Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT

VERIFIED PUBLISHER INTELLIGENCE

Release notes and known issues

Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.

85 official publisher sources registered · 83 collected automatically · 0 monitored for availability · 2 requires publisher access

1878 verified publisher records · Page 14 of 19

CLOUDFLARECLOUDFLARED-2026.9.1

2026.9.1

SHA256 Checksums: cloudflared-amd64.pkg: c4084991b83b2f538853c97a502f424805467e4375d18138ab80bc2414340997 cloudflared-arm64.pkg: b877c291db70cc83891785c4bf3da88ac3a82944d34ebeb953f932a4d5f02cf1 cloudflared-darwin-amd64.tgz: 1ea07ae775b03236bd6be18ca1848d6bdc4af2f4f3bce398823b5a36e5761b75 cloudflared-darwin-arm64.tgz: 9a0b19f67dc7a3011bc6b972c7ce06a5fcea8784ac6bd599ffa382ea4aeb5a6e cloudflared-fips-linux-amd64: 7fac1c6aae4ae2131e73056d88c3e35a7120feaa9088333e737d25ae9bb5116c cloudflared-fips-linux-amd64.deb: 673e05158218563b415532e30f2cb1d68ae73b908ffc0b0e526b9d852937480c cloudflared-fips-linux-x86_64.rpm: 485dc5891fd1944b67b9bac4541a37a066888240007127ee07edd7f37ac96e21 cloudflared-linux-386: 5d66134cf7646cb98f33aeee7bcc8b97d8feacd76db279f5903f9585226e0922 cloudflared-linux-386.deb: 7e57a9d784613fb5df8b8702e34aeabe0f6ceeaddb0a52885fef0aed9195bd11 cloudflared-linux-386.rpm: bde6c912d0e782eeddb6bbd4f0ca82f3a8919d16e00ade13d3cb8a4a0cd3fde1 cloudflared-linux-aarch64.rpm: 01c79e73b1e2b534e43352076cc5494d99049c097b8ffe4357462c79115446f7 cloudflared-linux-amd64: 03f1f25d1cc93b9ad6c60569d44060bc4f17ed97075760ed8cfca4b12dcd68cc cloudflared-linux-amd64.deb: 3be76adc4185d36a0bfb4c2dd8663292f0ed363797f2180333b513b43c81d419 cloudflared-linux-arm: 093ffa3638ab2b636de63c43a8c68f96a69cf71f9699dd8277a91b160b0f4fc0 cloudflared-linux-arm.deb: a53341634814b4d0f44147b8ba73169e33b160135d2a9224ba9fd2ea4beef5af cloudflared-linux-arm.rpm: 1f1dd1afecb74d1936e48758fd01089274b2770e1d291154fd9b13592eff937b cloudflared-linux-arm64: 3d97437c71848bd8df68041e12436b484a661d95073ea1937f01a845ce88faa3 cloudflared-linux-arm64.deb: 2a870d5bf6ea74d16c0923b804eabbf4943f1fd7c63a5c20fd41cc66b629c725 cloudflared-linux-armhf: 95420507a720fb543122a5d69372fbde8f5c919790e95ddd4374a449e0a6f4dd cloudflared-linux-armhf.deb: 813dc2ff3af161ec77c7fab4b84a15c732e03f5503bb709e3f51bb82ac261ca5 cloudflared-linux-armhf.rpm: b5ef384fc490cc1cc891322012bc001ae2ea9c36370b8cb71369256b9c84b54d cloudflared-linux-x86_64.rpm: e9e2daff5ecc2b3e8d3a5e1ce17f95b3dc2360e6bb846da29647bbb967cf52b9 cloudflared-windows-386.exe: 11b6e4b2d306950bd87e7caa4deee8e80a32d71ffee555a96237a76651eeae4c cloudflared-windows-386.msi: 8086e90565aa5e864df664242706e819341547525c220ca09f785d4969edfdae cloudflared-windows-amd64.exe: 2837888cc0f5d58f15b6dc478376de90b4d3ba5241c7947455d1e0a0df429712 cloudflared-windows-amd64.msi: 6f85717310db514c0db658c3b7bbdff36c1d613c4edeafb4981b3160cc7b836f

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPEN HOME FOUNDATIONHOME-ASSISTANT-2026.9.2

2026.9.2

Normalize Hive auth username before login ( @Oluwatobi-Mustapha - #168827 ) ( hive docs ) Don't mutate the module level Roomba SENSORS list ( @jasondillingham - #181107 ) ( roomba docs ) Fix Openhome players becoming unavailable between polls ( @bazwilliams - #181238 ) ( openhome docs ) (dependency) Clear webostv source when the current app is not in the source list ( @darkrain-nl - #181381 ) ( webostv docs ) Bump adext to 0.4.7 ( @Chang-Jin-Lee - #181384 ) ( alarmdecoder docs ) (dependency) Bump midea-local to 11.0.1 ( @chemelli74 - #181405 ) ( midea docs ) (dependency) Drop the unknown-app sentinel from vizio app_name on non-app inputs ( @raman325 - #181417 ) ( vizio docs ) Add l/min unit mapping to nibe_heatpump sensors ( @frankkopp - #181433 ) ( nibe_heatpump docs ) Bump airos to 0.6.12 ( @CoMPaTech - #181473 ) ( airos docs ) (dependency) Bump gcal-sync to 9.1.1 ( @allenporter - #181499 ) ( google docs ) (dependency) Add volume filter DF Portainer ( @erwindouna - #181510 ) ( portainer docs ) Bump satel_integra to 1.4.0 ( @Tommatheussen - #180960 ) ( satel_integra docs ) (dependency) Bump satel-integra to 1.5.0 ( @Tommatheussen - #181523 ) ( satel_integra docs ) (dependency) Bump aiortm to 0.20.1 ( @MartinHjelmare - #181524 ) ( remember_the_milk docs ) (dependency) Fix unique_id for service entities in Alexa Devices ( @chemelli74 - #181526 ) ( alexa_devices docs ) Handle monitoring failure for Satel Integra ( @Tommatheussen - #181548 ) ( satel_integra docs ) Fix Vizio soundbars requiring authentication ( @raman325 - #181556 ) ( vizio docs ) Bump vizaio to 0.6.2 ( @raman325 - #181562 ) ( vizio docs ) (dependency) Improve error messages in remote_calendar ( @allenporter - #181571 ) ( remote_calendar docs ) Update local_todo to explicitly specify UTF-8 encoding for ICS storage ( @allenporter - #181578 ) ( local_todo docs ) Repair local_todo malformed ICS files with CRLF newlines on setup ( @allenporter - #181581 ) ( local_todo docs ) Redact credentials from go2rtc server log output ( @balloob - #181583 ) ( go2rtc docs ) Fix MCP client double initialize in config flow ( @allenporter - #181594 ) ( mcp docs ) Increase HTTP timeout in remote_calendar ( @allenporter - #181599 ) ( remote_calendar docs ) Bound Tesla Fleet vehicle first refresh with a timeout ( @Bre77 - #181606 ) ( tesla_fleet docs ) Bump ZHA to 2.2.2, zha-quirks to 2.2.2 ( @TheJulianJES - #181610 ) ( zha docs ) (dependency) Retry ViCare setup when the API quota is spent ( @lackas - #181629 ) ( vicare docs ) Bump actron-neo-api to 0.5.16 ( @kclif9 - #181639 ) ( actron_air docs ) Rename Xbox follower sensor name to 'Followers' ( @neyzm - #181654 ) ( xbox docs ) Fix shared wakelock across Tesla Fleet vehicles ( @Bre77 - #181658 ) ( tesla_fleet docs ) Nest climate: recompute supported_features from live device traits ( @rqi14 - #181660 ) ( nest docs ) Bump waterfurnace to 1.9.0 ( @sdague - #181746 ) ( waterfurnace docs ) (dependency) Bump python-roborock to 7.4.1 ( @piitaya - #181754 ) ( roborock docs ) (dependency) Retry sftp_storage setup when the SSH connection fails ( @lackas - #181769 ) ( sftp_storage docs ) Stream usage prediction events instead of loading them into memory ( @balloob - #181770 ) ( usage_prediction docs ) Bump pyatag to 0.3.7.1 ( @JamieMagee - #181796 ) ( atag docs ) (dependency) Do not fail esphome setup when Supervisor is not ready ( @balloob - #181805 ) ( esphome docs ) Report UniFi WAN latency as unknown when a monitor is unresponsive ( @sdelmas - #181809 ) ( unifi docs ) Bump PyViCare to 2.62.1 ( @lackas - #181830 ) ( vicare docs ) (dependency) Bump reolink_aio to 0.21.16 ( @starkillerOG - #181861 ) ( reolink docs ) (dependency) Use PKCE for Weheat OAuth2 authorization ( @barryvdh - #181881 ) ( weheat docs ) Bump python-roborock to 7.4.2 ( @allenporter - #181907 ) ( roborock docs ) (dependency) Preserve form values on error in Remote Calendar config flow ( @allenporter - #181908 ) ( remote_calendar docs ) Fix MELCloud Home energy interval ( @er

