"The AI Compass: 15 questions. Where do you actually land on AI?" bambamramfan.github.io/ai-compass/
Kévin Dunglas
@dunglas.dev
⚒️ FrankenPHP.dev, Mercure.rocks, @api-platform.com, @symfony.com 🧑💻 Founder of @les-tilleuls.coop, a developer co-op
Ignore the propaganda in that Qwen ad for a second. The core question for the Left remains valid: boycotting AI is a dead end. AI and robotics give us the tools to build the work-free, post-scarcity utopia envisioned by Lafargue and Bookchin.
"Face à l'IA, le refus moral et le boycott constituent une défaite stratégique. Sortir du purisme pour contester le contrôle politique et social de cette technologie est un impératif." blogs.mediapart.fr/paul-bartali...
Face à l'IA, dépasser l'impuissance
Face à l'IA, le refus moral et le boycott constituent une défaite stratégique. Sortir du purisme pour contester le contrôle politique et social de cette technologie est un impératif.
blogs.mediapart.fr
Just improved Caddy performance by fixing header casing on the hot path! 🚀 When using Go's net/http, make sure to use canonical HTTP header casing (e.g. Content-Type instead of content-type). Non-canonical keys trigger string formatting and allocations on every lookup. github.com/caddyserver/...
caddyhttp: use canonical header key casing to avoid re-canonicalization by dunglas · Pull Request #7911 · caddyserver/caddy
Summary http.Header.Get/Set re-canonicalize the passed key and allocate a new string whenever it isn't already in canonical MIME header form. Three call sites in the codebase were passing non-c...
github.com
Carré Bompard sur l'IA ! www.youtube.com/watch?v=wTTY...
L'HOMME DE L'OMBRE DE MÉLENCHON : MANUEL BOMPARD RÉVÈLE LA STRATÉGIE DE LFI
Aujourd'hui dans "Ils font Marseille", nous recevons Manuel Bompard, député de la 4e circonscription des Bouches-du-Rhône et coordinateur national de La France Insoumise. De son parcours atypique…
youtube.com
Isolate deprecated code in dedicated files behind dedicated build tags. Years later you delete ~1,700 lines in one PR, zero issues. Thanks, past-me. github.com/dunglas/merc...
FrankenPHP 1.12.5 is a security release. Upgrade if you run the official Docker images or the session extension as a shared module. Fixed: the default Docker welcome page ran phpinfo() (env vars, php.ini, system paths, all exposed). Now a static page with nothing to leak.
🔒 Vulcain 1.4.2 is out, a security release. Fixes 3 vulnerabilities in Preload/Fields directive handling: • High: quadratic response rebuild (DoS) • Medium: unbounded JSON-pointer recursion • Low: HTTP/2 push-counter race Upgrade: github.com/dunglas/vulc...
Release v1.4.2 · dunglas/vulcain
Security release fixing three vulnerabilities in request-directive handling, all reported by Alexandre Daubois (Les-Tilleuls.coop). Users on 1.4.1 and earlier should upgrade. 🔒 Security Fixes High...
github.com
We are incredibly proud to have @laravel.com support as a Gold sponsor for #APIPlatformCon 2026! The community is gathering in full force, and with Jeremy Nikolic's upcoming talk on the schedule, the energy in Lille is going to be unmatched. Join them now: api-platform.com/con/2026/
The countdown to #APIPlatformCon is on! Incredible speakers, deep-tech talks, and a surprise announcement during my opening keynote. If you are building real-time apps or exploring AI integrations, you need to be in the room. Secure your spot before tickets sell out: 👉 api-platform.com/con/2026/
Introducing prompt-mac: Turn a fresh Mac into an agent-first dev powerhouse with one command 🚄 github.com/dunglas/prom...
GitHub - dunglas/prompt-mac: one-shot, AI-first macOS setup for Apple Silicon
one-shot, AI-first macOS setup for Apple Silicon. Contribute to dunglas/prompt-mac development by creating an account on GitHub.
github.com
📢 #APIPlatformCon speaker reveal! Meet Yohan Giarelli who will demonstrate next September a fun "proof of concept" project: using a tech stack of PHP, Symfony, and Mercure to remotely unlock parcel lockers from a PWA. Don't miss out: api-platform.com/con/2026/tic...
@dunglas.dev and I just published a preprint on exposing Hypermedia APIs to LLM agents via a Dynamic Gateway Architecture Thanks @p20n.w3c.social.ap.brid.gy for depositing this work hal.science/hal-05630480
Making sure you're not a bot!
hal.science
Let's face it: coding agents work pretty well these days, and Claude Code is the leader. That's why I recently patched Symfony Docker to support it out of the box.
This link will take you to a page that’s not on LinkedIn
lnkd.in
🔒 API Platform CVE-2026-49858: JSON:API & HAL normalizers cached components across users on long-running runtimes (FrankenPHP, RoadRunner, Swoole). Patched in 4.1.29 / 4.2.25 / 4.3.8 — upgrade now. github.com/api-platform...
Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
### Impact `#[ApiProperty(security: ...)]` is evaluated per request to decide whether a property is exposed. The `componentsCache` arrays in `ApiPlatform\JsonApi\Serializer\ItemNormalizer` and `Ap...
github.com
FrankenPHP 1.12.4 is out, a security hardening release. Underscore header spoofing is now blocked at the server layer (Caddy 2.11.4), bundled Mercure 0.24.2 security fixes land, plus worker-mode crash and race fixes. Every user should upgrade. github.com/php/frankenp...
Release v1.12.4 · php/frankenphp
FrankenPHP 1.12.4 is a hardening and stability release. It pulls in upstream security fixes from Caddy 2.11.4 and Mercure 0.24.2, closes a class of HTTP header spoofing, and fixes several crashes a...
github.com
Mercure 0.24.2 is out: a security hardening release. Rejects SSE field injection (CWE-93) via id/type, blocks reserved-namespace forgery, fixes a Last-Event-ID leak, caps element counts against DoS. Upgrade your hub. github.com/dunglas/merc...
Release v0.24.2 · dunglas/mercure
Community Mercure 0.24.2 is a security hardening release. It closes an SSE field-injection vector (CWE-93), blocks forgery of the hub's reserved subscription-event topics, fixes a metadata leak in ...
github.com
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05... #php #opensource
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
thephp.foundation
Ready to code at the speed of thought? ⚡ Forget Docker headaches and slow cache warmups. At #SymfonOnline, I’m showing how FrankenPHP redefines @symfony.com DX with instant setups, true hot reloading via Mercure, and sandboxed AI agent integration. 📅 June 12 🎟️ live.symfony.com/2026-online-...
Schedule | SymfonyOnline June 2026
SymfonyOnline June 2026 (June 11 – 12, 2026)
live.symfony.com
This is exactly why we built FrankenPHP's extension infrastructure! Check out FrankenScriptling: a new extension that lets you use the Scriptling scripting language (Python-like) inside PHP. Since Scriptling is in Go, FrankenPHP makes embedding it seamless. Love seeing this! 🐘🐹
Building Frankenscriptling: Running Scriptling Inside FrankenPHP
A dive into embedding a Python-like scripting language into PHP via a Go-based web server. Because why not.
medium.com
Mercure 0.24.1 is out, riding on Caddy 2.11.3. We contributed native OTLP metrics push to Caddy upstream. Drop metrics { otlp } in your Caddyfile, set the OTEL_* env vars, and hub metrics land in any OTLP collector. github.com/dunglas/merc...
Release v0.24.1 · dunglas/mercure
Community Mercure 0.24.1 picks up Caddy 2.11.3, including our upstream contribution that adds OTLP metrics push to Caddy. The Helm chart now also surfaces a JSON values schema and a signed .prov pr...
github.com
🚀 FrankenPHP 1.12.3 is out! ⚡️ 7-8% throughput bump from a refreshed PGO profile 🔒 Fixes CVE-2026-45062 (CVSS 8.1) unsafe Unicode handling flaw. Upgrade if on v1.11.2 - v1.12.2! ⚙️ Adds per-thread max_requests & cross-platform thread force-kill. Release notes: github.com/php/frankenp...
Release v1.12.3 · php/frankenphp
This release fixes CVE-2026-45062 (high, CVSS 8.1): unsafe Unicode handling in CGI path splitting let an attacker have a non-.php file executed as PHP via a crafted URL, in any deployment where att...
github.com
Mercure 0.24 is out 🚀 Native OpenTelemetry tracing for the Hub: publish, subscribe, subscriptions, and transport history spans nest under Caddy's tracing directive, with zero allocations when disabled. github.com/dunglas/merc...
Release v0.24.0 · dunglas/mercure
Community Mercure 0.24 adds native OpenTelemetry tracing for the Hub's core operations, lets you point at a JWK Set on disk instead of running a separate HTTP endpoint, and ships a Helm chart that ...
github.com
🚀 Mercure v0.23.5 just landed! We've brought major Helm chart hardening for Kubernetes (NetworkPolicies, readOnlyRootFS, and tighter PodSecurity). I wrote a blog post covering all the new security and performance details. Check it out: dunglas.dev/2026/05/merc... #Kubernetes #Helm
Mercure 0.23.5: Helm chart hardening - Kévin Dunglas
Mercure v0.23.5 just landed, and the dominant theme is the Helm chart. If you run hubs on Kubernetes, especially in HA or multi-tenant mode, this release tightens defaults and adds the kind of policy ...
dunglas.dev
🚀 Mercure 0.23 is out! 🩺 Transport-aware Health Checks: K8s now detects actual broken connections, not just a live Caddy process. 🛥️ Helm: HTTProute support + deployment annotations. 🏢 Enterprise transports fully supported. 🔗 github.com/dunglas/merc...
Release v0.23.0 · dunglas/mercure
Community Transport-aware health checks come to Mercure. Kubernetes (and any other orchestrator) can now detect when a hub's transport connection is actually broken, not just that the Caddy process...
github.com
We've just finalized our next-gen AI-powered security audit tool at @les-tilleuls.coop! We used it to discover and patch a critical vulnerability in Mercure as well as in several of our clients' projects. The Mercure fix also made topic matching 38% faster! ⚡️
Coding at the Speed of Thought: The New Era of Symfony Docker dunglas.dev/2026/03/codi...
Coding at the Speed of Thought: The New Era of Symfony Docker - Kévin Dunglas
If we want to discuss Developer Experience (DX) in 2026, we have to talk about instantaneous feedback and coding agents. At SymfonyLive Paris 2026, I presented "Coding at the Speed of Thought: Symfony...
dunglas.dev
I'm cooking up something pretty insane for SymfonyLive Paris! Buckle up. 🐳🤖
Dimanche, Lille a rendez-vous avec l'histoire : devenons la première grande ville française à expérimenter 🌱✊ l'Écologie Sociale et 🗣️ le communalisme. Un seul bulletin permet l'alternative : "Lille insoumise, écologiste et populaire" menée par Laouharia Addouche. @offensive.eco #DimancheJeVoteLFI