IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.
IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.
Are there any languages doing something unique or are especially resilient in this respect?
Oh you mean like the attacks that occur in Rust's cargo?
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...
Javascript is plenty fast, but only if it has enough time to JIT the code and can keep it JITed in memory. For long-running backed services, it's plenty fast, for browser things, it's the only option, but for the command line, it adds needless startup time.
Agents make this even worse because they don't have a "sense of time", so if they accidentally do something which causes startup time to increase dramatically, they won't feel it like a human dev would, and won't immediately start optimizing. Unless you have some specific benchmarks in CI that fail any PR which makes the code too slow, agents will just make things slower and slower.
What would even be a good alternative? The language should have no ambient authority, be fully safe, run newly loaded code quickly, and be popular enough that current LLMs are good at it. I think the languages that fit the bill are JS/TypeScript and Lua.
JS as a tech stack breaks your "fully safe" constraint (unless you are talking about running a CLI JS application without using npm...)
codex-rs's code-mode-runtime uses plain V8 and gives it limited capabilities. (It gives it a very strange set of capabilities, but the point is that a program can grant specified capabilities to a JS script that it hosts, and the JS script can use those capabilities and nothing else.)
I suppose I should have added Lisp-like langauges to my list, although those don't have the kind of static type checking that TypeScript can offer.
Yes, and the user wants to use a command line app, regardless of what's running underneath.