TL;Der — Developer news digest

tlder@dev
tlder@dev:~$

Your dev world, TL;DR'd. 226 items across all categories. covering May 1 → Jun 2

└─worth-opening/(64 items)

The deprecation page lists exact model IDs being retired, replacement aliases, and the error behavior after June 15 — details that matter when hunting down hardcoded strings across a codebase.
└─
The official release schedule page explains the new annual cadence and what happens to the LTS promotion model — worth reading before planning your upgrade path.
└─·backend

└─cross-cutting/(44 items)

dbt Labs released dbt Core v2.0 in alpha at Snowflake Summit 2026, introducing support for user-defined function deferral.
└─·backend,data·dbt Labs
TeamPCP's latest Mini Shai-Hulud variant compromised 96 versions across 32 @redhat-cloud-services npm packages — the fifth time this actor has pulled the same playbook in six weeks, and their first confirmed pivot to GitHub Actions OIDC tokens instead of individual developer credentials.
└─·security,devtools·Wiz Research
May 28
May 28·cat news/20260528-react-native-expo-router-v56-fo
cat news/20260528-react-native-expo-router-v56-fo
Expo Router v56 Forks from React Navigation, Adds Streaming SSR and Android Toolbar
Expo Router v56 ships its own navigation stack — severing the React Navigation dependency — alongside streaming SSR and a new Android toolbar.
└─Expo Engineering Blog
May 26
May 26·cat news/20260526-ios-apple-266-first-betas
cat news/20260526-ios-apple-266-first-betas
Apple seeds the first 26.6 betas across all six platforms
Two weeks after shipping 26.5, Apple pushed first developer betas of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS 26.6.
└─Apple Developer
May 21
May 21·cat news/20260521-ios-macos27-rosetta2-sunset
cat news/20260521-ios-macos27-rosetta2-sunset
macOS 27 Named as Final Release Supporting Rosetta 2 for Intel Apps
Apple has announced that macOS 27 will be the last release to include Rosetta 2, after which Intel-only binaries will no longer run on Apple silicon Macs.
└─Apple Developer
May 13
May 13·cat news/20260513-ios-xcode-265-stable-release
cat news/20260513-ios-xcode-265-stable-release
Apple Releases Xcode 26.5 with Swift 6.3 and Queued Coding Assistant Messages
Xcode 26.5 ships as a stable release on May 13, bundling Swift 6.3, final iOS/iPadOS/tvOS/macOS/visionOS 26.5 SDKs, and coding assistant improvements including message queuing and clarifying questions.
└─MacTech
May 8
May 8·cat news/20260508-ios-ios265-rc2
cat news/20260508-ios-ios265-rc2
Apple Seeds iOS 26.5 and iPadOS 26.5 Release Candidate 2 (23F77)
Apple released the second Release Candidate for iOS 26.5 and iPadOS 26.5 (build 23F77) on May 8, advancing the release toward general availability.
└─Apple Developer
Apr 28
Apr 28·cat news/20260502-ios-appstore-sdk-ios26-req
cat news/20260502-ios-appstore-sdk-ios26-req
App Store Connect now requires iOS 26 SDK for all new app uploads
Starting April 28, 2026, all apps submitted to App Store Connect must be built with the iOS 26 and iPadOS 26 SDK.
└─Apple Developer
May 21
May 21·cat news/20260521-kmp-kotlinconf26-keynote-sub
cat news/20260521-kmp-kotlinconf26-keynote-sub
KotlinConf 2026 Keynote Unveils Kotlin 2.4.0 Preview, Wasm Beta, and Agent Client Protocol
The KotlinConf 2026 keynote landed Kotlin 2.4.0 in preview, pushed Kotlin/Wasm to Beta, introduced an 18-month security support policy for the standard library, and revealed JetBrains co-leading a new open Agent Client Protocol standard.
└─JetBrains Kotlin Blog
May 21
May 21·cat news/20260521-android-media3-181-stable
cat news/20260521-android-media3-181-stable
AndroidX Media3 1.8.1 Lands with Bug Fixes and Improvements
Media3 version 1.8.1 reached the AndroidX stable channel on May 21 with accumulated bug fixes and stability improvements.
└─Android Developers
May 20
May 20·cat news/20260521-android-io26-android-agents-cli
cat news/20260521-android-io26-android-agents-cli
Google I/O 2026 Ships Android CLI Agent Tool and Announces Migration Agent for React Native and iOS
Google I/O 2026 delivered a stable Android CLI enabling agents to access Android Studio capabilities, open-sourced Android skills for Jetpack Compose migration, and announced a migration agent that converts React Native and iOS codebases to native Kotlin.
└─Google Developers Blog
May 19
May 19·cat news/20260519-android-compose-1112-stable
cat news/20260519-android-compose-1112-stable
Jetpack Compose 1.11.2 Bug-Fix Stable Releases Across Core Libraries
AndroidX published stable 1.11.2 bug-fix releases for Compose Animation, Foundation, Material, Runtime, and UI on May 19, alongside Navigation3 1.1.2 and a stable promotion for Savedstate 1.5.0.
└─Android Developers
May 19
May 19·cat news/20260519-android-openharmony-v6-rce-cve2
cat news/20260519-android-openharmony-v6-rce-cve2
Three High-Severity CVEs Hit OpenHarmony v6.0 Including Two RCE Flaws
CVE-2026-27648, CVE-2026-24792, and CVE-2026-25781 affect OpenHarmony v6.0, exposing Huawei and OpenHarmony-compatible devices to remote code execution and local denial-of-service.
└─NVD / CVE.org
────────────────────────────────────────────────────────────
Jun 1
Jun 1·cat news/20260601-react-react-19-formdata-patch
cat news/20260601-react-react-19-formdata-patch
React 19 Patch Releases Fix FormData Regression in Server Actions
React 19.0.7, 19.1.8, and 19.2.7 all shipped June 1 with a same-day fix for a FormData regression in Server Actions introduced by the previous patch on each branch.
└─GitHub
May 20
May 20·cat news/20260520-react-wordpress-70-shipped
cat news/20260520-react-wordpress-70-shipped
WordPress 7.0 Ships on May 20 with Real-Time Collaboration Deferred
WordPress 7.0 reached final release on May 20 after a cycle extension, but real-time collaboration was pulled from the milestone due to unresolved race conditions and memory concerns.
└─WordPress Developer Blog
May 20
May 20·cat news/20260520-css-browsers-webmcp-origin-trial
cat news/20260520-css-browsers-webmcp-origin-trial
WebMCP Proposed as Open Web Standard for Browser-Based AI Agents, Chrome 149 Trial Launching
Google proposed WebMCP at Google I/O 2026 as an open web standard enabling browser-based AI agents to execute structured tool calls, with an experimental origin trial starting in Chrome 149.
