The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Wednesday, September 30, 2026 Vol. I — No. 679 · Page D2 € 0,00*  *as always

How a Mismatched PostgreSQL Index Turned a 40ms Query Into 4 Seconds ▶ D2

Zod 4.5 ships schema compilation, but zod-compiler still leads in benc… ▶ D2

htmx 4.0.0 Released ▶ D2

The Editorial!
Extra!read all about it

Your CI Runner Executes Strangers' Code, So Defend It Like Production

A maintainer nearly merged a dependency-bump PR that quietly edited his CI config to raid a self-hosted runner holding cloud credentials.

Kai argues the pipeline belongs in your threat model: fork PRs are remote code execution by invitation, containers only soften the blow, and per-job ephemeral machines plus short-lived scoped tokens are the setup worth copying.

▶ continued: summary & source

An editorial by Kai

SELinuxMount is the right call, and the pods it breaks were on borrowed time

Kubernetes v1.37 ships today with SELinuxMount on by default. If your nodes run SELinux enforcing and two differently-labeled pods share a PVC, one of them stops starting… ▶ D4

Releases: Node.js 26.8.0 released

The Editorial: Go 1.27 Settles a Fight PHP Finished Years Ago: Someone Must Carry the Weight

News: GitHub blames seven-hour August 17 outage on capacity limits amid AI-driven traffic surge

Reads: Supply Chain Attack on Rust Crate Sparks Debate Over Dependency Culture

Releases: TypeScript 7.0.2 Released as Patch Update

Releases: Bun 1.4 ships with Rust rewrite, big Node.js compatibility gains

Security: Critical GitLab GraphQL flaw already under attack, watchTowr reports

Security: Critical GitLab Flaw Lets Attackers Delete Projects

Reads: What to Expect From DuckDB's Upcoming 2.0 Release

Security: PostgreSQL patches 28 security flaws, two allow code execution

Reads: Buf ships language server support for Protobuf

Security: GitLab 19.2.2, 19.1.4 and 19.0.6 patch serious XSS flaws

Reads: Node.js Creator Open-Sources Durable Objects Beyond Cloudflare

Security: LiteLLM Supply-Chain Attack Exposes Credentials at 2,500 Organizations

Security: PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.6 Released with Major Security Fixes

Reads: Tailscale Engineering Uncovers 16-Year-Old SQLite Write-Ahead Log Race Condition

Security: AI-Assisted Bug Hunt Uncovers Zoom Screen-Sharing Flaw Enabling Device Takeover

The Editorial: No ALTER TABLE in Production Without a Lock Budget

Security: New research finds BMC flaws leave tens of thousands of servers open to backdoors

Releases: Node.js v26.7.0 Released

Releases: Next.js 16.3 Ships with up to 90% Lower Memory Usage and Instant Navigations

Reads: JEP 401 brings value objects as a preview feature to the JDK

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy