ZeroHour

Source: Simon Willison

4 items in the last 24h

datasette 1.0a40new

Datasette 1.0a40 alpha adds a background task plugin API and migrates to httpx2, carrying the same security fix as 0.65.5.

Simon Willison released Datasette 1.0a40, an alpha on the road to a stable 1.0, which includes the same security fix shipped in 0.65.5. New capabilities include a datasette.add_background_task() method letting plugins launch and manage background tasks, and a migration to httpx2 powering internal client methods like datasette.client.get(). Many bug fixes resulted from issue triage ahead of the 1.0 stable release.

Simon Willison · 1h agoAI tools & infra 5 sources

datasette 0.65.5new

Datasette 0.65.5 patches a permission bypass where a trailing newline in a table name could expose private rows (GHSA-h547-rmjf-5m2m).

Datasette 0.65.5 fixes a security issue tracked as GHSA-h547-rmjf-5m2m in which a trailing newline in a requested table name bypassed table permission checks and exposed private rows. The flaw was reported by dpfkdlemtp. The same fix is included in the 1.0a40 alpha release.

Simon Willison · 1h agoVulnerability 5 sources

Claude Cowork and chat are now one Claude

Anthropic is merging Claude Cowork and Claude chat into a single general-purpose agent experience, rolling out first to Pro and Max plans.

Simon Willison reports that Claude Cowork and Claude chat are merging into one Claude interface starting today, letting users hand off quick questions or longer tasks that continue running even after the laptop is closed. The rollout covers the Claude app on web, desktop, and mobile over the coming weeks for Pro and Max subscribers. Willison notes this effectively turns Claude into a general agent in its own right.

Simon Willison · 7h agoAI industry 5 sources

Quoting Mustafa Suleyman

Microsoft AI CEO Mustafa Suleyman argues against granting AI models rights or moral status, saying it would hinder containment and alignment.

Mustafa Suleyman published a warning about 'model welfare', arguing there is no evidence models have feelings, preferences, or rights, and that inviting them to share ethical or legal status would make AI containment and alignment harder. Simon Willison quotes the post on his blog.

Simon Willison · 9h agoAI safety & security