Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT

VERIFIED PUBLISHER INTELLIGENCE

Release notes and known issues

Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.

85 official publisher sources registered · 83 collected automatically · 0 monitored for availability · 2 requires publisher access

1898 verified publisher records · Page 16 of 19

BROADCOMSPRING-BOOT-4.0.8

v4.0.8

🐞 Bug Fixes Kafka consumer-specific security protocol is not taken into account #51365 Temporary file is not deleted when ExportedImageTar construction fails #51117 spring-boot-h2-console pulls servlet-api as transitive dependency #51094 Methods that return the result of Map#remove are not declared with a @Nullable return type #50972 PropertiesLauncher does not log nested archive paths #50968 JarFile is not closed when finding main class from archive #50949 CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50928 Resources are not cleaned up when resolving an image that is not yet present in the builder #50919 Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50916 GraphQlWebMvcAutoConfiguration should apply customizers in order #50908 Micrometer registries pin the application context #50886 Context refresh fails when using Actuator on Jersey without spring-boot-health #50858 Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50857 IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50798 Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50781 Application-managed JUL bridge handler should only be removed if installed #50779 Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50755 PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50737 High number of connections due to Mongo health indicator #50734 Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50701 NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50433 Fix ordering of Kotlinx Serialization CodecCustomizer #50428 Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #50096 📔 Documentation spring.profiles.group should have a 'spring-profile-name' hint provider #51273 Remove reference to removed InfluxDB auto-configuration #51172 Use JacksonJsonSerde in Kafka Streams documentation #51152 Document alternatives to HttpMessageConverters #51124 Caching documentation refers to AutoConfigureCache by its pre-4.0 package #51111 Metadata for spring.test.mockmvc.htmlunit.url declares the wrong type #51110 Fix examples in Metadata Format documentation chapter #51097 Improve discoverability of the AOT Cache How-to guides #50996 Table of auto-configured HealthIndicators lists the wrong key for MongoHealthIndicator #50931 Update OpenTelemetryResourceAttributes documentation #50867 Fix @Value placeholder syntax in external config docs #50859 Refer to spring-boot-starter-webmvc, not deprecated spring-boot-starter-web #50842 Fix forwarded headers property in cloud deployment docs #50841 Fix duplicate word typos in documentation #50738 🔨 Dependency Upgrades Upgrade to CycloneDX Maven Plugin 2.9.3 #51178 Upgrade to DB2 JDBC 12.1.5.0 #50977 Upgrade to Elasticsearch Client 9.2.9 #51366 Upgrade to Groovy 5.0.8 #51179 Upgrade to Hibernate 7.2.24.Final #51180 Upgrade to Jackson 2 Bom 2.21.5 #50980 Upgrade to Jackson Bom 3.1.5 #50981 Upgrade to Jetty 12.1.12 #51298 Upgrade to jOOQ 3.19.37 #51299 Upgrade to JSpecify 1.0.1 #51181 Upgrade to Log4j2 2.25.5 #50984 Upgrade to Logback 1.5.38 #50985 Upgrade to MariaDB 3.5.10 #51182 Upgrade to Maven Help Plugin 3.5.2 #50987 Upgrade to Micrometer 1.16.7 #51235 Upgrade to Micrometer Tracing 1.6.7 #51236 Upgrade to Netty 4.2.17.Final #51300 Upgrade to Postgresql 42.7.13 #50989 Upgrade to R2DBC MariaDB 1.3.1 #50990 Upgrade to R2DBC MSSQL 1.0.5.RELEASE #50991 Upgrade to R2DBC MySQL 1.4.3 #51183 Upgrade to R2DBC Postgresql 1.1.2.RELEASE #50992 Upgrade to Reactor Bom 2025.0.7 #51237 Upgrade to Spring AMQP 4.0.5 #51238 Upgrade to Spring Batch

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-BOOT-4.1.1

v4.1.1

⚠️ Attention Required Spring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the protobuf extension with the grpc plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of protoc-gen-grpc-java as before. #50822 🐞 Bug Fixes Kafka consumer-specific security protocol is not taken into account #51369 Structured logging: a failed JSON encode corrupts the next log event written on the same thread #51156 Micrometer registries pin the application context #51135 Temporary file is not deleted when ExportedImageTar construction fails #51132 Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #51098 spring-boot-h2-console pulls servlet-api as transitive dependency #51095 PropertiesLauncher does not log nested archive paths #51089 Methods that return the result of Map#remove are not declared with a @Nullable return type #51087 NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50964 Fix ordering of Kotlinx Serialization CodecCustomizer #50961 JarFile is not closed when finding main class from archive #50959 Application-managed JUL bridge handler should only be removed if installed #50950 CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50944 Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50942 Resources are not cleaned up when resolving an image that is not yet present in the builder #50941 GraphQlWebMvcAutoConfiguration should apply customizers in order #50914 Auto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true #50884 Context refresh fails when using Actuator on Jersey without spring-boot-health #50872 Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50871 IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50856 High number of connections due to Mongo health indicator #50852 Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50849 Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50845 PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50843 Exposing gRPC test server port should backoff if gRPC is not present #50825 JpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor #50801 spring.grpc.server.health.include-overall-health is not taken into account #50799 Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50790 Managed version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus #50780 Map properties bound from empty strings fail with ConverterNotFoundException #50773 Protobuf Common Protos should not be a managed dependency #50772 An application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not #50764 W3CHeaderParser's decoding is not compliant with RFC 3986 #50650 📔 Documentation Description of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide #51348 spring.profiles.group should have a 'spring-profile-name' hint provider #51284 Remove reference to removed InfluxDB auto-configuration #51176 Use JacksonJsonSerde in Kafka Streams documentation #51161 Document alternatives to HttpMessageConverters #51129 Fix stale type reference for OTLP logging transport metadata #51119 Metadata for spri

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-7.0.9

v7.0.9

⚠️ Attention Required In Spring Framework 7.0.9, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090 In Spring Framework 7.0.9, SimpleEvaluationContext no longer supports expression compilation by default, regardless of the compiler mode configured via SpelParserConfiguration or the spring.expression.compiler.mode system property or Spring property. Applications that intentionally use SimpleEvaluationContext with trusted expressions and require compilation for performance reasons can opt in by calling withCompilationSupported() on the SimpleEvaluationContext builder. Care should be taken when opting in to compilation, as doing so removes the safety guards applied during interpreted evaluation. #37035 ⭐ New Features Ignore an empty port value in URI parsing #37117 Avoid retaining class files in annotation metadata #37112 Add @Nullable annotations when treating Map.remove() as returning @Nullable #37067 Revisit SSE view fragments handling #37061 Check list index after auto-grow in AbstractNestablePropertyAccessor #37036 Disable SpEL expression compilation by default in SimpleEvaluationContext #37035 Limit result size of BigDecimal / BigInteger power operations in SpEL #37034 Refactor redirect handling in UrlHandlerFilter #37030 Revise stylesheet source handling in XsltView #37029 Revise view name handling in UrlFilenameViewController #37027 Handle pre-flight requests in functional endpoint setup without DispatcherHandler #37024 Improve WebSocket handshake error logging #37023 Fix missing nullability in JdbcTemplate.batchUpdate #37012 Timeout property in RetryPolicy does not have a default constant #36983 Write native configuration files as UTF-8 #36972 DefaultServerRequest.ServletParametersMap.entrySet() does not retain HttpServletRequest.getParameterMap() order #36966 Perform nextKey within synchronization for SQLite as well #36959 Add support for custom ObjectInputFilter on DefaultDeserializer #36958 Revise resource bundle caching for common locales #36957 Improve nullability for getSession(*) in MockHttpServletRequest #36926 Improve fallback logic in ParameterContentNegotiationStrategy and ParameterContentTypeResolver #36925 Improve ambiguous match check on preflight request #36903 Improve Groovy markup template loading #36902 Improve request path handling on a Reactor Netty server #36893 Improve JettyWebSocketSession error handling #36891 🐞 Bug Fixes EclipseLinkJpaDialect singleton lock in EclipseLinkConnectionHandle.getConnection() serializes all JDBC connection acquisitions under load #37085 MetadataReader fails to read byte[] array from annotation #37083 Ensure parsing/tostring symmetry in ContentDisposition #37064 Character outside of permitted range in Content Disposition #37062 Release Jackson BufferRecycler to its pool in encoders #37059 Ensure consistent error escaping #37055 Refine template name processing #37054 Reset TwoByteMatcher partial match on mismatching byte #37053 Refactor async XML parsing limit checks #37031 Fix part constraint checks in PartEventHttpMessageReader #37028 Fix buffer leak in RSocket SETUP frame handling #37026 Ensure correct Jetty core response cookie handling #37025 Align domainToAscii with current WhatWG spec #37018 Ensure consistent ButtonTag value attribute processing #37017 SpEL's InlineList is cached as a mutable list in compiled mode #37001 Write native configuration

