Shopify is turning off its old cross-merchant catalog REST API on November 2. The replacement is a UCP-compatible MCP server, not a renamed URL: agents must remap tools, payloads and saved-catalog identifiers.
Developers can now profile a deployed Worker or a specific Durable Object without reproducing production traffic locally. Captures require an active isolate and measure allocations during the capture window, not retained memory.
The consequential change in Formbricks 6 isn't its new charts: self-hosted operators need a separate authorization service, a maintenance window and verified migration before enabling v6 traffic. Existing follow-up automations also have a December deadline.
The important part of pg_vault_tde's 1.7.2 release is the operational migration: v4 rows can still be read after upgrade, but UPDATE can crash until they are rewritten.
A security fix for a widely used PostgreSQL vector extension makes index-build permissions and extension patching part of AI search infrastructure hygiene.
A follow-up security fix shows why wrapper capabilities need path restrictions as well as origin checks: tinyjs 0.48.0 now confines direct PDF writes and requires user confirmation for other locations.
PostgreSQL operators gain per-statement and per-transaction estimated-cost limits across versions 14–18, useful for runaway reports and ORMs. The guard is disabled by default and can be bypassed by users allowed to change planner cost parameters.
Effect 4 changes runtime architecture and maintenance guarantees, not just APIs. Its reported 5x smaller bundles and 86% lower fiber memory are vendor benchmarks requiring workload-specific validation.
Preact's long-awaited major release brings concrete rendering changes and a packaging break. Most modern projects should migrate easily, but old import paths and CommonJS tooling need attention.
The October release is more than a version bump: PHP server operators should patch document-root and header risks, then test worker/thread budgets and stricter proxy defaults before upgrading.
JPEG XL is leaving the experimental-browser niche. Chrome 155 now decodes it by default, but Edge, older installed browsers and Safari's partial feature set still require fallbacks.
The October major release simplifies SvelteKit's architecture but breaks familiar config files and legacy imports. Teams should run the codemod and verify adapters and deployments.
Fitbit API integrations have less than a month to migrate. The replacement changes authentication and API surface, while Google is still restricting onboarding for new Health API projects.
The October 6 release is broader than WordPress 7.1.2's single critical RCE fix: it closes seven separate core flaws, including stored XSS through pending comments, second-order SQL injection in WXR exports and unauthenticated disclosure of comments on private posts.
The useful part of Kanbanchi’s case is that it did not need a new product category or a giant ad budget. A 25-person bootstrapped team changed the economics and presentation of an existing product, made team savings visible and progressively moved its customer mix toward multi-seat accounts.
The migration is no longer an open-ended future plan. Reddit is killing RSS on November 13 and says remaining public API access ends by March 2027, giving bots, moderation tools, social-listening products and research integrations concrete deadlines.
Tailcat remains useful as a small encrypted peer-connectivity primitive, but its first documented malware adoption changes the operational context: Kothamine can use Tailcat to avoid a conventional command-and-control domain that defenders would otherwise block.
The exploitation signal has strengthened again: CISA added CVE-2026-87902 to KEV on September 25. That turns earlier vendor and security-company telemetry into formal U.S. government confirmation of in-the-wild exploitation.
The sharpest operational trap is CVE-2026-91768: PHP-FPM’s listen.allowed_clients can treat an allowed IPv6 address as an entire /96 prefix. Teams relying on that ACL should patch rather than assuming the configured address restriction is exact.