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.8

v3.6.0-rc.8

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-3.22.0

Helm v3.22.0

Helm v3.22.0 is a feature release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Notable Changes primarily dependency updates and k8s-io group to 0.37.0 Installation and Upgrading Download Helm v3.22.0. The common platform binaries are here: MacOS amd64 ( checksum / bd1d09f316558dda23698527859600936fed1371021ce0f2272d66b2fdcfa69c) MacOS arm64 ( checksum / 4c9982a6cdeb458b60258df66b55398ca5b19293f6877faffe2909ad6f23dfe0) Linux amd64 ( checksum / 1e4ab49e429626cf6c6958d914248b78c9730803c2751b87627e171dc800e7bb) Linux arm ( checksum / 695793765e2246824a7c859562886f79b1cc89d99420c89f940590440f7129ee) Linux arm64 ( checksum / f14e804dfee240f55525b667488fe9adca349e63e00c9af634c0beb1421ac310) Linux i386 ( checksum / b96b7a125cc7d38aa952a78b16e96d05426cd9791dd013be51ebab1c203d6729) Linux loong64 ( checksum /  BlobNotFound The specified blob does not exist. RequestId:8c31497a-101e-0042-27b6-404cb4000000 Time:2026-09-09T23:55:30.1192401Z) Linux ppc64le ( checksum / fa304f47163a19f4e275fe4e890465a8a80a6f26ce4772c6b1649355c995def1) Linux s390x ( checksum / 3f2cfd73018dcb9c25814e89c5946a362a8b951d8cce03152138d8cb28abcbff) Linux riscv64 ( checksum / 50f84d698daac65bded677c61db7138e082b23e667a3cabeff4fd2521614e498) Windows amd64 ( checksum / 899615865726d39f9b245e71e848c5bf4adc7ed33a8c43ede660facb48151b43) Windows arm64 ( checksum / 75a331a3b03d11aed6369bdf6a1f8f9d33635bc820de5cd6025a581292046805) This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @scottrigby keybase account . Please use the attached signatures for verifying this release using gpg . The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.3.1 and 3.22.1 are the next patch releases scheduled for October 14, 2026 4.4.0 is the next minor release scheduled for January 13, 2027. There will be no further Helm 3 minor releases (see https://helm.sh/blog/helm-v3-end-of-life ) Changelog chore(deps): bump the k8s-io group across 1 directory with 6 updates 144ca65 (dependabot[bot]) bump version to 3.22 ( #32606 ) b5de8bb (Scott Rigby) fix: set [pull,push] scope when helm push to a registry(use token auth) (backport) ( #32362 ) 9dbcb9f (kimsungmin1) chore(deps): bump the github-actions group across 1 directory with 4 updates ( #32575 ) 665ab55 (dependabot[bot]) chore(deps): bump the k8s-io group with 7 updates ( #32573 ) 0841093 (dependabot[bot]) chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 ( #32563 ) d0569c7 (dependabot[bot]) chore(deps): bump the github-actions group across 1 directory with 4 updates ( #32557 ) bcbdb1e (dependabot[bot]) chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 ( #32554 ) 6cdcc8f (dependabot[bot]) chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 ( #32542 ) 158719f (dependabot[bot]) [dev-v3 backport] deps: bump google.golang.org/grpc@v1.82.1 for GO-2026-6061 ( #32536 ) a442b8c (Scott Rigby) fix: bump go.opentelemetry.io/otel@v1.44.0 for GO-2026-5158 ( #32535 ) adab0ef (Scott Rigby) chore(deps): bump the github-actions group with 4 updates ( #32524 ) c068b54 (dependabot[bot]) chore(deps): bump the github-actions group with 4 updates 74271c4 (dependabot[bot]) chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6 1c50d2f (dependabot[bot]) chore(deps): bump the github-actions group with 4 updates ( #32509 ) 8821540 (dependabot[bot]) chore(deps): bump actions/stale in the github-actions group ( #32488 ) 05a2798 (dependabot[bot]) chore(deps): bump ossf/scorecard-action in the github-actions group ( #32461

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-4.3.0

Helm v4.3.0

Helm v4.3.0 is a feature release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Notable Changes feat: Add duration functions by @aeroyorch in #31695 feat(engine): add debug logging when lookup returns empty by @ogulcanaydogan in #32205 feat: add ownership verification before deleting resources during uni… by @banjoh in #31584 feat: honor SOURCE_DATE_EPOCH for chart archives by @lohitkolluri in #32162 feat(rollback): add --description flag to provide rollback reason by @biagiopietro in #31580 fix (internal/plugin): remove zero-width spaces from plugin name comment by @lexfrei in #32134 fix(loader): do not drop values files ending at a 4096-byte boundary by @locker95 in #32525 fix(chart): normalize StampModTimes timestamp to UTC/truncate + Chart.lock reproducibility test by @Mentigen in #32485 fix(provenance): support GnuPG keybox (pubring.kbx) keyrings by @ruslan-shaydullin in #32281 fix(template): regression - route registry messages to stderr in template and show by @amarkdotdev in #32217 refactor: lower resync period from one hour to 3 minutes by @AustinAbro321 in #31944 perf: enable concurrent status computation to prevent multi-minute delays by @mapleeit in #32043 chore(deps): bump the k8s-io group to 0.37.0 - #32598 Installation and Upgrading Download Helm v4.3.0. The common platform binaries are here: MacOS amd64 ( checksum / 347a784877e0e20eac865e8d1c36a80f6bb0861d6f29abd34defb6570ef95d92) MacOS arm64 ( checksum / d3870437e1e95b67f8edbde964156c84a26503f560821d40c542441658934fba) Linux amd64 ( checksum / 86584a54def73570558f66f5111cc53dfed56689637ae32c1201205d494f54fb) Linux arm ( checksum / 467c353e4a1ab57412dd00c6bfb1a6a2ab4a57d775506f8b38c58502c0ba6861) Linux arm64 ( checksum / 31c5794dd55c66a51e6b7d2e2ac7a114ae8b1de41ff1d9ba51748ac973b06a08) Linux i386 ( checksum / e969a9492ac128097069aef7eb63be3b2504a20b5377a240b4c5c9bfc4b51575) Linux loong64 ( checksum / 4ffe485ef474d722699794851642e1c7037e4776233e77637c649f69f3e9a4ce) Linux ppc64le ( checksum / 5ff7d5ea6f396c15f3cfda3fb8ecb0ecb1b11bc283785adeb55eefb2c62e0bda) Linux s390x ( checksum / ab637a6a1c3d457b9975726c100d74e484e579d5462c4fd2e3bfcfa97df57cd7) Linux riscv64 ( checksum / 5359f5544478de80de2dfd60bdc5e0c22f26255b3c44335483e0f9bd3ba6ec58) Windows amd64 ( checksum / 304ea163cce4d9ad14e189c01846c6a34de9cfdfe48536ae54b2e8ba7884e67c) Windows arm64 ( checksum / 4a9eefa30d26eb73900a9a0f16e97eae678582172204db60cbd454c68acea246) This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @scottrigby keybase account . Please use the attached signatures for verifying this release using gpg . The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.3.1 and 3.22.1 are the next patch releases scheduled for October 14, 2026 4.4.0 is the next minor release scheduled for January 13, 2027. There will be no further Helm 3 minor releases (see https://helm.sh/blog/helm-v3-end-of-life ) Changelog chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 bec5b06 (dependabot[bot]) chore(deps): bump the k8s-io group across 1 directory with 6 updates d0d42e7 (dependabot[bot]) bump version to 4.3 ( #32605 ) 7328f42 (Scott Rigby) chore: Fix independent-merge lint issues ca6681c (George Jenkins) refactor(repo): Use byte buffer to build index file ( #32579 ) 37752b7 (Tom Wieczorek) chore: fix gofumpt extra-rules ( #32486 ) 28e64bd (Matthieu MOREL) Remove deprecated internal/chart/v3/ code ( #32365 ) 4dfbaa4 (George Jenkins) fix(template): regression - route registry messages to stderr in te

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.580.1

2.580.1 RC

Please report any issues found to the release candidate announcement thread . The final release is scheduled for September 30, 2026 . Download the release from the artifact repository After the final release, the official changelog and official upgrade guide will be available on www.jenkins.io/download .

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VEEAMKB4820

What Microsoft's EWS Retirement Means for Your Veeam Backups

What Microsoft's EWS Retirement Means for Your Veeam Backups KB ID: 4820 Product: Veeam Data Cloud for Microsoft 365 Veeam Backup for Microsoft 365 Published: 2026-03-25 Last Modified: 2026-09-28 Updated September 2026 This article has been revised to reflect: Microsoft's October 1, 2026 enforcement timeline. The introduction of the EWSAllowedAppIDs allow list. The current status of Veeam's transition to Microsoft Graph. Customers who have previously read this article are advised to review Steps 1 and 2 closely. Challenge Microsoft is retiring Exchange Web Services (EWS) in Exchange Online. EWS is the protocol Veeam currently uses to back up Exchange Online mailboxes. Key dates: October 1, 2026 — Microsoft begins disabling EWS tenant by tenant. Tenants who have not explicitly enabled EWS will be automatically blocked as the rollout proceeds. April 1, 2027 — EWS is fully and permanently shut down for all tenants. Note: These EWS phase-out dates apply to all Exchange Online mailbox types (including Kiosk/F1/F3). Configuring EWSAllowedAppIDs as described in Step 2 will maintain backup access for all mailboxes through the end of the transition period. However, if you take no action before October 1, your Exchange Online mailbox backups will fail. Veeam's transition to Microsoft Graph Veeam is actively transitioning Exchange backup functionality from EWS to the Microsoft Graph API. This requires additional Microsoft Graph permissions. However, Microsoft has not yet completed all the Graph API capabilities required — specifically, delta sync support needed for incremental backups. Veeam is working closely with Microsoft to close this gap. Until it is resolved, EWS must remain accessible for Exchange Online backups to continue. See Microsoft's parity gap roadmap for the latest status. Solution Exchange Online PowerShell Module Requirements The Exchange Online commands in this article are run using the Exchange Online PowerShell module. Instructions for installing or updating the module are provided in Install and update the Exchange Online PowerShell module , and instructions for connecting to the tenant are provided in Connect to Exchange Online PowerShell . Step 1: Keep EWS enabled in your tenant EWS access in Exchange Online is controlled by the EwsEnabled setting in your organization's configuration. Most tenants are currently at the default value of $null , and you will need to change this to $true before October 1, 2026. What happens to each setting value starting October 1, 2026 If EwsEnabled Value Is: This will happen starting October 1, 2026: $null (default — most tenants) Microsoft automatically changes this to $false . EWS is blocked for all apps. You can re-enable it afterward, but that change can take time to propagate, and you will then need a validated App ID allow list (see Step 2 ) before EWS access is restored. $true Microsoft honors an explicitly configured $true value and does not change it to $false during the rollout. However, the setting alone no longer determines access. If the App ID allow list is empty, all EWS access will be blocked. If the list is populated, only the applications on it can use EWS, which is already true before this date (see Step 2 ). $false EWS remains blocked. Swipe to show more of the table Action required: Explicitly set EwsEnabled to $true now Run the following PowerShell command against the Exchange Online tenant to check the current value first: Get-OrganizationConfig | Format-List EwsEnabled Copy If the current value is anything other than $true , run the following command to set the value to $true : Set-OrganizationConfig - EwsEnabled $true Copy Setting this explicitly to $true before October 1 protects your tenant from the automatic $null → $false conversion and gives you control over the transition timeline. Step 2: Manage your EWS App ID allow list Microsoft has introduced EWSAllowedAppIDs , an allow list that controls which Entra ID app registrations are permitted to use EWS.

Published 10 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
VEEAMKB4885

Windows 11 24H2/25H2 | Server 2025 - Recovery Media Restore Fails with: The Local Security Authority cannot be contacted

Windows 11 24H2/25H2 | Server 2025 - Recovery Media Restore Fails with: The Local Security Authority cannot be contacted KB ID: 4885 Product: Veeam Agent for Microsoft Windows Published: 2026-07-28 Last Modified: 2026-09-10 Issue Resolved in September 8 2026 Windows Updates The underlying issue documented in this article was resolved by Microsoft in the September 8 2026 security updates for Windows 11 (KB5124008) and Windows Server 2025 (KB5122871). After applying the update, the Veeam Recovery Media must be recreated. Challenge When attempting to perform a restore using the Veeam Recovery Media , the restore fails while establishing the connection to the local VeeamAgent.exe process, and the following error occurs: The Local Security Authority cannot be contacted Because the failure occurs before a recovery operation can begin, it prevents restoring from any backup location, including local storage, a network shared folder or Veeam backup repository, and cloud repositories. Cause This issue occurs due to a regression introduced by the Microsoft June 2026 security update for Windows 11 and Windows Server 2025. The update changed the behavior of the Windows security subsystem (Local Security Authority and Schannel) within the Windows Recovery Environment (WinRE), on which the Veeam Recovery Media is based. As a result, the TLS handshake that secures the connection between the restore wizard and the local VeeamAgent.exe process cannot be completed. This behavior has been confirmed with the following Microsoft Windows updates for Windows 11 (versions 24H2 and 25H2) and Windows Server 2025, and later updates released before September 2026: KB5094126 (OS builds 26100.8655 and 26200.8655) KB5099536 (OS build 26100.33158) Recovery media created from a system running an earlier update (for example, KB5089549, OS build 26200.8457, or earlier) is not affected. Solution This issue was resolved by Microsoft in the September 8 2026 security updates. To resolve the issue, install the applicable update on the machine where the Veeam Recovery Media is created: Windows 11 (versions 24H2 and 25H2): KB5124008 (OS builds 26200.9445 and 26100.9445) Windows Server 2025: KB5122871 (OS build 26100.33438) After the update has been installed, the Veeam Recovery Media must be recreated . Recovery media created before the update was installed remains affected. Workaround If the September 8 2026 update cannot be installed, the Veeam Recovery Media can be built using the Windows Assessment and Deployment Kit (Windows ADK) instead of the Windows Recovery Environment (WinRE). Recovery media built using the Windows ADK is not affected by this issue. Ensure that the Windows Assessment and Deployment Kit (Windows ADK) and the corresponding Windows PE add-on are installed on the machine where the Veeam Recovery Media will be recreated. Create the following registry value on the machine where Veeam Agent for Microsoft Windows is installed to configure it to build the Veeam Recovery Media using the Windows ADK: Location: HKEY_LOCAL_MACHINE\SOFTWARE\Veeam\Veeam Endpoint Backup Value Type: DWORD (32-Bit) Value Value Name: ForceUseAdkForRecoveryMedia Value Data: 1 Alternatively, the registry value can be created using the following PowerShell command: New-ItemProperty - Path "HKLM:\SOFTWARE\Veeam\Veeam Endpoint Backup" - Name "ForceUseAdkForRecoveryMedia" - PropertyType DWORD - Value 1 - Force Copy Recreate the Veeam Recovery Media . If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Published 10 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
VEEAMKB4900

Outbound Public IP Addresses Used by Veeam Data Cloud

Outbound Public IP Addresses Used by Veeam Data Cloud KB ID: 4900 Product: Veeam Data Cloud for Microsoft 365 Veeam Data Cloud for Microsoft Azure Published: 2026-09-10 Last Modified: 2026-09-10 Purpose This article lists the outbound public IP addresses that Veeam Data Cloud uses when connecting from the cloud to infrastructure that a customer hosts and controls, for example a Microsoft Azure Key Vault used for BYOK encryption. These addresses are not used for inbound connections made to Veeam Data Cloud. The addresses belong to the control plane shared by all Veeam Data Cloud products, so they are not specific to any one product. If a resource in the environment receives connections from Veeam Data Cloud and restricts access with an IP-based rule, whether in a firewall, a security group, a conditional access policy, or a similar control, that rule must account for the addresses listed below. If no IP-based restrictions are applied to connections from Veeam Data Cloud, no action is required. Solution Address Change Scheduled for October 2026 The addresses listed below are changing. Five new ranges come into use on 2026-10-12, and the three existing addresses will be retired on 2026-10-22. To ensure a smooth transition, any IP-based rule governing connections from Veeam Data Cloud must be updated to include the new ranges. Outbound Public IP Addresses IP address Status Notes 4.223.88.40/30 (4.223.88.40 – 4.223.88.43) Upcoming Will become active on 2026-10-12 13.78.8.220/30 (13.78.8.220 – 13.78.8.223) Upcoming Will become active on 2026-10-12 20.28.182.92/30 (20.28.182.92 – 20.28.182.95) Upcoming Will become active on 2026-10-12 20.46.44.192/30 (20.46.44.192 – 20.46.44.195) Upcoming Will become active on 2026-10-12 52.189.108.8/30 (52.189.108.8 – 52.189.108.11) Upcoming Will become active on 2026-10-12 20.18.9.116/32 Active Will be retired after 2026-10-22 40.86.73.61/32 Active Will be retired after 2026-10-22 135.225.48.195/32 Active Will be retired after 2026-10-22 Swipe to show more of the table Advised Action Any IP-based rule that governs connections from Veeam Data Cloud should permit every address listed above as Upcoming or Active. Permitting an upcoming address early has no effect on traffic and avoids a gap in connectivity when it comes into use. Leave an active address in place until after its retirement date, so that connections from Veeam Data Cloud continue to reach the environment while the change is applied. An address listed as Retired is no longer used and can be removed from the rule. Keeping Your Configuration Current This list is not fixed. Addresses may be added, changed, or withdrawn as the service evolves, and any rule that references them must be updated to match. Changes are published on this page in advance whenever possible. Because a rule built against an out-of-date list may block legitimate traffic, this page should be reviewed periodically. If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Published 10 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTMICROSOFT-AZURE-31E26C0B0251CF38

