Today, in a paper published in @nature.com, Google researchers demonstrated that our WeatherNext 2 AI model from Google DeepMind can predict hurricanes with an extra day of lead time → goo.gle/4xpDEuV Now, we’re open sourcing the model to the global research community.
Mauricio Lauffer
@mauriciolauffer.bsky.social
Into SAP tech, nodejs and web dev stuff...
@ui5.bsky.social any plans to split this 9h video from UI5con in a playlist? www.youtube.com/watch?v=CMPu...
UI5con 2026: Live from the Main Stage!
YouTube video by UI5
youtube.com
ARC-1 released Version 1.0.0 with a big changelog, main feature in the is the support of multi system/client in BTP CF github.com/arc-mcp/arc-...
Release v1.0.0 · arc-mcp/arc-1
1.0.0 (2026-07-31) Features add experimental destination-discovered multi-target endpoints (#579) (5ec27fc) add procedural unit source surgery (#571) (b712616) advertise configurable MCP server na...
github.com
New SAP CAP versions may introduce config changes and deprecate old flags. Navigating the docu to find them can be a cumbersome task. So, I've created an ESLint plugin to check the usage of deprecated flags in your "package.json" and ".cdsrc.json" files. #sap #sapcap #sapbtp #eslint #CAPirates 🏴☠️🏴☠️🏴☠️
Hey #SAPCAP folks! The recordings from the Audimax and W1/W2 tracks at #reCAP last week have been sliced, diced & prepared for your watching pleasure, by our media elf. Two playlists, one for each track. Share & enjoy! Get them from the #reCAP YT channel home page 👉 www.youtube.com/@reCAP_uncon...
#sapcap v10 is out! No more "axios" or "better-sqlite3", just native modules "fetch" and "node:sqlite". Dependencies down from 190 to 78! ESM is soon to be default module system for all new projects. Adios CJS. FINALLY Jest is going away. Native node:test and Vitest are the preferred test runners 🥳
June 2026 | capire
Documentation for SAP Cloud Application Programming Model
cap.cloud.sap
Workflow automation is evolving fast and agentic design is at the center of that shift. @jorgt.bsky.social and @katan-patel.bsky.social from Shebang Software are bringing their session on n8n and agentic integrations to UI5con 2026. 👉 Swipe for a first glimpse! #UI5con2026 #n8n #Automation
That said, there’s still some friction for people to start benefiting from agents, and the cost can be a barrier. If you’re actively contributing to OSS and want to use agents to help with your work, DM me with your contributions or plans. I’d be happy to sponsor your agent bills for a few months.
I want to say thanks to @hyf0.bsky.social, who wrote me a long email back then explaining the benefit of using agents, with a $100 sponsorship for me to try them. It has significantly changed my attitude and workflow (still exploring the best practices tho, hopefully to be able to share soon).
🛑 Stop letting your coding agent burn tokens guessing at performance fixes. With Chrome DevTools for agents, your AI can verify and automate fixes using real traces and agentic Lighthouse audits → goo.gle/4wVbLvc
How did the "Mini Shai-Hulud" attack compromise 170+ packages while maintaining valid SLSA Build L3 attestations? Read the full blog to see where SLSA’s boundaries fall and how to secure your pipeline with defense in depth. 🔗: openssf.org/blog/2026/06...
Mermaid diagrams are now built directly into VS Code. 🎉 No extra extension required. 🙌
We asked people when they knew they wanted to be a developer. ✨ When was that "aha" moment for you? Share your story in the comments!
Here's an easter egg in the new Lego Batman that I think all of you will REALLY appreciate. It's so good, I had to make a video.
✨ Introducing @GoogleGemma 4 12B, a unified open model bringing high-performance agentic multimodal intelligence directly to your laptop. Bridging the gap between edge efficiency and advanced reasoning, nearing 26B MoE at <50% the memory footprint.
