BrokeIt - Trending Repos · All episodes: ↗

Node.js Patches 10 CVEs, Registries Fight Poisoned Packages, Postgres 19 Graph Queries

2026-07-31 · 7 min

Listen · Apple Podcasts Listen · Spotify

Stories covered

Transcript

Intro

Sam: Ten CVEs, three of them high-severity, and the fix shipped two days late because their own infrastructure fell over.

Kai: [excited] And on that cheerful note — I'm Kai!

Sam: I'm Sam.

Kai: It's July 31st, 2026, and we've got three open-source stories that actually matter today.

Sam: [dry] Three stories, and at least two of them are me telling you to patch something. Let's go.

Kai: Node.js just dropped emergency patches across all three active lines — ten CVEs in one swing.

Sam: GitHub and PyPI rolled out new rules to slow down poisoned packages — cooldowns and upload freezes.

Kai: And [excited] PostgreSQL 19 Beta 2 lands with native graph queries. Graphs! In Postgres!

Sam: Hold that hype. We'll need it.

Node.js ships emergency patches 22.23.2, 24.18.1 & 26.5.1 fixing 10 CVEs across all active lines

Sam: So Node.js just published coordinated security releases: 22.23.2, 24.18.1, and 26.5.1. Ten CVEs.

Kai: Ten in one drop! That's a busy Tuesday for the release team.

Sam: Three high-severity is the part that matters. HTTP/2 routing, heap memory management, and — this one hurts — the permission sandbox model.

Kai: Wait, the `--permission` flag? The thing that was supposed to BE the sandbox?

Sam: [dry] Yep. The security feature had a security flaw. Very meta.

Kai: Okay, but be fair — there's medium stuff too, right? DNS response handling, a zlib crash—

Sam: —and mTLS certificate reuse. That last one's sneaky — reusing certs across connections when you shouldn't.

Kai: Here's my hot take: coordinated releases across all three lines on the same day is actually good discipline. That's maturity.

Sam: Agreed — except it shipped two days LATE because their infrastructure buckled. The org securing your runtime couldn't keep its own pipes up.

Kai: [sighs] Fine. Fair shot.

Sam: What this means for you: if you run Node in production, stop what you're doing and upgrade. Not this sprint — today.

Kai: And check which line you're on — 22, 24, or 26 — grab the matching patch. Don't assume your host already did it.

Sam: The HTTP/2 one is remotely reachable on a lot of edge setups. Treat it as active-exploitation-adjacent until proven otherwise.

New GitHub and PyPI policies target fast propagation of poisoned packages

Kai: Story two — GitHub and PyPI both shipped policies to slow down poisoned packages. The supply-chain fallout continues.

Sam: Finally. Dependabot now waits three days before it opens a PR for a brand-new release.

Kai: [excited] Oh, that's smart! So a poisoned version can't auto-PR itself into your repo the instant it publishes.

Sam: Right. Most malicious releases get yanked within hours. Three days lets the immune system catch it first.

Kai: And the PyPI one — they're rejecting new file uploads to releases older than 14 days?

Sam: Exactly. So an attacker can't quietly slip a poisoned wheel into version 1.2.0 that's been trusted for a year.

Kai: Hold on — that's the attack I keep forgetting about. You don't publish new evil, you poison the OLD trusted thing everyone already pins.

Sam: That's the one. People pin old versions thinking they're safe. This closes that door.

Kai: My hot take: this is boring, unglamorous, and it's the best security news of the month.

Sam: [dry] Look at us agreeing twice in one episode. Someone screenshot it.

Kai: But push back for me — is a three-day cooldown gonna annoy people who WANT fast patches?

Sam: A little. But you can override it for genuine security fixes. Speed versus safety, and they picked a sane default.

Sam: What this means for you: don't disable the cooldown just because a shiny update dropped. Let it bake.

Kai: And on PyPI — if your workflow patched old releases, that's dead now. Cut a new version instead.

PostgreSQL 19 Beta 2 released with native SQL/PGQ graph queries and unified REPACK

Kai: Last one — [excited] PostgreSQL 19 Beta 2 is out. Feature freeze, GA later this year. And it's got NATIVE graph queries!

Sam: SQL/PGQ — property-graph queries baked into the standard. So you can traverse relationships without bolting on a separate graph database.

Kai: Do you know how many teams stood up a whole second database just for this? And now it's just... in Postgres.

Sam: [dry] It's Beta 2, Kai. Nobody's ripping out Neo4j on a beta.

Kai: Buzzkill. But there's more — a unified REPACK command for zero-downtime table reorg!

Sam: Okay, THAT one I'm genuinely happy about. Reorganizing bloated tables without locking everyone out has been a nightmare for years.

Kai: And they shifted the defaults for JIT and TOAST compression — tuning that's been argued about forever.

Sam: Here's my skeptic beat, though: there are breaking changes. String handling, index opclasses, encoding. This is not a lazy upgrade.

Kai: Wait — index opclasses breaking? That can quietly change query behavior, right?

Sam: It can. You need real migration planning, not a `pg_upgrade` and a prayer.

Kai: My hot take: SQL/PGQ is the sleeper feature of the decade for Postgres. Graphs going mainstream in the default database.

Sam: [sarcastic] The decade. It's July. We've got a lot of decade left.

Kai: [laughs] Fair, fair.

Sam: What this means for you: play with Beta 2 in staging, test the graph queries, but read the breaking-change notes before you even THINK about production.

Kai: So today: Node.js dropped ten CVEs of emergency patches across all three lines — go upgrade now.

Sam: GitHub and PyPI added cooldowns and upload freezes to starve poisoned packages of that fast-propagation window.

Kai: And PostgreSQL 19 Beta 2 brought native graph queries and zero-downtime REPACK — with breaking changes attached.

Sam: Before we go — one thing that made me laugh. Someone benchmarked that Postgres graph query against a dedicated graph DB and posted the results with, uh, very enthusiastic stars.

Kai: [excited] See, star counts don't lie—

Sam: [dry] Kai. The repo was four hours old and had eight hundred stars. That's not momentum, that's a botnet with a hobby.

Kai: [laughs] Okay, THAT'S the show for July 31st. Patch your Node, let your dependencies bake, and test that beta in staging.

Sam: And if a brand-new repo has more stars than commits — real momentum, or a botnet with a hobby? See you tomorrow.

This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.