Dev Weekly roundup for May 11 to 17, 2026. The TanStack npm supply chain attack on May 11 compromises 42 @tanstack/* packages with 84 malicious versions in a six minute window, signed using legitimate OIDC trusted publishing, and reaches OpenAI's internal source code repos, forcing a Mac code signing rotation with a June 12 update deadline for ChatGPT Desktop users. Microsoft Patch Tuesday on May 12 ships 137 fixes with 13 rated critical and no zero days under active exploitation, including Netlogon RCE CVE-2026-41089 and DNS Client RCE CVE-2026-41096. Anthropic opens talks on May 12 to raise at least 30 billion dollars at a valuation above 900 billion dollars, ahead of an expected end of May close. Google holds The Android Show I/O Edition on May 12 and unveils Gemini Intelligence on Android, Create My Widget vibe coded widgets, Rambler in Gboard, Adobe Premiere on Android, and the Googlebook AI native laptop line. Cursor 3.4 ships May 13 with cloud agent dev environments, multi repo support, build secrets, Dockerfile config, 70 percent faster layer caching, version history rollback, and audit logs. Cursor Bugbot Effort Levels land May 11. Claude Code v2.1.139 arrives May 11 with the Agent view, the /goal command, the /scroll-speed setting, and CLAUDE_PROJECT_DIR for MCP stdio servers. Anthropic launches Claude for Small Business on May 13 with 15 ready to run agentic workflows for finance, HR, marketing, and ops. OpenAI launches Daybreak on May 11 with Codex Security and three GPT-5.5 tiers including GPT-5.5-Cyber, plus the OpenAI Deployment Company with over 4 billion dollars committed, the Tomoro acquisition, and 19 partner firms. OpenAI brings Codex to the ChatGPT mobile app on May 14 with Hooks, Remote SSH, and HIPAA support. Microsoft cancels Claude Code licenses inside Experiences and Devices and moves engineers to GitHub Copilot CLI by June 30. Microsoft Security ships its MDASH multi model agentic security system on May 12. GitHub introduces Copilot Pro, P