└─Google Developers Blog
May 20
May 20·cat news/20260520-css-browsers-html-canvas-api
cat news/20260520-css-browsers-html-canvas-api
Google I/O 2026 Previews HTML-in-Canvas API for Searchable, Accessible 3D Web Experiences
Google previewed a new HTML-in-Canvas API at I/O 2026 that lets developers embed live HTML content inside WebGL/Canvas contexts, preserving accessibility and search indexability in immersive scenes.
└─Google Developers Blog
May 20
May 20·cat news/20260520-css-browsers-devtools-agents
cat news/20260520-css-browsers-devtools-agents
Chrome DevTools Gains AI Agent Automation for Quality Audits and UX Testing
Google announced at I/O 2026 that Chrome DevTools now supports AI agent automation, enabling programmatic quality audits and real-world user experience testing without manual interaction.
└─Google Developers Blog
May 19
May 19·cat news/20260519-css-browsers-firefox-151-stable
cat news/20260519-css-browsers-firefox-151-stable
Firefox 151 Ships Web Serial API, Container Style Queries, and PDF Merge
Firefox 151, released May 19, adds Web Serial API support, container style queries, document picture-in-picture, PDF merging in the built-in viewer, and enhanced fingerprinting protection.
└─Mozilla
May 13
May 13·cat news/20260513-nextjs-nextjs-security-13-cves
cat news/20260513-nextjs-nextjs-security-13-cves
Next.js Security Release Expands to 13 Advisories with CVE-2026-23870 RSC DoS
Vercel's May security release now covers 13 advisories including CVE-2026-23870, a React Server Components denial-of-service vulnerability, with patched versions Next.js 15.5.18 and 16.2.6 available.
└─Vercel
May 1
May 1·cat news/20260501-svelte-sveltekit-may-2026-rel
cat news/20260501-svelte-sveltekit-may-2026-rel
SvelteKit 2.56-2.57, Svelte 5.55, and sv CLI 0.1.0 ship TypeScript 6.0 support and breaking query changes
The Svelte May 2026 roundup brings SvelteKit TypeScript 6.0 compatibility, a new form-field default-value API, motion-type exports in Svelte 5.55, and the sv CLI's first stable community add-ons feature — alongside several breaking changes to query lifecycle.
└─Svelte Blog
────────────────────────────────────────────────────────────
Jun 1
Jun 1·cat news/20260601-nodejs-node-25-eol-june-2026
cat news/20260601-nodejs-node-25-eol-june-2026
Node.js 25 Reaches End of Support
Node.js 25 went end-of-life on June 1, 2026 and will receive no further security updates.
└─Node.js
May 5
May 5·cat news/20260505-nodejs-node-26-major-release
cat news/20260505-nodejs-node-26-major-release
Node.js 26.0.0 Released with Temporal API and V8 14.6
Node.js 26 ships as the new Current release with Temporal API enabled by default, V8 14.6, and several breaking changes including removal of legacy stream modules and the writeHeader method.
└─Node.js
Jun 1
Jun 1·cat news/20260601-apis-dbt-v2-alpha-snowflake-summit
cat news/20260601-apis-dbt-v2-alpha-snowflake-summit
dbt Core v2.0 Alpha Debuts at Snowflake Summit
dbt Labs released dbt Core v2.0 in alpha at Snowflake Summit 2026, introducing support for user-defined function deferral.
└─dbt Labs
May 21
May 21·cat news/20260521-apis-kotlinconf-acp-open-stand
cat news/20260521-apis-kotlinconf-acp-open-stand
JetBrains Unveils Agent Client Protocol, an Open Standard for IDE-Agent Communication
JetBrains co-launched the Agent Client Protocol at KotlinConf, an open standard defining how coding agents interact with IDEs.
└─JetBrains Blog
May 13
May 13·cat news/20260513-apis-github-enterprise-install-api
cat news/20260513-apis-github-enterprise-install-api
GitHub Launches Enterprise Installation API in Public Preview
A new GitHub API in public preview lets GitHub Apps directly query whether they are installed on a specific enterprise and retrieve the installation ID, eliminating the need to paginate all installations.
└─GitHub Changelog
May 1
May 1·cat news/20260501-apis-openai-gpt55-api-la
cat news/20260501-apis-openai-gpt55-api-la
OpenAI launches GPT-5.5 and GPT-5.5 Pro via API
OpenAI released GPT-5.5 and GPT-5.5 Pro for API developers with a 1M-token context window, priced at $5/$30 and $30/$180 per million input/output tokens respectively.
└─Releasebot
May 28
May 28·cat news/20260528-rust-rust-1-96-0
cat news/20260528-rust-rust-1-96-0
Rust 1.96.0 Released
The new core::range types are now Copy, two pattern-matching assertion macros land, and the wasm linker stops silently inventing imports.
└─Rust Blog
May 15
May 15·cat news/20260515-rust-azure-sdk-rust-stable
cat news/20260515-rust-azure-sdk-rust-stable
Microsoft Releases Stable Azure SDK for Rust
Microsoft shipped the stable Azure SDK for Rust, delivering production-ready crates for Core, Identity, Key Vault, and Storage services.
└─Microsoft Dev Blogs
May 21
May 21·cat news/20260521-javajvm-kotlin-240-preview-sec
cat news/20260521-javajvm-kotlin-240-preview-sec
Kotlin 2.4.0 Preview Ships with 18-Month Standard Library Security Support
JetBrains previewed Kotlin 2.4.0 at KotlinConf and committed to an 18-month security support window for stable standard library releases.
└─JetBrains Blog
May 19
May 19·cat news/20260519-javajvm-jdk27-jeps-batch-may19
cat news/20260519-javajvm-jdk27-jeps-batch-may19
Four JDK 27 JEPs Advance to Review: G1 Universal Default, Compact Headers, Vector API, PEM
JDK 27 review cycles opened for JEP 523 (G1 as universal default GC), JEP 534 (compact object headers default), JEP 537 (Vector API 12th incubator), and JEP 538 (new PEM encoding/decoding API).
└─TensorBlue / Java News Roundup
May 14
May 14·cat news/20260514-javajvm-java-post-quantum-tls
cat news/20260514-javajvm-java-post-quantum-tls
Java Gets Post-Quantum TLS - Inside Java Newscast #112
Oracle's Inside Java Newscast #112 details post-quantum TLS support being added to the JDK, a major cryptographic hardening ahead of quantum computing threats.