[Launched] Generally Available: TLS/SSL certificate and end-to-end TLS encryption support for Azure Functions Flex Consumption

Azure Functions Flex Consumption support for TLS/SSL certificates is now generally available through a new site-scoped certificate model. Each function app can hold up to 3 private (.pfx) and 3 public (.cer) certificates uploaded directly, imported from A

Published 10 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.7.13

v3.7.13

Important: Please read the migration guide . CVE fixed: Advisory GHSA-qqjf-53cj-pwvv Advisory GHSA-f52w-8j3h-j724 Advisory GHSA-v67p-phpq-fc8x Advisory GHSA-w4v4-9rw7-5326 Advisory GHSA-8fcf-v89g-xpg6 Bug fixes: [acme] Bump github.com/go-acme/lego/v5 to v5.4.1 ( #13759 @ldez ) [acme] Disable recursive nss propagation by default for DNS challenge ( #13830 @rtribotte ) [acme] Do not require recursive nameservers propagation by default for the DNS-01 challenge ( #13710 @amazon7737 ) [acme, tls] Ignore negated matchers when parsing rule domains ( #13725 @rtribotte ) [consulcatalog, nomad] Build a collision-free item key in the Consul Catalog and Nomad providers ( #13741 @rtribotte ) [http3] Dedicate a transport per HTTP/3 client connection ( #13812 @sdelicata ) [k8s/ingress-nginx] Fix sticky cookie expiration per request ( #13496 @makaiver ) [k8s/ingress-nginx] Create HTTP redirect router for ssl-passthrough with force-ssl-redirect ( #13457 @mmatur ) [k8s/ingress-nginx] Preserve leading dot in sticky session cookie Domain attribute ( #13456 @mmatur ) [logs, middleware] Set access log entry level and time before formatting the OTLP body ( #13767 @emilevauge ) [logs, tls, k8s/crd] Downgrade default TLS resources namespace mismatch log to warning ( #13780 @lazerg ) [middleware] Fix {url} placeholder in customErrors middleware now includes correct scheme ( #13320 @AnouarMohamed ) [middleware, authentication] Prevent user enumeration through the basic auth singleflight key ( #13816 @sdelicata ) [server] Build the configuration copy once per change ( #13746 @jspdown ) [server] Do not forward h2c upgrade headers to the backend ( #13797 @sdelicata ) [server] Deny request with an opaque request target ( #13796 @sdelicata ) [server] Do not forward request trailer values to the backend ( #13822 @rtribotte ) [server] Bump github.com/quic-go/quic-go to v0.62.0 ( #13807 @Nelwhix ) [tls] Redact duplicate TLS certificates in provider merge logs ( #13548 @xsergos ) [webui] Fix displayed number on details pages ( #13779 @gndz07 ) Documentation: [k8s] Add warning about Ingress API frozen state ( #13783 @jnoordsij ) [k8s] Remove namespace reference for providers.kubernetesGateway.labelSelector ( #13790 @jnoordsij ) [k8s/crd] Fix broken redirect for the Kubernetes CRD reference docs ( #13811 @thev1ndu ) Tell scanning agents to read the security policy and decisions pages ( #13753 @emilevauge )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOOGLEANGULAR-22.2.0-NEXT.6

22.2.0-next.6

compiler Commit Description namespace @property declarations compiler-cli Commit Description do not flag callable objects with zero parameters in uninvoked track function check core Commit Description add ErrorBoundary programmatic APIs ( #70463 ) allow reading Injector from a view or content query apply SkipSelf to only the starting node in embedded views language-service Commit Description add support for @boundary blocks ( #70463 ) platform-server Commit Description avoid sourcemap corruption during domino path substitution router Commit Description expose router resources in public API determine blocking state solely by resource loading status keep detached route subtree contexts isolated and intact

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARED-2026.9.0

2026.9.0

SHA256 Checksums: cloudflared-amd64.pkg: 57f6a86a7f77b75722227729f6d6ce41e5ab1bc82415bd4d39a734c7d9e0c4ce cloudflared-arm64.pkg: 3372ef71d54c93217efeeec486e53c44b8746032ff0a85088556ed51c80e1a6d cloudflared-darwin-amd64.tgz: 53481a9eed22fbf29cf3be7638d7c437acb423cdbe06e62639d8467b05d2f44f cloudflared-darwin-arm64.tgz: 2d67b7315f96799123e19442580ce7c7616d6d7f322686fa829dd4e3fddfe715 cloudflared-fips-linux-amd64: 2accaa85e279995f2e1e0179e5258c99dcafbafbbeb559f05eb031daa4c57f08 cloudflared-fips-linux-amd64.deb: 543e1513f60ec7a2c47970b0769cf354da5430dc046138fa6f05938d9533b2bc cloudflared-fips-linux-x86_64.rpm: b45120bdc6e43b3eadf8043836252763afa3d9fd1c0b2c0d345de1911ff053ff cloudflared-linux-386: d18731b05ae5c457ae5bdab76f0d517918403789ac7df754e37565d8375c6f24 cloudflared-linux-386.deb: 97e56b9818b2b94556507dd06949033d6d59e5de37d2ced6c56ef230186e7f5d cloudflared-linux-386.rpm: 89f5d28faa57b710e1d3280198790be2a62167b9d29a89789e7ac13619755762 cloudflared-linux-aarch64.rpm: 842ee766fb9b6d97ab8be35131738db72eb6a13f78de775d29f802a67672e6bd cloudflared-linux-amd64: 53b7a7a5420d188758d24341294acb0d1bca54296548ac05e38811a694ac6134 cloudflared-linux-amd64.deb: 1ea48af7a774376b71e329c6fdc0b7853298df270356132a294f8d8d5eb0e543 cloudflared-linux-arm: 0077f9b0ce9d9bd95e67c22aff33d132c83513c0e80b0bc686f00fe418bb336b cloudflared-linux-arm.deb: 68af658a4d6a812c613c804f5a4e93287797f84597e1657f7a491ef3b3837284 cloudflared-linux-arm.rpm: c21f54f6966ab1148d3e15af2a8e15a380ab1c0cb7d0feab84b27e19a7ef230c cloudflared-linux-arm64: 98aca3173f73248fad6180fc75dade2d186a6e54fa807e088108cb4345de8efe cloudflared-linux-arm64.deb: 2355fac318375a79d4f62690251e92a52d56f2737e30f053bb3419000fc32593 cloudflared-linux-armhf: 738271eeb53f010c30c559071fa7b312262bbcad2f358232fb4b710075d80d47 cloudflared-linux-armhf.deb: 444a5b5e8db1bb0b5b58d2889b05d9a6c2e04656139fc24e3a39355eb57c94bf cloudflared-linux-armhf.rpm: 059ff745b6483b25b8fb7ff7d7d66eda822fa5c4b40f2d6c7318693422e819b1 cloudflared-linux-x86_64.rpm: 8f2ba4ee8655edf99adece12c1b93776bbdb29b8ef7a3e8bdb5193699c93eb22 cloudflared-windows-386.exe: e11ee417d5bab1918c3e257c2b1f9541d6febd545091ecf87e249c3cfb7880b0 cloudflared-windows-386.msi: af64b20c2c71419a3641f24c1e2b7f6d039da7dfb24b8986b6d599ab870ab94a cloudflared-windows-amd64.exe: 547057326266f0e1c7d50d102dbd22ff283d740c055bd61e94f10e2c606f89af cloudflared-windows-amd64.msi: 7ee5b66c158c40f8f6cb62b01b7e48ee8cf5907e35b1a1fad3534d41b6d29488

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0308

PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Published 9 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0309

PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM). The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Published 9 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0310

PAN-OS: Buffer Overflow Vulnerability via XML Processing

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. Panorama is impacted by this vulnerability.

