Blog
Insights on software development, security, and technology from our team.

A Next.js OG-image bug can run code on your server. Patch to 16.3.6.
Vercel shipped an out-of-band Next.js update on September 22 to fix CVE-2026-94545, a critical remote code execution bug in the Node.js `ImageResponse` from `next/og`, scored CVSS 9.5. It only bites apps that feed visitor-controlled values into dynamic Open Graph images, but that describes most share-card setups. Here is who is exposed, why patching the framework alone may not be enough, and what to check today.

React 19.3 makes View Transitions stable. Turn on Trusted Types while you're there.
React 19.3 shipped on September 9, 2026, promoting View Transitions and Fragment Refs to stable and adding Trusted Types support and a use(browser()) escape hatch. Here's what web, security, and mobile teams should actually do with it.

React Compiler goes Rust, and Next.js 16.3 can already use it
The React team rewrote the React Compiler in Rust, and Vercel wired it into Turbopack. Next.js 16.3 reports 20 to 50% faster route compilation on the native path. We break down whether the experimental flag is worth flipping, and how to test it without risking production.

TypeScript 7.0 is 10x faster and written in Go. Here's how to adopt it without breaking CI.
Microsoft shipped the TypeScript 7.0 Release Candidate on June 18, 2026, and the big change is the compiler itself, now written in Go and roughly 10x faster than 6.0. It's a port rather than a rewrite, so the type rules stay the same. The smart move is to run it as a shadow CI job now and adopt it on your own schedule.

Next.js just patched 13 security advisories. Self-hosted teams have the most work.
Vercel shipped a coordinated security release on May 7: 13 Next.js and React Server Components advisories covering DoS, SSRF, cache poisoning, and middleware bypasses in App Router. Self-hosted teams running Node are hit hardest. The deeper takeaway: middleware was never an authorization boundary.

A Chrome zero-day is being exploited right now. Here's what your dev team should actually do.
CVE-2026-3910 targets Chrome's V8 JavaScript engine and is already being used in real attacks. It affects every Chromium-based browser your team uses. We break down what happened, why it matters beyond "just update Chrome," and the practical steps most teams are still skipping.
Laravel's AI SDK just dropped. So did six zero-days. Here's what matters.
Laravel shipped a first-party AI SDK with unified provider support and an Agent pattern. Meanwhile, Microsoft's February Patch Tuesday fixes six actively exploited zero-days. We break down what both mean for development teams right now.
Laravel just shipped a first-party AI SDK. Here's what it actually means for your team.
Laravel released its official AI SDK on February 5, giving PHP developers a unified way to work with OpenAI, Anthropic, Gemini, and others. We break down what matters, what to watch out for, and whether you should adopt it now.

Laravel ships an AI SDK, Apple opens Xcode to autonomous agents, and we have thoughts
This week Laravel released a first-party AI SDK that unifies multiple AI providers behind a single API. Days earlier, Apple dropped Xcode 26.3 with built-in support for autonomous coding agents from Anthropic and OpenAI. Here's what both moves mean for development teams.

When There's No Breaking News: What Development Teams Should Focus On Instead
Sometimes the biggest tech story is that there isn't one. Here's what your development team should prioritize when the news cycle goes quiet.

Symfony's Dual Release Strategy: Why Identical Features with Different PHP Requirements Changes Everything
Symfony 7.4 LTS and 8.0 launched simultaneously with identical features but different PHP requirements. This strategic shift forces teams to choose between long-term stability and modern performance.

The PHP Framework Wars Are Getting Interesting Again
Symfony 8.1 development is picking up steam while newcomer Doppar challenges the Laravel-Symfony duopoly. Here's what this means for development teams picking their next stack.