk health/financial uses. The most notable change bans "sustained and needless abusive or cruel behavior" toward Claude. This follows Anthropic's August announcement letting Claude end conversations with persistently harmful or abusive users, part of its "model welfare" research. Conversation termination remains the primary enforcement mechanism. Anthropic did not provide additional comment.

Can you trust Meta’s Muse or OpenAI’s Dots to run your life?

A Decoder interview with The Verge's Hayden Field on Meta's Muse and OpenAI's Dots, new consumer AI agents. Both derive from the OpenClaw model: an LLM harness driving a browser on a cloud computer (Meta gives a small Linux VM; Muse is free, Dots requires $100–200/month subscriptions). OpenAI positions Dots for enterprise/knowledge work with paid "specialist" agents, while Meta leverages its distribution and consumer design to flood the market despite lacking a frontier model. Reliability is uneven — agents hit CAPTCHAs, get blocked (e.g., Amazon), and act inconsistently, and consumers abandon them after first failures. Major privacy concerns: Muse builds profiles of friends/family, aggressively reads Mac disk data (prompting Apple permission changes), and a Marketplace incident where it impersonated a user. Monetization is unresolved: Meta plans backend transaction cuts, raising "corrupt butler"/paid-recommendation trust issues, while OpenAI relies on enterprise revenue.

Older Pixel watches are losing free cellular access to several safety features

Google announced that LTE Pixel Watch 2 and 3 models will lose free cellular access to Safety Signal after December 12th. Safety Signal let Emergency SOS, Fall Detection, and Safety Check work over LTE without a carrier plan. The connectivity was bundled free as part of Google Health Premium. After the cutoff, users must pay for a mobile plan to keep using Safety Signal on LTE. Users with free access will be notified via notifications and email. Safety Signal features will reportedly still be available over Wi-Fi.

Amazon is phasing out Fire Tablets because they weren’t ‘giving customers what they were asking for’

Amazon is phasing out its Fire tablet line, confirmed by consumer electronics chief Panos Panay in a Bloomberg interview. The Fire brand is being replaced by a new lineup of Alexa Tablets. The new tablets run proper Android instead of the custom Fire OS. They also get full access to the Google Play Store. Fire tablets lacked official Google apps like Gmail, YouTube, and Drive, which were browser-only. Panay said Fire tablets "weren't giving customers what they were asking for," citing the restricted app access.

Tools

1

Upcoming Next.js Security Update for Upstream Vulnerabilities

Next.js announced an out-of-band security release scheduled for Wednesday, October 14, 2026. The update fixes three vulnerabilities in upstream dependencies. Two are rated Critical severity and one High severity. No further technical details, affected versions, or CVEs were disclosed in the announcement.

Top Reddit

2

I'm thinking of using a static site generator (11ty or Astro) to rebuild my website, which is best for lightly interactive components?

The author has an Angular-built site that is mostly static, making Angular feel like overkill, and wants to rebuild it with a static site generator. Their interactivity needs are light: pages with tables that include a text input filtering rows as you type. They are choosing between 11ty and Astro and ask which is better suited for lightly interactive components. No conclusion or recommendation is given in the post itself.

Looking back at more than 5 years at Shopify

A Reddit post linking to a personal blog article by /u/mawburn titled "Looking back at more than 5 years at Shopify". The post is a career retrospective by a former employee summarizing over five years at Shopify. No further technical details or article content are available in the source.

YouTube Channels

4

Scaling agentic coding practices across your team

A Google Cloud Tech video (Annie Wang, Tilde Thurium) explains scaling agentic coding across teams using markdown spec files. DESIGN.md defines visual guardrails, design systems, and styling tokens; AGENTS.md provides global project guidance, coding standards, and build/test instructions; SKILL.md captures reusable domain-specific tasks and workflows. The talk contrasts agent specifications with prompt/context engineering and cites benchmark data on token savings and performance gains from AGENTS.md. Best practices include separation of concerns and splitting shared team rules (project layer) from personal developer preferences (user layer). Real-world examples include Google ADK and DeepMind's Simply repository.

Build & connect an incident investigation agent with Elastic Agent Builder and Gemini Enterprise

Demo video showing an incident-investigation agent built with Elastic Agent Builder and integrated into Google Cloud's Gemini Enterprise.

Elastic Agent Builder's GUI is used to define custom tools and runbook skills for automated troubleshooting.

The agent is grounded in Elastic Observability data (logs, metrics, traces) to diagnose performance regressions, e.g., latency issues in a frontend proxy, with full inspectability of its reasoning.

