<p>News includes Elixir 1.20.0-rc.6 arriving as likely the final release candidate before v1.20.0 ships, completing a ~15-week roadmap and delivering full type inference across applications and dependencies. The EEF 2026 election results are in with 3 returning and 1 new board member, LiveStash v0.3.0 lands with a Redis adapter and auto-stashing for Phoenix LiveView state recovery on WebSocket reconnects, a call goes out for BEAM ecosystem companies to step up and support the EEF’s critical security work, and GitHub suffered a significant breach when a hijacked VS Code extension quietly exfiltrated ~3,800 internal repositories in just 11 minutes, and more!</p>
<p>Show Notes online - <a href="http://podcast.thinkingelixir.com/305" rel="nofollow noopener">http://podcast.thinkingelixir.com/305</a></p>
<p><strong>Elixir Community News</strong></p>
<ul>
<li><a href="https://paraxial.io/?utm_source=thinkingelixir&utm_campaign=thinkingelixir-oct2025" rel="nofollow noopener">https://paraxial.io/</a> – Paraxial.io is sponsoring today's show! Sign up for a free trial of Paraxial.io today and mention Thinking Elixir when you schedule a demo for a special offer.</li>
<li><a href="https://elixirforum.com/t/elixir-v1-20-0-rc-6-released/75448?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://elixirforum.com/t/elixir-v1-20-0-rc-6-released/75448</a> – Elixir v1.20.0-rc.6 released on the ElixirForum - the likely final release candidate before v1.20.0 final, completing the ~15 week type inference roadmap. Includes tips for profiling compile times before and after upgrading.</li>
<li><a href="https://github.com/elixir-lang/elixir/releases/tag/v1.20.0-rc.6?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://github.com/elixir-lang/elixir/releases/tag/v1.20.0-rc.6</a> – GitHub release page for Elixir v1.20.0-rc.6. Highlights include full type inference across applications and type inference across deps.</li>
<li><a href="https://erlef.org/blog/eef/election-2026-results?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://erlef.org/blog/eef/election-2026-results</a> – EEF 2026 election results - David Bernheisel, Francesco Cesarini, Amos King, and Alistair Woodman were elected.</li>
<li><a href="https://x.com/swmansionelixir/status/2054945784148201684?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://x.com/swmansionelixir/status/2054945784148201684</a> – Software Mansion announces LiveStash v0.3.0, featuring a new Redis Adapter and Auto-Stashing for Phoenix LiveView state recovery on WebSocket reconnects.</li>
<li><a href="https://github.com/software-mansion-labs/live-stash?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://github.com/software-mansion-labs/live-stash</a> – GitHub repo for LiveStash - a library providing a reliable API to stash and recover Phoenix LiveView assigns when socket connections are interrupted or re-established.</li>
<li><a href="https://x.com/ZachSDaniel1/status/2057517360060522872?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://x.com/ZachSDaniel1/status/2057517360060522872</a> – A call to action for companies generating revenue on the BEAM ecosystem to support the EEF. The EEF maintains a CNA and coordinates security across the ecosystem including hex.pm, but the current effort is no longer sustainable.</li>
<li><a href="https://hauleth.dev/post/writing-tests/?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://hauleth.dev/post/writing-tests/</a> – A solid blog post on writing better Elixir tests. Covers using a @subject module attribute, grouping tests with describe, preferring dependency injection over mocking, avoiding factory libraries in favor of calling context functions directly, and using property-based testing with StreamData.</li>
<li><a href="https://x.com/github/status/2056884788179726685?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://x.com/github/status/2056884788179726685</a> – GitHub's official tweet confirming unauthorized access to their internal repositories. No confirmed evidence of impact to customer data outside GitHub's internal repos at time of posting.</li>
<li><a href="https://x.com/intcyberdigest/status/2056970677668770117?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://x.com/intcyberdigest/status/2056970677668770117</a> – Report that GitHub was compromised by TeamPCP via a poisoned VS Code extension on an employee device, resulting in ~3,800 internal repositories being exfiltrated and sold on a cybercrime forum.</li>
<li><a href="https://x.com/star_knight12/status/2056977944334266428?utm_source=thinkingelixir&utm_medium=shownotes" rel="nofollow noopener">https://x.com/star_knight12/status/2056977944334266428</a> – Detailed breakdown of the GitHub hack - the Nx Console VS Code extension (2.2M installs) was hijacked with a credential stealer hidden in an orphan commit. It harvested tokens from GitHub, npm, AWS, Kubernetes, and 1Password. The poisoned version was live for only 11 minutes before detection.</li>
</ul>
<p>Do you have some Elixir news to share? Tell us at <a href="https://x.com/ThinkingElixir" rel="nofollow noopener">@ThinkingElixir</a> or email at <a href="mailto:show@thinkingelixir.com" rel="nofollow noopener">show@thinkingelixir.com</a></p>
<p><strong>Find us online</strong></p>
<ul>
<li>Message the show - <a href="https://bsky.app/profile/thinkingelixir.com" rel="nofollow noopener">Bluesky</a></li>
<li>Message the show - <a href="https://x.com/ThinkingElixir" rel="nofollow noopener">X</a></li>
<li>Message the show on Fediverse - <a href="https://genserver.social/ThinkingElixir" rel="nofollow noopener">@ThinkingElixir@genserver.social</a></li>
<li>Email the show - <a href="mailto:show@thinkingelixir.com" rel="nofollow noopener">show@thinkingelixir.com</a></li>
<li>Mark Ericksen on X - <a href="https://x.com/brainlid" rel="nofollow noopener">@brainlid</a></li>
<li>Mark Ericksen on Bluesky - <a href="https://bsky.app/profile/brainlid.bsky.social" rel="nofollow noopener">@brainlid.bsky.social</a></li>
<li>Mark Ericksen on Fediverse - <a href="https://genserver.social/brainlid" rel="nofollow noopener">@brainlid@genserver.social</a></li>
<li>David Bernheisel on Bluesky - <a href="https://bsky.app/profile/david.bernheisel.com" rel="nofollow noopener">@david.bernheisel.com</a></li>
<li>David Bernheisel on Fediverse - <a href="https://genserver.social/dbern" rel="nofollow noopener">@dbern@genserver.social</a></li>
</ul><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://paraxial.io/?utm_source=thinkingelixir&utm_campaign=thinkingelixir-oct2025">Paraxial.io</a>: <a rel="nofollow" href="https://paraxial.io/?utm_source=thinkingelixir&utm_campaign=thinkingelixir-oct2025">Paraxial.io is sponsoring today's show! Sign up for a free trial of Paraxial.io today and mention Thinking Elixir when you schedule a demo for a special offer.
</a></li></ul>