Today's digest · Thursday, August 20

The 8 things in AI/dev today.

LiveNext issue at 7:00 CET
#1 / TODAY
GitHub Changelog·1 min·8h agoFREE

CodeQL 2.26.3 improves GitHub Actions queries and JavaScript modeling

GitHub released CodeQL 2.26.3, which improves GitHub Actions queries and JavaScript modeling. The update enhances the static analysis tool's ability to detect issues in GitHub Actions workflows and JavaScript code. Developers using CodeQL for security scanning can benefit from more accurate and comprehensive query results in these areas.

CodeQL 2.26.3 improves detection of issues in GitHub Actions and JavaScript, helping developers find more vulnerabilities.

codeqlsecuritygithub-actionsjavascript
github.blog
CodeQL 2.26.3 improves GitHub Actions queries and JavaScript modeling
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
#2 / TOP STORY
The Hacker NewsFREE

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers are exploiting a server-side request forgery (SSRF) flaw in MLflow to steal cloud credentials and secrets. The vulnerability allows unauthorized access to cloud metadata services, leading to credential theft. The source reports that this attack is actively targeting MLflow deployments, posing a significant risk to organizations using the platform.

Mojo🔥 is now open source
#3 / TOP STORY
Simon WillisonFREE

Mojo🔥 is now open source

Mojo, the programming language from Modular, has been released as open source under an Apache 2 license, following its 1.0 release last week. Originally intended as a Python superset, the project shifted focus in August 2025, and now Mojo is its own language optimized for GPU programming with Python-inspired syntax.

aigest · daily

Get this every morning.

One email. The signal. Built for builders.

Free · Unsubscribe in one click · No trackers

// Worth knowing5 stories
// Yesterday10 stories