Skip to content

project

PostgreSQL

PostgreSQL is an open-source relational database management system known for SQL compliance, extensibility, and reliability, powering many applications.

Known aliases

  • pg_advisory_xact_lock
  • pg_dump
  • pg_restore
  • pgsql
  • pg_stat_statements
  • Postgres
  • Postgres 16
  • postgres:16-alpine
  • Postgres 17
  • PostgreSQL 15
  • PostgreSQL 16
  • PostgreSQL 16.13
  • PostgreSQL 17
  • PostgreSQL 17.11
  • PostgreSQL 17.9
  • PostgreSQL 18
  • PostgreSQL 18.3
  • postgresql-contrib
  • psql
  • The PostgreSQL Project

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

n8n's Postgres node inlines $1 parameters as SQL literals

n8n 2.41.6's Postgres node writes $1 values into SQL text via pg-promise 11.9.1, so Postgres never gets a bind parameter. A psql PREPARE dry-run tests a path the node never uses, and Postgres types inlined literals before any CASE guard runs.

Publishers:dev.to

Reality

Evidence70
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence65
build7 publishers

Supabase agrees to buy Turso to give each AI agent its own SQLite-compatible database

Supabase raised $150 million and agreed to buy Turso, whose SQLite-compatible engine gives AI agents large numbers of small, isolated databases. The deal rests on Supabase's own count of agent-created databases, and Turso's customers now build on that bet.

Publishers:mezha.netprnewswire.compulse2.comruntimewire.comsiliconangle.comsupabase.comturso.techventureburn.com

Perspective Coverage

8 publishers
Builder
Builder 42%
Operator
Operator 26%
Investor
Investor 32%

Reality

Evidence62
Adoption45
Hype gap+30
Incentives80
Confidence64
build1 publisher

One COPY line runs a shell despite AWS's read-only Postgres MCP filter

AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives40
Confidence50
build1 publisher

Turbopuffer v3 demotes the ANN index to one secondary index among several

Turbopuffer is rewriting its serverless database as v3, moving the ANN index out of the core of storage and making it one of several secondary indexes. A dev.to explainer of the September 30 post says the vector-first layout held back GROUP BY and aggregation queries.

Publishers:dev.to

Reality

Evidence40
Adoption25
Hype gap+35
Incentives45
Confidence50
build1 publisher

Plain-language questions push SEPA rulebook answers out of a top-5 vector search

One developer's test on 484 SEPA rulebook passages found that plain-English questions push several answers out of a top-5 vector search. Because the test measures each answer's rank directly, the failure shows up in retrieval, before the language model writes anything.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence45
build1 publisher

Laravel's one-line foreign key migration stalls writes on two Postgres tables

Postgres locks both tables with SHARE ROW EXCLUSIVE when a migration adds a foreign key, blocking writes until every child row is scanned. A dev.to guide on Laravel migrations splits the change into two statements so the slow scan stops holding up the app's writes.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence50
build1 publisher

LiteLLM's Lens moves agent-failure analysis into the self-hosted gateway that routes model calls

LiteLLM launched Lens on September 30, a tool that uses AI agents to find recurring failures across agent traces sent through its model gateway. Customers host the analyzer and its databases, and the 200,000-trace volume CTO Ishaan Jaffer cites is a future target Lens has not been measured against.

Publishers:runtimewire.com

Reality

Evidence40
Adoption
Insufficient
Hype gap+25
Incentives60
Confidence40

Earlier coverage

  1. PostgreSQL accepts SET NULL foreign keys that fail only when a parent row is deleted

    Build · September 30, 2026 · 1 publisher

  2. COMMIT; DROP TABLE slips past the reference Postgres MCP server's read-only guard

    Build · September 30, 2026 · 1 publisher

  3. postgres-js pads pooled query results with empty slots after a mid-stream timeout

