n8n 2.41.6's Postgres node writes $1 values into SQL text via pg-promise 11.9.1, so Postgres never gets a bind parameter. A psql PREPARE dry-run tests a path the node never uses, and Postgres types inlined literals before any CASE guard runs.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence65
Supabase raised $150 million and agreed to buy Turso, whose SQLite-compatible engine gives AI agents large numbers of small, isolated databases. The deal rests on Supabase's own count of agent-created databases, and Turso's customers now build on that bet.
Perspective Coverage
8 publishers
- Builder
- Builder 42%
- Operator
- Operator 26%
- Investor
- Investor 32%
Reality
- Evidence62
- Adoption45
- Hype gap+30
- Incentives80
- Confidence64
Omnara has replaced its remote-coding app with an Apache 2.0 control plane that keeps each agent's identity and history while worker machines come and go. Teams get one more self-hostable backend for agents run as durable services, though the only usage figures so far describe the retired app.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence50
AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence50
Turbopuffer is rewriting its serverless database as v3, moving the ANN index out of the core of storage and making it one of several secondary indexes. A dev.to explainer of the September 30 post says the vector-first layout held back GROUP BY and aggregation queries.
Reality
- Evidence40
- Adoption25
- Hype gap+35
- Incentives45
- Confidence50
UpGuard found 16,326 Supabase databases with readable tables in a scan of roughly 300,000 domains. Supabase's new default keeps new tables off its APIs, but older tables keep their grants until owners review them and their row-level security.
Reality
- Evidence68
- Adoption70
- Hype gap+15
- Incentives45
- Confidence66
SaaStr says one estimate puts AI-agent access to Salesforce, Atlassian and HubSpot at up to $240,000 a year, for API calls it never paid for. Its own revenue agent proposed mirroring the data into a $5 Postgres database, so vendors are now pricing against a buyer's cost of calling them less.
Reality
- Evidence35
- Adoption30
- Hype gap+20
- Incentives60
- Confidence40
One developer's test on 484 SEPA rulebook passages found that plain-English questions push several answers out of a top-5 vector search. Because the test measures each answer's rank directly, the failure shows up in retrieval, before the language model writes anything.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Postgres row-level security on a tenant_id column is the right default for most B2B SaaS apps, a dev.to guide argues, at two statements and a policy per table. Its warning is that a policy can look secure in a migration diff and still let one tenant reach another's data.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Postgres locks both tables with SHARE ROW EXCLUSIVE when a migration adds a foreign key, blocking writes until every child row is scanned. A dev.to guide on Laravel migrations splits the change into two statements so the slow scan stops holding up the app's writes.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
Drizzle-kit generated a DROP TABLE ... CASCADE for a table still in production when a developer asked it for two new tables. The developer traces it to schema.ts, drizzle-kit's snapshot and the live database each describing a different schema.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence60
Ninety-eight of 100 public Supabase migration histories leave a table the Data API cannot reach once automatic grants end on Oct 30, a dev.to replay found. Existing tables keep their grants, so the failures land on new tables and on environments rebuilt from those files.
Reality
- Evidence55
- Adoption5
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Django's icontains made Postgres filter UPPER(product_name) while a team's pg_trgm index covered the raw column, so product searches ran for several seconds. Having the indexes proved nothing until the team read the generated SQL beside the query plan.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence60
AWS has embedded DuckDB in Aurora PostgreSQL from versions 17.11 and 18.6, so one SQL query can join live rows with Iceberg and Parquet tables in S3. Reverse-ETL jobs that exist only for that join can be retired if the database instance has room for the lake scans.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives72
- Confidence70
Microsoft-led DocumentDB 0.117 adds scalar $group index pushdown, so Postgres can sum an indexed field for a MongoDB query that carries no hint. Because the feature ships off, MongoDB users weighing DocumentDB swap a query hint for a server setting.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence45
Databricks says Lakebase restores Postgres in seconds even at 100 TB by creating a branch at a timestamp. The figure times branch creation, so it matches a finished RDS restore only if that branch serves production reads at once.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+45
- Incentives85
- Confidence40
One developer moving a 99-table SaaS off Supabase Cloud saw all 228 row-level security policies fail silently until auth.uid() moved with the database. Any app that queries Postgres from the browser has to bring its auth and session layers across in the same cutover.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
LiteLLM launched Lens on September 30, a tool that uses AI agents to find recurring failures across agent traces sent through its model gateway. Customers host the analyzer and its databases, and the 200,000-trace volume CTO Ishaan Jaffer cites is a future target Lens has not been measured against.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence40
Schemity's developer showed that a PostgreSQL role with only CONNECT and USAGE reads the full schema from pg_catalog while every table SELECT fails. Diagram tools built on information_schema show that same role an empty database.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives50
- Confidence62
PostgreSQL 18.3 spent 10.4 seconds rewriting a 5-million-row table to add a gen_random_uuid() column, against 10 ms for a constant default. Values computed per row need a staged migration, with every statement run under lock_timeout.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives20
- Confidence65
Earlier coverage
- PostgreSQL accepts SET NULL foreign keys that fail only when a parent row is deleted
Build · September 30, 2026 · 1 publisher
- COMMIT; DROP TABLE slips past the reference Postgres MCP server's read-only guard
Build · September 30, 2026 · 1 publisher
- postgres-js pads pooled query results with empty slots after a mid-stream timeout
Build · September 30, 2026 · 1 publisher
- One index scan answers a filtered, sorted page of embedded array data in DocumentDB 0.109
Build · September 29, 2026 · 1 publisher
- DocumentDB 0.116 lets $group read rows in the order an existing index already provides
Build · September 29, 2026 · 1 publisher
- UpGuard finds more than 16,000 Supabase databases left readable through missing row-level security
Security · September 28, 2026 · 1 publisher
- Timescale's agent-run memory sprint turned on a human checking what each metric counted
Product · September 28, 2026 · 1 publisher
- Nightly archive of auditd logs kept 234 of 696 hours on a busy database server
Build · September 28, 2026 · 1 publisher
- Agent memory handoffs cut replaced context 98.65% by moving verbatim text out of the prompt
Build · September 27, 2026 · 1 publisher
- One GCP VM runs an ML team's Airflow for under $150 a month against Composer's $350 estimate
Build · September 27, 2026 · 1 publisher
- PostgreSQL foreign key inserts take a hidden row lock that deadlocks ledger deposits
Build · September 27, 2026 · 1 publisher
- Penalising sequential scans in tests exposes the missing index a 20-row table hides
Build · September 27, 2026 · 1 publisher
- SvelteKit starter kits' boot-time migrations race once a second replica starts
Build · September 27, 2026 · 1 publisher
- A coding agent built a four-platform Kotlin messenger from a 33 KB plan cut into five steps
Build · September 27, 2026 · 1 publisher
- Indexing a PostgreSQL 18 generated column requires writing STORED
Build · September 27, 2026 · 1 publisher
- Drizzle's generated SQL migrations keep the audit trail that push skips
Build · September 26, 2026 · 1 publisher
- University team runs 10,000 Stalwart mailboxes on PostgreSQL and S3 storage
Build · September 26, 2026 · 1 publisher
- A Kafka Streams auth cache kept a revoked API key working for four days
Build · September 26, 2026 · 1 publisher
- PostgreSQL's VACUUM strands sparse b-tree pages until a REINDEX rebuilds them
Build · September 26, 2026 · 1 publisher
- Missing Column GRANT, Not RLS, Blocked an Admin Balance Top-Up in Postgres
Build · September 25, 2026 · 1 publisher
- Any PostgreSQL replication account can load a shared library as the postgres OS user
Security · September 4, 2026 · 4 publishers
- Postgres 18.6 fails closed on PGP columns OpenSSL never actually encrypted
Build · September 6, 2026 · 1 publisher
- Temperô's iFood integration discarded every real polled event for weeks by switching on the short code
Build · September 25, 2026 · 1 publisher
- Each background job retry gets its own Postgres row in a design built around tenant incident queries
Build · September 25, 2026 · 1 publisher
- Headers and index page splits stretch a 20-byte Postgres sensor row to 95.6 bytes
Product · September 25, 2026 · 1 publisher
- Checking membership inside Postgres policies closes a 15.5-minute revocation gap in a no-backend app
Build · September 25, 2026 · 1 publisher
- NocoBase's 2.2.14 upgrade adds 44 columns, 42 of them in four new tables
Build · September 24, 2026 · 1 publisher
- Postgres logical replication copies a reporting replica's rows but leaves its schema and sequences behind
Build · September 24, 2026 · 1 publisher
- DocumentDB 0.116 adds a $group distinct scan that reads one index entry per value
Build · September 24, 2026 · 1 publisher
- A Postgres role with no grants reads the FORCE flag on tables it cannot select from
Build · September 24, 2026 · 1 publisher
- ParkEase puts its no-double-booking rule inside a GiST exclusion constraint
Build · September 24, 2026 · 1 publisher
- An eight-attempt history has to climb 3.5 points before CogniPrep draws an arrow
Build · September 24, 2026 · 1 publisher
- MCP's stateless core moves a 30-minute approval pause into your database
Build · September 23, 2026 · 1 publisher
- Post-filtering a RAG query spends its LIMIT 10 on chunks the user cannot read
Build · September 23, 2026 · 1 publisher
- A pricing policy built to resist promos never reads its promo label
Build · September 23, 2026 · 1 publisher
- The cancellation went into cancel_at while the dashboard read cancel_at_period_end
Build · September 23, 2026 · 1 publisher
- Three flipped defaults in n8n 2.0 can change a workflow nobody edited
Build · September 22, 2026 · 1 publisher
- PostgreSQL 19's online checksum conversion ran slower than the outage it replaces
Build · September 22, 2026 · 1 publisher
- GoVueKit runs one typed membership lookup before any handler sees a tenant request
Build · September 22, 2026 · 1 publisher
- A dedicated vector database adds a sync job to every write
Build · September 22, 2026 · 1 publisher