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-2.11.55

v2.11.55

Important: Please read the migration guide . CVE fixed: Advisory GHSA-5w68-77r2-r64c Advisory GHSA-g55h-rg46-x9c5 Bug fixes: [k8s/crd] Prevent generated name collisions in the Kubernetes CRD provider ( #13656 @rtribotte ) [k8s/crd] Add an option to restrict the namespace of the default TLS resources ( #13665 @rtribotte ) [k8s/crd] Scope generated Kubernetes Service names to their parent in the CRD provider ( #13668 @rtribotte ) [k8s/crd] Add safe naming option to avoid collisions for Kubernetes CRD provider ( #13689 @gndz07 ) [k8s/gatewayapi] Fix Gateway API router rules ( #13645 @rtribotte ) [middleware, authentication] Bump github.com/containous/go-http-auth to b975dcaa8c48 ( #13636 @kevinpollet ) [tls] Add an option to disable the fallback to the default TLS options ( #13639 @rtribotte ) Bump golang.org/x dependencies ( #13699 @mmatur )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.7.11

v3.7.11

Important: Please read the migration guide . CVE fixed: Advisory GHSA-5w68-77r2-r64c Advisory GHSA-g55h-rg46-x9c5 Advisory GHSA-j994-9gqj-9hwq Advisory GHSA-m6wx-622r-48r9 Bug fixes: [fastproxy] Reject out-of-range status codes from backends when using FastProxy ( #13635 @gndz07 ) [http3] Bump github.com/quic-go/quic-go to v0.61.0 ( #13688 @jnoordsij ) [k8s/crd] Prevent generated name collisions in the Kubernetes CRD provider ( #13656 @rtribotte ) [k8s/crd] Add an option to restrict the namespace of the default TLS resources ( #13665 @rtribotte ) [k8s/crd] Scope generated Kubernetes Service names to their parent in the CRD provider ( #13668 @rtribotte ) [k8s/crd] Name failover generated services after the referenced Kubernetes Service ( #13677 @rtribotte ) [k8s/crd] Add safe naming option to avoid collisions for Kubernetes CRD provider ( #13689 @gndz07 ) [k8s/gatewayapi] Preserve encoded path segments in Gateway API URLRewrite and RequestRedirect ( #13641 @gndz07 ) [k8s/gatewayapi] Fix Gateway API router rules ( #13645 @rtribotte ) [k8s/ingress-nginx] Dedupe client-auth TLS options across ingresses sharing a host for ingress-nginx provider ( #13638 @gndz07 ) [k8s/ingress-nginx] Apply auth, custom-headers, custom errors and ssl-redirect to ingress default backend ( #13575 @rtribotte ) [k8s/ingress-nginx] Honor asDefault and exclude internal entrypoints from default selection for ingress-nginx provider ( #13629 @gndz07 ) [k8s/ingress] Enforce crossProviderNamespace for Kubernetes Ingress service middleware ( #13670 @gndz07 ) [middleware, authentication] Bump github.com/containous/go-http-auth to b975dcaa8c48 ( #13636 @kevinpollet ) [tls] Add an option to disable the fallback to the default TLS options ( #13639 @rtribotte ) Bump golang.org/x dependencies ( #13699 @mmatur ) Documentation: [accesslogs] Clarify OriginStatus and DownstreamStatus in access logs documentation ( #13609 @rtribotte ) [api] Fix doubled word in API/dashboard reference docs ( #13663 @latent-9 ) [docker] Remove :ro from docker.sock ( #12656 @bluepuma77 ) [k8s/gatewayapi] Clarify v3.7.10 migration guide for Gateway API 1.6.1 ( #13628 @rtribotte ) [k8s/gatewayapi] Document the Experimental Channel CRDs requirement of the Kubernetes Gateway provider ( #13634 @rtribotte ) [k8s/ingress-nginx] Docs: Update supported server snippet directives ( #13687 @rtsui-harmonicinc) [middleware] Add rejectStatusCode to the ipAllowList middleware configuration example ( #13664 @amazon7737 ) [middleware] Mark the errors middleware service option as required ( #13684 @lazerg ) [tls] Document the TLS options conflict resolution ( #13640 @rtribotte ) [tls] Clarify router TLS replaces entrypoint TLS ( #13630 @sornapudisuresh ) Document Redis keyspace notifications requirement ( #13691 @omkar619-dev ) Remove retired Go Report Card badge ( #13637 @yardenshoham ) Restore the systemd socket activation documentation ( #13701 @lazerg ) Update version support policy starting with v3.6 ( #13627 @nmengin )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.5

v3.6.0-rc.5

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-9.5.2

Beats 9.5.2

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats\#beats-9.5.2-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OVENBUN-1.4

Bun v1.4

To install Bun v1.4 curl -fsSL https://bun.com/install | bash # or you can use npm # npm install -g bun Windows: powershell -c " irm bun.com/install.ps1|iex " To upgrade to Bun v1.4.0: bun upgrade Read the blog post : Thank you Bun is free, open source, and MIT-licensed. We receive a lot of contributions from the community, and we'd like to thank everyone who fixed a bug or contributed since Bun v1.3. @190n @alanstott @alii @alinalihassan @amdad121 @ant-kurt @anthonybaldwin @avarayr @baboon-king @billywhizz @bmwalters @Boshen @braden-w @c-stoeckl @carlsmedstad @chrislloyd @cirospaciari @coleleavitt @connerlphillippi @crishoj @csvlad @d4mr @darwin808 @ddmoney420 @dioro @djs5008 @dylan-conway @Elfayer @emwadde @eroderust @fraidev @franklinfollis @gameroman @gaowhen @halil-pan @hamidrezahanafi @HK-SHAO @Hona @hoXyy @ig-ant @igorkofman @jackkleeman @Jarred-Sumner @jsparkdev @kirillmarkelov @kjanat @km-anthropic @kylekz @ldkhang1201 @Lillious @lydiahallie @makuko @mariusz4044 @markovejnovic @martinamps @mattermoran @MiniGod @mippbipp @mmitchellg5 @nathanosoares @nektro @nfreya @NicoCevallos @nkxxll @ocodista @paperclover @pfgithub @prekucki @rekram1-node @remorses @RiskyMH @robjtede @RyanGst @shendongming @ShlomoCode @sosukesuzuki @sqdshguy @ssing2 @Tamicktom @taylordotfish @vadim-anthropic @veggiesaurus @WhiteMinds @xingxingmofashu @yinheli @zackradisic @brunorodmoreira @pxseu

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-9.5.2

Elasticsearch 9.5.2

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.5.2-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.34.11

v1.34.11

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.35.8

v1.35.8

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.36.4

v1.36.4

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KUBERNETESKUBERNETES-1.37.0-RC.1

v1.37.0-rc.1

See kubernetes-announce@ . Additional binary downloads are linked in the CHANGELOG . See the CHANGELOG for more details.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICLOGSTASH-9.5.2

Logstash 9.5.2

Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.5.2-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
BROADCOMSPRING-FRAMEWORK-7.1.0-M1

v7.1.0-M1

⚠️ Attention Required starting in Spring Framework 7.1, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each require a boolean argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property enables use of "X-Forwarded-Prefix" if needed. The default constructor with the existing behaviour of checking both types of headers is still available but deprecated and marked for removal. The new constructor makes forwarded header processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section, as well as related changes in Spring Boot spring-projects/spring-boot#51030 . #37072 Default context config is not detected when superclass or enclosing class is not annotated with @ContextConfiguration #31456 ⭐ New Features Add logging operators in DefaultExchangeFunction only when debug is enabled #37095 Consistently enforce non-null instance in AbstractFactoryBean #37091 Reinstate invalid resource location checks #37063 Preserve original bean names as aliases with FullyQualifiedConfigurationBeanNameGenerator #37038 Improve forwarded header parsing #36964 Avoid "NullAway.Init" suppression in favor of explicit field handling #36961 Refine and better specify error handling in MultipartParser #36947 Use double division to calculate applied jitter in ExponentialBackOff #36943 Throw ClassNotFoundException for missing class resource in ThrowawayClassLoader #36938 Replace isAssignableFrom() with isInstance() where feasible #36899 Simplify BUFFER_COUNT in ConcurrentLruCache to a constant #36872 Apply auto-grow collection limit to direct field binding #36862 Reject duplicate MIME type parameters #36841 Add DataSize converters to DefaultConversionService #36830 Only update ObservationThreadLocalAccessor when a test has an active ApplicationContext #36817 Deprecate setDisallowedFields in DataBinder for removal #36816 Optimize ClassNameReader.getClassName via direct ASM API #36814 AbortedException from client logged at ERROR level with WebFlux functional endpoint #36811 Add dedicated exception for HttpStatus.PRECONDITION_FAILED #36807 Reset mocks only when a test has an active ApplicationContext #36782 Improve MimeType parser for RFC compliance #36729 Reject unsafe static resource locations in MVC and WebFlux #36695 Use String#replace instead of String#replaceAll where appropriate #36678 Beans created with BeanRegistrar on GenericApplicationContext do not honor allow-bean-definition-overriding setting #36648 Use defensive Date copies for SimpleMailMessage sentDate #36626 Align StandardMethodMetadata with ASM/ClassFile support for getReturnTypeName() #36619 Use canonical names in error messages in annotation processing #36607 Provide bean conditional registration capabilities in BeanRegistrarDsl #36601 Align with JDK behavior by throwing TypeNotPresentException during annotation processing #36593 Deprecate RestTemplate and related types #36574 Remove deprecated methodIdentification() method in CacheAspectSupport #36560 Reject unbalanced parentheses in profile expressions #36550 Introduce ResolvableType.forParameter() factory method #36545 Remove redundant Assert.notNull() checks in ResolvableType #36544 Introduce support for custom parameter names in ParameterResolutionDelegate #36534 Perform case-insensitive lookup in HttpMethod.valueOf() #36518 Add "application/jsonl" support alongside "application/x-ndjson" for streaming #36485 Replace HandlerMappingIntrospector with PreFlightRequestHandler bean in MVC config #36481 GenericTypeResolver.resolveType should resolve TypeVariable with nested ParameterizedType #36480 Introduce classpath*: support for ResourceLoader#getResource with fully specified resource path #36415 Support for Map body types in FormHttpMessageConverter #36408 Support compilation of SpEL expressions that use Optional with null-safe and Elvis operators #36330 Skip Jaxb auto-detection in Http

