Hello Here is the latest OCaml Weekly News, for the week of July 14 to 21, 2026. Table of Contents ───────────────── ocamlgrep 0.1.1 MirageOS on Unikraft ppx_deriving_melange 0.1.0 - eq, ord, show, map, iter derivers for Melange hegel 0.12.1 A small extension of Bigarray.Genarray adding iteration, mapping and folding OCaml Security Team, report for first half of 2026 Dune Package Management Updates opam 2.6.0~alpha1 The little type that could too much Old CWN ocamlgrep 0.1.1 ═══════════════ Archive: Nicolas Ojeda Bar announced ─────────────────────────── We are happy to announce the first public release of `ocamlgrep', a tool for structural grepping of OCaml code. This tool has existed within the walls of LexiFi for a long time and we were keen on open-sourcing it, but it was not in a form that could be used by the wider public. Now, thanks to the work of @mjambon, we are able to to finally do so. To install: ┌──── │ $ opam install ocamlgrep └──── The idea behind the tool is simple: you call it from within your Dune project[^1] with a query (after having built all `.cmt~/'.cmti~ artifacts, eg by doing `dune build @check'), and the tool returns the list of matches it can find in the source tree. A _query_ is syntactically an OCaml expression, possibly with _holes_ `__' in it. Some examples follow to give an idea of how the tool is used in practice. The following query searches for the anti-pattern `List.rev e1 @ e2' (where `e1' and `e2' are arbitrary expressions. ┌──── │ $ ocamlgrep 'List.rev __ @ __` └──── NoteNote that as the tool works at the level of the OCaml AST, it will also match expressions of the form `(@) (e1 |> List.rev) e2', since they produce the same AST. The syntax of type constraints `(e : ty)' is overloaded to impose a type condition on the search term. For example, the following search query looks for function calls where the first argument is an `int' and the second one a `string'. ┌──── │ $ ocamlgrep '__ (__ : int) (__ : string)' └──── The _holes_ can be numbered, `__1', `__2', etc, to express repetitions of the same term. For example, the following query searches for a pattern matching on an option that sends `Some x' to `Some x' (ie reconstructing the same value): ┌──── │ $ ocamlgrep 'match __ with Some __1 -> Some __1 | None -> __' └──── We can also look for applications of the polymorphic operator `=' applied to `float' arguments: ┌──── │ $ ocamlgrep '(__ : float) = __' └──── Historically, this tool has been useful for large-scale refactorings and linting of our codebase. Nowadays, such refactorings can often be done using AI agents. However, the tool is still able to do things that seem a bit beyond of what AI agents can do today, eg to look for applications of polymorphic functions where one of the arguments is of a specific type. This was for example useful when [migrating] our codebase to `no-flat-float-array' mode, where we wanted to make sure that polymorphic array operations were not being applied to `float array' values. Happy grepping! Cheers, Nicolas [^1]: Only Dune projects are supported for now. Adding support for other build systems should not be very hard, issues and/or PRs are welcome. [migrating] MirageOS on Unikraft ════════════════════ Archive: Continuing this thread, shym announced ────────────────────────────────────── I’m happy to announce that OCaml/Unikraft 1.2.0 [has been released] with: • support for OCaml 5.4.1 and 5.5.0, • a way to use fine-tuned Unikraft configurations when that’s needed, • a new version number scheme for some of the packages, to combine the OCaml/Unikraft version with the underlying Unikraft version. Happy unikerneling! [has been released] ppx_deriving_melange 0.1.0 - eq, ord, show, map, iter derivers for Melange ══════════════════════════════════════════════════════════════════════════ Archive: Atlas07 announced ───────────────── Hi everyone, I'm happy to announce the first release of *ppx_deriving_melange*, a Melange-compatible subset of `ppx_deriving': Why ╌╌╌ The original `ppx_deriving' can't support Melange: it predates dune's Melange integration — it is distributed through findlib META files, and its generated code depends on a runtime library that isn't built in Melange mode. Melange can only link libraries that dune builds for it, so common patterns like `\[@@deriving eq, show\]' were off the table when writing frontend OCaml. `ppx_deriving_melange' fills that gap: same derivers, same naming conventions and attributes, implemented on ppxlib and tested against Melange — and its generated code is self-contained, so nothing extra needs to link into your bundle. A key use case is *universal code* — libraries compiled both natively and to JavaScript. Put your shared types in a library with `(modes :standard melange)', derive once, and the exact same `equal~/~compare~/~show' functions run on the server and in the browser. (This is how the project tests itself: one test-case library exercised by OUnit natively and by node on the Melange side.) What you get ╌╌╌╌╌╌╌╌╌╌╌╌ ┌──── │ type user = { │ │ name : string; │ │ roles : string list; │ │ } │ │ [@@deriving eq, ord, show] │ │ │ │ (* generates: │ │ val equal_user : user -> user -> bool │ │ val compare_user : user -> user -> int │ │ val pp_user : Format.formatter -> user -> unit │ │ val show_user : user -> string *) └──── Supported derivers in 0.1.0: `eq', `iter', `map', `ord', and `show', following the native `ppx_deriving' conventions — including the `equal', `compare', and `printer' attribute overrides, the `with_path' option for `show', tuples, records, (polymorphic) variants, options, lists, arrays, results, type parameters, and recursive type groups. The README documents the exact supported scope of each deriver. Two design points worth calling out: • *Self-contained generated code.* There is no runtime library: the generated functions only use the stdlib, so the ppx is a build-time dependency only. • *Bundle-size-aware `show'.* Melange compiles `Stdlib.Format' into a lot of JavaScript, so `show' builds its string directly and only falls back to `Format' where the type requires it (custom printers, etc.). Code that only calls `show' doesn't pull Format into your bundle; `pp' stays fully Format-based and native-compatible. What's not there (yet) ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ Some `ppx_deriving' derivers aren't implemented yet (`enum', `fold', `make', …), and a few type shapes are out of scope for now (`ref', `lazy_t', `nativeint', functor-applied types). If you need one of these — or hit anything that behaves differently from native `ppx_deriving' — please open an issue; that's exactly the feedback that will drive what gets built next. Using it ╌╌╌╌╌╌╌╌ ┌──── │ opam install ppx_deriving_melange └──── ┌──── │ (library │ │ (name my_frontend_lib) │ │ (modes melange) │ │ (preprocess │ │ (pps ppx_deriving_melange))) └──── Thanks to the `ppx_deriving' authors — this project follows their design and behavior closely, and includes their license attribution — and to [davesnx] for reviews and encouragement along the way. Feedback, issues, and deriver requests very welcome! [davesnx] hegel 0.12.1 ════════════ Archive: Ethan Chou announced ──────────────────── Hello! I work at [Antithesis], a deterministic simulation testing startup. Recently, we released Hegel for OCaml. Hegel is a family of PBT libraries based on Hypothesis, providing powerful, ergonomic property-based testing for many different languages. Hegel lets you declare data generation inline with your test code, and provides native support for stateful testing. The installation instructions can be found at the Github repository [here]. Click on the link in the about section in the repository to see the documentation sorry, I can't post more than two links yet). We encourage people to contribute! Here's an example Hegel test: ┌──── │ let bad_map _ xs = xs │ │ let%hegel_test bad_map_vs_map tc = │ let int_gen = integers () in │ let int_fn_gen = functions ~sexp_of_arg:Core.Int.sexp_of_t ~returns:int_gen () in │ let f = draw_silent tc int_fn_gen │ and xs = draw tc (lists int_gen ()) in │ require_equal │ tc │ (Core.List.sexp_of_t Core.Int.sexp_of_t) │ (bad_map f xs) (List.map f xs) └──── prints (with colors in the terminal): ┌──── │ --- Failure: bad_map_vs_map (examples/higher_order.ml:20) -------------- │ Falsified after 2 test cases (0 discarded): │ │ xs = (0) │ f 0 = 1 │ require_equal: values differ (- lhs / + rhs): │ (0) (1) │ │ Exception: Failure("require_equal: values differ") │ rerun with: [@@failure_blobs [ "AAQAAAABAQAKAQAAAAABAAAKAQAAAAE=" ]] └──── Happy testing! [Antithesis] [here] A small extension of Bigarray.Genarray adding iteration, mapping and folding ════════════════════════════════════════════════════════════════════════════ Archive: Continuing this thread, NAlec announced ─────────────────────────────────────── Just to let you know, it is now available as [GenArrayIter] opam package. PR welcome of course. Documentation [here] [GenArrayIter] [here] OCaml Security Team, report for first half of 2026 ══════════════════════════════════════════════════ Archive: Hannes Mehnert announced ──────────────────────── Throughout the first half of 2026, the security team has worked on security advisories: the publishing pipeline (from report over communication and fixes, to the security vulnerability database - these days osv.dev and CVE). The team consists of: • Hannes Mehnert - @hannesm - individual, robur.coop • Mindy Preston - @yomimono - individual • Joe - @cfcs - individual • Edwin Török - @edwintorok - individual, Tarides • Nicolás Ojeda Bär - @nojb - LexiFi • Louis Roché - @Khady - ahrefs • Boning Dong - @bn-d - Bloomberg Vulnerability Database ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ The public vulnerability database () is established, and filled as well with old security advisories (from the MirageOS project, etc.). There is tooling via CI which generates a branch "generated-osv", which is a source for the Open Source Vulnerability database (), run by Google. The direct link for all security advisories of the OCaml Security team is [here]. The tooling is available from . [here] Audit Tooling ╌╌╌╌╌╌╌╌╌╌╌╌╌ Another utility to check your "opam switch" for installed vulnerable packages (using the above mentioned vulnerability database), has been developed - available at . Public Meetings ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ On March 19th a public OCaml security meeting took place with 10 attendees. The meeting notes are available at Modification Policy of the opam-repository ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ The Security Team proposed to make the immutability policy stricter (see ) - which has been merged. So, any published opam package must not modify its sources (change tarball, add patches, modify build instructions, …). Instead, a new version must be published. This makes the package URL () sensible and point to a precise source. Grant Proposals ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ A call for contributions was opened until end of March 2026. The Security Team is impressed by the amount and quality of the proposals. Evaluation and finding funding for proposals is still ongoing. We have some preliminary decisions and will reach out to the applicants by the end of July 2026. Advisories ╌╌╌╌╌╌╌╌╌╌ So far, there have been 10 advisories (OSEC-2026-01 until OSEC-2026-10) published, and some more are worked on. Our primary communication channel is email, and we reach out to reports that we received GitHub by email. A [public mailing list] is available where security advisories are announced. They range from issues in the OCaml runtime (Marshal buffer over-read OSEC-2026-01 CVE-2026-28364, Bigarray.reshape interger overflow OSEC-2026-04 CVE-2026-34353, command injection on Windows via filename OSEC-2026-05 CVE-2026-41083), opam sandbox escape (OSEC-2026-03 CVE-2026-41082, OSEC-2026-10 CVE-2026-57825), insufficient certificate property checks (in tls, OSEC-2026-06 CVE-2026-45388, OSEC-2026-07 CVE-2026-45389), path traversal (in tar, OSEC-2026-08 CVE-2026-45390), memory exhaustion (unbounded memory usage in arp, OSEC-2026-02, infinite loop in albatross-console, OSEC-2026-09). The variety of reporters - 8 different people in 10 reports - is amazing. Thanks to all reporters, as well as the upstream developers. It has been a pleasure to coordinate the vulnerabilities. [public mailing list] Future Plans ╌╌╌╌╌╌╌╌╌╌╌╌ The Security Team also hopes to publish security guides for OCaml programmers and project maintainers. Acknowledgements ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ The Security Team is an initiative of the OCaml Software Foundation and is grateful to the OCSF and its sponsors for their support. Dune Package Management Updates ═══════════════════════════════ Archive: Continuing this thread, Shon announced ────────────────────────────────────── Hello! We have just made our roadmap for dune package management available on the wiki for dune: . About the roadmap ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ This living document aims to set out and explain the current status and the planned trajectory of our ongoing work. It should help to convey both what what we are working on and why we think it is important. It is not heavy on technical details, but aims to give a high level view of the project trajectory. For technical details, please click thru to the tracking issues: they are are in varying stages of discovery, but some are very well developed or provide a view into the history of completed work on the milestone. We will keep this document up to date and it will be revised as needed, to keep our projections in line with our emerging understanding, and to incorporate feedback and guidance from interested stakeholders. Support for the relocatable compiler in dune package management is now available in dune 3.24 ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ As you will see on the roadmap, a substantial course of work led by @Alizter, and supported by @ElectreAAS (among others), has made the relocatable compiler available by