Critical Next.js flaws allow remote code execution, Windows servers affected
Vercel has patched two critical vulnerabilities in Next.js with its August security release. One flaw in the libheif library enables heap buffer overf… ▶ D2
Independent. Nonpartisan. Untested in production.
How a Mismatched PostgreSQL Index Turned a 40ms Query Into 4 Seconds ▶ D2
Zod 4.5 ships schema compilation, but zod-compiler still leads in benc… ▶ D2
htmx 4.0.0 Released ▶ D2
A maintainer nearly merged a dependency-bump PR that quietly edited his CI config to raid a self-hosted runner holding cloud credentials.
Kai argues the pipeline belongs in your threat model: fork PRs are remote code execution by invitation, containers only soften the blow, and per-job ephemeral machines plus short-lived scoped tokens are the setup worth copying.
An editorial by Kai
Vercel has patched two critical vulnerabilities in Next.js with its August security release. One flaw in the libheif library enables heap buffer overf… ▶ D2
A newly published paper on mold, the massively parallel linker, is drawing discussion on r/programming. Its ablation study finds that speed gains do n… ▶ D3
Node.js 24.20.0 'Krypton' (LTS), released 2026-08-26 by Antoine du Hamel, adds using scopes to AsyncLocalStorage, a buffer end parameter, permission.d… ▶ D4
Kubernetes v1.37 ships today with SELinuxMount on by default. If your nodes run SELinux enforcing and two differently-labeled pods share a PVC, one of them stops starting… ▶ D4
Releases: Node.js 26.8.0 released
The Editorial: Go 1.27 Settles a Fight PHP Finished Years Ago: Someone Must Carry the Weight
News: GitHub blames seven-hour August 17 outage on capacity limits amid AI-driven traffic surge
Reads: Supply Chain Attack on Rust Crate Sparks Debate Over Dependency Culture
Releases: TypeScript 7.0.2 Released as Patch Update
Releases: Bun 1.4 ships with Rust rewrite, big Node.js compatibility gains
Security: Critical GitLab GraphQL flaw already under attack, watchTowr reports
Security: Critical GitLab Flaw Lets Attackers Delete Projects
Reads: What to Expect From DuckDB's Upcoming 2.0 Release
Security: PostgreSQL patches 28 security flaws, two allow code execution
Reads: Buf ships language server support for Protobuf
Security: GitLab 19.2.2, 19.1.4 and 19.0.6 patch serious XSS flaws
Reads: Node.js Creator Open-Sources Durable Objects Beyond Cloudflare
Security: LiteLLM Supply-Chain Attack Exposes Credentials at 2,500 Organizations
Security: PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.6 Released with Major Security Fixes
Reads: Tailscale Engineering Uncovers 16-Year-Old SQLite Write-Ahead Log Race Condition
Security: AI-Assisted Bug Hunt Uncovers Zoom Screen-Sharing Flaw Enabling Device Takeover
The Editorial: No ALTER TABLE in Production Without a Lock Budget
Security: New research finds BMC flaws leave tens of thousands of servers open to backdoors
Releases: Node.js v26.7.0 Released
Releases: Next.js 16.3 Ships with up to 90% Lower Memory Usage and Instant Navigations
Reads: JEP 401 brings value objects as a preview feature to the JDK
All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy