Des postes

Techie
messages de Techie
Twig CVE-2025-24374: Missing output escaping for the null coalesce operator

Affected versions

Twig versions >=3.16.0,<3.19.0 are affected by this security issue.

The issue has been fixed in Twig 3.19.0.

Description

When using the null coalesce operator (??), output escaping was missing for the expression on the left side of… https://symfony.com/blog/twig-cve-2025-24374-missing-output-escaping-for-the-null-coalesce-operator?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

7d | Symfony
Symfony 7.1.11 released

Symfony 7.1.11 has just been released. Here is the list of the most important changes since 7.1.10:

bug #58889 [Serializer] Handle default context in Serializer (@Valmonzo)

bug #59631 [HttpClient] Fix processing a NativeResponse after its client has… https://symfony.com/blog/symfony-7-1-11-released?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

7d | Symfony
Symfony 6.4.18 released

Symfony 6.4.18 has just been released. Here is the list of the most important changes since 6.4.17:

bug #58889 [Serializer] Handle default context in Serializer (@Valmonzo)

bug #59631 [HttpClient] Fix processing a NativeResponse after its client has… https://symfony.com/blog/symfony-6-4-18-released?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

7d | Symfony
Symfony 7.2.3 released

Symfony 7.2.3 has just been released. Here is the list of the most important changes since 7.2.2:

bug #58889 [Serializer] Handle default context in Serializer (@Valmonzo)

bug #59631 [HttpClient] Fix processing a NativeResponse after its client has been… https://symfony.com/blog/symfony-7-2-3-released?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

7d | Symfony
 4 key trends redefining the IT landscape

Generative AI, sustainable computing and secure enterprise are pushing organizations to rethink approaches to innovation.

https://www.techradar.com/pro/4-key-trends-redefining-the-it-landscape

AI bots everywhere. Does anyone have a good whitelist for robots.txt?

My niche little site, http://golfcourse.wiki seems to be very popular with AI bots. They basically become most of my traffic. Most of them follow robots.txt, and that's nice and all, but they are costing me non-trivial amounts of money.

I don't want to block most search engines. I don't want to block legitimate institutions like archive.org. Is there a whitelist that I could crib instead of pretty much having to update my robots file every damn day?


Comments URL:

America's First Civilian Aircraft to Fly Supersonic video

Boom Supersonic's XB-1 demonstrator aircraft broke the sound barrier for the first time on Jan. 28, 2025. The event was livestreamed, and we've gathered all the highlights for you here. https://www.cnet.com/roadshow/videos/americas-first-civilian-aircraft-to-fly-supersonic/#ftag=CADf328eec

7d | cnet.com
Show HN: Meelo, self-hosted music server for collectors and music maniacs

I've been working on this alternative for Plex for almost 3 years now. It's main selling point is that it correctly handles multiple versions of albums and songs. As of today, it only has a web client.

It tries to be as flexible as possible, but still requires a bit of configuration (including regexes, but if metadata is embedded into the files, it can be skipped).

I just released v3.0, making videos first-class data, and scanning + metadata matching faster.


Comments URL:

Tim Cook Stars in Severance Season 2 Promo video

Watch Apple CEO Tim Cook as Tim C. in the season 2 promo for hit show Severance on Apple TV Plus. https://www.cnet.com/videos/tim-cook-stars-in-severance-season-2-promo/#ftag=CADf328eec

7d | cnet.com
 Max just made a big change, and your streaming life will probably get easier

Max is making a design change to the homepage of its streaming service by moving the top navigation menu to the left-hand side and tossing in two new options.

https://www.techradar.com/streaming/max-just-made-a-big-change-and-your-streaming-life-will-probably-get-easier

 NYT Connections today — my hints and answers for Wednesday, January 29 (game #598)

Looking for NYT Connections answers and hints? Here's all you need to know to solve today's game, plus my commentary on the puzzles.

https://www.techradar.com/gaming/nyt-connections-today-answers-hints-29-january-2025

Softwarová sklizeň (29. 1. 2025): ovládněte systemd interaktivně

Sonda do světa otevřeného softwaru. Dnes si nakreslíme pár symbolů, podíváme se na TUI nadstavbu pro systemd, vytvoříme si flashkarty a připojíme se na Discord z architektury ARM. https://www.root.cz/clanky/softwarova-sklizen-29-1-2025-ovladnete-systemd-interaktivne/?utm_source=rss&utm_medium=text&utm_campaign=rss

7d | root.cz
Multimediální frameworky: stavíme vlastní přehrávač videa s pomocí FFmpeg

V článku si vysvětlíme základní práci s kontejnerem a vytvoříme si jednoduchý přehrávač videa. Popíšeme si celý proces práce se snímky, abychom mohli přehrávat video. Použijeme k tomu API frameworku FFmpeg. https://www.root.cz/clanky/multimedialni-frameworky-stavime-vlastni-prehravac-videa-s-pomoci-ffmpeg/?utm_source=rss&utm_medium=text&utm_campaign=rss

7d | root.cz
How Accurate Is Groundhog Day? NOAA Grades The Woodchucks

Punxsutawney Phil is adorable, but a woodchuck from New York has him beat for accuracy, according to NOAA weather data analysis. https://www.cnet.com/science/how-accurate-is-groundhog-day-noaa-grades-the-woodchucks/#ftag=CADf328eec

7d | cnet.com
52 Best Wellness Valentine's Day Gifts for the Health Gurus Who Have It All

Whether you're shopping for a holistic health connoisseur or a fitness enthusiast or, our editors' favorite picks have you covered for Valentine's Day. https://www.cnet.com/health/52-best-valentines-wellness-gifts-for-the-health-gurus-that-have-it-all/#ftag=CADf328eec

7d | cnet.com
 “Everything that moves will be robotic”: Nvidia CEO Jensen Huang says robots and self-driving cars are just around the corner

"A future where you’re just surrounded by robots is for certain," Huang says. Is this something to look forward to, or something to be wary of?

https://www.laptopmag.com/laptops/nvidia-ceo-jensen-huang-robots-self-driving-cars-

 DeepSeek jailbreakers are tricking the chatbot into bad-mouthing the Chinese government

Just like ChatGPT, jailbreakers are already finding ways to get DeepSeek to do exactly what it's not supposed to

https://www.laptopmag.com/ai/deepseek-jail-break-china-government-ai-chatgpt

 The results are in: Samsung Galaxy S25 Ultra crushes Apple iPhone 16 Pro Max in lab tests

The Galaxy S25 Ultra test results are in with Samsung's latest taking down the iPhone 16 Pro Max in several key metrics, revealing itself to be a bigger upgrade than you may realize.

https://www.laptopmag.com/phones/android-phones/samsung-galaxy-s25-ultra-vs-iphone-16-pro-max-benchmarks

DeepSeek rains on the AI hype parade

Uh-Oh. Who could have predicted “AI” is a dotcom bubble?

7d | UX Design
Get more than $400 off one of our favorite Alienware gaming monitors

Looking to upgrade your gaming rig? Dell is selling one of its most popular Alienware gaming monitors

7d | Engadget
CVS tries to juice app signups with cabinet unlocking feature

CVS is launching a new app today and it could address one of the more obnoxious elements of in-person drugstore shopping: locked

7d | Engadget
Some Garmin GPS watches are stuck in a blue triangle boot loop

If you own a Garmin GPS watch, you may want to power it down for a while. Users on Reddit and

7d | Engadget
Jack Dorsey’s Block has an AI agent too

Jack Dorsey’s Block has created its own open-source AI agent. Called “codename goose,” the tool allows users to complete tasks using popular large language models.

“You can think of Goose as an assistant that is ready to take your instructions, and do the work for you,” Block explains in a

7d | Engadget
Good luck figuring out what time it is on this cool Asteroids watch

Here's one for the fashion-conscious retro gamers out there. Atari has teamed up with watchmaker Nubeo to release an Asteroids-themed watch to celebrate the game's 45th a

7d | Engadget
Doom + Doom II now supports multiplayers mods

Old-school Doom fans have something new to chew on until The Dark Ages arrives. Doom + Doom II, the latest in a long line of rereleases of the two id Software classics, was updated on Tuesday with multiplayer mod support. And balance was restored in Hades.

At launch in August, the bundle — available for

7d | Engadget
Call of Duty Black Ops 6 and Warzone Season 2 Is Live Now

The new Call of Duty Black Ops 6 update adds three new maps, the iconic Gun Game mode, and another zombies map with a fan-favorite wonder weapon. https://www.cnet.com/tech/gaming/call-of-duty-black-ops-6-and-warzone-season-2-live-now/#ftag=CADf328eec

7d | cnet.com
Nvidia begins warning that GeForce 5080, 5090 may sell out
What does the symbol on a power button mean? How did it come about?