Starlette 1.7.0 ships built-in OpenTelemetry tracing and exposes scope["route"] for accurate endpoint naming, plus a breaking AnyIO 4 requirement. What it means for your APM: scoutapm.com/blog/starlette-…
Predis 3.6.1 patches a real CRLF command-smuggling CVE (GHSA-w6f5-v2h6-g786) in the Redis connection layer. If your Laravel app uses the redis cache driver, queues, or sessions, this is worth prioritizing over routine deps. scoutapm.com/blog/predis-3-6…
openai-python 3.17.0 has a real breaking change queued: local shell tool output must now declare a call ID. If you're using the local shell tool, check this before upgrading. scoutapm.com/blog/openai-pyt…
Predis v3.6.1 is officially out, packaging the CRLF command-smuggling fix (CVE GHSA-w6f5-v2h6-g786) we covered when it merged, plus deprecating CommandInterface::deserializeCommand() as part of closing the gap. github.com/predis/predis/rel…
ruby-pg had a real SQL injection: PG::Connection#set_client_encoding interpolated its argument into a SET statement. The fix's repro ran pg_sleep(0.25) through it to prove arbitrary SQL executed. Patched now: github.com/ged/ruby-pg/pull/…
Anomaly Detection is out of beta and on every Scout plan, including free. It learns each endpoint's normal behavior and flags real deviations, no thresholds to set, no pages for normal Monday traffic spikes. scoutapm.com/blog/anomaly-de…
Express 5.3.0 fixes CVE-2026-2391: a qs arrayLimit bypass that let arbitrarily large arrays in a query string cause a DoS. Also fixes a Content-Length/Transfer-Encoding header conflict in res.send(). Update if you're on Express. github.com/expressjs/express…
Context is a budget and most AGENTS.md files spend it badly. Here are the three levers for what an AI coding agent actually sees, and why bigger isn't better. scoutapm.com/blog/prompts-sk…
An AI coding agent running real CI needs real credentials, unless you sandbox it first. Corral runs Claude in Docker-in-Docker, zero blast radius if it goes wrong. scoutapm.com/blog/can-we-liv…
Laravel v13.27.0 adds a Cloud facade, refreshForUpdate() for Eloquent models, and re-introduces orWhereKey()/orWhereKeyNot() without breaking Builder subclasses. Solid QoL release. #Laravel#PHPgithub.com/laravel/framework…
Three monitoring tools means three context switches every time something breaks. Error tracker, APM, log aggregator. Each is fine alone. Together they cost you 15 minutes per debugging session. There's a better way. scoutapm.com/blog/unified-lo…
anthropic-python v1.0.0 is out. The big change: httpx2 replaces httpx as the HTTP client. This is a stability commitment after 125 pre-1.0 releases. Check MIGRATION.md before upgrading. #Python#AI#Anthropicgithub.com/anthropics/anthro…
Sentry is error-first. Datadog is infrastructure-first. Neither is built for dev teams that want errors, traces, and APM in one tool without a platform team to run it. We compared all three approaches. scoutapm.com/blog/sentry-vs-…
NestJS v12 ships @nestjs/observe, a first-party observability SDK. Native tracing built into the framework instead of relying on third-party instrumentation. Here's what it means for monitoring. #NestJS#NodeJS#Observabilityscoutapm.com/blog/nestjs-v12…
Your AI coding agent can read your codebase but not your production errors or traces. That is a solvable problem. Connect your monitoring via MCP and your agent debugs with real production context. scoutapm.com/blog/production…
NestJS v12 just shipped a first-party observability SDK. Symfony pushed security patches. Two major Python SDKs (Anthropic, httpx2) hit stability milestones. Our roundup covers what changed and what to watch. #NestJS#Laravel#Symfony#OpenSourcescoutapm.com/blog/last-week-…
Node.js performance problems hide in places other runtimes don't have. Event loop blocking, connection pool saturation, Prisma N+1 patterns that only show up at production scale. A guide to what to track and how to fix it. scoutapm.com/blog/nodejs-per…
Bootsnap v1.25.0: YJIT toggling no longer invalidates your compile cache. The +YJIT marker in RUBY_DESCRIPTION was part of the cache key, so enabling YJIT threw away all cached instruction sequences. Fixed. github.com/rails/bootsnap/re…