MICROSOFTMICROSOFT-AZURE-9849144216147346
Azure Private Link over IPv6 enables you to privately access Azure PaaS services, such as Azure Storage and Azure SQL Database, over IPv6-based connectivity. You can now use IPv6 private endpoints to connect from IPv6 clients in an Azure virtual network o
Published 4 Aug 2026 · Source checked 28 Sep 2026
Release notes and known issues →HASHICORPVAULT-2.0.4
2.0.4 August 04, 2026 BREAKING CHANGES: containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps. SECURITY: acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters / denied_parameters constraints. identity/scim (enterprise): The identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries. identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace. identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity CHANGES: auth/oci: Update plugin to v0.21.3 core: Bump Go version to 1.26.5. core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with duplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment variable that previously restored the legacy behavior has been removed. FEATURES: secrets: Added ability to view secrets in YAML format IMPROVEMENTS: auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener. core (enterprise): Add an endpoint at sys/config/oauth-resource-server/id/:config_id to read oauth resource server profiles by config_id core (enterprise): Make OAuth resource server JWT typ validation more permissive for tokens from IdPs such as Okta by allowing a missing typ header, while restricting present typ values to at+jwt , application/at+jwt , and JWT . core (entreprise): Ameriolate sealwrap lock contention for core paths. core/acl: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/identity: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/managed-keys/PKCS#11 (enterprise): Providing a non-empty value for one field while the other is already saved is rejected. To switch addressing modes, you must explicitly clear the old field by sending it as an empty string ("") in the same request alongside the new value. core/managed-keys/PKCS#11 (enterprise): slot and token_label are now strictly enforced as mutually exclusive identifiers for an HSM token events: Add VAULT_EVENT_NOTIFICATIONS_BOUNDED_QUEUE_SIZE environment variable to configure bounded event queues for event notification subscribers. Set to a positive integer (e.g., 16) to enable buffered channels of that size (maximum 1000). This prevents resource exhaustion in deployments with high subscriber counts, but comes at the cost of the potential for subscribers to miss events. Defaults to 0 (unbuffered) for backward compatibility. identity/scim (enterprise): Added filtering support to the GET /scim/v2/Users and GET /scim/v2/Groups endpoints per RFC 7644. Supported filters: userName eq , externalId eq , active eq , and meta.lastModified gt/ge/lt/le for Users; displayName eq and meta.lastModified gt/ge/lt/le for Groups. Unsupported filter expressions return HTTP 400. ServiceProviderConfig now advertises filter.supported: true . identity/scim (enterprise): Improve SCIM User and Group listing endpoint performance by using prefix sort instead of a separate sort pass. identity: Include entity status and entity/alias timestamp details in entity list key_info responses. oauth-resource-server: Add support for fine-grained policy control options (par
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CEPHCEPH-20.2.3
v20.2.3
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.4.0
What's Changed ℹ️ This release introduces a new way to reconcile resources such as volumes and networks ✨ Improvements Feat(reconcile): model volume recreation in the plan by @ndeloof in #13962 Feat(reconcile): model network lifecycle in the plan by @ndeloof in #13966 🐛 Fixes Fix(reconcile): preserve zero-replica services during hashing by @junhaoliao in #13931 Fix(config): warn when service selection is silently ignored by @glours in #13950 Fix(build): use platform image-manifest digest, not attested index by @glours in #13949 Fix(oci): honor --insecure-registry when up re-loads the model by @ptrdom in #13894 Fix(config): pin type:image volume sources and pre_start hook images by @glours in #13956 Tolerate missing env file on more runtime commands by @maxproske in #13603 Resolve pre_start hook images alongside service images by @ndeloof in #13937 Fix(cp): return non-nil Content from dry-run CopyFromContainer by @glours in #13982 Fix(config): apply config flags to --services / --volumes / --networks / --models / --hash by @glours in #13979 Fix: tolerate missing env file on scale, watch and shell completion by @glours in #13973 🔧 Internal README: remove Go Report Card badge by @thaJeztah in #13926 Docs: adopt AGENTS.md standard, symlink CLAUDE.md to it by @glours in #13871 Dockerfile: update golang image to alpine 3.23 by @thaJeztah in #13921 Docs: require dated AI_AGENT_DISCLOSURE.md , drop committed copy by @glours in #13976 CI: publish images to Docker Hub using OIDC by @glours in #13994 ⚙️ Dependencies Build(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0 by @dependabot [bot] in #13942 Build(deps): bump the docker-actions group across 1 directory with 4 updates by @dependabot [bot] in #13941 Build(deps): bump actions/stale from 10.3.0 to 10.4.0 by @dependabot [bot] in #13943 Build(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 by @dependabot [bot] in #13948 Build(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 by @dependabot [bot] in #13927 Build(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0 by @dependabot [bot] in #13928 Build(deps): bump docker/github-builder/.github/workflows/bake.yml from 1.13.0 to 1.14.0 in the docker-actions group by @dependabot [bot] in #13953 Build(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 by @dependabot [bot] in #13922 Build(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 by @dependabot [bot] in #13955 Build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by @dependabot [bot] in #13960 Build(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 in the go_modules group across 1 directory by @dependabot [bot] in #13961 Build(deps): bump github.com/docker/cli from 29.6.1+incompatible to 29.6.2+incompatible by @dependabot [bot] in #13968 Build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3 by @dependabot [bot] in #13981 Build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot [bot] in #13970 Build(deps): bump github.com/moby/buildkit from 0.31.1 to 0.31.2 by @dependabot [bot] in #13969 Bump compose-go to version v2.14.0 by @glours in #13983 Bump go-archive to version v0.3.0 by @glours in #13986 Build(deps): bump docker/github-builder/.github/workflows/bake.yml from 1.14.0 to 1.15.0 in the docker-actions group by @dependabot [bot] in #13989 Chore(deps): bump github.com/moby/go-archive v0.3.2 by @thaJeztah in #13991 Update to go1.26.5 by @thaJeztah in #13920 Build(deps): bump actions/stale from 10.4.0 to 11.0.0 by @dependabot [bot] in #13996 Build(deps): bump docker/docker-agent-action/.github/workflows/review-pr.yml from 2.0.2 to 2.0.3 in the docker-actions group by @dependabot [bot] in #13995 Build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by @dependabot [bot] in #13984 Chore(deps): github.com/docker/buildx v0.36.0 , buildkit v0.32.0 by @glours in #13975 Bump buildkit v0.32.1 by @glours in #13997 New Contributors @junhaoliao made their first contribution in #13931 Full Changelog :
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENJS FOUNDATIONNODEJS-26.6.0
Notable Changes [ 5a36018abc ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ 9b04f82d7b ] - (SEMVER-MINOR) ffi : add getCurrentEventLoop (Paolo Insogna) #64323 [ bb51f2c960 ] - (SEMVER-MINOR) test_runner : add context.log() and test:log event (Moshe Atlow) #64389 [ 56ce83b3ee ] - (SEMVER-MINOR) test_runner : report entryFile in TestStream events (Moshe Atlow) #64309 Commits [ 248ff9fa5c ] - assert,util : fix TypeError on Maps with null keys (Paul Bouchon) #64441 [ 3b5baceafe ] - benchmark : add bytes variant to webstreams async-iterator (Matteo Collina) #64291 [ 0a46d1ef66 ] - buffer : normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115 [ d9ada18b70 ] - buffer : fix Blob.stream() leaking source buffer (semimikoh) #63577 [ d05993bcf6 ] - build : merge multiple on download artifact (Chengzhong Wu) #64633 [ 6c25ac909a ] - build : extract temporal_capi crate directory name into gyp variable (René) #64482 [ 612f60c300 ] - cli : style node --help output with util.styleText (Adrián Estrada) #64484 [ 29a938ddbb ] - crypto : preserve RSA-PSS legacy pubkey DER (Filip Skokan) #64547 [ 2fde794357 ] - crypto : cleanse provider private key copies (Filip Skokan) #64547 [ 33a0e08d41 ] - crypto : handle incomplete RSA private keys (Filip Skokan) #64547 [ 11b4d505ef ] - crypto : retain legacy DH validation (Filip Skokan) #64547 [ 6e302041e1 ] - crypto : limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) #64557 [ 195f103e87 ] - crypto : split OpenSSL 3, BoringSSL, and legacy backends (Filip Skokan) #64211 [ ec67e24eee ] - deps : update googletest to fa005b296f90faec4f352d7ab382287bf6548c8d (Node.js GitHub Bot) #64587 [ 32ffff88fd ] - deps : histogram: cherry-pick 62ea52b07ee9b195 (StefanStojanovic) #64296 [ e0664f1f09 ] - deps : update histogram to 0.11.10 (Node.js GitHub Bot) #64296 [ cf0622bdd6 ] - deps : update amaro to 1.1.11 (Node.js GitHub Bot) #64586 [ 04c78b8b24 ] - deps : update timezone to 2026c (Node.js GitHub Bot) #64588 [ 59f4318976 ] - deps : V8: cherry-pick 1158ae719749 (René) #64432 [ e5ea7cd299 ] - deps : update googletest to 8240fa7d62f73e01c7af27d61ed965d6d66698fa (Node.js GitHub Bot) #64439 [ 0e7554cee4 ] - deps : update libffi to 3.7.1 (Node.js GitHub Bot) #64438 [ 46c9d724ad ] - deps : update ngtcp2 to 1.24.0 (Node.js GitHub Bot) #64297 [ 3519aac9af ] - deps : enable OpenSSL asm support for riscv64 (Jamie Magee) #62606 [ c09701218b ] - deps : update c-ares to 1.34.8 (Node.js GitHub Bot) #64330 [ ad2f3bc95b ] - deps : upgrade npm to 11.18.0 (npm team) #64199 [ d7a4b22c86 ] - deps : V8: backport a05321ebd98e (Chengzhong Wu) #64202 [ 8679cff291 ] - deps : update zlib to 1.3.2.1-motley-8b3aa8a (Node.js GitHub Bot) #64295 [ df5b1e10ba ] - doc : remove unsupported syntax from stream_iter.md (Antoine du Hamel) #64649 [ 8a4ca9083f ] - doc : clarify rules for adding new built-in modules (Antoine du Hamel) #64648 [ 7d50fe6b7a ] - doc : mention DEPENDENCY custom field for H1 reports (Rafael Gonzaga) #64634 [ 8f415bf5fc ] - doc : fix dnsPromises.lookup verbatim default (Shivam S) #64658 [ c6378f724d ] - doc : fix broken links and clean up type map (Antoine du Hamel) #64625 [ 9b53ec19a2 ] - doc : fix typo in releases guide (Jihwan) #64621 [ 5a36018abc ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ d2c8acd764 ] - doc : use promote wording in release guide (Md Muhtasim Munif Fahim) #64371 [ 5c692cb576 ] - doc : fix import.meta example for vm.SourceTextModule (Muhammad Zeeshan) #64112 [ 7568ce71ca ] - doc : mention crypto.hash() for better perf (Steven) #63420 [ cf3f631936 ] - doc : update sea example by fixing wrong code example (Maxence Robinet) #64025 [ ce21e567a4 ] - doc : fix socket.readyState state descriptions (YuSheng Chen) #64468 [ 018c7f1c01 ] - doc : replace large tables in crypto.md and webcrypto.md with lists (Filip Skokan) #64582 [ cf82de8d8b ] - doc : note --env-file is not applied to --run (Paul Bouchon) #64442 [ e635ce5201 ] - doc : fix typo in embed
Published Never · Source checked 29 Sep 2026
Release notes and known issues →TRAEFIK LABSTRAEFIK-2.11.54
CVE fixed: Advisory GHSA-62fc-8686-hfmq Bug fixes: [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ( #13530 @kevinpollet ) Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ( #13574 @mmatur ) [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider ( #13573 @gndz07 ) [middleware] Bump github.com/klauspost/compress to v1.18.7 ( #13587 @mmatur )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →TRAEFIK LABSTRAEFIK-3.6.25
CVE fixed: Advisory GHSA-fgjj-px3w-67xx Advisory GHSA-62fc-8686-hfmq Advisory GHSA-6765-c87h-8mrf Bug fixes: [acme] Bump github.com/go-acme/lego/v5 to v5.3.1 ( #13547 @ldez ) [middleware, authentication] Fix auth singleflight key collision ( #13572 @mmatur ) [k8s/gatewayapi] Avoid router name collisions in Kubernetes Gateway API provider ( #13580 @gndz07 ) [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ( #13530 @kevinpollet ) Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ( #13574 @mmatur ) [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider ( #13573 @gndz07 ) [middleware] Bump github.com/klauspost/compress to v1.18.7 ( #13587 @mmatur )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →TRAEFIK LABSTRAEFIK-3.7.10
CVE fixed: Advisory GHSA-fgjj-px3w-67xx Advisory GHSA-62fc-8686-hfmq Advisory GHSA-6765-c87h-8mrf Bug fixes: [acme] Bump github.com/go-acme/lego/v5 to v5.3.1 ( #13547 @ldez ) [middleware, authentication] Fix auth singleflight key collision ( #13572 @mmatur ) [k8s/gatewayapi] Avoid router name collisions in Kubernetes Gateway API provider ( #13580 @gndz07 ) [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ( #13530 @kevinpollet ) Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ( #13574 @mmatur ) [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider ( #13573 @gndz07 ) [middleware] Bump github.com/klauspost/compress to v1.18.7 ( #13587 @mmatur ) [k8s/gatewayapi] Bump sigs.k8s.io/gateway-api to v1.6.1 ( #13589 @rtribotte ) Documentation: [k8s/ingress-nginx] Clarify auth-url/rewrite-target interaction on ingress-nginx provider ( #13607 @gndz07 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OWNCLOUDOWNCLOUD-10.16.4
Classic ownCloud Server 10.16.4. Archives mirrored from https://download.owncloud.com/server/stable . This is a security release. Upgrading is strongly recommended for all installations. See the release notes for details: https://doc.owncloud.com/server_release_notes.html#changes-in-10-16-4
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OWNCLOUDOWNCLOUD-11.0.0
Classic ownCloud Server 11.0.0 — the first major release of the 11.x line. This release contains 11 security fixes. Upgrading is strongly recommended for all installations. Full changelog: https://github.com/owncloud/core/blob/v11.0.0/CHANGELOG.md (47 entries: 11 security, 19 bugfixes, 17 changes.) Highlights PHP 8.3 is now the minimum supported version. G2 code signing. Releases are signed with the new per-app G2 PKI (ECDSA-P384/SHA-384, one CN-matched leaf per app, chaining to the G2 root). G1 signatures are sunset and occ integrity:sign-app / integrity:sign-core have been removed. Legacy and deprecated code inherited from earlier releases has been removed — see the Change entries for the full list, including the dropped db:convert-type command and the removal of the caching router. The group-admin feature is now disabled by default behind allow_subadmins . Upgrading Upgrades are supported from 8.2.11, 9.0.9, and 9.1 onwards. Review the Change section of the changelog before upgrading: this is a major release and several deprecated features and commands have been removed. Downloads Four variants are published here, each as .tar.bz2 and .zip with .asc / .md5 / .sha256 sidecars: Variant Asset Server owncloud-11.0.0 Server + test apps (QA) owncloud-11.0.0-qa Complete bundle owncloud-complete-20260730 Complete bundle (QA) owncloud-complete-20260730-qa Verify a download against the release signing key: gpg --verify owncloud-11.0.0.tar.bz2.asc owncloud-11.0.0.tar.bz2 # Good signature from "ownCloud Release Signing <releases@owncloud.com>" # Primary key fingerprint: A84D B0E2 D0F0 F587 A04E FC69 BAC1 ADE9 1978 CC39
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OWNCLOUDOWNCLOUD-11.0.0-RC3
chore: bump version string to 11.0.0-rc3 ( #41755 ) Bump `$OC_VersionString` from 11.0.0-rc2 to 11.0.0-rc3 for the upcoming 11.0.0-rc3 release. The code ($OC_Version) is unchanged; this only updates the human-readable version string reported by the server. Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Published Never · Source checked 29 Sep 2026
Release notes and known issues →WORDPRESSWORDPRESS-AA459772D860758D
WordPress 7.1 Beta 4 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta […]
Published 29 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →ZABBIXZABBIX-7.4.13
.......... [ZBXNEXT-826] release of 7.4.13
Published Never · Source checked 29 Sep 2026
Release notes and known issues →ZABBIXZABBIX-7.0.29
.......... [ZBXNEXT-826] release of 7.0.29
Published Never · Source checked 29 Sep 2026
Release notes and known issues →TRAEFIK LABSTRAEFIK-3.7.9
Important: Please read the migration guide . CVE fixed: Advisory GHSA-3ccp-42pg-hgv6 Bug fixes: [k8s/ingress-nginx] Fix redirect with use-regex in IngressNGINX provider ( #13476 @AmariahAK ) [middleware] Disable Zstd support in the gzhttp wrapper ( #13533 @kevinpollet ) [server] Defer the CONNECT payload until the backend accepts the tunnel ( #13542 @sdelicata ) [server] Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy ( #13543 @sdelicata ) [server] Bump google.golang.org/grpc to v1.82.1 ( #13551 @piscue ) [server] Do not add back CONNECT requests to the pool ( #13556 @kevinpollet ) Documentation: [k8s/gatewayapi] Document Gateway API generated service names change in the migration guide ( #13541 @rtribotte ) [k8s/ingress-nginx] Fix typo in nginx annotation proxy-buffer-numbers ( #13545 @fischerman ) Add a migration note for CONNECT requests ( #13554 @kevinpollet )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →KEYCLOAKKEYCLOAK-26.6.5
Signed-off-by: stianst stianst@gmail.com
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPPACKER-1.16.0
1.16.0 (July 24, 2026) FEATURES: provenance: add new provenance post-processor and packer verify-attestation command for SLSA Build L1/L2 supply-chain attestations. Derives in-toto subjects from Packer artifacts, builds SLSA Provenance v1 predicates with Git/CI metadata, and signs via local PEM key, cloud KMS ( awskms:// , gcpkms:// , azurekms:// , hashivault:// ), or keyless Sigstore (Fulcio + optional Rekor transparency log). Reference CI workflows for L2 keyless and L3-compatible delegated-signing patterns are included under examples/ci/ . GH-13667 core/hcl2: add rfc3339_parse and unix_timestamp_parse template functions. Both accept RFC 3339 timestamps; unix_timestamp_parse additionally accepts Unix epoch integers. GH-13669 core/hcl2: add continue_on_error meta-argument to provisioner blocks. When set to true , a provisioner failure is logged and the build continues rather than halting. GH-13674 core/hcl2: variable object types now support optional() attribute modifiers, allowing object variables to declare per-attribute defaults and omit fields that have a default set. GH-13670 BUG FIXES: plugin/getter: prevent path traversal vulnerability in GitHub plugin getter filename handling. GH-13680 build: update build constraints to support arm architecture on FreeBSD. GH-13650 SECURITY: security: drop x/crypto/openpgp by upgrading go-github v33 → v75. GH-13676 security: suppress false positive for GO-2026-5932. GH-13677 deps: bump golang.org/x/crypto to v0.54.0. GH-13672 DEPENDENCIES: deps: bump github.com/hashicorp/packer-plugin-sdk to v0.6.10 . GH-13673 deps: bump github.com/hashicorp/hcp-sdk-go to v0.174.0 . GH-13673 deps: bump github.com/zclconf/go-cty to v1.18.1 . GH-13673 deps: bump github.com/google/go-github v33 → v75. GH-13676 deps: bump golang.org/x/net to v0.56.0 . GH-13664 deps: update various Go module dependencies. GH-13673 INTERNAL: ci: pin GitHub Action refs to latest verified SHAs. GH-13675 chore: remove old website references. GH-13668
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CLOUDFLARECLOUDFLARED-2026.7.3
SHA256 Checksums: cloudflared-amd64.pkg: 6ea8e24e33fe530d3bea623ae1625ae22cc13a3937ffebc325556f785d492f2b cloudflared-arm64.pkg: bc33145624dd2a81bf9ff23bce66d720cab06d9f818f6af748245063dafe1b72 cloudflared-darwin-amd64.tgz: e88fe5874d42a94f49a7ea59cabc3722d2962d0449232b0f3b1a426a712e275c cloudflared-darwin-arm64.tgz: f35c50089cd25f77a4cb5a2152036bc26db15aa31fbe11f7995d2e42a4ed6257 cloudflared-fips-linux-amd64: dac96ecb6d017f1a9d128d29dd7b4cbc75124ec3dac0f1492a9552a31dd7702f cloudflared-fips-linux-amd64.deb: 83ff18e7f8e24e5d360ecf5910ea14e07583cf533c0c728697289688b8da3ee1 cloudflared-fips-linux-x86_64.rpm: fc99457f0af90247d8ca7d5697ffbd5deb9600b1c27c35bc87e93f41fa5da152 cloudflared-linux-386: 6c982e77e644644f5bce76781dd2b69ddc0bfa5e1dd1f55f0037850ac0946771 cloudflared-linux-386.deb: 8696320238a9c04102491d032297f99cadb4554f039947d7b58c03524260021e cloudflared-linux-386.rpm: 7adf5ff15897dc584fda148e254c60553a7bbdaecce4b18bebc03fb772f9e0be cloudflared-linux-aarch64.rpm: 133677939d14ba6f9d90ea1bb4c78dfdf1ffacb4c12c60b22a3deb38f8fd9c2a cloudflared-linux-amd64: 9d71c677db00134c1bd4144b7783486b654ad281b1ea62b4972098d19f770f17 cloudflared-linux-amd64.deb: 049777d30f9bf93da6df8bbe31383460eb2aa51a832c6551824d56f9fcc55974 cloudflared-linux-arm: 6dadd979b8833760e9f6d840a6239a8c08c8bcf73b4231ec537f483873f37c73 cloudflared-linux-arm.deb: a12ca7a373cd8f2be0e5a2b3ea9461cbb306402b8b96bddeb862a384aa63cdfc cloudflared-linux-arm.rpm: a0ecd03050646aa2652201c478ec07ba8c96e1860b9c44caa0028a391df25e3d cloudflared-linux-arm64: 65259e652a7bea08bf5df603233ab22b8bf3116af8df9f9206209af6a1b955c0 cloudflared-linux-arm64.deb: d3ea7d22dd337b465da33d6bc1c4b3cfd381407447a2a7d29542c19783430db3 cloudflared-linux-armhf: 2aadbe6416e5c52cb7ebba99119f413a124f358516c17d4ecaacb89a363e8a35 cloudflared-linux-armhf.deb: 3e6f1733d5188a34c787f00dc4c08be94ed6de7790fb8600757bdc68af48aca1 cloudflared-linux-armhf.rpm: cde7c9f2a8c19de3d61d617464119105dc5493bac846d4961e83e84fb7b8a610 cloudflared-linux-x86_64.rpm: 4d4d65759af8079d0c87ed0f03716218479b56c101078ff5ec7e3d99078bcb41 cloudflared-windows-386.exe: d026e39d9be21c70ea652528fda2801e164d5e25688b7b0fb3b65080cbd96503 cloudflared-windows-386.msi: 95147b1471c383e236d2c28f9cd4f3ce2ab276b74ab3da0d22a714df9722b477 cloudflared-windows-amd64.exe: 8635da433b6df8194746e88ed9d2589566c20e38bfc2a80e431a348b7c765841 cloudflared-windows-amd64.msi: 77e432aa86b152335fd1c8e8d37b9cc7fec9859f27fa5885abbc6ec3345c6830
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DENODENO-2.9.4
2.9.4 / 2026.07.23 feat(desktop): enable --hmr for React Router ( #35900 ) feat(ext/node): add a byteLength/length parameter to Buffer.indexOf/lastIndexOf/includes ( #35872 ) feat(ext/node): support raw chacha20 cipher in crypto.createCipheriv ( #36016 ) feat: upgrade V8 to 150.2.0 ( #36098 ) fix(add): support --minimum-dependency-age flag in deno add/remove ( #36099 ) fix(cache): store Web Cache under origin data ( #36145 ) fix(canvas): require FFI permission for native window handles ( #36080 ) fix(clean): reject symlinked node_modules cleanup roots ( #36190 ) fix(compile): bump libsui to 0.16.4 to fix Windows resource SizeOfImage ( #36242 ) fix(core): allow dynamic imports during cached module evaluation ( #36258 ) fix(core): bound error graph conversion ( #36070 ) fix(core): enforce JSON requests in FsModuleLoader ( #36137 ) fix(core): handle malformed error constructors ( #36071 ) fix(core): stop rejected dynamic imports before loading ( #36136 ) fix(desktop): make BrowserWindow bindings typeable ( #35907 ) fix(desktop): preserve binding wrappers after lazy op upgrade ( #36065 ) fix(desktop): strip runtime extension from app name ( #36060 ) fix(ext/napi): cancel async sends after close ( #36077 ) fix(ext/napi): scope callback info per invocation ( #36076 ) fix(ext/node): apply backpressure to http2 stream writes ( #36044 ) fix(ext/node): don't leave 0-byte .heapsnapshot files near the heap limit ( #36113 ) fix(ext/node): implement worker_threads.locks via Web Locks ( #35963 ) fix(ext/node): node:sqlite backup() and deserialize() argument validation ( #36127 ) fix(ext/node): retry DNS query when its per-attempt timeout fires ( #35955 ) fix(ext/node): stop http2 file reads on stream close ( #36061 ) fix(ext/web): handle failed webtransport datagram setup ( #36067 ) fix(ext/webidl): implement async_sequence for ReadableStream.from ( #35976 ) fix(fetch): bound multipart part headers ( #36096 ) fix(fmt): keep embedded CSS custom property indentation stable ( #35949 ) fix(fs): require