Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT

VERIFIED PUBLISHER INTELLIGENCE

Release notes and known issues

Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.

85 official publisher sources registered · 83 collected automatically · 0 monitored for availability · 2 requires publisher access

1878 verified publisher records · Page 15 of 19

GRAFANA LABSGRAFANA-12.4.10

12.4.10

Download page What's new highlights Security Security: Fix CVE-2026-14199 Security: Fix CVE-2026-19475 Bug fixes Dashboards: Fix adhoc and groupby variable datasource on UI import #131821 , @ivanortegaalba Dashboards: Fix version dates and user display names in the legacy version history page #131808 , @ivanortegaalba

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-13.0.8

13.0.8

Download page What's new highlights Security Security: Fix CVE-2026-12704 Security: Fix CVE-2026-14199 Security: Fix CVE-2026-19475 Bug fixes Dashboards: Fix version dates and user display names in the legacy version history page #131809 , @ivanortegaalba

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-13.1.5

13.1.5

Download page What's new highlights Security Security: Fix CVE-2026-12704 Security: Fix CVE-2026-14199 Security: Fix CVE-2026-19475

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-13.2.1

13.2.1

Download page What's new highlights Security Security: Fix CVE-2026-12704 Security: Fix CVE-2026-14199 Bug fixes Dashboards: Fix adhoc and groupby variable datasource on UI import #131819 , @grafana-writer[bot] Packaging: Fix issue with bundled plugins not being moved properly #131037 , @grafana-writer[bot] PanelEditor: Fix options pane not resizable beyond the preview's content width #131608 , @grafana-writer[bot]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.580

2.580

This is an automatically generated changelog draft for Jenkins weekly releases. See https://www.jenkins.io/changelog/2.580/ for the official changelog for this release. 🔒 Security Multiple security fixes. See the 2026-09-02 security advisory for details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
LINUX KERNEL ORGANIZATIONLINUX-6AB18A679ACD66AF

7.1.13: stable

Version: 7.1.13 (EOL) (stable) Released: 2026-09-02 Source: linux-7.1.13.tar.xz PGP Signature: linux-7.1.13.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-7.1.13

Published 2 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
LINUX KERNEL ORGANIZATIONLINUX-7.1.13

7.1.13: stable

Version: 7.1.13 (EOL) (stable) Released: 2026-09-02 Source: linux-7.1.13.tar.xz PGP Signature: linux-7.1.13.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-7.1.13

Published 2 Sep 2026 · Source checked 26 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.16.1

v1.16.1

1.16.1 (September 2, 2026) BUG FIXES: cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations ( #38751 ) Support referencing modules containing dynamic sources in Terraform Test ( #38950 ) stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. ( #38829 ) Fix panic when import identity references sensitive value ( #39013 ) import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count . ( #39068 ) state show: Fix a panic when given an attribute path instead of a resource instance address ( #39087 ) Fix create_before_destroy ordering in some combinations of changes ( #39091 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-8.19.21

Beats 8.19.21

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-8.19.21-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-9.4.6

Beats 9.4.6

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-9.4.6-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-8.19.21

Elasticsearch 8.19.21

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/guide/en/elasticsearch/reference/8.19/release-notes-8.19.21.html

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-9.4.6

Elasticsearch 9.4.6

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.4.6-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-26.8

[release-branch.go1.26] go1.26.8

Change-Id: Id4a4603dc387badef0164e9463093ccd636b67ac Reviewed-on: https://go-review.googlesource.com/c/go/+/825885 Reviewed-by: David Chase drchase@google.com TryBot-Bypass: Gopher Robot gobot@golang.org Auto-Submit: Gopher Robot gobot@golang.org Reviewed-by: Michael Pratt mpratt@google.com

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-27.1

[release-branch.go1.27] go1.27.1

Change-Id: I14348d1dc655281274a8731f077ae62725175397 Reviewed-on: https://go-review.googlesource.com/c/go/+/825985 Reviewed-by: David Chase drchase@google.com Reviewed-by: Michael Pratt mpratt@google.com TryBot-Bypass: Gopher Robot gobot@golang.org Auto-Submit: Gopher Robot gobot@golang.org

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICLOGSTASH-9.4.6

Logstash 9.4.6

Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.4.6-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTMICROSOFT-AZURE-BEB0692A4134CAF1

[Launched] Generally Available: Microsoft Defender for Cloud support for Azure Container Apps (Serverless Containers Posture)

Customers can now bring Azure Container Apps environments into Microsoft Defender for Cloud’s Serverless Containers Posture experience, helping security teams extend posture management across more of their container estate from a single workflow. This mak

Published 1 Sep 2026 · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPVAULT-2.1.0

v2.1.0

2.1.0 September 01, 2026 SECURITY: core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107. core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052. CHANGES: License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model. core: Bump Go version to 1.26.7. oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id. oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim. oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the sys/activation-flags/oauth-resource-server/activate endpoint. oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor. secrets/openldap (enterprise): Update plugin to v0.18.4+ent FEATURES: Agent Registry UI (enterprise) : Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status. Automatic DNS-01 Challenge Fulfillment for PKI External CA : Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers. PKI PKCS#12 and JKS Support : Adds support for PKCS#12 (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files. SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise) : Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and Ed25519. secrets/pki-external-ca (enterprise): Add support for handling dns-01 challenges for Azure, AWS, GCP, and rfc2136 DNS. IMPROVEMENTS: agent-registry (enterprise): Removed the restriction that disallowed the use of 'deny' in ceiling policies, resulting in request errors. agent/pkiexternalca: Replace go.uber.org/atomic with sync/atomic (stdlib) for atomic boolean operations in the pkiexternalca package. auth/token: Add global denylist for revoking OAuth JWTs to prevent authorization of specific tokens across all namespaces. core/seal (enterprise): Update Oracle Cloud library to enable seal integration with newer regions. ui: Bump dompurify from 3.4.6 to 3.4.13 . ui: Bump shell-quote from 1.8.4 to 1.9.0. ui: Exposing the RSA Private Key field in the UI when generating credentials with the snowflake database secrets engine. Previously, this field was only shown in the cli. ui: Secrets engine delete confirmation modal now requires typing delete-engine to confirm, displays the engine name, secret count (KV engines only), and a list of what will be permanently deleted. ConfirmModal has now been updated to include a optional type-to-confirm. BUG FIXES: agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where ca_chain field was always empty in templates due to incorrect type handling of array responses api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire. core (enterprise): Fix a data race and potential panic during seal/unseal core (enterprise): Fix panic in collectOperatorImportMetrics when router.Route returns a nil response with no error during KVv2 metadata reads on performance secondary nodes. This condition occurs during the WAL-stream partial-sync phase of an initial join. core/login: Fix panic on malformed login r

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ANSIBLEANSIBLE-CORE-2.19.13

v2.19.13rc1

Changelog See the full changelog for the changes included in this release. Release Artifacts Built Distribution: ansible_core-2.19.13rc1-py3-none-any.whl - ‌2426823 bytes a88c1c365ace3f88a596d01c1f9f97ac2758e66d1501f3b9979cab041729a3eb (SHA256) Source Distribution: ansible_core-2.19.13rc1.tar.gz - ‌3436738 bytes 1ae0bb0b1a6ce72cc54f2844c4ec0828f420d874b66068e45962ab07f706e369 (SHA256)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ANSIBLEANSIBLE-CORE-2.20.9

v2.20.9rc1

Changelog See the full changelog for the changes included in this release. Release Artifacts Built Distribution: ansible_core-2.20.9rc1-py3-none-any.whl - ‌2430616 bytes 804a27ce3b78629fbe23830c8a7d2b1a31045bf44f03896d7d019cdb9f1e8b8d (SHA256) Source Distribution: ansible_core-2.20.9rc1.tar.gz - ‌3354356 bytes 670b1b81a0e40f9a6d48a6cd399cb828166c464643586d640cd5b3f4efef271e (SHA256)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ANSIBLEANSIBLE-CORE-2.21.4

v2.21.4rc1

Changelog See the full changelog for the changes included in this release. Release Artifacts Built Distribution: ansible_core-2.21.4rc1-py3-none-any.whl - ‌2457232 bytes 3a0ed41b15c62304553c4e49d0fbb805cc95677697aef523471529d848221b3f (SHA256) Source Distribution: ansible_core-2.21.4rc1.tar.gz - ‌3398908 bytes 5df62faf908c5ff4f91fdf6c5cd51c7c569222d73317a7a11a4359c66da52e18 (SHA256)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARE-93EC90DDAC7C7A1A

Introducing Adaptive Intelligence: Undermining the economics of every bot attack

Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from the meta-signals of live traffic and deploying disposable rules, making automated attacks too expensive to sustain.

