Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT

VERIFIED PUBLISHER INTELLIGENCE

Release notes and known issues

Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.

85 official publisher sources registered · 83 collected automatically · 0 monitored for availability · 2 requires publisher access

1898 verified publisher records · Page 17 of 19

WORDPRESSWORDPRESS-027E30A6B1AC6213

WordPress 7.0.4 Release

WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

Published 12 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-7.0.4

WordPress 7.0.4 Release

WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

Published 12 Aug 2026 · Source checked 26 Sep 2026

Release notes and known issues →
MICROSOFTDOTNET-10.0.11

.NET 10.0.11

Release Notes Install Instructions Repos Aspnetcore dotnet dotnet dotnet EF Core Runtime SDK SDK SDK Templating Templating Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-august-2026-servicing-updates/#release-changelogs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTDOTNET-8.0.30

.NET 8.0.30

Release Notes Install Instructions Repos Aspnetcore EF Core Installer Installer Runtime SDK SDK Templating Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-august-2026-servicing-updates/#release-changelogs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
MICROSOFTDOTNET-9.0.19

.NET 9.0.19

Release Notes Install Instructions Repos Aspnetcore EF Core Runtime SDK SDK Templating Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-august-2026-servicing-updates/#release-changelogs

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-8.19.20

Elasticsearch 8.19.20

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/guide/en/elasticsearch/reference/8.19/release-notes-8.19.20.html

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-9.4.5

Elasticsearch 9.4.5

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.4.5-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICELASTICSEARCH-9.5.1

Elasticsearch 9.5.1

Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.5.1-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GITEAGITEA-1.27.1

v1.27.1

SECURITY Fix: orgmode render include path ( #38642 ) ( #38645 ) Fix: git patch apply ( #38637 ) ( #38638 ) API fix(api): align Swagger schemas for UserSettings and TopicListResponse ( #38590 ) ( #38592 ) ENHANCEMENTS enhance: improve diff contrast in light and dark themes ( #37477 ) ( #38574 ) BUGFIXES fix: skip OIDC end-session after password login for OAuth2 users ( #38439 ) ( #38666 ) fix: make Actions log parser support multiple line message encoding ( #38659 ) ( #38664 ) fix(actions): use base branch ref for pull_request_target context ( #38636 ) ( #38657 ) fix(actions): skip already-approved runs in ApproveRuns ( #38653 ) ( #38654 ) fix: orgmode render include path ( #38642 ) ( #38645 ) fix(actions): cancel tasks immediately when the runner stopped reporting ( #38616 ) ( #38644 ) fix(issues): fix label bulk-load key and reduce log noise in LoadLabel ( #38632 ) ( #38643 ) fix(actions): improve runner list status sorting, labels and task job links ( #38586 ) ( #38633 ) fix(actions): correctness and hardening fixes ( #38518 ) ( #38631 ) fix(repo): prevent double-write redirect collisions on dependency errors, fix ui ( #38627 ) ( #38628 ) fix: delete repo-scoped rows of seven more tables when deleting a repository ( #38534 ) ( #38618 ) fix(webhook): remove slack channel name check ( #38608 ) ( #38612 ) fix: download dropdown menu clipped on the branches page ( #38604 ) ( #38609 ) fix(project): prevent database mutations on invalid MoveIssues payload ( #38600 ) ( #38602 ) fix(actions): make SingleWorkflow.Marshal round-trip multi-line run blocks (stop silent job stranding) ( #38520 ) ( #38599 ) fix(file-tree): handle submodule links and missing view container ( #38033 ) ( #38589 ) fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing ( #38565 ) ( #38587 ) fix: keep serving valid ACME cert when renewal fails at startup ( #38554 ) ( #38583 ) fix: branch protection user list ( #38570 ) ( #38584 ) fix(pulls): respect diff.orderFile in diff file tree ( #38566 ) ( #38578 ) fix(issue): make issue action (issue list batch operation) elements have correct attributes ( #38575 ) ( #38580 ) fix(actions): support matrix when evaluating workflow if expression ( #38474 ) ( #38557 ) fix(actions): align status icon span for Safari rendering ( #38558 ) ( #38562 ) fix: revert git clone http redirection forbidden ( #38530 ) ( #38545 ) fix: clean up orphaned user-keyed tables in deleteUser ( #38511 ) ( #38514 ) fix(actions): coerce workflow_dispatch boolean inputs to native types ( #38472 ) ( #38521 ) fix: make the merge box button red if some checks fail ( #38508 ) ( #38516 ) fix(pull): sign the commit when updating a branch by merge ( #38441 ) ( #38499 ) fix: make commit message merge correctly ( #38490 ) ( #38502 ) fix(actions): explain why a blocked or waiting job has not started ( #38476 ) ( #38498 ) fix(actions): make cancelled() work in job if evaluation ( #38495 ) ( #38497 ) fix(actions): show retention info on hover for expired artifacts ( #38477 ) ( #38493 ) fix(actions): group reusable-workflow matrix legs in the workflow graph ( #38475 ) ( #38492 ) fix: full file highlighting for git diff with CR char ( #38484 ) ( #38491 ) fix(packages): serve noarch Alpine index for any requested architecture ( #38479 ) ( #38486 ) fix: 500 error when updating user visibility ( #38480 ) ( #38483 ) fix(actions): make job list item fully clickable ( #38462 ) ( #38471 ) fix: mail template for push event ( #38467 ) ( #38468 ) fix: make "test push webhook" always work ( #38425 ) ( #38455 ) fix(actions): prevent bulk actions from affecting all runners ( #38453 ) ( #38457 ) fix(org): align follow button and wrap description ( #38448 ) ( #38454 ) fix(actions): populate github.event for scheduled runs ( #38446 ) ( #38452 ) MISC refactor: git patch apply ( #38637 ) ( #38638 ) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
JENKINSJENKINS-2.577

2.577

This is an automatically generated changelog draft for Jenkins weekly releases. See https://www.jenkins.io/changelog/2.577/ for the official changelog for this release. 🎉 Major features and improvements Standardise experimental Jenkins pages, make the side panel independently scrollable + make the build bar sticky ( #26863 ) @janfaracik 🚀 New features and improvements Remove remaining detached-plugin bundling from jenkins.war ( #27129 ) @timja , @Copilot 👷 Changes for plugin developers Correct Javadoc for QuotedStringTokenizer.quote(String) to reflect unconditional quoting ( #27165 ) @thswlsqls All contributors: @janfaracik , @thswlsqls , @timja and @Copilot

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICLOGSTASH-9.4.5

Logstash 9.4.5

Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.4.5-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ELASTICLOGSTASH-9.5.1

Logstash 9.5.1

Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.5.1-release-notes

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.6.0-RC.3

v3.6.0-rc.3

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ANSIBLEANSIBLE-CORE-2.19.12

v2.19.12

Changelog See the full changelog for the changes included in this release. Release Artifacts Built Distribution: ansible_core-2.19.12-py3-none-any.whl - ‌2416747 bytes b6bbdf05952852ad908861d652a9009c8474f1fe9c63a77ec202979a329d7d99 (SHA256) Source Distribution: ansible_core-2.19.12.tar.gz - ‌3436037 bytes cfb63b021558d5daddb1d0cd35886a5e1b18db2fc254d1f342e1527c62dac058 (SHA256)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ANSIBLEANSIBLE-CORE-2.20.8

v2.20.8

Changelog See the full changelog for the changes included in this release. Release Artifacts Built Distribution: ansible_core-2.20.8-py3-none-any.whl - ‌2420535 bytes fc6b18073900b6c886124faf5298ae0fc5d148e58635a04c9b358048981136d8 (SHA256) Source Distribution: ansible_core-2.20.8.tar.gz - ‌3354686 bytes 66e0e91ee43d98b3968a612c42c8e6e3d1ea43be501c4f8f6fc8c75b35892cdf (SHA256)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
ANSIBLEANSIBLE-CORE-2.21.3

v2.21.3

Changelog See the full changelog for the changes included in this release. Release Artifacts Built Distribution: ansible_core-2.21.3-py3-none-any.whl - ‌2446988 bytes 9e7dd367f7dc5d5e9fc5ae1baf8af9c4edc09e916a73a40108a3f32e3ad93f10 (SHA256) Source Distribution: ansible_core-2.21.3.tar.gz - ‌3397615 bytes 4194fbd82273cbacfd06d86d74d2d7168c3c4b8426c03e93562cd7217f811ae1 (SHA256)

