€0.00 — free as in speechtonight's forecast: clear skies over production Cache: warm · Deploys: fair, 0% rollbacks expectedset by moonlight, shipped before dawn · deploy freely Page A1

The Daily Commit The Nightly Build

Dev news, typeset daily — PHP · AI · The Wider Stack

The developer's evening paper — PHP · AI · The Wider Stack

Motto of the dayMotto of the night

“PHP 8.6: the small release that fails your build for your own good.”

Thursday, September 10, 2026 Vol. I — No. 513 · Morning editionLate edition EN DE FR ES

PHP · The Lead · Releases

PHP 8.6.0beta3 ready for testing

The PHP project has tagged PHP 8.6.0beta3 — a pre-release of the upcoming 8.6 branch with 37 changelog entries across 18 components.

The PHP project has tagged PHP 8.6.0beta3, a pre-release build of the upcoming 8.6 branch. It is meant for testing, not for production: the 37 changelog entries across 18 components — among them BCMath, Core, CLI, DOM, Hash, Intl … — preview what 8.6 will ship.

Now is the time to run your applications and extensions against this build and report regressions upstream — every issue caught before GA saves the whole ecosystem an upgrade headache. The changelog so far is below; QA builds are available on qa.php.net.

continued: summary & source

PHP · Releases

Laravel 12.69.2 sets Cloud exit code default and fixes closure types

Laravel released v12.69.2, a patch on the 12.x branch. It sets a default memoryExceededExitCode for Laravel Cloud and corrects closure return types in withFreshQueryLog() and askWithCompletion(). The release is available on GitHub.

curated by Sönke


Ad — php-net.pro · in our own cause

Ad · php-net.pro

Reach 145,000+ PHP developers.

Sponsored posts on @php_net — the largest independent PHP account on X. From €399, booked online in minutes: write, preview, schedule, pay.

Book a post →

◇ this ad position rotates with every refresh · plus VAT where applicable


PHP · Security

Critical GiveWP flaw chains unserialize helper into unauthenticated RCE

CVE-2026-82222 affects GiveWP up to 4.16.7.1, a WordPress donation plugin with over 100,000 installs. An unauthenticated attacker can chain a registration bypass, a weak unserialize helper and a TCPDF gadget chain into remote code execution. CVSS 10.0. Update to 4.16.7.2 immediately.

curated by Sönke

PHP · RFC Watch

Vote Opens on PREG_THROW_ON_ERROR Flag for preg_* Functions

Voting has started on a PHP RFC that adds an opt-in PREG_THROW_ON_ERROR flag for preg_* functions. With the flag, PCRE errors surface as a \PregException instead of requiring preg_last_error() checks. The vote closes on 2026-09-18, with Tim Düsterhus among the early opponents.

curated by Georg

The Wider Stack

Dev · Releases

Node.js 26.8.2 updates Undici, OpenSSL and npm

Node.js 26.8.2 (Current), released 9 September 2026 by Antoine du Hamel, updates Undici to 8.10.2, OpenSSL to 3.5.8, npm to 11.19.1 and corepack to 0.36.0. The release also deprecates the internal Server.prototype._listen2 API in node:net and refines the security posture for experimental features.

curated by Sönke


Situations Vacant — PHP

live from the Job.bo index — toggle skills, filter by location or remote

Browse all 1135 PHP jobs → · Powered by Job.bo