default in dune package management, building on even more substantial prior work by @dra27's. This makes use of David's overlay compiler packages to provide relocatability for previous recent compiler versions. In my personal experience, this has made a decisive improvement in the the UX of setting up projects with dune package management, and came along with many additional fixes improving opam package compatibility. As a very welcome bonus, dune package management now supports the installation of packages that use symlinks in their sources! Input and contributions ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ Please feel free to share any input or raise any questions! Input can be shared in this thread, or through our [documented channels for feedback]. [documented channels for feedback] opam 2.6.0~alpha1 ═════════════════ Archive: Kate announced ────────────── Hi everyone, We are happy to announce the first alpha release of opam 2.6.0. This is the culmination of 2 years of team work requiring large internal changes, we hope you'll enjoy it. This version is an alpha, we invite users to test it to spot previously unnoticed bugs as we head towards the stable release. What’s new? Some highlights: ╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌ • :money_bag: For people using the shell hooks, this release changed the way `PATH' is kept up-to-date from opam taking priority over any other elements of `PATH' by making sure to always be in front, to replacing the directory managed by opam in-place, keeping the order asked by the user. To benefit from this, make sure `opam init --reinit -ni' was ran once after upgrading to this version (automatically done by our install script if it detects an existing opam installation). ([#6859], [#6815]). /Thanks to [@gridbugs] for this contribution./ • :wastebasket: Reduce the disk space usage of opam by removing the `build' directory as soon as possible and removing redundant archive caches. While the disk usage used by opam can be reduced over time while simply reinstalling packages, you can liberate some free GB in one go using `opam clean --all-switches'. ([#6440], [#4056], [#5448]) • :high_speed_train: Improve performance drastically on certain file-systems (e.g. NTFS on Windows or IO constrained machines) by changing the format HTTP repositories such as opam.ocaml.org are stored in internally. ([#6625], [#5346], [#5741], [#5648], [#5484], [#5559], [#3050], [#6974]). • :envelope_with_arrow: Add `root' and `rootexec' sections to `.install' files to install files from the root prefix ([#6938], [#6919]). *Thanks to [@WardBrian] for this contribution.* • :woman_technologist: Add a new `--ignore-available-on' argument to allow ignoring the `available:' field of certain packages ([#6836], [#5283]). *Thanks once-again to [@WardBrian] for this contribution.* • :ocean: Many more UI additions and improvements, bug fixes, … :open_book: You can read our [blog post] for more information about these changes and more, and for even more details you can take a look at the [release note] or the [changelog]. [#6859] [#6815] [@gridbugs] [#6440] [#4056] [#5448] [#6625] [#5346] [#5741] [#5648] [#5484] [#5559] [#3050] [#6974] [#6938] [#6919] [@WardBrian] [#6836] [#5283] [blog post] [release note] [changelog] Try it! ╌╌╌╌╌╌╌ The upgrade instructions are unchanged: For Unix systems ┌──── │ bash -c "sh <(curl -fsSL https://opam.ocaml.org/install.sh) --version 2.6.0~alpha1" └──── or from PowerShell for Windows systems ┌──── │ Invoke-Expression "& { $(Invoke-RestMethod https://opam.ocaml.org/install.ps1) } -Version 2.6.0~alpha1" └──── Please report any issues to the [bug-tracker]. Happy hacking, <> <> The opam team <> <> :camel: — /Special thanks to the Haematology department and Bone Marrow Transplant Unit of the NHS Greater Glasgow for making this release possible <3/ [bug-tracker] The little type that could too much ═══════════════════════════════════ Archive: Raphaël Proust announced ──────────────────────── I wrote a small blog post about how some types are intended for multiple use cases and it's not always grerat. It uses the Stdlib as a small example in the intro, but the real focus is on Lwt. Feedback (on the post or on the points of Lwt that are discussed) is very welcome. I'll probably start working on improving the Lwt bits soon so let me know what you think. Old CWN ═══════ If you happen to miss a CWN, you can [send me a message] and I'll mail it to you, or go take a look at [the archive] or the [RSS feed of the archives]. If you also wish to receive it every week by mail, you may subscribe to the [caml-list]. [Alan Schmitt] [send me a message] [the archive] [RSS feed of the archives] [caml-list] [Alan Schmitt]