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-25.14

[release-branch.go1.25] go1.25.14

Change-Id: I9e3fddf67829ff8d68e49f38b44e298327d554db Reviewed-on: https://go-review.googlesource.com/c/go/+/817740 Reviewed-by: Dmitri Shuralyov dmitshur@google.com Reviewed-by: Carlos Amedee carlos@golang.org Auto-Submit: Gopher Robot gobot@golang.org TryBot-Bypass: Gopher Robot gobot@golang.org

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-26.7

[release-branch.go1.26] go1.26.7

Change-Id: Ia3e132d4c983f77f720a01d12ff0222a39d03c18 Reviewed-on: https://go-review.googlesource.com/c/go/+/817760 TryBot-Bypass: Gopher Robot gobot@golang.org Reviewed-by: Carlos Amedee carlos@golang.org Auto-Submit: Gopher Robot gobot@golang.org Reviewed-by: Dmitri Shuralyov dmitshur@google.com

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-27.0

[release-branch.go1.27] go1.27.0

Change-Id: I9ff6bc81cccdd7876e7b36c395151f70ab3ac654 Reviewed-on: https://go-review.googlesource.com/c/go/+/817701 Reviewed-by: Carlos Amedee carlos@golang.org Auto-Submit: Gopher Robot gobot@golang.org TryBot-Bypass: Gopher Robot gobot@golang.org Reviewed-by: Dmitri Shuralyov dmitshur@google.com

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-13.2.0

13.2.0

Download page What's new highlights Security CVE-2026-17183 Features and enhancements Alerting: Add Import tab in alerting settings page #129051 , @rodrigopk Alerting: Add notification template import to the import-to-GMA wizard #128329 , @rodrigopk Alerting: Add promote and auto sync to ImportToGMAWizard #126907 , @rodrigopk Alerting: Add staged configuration summary in import settings page #129204 , @rodrigopk Alerting: Compute staged config origin server-side #130727 , @rodrigopk Alerting: Migrate notifications API to v1beta1 #124702 , @rodrigopk Alerting: Recognize "default" and "user-defined" as the default routing tree (1/4) #127880 , @rodrigopk Alerting: Recognize "default" and "user-defined" as the default routing tree (2/4) #127881 , @rodrigopk Alerting: Recognize "default" and "user-defined" as the default routing tree (3/4) #127883 , @rodrigopk Alerting: Recognize "default" and "user-defined" as the default routing tree (4/4) #127884 , @rodrigopk Alerting: Return 403 instead of 500 on contact point provenance mismatch #127699 , @rwwiv Alerting: Revert a staged import configuration #129243 , @rodrigopk Alerting: Show unusable time intervals as disabled in the mute timings selector #130323 , @rodrigopk Alerting: Track import method analytics in import to gma #128142 , @rodrigopk Alerting: remove AlertingCentralHistory FT #130164 , @konstantinmv Analytics: Add public dashboard UID to loki usage insights events (Enterprise) Auditing: Record the user name on user deletion audit logs (Enterprise) Azure Monitor: Cache subscription lookups and collapse double Unmarshal in buildQuery #123556 , @adamyeats Azure monitor: Azure Metrics Batch API Implementation backend #123696 , @bossinc CloudWatch Logs: Add frontend support for querying by data source #123742 , @kevinwcyu ColorScale: Remove live hoverValue, remove from HeatMap tooltip #128812 , @leeoniya DashList: Show dashboard description tooltip when it's available #130006 , @DeeGeeGit Dashboard: redirect from dashboard settings tabs to sidebar counterparts #125966 , @bfmatei Dashboards: Allow threshold interpolation #128451 , @mdvictor Dashboards: Deprecate scripted dashboards and disable them by default #130207 , @kristinademeshchik Dashboards: Enable new view panel controls by default #129187 , @torkelo Dashboards: Increase nesting depth to 4 and allow nested tabs #129174 , @bfmatei Dashboards: Show panel query errors and notices in one UI #127436 , @mdvictor Developer Guide: Add note about requiring signed commits #127162 , @gelicia Docs: document the tracing file exporter #129339 , @leandro-deveikis Explore Logs: log line highlight color lighten in dark, update deprecated pinned color #130516 , @L2D2Grafana Folder API: Replace legacy access control logic with app platform API call #125642 , @aocenas Go: Update version to 1.26.5 #128011 , @macabu GrafanaUI: Add real magnification effect to GrotNotFound lens #130118 , @xndcn Home: Enable unified homepage for all users (remove flag) #129054 , @MattIPv4 Live: Support redis:// and rediss:// (TLS) connection URLs in ha_engine_address #129938 , @DeeGeeGit Logs: Add more suggested fields and integrate with the new Logs Table #128002 , @matyax Logs: use gray (dimgray) for debug level color #129896 , @L2D2Grafana Plugins: Force TLS 1.3 feature toggle #130390 , @aangelisc Provisioning (enterprise): (4/8) Add OAuth app connections for GitLab and Bitbucket (Enterprise) Provisioning: Add Dashboard Previews to GitHub Enterprise #127614 , @floriecai Provisioning: Add Github Enterprise frontend #127209 , @floriecai Provisioning: Add filter for out-of-sync resources in Resources tab #128456 , @MissingRoberto Provisioning: Add option to author commits as the signer #127970 , @amalavet Provisioning: Add resource kind icons to job summary table #127237 , @MissingRoberto Provisioning: Add webhook support for GithubEnterprise (Enterprise) Provisioning: Allow overriding the Git Sync commit author #130547 , @amalavet Provisioning: Attribute job

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.568.3

2.568.3 RC

Please report any issues found to the release candidate announcement thread. The final release is scheduled for September 2nd, 2026 . Download the release from the artifact repository After the final release, the official changelog and official upgrade guide will be available on www.jenkins.io/download .

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KEYCLOAKKEYCLOAK-26.7.2

26.7.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [ CVE-2026-14613 ] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [ CVE-2026-59888 and CVE-2026-59889 ] Upgrade jackson-databind to 2.21.5 to fix #50966 [ CVE-2026-15945 ] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions #51145 [ CVE-2026-17048 ] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass Weaknesses #50844 show-config prints the vault keystore password in cleartext dist/quarkus Enhancements #51344 Upgrade to Quarkus 3.33.3.1 Bugs #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication #50849 Correct SCIM name.formated scim #50855 Rotated client secret remains valid when the feature is disabled oidc #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn #51088 Verify email not working in incognito browser tab after Keycloak restart authentication #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan #51164 WebAuthn tests are being skipped in Github workflows workflows #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 dist/quarkus #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac #51331 Adding org member fails with 500 with stateless:v1 feature enabled organizations #51407 The dist for Java API docs is empty docs #51449 Incorrect query parameter name for "max" #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt docs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
NGINXNGINX-1.31.4

release-1.31.4

nginx-1.31.4 mainline version has been released. See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Xslt: xmlCreatePushParserCtxt() error handling by @VadimZhestikov in #1565 Image filter: bounded size parser reads by received data by @VadimZhestikov in #1574 Updated security policy report methods by @pluknet in #1586 Autoindex: use temporary pool for directory entries by @Srujan-rai in #1311 Perl: fixed $r->print() zero copy with mutable scalars by @devnexen in #1581 Events: validate descriptor before FD_SET() by @sbhowmikf5 in #1598 Format specifier fixes in error logging by @nishat-06 in #1592 GH: restrict the mark_stale job to nginx/nginx by @aminvakil in #1605 QUIC: apply stream flow control to RESET_STREAM final_size by @arut in #1612 Script: improved compatibility of complex value codes by @bavshin-f5 in #1601 gRPC: narrowed special handling of "trailer only" responses by @vinaykumar-1591 in #1591 Fixed overflow detection in chunked parser by @pluknet in #1625 Upstream: special handling of the "Host" header in HTTP and gRPC by @arut in #1593 Upstream: reject zero WINDOW_UPDATE increments by @felix314159 in #1622 Core: added data model and JSON serialization libraries by @hyuan-netizen in #1569 Upstream: fixed MSVC compilation after dea68db by @VadimZhestikov in #1635 Upstream: reserved padding in state structures. by @dplotnikov-f5 in #1631 Stream: PROXY protocol version 2 upstream write support by @VadimZhestikov in #1204 New Contributors @Srujan-rai made their first contribution in #1311 @nishat-06 made their first contribution in #1592 @aminvakil made their first contribution in #1605 @felix314159 made their first contribution in #1622 Full Changelog : release-1.31.3...release-1.31.4