Published 31 Aug 2026 · Source checked 28 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARED-2026.8.3

2026.8.3

SHA256 Checksums: cloudflared-amd64.pkg: 95f499fba19643893212bbe912733e5e80394af111fea6c67f066b46a70c3194 cloudflared-arm64.pkg: 8dc66777e1ace4c24a347857eef63a3cbb23ccdfbf3ba72f3d621bdd5e6af203 cloudflared-darwin-amd64.tgz: 936aa4ed783b0e191fac48e7140c34605b25d8d5c0495c3599c90e350ae6e4c4 cloudflared-darwin-arm64.tgz: 50a04624531e7a98ddb65f1223905e32f84e7488ed3ee8dadcd3260aa8932603 cloudflared-fips-linux-amd64: 99e8ad6e87228afd213890cc39176b7dd02b76fcf81030af4040645b89f8a205 cloudflared-fips-linux-amd64.deb: 9510f46a1fad3bd8f31551fad978bde9e0e92796be01a25288efbac413db3980 cloudflared-fips-linux-x86_64.rpm: 0697fbebcd25a61db5cbcffc7ba47a561ec94291327b365752f469f6cecafe46 cloudflared-linux-386: 691e3a2b8926f90ec4fcec4f4bc8e38b1de14f6232d93a24f6cb7b2c23ab5e92 cloudflared-linux-386.deb: 68e7e2cec6934a6bc5f06ca6703d55e898369fef297e33e3b23d02b1f7282a4e cloudflared-linux-386.rpm: b2fc222ef9410ee81a04e0058b00a4e4944274c253c2eb1ebda0ea63583c18b5 cloudflared-linux-aarch64.rpm: 85bda0d5385757549c04f036571a453a933b6e9f32f3cd84cf8692ccf25f5bb6 cloudflared-linux-amd64: f29324fe934d1e100617484c78deef803c4dc2cd351d645bbde42e96b4fccc5e cloudflared-linux-amd64.deb: 660b348d473bba81997445b534e7eaefaf4c4e16331866922326c338a7013dd9 cloudflared-linux-arm: 7a7cac4ad4561ff55797eaf27aae1a0be37498c85502715bc87e3bad919d928c cloudflared-linux-arm.deb: f1ee5c2e42771d1f63313910e792a1d1e355fc1b55cd69bececac7a8ff6acb12 cloudflared-linux-arm.rpm: ce958ce42ad88b5a436e5b6d72bb988e23167f4f670cea69c05f2702c3ad62e7 cloudflared-linux-arm64: 4bcfd35521a7cbc545ebfd5d57334a71ee180e2a64874981f374c81472118391 cloudflared-linux-arm64.deb: 2c0d991ed6061e55d2e0148b794d86f594ddb473c1db43cf0647278b62e326ab cloudflared-linux-armhf: d8bd9d00c15398ef4c6e6bc1a0486b6f1eb8c0dfd93e7479e07a121aa4e3dd57 cloudflared-linux-armhf.deb: dc1265f86d79c425cacc4e8a2a036a6276d189f118d95c319e833e74ae4b0f2e cloudflared-linux-armhf.rpm: 4ac13cfb739c30330739655ae4aad6cf24a53d860b11de0d33f1e48885915045 cloudflared-linux-x86_64.rpm: f442d9c2bd9afc595c6fbe9d1a19a9ff0d3a44911c0ccc00666fa28c08d1a31f cloudflared-windows-386.exe: bdfab00122a3c2a0772d3f176445f6baf0271fed71656d0902cbc23a0eea7048 cloudflared-windows-386.msi: a21d6c4a60e076e2e34a2df800fd94e70aabd6427f07d55c987ae11cabc025bf cloudflared-windows-amd64.exe: 83e726ed18ea78c5ad5213c4c3a3a27051393950d2bc8ed4de69bec12d14eaae cloudflared-windows-amd64.msi: 4236c68898bcd9d1e9aeea70268e6482d13a7bb9ea111e532299f35fde82f721

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-3.22.0-RC.1

Helm v3.22.0-rc.1

Helm v3.22.0-rc.1 is a pre-release. It is to help gather feedback from the community as well as give users a chance to test Helm in staging environments before v3.22.0 is officially released. The official changelog will come out with the v3.22.0 release. For now, you can see the commit changes from v3.21.4 here . The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Installation and Upgrading Download Helm v3.22.0-rc.1. The common platform binaries are here: MacOS amd64 ( checksum / 6c73354355d0d956d976f348dd14441b667ff7ed44ba5eff67f33d959c972848) MacOS arm64 ( checksum / 6b7fd364dfcb1b6a86c651a2db452de976d58f623ee57f1f3e06b2bf03fe7ba5) Linux amd64 ( checksum / c64ef32b65487bb238f1a56990ca6ec3c68d0536f21d71679d14d239ae4caed0) Linux arm ( checksum / b495f12090c8ab8a704f0039308f73ba5a50a714f89307f0027d33b0440c6bfe) Linux arm64 ( checksum / ee1d5a720c66f477fe47ba8afed922a6679a3334a9b006c84ce70552a3e2c19b) Linux i386 ( checksum / 640223f532d1a08d3139fad99154afcbf84bdfbc79f6f5eb10b1cadfe680c9a3) Linux ppc64le ( checksum / b7cbcc7456188157d8719d6b389a05c1f75144b7b72b7c147adcf75a07167fc7) Linux s390x ( checksum / 2f3c7420517278b2c8e68ef006dbec69dcff7654d4f60f6e0a2997ab27254848) Linux riscv64 ( checksum / 694c004a0661da42a6a7564c180a97c9a176759a3db598f6c992dd6b3086b033) Windows amd64 ( checksum / b3dad8258fe11dcbd0a794b6672c7e1da592a8c36461cbef3a40e885cb724356) Windows arm64 ( checksum / 47497b4c10d07bcb85bd47d10edbd12bd73dab36251e953c951186f8f1ea840a) This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @scottrigby keybase account . Please use the attached signatures for verifying this release using gpg . The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash .

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-4.3.0-RC.1

Helm v4.3.0-rc.1

Helm v4.3.0-rc.1 is a pre-release. It is to help gather feedback from the community as well as give users a chance to test Helm in staging environments before v4.3.0 is officially released. The official changelog will come out with the v4.3.0 release. For now, you can see the commit changes from v4.2.4 here . The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Installation and Upgrading Download Helm v4.3.0-rc.1. The common platform binaries are here: MacOS amd64 ( checksum / 0dc08c66cd19eba483d9f62239e9b48c9a221d98aa00bf11d2bb7835a8068cd3) MacOS arm64 ( checksum / 1aaf22c1b545cf7d589f7421ee7c595a25e07aaa82846c63a8e224685fe3358c) Linux amd64 ( checksum / 71c5b52fbe66e048ca51d23a0da81238d1e3e7af7e470e2a0c805af9ae66e22e) Linux arm ( checksum / 78424440e2ef021127348824dce243209e01285d0c806e7c991434bd93ee36ac) Linux arm64 ( checksum / 0236e2ebea9577799375a236c5e0e98d0eded4b9a3260678e51bfbc9dcca97a1) Linux i386 ( checksum / f445cdb7e34786e917ec53dc035def5355af96094fad8665454c3e5d7256cdf5) Linux loong64 ( checksum / bd25666074c233dd5194936124628ef5be3a38b549ebc43126c464c8e91682b1) Linux ppc64le ( checksum / 34c43122611418c751002da22203c2ac67e911c6c843d94376a831815a5b313f) Linux s390x ( checksum / 1db55052595c3490c902df4a430fec03bb56591b8d7e5a984419c68d15564911) Linux riscv64 ( checksum / 7916f2006846d55c81e6e0869ac3e3d860d78501be7350db8b8f4f754fdf3897) Windows amd64 ( checksum / 217db2cfca0ce01831918d3cdd57e5226a638441f2bf74e7bb2b8e8f873c2239) Windows arm64 ( checksum / 02398a3aee14397ce4cbbcf38f34a36155b894f665826485567c6893d1e8fe6f) This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @scottrigby keybase account . Please use the attached signatures for verifying this release using gpg . The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash .

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPEN HOME FOUNDATIONHOME-ASSISTANT-2026.9.0

2026.9.0b5

Resolve missing local addresses for Mitsubishi Comfort devices ( @nikolairahimi - #173270 ) velbus: fix unique_id collision for Property sensor entities ( @StefCoene - #176343 ) Fix mangled model names in Google Generative AI options ( @noron12234 - #178686 ) Use SmartThings custom setpoint bounds for air conditioners ( @StellarSea - #180304 ) Support Shellies with enhanced_security and HTTP ( @burmistrzak - #180438 ) Report an uncalibrated Shelly roller by its last direction ( @frenck - #180485 ) Let LG ThinQ unload when the network is down ( @frenck - #180610 ) Ask Google for the calendar access the entry is set to ( @frenck - #180612 ) Seed Sofar total sensors' high-water marks before the first poll ( @darkrain-nl - #180624 ) Add support for Miele KM7740 and KM7899 ( @SvenC81 - #180632 ) Do not crash the Synology DSM options on an unloaded entry ( @frenck - #180692 ) Bump midea-local to 10.1.0 ( @rokam - #180694 ) Abort the Silla Prism config flow when MQTT is unavailable ( @ebaschiera - #180712 ) Fix Prana fan percentage rounding so displayed values map to the same step ( @alexx9363 - #180718 ) Bump pytrafikverket to 2.0.0 ( @gjohansson-ST - #180820 ) Fix Trafikverket Ferry no time ( @gjohansson-ST - #180822 ) Correctly display sn and mac in Midea device page ( @rokam - #180848 ) Bump solaredge-web to 0.4.0 ( @tronikos - #180861 ) Add Tuya indicator light on translation ( @minimicro34 - #180865 ) Bump reolink_aio to 0.21.14 ( @starkillerOG - #180870 ) Stop the Hikvision event stream on Home Assistant shutdown ( @ptarjan - #180873 ) Bump habluetooth to 6.26.11, bleak-retry-connector to 4.7.0 and bluetooth-data-tools to 1.29.24 ( @bdraco - #180877 ) Bump wiim to 0.1.7 ( @Linkplay2020 - #180884 ) Bump pyHik to 0.4.4 ( @ptarjan - #180837 ) Bump pyHik to 0.4.5 ( @ptarjan - #180885 ) Remove the Sofar waiting-ends sensor ( @darkrain-nl - #180899 ) Bump tuya-device-handlers to 0.0.27 ( @epenet - #180906 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KEYCLOAKKEYCLOAK-26.7.3

26.7.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50785 CVE-2026-35563 : LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname ldap #50997 [ CVE-2026-16093 ] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers oidc #50998 [ CVE-2026-16072 ] Organization managers can create managed members through stored registration links without manage-users organizations #51001 [ CVE-2026-16108 ] Realm default-group reads disclose hidden groups under FGAP v2 admin/fine-grained-permissions #51002 [ CVE-2026-16105 ] Missing per-role authorization on RoleContainerResource composite endpoints admin/rbac #51003 [ CVE-2026-16089 ] Authorization codes can be retargeted to another client session oidc #51005 [ CVE-2026-16104 ] Authenticator config surfaces expose raw reCAPTCHA secrets admin/fine-grained-permissions #51112 [ CVE-2026-16106 ] Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles admin/fine-grained-permissions #51142 [ CVE-2026-17059 ] Information disclosure: GET /roles/{role}/users returns user PII without the per-user view filter admin/fine-grained-permissions #51279 [ CVE-2026-18218 ] Client not-before revocation is ignored when realm not-before is older but nonzero oidc #51282 [ CVE-2026-18215 ] Microsoft external access-token exchange bypasses configured tenant token-exchange #51283 [ CVE-2026-18201 ] Generic identity-provider creation can bind brokers to organizations without manage-organizations organizations #51286 [ CVE-2026-18209 ] Incomplete fix for redirect_uri OIDC response-parameter injection: forbidden-parameter check (commit 18832bc ) inspects only the query string, not the URL fragment oidc #51287 [ CVE-2026-18214 ] Google external access-token exchange bypasses hosted-domain restriction token-exchange #51378 [ CVE-2026-18571 ] FGAP V2: Group assignment bypass during user creation (POST /users) allows adding unpermitted groups admin/fine-grained-permissions #51379 [ CVE-2026-18572 ] UMA claim token can override the authorization time-policy clock authorization-services #51380 [ CVE-2026-18573 ] Client access-type condition evaluates updates against the old client type oidc #51382 [ CVE-2026-18570 ] Full-scope-disabled client policy validation can be bypassed by omitting fullScopeAllowed oidc #51745 [ CVE-2026-19729 ] Incomplete fix for CVE-2026-9083 — relative path traversal still enables filesystem probing in 26.6.4 core #52028 [ CVE-2026-79652 ] Keycloak jwt-bearer authorization grant does not enforce consentRequired oidc Weaknesses #50581 Admin API: User/group role-mapping endpoints disclose hidden client role metadata under FGAP v2 admin/fine-grained-permissions #50583 Admin API: Composite role endpoints do not filter child roles by FGAP v2 view permission admin/fine-grained-permissions #50990 Admin UI extension effective-role endpoints disclose hidden composite roles admin/fine-grained-permissions #51143 Aggregate policy partial evaluation diverges from runtime semantics under FGAP v2 admin/fine-grained-permissions #51144 Partial evaluation misses ancestor group policies with extendChildren admin/fine-grained-permissions #51202 Client-protocol condition can be bypassed on admin client creation by omitting protocol oidc Bugs #50825 Creating an organization without a domain leads to an error organizations #50963 V1 token-exchange strips the DPoP sender-constraint from a bound access token token-exchange #51510 SQLGrammarException: The incoming request has too many parameters core #51523 Sustained high CPU on all nodes after upgrade admin/api #51554 Admin API per-request cost grows super-linearly with realm count since 26.7.1 admin/api #51589 NPE in RoleUtils.expandCompositeRoles when a cached client scope references a deleted role core #51602 Invalid redirect on https://access.redhat.com/

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GITEAGITEA-1.27.3

v1.27.3

SECURITY fix(packages): restrict/limited/token-scope access ( #39041 , #39043 , #39044 , #39047 , #39046 ) ( #39058 ) fix(attachments): enforce owning repository path ( #39048 ) ( #39077 ) fix(markup): enforce same-repository issue access ( #39045 ) ( #39054 ) fix(actions): verify raw artifact signatures first ( #39049 ) ( #39053 ) fix(api): hide limited users from restricted viewers ( #39004 ) ( #39039 ) fix(repo): limit gitignore template selections ( #39027 ) ( #39040 ) fix(migrations): cancel GitLab version probes ( #39023 ) ( #39035 ) fix(packages): limit Swift package manifests ( #39025 ) ( #39032 ) fix(migrations): bound OneDev version responses ( #39024 ) ( #39033 ) fix(packages): limit Maven checksum uploads ( #39028 ) ( #39031 ) fix(packages): bound Alpine metadata entries ( #39026 ) ( #39029 ) fix(actions): enforce fork pull request trust boundaries ( #39005 ) ( #39018 ) fix(git): restrict hook permissions ( #39008 ) ( #39016 ) fix(api): enforce repository creation token authorization ( #39007 ) ( #39014 ) fix(api): enforce public-only scope for compare heads ( #39006 ) ( #39013 ) fix(repo): hide repositories of hidden owners ( #39009 ) ( #39012 ) fix: avoid enumerating every public repository in issue search ( #38992 ) ( #39000 ) refactor: private endpoints ( #38964 ) ( #38965 ) ENHANCEMENTS enhance: add permalinks to pull request reviews ( #38849 ) ( #39036 ) BUGFIXES fix: add missing query parameters on runner list page ( #39163 ) fix(actions): keep step-level continue-on-error expressions unevaluated ( #39141 ) ( #39148 fix(packages): preserve SemVer prerelease identifiers in Swift Registry ( #39156 ) ( #39158 ) fix(repo): prevent MarkAsBrokenEmpty when repository is being migrated ( #39091 ) ( #39092 ) fix(asymkey): do not verify OpenPGP signatures with an SSH instance key ( #39073 ) ( #39086 ) fix(pull): keep the merged state in sync with git ( #39062 ) ( #39118 ) fix(pull): name the head repository in default compare links ( #39075 ) ( #39079 ) fix(git): parse co-author trailers that are not RFC 5322 addresses ( #39076 ) ( #39081 ) fix(actions): show "Complete job" logs when the last step is skipped ( #38939 ) ( #39003 ) fix(actions): Fix how jobs in matrixes are grouped ( #38980 ) ( #38998 ) fix: resolve YAML anchors and aliases in Actions workflows ( #38984 ) ( #38996 ) fix: honor environment variables during install ( #38974 ) ( #38976 ) fix: grant limited-org unit read access to authenticated non-members ( #38871 ) ( #38963 ) fix: allow anonymous theme switching when REQUIRE_SIGNIN_VIEW is set ( #38956 ) ( #38961 ) fix(actions): drop wrapper span around the action status icon ( #38957 ) ( #38959 ) fix(issues): sort scoped labels by exclusive order in dropdowns ( #38893 ) ( #38954 ) fix(indexer): correct bleve indexer token filters ( #38853 ) ( #38951 ) fix: make "login_name" field optional for API edit user ( #38917 ) ( #38945 ) fix(actions): reject non-mapping matrix include/exclude ( #38933 ) fix(ui): respect FEED_PAGING_NUM on the dashboard feed ( #38935 ) ( #38936 ) MISC chore: repo compare link ( #39088 ) ( #39119 ) ci: remove AWS S3 uploads from release workflows ( #38928 ) ( #38929 ) chore: Pre-register a builtin OAuth2 application for the official Gitea mobile app ( #38880 ) ( #38922 ) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RUST FOUNDATIONRUST-1.98.0

Rust 1.98.0

Language Allow shortening lifetime of &mut when unsize-coercing, even in an invariant position. For example, you can now coerce a Cell<&'long mut i32> to a Cell<&'short mut dyn Send> . Such shortenings were already previously allowed when coercing a &mut to a & , or coercing a & to a & . Add deny-by-default invalid_runtime_symbol_definitions lint and warn-by-default suspicious_runtime_symbol_definitions lint The lints currently specifically targets core runtime symbols like memcmp , memset , strlen , ... and is planned to be expanded in the next few releases. Add warn-by-default c_void_returns lint to check core::ffi::c_void as a return type Platform Support Add powerpc64-unknown-linux-gnuelfv2 as Tier 3 Add aarch64-unknown-linux-pauthtest as Tier 3 target Promote thumbv7a-none-eabi to Tier 2 Promote thumbv7a-none-eabihf to Tier 2 Promote thumbv7r-none-eabi to Tier 2 Promote thumbv7r-none-eabihf to Tier 2 Promote thumbv8r-none-eabihf to Tier 2 Refer to Rust's platform support page for more information on Rust's tiered platform support. Libraries Change Location<'_> lifetime to 'static in Panic[Hook]Info Document panic in RangeInclusive::from(legacy::RangeInclusive) Document that ManuallyDrop 's Box interaction has been fixed Stabilize LoongArch CRC Intrinsics The derive macro is available at {core,std}::derive . This was previously unintentionally stabilized in 1.96 , but is now explicitly accepted as a stabilized API. Please note that the MSRV for {core,std}::derive will be 1.96, and not 1.98. Stabilized APIs str::substr_range [T]::subslice_range core::fmt::NumBuffer <{integer}>::format_into Send/Sync for std::process::CommandArgs {fN}::algebraic_add {fN}::algebraic_sub {fN}::algebraic_mul {fN}::algebraic_div {fN}::algebraic_rem NonZero<{integer}>::from_str_radix String::from_utf16le String::from_utf16le_lossy String::from_utf16be String::from_utf16be_lossy [T]::strip_circumfix str::strip_circumfix Atomic<T>::from_mut Atomic<T>::get_mut_slice Atomic<T>::from_mut_slice std::range::legacy bool::ok_or bool::ok_or_else Compatibility Notes If fully elided, lifetime bounds of trait object types may now resolve differently or even get rejected in very specific niche scenarios Error in more cases of ambiguous imports Switch the destructors implementation for thread locals on Windows to use Fiber Local Storage (FLS) Convert some cases of the ambiguous_glob_imports lint into a hard error Where-bounds of the form Type = Type and Type == Type are no longer syntactically allowed Ensure Send/Sync is not implemented for std::env::Vars{,Os} Fix that in some attributes, arguments were not properly rejected repr(transparent) is now more strict about which fields have "trivial" layout and hence can be ignored: repr(C) types, types with private fields, and #[non_exhaustive] types are no longer considered "trivial" Correctly check whether types have equal size in transmute() when some repr attributes are involved. More characters are escaped when printing strings and chars Implement fast path for derive(PartialOrd) when deriving Ord This can break crates in practice where a type's PartialOrd and Ord impls were inconsistent with each other. Add temporary scope to assert_eq and assert_ne Closed a hole in the pattern matching structural equality check, preventing cases where a match of a constant would be allowed, despite disagreeing with a manually written PartialEq implementation, when a derive(PartialEq) implementation for that type also exists. On Emscripten the WASM exception handling ABI is now unconditionally used The -Zemscripten-wasm-eh=false flag to switch back to JS exceptions has been removed. The UNSAFE_CODE lint is now consistently emitted for all unsafe attributes Solaris: remove File::lock implementation, it has the wrong semantics (return "unsupported" instead) Windows-gnu targets now specify baseline tools versions rustfmt now discovers module files that are defined in cfg_select! This may cause more code to be formatted which was

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.6

v3.6.0-rc.6

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DENODENO-2.9.6

v2.9.6

2.9.6 / 2026.08.27 feat(compressible): add support for 'text/x-component' content type ( #36450 ) feat(desktop): clipboard api ( #35750 ) feat(desktop): support checked, icon, and tooltip on menu items ( #36649 ) fix(bundle): isolate esbuild downloads from workspace registries ( #36467 ) fix(cache): combine duplicate headers for Vary matching ( #36476 ) fix(cli_parser): remove orphaned sync-types parser fix(core): cap adaptive buffer initial allocations ( #36432 ) fix(core): make Unix pipe fd ownership explicit ( #36353 ) fix(core): make user timer waker state thread-safe ( #36495 ) fix(coverage): compare a range against a line in V8's units ( #36613 ) fix(crypto): preserve RSA-OAEP label bytes ( #36441 ) fix(desktop): keep dots in the app name when resolving the runtime library ( #36006 ) fix(desktop): keep the macOS bundle signature valid unless an update is applied ( #36574 ) fix(desktop): never block the JS thread on the error-report dialog ( #36575 ) fix(desktop): propagate deno.json version and license into packaged installers ( #36577 ) fix(desktop): run Vite-based HMR dev servers inside the desktop runtime ( #36488 ) fix(desktop): transport binding args and results as DesktopValue so Uint8Array survives ( #36573 ) fix(ext/fetch): enforce permissions for proxy transports ( #36217 ) fix(ext/fetch): only retry transport errors on pooled connections ( #36415 ) fix(ext/fetch): raise default HTTP/2 SETTINGS_MAX_HEADER_LIST_SIZE to 256KB ( #36558 ) fix(ext/http): keep request body readable after response is sent ( #36629 ) fix(ext/http): route invalid async responses to onError ( #36437 ) fix(ext/napi): don't invoke napi_wrap finalizer twice at teardown ( #36556 ) fix(ext/napi): run JS-calling finalizers safely, NULL string result, and Float16Array ( #36572 ) fix(ext/napi): surface OS error and path on addon load failure ( #36630 ) fix(ext/napi): track pending finalizers by identity ( #36551 ) fix(ext/napi): wake the event loop at the next uv_timer deadline ( #36559 ) fix(ext/net): skip unsupported DNS records in ANY queries ( #36650 ) fix(ext/node): accept string ports in dns.lookupService ( #36546 ) fix(ext/node): build the proxied request target with the URL parser ( #36557 ) fix(ext/node): do not resume client TLS sessions unless requested ( #36592 ) fix(ext/node): fix perf_hooks detail.req.url proxied path duplication ( #36407 ) fix(ext/node): handle readv short reads ( #36211 ) fix(ext/node): require sys permission for inspector.open ( #36465 ) fix(ext/node_sqlite): invalidate sessions on database close ( #36633 ) fix(ext/tls): avoid panic for mismatched client certificate and key ( #36457 ) fix(ext/web): clean up abort handlers when listeners are removed ( #36226 ) fix(ext/web): close transfer MessagePort when a transferred readable is cancelled ( #36270 ) fix(ext/web): snapshot SharedArrayBuffer input in TextDecoder.decode() ( #36611 ) fix(fetch): require an initial multipart boundary ( #36470 ) fix(ffi): validate struct return buffers ( #36373 ) fix(fmt): honor .editorconfig when formatting from stdin ( #36267 ) fix(fs): require write permission for creating opens ( #36497 ) fix(fs): use a private FsFile constructor token ( #36439 ) fix(glob): retain valid gitignore rules after parse errors ( #36478 ) fix(http): preserve keep-alive after reading request body ( #36690 ) fix(http): truncate streaming responses to content length ( #36496 ) fix(lsp): restrict registry completion endpoint schemes ( #36477 ) fix(node): check reads during require resolution ( #36461 ) fix(node): match domain uncaught exception handling ( #36475 ) fix(node): preserve v8 deserializer view offsets ( #36460 ) fix(node): validate Brotli encoder operations ( #36530 ) fix(node): validate raw outgoing HTTP headers ( #36471 ) fix(node/crypto): preserve binary key export passphrases ( #36443 ) fix(node_crypto): apply RFC 7748 scalar decoding for X448 ( #36466 ) fix(node_crypto): size cipher updates by byte length ( #36459 ) fix(node_shim): preserve e

