Sign in

Kévin Dunglas

@dunglas.dev
1.7K followers 145 following 323 posts

⚒️ FrankenPHP.dev, Mercure.rocks, @api-platform.com, @symfony.com 🧑‍💻 Founder of @les-tilleuls.coop, a developer co-op

PostsRepliesMedia
Kévin Dunglas @dunglas.dev · 26/09/2026
My pair programming partner of the past 13 years passed away today. 😢 Godspeed, my dear George.
3210
Kévin Dunglas @dunglas.dev · 11/09/2026
🥳 Laravel 13 will have native support for Mercure!! 🪽🤝 github.com/laravel/fram...
github.com
[13.x] Add a Mercure broadcast driver by dunglas · Pull Request #61474 · laravel/framework
As discussed with @taylorotwell and the team, here the PR introducing support for the upcoming 1.0 version of the Mercure real-time protocol for Broadcast. Companion PR for Echo: laravel/echo#549 M...
061
Kévin Dunglas @dunglas.dev · 10/09/2026
The hype is real! I’m so excited to see such an incredible mix of communities coming together next week in my hometown: maintainers of Laravel, Symfony, Caddy, PHP core, and of course API Platform will be there! api-platform.com/con/2026/
131
Reposted by Kévin Dunglas
AFUP @afup.org · 07/09/2026
Pour démarrer la semaine, lisez l'interview de @dunglas.dev : il nous parle notamment de la genèse mouvementée de FrankenPHP et tease Mercure 1.0, fruit de 5 ans de travail, qui sera sorti à l'heure où Kévin donnera son talk et animera son atelier au Forum PHP 2026 ! buff.ly/26Zgz6w
MERCURE 1.0 : BÂTIR DES APPLICATIONS TEMPS RÉEL N'A JAMAIS ÉTÉ AUSSI SIMPLE, RAPIDE ET SÉCURISÉ
Kévin DUNGLAS[ATELIER] MERCURE 1.0 : BÂTIR DES APPLICATIONS TEMPS RÉEL N'A JAMAIS ÉTÉ AUSSI SIMPLE, RAPIDE ET SÉCURISÉ
Kévin DUNGLAS
012
Kévin Dunglas @dunglas.dev · 31/08/2026
Marx, Keynes, and A.I. www.unpopularfront.news/p/marx-keyne...
unpopularfront.news
Marx, Keynes, and A.I.
Coercive Competition and the Future of Work
010
Kévin Dunglas @dunglas.dev · 11/08/2026
🚀 Mercure 1.0 alpha is here! The biggest release in the project’s history brings: 🎯 New matcher system built on top of the WHATWG URL Pattern ⚙️ Revamped authorization mechanism using OAuth 2.0 Rich Authorization Requests 🛠️ Brand-new UI debugger and dev playground 🔒 Security hardening
dunglas.dev
Mercure 1.0 alpha is here - Kévin Dunglas
Mercure 1.0 is here in its first public preview, and it is the biggest release in the project's history! Mercure powers mission-critical real-time communication across hundreds of production deploymen...
183
Kévin Dunglas @dunglas.dev · 10/08/2026
This happened because the API was flawed from the start. It will keep happening unless you secure your codebase. Fix your endpoints now, or contact @les-tilleuls.coop and we'll do it for you! www.abc.net.au/news/2026-08...
abc.net.au
How a simple request for AI to book a gym class exposed a major threat
When Andrew asked his AI personal assistant to book him a spot in a gym class, he had no idea he would accidentally initiate an autonomous cyber attack.
010
Kévin Dunglas @dunglas.dev · 10/08/2026
Tried GitHub's new syntactic sugar for parallel action steps on FrankenPHP's CI. Gains were minimal for our use case, and it currently breaks actionlint (unsupported parallel keyword). Shelved for now: github.com/php/frankenp...
github.com
ci: run independent steps in parallel by dunglas · Pull Request #2597 · php/frankenphp
GitHub Actions added native parallel steps: https://github.blog/changelog/2026-06-25-actions-steps-can-now-be-run-in-parallel/ Grouped independent steps that were previously run sequentially for no...
030
Reposted by Kévin Dunglas
Druid @druid.fi · 05/08/2026
If you want to test-drive Drupal 11 on #FrankenPHP - you can use this repo to quickly spin it up ⚡ github.com/dunglas/fran... @dunglas.dev @marko.bluesky.druid.fi
github.com
GitHub - dunglas/frankenphp-drupal: Drupal on FrankenPHP
Drupal on FrankenPHP. Contribute to dunglas/frankenphp-drupal development by creating an account on GitHub.
