source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, OCTOBER 10, 2026
  1. 001Hacker NewsOCT · 10English

    Next.js 16.4

    Next.js 16.4 introduces Cache Components as the default programming model, offering fast initial loads, instant client navigations, and declarative, opt-in caching. The release includes performance improvements like reduced memory usage, smaller bundles, and React 19.3 support, with new agentic tooling to help existing apps migrate.

    By jhuleatt
  2. 002Hacker NewsOCT · 09English

    Show HN: Tode – Analytics for Figma plugins, which run in a null-origin iframe

    Tode is an analytics platform designed specifically for Figma plugins and widgets, addressing limitations of traditional browser analytics tools by using the Figma plugin API to accurately track users, sessions, and custom actions in sandboxed iframe environments. The SDK supports multiple frameworks (React, Vue, Angular, Svelte, vanilla JS), offers flexible pricing from free to business tiers, and collects minimal user data while providing dashboards with metrics like daily active users, retention, and feature adoption.

    By kolebayev
  3. 003Hacker NewsOCT · 09English

    CVE-2026-23870: A Single Post Freezes Any Next.js Server

    CVE-2026-23870 is a denial-of-service vulnerability in Next.js server actions where an attacker can craft a malicious POST request with thousands of nested form pointers and fields, causing React's request parsing to perform millions of string checks on a single thread, freezing the server for seconds. The vulnerability requires no authentication and can be exploited by extracting the action ID from public HTML or JavaScript files.

    By Simon Koeck