└─Inside Java (Oracle)
May 14
May 14·cat news/20260514-javajvm-geecon-2026-krakow
cat news/20260514-javajvm-geecon-2026-krakow
GeeCon 2026 in Kraków, Poland (May 14-15)
GeeCon 2026 runs May 14-15 in Kraków with sessions on JDK 27 roadmap items including Structured Concurrency and what excites developers most about Java in 2026.
└─JetBrains Blog
May 6
May 6·cat news/20260506-python-python-2026-roadma
cat news/20260506-python-python-2026-roadma
Python 2026 Roadmap: Free-Threading, Lazy Imports, and Further Speed Gains
A New Stack overview of Python's 2026 roadmap highlights official free-threading support, lazy import machinery, and continued interpreter performance work as the main themes for the year.
└─The New Stack
May 5
May 5·cat news/20260505-python-packaging-council-gov
cat news/20260505-python-packaging-council-gov
Python Establishes a New Packaging Council
The Python community formed a dedicated Packaging Council to consolidate governance over the fragmented packaging ecosystem.
└─Real Python
May 4
May 4·cat news/20260504-python-314-5rc1-release
cat news/20260504-python-314-5rc1-release
Python 3.14.5rc1 Released
The Python core team published the first release candidate for Python 3.14.5, opening the final validation window before the stable patch ships.
└─Real Python
────────────────────────────────────────────────────────────
Jun 1
Jun 1·cat news/20260601-pipelines-etl-dbt-v2-alpha-snow
cat news/20260601-pipelines-etl-dbt-v2-alpha-snow
dbt Core v2.0 enters alpha at Snowflake Summit
dbt Labs unveiled the first alpha of dbt Core v2.0 at Snowflake Summit, the biggest version bump since the project launched, headlined by UDF-aware deferral.
└─dbt Labs
May 27
May 27·cat news/20260527-pipelines-etl-gcp-managed-airflow
cat news/20260527-pipelines-etl-gcp-managed-airflow
Managed Airflow gets environment tags and a dark console
Google's Managed Service for Apache Airflow began rolling out a release that adds resource tags for IAM policy conditions, a dark theme in the Cloud Console, and faster worker startup on package-heavy environments.
└─Google Cloud
Jun 1
Jun 1·cat news/20260601-streaming-confluent-flink-dbt-ada
cat news/20260601-streaming-confluent-flink-dbt-ada
Confluent Cloud for Apache Flink gains a dbt adapter
Confluent's Q2 2026 launch post introduces a dbt-confluent adapter, letting developers write streaming Flink transformations as ordinary dbt models.
└─Confluent
May 26
May 26·cat news/20260526-streaming-flink-k8s-operator-1150
cat news/20260526-streaming-flink-k8s-operator-1150
Flink Kubernetes Operator 1.15.0 ships native Conditions and Logback support
The Apache Flink community released version 1.15.0 of its Kubernetes Operator, adding Kubernetes-native status Conditions to FlinkDeployment and Flink 2.2 compatibility.
└─Apache Flink
May 20
May 20·cat news/20260520-streaming-confluent-metrics-api-up
cat news/20260520-streaming-confluent-metrics-api-up
Confluent Cloud adds four new Metrics API signals for Kafka observability
Confluent Cloud expanded its Metrics API with signals covering client throttling by principal, consumer group rebalance duration, connection attempt spikes, and compacted partition counts.
└─Confluent
Nov 12
Nov 12·cat news/20261112-databases-postgresql-14-eol-deadline
cat news/20261112-databases-postgresql-14-eol-deadline
PostgreSQL 14 reaches end-of-life on November 12, 2026
PostgreSQL 14 will receive no further security patches or bug fixes after November 12, 2026, requiring teams to migrate to a supported major version.
└─PostgreSQL Global Development Group
May 29
May 29·cat news/20260529-databases-neon-backend-platform
cat news/20260529-databases-neon-backend-platform
Neon wants to be your whole backend, not just the database
Neon now pitches itself as a complete backend for apps and agents — Postgres, Auth, and a Data API today, with object storage, compute, and an AI gateway flagged as coming — and shipped a batch of changelog fixes the same day.
└─Neon
May 20
May 20·cat news/20260520-databases-duckdb-153-quack-protoc
cat news/20260520-databases-duckdb-153-quack-protoc
DuckDB 1.5.3 ships Quack protocol as a core extension
DuckDB 1.5.3 promotes the Quack client-server protocol to a bundled core extension and lands significant Iceberg and DuckLake improvements.
└─duckdb.org
May 20
May 20·cat news/20260520-databases-clickhouse-v26437-stable
cat news/20260520-databases-clickhouse-v26437-stable
ClickHouse v26.4.3.37-stable released
A bug-fix stable patch lands on top of the 26.4 feature release, which added VALUES as a table expression, natural join, and compound INTERVAL literals.
└─ClickHouse
May 20
May 20·cat news/20260520-databases-oracle-goldengate-gcp-ga
cat news/20260520-databases-oracle-goldengate-gcp-ga
Oracle GoldenGate support reaches GA on Oracle Database@Google Cloud
Oracle Cloud Infrastructure GoldenGate is now generally available on Oracle Database@Google Cloud, enabling real-time data replication and transformation between systems.
└─Google Cloud
May 4
May 4·cat news/20260504-warehouses-amazon-quick-ga
cat news/20260504-warehouses-amazon-quick-ga
Amazon Quick launches free and paid tiers with expanded enterprise data source integrations
Amazon's Quick AI assistant is now available in Free and Plus pricing tiers with a native desktop app for macOS and Windows, adding connectors for Google Workspace, Zoom, Airtable, Dropbox, and Microsoft Teams alongside visual asset generation.
└─AWS Blog
────────────────────────────────────────────────────────────
Jun 15
Jun 15·cat news/20260615-llms-claude-sonnet4-opus4-eol
cat news/20260615-llms-claude-sonnet4-opus4-eol
Claude Sonnet 4 and Opus 4 Retire June 15
Anthropic is retiring Claude Sonnet 4 and Opus 4 on June 15, requiring API callers to migrate to current model versions before that date.
└─Anthropic Docs
Jun 1
Jun 1·cat news/20260601-llms-anthropic-prog-billing-june15
cat news/20260601-llms-anthropic-prog-billing-june15
Anthropic splits programmatic Claude usage into a separate credit pool starting June 15
Claude programmatic usage — CI runs, Agent SDK automation, GitHub Actions, third-party agent frameworks — moves to a dedicated monthly credit pool on June 15, separate from interactive usage.