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-3.6.16

v3.6.16

3.6.16 (2026-08-27) Features Add flag to ignore missing chunks during deletion of logs with line filter [release-3.6.x] ( #24232 ) ( b87159f ) Bug Fixes security/UNKNOWN/: Update module go.etcd.io/etcd/client/pkg/v3 to v3.5.33 [SECURITY] (release-3.6.x) ( #24062 ) ( bf4b367 ) storage: Pre-compute SHA-256 to avoid aws-chunked on PutObject [release-3.6.x] ( #24214 ) ( 0a29895 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-3.7.7

v3.7.7

3.7.7 (2026-08-27) Features Add flag to ignore missing chunks during deletion of logs with line filter [release-3.7.x] ( #24233 ) ( 7a40404 ) Bug Fixes security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.2.5 [SECURITY] (release-3.7.x) ( #24097 ) ( 07cd1f0 ) security/UNKNOWN/: Update module go.etcd.io/etcd/client/pkg/v3 to v3.6.14 [SECURITY] (release-3.7.x) ( #24061 ) ( 9d1c9ee ) security/UNKNOWN/: Update module golang.org/x/mod to v0.40.0 [SECURITY] (release-3.7.x) ( #23962 ) ( 1d5e027 ) storage: Pre-compute SHA-256 to avoid aws-chunked on PutObject [release-3.7.x] ( #24215 ) ( 3d6f245 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.17.0-ALPHA20260827

v1.17.0-alpha20260827

1.17.0-alpha20260827 (August 27, 2026) NEW FEATURES: A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. ( #35290 ) ENHANCEMENTS: command/init: Enrich log messages with provider versions ( #38918 ) command/login: display warning after successful login if user is subject to an organization's TTL policy BUG FIXES: funcs: pow and log no longer panic when result is not a number ( #38912 ) ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. ( #38989 ) Fix panic when import identity references sensitive value ( #39013 ) NOTES: version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. ( #38930 ) EXPERIMENTS: Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases. The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan , permits count and for_each arguments in module , resource , and data blocks to have unknown values and allows providers to react more flexibly to unknown values. terraform test cleanup : The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention. terraform test : backend blocks and skip_cleanup attributes: Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations. Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command. terraform query : The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation. Previous Releases For information on prior major and minor releases, refer to their changelogs: v1.16 v1.15 v1.14 v1.13 v1.12 v1.11 v1.10 v1.9 v1.8 v1.7 v1.6 v1.5 v1.4 v1.3 v1.2 v1.1 v1.0 v0.15 v0.14 v0.13 v0.12 v0.11 and earlier

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-2.11.56

v2.11.56

Important: Please read the migration guide . CVE fixed: Advisory GHSA-7ghq-v6jf-g56c Advisory GHSA-rf44-j88r-hh8c Bug fixes: [http3] Apply read timeout, idle timeout, and max header bytes for HTTP/3 ( #13717 @gndz07 ) [server] Add an entry point option to handle request headers with aliasing names ( #13720 @rtribotte ) [tcp, udp] Reject negative weights in TCP and UDP weighted services ( #13749 @rtribotte ) Bump etcd client modules to v3.5.33 ( #13756 @mmatur )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.7.12

v3.7.12

Important: Please read the migration guide . CVE fixed: Advisory GHSA-cjr6-pf59-jq29 Advisory GHSA-7ghq-v6jf-g56c Advisory GHSA-rf44-j88r-hh8c Bug fixes: [fastproxy] Bump github.com/valyala/fasthttp to v1.73.0 ( #13769 @mmatur ) [file] Include the filename in file provider configuration errors ( #13527 @lazerg ) [http3] Apply read timeout, idle timeout, and max header bytes for HTTP/3 ( #13717 @gndz07 ) [k8s] Fix typos in docs and an OCSP log message ( #13722 @MsfPablo ) [k8s, k8s/ingress-nginx] Fix redirect www host with a non-numeric port ( #13708 @mmatur ) [k8s/ingress-nginx] Fix TLS option name collision across namespaces in the ingress-nginx provider ( #13721 @gndz07 ) [server] Add an entry point option to handle request headers with aliasing names ( #13720 @rtribotte ) [tcp, udp] Reject negative weights in TCP and UDP weighted services ( #13749 @rtribotte ) Bump etcd client modules to v3.5.33 ( #13756 @mmatur ) Documentation: [k8s] Update redirections block reference in basic.md ( #13723 @Larzenegger ) [k8s] Fix formatting in Kubernetes setup guide ( #13742 @stefkiourk ) [security] Document the security threat model and settled security decisions ( #13740 @emilevauge ) [service] Clarify ServersTransport behavior for the errors middleware in Kubernetes ( #13531 @lazerg ) Fix v3.7.11 migration guide ( #13730 @gndz07 ) Move Jean-Baptiste Doumenjou and Mathieu Lonjaret to past maintainers ( #13736 @emilevauge ) Reduce SECURITY.md to a pointer to the security documentation ( #13732 @emilevauge ) Update end of support dates ( #13712 @nmengin )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.5.42

v3.5.42

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.37.0

v1.37.0

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-24.20.0

2026-08-26, Version 24.20.0 'Krypton' (LTS), @aduh95

Notable Changes [ b12bcc9ae1 ] - (SEMVER-MINOR) async_hooks : add using scopes to AsyncLocalStorage (Stephen Belanger) #61674 [ e2eb88b36b ] - (SEMVER-MINOR) buffer : add end parameter (Robert Nagy) #62390 [ 1fefdda18e ] - crypto : update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746 [ 4a158cf1ab ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ d4cafce076 ] - (SEMVER-MINOR) lib,permission : add permission.drop (Rafael Gonzaga) #62672 [ b3cfb55267 ] - (SEMVER-MINOR) loader : implement package maps (Maël Nison) #62239 [ cd1eb3e60b ] - (SEMVER-MINOR) src,permission : add --permission-audit (RafaelGSS) #61869 [ 28dc85d8d2 ] - (SEMVER-MINOR) stream : add node:stream/iter implementation (James M Snell) #62066 [ d31c168740 ] - (SEMVER-MINOR) test_runner : add context.log() and test:log event (Moshe Atlow) #64389 [ add1edbc42 ] - (SEMVER-MINOR) test_runner : report entryFile in TestStream events (Moshe Atlow) #64309 [ d937c8c6cd ] - (SEMVER-MINOR) wasm : enable JSPI (Guy Bedford) #59941 Commits [ 1822c0f335 ] - assert,util : fix TypeError on Maps with null keys (Paul Bouchon) #64441 [ b12bcc9ae1 ] - (SEMVER-MINOR) async_hooks : add using scopes to AsyncLocalStorage (Stephen Belanger) #61674 [ 984260bf44 ] - async_hooks : use validateBoolean for trackPromises (Soul Lee) #64731 [ ba2612cca2 ] - benchmark : fix calibrate-n option handling (Luan Muniz) #64146 [ 236dc4d2d7 ] - benchmark : add bytes variant to webstreams async-iterator (Matteo Collina) #64291 [ b022a1419c ] - benchmark : respect stream/iter broadcast backpressure (Trivikram Kamat) #63314 [ a290f51f15 ] - (SEMVER-MINOR) benchmark : add benchmarks for experimental stream/iter (James M Snell) #62066 [ 465f2bfb74 ] - buffer : use Clamp conversion in Blob slice (Donghoon Kang) #64739 [ 74a22cd0c5 ] - buffer : validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #63904 [ 21e24208dc ] - buffer : normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115 [ ddacb3ff10 ] - buffer : fix Blob.stream() leaking source buffer (semimikoh) #63577 [ 49198d2313 ] - buffer : fix end parameter bugs in indexOf/lastIndexOf (Robert Nagy) #62711 [ e2eb88b36b ] - (SEMVER-MINOR) buffer : add end parameter (Robert Nagy) #62390 [ e2e5c4fe88 ] - build : update binary-upload to use correct tarball name (Stewart X Addison) #65282 [ b78a212553 ] - build : pin envinfo versions in github actions (Joyee Cheung) #64117 [ 094fb840aa ] - build : add QUIC CI job for PRs matching QUIC related paths (Tim Perry) #63875 [ 91f5003cad ] - build : fix flags for ngtcp2 on IBM i (SRAVANI GUNDEPALLI) #60073 [ e83648effd ] - build,test : add tests for binary linked with shared libnode (Joyee Cheung) #61463 [ 4a425b41d9 ] - build,tools : fix shared library cross-compile (Kirill Saied) #63963 [ fe8fa45ff2 ] - cli : style node --help output with util.styleText (Adrián Estrada) #64484 [ 3cd1576cb2 ] - crypto : preserve OpenSSL errors from KDF failures (Filip Skokan) #64776 [ 74b3023565 ] - crypto : handle XOF output allocation failure (Filip Skokan) #64851 [ fea0666a1b ] - crypto : clarify missing cipher error (Filip Skokan) #64852 [ 33fec91b54 ] - crypto : reuse X509 issuer result (Filip Skokan) #64852 [ 44c1473348 ] - crypto : validate key generation options (Filip Skokan) #64852 [ c2c53a18e5 ] - crypto : fix Argon2 validation errors (Filip Skokan) #64852 [ edc1f2126d ] - crypto : initialize KeyObjectData mutex eagerly (Filip Skokan) #64851 [ be8237240c ] - crypto : handle DH operation failures (Filip Skokan) #64851 [ b65a8f3875 ] - crypto : preserve RSA-PSS legacy pubkey DER (Filip Skokan) #64547 [ 49f2ae204b ] - crypto : cleanse provider private key copies (Filip Skokan) #64547 [ a5d4ac8208 ] - crypto : handle incomplete RSA private keys (Filip Skokan) #64547 [ b72c0b9616 ] - crypto : retain legacy DH validation (Filip Skokan) #64547 [ 24a1be5886 ] - crypto : limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) #64557 [ 0290e0a61e ] - crypto : sp