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.15.9

v1.15.9

1.15.9 (August 19, 2026) BUG FIXES: validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. ( list , import , backend , and cloud ) ( #38994 ) NOTES: Update go-slug to v0.18.3 to mitigate CVE-2026-14978 , which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run ( #39036 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPTERRAFORM-1.16.0-RC2

v1.16.0-rc2

1.16.0-rc2 (August 19, 2026) NEW FEATURES: Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. ( #37986 ) terraform_data : The new store block can hold ephemeral and sensitive values across plan and apply. ( #38298 ) Providers can now use nested blocks as computed values ( #38305 ) import: import blocks inside modules are now supported. ( #38352 ) Terraform is now available as a pre-built binary for Linux s390x (zLinux). ( #38384 ) Resource action triggers can now use on_failure modes of halt , taint , or continue . ( #38722 ) ENHANCEMENTS: state show: The state show command can now produce machine-readable output when supplied with the -json flag ( #23940 ) workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag ( #38397 ) test: Terraform now reports which resources were left behind when skip_cleanup is set. ( #38449 ) stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. ( #38668 ) Actions can now use before_destroy and after_destroy events. ( #38668 ) cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. ( #38715 ) policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init , plan , and apply , rather than requiring the plugin to read credentials itself. ( #38716 ) graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. ( #38719 ) Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. ( #38778 ) Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. ( #38784 ) The contains() function can now test for null values. ( #38792 ) console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. ( #31861 ) -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. ( #38845 ) The terraform stacks command now automatically infers the target hostname from the local credentials file ( credentials.tfrc.json ) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set ( #38896 ) BUG FIXES: import blocks now correctly respect provider local names. ( #38338 ) terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. ( #38586 ) workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. ( #38594 ) test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. ( #38603 ) init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override . ( #38634 ) init: Terraform now warns when unmanaged providers are in use and may impact provider installation. ( #38656 ) Actions are now invoked with respect to all resource dependencies. ( #38668 ) Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. ( #38782 ) The merge() function no longer panics when passed null objects. ( #38792 ) Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid ( #38894 ) test: Optional ephemeral values do not have to be set at plan time ( #38974 ) NOTES: init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. ( #38561 ) UPGRADE NOTES: bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. ( #38318 ) P

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-C0BE4B653CDAF9B4

WordPress 7.1 “Mary Lou”

WordPress 7.1, “Mary Lou,” is here—celebrating the pioneering jazz pianist, composer, and arranger Mary Lou Williams and her spirit of reinvention and collaboration. This release brings a more flexible, responsive, and collaborative WordPress experience, with new responsive styling controls, a redesigned media editor, richer Notes with mentions and inline feedback, improved image processing, and new Playlist and Tabs blocks.

Published 19 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-13.1.4

13.1.4

Download page What's new highlights Security CVE-2026-17183 Bug fixes Reporting: batch dashboard lookups when listing reports (Enterprise)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-0.11.0

operator: v0.11.0

0.11.0 (2026-08-18) ⚠ BREAKING CHANGES Remove support for experimental LogQL variants() queries ( #23823 ) Features operator: Enable multi-variant queries ( #21009 ) ( 709e318 ) operator: Support private VPC S3 endpoints in endpoint validation ( #22395 ) ( 394caef ) operator: Watch object storage Services for NetworkPolicy updates and surface ports in status ( #22436 ) ( 12822d5 ) Remove support for experimental LogQL variants() queries ( #23823 ) ( 132e5f9 ) Bug Fixes operator: Move telemetry recording rules to OpenShift bundle ( #22814 ) ( 4632368 ) operator: Release leader lease on shutdown so upgrades are faster ( #24042 ) ( ee0d59d ) operator: Use ruler remote_write clients key instead of deprecated client ( #23455 ) ( f5ddb02 ) security/UNKNOWN/operator: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (main) ( #23608 ) ( e1e4e0e ) security/UNKNOWN/operator: Update module golang.org/x/net to v0.56.0 [SECURITY] (main) ( #23388 ) ( 9362a5e ) security/UNKNOWN/operator: Update module golang.org/x/text to v0.39.0 [SECURITY] (main) ( #23389 ) ( 50589e1 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.578

2.578

This is an automatically generated changelog draft for Jenkins weekly releases. See https://www.jenkins.io/changelog/2.578/ for the official changelog for this release. No notable changes in this release.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSPROMETHEUS-3.14.0

3.14.0 / 2026-08-17

[CHANGE] API: Deprecate the stats query parameter of /api/v1/query and /api/v1/query_range for values other than true and all . Other values still enable basic statistics but now return a deprecation warning; they will be rejected in the next major release. #19124 [CHANGE] API: /api/v1/status/config now correctly shows separator: "" and replacement: "" in relabel configs when explicitly set to empty, instead of omitting them. #18653 [CHANGE] Discovery/Hetzner: Drop the __meta_hetzner_datacenter label for hcloud targets, following its removal from the Hetzner Cloud API. #19269 [CHANGE] PromQL: Enable duration expressions by default. The promql-duration-expr feature flag is now a no-op. #19033 [CHANGE] PromQL: Promote first_over_time to stable. It no longer requires the promql-experimental-functions feature flag. #19093 [FEATURE] Discovery: Add Oracle Cloud Infrastructure compute service discovery ( oci_sd_configs ). #18919 [FEATURE] PromQL: Add experimental start_timestamp(instant-vector) function returning the start timestamp of each sample in the given vector. Requires the use-start-timestamps feature flag. #19089 [FEATURE] PromQL: Allow rate() and increase() to use start timestamps as an alternative for rate extrapolation. Hidden behind the use-start-timestamps feature flag. #18619 [FEATURE] TSDB: Add experimental support for encoding start timestamps in histograms and float histograms. Hidden behind the histograms-st-encoding feature flag. #18609 [ENHANCEMENT] OTLP: Emit a warning when OTLP attribute names collide into the same Prometheus label after sanitization (e.g. k8s.pod.name and k8s_pod_name both become k8s_pod_name ), and expose the prometheus_api_otlp_translation_warnings_total counter labelled by category to track such warnings. #18957 [ENHANCEMENT] Promtool: Add --remote-write.path flag to push metrics for backends that use a non-default remote-write endpoint. #19086 [ENHANCEMENT] Remote write: Forward histogram start timestamps in the remote write V2 protocol. #18903 [ENHANCEMENT] TSDB: Add prometheus_tsdb_head_native_histogram_series and prometheus_tsdb_head_native_histogram_buckets gauges tracking the number of native histogram series and buckets in the head. #19170 [ENHANCEMENT] UI: Add syntax highlighting, autocompletion, and linting for PromQL duration expressions ( step() , range() , min_of() , max_of() ) in range selectors and subqueries. #18625 [ENHANCEMENT] UI: Add copy button next to rule names on the Rules and Alerts pages. #18706 [ENHANCEMENT] UI: Improve rule group title contrast on the Rules page. #19181 [PERF] Speed up regex label matchers matching a set of literal values (e.g. {job=~"foo|bar|baz"} ). #18833 [PERF] Remote read: Improve remote read throughput by removing unnecessary per-write flushing. #18470 [PERF] Scrape: Parse text and OpenMetrics formats without recursion, preventing stack overflow from deeply nested or malicious exposition input. #19143 [PERF] Scrape: Reduce native histogram scrape parsing allocations by ~49%. #19282 [PERF] TSDB: Speed up queries on series with many in-memory chunks. #18300 [BUGFIX] Alerting: Fix 100% CPU usage on shutdown that could delay graceful shutdown and trigger timeout-based kills. #17859 [BUGFIX] Discovery/AWS: Stop promtool check config from making AWS metadata service (IMDS) network calls when the region field is omitted in EC2, ECS, RDS, MSK, ElastiCache, and Lightsail service discovery configs. #19037 [BUGFIX] Discovery/Docker: Set a request timeout for docker_sd and dockerswarm_sd on unix , npipe , and tcp hosts. Previously an unresponsive daemon could freeze discovery indefinitely, silently pinning targets to a stale snapshot. #19237 [BUGFIX] Discovery/Docker: Fix panic in Docker Swarm service discovery when a service runs as a plugin or network-attachment. #19102 [BUGFIX] Discovery/Docker: Fix discovery of IPv6-only containers. #18778 [BUGFIX] PromQL: Fix case-insensitive regex label matchers silently dropping matching values. #19167 [BUGFIX] P