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
KEYCLOAKKEYCLOAK-26.7.1

26.7.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49429 [ CVE-2026-9793 ] JWE request object bypasses requestObjectSignatureAlg enforcement oidc #50445 [ CVE-2026-4629 ] Privilege escalation via hardcoded role mapper injection in manage-clients admin/api #50569 [ CVE-2026-14209 ] Keycloak Admin UI Extension `brute-force-user` User Disclosure via `search=id:` under FGAP v2 admin/fine-grained-permissions #50615 [ CVE-2026-14614 ] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment admin/fine-grained-permissions #50617 [ CVE-2026-14615 ] FGAP v2 parent group children endpoint bypasses per-child view permission filter admin/fine-grained-permissions #51467 CVE-2026-15573 Authorization bypass via unnormalized uri matching in pathmatcher #51468 CVE-2026-15572 DCR protocol mapper type-swap policy bypass allows privilege escalation #51469 CVE-2026-16100 Unbounded metric cardinality in user event metrics via request-controlled error text #51470 CVE-2026-16442 SAML idp-initiated broker login bypasses link-only restriction #51471 CVE-2026-16443 SAML broker metadata import disables response signature validation #51472 CVE-2026-16071 LDAP entry-dn user search bypasses configured users dn boundary #51473 CVE-2026-16102 Default DCR policy allows role forgery via user property mappers Bugs #50719 WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field authentication/webauthn #50750 Clustering test broken in 26.7 release branch ci #50836 Kustomize cluster-wide faulty Role&RoleBinding operator #50850 New Password is commited when multiple Password Reset is detected authentication #50882 500 when client requests `organization` scope with it already set to `Default` authentication #50928 IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion core

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DENODENO-2.9.5

v2.9.5

2.9.5 / 2026.08.06 feat(add): --unscoped flag to alias packages by their unscoped name ( #36319 ) feat(task): add --members flag to run tasks in workspace members only ( #35748 ) feat: add Blob/Body textStream() ( #35616 ) feat: add experimental QuickJS backend ( #36194 ) fix(bundle): avoid esbuild protocol deadlock ( #36427 ) fix(bundle): respect runtime file permissions ( #36107 ) fix(cjs): use loader sources for recursive analysis ( #36111 ) fix(cli): escape control characters in external metadata ( #36198 ) fix(core): don't resolve internal module imports with the user's import map ( #36303 ) fix(crypto): add "raw-secret" to KeyFormat type ( #35708 ) fix(desktop): handle colored HMR URLs and page loads ( #36316 ) fix(desktop): retain update signature verification op ( #36152 ) fix(ext/crypto): allow deriveBits with length 0 ( #36283 ) fix(ext/napi): polyfill uv_handle_size and uv_strerror ( #36308 ) fix(ext/net): release completed QUIC stream resources ( #36247 ) fix(ext/net): require --allow-sys for node:dns.getServers() ( #35941 ) fix(ext/node): Node compat for web streams ( #36285 ) fix(ext/node): apply backpressure in Readable.toWeb() ( #36321 ) fix(ext/node): defer TLS write completion callback to avoid reentrancy panic ( #35867 ) fix(ext/node): don't fire http2 settings callback after session destroy ( #36230 ) fix(ext/node): gate constrained memory cgroup reads ( #36218 ) fix(ext/node): handle pre-quoted shell arguments ( #36371 ) fix(ext/node): implement node:test tags ( #36292 ) fix(ext/node): implement util.diff ( #36289 ) fix(ext/node): implement v8.promiseHooks API ( #36281 ) fix(ext/node): sort fs.readdir entries to match Node.js ( #36341 ) fix(ext/node): stop http2 file reads after stream close ( #36300 ) fix(ext/node): store blocklist ranges compactly ( #36212 ) fix(ext/node): support the fs flush option for writes ( #36290 ) fix(ext/node): use signatureAlgorithm digest for X509 ECDSA verify ( #36326 ) fix(ext/node_crypto): use named group exponent sizes ( #36347 ) fix(ext/web): attach Node error codes to WHATWG API validation errors ( #36288 ) fix(ext/websocket): disable HTTP/2 server push on wss upgrade path ( #36327 ) fix(fetch): scope redirect-sensitive headers by origin ( #36361 ) fix(ffi): reject resizable buffers in nonblocking calls ( #36259 ) fix(fmt): accept xml and svg extensions for stdin ( #36149 ) fix(fmt): update lax-markup to 0.3.2, lax-css and lax-sql to 0.3.0 ( #36397 ) fix(http): preserve stripped headers across redirects ( #36360 ) fix(inspector): validate request host headers ( #36348 ) fix(net): cancel pending writes on stream close ( #36369 ) fix(net): clean up concurrently dropped load-balanced listeners ( #36246 ) fix(net): handle malformed DNS record text ( #36374 ) fix(node): clean up Web Stream finished listeners ( #36227 ) fix(node): retain consumed HTTP stream wrapper ( #36254 ) fix(npm): ignore invalid package bin targets ( #36354 ) fix(npm): tolerate malformed scripts field in packuments ( #36324 ) fix(npmrc): match auth configs by authority and path ( #36359 ) fix(outdated): don't report JSR pre-release versions as latest ( #36325 ) fix(publish): report when the registry rejects a provenance attestation ( #36404 ) fix(resolver): don't treat deno eval modules as npm package files ( #36304 ) fix(runtime): map notify's Windows missing-path error to NotFound ( #35864 ) fix(sync-types): add reason to too_many_arguments allows (lint) fix(telemetry): handle reentrant attribute conversion ( #36256 ) fix(webgpu): own mapped range backing stores ( #36257 ) fix(webstorage): preserve Storage constructor name ( #35944 ) fix: capitalize IP in help text ( #36170 ) fix: upgrade deno_task_shell to 0.33.3 ( #36406 ) fix: wire no-legacy-abort unstable flag from deno.json config ( #36312 ) perf(core): run the common-path tick drain in Rust ( #36157 ) perf(ext/node): bypass dns lookup on literal IPs in udp send ( #35909 ) perf(ext/web): implement base64url encode/decode as simdutf ops ( #36398 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-3.6.15

v3.6.15

3.6.15 (2026-08-05) Bug Fixes queryrange: Preserve sketch in MergeLabels [release-3.6.x] ( #23771 ) ( 20087cd )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-3.7.6

v3.7.6

3.7.6 (2026-08-05) Bug Fixes queryrange: Preserve sketch in MergeLabels [release-3.7.x] ( #23770 ) ( d48329d )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-42F4C3512480E50D

