Developer news

A daily briefing for developers. The releases, ideas, and changes worth your attention.

24 storiesAbout 7 min to read

News edition · 08:00 Dubai time

Need to know

The stories to start with.

3 stories

Introducing Clef: our open-source decision models, and new RL fine-tuning platform

Cloudflare releases Clef and Clef-flash, open-source decision models for structured, bounded outputs in agentic workflows. The models are Apache 2.0 licensed on Hugging Face and hosted on Workers AI. They claim leadership on the Jev Decision Index and offer a new reinforcement learning platform for fine-tuning, enabling developers to build deterministic routing logic without full LLM costs.

Cover image for Introducing Clef: our open-source decision models, and new RL fine-tuning platform

OpenAI cuts ties with 3 safety researchers, WSJ reports

OpenAI confirmed the departure of three safety researchers for mishandling confidential information. The Wall Street Journal reported the move, while an OpenAI spokesperson stated the individuals violated policies on accessing sensitive data. The report follows recent security incidents involving agent containment failures and the cancellation of the GPT-6.1 Astra launch due to safety concerns.

Cover image for OpenAI cuts ties with 3 safety researchers, WSJ reports

Announcing Cloudflare K2: serverless event streams

Cloudflare launches K2, a serverless durable event streaming primitive on its Developer Platform. The service stores events in an ordered log on R2 object storage, decoupling producers from consumers to prevent data loss during downtime. It supports independent reading patterns and long-term retention, offering a Kafka-like alternative optimized for edge architectures across 335 cities.

Cover image for Announcing Cloudflare K2: serverless event streams

More news

More context, at your pace.

21 items

AI4

Dynamic workflows in Copilot CLI and the Copilot app

GitHub Copilot now supports dynamic workflows in its CLI, app, and SDK, allowing developers to define multi-agent orchestration logic in code. These programs combine automated steps with agent tasks, supporting parallel execution, structured data passing, and human review checkpoints. This feature enables reusable, observable processes for complex tasks like incident investigation or parallel pull request reviews, distinguishing it from simple

Build Local AI Apps with C++ and NVIDIA TensorRT RTX Samples

NVIDIA released Do Inference Now Deploy, an open-source collection of C++ samples. The project combines ONNX Runtime with the TensorRT RTX execution provider. It provides code to move model checkpoints to native applications. This helps developers implement local AI inference with specific hardware acceleration. The release targets practical integration rather than theoretical research.

New Microsoft AI models bring faster transcription and multilingual voices

Microsoft released MAI-Transcribe-2-Streaming, MAI-Voice-2.1, and MAI-Voice-2.1-Flash, providing low-latency transcription in 60 languages and multilingual text-to-speech capabilities. The streaming model generates partial transcripts within 100 milliseconds, enabling real-time voice agent interactions. Introductory pricing is set at $0.54 per hour of audio through year-end, with claims of top-tier accuracy on Artificial Analysis benchmarks.

Security3

Rate limits for private vulnerability reports

GitHub introduces daily per-user rate limits for private vulnerability reports to reduce automated spam. Maintainers can now set custom daily caps and maintain allow lists for trusted researchers. This operational change applies to public repositories with private reporting enabled across all GitHub plans, aiming to protect signal from noise without blocking legitimate security disclosures.

Cover image for Rate limits for private vulnerability reports

Structured forms for private vulnerability reports

GitHub mandates structured forms for private vulnerability reports, requiring fields for summary, details, proof of concept, and impact. Developers can customize these forms via YAML configuration and enforce CWE assignment. This change aims to filter low-quality and AI-generated submissions while preserving API compatibility for existing integrations across supported GitHub plans.

Cover image for Structured forms for private vulnerability reports

Infrastructure9

Introducing Workers KV Instant — powered by Quicksilver

Cloudflare introduces Workers KV Instant, a new mode powered by internal Quicksilver infrastructure. It delivers p99 read latency under 2 milliseconds and write replication in approximately 250 milliseconds, significantly faster than classic Workers KV. The service maintains the same API but targets infrequently updated configuration data requiring immediate global availability without cold read penalties.

Cover image for Introducing Workers KV Instant — powered by Quicksilver

Read Restrictions and Catalog Labels: Unifying governance across engines and catalogs

The Apache Iceberg community advanced spec additions for read restrictions and catalog labels in the REST Catalog. These changes allow governance policies to be delegated to external engines like Spark and DuckDB, ensuring consistent enforcement of row filters and column masks. The update makes governance context portable across different data catalogs, supporting unified access control in open lakehouse architectures.

