A maintainer nearly merged a dependency-bump PR that quietly edited his CI config to raid a self-hosted runner holding cloud credentials. Kai argues the pipeline belongs in your threat model: fork PRs are remote code exe…
A developer traces a recurring PostgreSQL bug: an index on customer_id existed but Postgres ran a sequential scan anyway because the query also sorted by created_at. A composite index cut runtime from four seconds to nin…
Zod v4.5 introduces schema compilation promising 3 to 9 times faster validation. The maintainer of zod-compiler responded with benchmarks showing his tool still outperforms Zod's native z.compile() by a median of 1.75x, …
The htmx project has published version 4.0.0, announced on its four.htmx.org site on August 28, 2026. htmx is a small JavaScript library that lets developers add AJAX requests, WebSockets and other dynamic page behavior …
Vercel has patched two critical vulnerabilities in Next.js with its August security release. One flaw in the libheif library enables heap buffer overflows during AVIF image optimization (CVSS 9.8), the other (CVE-2026-75…
A newly published paper on mold, the massively parallel linker, is drawing discussion on r/programming. Its ablation study finds that speed gains do not come from any single optimization, but from running every linking p…
Node.js 24.20.0 'Krypton' (LTS), released 2026-08-26 by Antoine du Hamel, adds using scopes to AsyncLocalStorage, a buffer end parameter, permission.drop, a --permission-audit flag, package maps in the loader, a node:str…
Kubernetes v1.37 ships today with SELinuxMount on by default. If your nodes run SELinux enforcing and two differently-labeled pods share a PVC, one of them stops starting. I think you should upgrade into that break rathe…
The Node.js project has published version 26.8.0 of its JavaScript runtime. The release is part of the current 26.x line and is available for download from the official Node.js distribution channels. Details on included …
Go 1.27 ships generic methods, a rebuilt JSON engine under the old API, stdlib UUIDs and post-quantum crypto, and Go folks are asking if their minimalist language just blinked. Kai argues PHP resolved this debate long ag…
GitHub's August 17 outage lasted seven hours and 47 minutes and hit authentication, repositories, pull requests and Copilot. CTO Vlad Fedorov's postmortem blames a traffic spike: monthly commits doubled since April to 2.…
A supply chain attack on a Rust crate has reignited debate about dependency culture. A widely discussed Reddit post argues that Rust shares the npm mindset of pulling in many small packages, and that languages with large…
Microsoft has published TypeScript 7.0.2, a patch release in the new 7.x major version line. The tag was originally created in the typescript-go repository and points to the TypeScript 7.0 announcement for details on the…
Bun 1.4 completes the runtime's rewrite from Zig to Rust, adds 1,517 newly passing Node.js test-suite tests, and cuts idle CPU usage by a factor of five. New built-ins include Bun.Image, Bun.WebView, Bun.cron and a nativ…
Attack attempts against CVE-2026-19478, a critical GitLab vulnerability patched in an out-of-band release on Monday, have been observed by security firm watchTowr. The flaw lets unauthenticated attackers delete projects …
GitLab has patched two vulnerabilities, one rated critical, that allow attackers to manipulate or delete public projects and user data via the GraphQL API. Fixed versions are 18.11.11, 19.0.8, 19.1.6 and 19.2.4. Self-hos…
A community piece previews the next major version of DuckDB, the in-process analytical database popular with data engineers. Worth a read for anyone running DuckDB in production or evaluating it, since a major version bu…
PostgreSQL's team released versions 14.24, 15.19, 16.15, 17.11 and 18.6, fixing 28 vulnerabilities. Most let attackers run arbitrary code after a successful attack and gain full control of instances. Two high-severity CV…
Buf has released LSP support for Protocol Buffers, bringing IDE features like completion, navigation and diagnostics to .proto files. The announcement, discussed on r/programming, also drew comments on Buf's pricing: 36 …
GitLab has published patch releases 19.2.2, 19.1.4 and 19.0.6 with important security fixes. Among the addressed issues are cross-site scripting vulnerabilities whose CVSS scores classify them as severe risks.
Ryan Dahl has released Durable Objects as open-source technology, decoupling them from Cloudflare's platform. This move enables developers to deploy stateful, globally-distributed computing workloads independently, expan…
A compromised AI development tool exposed terabytes of credentials from over 2,500 organizations including Microsoft, Amazon, Nvidia, and Salesforce. The attack affected 434,000 CI/CD pipelines during a 40-minute window …
PostgreSQL released four maintenance versions and one beta addressing 33 security vulnerabilities and numerous functional bugs. Key fixes include restrictions on logical decoding plugins, detection of unsupported ciphers…
Tailscale's investigation into data corruption issues led to the discovery of a long-dormant bug in SQLite's write-ahead log (WAL) checkpoint mechanism. A race condition during WAL reset under specific concurrent conditi…
Researchers at A Security used public AI models with fewer than 20 prompts to find Zoom vulnerabilities in the screen-sharing annotation protocol. The flaws, now patched, let any call participant silently hijack another …
A recent Medium piece walks through a classic Postgres outage: a trivial column addition stalls behind a long read and takes the whole table hostage. The fix is known, cheap, and almost nobody's default. I think that's o…
At Black Hat, runZero founder HD Moore presented over a dozen new vulnerabilities in baseboard management controllers from HPE, Supermicro, Dell, Lenovo, Huawei and others. Scans found more than half of 86,000 internet-e…
Node.js v26.7.0 is now available from the project's distribution channels. The release continues the v26 line of the JavaScript runtime, shipping the usual batch of fixes and dependency updates. Details on included commi…
Vercel has released Next.js 16.3, cutting Turbopack's RAM consumption in dev mode by up to 90 percent through disk caching and memory eviction. The release also adds Instant Navigations and an experimental Rust-based Rea…
Project Valhalla's JEP 401, covering value objects, is heading into JDK integration as a preview feature. Value objects aim to let Java developers declare identity-free, immutable class instances that the JVM can optimiz…