Medusa 2.20.1 closes a field-filter data exposure — patch now
Medusa 2.20.1 makes field filters strip disallowed fields without the RBAC flag. What the gap exposed, how to upgrade from 2.19.x, and how to test it.
Read articleBlog
Magento 2 and Adobe Commerce operations, commerce migrations to Medusa.js and Vendure, Next.js storefronts, and the hard parts of cutting over without freezing the business.
Medusa 2.20.1 makes field filters strip disallowed fields without the RBAC flag. What the gap exposed, how to upgrade from 2.19.x, and how to test it.
Read articleVendure 3.7.3 fixes eleven reported vulnerabilities, four critical, plus channel-scoping and shipping-line changes that alter behaviour after upgrade.
Read articleVendure evaluates cron expressions in the Node process timezone, so nightly jobs fire at the wrong local hour and drift at DST. How to audit and fix it.
Read articleIn Medusa 2.19.0 the admin create-fulfillment flow drops items.variant.metadata, so dropship and print-on-demand providers get line items they cannot map.
Read articleNext.js 16.3.3 fixes two critical advisories — Windows-hosted server RCE and Image Optimization AVIF RCE. Here's who is exposed and how to mitigate.
Read articleMedusa 2.19.0's inventory reservations are not concurrency-safe when called directly — here's where the race is and how to detect and close it.
Read articleVendure 3.7.2 fixes four reported vulnerabilities and tightens channel scoping on update and delete paths — here is what to test before you ship it.
Read articleOrder exports in Medusa 2.18.0 and 2.19.0 fail silently on any order with a shipping method. How to confirm it and what to do until it's fixed.
Read articleWhy Medusa 2.19.0's caching module runs unbounded invalidation on worker_mode: server processes, how to confirm it, and what to change before a migration
Read articleVendure 3.7.0 fixes five advisories, including a critical account takeover never backported to 3.6.x. Who is exposed, and what the upgrade actually costs.
Read articleHow to confirm a SessionReaper/PolyShell compromise on Magento 2.4.x, remove the injected backdoors, restore wiped catalog data, and close the entry point.
Read articleHow Magento 2 and Adobe Commerce shops accumulate extension debt, how to inventory it, and when rescue work is cheaper than a full replatform.
Read articleA practical comparison of Medusa.js and Vendure when you are leaving Magento 1, Magento 2, Adobe Commerce, or WooCommerce - without the hype.
Read articleWhat enterprise Next.js commerce work actually includes when Magento, Medusa.js, or Vendure owns the cart - and when headless CMS fits.
Read article