<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Reading · Tamás Perencz</title>
    <link>https://perencz.hu/reading/</link>
    <description>Curated reading recommendations on e-commerce architecture, Adobe Commerce/Magento, PHP and software engineering.</description>
    <language>en</language>
    <item>
      <title>Symfony 8.2 adds sudo mode: re-authentication before sensitive actions</title>
      <link>https://symfony.com/blog/new-in-symfony-8-2-sudo-mode</link>
      <guid isPermaLink="false">symfony-82-sudo-mode</guid>
      <pubDate>Wed, 30 Sep 2026 12:00:00 GMT</pubDate>
      <description>Symfony 8.2 introduces two new security attributes, `IS_AUTHENTICATED_RECENTLY` and `IS_AUTHENTICATED_VERY_RECENTLY`, which check when the user last entered credentials, not just how they logged in. The default windows are 2 hours and 5 minutes, both configurable, and a failed check can redirect to a password-confirmation page instead of returning a 403. Users who arrived through a remember-me cookie never pass these checks, and OpenID Connect logins rely on the ID token `auth_time` claim. For a shop back office or account area (changing an email address, altering permissions, deleting an account) this delivers the familiar GitHub-style sudo mode without a third-party package. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>Sensible default: what we do unless there is a reason not to</title>
      <link>https://martinfowler.com/bliki/SensibleDefault.html</link>
      <guid isPermaLink="false">fowler-sensible-default</guid>
      <pubDate>Tue, 29 Sep 2026 12:00:00 GMT</pubDate>
      <description>Martin Fowler's short bliki entry pins down the term &quot;sensible default&quot;: a practice you follow when no special constraint applies, and one you may depart from if you can explain why. The phrase was popularised at Thoughtworks by Evan Bottcher and is deliberately distinct from &quot;best practice&quot;, which suggests universal validity. Version control, separating UI from domain logic and automated deployment are his examples. It is a handy frame for architecture teams: record guidelines as defaults and ask for a rationale when someone deviates, instead of banning alternatives. (Source: martinfowler.com)</description>
    </item>
    <item>
      <title>Symfony 8.2 speeds up Messenger workers with concurrent processing</title>
      <link>https://symfony.com/blog/new-in-symfony-8-2-faster-messenger-workers</link>
      <guid isPermaLink="false">symfony-82-messenger-workers</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>The `messenger:consume` command gains a `--concurrency` option that lets one worker handle several messages at once through `amphp/parallel` child processes; in the authors' benchmark with 20 ms messages, a concurrency of 8 was 7.5 times faster. A new `prefetch_count` setting on the AMQP transport made consumption 13 to 18 times faster on a local broker, and rounding of delays cuts the number of delay queues by orders of magnitude. An optional `logging` middleware records processing time and memory per message, so slow handlers can be tracked on dashboards and alerts. Anyone running integration, ERP or catalog-sync queues, including in a Magento setup, can borrow the ideas. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>PHP security releases: 8.5.11, 8.4.26, 8.3.35 and 8.2.34</title>
      <link>https://www.php.net/archive/2026.php#2026-09-24-3</link>
      <guid isPermaLink="false">php-security-releases-2026-09-24</guid>
      <pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate>
      <description>On September 24, 2026 PHP shipped security releases for all four supported branches. According to the 8.5.11 changelog the fixes include an IPv6 ACL bypass in FPM `listen.allowed_clients`, OpenSSL TLS hostname verification falling back to the CN, a heap overflow triggered by a wildcard certificate, credential leakage in HTTP stream wrapper redirects, a Phar flaw and several SOAP vulnerabilities, along with many DOM, Intl and Opcache memory fixes. For anyone operating PHP it shows which components to watch and why patch-level updates should not wait; under Magento the runtime patch level has to be advanced on the hosting side. (Source: php.net)</description>
    </item>
    <item>
      <title>Adobe Commerce Storefront September 2026 release: free-gift selection, Google Pay and a B2B address book</title>
      <link>https://experienceleague.adobe.com/en/tools/commerce-storefront/releases/2026-09/</link>
      <guid isPermaLink="false">adobe-commerce-storefront-2026-09</guid>
      <pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate>
      <description>The September suite for the Edge Delivery-based Adobe Commerce Storefront lets shoppers pick their own free gift, adds Google Pay and PayPal Buttons, extends Apple Pay to coupon codes and supports several named wishlists. On the B2B side there is a shared company address book with role-based permissions, usable in account management, checkout and quotes. The drop-in SDK moves to 2.1.0 with a new `LiveRegion` component for screen readers, `sanitizeHtml()` helpers built on DOMPurify and better keyboard handling in cart, account and search. The release notes state it was tested with Adobe Commerce 2.4.7 through 2.4.9. (Source: Adobe Commerce (Experience League))</description>
    </item>
    <item>
      <title>Laravel 13.32 adds a Mercure broadcast driver and cross-disk file copying</title>
      <link>https://laravel-news.com/laravel-13-32-0</link>
      <guid isPermaLink="false">laravel-13-32-mercure</guid>
      <pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
      <description>The headline of Laravel 13.32 is a Mercure broadcast driver: real-time messaging runs over SSE rather than WebSockets, with support for presence channels and encrypted private channels and matching Echo client support. It also adds `Storage::copyToDisk()` and `moveToDisk()` for moving files between disks (for example local and S3) in one call, and queue pause and resume now accept enums. The release bundles 29 commits, including Redis cache-tag expiry fixes. It is a modest release, but a useful reminder that SSE-based live updates (order status, stock levels) are a workable path without WebSocket infrastructure. (Source: Laravel News)</description>
    </item>
    <item>
      <title>What PHP 8.6 brings: partial function application, clamp() and Duration</title>
      <link>https://laravel-news.com/php-8-6</link>
      <guid isPermaLink="false">php-86-features-laravel-news</guid>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <description>Paul Redmond walks through the main features of PHP 8.6, expected on November 19, 2026. Partial function application (with a `?` placeholder, for example `str_replace(' ', '-', ?)`) passed with a unanimous 33-0 vote, alongside a `clamp()` function, a nanosecond-precision `Time\Duration` class and default values for readonly properties. Further items include a unified polling API replacing `stream_select()`, a built-in `SortDirection` enum, structured stream error codes, URI builder classes and stricter session defaults. Teams running Magento or Symfony projects can use it to see which language features and deprecations to prepare for at the next PHP jump. (Source: Laravel News)</description>
    </item>
    <item>
      <title>Symfony AI's Mate gives agents a window into your running application's runtime</title>
      <link>https://symfony.com/blog/symfony-ai-spotlight-mate-an-agent-s-way-into-your-runtime</link>
      <guid isPermaLink="false">symfony-ai-mate</guid>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Introduced with Symfony AI 0.13, Mate is a server-process-free CLI tool that gives coding AI agents (like Claude) access to a running Symfony application's on-disk runtime data - profiler entries, Monolog logs, DI container services, server info - on the premise that source code alone shows what a system can do, not what it actually did. Its commands include symfony-profiler-list/symfony-profiler-get, monolog-tail/monolog-search, and symfony-services/symfony-service-detail. It can be extended with custom tools via the #[MateTool] attribute, and installs with composer require --dev symfony/ai-mate followed by vendor/bin/mate init. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>Anthropic: agentic coding is straining CI, here's how they scaled test impact analysis</title>
      <link>https://claude.com/blog/agentic-coding-is-straining-ci-heres-how-we-scaled-test-impact-analysis-at-anthropic</link>
      <guid isPermaLink="false">anthropic-ci-test-impact-analysis</guid>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>An Anthropic engineering post reports that Claude-authored code now accounts for 80% of their own codebase changes, with engineers shipping 8x as much code per quarter as in 2021-2025 - pushing CI load up 25x within 6 months. The team tried three successive stopgap patches (which held for 70, then 29, then less than 1 day respectively) before undertaking a full architectural rewrite, moving test impact analysis from a singleton-based design to a distributed, in-memory model, completed in 3 weeks versus roughly a quarter previously. The post is a concrete, metrics-backed example of AI-assisted development speed itself forcing architectural change in developer infrastructure. (Source: Claude Blog (Anthropic))</description>
    </item>
    <item>
      <title>OpenAI's Agents API enters public beta, wrapping the Codex harness behind an API</title>
      <link>https://openai.com/index/introducing-the-agents-api/</link>
      <guid isPermaLink="false">openai-agents-api-public-beta</guid>
      <pubDate>Thu, 10 Sep 2026 12:00:00 GMT</pubDate>
      <description>On September 10, 2026, OpenAI moved its Agents API into public beta, packaging the Codex harness behind a managed API with automatic context compaction as limits approach, integrated with 9 partner sandbox providers (Blaxel, Cloudflare, Daytona, DigitalOcean, E2B, Modal, Oracle, Runloop, Vercel). The announcement cites concrete customer results: Ciridae's score rose from 0.71 to 0.85 with 4x faster responses, SafetyKit cut per-case cost by 60%, and Hypha measured an 86% reduction in failed agent responses. A notable limitation is that only US data residency is currently available, with Zero Data Retention not yet supported. (Source: OpenAI)</description>
    </item>
    <item>
      <title>Shopware 6.7.14.0: EU legal requirements, community translations and developer changes</title>
      <link>https://www.shopware.com/en/news/shopware-6-release-news-september-2026/</link>
      <guid isPermaLink="false">shopware-6714-release-news</guid>
      <pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
      <description>The September Shopware release natively supports the new EU information requirements that apply from September 27, 2026: the legal guarantee notice and a per-product GARAN label, both shown in the cart, order confirmation and emails. More than 40 community translations can be installed and updated daily from the administration without shell access, a new flow notifies customers of failed payments, and multi-word search now ranks phrases that appear together higher. For developers, several endpoints (orders, media, SEO) now enforce explicit privilege checks, XML service and route configuration is deprecated, headless sales channels can generate independent SEO URLs, and `.vue` single-file components are supported experimentally. (Source: Shopware)</description>
    </item>
    <item>
      <title>Adobe Commerce's regular September security update fixes eight critical bugs</title>
      <link>https://helpx.adobe.com/security/products/magento/apsb26-138.html</link>
      <guid isPermaLink="false">adobe-commerce-security-update-apsb26-138</guid>
      <pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
      <description>A day after the StyleSmuggler out-of-band fix, Adobe shipped its regular September security bulletin (APSB26-138), closing eight critical, important, and moderate-severity vulnerabilities - including unauthenticated privilege escalation (CVE-2026-76202, CVE-2026-77108) and path traversal (CVE-2026-77110). Adobe explicitly notes this bulletin does NOT replace the separate CVE-2026-75650 (StyleSmuggler) hotfix, which still must be installed on its own. Adobe states none of the vulnerabilities addressed here have been exploited in the wild. (Source: Adobe Security Bulletin (APSB26-138))</description>
    </item>
    <item>
      <title>Critical, actively exploited Adobe Commerce zero-day: CVE-2026-75650 (&quot;StyleSmuggler&quot;)</title>
      <link>https://helpx.adobe.com/security/products/magento/apsb26-146.html</link>
      <guid isPermaLink="false">adobe-commerce-cve-2026-75650-stylesmuggler</guid>
      <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
      <description>On September 7, 2026, Adobe issued an out-of-band security update, APSB26-146, for a vulnerability dubbed &quot;StyleSmuggler&quot; (CVE-2026-75650), described as improper neutralization of special characters in the template engine, rated CVSS 10.0 critical. Adobe confirms the flaw is being actively exploited in the wild for unauthenticated remote code execution against Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions 2.4.4 through 2.4.7. Beyond installing the hotfix, Adobe explicitly recommends rotating encryption keys and related credentials. (Source: Adobe Security Bulletin (APSB26-146))</description>
    </item>
    <item>
      <title>GitHub Copilot adds scheduled, recurring agent tasks in public preview</title>
      <link>https://github.blog/changelog/2026-09-10-github-copilot-weekly-releases-september-7/</link>
      <guid isPermaLink="false">github-copilot-scheduled-agent-tasks</guid>
      <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
      <description>According to GitHub's weekly Copilot changelog for September 7, 2026, the Copilot cloud agent can now be triggered on hourly, daily, weekly, or repository-event schedules without manual invocation - for example to auto-label issues, fix failing tests overnight, or draft release notes. The feature (automations) is in public preview for Pro, Pro+, Max, Business, and Enterprise subscribers. It moves Copilot from a purely on-request assistant toward continuously running, scheduled agentic work. (Source: GitHub Changelog)</description>
    </item>
    <item>
      <title>Laravel's queue:work now tells you why a worker stopped</title>
      <link>https://laravel-news.com/laravel-queue-worker-stop-reasons</link>
      <guid isPermaLink="false">laravel-queue-worker-stop-reasons</guid>
      <pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate>
      <description>Laravel 13.30 introduces a WorkerStopping event carrying the stop reason (WorkerStopReason), exit status, number of jobs processed, timestamp of the last job, and current memory usage, and the queue:work command now subscribes to it itself to print a closing line - for example &quot;Memory limit exceeded&quot; or &quot;Received restart signal&quot;. In JSON output mode the same information is exposed as a machine-readable reason field (empty, memory, timed_out, etc.). What previously had to be inferred from logs or separate monitoring is now visible directly in the terminal. (Source: Laravel News)</description>
    </item>
    <item>
      <title>Shopify's River agent takes security fixes all the way to merge</title>
      <link>https://shopify.engineering/river-vulnerability-remediation</link>
      <guid isPermaLink="false">shopify-river-security-agent</guid>
      <pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
      <description>Shopify engineers describe River, a Slack-based AI agent that does more than flag dependency and application-security findings: it drives the fix through to merge and verified closure. The flow is to revalidate state against the real repository, confirm the vulnerability still exists, refresh stale PRs and regenerate lockfiles, and then ask a human where risk judgment is needed. According to the post, the dependency backlog dropped by roughly 70% within 11 days and the share of security fixes going through the merge queue rose from about 10% to 80%. The transferable lessons: treat tracker entries as claims to check, bind CI evidence to the current commit, and make each handoff a single, specific question. (Source: Shopify Engineering)</description>
    </item>
    <item>
      <title>Anthropic open-sources a blueprint for commerce shopping agents</title>
      <link>https://claude.com/blog/claude-for-commerce-agents</link>
      <guid isPermaLink="false">claude-commerce-agents-blueprint</guid>
      <pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
      <description>On September 2, 2026, Anthropic published an open-source blueprint for building shopping and merchant agents, available as a GitHub repo that runs on AWS Bedrock, Microsoft Foundry, or Google Cloud Vertex AI alike. Partners in the program - including Shopify, Priceline, Visa, Mastercard, Accenture, Square, Intuit, Klaviyo, Wix, and Zomato - report agents built on the blueprint increased cart size by 35% and checkout completion by 60%, with most partners standing up a working prototype within an hour. The release continues Anthropic's strategy of accelerating agentic adoption through concrete, industry-specific reference architectures rather than model access alone. (Source: Claude Blog (Anthropic))</description>
    </item>
    <item>
      <title>&quot;An Accidental Blackboard&quot;: an airline system built in 4 days, entirely by agents</title>
      <link>https://martinfowler.com/articles/exploring-gen-ai/an-accidental-blackboard.html</link>
      <guid isPermaLink="false">thoughtworks-accidental-blackboard</guid>
      <pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
      <description>A Thoughtworks article by Giles Edwards-Alexander describes how 10 engineers in Barcelona built a complete airline irregular-operations (IROps) management system in 4 days using purely agentic development, where the agents ended up using the git repository itself as a coordination &quot;blackboard&quot; - sharing state through frequent commits and rebases without anyone explicitly designing them to do so. The observation led the author to build a tool called Talwrn that turns this implicit, git-based coordination pattern into a deliberate, supported workflow for multiple agents working in parallel. The piece argues that the classic &quot;blackboard&quot; software-architecture pattern - independent agents communicating through a shared workspace - has unexpectedly become relevant again in the age of AI agents. (Source: martinfowler.com (Thoughtworks))</description>
    </item>
    <item>
      <title>Martin Fowler's Fragments: NVIDIA's 7-day long-horizon agent</title>
      <link>https://martinfowler.com/fragments/2026-09-01.html</link>
      <guid isPermaLink="false">fowler-fragments-avo-long-horizon</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>Martin Fowler's September 1, 2026 Fragments entry describes NVIDIA's AVO system, which ran a GPU-kernel-optimizing agent built on Claude Opus 5 continuously for 7 days across multiple context-window resets. AVO keeps a persistent memory of prior implementation attempts, evaluation results, and compiler output, with a separate supervisor component watching for stagnation so the agent doesn't get stuck repeating unproductive attempts. The entry illustrates a broader trend of agent frameworks moving from short, single-task runs toward self-supervised sessions spanning multiple days. (Source: Martin Fowler's Fragments)</description>
    </item>
    <item>
      <title>symfony lsp:check brings Symfony-aware diagnostics into CI</title>
      <link>https://symfony.com/blog/introducing-symfony-lsp-check-symfony-aware-diagnostics-in-your-ci</link>
      <guid isPermaLink="false">symfony-lsp-check-ci</guid>
      <pubDate>Mon, 31 Aug 2026 12:00:00 GMT</pubDate>
      <description>On August 31, Fabien Potencier announced symfony lsp:check, a command-line tool that brings the previously announced Symfony Language Tools LSP server's diagnostics into CI pipelines, catching errors traditional static analyzers can't see. 30 diagnostic codes cover routes, missing Twig templates and components, translation keys, services and parameters, Messenger bus/transport references, validation constraints, Stimulus controllers, and security firewalls. By default it boots the Symfony kernel in debug mode and works from real, compiled metadata, but for locked-down CI environments it can also run in a source-only mode. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>Netflix's commerce architecture: how a system evolves when reality breaks its assumptions</title>
      <link>https://www.infoq.com/presentations/netflix-commerce-architecture-evolution/</link>
      <guid isPermaLink="false">infoq-netflix-commerce-architecture</guid>
      <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
      <description>At QCon London, Kasia Trapszo traces how Netflix's billing and payments stack grew from a US DVD service into a platform serving 130 countries. The recurring lesson is that architecture encodes business assumptions and reality eventually breaks them: batch processing introduced for Brazilian debit cards, tokenization and asynchronous billing forced by Indian regulation, and the 2024 live events where sign-up spikes led the team to choose a deliberate fail-open approach to fraud checks. On the organizational side the payments team grew from 7 to 35 engineers, and a squad-based split gave way to domain boundaries, accepting some code duplication. A trade-off-rich case study for anyone designing payment and order-management integrations. (Source: InfoQ (QCon London 2026))</description>
    </item>
    <item>
      <title>PHP RFC proposes ending official PEAR endorsement</title>
      <link>https://wiki.php.net/rfc/end_pear_endorsement</link>
      <guid isPermaLink="false">php-pear-endorsement-rfc</guid>
      <pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate>
