JPEG XL is leaving the experimental-browser niche. Chrome 155 now decodes it by default, but Edge, older installed browsers and Safari's partial feature set still require fallbacks.
The October 6 release is broader than WordPress 7.1.2's single critical RCE fix: it closes seven separate core flaws, including stored XSS through pending comments, second-order SQL injection in WXR exports and unauthenticated disclosure of comments on private posts.
Buttondown’s 'Great Pruning' is a small-SaaS operations story about deleting architecture rather than adding it. The company removed duplicated or over-retained request and email-event data after changing how those workloads were processed.
The pricing change is also a packaging change: beehiiv is charging more for paid tiers while putting newsletters, websites, podcasts, community and digital products across the plan family and extending self-serve scale.
The ruling does not decide whether AI Overviews hurt publisher traffic or whether reuse of publisher content is fair. It narrows one legal route for challenging that shift: these complaints did not turn the search-for-content relationship into an antitrust agreement, and the court said broader economic dislocation is a question for lawmakers.
Brazilian customers can authorize Pix Automático mandates for Paddle subscriptions without a separate early-access application. The path broadens local-payment access for SaaS, while delayed renewals, fixed mandate amounts and re-authorisation requirements still create implementation caveats.
The replacement is not a drop-in path rename: Cloudflare separates domain search, availability checks and registration operations into newer endpoints, so old registrar automation can break after the cutoff.
The sharpest operational trap is CVE-2026-91768: PHP-FPM’s listen.allowed_clients can treat an allowed IPv6 address as an entire /96 prefix. Teams relying on that ACL should patch rather than assuming the configured address restriction is exact.
Theme developers using Shopify CLI 3.83.x and older against password-protected storefronts are now past the documented cutoff. Shopify requires 3.84.0 or later for these flows; the live changelog's September 23 date supersedes the earlier October 1 deadline in this dossier.
This was not a Firecracker escape or access to a live victim disk. It was a storage-isolation failure underneath the sandbox: researchers recovered foreign directory structures, database pages and complete SQLite databases from reused blocks, and Cloudflare had to fix allocation plus retire existing disks and cached snapshots.
The useful change is not another reporting dimension. GA properties can now discard events whose hostname is not approved, directly addressing Measurement-ID abuse and ghost traffic while reducing the maintenance burden of chasing new spam domains.
GitHub’s credential-response story now has both discovery and containment: enterprise owners can export SSH keys, PATs, OAuth and GitHub App tokens with ownership, scope and last-use metadata, then use selective revocation rather than invalidating every credential a user holds.
Google must build Prebid integrations, let rival publisher ad servers receive real-time AdX bids, make publisher data portable and stop preferential AdWords bidding under a six-year court-supervised remedy.
The useful change is operational rather than a new PostgreSQL feature: Railway is packaging major-version migration into a managed workflow while keeping the two dangerous boundaries explicit — downtime during the upgrade and post-upgrade writes lost if you revert.
The interesting change is security economics rather than another hosting feature. A control that previously sat behind a $150/month add-on is now free across plans, changing the cost boundary for private dashboards, internal tools and pre-launch production domains.
The interesting change is architectural rather than another storage feature: migration becomes a server-to-server transfer initiated through an S3-compatible PutObject or UploadPart call, with range and multipart support for large objects.
The useful change is where enforcement happens. Teams can now make unresolved leaked credentials a branch-policy failure, with organization and enterprise rollout plus API configuration for large repository fleets.
The useful shift is automation at the CDN-to-origin boundary: operators no longer need to manually force post-quantum key exchange, while Cloudflare says its measured HelloRetryRequest rate fell from about 52% to 3.7% across the scanned cohort.
The interesting change is not another desktop-shell release. Noctalia has moved plugin logic away from the older QML-centric model into isolated scripting runtimes, creating a clearer extension boundary while still treating plugins as trusted code.
The release consolidates several recurring cluster-management jobs into core APIs and controllers. HPA scale-to-zero is now default-on Beta, storage-version migration and Pod Certificates are Stable, DRA can satisfy existing extended-resource requests, and large etcd reads gain a streaming path that reduces peak memory pressure.