Watch the video, transcript and sources
- Deno Deploy: six-month runway
+ Microsoft MXC: sandbox SDK
+ Bevy 0.20: Solari upgradesOpen source sounds permanent. Deno's entire team is joining Cloudflare, and Deno Deploy gets six months before shutdown. Deno is an open source runtime, the program that runs JavaScript and TypeScript outside your browser. It includes tools for testing and packaging your code. Deno Deploy is the separate hosting service that runs your applications on somebody else's servers. Those have different futures. Ryan Dahl, who created Node, announced the move today. Microsoft has a sandbox for the code your agent wants to run, and yesterday Bevy shipped prettier Rust game graphics. Apparently Friday's migration ticket comes with ray traced emotional support.
Here's the hosting deadline in Deno's own announcement. Deploy keeps operating for six months, then shuts down. Paying customers get migration support to Cloudflare Workers. If Deploy hosts your business, that calendar now belongs in your incident planning, alongside the coffee budget. Workers runs server side code on Cloudflare's network. Moving there means checking your app's assumptions. Inventory database connections, background jobs and stored data. Migration help needs a compatibility review before you promise the boss a painless weekend. Everybody else gets the shutdown notice. That's a useful distinction when somebody forwards the headline with the reassuring words, should be fine, and immediately goes offline.
The runtime gets another year of monthly bug fixes and security updates from this team. Then their development ends. The source stays open, and other maintainers can continue it. Your existing executable keeps running, but its future support now needs an owner. JSR, the package registry for JavaScript and TypeScript, continues operating while its infrastructure moves to Cloudflare. The team also keeps supporting rusty_v8, its Rust bindings to Google's JavaScript engine, and plans to integrate that work into Cloudflare's runtime. So the dinosaur logo survives, the hosting has a deadline, and the people building the runtime have chosen another project. An open license preserves your ability to take over the work. Unfortunately, it ships without the spare engineering team required to do that.
The new focus is merging workerd and celld to simplify self hosting Workers and Durable Objects. A Durable Object is an individually addressable piece of server code with its own database, useful for keeping a chat room's messages and connections together. Use one object per room, and the platform can distribute rooms across machines. Dahl describes celld as a Rust binary with object storage as its only external service dependency. That's the ambition, fewer infrastructure projects attached to each application. That sounds attractive if you've ever built a chat app and accidentally founded a database administration department. Developers could operate the same programming model themselves. The operational escape hatch still needs the work we'll come back to.
Microsoft MXC: choose the boundary
Microsoft's Execution Container, or MXC, is a software kit your application embeds to run untrusted code inside a sandbox. That means restricting what a plugin or an agent's generated program can access, instead of handing it your whole laptop and hoping the prompt was polite. It supports Windows, Linux and macOS, with SDKs for Rust, .NET and Node. You specify the workload and policy. Version 1.0 arrived on October 7, and the repository has a June public release commit. Today's attention came later. The clever part is a common interface over different boundaries. The dangerous part is assuming they're identical because the API looks tidy. It can also put the complicated bit just far enough away that nobody checks it.
Linux defaults to Bubblewrap, and macOS uses Seatbelt. Windows defaults to a process container. Other backends include virtual machines, with some marked experimental. An operating system process sandbox and a separate virtual machine have different security boundaries. Choose the backend for the workload you're actually running. And read the audit mode warning. Audit turns off all sandbox security for the workload being analyzed. It's for learning what a trusted tool needs, so you can author its policy. Putting an unknown agent script through that mode would defeat the reason you installed the sandbox.
Bevy 0.20: real graphics, real qualifications
Bevy is a free, open source game engine built in Rust. Version 0.20 arrived October 8. Its experimental Solari renderer simulates light bouncing around a scene in real time, with improved moving shadows and less shimmery reflections as the camera moves. The episode uses the release and Solari author's real demonstrations.
Solari needs ray query support. It now runs on macOS through Metal, although the Mac version has no built in denoiser. The light sampling technique called ReSTIR is off by default for performance. That can reduce shadow quality and lose shadows in motion in scenes with many lights. Test your scene before celebrating. There are more interface widgets and a shader language extension called WESL. You can scrub a number input by dragging, a refreshingly small demo after discovering where your servers will live.
The self-hosting gap
Here's that missing piece. Open source workerd supports Durable Objects on a single instance, which limits scaling. Merging celld is meant to fill that gap. Cloudflare's self hosting push could make an exit easier, but the finished distributed platform remains future work.
Verdict: NEEDS REVIEW — Plan the migration; name the maintenance owner
Sources
Photo credit: Ryan Dahl at YUIConf 2010, David Calhoun, CC BY 2.0, via Wikimedia Commons. Cropped, background removed and mirrored for thumbnails. This is a historical portrait.
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · Newsletter · thedailydiff.dev · forward this to the intern who deployed on Friday.

