ON
← Back to feed
Security patches for GitLab, Postgres and Python
Germany💻 Technology9 days ago

Security patches for GitLab, Postgres and Python

The article provides a roundup of various software updates and security patches released by different projects and companies. It mentions that the pnpm team has rewritten their JavaScript package manager in Rust for version 12 while maintaining compatibility with previous versions. GitLab has released several patch versions (19.2.2, 19.1.4, 19.0.6) addressing critical security vulnerabilities, including cross-site scripting issues rated as high risk. PostgreSQL is introducing a new JDBC driver in pre-release, optimized for concurrency with virtual threads from Java 21, and updating multiple supported versions. Python receives security updates for versions 3.10, 3.11, and 3.12. Other updates include the release of Mojo programming language version 1.0, designed for machine learning applications, the development environment Delta which allows collaborative coding with agents, and Google’s open-source C++ library Credentio for validating content credentials. React Native 0.87 introduces strict TypeScript API as standard and experimental support for Swift Package Manager.

Developer teams have released critical security patches and updates for several widely used open-source technologies, including GitLab, PostgreSQL, and Python. The latest updates address vulnerabilities with high-risk ratings and introduce new features aimed at improving performance and security. These changes reflect ongoing efforts within the developer community to maintain robust software ecosystems. The GitLab team has issued three patch releases, 19.2.2, 19.1.4, and 19.0.6, that include important security fixes. Among these, the updates target cross-site scripting (XSS) vulnerabilities, which have been classified as high-risk based on their Common Vulnerability Scoring System (CVSS) values. These patches are intended for users running versions of GitLab that are still supported. Additionally, PostgreSQL has rolled out updates for its current and older supported versions, including 18.6, 17.11, 16.15, 15.19, 14.24, and a beta version of 19. The updates aim to close high-severity security gaps, with improvements focused on concurrency support through virtual threads introduced in Java 21. Meanwhile, Python developers have released security updates for versions 3.10, 3.11, and 3.12. These updates consist solely of source code modifications designed to address known vulnerabilities. The changes follow a trend toward more frequent and targeted maintenance cycles, ensuring that even less commonly used versions receive necessary security enhancements. In another update, the pnpm team has rewritten its JavaScript package manager entirely in Rust for version 12, while maintaining backward compatibility with previous versions. This shift aims to improve performance and reliability without disrupting existing workflows. Similarly, the Django framework is transitioning away from long-term support (LTS) releases, instead offering regular updates every twelve months with three years of support per version. This change is scheduled to take effect starting with the January 2028 release of Django 2028. The programming language Mojo has reached its 1.0 release, marking the culmination of efforts to create a language optimized for machine learning applications. Designed to work across the entire stack, from hardware-level programming to business logic, Mojo represents a significant step forward in the field of computational linguistics and application development. Google has also contributed to the open-source community by releasing Credentio, a C++ library that enables local validation of media content according to the C2PA standard. This tool eliminates the need to upload large binary files to cloud services, thereby enhancing privacy and reducing dependency on external infrastructure. Zed’s new development environment, Delta, introduces a collaborative coding experience where developers and AI agents can work together on codebases. The platform uses a proprietary database called DeltaDB to track changes and provide context-aware assistance throughout the development process. This innovation highlights the growing integration of artificial intelligence into software development tools. React Native 0.87 has made the strict TypeScript API its default option for JavaScript usage, aligning with modern development practices. It also supports experimental integration with Swift Package Manager (SwiftPM), expanding its utility for iOS developers. The update requires minimum system requirements such as Node.js 22, Gradle plugin 9 for Android, and Kotlin 2.0, reflecting broader industry shifts towards newer technologies. These updates underscore the dynamic nature of open-source development, where continuous improvement and adaptation are essential to addressing emerging threats and leveraging new capabilities. As the tech landscape evolves, so too does the commitment of developers to ensure the safety, efficiency, and longevity of the software they build.

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 959 days ago
Security patches for GitLab, Postgres and Python

The article provides a roundup of various software updates and security patches released by different projects and companies. It mentions that the pnpm team has rewritten their JavaScript package manager in Rust for version 12 while maintaining compatibility with previous versions. GitLab has released several patch versions (19.2.2, 19.1.4, 19.0.6) addressing critical security vulnerabilities, including cross-site scripting issues rated as high risk. PostgreSQL is introducing a new JDBC driver in pre-release, optimized for concurrency with virtual threads from Java 21, and updating multiple supported versions. Python receives security updates for versions 3.10, 3.11, and 3.12. Other updates include the release of Mojo programming language version 1.0, designed for machine learning applications, the development environment Delta which allows collaborative coding with agents, and Google’s open-source C++ library Credentio for validating content credentials. React Native 0.87 introduces strict TypeScript API as standard and experimental support for Swift Package Manager.

Bias read (Center): The article presents a non-partisan overview of technical updates and security patches across various software projects. There is no indication of ideological leaning or biased framing toward any particular political group or ideology. The focus remains on technological developments and security, as

Why factuality (85): The article accurately mentions GitLab's patch releases 19.2.2, 19.1.4, and 19.0.6 containing important security fixes including Cross-Site Scripting vulnerabilities with CVSS scores. It also references PostgreSQL and other technologies but does not misrepresent GitLab's announcement. However, it la

Why objectivity (95): The article presents the information neutrally, using descriptive language without apparent bias. It frames the updates as 'kleine, aber interessante Meldungshäppchen' which is a light-hearted approach but still factual. The tone remains objective throughout.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories