CloudNativePG 1.30.1 修复扩展路径校验绕过与集群切换挂起问题
CloudNativePG 1.30.1 修复了扩展路径校验绕过漏洞:此前含 `..` 的绝对路径可通过验证,运行时解析后能逃出扩展挂载点,现在这类记录会在 admission 检查、主版本升级和已存 Cluster 规格处理时被拒绝或跳过。
Awaiting translation
CloudNativePG 1.30.1 修复了扩展路径校验绕过漏洞:此前含 `..` 的绝对路径可通过验证,运行时解析后能逃出扩展挂载点,现在这类记录会在 admission 检查、主版本升级和已存 Cluster 规格处理时被拒绝或跳过。
Awaiting translation
Cloudflare 的 workerd 1.20260924.1 新增 env.AI.websearch 接口,为 Workers AI 提供网页搜索,并把 REST 请求的调用方上下文传给下游 AI Gateway。
Awaiting translation
Lovable 聊天功能现已免费开放,Free、Pro 和 Business 工作区每天都有免费聊天额度。用户可以让它评估该做哪个创意、把客户反馈整理成计划,或分析已上线应用的代码和 Lovable Cloud 数据库用量。聊天在生成图片、视频或转交 Plan、Build 时仍照常消耗 credits,当前聊天定价(含每日免费额度)适用至 2026 年 10 月 31 日。
Awaiting translation
Visual Studio Code 1.139 稳定版发布,AI 智能体现在可以在 SSH、Tunnel 和 WSL 远程主机的 Dev Containers 中构建和测试项目,使用容器内配置的工具与依赖。
Awaiting translation
GitHub 于 9 月 23 日为 GitHub Copilot App 推出本地沙箱,目前处于公开预览,仅适用于使用本地仓库和工作树的会话。沙箱可分别限制文件系统读写路径、外网与局域网访问,以及 Git credentials 和 GitHub CLI 数据的使用,企业策略还能进一步收紧;若操作系统无法应用规则,隔离环境会报错退出而不执行命令。
Awaiting translation
UiPath 于 9 月 23 日更新 UiPath Platform,Automation Suite 全栈现可在本地 Linux 基础设施上运行,面向有数据存储、安全和环境控制要求的企业。
Awaiting translation
OpenAI 于 9 月 22 日在 API 发布 gpt-6-sol 和 gpt-6-luna,两者接受文本和图像输入、只生成文本。标准处理下,GPT-6 Sol 每百万输入 token 收费 2 美元、缓存 token 0.20 美元、输出 10 美元;GPT-6 Luna 分别为 0.10、0.01 和 0.50 美元。
Awaiting translation
systemd 262 于 9 月 22 日发布,可将 PID 1 与 executor 编译为单一静态链接二进制文件,用于小型容器,且不通过 dlopen() 加载额外库、无需 NSS 查找用户和组。
Awaiting translation
On September 22, Anthropic released its flagship model Claude Opus 5.5, aimed at developers and teams who want agents to handle multi-step tasks like coding and data analysis. The company says it delivers better performance and lower cost than Opus 5.
Why it matters: Anthropic's published pricing and the default workload cost reduction help developers estimate the migration cost for long-running agent tasks.
Cursor has released two bots, Rollouts and Security Review, both available on Team and Enterprise plans.
Why it matters: The official docs cover the monitoring and security review workflows for both bots, so readers can judge whether they fit into their existing delivery pipeline.
Lovable has shipped Opus 5.5, which the company says matches Opus 5 in results while cutting the number of steps by one-third to one-half. On Lovable's internal benchmarks, Opus 5.5 ties Opus 5 on 0-to-1 builds and iterative code changes, and comes out 4% to 6% ahead on validation discipline; across all reasoning effort levels, steps per task drop by 26% to 57% and input tokens fall by 21% to 59%, with the differences significant at the 95% confidence level.
Why it matters: Lovable shares official comparison data between Opus 5.5 and Opus 5 on step counts and tokens, so readers can judge the real change in build efficiency.
Cline CLI 3.0.63 发布,修复了 Windows 下可能从工作目录而非系统 PATH 执行 rg、git、powershell 的问题,恶意仓库放置的 rg.exe 等文件可能在索引阶段、确认提示之前就被执行,新版本在 CLI 及其后台服务启动时禁用该行为。
Awaiting translation
Awaiting translation
MiMo-V2.6-Pro debuts as the top open weights model on the Artificial Analysis Intelligence Index (46). At $0.13 per Intelligence Index task, it lands on the Intelligence vs. Cost per Task Pareto frontier @Xiaomi has just released MiMo-V2.6-Pro, an open weights model with major advances in intelligence over its predecessor, MiMo-V2.5-Pro (Intelligence Index: 26). Despite the improvement, it retains the same attractive pricing at $0.435 per 1M input tokens (with a 99% cache-hit discount) and $0.87 per 1M output tokens. This makes MiMo-V2.6-Pro one of the most cost-efficient models to deploy. MiMo-V2.6-Pro is an MoE model with 1.02T total parameters and 42B active parameters. Stay tuned for additional analysis of the model. Check out MiMo-V2.6-Pro full benchmarking breakdown here: https://artificialanalysis.ai
Lovable 与 AWS、CrowdStrike、Databricks、Docker、Google Cloud、Okta、Proofpoint、Salesforce、ServiceNow、Wiz、Zscaler 共同成为 Blueprint Alliance 创始成员,该联盟推动面向企业级 AI 智能体安全与治理的开放参考架构。
Awaiting translation
俄罗斯团队 Маракуйя ИИ 的智能体框架首次参加 Terminal-Bench 4 和 OSWorld 2 两项基准测试,取得亮眼成绩。
Awaiting translation
Superpowers 6.4 发布,新增对 Meta Muse、OpenCode 2.0 和 Qwen Code 三个编程智能体的支持,并重写了 executing-plans 技能中的 Native Execution。
Awaiting translation
Claude Code 从 2.1.277 版本开始支持 AGENTS.md:当文件夹中没有 CLAUDE.md 时,Claude 会检查并使用 AGENTS.md。该支持基于 Claude Code mods 构建,这是其即将推出的定制 Claude Code harness 的方式,属于内置 mod,用户之后也可以自行构建自定义版本的项目指令。
Awaiting translation
Lovable has released OJ, a preview engine written from scratch in Rust. It reads your existing vite.config.ts and runs real Vite plugins through a compatibility layer, all in a single binary, with no toolchain installed into the project.
Why it matters: Lovable rewrote its preview engine OJ in Rust, sharing cold start and memory comparisons against Vite, plus canary data from production.
Cline has released an early version of its open-source desktop app, Cline Desktop, moving the agent runtime that previously lived in the VS Code extension and CLI into a standalone workspace. It supports parallel sessions, scheduled tasks, and a Marketplace for extending tools and integrations.
Why it matters: The official release lays out the desktop app's capabilities and open entry points, so readers can judge whether it fits their multi-agent parallel workloads.
开发者 pdfu 在 iOS 27 和 macOS Golden Gate 的私有框架中发现,Apple 的新 Siri 架构设计了与第三方 AI 模型对接的机制。
Awaiting translation
Cursor introduces “Projects,” a feature built for long-running work like a single feature, a migration, or an entire application. It keeps context over months and delegates tasks to thousands of sub-agents. Projects are powered by cloud agents: the coordinating agent doesn’t write code, it only plans, assigns work, and hands back results, spinning up local agents when on-device testing is needed. Each project keeps a set of files synced between the cloud and local machines, steadily accumulating research findings, artifacts, and knowledge of the codebase.
Why it matters: The official docs lay out the context-sharing and auto-triggering mechanisms for project-based multi-agent collaboration, which you can use to judge how long-running tasks get taken over.
Lovable 正式启动 Partner Program,分为面向独立开发者和小型机构的 Expert 与面向咨询公司、系统集成商的 Solution Partner 两条路径,并提供 Partner Directory 供企业查找和雇佣伙伴。
Awaiting translation
Lovable 上线 drafts 功能,为项目创建带独立对话和预览的副本,团队可并行探索同一项目的多个版本,改动只有接受并发布后才会应用到线上应用。该功能适用于任何项目,首个版本仅覆盖前端改动,涉及数据库结构或登录设置的修改仍需在项目对话中完成。
Awaiting translation
GitHub has launched Project HydraFusion as a research preview in the Copilot CLI. It uses runtime orchestration to pick an execution plan across models from multiple providers. Users select it just like any other model, and billing follows each model's standard rates.
Why it matters: GitHub lays out three orchestration modes for HydraFusion and compares cost versus quality across three benchmarks, so you can judge the trade-offs of multi-model orchestration on real coding tasks.
On September 3, 2026, OpenAI released GPT-6 Astra and Astra Pro, initially limited to enterprises in the Daybreak cybersecurity program, with paid ChatGPT, the API, and AWS opening up over the following days.
Why it matters: We break down the benchmark comparison between GPT-6 Astra and Fable 5.1, pointing out that the tested versions and harnesses differ across teams, so readers can judge which scores are actually comparable.
Cursor supports self-hosted machines: code repositories, build artifacts, and secrets all stay on internal machines within your own infrastructure, and the agent handles tool calls locally. My Machines connects a single laptop or VM to a personal workflow, while Team Pools are named worker queues for teams or enterprises—scaling capacity up with requests and down when workers disconnect. Pools aren't tied to code repositories, and idle machines can sleep and then resume within a reconnection window.
Why it matters: The official docs lay out pooled scheduling and sandbox integration for self-hosted machines, so readers can judge whether tool execution can stay within their own network.
Lovable 现已接入 Fable 5.1,早期测试显示其在修复和改进现有应用上比 Fable 5 最高提升 17%,单任务成本最多降低 31%。该模型在中等和高推理强度下的 UI 与视觉设计质量最高提升 3.5%,并会在完成任务前打开浏览器运行应用进行自我验证。Lovable 正将卡住的会话以及更长、更复杂的任务路由到 Fable 5.1。
Awaiting translation
WikiSkill 是一个让 Agent Skill 与持久知识库(wiki)协同演化的框架,它把原始执行经验、累积知识和可执行 Skill 分离,并持续将经验沉淀进 wiki 供后续 Skill 更新使用。
Awaiting translation
Terminal-Bench 发布 4.0 版本,校准任务的时间、CPU 和内存资源,修复 19 个任务并移除 8 个饱和或存在质量问题的任务,所有任务统一设为 8 小时 agent 超时。
Awaiting translation
Cursor 云端智能体不再需要连接 GitHub 或其他第三方 SCM 提供商,用户可直接输入提示开始工作,Cursor 会在后台创建 Origin 代码仓库。满意后可点击“创建代码仓库”将工作保存到 Origin,并设置私有或内部可见性。Cursor 还能通过端口转发在浏览器中实时预览云端智能体环境,连接 Vercel 账户后点击“发布”即可生成可访问 URL。
Awaiting translation
斯坦福大学研究人员主导、Terminal-Bench 团队联合全球科研机构专家打造的 Terminal-Bench-Science 0.1 发布,首批含生命、物理、地球、数学和工程科学领域的 70 项任务。
Awaiting translation
Cline 让八个模型在自家 harness 里做 IMO 2026 六道题,证明由 GPT-5.5 和 Claude Opus 5 双盲按 0–7 分制评分、Gemini 3.1 Pro 仲裁,金牌线为 29 分。
Awaiting translation
Why it matters: Cline 用同一套 harness 盲评八个模型做 IMO 2026,给出分数与单次成本对照,可看开源权重模型的实际性价比。
Vercel Connect 结束公开测试正式 GA,用运行时按任务申请、自动过期的短期 token 取代长期凭证,应用无需存储 provider secret。
Awaiting translation
OpenAI has launched Daybreak, combining ChatGPT, Codex Security, and the open-source Codex Security CLI into a security defense workflow that covers pre-merge PR reviews, repository and vulnerability backlog scans, and regular CI checks.
Why it matters: The official documentation walks through the full Codex Security workflow—from PR reviews and repository scans to CLI-based batch scanning—so you can decide how to plug it into your existing security processes.
Simon Willison 用 Claude Code for web 做了一个约 150 行、零依赖的 TypeScript 服务原型,基于 Bun 1.4 实验性的 Bun.WebView 提供 shot-scraper 风格的 JSON API,支持执行 JavaScript 和输出 PNG/JPEG/WebP 截图,无需 Puppeteer 或 Playwright。
Awaiting translation
Cursor has updated its cloud agents and Cursor harness so cloud agents can subscribe to event sources, resume when there's new activity in a PR, Slack thread, or scheduled task, and keep going until the work is done—fixing CI failures and handling bot comments.
Why it matters: Cloud agents are moving from one-shot runs to subscribing to events and following up continuously on PRs and Slack threads, which gives readers a way to judge how the boundaries of automation are shifting.
OpenAI has open-sourced the harness that drives the Codex app, CLI, and IDE extensions, and through the Codex app-server client protocol it exposes capabilities like creating threads, starting turns, receiving events, and handling approval requests.
Why it matters: With the Codex harness and app-server protocol now public, developers can see how to embed the agent in their own products and where the boundaries are.
Lovable 宣布完成 4 亿美元 C 轮融资,估值达 133 亿美元,由 Menlo Ventures 领投、Scaleup Europe Fund 联合领投。
Awaiting translation
NVIDIA has released Nemotron 3.5 Lightning, a customizable open-source model built for persistent agents, and it's now available for free in Cline.
Why it matters: NVIDIA's new open-source model is free to use on Cline, so you can decide whether it's worth switching for high-frequency agent workloads.
Anthropic 宣布从 8 月 14 日起,Pro、Max 和 Team 套餐的新会话默认运行 auto mode,并停止对分类器额外 token 开销收费;Enterprise、Claude API、AWS、Bedrock、Google Cloud 和 Microsoft Foundry 暂时保持可选,计划下个月改为默认。
Awaiting translation
Why it matters: Anthropic 公布 auto mode 的安全评测数据与内部拦截案例,可据此判断默认权限模式对现有工作流的影响。