└─devtoolpicks.com
May 8
May 8·cat news/20260508-llms-anthropic-50b-fundraise
cat news/20260508-llms-anthropic-50b-fundraise
Anthropic Weighs $50B Raise at ~$900B Valuation as Annualized Revenue Approaches $45B
Anthropic is in advanced discussions to raise as much as $50 billion at a pre-money valuation of roughly $900 billion, with a close expected within two months.
└─Bloomberg / The Information (via llm-stats.com)
May 7
May 7·cat news/20260507-llms-openai-voice-api-launch
cat news/20260507-llms-openai-voice-api-launch
OpenAI Rolls Out New Voice Intelligence Capabilities in the API
OpenAI launched expanded voice intelligence features in its API, enabling developers to build more capable speech-driven applications.
└─llm-stats.com
May 1
May 1·cat news/20260501-llms-openai-gpt55-api-pric
cat news/20260501-llms-openai-gpt55-api-pric
OpenAI launches GPT-5.5 API with 1M context window at $5/1M input tokens
OpenAI released GPT-5.5 for API access with a 1 million token context window, priced at $5/1M input and $30/1M output, plus a higher-tier GPT-5.5-pro at $30/1M input and $180/1M output.
└─ReleaseBot
May 29
May 29·cat news/20260529-models-anthropic-65b-965b-mythos
cat news/20260529-models-anthropic-65b-965b-mythos
Anthropic closes $65B Series H at $965B valuation, previews Mythos model
Anthropic's Series H puts it past OpenAI on valuation at $965B, bankrolled by Altimeter, Sequoia, and a $5B Amazon tranche, with annualized revenue already at $47B and a new frontier model called Mythos on deck.
└─Fortune
May 28
May 28·cat news/20260528-models-anthropic-opus-4-8
cat news/20260528-models-anthropic-opus-4-8
Anthropic launches Claude Opus 4.8
Anthropic's Opus 4.8 shipped everywhere on launch day, with gains across coding, reasoning, and agentic computer use.
└─MacRumors
May 20
May 20·cat news/20260520-models-google-android-bench-open
cat news/20260520-models-google-android-bench-open
Google Open-Sources Android Bench, a Leaderboard for Evaluating LLMs on Android Tasks
Google released Android Bench as an open-source leaderboard at I/O 2026 to provide a standardized way to measure LLM performance on real-world Android development tasks.
└─Google Developers Blog
May 19
May 19·cat news/20260519-models-google-gemini35-flash-rel
cat news/20260519-models-google-gemini35-flash-rel
Google Releases Gemini 3.5 Flash, a Lightweight Multimodal Model
Google shipped Gemini 3.5 Flash on May 19, expanding the 3.5 family with a lightweight multimodal model carrying a January 31, 2026 knowledge cutoff.
└─llm-stats.com
May 28
May 28·cat news/20260528-agents-claude-code-dynamic-workflows
cat news/20260528-agents-claude-code-dynamic-workflows
Claude Code gets dynamic workflows in research preview
Alongside Opus 4.8, Claude Code can now plan a task and fan it out across hundreds of parallel subagents in one session.
└─TechCrunch
May 21
May 21·cat news/20260521-agents-kotlinconf-acp-standard
cat news/20260521-agents-kotlinconf-acp-standard
JetBrains Co-Leads Agent Client Protocol, an Open Standard for IDE-Agent Communication
JetBrains announced at KotlinConf 2026 that it is co-leading the Agent Client Protocol, an open standard defining how coding agents and IDEs exchange context, instructions, and results.
└─JetBrains Blog
May 20
May 20·cat news/20260520-agents-google-antigravity-20-launch
cat news/20260520-agents-google-antigravity-20-launch
Google Launches Antigravity 2.0 Agent Orchestration Platform with New CLI and SDK
Google unveiled Antigravity 2.0 at I/O 2026, introducing a redesigned CLI for building specialized subagents and an SDK for deploying agent workflows on custom infrastructure.
└─Google Developers Blog
May 20
May 20·cat news/20260520-agents-google-managed-agents-api
cat news/20260520-agents-google-managed-agents-api
Google Adds Managed Agents Feature to Gemini API for Simplified Agent Deployment
Google introduced Managed Agents via the Gemini API at I/O 2026, providing infrastructure scaffolding that reduces the setup burden for teams deploying production AI agents.
└─Google Developers Blog
May 20
May 20·cat news/20260520-frameworks-google-ai-studio-io26
cat news/20260520-frameworks-google-ai-studio-io26
Google AI Studio Gains Native Kotlin Support, Workspace Integrations, and Cloud Run Export
Google expanded AI Studio at I/O 2026 with native Kotlin support, Google Workspace integrations, one-click Cloud Run deployment, and direct export to Antigravity.
└─Google Developers Blog
May 19
May 19·cat news/20260519-frameworks-autogpt-cve-33233-rce
cat news/20260519-frameworks-autogpt-cve-33233-rce
AutoGPT Unsafe Pickle Deserialization Enables Arbitrary Code Execution (CVE-2026-33233)
A CVSS 7.6 vulnerability in AutoGPT allows remote code execution through unsafe pickle deserialization.
└─CVE Records
May 19
May 19·cat news/20260519-frameworks-autogpt-cve-33232-dos
cat news/20260519-frameworks-autogpt-cve-33232-dos
AutoGPT Unauthenticated DoS via Disk Space Exhaustion (CVE-2026-33232)
CVE-2026-33232 allows an unauthenticated attacker to exhaust disk space on AutoGPT instances, rated CVSS 7.5.
└─CVE Records
May 19
May 19·cat news/20260519-frameworks-autogpt-cve-33234-ssrf
cat news/20260519-frameworks-autogpt-cve-33234-ssrf
AutoGPT SSRF Filter Bypass (CVE-2026-33234)
CVE-2026-33234 describes a server-side request forgery bypass in AutoGPT rated CVSS 5.0.
└─CVE Records
May 12
May 12·cat news/20260512-mcp-figma-mcp-server-launch
cat news/20260512-mcp-figma-mcp-server-launch
Figma Launches Official MCP Server for Bidirectional Code-Design Workflows
Figma released an official MCP server enabling AI agents to translate code into Figma designs, modify design systems, and convert designs back to code via the open MCP standard.
└─Figma Help Center
May 5
May 5·cat news/20260505-mcp-jama-connect-mcp-server
cat news/20260505-mcp-jama-connect-mcp-server
Jama Software Launches MCP Server for Jama Connect, Enabling AI Coding Assistants to Access Requirements Traceability
Jama Software has released an MCP Server for Jama Connect, letting AI coding tools such as Claude, Codex, Cursor, and GitHub Copilot query and navigate requirements traceability data while respecting existing permissions and audit workflows.
└─IT Business Net
────────────────────────────────────────────────────────────
May 29
May 29·cat news/20260529-cloud-cloudflare-one-client-redesign
cat news/20260529-cloud-cloudflare-one-client-redesign
Cloudflare's desktop client can now lock traffic until you log in
Beta builds of the Cloudflare One client for macOS and Windows landed with a redesigned interface, and the Windows build can block all internet traffic from boot until the user authenticates.
└─Cloudflare
May 28
May 28·cat news/20260528-cloud-aws-resilience-hub-next-gen-ga
cat news/20260528-cloud-aws-resilience-hub-next-gen-ga
Next-gen AWS Resilience Hub reaches general availability
The reworked Resilience Hub adds a systems-to-services hierarchy and AI-assisted failure-mode analysis for SRE teams.
└─AWS
May 20
May 20·cat news/20260520-cloud-gcp-apigee-ssrf-cve-2026-2264
cat news/20260520-cloud-gcp-apigee-ssrf-cve-2026-2264
GCP Apigee X Security Bulletin GCP-2026-034: SSRF via SetIntegrationRequest Policy
Google issued security bulletin GCP-2026-034 for a server-side request forgery vulnerability in Apigee X that allows attackers to exfiltrate service account tokens through an unvalidated IntegrationRegion parameter.
└─GCP Release Notes
May 20
May 20·cat news/20260520-cloud-gcp-guest-env-critical-fix
cat news/20260520-cloud-gcp-guest-env-critical-fix
GCP Guest Environment v20260511.00 Fixes Control Plane Error That Broke SSH and Password Reset
Google shipped Guest Environment version 20260511.00 to repair a May 4–11 control plane error that accidentally removed the core plugin, disabling SSH access and password reset on affected instances.
└─GCP Release Notes
May 17
May 17·cat news/20260517-cloud-cisco-sdwan-cve-2026-20182
cat news/20260517-cloud-cisco-sdwan-cve-2026-20182
CISA Mandates Federal Patch for Critical Cisco Catalyst SD-WAN Auth Bypass CVE-2026-20182
CISA has ordered federal agencies to patch a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller and Manager by May 17, 2026, following confirmed active exploitation.
└─BleepingComputer
May 12
May 12·cat news/20260512-cloud-cisa-kev-cve-2026-32202
cat news/20260512-cloud-cisa-kev-cve-2026-32202
CISA KEV Patch Deadline Arrives for Windows Shell Spoofing CVE-2026-32202
The FCEB mandatory patching deadline for CVE-2026-32202, a zero-click Windows Shell spoofing vulnerability actively exploited by APT28, falls today, May 12, 2026.
└─CISA / The Hacker News
May 9
May 9·cat news/20260509-cloud-cisa-pan-os-0300-deadline
cat news/20260509-cloud-cisa-pan-os-0300-deadline
CISA May 9 Deadline Forces PAN-OS CVE-2026-0300 Mitigations Ahead of Planned May 13 Patch
CISA's May 9 enforcement deadline for federal agencies to mitigate the actively exploited PAN-OS root-level RCE (CVE-2026-0300) arrives while Palo Alto's patch remains four days away.
└─The Hacker News
May 21
May 21·cat news/20260521-k8s-cncf-obs-summit-na-opened
cat news/20260521-k8s-cncf-obs-summit-na-opened
CNCF Observability Summit North America 2026 Opens in Minneapolis
The CNCF Observability Summit North America 2026 opened on May 21 in Minneapolis, moving from a scheduled conference to an active two-day event.
└─CNCF
May 20
May 20·cat news/20260520-k8s-cncf-cloud-svc-mesh-status
cat news/20260520-k8s-cncf-cloud-svc-mesh-status
GCP Cloud Service Mesh Adds Acceptance and Rejection Status Reporting for Istio APIs
Google Cloud Service Mesh now surfaces acceptance and rejection status codes for Istio API resources, letting operators see detailed error codes through resource and mesh state displays.
└─GCP Release Notes
May 13
May 13·cat news/20260513-k8s-cncf-kubecon-japan-2026-sc
cat news/20260513-k8s-cncf-kubecon-japan-2026-sc
CNCF Debuts KubeCon + CloudNativeCon Japan 2026 Schedule
CNCF has published the full session schedule for KubeCon + CloudNativeCon Japan 2026, taking place July 29-30 at PACIFICO Yokohama, with registration open through June 16.
└─CNCF
May 8
May 8·cat news/20260508-k8s-cncf-microcks-incubating
cat news/20260508-k8s-cncf-microcks-incubating
Microcks Promoted to CNCF Incubating Project
The CNCF TOC voted on May 7 to advance Microcks from Sandbox to Incubating status, recognizing its growth as a cloud-native API mocking and contract testing platform.
└─CNCF Blog
May 8
May 8·cat news/20260508-cicd-github-agentic-wf-sec
cat news/20260508-cicd-github-agentic-wf-sec
GitHub Details Defense-in-Depth Security Architecture for Agentic CI/CD Workflows
GitHub published a comprehensive security model for agentic workflows, covering sandboxed execution, credential isolation, and full traceability across trust boundaries.
└─InfoQ
────────────────────────────────────────────────────────────
Jun 1
Jun 1·cat news/20260601-supply-chain-miasma-redhat-npm-teampc
cat news/20260601-supply-chain-miasma-redhat-npm-teampc
Miasma Supply Chain Attack Hits 32 Red Hat npm Packages via Compromised CI/CD Pipeline
TeamPCP's latest Mini Shai-Hulud variant compromised 96 versions across 32 @redhat-cloud-services npm packages — the fifth time this actor has pulled the same playbook in six weeks, and their first confirmed pivot to GitHub Actions OIDC tokens instead of individual developer credentials.
└─Wiz Research
May 31
May 31·cat news/20260531-supply-chain-triple-registry-npm-pypi-docker
cat news/20260531-supply-chain-triple-registry-npm-pypi-docker
Three Simultaneous Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours
Three separate credential-stealing campaigns targeted npm, PyPI, and Docker Hub within the same 48-hour window — the Docker Hub incident involved a trojanized Trivy image and picked up CVE-2026-33634.
└─GitGuardian
May 28
May 28·cat news/20260528-supply-chain-openssf-python-secure-coding
cat news/20260528-supply-chain-openssf-python-secure-coding
OpenSSF cuts its first Python Secure Coding Guide to v1.0.0
Among the OpenSSF Community Day North America roundup, the headline artifact is a 1.0.0 Python secure-coding guide developers can actually pin against.
└─OpenSSF
May 25
May 25·cat news/20260525-supply-chain-trapdoor-ai-config-stealer
cat news/20260525-supply-chain-trapdoor-ai-config-stealer
TrapDoor: a cross-ecosystem stealer that poisons your AI assistant
Socket flagged a coordinated stealer across three package registries that also drops poisoned AI config files to turn your coding assistant against you.
└─The Hacker News
May 20
May 20·cat news/20260603-cves-advisories-defender-kev-june3-deadl
cat news/20260603-cves-advisories-defender-kev-june3-deadl
CISA Sets June 3 Deadline for Two Exploited Microsoft Defender Zero-Days
CVE-2026-41091 lets a local attacker escalate to SYSTEM through Defender's Malware Protection Engine, while CVE-2026-45498 kills definition updates — patched together, federal deadline June 3.
└─WinBuzzer / The Hacker News
May 27
May 27·cat news/20260527-cves-advisories-cisa-kev-linux-ivanti-panos
cat news/20260527-cves-advisories-cisa-kev-linux-ivanti-panos
Three infrastructure CVEs hit CISA's KEV — patch PAN-OS first
CISA added three infrastructure CVEs to its Known Exploited Vulnerabilities catalog on May 27 — a Linux kernel local privilege escalation to root, an Ivanti EPMM authenticated RCE, and an unauthenticated out-of-bounds write in PAN-OS that also lands root.
└─CISA
May 27
May 27·cat news/20260527-cves-advisories-cisa-kev-supply-chain
cat news/20260527-cves-advisories-cisa-kev-supply-chain
CISA puts three supply-chain compromises on the patch clock
CISA marked credential-stealing compromises in DAEMON Tools Lite, TanStack, and the Nx Console editor extension as actively exploited and added all three to its Known Exploited Vulnerabilities catalog.
└─CISA
May 26
May 26·cat news/20260526-cves-advisories-litespeed-cpanel-kev-exploited
cat news/20260526-cves-advisories-litespeed-cpanel-kev-exploited
Patch LiteSpeed now — CISA confirms the perfect-10 cPanel bug is being exploited
Three days after disclosure, CISA added the maximum-severity LiteSpeed cPanel privilege-escalation flaw to its Known Exploited Vulnerabilities catalog with a federal patch deadline of May 29.
└─CISA
May 25
May 25·cat news/20260525-cves-advisories-ghost-cms-cve-2026-26980
cat news/20260525-cves-advisories-ghost-cms-cve-2026-26980
Ghost CMS SQL injection is hijacking 700+ sites — Harvard and DuckDuckGo among them
A critical SQL injection in Ghost's Content API, patched back in February, is being mass-exploited to steal admin API keys and inject ClickFix malware into more than 700 sites.
└─BleepingComputer
May 21
May 21·cat news/20260521-cves-advisories-cisa-kev-langflow-trendmicro
cat news/20260521-cves-advisories-cisa-kev-langflow-trendmicro
CISA Adds Langflow and Trend Micro Apex One to KEV Catalog
CISA flagged CVE-2025-34291 (Langflow origin validation error) and CVE-2026-34926 (Trend Micro Apex One directory traversal) as actively exploited, requiring federal agencies to patch under BOD 22-01.
└─CISA
May 20
May 20·cat news/20260520-cves-advisories-cisa-kev-may20-seven-cves
cat news/20260520-cves-advisories-cisa-kev-may20-seven-cves
CISA KEV Adds Seven CVEs Including Two 2026 Microsoft Defender Flaws and Five Legacy Exploits
Seven vulnerabilities joined the KEV catalog on May 20, mixing two fresh Microsoft Defender CVEs with five bugs from 2008-2010 that are, apparently, still being weaponized.
└─CISA
May 17
May 17·cat news/20260517-cves-advisories-cisco-sdwan-cve-2026-20182
cat news/20260517-cves-advisories-cisco-sdwan-cve-2026-20182
CISA Orders Federal Agencies to Patch Cisco Catalyst SD-WAN Auth Bypass CVE-2026-20182 by May 17
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited in the wild, with CISA mandating federal agency remediation by May 17, 2026 and no complete workaround available short of upgrading.
└─BleepingComputer
May 10
May 10·cat news/20260510-cves-advisories-ivanti-epmm-cisa
cat news/20260510-cves-advisories-ivanti-epmm-cisa
CISA May 10 Deadline Passes for Ivanti EPMM Remote Code Execution Flaw
CISA's May 10 remediation deadline for an Ivanti Endpoint Manager Mobile improper-input-validation bug enabling authenticated-admin RCE has now lapsed, increasing exposure for federal and enterprise deployments.
└─CISA
May 10
May 10·cat news/20260510-cves-advisories-ivanti-epmm-cve6973
cat news/20260510-cves-advisories-ivanti-epmm-cve6973
CISA Adds Ivanti EPMM CVE-2026-6973 to KEV; Federal Patch Deadline Is Today
Ivanti Endpoint Manager Mobile carries a CVSS 7.2 RCE flaw under active exploitation, and CISA ordered Federal Civilian Executive Branch agencies to apply patches by May 10, 2026.
└─The Hacker News
May 9
May 9·cat news/20260509-cves-advisories-cve-2026-0300-deadline
cat news/20260509-cves-advisories-cve-2026-0300-deadline
CISA Deadline Passes for PAN-OS CVE-2026-0300 as Patches Remain Unavailable Until May 13
The CISA May 9 remediation deadline for the actively exploited Palo Alto PAN-OS root-level RCE (CVE-2026-0300) has arrived with official patches still not available, requiring agencies to apply interim mitigations immediately.
└─The Hacker News
May 28
May 28·cat news/20260528-platform-security-microshift-grpc-patch
cat news/20260528-platform-security-microshift-grpc-patch
Red Hat patches gRPC auth-bypass in MicroShift 4.16.63
RHSA-2026:20436 lands the gRPC-Go fix for CVE-2026-33186 in MicroShift, closing an authorization bypass triggered by a non-canonical request path.
└─Red Hat
May 12
May 12·cat news/20260512-platform-security-cve-2026-32202-cisa-kev
cat news/20260512-platform-security-cve-2026-32202-cisa-kev
CISA KEV Deadline: Federal Agencies Must Patch Windows Shell CVE-2026-32202 by May 12
CISA's May 12 patching deadline for CVE-2026-32202 — an APT28-exploited Windows Shell spoofing flaw enabling zero-click NTLMv2 hash theft — arrives today, requiring the April 2026 cumulative update KB5083769.
└─CISA / The Hacker News
────────────────────────────────────────────────────────────
Jun 2
Jun 2·cat news/20260602-github-gitlab-copilot-desktop-app-prev
cat news/20260602-github-gitlab-copilot-desktop-app-prev
GitHub Copilot Gets a Standalone Desktop App
GitHub announced a technical preview of a standalone Copilot desktop application that consolidates coding agents, pull requests, issues, and development sessions in one place.
└─GitHub
Jun 1
Jun 1·cat news/20260601-github-gitlab-copilot-ai-credits-bill
cat news/20260601-github-gitlab-copilot-ai-credits-bill
GitHub Copilot Switches to AI Credits Billing Today
Copilot's billing model flips to usage-based AI Credits on June 1, replacing Premium Request Units with token-consumption pricing at $0.01 per credit.
└─GitHub Blog
Jun 1
Jun 1·cat news/20260601-github-gitlab-copilot-actions-min-bill
cat news/20260601-github-gitlab-copilot-actions-min-bill
GitHub Copilot Code Review to Start Consuming GitHub Actions Minutes on June 1, 2026
Starting June 1, 2026, Copilot code review on private repositories will draw from GitHub Actions minutes under the new AI Credits billing model.
└─Microsoft Learn
May 29
May 29·cat news/20260529-github-gitlab-copilot-cli-1056
cat news/20260529-github-gitlab-copilot-cli-1056
Copilot CLI opens the model picker to free and student accounts
Copilot CLI 1.0.56 lets Free and Student users pick a model other than Auto, on top of a long run of terminal-rendering and config fixes.
└─GitHub
May 29
May 29·cat news/20260529-github-gitlab-copilot-usage-cohorts
cat news/20260529-github-gitlab-copilot-usage-cohorts
Copilot's usage metrics API now sorts developers into AI-adoption phases
GitHub added an adoption-phase classifier to the Copilot usage metrics API, bucketing each engaged developer by how they actually use the tool over a rolling 28-day window.
└─GitHub
Jun 30
Jun 30·cat news/20260630-ides-microsoft-ends-claude-code-lice
cat news/20260630-ides-microsoft-ends-claude-code-lice
Microsoft Phases Out Internal Claude Code Licenses by June 30
Microsoft is retiring Claude Code seats for Experiences & Devices engineers by June 30, consolidating those workflows onto GitHub Copilot CLI instead.
└─WinBuzzer
May 30
May 30·cat news/20260530-ides-claude-code-auto-mode
cat news/20260530-ides-claude-code-auto-mode
Claude Code opens auto mode to Bedrock, Vertex, and Foundry
Version 2.1.158 lets Opus 4.7 and 4.8 run auto mode on the three big cloud backends, not just Anthropic's first-party API.
└─Claude Code changelog
May 28
May 28·cat news/20260528-ides-vscode-1122-airgapped-byok
cat news/20260528-ides-vscode-1122-airgapped-byok
VS Code 1.122 ships air-gapped BYOK and a browser device emulator
VS Code 1.122 lands air-gapped BYOK support for Ollama and other local models, a browser device emulator for responsive testing, and a preview Agents Window for managing multi-project agent sessions.
└─Visual Studio Code Blog
May 20
May 20·cat news/20260520-ides-vscode-1121-mermaid-remote
cat news/20260520-ides-vscode-1121-mermaid-remote
VS Code 1.121 Adds Native Mermaid Preview, HTML Preview, and Remote Agent Sessions
VS Code 1.121 ships built-in Mermaid diagram rendering in Markdown previews, native HTML file preview without extensions, and a preview of agent sessions running on remote machines over SSH or dev tunnels.
└─Visual Studio Code
May 20
May 20·cat news/20260520-ides-android-studio-cli-agents
cat news/20260520-ides-android-studio-cli-agents
Google Releases Stable Android Studio CLI Tool for Agent Workflows at Google I/O 2026
Google shipped a stable command-line interface for Android Studio at Google I/O 2026, enabling AI agents to programmatically access Android Studio capabilities.
└─Google Developers Blog
May 15
May 15·cat news/20260515-build-tools-msvc-preview-may-2026
cat news/20260515-build-tools-msvc-preview-may-2026
MSVC Build Tools Preview May 2026 Ships C++23 consteval Propagation and ARM64 Improvements
Microsoft's May 2026 MSVC build tools preview delivers C++23 consteval propagation (P2564R3), C++ modules fixes, ARM64 Neon and loop optimizations, and an AddressSanitizer heap-address caching speedup.
└─Microsoft C++ Team Blog
May 1
May 1·cat news/20260501-build-tools-figma-desktop-may-2026
cat news/20260501-build-tools-figma-desktop-may-2026
Figma desktop app update improves file navigation and search for recent work
Figma's May 1 desktop update lets users move between files without losing context, opens links in place rather than spawning new windows, and adds search over recently accessed work.
└─Figma
────────────────────────────────────────────────────────────
Jun 1
Jun 1·cat news/20260601-governance-eu-ai-act-cop-labeling
cat news/20260601-governance-eu-ai-act-cop-labeling
EU AI Act Code of Practice on AI Content Labeling Due in June as August Enforcement Looms
The EU is publishing its voluntary Code of Practice for AI-generated content transparency this month, ahead of the full AI Act becoming enforceable on August 2, 2026.
└─EU Commission / artificialintelligenceact.eu
May 18
May 18·cat news/20260518-governance-open-source-summit-na
cat news/20260518-governance-open-source-summit-na
Open Source Summit North America Opens May 18 in Minneapolis
The Linux Foundation's Open Source Summit North America runs May 18–20 in Minneapolis, co-located with the CNCF Observability Summit.
└─Open Source Initiative
May 11
May 11·cat news/20260511-governance-gsa-open-source-panel
cat news/20260511-governance-gsa-open-source-panel
GSA Leads Government Open Source Governance Panel at O'Reilly Open Source Conference
The US General Services Administration is headlining a government panel on open source policy and governance at the O'Reilly Open Source Conference in Austin on May 11, 2026.
└─GSA / O'Reilly
May 1
May 1·cat news/20260501-governance-osi-state-open-source
cat news/20260501-governance-osi-state-open-source
OSI's 2026 State of Open Source Report Frames AI Tooling as a Dependency Risk
The Open Source Initiative's 2026 annual report identifies open source as a strategic asset while calling out AI coding assistants as a new vector for uncontrolled dependency intake.
└─Open Source Initiative
Jun 1
Jun 1·cat news/20260601-industry-kubecon-india-2026-june
cat news/20260601-industry-kubecon-india-2026-june
KubeCon + CloudNativeCon India 2026 Scheduled for June 18-19 in Mumbai
CNCF's India edition of KubeCon runs June 18-19 in Mumbai, the conference's first dedicated India event of the 2026 cycle.
└─CNCF
May 29
May 29·cat news/20260529-industry-142k-layoffs-ai-infra-anal
cat news/20260529-industry-142k-layoffs-ai-infra-anal
142,000 Tech Layoffs in Five Months — Profitable Companies Are Funding AI Infra on Headcount Savings
A late-May tally puts year-to-date tech layoffs at 142,000 across 212+ companies, with the $700B AI infrastructure build cited explicitly as the destination for payroll savings.
└─TechTimes
May 28
May 28·cat news/20260528-industry-ibm-redhat-project-lightwell
cat news/20260528-industry-ibm-redhat-project-lightwell
IBM and Red Hat back open-source security with $5B Project Lightwell
IBM and Red Hat are committing $5 billion to a clearinghouse that triages and patches open-source vulnerabilities for enterprises.
└─IBM Newsroom
May 25
May 25·cat news/20260525-industry-wix-1000-layoffs-ai
cat news/20260525-industry-wix-1000-layoffs-ai
Wix cuts ~1,000 jobs — a fifth of its staff — in its largest layoff yet
Wix said it will lay off around 1,000 people, near a fifth of its workforce, blaming a strong shekel and an AI-driven rethink of how it builds software.
└─Calcalist
May 15
May 15·cat news/20260515-hiring-comptia-tech-jobs-three-year
cat news/20260515-hiring-comptia-tech-jobs-three-year
CompTIA: New Tech Job Postings Hit Three-Year High in April 2026
April 2026 saw 271,483 new tech job postings — the strongest year-over-year gain of 2026 and a three-year peak — signaling that the tech hiring market has moved from recovery into sustained expansion.
└─CompTIA / PR Newswire
May 11
May 11·cat news/20260511-hiring-fidelity-3300-new-hires-20
cat news/20260511-hiring-fidelity-3300-new-hires-20
Fidelity Plans 3,300 Net-New Hires in 2026, Half in Tech, Alongside Restructuring
Despite trimming 800 roles from its agile squad organization, Fidelity Investments is targeting 3,300 new hires this year — roughly half in technology and product — plus 2,000 early-career positions, making it one of the larger financial-services hiring programs announced so far in 2026.
└─Boston Globe
May 1
May 1·cat news/20260501-hiring-aws-11000-developers
cat news/20260501-hiring-aws-11000-developers
AWS Plans to Hire 11,000 Developers in 2026 Despite Industry-Wide Layoffs
AWS CEO Matt Garman announced a plan to bring on 11,000 developers this year, framing the hires as necessary for AI-driven cloud infrastructure while defending concurrent AI-led workforce reductions elsewhere.
└─Analytics Insight
May 1
May 1·cat news/20260501-hiring-junior-dev-contraction
cat news/20260501-hiring-junior-dev-contraction
Junior Developer Roles Contract as AI Tools Absorb Entry-Level Work
AI coding tools are displacing work previously assigned to junior engineers, raising serious concerns about the long-term health of the developer talent pipeline.
└─Rest of World
May 4
May 4·cat news/20260504-career-gsoc-2026-contributors-welcome
cat news/20260504-career-gsoc-2026-contributors-welcome
Google Summer of Code 2026 Welcomes 1,141 Contributors; Coding Period Begins May 25
Google has selected 1,141 contributors across 184 mentoring organizations for GSoC 2026, with the official coding period opening May 25.
└─Google Open Source Blog
May 1
May 1·cat news/20260501-career-displaced-workers-landing
cat news/20260501-career-displaced-workers-landing
Displaced Tech Workers Finding Roles in Cloud, Security, and Mid-Market IT Leadership
Cloud migration, cybersecurity, and mid-market IT leadership are emerging as the primary landing zones for tech professionals displaced by 2026's wave of layoffs.
└─Kore1
────────────────────────────────────────────────────────────
May 28
May 28·cat news/20260528-design-systems-figma-make-launch
cat news/20260528-design-systems-figma-make-launch
Figma Make Launches as an AI Coding Agent That Connects Canvas to Your Codebase
Figma Make shipped on May 28 as a distinct AI agent that reads prompts, edits your canvas, and writes the corresponding code changes against your local codebase via MCP.
└─Figma Help Center
May 20
May 20·cat news/20260520-design-systems-figma-agent-beta-la
cat news/20260520-design-systems-figma-agent-beta-la
Figma Launches Agent in Beta for Generative Design and Automation
Figma's new embedded agent generates and remixes designs, handles repetitive tasks, and respects your existing design system — rolling out gradually in beta with no credit cost during the preview.
└─Figma
May 12
May 12·cat news/20260512-design-systems-figma-mcp-server-launch
cat news/20260512-design-systems-figma-mcp-server-launch
Figma Launches Full MCP Server with Code-to-Canvas Workflows and Variable Engine
Figma's May 2026 release formalizes its MCP Server at mcp.figma.com/mcp, shipping four agent skills, three design-to-code workflows, and a live variable engine that syncs Figma values to code tokens in real time.
└─Figma Help Center
May 1
May 1·cat news/20260501-design-systems-figma-desktop-update
cat news/20260501-design-systems-figma-desktop-update
Figma Desktop Update Improves File Navigation and Recent Work Search
Figma's May 1 desktop update lets users move between files without interruptions and makes recent work searchable.
└─Figma
May 20
May 20·cat news/20260520-css-html-in-canvas-api-google-io
cat news/20260520-css-html-in-canvas-api-google-io
Google I/O 2026: HTML-in-Canvas API Brings Accessible, Searchable 3D Web Experiences
Google announced the HTML-in-Canvas API at I/O 2026, enabling developers to render HTML content inside canvas elements for immersive 3D experiences that remain fully accessible and indexable.
└─Google Developers Blog
May 5
May 5·cat news/20260505-css-chrome-148-container-lazy
cat news/20260505-css-chrome-148-container-lazy
Chrome 148 Adds Name-Only Container Queries and Lazy Loading for Video and Audio
Chrome 148 ships two web-platform improvements: container queries that match by name without requiring container-type, and lazy loading support via loading="lazy" on video and audio elements.
└─Chrome Developers
May 1
May 1·cat news/20260501-css-w3c-css-snapshot-2026
cat news/20260501-css-w3c-css-snapshot-2026
W3C Publishes CSS Snapshot 2026
The W3C released CSS Snapshot 2026, the authoritative reference cataloguing which CSS specifications are stable and suitable for implementation.
└─W3C
May 1
May 1·cat news/20260501-motion-svelte-motion-types-exported
cat news/20260501-motion-svelte-motion-types-exported
Svelte 5.55.0 Exports Motion Primitive Types from svelte/motion
Svelte 5.55.0 now exports TweenOptions, SpringOptions, EasingFunction, and related types directly from the svelte/motion module, making them available for typed consumer code.
└─Svelte Blog
May 1 → Jun 2all226 entries