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.5.0

v5.5.0

What's Changed ℹ️ This release overhauls image digest reconciliation to prevent unnecessary container recreation. Existing containers may be recreated the first time you run compose up after upgrading, as image digests are re-evaluated using the new logic. compose pull now honors pull_policy refresh windows ( daily , weekly , every_N ). ✨ Improvements New image digest reconciliation process by @glours & @ndeloof #14011 #14041 🐛 Fixes Fix(bridge): skip pulling default image references for build-only ser… by @ericwyles in #14010 Fix(watch): stop pruning every dangling image of the project by @glours in #14012 Fix(config): resolve service environment when computing --hash by @glours in #14002 Fix(watch): skip unreadable directories instead of failing the watch by @Endika in #13992 Fix: ignore one-off container events in up monitor by @brano-osif in #14038 Fix(bridge): validate arguments of bridge subcommands by @glours in #14003 Fix(images): tolerate containers whose image record is gone by @ndeloof in #14028 🔧 Internal Test: Set stop_signal to SIGTERM in nginx-based services by @ricardobranco777 in #13881 Chore: inline needlessly extracted single-use helpers by @ndeloof in #14048 Add ENGINE column driven by label by @nicksieger in #13959 ⚙️ Dependencies Build(deps): bump github.com/moby/moby/client from 0.5.0 to 0.5.1 by @dependabot [bot] in #13999 Build(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.4 by @dependabot [bot] in #14009 Build(deps): bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.5 by @dependabot [bot] in #14019 Build(deps): bump github.com/moby/buildkit from 0.32.1 to 0.32.2 by @dependabot [bot] in #14033 Build(deps): bump github.com/docker/buildx from 0.36.0 to 0.36.1 by @dependabot [bot] in #14034 Build(deps): bump docker/github-builder/.github/workflows/bake.yml from 1.15.0 to 1.16.0 in the docker-actions group by @dependabot [bot] in #14035 Build(deps): bump github.com/moby/go-archive from 0.3.2 to 0.3.3 by @dependabot [bot] in #14043 Build(deps): bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 by @dependabot [bot] in #14022 Build(deps): bump github.com/docker/cli from 29.6.2+incompatible to 29.7.2+incompatible by @dependabot [bot] in #14042 Build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 by @dependabot [bot] in #14008 Bump golang to version 1.26.6 by @glours in #14045 New Contributors @ericwyles made their first contribution in #14010 @Endika made their first contribution in #13992 @brano-osif made their first contribution in #14038 Full Changelog : v5.4.0...v5.5.0

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTMICROSOFT-AZURE-8C046F1AC48E01CF

[In preview] Public Preview: Azure Linux on WSL

Azure Linux on WSL is now available in Public Preview (Beta). Extending Azure Linux to the developer workstation means that teams can now:Validate behavior using production-aligned configurationsReproduce issues more reliablyReduce time spent debugging c

Published 17 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.3.5

RabbitMQ 4.3.5

RabbitMQ 4.3.5 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version The minimum supported Erlang version for this release series is 27.0 . RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes With direct reply-to , a message routed to multiple targets that resolved to the same process could be delivered to it more than once. GitHub issue: #17071 Quorum queue recovery from a recovery checkpoint could leave a part of the queue's internal state only partially initialized. GitHub issue: #17012 In clusters that run a mix of 4.2.x and 4.3.x nodes during a rolling upgrade, local quorum queue queries now fall back to the previous state machine version instead of failing. GitHub issue: #17128 A malformed AMQP 1.0 frame now results in a framing error returned to the client instead of an exception. GitHub issue: #17101 The AMQP 1.0 message parser now validates message sections more strictly and decodes certain types of arrays more efficiently. GitHub issue: #17049 Topic exchanges now limit the number of multi-segment ( # ) wildcards a binding key can use to two. The # wildcard is meant to be used as the final segment, that is, just once. GitHub issue: #17039 When connection credentials are refreshed (for example, when an OAuth 2 token is renewed), the user's tags are now updated instead of being carried over from the original state. GitHub issue: #17029 Definition import from an HTTPS endpoint no longer fails when a password-protected TLS (HTTPS) client certificate is used. Contributed by @Pyolar . GitHub issue: #16973 The AMQP 1.0 Erlang client no longer logs an exception when a link is already detached. Workloads that use short lived links could produce a substantial amount of log noise. GitHub issue: #17124 Enhancements Authentication events are now logged under a new logging category, user . Successful logins are logged at the info level, failed login attempts at the warning level. GitHub issue: #16907 CLI Tools Enhancements rabbitmqctl hash_password now supports more password hashing functions. GitHub issues: #14215 , #17108 Stream Plugin Bug Fixes A stream protocol connection can have at most 256 publishers and 256 subscriptions, a limit that comes from the protocol's wire format. Attempts to go over these limits are now rejected early with a clear error instead of failing later with an unrelated one. GitHub issue: #17123 Enhancements Before a stream client connection completes authentication and authorization (that is, before a successful open ), the server now enforces a low frame_max ceiling instead of the full configured value. The default, 8192 bytes, is high enough to accommodate realistic JWT tokens used with SASL PLAIN authentication, and mirrors a mechanism already in place for AMQP 0-9-1 connections. It can be adjusted with the new stream.initial_frame_max setting. GitHub issue: #17053 New setting: stream.max_uncompressed_sub_entry_batch_size . It bounds the declared uncompressed size of a published sub-entry batch, and defaults to 67108864 (64 MiB), the same default already used by the Java client's maxUncompressedSubEntryBatchSize . The broker and any client publishing to it should be configured with the same value. GitHub issue: #17103 Management Plugin Bug Fixes HTTP API endpoints that accept a node name, including the federation and tracing related ones, now validate that the target node is a cluster member. GitHub issues: #17106 , #17118 The management UI no longer displays certain alert messages twice. GitHub issue: #17127 Enhancements When management.credential_encryption_secret is configured, the management UI login endpoint ( POST /api/login )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
REDISREDIS-8.10.1

8.10.1

Update urgency: SECURITY : There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another pending connection A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
REDISREDIS-8.4.6

8.4.6

Update urgency: SECURITY : There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another pending connection #15478 ACL key permission bypass in SORT , GEORADIUS / GEORADIUSBYMEMBER and XREAD / XREADGROUP : the keys validated by ACL could differ from the keys the command actually accesses #14847 Out-of-bounds argv access during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g. EVAL ) with wrong arity A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Published Never · Source checked 28 Sep 2026

Release notes and known issues →
REDISREDIS-8.6.6

8.6.6

Update urgency: SECURITY : There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another pending connection #15478 ACL key permission bypass in SORT , GEORADIUS / GEORADIUSBYMEMBER and XREAD / XREADGROUP : the keys validated by ACL could differ from the keys the command actually accesses A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
REDISREDIS-8.8.2

8.8.2

Update urgency: SECURITY : There are security fixes in the release. Security fixes (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write Out-of-bounds access in TopK heap cleanup path (MOD-15410) Use-after-free in the TLS pending-data list when a command closes another pending connection #15478 ACL key permission bypass in SORT , GEORADIUS / GEORADIUSBYMEMBER and XREAD / XREADGROUP : the keys validated by ACL could differ from the keys the command actually accesses A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PROMETHEUSALERTMANAGER-0.34.0

0.34.0 / 2026-08-16

[CHANGE] notify: The reason label on alertmanager_notifications_failed_total now distinguishes authError (HTTP 401/403) and rateLimited (HTTP 429) from the generic clientError . Dashboards/alerts matching reason="clientError" for these codes must be updated. #5332 [FEATURE] Add optional templatable labels to alert routes. #5328 [FEATURE] eventrecorder: Add inhibit rule names to inhibition_muted_alert events. #5315 [FEATURE] eventrecorder: Add stdout output type. #5311 [FEATURE] silences: Add active, expired, and pending boolean filter parameters to GET /api/v2/silences to allow filtering silences by state server-side. #5406 [FEATURE] sns: Add aws external_id support in sigv4 configuration. #5157 [FEATURE] template: Add toDate and mustToDate functions. #5327 [ENHANCEMENT] doc: Add AlertmanagerClusterFailedPeers alertmanager-mixin. #5301 [ENHANCEMENT] doc: Add description for Rocketchat parameters in global config. #5181 [ENHANCEMENT] doc: Add top level tracing configuration key. #5314 [ENHANCEMENT] doc: Fix Alertmanager port in amtool config routes example. #5312 [ENHANCEMENT] eventrecorder: Add optional webhook batching. #5392 [ENHANCEMENT] notify: The discord and webex integrations now report a failure reason on alertmanager_notifications_failed_total . #5332 [ENHANCEMENT] ui: Improve responsiveness of UI when loading thousands of alerts. #5357 [BUGFIX] eventrecorder: Fixed a minor performance regression when the event recorder is enabled. #5307 [BUGFIX] msteamsv2: Inherit global proxy_url into partial http_config . #5379 [BUGFIX] webhook: Keep custom payload string values verbatim instead of reinterpreting JSON leaves that look like YAML (e.g. values ending with a colon). #5304

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARED-2026.8.0

2026.8.0

Warning Known issue: This release strips trailing slashes from requests sent to HTTP origins, which can cause redirect loops for applications that require canonical trailing-slash URLs, such as WordPress. Do not use this version; upgrade to 2026.8.2 or later. See #1717 . SHA256 Checksums: cloudflared-amd64.pkg: d7e11466bacadb0a082d792d2d24f276ed33d012e1975282bab945729df15892 cloudflared-arm64.pkg: d00a471abaa65d1425a8696a8f4a9b6bce11afee9c6679fd86a825990d09f910 cloudflared-darwin-amd64.tgz: 8719803e89e2cbec3196a285abdc3f9fa5d5aac916d5890fd6b252470a584092 cloudflared-darwin-arm64.tgz: 145790f4f8a6413f69ce08800c401bc15a2a18afcc3b5ffea0a861623566c0a9 cloudflared-fips-linux-amd64: ecebd9fba5a2ebfb05de740bab2d78f734f23c6641d244948eabd97d7dd31623 cloudflared-fips-linux-amd64.deb: 9c28c2d5ef3801353374fe7798a4accdc6872dd28d5900f410dd0d03a286747d cloudflared-fips-linux-x86_64.rpm: 4de81d3aed2e3807cc41d514038f9c2fd9882a8b1b9311aa2f4e390ebb08b02b cloudflared-linux-386: 2e156c495fa7e1badbdf99cf0a91825453cb8bcb47d773572f466ce1d6114b5b cloudflared-linux-386.deb: 20707c2a6a69747d5ad467fdf8175b8e9bffc2e912571c1dbb7f10fce5476272 cloudflared-linux-386.rpm: bb881d9dfea1a1bbd1ff72987ccebf25f54afb858820f88c0c98bca7ad41e43a cloudflared-linux-aarch64.rpm: ae718ca4b79b94a03891b130bc91fdead991462cf9e7c67cf3a1a4899d45bfc3 cloudflared-linux-amd64: 14ecae0dd17ba74f8055e22b8f5b5acc3cbb5a9c3be4e7d6507fe1c4eadaea95 cloudflared-linux-amd64.deb: 81b5cd625beae2b64e025073402a69c0e8571aeda45a1f4726e33adab3e5824d cloudflared-linux-arm: e5853ce169323c10be2fff3fc810e860ead5ab8ee36b8b77268e6c6fbc9ba738 cloudflared-linux-arm.deb: fb88281753b5ff40f39098d6477771e6c3b60f3ed06afa82faabeb5e7e9e32b4 cloudflared-linux-arm.rpm: 6539ff302af568aa13ed4eacac1c9e736e0dbb40b7f64557b62f133092ed4890 cloudflared-linux-arm64: d2b49df8dbb3a36e743ce00b091c180e0942a0b67487257c573a631db001796c cloudflared-linux-arm64.deb: d84438ebce2badd4662dd92099769ca07b7b4337ab29cbeef65e621e9ef2de33 cloudflared-linux-armhf: e730601634b2428f19cb4eb20256585321fc2791824038f629146b1556d8ee67 cloudflared-linux-armhf.deb: 32131fadf4a339eeed50b4d491485c8048cac52bd1b3832027d949b9f3c080b1 cloudflared-linux-armhf.rpm: a3452299221ddad31219f6f083e7ac09716e15322af6631e60bf8b76f69be2b7 cloudflared-linux-x86_64.rpm: 31092f77696b077e99861d6a12ef098c913d773788f4560192d48804cc8234c8 cloudflared-windows-386.exe: 988c01bab27e824285573306a92af7b47600854e96e1140ba78077a267c18e53 cloudflared-windows-386.msi: c5411ca092702b963fbdcb8aa73c480ec5be2dce5830d2508c7f2fb4fdd513e1 cloudflared-windows-amd64.exe: 82781b3ba8cb66c0f8fbc7d34974bc4bd8eb1fcc76f27badb97eb4cc7060f5ad cloudflared-windows-amd64.msi: e4666555e36a40f40231de0f577444a44969169956fbcb7e652d38e6418dd9a2

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARED-2026.8.1

2026.8.1

Warning Known issue: This release normalize paths from requests sent to HTTP origins, which can cause issues in some applications that require the encoded value to be sent in the URLs. Do not use this version; upgrade to 2026.8.2 or later. See #1719 . SHA256 Checksums: cloudflared-amd64.pkg: 2289fb79b869f53af9349c6aacf1fdbe81695100c8e7e009ac12b51e2a56a9d2 cloudflared-arm64.pkg: 4fee9b8e7b8182ad039fa5ee76d06997a15a5126fc5c395d0fa8ca3da5c46a89 cloudflared-darwin-amd64.tgz: 3bb5d94cb7756ee9a12406f229777640eef39edcd78e93e73a4d4a1f163df69e cloudflared-darwin-arm64.tgz: ebd6cc90cc6342b8e512f77cfaeb241852d87c557a317d91d23c63f4f99333d9 cloudflared-fips-linux-amd64: e60b9cd460e01e0329ebe1846084e66123f3bf2363f697318752b047a1c69cae cloudflared-fips-linux-amd64.deb: 5cecd94c8a8466b5b9521f6f5512c6169b4c101009c5864fb4fa558e07d8fba8 cloudflared-fips-linux-x86_64.rpm: e1a55e5fefdb50d540a1554a2dd6a6c241a3f3c89457c7f40748f9a3fed971dc cloudflared-linux-386: cfc47459b9cdd190f16e1ba35a9476c5616bf68130ba12c49b7d1fcc95f50c03 cloudflared-linux-386.deb: 674d36b335fc992fa7dc828150aa4679e0115d872029b8553ef4245bbd2171bb cloudflared-linux-386.rpm: 79fc3187b919286621d7dddb6a9c172dbd202fb41e28cda30e0f0a01629a9492 cloudflared-linux-aarch64.rpm: 472207f15374e33c9247cb7c3260612c23fbf1d908b8bfc735c807307ecb2d22 cloudflared-linux-amd64: 98d8eadbfdf8c7ec994e08260599c9be991e7833c746f98692b18bdf71c9b9dc cloudflared-linux-amd64.deb: e430a257d74d60a80b870ac86d4c6be0bf6d4766f2a72461a6056afce9d8a140 cloudflared-linux-arm: 61a4818c1537197a5f1c0a4662808e2e7e166b8eba701a91b62b33d7adba9b32 cloudflared-linux-arm.deb: 9ff25da68a38c2d40fd14d9007931e64e4765d5e1247122d26c04d1c557a1bb0 cloudflared-linux-arm.rpm: e4d7587458ec1baf56675ab75f9f45a1712740795680aa676ae543a4085a1c03 cloudflared-linux-arm64: 6d517efc10dfce17440177bd7011909166eab44bae0f6998182183df717c7dba cloudflared-linux-arm64.deb: ee3fe95ac038c70dc0bbe4823667a2794422fa30c6068520537dc2fe3d7ce282 cloudflared-linux-armhf: 716b092a6e04260bf7e18ec6f44ea38c5934911cadf248c56dc5a570a7cb0d3a cloudflared-linux-armhf.deb: 3e902455786301636ba3a71b198415fbfabb74f05e834106115728b5d564fad2 cloudflared-linux-armhf.rpm: 94ec6c19d3ac82d433bf5a45168381ace7a7d398b27cbafef55327f64b5e4716 cloudflared-linux-x86_64.rpm: b9613530797eb3e63b4eb84baae5b911df830934ec928191c9546503b88a316a cloudflared-windows-386.exe: 300e0608dceb9e224dae6594b341e087b232c62a121106445a53b4dd153d8065 cloudflared-windows-386.msi: 8e129ecd844017fb586dbed6e6f414291c253ebf0faeee081dd08328a7aafe89 cloudflared-windows-amd64.exe: 8f1d6f87b8756dbf37064b16e2c8251b69d816305e4f4373e1b80efb28d13b83 cloudflared-windows-amd64.msi: 97eea2f6db99b065d5847c0f053ce593c6945b69416ba289d8ad50e9483c7827

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARED-2026.8.2

2026.8.2

SHA256 Checksums: cloudflared-amd64.pkg: 29102028ce6b69d956956bdc91725b6fbdbba74db370542831429af05b9fa700 cloudflared-arm64.pkg: 7fdf9031872f4cbd4715fa3a3b96b91d99a8b91cce849a43cc384a45a989e829 cloudflared-darwin-amd64.tgz: b0f770e1e0b281399a57219b840fd8eef1cc25387a404124248157ea2073727a cloudflared-darwin-arm64.tgz: b61054d3d6326ea558cb49826eebf5676e0d0a36d51b546975096ca3e0e3c89d cloudflared-fips-linux-amd64: 473e0aa84ae98728e7acc695d9898975f42f2fb49893248bb121b2268bbe7730 cloudflared-fips-linux-amd64.deb: 512f589b9b08bd132119399fd29c814577330fafb99bde4bdbf563f4fa0e3ac4 cloudflared-fips-linux-x86_64.rpm: 6dc8ca61d3108bde788802438be8fa00a912730426f4f0283fd55fd2f7cd41f8 cloudflared-linux-386: 39845d980a4b74b9c84530a28d8fea1fe6c476de26460275602162b349f1cbef cloudflared-linux-386.deb: aa7143b5194b60e4bf3023461b686d1d1f359c84ce9ce6f6c3f597b71cbe338b cloudflared-linux-386.rpm: 80e59a537f5fb042e77710bcfcb7c1f4e50036bbf5f19fa3f53f7a2b5270dace cloudflared-linux-aarch64.rpm: b7a73e26026c66977d97b6ace6232dc973d61fcfdbb370e77f3a65ff43711491 cloudflared-linux-amd64: fcfb02b575a52ca1af2e3267af4e1517bcdeb30ac48c834c69abaed3c0576ad2 cloudflared-linux-amd64.deb: c805c7c8102190c04dfc16e3b4cc4acc9007d5b19b3afbcd608ea6fed7645a43 cloudflared-linux-arm: 19809425f60a6261241dfa66a42b4115bab07c295396a3c4d5d7c247fc4e1412 cloudflared-linux-arm.deb: 968d63426166f70fb82580dc691b3c21c0b8a63494e5f20707a3a9ca05aa325b cloudflared-linux-arm.rpm: e0c69d6ba48a8dabc2b9876431de74ae7a0b03f64840fc6702e259840c12664c cloudflared-linux-arm64: 7747d94570fb390cf47dcb4f9555c193c6355cda9793f0d878d9049e5d6a7790 cloudflared-linux-arm64.deb: 096739c69f62cace40b144f0e6c81e61333f3d320ce07a265c7b17b5e925731c cloudflared-linux-armhf: 8e17268b7033061f505cd560eeafb04fdf020a354c975d1f0197bb63e9d0e0e5 cloudflared-linux-armhf.deb: 2ddaadc63910d1704f1a562044b4ae330a924da7a49c5dbd44207eaa91e44a1d cloudflared-linux-armhf.rpm: 5b6d79800244e2cfdda513f04c9169c35661e722fa7158d5d1339a3c8e9b2473 cloudflared-linux-x86_64.rpm: f5bc9c1b70c87a003bf293204bbae0af975d1c2ab32c8887d8f8118870bdbf5f cloudflared-windows-386.exe: 6acb072357618fa16c53c43e05438ed728aacd47119f1c6c3aa1a668c3299b43 cloudflared-windows-386.msi: c8d16c3cf20106958ec907361844c170cbeafb1f1c8ba24c906f332413381dc5 cloudflared-windows-amd64.exe: c29eee2b121f5436a642eed69fd9767da7e7b8c510fa50aaa130337f931357b5 cloudflared-windows-amd64.msi: 7067806367266ad66ae8e742b2856827a8ff07e1eb45f8fcbb335d4a28988a23

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-3.21.4

Helm v3.21.4

Helm v3.21.4 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Notable Changes fix(engine): prevent Files.Lines panic on empty file (backport to v3)- #32303 by @mahesh-sadupalli fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932- #32463 by @karan-vk [dev-v3 backport] fix: bump go.opentelemetry.io/otel@v1.44.0 for GO-2026-5158- #32535 by @scottrigby [dev-v3 backport] deps: bump google.golang.org/grpc@v1.82.1 for GO-2026-6061- #32536 by @scottrigby chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0- (includes golang.org/x/text v0.40.0 to fix GO-2026-5970) #32308 Installation and Upgrading Download Helm v3.21.4. The common platform binaries are here: MacOS amd64 ( checksum / 9173d05edf9592c6be1d0412ffafd935448dfc7a63c2bc732b8c67e55503e8a8) MacOS arm64 ( checksum / 6e0bf5eb6daafc2b1ec34bb5ba04ef103f3afc16192fb19805c2924d7ea1033f) Linux amd64 ( checksum / 61f88ab166748cb19604d7884cb100ae9ccb13804ddeb98e08af167eacbb6a14) Linux arm ( checksum / b02709eab565cfcee8acdb10c143daf05ab06d994baeb85e63976513367925a7) Linux arm64 ( checksum / b54c04b4e0b2540bbdc08c17a121dab70e9a2ed0de5705528fec68a5fd3b85a7) Linux i386 ( checksum / 71280742be811c7d9d6b4546125f185ba01c6fd967e47491766b0055a0570cf5) Linux ppc64le ( checksum / ba4e4f440b6992f119160e3ceea29d80158546c9241748332ffa1cfdfbb0bd8f) Linux s390x ( checksum / 321de1ff6fe57a9a5eca6b56d78d6959babe295ec7aab49af1a0d2bcfc02dfc8) Linux riscv64 ( checksum / fef3ec7e1ddafe8927253ad79f2f8e3ac41f3f92328eb2c23bd4513b4421e5d9) Windows amd64 ( checksum / 268a7b98b313403055e4f31807aeaac529c90e1188acd7857ae3e960b0f67cce) Windows arm64 ( checksum / e23545fff21ef04853a9540925dd73c4b9caaa24ee7fdd8482b1ee626a4eecc9) This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @scottrigby keybase account . Please use the attached signatures for verifying this release using gpg . The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026 Changelog chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 ( #32308 ) 813176c (dependabot[bot]) [dev-v3 backport] deps: bump google.golang.org/grpc@v1.82.1 for GO-2026-6061 b6aa8b1 (Scott Rigby) fix: bump go.opentelemetry.io/otel@v1.44.0 for GO-2026-5158 57ce7ae (Scott Rigby) fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932 ab71449 (Karan V) fix(engine): prevent Files.Lines panic on empty file 955dfab (Mahesh Sadupalli) Full Changelog : v3.21.3...v3.21.4

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HELMHELM-4.2.4

Helm v4.2.4

Helm v4.2.4 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Notable Changes fix: Improve error reporting for helm template --debug with --show-only- #31185 by @kyokuping fix: fetch logs from all containers in test pods- #32099 by @SebTardif fix(provenance): check error return in Digest and encodeRelease- #32136 by @SebTardif fix panic on repeated IsReachable calls- #32184 by @atkrad fix: set [pull,push] scope when helm push to a registry(use token auth) - v4- #31211 by @kimsungmin1 Fix missing conflict retry with server-side apply- #32088 by @Kajot-dev Properly format the extra field in gzipped packages- #31884 by @ouillie Fix vanishing empty lines- #32327 by @matheuscscp fix: pass registry client to downloader.Manager in upgrade- #32400 by @SetagGnaw chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1- for GO-2026-6061 #32450 fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158- #32521 by @TerryHowe Installation and Upgrading Download Helm v4.2.4. The common platform binaries are here: MacOS amd64 ( checksum / 6c163d687ca03c3b5c01928e53bbbcf9518278f47ce7a2f249a5a08e8bdaa2bc) MacOS arm64 ( checksum / d747eb4e28bd2727173d15b759fa0a17822291ec09db7ced3d55af290a3661a2) Linux amd64 ( checksum / c306b46f719b0a4da32d0f78ee21bf90ce8d602f15b22ab753f0674d1670a7f3) Linux arm ( checksum / 894e901f7daaf9b458baad7b5c685bfeef49070d7d53f99687bd5846a6c13639) Linux arm64 ( checksum / 564de2191b881e9f71b5606b25345821ea1682f06ab90499d3ab22b530176da1) Linux i386 ( checksum / 45297aeac0c65173a89e8de832997f952ba5115c2db09b2e3f2c23a601e70583) Linux loong64 ( checksum / faafbfecc1a06196e650c3ce0c74d5ac32cb1c0c0a855fa76e59dd100cb8d4c4) Linux ppc64le ( checksum / 5c00073e9d493de201384bb7eb19d60615bd7c39db52148473e8ce6da84bc70a) Linux s390x ( checksum / 5396a35fca5fa46e5614140363f389ce66f96886c1b25f256d9e3028299422fa) Linux riscv64 ( checksum / d8532a3524ca842887b15ab794377dc9c8ced8f26264c84171b4b0aafff05411) Windows amd64 ( checksum / e94d83a4706fd82078c98dade2079fa9d9680c1c2bfb93bfc304ee6bc2412a32) Windows arm64 ( checksum / dbe8b49ea9877abe3d77354a792efb01920da9f65a492fcb8b4fce4e08bbae8f) This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @scottrigby keybase account . Please use the attached signatures for verifying this release using gpg . The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026 Changelog Minimal fix to build failure from #31211 . 3900f43 (Scott Rigby) fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158 ( #32521 ) f7c6e8f (Terry Howe) chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 035a2c3 (dependabot[bot]) fix: pass registry client to downloader.Manager in upgrade f76a5f4 (Gates Wang) Apply suggestions 5a7c6c7 (Will Noble) Properly format the extra field in gzipped packages 2281848 (Will Noble) Fix missing conflict retry with server-side apply ( #32088 ) 2c979a1 (Jakub Jaruszewski) Potential fix for pull request finding 2bd2c66 (kimsungmin1) fix(registry): resolve golangci-lint issues in token-auth tests 183a540 (kimsm28) chore: go mod tidy after rebase on main 08d8da1 (kimsm28) fix(registry): use plain-http registry in token-auth scope test 9655b5a (kimsm28) Update pkg/registry/client.go 430dfac (Terry Howe) test: improve client_scope_test.go to avoid data races and brittle assertions 9569605 (kimsm28) fix typos in withScopeHint function comment 63f2b68 (kimsm28) fix registry test failures