sys permission for umask ( #36222 ) fix(http): preserve trust proxy environment setting ( #36073 ) fix(init): validate temporary node_modules parent ( #36142 ) fix(jupyter): report codemirror_mode as a string ( #36241 ) fix(loader): reject non-JSON modules for JSON imports ( #36135 ) fix(napi): synchronize external string finalizers ( #36078 ) fix(net): clean up cancellation resources on early errors ( #36229 ) fix(net): limit WebTransport handshake frame buffering ( #36068 ) fix(node_http2): clean up destroyed sessions ( #36043 ) fix(node_resolver): handle CJS filesystem path edge cases ( #36112 ) fix(node_stream): handle Web Stream adapter errors ( #36193 ) fix(npm): avoid following lock poll symlinks ( #36192 ) fix(npm): download tarballs from the configured registry instead of registry.npmjs.org ( #36187 ) fix(npm): reject symlinked package materialization dirs ( #36191 ) fix(outdated): keep type-only dependencies in the lockfile ( #36140 ) fix(pack): support file paths longer than the tar name field ( #36105 ) fix(permissions): escape bidi controls in prompts ( #36195 ) fix(process): avoid collisions in Windows stdio pipe names ( #36081 ) fix(publish): constrain generated source rewrites ( #36109 ) fix(release): insert into versions.json in semver order ( #36097 ) fix(rt): isolate extracted native addons ( #36144 ) fix(runtime): bridge console to the inspector regardless of --inspect flag ( #35795 ) fix(runtime): give worker isolate threads the stack size we report ( #36114 ) fix(test): escape control characters in test names ( #36196 ) fix(tests): make npm test registry tolerate a bad advisories request body ( #36138 ) fix(tls): resolve sni requests concurrently ( #36062 ) fix(update): don't downgrade lockfile when npm cache is stale ( #35904 ) fix(webtransport): avoid url parse panic ( #36066 ) fix(webtransport): validate certificate dates ( #36069 ) fix(x): honor --minimum-dependency-age and deno.json minimumDependencyAge ( #36025 ) fix: d
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DRUPALDRUPAL-10.6.14
Drupal 10.6.14
Published Never · Source checked 26 Sep 2026
Release notes and known issues →DRUPALDRUPAL-11.3.16
Drupal 11.3.16
Published Never · Source checked 26 Sep 2026
Release notes and known issues →OWNCLOUDOWNCLOUD-11.0.0-RC2
chore: bump version string to 11.0.0-rc2 ( #41714 ) Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
Published Never · Source checked 29 Sep 2026
Release notes and known issues →WORDPRESSWORDPRESS-2FF4549BFE6CF036
WordPress 7.1 Beta 3 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta […]
Published 22 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →METAREACT-19.0.8
React Server Components Performance improvements when decoding ( #37089 by @eps1lon )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →METAREACT-19.1.9
React Server Components Performance improvements when decoding ( #37088 by @eps1lon )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →METAREACT-19.2.8
React Server Components Performance improvements when decoding ( #37087 by @eps1lon )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPNOMAD-2.0.4
2.0.4 (July 07, 2026) SECURITY: docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task. This is CVE-2026-14891 . [ GH-28190 ] docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896 . [ GH-28177 ] dynamic host volumes: Fixed a bug where users with host-volume-delete in one namespace could delete claims from another namespace [ GH-28205 ] IMPROVEMENTS: cli: Add a -kv-path flag to nomad setup vault to configure the Vault KV mount used by the generated workload policy [ GH-28183 ] cli: Added -json and -t options to the operator autopilot get-config command. [ GH-27991 ] client: Add tunable for Vault default lease duration on templates for paths without leases. [ GH-28199 ] consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [ GH-28106 ] driver: Added optional Init function for task driver plugins [ GH-28104 ] driver: Added optional Shutdown function for task driver plugins [ GH-28102 ] scheduler: Stop failed allocations first when downscaling a task group [ GH-27971 ] DEPRECATIONS: agent: Unauthenticated server join via the CLI or API is deprecated. [ GH-28176 ] BUG FIXES: api: allow using WI tokens on plan endpoint [ GH-28139 ] cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [ GH-28138 ] client: Fixed a bug where a client could panic after an alloc is GC'd [ GH-28187 ] dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [ GH-28198 ] metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [ GH-28170 ] scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [ GH-28097 ] scheduler: Fixed a bug where setting sticky on a static host volume could fail the evaluation instead of being rejected during feasibility checking [ GH-28097 ] scheduler: keep draining batch alloc counted when node is re-enabled [ GH-28018 ] task runner: Improve the memory management for secrets [ GH-28140 ] ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the /v1/jobs/statuses endpoint [ GH-28132 ] ui: fixes an issue where streaming task logs would error [ GH-28137 ]
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RABBITMQRABBITMQ-4.2.9
RabbitMQ 4.2.9 is a maintenance release in the 4.2.x release series . It is strongly recommended that you read 4.2.0 release notes in detail if upgrading from a version prior to 4.2.0 . Minimum Supported Erlang Version Important : starting with this release, the minimum supported Erlang version is 27.0 . Erlang/OTP 26 has reached end of life and is no longer supported. GitHub issue: #16914 RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Classic queue index directory paths could accumulate slashes, eventually failing with an enametoolong file system error. GitHub issue: #16833 AMQP 1.0 management operations that declare an exchange with an alternate exchange now verify the necessary permissions on the alternate exchange, matching AMQP 0-9-1. GitHub issue: #16785 AMQP 1.0 management GET /bindings operations now behave consistently with the rest of the binding-related handlers. GitHub issue: #16790 Worker pool processes no longer terminate when they receive an unexpected message. Contributed by @Ayanda-D . GitHub issue: #16666 A race condition between concurrent queue (or virtual host) deletion and a Ra cluster shutdown could log an exception. Contributed by @Ayanda-D . GitHub issue: #16880 A closing channel (connection) that failed to send channel.close_ok on an already terminated writer or socket no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16651 Unexpected failures during channel termination cleanup no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16740 Code paths that use rabbit_queue_type_util:erpc_call/5 now handle more errors. Contributed by @Ayanda-D . GitHub issue: #16701 Nodes could fail to start with a bad_generator exception in rabbit_queue_decorator:select/1 when a quorum queue record in the metadata store had its decorators set to undefined . GitHub issues: #16843 , #16844 Enabling tracing on multiple virtual hosts concurrently could silently drop some of the virtual hosts from the traced set. All virtual host tracing state modifications are now linearized. GitHub issues: #16755 , #16763 Enhancements Password salts are now generated using a cryptographically secure pseudo-random number generator (CSPRNG). GitHub issue: #16775 Socket-level metric collection used by several protocol readers and the management agent now handles concurrently closed connections safely. Inspired by a contribution of @MugemaneBertin2001 . GitHub issues: #16856 , #16832 CLI Tools Bug Fixes rabbitmq-plugins commands now tolerate plugins that are listed as enabled but are not installed. GitHub issue: #16896 rabbitmq-plugins list no longer outputs an empty plugin table when the target node cannot be reached. GitHub issue: #16791 rabbitmq-plugins commands now correctly handle file paths of remote nodes, validate remote nodes in offline mode, and no longer report false positives for rabbitmq-plugins is_enabled . GitHub issue: #16842 Shell (Bash, zsh) command completion fixes. Contributed by @Chr1s70ph . GitHub issue: #16776 Enhancements rabbitmq-queues and rabbitmq-streams now provide transfer_leadership commands for individual queues and streams. GitHub issue: #16757 rabbitmq-upgrade drain safety improvements: the command now handles certain failures more gracefully. Proposed by @MugemaneBertin2001 . GitHub issues: #16865 , #3369 Stream Plugin Bug Fixes Permissions required for certain stream protocol operations were adjusted to be consistent with comparable operations over other protocols. GitHub issue: #16754 Enhancements The maximum number of super stream partitions is now limited to 1,000 partitions by default. This limit can be increased using the stream.max_super_stream_partitions key in rabbitmq.conf . GitHub issues: #16689 , #16706 A client RPC timeout is now logge
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RABBITMQRABBITMQ-4.3.3
RabbitMQ 4.3.3 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version Important : starting with this release, the minimum supported Erlang version is 27.0 . Erlang/OTP 26 has reached end of life and is no longer supported. GitHub issue: #16914 RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Quorum queue, Khepri and other Raft leaders could optimistically commit new log entries in certain scenarios. GitHub issue: rabbitmq/ra#637 Quorum queues that use at-least-once dead lettering could get their dead lettering process permanently stuck after repeated queue membership changes. GitHub issue: #16652 Classic queue index directory paths could accumulate slashes, eventually failing with an enametoolong file system error. GitHub issue: #16833 Enabling the tie_binding_to_dest_with_keep_while_cond feature flag could fail with an exception when certain exchange-to-exchange topologies. GitHub issue: #16824 An invalid consumer_timeout value in the configuration now falls back to the default value (24 hours) instead of being used as is. GitHub issue: #16799 AMQP 1.0 management operations that declare an exchange with an alternate exchange now verify the necessary permissions on the alternate exchange, matching AMQP 0-9-1. GitHub issue: #16785 AMQP 1.0 management GET /bindings operations now behave consistently with the rest of the binding-related handlers. GitHub issue: #16790 Worker pool processes no longer terminate when they receive an unexpected message. Contributed by @Ayanda-D . GitHub issue: #16666 A race condition between concurrent queue (or virtual host) deletion and a Ra cluster shutdown could log an exception. Contributed by @Ayanda-D . GitHub issue: #16880 A closing channel (connection) that failed to send channel.close_ok on an already terminated writer or socket no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16651 Unexpected failures during channel termination cleanup no longer produce log noise. Contributed by @Ayanda-D . GitHub issue: #16740 Code paths that use rabbit_queue_type_util:erpc_call/5 now handle more errors. Contributed by @Ayanda-D . GitHub issue: #16701 Nodes could fail to start with a bad_generator exception in rabbit_queue_decorator:select/1 when a quorum queue record in the metadata store had its decorators set to undefined . GitHub issues: #16843 , #16844 Enabling tracing on multiple virtual hosts concurrently could silently drop some of the virtual hosts from the traced set. All virtual host tracing state modifications are now linearized. GitHub issues: #16755 , #16763 Enhancements Password salts are now generated using a cryptographically secure pseudo-random number generator (CSPRNG). GitHub issue: #16775 Socket-level metric collection used by several protocol readers and the management agent now handles concurrently closed connections safely. Inspired by a contribution of @MugemaneBertin2001 . GitHub issues: #16856 , #16832 CLI Tools Bug Fixes rabbitmq-plugins commands now tolerate plugins that are listed as enabled but are not installed. GitHub issue: #16896 rabbitmq-plugins list no longer outputs an empty plugin table when the target node cannot be reached. GitHub issue: #16791 rabbitmq-plugins commands now correctly handle file paths of remote nodes, validate remote nodes in offline mode, and no longer report false positives for rabbitmq-plugins is_enabled . GitHub issue: #16842 Shell (Bash, zsh) command completion fixes. Contributed by @Chr1s70ph . GitHub issue: #16776 Enhancements rabbitmq-queues and rabbitmq-streams now provide transfer_leadership commands for individual queues and streams. GitHub issue
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OVENBUN-272C9CD56EF411DB
step 7.sweep-wip2: snapshot before cap-raise resume
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OVENBUN-2.4
step 3.fix0: drop package-rename deps; apply 2.4/2.5/3.6 seds
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OVENBUN-4.2
step 4.fix0: drop package-rename deps; apply 4.2/4.4/4.5/4.6 seds
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OVENBUN-C9D7843A5818F754
step 5.fix0: route bun_s3_signing::error/Error via s3_signing mount path
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OVENBUN-F1F710FC5DB68525
step 1.fix0: regenerate stale build/debug/codegen rust outputs
Published Never · Source checked 29 Sep 2026
Release notes and known issues →WORDPRESSWORDPRESS-7.0.2
WordPress 7.0.2 is now available. The 7.0.2 security release addresses one critical and one high severity security issue. Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions. To manually […]
Published 17 Jul 2026 · Source checked 26 Sep 2026
Release notes and known issues →WORDPRESSWORDPRESS-92BE7BE0C3544B19
WordPress 7.0.2 is now available. The 7.0.2 security release addresses one critical and one high severity security issue. Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions. To manually […]
Published 17 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →CEPHCEPH-21.1.0
v21.1.0
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.97.1
rustc: Fix miscompilation in LLVM optimization This backports an LLVM submodule bump to include the LLVM-side fix and a revert of the rustc change that is one known trigger for the bug. The rustc side revert should not be strictly necessary but is done out of abundance of caution.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CLOUDFLARECLOUDFLARED-2026.7.2
SHA256 Checksums: cloudflared-amd64.pkg: bc6d9d21d447af25ee437ff6669905a1c843362739d8ef50f647a0c4b016ac52 cloudflared-arm64.pkg: 011f985b710d1aff335d69d107847b1a121433bd4680e792cfdf6557cec1989d cloudflared-darwin-amd64.tgz: a5afb0ba3da859da47bebc9a918d5b196bf7e4aec23589419b46356731bcc75f cloudflared-darwin-arm64.tgz: 0588df58494a6cadd38b9deb6078908a5054063c80784d92fdb8d4a5f3de1c67 cloudflared-fips-linux-amd64: a4e3b8f2191ce3f6ad97f2f05e1ff629b7188a6d16a55188e7ec42110a3cef8e cloudflared-fips-linux-amd64.deb: ca80c7312aa29fd91e880f0bd8592aa12811f1913551fbf5bd238617bfb32e30 cloudflared-fips-linux-x86_64.rpm: 161c36941608661c27f68c4b545d3a58f7a6f229776c7b2607e5e9f0a7cd5a10 cloudflared-linux-386: cbad04f2700ae4d4971fe07e9ded67327142f2d3338aef86ae04e6042f7ce990 cloudflared-linux-386.deb: dd4d7a07fd17b1494a32209ca02408a52b095d36995df235e8358eafba5c2a29 cloudflared-linux-386.rpm: a27d7182c21da107ca37c970993b90ac093b3f06e2b0b01de95c695dc30defbf cloudflared-linux-aarch64.rpm: 90667866ad18c502ba6921b8db58645dc8a29ea3290f3fbdba1d30d82d6d2f4d cloudflared-linux-amd64: ec905ea7b7e327ff8abdde8cb64697a2152de74dbcdbf6aec9db8364eb3886cd cloudflared-linux-amd64.deb: 88195157a136199a86977c122a22084dae6907480bbe3640222b7b55834afc3a cloudflared-linux-arm: 80dc01d7e284f269395824de841f8c7396c6641871eacc46add53a394b4548f4 cloudflared-linux-arm.deb: cb8af4fd776503327d701115a59f3267b949691bdd43707ff5742b456b73aa4b cloudflared-linux-arm.rpm: 1a08bb17cd739043d93e69aeb7f3f02d0fb63508f2fa5154025cdb575efbea30 cloudflared-linux-arm64: 405df476437e027fc6d18729a5a77155c0a33a6082aeee60a799a688f3052e66 cloudflared-linux-arm64.deb: ddd7d2a0d55a1879485ac34354e936424f1df92e306bfa6428a81908aaddbe87 cloudflared-linux-armhf: e4f86d1a24cfcd065268f2bc874d0510f278f12842c0d220ce6e887489b16a70 cloudflared-linux-armhf.deb: 2f6ae79aa05128747c3f0c5ca520e72af8e4eb060a95ae16188a80ae762e0bf9 cloudflared-linux-armhf.rpm: 2df5714d7ed108773a399ac8544a13b3e2debe54d455f38e2453e784066488f8 cloudflared-linux-x86_64.rpm: 243ae0f3e25225b322fca700ac45be53fe3f6821f9a43a944a36cd9e9f9895ad cloudflared-windows-386.exe: 32decf512bb37dfcf8f915e923b8132803cb0f7262995d0b168495694b1ee2d7 cloudflared-windows-386.msi: 0219784e6489e418ae00dc22ff99dc56addd6da84a2af0f9bcee3a2bc65538c7 cloudflared-windows-amd64.exe: cdb5d4432f6ae1595654a692a51308b69d2bf7af961f5578d9391837cf072df9 cloudflared-windows-amd64.msi: d783b28eb067b1b901e27b84f89f802d0d1437a02c8b957207a3038fcf94b0c8
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DENODENO-2.9.3
2.9.3 / 2026.07.15 feat(cli): deno add --no-save and --save-optional ( #36039 ) feat(cli): add --min-dep-age alias ( #35914 ) feat(compile): support aarch64-pc-windows-msvc target ( #36004 ) feat(ext/fetch): add http2MaxHeaderListSize option to Deno.createHttpClient ( #33194 ) fix(bundle): preserve raw imports in watch mode ( #36040 ) fix(canvas): don't hold SurfaceData mut borrow over window resize ( #35993 ) fix(config): reject out-of-range minimum dependency ages ( #36051 ) fix(core): block user ext imports after resolution ( #36012 ) fix(core): deactivate idle TTY write handles ( #35886 ) fix(core): restrict extension loaders to internal modules ( #36013 ) fix(core): root slow op string coercions ( #36018 ) fix(desktop): don't let op_desktop_send_error_report target caller-supplied URLs ( #35940 ) fix(ext/http): don't panic recycling cancelled record on native response ( #36053 ) fix(ext/napi): don't free threadsafe function on abort while refs remain ( #36032 ) fix(ext/napi): don't resurrect a released threadsafe function in acquire ( #36054 ) fix(ext/node): add deprecation warning for Duplex.toWeb({ type }) DEP0201 ( #35972 ) fix(ext/node): guard sqlite deserialize during callbacks ( #36023 ) fix(ext/node): handle UTF-16 assert source positions ( #36029 ) fix(ext/node): handle sqlite conversion failures ( #36024 ) fix(ext/node): respect base64 buffer ranges ( #36030 ) fix(ext/process): don't double-close extra stdio pipe handles on Windows ( #36005 ) fix(lsp): respect lint rule exclusion for no-slow-types diagnostics ( #35924 ) fix(node): stop active read on stream close to avoid leaking Socket/TCPWrap ( #35898 ) fix(node_http2): keep header validation enabled ( #36042 ) fix(node_http2): validate serialized headers ( #36041 ) fix(npm): don't fetch registry info for deprecated packages under --cached-only ( #35903 ) fix(npm): normalize path in BYONM read permission check ( #35882 ) fix(pm): hint about minimumDependencyAge when no version is old enough ( #35890 ) fix(release): only strip Mach-O signature for x86_64-apple-darwin ( #35902 ) fix(release): strip Mach-O signature before patchver on apple targets ( #35897 ) fix(runtime): guard usage op output buffers ( #36020 ) fix(serde_v8): handle deserialization exceptions ( #36021 ) fix(web): guard encodeInto fallback result buffer ( #36019 ) fix(web): support Event subclasses with readonly toStringTag ( #35920 ) fix(worker): remove imported ops during bootstrap ( #36014 ) fix: don't print duplicate parse diagnostics ( #35933 ) perf(ext/crypto): batch randomUUID generation ( #35953 ) perf(ext/fetch): remove quadratic line buffering in EventSource ( #35881 ) perf(ext/node): cache compiled glob matchers + bump bundled minimatch to 10.2.5 ( #35873 ) perf(ext/node): fast path fs cp ( #35856 ) perf(ext/node): right-size small socket reads instead of pinning the 64KB slab ( #35779 ) perf(ext/node): speed up sqlite.StatementSync.all() and run() ( #35863 ) perf(ext/web): avoid copy-back in op_base64_atob large path ( #35862 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →MICROSOFTDOTNET-10.0.10
Release Notes Install Instructions Repos Aspnetcore dotnet dotnet EF Core Runtime SDK SDK Templating Templating Winforms WindowsDesktop WPF What's Changed https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates/#release-changelogs
Published Never · Source checked 29 Sep 2026
Release notes and known issues →MICROSOFTDOTNET-5DE6BCCC501F20DA
Release
Published Never · Source checked 29 Sep 2026
Release notes and known issues →NGINXNGINX-1.30.4
nginx-1.30.4 stable version has been released, with fixes for buffer overflow vulnerability when using map with regex ( CVE-2026-42533 ), memory disclosure vulnerability when using ngx_http_slice_module ( CVE-2026-60005 ), and use-after-free vulnerability when using ngx_http_ssi_module ( CVE-2026-56434 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.4 by @arut in #1563 Full Changelog : release-1.30.3...release-1.30.4
Published Never · Source checked 29 Sep 2026
Release notes and known issues →NGINXNGINX-1.31.3
nginx-1.31.3 mainline version has been released, with fixes for buffer overflow vulnerability when using map with regex ( CVE-2026-42533 ), memory disclosure vulnerability when using ngx_http_slice_module ( CVE-2026-60005 ), and use-after-free vulnerability when using ngx_http_ssi_module ( CVE-2026-56434 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Configure: set cache line size for loongarch64 by @shankerwangmiao in #1489 HTTP/2: fix overlapping memcpy in CONTINUATION frames by @wufengwind in #1486 Add missing bounds check in ngx_{http,stream}_compile_complex_value() by @wufengwind in #1484 Revert "HTTP/2: fixed overlapping memcpy in CONTINUATION frames" by @ac000 in #1517 GH: explicitly set permissions in workflows by @ac000 in #1451 Charset: disabled charset_map with utf-8 in the first column by @pluknet in #1523 Upstream: Upgrade header processing by @vinaykumar-1591 in #1476 Fix setting the IPV6_DONTFRAG socket option by @arut in #1544 Xslt: disable loading of external entities by default by @VadimZhestikov in #1549 SSL: fixed memory leak in ngx_ssl_get_ech_outer_server_name(). by @devnexen in #1471 Fixing HTTP/2 issues by @hongzhidao in #1441 Perl fixes by @pluknet in #1556 Configure: include crypt.h for crypt() feature tests by @bavshin-f5 in #1552 HTTP/2: Reject requests with pseudo-headers after headers by @nitin9977 in #1541 Stream and HTTP: rcvbuf and sndbuf directives for upstream sockets by @patrikwl in #1298 Tunnel body improvements by @arut in #1560 Nginx 1.31.3 security fixes by @arut in #1561 nginx-1.31.3-RELEASE by @pluknet in #1562 New Contributors @shankerwangmiao made their first contribution in #1489 @wufengwind made their first contribution in #1486 @vinaykumar-1591 made their first contribution in #1476 @patrikwl made their first contribution in #1298 Full Changelog : release-1.31.2...release-1.31.3
Published Never · Source checked 29 Sep 2026
Release notes and known issues →WORDPRESSWORDPRESS-7.1
WordPress 7.1 Beta 1 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta 1 […]
Published 15 Jul 2026 · Source checked 26 Sep 2026
Release notes and known issues →WORDPRESSWORDPRESS-D90868E4BE01F5DF
WordPress 7.1 Beta 1 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta 1 […]
Published 15 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-2941EBF393B08634
CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-3917C34972D1BB3D
CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-6698AC05BB648A3D
CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-7604FE79CB5C3A2B
CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-7E8B915707E29F91
CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-8A1F644EBBB66565
CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-9D3E25890BDDC3B6
CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-AB902B8E4AE3DC7C
CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-B22231C8EC81EB6F
CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-DCB64474FEA68661
CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →FORTINETFORTINET-PRODUCTS-E62CD7E71CF960F7
CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00
Published 14 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →GITEAGITEA-1.27.0
