Combined feed from package-managers-opml. 209 items from 79 feeds, generated 2026-07-22T16:50:29Z.

Wed 22 Jul 2026

  • Renovate releases 43.278.3

    43.278.3 (2026-07-22) Miscellaneous Chores deps: update dependency vitest-mock-extended to v5 (main) ( #44786 ) ( d6f2426 ) Build System deps: update dependency typescript to v7 (main) ( #44785 ) ( b01c6db )

  • Renovate releases 43.278.2

    43.278.2 (2026-07-22) Bug Fixes preset/monorepo: re-add old facebook/react URL ( #44782 ) ( da47cb0 )

  • Renovate releases 43.278.1

    43.278.1 (2026-07-22) Build System deps: update dependency @opentelemetry/otlp-transformer to v0.220.0 (main) ( #44783 ) ( 89b60af )

  • Renovate releases 43.278.0

    43.278.0 (2026-07-22) Features instrumentation: allow exporting OTLP JSON file ( #42284 ) ( adbc20e )

  • NuGet Client releases 7.10.0.29

    Insert 7.10.0.29 into main on 07/22/2026 12:43:12

  • Renovate releases 43.277.1

    43.277.1 (2026-07-22) Bug Fixes presets/monorepo: update react and react-native source URLs to react/react org ( #44780 ) ( 61e4c9c ) Documentation manager: make sure that Supported Datasources are de-duped and sorted ( #44765 ) ( 3888247 ), closes #44764

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-20-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-20-a

  • Renovate releases 43.277.0

    43.277.0 (2026-07-22) Features gitlab: add gitlab codeowners role support ( #44621 ) ( 2f9735f ) Bug Fixes schedule: match cron schedules on the edge of an hour ( #44757 ) ( 54acab0 )

  • Renovate releases 43.276.0

    43.276.0 (2026-07-22) Features github-actions: support sigstore/cosign-installer version input ( #44766 ) ( f01f1b5 ) managers: add support for the Smithy framework ( #44737 ) ( 8708834 ) Bug Fixes manager/npm: don't include versions in extracted Yarn resolutions ' depName # ( #44776 ) ( 476d10a ), closes #44768 Miscellaneous Chores deps: update dependency tsdown to v0.22.8 (main) ( #44778 ) ( d2ef8e8 ) deps: update dependency uv to v0.11.31 (main) ( #44770 ) ( 2bebe63 )

  • Renovate releases 43.275.2

    43.275.2 (2026-07-22) Bug Fixes deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.11 (main) ( #44775 ) ( 381a5b4 ) Miscellaneous Chores deps: update dependency @biomejs/biome to v2.5.4 (main) ( #44773 ) ( df82d39 ) deps: update github/codeql-action action to v4.37.3 (main) ( #44774 ) ( a04cf91 )

  • RubyGems releases bundler-v4.0.17

    Enhancements: Open compact index cache in binary mode when appending. Pull request #9679 by hsbt Bug fixes: Unquote Gem.ruby when spawning it as a separate argv element. Pull request #9695 by hsbt Escape glob metacharacters in install paths when globbing. Pull request #9687 by hsbt Avoid space-containing absolute path in RUBYOPT. Pull request #9696 by hsbt Preserve the locked Bundler checksum when the gem isn't cached. Pull request #9658 by rwstauner Documentation: Point Bundler gemspec metadat…

  • RubyGems releases v4.0.17

    Enhancements: Validate spec name before writing to the spec cache. Pull request #9690 by hsbt Installs bundler 4.0.17 as a default gem. Bug fixes: Unquote Gem.ruby when spawning it as a separate argv element. Pull request #9695 by hsbt Escape glob metacharacters in install paths when globbing. Pull request #9687 by hsbt Preserve Windows editor paths in gem open and bundle open. Pull request #9694 by hsbt Preserve Windows paths in MAKE and rake environment variables. Pull request #9693 by hsbt F…

  • Renovate releases 43.275.1

    43.275.1 (2026-07-22) Bug Fixes deps: update ghcr.io/renovatebot/base-image docker tag to v13.76.10 (main) ( #44771 ) ( 5586073 ) Miscellaneous Chores deps: update dependency @smithy/util-stream to v4.7.9 (main) ( #44767 ) ( 6894228 ) deps: update dependency astral-sh/uv to v0.11.31 (main) ( #44769 ) ( f31eedd )

  • Podman releases v6.0.2

    Bugfixes Fixed a bug where podman machine VMs created by the WSL provider on Windows were not properly cleaned up if the podman machine init command failed ( #27036 ). Fixed a bug where the Windows installer for Podman would, when installing for all users, incorrectly modify the path of only the user installing Podman ( #29160 ). Fixed a bug where the remote Podman client would throw errors when run on a Linux system that was not using Cgroups v2 ( #29241 ). Misc Updated Buildah to v1.44.1

  • uv releases 0.11.31

    Release Notes Released on 2026-07-21. Enhancements Allow workspace sources to reference members in another workspace by path ( #18401 ) Support .venv files containing paths to centralized project environments ( #20022 ) Update bundled Windows timezone data to IANA 2026c ( #20554 ) Preview features Add an index-specific hash-algorithm setting for lockfile generation ( #20605 ) Configuration Add audit.malware-check and audit.malware-check-url settings ( #20587 ) Performance Avoid quadratic work w…

  • Pub releases SDK-3.14.0-49.0.dev

    SDK 3.14.0-49.0.dev

  • Pub releases SDK-3.14.0-48.0.dev

    SDK 3.14.0-48.0.dev

  • Pub releases SDK-3.14.0-47.0.dev

    SDK 3.14.0-47.0.dev

  • Pub releases SDK-3.14.0-46.0.dev

    SDK 3.14.0-46.0.dev

  • Pub releases SDK-3.14.0-45.0.dev

    SDK 3.14.0-45.0.dev

  • Pub releases SDK-3.14.0-44.0.dev

    SDK 3.14.0-44.0.dev

  • Pub releases SDK-3.13.0-282.3.beta

    SDK 3.13.0-282.3.beta

  • RubyGems Blog 4.0.17 Released

    RubyGems 4.0.17 includes enhancements and bug fixes and Bundler 4.0.17 includes enhancements, bug fixes and documentation. To update to the latest RubyGems you can run: gem update --system [--pre] To update to the latest Bundler you can run: gem install bundler [--pre] bundle update --bundler=4.0.17 RubyGems Release Notes Enhancements: Validate spec name before writing to the spec cache. Pull request #9690 by hsbt Installs bundler 4.0.17 as a default gem. Bug fixes: Unquote Gem.ruby when spawni…

Tue 21 Jul 2026

  • NuGet Client releases 7.9.0.83

    Insert 7.9.0.83 into rel/insiders on 07/21/2026 23:18:08

  • Renovate releases 43.275.0

    43.275.0 (2026-07-21) Features onboarding: use summary view if hitting platform limits ( #44256 ) ( 969d1a1 ), closes #41502

  • Snapd releases 2.76.1

    tagging package snapd version 2.76.1

  • Snapd releases 2.76.2

    tagging package snapd version 2.76.2

  • Snapd releases 2.76.3

    tagging package snapd version 2.76.3

  • opam releases 2.6.0~alpha1

    This is the first alpha release of opam 2.6.0. Binaries and full archive are signed by the opam dev team (fingerprint 92C5 26AE 50DF 3947 0EB2 911B ED4C F1CA 67CB AA92 ). To verify the authenticity of one of these files, run the following commands: curl -fsSLO https://opam.ocaml.org/opam-dev-pubkey.pgp gpg --import opam-dev-pubkey.pgp gpg --verify *.sig Please see our blog post for a highlight on the major changes and upgrade instructions. Changelog : Major changes The shell env hook will now u…

  • Cabal releases Cabal-hooks-v3.18.1.0

    Cabal-hooks-v3.18.1.0

  • Cabal releases Cabal-syntax-v3.18.1.0

    Cabal-syntax-v3.18.1.0

  • Cabal releases Cabal-v3.18.1.0

    Cabal-v3.18.1.0

  • cabal-install-solver-v3.18.1.0

  • Cabal releases cabal-install-v3.18.1.0

    cabal-install-v3.18.1.0

  • Cabal releases hooks-exe-v3.18.1.0

    hooks-exe-v3.18.1.0

  • pipx releases 1.16.2

    What's Changed 👷 ci: test against Python 3.15 beta by @gaborbernat in #1971 Full Changelog : 1.16.1...1.16.2

  • Cabal releases cabal-head

    No release body provided.

  • Pub releases SDK-3.14.0-43.0.dev

    SDK 3.14.0-43.0.dev

  • Pub releases SDK-3.14.0-42.0.dev

    SDK 3.14.0-42.0.dev

Mon 20 Jul 2026

  • This release sharpens task handling around remote files, global config, and tool selectors, trims redundant work from shell activation, and fixes several bootstrap and platform-specific edge cases. Note This is the first published release since v2026.7.7 — versions 2026.7.8 through 2026.7.10 were tagged but never published due to a release pipeline issue. Their changes are included here; see Also in this release below. Added config: structured tool definitions now accept version , path , prefix…

  • pipx releases 1.16.1

    What's Changed 📝 docs: strip the prompt from copied console snippets by @gaborbernat in #1962 🐛 fix: don't crash scanning a foreign binary in the bin dir by @gaborbernat in #1970 Full Changelog : 1.16.0...1.16.1

  • uv releases 0.11.30

    Release Notes Released on 2026-07-20. Python Add CPython 3.15.0b4 ( #20519 ) Preview features Allow uv workspace metadata --sync to target the active virtual environment with --active ( #20500 ) Reuse centralized project environments when workspaces are accessed through symlinks ( #20436 ) Performance Skip resolver candidates whose files are all excluded by exclude-newer ( #20460 ) Limit parallel cache reads to reduce resolver scheduling and allocation overhead ( #20427 ) Accelerate lockfile se…

  • mise releases vfox-v2026.7.16

    Release vfox 2026.7.16

  • mise releases mise-sigstore-v2026.7.1

    Release mise-sigstore 2026.7.1

  • pnpm releases pnpm 12 Alpha 17

    Minor Changes Added support for alias-less Git dependency adds, preserved locked Git commits during unrelated dependency changes, and reported Git package versions in install logs. pnpm list and pnpm why are now feature complete and behaviorally identical to the TypeScript CLI. pnpm list gained --only-projects , --find-by (finders declared in .pnpmfile.cjs ), search by version range ( pnpm ls "foo@^2" ), subtree deduplication with [deduped] markers, peer/skipped annotations, the package-count s…

  • Homebrew releases 6.0.12

    What's Changed vulns: advisory database repo renamed to Homebrew/advisory-database by @andrew in #23117 Bump vendored portable-ruby to 4.0.6 by @brew-commit-app[bot] in #23118 formulary: map resolves information from API by @Bo98 in #23114 downloadable: skip repeated checksum verification of the same file by @aholland in #23116 Enable cask FFI helpers for all users by @MikeMcQuaid in #23061 cmd/upgrade: don't show upgrade size with --build-from-source by @Bo98 in #23109 readline_nonblock: use l…

  • Spack releases v1.0.4 (2026-02-23)

    v1.0.4 (2026-02-23) Bug fixes Concretizer bugfixes: solver: remove a special case for provider weighting #51347 solver: improve timeout handling and add Ctrl-C interrupt safety #51341 solver: simplify interrupt/timeout logic #51349 Repo management bugfixes: repo.py: support rhel 7 #51617 repo.py: fix checking out commits #51695 git: pull_checkout_branch RHEL7 git 1.8.3.1 fix #51779 git: fix locking issue in pull_checkout_branch #51854 spack repo remove: allow removing from unspecified scope #51…

  • Spack releases v1.2.2 (2026-07-20)

    Bug fixes Concretization cache: Fix accidental exponential complexity issue in spec hash, and disable for spliced specs ( #52665 ) Fix serialization issues with abstract input spec ( #52714 , #52716 ) Prune cache only after write ( #52715 ) Reduce excessive syscalls ( #52721 ) Make spack --disable-locks apply to all file system locks used by Spack ( #52270 ) Fix a patch file lookup issue when using multiple package repositories ( #52675 ) Fix a few issues with spack isolate --self ( #52725 ) Fi…

  • Signed-off-by: Harmen Stoppels [email protected]

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-17-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-17-a

Sun 19 Jul 2026

  • pnpm releases pnpm 12 Alpha 16

    Minor Changes Completed pnpm runtime installation parity for Node.js, Deno, and Bun, including runtime failure policy, target architecture selection, and dependency runtime engines. Runtime failure overrides now preserve explicit runtime dependencies without matching engine entries. Deprecated packages are reported during installation: a directly depended-on deprecated package gets an immediate warning, and deprecated subdependencies are summarized in a single <N> deprecated subdependencies fou…

  • pnpm releases pnpm 11.15.1

    Patch Changes pnpm install now detects a supportedArchitectures change and re-evaluates previously skipped platform-specific optional dependencies, instead of reporting the project as up to date and leaving the packages for the old architecture set in place. pnpm setup now removes leftover v10-layout shims at the top of PNPM_HOME , so pnpm self-update no longer warns about a v10 installation layout after PATH has been migrated to the v11 PNPM_HOME/bin layout. Applies to both the TypeScript CLI …

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-16-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-16-a

Sat 18 Jul 2026

  • pnpm releases pnpm 12 Alpha 15

    Minor Changes Optional peer dependencies declared only via peerDependenciesMeta (for example debug 's supports-color peer) are now resolved from a satisfying version already present in the dependency graph, the same way explicitly declared optional peer dependencies are. Previously such peers were only resolved this way when the package's metadata was read back from the lockfile, so an unrelated dependency change could rewrite peer resolutions across the whole lockfile. Added pnpm licenses comm…

  • pnpm releases pnpm 11.15

    Minor Changes Optional peer dependencies declared only via peerDependenciesMeta (for example debug 's supports-color peer) are now resolved from a satisfying version already present in the dependency graph, the same way explicitly declared optional peer dependencies are. Previously such peers were only resolved this way when the package's metadata was read back from the lockfile, so an unrelated dependency change could rewrite peer resolutions across the whole lockfile. Patch Changes Updated ad…

  • pnpm releases [email protected]

    chore(release): 11.15.0, pacquet 12.0.0-alpha.15, pnpr 0.1.0-alpha.4 …

  • pnpm releases v12.0.0-alpha.15

    chore(release): 11.15.0, pacquet 12.0.0-alpha.15, pnpr 0.1.0-alpha.4 …

  • NuGet Client releases 7.10.0.26

    Insert 7.10.0.26 into main on 07/18/2026 12:19:54

  • step 7.sweep-wip2: snapshot before cap-raise resume

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-15-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-15-a

  • Pub releases SDK-3.14.0-41.0.dev

    SDK 3.14.0-41.0.dev

  • pnpm Blog pnpm 11.11-11.14

    pnpm 11.11 through 11.14 add native workspace release management (pnpm change, pnpm lane, and a bare pnpm version -r), a pnpm doctor command that diagnoses your installation end to end, the pnpm access and pnpm team commands for managing packages and organizations on the registry, convergence overrides, and scheme-carrying peerDependencies specifiers. They also fix a path-traversal vulnerability, cut peak memory during cold-cache resolution by roughly 30%, and resolve a peer dependency deadlock.

Fri 17 Jul 2026

  • This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by filing an issue . New in v1.30 Nothing yet. Bug Fixes Fixed a crash ( 0x8000ffff ) when using --disable-interactivity with the Resume experimental feature enabled during install operations. What's Changed Apply latest loc patch by @florelis in #6262 Remove old…

  • step 5.fix0: route bun_s3_signing::error/Error via s3_signing mount path

  • pnpm releases pnpm 12 Alpha 14

    chore(release): 11.14.0, pacquet 12.0.0-alpha.14 ( #13113 ) Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

  • pnpm releases pnpm 11.14

    Minor Changes peerDependencies now accept dependency specifiers that carry a scheme — a named-registry spec ( <registry>:<version> ), an npm: alias, or a file: /git/URL spec — instead of rejecting them with ERR_PNPM_INVALID_PEER_DEPENDENCY_SPECIFICATION #13095 . Such a peer is matched against the semver range carried by the specifier ( work:5.x.x is checked as 5.x.x , npm:bar@^5 as ^5 ), or against * when it carries no version, while the original specifier still selects the package to auto-inst…

  • step 4.fix0: drop package-rename deps; apply 4.2/4.4/4.5/4.6 seds

  • step 3.fix0: drop package-rename deps; apply 2.4/2.5/3.6 seds

  • step 1.fix0: regenerate stale build/debug/codegen rust outputs

  • Gradle releases 9.7.0 RC1

    The Gradle team is excited to announce Gradle 9.7.0 RC1. Here are the highlights of this release: Isolated Projects graduates to incubating Broader Configuration Cache compatibility More source locations in problem reports Read the Release Notes We would like to thank the following community members for their contributions to this release of Gradle: Adam , Aman Gautam , Aman Kumar , Aurimas , gbhavya07 , Josh Friend , nicklauslittle-gov , Pragati , project516 , Ravi , sk-reddy17 , Suvrat Achary…

  • NuGet Client releases 7.10.0.21

    Insert 7.10.0.21 into main on 07/17/2026 12:30:36

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-14-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-14-a

  • mise releases v2026.7.10

    (backend) skip remote discovery for exact versions in more back…

  • mise releases vfox-v2026.7.15

    Release vfox 2026.7.15

  • sbt releases 1.12.14

    🐛 bug fixes fix: Backports the packager cache fix for CVE-2026-26032 by @raboof in sbt/ivy#57 deps: sjson-new 0.10.3, which transitively updates Jawn to 1.7.0 for GHSA-cc4v-rvgp-2pf3 and GHSA-w4cm-gvhj-cgw6 by @eed3si9n in #9460 fix: Fixes BSP dependency parsing by @anatoliykmetyuk in #9451 fix: Fixes JVM option capability in the launcher config by @anatoliykmetyuk in #9452 fix: Fixes sbt shutdownall by @eed3si9n in #9435 updates sbtn 2.0.0-b4d628dd by @eed3si9n in #9443 deps: ipcsocket 1.8.0 b…

  • sbt releases 2.0.3

    🐛 bug fixes fix: Backports the packager cache fix for CVE-2026-26032 by @raboof in sbt/ivy#57 deps: sjson-new 0.15.1, which transitively updates Jawn to 1.7.0 for GHSA-cc4v-rvgp-2pf3 and GHSA-w4cm-gvhj-cgw6 by @eed3si9n in #9458 fix: Fixes JVM option capability in the launcher config by @anatoliykmetyuk in #9452 Full Changelog : v2.0.2...v2.0.3

Thu 16 Jul 2026

  • Dependabot Core releases v0.387.0

    What's Changed Type the gradle, swift, and pre_commit ecosystems by @JamieMagee in #15534 Default cooldown to 3 days when default-days is not specified (behind a feature flag) by @robaiken with @Copilot in #15344 Use shared base cooldown in git_submodules by @robaiken in #15537 [Update graph] Avoid PathDependenciesNotReachable killing the whole job by @brrygrdn in #15522 [Update Graph] Ensure that txt/in pairs are included properly in layers when working out references by @brrygrdn in #15581 bu…

  • mise releases v2026.7.8

    (bootstrap) add repos update and exec commands by @jdx in [#110…

  • Docker Engine releases v29.6.2

    29.6.2 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: docker/cli, 29.6.2 milestone moby/moby, 29.6.2 milestone Security This release includes fixes for multiple security vulnerabilities affecting Docker Engine. CVE-2026-15793 : Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv CVE-2026-15792 : Incorrect parameters sent from a frontend could cause a panic. GHSA-qx3x-mv6r-52p6 CVE-2026-15791 : An LLB…

  • mise releases aqua-registry-v2026.7.3

    Release aqua-registry 2026.7.3

  • mise releases vfox-v2026.7.13

    Release vfox 2026.7.13

  • NuGet Client releases 7.10.0.16

    Insert 7.10.0.16 into main on 07/16/2026 12:28:37

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-13-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-13-a

  • pnpm releases pnpm 11.13.1

    Patch Changes Fixed pnpm pack applying workspace-root ignore rules when a workspace package has its own .npmignore file. Keep the interactive minimumReleaseAge approval prompt visible during pnpm install . The progress reporter now pauses its redraws while a prompt is waiting for input instead of overwriting it, so the install no longer hangs on a question the user cannot see #13019 . Fixed pnpm self-update failing to link native platform binaries stored in sibling global virtual store slots.

  • pipx releases 1.16.0

    What's Changed 📝 docs: restore the 1.16.0 changelog fragments by @gaborbernat in #1961 Full Changelog : 1.15.2...1.16.0

  • The Rust team has published a new point release of Rust, 1.97.1. Rust is a programming language that is empowering everyone to build reliable and efficient software. If you have a previous version of Rust installed via rustup, getting Rust 1.97.1 is as easy as: rustup update stable If you don't have it already, you can get rustup from the appropriate page on our website. What's in 1.97.1 Rust 1.97.1 fixes a miscompilation in an LLVM optimization . We have backported both an LLVM fix and a disab…

Wed 15 Jul 2026

  • pipx releases 1.15.2

    Full Changelog : 1.15.1...1.15.2

  • pipx releases 1.15.1

    What's Changed Keep trash cleanup non-fatal for locked files by @cyphercodes in #1848 Fix --with being dropped for PEP 723 scripts on the pip backend by @2ykwang in #1849 Fix uninject leaving man page symlinks behind by @sronix in #1854 Refresh metadata after runpip installs by @itscloud0 in #1855 🐛 fix(spec): accept local VCS URLs by @gaborbernat in #1859 🐛 fix(install): resolve local find-links by @gaborbernat in #1860 🐛 fix(ensurepath): configure global PATH by @gaborbernat in #1861 🐛 fix(me…

  • This release extends dependency providers and systemd bootstrap to monorepo and timer-based workflows, and hardens GitHub OAuth token refreshes and cache clearing against concurrent mise processes. Added deps: experimental mise deps --monorepo runs dependency providers across every explicitly configured [monorepo].config_roots entry, aligned with mise install --monorepo . Provider IDs are qualified by config root (e.g. //apps/api:uv ) so repeated provider names across subprojects no longer coll…

  • uv releases 0.11.29

    Release Notes Released on 2026-07-15. Python Use gzip-compressed artifacts for PyPy downloads ( #20265 ) Enhancements Add JSON output to uv tree ( #19978 ) Add CUDA 13.2 as a supported PyTorch backend ( #20267 ) Prefer local artifacts over URLs when installing from pylock.toml ( #20393 ) Clarify diagnostics for unsatisfiable direct requirement ranges ( #20227 ) Include the selected project name in missing-extra errors ( #20358 ) Preview features Preserve extras and dependency-group conflict con…

  • Athens releases v0.18.1

    What's Changed chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 by @dependabot [bot] in #2148 Revert in-process subprocess reaper, rely on tini by @matt0x6F in #2137 Replace OpenCensus with OpenTelemetry by @matt0x6F in #2138 update-github-action(deps): bump actions/upload-pages-artifact from 4 to 5 by @dependabot [bot] in #2129 update-github-action(deps): bump docker/setup-buildx-action from 3 to 4 by @dependabot [bot] in #2130 update-go-pkg(deps): bump github.com/go-sql-driver/mysq…

  • mise releases vfox-v2026.7.12

    Release vfox 2026.7.12

  • Deno releases v2.9.3

    2.9.3 / 2026.07.15 feat(cli): deno add --no-save and --save-optional ( #36039 ) feat(cli): add --min-dep-age alias ( #35914 ) feat(compile): support aarch64-pc-windows-msvc target ( #36004 ) feat(ext/fetch): add http2MaxHeaderListSize option to Deno.createHttpClient ( #33194 ) fix(bundle): preserve raw imports in watch mode ( #36040 ) fix(canvas): don't hold SurfaceData mut borrow over window resize ( #35993 ) fix(config): reject out-of-range minimum dependency ages ( #36051 ) fix(core): block …

  • NuGet Client releases 7.10.0.11

    Insert 7.10.0.11 into main on 07/15/2026 12:21:38

  • pixi releases v0.73.0

    [0.73.0] - 2026-07-15 ✨ Highlights This release brings two big features: workspace = true now also works in environment [dependency] tables TOML 1.1 multiline inline tables are now fully supported As usual we also fixed a couple of bugs. workspace = true in environment dependency tables Until now, { workspace = true } only worked in the package dependency tables and required the pixi-build preview. With this release, the environment tables can inherit from [workspace.dependencies] as well, no p…

Tue 14 Jul 2026

  • Homebrew releases 6.0.11

    What's Changed Enable more cask metadata migration to JSON for all users by @MikeMcQuaid in #22958 Skip rewriting Mach-O binaries when delete_rpath changes nothing by @hyuraku in #23079 test_bot/formulae: remove generic tests by @cho-m in #23082 Return a shared type instance from type constructors when runtime checking is disabled by @dduugg in #23078 test_bot/formulae: skip portable Ruby tests on macOS if same version by @cho-m in #23083 Test fixes for portable Ruby macOS runners by @cho-m in …

  • vcpkg releases 2026-07-13 Release

    What's Changed Fix collide on shared .partial extraction directory on POSIX by @Erik-White in #2036 Sanitize DESTDIR on non-Windows platforms by @BillyONeal in #2039 Update NPM dependencies. by @BillyONeal in #2047 Support CURL_CA_BUNDLE like the curl command line tool by @Matus-p in #2042 [curl] Add VCPKG_SSL_REVOKE_BEST_EFFORT to fix Schannel proxy revocation errors by @sdn9002 in #2043 Change GITHUB_SERVER_URL to GITHUB_API_URL to allow submission of dependency graph data again by @rwindegge…

  • ORAS releases v1.3.3

    ORAS CLI v1.3.3 is a maintenance release focused on security hardening, dependency updates, and a few user-facing improvements to oras attach . Highlights 🔒 Security: upgraded oras-go to v2.6.2 , which addresses a tar-extraction path-traversal advisory ( GHSA-fxhp-mv3v-67qp ) affecting hardlink entries during pull /extract. ✨ oras attach gains --config support, and --annotation $config:* values now flow through to the packed manifest. 🛡️ Supply-chain hardening: GitHub Actions are now pinned to …

  • NuGet Client releases 7.10.0.8

    Insert 7.10.0.8 into main on 07/14/2026 12:38:48

  • pub.dev releases 20260714t095300-all

    Deployment at 2026-07-14T09:53:17.406059Z.

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-11-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-11-a

  • pub.dev releases 20260714t082700-all

    Deployment at 2026-07-14T08:27:40.466795Z.

  • Nix releases 2.35.1

    Tagging release 2.35.1

Mon 13 Jul 2026

  • Verdaccio releases v6.8.0

    Minor Changes 962fba8 : feat: add unpublish notification hooks Port of #5920 (ref #5328 ). The notify webhook now also fires when a package is unpublished entirely and when a single version (tarball) is removed, not only on publish. Notification templates can distinguish the event through the new {{ publishType }} ( publish | unpublish ) and {{ publishedPackage }} variables, and the {{ publisher }} object exposes only name , groups and real_groups , so the remote user auth token can never leak …

  • Nix releases 2.35.0

    Tagging release 2.35.0

  • Dependabot Core releases v0.386.0

    What's Changed Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512 Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513 [Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508 Handle global.json with no SDK version in dotnet_sdk parser by @brettfo in #15510 Type the cargo ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15492 Type the conda ecosystem and remove…

  • Homebrew releases 6.0.10

    What's Changed version/parser: speed up StemParser by @Bo98 in #23007 Send bundle check failures to stderr by @MikeMcQuaid in #23009 Guard release against stale main by @MikeMcQuaid in #23008 dev-cmd/bump-formula-pr: keep failures when downgrade fails by @cho-m in #23006 Skip incompatible cask upgrades by @MikeMcQuaid in #23012 Remove redundant T.let annotations Sorbet can infer by @dduugg in #23013 Avoid generated rmdir for shared file lists by @loganrosen in #22940 docs: escape braces to avoi…

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-10-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-10-a

  • Maven releases 3.10.0-rc-1

    💥 Breaking changes Remove release-profile from super POM ( #11999 ) @slawekjaranowski Remove deprecated plugin management from super POM ( #11986 ) @slawekjaranowski 🚀 New features and improvements Feat: Align Maven 3.10.x and 4.0.x ( #12442 ) @cstamas Feat: Align CP ordering with Maven 4 ( #12327 ) @cstamas Feat: Apply latest Resolver 2.0.19 changes ( #12246 ) @cstamas Feat: Maven 3.10.x super POM ( #12032 ) @cstamas In failed build limit reactor summary to only failed modules ( #11977 ) @slaw…

  • sbt releases 2.0.2

    🐛 bug fixes fix: Fixes remote cache ByteStream timeout by @yhefamly in #9413 fix: Fixes metabuild dependency downgrade via plugin by @anatoliykmetyuk in #9426 fix: Fixes build pipelining by @anatoliykmetyuk in #9425 fix: Fixes auto import of givens by @xuwei-k in #9409 fix: Fixes sbtn stdout relaying by @BrianHotopp in #9411 / #9414 fix: Fixes shutdownall in sbt runner by @eed3si9n in #9435 fix: Fixes attribute string in pom.xml to be deterministic @raboof in sbt/ivy#51 fix: Fixes ivyless publi…

  • Another six months have passed since our last development update , and the crates.io team has been busy. Here's a summary of the most notable changes and improvements made to crates.io since then. Source Code Viewer Crate pages now have a "Code" tab that lets you browse the contents of published crate versions directly on crates.io. This shows you the exact files that cargo downloads when you add a crate as a dependency, which might differ from the linked repository. This makes it much easier t…

Sun 12 Jul 2026

Sat 11 Jul 2026

  • Verdaccio releases v7.0.0-next-7.23

    Patch Changes a768d16 : chore: replace eslint and prettier with oxlint and oxfmt

Fri 10 Jul 2026

  • Signed-off-by: Terry Howe [email protected]

  • npm CLI releases libnpmpack: v10.0.1

    Dependencies workspace : @npmcli/[email protected]

  • npm CLI releases libnpmfund: v8.0.1

    Dependencies workspace : @npmcli/[email protected]

  • npm CLI releases libnpmexec: v11.0.1

    Dependencies workspace : @npmcli/[email protected]

  • npm CLI releases libnpmdiff: v9.0.1

    Dependencies workspace : @npmcli/[email protected]

  • npm CLI releases arborist: v10.0.1

    10.0.1 (2026-07-10) Bug Fixes 47fc8b1 #9740 correct bundled sigstore from dev dependency conflict ( #9740 ) ( @james-pre )

  • npm CLI releases v12.0.1

    12.0.1 (2026-07-10) Bug Fixes ecb02a8 #9745 view: avoid wrapping array results ( #9745 ) ( @reggi , @martinrrm , @Copilot) 47fc8b1 #9740 correct bundled sigstore from dev dependency conflict ( #9740 ) ( @james-pre ) Dependencies workspace : @npmcli/[email protected] workspace : [email protected] workspace : [email protected] workspace : [email protected] workspace : [email protected]

  • tl;dr: There is a renewed effort to improve documentation, head to https://opencollective.com/nixos/projects/nix-documentation or contact [email protected] to chip in with funding! With the 2023 crowd-funding in documentation funding , we've seen some improvements, but a lot more is needed to make significant progress towards improving the overall experience with Nix documentation, including onboarding and discovery. Especially newcomers frequently struggle with our documentation, get frustr…

  • RubyGems releases bundler-v4.0.16

    Enhancements: Bundler: Fix Bundler::Fetcher for PQC support, adding integration connection tests. Pull request #9637 by junaruga Reuse RubyGems' vendored tsort in Bundler. Pull request #9647 by hsbt Bug fixes: Initialize the new gem's git repo without a subshell. Pull request #9670 by hsbt Preserve CRLF lockfile line endings on Windows. Pull request #9669 by hsbt Fix the gemspec error snippet on Windows drive-letter paths. Pull request #9668 by hsbt Documentation: Point Bundler gemspec metadata…

  • RubyGems releases v4.0.16

    Enhancements: Installs bundler 4.0.16 as a default gem. Bug fixes: Skip the make job server when using BSD make. Pull request #9676 by flavorjones

  • Gradle releases v9.7.0-M3

    Prepare release notes for Gradle 9.7.0RC1 ( #38479 )

  • RubyGems Blog 4.0.16 Released

    RubyGems 4.0.16 includes enhancements and bug fixes and Bundler 4.0.16 includes enhancements, bug fixes and documentation. To update to the latest RubyGems you can run: gem update --system [--pre] To update to the latest Bundler you can run: gem install bundler [--pre] bundle update --bundler=4.0.16 RubyGems Release Notes Enhancements: Installs bundler 4.0.16 as a default gem. Bug fixes: Skip the make job server when using BSD make. Pull request #9676 by flavorjones Bundler Release Notes Enhanc…

Thu 9 Jul 2026

  • Hex releases v2.5.1

    Enhancements Add ignore_advisories and ignore_retirements configs to acknowledge security advisories and package retirements. Configure them in the mix.exs :hex block ( ignore_advisories: ["CVE-2026-32686"] , ignore_retirements: [:decimal, phoenix: "1.0.0"] ) or with the HEX_IGNORE_ADVISORIES and HEX_IGNORE_RETIREMENTS environment variables. An advisory can be ignored by any of its aliased identifiers (for example the GHSA alias of a CVE). mix hex.audit lists ignored findings in separate sectio…

  • Helm releases Helm v3.21.3

    Helm v3.21.3 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Installation and Upgrading Download Helm v3.21.3. The common platform binaries are here: MacOS amd64 ( check…

  • Helm releases Helm v4.2.3

    Helm v4.2.3 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! Join the discussion in Kubernetes Slack : for questions and just to hang out for discussing PRs, code, and bugs Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom Test, debug, and contribute charts: ArtifactHub/packages Installation and Upgrading Download Helm v4.2.3. The common platform binaries are here: MacOS amd64 ( checksu…

  • NuGet Client releases 7.10.0.5

    Insert 7.10.0.5 into main on 07/09/2026 20:52:07

  • Swift Package Manager releases swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-06-a

    Tag build swift-6.4.x-DEVELOPMENT-SNAPSHOT-2026-07-06-a

  • opam releases 2.5.2

    This is the release of opam 2.5.2. Binaries and full archive are signed by the opam dev team (fingerprint 92C5 26AE 50DF 3947 0EB2 911B ED4C F1CA 67CB AA92 ). To verify the authenticity of one of these files, run the following commands: curl -fsSLO https://opam.ocaml.org/opam-dev-pubkey.pgp gpg --import opam-dev-pubkey.pgp gpg --verify *.sig Please see our blog post for more details and the upgrade instructions. Changelog : Security fix Fix a bug that allowed a package to install files anywhere…

  • pixi releases v0.72.2

    [0.72.2] - 2026-07-09 ✨ Highlights This release contains more fixes for rich platforms. Added Add pixi workspace platform add --auto-detected by @hunger in #6355 Explain why each declared platform cannot run here by @hunger in #6491 Changed Compose sysreq platforms from customisations only by @kilian-hu in #6520 Report unsatisfied virtual packages instead of a misleading interpreter error by @hunger Documentation Document the build variants pixi sets automatically by @hunger in #6534 Fixed Quic…

  • Cargo releases 0.98.0

    0.98.0 release

  • NuGet Client releases 7.9.0.76

    Insert 7.9.0.76 into main on 07/09/2026 12:25:12

  • The Rust team is happy to announce a new version of Rust, 1.97.0. Rust is a programming language empowering everyone to build reliable and efficient software. If you have a previous version of Rust installed via rustup , you can get 1.97.0 with: $ rustup update stable If you don't have it already, you can get rustup from the appropriate page on our website, and check out the detailed release notes for 1.97.0 . If you'd like to help us out by testing future releases, you might consider updating …

Wed 8 Jul 2026

  • npm CLI releases libnpmversion: v9.0.0

    9.0.0 (2026-07-08) ⚠️ BREAKING CHANGES npm shrinkwrap is removed, the shrinkwrap config alias is removed, and npm-shrinkwrap.json is no longer loaded or honored at the project root or from inside dependency tarballs. Rename project-root npm-shrinkwrap.json to package-lock.json ; use bundleDependencies if you need to ship a locked dependency tree. npm now supports node ^22.22.2 || ^24.15.0 || >=26.0.0 Features 5b83698 #9737 trigger release process ( #9737 ) ( @reggi )

  • npm CLI releases libnpmteam: v9.0.0

    9.0.0 (2026-07-08) ⚠️ BREAKING CHANGES npm now supports node ^22.22.2 || ^24.15.0 || >=26.0.0 Features 5b83698 #9737 trigger release process ( #9737 ) ( @reggi )

  • npm CLI releases v12.0.0

    12.0.0 (2026-07-08) ⚠️ BREAKING CHANGES npm view --json now always returns an array. npm sbom --sbom-format=cyclonedx now reports the name field from each package's package.json instead of the on-disk directory name. The name , bom-ref , and purl of the root component and of aliased dependencies may change. npm no longer registers man pages with the system when installed globally. man npm-install will no longer work, but npm help install is unaffected. The npm pkg output is no longer forced to …

  • Podman releases v6.0.1

    Bugfixes Fixed a bug where Podman Machine VMs on Mac using the libkrun provider could be regularly turned off by a port-scanning process on the host unintentionally commanding the VM to shut down. Fixed a bug where the podman machine init command would fail on Windows hosts when using the hyperv provider when WSL was not installed ( #29053 ). Fixed a bug where the podman machine init command would fail on Windows hosts when using the wsl provider when the user was a Hyper-V admin but Hyper-V is…

  • npm CLI releases v12.0.0-pre.3

    12.0.0-pre.3 (2026-07-08) Features fd75880 #9729 warn instead of error on unknown .npmrc configs ( #9729 ) ( @reggi ) 42b12c2 #9697 install-scripts: use install-scripts as the warning log title ( @manzoorwanijk ) Chores 6fefd0e #9733 clarify unknown-config breaking change note in changelog ( #9733 ) ( @reggi , @Copilot) Dependencies workspace : @npmcli/[email protected]

  • Podman releases v5.8.5

    Bugfixes Fixed a bug where Podman Machine VMs on Mac using the libkrun provider could be regularly turned off by a port-scanning process on the host unintentionally commanding the VM to shut down.

  • Yarn releases v4.17.1

    What's Changed Handle optional compat patch failures for TypeScript 7 by @hamidrezahanafi in #7190 New Contributors @hamidrezahanafi made their first contribution in #7190 Full Changelog : https://github.com/yarnpkg/berry/compare/@yarnpkg/cli/4.17.0...@yarnpkg/cli/4.17.1

  • Yarn releases 2026-07-08

    2026-07-08

  • @yarnpkg/plugin-compat

  • @yarnpkg/plugin-patch

  • Deno releases v2.9.2

    2.9.2 / 2026.07.08 feat(desktop): autodetect React Router framework ( #35557 ) feat(desktop): enable --hmr for Vite and Nuxt ( #35851 ) feat(desktop): run HMR by framework dev server ( #35722 ) feat(desktop): window opacity and transparency APIs ( #35646 ) feat(desktop): wire --exclude-unused-npm through to compile ( #35740 ) feat(ext/node): implement v8.setHeapSnapshotNearHeapLimit ( #35694 ) feat(ext/telemetry): honor OTEL_ATTRIBUTE_VALUE_LENGTH_LIMIT ( #35068 ) feat(inspector): start inspect…

  • pixi releases pixi-build-ros-v0.6.5

    chore: bump backend versions ( #6562 )

  • Composer releases 2.10.2

    Security: Validate package names ( GHSA-499r-g7pc-vmp9 / CVE-2026-59948 ) Security: Validate package bin paths against path traversal ( GHSA-gjfg-22fp-rrxx / CVE-2026-59946 ) Security: Sanitize URL-embedded usernames/token in verbose output ( GHSA-g6xq-892h-64w3 / CVE-2026-59947 ) Security: Only follow HTTP redirects from HTTP responses ( #12948 ) Security: Prevent phar metadata unserialization on unsafe PHP versions ( #12946 ) Security: Sanitize JSON parse errors in http responses to avoid lea…

  • Homebrew releases 6.0.9

    What's Changed install_steps: handle EUID/UID like postinstall does by @Bo98 in #22985 cask/upgrade: don't lose the original exception when rollback itself fails by @aholland in #22997 Defer reinstall keg backup and silence analytics curl output by @p-linnane in #22994 cask: don't crash upgrade when staged version directory is missing by @gecube in #22999 perf/config: gather system configuration concurrently (~31% faster) by @dduugg in #22989 github_runner_matrix: unique runner for each shard b…

  • Hatch releases Hatch v1.17.1

    Fixed Use TemporaryDirectory and pylock*.toml for temporary lock files. Skip injection of ruff extend if a key already exists in ruff.toml . Pass --no-header to uv pip compile in the uv locker so that generated lockfiles are deterministic. Fix env-dependency extras being dropped when a metadata hook is configured and resolve workspace-member extras from the member's own metadata.

