Kévin Dunglas

@dunglas.dev

⚒️ FrankenPHP.dev, Mercure.rocks, @api-platform.com, @symfony.com 🧑‍💻 Founder of @les-tilleuls.coop, a developer co-op

🐘 FrankenPHP 1.13 is out! Caddy 2.11.7 (Slowloris protection, url_pattern matcher, RFC 10036 Incremental header), Mercure 1.0 built in, and config reloads validated before they go live. 5 security fixes, 2 rated high. Please upgrade.

Pour démarrer la semaine, lisez l'interview de @dunglas.dev : il nous parle notamment de la genèse mouvementée de FrankenPHP et tease Mercure 1.0, fruit de 5 ans de travail, qui sera sorti à l'heure où Kévin donnera son talk et animera son atelier au Forum PHP 2026 ! buff.ly/26Zgz6w

MERCURE 1.0 : BÂTIR DES APPLICATIONS TEMPS RÉEL N'A JAMAIS ÉTÉ AUSSI SIMPLE, RAPIDE ET SÉCURISÉ
Kévin DUNGLAS[ATELIER] MERCURE 1.0 : BÂTIR DES APPLICATIONS TEMPS RÉEL N'A JAMAIS ÉTÉ AUSSI SIMPLE, RAPIDE ET SÉCURISÉ
Kévin DUNGLAS

🚀 Mercure 1.0 alpha is here! The biggest release in the project’s history brings: 🎯 New matcher system built on top of the WHATWG URL Pattern ⚙️ Revamped authorization mechanism using OAuth 2.0 Rich Authorization Requests 🛠️ Brand-new UI debugger and dev playground 🔒 Security hardening

Mercure 1.0 alpha is here - Kévin Dunglas

Mercure 1.0 is here in its first public preview, and it is the biggest release in the project's history! Mercure powers mission-critical real-time communication across hundreds of production deploymen...

dunglas.dev

FrankenPHP 1.12.7 fixes a bug where output written after fastcgi_finish_request() got silently dropped in classic mode, and killed the rest of the script execution right there. If you use that pattern for background cleanup, go upgrade. github.com/php/frankenp...

Release v1.12.7 · php/frankenphp

FrankenPHP 1.12.7 fixes a bug where output written after fastcgi_finish_request()/frankenphp_finish_request() was silently discarded in classic (non-worker) mode: with the default ignore_user_abort...

github.com

Ignore the propaganda in that Qwen ad for a second. The core question for the Left remains valid: boycotting AI is a dead end. AI and robotics give us the tools to build the work-free, post-scarcity utopia envisioned by Lafargue and Bookchin.

Just improved Caddy performance by fixing header casing on the hot path! 🚀 When using Go's net/http, make sure to use canonical HTTP header casing (e.g. Content-Type instead of content-type). Non-canonical keys trigger string formatting and allocations on every lookup. github.com/caddyserver/...

caddyhttp: use canonical header key casing to avoid re-canonicalization by dunglas · Pull Request #7911 · caddyserver/caddy

Summary http.Header.Get/Set re-canonicalize the passed key and allocate a new string whenever it isn't already in canonical MIME header form. Three call sites in the codebase were passing non-c...

github.com

FrankenPHP 1.12.5 is a security release. Upgrade if you run the official Docker images or the session extension as a shared module. Fixed: the default Docker welcome page ran phpinfo() (env vars, php.ini, system paths, all exposed). Now a static page with nothing to leak.

Bild

🔒 Vulcain 1.4.2 is out, a security release. Fixes 3 vulnerabilities in Preload/Fields directive handling: • High: quadratic response rebuild (DoS) • Medium: unbounded JSON-pointer recursion • Low: HTTP/2 push-counter race Upgrade: github.com/dunglas/vulc...

Release v1.4.2 · dunglas/vulcain

Security release fixing three vulnerabilities in request-directive handling, all reported by Alexandre Daubois (Les-Tilleuls.coop). Users on 1.4.1 and earlier should upgrade. 🔒 Security Fixes High...

github.com