
FeaturedPatch nowJS & TypeScript
Next.js 16.3.6 fixes a critical remote code execution flaw in next/og
The September 22 release fixes a critical RCE in the Node.js ImageResponse of next/og. Versions 16.2.0 up to 16.3.5 are affected.
Karlen Trimino ·
Every story Web Programming has published, newest first, each with its primary sources.

FeaturedPatch nowJS & TypeScript
The September 22 release fixes a critical RCE in the Node.js ImageResponse of next/og. Versions 16.2.0 up to 16.3.5 are affected.
Karlen Trimino ·

Patch nowPHP & Laravel
CVE-2026-17543 (High) is an SQL injection in pg_insert, pg_update, pg_select and pg_delete. It was fixed in the July 30 releases.

Patch nowJS & TypeScript
The July 29 security releases (26.5.1, 24.18.1, 22.23.2) fixed 11 CVEs, three of them rated High.

PlanJS & TypeScript
npm v12 became the default on July 8. Dependency lifecycle scripts, Git dependencies and remote URL dependencies are now opt-in.

PlanJS & TypeScript
TypeScript 7.0, the native port written in Go, shipped July 8. It has no stable programmatic API yet, and its new defaults change your tsconfig.

PlanPHP & Laravel
Laravel 12 stopped receiving bug fixes on August 13, 2026. Laravel 13 supports PHP 8.3 to 8.5, with security fixes until March 17, 2028.

WatchPHP & Laravel
RC1 lands on September 24 and general availability on November 19. Leave ? or ... in place of arguments and you get a closure back.

Patch nowPHP & Laravel
Versions 2.10.2 and 2.10.3 fixed a run of CVEs, from path traversal through package bin paths to command injection through malicious Perforce URLs.

Patch nowPHP & Laravel
Three framework advisories landed this summer, including a High-severity CRLF injection in the default email validation rule.

PlanJS & TypeScript
An attacker chained a pull_request_target workflow into 84 malicious TanStack versions, and a worm planted persistence in editor and AI tool config.