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-26.8.0

2026-08-26, Version 26.8.0 (Current), @aduh95

Notable Changes [ 74234ee30e ] - (SEMVER-MINOR) benchmark : add --analyze mode to compare.js (James M Snell) #65416 [ 4232997fa2 ] - crypto : update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495 [ f0531f1c87 ] - (SEMVER-MINOR) crypto : enable SIV and GCM-SIV modes in Cipher/Decipher APIs (Filip Skokan) #63411 [ 3f4b80ebb5 ] - diagnostics_channel : mark TracingChannel as stable (Abdelrahman Awad) #64525 [ 753033c110 ] - (SEMVER-MINOR) lib,src : improve histogram implementation (James M Snell) #65024 [ 3d7d277493 ] - (SEMVER-MINOR) net : improve performance of net.BlockList (James M Snell) #64974 [ 9e8e9080fd ] - (SEMVER-MINOR) perf_hooks : add statistical hypothesis testing to histogram (James M Snell) #65416 [ c18b0aa54e ] - repl : add basic syntax highlighting (Aviv Keller) #64591 [ 58ea88e1d3 ] - (SEMVER-MINOR) sqlite : add StatementSync.prototype.close() (Guilherme Araújo) #64232 [ 7c61b08aed ] - (SEMVER-MINOR) sqlite : add StatementSync.prototype[Symbol.dispose]() (Guilherme Araújo) #64232 [ 4299cd5897 ] - (SEMVER-MINOR) util : add non-throwing MIMEType.parse (James M Snell) #64965 [ df48191061 ] - (SEMVER-MINOR) zlib : add ZipEntry, ZipFile, and ZipBuffer (Philipp Dunkel) #64339 Commits [ 162257b403 ] - assert : improve documentation wording (Kamal Rawal) #64953 [ 74234ee30e ] - (SEMVER-MINOR) benchmark : add --analyze mode to compare.js (James M Snell) #65416 [ 2cb96dd462 ] - benchmark : add test-only and mock timers cases (Luan Muniz) #64097 [ 562168f93f ] - benchmark : apply highWaterMark in webstreams pipe-to (Matteo Collina) #65138 [ fbec4eb386 ] - benchmark : complete the sqlite is-transaction fix (Edy Silva) #65218 [ d8acfc45f1 ] - benchmark : add test runner hooks and options (Luan Muniz) #63754 [ 13e7d54f67 ] - buffer : prevent string write offset overflow (Matteo Collina) #65043 [ 615273deac ] - buffer : support aligned allocations (Robert Nagy) #65003 [ bc6b630e21 ] - buffer : treat detached ArrayBuffers as empty (Archkon) #64504 [ ddf9f9d265 ] - build : target Power 9 and z14 (Richard Lau) #65439 [ fda8ee894e ] - build : use build-ci for benchmark merge-commit rebuild (Yagiz Nizipli) #65362 [ 03692786ef ] - build : add simdutf dir to include path in GN build (Shelley Vohr) #65382 [ 3da555a3ed ] - build : pass target architecture to small-icu genccode (ulofiai) #65095 [ ffe1e7cbea ] - build : update binary-upload to use correct tarball name (Stewart X Addison) #65282 [ 50174cb94a ] - build : deprecate always enabled --enable-static (Chengzhong Wu) #65103 [ 28f662b424 ] - build : check FIPS option value in node.gyp (Filip Skokan) #64982 [ 29a2ecefeb ] - build : handle malformed OpenSSL macros (Filip Skokan) #64982 [ 6deeef1801 ] - build : enable perfetto updater (Chengzhong Wu) #64966 [ 312f0c6a7e ] - build : add host toolset to perfetto_sdk (Ryuhei Shima) #64751 [ 1a4f5e537b ] - build,win : add PGO workload scripts (Stefan Stojanovic) #63696 [ 21655dccbc ] - child_process : keep SIGWINCH from killing on Win (Kirill Saied) #64510 [ 4232997fa2 ] - crypto : update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495 [ f0531f1c87 ] - (SEMVER-MINOR) crypto : enable SIV and GCM-SIV modes in Cipher/Decipher APIs (Filip Skokan) #63411 [ 109566a2f7 ] - crypto : fix missing error checks on ASN1_STRING_to_UTF8() (Nora Dossche) #65200 [ 501f81612d ] - crypto : improve SubtleCrypto.supports() accuracy (Filip Skokan) #65222 [ 137ff67fd3 ] - crypto : use available BoringSSL APIs (Filip Skokan) #65423 [ 0e87576ed4 ] - crypto : remove obsolete BoringSSL shims (Filip Skokan) #65423 [ af867ce3e4 ] - crypto : add mgf1Hash for RSA-OAEP (Adam Mcgrath) #65073 [ 66ee4792bf ] - crypto : disable non-FIPS WebCrypto paths in FIPS mode (Filip Skokan) #65172 [ 6a142c03e9 ] - crypto : read WebCrypto inputs through primordials (Filip Skokan) #65115 [ 92e3110462 ] - crypto : fix disabling FIPS mode (Filip Skokan) #64982 [ d69bed2f49 ] - debugger : wait for target startup (Filip Skokan) #65194 [ 5c7c0b8b15 ] - deps : update z

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-26.8.1

2026-08-26, Version 26.8.1 (Current), @aduh95

Notable Changes Out-of-band release to fix node --version which was reporting an alpha version. Commits [ ebd35a9eec ] - src : revert accidental alpha designation (Antoine du Hamel) #65568 [ 0b0dd87fcc ] - tools : fix tools/nix/list-requisites.sh (Antoine du Hamel) #65560

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.3.4

RabbitMQ 4.3.4

RabbitMQ 4.3.4 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version The minimum supported Erlang version for this release series is 27.0 . RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Quorum queues in clusters upgraded from 3.13.x to 4.2.x and then to 4.3.x could stop emitting metrics and taking snapshots after a node restart. GitHub issues: #16974 , #16990 The AMQP 1.0 parser now detects standard message body sections more strictly. GitHub issue: #17017 The AMQP 1.0 parser now decodes certain array values more efficiently. GitHub issue: #16994 Stream Plugin Bug Fixes The single active consumer coordinator did not notify a consumer that was re-selected for activation while it was still deactivating, leaving the group without an active consumer. Contributed by @pterygota . GitHub issues: #16975 , #16976 Management Plugin Bug Fixes Very short lived exclusive queues could cause an exception during metric collection, producing log noise. GitHub issues: #16989 , #16999 , #17002 After an IdP-initiated OAuth 2 login, the management UI now returns the user to the page that was open before the login instead of the default one. Contributed by @thisisnsh . GitHub issues: #16957 , #16961 Several security fixes and validation gaps were addressed: The HTTP API now returns 404 Not Found instead of 401 Unauthorized when a user lacks permission to a vhost, avoiding disclosure of the vhost's existence. Token expiry values that use a floating point number are now accepted, not just integers. To access all user-limits it is required administrator priviledge To access a user-limits for a specific user now require the requester to be that same user or have administrator/monitoring privileges. GitHub issue: #16709 Enhancements The management UI Content Security Policy (CSP) no longer includes the unsafe-eval and unsafe-inline directives. GitHub issue: #16916 Federation Plugin Bug Fixes In scenarios that involved a federated queue and a federated exchange with exactly the same name in the same virtual host, deleting an upstream unintentionally corrupted the federated exchange(s) operating state, breaking federation for the exchange in question. GitHub issues: #16991 , #16997 Dependency Changes None in this release.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.16.0

v1.16.0

1.16.0 (August 26, 2026) NEW FEATURES: Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. ( #37986 ) terraform_data : The new store block can hold ephemeral and sensitive values across plan and apply. ( #38298 ) Providers can now use nested blocks as computed values ( #38305 ) import: import blocks inside modules are now supported. ( #38352 ) Terraform is now available as a pre-built binary for Linux s390x (zLinux). ( #38384 ) Resource action triggers can now use on_failure modes of halt , taint , or continue . ( #38722 ) ENHANCEMENTS: state show: The state show command can now produce machine-readable output when supplied with the -json flag ( #23940 ) workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag ( #38397 ) test: Terraform now reports which resources were left behind when skip_cleanup is set. ( #38449 ) stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. ( #38668 ) Actions can now use before_destroy and after_destroy events. ( #38668 ) cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. ( #38715 ) policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init , plan , and apply , rather than requiring the plugin to read credentials itself. ( #38716 ) graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. ( #38719 ) Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. ( #38778 ) Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. ( #38784 ) The contains() function can now test for null values. ( #38792 ) console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. ( #31861 ) -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. ( #38845 ) The terraform stacks command now automatically infers the target hostname from the local credentials file ( credentials.tfrc.json ) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set ( #38896 ) BUG FIXES: import blocks now correctly respect provider local names. ( #38338 ) terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. ( #38586 ) workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. ( #38594 ) test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. ( #38603 ) init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override . ( #38634 ) init: Terraform now warns when unmanaged providers are in use and may impact provider installation. ( #38656 ) Actions are now invoked with respect to all resource dependencies. ( #38668 ) Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. ( #38782 ) The merge() function no longer panics when passed null objects. ( #38792 ) Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid ( #38894 ) test: Optional ephemeral values do not have to be set at plan time ( #38974 ) NOTES: init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. ( #38561 ) UPGRADE NOTES: bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. ( #38318 ) Previ

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.579

2.579

This is an automatically generated changelog draft for Jenkins weekly releases. See https://www.jenkins.io/changelog/2.579/ for the official changelog for this release. 🚀 New features and improvements Add abort support to FormChecker delayed checks ( #26595 ) @KevinSailema , @Copilot, Kevin, @timja 🐛 Bug fixes Retrying renamedTo operation up to 5 times because it randomly fails … ( #11216 ) @a-zitzewitz , @timja Fix incorrect Unicode escape decoding in QuotedStringTokenizer.unquote ( #26467 ) @Zhang-Charlie , @Copilot, @MarkEWaite Revert "Standardise experimental Jenkins pages, make the side panel independently scrollable + make the build bar sticky ( #26863 )" ( #27265 ) @gbhat618 Show only accessible links in sidepanel for new manage Jenkins UI ( #27228 ) @mawinter69 , @MarkEWaite Improve diagnostics for unreadable artifacts ( #27201 ) @Hardik180704 Fix dropdown suggestions requiring a double tap on touch devices ( #26923 ) @Anexus5919 fix combobox suggestion list flashing on click ( #26922 ) @Anexus5919 👷 Changes for plugin developers Removes commons-lang:2.6 from core ( #26105 ) @alecharp , @daniel-beck , @gbhat618 , @MarkEWaite , @timja All contributors: @a-zitzewitz , @alecharp , @Anexus5919 , @gbhat618 , @Hardik180704 , @KevinSailema , @mawinter69 , @Zhang-Charlie , @Copilot, @daniel-beck , Kevin, @MarkEWaite and @timja

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTMICROSOFT-AZURE-A1D2149125D63AD2

Announcing: Aspire 13.5 has shipped

Aspire 13.5 refreshes the dashboard and aspire.dev, expands the Interaction Service, adds cross-scope Azure references and persistent Kubernetes volumes, and brings live terminals into the apphost.Learn more.

Published 25 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.0.8

v4.0.8

🐞 Bug Fixes Kafka consumer-specific security protocol is not taken into account #51365 Temporary file is not deleted when ExportedImageTar construction fails #51117 spring-boot-h2-console pulls servlet-api as transitive dependency #51094 Methods that return the result of Map#remove are not declared with a @Nullable return type #50972 PropertiesLauncher does not log nested archive paths #50968 JarFile is not closed when finding main class from archive #50949 CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50928 Resources are not cleaned up when resolving an image that is not yet present in the builder #50919 Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50916 GraphQlWebMvcAutoConfiguration should apply customizers in order #50908 Micrometer registries pin the application context #50886 Context refresh fails when using Actuator on Jersey without spring-boot-health #50858 Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50857 IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50798 Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50781 Application-managed JUL bridge handler should only be removed if installed #50779 Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50755 PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50737 High number of connections due to Mongo health indicator #50734 Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50701 NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50433 Fix ordering of Kotlinx Serialization CodecCustomizer #50428 Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #50096 📔 Documentation spring.profiles.group should have a 'spring-profile-name' hint provider #51273 Remove reference to removed InfluxDB auto-configuration #51172 Use JacksonJsonSerde in Kafka Streams documentation #51152 Document alternatives to HttpMessageConverters #51124 Caching documentation refers to AutoConfigureCache by its pre-4.0 package #51111 Metadata for spring.test.mockmvc.htmlunit.url declares the wrong type #51110 Fix examples in Metadata Format documentation chapter #51097 Improve discoverability of the AOT Cache How-to guides #50996 Table of auto-configured HealthIndicators lists the wrong key for MongoHealthIndicator #50931 Update OpenTelemetryResourceAttributes documentation #50867 Fix @Value placeholder syntax in external config docs #50859 Refer to spring-boot-starter-webmvc, not deprecated spring-boot-starter-web #50842 Fix forwarded headers property in cloud deployment docs #50841 Fix duplicate word typos in documentation #50738 🔨 Dependency Upgrades Upgrade to CycloneDX Maven Plugin 2.9.3 #51178 Upgrade to DB2 JDBC 12.1.5.0 #50977 Upgrade to Elasticsearch Client 9.2.9 #51366 Upgrade to Groovy 5.0.8 #51179 Upgrade to Hibernate 7.2.24.Final #51180 Upgrade to Jackson 2 Bom 2.21.5 #50980 Upgrade to Jackson Bom 3.1.5 #50981 Upgrade to Jetty 12.1.12 #51298 Upgrade to jOOQ 3.19.37 #51299 Upgrade to JSpecify 1.0.1 #51181 Upgrade to Log4j2 2.25.5 #50984 Upgrade to Logback 1.5.38 #50985 Upgrade to MariaDB 3.5.10 #51182 Upgrade to Maven Help Plugin 3.5.2 #50987 Upgrade to Micrometer 1.16.7 #51235 Upgrade to Micrometer Tracing 1.6.7 #51236 Upgrade to Netty 4.2.17.Final #51300 Upgrade to Postgresql 42.7.13 #50989 Upgrade to R2DBC MariaDB 1.3.1 #50990 Upgrade to R2DBC MSSQL 1.0.5.RELEASE #50991 Upgrade to R2DBC MySQL 1.4.3 #51183 Upgrade to R2DBC Postgresql 1.1.2.RELEASE #50992 Upgrade to Reactor Bom 2025.0.7 #51237 Upgrade to Spring AMQP 4.0.5 #51238 Upgrade to Spring Batch

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.1.1

v4.1.1

⚠️ Attention Required Spring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the protobuf extension with the grpc plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of protoc-gen-grpc-java as before. #50822 🐞 Bug Fixes Kafka consumer-specific security protocol is not taken into account #51369 Structured logging: a failed JSON encode corrupts the next log event written on the same thread #51156 Micrometer registries pin the application context #51135 Temporary file is not deleted when ExportedImageTar construction fails #51132 Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #51098 spring-boot-h2-console pulls servlet-api as transitive dependency #51095 PropertiesLauncher does not log nested archive paths #51089 Methods that return the result of Map#remove are not declared with a @Nullable return type #51087 NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50964 Fix ordering of Kotlinx Serialization CodecCustomizer #50961 JarFile is not closed when finding main class from archive #50959 Application-managed JUL bridge handler should only be removed if installed #50950 CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50944 Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50942 Resources are not cleaned up when resolving an image that is not yet present in the builder #50941 GraphQlWebMvcAutoConfiguration should apply customizers in order #50914 Auto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true #50884 Context refresh fails when using Actuator on Jersey without spring-boot-health #50872 Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50871 IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50856 High number of connections due to Mongo health indicator #50852 Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50849 Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50845 PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50843 Exposing gRPC test server port should backoff if gRPC is not present #50825 JpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor #50801 spring.grpc.server.health.include-overall-health is not taken into account #50799 Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50790 Managed version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus #50780 Map properties bound from empty strings fail with ConverterNotFoundException #50773 Protobuf Common Protos should not be a managed dependency #50772 An application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not #50764 W3CHeaderParser's decoding is not compliant with RFC 3986 #50650 📔 Documentation Description of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide #51348 spring.profiles.group should have a 'spring-profile-name' hint provider #51284 Remove reference to removed InfluxDB auto-configuration #51176 Use JacksonJsonSerde in Kafka Streams documentation #51161 Document alternatives to HttpMessageConverters #51129 Fix stale type reference for OTLP logging transport metadata #51119 Metadata for spri

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-7.0.9

v7.0.9

⚠️ Attention Required In Spring Framework 7.0.9, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090 In Spring Framework 7.0.9, SimpleEvaluationContext no longer supports expression compilation by default, regardless of the compiler mode configured via SpelParserConfiguration or the spring.expression.compiler.mode system property or Spring property. Applications that intentionally use SimpleEvaluationContext with trusted expressions and require compilation for performance reasons can opt in by calling withCompilationSupported() on the SimpleEvaluationContext builder. Care should be taken when opting in to compilation, as doing so removes the safety guards applied during interpreted evaluation. #37035 ⭐ New Features Ignore an empty port value in URI parsing #37117 Avoid retaining class files in annotation metadata #37112 Add @Nullable annotations when treating Map.remove() as returning @Nullable #37067 Revisit SSE view fragments handling #37061 Check list index after auto-grow in AbstractNestablePropertyAccessor #37036 Disable SpEL expression compilation by default in SimpleEvaluationContext #37035 Limit result size of BigDecimal / BigInteger power operations in SpEL #37034 Refactor redirect handling in UrlHandlerFilter #37030 Revise stylesheet source handling in XsltView #37029 Revise view name handling in UrlFilenameViewController #37027 Handle pre-flight requests in functional endpoint setup without DispatcherHandler #37024 Improve WebSocket handshake error logging #37023 Fix missing nullability in JdbcTemplate.batchUpdate #37012 Timeout property in RetryPolicy does not have a default constant #36983 Write native configuration files as UTF-8 #36972 DefaultServerRequest.ServletParametersMap.entrySet() does not retain HttpServletRequest.getParameterMap() order #36966 Perform nextKey within synchronization for SQLite as well #36959 Add support for custom ObjectInputFilter on DefaultDeserializer #36958 Revise resource bundle caching for common locales #36957 Improve nullability for getSession(*) in MockHttpServletRequest #36926 Improve fallback logic in ParameterContentNegotiationStrategy and ParameterContentTypeResolver #36925 Improve ambiguous match check on preflight request #36903 Improve Groovy markup template loading #36902 Improve request path handling on a Reactor Netty server #36893 Improve JettyWebSocketSession error handling #36891 🐞 Bug Fixes EclipseLinkJpaDialect singleton lock in EclipseLinkConnectionHandle.getConnection() serializes all JDBC connection acquisitions under load #37085 MetadataReader fails to read byte[] array from annotation #37083 Ensure parsing/tostring symmetry in ContentDisposition #37064 Character outside of permitted range in Content Disposition #37062 Release Jackson BufferRecycler to its pool in encoders #37059 Ensure consistent error escaping #37055 Refine template name processing #37054 Reset TwoByteMatcher partial match on mismatching byte #37053 Refactor async XML parsing limit checks #37031 Fix part constraint checks in PartEventHttpMessageReader #37028 Fix buffer leak in RSocket SETUP frame handling #37026 Ensure correct Jetty core response cookie handling #37025 Align domainToAscii with current WhatWG spec #37018 Ensure consistent ButtonTag value attribute processing #37017 SpEL's InlineList is cached as a mutable list in compiled mode #37001 Write native configuration

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-2.11.55

v2.11.55

Important: Please read the migration guide . CVE fixed: Advisory GHSA-5w68-77r2-r64c Advisory GHSA-g55h-rg46-x9c5 Bug fixes: [k8s/crd] Prevent generated name collisions in the Kubernetes CRD provider ( #13656 @rtribotte ) [k8s/crd] Add an option to restrict the namespace of the default TLS resources ( #13665 @rtribotte ) [k8s/crd] Scope generated Kubernetes Service names to their parent in the CRD provider ( #13668 @rtribotte ) [k8s/crd] Add safe naming option to avoid collisions for Kubernetes CRD provider ( #13689 @gndz07 ) [k8s/gatewayapi] Fix Gateway API router rules ( #13645 @rtribotte ) [middleware, authentication] Bump github.com/containous/go-http-auth to b975dcaa8c48 ( #13636 @kevinpollet ) [tls] Add an option to disable the fallback to the default TLS options ( #13639 @rtribotte ) Bump golang.org/x dependencies ( #13699 @mmatur )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.7.11

v3.7.11

Important: Please read the migration guide . CVE fixed: Advisory GHSA-5w68-77r2-r64c Advisory GHSA-g55h-rg46-x9c5 Advisory GHSA-j994-9gqj-9hwq Advisory GHSA-m6wx-622r-48r9 Bug fixes: [fastproxy] Reject out-of-range status codes from backends when using FastProxy ( #13635 @gndz07 ) [http3] Bump github.com/quic-go/quic-go to v0.61.0 ( #13688 @jnoordsij ) [k8s/crd] Prevent generated name collisions in the Kubernetes CRD provider ( #13656 @rtribotte ) [k8s/crd] Add an option to restrict the namespace of the default TLS resources ( #13665 @rtribotte ) [k8s/crd] Scope generated Kubernetes Service names to their parent in the CRD provider ( #13668 @rtribotte ) [k8s/crd] Name failover generated services after the referenced Kubernetes Service ( #13677 @rtribotte ) [k8s/crd] Add safe naming option to avoid collisions for Kubernetes CRD provider ( #13689 @gndz07 ) [k8s/gatewayapi] Preserve encoded path segments in Gateway API URLRewrite and RequestRedirect ( #13641 @gndz07 ) [k8s/gatewayapi] Fix Gateway API router rules ( #13645 @rtribotte ) [k8s/ingress-nginx] Dedupe client-auth TLS options across ingresses sharing a host for ingress-nginx provider ( #13638 @gndz07 ) [k8s/ingress-nginx] Apply auth, custom-headers, custom errors and ssl-redirect to ingress default backend ( #13575 @rtribotte ) [k8s/ingress-nginx] Honor asDefault and exclude internal entrypoints from default selection for ingress-nginx provider ( #13629 @gndz07 ) [k8s/ingress] Enforce crossProviderNamespace for Kubernetes Ingress service middleware ( #13670 @gndz07 ) [middleware, authentication] Bump github.com/containous/go-http-auth to b975dcaa8c48 ( #13636 @kevinpollet ) [tls] Add an option to disable the fallback to the default TLS options ( #13639 @rtribotte ) Bump golang.org/x dependencies ( #13699 @mmatur ) Documentation: [accesslogs] Clarify OriginStatus and DownstreamStatus in access logs documentation ( #13609 @rtribotte ) [api] Fix doubled word in API/dashboard reference docs ( #13663 @latent-9 ) [docker] Remove :ro from docker.sock ( #12656 @bluepuma77 ) [k8s/gatewayapi] Clarify v3.7.10 migration guide for Gateway API 1.6.1 ( #13628 @rtribotte ) [k8s/gatewayapi] Document the Experimental Channel CRDs requirement of the Kubernetes Gateway provider ( #13634 @rtribotte ) [k8s/ingress-nginx] Docs: Update supported server snippet directives ( #13687 @rtsui-harmonicinc) [middleware] Add rejectStatusCode to the ipAllowList middleware configuration example ( #13664 @amazon7737 ) [middleware] Mark the errors middleware service option as required ( #13684 @lazerg ) [tls] Document the TLS options conflict resolution ( #13640 @rtribotte ) [tls] Clarify router TLS replaces entrypoint TLS ( #13630 @sornapudisuresh ) Document Redis keyspace notifications requirement ( #13691 @omkar619-dev ) Remove retired Go Report Card badge ( #13637 @yardenshoham ) Restore the systemd socket activation documentation ( #13701 @lazerg ) Update version support policy starting with v3.6 ( #13627 @nmengin )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.5

v3.6.0-rc.5

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-9.5.2

Beats 9.5.2

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats\#beats-9.5.2-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OVENBUN-1.4

Bun v1.4

To install Bun v1.4 curl -fsSL https://bun.com/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.com/install.ps1|iex " To upgrade to Bun v1.4.0: bun upgrade Read the blog post : Thank you Bun is free, open source, and MIT-licensed. We receive a lot of contributions from the community, and we'd like to thank everyone who fixed a bug or contributed since Bun v1.3. @190n @alanstott @alii @alinalihassan @amdad121 @ant-kurt @anthonybaldwin @avarayr @baboon-king @billywhizz @bmwalters @Boshen @braden-w @c-stoeckl @carlsmedstad @chrislloyd @cirospaciari @coleleavitt @connerlphillippi @crishoj @csvlad @d4mr @darwin808 @ddmoney420 @dioro @djs5008 @dylan-conway @Elfayer @emwadde @eroderust @fraidev @franklinfollis @gameroman @gaowhen @halil-pan @hamidrezahanafi @HK-SHAO @Hona @hoXyy @ig-ant @igorkofman @jackkleeman @Jarred-Sumner @jsparkdev @kirillmarkelov @kjanat @km-anthropic @kylekz @ldkhang1201 @Lillious @lydiahallie @makuko @mariusz4044 @markovejnovic @martinamps @mattermoran @MiniGod @mippbipp @mmitchellg5 @nathanosoares @nektro @nfreya @NicoCevallos @nkxxll @ocodista @paperclover @pfgithub @prekucki @rekram1-node @remorses @RiskyMH @robjtede @RyanGst @shendongming @ShlomoCode @sosukesuzuki @sqdshguy @ssing2 @Tamicktom @taylordotfish @vadim-anthropic @veggiesaurus @WhiteMinds @xingxingmofashu @yinheli @zackradisic @brunorodmoreira @pxseu

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-9.5.2

Elasticsearch 9.5.2

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.5.2-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.34.11

v1.34.11

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.35.8

v1.35.8

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.36.4

v1.36.4

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.37.0-RC.1

v1.37.0-rc.1

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICLOGSTASH-9.5.2

Logstash 9.5.2

Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.5.2-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →