- pnpm 11.13 introduces pnpm change for native changeset-compatible release planning, pnpm team for registry management, and versioning.epics config for version band alignment.
- Deno 2.9.3 adds flags like --no-save, --save-optional, and --min-dep-age.
- pixi 0.73.0 supports workspace = true in environment dependency tables, allowing centralized version declaration.
- uv 0.11.29 adds JSON output to uv tree and prefers local artifacts over URLs in pylock.toml.
- Verdaccio 6.8.0 fires notification webhooks on unpublish and single-version removal, with improved security by exposing only limited user info.
- zizmor 1.27 adds experimental support for auditing GitHub’s parallel steps pattern.
- Rust 1.97.1 is a point release backporting an LLVM fix for a miscompilation issue.
- Homebrew 6.0.11 merges brew vulns for built-in CVE scanning of installed formulae.
- Docker Engine 29.6.2 fixes three CVEs related to git source checkout, BuildKit panic, and LLB file operation.
- sbt 1.12.14 backports a fix for CVE-2026-26032 in Apache Ivy PackagerResolver.
- Articles cover crates.io updates (Code tab, GitHub login separation, Svelte migration), Composer/Packagist supply-chain stress, and AI security engineering at Rust Foundation.
- Papers discuss software supply chain regeneration using generative AI, weaponizing setup instructions against AI coding agents, and modeling the distributed open-source vulnerability ecosystem.
- Forgejo 16.0 adds per-repository watch options, authorized integrations, and multi-line review comments.
- Ruby 4.0.6 is a routine bugfix release.