WordPress 7.0.3 release

WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

Published 6 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-7.0.3

WordPress 7.0.3 release

WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

Published 6 Aug 2026 · Source checked 26 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-3.6.14

v3.6.14

3.6.14 (2026-08-04) Bug Fixes Backport WAL replay hang fix to release-3.6.x ( #21176 ) ( #23630 ) ( 355e2f3 ) ci: Backport deb/rpm packaging fix to release-3.6.x ( #23680 ) ( #23722 ) ( d7ee4de ) security/UNKNOWN/cmd/chunks-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) ( #23615 ) ( a6cc2e5 ) security/UNKNOWN/cmd/dataobj-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) ( #23616 ) ( a71c910 ) security/UNKNOWN/operator: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) ( #23618 ) ( 59970a9 ) security/UNKNOWN/: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.6.x) ( #23614 ) ( 8308a12 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
GRAFANA LABSGRAFANA-LOKI-3.7.5

v3.7.5

3.7.5 (2026-08-05) Bug Fixes Build deb/rpm packages again in the release workflow ( #23598 ) ( 6f49272 ) ci: Disable docker plugin publishing on release-3.7.x ( #23440 ) ( 6095f71 ) ingester: Fix flush race in ingester [release-3.7.x] ( #23682 ) ( ff152dc ) security/UNKNOWN/cmd/chunks-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) ( #23611 ) ( 11c4b29 ) security/UNKNOWN/cmd/dataobj-inspect: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) ( #23612 ) ( 1e3108e ) security/UNKNOWN/cmd/dataobj-inspect: Update module go.opentelemetry.io/otel to v1.42.0 [SECURITY] (release-3.7.x) ( #23518 ) ( 28917d3 ) security/UNKNOWN/cmd/dataobj-inspect: Update module golang.org/x/text to v0.39.0 [SECURITY] (release-3.7.x) ( #23419 ) ( 5d2b9d4 ) security/UNKNOWN/operator: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) ( #23613 ) ( 8d71c59 ) security/UNKNOWN/: Update module github.com/klauspost/compress to v1.18.7 [SECURITY] (release-3.7.x) ( #23610 ) ( 941b557 ) security/UNKNOWN/: Update module golang.org/x/text to v0.39.0 [SECURITY] (release-3.7.x) ( #23418 ) ( 2347a9a ) security/UNKNOWN/: Update module google.golang.org/grpc to v1.82.1 [SECURITY] (release-3.7.x) ( #23405 ) ( f290af0 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-26.7.0

2026-08-05, Version 26.7.0 (Current), @aduh95

Notable Changes [ 58717685a1 ] - (SEMVER-MINOR) crypto : support loading private keys through STORE loaders (Filip Skokan) #63949 [ 44b940ee8c ] - crypto : update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746 [ c1e4f7365e ] - (SEMVER-MINOR) lib : add perfetto support (Chengzhong Wu) #64565 [ 11c2f9c642 ] - (SEMVER-MINOR) module : implement Symbol.dispose in ModuleHooks (Remco Haszing) #63928 [ a646319f61 ] - (SEMVER-MINOR) test_runner : add support for --test-coverage-include-all (avivkeller) #64830 Commits [ a2d3f891d3 ] - async_hooks : use validateBoolean for trackPromises (Soul Lee) #64731 [ d7266cdd99 ] - benchmark : fix calibrate-n option handling (Luan Muniz) #64146 [ 2e64293e3f ] - buffer : use Clamp conversion in Blob slice (Donghoon Kang) #64739 [ 5fda0958bd ] - buffer : validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #63904 [ 5298db40f9 ] - build : run perfetto build and test on GHA (Chengzhong Wu) #64721 [ e3eac7cef9 ] - build : fix v8_use_perfetto source scraping (Chengzhong Wu) #64721 [ ab5f076d7f ] - build : bump rustc requirement to >=1.86 (Renegade334) #64543 [ df608e061f ] - (SEMVER-MINOR) build : perfetto-sdk (Chengzhong Wu) #64565 [ 74928adc46 ] - build,tools : fix shared library cross-compile (Kirill Saied) #63963 [ 58717685a1 ] - (SEMVER-MINOR) crypto : support loading private keys through STORE loaders (Filip Skokan) #63949 [ 58d13b6f3d ] - crypto : preserve OpenSSL errors from KDF failures (Filip Skokan) #64776 [ 478a719cb5 ] - crypto : fix Argon2 bypassing FIPS mode (Filip Skokan) #64776 [ 44b940ee8c ] - crypto : update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746 [ fde85237c7 ] - crypto : clarify missing cipher error (Filip Skokan) #64852 [ c604d8846d ] - crypto : reuse X509 issuer result (Filip Skokan) #64852 [ c68c7d0112 ] - crypto : validate key generation options (Filip Skokan) #64852 [ c36bb1d017 ] - crypto : fix Argon2 validation errors (Filip Skokan) #64852 [ f61408bb27 ] - crypto : handle XOF output allocation failure (Filip Skokan) #64851 [ 2b4053d046 ] - crypto : initialize KeyObjectData mutex eagerly (Filip Skokan) #64851 [ 4b7b2adf44 ] - crypto : handle DH operation failures (Filip Skokan) #64851 [ 12170c3753 ] - crypto : use user-facing error for output encoding changes (Archkon) #64692 [ 474f06d550 ] - debugger : preserve overlapping CDP request state (Trivikram Kamat) #64467 [ 718cbe9497 ] - deps : upgrade npm to 11.19.0 (npm team) #64883 [ 657c6154b3 ] - deps : update ngtcp2 to 1.25.0 (Node.js GitHub Bot) #64944 [ 75a1fbeff9 ] - deps : update nghttp3 to 1.18.0 (Node.js GitHub Bot) #64943 [ 07d7cb7cd8 ] - deps : update minimatch to 10.2.6 (Node.js GitHub Bot) #64945 [ f7d56359f1 ] - deps : update simdjson to 4.6.6 (Node.js GitHub Bot) #64942 [ 8b06457cfb ] - deps : update acorn to 8.18.0 (Node.js GitHub Bot) #64941 [ 5919d01525 ] - deps : update googletest to 1b6f64d659944658a4c685b7bd9f04c1c3b8a39b (Node.js GitHub Bot) #64940 [ 4a87ad6cff ] - deps : update nghttp2 to 1.70.0 (Node.js GitHub Bot) #64939 [ c96d76a7c8 ] - deps : update zlib to 1.3.2.1-motley-42c2f19 (Node.js GitHub Bot) #64744 [ 2b59984c0f ] - deps : V8: backport 5177b10891e6 (avivkeller) #64631 [ b839af91da ] - deps : update ada to 4.0.0 (Node.js GitHub Bot) #64790 [ 70dedef942 ] - deps : update sqlite to 3.53.4 (Node.js GitHub Bot) #64745 [ 7bc4c171f5 ] - deps : update Rust crates for V8 14.6.202.34-node.26 (Renegade334) #64543 [ 308c6b2ac3 ] - deps : V8: backport 7d9b7e03141d (Manish Goregaokar) #64543 [ 8eeae28e88 ] - deps : V8: backport c4d06ba586f3 (liujiahui) #63731 [ bbd6fc58c4 ] - diagnostics_channel : grow native channel storage (Stephen Belanger) #64497 [ ce8b292955 ] - doc : fix grammar and punctuation in dgram documentation (Kamal Rawal) #64957 [ 1a413a60cf ] - doc : fix grammar and editorial issues in addons documentation (Kamal Rawal) #64952 [ 63fbd59e64 ] - doc : formalize fn/name as part of TestOptions API (Christopher Hiller) #64946 [ b263b0bca1 ] - doc