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.4

v3.6.0-rc.4

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GITEAGITEA-1.27.2

v1.27.2

SECURITY Fix: update collaborator access mode and httpsign ( #38894 , #38862 ) ( #38895 ) Refactor: external render ( #38885 ) ( #38898 ) Fix(actions): resolve pull_request_target reusable workflows at the base commit ( #38886 ) ( #38897 ) Refactor: markup render ( #38864 ) ( #38869 ) Fix(deps): update dependency mermaid to v11.16.1 ( #38816 ) Fix(auth): set WebAuthn user verification per request ( #38805 ) ( #38810 ) Fix: render highlight language ( #38793 ) ( #38795 ) ENHANCEMENTS enhance: add missing npm package metadata properties ( #38826 ) ( #38831 ) BUGFIXES fix(actions): keep github.event.inputs as strings for workflow_dispatch ( #38899 ) ( #38908 ) fix(actions): let a rerun of selected jobs read the previous attempt's artifacts ( #38857 ) ( #38901 ) fix(lfs): accept successful transfer responses ( #38866 ) ( #38875 ) fix(packages): ignore nested Package.swift ( #38788 ) ( #38836 ) fix: drop newline-bearing member names in arch ParsePackage ( #38102 ) ( #38830 ) fix(storage): fix Azure Blob dump failing with file does not exist ( #38814 ) ( #38828 ) fix(migration): migration deletion returned json redirection ( #38796 ) ( #38825 ) fix(ui): change underlines to default browser style ( #38819 ) ( #38823 ) fix(actions): allow cancelling runs without running jobs ( #35842 ) ( #38812 ) fix(actions): evaluate each ${{ }} part on its own ( #38754 ) ( #38797 ) fix(actions): write an action task report in one transaction ( #38792 ) ( #38794 ) fix: markup link ( #38764 ) ( #38765 ) fix: set a minio part size when the content size is unknown ( #38753 ) ( #38755 ) fix: bad path escape in subpath archive download ( #38749 ) ( #38750 ) fix: remove the pull merge box from UI when the refreshed page doesn't contain it ( #38742 ) ( #38744 ) fix(markdown): fix double strikethough on code ( #38707 ) ( #38729 ) fix(lfs): failed upload deletes a concurrent upload's meta object ( #38693 ) ( #38722 ) fix: correct full url when using sub-path ( #38712 ) ( #38716 ) fix: avoid markup render panic ( #38698 ) ( #38703 ) fix(ui): too many participants shown in commit avatar stacks ( #38689 ) ( #38700 ) fix: support HEAD requests on Alpine registry APKINDEX.tar.gz ( #38686 ) ( #38688 ) fix(migrations): use all configured GitHub tokens ( #38841 ) ( #38846 ) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-25.13

[release-branch.go1.25] go1.25.13

Change-Id: I4b70d995adc305fd68e4dfc6bc5c42cd001513b5 Reviewed-on: https://go-review.googlesource.com/c/go/+/814722 Reviewed-by: Mark Freeman mark@golang.org Reviewed-by: Dmitri Shuralyov dmitshur@google.com TryBot-Bypass: Gopher Robot gobot@golang.org Auto-Submit: Gopher Robot gobot@golang.org

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-26.6

[release-branch.go1.26] go1.26.6

Change-Id: I04258bea694def9a16dd544fba28fea45eeadbbb Reviewed-on: https://go-review.googlesource.com/c/go/+/814840 TryBot-Bypass: Gopher Robot gobot@golang.org Reviewed-by: Mark Freeman mark@golang.org Auto-Submit: Gopher Robot gobot@golang.org Reviewed-by: Dmitri Shuralyov dmitshur@google.com

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GOGO-5B7E0CB87454A0BD

[release-branch.go1.27] go1.27rc3

Change-Id: I400bf6802223b50d5b0273153984e801a66bc317 Reviewed-on: https://go-review.googlesource.com/c/go/+/814825 Auto-Submit: Gopher Robot gobot@golang.org Reviewed-by: Dmitri Shuralyov dmitshur@google.com Reviewed-by: Mark Freeman mark@golang.org TryBot-Bypass: Gopher Robot gobot@golang.org

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-2.0.5

v2.0.5

BREAKING CHANGES: plugin: The DriverNetwork.Hash method has been removed from the plugin/drivers package. [ GH-28342 ] IMPROVEMENTS: build: Update Go to v1.26.5 [ GH-28260 ] checks: Nomad native service check IDs are now SHA256 [ GH-28361 ] cli: add -json-output and -t flags to nomad job plan for structured plan output [ GH-27369 ] consul: Added the issuing Nomad client's node ID to the metadata of Consul tokens created via workload identity [ GH-28133 ] consul: Check IDs are now derived from SHA256 instead of SHA1 [ GH-28362 ] jobspec: Removed the requirement that a variable validation error_message be a full English sentence, allowing messages written in any language [ GH-28246 ] planner: Added plan_apply_pipeline configuration that allows the leader to have more outstanding Raft writes when evaluating plans [ GH-28249 ] services: rendezvous hashes are now SHA256 [ GH-28363 ] template: Add run_on_first_render option to change_script to execute scripts on the initial template render via the task Poststart lifecycle hook. [ GH-27819 ] BUG FIXES: agent: Fixed a bug where the startup banner would display the wrong node ID for servers after restart [ GH-28276 ] api: Fixed a bug where the client allocation endpoints returned a 500 error instead of a 404 when the allocation's node could not be found [ GH-28261 ] auth: Fixed a bug where nodes could not sync allocations placed on them after being moved to a different node pool [ GH-28110 ] cli: Fixed a bug where nomad operator root keyring remove would not accept an abbreviated key ID [ GH-24148 ] client: Fix issue where deleted allocations may remain running [ GH-28394 ] client: Fixed a bug where a client could panic after an alloc is GC'd [ GH-28187 ] client: Fixed a bug where the client would not remount the secret and private tmpfs after a restart [ GH-28345 ] client: Fixed a bug where the previous allocation watcher would retry forever when the server returned a permanent error during data migration [ GH-28191 ] csi: Fixed a bug where evals blocked on missing CSI volumes would not unblock [ GH-28275 ] deployments: Fix garbage collection to respect threshold [ GH-28225 ] docker: Fixed a bug where tasks could execute outside of their assigned cpuset range [ GH-28272 ] drivers/java: Fixed a bug where the Java driver did not correctly decode the work_dir option [ GH-28330 ] jobspec: Fixed a bug where a negative cores value in a task's resource block was accepted during job validation and registration [ GH-10511 ] quota (Enterprise): Fixed a bug where disabling the use of cores in a quota would block the ability to use either cores or CPU in a job scheduler: Ensure deployment IDs are not written to an evaluation when the generated deployment is not persisted to state due to plan apply retries [ GH-28307 ] scheduler: Fixed a bug where the scheduler could panic with a nil pointer dereference when checking host volume feasibility for an allocation whose job had been purged [ GH-28301 ] secrets: Fixed hooks to allow refetch during prestart [ GH-28237 ] services: Fixed a bug where task secrets were not interpolated into service check Header and Args , or into service Tags [ GH-28212 ] ui: Fixed SSO sign in display not displaying when SSO enabled [ GH-28262 ] ui: Fixed a bug where the job status panel would show "Complete" instead of "Scaled Down" for system and sysbatch jobs with zero allocations [ GH-27949 ] ui: Fixed the region identifier header showing as empty in single region clusters [ GH-28310 ] ui: Fixed version diff display and missing deployment version numbers [ GH-28294 ] ui: check websocket upgrade headers with multiple values [ GH-28234 ] ui: refetch nomad license when logging in with new token [ GH-28284 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-8.19.20

Beats 8.19.20

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-8.19.20-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-9.4.5

Beats 9.4.5

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-9.4.5-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICBEATS-9.5.1

Beats 9.5.1

Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-9.5.1-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0291

Prisma Access Agent: Authenticated Limited File Deletion on Linux

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0292

Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0293

Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
PALO ALTO NETWORKSCVE-2026-0294

Prisma Access Agent: Local Privilege Escalation

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETCVE-2026-49975

HTTP/2 Bomb CVE-2026-49975

CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-19 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-03289E332A5C97E2

Broken access control in the RADIUS type admin group

CVSSv3 Score: 8.8 An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-0CFA15AE75B452E8

FGFM Authentication Weakening via CLI Configuration

CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-5AF92102F2F24C74

Content-Encoding WAF Evasion

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-89FF6F00E05934BB

Heap overflow in kernel driver due to missing size validation

CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-A2121F72B68EB4C3

Stack buffer overflow in WAD

CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-C8B96865F70B0E39

UI DoS attack

CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
FORTINETFORTINET-PRODUCTS-CFB47B42FCFE80AB

Server-Side Request Forgery (SSRF)

CVSSv3 Score: 3.4 A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via specially crafted HTTP requests Revised on 2026-08-12 00:00:00

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →