Stack news
Release notes and updates from the frameworks we build on. Filed straight from the wire, curated continuously.
Nuxt v4.5.1 Emergency Security Release: Patch Critical Server-Side RCE and DoS Vulnerabilities
Nuxt v4.5.1 fixes multiple severe security issues including server-side RCE, authorization bypass, and DoS; all users should upgrade immediately.
Nuxt v3.21.10 Security Release: Critical Patches for RCE, Authorization Bypass, and More
Nuxt v3.21.10 addresses multiple high-severity security vulnerabilities, including server-side RCE and unauthorized component instantiation, along with several important bug fixes.
FastAPI 0.140.1: Updated Dependency LRU Cache for Large Apps
FastAPI 0.140.1 bumps the LRU cache limit for dependency results to better support large-scale applications.
Cloudflare Reveals Widespread BGP ORIGIN Manipulation and Calls for Deprecation
Cloudflare's in-depth testing shows nearly 70% of BGP paths have their ORIGIN attribute rewritten by transit providers, undermining network security and performance.
FastAPI 0.140.0: Memory Optimization, Revamped Docs, and CI Benchmarks
FastAPI 0.140.0 reduces dependency memory usage, fixes documentation links, introduces a Library Skills page, and adds CI memory benchmarks.
Traefik v2.11.53: CONNECT Handling Fixes and CRD Field Addition
This patch release addresses critical CONNECT tunnel management issues and adds a missing field to Kubernetes CRDs.
Traefik v3.6.24: Critical CONNECT Proxy Fixes and CRD Alignment
Traefik v3.6.24 addresses several bugs around CONNECT request handling, HTTP middleware, and logs, plus documentation improvements for Kubernetes CRDs.
Traefik v3.7.9: Bug Fixes for CONNECT Handling and IngressNGINX Redirects
Traefik v3.7.9 addresses critical bugs in CONNECT request handling, Zstd support, and ingress-nginx redirects, along with documentation updates for Gateway API migration.
Cloudflare Cache Response Rules: Override Origin Caching Headers
Cache Response Rules let developers override origin Set-Cookie and Cache-Control headers at Cloudflare's edge, ensuring content isn't unnecessarily revalidated.
Agentic AI Needs Guardrails, Not Guesswork: Docker’s Security Panel Insights
Docker convened enterprise security leaders to discuss governing AI agents effectively without hindering developer velocity.
Docker Runtime Enforcement: From Advice to Isolation Policies for Agentic Systems
Docker announces runtime enforcement features for agentic systems, moving from mere advice to enforced isolation and policy controls at the runtime layer.
Vue 3.6.0-rc.2 Released: Performance Improvements and New Features
Vue 3.6.0-rc.2 is now available, bringing enhanced reactivity and a new compile-time optimization.