  • Hatch releases Hatchling v1.31.0

    Fixed Only rewrite the shebang of a shared script when a Python shebang is present on the first line, preserving binary files and other content verbatim instead of dropping leading bytes.

Tue 7 Jul 2026

  • uv releases 0.11.28

    Release Notes Released on 2026-07-07. Security This release updates our ZIP library, astral-async-zip , to v0.0.20, which includes 15 changes that harden our ZIP handling against parser differentials . uv may reject ZIP archives with malformed or ambiguous content that were previously accepted. See the upstream commits for a full list of changes. Python Upgrade GraalPy to 25.1.3 ( #20069 ) Enhancements Improve trace logs for unexpected error chains ( #20220 ) Move lockfile update guidance to a …

  • Change-Id: Iee4d231b5b040576ab9c1175ba726e03090fff7c Reviewed-on: https://go-review.googlesource.com/c/go/+/797800 TryBot-Bypass: Gopher Robot [email protected] Reviewed-by: Junyang Shao [email protected] Reviewed-by: David Chase [email protected] Auto-Submit: Gopher Robot [email protected]

  • Change-Id: Ie3ced7f6cf7301d878818c6ec858b659bb5f04df Reviewed-on: https://go-review.googlesource.com/c/go/+/797760 Reviewed-by: Junyang Shao [email protected] Reviewed-by: David Chase [email protected] Auto-Submit: Gopher Robot [email protected] TryBot-Bypass: Gopher Robot [email protected]

  • Change-Id: I87dc3d84cde11db83a0d88a60262a38fc429838d Reviewed-on: https://go-review.googlesource.com/c/go/+/797740 Auto-Submit: Gopher Robot [email protected] Reviewed-by: David Chase [email protected] Reviewed-by: Junyang Shao [email protected] TryBot-Bypass: Gopher Robot [email protected]

  • Spack releases v1.2.1 (2026-07-06)

    Bug fixes Installer bugfixes: Fix a hang of the new installer when running under forkserver ( #52621 ) Sanitize the computed build log filename ( #52660 ) Allow local installs for packages missing in upstream ( #52630 ) Restore working_dir in build subprocess ( #52576 ) Solver bugfixes: Restore performance on macOS ( #52604 , #52603 ) Fix the solver heuristic for build_set_id ( #52634 ) Drop noisy debug message ( #52640 ) Fix environment view regeneration when using multiple overlayfs layers ( …

  • asdf releases v0.20.0

    0.20.0 (2026-07-07) Features add warning to asdf info output when ASDF_TOOL_VERSIONS_FILENAME value is invalid ( #2293 ) ( 244e513 ) Bug Fixes shallow clone plugin repositories for faster installs ( #2256 ) ( badc9db ) update nushell completion code so it works on latest version of nushell ( #2275 ) ( 51ebfb4 )

  • This is the next post in our supply chain security series, following the supply chain security update and the Composer 2.10 release . Each post in this series covers a specific behavior worth understanding, and a change we are making on top of it. Today: Stable version metadata on Packagist.

  • pixi releases pixi-build-mojo-v0.2.4

    chore: bump backend versions ( #6539 )

  • pixi releases pixi-build-python-v0.8.3

    chore: bump backend versions ( #6539 )

  • pixi releases pixi-build-r-v0.1.5

    chore: bump backend versions ( #6539 )

  • chore: bump backend versions ( #6539 )

  • pixi releases pixi-build-ros-v0.6.4

    chore: bump backend versions ( #6539 )

  • pixi releases pixi-build-rust-v0.5.4

    chore: bump backend versions ( #6539 )

  • pixi releases v0.72.1

    [0.72.1] - 2026-07-07 ✨ Highlights This release contains important bugfixes for rich platforms, v3 repodata handling, pixi-build-r and more. Changed Do not fail when running tasks in an environment by @hunger in #6507 Provide R packages under their r-prefixed conda name by @roaldarbol in #6515 Suggest pixi self-update --version for requires-pixi errors by @hunger in #6516 Register run-export-introduced source deps on the assembled record by @wolfv in #6519 Let explicit source registrations win …

Mon 6 Jul 2026

  • CocoaPods releases 1.17.0

    Enhancements Added --no-lint option for pod repo push command to allow skipping Lint phase when publishing a Pod. Guillermo Mazzola #12706 Bump minimum Xcodeproj to 1.28.0. Eric Amorde #12913 Remove unused escape dependency. Samuel Giddins , Eric Amorde #12914 Bug Fixes Update ruby-macho to 4.1.0 to address new mergable libraries not beind detected correctly. Parsa Nasirimehr #12691 Fix a crash when run with certain versions of active_support. Eric Amorde #12915

  • uv releases 0.11.27

    Release Notes Released on 2026-07-06. Enhancements Continue on ignored errors when fetching wheel metadata ( #12255 ) Use caching for --python-downloads-json-url ( #16749 ) Preview features Discover extensionless shebang scripts in uv workspace list --scripts ( #20099 ) Performance Avoid full site-packages scans for direct reinstalls ( #20119 ) Avoid redundant pyproject parsing ( #20076 ) Cache default dependency markers when reading locks ( #20125 ) Enable SIMD-accelerated TOML parsing ( #2007…

  • Nix releases 2.34.8

    Tagging release 2.34.8

  • Homebrew releases 6.0.8

    What's Changed test/bundle/brew_spec: allow running test on generic OS by @cho-m in #22973 Add source option to brew bundle uv tools by @danielfleischer in #22963 test/test_bot_spec: use :trust_store context when testing trust by @cho-m in #22972 Update issue links in docs to use correct template by @SMillerDev in #22982 Store bottle SBOM data in manifests by @MikeMcQuaid in #22981 Clarify install output for durations and single deps by @HaraldNordgren in #22980 perf/sorbet: skip sorbet-runtime…

  • Dependabot Core releases v0.385.0

    What's Changed Support package-scoped NuGet release notes by @Cjewett in #15211 Filter null entries from job directories by @brettfo in #15457 devcontainers: preserve major-only Feature pins when precision-matching tags are absent by @thavaahariharangit with @Copilot in #15445 Type opaque hashes in common with T.anything by @JamieMagee in #15458 Type the options passthrough in base classes with T.anything by @JamieMagee in #15459 Apply git-tag cooldown across ecosystems by @robaiken in #15369 T…

  • Homebrew releases 6.0.7

    What's Changed ENV/super: set CC and CXX to unversioned gcc on Linux by @cho-m in #22889 audit: require curl dependencies to have a working HTTP mirror by @p-linnane in #22898 Force CMake to find shims before $HOMEBREW_PREFIX/bin by @cho-m in #22916 Improve awkward wording of Backing Up App by @carter-thaxton in #22918 bump-cask-pr: error when update fails by @samford in #22901 contributions: fix type error by @samford in #22915 extend/ENV/super: set CC/CXX to real names for llvm_clang by @cho-…

Sun 5 Jul 2026

  • pnpm Blog pnpm 11.10

    pnpm 11.10 adds the _auth setting for CI-friendly registry authentication, new pnpm prefix and pnpm issues commands, and the ability for pnpm self-update to install pnpm v12 (the Rust port). It also improves pnpm up accuracy, speeds up resolution against registries that ignore abbreviated metadata, and hardens global package management, pnpm deploy, and pnpm pack-app.