Published 9 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-26.8.2

2026-09-09, Version 26.8.2 (Current), @aduh95

Notable Changes [ 616bd3fa26 ] - doc : deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593 [ ae1801eb55 ] - meta : refine the security vuln posture for experimental features (James M Snell) #65438 [ 09feba74c8 ] - deps : update Undici to 8.10.2 (Node.js GitHub Bot) #65788 [ 7efdbe3eb9 ] - deps : update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542 Commits [ d8aedd6584 ] - build : skip dockit on riscv64 (Stewart X Addison) #62251 [ 1899c274eb ] - build : activate correct default flags for riscv64 (Stewart X Addison) #65708 [ ec8a3be996 ] - build : derive NODE_ARCH from target_cpu in the GN build (Shelley Vohr) #65491 [ b73118a507 ] - build,win : remove LTO parallelisation limit (Stefan Stojanovic) #65535 [ 09feba74c8 ] - deps : update undici to 8.10.2 (Node.js GitHub Bot) #65788 [ e47c432dd6 ] - deps : upgrade npm to 11.19.1 (npm team) #65573 [ 2fd6ce36a9 ] - deps : update corepack to 0.36.0 (Node.js GitHub Bot) #65653 [ 49dec2767a ] - deps : update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d (Node.js GitHub Bot) #65654 [ 676174a071 ] - deps : update simdjson to 4.6.9 (Node.js GitHub Bot) #65655 [ 2f1b7fa0bb ] - deps : update perfetto to 58.2 (Node.js GitHub Bot) #65656 [ 12acd0ad15 ] - deps : update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) #65494 [ 48631c80fb ] - deps : update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542 [ 7efdbe3eb9 ] - deps : upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542 [ bdc75900ee ] - doc : replace node:modules documentation header (René) #65800 [ 44c8a499ba ] - doc : clarify return type of fs.mkdtemp* (Antoine du Hamel) #65743 [ 025fb5eeb0 ] - doc : update changelog-maker instructions for releasing (Juan José) #65707 [ 5f64847afa ] - doc : add stability status to crypto.setEngine (Antoine du Hamel) #65746 [ 299dee0cb9 ] - doc : remove outdated TLS authorized warning (Tim Perry) #65597 [ e97dcc0278 ] - doc : fix broken using link in ffi.md (Soul Lee) #65632 [ 2c9cc7d237 ] - doc : fix some broken links (Antoine du Hamel) #65583 [ 0c330ec329 ] - doc : fix stale TOC in maintaining-dependencies (greenhead) #65523 [ 9c522a3a69 ] - doc : refactor the AI guidelines (Joyee Cheung) #65269 [ 46cbf1bf8c ] - doc : fix triggerAsyncId() comment in async_hooks example (soreavis) #64583 [ 788904ff78 ] - doc : fix fsPromises.watch overflow value (Matt Radbourne) #64605 [ 3d06ff19e8 ] - doc : clarify stream direction in options.stdio note (Avocado) #65236 [ d334838379 ] - doc : clarify signal listener behavior (Som Samantray) #65243 [ d55a2bd56a ] - doc : add test reporter event lifecycle diagram (sangwook) #63780 [ c17dfc87de ] - doc : discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) #64342 [ 616bd3fa26 ] - doc : deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593 [ 4e6d7e0ca6 ] - meta : cleanup targos emeritus changes (Antoine du Hamel) #65738 [ a70cfe1747 ] - meta : bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot[bot]) #65714 [ e43a0ad4ce ] - meta : bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot[bot]) #65717 [ 99e06288f1 ] - meta : bump actions/checkout from 7.0.0 to 7.0.1 (dependabot[bot]) #65718 [ 89662762b3 ] - meta : bump cachix/install-nix-action from 31.11.0 to 31.11.1 (dependabot[bot]) #65719 [ 6b8f078672 ] - meta : bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot[bot]) #65720 [ 6c6fb18e63 ] - meta : bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot[bot]) #65721 [ 0e002e859f ] - meta : bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot[bot]) #65722 [ 98aaffe4b9 ] - meta : bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot[bot]) #65723 [ d247cb2975 ] - meta : document collaborator automation (Filip Skokan) #65671 [ ae1801eb55 ] - meta : refine the security vuln posture for experimental features (James M Snell) #65438 [ fab81d15c3 ] - test : widen the gap in the resolver maxTimeout comparison

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-2.0.6

v2.0.6

SECURITY: dependency: Upgrade to the latests go-getter [ GH-28510 ] IMPROVEMENTS: api: Updated the Go module to require at least 1.26.0 [ GH-28460 ] build: Updated Go to v1.27.1 [ GH-28451 ] client: Added the unique.host_id node attribute to the host fingerprint, when available [ GH-28406 ] job: Allow setting reschedule.delay to values as low as 1s [ GH-28477 ] jobspec2: Decouple from Nomad core with isolated Go module named github.com/hashicorp/nomad/jobspec2 [ GH-28419 ] scheduler: Improved robustness of reschedule logic for invalid states [ GH-28445 ] ui: prevent stuck requests due to exceeding connection limit, enable HTTP2 [ GH-28364 ] BUG FIXES: api: Fixed a bug where a job plan diff sorted indexed fields such as args lexically, listing args[10] before args[2] [ GH-4421 ] client: prevent Alloc FS API from accessing secret dir when symlinked into task [ GH-28468 ] core: Fixed a bug where an artifact checksum of the form file:<url> (fetching the checksum from a remote file) was rejected during job validation [ GH-9764 ] jobspec: Fixed a bug where a task group containing only lifecycle tasks and no main task was accepted during job validation [ GH-17570 ] planner: Fixed a bug where valid evaluations could be unnecessarily retried, delaying workload placement under load [ GH-28452 ] scheduler: Fixed a bug where task groups with per_alloc volumes could skip real feasibility checks for allocs after the first placement failure in the same task group [ GH-28422 ] state: Fixed a bug where plans from older versioned followers did not have allocation resource schemas upgraded when written on the leader [ GH-28447 ] vault: Fixed a bug where a task's change_mode was triggered on each Vault token renewal [ GH-28409 ] vault: fixes an issue where dead tasks continued to have their tokens renewed [ GH-28501 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
METAREACT-19.3.0

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes. Read the React 19.3 release post for more information. New React Features <ViewTransition /> : Adds <ViewTransition /> and addTransitionType APIs to power View Transition animations in React ( @sebmarkbage , @jackpope , @gaearon : #31975 , #31987 , #31996 , #31999 , #32001 , #32002 , #32028 , #32029 , #32031 , #32034 , #32038 , #32041 , #32050 , #32090 , #32105 , #32254 , #32379 , #32422 , #32462 , #32540 , #32545 , #32585 , #32599 , #32611 , #32612 , #32617 , #32651 , #32653 , #32656 , #32664 , #32699 , #32723 , #32734 , #32751 , #32752 , #32760 , #32761 , #32764 , #32772 , #32790 , #32819 , #32820 , #32822 , #32833 , #32849 , #33094 , #33191 , #33200 , #33206 , #33293 , #33330 , #33331 , #33332 , #33357 , #33362 , #33433 , #33576 , #34374 , #34450 , #34481 , #34500 , #34502 , #34510 , #34511 , #34539 , #35567 , #35564 , #35485 , #35380 , #35063 , #35060 , #34676 , #36917 , #35337 , #35520 ) Fragment Refs: Add Refs to <Fragment /> to support composable platform behavior ( @jackpope , @sebmarkbage , @eps1lon , @Dhakshin2007 , @chirokas , @teamleaderleo , @fallintoplace : #32465 , #32613 , #32619 , #32654 , #32660 , #32682 , #32722 , #32813 , #32814 , #33056 , #33058 , #33093 , #34069 , #34103 , #34544 , #34545 , #37062 , #37061 , #37060 , #36047 , #36010 , #35642 , #35641 , #35637 , #35630 , #34935 , #37457 , #37408 , #37326 , #37251 , #37171 , #37169 , #37168 , #37167 , #37166 , #37165 , #37164 , #37163 , #37162 , #37161 , #37160 , #37125 , #37063 ) New React DOM Features browser() : a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error ( @gnoff : #37143 , #37241 ) Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser ( @gnoff #37193 ) Notable changes Enable Trusted Types API integration ( @rickhanlonii #35816 ) Transitions now render independently instead of being entangled into a single render, so a slow transition no longer holds up unrelated ones ( @acdlite #37290 ) Added a DEV-only warning when a component appears to have been unblocked by calling use() conditionally ( @hoxyq , @eps1lon : #37104 , #37203 , #37491 ) All Changes React Fast Refresh Fixes Fix Fast Refresh to find and remount edits to components wrapped behind lazy() ( @sophiebits #36965 ) Fix Fast Refresh so edits to a memo() comparison function take effect ( @sophiebits #36964 ) Fix Fast Refresh crash when an edit changes the kind of a component's type ( @sophiebits #36963 ) Unify hot reload type resolution for Fast Refresh ( @sophiebits #36962 ) Fix Fast Refresh to remount correctly when an edit changes the component kind ( @sophiebits #36950 ) Double invoke effects in StrictMode after Fast Refresh ( @eps1lon #35962 ) Performance Track Fixes Prevent crash when accessing $$typeof in Performance Tracks ( @eps1lon #35679 ) Handle non-string function names in Performance Tracks ( @eps1lon #35659 ) Use minus ( - ) instead of en dash for removed props in Performance Tracks ( @eps1lon #35649 ) Handle arrays with bigints in deep objects in Performance Tracks ( @eps1lon #35648 ) Don't enumerate typed array props in Performance Tracks in DEV ( @UditDewan #36913 ) Bail out of diffing wide objects and arrays in Performance Tracks ( @eps1lon #34742 ) Clear potentially large performance measures in DEV ( @hoxyq #34803 ) Fix missing else branch for renders with no props change in Performance Tracks ( @hoxyq #34837 ) Activity Fixes Fix useSyncExternalStore missing store mutations that happened while an Activity tree was hidden ( @sophiebits #36947 ) Hide portal contents when an Activity is hidden ( @acdlite #35091 ) Prevent metadata hoisting in hidden <Activity> trees ( @ronnakamoto #34983 ) Prevent errors thrown inside a hidden Activity from escaping to the visible UI ( @acdlite #35074 ) Don't

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.16.2

v1.16.2

1.16.2 (September 9, 2026) BUG FIXES: Fix panic in module installation when encoutering invalid module calls ( #39129 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.17.0-BETA1

v1.17.0-beta1

1.17.0-beta1 (September 09, 2026) NEW FEATURES: Terraform now supports variables and locals in provider requirements ( #39153 ) A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. ( #35290 ) policy: Terraform Policy is now generally available. The -policies flag for plan , apply , and init no longer requires the -allow-experimental-features flag. See https://developer.hashicorp.com/terraform/policy for more information. ( #38970 ) ENHANCEMENTS: command/init: Enrich log messages with provider versions ( #38918 ) test: Add mock_provider support for ephemeral resources ( #38928 ) command/login: display warning after successful login if user is subject to an organization's TTL policy BUG FIXES: funcs: pow and log no longer panic when result is not a number ( #38912 ) ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. ( #38989 ) test: Deterministic dependency ordering in cleanup graph ( #38247 ) query: report Unknown and N/A results for policy evaluations of discovered resources ( #39058 ) NOTES: version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. ( #38930 ) Previous Releases For information on prior major and minor releases, refer to their changelogs: v1.16 v1.15 v1.14 v1.13 v1.12 v1.11 v1.10 v1.9 v1.8 v1.7 v1.6 v1.5 v1.4 v1.3 v1.2 v1.1 v1.0 v0.15 v0.14 v0.13 v0.12 v0.11 and earlier

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTDOTNET-10.0.12

.NET 10.0.12

Release Notes Install Instructions Repos Aspnetcore dotnet dotnet EF Core Runtime SDK SDK Templating Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-september-2026-servicing-updates/#release-changelogs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTDOTNET-8.0.31

.NET 8.0.31

Release Notes Install Instructions Repos Aspnetcore EF Core Installer Installer Runtime SDK SDK Templating Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-september-2026-servicing-updates/#release-changelogs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTDOTNET-9.0.20

.NET 9.0.20

Release Notes Install Instructions Repos Aspnetcore EF Core Runtime SDK SDK Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-september-2026-servicing-updates/#release-changelogs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-0580D81750C935AD

Uncontrolled Resource Consumption in SNMP

CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-078ABE241B1E82BF

Open Redirect on FortiSIEM

CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-1D83DC268892C0B4

Cron Job Injection in Remote Backup

CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-1EFF8F97C4C51441

Broken Access control on Websocket streams

CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-858738FBE1ECCD2E

ZTNA Portal Improper Certificate Validation

CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-9315ABD10B69B903

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-D3A3359BA2653C5B

Null Pointer Dereference in Log Report

CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-EDABAEB7EB11C331

Workflow session email approval process bypass

CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.581

2.581

This is an automatically generated changelog draft for Jenkins weekly releases. See https://www.jenkins.io/changelog/2.581/ for the official changelog for this release. 🐛 Bug fixes Restore iconOnly summary link behavior ( #27353 ) @oleksii-tumanov Use locale-independent matching in build history search ( #27350 ) @cuishuang JENKINS-71211 - Fix experimental flags value column clipping ( #27047 ) @AbdelHamdyGhanem , @MarkEWaite All contributors: @AbdelHamdyGhanem , @cuishuang , @oleksii-tumanov and @MarkEWaite

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VEEAMKB4914

Build Numbers and Versions of Veeam Plug-In for KubeVirt

Build Numbers and Versions of Veeam Plug-In for KubeVirt KB ID: 4914 Product: Veeam Backup & Replication Published: 2026-09-08 Last Modified: 2026-09-09 This KB article lists all versions of the Veeam Plug-In for KubeVirt and their respective worker build numbers. Version Plug-In / Worker Build Release Date Veeam Plug-In for KubeVirt 1 Releases Veeam Plug-In for KubeVirt 1.0 Independent Plug-In Release 13.1.0.428 2026-09-08 Swipe to show more of the table Independent Plug-In releases are available in the My Account portal: My Account > My Products > Additional downloads > Virtualization Plug-ins The additional downloads section is at the very bottom of the My Products page. Note: Veeam Plug-In for KubeVirt may also be listed as Veeam Plug-In for Red Hat OpenShift Virtualization . Related Articles Build Numbers and Versions of Veeam Backup & Replication ├ Build Numbers and Versions of Veeam Plug-In for Nutanix AHV ├ Build Numbers and Versions of Veeam Plug-In for Proxmox VE ├ Build Numbers and Versions of Veeam Plug-In for oVirt KVM ├ Build Numbers and Versions of Veeam Plug-In for Scale Computing HyperCore ├ Build Numbers and Versions of Veeam Plug-In for HPE Morpheus VM Essentials ├ Build Numbers and Versions of Veeam Plug-In for Platform9 ├ Build Numbers and Versions of Veeam Plug-In for Sangfor aSV ├ Build Numbers and Versions of Veeam Plug-In for Verge OS ├ Build Numbers and Versions of Veeam Plug-In for Xen ├ Build Numbers and Versions of Veeam Plug-In for KubeVirt ├ Build Numbers and Versions of Veeam Plug-In for AWS ├ Build Numbers and Versions of Veeam Plug-In for Microsoft Azure └ Build Numbers and Versions of Veeam Plug-In for Google Cloud Build Numbers and Versions of Veeam ONE Build Numbers and Versions of Veeam Recovery Orchestrator Build Numbers and Versions of Veeam Service Provider Console Build Numbers and Versions of Veeam Agent for Microsoft Windows Build Numbers and Versions of Veeam Agent for Linux Build Numbers and Versions of Veeam Agent for Mac Build Numbers and Versions of Veeam Agent for IBM AIX Build Numbers and Versions of Veeam Agent for Oracle Solaris Build Numbers and Versions of Veeam Backup for Microsoft 365 Build Numbers and Versions of Veeam Backup for Salesforce Veeam Data Cloud for Microsoft 365 Release Information and Build Numbers Veeam Data Cloud for Microsoft Azure Release Information and Build Numbers If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
VEEAMKB4916

How to Disable the Automatic Installation of Security Updates When Adding a Veeam Infrastructure Appliance to Veeam Backup & Replication

How to Disable the Automatic Installation of Security Updates When Adding a Veeam Infrastructure Appliance to Veeam Backup & Replication KB ID: 4916 Product: Veeam Backup & Replication | 13.1 Published: 2026-09-08 Last Modified: 2026-09-08 Purpose By default, when a new Veeam Infrastructure Appliance is added to the Veeam Backup & Replication infrastructure, all available security updates are installed on that appliance automatically by the Veeam Updater running on it. The installation of updates can take a significant amount of time, during which the wizard used to add the appliance is blocked, and the appliance is rebooted automatically at the end of the process if a reboot is required. In environments where the appliance has no access to the Veeam software repositories, the update check cannot succeed, and the wizard is delayed until the check has exhausted its retries, which takes approximately three minutes by default. This article describes how to disable the automatic update check and installation for Veeam Infrastructure Appliance hosts that are being added to the Veeam Backup & Replication infrastructure. The setting described in this article is available in Veeam Backup & Replication 13.1.0.411 and later. Solution Security Impact of Disabling the Update Check When the automatic update check is disabled, security updates are not installed on Veeam Infrastructure Appliance hosts while they are being added to the infrastructure. Updates must then be installed on each appliance separately, either through the Veeam Updater on that appliance or through a centralized update mirror. Review How Updates Work in the User Guide before this setting is applied. Windows-based Veeam Backup & Replication On the Veeam Backup Server, the following registry value must be created. A restart of the Veeam Backup & Replication services is not required after the value is created. Key: HKEY_LOCAL_MACHINE\SOFTWARE\Veeam\Veeam Backup and Replication Value Name: SkipInfrastructureApplianceUpdateCheck Value Type: DWORD (32-Bit) Value Value Data: 1 PowerShell Registry Value Creation New-ItemProperty - Path 'HKLM:\SOFTWARE\Veeam\Veeam Backup and Replication\' - Name 'SkipInfrastructureApplianceUpdateCheck' - Value "1" - PropertyType DWORD - Force Copy Veeam Software Appliance On Veeam Backup & Replication deployed as a Veeam Software Appliance, the equivalent setting is stored in the /etc/veeam/veeam_backup_and_replication.conf configuration file. That file must be exported from the Veeam Host Management Console, modified, and then imported again, as described in KB4779: Applying Custom Settings to Veeam Software Appliance . Add the following line to the [root] section of the configuration file. A restart of the Veeam Backup & Replication services is not required after the line is added. SkipInfrastructureApplianceUpdateCheck=1 Copy More Information Veeam Backup & Replication User Guide > Backup Infrastructure Components > Virtualization Servers and Hosts > Adding Veeam Infrastructure Appliances Veeam Backup & Replication User Guide > Deployment > Upgrade and Update > Updating Veeam Appliances > How Updates Work KB4779: Applying Custom Settings to Veeam Software Appliance If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Published 8 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-24.21.0

