Sam: Ten CVEs, three of them high-severity, and the fix shipped two days late because their own infrastructure fell over.
Kai: [excited] And on that cheerful note — I'm Kai!
Sam: I'm Sam.
Kai: It's July 31st, 2026, and we've got three open-source stories that actually matter today.
Sam: [dry] Three stories, and at least two of them are me telling you to patch something. Let's go.
Kai: Node.js just dropped emergency patches across all three active lines — ten CVEs in one swing.
Sam: GitHub and PyPI rolled out new rules to slow down poisoned packages — cooldowns and upload freezes.
Kai: And [excited] PostgreSQL 19 Beta 2 lands with native graph queries. Graphs! In Postgres!
Sam: Hold that hype. We'll need it.
Sam: So Node.js just published coordinated security releases: 22.23.2, 24.18.1, and 26.5.1. Ten CVEs.
Kai: Ten in one drop! That's a busy Tuesday for the release team.
Sam: Three high-severity is the part that matters. HTTP/2 routing, heap memory management, and — this one hurts — the permission sandbox model.
Kai: Wait, the `--permission` flag? The thing that was supposed to BE the sandbox?
Sam: [dry] Yep. The security feature had a security flaw. Very meta.
Kai: Okay, but be fair — there's medium stuff too, right? DNS response handling, a zlib crash—
Sam: —and mTLS certificate reuse. That last one's sneaky — reusing certs across connections when you shouldn't.
Kai: Here's my hot take: coordinated releases across all three lines on the same day is actually good discipline. That's maturity.
Sam: Agreed — except it shipped two days LATE because their infrastructure buckled. The org securing your runtime couldn't keep its own pipes up.
Kai: [sighs] Fine. Fair shot.
Sam: What this means for you: if you run Node in production, stop what you're doing and upgrade. Not this sprint — today.
Kai: And check which line you're on — 22, 24, or 26 — grab the matching patch. Don't assume your host already did it.
Sam: The HTTP/2 one is remotely reachable on a lot of edge setups. Treat it as active-exploitation-adjacent until proven otherwise.
Kai: Story two — GitHub and PyPI both shipped policies to slow down poisoned packages. The supply-chain fallout continues.
Sam: Finally. Dependabot now waits three days before it opens a PR for a brand-new release.
Kai: [excited] Oh, that's smart! So a poisoned version can't auto-PR itself into your repo the instant it publishes.
Sam: Right. Most malicious releases get yanked within hours. Three days lets the immune system catch it first.
Kai: And the PyPI one — they're rejecting new file uploads to releases older than 14 days?
Sam: Exactly. So an attacker can't quietly slip a poisoned wheel into version 1.2.0 that's been trusted for a year.
Kai: Hold on — that's the attack I keep forgetting about. You don't publish new evil, you poison the OLD trusted thing everyone already pins.
Sam: That's the one. People pin old versions thinking they're safe. This closes that door.
Kai: My hot take: this is boring, unglamorous, and it's the best security news of the month.
Sam: [dry] Look at us agreeing twice in one episode. Someone screenshot it.
Kai: But push back for me — is a three-day cooldown gonna annoy people who WANT fast patches?
Sam: A little. But you can override it for genuine security fixes. Speed versus safety, and they picked a sane default.
Sam: What this means for you: don't disable the cooldown just because a shiny update dropped. Let it bake.
Kai: And on PyPI — if your workflow patched old releases, that's dead now. Cut a new version instead.
Kai: Last one — [excited] PostgreSQL 19 Beta 2 is out. Feature freeze, GA later this year. And it's got NATIVE graph queries!
Sam: SQL/PGQ — property-graph queries baked into the standard. So you can traverse relationships without bolting on a separate graph database.
Kai: Do you know how many teams stood up a whole second database just for this? And now it's just... in Postgres.
Sam: [dry] It's Beta 2, Kai. Nobody's ripping out Neo4j on a beta.
Kai: Buzzkill. But there's more — a unified REPACK command for zero-downtime table reorg!
Sam: Okay, THAT one I'm genuinely happy about. Reorganizing bloated tables without locking everyone out has been a nightmare for years.
Kai: And they shifted the defaults for JIT and TOAST compression — tuning that's been argued about forever.
Sam: Here's my skeptic beat, though: there are breaking changes. String handling, index opclasses, encoding. This is not a lazy upgrade.
Kai: Wait — index opclasses breaking? That can quietly change query behavior, right?
Sam: It can. You need real migration planning, not a `pg_upgrade` and a prayer.
Kai: My hot take: SQL/PGQ is the sleeper feature of the decade for Postgres. Graphs going mainstream in the default database.
Sam: [sarcastic] The decade. It's July. We've got a lot of decade left.
Kai: [laughs] Fair, fair.
Sam: What this means for you: play with Beta 2 in staging, test the graph queries, but read the breaking-change notes before you even THINK about production.
Kai: So today: Node.js dropped ten CVEs of emergency patches across all three lines — go upgrade now.
Sam: GitHub and PyPI added cooldowns and upload freezes to starve poisoned packages of that fast-propagation window.
Kai: And PostgreSQL 19 Beta 2 brought native graph queries and zero-downtime REPACK — with breaking changes attached.
Sam: Before we go — one thing that made me laugh. Someone benchmarked that Postgres graph query against a dedicated graph DB and posted the results with, uh, very enthusiastic stars.
Kai: [excited] See, star counts don't lie—
Sam: [dry] Kai. The repo was four hours old and had eight hundred stars. That's not momentum, that's a botnet with a hobby.
Kai: [laughs] Okay, THAT'S the show for July 31st. Patch your Node, let your dependencies bake, and test that beta in staging.
Sam: And if a brand-new repo has more stars than commits — real momentum, or a botnet with a hobby? See you tomorrow.
This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.