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENSEARCHOPENSEARCH-3.8.0

3.8.0

Version 3.8.0 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 3.8.0 Features Add API to modify a data stream's backing indices ( POST /_data_stream/_modify ) ( #22487 ) Add multivalue_doc_count aggregation that returns the number of documents with two or more values ( #20472 ) Add pull-based ingestion from Hive tables via new ingestion-hive plugin ( #21700 ) Add support for HTTP/3 on the client side via JDK HttpClient ( #21718 ) Add gRPC support for Point-in-Time (PIT) create and delete operations ( #22105 ) Add gRPC API support for extra_field_values in bulk requests ( #21907 ) Add cross-cluster streaming support to the remote cluster client via Arrow Flight ( #22359 ) Add coordinator-side index-level field domain pruning before can_match for faster time-range queries ( #21865 ) Add bulkscorer script processing interface in ScriptScore query for bulk scoring optimizations ( #22423 ) Add process-wide ObjectInputFilter to reject Java deserialization by default, gated behind bootstrap.serial_filter setting ( #22073 ) Add cluster-level default setting for delayed shard allocation timeout ( cluster.routing.allocation.unassigned.node_left.delayed_timeout ) ( #22379 ) Enhancements Add HTTP request body decompression (gzip/deflate) to reactor-netty4 transport ( #22382 ) Add cross-setting validator to prevent cluster-manager crash loop when both balance factors are set to zero ( #22391 ) Add support for double, int, and long types in ExtraFieldValue for gRPC bulk indexing ( #22058 ) Add timing logs for repository create, update, and delete operations ( #22489 ) Add parent action name to ProcessorGenerationContext for conditional system-generated processor logic ( #22195 ) Add getter for remote translog transfer tracker to enable plugin access to tracking metrics ( #22453 ) Deprecate RestClient in favor of the internal HTTP client ( #22116 ) Disable Mustache partial template resolution in search templates ( #22438 ) Use binary serialization for resource usage headers to reduce CPU overhead on the search path ( #21230 ) Preserve resolved search pipeline id and inline pipeline source through query rewrite ( #22501 ) Fork GET _aliases serialization to MANAGEMENT thread pool to avoid blocking transport threads ( #21954 ) Strengthen scroll_id validation to prevent OOM from crafted scroll IDs ( #22396 ) Add depth tracking to recursive deserialization to prevent StackOverflowError ( #22404 ) Validate base_path in FsRepository to prevent path traversal outside path.repo ( #22328 ) Add path boundary validation in resolveAnalyzerPath to prevent directory traversal ( #22094 ) Register snapshot resilience settings ( snapshot.repository.io_timeout , max_outstanding_ops , cleanup_stale_blobs ) ( #22516 ) Wire request_timeout into S3 sync client to prevent indefinite hangs on degraded stores ( #22479 ) Separate internal ignore settings from user ignore settings during snapshot restore ( #20494 ) Validate total_primary_shards_per_node on index templates against the cluster instead of index-local flag ( #22203 ) Rollover checkBlock now scoped to write index only, skipping non-write alias members ( #21838 ) Bug Fixes Fix OpenSearchTimeoutException to return HTTP 504 instead of 500 ( #22064 ) Fix ClassCastException on malformed mappings in create index to return 400 instead of 500 ( #22371 ) Fix NPE for search-only indices without primaries in cluster allocation explain and bulk shard selection ( #22097 ) Fix NPE in S3 multipart upload when provideStream() throws, and fix shared segment array corruption ( #22309 ) Fix ReplicationCheckpoint.compareTo to return 0 for equal checkpoints, preventing TimSort crash during shard allocation ( #22376 ) Fix negative os.cpu.percent on cgroup v2 containers by granting read access to /sys/fs/cgroup/cpu.stat ( #22408 ) Fix snapshot listing failing on repositories containing legacy Elasticsearch snapshots ( #22193 ) Fix default SSE type to send AES256 header, preventing silent snapshot failure

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
VUE.JSVUE-3.5.41

v3.5.41

For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-F619A35EB761E4FC

WordPress 7.1 Release Candidate 1

The first Release Candidate (“RC1”) for WordPress 7.1 is ready for download and testing! This version of the WordPress software is still under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended to evaluate RC1 on a test server and site. WordPress 7.1 RC1 […]

Published 5 Aug 2026 · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPVAULT-2.0.4

v2.0.4

2.0.4 August 04, 2026 BREAKING CHANGES: containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps. SECURITY: acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters / denied_parameters constraints. identity/scim (enterprise): The identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries. identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace. identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity CHANGES: auth/oci: Update plugin to v0.21.3 core: Bump Go version to 1.26.5. core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with duplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment variable that previously restored the legacy behavior has been removed. FEATURES: secrets: Added ability to view secrets in YAML format IMPROVEMENTS: auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener. core (enterprise): Add an endpoint at sys/config/oauth-resource-server/id/:config_id to read oauth resource server profiles by config_id core (enterprise): Make OAuth resource server JWT typ validation more permissive for tokens from IdPs such as Okta by allowing a missing typ header, while restricting present typ values to at+jwt , application/at+jwt , and JWT . core (entreprise): Ameriolate sealwrap lock contention for core paths. core/acl: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/identity: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/managed-keys/PKCS#11 (enterprise): Providing a non-empty value for one field while the other is already saved is rejected. To switch addressing modes, you must explicitly clear the old field by sending it as an empty string ("") in the same request alongside the new value. core/managed-keys/PKCS#11 (enterprise): slot and token_label are now strictly enforced as mutually exclusive identifiers for an HSM token events: Add VAULT_EVENT_NOTIFICATIONS_BOUNDED_QUEUE_SIZE environment variable to configure bounded event queues for event notification subscribers. Set to a positive integer (e.g., 16) to enable buffered channels of that size (maximum 1000). This prevents resource exhaustion in deployments with high subscriber counts, but comes at the cost of the potential for subscribers to miss events. Defaults to 0 (unbuffered) for backward compatibility. identity/scim (enterprise): Added filtering support to the GET /scim/v2/Users and GET /scim/v2/Groups endpoints per RFC 7644. Supported filters: userName eq , externalId eq , active eq , and meta.lastModified gt/ge/lt/le for Users; displayName eq and meta.lastModified gt/ge/lt/le for Groups. Unsupported filter expressions return HTTP 400. ServiceProviderConfig now advertises filter.supported: true . identity/scim (enterprise): Improve SCIM User and Group listing endpoint performance by using prefix sort instead of a separate sort pass. identity: Include entity status and entity/alias timestamp details in entity list key_info responses. oauth-resource-server: Add support for fine-grained policy control options (par

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DOCKERDOCKER-COMPOSE-5.4.0

v5.4.0

What's Changed ℹ️ This release introduces a new way to reconcile resources such as volumes and networks ✨ Improvements Feat(reconcile): model volume recreation in the plan by @ndeloof in #13962 Feat(reconcile): model network lifecycle in the plan by @ndeloof in #13966 🐛 Fixes Fix(reconcile): preserve zero-replica services during hashing by @junhaoliao in #13931 Fix(config): warn when service selection is silently ignored by @glours in #13950 Fix(build): use platform image-manifest digest, not attested index by @glours in #13949 Fix(oci): honor --insecure-registry when up re-loads the model by @ptrdom in #13894 Fix(config): pin type:image volume sources and pre_start hook images by @glours in #13956 Tolerate missing env file on more runtime commands by @maxproske in #13603 Resolve pre_start hook images alongside service images by @ndeloof in #13937 Fix(cp): return non-nil Content from dry-run CopyFromContainer by @glours in #13982 Fix(config): apply config flags to --services / --volumes / --networks / --models / --hash by @glours in #13979 Fix: tolerate missing env file on scale, watch and shell completion by @glours in #13973 🔧 Internal README: remove Go Report Card badge by @thaJeztah in #13926 Docs: adopt AGENTS.md standard, symlink CLAUDE.md to it by @glours in #13871 Dockerfile: update golang image to alpine 3.23 by @thaJeztah in #13921 Docs: require dated AI_AGENT_DISCLOSURE.md , drop committed copy by @glours in #13976 CI: publish images to Docker Hub using OIDC by @glours in #13994 ⚙️ Dependencies Build(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0 by @dependabot [bot] in #13942 Build(deps): bump the docker-actions group across 1 directory with 4 updates by @dependabot [bot] in #13941 Build(deps): bump actions/stale from 10.3.0 to 10.4.0 by @dependabot [bot] in #13943 Build(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 by @dependabot [bot] in #13948 Build(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 by @dependabot [bot] in #13927 Build(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0 by @dependabot [bot] in #13928 Build(deps): bump docker/github-builder/.github/workflows/bake.yml from 1.13.0 to 1.14.0 in the docker-actions group by @dependabot [bot] in #13953 Build(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 by @dependabot [bot] in #13922 Build(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 by @dependabot [bot] in #13955 Build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by @dependabot [bot] in #13960 Build(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 in the go_modules group across 1 directory by @dependabot [bot] in #13961 Build(deps): bump github.com/docker/cli from 29.6.1+incompatible to 29.6.2+incompatible by @dependabot [bot] in #13968 Build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3 by @dependabot [bot] in #13981 Build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot [bot] in #13970 Build(deps): bump github.com/moby/buildkit from 0.31.1 to 0.31.2 by @dependabot [bot] in #13969 Bump compose-go to version v2.14.0 by @glours in #13983 Bump go-archive to version v0.3.0 by @glours in #13986 Build(deps): bump docker/github-builder/.github/workflows/bake.yml from 1.14.0 to 1.15.0 in the docker-actions group by @dependabot [bot] in #13989 Chore(deps): bump github.com/moby/go-archive v0.3.2 by @thaJeztah in #13991 Update to go1.26.5 by @thaJeztah in #13920 Build(deps): bump actions/stale from 10.4.0 to 11.0.0 by @dependabot [bot] in #13996 Build(deps): bump docker/docker-agent-action/.github/workflows/review-pr.yml from 2.0.2 to 2.0.3 in the docker-actions group by @dependabot [bot] in #13995 Build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by @dependabot [bot] in #13984 Chore(deps): github.com/docker/buildx v0.36.0 , buildkit v0.32.0 by @glours in #13975 Bump buildkit v0.32.1 by @glours in #13997 New Contributors @junhaoliao made their first contribution in #13931 Full Changelog :

