Articles, tools & resources for Vapor devs
SubscribeThe Future of Vapor
After nearly 400 releases, we're now looking to what comes after Vapor 4. With Swift 6 on the horizon, here's our thinking on Vapor 5 and the framework's future
On Fluent Models and Sendable warnings
Since FluentKit 1.48.0, every Fluent Model triggers a Sendable warning. Here's the Swift property-wrapper corner case behind it, and how to handle it.
JWTKit is no longer Boring!
JWTKit is the first Vapor package rebuilt around Swift's structured concurrency ahead of Swift 6. Here's what's new in this major release.
Vapor URI Parsing Security Vulnerability
Vapor 4.90.0 fixes CVE-2024-21631 in URI parsing, replacing the old C parser with a safer Swift implementation. Upgrade if you parse untrusted URIs.
Vapor HTTP Error Handling Security Vulnerability
Vapor 4.84.2 fixes CVE-2023-44386, an error-handling flaw that let an attacker crash an app by triggering a write to a closed channel. Upgrade now.
Upcoming changes to Vapor with `Sendable`
Advance warning of some upcoming changes to Vapor as we continue our Concurrency journey.
Penny Update - Keep Up With Swift's Evolution and More
Vapor's Penny Discord bot now tracks Swift Evolution, posting proposal updates in #swift-evolution — and you can follow them from your own server too.
PostgresNIO Security Vulnerability
PostgresNIO 1.14.2 fixes CVE-2023-31136, a TLS flaw letting a man-in-the-middle inject responses to a client's first queries. Upgrade as soon as possible.



