Dev News Daily ENDE

Who owns the plumbing: gVisor leaves Google, Turso joins Supabase, tokens grow

Three announcements from this week look unrelated: a sandbox changing owners, a database company being bought, and an authentication token changing shape. Read together, they are about the same thing — infrastructure that other software depends on, and who gets to decide how it changes.

gVisor moves from one company to a foundation. Google is donating the sandbox, including its name and trademarks, to the CNCF, which accepted it on 28 September. The project's own post is candid that single ownership cost it adoption and even kernel patches, which maintainers refused because gVisor belonged entirely to Google. The plan is outside maintainers with merge rights, CI on GitHub Actions instead of Google's internal systems, and voting by organisation. Source: https://gvisor.dev/blog/2026/10/02/gvisor-cncf/

Turso moves from independence into Supabase. Supabase is buying the company behind a Rust rewrite of SQLite, betting that AI agents will create databases by the million and that most of them should be small and cheap. Both products keep running and existing users are told nothing changes; the joint product is still a sketch. Source: https://supabase.com/blog/supabase-is-acquiring-turso

Who owns the plumbing: gVisor leaves Google, Turso joins Supabase, tokens grow
Who owns the plumbing: gVisor leaves Google, Turso joins Supabase, tokens grow — Dev News Daily

GitHub changes a format underneath its users. GitHub App installation tokens are now stateless and about 520 characters long instead of 40. Permissions and the one-hour lifetime are unchanged, but anything that stored, validated or redacted tokens by their old shape can break, and the header for testing both formats goes away on 30 November. Source: https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out/

What connects them. In each case the people who depend on the component did not choose the change, and in each case the announcement is honest about it — but honesty does not do the migration. Neutral governance for gVisor is a promise whose test is concrete: outside maintainers merging code and a kernel patch accepted upstream. "Nothing changes for existing users" after an acquisition is true on the day it is written; the useful question is which product the roadmap now serves. And a token that was always documented as opaque still breaks the systems that quietly assumed it was not.

The practical habit is the same for all three: write down which external components you rely on, what you have assumed about them that their owners never promised, and the dates on which those assumptions get tested. For this week, that is 30 November for GitHub tokens, the repository move for gVisor, and the first joint release from Supabase and Turso.

Written by Victoria Shinder.