Vendure 3.7 security advisories: why patching to 3.6.x is not enough
Vendure 3.7.0 fixes five advisories, including a critical account takeover never backported to 3.6.x. Who is exposed, and what the upgrade actually costs.
Read articleBlog
Magento 2 and Adobe Commerce operations, commerce migrations to Medusa.js and Vendure, Next.js storefronts, and the hard parts of cutting over without freezing the business.
Vendure 3.7.0 fixes five advisories, including a critical account takeover never backported to 3.6.x. Who is exposed, and what the upgrade actually costs.
Read articleHow to confirm a SessionReaper/PolyShell compromise on Magento 2.4.x, remove the injected backdoors, restore wiped catalog data, and close the entry point.
Read articleHow Magento 2 and Adobe Commerce shops accumulate extension debt, how to inventory it, and when rescue work is cheaper than a full replatform.
Read articleA practical comparison of Medusa.js and Vendure when you are leaving Magento 1, Magento 2, Adobe Commerce, or WooCommerce - without the hype.
Read articleWhat enterprise Next.js commerce work actually includes when Magento, Medusa.js, or Vendure owns the cart - and when headless CMS fits.
Read article