001
Kévin Dunglas @dunglas.dev · 08/08/2026
This is an absolute disgrace. We urgently need a system capable of preventing such ecocide. AI could benefit humanity, but not under capitalism. This system will kill us all. www.nytimes.com/2026/08/08/c...
nytimes.com
New Amazon Data Center Is Set to Have the Most Polluting Power Plant in the U.S.
The tech giant is investing in the natural-gas-burning power plant as part of a huge data center in Texas, even as it pledges to honor climate commitments.
3144
Kévin Dunglas @dunglas.dev · 07/08/2026
FrankenPHP 1.12.7 fixes a bug where output written after fastcgi_finish_request() got silently dropped in classic mode, and killed the rest of the script execution right there. If you use that pattern for background cleanup, go upgrade. github.com/php/frankenp...
github.com
Release v1.12.7 · php/frankenphp
FrankenPHP 1.12.7 fixes a bug where output written after fastcgi_finish_request()/frankenphp_finish_request() was silently discarded in classic (non-worker) mode: with the default ignore_user_abort...
130
Kévin Dunglas @dunglas.dev · 05/08/2026
"The AI Compass: 15 questions. Where do you actually land on AI?" bambamramfan.github.io/ai-compass/
020
Kévin Dunglas @dunglas.dev · 04/08/2026
Ignore the propaganda in that Qwen ad for a second. The core question for the Left remains valid: boycotting AI is a dead end. AI and robotics give us the tools to build the work-free, post-scarcity utopia envisioned by Lafargue and Bookchin.
120
Kévin Dunglas @dunglas.dev · 30/07/2026
"Face à l'IA, le refus moral et le boycott constituent une défaite stratégique. Sortir du purisme pour contester le contrôle politique et social de cette technologie est un impératif." blogs.mediapart.fr/paul-bartali...
blogs.mediapart.fr
Face à l'IA, dépasser l'impuissance
Face à l'IA, le refus moral et le boycott constituent une défaite stratégique. Sortir du purisme pour contester le contrôle politique et social de cette technologie est un impératif.
030
Kévin Dunglas @dunglas.dev · 30/07/2026
Just improved Caddy performance by fixing header casing on the hot path! 🚀 When using Go's net/http, make sure to use canonical HTTP header casing (e.g. Content-Type instead of content-type). Non-canonical keys trigger string formatting and allocations on every lookup. github.com/caddyserver/...
github.com
caddyhttp: use canonical header key casing to avoid re-canonicalization by dunglas · Pull Request #7911 · caddyserver/caddy
Summary http.Header.Get/Set re-canonicalize the passed key and allocate a new string whenever it isn't already in canonical MIME header form. Three call sites in the codebase were passing non-c...
010
Kévin Dunglas @dunglas.dev · 29/07/2026
Carré Bompard sur l'IA ! www.youtube.com/watch?v=wTTY...
youtube.com
L'HOMME DE L'OMBRE DE MÉLENCHON : MANUEL BOMPARD RÉVÈLE LA STRATÉGIE DE LFI
Aujourd'hui dans "Ils font Marseille", nous recevons Manuel Bompard, député de la 4e circonscription des Bouches-du-Rhône et coordinateur national de La France Insoumise. De son parcours atypique…
120
Kévin Dunglas @dunglas.dev · 22/07/2026
Isolate deprecated code in dedicated files behind dedicated build tags. Years later you delete ~1,700 lines in one PR, zero issues. Thanks, past-me. github.com/dunglas/merc...
050
Kévin Dunglas @dunglas.dev · 20/07/2026
FrankenPHP 1.12.5 is a security release. Upgrade if you run the official Docker images or the session extension as a shared module. Fixed: the default Docker welcome page ran phpinfo() (env vars, php.ini, system paths, all exposed). Now a static page with nothing to leak.
1101
Kévin Dunglas @dunglas.dev · 18/07/2026
🔒 Vulcain 1.4.2 is out, a security release. Fixes 3 vulnerabilities in Preload/Fields directive handling: • High: quadratic response rebuild (DoS) • Medium: unbounded JSON-pointer recursion • Low: HTTP/2 push-counter race Upgrade: github.com/dunglas/vulc...
github.com
Release v1.4.2 · dunglas/vulcain
Security release fixing three vulnerabilities in request-directive handling, all reported by Alexandre Daubois (Les-Tilleuls.coop). Users on 1.4.1 and earlier should upgrade. 🔒 Security Fixes High...
