Joas Schilling

@nickvergessen
153 Followers
113 Following
253 Posts
πŸ‘₯ Open Source
βš™οΈ Software Engineer, πŸ’¬ Talk Team Lead and πŸ›‘οΈ Security Team Lead @nextcloud
Homepagehttps://www.schilljs.com/
Verificationhttps://www.schilljs.com/

Introducing Nextcloud Hub 26 Spring: Built together, designed for the future πŸš€ 

What’s new:
πŸ’« Refined design and performance
✏️ Collabora & Euro-Office
πŸ’Œ Groupware updates
πŸ“ˆ Gantt chart in Nextcloud Deck
🧩 Pexip & Matrix integration
πŸ’ͺ Empowering developer platform

https://nextcloud.com/blog/nextcloud-hub26-spring/

How does software engineering in IT looks as of May 2026?

βœ”οΈ AI AI AI

βœ”οΈ AI driven layoffs not 1 or 2 employees but it comes in thousands of layoffs at a time

βœ”οΈ package manager getting compromised is daily event

βœ”οΈ cloud provider blocks your account randomly using AI agents and AI support doesn't understand anything

βœ”οΈ github hacked and all code is available for sale

βœ”οΈ AI submitted low quality patches overwhelming FLOSS devs

what else am i missing?

πŸ”’ Released setup-php 2.37.1

Includes important security fixes for input handling and Composer GitHub auth.

Please update!

πŸ“œ https://setup-php.com/r/tag/2.37.1

Release 2.37.1 Β· shivammathur/setup-php

Changelog Security Updates Fixed shell command escaping and PHP version input validation. Please see GHSA-pqwm-q9pv-ph8r. NoteThis can affect workflows that pass values from users or pull request...

GitHub
🚨 Security advisory: Composer 2.9.8 and 2.2.28 (LTS) fix a vulnerability that lead Composer to leak GitHub Actions GITHUB_TOKENs and GitHub App installation tokens into job logs.
GitHub's new ghs_<id>_<JWT> token format fails Composer's validation regex; the rejected token is printed into the error message and secret masking does not reliably catch it.
Update now or disable affected Actions workflows.
https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages

Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions issued GITHUB_TOKENs or GitHub App installation tokens to the GitHub Actions logs. GitHub introduced a

Private Packagist

Reclaim your digital autonomy: Meet Nextcloud Hub 26 Winter! πŸš€

🌐 Growing sovereignty: new federation, export and import features
πŸ’¬ Pin & schedule messages
πŸ”Ž File comparison
πŸ§‘β€πŸŽ¨ New Whiteboard tools
πŸ” New E2EE options
πŸ’ͺ Speed-up: ADA engine
πŸͺ„ more in all apps!

https://nextcloud.com/blog/nextcloud-hub26-winter/

RE: https://social.coop/@cwebber/115964484421440911

Then I have bad news for you about OSS software. It's not dead yet, but I fear it will be. The costs of developing are going up (slop bug bounty reports), the cost of infra are going up (LLM "learner" agents slam open projects with traffic), and real developers aren't being trained, It's a matter of time, and we probably can't even undo it at this point.

curl, which is one of the most popular CLI/API tools for network requests and data transfer on Linux/Unix, is to discontinue its HackerOne bug bounty program due to "too strong incentives to find and make up 'problems' in bad faith that cause overload and abuse".

The authors simply cannot keep up with LLM-generated fake security reports created to collect money using bots. So, it now shuts down at the end of January 2026. This is why we can't have good things

https://github.com/curl/curl/pull/20312

BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026 by bagder Β· Pull Request #20312 Β· curl/curl

Remove mentions of the bounty and hackerone. There will be more mentions, blog posts, timings etc in the coming weeks.

GitHub

Dear services that refuse email addresses that have the name of the service in the address:

We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

RE: https://phpc.social/@Xdebug/115662135830755552

I have just released Xdebug 3.5.0!

In the next few weeks I will create some content (text, and perhaps video) highlighting some new features in more detail.

Please share it with the world!

#php #php85 #xdebug #debugging

Ich hab da mal was designed