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OPENJS FOUNDATIONNODEJS-26.6.0

2026-08-03, Version 26.6.0 (Current), @aduh95

Notable Changes [ 5a36018abc ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ 9b04f82d7b ] - (SEMVER-MINOR) ffi : add getCurrentEventLoop (Paolo Insogna) #64323 [ bb51f2c960 ] - (SEMVER-MINOR) test_runner : add context.log() and test:log event (Moshe Atlow) #64389 [ 56ce83b3ee ] - (SEMVER-MINOR) test_runner : report entryFile in TestStream events (Moshe Atlow) #64309 Commits [ 248ff9fa5c ] - assert,util : fix TypeError on Maps with null keys (Paul Bouchon) #64441 [ 3b5baceafe ] - benchmark : add bytes variant to webstreams async-iterator (Matteo Collina) #64291 [ 0a46d1ef66 ] - buffer : normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115 [ d9ada18b70 ] - buffer : fix Blob.stream() leaking source buffer (semimikoh) #63577 [ d05993bcf6 ] - build : merge multiple on download artifact (Chengzhong Wu) #64633 [ 6c25ac909a ] - build : extract temporal_capi crate directory name into gyp variable (René) #64482 [ 612f60c300 ] - cli : style node --help output with util.styleText (Adrián Estrada) #64484 [ 29a938ddbb ] - crypto : preserve RSA-PSS legacy pubkey DER (Filip Skokan) #64547 [ 2fde794357 ] - crypto : cleanse provider private key copies (Filip Skokan) #64547 [ 33a0e08d41 ] - crypto : handle incomplete RSA private keys (Filip Skokan) #64547 [ 11b4d505ef ] - crypto : retain legacy DH validation (Filip Skokan) #64547 [ 6e302041e1 ] - crypto : limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) #64557 [ 195f103e87 ] - crypto : split OpenSSL 3, BoringSSL, and legacy backends (Filip Skokan) #64211 [ ec67e24eee ] - deps : update googletest to fa005b296f90faec4f352d7ab382287bf6548c8d (Node.js GitHub Bot) #64587 [ 32ffff88fd ] - deps : histogram: cherry-pick 62ea52b07ee9b195 (StefanStojanovic) #64296 [ e0664f1f09 ] - deps : update histogram to 0.11.10 (Node.js GitHub Bot) #64296 [ cf0622bdd6 ] - deps : update amaro to 1.1.11 (Node.js GitHub Bot) #64586 [ 04c78b8b24 ] - deps : update timezone to 2026c (Node.js GitHub Bot) #64588 [ 59f4318976 ] - deps : V8: cherry-pick 1158ae719749 (René) #64432 [ e5ea7cd299 ] - deps : update googletest to 8240fa7d62f73e01c7af27d61ed965d6d66698fa (Node.js GitHub Bot) #64439 [ 0e7554cee4 ] - deps : update libffi to 3.7.1 (Node.js GitHub Bot) #64438 [ 46c9d724ad ] - deps : update ngtcp2 to 1.24.0 (Node.js GitHub Bot) #64297 [ 3519aac9af ] - deps : enable OpenSSL asm support for riscv64 (Jamie Magee) #62606 [ c09701218b ] - deps : update c-ares to 1.34.8 (Node.js GitHub Bot) #64330 [ ad2f3bc95b ] - deps : upgrade npm to 11.18.0 (npm team) #64199 [ d7a4b22c86 ] - deps : V8: backport a05321ebd98e (Chengzhong Wu) #64202 [ 8679cff291 ] - deps : update zlib to 1.3.2.1-motley-8b3aa8a (Node.js GitHub Bot) #64295 [ df5b1e10ba ] - doc : remove unsupported syntax from stream_iter.md (Antoine du Hamel) #64649 [ 8a4ca9083f ] - doc : clarify rules for adding new built-in modules (Antoine du Hamel) #64648 [ 7d50fe6b7a ] - doc : mention DEPENDENCY custom field for H1 reports (Rafael Gonzaga) #64634 [ 8f415bf5fc ] - doc : fix dnsPromises.lookup verbatim default (Shivam S) #64658 [ c6378f724d ] - doc : fix broken links and clean up type map (Antoine du Hamel) #64625 [ 9b53ec19a2 ] - doc : fix typo in releases guide (Jihwan) #64621 [ 5a36018abc ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ d2c8acd764 ] - doc : use promote wording in release guide (Md Muhtasim Munif Fahim) #64371 [ 5c692cb576 ] - doc : fix import.meta example for vm.SourceTextModule (Muhammad Zeeshan) #64112 [ 7568ce71ca ] - doc : mention crypto.hash() for better perf (Steven) #63420 [ cf3f631936 ] - doc : update sea example by fixing wrong code example (Maxence Robinet) #64025 [ ce21e567a4 ] - doc : fix socket.readyState state descriptions (YuSheng Chen) #64468 [ 018c7f1c01 ] - doc : replace large tables in crypto.md and webcrypto.md with lists (Filip Skokan) #64582 [ cf82de8d8b ] - doc : note --env-file is not applied to --run (Paul Bouchon) #64442 [ e635ce5201 ] - doc : fix typo in embed

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-2.11.54

v2.11.54

CVE fixed: Advisory GHSA-62fc-8686-hfmq Bug fixes: [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ( #13530 @kevinpollet ) Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ( #13574 @mmatur ) [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider ( #13573 @gndz07 ) [middleware] Bump github.com/klauspost/compress to v1.18.7 ( #13587 @mmatur )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.6.25

v3.6.25

CVE fixed: Advisory GHSA-fgjj-px3w-67xx Advisory GHSA-62fc-8686-hfmq Advisory GHSA-6765-c87h-8mrf Bug fixes: [acme] Bump github.com/go-acme/lego/v5 to v5.3.1 ( #13547 @ldez ) [middleware, authentication] Fix auth singleflight key collision ( #13572 @mmatur ) [k8s/gatewayapi] Avoid router name collisions in Kubernetes Gateway API provider ( #13580 @gndz07 ) [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ( #13530 @kevinpollet ) Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ( #13574 @mmatur ) [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider ( #13573 @gndz07 ) [middleware] Bump github.com/klauspost/compress to v1.18.7 ( #13587 @mmatur )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.7.10

v3.7.10

CVE fixed: Advisory GHSA-fgjj-px3w-67xx Advisory GHSA-62fc-8686-hfmq Advisory GHSA-6765-c87h-8mrf Bug fixes: [acme] Bump github.com/go-acme/lego/v5 to v5.3.1 ( #13547 @ldez ) [middleware, authentication] Fix auth singleflight key collision ( #13572 @mmatur ) [k8s/gatewayapi] Avoid router name collisions in Kubernetes Gateway API provider ( #13580 @gndz07 ) [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ( #13530 @kevinpollet ) Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ( #13574 @mmatur ) [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider ( #13573 @gndz07 ) [middleware] Bump github.com/klauspost/compress to v1.18.7 ( #13587 @mmatur ) [k8s/gatewayapi] Bump sigs.k8s.io/gateway-api to v1.6.1 ( #13589 @rtribotte ) Documentation: [k8s/ingress-nginx] Clarify auth-url/rewrite-target interaction on ingress-nginx provider ( #13607 @gndz07 )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OWNCLOUDOWNCLOUD-10.16.4

v10.16.4

Classic ownCloud Server 10.16.4. Archives mirrored from https://download.owncloud.com/server/stable . This is a security release. Upgrading is strongly recommended for all installations. See the release notes for details: https://doc.owncloud.com/server_release_notes.html#changes-in-10-16-4

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OWNCLOUDOWNCLOUD-11.0.0

v11.0.0

Classic ownCloud Server 11.0.0 — the first major release of the 11.x line. This release contains 11 security fixes. Upgrading is strongly recommended for all installations. Full changelog: https://github.com/owncloud/core/blob/v11.0.0/CHANGELOG.md (47 entries: 11 security, 19 bugfixes, 17 changes.) Highlights PHP 8.3 is now the minimum supported version. G2 code signing. Releases are signed with the new per-app G2 PKI (ECDSA-P384/SHA-384, one CN-matched leaf per app, chaining to the G2 root). G1 signatures are sunset and occ integrity:sign-app / integrity:sign-core have been removed. Legacy and deprecated code inherited from earlier releases has been removed — see the Change entries for the full list, including the dropped db:convert-type command and the removal of the caching router. The group-admin feature is now disabled by default behind allow_subadmins . Upgrading Upgrades are supported from 8.2.11, 9.0.9, and 9.1 onwards. Review the Change section of the changelog before upgrading: this is a major release and several deprecated features and commands have been removed. Downloads Four variants are published here, each as .tar.bz2 and .zip with .asc / .md5 / .sha256 sidecars: Variant Asset Server owncloud-11.0.0 Server + test apps (QA) owncloud-11.0.0-qa Complete bundle owncloud-complete-20260730 Complete bundle (QA) owncloud-complete-20260730-qa Verify a download against the release signing key: gpg --verify owncloud-11.0.0.tar.bz2.asc owncloud-11.0.0.tar.bz2 # Good signature from "ownCloud Release Signing <releases@owncloud.com>" # Primary key fingerprint: A84D B0E2 D0F0 F587 A04E FC69 BAC1 ADE9 1978 CC39

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OWNCLOUDOWNCLOUD-11.0.0-RC3

v11.0.0-rc3

chore: bump version string to 11.0.0-rc3 ( #41755 ) Bump `$OC_VersionString` from 11.0.0-rc2 to 11.0.0-rc3 for the upcoming 11.0.0-rc3 release. The code ($OC_Version) is unchanged; this only updates the human-readable version string reported by the server. Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-AA459772D860758D

WordPress 7.1 Beta 4

WordPress 7.1 Beta 4 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta […]

Published 29 Jul 2026 · Source checked 29 Sep 2026

Release notes and known issues →
TRAEFIK LABSTRAEFIK-3.7.9

v3.7.9

Important: Please read the migration guide . CVE fixed: Advisory GHSA-3ccp-42pg-hgv6 Bug fixes: [k8s/ingress-nginx] Fix redirect with use-regex in IngressNGINX provider ( #13476 @AmariahAK ) [middleware] Disable Zstd support in the gzhttp wrapper ( #13533 @kevinpollet ) [server] Defer the CONNECT payload until the backend accepts the tunnel ( #13542 @sdelicata ) [server] Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy ( #13543 @sdelicata ) [server] Bump google.golang.org/grpc to v1.82.1 ( #13551 @piscue ) [server] Do not add back CONNECT requests to the pool ( #13556 @kevinpollet ) Documentation: [k8s/gatewayapi] Document Gateway API generated service names change in the migration guide ( #13541 @rtribotte ) [k8s/ingress-nginx] Fix typo in nginx annotation proxy-buffer-numbers ( #13545 @fischerman ) Add a migration note for CONNECT requests ( #13554 @kevinpollet )

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPPACKER-1.16.0

v1.16.0

1.16.0 (July 24, 2026) FEATURES: provenance: add new provenance post-processor and packer verify-attestation command for SLSA Build L1/L2 supply-chain attestations. Derives in-toto subjects from Packer artifacts, builds SLSA Provenance v1 predicates with Git/CI metadata, and signs via local PEM key, cloud KMS ( awskms:// , gcpkms:// , azurekms:// , hashivault:// ), or keyless Sigstore (Fulcio + optional Rekor transparency log). Reference CI workflows for L2 keyless and L3-compatible delegated-signing patterns are included under examples/ci/ . GH-13667 core/hcl2: add rfc3339_parse and unix_timestamp_parse template functions. Both accept RFC 3339 timestamps; unix_timestamp_parse additionally accepts Unix epoch integers. GH-13669 core/hcl2: add continue_on_error meta-argument to provisioner blocks. When set to true , a provisioner failure is logged and the build continues rather than halting. GH-13674 core/hcl2: variable object types now support optional() attribute modifiers, allowing object variables to declare per-attribute defaults and omit fields that have a default set. GH-13670 BUG FIXES: plugin/getter: prevent path traversal vulnerability in GitHub plugin getter filename handling. GH-13680 build: update build constraints to support arm architecture on FreeBSD. GH-13650 SECURITY: security: drop x/crypto/openpgp by upgrading go-github v33 → v75. GH-13676 security: suppress false positive for GO-2026-5932. GH-13677 deps: bump golang.org/x/crypto to v0.54.0. GH-13672 DEPENDENCIES: deps: bump github.com/hashicorp/packer-plugin-sdk to v0.6.10 . GH-13673 deps: bump github.com/hashicorp/hcp-sdk-go to v0.174.0 . GH-13673 deps: bump github.com/zclconf/go-cty to v1.18.1 . GH-13673 deps: bump github.com/google/go-github v33 → v75. GH-13676 deps: bump golang.org/x/net to v0.56.0 . GH-13664 deps: update various Go module dependencies. GH-13673 INTERNAL: ci: pin GitHub Action refs to latest verified SHAs. GH-13675 chore: remove old website references. GH-13668

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
CLOUDFLARECLOUDFLARED-2026.7.3

2026.7.3

SHA256 Checksums: cloudflared-amd64.pkg: 6ea8e24e33fe530d3bea623ae1625ae22cc13a3937ffebc325556f785d492f2b cloudflared-arm64.pkg: bc33145624dd2a81bf9ff23bce66d720cab06d9f818f6af748245063dafe1b72 cloudflared-darwin-amd64.tgz: e88fe5874d42a94f49a7ea59cabc3722d2962d0449232b0f3b1a426a712e275c cloudflared-darwin-arm64.tgz: f35c50089cd25f77a4cb5a2152036bc26db15aa31fbe11f7995d2e42a4ed6257 cloudflared-fips-linux-amd64: dac96ecb6d017f1a9d128d29dd7b4cbc75124ec3dac0f1492a9552a31dd7702f cloudflared-fips-linux-amd64.deb: 83ff18e7f8e24e5d360ecf5910ea14e07583cf533c0c728697289688b8da3ee1 cloudflared-fips-linux-x86_64.rpm: fc99457f0af90247d8ca7d5697ffbd5deb9600b1c27c35bc87e93f41fa5da152 cloudflared-linux-386: 6c982e77e644644f5bce76781dd2b69ddc0bfa5e1dd1f55f0037850ac0946771 cloudflared-linux-386.deb: 8696320238a9c04102491d032297f99cadb4554f039947d7b58c03524260021e cloudflared-linux-386.rpm: 7adf5ff15897dc584fda148e254c60553a7bbdaecce4b18bebc03fb772f9e0be cloudflared-linux-aarch64.rpm: 133677939d14ba6f9d90ea1bb4c78dfdf1ffacb4c12c60b22a3deb38f8fd9c2a cloudflared-linux-amd64: 9d71c677db00134c1bd4144b7783486b654ad281b1ea62b4972098d19f770f17 cloudflared-linux-amd64.deb: 049777d30f9bf93da6df8bbe31383460eb2aa51a832c6551824d56f9fcc55974 cloudflared-linux-arm: 6dadd979b8833760e9f6d840a6239a8c08c8bcf73b4231ec537f483873f37c73 cloudflared-linux-arm.deb: a12ca7a373cd8f2be0e5a2b3ea9461cbb306402b8b96bddeb862a384aa63cdfc cloudflared-linux-arm.rpm: a0ecd03050646aa2652201c478ec07ba8c96e1860b9c44caa0028a391df25e3d cloudflared-linux-arm64: 65259e652a7bea08bf5df603233ab22b8bf3116af8df9f9206209af6a1b955c0 cloudflared-linux-arm64.deb: d3ea7d22dd337b465da33d6bc1c4b3cfd381407447a2a7d29542c19783430db3 cloudflared-linux-armhf: 2aadbe6416e5c52cb7ebba99119f413a124f358516c17d4ecaacb89a363e8a35 cloudflared-linux-armhf.deb: 3e6f1733d5188a34c787f00dc4c08be94ed6de7790fb8600757bdc68af48aca1 cloudflared-linux-armhf.rpm: cde7c9f2a8c19de3d61d617464119105dc5493bac846d4961e83e84fb7b8a610 cloudflared-linux-x86_64.rpm: 4d4d65759af8079d0c87ed0f03716218479b56c101078ff5ec7e3d99078bcb41 cloudflared-windows-386.exe: d026e39d9be21c70ea652528fda2801e164d5e25688b7b0fb3b65080cbd96503 cloudflared-windows-386.msi: 95147b1471c383e236d2c28f9cd4f3ce2ab276b74ab3da0d22a714df9722b477 cloudflared-windows-amd64.exe: 8635da433b6df8194746e88ed9d2589566c20e38bfc2a80e431a348b7c765841 cloudflared-windows-amd64.msi: 77e432aa86b152335fd1c8e8d37b9cc7fec9859f27fa5885abbc6ec3345c6830

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
DENODENO-2.9.4

v2.9.4

2.9.4 / 2026.07.23 feat(desktop): enable --hmr for React Router ( #35900 ) feat(ext/node): add a byteLength/length parameter to Buffer.indexOf/lastIndexOf/includes ( #35872 ) feat(ext/node): support raw chacha20 cipher in crypto.createCipheriv ( #36016 ) feat: upgrade V8 to 150.2.0 ( #36098 ) fix(add): support --minimum-dependency-age flag in deno add/remove ( #36099 ) fix(cache): store Web Cache under origin data ( #36145 ) fix(canvas): require FFI permission for native window handles ( #36080 ) fix(clean): reject symlinked node_modules cleanup roots ( #36190 ) fix(compile): bump libsui to 0.16.4 to fix Windows resource SizeOfImage ( #36242 ) fix(core): allow dynamic imports during cached module evaluation ( #36258 ) fix(core): bound error graph conversion ( #36070 ) fix(core): enforce JSON requests in FsModuleLoader ( #36137 ) fix(core): handle malformed error constructors ( #36071 ) fix(core): stop rejected dynamic imports before loading ( #36136 ) fix(desktop): make BrowserWindow bindings typeable ( #35907 ) fix(desktop): preserve binding wrappers after lazy op upgrade ( #36065 ) fix(desktop): strip runtime extension from app name ( #36060 ) fix(ext/napi): cancel async sends after close ( #36077 ) fix(ext/napi): scope callback info per invocation ( #36076 ) fix(ext/node): apply backpressure to http2 stream writes ( #36044 ) fix(ext/node): don't leave 0-byte .heapsnapshot files near the heap limit ( #36113 ) fix(ext/node): implement worker_threads.locks via Web Locks ( #35963 ) fix(ext/node): node:sqlite backup() and deserialize() argument validation ( #36127 ) fix(ext/node): retry DNS query when its per-attempt timeout fires ( #35955 ) fix(ext/node): stop http2 file reads on stream close ( #36061 ) fix(ext/web): handle failed webtransport datagram setup ( #36067 ) fix(ext/webidl): implement async_sequence for ReadableStream.from ( #35976 ) fix(fetch): bound multipart part headers ( #36096 ) fix(fmt): keep embedded CSS custom property indentation stable ( #35949 ) fix(fs): require sys permission for umask ( #36222 ) fix(http): preserve trust proxy environment setting ( #36073 ) fix(init): validate temporary node_modules parent ( #36142 ) fix(jupyter): report codemirror_mode as a string ( #36241 ) fix(loader): reject non-JSON modules for JSON imports ( #36135 ) fix(napi): synchronize external string finalizers ( #36078 ) fix(net): clean up cancellation resources on early errors ( #36229 ) fix(net): limit WebTransport handshake frame buffering ( #36068 ) fix(node_http2): clean up destroyed sessions ( #36043 ) fix(node_resolver): handle CJS filesystem path edge cases ( #36112 ) fix(node_stream): handle Web Stream adapter errors ( #36193 ) fix(npm): avoid following lock poll symlinks ( #36192 ) fix(npm): download tarballs from the configured registry instead of registry.npmjs.org ( #36187 ) fix(npm): reject symlinked package materialization dirs ( #36191 ) fix(outdated): keep type-only dependencies in the lockfile ( #36140 ) fix(pack): support file paths longer than the tar name field ( #36105 ) fix(permissions): escape bidi controls in prompts ( #36195 ) fix(process): avoid collisions in Windows stdio pipe names ( #36081 ) fix(publish): constrain generated source rewrites ( #36109 ) fix(release): insert into versions.json in semver order ( #36097 ) fix(rt): isolate extracted native addons ( #36144 ) fix(runtime): bridge console to the inspector regardless of --inspect flag ( #35795 ) fix(runtime): give worker isolate threads the stack size we report ( #36114 ) fix(test): escape control characters in test names ( #36196 ) fix(tests): make npm test registry tolerate a bad advisories request body ( #36138 ) fix(tls): resolve sni requests concurrently ( #36062 ) fix(update): don't downgrade lockfile when npm cache is stale ( #35904 ) fix(webtransport): avoid url parse panic ( #36066 ) fix(webtransport): validate certificate dates ( #36069 ) fix(x): honor --minimum-dependency-age and deno.json minimumDependencyAge ( #36025 ) fix: d

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
OWNCLOUDOWNCLOUD-11.0.0-RC2

v11.0.0-rc2

chore: bump version string to 11.0.0-rc2 ( #41714 ) Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-2FF4549BFE6CF036

WordPress 7.1 Beta 3

WordPress 7.1 Beta 3 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta […]

Published 22 Jul 2026 · Source checked 29 Sep 2026

Release notes and known issues →
HASHICORPNOMAD-2.0.4

v2.0.4

2.0.4 (July 07, 2026) SECURITY: docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task. This is CVE-2026-14891 . [ GH-28190 ] docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896 . [ GH-28177 ] dynamic host volumes: Fixed a bug where users with host-volume-delete in one namespace could delete claims from another namespace [ GH-28205 ] IMPROVEMENTS: cli: Add a -kv-path flag to nomad setup vault to configure the Vault KV mount used by the generated workload policy [ GH-28183 ] cli: Added -json and -t options to the operator autopilot get-config command. [ GH-27991 ] client: Add tunable for Vault default lease duration on templates for paths without leases. [ GH-28199 ] consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [ GH-28106 ] driver: Added optional Init function for task driver plugins [ GH-28104 ] driver: Added optional Shutdown function for task driver plugins [ GH-28102 ] scheduler: Stop failed allocations first when downscaling a task group [ GH-27971 ] DEPRECATIONS: agent: Unauthenticated server join via the CLI or API is deprecated. [ GH-28176 ] BUG FIXES: api: allow using WI tokens on plan endpoint [ GH-28139 ] cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [ GH-28138 ] client: Fixed a bug where a client could panic after an alloc is GC'd [ GH-28187 ] dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [ GH-28198 ] metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [ GH-28170 ] scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [ GH-28097 ] scheduler: Fixed a bug where setting sticky on a static host volume could fail the evaluation instead of being rejected during feasibility checking [ GH-28097 ] scheduler: keep draining batch alloc counted when node is re-enabled [ GH-28018 ] task runner: Improve the memory management for secrets [ GH-28140 ] ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the /v1/jobs/statuses endpoint [ GH-28132 ] ui: fixes an issue where streaming task logs would error [ GH-28137 ]

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.2.9

RabbitMQ 4.2.9

RabbitMQ 4.2.9 is a maintenance release in the 4.2.x release series . It is strongly recommended that you read 4.2.0 release notes in detail if upgrading from a version prior to 4.2.0 . Minimum Supported Erlang Version Important : starting with this release, the minimum supported Erlang version is 27.0 . Erlang/OTP 26 has reached end of life and is no longer supported. GitHub issue: #16914 RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Classic queue index directory paths could accumulate slashes, eventually failing with an enametoolong file system error. GitHub issue: #16833 AMQP 1.0 management operations that declare an exchange with an alternate exchange now verify the necessary permissions on the alternate exchange, matching AMQP 0-9-1. GitHub issue: #16785 AMQP 1.0 management GET /bindings operations now behave consistently with the rest of the binding-related handlers. GitHub issue: #16790 Worker pool processes no longer terminate when they receive an unexpected message. Contributed by @Ayanda-D . GitHub issue: #16666 A race condition between concurrent queue (or virtual host) deletion and a Ra cluster shutdown could log an exception. Contributed by @Ayanda-D . GitHub issue: #16880 A closing channel (connection) that failed to send channel.close_ok on an already terminated writer or socket no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16651 Unexpected failures during channel termination cleanup no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16740 Code paths that use rabbit_queue_type_util:erpc_call/5 now handle more errors. Contributed by @Ayanda-D . GitHub issue: #16701 Nodes could fail to start with a bad_generator exception in rabbit_queue_decorator:select/1 when a quorum queue record in the metadata store had its decorators set to undefined . GitHub issues: #16843 , #16844 Enabling tracing on multiple virtual hosts concurrently could silently drop some of the virtual hosts from the traced set. All virtual host tracing state modifications are now linearized. GitHub issues: #16755 , #16763 Enhancements Password salts are now generated using a cryptographically secure pseudo-random number generator (CSPRNG). GitHub issue: #16775 Socket-level metric collection used by several protocol readers and the management agent now handles concurrently closed connections safely. Inspired by a contribution of @MugemaneBertin2001 . GitHub issues: #16856 , #16832 CLI Tools Bug Fixes rabbitmq-plugins commands now tolerate plugins that are listed as enabled but are not installed. GitHub issue: #16896 rabbitmq-plugins list no longer outputs an empty plugin table when the target node cannot be reached. GitHub issue: #16791 rabbitmq-plugins commands now correctly handle file paths of remote nodes, validate remote nodes in offline mode, and no longer report false positives for rabbitmq-plugins is_enabled . GitHub issue: #16842 Shell (Bash, zsh) command completion fixes. Contributed by @Chr1s70ph . GitHub issue: #16776 Enhancements rabbitmq-queues and rabbitmq-streams now provide transfer_leadership commands for individual queues and streams. GitHub issue: #16757 rabbitmq-upgrade drain safety improvements: the command now handles certain failures more gracefully. Proposed by @MugemaneBertin2001 . GitHub issues: #16865 , #3369 Stream Plugin Bug Fixes Permissions required for certain stream protocol operations were adjusted to be consistent with comparable operations over other protocols. GitHub issue: #16754 Enhancements The maximum number of super stream partitions is now limited to 1,000 partitions by default. This limit can be increased using the stream.max_super_stream_partitions key in rabbitmq.conf . GitHub issues: #16689 , #16706 A client RPC timeout is now logge

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
RABBITMQRABBITMQ-4.3.3

RabbitMQ 4.3.3

RabbitMQ 4.3.3 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version Important : starting with this release, the minimum supported Erlang version is 27.0 . Erlang/OTP 26 has reached end of life and is no longer supported. GitHub issue: #16914 RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Quorum queue, Khepri and other Raft leaders could optimistically commit new log entries in certain scenarios. GitHub issue: rabbitmq/ra#637 Quorum queues that use at-least-once dead lettering could get their dead lettering process permanently stuck after repeated queue membership changes. GitHub issue: #16652 Classic queue index directory paths could accumulate slashes, eventually failing with an enametoolong file system error. GitHub issue: #16833 Enabling the tie_binding_to_dest_with_keep_while_cond feature flag could fail with an exception when certain exchange-to-exchange topologies. GitHub issue: #16824 An invalid consumer_timeout value in the configuration now falls back to the default value (24 hours) instead of being used as is. GitHub issue: #16799 AMQP 1.0 management operations that declare an exchange with an alternate exchange now verify the necessary permissions on the alternate exchange, matching AMQP 0-9-1. GitHub issue: #16785 AMQP 1.0 management GET /bindings operations now behave consistently with the rest of the binding-related handlers. GitHub issue: #16790 Worker pool processes no longer terminate when they receive an unexpected message. Contributed by @Ayanda-D . GitHub issue: #16666 A race condition between concurrent queue (or virtual host) deletion and a Ra cluster shutdown could log an exception. Contributed by @Ayanda-D . GitHub issue: #16880 A closing channel (connection) that failed to send channel.close_ok on an already terminated writer or socket no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16651 Unexpected failures during channel termination cleanup no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16740 Code paths that use rabbit_queue_type_util:erpc_call/5 now handle more errors. Contributed by @Ayanda-D . GitHub issue: #16701 Nodes could fail to start with a bad_generator exception in rabbit_queue_decorator:select/1 when a quorum queue record in the metadata store had its decorators set to undefined . GitHub issues: #16843 , #16844 Enabling tracing on multiple virtual hosts concurrently could silently drop some of the virtual hosts from the traced set. All virtual host tracing state modifications are now linearized. GitHub issues: #16755 , #16763 Enhancements Password salts are now generated using a cryptographically secure pseudo-random number generator (CSPRNG). GitHub issue: #16775 Socket-level metric collection used by several protocol readers and the management agent now handles concurrently closed connections safely. Inspired by a contribution of @MugemaneBertin2001 . GitHub issues: #16856 , #16832 CLI Tools Bug Fixes rabbitmq-plugins commands now tolerate plugins that are listed as enabled but are not installed. GitHub issue: #16896 rabbitmq-plugins list no longer outputs an empty plugin table when the target node cannot be reached. GitHub issue: #16791 rabbitmq-plugins commands now correctly handle file paths of remote nodes, validate remote nodes in offline mode, and no longer report false positives for rabbitmq-plugins is_enabled . GitHub issue: #16842 Shell (Bash, zsh) command completion fixes. Contributed by @Chr1s70ph . GitHub issue: #16776 Enhancements rabbitmq-queues and rabbitmq-streams now provide transfer_leadership commands for individual queues and streams. GitHub issue

Published Never · Source checked 29 Sep 2026

Release notes and known issues →
WORDPRESSWORDPRESS-7.0.2

WordPress 7.0.2 Release

WordPress 7.0.2 is now available. The 7.0.2 security release addresses one critical and one high severity security issue. Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions. To manually […]

Published 17 Jul 2026 · Source checked 26 Sep 2026

Release notes and known issues →