Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path high
vulnerability · GHSA-9f4c-93c8-jc8g · osv.dev · Aug 5
Daily issue
260 items · compiled overnight
vulnerability · GHSA-9f4c-93c8-jc8g · osv.dev · Aug 5
vulnerability · GHSA-v3j7-r9gq-3gjw · osv.dev · Aug 5
vulnerability · GHSA-h7rp-cf8h-j98x · osv.dev · Aug 5
vulnerability · GHSA-89xv-2m56-2m9x · osv.dev · Jul 22
vulnerability · GHSA-p9j2-gv94-2wf4 · osv.dev · Jul 22
vulnerability · GHSA-6gpp-xcg3-4w24 · osv.dev · Jul 22
vulnerability · GHSA-m99w-x7hq-7vfj · osv.dev · Jul 22
vulnerability · GHSA-f88m-g3jw-g9cj · osv.dev · Jul 21
vulnerability · GHSA-gcfj-64vw-6mp9 · osv.dev · Jul 20
vulnerability · GHSA-26hh-7cqf-hhc6 · osv.dev · May 11
vulnerability · GHSA-mg66-mrh9-m8jx · osv.dev · May 11
vulnerability · GHSA-c4j6-fc7j-m34r · osv.dev · May 11
+59 more in this section
Anthropic is introducing Claude Sonnet 5, delivering improved performance for coding, agents, and professional work at scale. This is a new model release for the Sonnet tier, offering enhanced capabilities for your AI-powered applications.
model · anthropic.com
Anthropic is introducing Claude Opus 5, a significant improvement for long-running agents and professional work, including coding. This is a new model release for the Opus tier, potentially offering enhanced capabilities for your AI-powered applications.
model · anthropic.com
The Claude API TypeScript SDK has been updated to version 0.122.0. This release removes beta headers for file and skill operations, standardizing them with the non-beta endpoints and renaming BetaSkill to BetaContainerSkill, which may require minor adjustments in code that uses these specific beta features.
release · platform.claude.com
Anthropic is investigating degraded performance affecting Claude.ai, Claude Code, and Claude in Slack. This impacts the availability and responsiveness of the AI services he relies on for development tasks.
incident · status.claude.com · Aug 31
Claude Code v2.1.251 introduces PreModelSwitch and PostModelSwitch hooks, live streaming of tool calls for foreground subagents, and a spend limit bar in the usage interface. These features enhance control and visibility for developers using Claude Code.
release · github.com · Aug 28
Claude Code v2.1.248 adds a `--restricted` mode for enhanced security, experimental per-agent prompt cache TTL, and a self-hosted runner command. These features offer more control over execution environments and caching.
release · github.com · Aug 27
Cognizant and Anthropic are expanding their partnership to bring Claude to enterprise clients. This signifies growing adoption and integration of Anthropic's AI in business solutions, which could lead to more robust enterprise-focused features and support in the future.
model · anthropic.com
Claude.ai experienced degraded performance and elevated errors on August 31st, which have since been resolved. This may have impacted the availability of Claude models for API usage.
incident · status.claude.com · Aug 31
Claude Code and Claude Cowork on the web experienced elevated errors on August 28th due to an upstream cloud provider issue, which has been resolved. This could have temporarily affected access to Claude Code.
incident · status.claude.com · Aug 28
The Anthropic SDK for TypeScript has been updated to v0.122.0. This release promotes files/skills namespaces to General Availability, drops dated beta header pins, and includes bug fixes for cross-realm DOMException classification and SSE parse errors. It also improves forward compatibility for sessions and file view ranges.
release · github.com · Aug 27
Claude Code v2.1.247 introduces a SendFeedback tool for easier error reporting, customizable spinner tips, and an improved tip for Bash permission prompts. These updates aim to improve user experience and feedback mechanisms.
release · github.com · Aug 26
The Bedrock SDK for TypeScript has been updated to v0.33.2. This release fixes a bug where ambient first-party credentials were mistakenly sent to the Mantle endpoint.
release · github.com · Aug 26
+6 more in this section
This item indicates a potential breaking change or significant update related to Claude Code Opus 5's auto mode. Given the developer's use of Claude Code and the Anthropic API, this warrants attention for potential impacts on their AI-driven development workflows.
blog · simonwillison.net · Aug 27
OpenAI is winding down its contract to provide models to Cursor following Cursor's acquisition by SpaceX. This is a notable event for developers who might have used Cursor, as it signifies a shift in OpenAI's partnership strategy.
model · openai.com · Aug 28
OpenAI's ChatGPT Ads have reached $1 billion in annualized revenue run rate and are expanding globally. This indicates significant commercial traction and broader access to AI through free and affordable options, though it doesn't directly impact the developer's stack.
model · openai.com · Aug 31
This article discusses how even the rumor of a bug can be enough to trigger security exploits, highlighting the importance of prompt patching and robust security practices. While not directly impacting a specific package, it serves as a general reminder for developers to stay vigilant about potential vulnerabilities across their stack.
blog · simonwillison.net · Aug 28
This item refers to Qwen3.8-Flash-Next, likely a new or updated AI model. While the developer uses Claude, staying aware of advancements in other large language models can provide context and potential future alternatives or integrations.
blog · simonwillison.net · Aug 26
The article highlights how loveholidays uses OpenAI Codex to empower non-developers to build software, speeding up product development. This showcases a use case for AI in development but doesn't directly relate to your stack's core technologies.
model · openai.com · Aug 26
OpenAI is sharing insights from the Hugging Face security incident and outlining steps to improve AI model security. This is a general AI security topic and does not directly affect your specific stack or Claude's security.
model · openai.com · Aug 26
OpenAI's CFO discusses the 'full stack' behind abundant intelligence, covering advances in chips, compute, models, and products. This provides a high-level overview of AI infrastructure and scaling, relevant to the broader AI landscape but not your immediate stack.
model · openai.com · Aug 25
OpenAI has developed 'Jalapeño,' a custom inference chip designed for faster and more power-efficient AI inference. This is a significant hardware development in the AI space, but it does not directly impact your software development stack.
model · openai.com · Aug 25
Anthropic has introduced a new hardware standard for AI agents to control physical devices and communicate with each other. This is a significant development in AI agent capabilities and could be relevant to future AI integrations, especially given the developer's use of Anthropic's API.
blog · arstechnica.com · Aug 27
A lawsuit alleges that Elon Musk's xAI used child pornography to train its Grok models. This is a serious accusation against an AI company and is relevant due to the developer's work with AI, though it does not directly impact his stack's functionality.
blog · arstechnica.com · Aug 27
This GitHub blog post shares lessons learned on evaluating Large Language Models (LLMs) before production, specifically for secret scanning. This is highly relevant as the developer works with LLMs and Anthropic's API, offering practical insights for production deployment.
blog · github.blog · Aug 25
Hackers claim to have stolen millions of patient records from healthcare giant McKesson. This is a major data breach in the healthcare sector, but it does not directly affect the developer's technology stack.
blog · techcrunch.com · Aug 31
Clipto, a startup using AI to search video content, has raised $15 million at a $250 million valuation, reaching profitability. While it uses AI, the specific application and business model are not directly related to your current development stack.
blog · techcrunch.com · Aug 31
AI's growing effectiveness in finding vulnerabilities could make it harder for governments to use hacking tools, potentially leading to increased calls for device backdoors. This has broad implications for cybersecurity and software development, but no immediate direct impact on your specific stack.
blog · techcrunch.com · Aug 31
Nvidia is investing $3.5 billion in MediaTek, signaling its strategy to remain crucial in AI infrastructure as Big Tech develops its own AI chips. This is a significant move in the AI hardware landscape but doesn't directly affect your current software stack.
blog · techcrunch.com · Aug 31
ChatGPT and Reddit are now subject to the EU's Digital Services Act, which imposes stricter online safety regulations. This regulatory change is significant for large platforms but does not directly affect your development stack.
blog · arstechnica.com · Aug 31
This discussion explores 'agent memory as a file format,' a concept relevant to AI development. While not directly tied to your Anthropic API usage, it touches on broader AI agent capabilities that might influence future development.
blog · calpaterson.com · Aug 31 · 135 pts
Grindr is evolving into an 'everything app' for gay men, incorporating AI, new pricing tiers, and expanding into healthcare and matchmaking. While it uses AI, the specific business and feature expansion are not directly relevant to your current development stack.
blog · techcrunch.com · Aug 31
TechCrunch Mobility discusses the hidden human cost of robotaxis and the increasing role of AI in transportation. While AI is mentioned, the focus is on the broader implications of autonomous vehicles rather than specific development practices or tools relevant to your stack.
blog · techcrunch.com · Aug 30
A test of 100 companies revealed that privacy requests for data deletion often lead to confusion or dead ends. This highlights issues with data handling practices, but is not a direct security vulnerability affecting your stack.
blog · arstechnica.com · Aug 29
+6 more in this section
Next.js v16.3.3 addresses critical security vulnerabilities related to unauthenticated Remote Code Execution in both Windows-hosted servers and the Image Optimization API when using AVIF files. This is a critical security patch that should be applied immediately.
release · github.com · Aug 25
Next.js v15.5.24 contains critical security fixes for unauthenticated Remote Code Execution vulnerabilities affecting Windows-hosted servers and the Image Optimization API with AVIF files. This is a critical security patch that should be applied immediately.
release · github.com · Aug 25
React 19 is released with an upgrade guide detailing new features and adoption steps. This is a major version release for React, and understanding its new features is important for future development.
blog · react.dev
A critical unauthenticated remote code execution vulnerability has been discovered in React Server Components, patched in versions 19.0.1, 19.1.2, and 19.2.1. This is a high-severity security issue that requires immediate upgrading of React Server Components to prevent potential exploitation.
blog · react.dev
Vercel's Chat SDK now supports running Claude Managed Agents, which handle server-side agent logic including model, tools, and state. This integration simplifies building complex AI agents, such as research bots, for your applications.
blog · vercel.com · Aug 28
The Hy4 Preview model from Tencent is now available on Vercel AI Gateway, featuring a 1M token context window and optimized for coding and document analysis. This could be of interest for advanced AI-powered features in your Next.js or React Native applications.
blog · vercel.com · Aug 28
Cursor, an AI-powered code editor, is now supported in the Vercel AI SDK's harness layer via an official adapter. This allows for seamless switching between different coding agents like Claude Code without altering application code, enhancing development flexibility.
blog · vercel.com · Aug 27
Vercel's Security Dashboard is now generally available, providing a centralized view of security posture across projects and flagging misconfigurations. This is a valuable tool for maintaining the security of your Vercel deployments.
blog · vercel.com · Aug 26
Next.js has announced a security release for August 2026. While the exact version is not specified, this indicates a proactive approach to security for the framework.
security · nextjs.org · Aug 25
Vercel applications are protected from two critical Next.js August 2026 security vulnerabilities, with Vercel's managed Image Optimization service already patched. No customer action is required for Next.js apps hosted on Vercel.
blog · vercel.com · Aug 25
Vercel Connect aims to end credential sprawl for agents by replacing long-lived tokens with runtime, scoped, and expiring ones. This enhances the security of agent integrations with your services.
blog · vercel.com · Aug 25
Introducing the Run SDK for secure JavaScript and TypeScript execution within agents, preventing untrusted code from accessing sensitive resources. This is crucial for agent security when interacting with your stack.
blog · vercel.com · Aug 25
+31 more in this section
NestJS v12.0.0 is a major release introducing ESM-ready packages, first-class Standard Schema support, a rebuilt CLI, and native observability. While existing CommonJS applications remain compatible, migrating to ESM is optional, but the new features and CLI changes warrant attention.
release · github.com · Aug 27
pnpm 12 is a major release that changes how Git dependencies are handled, treating them as identities and canonicalizing URLs. This is a significant update to pnpm's core behavior and warrants attention for any developer using pnpm for dependency management.
release · github.com · Aug 26
NestJS v11.2.2 addresses critical bugs where ObserveInstrument could break app startup and Bootstrap crashes with CLS_REQ proxy providers. These are important fixes for stability, especially if you are using these specific features.
release · github.com · Aug 25
Node.js 26.8.0 is a current release, likely containing new features or improvements. As it's not an LTS version, the impact is generally lower unless you are specifically targeting the latest features.
release · nodejs.org · Aug 26
Node.js 24.20.0 is an LTS release, indicating a stable version with ongoing support. This patch likely includes bug fixes and security updates, which are important for maintaining a stable production environment.
release · nodejs.org · Aug 26
Clerk allows connecting OAuth clients with Client ID Metadata Documents. This update improves the management and security of OAuth integrations, which could be relevant if your application uses OAuth for authentication.
release · clerk.com
Clerk has introduced biometric sign-in support for Expo, iOS, and Android. This feature enhances user experience and security for mobile applications built with React Native and Expo, aligning with modern authentication practices.
release · clerk.com
Clerk now supports custom OAuth scopes, allowing developers to request specific permissions when integrating OAuth providers. This provides more granular control over user data access for integrated third-party services.
release · clerk.com
Clerk has added Application Logs, which provide detailed logs for application events and user activities. This feature aids in debugging and monitoring applications that use Clerk for authentication.
release · clerk.com
Clerk has introduced Admin Logs to the Audit Dashboard, providing visibility into administrative activities within the Clerk dashboard. This feature enhances security monitoring for developers managing user authentication.
release · clerk.com