    Build · September 30, 2026 · 1 publisher

  4. One index scan answers a filtered, sorted page of embedded array data in DocumentDB 0.109

    Build · September 29, 2026 · 1 publisher

  5. DocumentDB 0.116 lets $group read rows in the order an existing index already provides

    Build · September 29, 2026 · 1 publisher

  6. UpGuard finds more than 16,000 Supabase databases left readable through missing row-level security

    Security · September 28, 2026 · 1 publisher

  7. Timescale's agent-run memory sprint turned on a human checking what each metric counted

    Product · September 28, 2026 · 1 publisher

  8. Nightly archive of auditd logs kept 234 of 696 hours on a busy database server

    Build · September 28, 2026 · 1 publisher

  9. Agent memory handoffs cut replaced context 98.65% by moving verbatim text out of the prompt

    Build · September 27, 2026 · 1 publisher

  10. One GCP VM runs an ML team's Airflow for under $150 a month against Composer's $350 estimate

    Build · September 27, 2026 · 1 publisher

  11. PostgreSQL foreign key inserts take a hidden row lock that deadlocks ledger deposits

    Build · September 27, 2026 · 1 publisher

  12. Penalising sequential scans in tests exposes the missing index a 20-row table hides

    Build · September 27, 2026 · 1 publisher

  13. SvelteKit starter kits' boot-time migrations race once a second replica starts

    Build · September 27, 2026 · 1 publisher

  14. A coding agent built a four-platform Kotlin messenger from a 33 KB plan cut into five steps

    Build · September 27, 2026 · 1 publisher

  15. Indexing a PostgreSQL 18 generated column requires writing STORED

    Build · September 27, 2026 · 1 publisher

  16. Drizzle's generated SQL migrations keep the audit trail that push skips

    Build · September 26, 2026 · 1 publisher

  17. University team runs 10,000 Stalwart mailboxes on PostgreSQL and S3 storage

    Build · September 26, 2026 · 1 publisher

  18. A Kafka Streams auth cache kept a revoked API key working for four days

    Build · September 26, 2026 · 1 publisher

  19. PostgreSQL's VACUUM strands sparse b-tree pages until a REINDEX rebuilds them

    Build · September 26, 2026 · 1 publisher

  20. Missing Column GRANT, Not RLS, Blocked an Admin Balance Top-Up in Postgres

    Build · September 25, 2026 · 1 publisher

  21. Any PostgreSQL replication account can load a shared library as the postgres OS user

    Security · September 4, 2026 · 4 publishers

  22. Postgres 18.6 fails closed on PGP columns OpenSSL never actually encrypted

    Build · September 6, 2026 · 1 publisher

  23. Temperô's iFood integration discarded every real polled event for weeks by switching on the short code

    Build · September 25, 2026 · 1 publisher

  24. Each background job retry gets its own Postgres row in a design built around tenant incident queries

    Build · September 25, 2026 · 1 publisher

  25. Headers and index page splits stretch a 20-byte Postgres sensor row to 95.6 bytes

    Product · September 25, 2026 · 1 publisher

  26. Checking membership inside Postgres policies closes a 15.5-minute revocation gap in a no-backend app

    Build · September 25, 2026 · 1 publisher

  27. NocoBase's 2.2.14 upgrade adds 44 columns, 42 of them in four new tables

    Build · September 24, 2026 · 1 publisher

  28. Postgres logical replication copies a reporting replica's rows but leaves its schema and sequences behind

    Build · September 24, 2026 · 1 publisher

  29. DocumentDB 0.116 adds a $group distinct scan that reads one index entry per value

    Build · September 24, 2026 · 1 publisher

  30. A Postgres role with no grants reads the FORCE flag on tables it cannot select from

    Build · September 24, 2026 · 1 publisher

  31. ParkEase puts its no-double-booking rule inside a GiST exclusion constraint

    Build · September 24, 2026 · 1 publisher

  32. An eight-attempt history has to climb 3.5 points before CogniPrep draws an arrow

    Build · September 24, 2026 · 1 publisher

  33. MCP's stateless core moves a 30-minute approval pause into your database

    Build · September 23, 2026 · 1 publisher

  34. Post-filtering a RAG query spends its LIMIT 10 on chunks the user cannot read

    Build · September 23, 2026 · 1 publisher

  35. A pricing policy built to resist promos never reads its promo label

    Build · September 23, 2026 · 1 publisher

  36. The cancellation went into cancel_at while the dashboard read cancel_at_period_end

    Build · September 23, 2026 · 1 publisher

  37. Three flipped defaults in n8n 2.0 can change a workflow nobody edited

    Build · September 22, 2026 · 1 publisher

  38. PostgreSQL 19's online checksum conversion ran slower than the outage it replaces

    Build · September 22, 2026 · 1 publisher

  39. GoVueKit runs one typed membership lookup before any handler sees a tenant request

    Build · September 22, 2026 · 1 publisher

  40. A dedicated vector database adds a sync job to every write

    Build · September 22, 2026 · 1 publisher