BREAKING Feat(actions)!: improve support for reusable workflows ( #37478 ) Use Content-Security-Policy: script nonce ( #37232 ) SECURITY Fix: various security fixes ( #38406 ) ( #38426 ) Fix(security): harden access checks and migration validation ( #38324 ) ( #38400 ) Fix: enforce public-only token scope and harden push options / locale parsing ( #38323 ) ( #38399 ) Fix(pull): re-evaluate review official flag on target branch change ( #38319 ) ( #38402 ) Fix(api): stop leaking private repo metadata after access revocation ( #38321 ) ( #38390 ) Fix(lfs): require proof of possession for cross-repo objects ( #38322 ) ( #38389 ) Fix(mirror): disable HTTP redirects on pull mirror sync ( #38320 ) ( #38367 ) Fix: golang html template url escaping ( #38363 ) ( #38369 ) Fix(release): validate web attachment renames against allowed types ( #38314 ) ( #38328 ) Fix(release): gate draft release attachments on web download endpoints ( #38318 ) ( #38325 ) Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] ( #37786 ) Fix(oauth): restrict introspection to the token's client ( #38042 ) Fix(api): don't expose private org membership via public_members ( #38145 ) Fix(actions): deny fork-PR cross-repo access via collaborative owner ( #38214 ) Fix(migrations): prevent path traversal in repository restore ( #38215 ) FEATURES Feat(actions): add workflow status badge modal ( #38196 ) Feat(actions): support owner-level and global scoped workflows ( #38154 ) Feat(api): support ref suffixes in compare ( #38148 ) Feat(actions): implement jobs.<job_id>.continue-on-error ( #38100 ) Feat(actions): show run status on browser tab favicon ( #38071 ) Feat(api): add token introspection and self-deletion endpoint ( #37995 ) Feat(api): add q parameter to list branches API for server-side filtering ( #37982 ) Feat(repo): split repository creation limit into user and org scopes ( #37872 ) Feat(actions): bulk delete, disable and enable runners in admin UI ( #37869 ) Feat(actions): List workflows that were executed once but got removed from the default branch ( #37835 ) Feat(org): add team visibility so org members can discover teams ( #37680 ) Feat: add raw diff/patch endpoint for repository comparisons ( #37632 ) Feat: Add avatar stacks ( #37594 ) Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) ( #37500 ) Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support ( #37433 ) Support for Custom URI Schemes in OAuth2 Redirect URIs ( #37356 ) Feat(orgs): Add search bar for organization members tab page ( #37347 ) Feat(api): Add assignees APIs ( #37330 ) Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs ( #37196 ) Serve OpenAPI 3.0 spec at /openapi.v1.json ( #37038 ) Add project column picker to issue and pull request sidebar ( #37037 ) Allow multiple projects per issue and pull requests ( #36784 ) Feat(ui): add "follow rename" to file commit history list ( #34994 ) Feat(ssh): auto generate additional ssh keys ( #33974 ) ENHANCEMENTS Enhance(actions): only create filtered-out workflow commit status for required contexts ( #38371 ) ( #38385 ) Enhance: allow builtin default git config options to be overridden ( #38172 ) Enhance: allow MathML core elements ( #38034 ) Enhance(markup): improve issue title rendering ( #37908 ) Enhance(actions): set descriptive browser tab title on run view ( #37870 ) Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 ( #37866 ) Enhance(actions): show workflow name from YAML instead of filename ( #37833 ) Feat(actions): add before/after to PR synchronize event payload ( #37827 ) Enhance(actions): add branch filters to run list ( #37826 ) Enhance(actions): Make Summary UI more beautiful with more infos ( #37824 ) Feat: add copy button to action step header, improve other copy buttons ( #37744 ) Fix(icon): use repo-forked icon to display forks count ( #37731 ) Feat(api): add sort and order query parameters to job list endpoints ( #37672 ) Feat(api): add last_sync to r
Published Never · Source checked 29 Sep 2026
Release notes and known issues →POSTGRESQLPOSTGRESQL-DF4941C456A50AEC
Stamp 19beta2.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-3.5.9
Preparing Spark release v3.5.9-rc1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-3.5.9-RC1
Preparing Spark release v3.5.9-rc1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.0.4
Preparing Spark release v4.0.4-rc1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.0.4-RC1
Preparing Spark release v4.0.4-rc1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.1.3
Preparing Spark release v4.1.3-rc1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.1.3-RC1
Preparing Spark release v4.1.3-rc1
Published Never · Source checked 28 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.2.0
Preparing Spark release v4.2.0-rc6
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.2.0-RC6
Preparing Spark release v4.2.0-rc6
Published Never · Source checked 29 Sep 2026
Release notes and known issues →CEPHCEPH-19.2.5
v19.2.5
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HELMHELM-3.21.3
Helm v3.21.3 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Installation and Upgrading Download Helm v3.21.3. The common platform binaries are here: MacOS amd64 ( checksum / 76d0db4730b05d3d625eee11e80f0721b32b4d8422f4e5d093de6337bf3ac9f8) MacOS arm64 ( checksum / 19879a848cad832b7a1ac24b767a481d20fb3b95ab53a220849649422ada144e) Linux amd64 ( checksum / 15e041a93a590dce8100f39385cd98c84a765c9e36aeeb9e2dc6ff9e4769e2e0) Linux arm ( checksum / 60f3106ba5e24371af51574fccf489d382d2f59c56ce566d02f2a6f00bf4fb3b) Linux arm64 ( checksum / 67f58155079ff9ffab98ba5c88daff0ed9b542f3a4732f5dd426dde7dd0f5244) Linux i386 ( checksum / 95e7ef76d4631f30e3f6c17d4355420878ca85771dbe7deb7b797521007aebe4) Linux ppc64le ( checksum / c8657c0f77b7d3e2f9508c4a9a545b5862d01690f2a528fbbe659a3a4d534382) Linux s390x ( checksum / d6c2dd29b32da1cb9dfef5af0cb93a1f391beca4e714779186330681b39f4b59) Linux riscv64 ( checksum / ff063cc304a60af858242aa71b5635852d65aa7d3301a46eca17a31c54e8d994) Windows amd64 ( checksum / ff490897e07e976c65a9bd7690cfc139b35ba5e8f25d00eaf1e53a30f1ad3f62) Windows arm64 ( checksum / 1d409b98f99a38704ccb3f0917cbad2417ed53f75751902b6bd84447803b69a9) The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.2.4 and 3.21.4 are the next patch releases scheduled for August 12, 2026 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026 Changelog Apply suggestions from code review 1ad6e68 (Benoit Tigeot) fix: drop containerd v1 dep to resolve govulncheck CVEs 037733e (Benoit Tigeot) chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 d3e178b (dependabot[bot])
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HELMHELM-4.2.3
Helm v4.2.3 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Installation and Upgrading Download Helm v4.2.3. The common platform binaries are here: MacOS amd64 ( checksum / ff3ac86755a45f3422473bc1200776aac0fe04c5766abe6ca66699f7b564b23b) MacOS arm64 ( checksum / 048ecf5ad3160f83d918f9fe945238d2132b079640f7b106175331c25f242c64) Linux amd64 ( checksum / e9b88b4ee95b18c706839c28d3a0220e5bc470e9cd9262410c90793c45ff8b7c) Linux arm ( checksum / ba00678361ca7a03ec42ca1ea459543e1d8eab2a7d5429a5eda71dc9741c8a9b) Linux arm64 ( checksum / 21abd9354d39b2cd79a8d76be6912cd137a983cbf997193503fb8a6a6e2f2785) Linux i386 ( checksum / 31d57972d36e60388e173327fffcf9d58f272349dfa9ed3e1914f3cd88fe7283) Linux loong64 ( checksum / 232f82d787d530a621b2006965ed2b99644b4391bbc6261e9787f95700fc44f7) Linux ppc64le ( checksum / 43fc5a4b20839c3669a0748498bd2613b095e288425bf5678c6ba664eb4a0e70) Linux s390x ( checksum / 17932091e19d352585b540a482fca9b953d32a8ad7afec72bf9cbbcd96b094cb) Linux riscv64 ( checksum / 09ff0772730678c652b9ac4a2b32cd20f4e62a2b040403bcacd4ad845d3d3e9c) Windows amd64 ( checksum / 5ca7de684c92d48b93d5c34a029fdda57b38e1eac04bc8541bdf1eb249388679) Windows arm64 ( checksum / 5f444ed097688ed3abaf1d8801e21110d9bddeb6ed13939afcac302888527ab5) The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide . You can also use a script to install on any system with bash . What's Next 4.2.4 and 3.21.4 are the next patch releases scheduled for August 12, 2026 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026 Changelog chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 43e8b7f (Terry Howe)
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.97.0
Language Consider Result<T, Uninhabited> and ControlFlow<Uninhabited, T> to be equivalent to T for must use lint Add allow-by-default dead_code_pub_in_binary lint for unused pub items in binary crates Stabilize the div32 , lam-bh , lamcas , ld-seq-sa and scq target features Stabilize cfg(target_has_atomic_primitive_alignment) Allow trailing self in imports in more cases Platform Support nvptx64-nvidia-cuda: drop support for old architectures and old ISAs Refer to Rust's platform support page for more information on Rust's tiered platform support. Stabilized APIs Default for RepeatN Copy for ffi::FromBytesUntilNulError Send for std::fs::File on UEFI <{integer}>::isolate_highest_one <{integer}>::isolate_lowest_one <{integer}>::highest_one <{integer}>::lowest_one <{integer}>::bit_width NonZero<{integer}>::isolate_highest_one NonZero<{integer}>::isolate_lowest_one NonZero<{integer}>::highest_one NonZero<{integer}>::lowest_one NonZero<{integer}>::bit_width These previously stable APIs are now stable in const contexts: char::is_control Cargo Stabilize build.warnings config. This controls how lint warnings from local packages are treated. Useful for enforcing a warning-free build in CI, replacing -Dwarnings . docs Stabilize resolver.lockfile-path config. This allows specifying the path to the lockfile to use when resolving dependencies. Useful when working with read-only source directories. docs cargo-clean: Error when --target-dir doesn't look like a Cargo target directory. This prevents accidental deletion of non-target directories. Add -m shorthand for --manifest-path Remove curl dependency from crates-io crate Rustdoc Stabilize --emit flag Stabilize --remap-path-prefix Compatibility Notes Emit a future-compatibility warning when relying on f32: From<{float}> to constrain {float} Rust will use the v0 symbol mangling scheme by default. This may cause some tools (such as debuggers or profilers, especially with old versions) to fail to demangle symbols emitted by Rust. It may also cause the formatting of text in backtraces to change. Prevent deref coercions in pin! , in order to prevent unsoundness. The most likely case where this might impact users is: writing pin!(x) where x has type &mut T will now always correctly produce a value of type Pin<&mut &mut T> , instead of sometimes allowing a coercion that produces a value of type Pin<&mut T> . This coercion was previously incorrectly allowed since Rust 1.88.0. Deprecate std::char constants and functions Warn on linker output by default Remove hidden f64 methods which have been deprecated since 1.0 report the varargs_without_pattern lint in deps Forbid passing generic arguments to module path segments even if the module reexports a generic enum variant Error on invalid macho link_section specifier The encoding of certain enum s have changed . This is not a breaking change, as it only applies to enum s without layout guarantees, but is noted here as we've seen people impacted from having made assumptions about the layout algorithm. Error on #[export_name = "..."] where the name is empty Syntactically reject tuple index shorthands in struct patterns validate #[link_name = "..."] & #[link(name = "...")] parameters On Windows, after calling shutdown on a socket to shut down the write side, attempting to write to the socket will now produce a BrokenPipe error rather than Other . Map WSAESHUTDOWN to io::ErrorKind::BrokenPipe
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PALO ALTO NETWORKSCVE-2026-0285
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431). Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Published 8 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →PALO ALTO NETWORKSCVE-2026-0286
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
Published 8 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →PALO ALTO NETWORKSCVE-2026-0287
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.