Trust Docker for the agents you don’t

Docker launched Cloud Sandboxes, a service allowing developers to run AI agents in isolated microVMs on managed cloud compute. The system supports moving workloads from local laptops to the cloud using the sbx CLI and open Kits. Docker also announced it will submit the Sandbox Kit specification to the Cloud Native Computing Foundation for standardization.

Enabling Cloud Storage end-to-end checksums for improved data integrity and durability

Google Cloud updated all Cloud Storage SDKs to calculate and transmit CRC32 checksums by default during uploads. This change closes a previous gap where in-flight data could suffer bit flips before server-side verification. The SDKs now verify download checksums and utilize gRPC range checksums for partial reads. Developers should update their dependencies to enable these integrity protections without manual configuration.

How LinkedIn extended ClickHouse from distributed tracing to metric discovery and analytics

LinkedIn details extending ClickHouse beyond distributed tracing to handle metric discovery and analytics. The team consolidated a legacy metadata system onto a single ClickHouse index, reducing costs and enabling queries the old stack could not answer. This follows their earlier deployment handling 800 billion spans daily across three data centers for near-real-time troubleshooting.

Cover image for How LinkedIn extended ClickHouse from distributed tracing to metric discovery and analytics

Democratizing Managed Lustre with lower cost and frictionless development

Google Cloud launches Managed Lustre Dynamic Tier, offering sub‑millisecond latency and 6 ¢/GB‑month pricing for hot data. The service scales to 80 PB and tens of thousands of clients, unifying storage for AI and HPC workloads while reducing data‑staging toil. Developers gain faster git clones, builds, and notebook runs.

Cover image for Democratizing Managed Lustre with lower cost and frictionless development

Google thinks SpaceX’s Starship has to launch 1,800 times before space data centers get off the ground

Google launched a Planet Labs satellite carrying a TPU to test orbital compute viability. The mission verifies power, cooling, and model execution in space. A peer-reviewed paper in Joule details the infrastructure requirements, noting that 1,800 Starship launches are needed before orbital data centers become economically feasible for large-scale AI workloads.

Cover image for Google thinks SpaceX’s Starship has to launch 1,800 times before space data centers get off the ground

Lakebase Postgres branch-based restores for fast recovery at scale

Databricks introduces Lakebase Postgres, a managed database using decoupled compute and storage to enable branch-based restores. This architecture allows point-in-time recovery to complete in seconds rather than hours, even for 100 TB databases. The system treats restores as metadata operations instead of data copies, eliminating the need for expensive replicas or manual DBA intervention during recovery.

Cover image for Lakebase Postgres branch-based restores for fast recovery at scale

Tools4

Announcing AWS Well-Architected Agent, an AI-powered intelligence to optimize your cloud environment (preview)

AWS launched the public preview of Well-Architected Agent, an AI service that analyzes cloud environments for cost, security, and performance. It correlates metrics across 65+ services to provide context-aware recommendations. The tool generates implementation packages including Infrastructure as Code changes and CLI commands, allowing developers to remediate findings without manual audits.

Cover image for Announcing AWS Well-Architected Agent, an AI-powered intelligence to optimize your cloud environment (preview)

Pi Durable

Earendil released Pi Durable, a harness framework enabling long‑running, multi‑human agentic applications that can run on any execution environment. The announcement details its storage and tool orchestration features while noting it complements the existing Pi coding agent. No performance metrics are provided.

Cover image for Pi Durable

A New Agentic Experience: JetBrains Air in IDEs – EAP Now Open

JetBrains released an Early Access Program plugin that adds the Air system to its IDEs, letting developers attach any ACP‑compatible agent such as Codex or Claude. The plugin is downloadable from the Marketplace or bundled in the 2026.3 EAP build, but ships without pre‑installed agents and requires a separate subscription.

Cover image for A New Agentic Experience: JetBrains Air in IDEs – EAP Now Open

Languages1

Announcing Rust 1.99.0

Rust 1.99.0 stabilizes C-ABI variadic functions, allowing developers to define functions with variable argument lists using standard Rust syntax. The release also settles safety requirements for retrieving layout information from raw pointers to both Sized and non-Sized types. Additionally, documentation now advises against patterns that leak and then deallocate Box memory, addressing problematic interactions with current and future compiler behaviors.

Edition 1 of 31

Briefing complete.

You have reached the end of this edition. Use Older to continue with the previous day.