InfoQ Homepage News
-
Kubernetes Teams Get a Safer Way to See Their Own GPU Metrics
Adobe engineers have described an open-source approach for giving teams self-service access to their own Prometheus metrics in multi-tenant Kubernetes environments, without exposing the shared metrics of other teams.
-
Spring News Roundup: Second Milestone Releases of Boot, Framework, Data, Security, Integration
There was a flurry of activity during the week of September 21st, 2026, highlighting: second milestone releases of: Spring Boot, Spring Batch, Spring Security, Spring AMQP, Spring Integration, Spring Data, Spring Framework, Spring for GraphQL and Spring for Apache Kafka. There were also first milestone releases of Spring AI, Spring Cloud, Spring Web Services and Spring LDAP.
-
Atlassian Rebuilds Metrics Pipeline Around OpenTelemetry at Massive Scale
Software company Atlassian has published an account of its migration from gostatsd to OpenTelemetry, replacing the internal workings of a metrics platform that receives data from about 100,000 hosts across 14 regions. The existing service had a 99.95% SLO, so the team had to change the platform without disrupting the metrics used by production alerts.
-
Cloudflare Worker Previews: Per-Branch Environments for Workers
Cloudflare has introduced Worker Previews. This feature allows each Git branch to have its own isolated, production-like environment for a Worker. Each environment has a stable URL. It also has its own configuration and unique state for each branch. Plus, there’s scoped observability.
-
Python Workers Reach GA on Cloudflare, with Questions About Cold Starts and Upstream Maintenance
Cloudflare has made Python Workers generally available, built on PEP 783 and on socket syscalls implemented over the Workers connect API. The announcement carries no performance figures. A urllib3 maintainer questioned who supports the upstream work afterwards, and Wasmer's founder asked for cold-start numbers, citing about 1.027 seconds from Cloudflare's own earlier post.
-
Artifactory Vulnerabilities Under Active Exploitation Enable Authentication Bypass and Admin Access
Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits then enable dangerous activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures.
-
Radicle Discloses Critical Flaws Exposing Private Repositories in Plain Text
Radicle has identified two critical security vulnerabilities in its wire protocol, compromising confidentiality across all node releases. Attackers can access private repository data in cleartext and impersonate nodes. Due to architectural flaws, immediate halting of clearnet operations is advised. Fixes will require a shift to a new protocol (Iroh), creating backward incompatibility issues.
-
Meta’s ZGateway Cuts ZippyDB Connections 19x While Handling 1B+ Operations per Second
Meta has introduced ZGateway, a stateless proxy for ZippyDB that centralizes connection management, traffic routing, caching, load balancing, and admission control. The gateway handles more than 1 billion operations per second and about 40% of ZippyDB traffic, while Meta’s model estimates a 19x reduction in persistent connections.
-
Uber Separates Scaling Intent From Execution on Kubernetes Platform
Uber has published a detailed account of its new ServiceScale controller, which allows multiple orchestrators to safely manage the scaling of the same Kubernetes workloads. The blog post, written by senior software engineers Egor Grishechko and Srikar Paruchuru, describes how the company separated scaling intent from execution to support regional failover without carrying reserved idle capacity.
-
Linear Completes 1,000-PR Migration From styled-components to Meta's StyleX
Linear completed the transition of its React applications from styled-components to StyleX, Meta's CSS-in-JS library, involving over 1,000 pull requests. This migration aimed to enhance performance and enforce stricter component boundaries. The shift resulted in reduced main-thread work and improved navigation speeds, despite some criticism over StyleX's restrictive guidelines.
-
AWS Introduces Foreign Key Constraints in Aurora DSQL
AWS recently announced that Aurora DSQL now supports foreign key constraints, allowing applications to enforce referential integrity directly in the database, including CASCADE, SET NULL, and other referential actions. The addition addresses a long-standing gap that users had explicitly called out as an adoption blocker.
-
Java News Roundup: TornadoVM 7.0, Groovy 6.0, GraalVM, Hibernate, Quarkus, Gradle, Maven
This week's Java roundup for September 21st, 2026, features news highlighting: GA releases of TornadoVM 7.0 and Groovy 6.0; point releases of GraalVM and Gradle; maintenance releases of Quarkus and GDK for Micronaut; the seventh release candidate of Maven 4.0; milestone releases of Micrometer Metrics and Tracing; and beta releases of Open Liberty and Hibernate ORM.
-
Google Rewrites Critical C Dependencies to Rust Using AI and Differential Fuzzing
Google's security team developed a method to replace legacy C code in the giflib image-processing library with Rust, targeting inherent memory vulnerabilities. They utilised an automated migration process, ensuring compatibility and zero-day vulnerability mitigation. The project successfully maintained runtime performance while demonstrating that AI translations require ongoing human oversight.
-
Swift 6.4 Brings Subprocess 1.0, Improved Interoperability, Faster Wasm, and More
The latest release of Swift, Swift 6.4, introduces a range of language and tooling improvements, including better performance through expanded support for non-copyable values, up to 40 times faster Wasm generated code, improved interoperability with C++20 and Java, and a new Subprocess library that provides a cross-platform API for launching and interacting with external processes.
-
GKE Pod Snapshots Cut Model Load Times, and Move the Work to Snapshot Lifecycle Management
Google has published benchmarks for GKE Pod snapshots, reporting up to 89% lower startup latency and a 70B model loading in 37 seconds. The feature checkpoints CPU and GPU memory through gVisor into Cloud Storage. Practitioners have asked whether invalidation is the harder problem, since snapshots match on a spec hash, machine series, and kernel and driver versions.