Published 8 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →PALO ALTO NETWORKSCVE-2026-0288
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only.). Panorama is not impacted by this vulnerability.
Published 8 Jul 2026 · Source checked 29 Sep 2026
Release notes and known issues →DENODENO-2.9.2
2.9.2 / 2026.07.08 feat(desktop): autodetect React Router framework ( #35557 ) feat(desktop): enable --hmr for Vite and Nuxt ( #35851 ) feat(desktop): run HMR by framework dev server ( #35722 ) feat(desktop): window opacity and transparency APIs ( #35646 ) feat(desktop): wire --exclude-unused-npm through to compile ( #35740 ) feat(ext/node): implement v8.setHeapSnapshotNearHeapLimit ( #35694 ) feat(ext/telemetry): honor OTEL_ATTRIBUTE_VALUE_LENGTH_LIMIT ( #35068 ) feat(inspector): start inspector server on SIGUSR1 ( #35738 ) feat(node): implement getTestContext() in node:test ( #35678 ) feat: support wildcard patterns in minimumDependencyAge.exclude ( #35746 ) fix(check): don't interleave errors with "Check" lines in a workspace ( #35687 ) fix(compile): bump libsui to 0.16.1 to survive eu-strip in flatpak ( #35699 ) fix(compile): bump libsui to 0.16.3 to fix segfault under gVisor/Cloud Run ( #35701 ) fix(core): don't drain microtasks in mod_evaluate_sync mid-evaluation ( #35707 ) fix(coverage): count a branch-junction line as covered when either arm runs ( #35858 ) fix(coverage): don't count V8 block-boundary gaps as branches ( #35767 ) fix(coverage): don't let a trailing comment change a line's hit count ( #35741 ) fix(deploy): disable config discovery and refresh the cached CLI version ( #35754 ) fix(desktop): attribute bind calls to the registering window id ( #35654 ) fix(desktop): honor desktop.backend from deno.json ( #35815 fix(desktop): pin @std/http in generated Vite SPA entrypoint + add hermetic compile test ( #35676 ) fix(desktop): rename launcher to so it self-loads the runtime ( #35709 ) fix(desktop): run framework build step before bundling output ( #35603 ) fix(desktop): surface compiled-app startup errors instead of exiting silently ( #35567 ) fix(dprint): exclude tools/lzld submodule ( #35778 ) fix(ext): throw DataCloneError when posting non-serializable values ( #35604 ) fix(ext/cache): implement Cache.keys() ( #35455 ) fix(ext/fetch): reject transport failures with Node's "fetch failed" shape ( #35618 ) fix(ext/http): error non-Uint8Array response streams ( #35783 ) fix(ext/http): honor explicit content-length header on HEAD responses ( #35728 ) fix(ext/http): point legacy abort warning at docs.deno.com/go link ( #35713 ) fix(ext/napi): add uv_cond_* polyfills for native addons ( #35536 ) fix(ext/net): abort pending Deno.connect during DNS resolution ( #35729 ) fix(ext/node): allow adopting inherited extra stdio TCP fds ( #35805 ) fix(ext/node): don't panic when main module path has invalid percent-encoding ( #35534 ) fix(ext/node): don't schedule a pause in inspector.waitForDebugger() ( #35796 ) fix(ext/node): flush StringDecoder in cipher final() for stream ciphers ( #35800 ) fix(ext/node): mark TLSWrap dead on teardown before tls_conn check ( #35706 ) fix(ext/node): report all active resources from process.getActiveResourcesInfo ( #35532 ) fix(ext/node): require --allow-net=unix for node:net unix sockets ( #35835 ) fix(ext/node): support fd 3 pipes in spawned Deno children ( #34133 ) fix(ext/signals): unregister handler when SignalStream is dropped ( #35832 ) fix(ext/web): resolve pending BYOB read when teeing a byte stream that closes ( #35828 ) fix(fmt): format Astro inline scripts as TypeScript ( #35852 ) fix(fs): support pre-1970 (negative) timestamps in FsStat ( #35517 ) fix(inspector): close WebSocket connections when the runtime is torn down ( #35791 ) fix(install): don't panic on jsr specifier with a tag like @latest ( #35605 ) fix(install): don't write through hardlinks when copying package files ( #35735 ) fix(install): make setup cache packages hash deterministic ( #35825 ) fix(install): resolve lifecycle script dependency bins against the hoisted layout ( #35762 ) fix(install): support uninstalling multiple global packages ( #29352 ) fix(lint): don't error on non-analyzable package exports like CSS files ( #35732 ) fix(lint): include config file in workspace member invalid version error ( #357
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPNOMAD-1.10.14
SECURITY: docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task. This is CVE-2026-14891 . [ GH-28190 ] docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896 . [ GH-28177 ] dynamic host volumes: Fixed a bug where users with host-volume-delete in one namespace could delete claims from another namespace [ GH-28205 ] IMPROVEMENTS: consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [ GH-28106 ] driver: Added optional Init function for task driver plugins [ GH-28104 ] driver: Added optional Shutdown function for task driver plugins [ GH-28102 ] BUG FIXES: api: allow using WI tokens on plan endpoint [ GH-28139 ] cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [ GH-28138 ] dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [ GH-28198 ] metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [ GH-28170 ] scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [ GH-28097 ] scheduler: Fixed a bug where setting sticky on a static host volume could fail the evaluation instead of being rejected during feasibility checking [ GH-28097 ] scheduler: keep draining batch alloc counted when node is re-enabled [ GH-28018 ] task runner: Improve the memory management for secrets [ GH-28140 ] ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the /v1/jobs/statuses endpoint [ GH-28132 ] ui: fixes an issue where streaming task logs would error [ GH-28137 ]
Published Never · Source checked 29 Sep 2026
Release notes and known issues →HASHICORPNOMAD-1.11.8
SECURITY: docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task. This is CVE-2026-14891 . [ GH-28190 ] docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896 . [ GH-28177 ] dynamic host volumes: Fixed a bug where users with host-volume-delete in one namespace could delete claims from another namespace [ GH-28205 ] IMPROVEMENTS: consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [ GH-28106 ] driver: Added optional Init function for task driver plugins [ GH-28104 ] driver: Added optional Shutdown function for task driver plugins [ GH-28102 ] BUG FIXES: api: allow using WI tokens on plan endpoint [ GH-28139 ] cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [ GH-28138 ] dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [ GH-28198 ] metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [ GH-28170 ] scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [ GH-28097 ] scheduler: Fixed a bug where setting sticky on a static host volume could fail the evaluation instead of being rejected during feasibility checking [ GH-28097 ] scheduler: keep draining batch alloc counted when node is re-enabled [ GH-28018 ] task runner: Improve the memory management for secrets [ GH-28140 ] ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the /v1/jobs/statuses endpoint [ GH-28132 ] ui: fixes an issue where streaming task logs would error [ GH-28137 ]
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.3.1
What's Changed 🔧 Internal Ci: add concurrency group to pr-review-trigger to prevent duplicate reviews by @derekmisler in #13890 Fix grammar in Attestations field comment by @blackflytech in #13891 Ci: remove unused desktop-edge-test workflow by @thaJeztah in #13897 Ci: zizmor workflow by @crazy-max in #13901 Ci: fix docs-upstream workflow by @crazy-max in #13912 CODEOWNERS: add compose-reviewers by @thaJeztah in #13913 Ci: harden GitHub Actions workflows by @glours in #13896 GHA: dependabot: group docker/* actions updates by @thaJeztah in #13914 ⚙️ Dependencies Build(deps): bump github.com/moby/buildkit from 0.31.0 to 0.31.1 by @dependabot [bot] in #13892 Build(deps): bump github.com/moby/sys/user to v0.4.1 by @thaJeztah in #13893 Build(deps): bump go.yaml.in/yaml/v4 from 4.0.0-rc.4 to 4.0.0-rc.6 by @dependabot [bot] in #13876 Build(deps): bump github.com/docker/cli from 29.6.0+incompatible to 29.6.1+incompatible by @dependabot [bot] in #13895 Build(deps): bump actions/stale from 10.2.0 to 10.3.0 by @dependabot [bot] in #13902 Build(deps): bump the docker-actions group with 3 updates by @dependabot [bot] in #13916 Build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by @dependabot [bot] in #13908 Build(deps): bump actions/setup-go from 6.3.0 to 6.5.0 by @dependabot [bot] in #13907 Build(deps): bump test-summary/action from 2.4 to 2.6 by @dependabot [bot] in #13903 Build(deps): bump mxschmitt/action-tmate from 3.23 to 3.24 by @dependabot [bot] in #13910 Build(deps): bump codecov/codecov-action from 5.5.3 to 7.0.0 by @dependabot [bot] in #13904 Build(deps): bump github/codeql-action/upload-sarif from 3.36.3 to 4.36.2 by @dependabot [bot] in #13917 Build(deps): bump actions/checkout from 6.0.2 to 7.0.0 by @dependabot [bot] in #13911 New Contributors @blackflytech made their first contribution in #13891 Full Changelog : v5.3.0...v5.3.1
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GOGO-26.5
Change-Id: I87dc3d84cde11db83a0d88a60262a38fc429838d Reviewed-on: https://go-review.googlesource.com/c/go/+/797740 Auto-Submit: Gopher Robot gobot@golang.org Reviewed-by: David Chase drchase@google.com Reviewed-by: Junyang Shao shaojunyang@google.com TryBot-Bypass: Gopher Robot gobot@golang.org
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GOGO-955051D102C1E67A
Change-Id: Iee4d231b5b040576ab9c1175ba726e03090fff7c Reviewed-on: https://go-review.googlesource.com/c/go/+/797800 TryBot-Bypass: Gopher Robot gobot@golang.org Reviewed-by: Junyang Shao shaojunyang@google.com Reviewed-by: David Chase drchase@google.com Auto-Submit: Gopher Robot gobot@golang.org
Published Never · Source checked 29 Sep 2026
Release notes and known issues →OPENSEARCHOPENSEARCH-2.19.6
Version 2.19.6 Release Notes Compatible with OpenSearch and OpenSearch Dashboards version 2.19.6 Bug Fixes Fix hang in bulk request when index is deleted during primary phase ( #21305 ) Fix case insensitive and escaped query on wildcard fields ( #20870 ) Fix array index out of bounds exception with wildcard fields and aggregations ( #20862 ) Harden circuit breaker and failure handling logic to prevent negative estimated limits in query result consumer ( #20769 ) Prevent negative fielddata stats by guarding against stale removals after shard reallocation ( #22016 ) Maintenance Update Netty to 4.1.135.Final ( #21968 ) Bump org.apache.avro:avro to 1.12.1 ( #22350 ) Bump Bouncy Castle (bcprov/bcpkix-jdk18on) to 1.84 ( #22296 ) Bump ZooKeeper to 3.9.5 ( #22296 ) Bump plexus-utils to 3.6.1 ( #22296 ) Bump log4j to 2.25.4 ( #22292 ) Bump Jetty to 9.4.58 ( #22292 ) Bump maven-model to 3.9.16 ( #22292 ) Bump plexus-xml to 3.0.1 ( #22292 ) Bump commons-configuration2 to 2.15.0 ( #22292 ) Bump jsoup to 1.22.2 ( #22292 ) Bump Jackson to 2.18.8 ( #22292 ) Bump reactor-netty to 1.2.18 ( #22292 ) Bump reactor-core to 3.7.19 ( #22292 ) Update bundled JDK to JDK 21.0.11+10 ( #21419 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →RUST FOUNDATIONRUST-1.96.1
Cargo: fix timeout/retry behavior Cargo: apply patches for CVE-2025-15661, CVE-2026-55199, and CVE-2026-55200 to libssh2 rustc: fix miscompilation in MIR optimization
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PROMETHEUSALERTMANAGER-0.32.3
v0.32.3
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PROMETHEUSALERTMANAGER-0.33.1
[BUGFIX] doc: fix missing notification_reason field in webhook documentation ( #5329 ) [BUGFIX] silences: fix silences snapshot missing legacy matchers field. This caused a bug that prevented older alertmanager versions from reading newer snapshots unnecessarily. ( #5330 ) [BUGFIX] silence with no matchers should populate an empty array in API response ( #5331 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-TOMCAT-10.1.57
Tag 10.1.57
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-TOMCAT-11.0.24
Tag 11.0.24
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-TOMCAT-9.0.120
Tag 9.0.120
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-SPARK-4.2.0-RC5
Preparing Spark release v4.2.0-rc5
Published Never · Source checked 28 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.3.0
What's Changed ℹ️ This release introduces native support for init containers. ✨ Improvements Pre start init containers by @glours in #13862 🐛 Fixes Fix(oci): route authorizer token fetches through provided transport by @glours in #13873 Fix(run): scope Running events to project.Services by @glours in #13883 🔧 Internal Chore: migrate cagent-action to docker-agent-action (v2.0.0) by @docker-agent in #13869 Chore: migrate to docker-agent-action v2.0.1 by @docker-agent in #13872 Fix(reconcile): hash resolved service refs to match executor by @glours in #13880 Fix(compose/port): show private port in portNotFoundError message by @vmphase in #13875 Fix(run): normalize --no-TTY flag to --no-tty by @nickjj in #13885 ⚙️ Dependencies Bump compose-go to version v2.13.0 by @glours in #13886 New Contributors @docker-agent made their first contribution in #13869 @vmphase made their first contribution in #13875 @nickjj made their first contribution in #13885 Full Changelog : v5.2.0...v5.3.0
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DENODENO-2.9.1
2.9.1 / 2026.07.01 feat(check): add --desktop flag to type-check for deno desktop ( #35644 ) feat(desktop): register deep-link URL schemes at bundle time ( #35466 ) feat: update laufey to 0.5.0 ( #35663 ) fix(bundle): emit CSSStyleSheet for CSS raw imports ( #35598 ) fix(cache): skip checksums for cached 404 entries ( #35526 ) fix(config): don't strip workspace-member includes from deploy config ( #34788 ) fix(core): apply deferred fast-call op upgrade to the captured bootstrap clone ( #35630 ) fix(core): prevent shared-buffer timer expiry race from losing timers ( #35312 ) fix(desktop): default window title to app name instead of laufey_webview ( #35541 ) fix(desktop): detect SvelteKit adapter-node and error on unsupported adapters ( #35533 ) fix(desktop): discover deno.json in the project dir for deno desktop . ( #35660 ) fix(desktop): don't delete user directories that collide with app name ( #35513 ) fix(desktop): repair webview and raw backends on Windows (laufey v0.4.1) ( #35566 ) fix(desktop): resolve launcher symlink so .deb/.rpm apps find the backend ( #35632 ) fix(desktop): set LAUFEY_RUNTIME_PATH in Linux app launcher ( #35580 ) fix(desktop): show macOS tray icon in bundled .app launched via Finder ( #35626 ) fix(desktop): use zstd for appimage squashfs ( #35506 ) fix(doc): strip blockquote > prefixes from JSDoc code blocks ( #34866 ) fix(ext/fetch): include path and reason when fetching a file:// URL fails ( #35606 ) fix(ext/node): check permissions when binding node:net unix sockets ( #35564 ) fix(ext/node): export report as named export from node:process ( #35400 ) fix(ext/node): mock.reset() should also reset MockTimers ( #35588 ) fix(ext/node): pass Deno subcommands through child_process spawn ( #35599 ) fix(ext/node): send TLS close_notify on JS stream-backed socket shutdown ( #35582 ) fix(ext/node_sqlite): keep attach limit capped under scoped permissions ( #35232 ) fix(ext/web): make URL and URLSearchParams non-serializable ( #35423 ) fix(fmt): stable formatting of multi-line html/svg tagged templates ( #35540 ) fix(inspector): support Chrome worker debugging ( #35629 ) fix(install): pin pre-release npm versions added via dist-tag ( #35586 ) fix(jupyter): register stdin peer only after ZMTP handshake completes ( #35585 ) fix(lib): add PerformanceObserver and PerformanceObserverEntryList types ( #35640 ) fix(libs/http): add missing write_flushed in poll_start_fixed_response_with ( #35649 ) fix(lsp): watch .wasm files for changes ( #35560 ) fix(node): load graph-backed TypeScript modules synchronously ( #35527 ) fix(npm): decode percent-encoded subpath of npm specifiers ( #35505 ) fix(npm): fall back for age-filtered npm dist-tags ( #35561 ) fix(npm): normalize bin names with path separators ( #35555 ) fix(npm): realpath npm bin main module ( #35554 ) fix(npm): show scoped-registry auth hint on tarball 404 ( #35514 ) fix(npm): use case-insensitive match for trust-policy-exclude ( #35520 ) fix(rt_desktop): reveal initial window on first paint (startup black flash) ( #35620 ) fix: correct property name for JSX new line configuration in schema file ( #35565 ) fix: resolve LAUFEY_VERSION from crate-local Cargo.lock during publish ( #35507 ) fix: show clear error when V8 fails to create worker threads ( #32856 ) perf(core/webidl): check next method outside of iterator loop ( #35480 ) perf(ext/fetch): fast-path Response reconstruction ( #35495 ) perf(ext/http): coalesce chunked response writes into a single write ( #35523 )
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GITEAGITEA-1.27.0-RC0
BREAKING Feat(actions)!: improve support for reusable workflows ( #37478 ) Use Content-Security-Policy: script nonce ( #37232 ) SECURITY Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] ( #37786 ) Fix(oauth): restrict introspection to the token's client ( #38042 ) Fix(api): don't expose private org membership via public_members ( #38145 ) Fix(actions): deny fork-PR cross-repo access via collaborative owner ( #38214 ) Fix(migrations): prevent path traversal in repository restore ( #38215 ) FEATURES Feat(actions): add workflow status badge modal ( #38196 ) Feat(actions): support owner-level and global scoped workflows ( #38154 ) Feat(api): support ref suffixes in compare ( #38148 ) Feat(actions): implement jobs.<job_id>.continue-on-error ( #38100 ) Feat(actions): show run status on browser tab favicon ( #38071 ) Feat(api): add token introspection and self-deletion endpoint ( #37995 ) Feat(api): add q parameter to list branches API for server-side filtering ( #37982 ) Feat(repo): split repository creation limit into user and org scopes ( #37872 ) Feat(actions): bulk delete, disable and enable runners in admin UI ( #37869 ) Feat(actions): List workflows that were executed once but got removed from the default branch ( #37835 ) Feat(org): add team visibility so org members can discover teams ( #37680 ) Feat: add raw diff/patch endpoint for repository comparisons ( #37632 ) Feat: Add avatar stacks ( #37594 ) Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) ( #37500 ) Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support ( #37433 ) Support for Custom URI Schemes in OAuth2 Redirect URIs ( #37356 ) Feat(orgs): Add search bar for organization members tab page ( #37347 ) Feat(api): Add assignees APIs ( #37330 ) Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs ( #37196 ) Serve OpenAPI 3.0 spec at /openapi.v1.json ( #37038 ) Add project column picker to issue and pull request sidebar ( #37037 ) Allow multiple projects per issue and pull requests ( #36784 ) Feat(ui): add "follow rename" to file commit history list ( #34994 ) Feat(ssh): auto generate additional ssh keys ( #33974 ) ENHANCEMENTS Enhance: allow builtin default git config options to be overridden ( #38172 ) Enhance: allow MathML core elements ( #38034 ) Enhance(markup): improve issue title rendering ( #37908 ) Enhance(actions): set descriptive browser tab title on run view ( #37870 ) Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 ( #37866 ) Enhance(actions): show workflow name from YAML instead of filename ( #37833 ) Feat(actions): add before/after to PR synchronize event payload ( #37827 ) Enhance(actions): add branch filters to run list ( #37826 ) Enhance(actions): Make Summary UI more beautiful with more infos ( #37824 ) Feat: add copy button to action step header, improve other copy buttons ( #37744 ) Fix(icon): use repo-forked icon to display forks count ( #37731 ) Feat(api): add sort and order query parameters to job list endpoints ( #37672 ) Feat(api): add last_sync to repository API ( #37566 ) Enhance: Adjust Workflow Graph styling ( #37497 ) Improve code editor text selection and clean up lint enablement ( #37474 ) Add mirror auth updates to repo edit API and settings ( #37468 ) Replace olivere/elastic with REST API client, add OpenSearch support ( #37411 ) Feat: Add default PR branch update style setting ( #37410 ) Fix inconsistent disabled styling on logged-out repo header buttons ( #37406 ) Allow fast-forward-only merge when signed commits are required ( #37335 ) Enhance styling in actions page ( #37323 ) Fix: improve actions status icons and texts ( #37206 ) Make Markdown fenced code block work with more syntaxes ( #37154 ) Fix: Sort action run jobs by JobID and Name with matrix examples ( #37046 ) Add API endpoint to reply to pull request review comments ( #36683 ) PERFORMANCE Perf(web): sort the action_run query by a repo-scoped index when possible ( #38155 ) Perf: Various
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GITEAGITEA-1.28.0-DEV
fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2…
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DENODENO-2.9.0