Woooo yeaaah! The missing piece 🎉 everything is about to get a lot more secure
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
docs.npmjs.com
"Cognitive debt and burnout aren’t new, alas. With or without AI, we’ve all stayed up to 4AM working on a bug that won’t go away or pursuing an interesting idea to its end. Sometimes that’s heroic, but AI threatens to turn it into a lifestyle." Check out new #Radar article: bit.ly/4uPmJ3N
Burnout and Cognitive Debt
Steve Yegge’s article about programmer burnout (“The AI Vampire”) along with Margaret Storey’s article about Cognitive Debt started an ongoing conversation
bit.ly
SAP Stammtisch Brisbane - 28 May 2026! See y'all there! #sap #sapcommunity #sapstammtisch #brisbane community.sap.com/t5/brisbane-...
SAP Stammtisch Brisbane - May 2026
SAP community + drinks === good vibes Let's all get together to have some drinks, share the nice things we have been doing and complain about the new API policy
community.sap.com
ICYMI (and we hope you didn't): Node.js 20 went EOL last week. But you have options. Check out our EOL support: https://nodejs.org/en/about/eol
Reminder: Node.js v20 is end-of-life (EOL) today. Upgrade + get security support for EOL versions here: https://nodejs.org/en/about/eol
Node.js — End-Of-Life
Understand Node.js End-of-Life, what it means for security, tooling, and compliance, plus EOL version details and commercial support options.
nodejs.org
🚨 Supply chain attack: SAP CAP and Cloud MTA npm packages compromised to download and execute unverified binaries. Affected versions: → mbt@1.2.48 → @cap-js/db-service@2.10.1 → @cap-js/postgres@2.2.2 → @cap-js/sqlite@2.2.2 Details: socket.dev/blog/sap-cap...
SAP CAP npm Packages Hit by Supply Chain Attack - Socket
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...
socket.dev
avoid the next malicious package disaster with pnpm security hardening: github.com/lirantal/npm... Security Best Practice: Set trustPolicy: no-downgrade so that pnpm refuses to install any package version whose trust evidence is weaker than a previously published version of that package
AI agents are executing code, calling APIs, writing to databases, and most deployments have almost no controls around what they can do. @microsoft.com just open-sourced a runtime governance toolkit built around @owasp.org's Top 10 for Agentic Applications. Details → socket.dev/blog/microso...
Microsoft Releases Open Source Toolkit for AI Agent Runtime ...
Microsoft has released an open source toolkit for enforcing runtime security policies on AI agents as adoption accelerates faster than governance cont...
socket.dev
🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week. socket.dev/blog/attacke...
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
socket.dev
@sapcommunity.bsky.social @recap-conf.bsky.social another reason to stop using axios in SAP packages like cap or ai-sdk. Standard js APIs should suffice. Fetch is safer, lighter, and better.
🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today. We're still investigating. If you use axios, pin your version and audit your lockfile. socket.dev/blog/axios-n...
TypeScript 6.0 is now available! This release brings better type-checking for methods, new standard library features, new module features for Node.js, and more! But most important, this release brings us one step closer to the upcoming native-speed 7.0! devblogs.microsoft.com/typescript/a...
Announcing TypeScript 6.0 - TypeScript
TypeScript 6.0 is now available! TypeScript 6 is a stepping-stone release, aligning with the upcoming native-speed 7.0 release.
devblogs.microsoft.com
🆕 The URL Pattern API is Newly Available! Use it to match and extract parts of URLs, no need to reinvent routing logic. Supports literals, wildcards, named groups, and even regex constraints. Learn how it works 👇 developer.mozilla.org/en-US/docs/...
New in SAPUI5 Flexibility: Adapting UIs for specific user roles now also on SAP BTP, Cloud Foundry environment: community.sap.com/t5/technolog...
⚡️ Vite 8.0 is here! The most significant architectural change since Vite 2. ⏬ Powered by @rolldown.rs bringing faster production builds and more consistency 🛤️ New features such as tsconfig paths and emitDecoratorMetadata support vite.dev/blog/announc...
Vite 8.0 is out!
Vite 8 Release Announcement
vite.dev