2026-09-08, Version 24.21.0 'Krypton' (LTS), @aduh95

Notable Changes [ 71106e1f17 ] - crypto : update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495 [ afca0a912d ] - (SEMVER-MINOR) crypto : support loading private keys through STORE loaders (Filip Skokan) #63949 [ 6274fccbd9 ] - deps : update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542 [ 53cba013c7 ] - deps : update Undici to 7.29.1 (Node.js GitHub Bot) #65789 [ 0529772798 ] - (SEMVER-MINOR) lib,src : improve histogram implementation (James M Snell) #65024 [ 41c7062b81 ] - (SEMVER-MINOR) net : improve performance of net.BlockList (James M Snell) #64974 [ 5197b5a3c5 ] - (SEMVER-MINOR) perf_hooks : add statistical hypothesis testing to histogram (James M Snell) #65416 [ 35c635b032 ] - (SEMVER-MINOR) util : add non-throwing MIMEType.parse (James M Snell) #64965 Commits [ 84d706cb9b ] - assert : improve documentation wording (Kamal Rawal) #64953 [ 90d127db33 ] - (SEMVER-MINOR) benchmark : add --analyze mode to compare.js (James M Snell) #65416 [ ad1d7884c3 ] - benchmark : add test-only and mock timers cases (Luan Muniz) #64097 [ 1d8f045914 ] - benchmark : apply highWaterMark in webstreams pipe-to (Matteo Collina) #65138 [ ed7ba3c993 ] - benchmark : complete the sqlite is-transaction fix (Edy Silva) #65218 [ c8837e1aa3 ] - benchmark : add test runner hooks and options (Luan Muniz) #63754 [ 2ba8661e23 ] - buffer : prevent string write offset overflow (Matteo Collina) #65043 [ cc9ee6c2ae ] - buffer : treat detached ArrayBuffers as empty (Archkon) #64504 [ 5a5d73e4c5 ] - build : pass target architecture to small-icu genccode (ulofiai) #65095 [ 273e72d1a5 ] - build : deprecate always enabled --enable-static (Chengzhong Wu) #65103 [ 89a67246e3 ] - build : check FIPS option value in node.gyp (Filip Skokan) #64982 [ 2d21f41cd5 ] - build : handle malformed OpenSSL macros (Filip Skokan) #64982 [ f62bc0f862 ] - build,win : add PGO workload scripts (Stefan Stojanovic) #63696 [ 33d0c7dc12 ] - child_process : keep SIGWINCH from killing on Win (Kirill Saied) #64510 [ 71106e1f17 ] - crypto : update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495 [ 419af8b86d ] - crypto : fix missing error checks on ASN1_STRING_to_UTF8() (Nora Dossche) #65200 [ 8029383f3f ] - crypto : use available BoringSSL APIs (Filip Skokan) #65423 [ a9bd780e19 ] - crypto : remove obsolete BoringSSL shims (Filip Skokan) #65423 [ 7defefad3f ] - crypto : read WebCrypto inputs through primordials (Filip Skokan) #65115 [ 6ed1e38627 ] - crypto : fix disabling FIPS mode (Filip Skokan) #64982 [ afca0a912d ] - (SEMVER-MINOR) crypto : support loading private keys through STORE loaders (Filip Skokan) #63949 [ 9b9dd6e9cf ] - debugger : wait for target startup (Filip Skokan) #65194 [ 07faaeeffd ] - deps : update corepack to 0.36.0 (Node.js GitHub Bot) #65653 [ 53cba013c7 ] - deps : update undici to 7.29.1 (Node.js GitHub Bot) #65789 [ 0268ca547c ] - deps : update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542 [ 6274fccbd9 ] - deps : upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542 [ 6bdcd121fa ] - deps : update zlib to 1.3.2.1-motley-8002e91 (Node.js GitHub Bot) #65316 [ c2aa446b6d ] - deps : update simdjson to 4.6.7 (Node.js GitHub Bot) #65318 [ 3e58e48ea8 ] - deps : update googletest to 49495eacfdbda3f4b6ba219923fedbb2e3f99376 (Node.js GitHub Bot) #65317 [ 670b3665c0 ] - deps : cherry-pick libuv/libuv@ e640dc9 (ulofiai) #65118 [ ca1c67b021 ] - deps : float ICU-23262 patch for icu78 (René) #64678 [ 4ad043b0aa ] - deps : enable AVX-512 OpenSSL asm with clang (Daniel Lemire) #65136 [ 96b4af109b ] - deps : update googletest to d89aac5f0dd4021198d903d39de16f896726de21 (Node.js GitHub Bot) #65153 [ 774f663c56 ] - dgram : don't swallow bind errors when callback is provided (armanmikoyan) #62602 [ 94b118d62e ] - diagnostics_channel : validate before channel activation (Trivikram Kamat) #65313 [ 09788665bd ] - dns : validate address type in lookupService (Lazizbek Ergashev) #64878 [ 15f95fc0e2 ] - dns : validate port range in setServers() (René

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSPROMETHEUS-3.13.3

3.13.3 / 2026-09-07

[SECURITY] Bump github.com/klauspost/compress to v1.18.7 (GO-2026-5841) and golang.org/x/crypto to v0.55.0 (GO-2026-6303). [BUGFIX] Docker SD: Fix panic in Docker Swarm service discovery when a service runs as a plugin or network-attachment. #19102 [BUGFIX] PromQL: Fix case-insensitive regex label matchers silently dropping matching values. #19167 [BUGFIX] Scrape: Fix scrape manager spinning at 100% CPU on shutdown. #19149 [BUGFIX] Alerting: Fix 100% CPU usage on shutdown that could delay graceful shutdown and trigger timeout-based kills. #17859 [BUGFIX] TSDB: Fix out-of-order queries blocking compaction for hours, causing memory usage to grow. #19013 [BUGFIX] TSDB: Fix deleted series causing missing samples and errors after restart. #19140 [BUGFIX] TSDB: Fix goroutine and file handle leaks when Prometheus fails to open a corrupt TSDB. On Windows, the leaked directory handle also prevented TSDB directory removal. #18291

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-2.11.57

v2.11.57

Important: Please read the migration guide . CVE fixed: Advisory GHSA-qqjf-53cj-pwvv Advisory GHSA-f52w-8j3h-j724 Advisory GHSA-w4v4-9rw7-5326 Bug fixes: [acme] Disable recursive nss propagation by default for DNS challenge ( #13830 @rtribotte ) [http3] Dedicate a transport per HTTP/3 client connection ( #13812 @sdelicata ) [server] Deny request with an opaque request target ( #13796 @sdelicata ) [server] Do not forward h2c upgrade headers to the backend ( #13797 @sdelicata )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OVENBUN-1.4.2

Bun v1.4.2

To install Bun v1.4.2 curl -fsSL https://bun.sh/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.sh/install.ps1|iex " To upgrade to Bun v1.4.2: bun upgrade Read Bun v1.4.2's release notes on Bun's blog Thanks to 3 contributors! @dylan-conway @jarred-sumner @robobun

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPEN HOME FOUNDATIONHOME-ASSISTANT-2026.9.1

2026.9.1

Fix SMTP attaching valid images as files when content sniffing fails ( @Chang-Jin-Lee - #176774 ) ([smtp docs]) Warn that removing an app deletes its data in repair flows ( @agners - #181009 ) ([hassio docs]) Fix receive backup streaming ( @MartinHjelmare - #181012 ) ([backup docs]) Fix potential deadlock in receive_file backup util ( @emontnemery - #181070 ) ([backup docs]) Add missing state_class for miele filling level sensors ( @astrandb - #181093 ) ([miele docs]) Update python-roborock to 7.2.3 ( @Lash-L - #181096 ) ([roborock docs]) Bump vizaio to 0.6.1 for vizio state_extended 404 fallback fix ( @raman325 - #181131 ) ([vizio docs]) (dependency) Stop rounding Amber Electric prices to 2 decimal places ( @romeovan - #181157 ) ([amberelectric docs]) Fix host override ignored in UniFi Protect public-only mode ( @RaHehl - #181176 ) ([unifiprotect docs]) Purge unreachable deleted devices on device registry load ( @emontnemery - #181207 ) Bump pydaikin to 2.19.1 (hotfix) ( @GhislainC - #181219 ) ([daikin docs]) (dependency) Fix Besen config flow schema serialization ( @moryoav - #181223 ) ([besen docs]) Speed up lookup of colliding orphans in device registry ( @arturpragacz - #181244 ) Revert orjson to 3.11.9 ( @emontnemery - #181245 ) (dependency) Bump aioflo to 2026.9.3 and scope Flo consumption by device ( @BradKollmyer - #181246 ) ([flo docs]) Bump serialx to 1.10.0 ( @puddly - #181249 ) ([serial docs]) ([usb docs]) Bump env-canada to 0.19.2 ( @michaeldavie - #181250 ) ([environment_canada docs]) (dependency) Bump python-hotspring to 2.1.0 (hotfix) ( @Moustachauve - #181256 ) ([hotspring docs]) (dependency) Bump samsung-exlink to 1.1.1 ( @balloob - #181260 ) ([samsung_exlink docs]) (dependency) Reject Hot Spring Spa Network Adapter (SNA) in config flow (hotfix) ( @Moustachauve - #181261 ) ([hotspring docs]) Update knx-frontend to 2026.9.4.63549 ( @farmio - #181268 ) ([knx docs]) (dependency) Allow empty motionEye usernames ( @frenck - #181270 ) ([motioneye docs]) Handle Tradfri devices without a firmware version ( @frenck - #181276 ) ([tradfri docs]) Update frontend to 20260826.6 ( @bramkragten - #181293 ) ([frontend docs]) (dependency) Bump reolink_aio to 0.21.15 ( @starkillerOG - #181300 ) ([reolink docs]) (dependency) Bump pylitterbot to 2025.6.5 ( @natekspencer - #181346 ) ([litterrobot docs]) (dependency) Bump uiprotect to 16.6.1 ( @RaHehl - #180670 ) ([unifiprotect docs]) (dependency)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OVENBUN-1.4.1