Thu 2 Jul 2026

  • Gradle releases v9.7.0-M2

    Add feature preview for enhanced graph orderings ( #38077 )

  • NuGet Client releases 7.9.0.71

    Insert 7.9.0.71 into main on 07/02/2026 12:20:04

  • pub.dev releases 20260702t101200-all

    Deployment at 2026-07-02T10:12:51.191618Z.

  • Harbor releases v2.15.2

    What's Changed Component updates ⬆️ [CHERRY-PICK] Make openapi-generator-cli download URL configurable ( #23186 ) by @chlins in #23221 bump Go version from 1.25.9 to 1.26.3 by @stonezdj in #23236 [cherry-pick] Rebuild goharbor/photon image before create new harbor base images by @jUDASmILE in #23250 [cherry-pick]remove install net-tools from db dockerfile as photon removed it by @jUDASmILE in #23267 [CHERRY-PICK] feat: replace redis with valkey as cache backend ( #23157 ) by @chlins in #23261 […

  • Harbor releases v2.15.2-rc3

    What's Changed Component updates ⬆️ [CHERRY-PICK] Make openapi-generator-cli download URL configurable ( #23186 ) by @chlins in #23221 bump Go version from 1.25.9 to 1.26.3 by @stonezdj in #23236 [cherry-pick] Rebuild goharbor/photon image before create new harbor base images by @jUDASmILE in #23250 [cherry-pick]remove install net-tools from db dockerfile as photon removed it by @jUDASmILE in #23267 [CHERRY-PICK] feat: replace redis with valkey as cache backend ( #23157 ) by @chlins in #23261 […

Wed 1 Jul 2026

  • This is the latest of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by filing an issue . New in v1.29 New Feature: Source Priority Note Experimental under sourcePriority ; defaulted to disabled. With this feature, one can assign a numerical priority to sources when added or later through the source edit command. Sources with higher priority are sorted first in the list of sources, which results in them getting put first in the results if other things are eq…

  • Deno releases v2.9.1

    2.9.1 / 2026.07.01 feat(check): add --desktop flag to type-check for deno desktop ( #35644 ) feat(desktop): register deep-link URL schemes at bundle time ( #35466 ) feat: update laufey to 0.5.0 ( #35663 ) fix(bundle): emit CSSStyleSheet for CSS raw imports ( #35598 ) fix(cache): skip checksums for cached 404 entries ( #35526 ) fix(config): don't strip workspace-member includes from deploy config ( #34788 ) fix(core): apply deferred fast-call op upgrade to the captured bootstrap clone ( #35630 )…

  • Composer releases 2.2.29

    Security: Validate package names ( GHSA-499r-g7pc-vmp9 ) Security: Validate package bin paths against path traversal ( GHSA-gjfg-22fp-rrxx ) Security: Sanitize URL-embedded usernames/token in verbose output ( GHSA-g6xq-892h-64w3 ) Security: Only follow HTTP redirects from HTTP responses ( #12948 ) Security: Prevent phar metadata unserialization on unsafe PHP versions ( #12946 ) Security: Sanitize JSON parse errors in http responses to avoid leaking response body data ( #12959 ) Fixed GitHub tok…

Tue 30 Jun 2026

  • Dependabot Core releases v0.384.0

    What's Changed Bazel: Fix prerelease filtering with same-release-line scoping by @v-HaripriyaC in #15332 Respect cooldown for Docker digest updates and suppress multi-arch no-ops by @robaiken in #15354 Bypass npmrc min-release-age for transitive npm security updates by @robaiken in #15386 Ratchet the Sorbet T.untyped burndown by @JamieMagee in #15399 feat(docker): implement single-platform image detection and optimize manifest fetching logic by @jpinz in #15390 Fix private registry config not f…

  • uv releases 0.11.26

    Release Notes Released on 2026-06-30. Performance Adapt uv to IDs-only PubGrub dependencies ( #20048 ) Avoid allocations in ForkMap::contains ( #20023 ) Reuse resolver work across PubGrub iterations ( #20020 ) Speed up candidate selection for disjoint ranges ( #20026 ) Bug fixes Warn when the build cache is inside the source directory ( #20056 ) Install uv 0.11.26 Install prebuilt binaries via shell script curl --proto ' =https ' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/dow…

  • Cargo releases 0.97.2

    0.97.2 release

  • Homebrew releases 6.0.6

    What's Changed Flag scoped service path helpers by @MikeMcQuaid in #22858 linkage_checker: always report incorrect :no_linkage by @cho-m in #22887 Cleanup brew-rs leftovers by @botantony in #22895 Add shared Utils::Path.ensure_child_of! containment helper by @p-linnane in #22890 test: add :needs_daemon_manager to some tests by @cho-m in #22905 test/cmd/update_spec: fix local test run failures by @cho-m in #22906 Resolve patch targets via patch --dry-run for containment by @p-linnane in #22908 R…

  • The Rust team has published a new point release of Rust, 1.96.1. Rust is a programming language that is empowering everyone to build reliable and efficient software. If you have a previous version of Rust installed via rustup, getting Rust 1.96.1 is as easy as: rustup update stable If you don't have it already, you can get rustup from the appropriate page on our website. What's in 1.96.1 Rust 1.96.1 fixes: Missing retries / timeouts in Cargo's HTTP client Miscompilation in a MIR optimization It…

Mon 29 Jun 2026

  • Conan releases 2.30.0 (29-Jun-2026)

    Feature: Add SPDX expression support in SBOM generation. ( #20112 ) Feature: Add type annotations to LockfileAPI for improved IDE support. ( #20104 ) Feature: Add missing favicon to Conan HTML output. ( #20087 ) Feature: Implement the conf=~ for the "unset" operation (alias for conf=! ). ( #20084 ). Docs: 📃 Feature: Add ASFLAGS to AutotoolsToolchain / GnuToolchain , including architecture and sysroot flags. ( #20078 ). Docs: 📃 Feature: Add IntelCC support in Meson, Autotools and Premake toolcha…

  • sbt releases 2.0.1

    🐛 bug fixes fix: Fixes sbt runner parsing build.properties with whitespaces by @anatoliykmetyuk in #9374 fix: Fixes global plugin loading by @eed3si9n in #9391 / #9380 fix: Fixes sbt runner support on OpenBSD by @eed3si9n in #9394 fix: Fixes --allow-empty and --sbt-create by @anatoliykmetyuk in #9370 fix: Fixes BSP publishDiagnostics propagation by @anatoliykmetyuk in #9376 fix: Fixes macro expansion for higher-kinded type arguments by @tanishiking in #9377 fix: Fixes IllegalAccessError analyzi…

  • Hex releases v2.5.0

    Enhancements Add organization-defined dependency policies that filter the package versions available during dependency resolution. An organization publishes a named policy through its repository, and a project opts into one with the policy config ( HEX_POLICY , [org: "ORG", name: "NAME"] in the mix.exs :hex block, or mix hex.config ). A policy constrains one or more repositories — typically the organization's own repo and hexpm — and for each can block releases that: carry a security advisory a…

Sat 27 Jun 2026

  • Harbor releases v2.15.2-rc2

    What's Changed Component updates ⬆️ [CHERRY-PICK] Make openapi-generator-cli download URL configurable ( #23186 ) by @chlins in #23221 bump Go version from 1.25.9 to 1.26.3 by @stonezdj in #23236 [cherry-pick] Rebuild goharbor/photon image before create new harbor base images by @jUDASmILE in #23250 [cherry-pick]remove install net-tools from db dockerfile as photon removed it by @jUDASmILE in #23267 [CHERRY-PICK] feat: replace redis with valkey as cache backend ( #23157 ) by @chlins in #23261 […

  • uv releases 0.11.25

    Release Notes Released on 2026-06-26. Security This release updates our tar library, astral-tokio-tar , to v0.6.3, which includes over 20 changes that harden our tar handling against parser differentials . uv may reject source distributions with malformed or ambiguous content that were previously accepted. See the upstream commits for a full list of changes. Enhancements Add a full "lockfile" to tool receipts ( #18937 ) Allow scoped overrides to add dependencies ( #19974 ) Avoid writing redunda…

Fri 26 Jun 2026

  • Homebrew releases 6.0.5

    What's Changed rubocop/formula_path_methods: add formula_opt_include method by @botantony in #22867 Reject patch targets that escape the staged source tree by @p-linnane in #22881 system_command: use Process.spawn to avoid fork-unsafe exec3 child by @p-linnane in #22880 formula: std_meson_args prefix param and relative libdir by @cho-m in #22888 Expand deferred env in curl URLs by @MikeMcQuaid in #22886 Full Changelog : 6.0.4...6.0.5

  • Gradle releases 9.6.1

    The Gradle team is excited to announce Gradle 9.6.1. Here are the highlights of this release: Improved Configuration Cache hit rates Additional CLI rendering options Important project hierarchy lookup deprecations Read the Release Notes We would like to thank the following community members for their contributions to this release of Gradle: Aharnish Solanki , Benedikt Johannes , Devendra Reddy Pennabadi , Dmytro Rodionov , Dreeam , Elías Hernández Rodríguez , Eng Zer Jun , FinlayRJW , Kamal Kan…

  • Podman releases v5.8.4

    Security This release addresses CVE-2026-57231, where a malicious image using malformed Env entries could cause host environment variables to leak into containers run based on the image, including the ability to use the * glob operator to leak large numbers of environment variables without knowing their exact names ( GHSA-4hq8-gpf5-8p68 ). The golang.org/x/crypto library has been updated to v0.53.0, addressing CVE-2026-39830 and CVE-2026-42508 . Bugfixes Fixed a bug where the remote Podman clie…

  • Docker Engine releases v29.6.1

    29.6.1 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: docker/cli, 29.6.1 milestone moby/moby, 29.6.1 milestone Security This release includes fixes for multiple security vulnerabilities affecting Docker Engine. A malicious image could supply a malicious /etc/passwd or /etc/group -style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions. GHSA-mjcv-p78q-w5fw , GHSA-jp…

Thu 25 Jun 2026

  • Deno releases v2.9.0

    2.9.0 / 2026.06.25 Read more: http://deno.com/blog/v2.9 feat(bundle): add --declaration flag to generate rolled-up .d.ts files ( #33838 ) feat(cli): add deno link and deno unlink subcommands ( #34359 ) feat(cli): add deno watch subcommand ( #35301 ) feat(cli): add deno list subcommand to list declared dependencies ( #34972 ) feat(cli): auto-migrate pnpm-workspace.yaml on resolution failure ( #34993 ) feat(cli): provide a node on PATH when Node.js is not installed ( #34969 ) feat(compile): persi…

  • pub.dev releases 20260625t134000-all

    Deployment at 2026-06-25T13:40:20.581204Z.

  • Homebrew releases 6.0.4

    What's Changed Cask Cookbook: document generate_completions_from_executable stanza by @bevanjkay in #22848 generate_completions: add style for default shells and auto corrections by @daeho-ro in #22841 Add bump-compatibility-version command by @p-linnane in #22846 Filter info JSON package types by @MikeMcQuaid in #22851 Enable formula path helper cop by @MikeMcQuaid in #22845 Rescue MethodDeprecatedError when attempting to load installed caskfiles by @Rylan12 in #22856 Speed up tests by @MikeMc…

  • conda-pypi beta enables conda CLI to install pure Python packages from PyPI natively and alongside conda packages in a single dependency solve, without a separate pip step

  • This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research , we explored what people love about Rust , dug into what it takes to ship safety-crticial Rust , and described some of the major challenges that people face when using Rust . In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered. As a …

Wed 24 Jun 2026

  • pipx releases 1.15.0

    What's Changed Add --dry-run flag to pipx ensurepath by @somaz94 in #1842 Fix uninject for uv-backed venvs by @sjh9714 in #1844 New Contributors @somaz94 made their first contribution in #1842 Full Changelog : 1.14.1...1.15.0

  • Podman releases v6.0.0

    Security This release addresses CVE-2026-57231, where a malicious image using malformed Env entries could cause host environment variables to leak into containers run based on the image, including the ability to use the * glob operator to leak large numbers of environment variables without knowing their exact names ( GHSA-4hq8-gpf5-8p68 ). Breaking Changes Due to breaking changes in this release, Podman v6.0.0 must be used with Buildah v1.44.0, Skopeo v1.23, Netavark and Aardvark v2.0.0, and co…

  • Dependabot Core releases v0.383.0

    What's Changed Bump bundled npm from 11.8.0 to 11.17.0 by @kbukum1 in #15335 Fix composer specs failure due to block-insecure feature by @AbhishekBhaskar in #15334 Add blocked_versions.ignored metric for Security-blocked update checks by @kbukum1 in #15333 Preserve original bundler checksum on Bundler 4.0.11+ lockfile updates by @lucasmazza in #15249 Generate .npmrc from scope property when lockfile inference fails by @AbhishekBhaskar in #15264 Revert disabling block insecure flag in composer b…

  • RubyGems Blog 4.0.15 Released

    RubyGems 4.0.15 includes enhancements and bug fixes and Bundler 4.0.15 includes enhancements and bug fixes. To update to the latest RubyGems you can run: gem update --system [--pre] To update to the latest Bundler you can run: gem install bundler [--pre] bundle update --bundler=4.0.15 RubyGems Release Notes Enhancements: Rubygems: Fix Gem::Request for PQC support, adding integration connection tests. Pull request #9615 by junaruga Reduce peak memory usage of full index loading and bundle instal…

Tue 23 Jun 2026

  • RubyGems releases bundler-v4.0.15

    Enhancements: Resolve Git LFS files in git sources from the real remote. Pull request #9632 by hsbt Suggest access issues, not only yanking, for missing locked gems. Pull request #9631 by hsbt Implement a make jobserver (continuation of #9210 ). Pull request #9625 by hsbt Reduce peak memory usage of full index loading and bundle install. Pull request #9618 by hsbt Bump up to rb-sys 0.9.128. Pull request #9569 by hsbt Bug fixes: Skip the make jobserver on Windows. Pull request #9630 by hsbt Don'…

  • RubyGems releases v4.0.15

    Enhancements: Rubygems: Fix Gem::Request for PQC support, adding integration connection tests. Pull request #9615 by junaruga Reduce peak memory usage of full index loading and bundle install. Pull request #9618 by hsbt Installs bundler 4.0.15 as a default gem. Bug fixes: Forward security policy to old-format gems. Pull request #9611 by hsbt

  • uv releases 0.11.24

    Release Notes Released on 2026-06-23. Python Add CPython 3.15.0b3 ( #19964 ) Preview features Make project environments relocatable under preview ( #19965 ) Performance Use a compact index for lazy version maps ( #19959 ) Bug fixes Allow disabling exclude-newer ( #19934 ) Avoid archive id collisions ( #19949 ) Reapply "Fix transparent Python upgrades in project environments" ( #19928 ) Clean up partial tool entrypoint installs ( #19966 ) Fix relocatable activate.fish and broaden Fish version su…

  • Docker Engine releases v29.6.0

    29.6.0 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: docker/cli, 29.6.0 milestone moby/moby, 29.6.0 milestone New POST /containers/{id}/update now supports per-device blkio resource settings. moby/moby#52651 Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image. Supports optional platform selection, predicate type filtering, and a statement quer…

  • PDM releases v2.28.0

    Features & Improvements Add experimental workspace support for managing local member projects in a shared root lock file. ( #1505 ) Defer startup-time imports for Python, virtualenv, and self-management commands. ( #3673 ) Bug Fixes Fix pdm completion bash printing __ltrim_colon_completions: command not found (and a similar error for _get_comp_words_by_ref ) when the generated script is sourced in a bash without the bash-completion package loaded, such as Git Bash on Windows or minimal Linux co…

  • pnpm Blog pnpm 11.9

    pnpm 11.9 computes missing tarball integrity for registries that cannot publish checksums, adds pnpm sbom --exclude-peers, improves audit performance on cyclic lockfiles, fixes peer-resolution nondeterminism, and tightens exclusion handling for minimumReleaseAge and trustPolicy.