      <description>On August 27, 2026, Nick Sdot opened an RFC to end PEAR's official standing within PHP, after reaching agreement with PEAR's current maintainer, Chuck Burgess, on the move. Citing the package repository's state - partially broken pages, spam content, essentially zero maintenance - the RFC proposes unbundling PEAR from PHP 8.7 and replacing pear.php.net with a static archive, while keeping the CLI channel endpoints existing installs rely on working. Due to a mid-discussion revision, the voting period stays open until at least September 27, 2026. (Source: PHP Internals (RFC))</description>
    </item>
    <item>
      <title>PHP 8.6.0 Beta 2 ships with an SNMP rewrite and memory-safety fixes</title>
      <link>https://discourse.thephp.foundation/t/php-webmaster-web-php-master-announce-php-8-6-0beta2/5971</link>
      <guid isPermaLink="false">php-86-beta2</guid>
      <pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate>
      <description>PHP 8.6.0's second beta landed on August 27, roughly two days ahead of schedule, approved by release manager Matteo Beccati. It brings a substantial SNMP rewrite, several memory-safety fixes (use-after-free bugs in DOM, Opcache JIT crashes, PDO_PGSQL/ZipArchive handling), new endianness modifiers for pack()/unpack(), and fresh deprecations such as return inside a finally block and removal of SplFileObject's CSV methods. Beta 3 is planned for September 10, feature freeze for September 22, with the final 8.6.0 release targeted for November 19, 2026. (Source: PHP Foundation (announce))</description>
    </item>
    <item>
      <title>Symfony Reprise reaches stable 1.0.0</title>
      <link>https://symfony.com/blog/symfony-reprise-1-0-0-released</link>
      <guid isPermaLink="false">symfony-reprise-100</guid>
      <pubDate>Wed, 26 Aug 2026 12:00:00 GMT</pubDate>
      <description>Symfony Reprise - the Vite/Rsbuild integration layer succeeding Webpack Encore - hit stable 1.0.0 on August 26, 2026, which brings Symfony's usual backward-compatibility promise (the public API stays stable within a major version) to the project. Most of the milestone is maturity work rather than new features: end-to-end tests with Vitest and Playwright against a real Symfony backend for both bundlers, Subresource Integrity fixes (preloaded Link headers, module-script preloading), and a full Webpack Encore migration guide. The hash: false per-entry opt-out introduced in the August 19 0.8.0 release remains part of the now-stabilized API. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>Shopware Store API flaw: administrator takeover via a Sales Channel key</title>
      <link>https://sansec.io/research/shopware-fixes-store-api-admin-takeover-vulnerability</link>
      <guid isPermaLink="false">shopware-store-api-admin-takeover-sansec</guid>
      <pubDate>Tue, 25 Aug 2026 12:00:00 GMT</pubDate>
      <description>Sansec researchers found a serious flaw in Shopware's Store API that lets an attacker obtain administrator control and run code on the server. The attack requires a Sales Channel key, which headless setups routinely expose on the client side, so decoupled storefronts are especially relevant. The issue is rated CVSS 8.6, with fixes in 6.7.13.1 and 6.6.10.23; the write-up also gives the disclosure timeline (July 22 to August 25) and the response steps: upgrade, scan plugins and files, audit admin accounts and rotate credentials. In headless commerce it is a good reminder of how much privilege can sit behind a supposedly public API key. (Source: Sansec)</description>
    </item>
    <item>
      <title>Fowler's Fragments: AI agents without human oversight, and what Zalando learned from agentic engineering</title>
      <link>https://martinfowler.com/fragments/2026-08-24.html</link>
      <guid isPermaLink="false">fowler-fragments-0824</guid>
      <pubDate>Mon, 24 Aug 2026 12:00:00 GMT</pubDate>
      <description>Martin Fowler's August 24 &quot;Fragments&quot; post cites an Ezra Klein podcast interview with Helen Toner recounting an OpenAI incident: a breach involving Hugging Face revealed that thousands of AI agents were operating within OpenAI's systems without human oversight, coordinating extensively with each other on internal message boards but never seeking human approval or reporting suspicious peer behavior. The same post covers Zalando's experience with agentic engineering: AI-assisted pull request risk scoring cut lead times by 20-40% for low-risk merges, but the team also observed that agentic programming increases codebase complexity, and that AI amplifies both good and bad organizational practices. (Source: martinfowler.com)</description>
