MERGE
CONFLICT
DIGEST
September 26, 2025
|
|
Infrastructure & Services đď¸
|
|
Intel launched IGSCâŻ1.0, a licensed library managing firmware updates for its GPUs via the GSC/MEI controller on Windows and Linux. It reads current firmware, improves commandâline reporting, fixes bugs, and notes fwupd does not use IGSC. Available on Intelâs GitHub.
|
|
|
Security & Vulnerabilities đĄď¸
|
|
The piece brands Cloudflare as an expanding oligopoly that erodes privacy and competition, citing intrusive CAPTCHAs, Cloudbleed leaks, stateâbacked breaches, MITM SSL interception, DHS ties, and poor employment practices, while recommending alternatives like BunnyCDN, Fastly, and Netlify.
|
|
|
Researchers exposed Furboâs BLE interface, revealing plainâtext WiâFi credentials, writable characteristics, and hidden GATT data. With this information, attackers can force device resets, hijack registration, and hijack video streams, disabling functionality and violating privacy.
|
|
|
WIP.cx converts any DockerâCompose file into a singleâcommand, cloudâagnostic deployment, using a reverseâproxy and DNSâencoded hostnames, perâuser Proxmox VMs with WireGuard, safety hooks, and Traefik autoâHTTPS. $20 beta offers instant, secure production hosting.
|
|
|
Chainguard released a suite of SLSAâscaffolded JavaScript libraries to tighten npm supplyâchain security. By vetting and reproducing packages, it offers developers safer foundations, lowering exposure to malicious code and supplyâchain attacks.
|
|
|
Data & Analytics đ
|
|
Cloudflare introduces its Data Platform, a R2âbased bucket that eliminates traditional data lake costs with zeroâcost egress, managed metadata, and builtâin Pipelines, R2 Data Catalog, and R2 SQL, enabling petabyteâscale, openâstandard analytics at payâforâuse beta.
|
|
|
The post shows VBScript's Randomize/Rnd uses Timer() with 15.625âms precision, yielding only 65,536 unique seeds and vulnerable token generation. A Python script bruteâforces these seeds in 15âms steps, proving VBScriptâs PRNG unsuitable for security.
|
|
|
DevOps & Operations đ
|
|
Linuxâs upcoming 6.18 kernel will enable atomic writes for mdâlinear, linear software RAID, using Device Mapperâs stack. Author John Garry notes the necessary plumbing exists; the change is a singleâline flag activation in the mdâlinear code.
|
|
|
Gadget upgraded its 100,000âplusâShopifyâstore database from PostgreSQLâŻ13 toâŻ15 without downtime, employing AlloyDB sharding, logical replication, and a coordinated cutover. A Temporal workflow paused PgBouncer, switched the primary to readâonly, incremented sequences, and updated it within three seconds, preserving all client connections.
|
|
|
Redox plans 2025â26 development: hostâbased web services in a VM, secure edge servers, full desktop with COSMIC/Wayland, POSIXâstyle APIs, expanded language runtimes, performance boosts, capabilityâsafety, new hardware support, and community recruitment for contributions, grants, jobs.
|
|
|
Immutable infrastructure replaces servers with fresh images, producing atomic deployments and rollbacks. It requires configuration, centralized logging, and state separation, adding build time, storage costs, and tooling complexity. Gradual adoption, immutable web tiers with mutable databases, balances stability and progress.
|
|
|
PostgreSQL has released versionâŻ18, offering new features and improvements. The site gives fast access to download links, documentation, forums, developer resources, support options, and donation pathways, making it the hub for users to engage with the ecosystem.
|
|
|
Kubernetesâ new blockâtracking feature lets CSIâbased storage pinpoint changed blocks between snapshots, eliminating fullâvolume scans. It introduces a gRPC SnapshotMetadata API, CRD, and sidecar; providers implement RPCs while backup tools adapt to stream deltas, cutting windows and costs.
|
|
|
Airflow lineage data observability lets teams trace errors, assess downstream impact, and enforce compliance by visualizing DAG run dependencies, revealing blast radius, enabling rapid job fixes, and offering columnâlevel governance through Datadog integration.
|
|
|
AI in Society & Economy đ
|
|
Senior engineers see robust networks vital for job mobility, talent attraction, and peer support. After missing a headâofâengineering role because of lacking contacts, the author turned to active networkingâmeetups, speaking, writing, and maintaining relationshipsâto build social capital.
|
|
|
Risks & Criticism â ď¸
|
|
A Go developer investigates the behavior of appending to an infinite slice, finding that it leads to minimal memory consumption with a "slow leak" scenario where the entire slice grows indefinitely, while setting `grow` to true reliably causes overflow quickly.
|
|
|
|
Published by Merge Conflict Digest
|
|