140
Reposted by Kévin Dunglas
API Platform @api-platform.com · 17/07/2026
We are incredibly proud to have @laravel.com support as a Gold sponsor for #APIPlatformCon 2026! The community is gathering in full force, and with Jeremy Nikolic's upcoming talk on the schedule, the energy in Lille is going to be unmatched. Join them now: api-platform.com/con/2026/
Laravel is a Fabulous Gold Sponsor
022
Kévin Dunglas @dunglas.dev · 16/07/2026
The countdown to #APIPlatformCon is on! Incredible speakers, deep-tech talks, and a surprise announcement during my opening keynote. If you are building real-time apps or exploring AI integrations, you need to be in the room. Secure your spot before tickets sell out: 👉 api-platform.com/con/2026/
142
Kévin Dunglas @dunglas.dev · 09/07/2026
Introducing prompt-mac: Turn a fresh Mac into an agent-first dev powerhouse with one command 🚄 github.com/dunglas/prom...
github.com
GitHub - dunglas/prompt-mac: one-shot, AI-first macOS setup for Apple Silicon
one-shot, AI-first macOS setup for Apple Silicon. Contribute to dunglas/prompt-mac development by creating an account on GitHub.
170
Reposted by Kévin Dunglas
API Platform @api-platform.com · 08/07/2026
📢 #APIPlatformCon speaker reveal! Meet Yohan Giarelli who will demonstrate next September a fun "proof of concept" project: using a tech stack of PHP, Symfony, and Mercure to remotely unlock parcel lockers from a PWA. Don't miss out: api-platform.com/con/2026/tic...
Meet YohanPHP, Mercure et IoT : quand PHP devient plus que Full Stack
This talk challenges the idea that IoT is restricted to languages like C++ or Python by demonstrating how to use a PHP, Symfony, and Mercure stack to unlock physical parcel lockers from a web app.
121
Reposted by Kévin Dunglas
Antoine Bluchet @soyuka @soyuka.me · 27/06/2026
@dunglas.dev and I just published a preprint on exposing Hypermedia APIs to LLM agents via a Dynamic Gateway Architecture Thanks @p20n.w3c.social.ap.brid.gy for depositing this work hal.science/hal-05630480
hal.science
Making sure you're not a bot!
174
Kévin Dunglas @dunglas.dev · 22/06/2026
Let's face it: coding agents work pretty well these days, and Claude Code is the leader. That's why I recently patched Symfony Docker to support it out of the box.
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
330
Reposted by Kévin Dunglas
Antoine Bluchet @soyuka @soyuka.me · 04/06/2026
🔒 API Platform CVE-2026-49858: JSON:API & HAL normalizers cached components across users on long-running runtimes (FrankenPHP, RoadRunner, Swoole). Patched in 4.1.29 / 4.2.25 / 4.3.8 — upgrade now. github.com/api-platform...
github.com
Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
### Impact `#[ApiProperty(security: ...)]` is evaluated per request to decide whether a property is exposed. The `componentsCache` arrays in `ApiPlatform\JsonApi\Serializer\ItemNormalizer` and `Ap...
076
Kévin Dunglas @dunglas.dev · 04/06/2026
FrankenPHP 1.12.4 is out, a security hardening release. Underscore header spoofing is now blocked at the server layer (Caddy 2.11.4), bundled Mercure 0.24.2 security fixes land, plus worker-mode crash and race fixes. Every user should upgrade. github.com/php/frankenp...
github.com
Release v1.12.4 · php/frankenphp
FrankenPHP 1.12.4 is a hardening and stability release. It pulls in upstream security fixes from Caddy 2.11.4 and Mercure 0.24.2, closes a class of HTTP header spoofing, and fixes several crashes a...
254
Kévin Dunglas @dunglas.dev · 02/06/2026
Mercure 0.24.2 is out: a security hardening release. Rejects SSE field injection (CWE-93) via id/type, blocks reserved-namespace forgery, fixes a Last-Event-ID leak, caps element counts against DoS. Upgrade your hub. github.com/dunglas/merc...
github.com
Release v0.24.2 · dunglas/mercure
Community Mercure 0.24.2 is a security hardening release. It closes an SSE field-injection vector (CWE-93), blocks forgery of the hub's reserved subscription-event topics, fixes a metadata leak in ...