Bun v1.4.1

To install Bun v1.4.1 curl -fsSL https://bun.sh/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.sh/install.ps1|iex " To upgrade to Bun v1.4.1: bun upgrade Read Bun v1.4.1's release notes on Bun's blog Thanks to 7 contributors! @alii @dylan-conway @jarred-sumner @jvitormelo @marshallofsound @robobun @sosukesuzuki

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VEEAMKB4910

Applications Restored by Veeam Kasten Disaster Recovery Fail to Export with: invalid repository password

Applications Restored by Veeam Kasten Disaster Recovery Fail to Export with: invalid repository password KB ID: 4910 Product: Veeam Kasten for Kubernetes Published: 2026-09-04 Last Modified: 2026-09-04 Challenge After a Veeam Kasten Disaster Recovery (KDR) restore is performed on an instance of Veeam Kasten for Kubernetes running a version earlier than 8.5.4, and that instance is later upgraded to version 8.5.4 or newer, export and backup actions for the restored applications fail with an error similar to the following: invalid repository password The restore points imported by the KDR restore are present in the catalog, but any policy or export action that references them afterward fails. Cause This issue occurs because Veeam Kasten for Kubernetes versions earlier than 8.5.4 import application restore points into the local catalog without correctly linking the encryption key artifact (EKA) to the corresponding repository artifact. The catalog entry appears complete, but the repository password derived from it does not match, so any later operation that requires decrypting or reconnecting to that repository fails. The binding behavior was corrected in version 8.5.4. That correction applies to restore points imported after the upgrade, so restore points that were already imported under the earlier binding remain broken in the catalog. Solution Starting in Veeam Kasten for Kubernetes 9.0.5, the KastenDRRestore resource supports the forceReimportAppRestorePoints option. When this option is set to true , every application restore point being imported is reprocessed and its repository artifact is rebound to a valid encryption key, including restore points that were already imported successfully by an earlier KDR restore. The repair is applied by running a new KDR restore with this option enabled. The option is a field on the KastenDRRestore resource, so the repair restore is performed using the CLI or API method, regardless of how the original KDR restore was performed. Confirm that the Veeam Kasten for Kubernetes instance is running version 9.0.5 or later. Edit or create the KastenDRRestore resource for the affected restore, and set forceReimportAppRestorePoints to true : apiVersion: dr.kio.kasten.io/v1alpha1 kind: KastenDRRestore metadata: name: sample-kdrrestore namespace: kasten-io spec: sourceClusterInfo: profileName: my-profile sourceClusterID: <cluster-id> forceReimportAppRestorePoints: true Copy Alternatively, reference a restore point from an existing KastenDRReview resource: apiVersion: dr.kio.kasten.io/v1alpha1 kind: KastenDRRestore metadata: name: sample-kdrrestore namespace: kasten-io spec: kastenDRReviewDetails: kastenDRReviewRef: name: <KastenDRReview Name> namespace: kasten-io id: <KDR Restore Point ID from KastenDRReview RestorePointList> forceReimportAppRestorePoints: true Copy Run the KDR restore as described in Recovering Veeam Kasten from a Disaster via CLI . Once the restore has completed, verify that the export or backup action that previously failed for the affected application now succeeds. More Information Note: Do not enable forceReimportAppRestorePoints for a KDR restore performed on a clean installation, or for the first KDR restore performed on a cluster. In those cases no existing bindings are present to repair, so the option is unnecessary. Veeam Kasten Documentation > Operating Veeam Kasten > Veeam Kasten Disaster Recovery Veeam Kasten Documentation > API > KastenDR Resources If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Published 4 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.7

v3.6.0-rc.7

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-9.5.3

Beats 9.5.3

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-9.5.3-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARE-E2940D92C1E0AC65

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.

Published 3 Sep 2026 · Source checked 28 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.5.1

v5.5.1

What's Changed ✨ Improvements Feat(hooks): capture and surface lifecycle hook output by @glours in #14091 Feat(tracing): surface otel shutdown errors via --debug by @htoyoda18 in #14152 🐛 Fixes Fix(events): validate service names before subscribing to events by @glours in #14076 Fix: bake target names collision for services differing by . vs _ by @ndeloof in #14058 Fix(watch): sync into a symlinked directory instead of failing by @Endika in #14084 Fix(hooks): include hook output in the error when a hook fails by @dennislapchenko in #14088 Fix(build): TTY progress on Windows — hand the real stdout to buildkit by @ndeloof in #14090 Fix(watch): sync all files on initial_sync , regardless of mtime by @glours in #14096 Fix(network): pass IPAM options when creating networks by @glours in #14094 Fix(ps): honor psFormat from Docker CLI config when no --format flag given by @glours in #14095 Fix: dependency wait timeout surfaced only by luck by @ndeloof in #14105 Fix: hold startMx on the start path actually exercised by @ndeloof in #14106 Fix(watch): exclude Dockerfile and compose files from initial sync by @htoyoda18 in #14117 Fix(display): stop ttyWriter.Done from hanging after context cancel by @glours in #14119 Fix(build): honor provenance/sbom false in per-service bake attest by @glours in #14112 Fix(compose): reject unknown subcommands under bridge/transformations by @glours in #14143 Fix(plugins): honor PATHEXT for provider lookup on Windows by @ndeloof in #14159 Fix(watch): stop swallowing SetRecursive errors via nolint by @glours in #14165 Fix(bridge): confirm before wiping non-empty convert output dir by @glours in #14174 Fix(down): spare dangling images of orphaned services, like their tagged image by @htoyoda18 in #14154 🔧 Internal CI: raise e2e go-test timeout to 20m by @ndeloof in #14072 Lint: replace gocyclo with gocognit by @ndeloof in #14057 Test(e2e): prepend provider bin dir to PATH in provider tests by @glours in #14079 Refactor: dismantle the gocognit hotspots, one concern per function by @ndeloof in #14060 Test(e2e): declarative Scenario layer, project files under testdata// by @ndeloof in #14087 Docs: document engine container event sequences in up monitor by @ndeloof in #14024 E2E: fix test resource isolation and make standalone parallelism configurable by @glours in #14073 API: ScaleOptions carries the replica counts by @ndeloof in #14077 Chore: explicit, unique, greppable internal names by @ndeloof in #14049 Docs: update CONTRIBUTING.md to reflect current tooling and practices by @glours in #14098 API: option structs document what the implementation actually honors by @ndeloof in #14078 Test: unit-lock the imperative start path by @ndeloof in #14104 CLI: display.Mode always resolves to the mode actually rendered by @ndeloof in #14103 CI: validate generated mocks are in sync by @ndeloof in #14102 Docs(sdk): document the EventProcessor API that actually exists by @ndeloof in #14131 Test(e2e): gate the e2e suite behind the build tag the docs already promise by @ndeloof in #14132 Build: error messages name the real remedy, not a removed builder by @ndeloof in #14133 Docs(contributing): legibility guidelines — comments state behavior, not history by @ndeloof in #14135 Test(docs): compile the sdk.md examples by @ndeloof in #14136 Chore(compose): rename convergence.go, whose convergence engine no longer exists by @ndeloof in #14129 Chore(compose): comments state behavior, not history by @ndeloof in #14130 Test(build): re-enable wrong ssh key id test by @htoyoda18 in #14120 Chore(compose): orphan semantics stated where up and down diverge by @ndeloof in #14142 Refactor: NewGraph stops mutating the project by @ndeloof in #14124 Test(e2e): bump compose-bridge images to v0.0.7 by @ricardobranco777 in #14170 ⚙️ Dependencies Build(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 by @dependabot [bot] in #14101 Remove buildx as a Go dependency by @ndeloof in #14123 Chore(deps): github.com/sirupsen/logrus v

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-9.5.3

Elasticsearch 9.5.3

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.5.3-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICLOGSTASH-9.5.3

Logstash 9.5.3

Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.5.3-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →