Urgent.News

What's breaking now, across thousands of outlets.

Tech

React 19.3, the compiler, and a CVSS 10: what changed while you weren't looking

Esta semana saqué Create React App de un proyecto y dejé escrito el plan para sacarlo de otro. Los dos eran de 2022 y 2023, y los dos seguían funcionando. Eso es lo engañoso: seguir funcionando y seguir siendo la forma correcta de hacerlo son cosas distintas, y entre una y otra pasaron cuatro cambios grandes en React que no se enteran solos. Ninguno es un rumor. Los cuatro están publicados en el…

Translated from Spanish Read in Spanish

The React ecosystem has seen significant changes with the release of several updates. React Compiler, which reached version 1.0 on October 7, 2025, automatically memoizes components and hooks, making some manual optimizations obsolete. Additionally, a critical vulnerability was discovered in React Server Components on December 3, 2025, with a CVSS score of 10.0, which allowed for remote code execution.

Several patches were released to address this issue, affecting popular frameworks such as Next, React Router, and Waku. React 19.3, released on September 9, 2026, introduced new features, including ViewTransition for animating elements and improved handling of refs in Fragments.

Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Generated Video Delivery — Status-Gated Download URLs in Marketplace OCR Pipelines

Short answer: issue a generated-video download URL only after the persisted asset is ready and its moderation evidence covers the bytes a buyer will receive.

  • Download URLs released only after OCR coverage completed and verified
  • Download URL minted from ready record with attached OCR decision
  • State transitions from submitted to ready to blocked with clear paths

A Docker container is containment, not a credential boundary

The RubyGems story has a detail that keeps tripping me up. The "GemStuffer" gems didn't sneak payloads through gem install.

  • Docker containers do not provide secure credential boundaries
  • Containers only contain blast radius, not secure access
  • Exposed credentials and sessions pose significant risks

More from Wednesday 16 September →