€0.00 — free as in speechtonight's forecast: clear skies over production Cache: warm · Deploys: fair, 0% rollbacks expectedset by moonlight, shipped before dawn · deploy freely Page A1

The Daily Commit The Nightly Build

Dev news, typeset daily — PHP · AI · The Wider Stack

The developer's evening paper — PHP · AI · The Wider Stack

Motto of the dayMotto of the night

“Will 10505 push 10454's NoSerialize into AI runtime governance?”

Tuesday, September 8, 2026 Vol. I — No. 501 · Morning editionLate edition EN DE FR ES

PHP · The Lead · Releases

Laravel 12.69.2 sets Cloud exit code default and fixes closure types

Laravel released v12.69.2, a patch on the 12.x branch. It sets a default memoryExceededExitCode for Laravel Cloud and corrects closure return types in withFreshQueryLog() and askWithCompletion(). The release is available on GitHub.

The Laravel team tagged v12.69.2 on the 12.x maintenance branch on September 8, 2026.

The patch contains three changes. Jack Bayliss added a default memoryExceededExitCode value for Laravel Cloud in PR #61432, so workers killed for exceeding memory limits now exit with a defined code. Sander Muller wrapped the closure return type in withFreshQueryLog() in PR #61458 and wrapped the autocompleter callback return type in askWithCompletion() in PR #61487, both corrections to the framework's type annotations.

The release is published on GitHub as an immutable tag. Projects on Laravel 12.x receive the fixes via a routine composer update.

continued: summary & source

curated by Sönke

PHP · Security

Critical GiveWP flaw chains unserialize helper into unauthenticated RCE

CVE-2026-82222 affects GiveWP up to 4.16.7.1, a WordPress donation plugin with over 100,000 installs. An unauthenticated attacker can chain a registration bypass, a weak unserialize helper and a TCPDF gadget chain into remote code execution. CVSS 10.0. Update to 4.16.7.2 immediately.

curated by Sönke


Ad — php-net.pro · in our own cause

Ad · php-net.pro

Reach 145,000+ PHP developers.

Sponsored posts on @php_net — the largest independent PHP account on X. From €399, booked online in minutes: write, preview, schedule, pay.

Book a post →

◇ this ad position rotates with every refresh · plus VAT where applicable


PHP · RFC Watch

Vote Opens on PREG_THROW_ON_ERROR Flag for preg_* Functions

Voting has started on a PHP RFC that adds an opt-in PREG_THROW_ON_ERROR flag for preg_* functions. With the flag, PCRE errors surface as a \PregException instead of requiring preg_last_error() checks. The vote closes on 2026-09-18, with Tim Düsterhus among the early opponents.

curated by Georg

PHP · News

PHP 8.5 Pipe Operator Ends Inside-Out Nesting

PHP 8.5's new pipe operator lets developers write chained function calls in execution order instead of nested inside-out. The syntax compiles to the same opcodes as traditional calls, so there is no runtime cost. Multi-argument functions still need arrow function wrappers.

curated by Georg

PHP · Releases

FrankenPHP 1.12.7 Fixes Lost Output After finish_request()

FrankenPHP 1.12.7 is out. The patch release fixes a classic-mode bug where output sent after fastcgi_finish_request() was silently dropped, corrects a thread-count metric, tones down client-disconnect logging, and removes an opcache restart hook that could trigger recursive restarts.

curated by Sönke

The Wider Stack

Dev · Security

Actively Exploited V8 Flaw Puts Every Chromium App and Electron Tool at Risk

CVE-2026-85046, a type confusion bug in Chrome's V8 engine, is being exploited in the wild via a single crafted HTML page. Google patched it in Chrome 152.0.7977.82 on September 3, 2026; CISA added it to its Known Exploited Vulnerabilities list a day later. The flaw also threatens Electron apps and …

curated by Sönke


Situations Vacant — PHP

live from the Job.bo index — toggle skills, filter by location or remote

Browse all 991 PHP jobs → · Powered by Job.bo