Zum Inhalt springen

DevOps und Container: Release Notes

Container, Kubernetes, Proxys, CI/CD und Infrastruktur als Code. 24 Hersteller, 716 Einträge.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer

Portainer 2.45.2 LTS mit Sicherheitsfixes und neuen Node-Spalten

Portainer 2.45.2 LTS behebt mehrere Sicherheitsprobleme (Umgehung der Einstellung „Hide bind mounts for non-administrators“, vorzeitiges Entfernen von Kubernetes-Namespace-Daten bei abgelehnter Löschung, fehlende TLS-Zertifikatsprüfung bei In-Cluster-HTTPS-Verbindungen) und ergänzt in der Kubernetes-Node-Liste eine Node-group-Spalte sowie optionale Spalten für Instance type, Labels und Taints.

Known issues

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot

Known issues with Podman support

  • Podman environments aren't supported by auto-onboarding script
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
  • Support for only CentOS 9, Podman 5 rootful

Changes

Security

  • Fixed a bypass of the "Hide bind mounts for non-administrators" setting. When it is enabled, Compose files deployed by non-administrators can no longer reference host files outside the stack directory (for example in configs, secrets or env_file), and include is disabled for them.
  • Fixed a denied, failed or dry-run Kubernetes namespace deletion still removing Portainer's namespace access policies, stack records and registry bindings. These records are now removed only after Kubernetes accepts the deletion
  • Fixed in-cluster HTTPS connections to the Kubernetes API server skipping TLS certificate verification during stack deploy and removal, on both the server and the agent

Features

  • Added a Node group column to the Kubernetes cluster node list for clusters using EKS, GKE, AKS, Karpenter or kops node pools, plus optional Instance type, Labels and Taints columns that can be turned on from the column menu

Bug Fixes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Portainer Business von Portainer

Portainer Business 2.45.2 LTS mit Breaking Change

Version 2.45.2 LTS verlangt bei POST und PUT auf /api/cloud/gitcredentials nun den Parameter urlPattern (sonst Fehler 400), während bereits gespeicherte Zugangsdaten bis zur Bearbeitung weiterhin für beliebige URLs funktionieren.

October 8, 2026

Breaking Changes

  • POST and PUT /api/cloud/gitcredentials now require urlPattern: one or more comma-separated glob patterns (for example github.com/portainer/*) that a repository URL must match before the shared credential is used. * matches a single path segment; or scheme://* alone matches everything. Requests without urlPattern return 400. Credentials saved before upgrading keep working against any URL until they are edited; administrators should set a pattern on each existing shared credential

Known Issues <a href="#known-issues" id="known-issues"></a>

  • On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
  • kubectl port-forward fails with Portainer kubeconfig in some configurations

Known issues with Podman

  • Support for only CentOS 9, Podman 5 rootful
  • Auto onboarding a Podman environment defaults to “Standard” and not “Podman”
  • It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)

Known issues with Talos clusters managed by Omni (BE only)

  • Loading Omni specific information in the Cluster Details view and configuring an existing Talos cluster is currently restricted to Portainer Admins. Environment Admins will get a forbidden error when attempting to do this. This only applies to Omni configuration, and does not affect authentication for any other functionality in the cluster …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terragrunt von Gruntwork

Terragrunt v1.2.0-rc2: zweiter Release Candidate mit Fehlerbehebungen

Der zweite Release Candidate für Terragrunt v1.2 schließt dieselben elf Experimente wie rc1 ab, behebt vor allem Fehler in CAS, Catalog, Provider Cache Server und exclude-Blöcken und lässt base64gzip() nun die Ausgabe des Go-1.27-Encoders liefern.

🎉 v1.2.0 Release Candidate

This is the second release candidate for Terragrunt v1.2.

It completes the same eleven experiments as v1.2.0-rc1, and adds bug fixes found since then, most of them in the CAS, the catalog, the Provider Cache Server, and exclude blocks.

Future release candidates for v1.2.0 will include bug fixes related to these experiments or other urgent bug fixes as necessary, and documentation improvements.

Please try out this release candidate in lower environments and share your feedback in the associated GitHub discussion.

🛠️ Breaking Changes

base64gzip() uses the current Go encoder

Go 1.27 changed the compressed output of its gzip encoder. Terragrunt v1.1.5 kept base64gzip() on the older output and warned once per run that this was legacy behavior. base64gzip() now returns what the Go 1.27 encoder produces. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-rc1: Variablen in Provider-Anforderungen, Terraform Policy GA

Terraform 1.17.0-rc1 erlaubt Variablen und Locals in Provider-Anforderungen, bringt die Planungsoption -minimal-refresh, macht Terraform Policy (-policies) allgemein verfügbar, unterstützt mock_provider für Ephemeral Resources und behebt Panics bei pow und log.

1.17.0-rc1 (October 07, 2026)

NEW FEATURES:

  • Terraform now supports variables and locals in provider requirements (#39153)

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

  • policy: Terraform Policy is now generally available. The -policies flag for plan, apply, and query no longer requires an experimental build or the -allow-experimental-features flag. Query policies evaluate resources discovered by list blocks and report human-readable or JSON results. See https://developer.hashicorp.com/terraform/policy for more information. (#38970)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • test: Add mock_provider support for ephemeral resources (#38928)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pulumi

Pulumi 3.268.0: OutputValues bei Invoke und neue Automation-API-Funktionen

Pulumi 3.268.0 ermöglicht über die neue Handshake-Fähigkeit accepts_outputs_in_invoke die Übergabe von OutputValues bei Invoke, ergänzt version, whoami und install in den generierten Automation APIs für NodeJS, Python und Go und behebt Fehler unter anderem bei Assets, Resource Transforms, PCL-Typen und der NodeJS-Doku.

3.268.0 (2026-10-07)

Features

  • [engine] Negotiate OutputValues on Invoke so SDKs can pass dependency-carrying values in args and receive them in the response, and providers can process them, gated by a new accepts_outputs_in_invoke handshake capability #24953
  • [auto] Add version to the generated automation APIs for NodeJS, Python and Go #24990
  • [auto] Add whoami to the generated automation APIs for NodeJS, Python and Go #25024
  • [auto] Add install to the generated automation APIs for NodeJS, Python and Go #25038

Bug Fixes

  • [engine] Restore elided asset contents from prior state when a provider echoes assets back from refresh or update #24570
  • [engine] Apply resource transforms declared on an ancestor component to resources parented under a resource read #24689
  • [pcl] Unify two recursive object types, or a map with an object, to the same finite type on every run instead of overflowing the stack or picking a different type each time #24805
  • [sdkgen/nodejs] Link @pulumi/pulumi types in generated docs to their TypeDoc pages instead of missing anchors #24928 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Atlantis

Atlantis Version 0.48.1: Sicherheitskorrektur für Repo-Allowlist

Version 0.48.1 behebt eine Sicherheitslücke (GHSA-fwc4-2f3p-7qm7), indem das Präfix verankert wird, wenn eine Repo-Allowlist-Regel einen Platzhalter mitten im String enthält.

<!-- Release notes generated using configuration in .github/release.yml at release-0.48 -->

What's Changed

Security changes

Full Changelog: https://github.com/runatlantis/atlantis/compare/v0.48.0...v0.48.1

Thanks to @arpitjain099 for reporting and reviewing this fix, and to @pseudomorph for reviewing.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vercel AI von Vercel

ai 7.0.130: Abbruch-Signal und Refusal-Antworten

Version 7.0.130 weist ausstehende Ergebnis-Promises ab und bricht den laufenden Stream ab, wenn das Abort-Signal auslöst, und meldet abgelehnte Entscheidungen als Refusal-Antworten.

Patch Changes

  • 6f6b9c0: fix(ai): reject pending result promises and cancel the pending stream when the abort signal fires
  • d3bcad9: feat(provider): report decision refusals as refusal answers
  • Updated dependencies [d3bcad9]

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vercel AI von Vercel

ai 6.0.302: Fehlerbehebungen bei Usage, Streams und Tools

Version 6.0.302 behebt mehrere Fehler, darunter erhaltene Total-Tokens in der Raw-Usage bei V2-Providern, die Anzeige des letzten Fehlers nach wiederholten Stream-Resume-Versuchen, doppelte Schrägstriche in Chat-Reconnect-URLs und die Offenlegung gespeicherter Ausgaben durch nicht verfügbare Tools.

Patch Changes

  • 5430af1: fix(ai): preserve V2 provider-reported total tokens in raw usage
  • f8d8324: fix(ai): publish the latest error after repeated failed stream resume attempts
  • 5df41a7: fix(ai): prevent unavailable tools, including tools named after Object.prototype properties, from exposing persisted output to models
  • 6a12ead: fix(ai): avoid duplicate slashes in chat reconnect URLs
  • Updated dependencies [bedd5bb]
  • Updated dependencies [6dd6693]
  • Updated dependencies [5607cb2]
  • Updated dependencies [fca8a28]

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vercel AI von Vercel

ai 5.0.273: Schutz vor Offenlegung gespeicherter Ausgaben

Version 5.0.273 verhindert, dass nicht verfügbare oder gelöschte Tools (auch mit Namen von Object.prototype-Eigenschaften) gespeicherte Ausgaben an Modelle weitergeben, und vermeidet doppelte Schrägstriche in Chat-Reconnect-URLs.

Patch Changes

  • 223133e: fix(ai): prevent deleted tools named after Object.prototype properties from exposing persisted output to models
  • 51e2b34: fix(ai): prevent unavailable tools from exposing persisted output to models
  • 5f95b09: fix(ai): avoid duplicate slashes in chat reconnect URLs
  • Updated dependencies [4a65dd5]
  • Updated dependencies [8f63231]
  • Updated dependencies [95c921d]
  • Updated dependencies [c858a31]

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vercel AI von Vercel

@ai-sdk/xai 5.0.18: Mehr X-Handles im xSearch-Tool

Im xSearch-Tool sind nun bis zu 20 Einträge für allowedXHandles bzw. excludedXHandles erlaubt.

Patch Changes

  • fab95c1: fix(xai): allow up to 20 allowedXHandles / excludedXHandles in the xSearch tool

Originalquelle(öffnet in neuem Tab)Problem melden