2.9.0 / 2026.06.25 Read more: http://deno.com/blog/v2.9 feat(bundle): add --declaration flag to generate rolled-up .d.ts files ( #33838 ) feat(cli): add deno link and deno unlink subcommands ( #34359 ) feat(cli): add deno watch subcommand ( #35301 ) feat(cli): add deno list subcommand to list declared dependencies ( #34972 ) feat(cli): auto-migrate pnpm-workspace.yaml on resolution failure ( #34993 ) feat(cli): provide a node on PATH when Node.js is not installed ( #34969 ) feat(compile): persist Web Storage/KV in a per-app data directory ( #34618 ) feat(coverage): add configurable coverage thresholds ( #35056 ) feat(desktop): --compress for self-extracting app bundles ( #35420 ) feat(desktop): add Linux .deb and .rpm installer output formats ( #35296 ) feat(desktop): add Windows .msi installer output format ( #35378 ) feat(desktop): autodetect Vite framework ( #35470 ) feat(desktop): default UI backend to webview ( #35442 ) feat(ext/crypto): support remaining modern WebCrypto algorithms ( #35223 ) feat(ext/http): deprecation warning for legacy request abort ( #34397 ) feat(ext/net): implement Happy Eyeballs for Deno.connect and Deno.connectTls ( #31726 ) feat(ext/node): implement node:test mock.module ( #35329 ) feat(ext/node): implement node:test mock.timers ( #33946 ) feat(ext/web): web locks api ( #31166 ) feat(fmt): add sortNamedImports and sortNamedExports options ( #33313 ) feat(fmt): infer config from .editorconfig ( #34071 ) feat(fmt): use lax-css for CSS, SCSS, and Less ( #35160 ) feat(fmt): use lax-markup for HTML, XML, SVG, and components ( #35174 ) feat(fmt): use lax-sql for SQL formatting ( #35161 ) feat(http): allow disabling serve compression ( #35253 ) feat(http): disable Deno.serve automatic compression by default ( #35486 ) feat(install): create node_modules for workspace members ( #34970 ) feat(install): seed deno.lock from bun.lock ( #35394 ) feat(install): seed deno.lock from package-lock.json ( #35330 ) feat(install): seed deno.lock from pnpm-lock.yaml ( #35346 ) feat(install): seed deno.lock from yarn.lock ( #35350 ) feat(install): warn on package.json engines mismatch ( #34225 ) feat(lockfile): auto-resolve git merge conflicts in deno.lock ( #34726 ) feat(lsp): add inferred type request ( #35099 ) feat(napi): implement Node-API version 10 ( #35270 ) feat(node): bump reported process.version to v26.3.0 ( #34747 ) feat(npm): install jsr deps into node_modules via npm-compat registry ( #35029 ) feat(npm): publishing-trust ranking and no-downgrade trust policy ( #34927 ) feat(runtime): add request_builder_hook for fetch token and cdn-loop headers ( #35088 ) feat(task): add --if-present flag to deno task ( #35315 ) feat(task): add --jobs/--concurrency flag to deno task ( #35318 ) feat(task): input-based caching with files/output/env ( #34509 ) feat(task): set npm_execpath, npm_node_execpath and npm_command for package.json scripts ( #35317 ) feat(test): add --changed and --related flags to deno test ( #35199 ) feat(test): add --shard flag to split a test run across machines ( #35057 ) feat(test): add Deno.test.each for parameterized tests ( #34938 ) feat(test): add retry and repeats options to Deno.test ( #35053 ) feat(test): built-in snapshot testing via t.assertSnapshot ( #35139 ) feat(test): show sub-millisecond test durations ( #35200 ) feat(unstable): CSS module imports (with { type: "css" }) ( #35093 ) feat: deno desktop subcommand ( #33441 ) feat: deno remove --global as alias for deno uninstall --global ( #35327 ) feat: add "preferPackageJson" deno.json setting ( #35392 ) feat: add stable --unsafe-proto flag ( #34738 ) feat: enable default minimum dependency age ( #35458 ) feat: stabilize "links" field in deno.json ( #34996 ) feat: stabilize bare node built-in resolution ( #33316 ) feat: support ignore option in Deno.watchFs ( #31582 ) feat: support navigator.userAgentData ( #34743 ) fix(check): treat npm .d.ts as CJS based on package.json ( #35166 ) fix(core): always register isolate to prevent sil
Published Never · Source checked 29 Sep 2026
Release notes and known issues →BROADCOMSPRING-BOOT-3.5.16
🔨 Dependency Upgrades Upgrade to Spring AMQP 3.2.12 #50818 Upgrade to Spring Data Bom 2025.0.13 #50819 Upgrade to Spring Integration 6.5.10 #50820
Published Never · Source checked 29 Sep 2026
Release notes and known issues →APACHE SOFTWARE FOUNDATIONAPACHE-KAFKA-4.3.1
Apache Kafka 4.3.1 release
Published Never · Source checked 29 Sep 2026
Release notes and known issues →DOCKERDOCKER-COMPOSE-5.2.0
What's Changed ℹ️ This version introduces a new reconciliation algorithm between the observed state and the expected state. If you experience any issues with a Compose workload that was previously working, please open an issue. ✨ Improvements Reconciliation plan by @ndeloof & @glours in #13830 Add rawsetenv message type for provider plugins by @rajyan in #13742 🐛 Fixes Fix(build): skip remote URL contexts from bake fs.read allowlist by @ndeloof in #13816 Skip validation when extracting config variables by @scarab-systems in #13831 Fix(progress): probe stderr (not stdout) for TTY auto-detection by @glours in #13837 Fix(publish): honor env_file required: false for missing files by @Ijtihed in #13848 🔧 Internal Docs: compose logs: add links for since/until flag descriptions by @thaJeztah in #13806 Ci: add Dependabot cooldown (20260603-170456) by @securityeng-bot[bot] in #13820 Docs(CLAUDE.md): note that commits must be signed off (DCO) by @ndeloof in #13817 Refactor: replace Split in loops with more efficient SplitSeq and replace HasPrefix+TrimPrefix with CutPrefix by @caltechustc in #13810 Chore: fix some comments to improve readability by @solunolab in #13823 GHA: update docs-upstream to pin workflows by sha by @thaJeztah in #13834 Docs: compose logs: add more links for flag descriptions by @thaJeztah in #13833 Fix/progress tty line overflow 13595 by @glours in #13840 Fix(publish): bypass Docker Desktop proxy for loopback registries by @ptrdom in #13825 Watch: do not rebuild depends_on services on file change by @ndeloof in #13856 pkg/e2e: fix malformed JWT in fixtures by @thaJeztah in #13857 pkg/e2e: drop unused run param from getEnv by @glours in #13867 Docs: ps --format json outputs JSON Lines, not a JSON array by @glours in #13868 ⚙️ Dependencies Build(deps): bump github.com/docker/cli from 29.5.1+incompatible to 29.5.2+incompatible by @dependabot [bot] in #13802 Update to go 1.26.4 by @thaJeztah in #13828 Chore(deps): github.com/containerd/typeurl/v2 v2.3.0 by @thaJeztah in #13829 Build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 by @dependabot [bot] in #13838 Chore(deps): github.com/docker/cli v29.5.3 , github.com/docker/buildx v0.34.1 , buildkit v0.30.0 by @thaJeztah in #13841 Build(deps): bump golang.org/x/sys from 0.45.0 to 0.46.0 by @dependabot [bot] in #13832 Chore(deps): golang.org/x/crypto v0.53.0 by @thaJeztah in #13844 Build(deps): bump github.com/containerd/containerd/v2 from 2.2.3 to 2.2.4 in the go_modules group across 1 directory by @dependabot [bot] in #13804 Chore(deps): bump github.com/containerd/containerd/v2 to v2.2.5 by @thaJeztah in #13855 Chore(deps): bump github.com/golang-jwt/jwt/v5 to v5.3.1 by @thaJeztah in #13847 Chore(deps): github.com/docker/cli v29.6.0 , github.com/docker/buildx v0.35.0 , buildkit v0.31.0 by @thaJeztah in #13842 Bump compose-go to version v2.12.1 by @glours in #13865 New Contributors @securityeng-bot[bot] made their first contribution in #13820 @caltechustc made their first contribution in #13810 @solunolab made their first contribution in #13823 @scarab-systems made their first contribution in #13831 @ptrdom made their first contribution in #13825 @rajyan made their first contribution in #13742 @Ijtihed made their first contribution in #13848 Full Changelog : v5.1.4...v5.2.0
Published Never · Source checked 29 Sep 2026
Release notes and known issues →PYTHON SOFTWARE FOUNDATIONPYTHON-3.15.0
Python 3.15.0b3
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GITEAGITEA-1.26.3
Warning Please upgrade to 1.26.4 directly. A regression in this release can cause "context deadline exceeded" errors when opening any repository's code pages ( #38177 ). Please hold off on upgrading until a fix is released. BREAKING fix(actions)!: require merged PR to bypass fork PR approval gate ( #38010 ) ( #38041 ) SECURITY fix(hostmatcher): patch incorrect private list ( #38170 ) ( #38173 ) fix: Various security fixes ( #38103 ) ( #38151 ) fix: Various sec fixes ( #38108 ) ( #38147 ) fix: allow git clone of private repos with anonymous code access ( #38074 ) ( #38146 ) fix(auth): ignore stale OIDC external login links to organizations ( #37875 ) ( #38141 ) fix(hostmatcher): block reserved IP ranges from external/private filters ( #38039 ) ( #38059 ) fix(lfs): require Code-unit access for cross-repo LFS object reuse ( #38006 ) ( #38050 ) fix(lfs): reject unknown SSH LFS sub-verbs to prevent auth bypass ( #38008 ) ( #38015 ) fix: bound CODEOWNERS regex match time ( #38011 ) ( #38025 ) fix: bound debian ParseControlFile to a single control stanza ( #38044 ) ( #38055 ) fix(deps): update module golang.org/x/net to v0.55.0 [security] ( #37813 ) ( #37829 ) API feat(api): add Link header in ListForks ( #38052 ) ( #38063 ) BUGFIXES fix: Fix the panic when ssh remote lfs endpoint parsing failure ( #38026 ) ( #38158 ) fix(api): nil pointer panic when filtering tracked times by a non-existent user ( #38112 ) ( #38115 ) fix: keep literal "false" value displayed in workflow_dispatch choice dropdowns ( #38080 ) ( #38096 ) fix: parse HEAD ref ( #38119 ) fix: git cmd ( #38084 ) ( #38087 ) fix(releases): generate notes for initial tag ( #37697 ) ( #37986 ) fix(actions): return 404 when job log blob is missing ( #38003 ) ( #38004 ) fix(actions): exclude workflow_call from workflow trigger detection ( #37894 ) ( #37899 ) fix(actions): keep action run title clickable when commit subject is a URL ( #37867 ) ( #37898 ) fix(actions): reject workflow_dispatch for workflows without that trigger ( #37660 ) ( #37895 ) fix(actions): ack re-sent UpdateLog finalize idempotently ( #37885 ) ( #37892 ) fix: http content file render ( #37850 ) ( #37856 ) fix(issues): clear stale ReviewTypeRequest when submitting pending review ( #37809 ) ( #37815 ) fix: Fix issue target branch selection for non-collaborators ( #36916 ) ( #38164 ) BUILD fix(deps): update @playwright/test to 1.60.0 ( #38144 ) ci: add tools/ci-tools.ts for the PR labeler workflow ( #37831 ) fix(build): swagger css import ( #37801 ) ( #37803 ) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →GITEAGITEA-1.26.4
SECURITY fix(auth): do not auto-reactivate disabled users on OAuth2 callback ( #38009 ) ( #38183 ) BUGFIXES fix: walk git log context error handling ( #38182 ) ( #38185 ) Instances on Gitea Cloud will be automatically upgraded to this version during the specified maintenance window.
Published Never · Source checked 29 Sep 2026
Release notes and known issues →