The agent is exposed externally via the Agent-to-Agent (A2A) protocol by exporting an agent card through an endpoint.

The agent card is registered in Gemini Enterprise, enabling querying and running Elastic-grounded workflows from its web interface as a centralized platform.

Limitations: it is a vendor demo; no details on pricing, security, or production deployment are provided.

Navigating AI automation in Looker: Essential developer tools for agents

A Google Cloud Tech video (presented by Chrissie Goodrich) introduces five core tools in the "Agentic Looker Developer Stack" for AI automation and LookML authoring: Looker Skills (documentation), Looker CLI (automation), Looker Managed MCP server, MCP Toolbox for Databases, and the Looker VS Code Extension. A companion codelab on authoring LookML with agentic coding tools is linked at g.dev/ai/looker-agentic-lookml. The video covers each tool briefly (~1 minute per chapter) and is tagged around AI agents, LookML, semantic layers, and BI data modeling.

"Beyond the Server: Frames, SPAs, and Testing in Remix" by Matt Brophy

Talk by Matt Brophy on extending Remix beyond the server boundary. Frames in the browser enable incremental navigation with granular updates to route-owned UI regions. A dedicated SPA package runs Remix routes entirely on the client. Testing tools cover direct route testing, component testing in real browsers, and end-to-end flows. The goal is a consistent, web-standard programming model spanning server, browser, and test environments.

Medium

4

checkpointd: Automatic Crash Recovery of Stateful Agents from Memory Checkpoints on Kubernetes

This post introduces checkpointd, an NTT Labs tool for automatic crash recovery of stateful, long-running AI agents on Kubernetes, using memory checkpoints. It targets the problem that Kubernetes containers can be killed or rescheduled while agents hold in-memory state. Checkpointd checkpoints an agent's process memory so it can be restored after a crash instead of restarting from scratch. The article feed provides only a snippet, so detailed implementation specifics are not available here. Concrete limitations of the approach (memory checkpoint size, compatibility constraints) are not covered in the provided excerpt.

The Semantic Cache: Reusing Answers in a System That Never Repeats Itself

The post discusses semantic caching for LLM/AI systems: reusing prior answers for semantically similar queries instead of only exact matches. It frames the core trade-off: similarity-keyed caching saves cost/latency but can silently "poison" results when near-miss queries get mismatched cached answers. A key theme is setting the similarity threshold honestly — calibrating it so only genuinely equivalent queries hit the cache. The article covers where semantic caching genuinely pays off versus where it introduces silent quality regressions. Full technical details are behind the linked Towards AI article; the feed excerpt contains only the summary.

5 bugs silencieux dans Microsoft Agent Framework, et comment savoir si vos agents sont touchés

L'article recense cinq bugs silencieux trouvés dans Microsoft Agent Framework. Sont cités : perte du lien de consentement, disparition des citations, appels d'outils en parallèle, filtres Qdrant retournant de faux résultats, et proxy ignoré. L'auteur propose aussi des moyens de vérifier si ses agents sont affectés. Le flux RSS ne donne qu'un résumé ; les détails et corrections sont dans l'article complet.

Local LLM Tool Calling Depends on Your Runtime’s Parser

A source-code study of four local LLM runtimes found that 41 model families have a dedicated tool-call parser in at least one runtime. Tool-calling behavior therefore depends heavily on the runtime's parser, not just the model itself. Coverage varies across runtimes, so a model may work for tool calls in one runtime but not another. This is part 1 of a 3-part "Local Agent Lab" series. Full details are in the linked article; the snippet itself contains limited specifics.

Releases

4

v8.0.0-rc.17-dev.5: Rename symbol in the PSL language server (#30633)

The PSL language server (v8.0.0-rc.17-dev.5, PR #30633) adds LSP rename support for models, composite types, named types, blocks, fields, and namespaces. provideRename reuses find-references (with declaration included) to build a single WorkspaceEdit, so edits exactly match go-to-definition targets; prepareRename returns the identifier range or null. Renaming a model or field can also insert @map/@@map with the old name so database table/column names stay unchanged; map insertion depends on project attribute specs and a new nameIsStorageName block-descriptor flag (used by Postgres native enums). Invalid new names are rejected before edits; there is no collision check, so renaming to an existing name can merge symbol identities (accepted behavior matching TypeScript/Prisma 7). Known gaps: native_enum usages inside pg.enum(...) and enum members aren't renamed (binder lacks resolutions), and names without map attributes (namespaces, composite type members, roles/policies) are renamed by name only. Playground opens unopened scratch files before applying multi-file edits, and file selection now reads the editor's model so rename-modified text isn't reverted. Tests cover all symbol kinds, capabilities, and error responses; VS Code manual checks are still pending.

v8.0.0-rc.17

Prisma ORM v8.0.0-rc.17 makes migrations refuse data loss by default: migration plan and db update ask per dropped model/field, answered with --delete <subject>, the new --rename <old>:<new> (keeps rows; MongoDB renames refused), or --allow <Model> for access-widening ops like dropping RLS policies; --confirm no longer implies consent and scripts must switch flags, with CLI.CONSENT_REQUIRED errors listing needed flags. destructive is redefined as actual data loss; drops of indexes/constraints/defaults and value-preserving type changes are now non-consenting widening ops; unapplied migration.ts files get new ops.json/migrationHash. Control API breaking change: executeMigrationPlanCommand, executeDbUpdate, and dbUpdate require an answerQuestions callback; consent is removed, acceptDataLoss no longer covers access widening (use acceptAccessWidening), and MIGRATION.DESTRUCTIVE_CHANGES/CONSENT_PLAN_MISMATCH errors are gone. SQL client renames: collection method apply → with, scope → fragment (via db.orm.fragment(...)), with types Scope* → Fragment*. db.enums members now hold values as queries return them (bigint → bigint, dates → Date/Temporal, bytes → Uint8Array); enum members must be written as the database stores them (pg/numeric, pg/inet normalized forms enforced) and several lossy codecs (pg/timestamp-string@1, pg/bytea@1, mongo/json@1, etc.) are refused for enums. New features: row locks (forUpdate, forShare, forNoKeyUpdate, forKeyShare with nowait/skipLocked), @default(autoincrement()) on existing columns plans a sequence past current max, and relations can name their backing foreign-key index via index: "<name>" (all SQL contracts get new storage hashes requiring re-emit). Other breaking changes: MongoDB index sort syntax becomes sort(field, Desc); CHECK constraints on enum-list columns change; extension authors must adapt planner signatures (statements, origin, dataLoss, accessWidening), enum codec equality trait requirements, and regenerate bundled SQL contracts.

v1.64.0

Playwright v1.64.0 adds WebMCP support via page.webmcp/frame.webmcp to list and call page-registered MCP tools (Chromium requires --enable-features=WebMCP); Playwright MCP exposes them as webmcp_ with --no-webmcp opt-out, and playwright-cli gains webmcp-list/webmcp-call. Video recording gains a custom fps option (Firefox/WebKit capped at 25 fps), CSS-styled action decorations replacing deprecated fontSize, a persistent eased cursor, and VP9 encoding for lower CPU and smaller files. Test runner adds testProject.default to run a single project by default, --shuffle with reproducible seeds, test.describe.configure({lock}) test locks, and toHaveScreenshot type:'webp' for unnamed snapshots. New locator.within() scopes one locator inside another with per-parent relative resolution; other APIs include page.getByRef(), includeShadow DOM serialization, virtual credential signCount, fullConfig.filteredProjects, and APIRequestContext cookie methods. Breaking changes: device screen descriptors are now forwarded (opt out with screen: undefined), JSX follows tsconfig with automatic react/jsx-runtime default, --update-snapshots=missing now passes the run, and elements in hidden iframes count as hidden. Ships Chromium 156.0.8078.4, Firefox 157.0, WebKit 27.2; also tested against Chrome 155 and Edge 155.

v8.0.0-rc.17-dev.2: TML-3340: close out the one-config-file project (#30654)

This release-tag commit closes Prisma's "one-config-file" project by deleting its working folder (25 files changed, 1 insertion, 2,833 deletions) and fixing a duplicate failure-mode number (F39 renumbered to F42). Composer's configuration now lives in the composer section of prisma.config.ts; the old prisma-composer.config.ts and configPath are refused with CONFIG.FILE_RETIRED / CONFIG.FIELD_RETIRED diagnostics (exit 2). The standalone prisma-composer binary is removed; the unified prisma host ([email protected]) runs Composer 0.26.0 with bare prisma dev and prisma deploy commands. Published packages declare no bin, a CI lint (lint:retired-binary-name) blocks references to the old binary name, and decisions are preserved in ADRs (0049, 0050) and the consolidation plan. Definition of Done is met with deviations: no real prisma deploy ran from the host build (no service token), and pnpm-project failures are fixed in an unreleased PR (TML-3520 tracks releasing Composer 0.29.0 with the fix). Deferred items are ticketed as TML-3520–3528, covering shared local Postgres, flaky emulator tests, stale pins, Alchemy startup edge cases, and repos still using the retired config. Windows edge cases are explicitly out of scope, as Windows is unsupported for local tooling.