020
Reposted by Kévin Dunglas
The PHP Foundation @thephpf.bsky.social · 27/05/2026
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05... #php #opensource
thephp.foundation
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
096
Kévin Dunglas @dunglas.dev · 26/05/2026
Ready to code at the speed of thought? ⚡ Forget Docker headaches and slow cache warmups. At #SymfonOnline, I’m showing how FrankenPHP redefines @symfony.com DX with instant setups, true hot reloading via Mercure, and sandboxed AI agent integration. 📅 June 12 🎟️ live.symfony.com/2026-online-...
live.symfony.com
Schedule | SymfonyOnline June 2026
SymfonyOnline June 2026 (June 11 – 12, 2026)
050
Kévin Dunglas @dunglas.dev · 18/05/2026
This is exactly why we built FrankenPHP's extension infrastructure! Check out FrankenScriptling: a new extension that lets you use the Scriptling scripting language (Python-like) inside PHP. Since Scriptling is in Go, FrankenPHP makes embedding it seamless. Love seeing this! 🐘🐹
medium.com
Building Frankenscriptling: Running Scriptling Inside FrankenPHP
A dive into embedding a Python-like scripting language into PHP via a Go-based web server. Because why not.
050
Kévin Dunglas @dunglas.dev · 16/05/2026
Mercure 0.24.1 is out, riding on Caddy 2.11.3. We contributed native OTLP metrics push to Caddy upstream. Drop metrics { otlp } in your Caddyfile, set the OTEL_* env vars, and hub metrics land in any OTLP collector. github.com/dunglas/merc...
github.com
Release v0.24.1 · dunglas/mercure
Community Mercure 0.24.1 picks up Caddy 2.11.3, including our upstream contribution that adds OTLP metrics push to Caddy. The Helm chart now also surfaces a JSON values schema and a signed .prov pr...
074
Kévin Dunglas @dunglas.dev · 16/05/2026
🚀 FrankenPHP 1.12.3 is out! ⚡️ 7-8% throughput bump from a refreshed PGO profile 🔒 Fixes CVE-2026-45062 (CVSS 8.1) unsafe Unicode handling flaw. Upgrade if on v1.11.2 - v1.12.2! ⚙️ Adds per-thread max_requests & cross-platform thread force-kill. Release notes: github.com/php/frankenp...
github.com
Release v1.12.3 · php/frankenphp
This release fixes CVE-2026-45062 (high, CVSS 8.1): unsafe Unicode handling in CGI path splitting let an attacker have a non-.php file executed as PHP via a crafted URL, in any deployment where att...
084
Kévin Dunglas @dunglas.dev · 12/05/2026
Mercure 0.24 is out 🚀 Native OpenTelemetry tracing for the Hub: publish, subscribe, subscriptions, and transport history spans nest under Caddy's tracing directive, with zero allocations when disabled. github.com/dunglas/merc...
github.com
Release v0.24.0 · dunglas/mercure
Community Mercure 0.24 adds native OpenTelemetry tracing for the Hub's core operations, lets you point at a JWK Set on disk instead of running a separate HTTP endpoint, and ships a Helm chart that ...
171
Kévin Dunglas @dunglas.dev · 05/05/2026
🚀 Mercure v0.23.5 just landed! We've brought major Helm chart hardening for Kubernetes (NetworkPolicies, readOnlyRootFS, and tighter PodSecurity). I wrote a blog post covering all the new security and performance details. Check it out: dunglas.dev/2026/05/merc... #Kubernetes #Helm
dunglas.dev
Mercure 0.23.5: Helm chart hardening - Kévin Dunglas
Mercure v0.23.5 just landed, and the dominant theme is the Helm chart. If you run hubs on Kubernetes, especially in HA or multi-tenant mode, this release tightens defaults and adds the kind of policy ...
060
Kévin Dunglas @dunglas.dev · 21/04/2026
🚀 Mercure 0.23 is out! 🩺 Transport-aware Health Checks: K8s now detects actual broken connections, not just a live Caddy process. 🛥️ Helm: HTTProute support + deployment annotations. 🏢 Enterprise transports fully supported. 🔗 github.com/dunglas/merc...
github.com
Release v0.23.0 · dunglas/mercure
Community Transport-aware health checks come to Mercure. Kubernetes (and any other orchestrator) can now detect when a hub's transport connection is actually broken, not just that the Caddy process...
041
Kévin Dunglas @dunglas.dev · 10/04/2026
We've just finalized our next-gen AI-powered security audit tool at @les-tilleuls.coop! We used it to discover and patch a critical vulnerability in Mercure as well as in several of our clients' projects. The Mercure fix also made topic matching 38% faster! ⚡️
173
Kévin Dunglas @dunglas.dev · 31/03/2026
Coding at the Speed of Thought: The New Era of Symfony Docker dunglas.dev/2026/03/codi...
dunglas.dev
Coding at the Speed of Thought: The New Era of Symfony Docker - Kévin Dunglas
If we want to discuss Developer Experience (DX) in 2026, we have to talk about instantaneous feedback and coding agents. At SymfonyLive Paris 2026, I presented "Coding at the Speed of Thought: Symfony...
0122
Kévin Dunglas @dunglas.dev · 25/03/2026
I'm cooking up something pretty insane for SymfonyLive Paris! Buckle up. 🐳🤖
091
Kévin Dunglas @dunglas.dev · 21/03/2026
Only 2 days left!
030
Kévin Dunglas @dunglas.dev · 20/03/2026
Dimanche, Lille a rendez-vous avec l'histoire : devenons la première grande ville française à expérimenter 🌱✊ l'Écologie Sociale et 🗣️ le communalisme. Un seul bulletin permet l'alternative : "Lille insoumise, écologiste et populaire" menée par Laouharia Addouche. @offensive.eco #DimancheJeVoteLFI
092
Kévin Dunglas @dunglas.dev · 16/03/2026
✊ Score historique pour "Lille insoumise, écologiste et populaire" : le changement est à portée de main Les Lilloises et les Lillois ont tranché : ils veulent en finir avec le système PS. Pour la première fois depuis 70 ans, la rupture est possible !
231
Kévin Dunglas @dunglas.dev · 13/03/2026
🔴⚫️🟢 Je suis fier d'être présent sur la liste Lille insoumise, écologiste et populaire au nom de Vert ! La Commune / @offensive.eco. #DimancheJeVoteLFI
1216
Reposted by Kévin Dunglas
onestla.tech @onestla.tech · 12/03/2026
Le maire de Lille, Arnaud Deslandes, incite les lillois·es à installer une app appartenant à Meta, multinationale US sans foi ni loi qui espionne ses utilisateurs et manipule les élections. Dimanche, votez pour une liste qui défend les libertés numériques, le logiciel libre et les coopératives !
064
Kévin Dunglas @dunglas.dev · 12/03/2026
🛡️ Symfony Docker now provides a rootless production image that contains only what is strictly necessary to run #FrankenPHP and #Symfony. They are 60% smaller than before, dropping from 704MB down to just 290MB! 📉✨ github.com/dunglas/symf...
github.com
feat: use rootless Debian slim images for prod by dunglas · Pull Request #909 · dunglas/symfony-docker
Hardens production images using a method to https://frankenphp.dev/docs/docker/#hardening-images, but using Debian Slim instead of distroless because we need a shell for the entrypoint, (Docker Har...
1178
Reposted by Kévin Dunglas
Les-Tilleuls.coop @les-tilleuls.coop · 11/03/2026
C'était une fonctionnalité très attendue par l'écosystème : FrankenPHP est désormais disponible sur Windows ! Découvrez dans cet article de @dunglas.dev le chemin parcouru vers cette release, ainsi que les défis techniques rencontrés. les-tilleuls.coop/blog/windows...
les-tilleuls.coop
Windows pour FrankenPHP désormais disponible  | Les-Tilleuls.coop
Le support officiel de Windows pour FrankenPHP est enfin disponible, avec ses fonctionnalités phares comme le mode worker ou le hot reload.
011
Kévin Dunglas @dunglas.dev · 10/03/2026
FrankenPHP 1.12.1 is out! It fixes some bugs introduced in 1.12.0. github.com/php/frankenp...
github.com
Release v1.12.1 · php/frankenphp
What's Changed 🐛 Bug Fixes Fix PHP startup errors when ini files contain environment variables by @henderkes in #2252 Fix sigsev on bind permissions denied by @henderkes in #2251 📖 Documentation ...
062
Kévin Dunglas @dunglas.dev · 06/03/2026
🧟 Official native Windows support for FrankenPHP is here 🪟🚀 dunglas.dev/2026/03/wind...
dunglas.dev
Windows Support for FrankenPHP: It’s Finally Alive! - Kévin Dunglas
It’s happening! I am thrilled to announce the immediate availability of official Windows support for FrankenPHP. Since the project's initial release, this has been by far the most requested feature.…
0103
Reposted by Kévin Dunglas
Castopod @castopod.org · 18/02/2026
🙏 Thank you @les-tilleuls.coop @dunglas.dev for FrankenPHP!
021
Reposted by Kévin Dunglas
Johan Janssens @johanjanssens.bsky.social · 26/02/2026
Slides from my talk "#PHP 150x Faster, Still Legacy Friendly!" at #confoo are up. #FrankenPHP threads + Go semaphore = true parallelism for any blocking PHP code. Legacy scripts stay unchanged, just compose them. Kudos to @dunglas.dev , FrankenPHP rocks! gamma.app/docs/PHP-150...
gamma.app
PHP, 150x Faster Still Legacy Friendly
This talk explores how to push PHP to its limits using FrankenPHP and Swow, a sprinkle of PHP, and a dash of Go to orchestrate it all.
041