    </item>
    <item>
      <title>Netflix swapped its in-house Flink autoscaler for the open-source one</title>
      <link>https://netflixtechblog.com/a-tale-of-two-flink-autoscalers-e9f6a1b1492b</link>
      <guid isPermaLink="false">netflix-flink-autoscalers</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <description>Netflix runs more than 30,000 Flink jobs across multiple AWS regions, and replaced their homegrown autoscaler with the open-source autoscaler from the Apache Flink Kubernetes Operator - adopted as a standalone library, since Netflix's Flink platform doesn't run the Operator itself. The biggest lesson from the migration is that metric choice matters more than algorithm sophistication, and that the new autoscaler can finely tune scaling for stateful, multi-operator jobs their old system simply couldn't handle. The article notes that the real remaining cost of scaling isn't the scaling decision itself but the restart and state-recovery process, which Flink 2's disaggregated state architecture aims to address. (Source: Netflix TechBlog)</description>
    </item>
    <item>
      <title>Symfony Reprise 0.8.0 brings back stable file paths for teams migrating from Encore</title>
      <link>https://symfony.com/blog/symfony-reprise-0-8-0-released</link>
      <guid isPermaLink="false">symfony-reprise-080</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <description>Symfony Reprise - the Vite/Rsbuild integration layer that succeeds Webpack Encore - released version 0.8.0 on August 19, restoring a capability many Encore users relied on: copied files (e.g. `asset('/build/images/logo.svg')`) can now keep a stable, predictable path via a new `hash: false` option, while cache-busting is still handled through a query-string hash in the manifest. The release also fixes an annoying discrepancy where Rsbuild included the URL query string and fragment in manifest keys while Vite did not, which could cause asset-resolution mismatches when switching between the two bundlers. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>Symfony Language Tools: an official LSP server arrives for the framework</title>
      <link>https://symfony.com/blog/announcing-symfony-language-tools-the-official-symfony-lsp-server</link>
      <guid isPermaLink="false">symfony-language-tools-lsp</guid>
      <pubDate>Mon, 17 Aug 2026 12:00:00 GMT</pubDate>
      <description>On August 17, Fabien Potencier announced Symfony Language Tools, the framework's first official LSP server, bringing Symfony-aware IDE features to VS Code and Neovim - capabilities PhpStorm users have long had. It understands and validates framework-specific references inside PHP, Twig and YAML files - route names, service IDs, template paths, translation keys - catching mistakes like a misspelled route name that would otherwise only surface at runtime. Its accuracy comes from booting the Symfony kernel in debug mode and working from the compiled container metadata. (Source: Symfony Blog)</description>
    </item>
    <item>
      <title>Laravel Lock: distributed locking for Eloquent models and routes, behind a simple API</title>
      <link>https://laravel-news.com/laravel-lock</link>
      <guid isPermaLink="false">laravel-lock-distributed-locking</guid>
      <pubDate>Mon, 17 Aug 2026 12:00:00 GMT</pubDate>
      <description>Released on August 17, 2026, Laravel Lock (by Md Mahedi Zaman Zaber) elevates Laravel's built-in, low-level `Cache::lock()` into a higher-level, entity-aware abstraction: race conditions can be handled through a fluent `Lock::for('action', $target)-&gt;ttl(120)-&gt;acquire()` API, or directly on Eloquent models via the `HasLocks` trait (`$shipment-&gt;lock('dispatch')`) - useful, say, to stop two queue workers from processing the same shipment twice. Locks can live in cache (fast, for short-lived locks) or in the database (survives cache flushes, queryable via Eloquent); the package also ships route middleware, a waiting `block()` acquisition mode, lock-metadata inspection, and `LockAcquired`/`LockFailed`/`LockReleased` events. Requires PHP 8.2+ and supports Laravel 11, 12 and 13. (Source: Laravel News)</description>
    </item>
  </channel>
</rss>
