<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — Bun</title><description>Articles on devtake.dev covering Bun.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Jarred Sumner rewrote 960,000 lines of Bun from Zig to Rust in six days. He might throw it all away.</title><link>https://devtake.dev/article/bun-rust-rewrite-zig-test-compatibility/</link><guid isPermaLink="true">https://devtake.dev/article/bun-rust-rewrite-zig-test-compatibility/</guid><description>Bun&apos;s creator used Claude to port the JavaScript runtime from Zig to Rust, hitting 99.8% test compatibility. He says there&apos;s a &apos;very high chance&apos; it gets scrapped.</description><pubDate>Sun, 10 May 2026 09:45:00 GMT</pubDate><category>open-source</category><category>bun</category><category>rust</category><category>zig</category><category>javascript</category><category>runtime</category><category>anthropic</category><category>open-source</category><category>dev-tools</category><author>soren-vanek</author></item><item><title>Mini Shai-Hulud hit PyTorch Lightning. The 11.6M-download PyPI package shipped a credential stealer.</title><link>https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</link><guid isPermaLink="true">https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</guid><description>Two malicious lightning releases hit PyPI on April 30. The 42-minute window was enough to ship an RSA-encrypted infostealer to ML developers worldwide.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>security</category><category>pytorch-lightning</category><category>pypi</category><category>supply-chain</category><category>mini-shai-hulud</category><category>credential-theft</category><category>python</category><category>ml</category><category>security</category><author>luca-reinhardt</author></item></channel></rss>