🕵️ Sicherheitslücken0patch liefert drei Jahre Support für Microsoft Office 2021 - BornCity(07.09.2026 um 00:15 Uhr)
🕵️ SicherheitslückenCVE-2026-78150 | Smart Post Plugin up to 4.0.7 on WordPress authorization(07.09.2026 um 04:49 Uhr)
🕵️ Sicherheitslücken0patch liefert drei Jahre Support für Microsoft Office 2021 - BornCity(07.09.2026 um 00:15 Uhr)
🕵️ SicherheitslückenCVE-2026-78150 | Smart Post Plugin up to 4.0.7 on WordPress authorization(07.09.2026 um 04:49 Uhr)

🪟 Windows Tipps 🕛 kürzlich 4 Min Lesezeit
0

GitHub Release: dependabot/dependabot-core v0.394.0 (31.08.2026)

↗ Quelle (GitHub · dependabot/dependabot-core)
🗣️ Stimme:
GitHub Release: dependabot/dependabot-core v0.394.0 (31.08.2026)
📑 Inhaltsübersicht
Avatar
$ git clone https://github.com/dependabot/dependabot-core.git

What's Changed



  • Remove enable_corepack_for_npm_and_yarn and preserve direct execution by

  • Remove enable_private_registry_for_corepack flag and make private-registry corepack env permanent by

  • Nix: lock the selected revision by

  • Remove allow_refresh_for_existing_pr_dependencies feature flag by

  • Remove allow_refresh_group_with_all_dependencies and make group-refresh behavior permanent by

  • Remove enhanced updater error details feature flag by

  • Remove enable_exclude_paths_subdirectory_manifest_files and make exclude-path filtering unconditional by

  • Add typed pyproject wire models by

  • Type Python pyproject parsing by

  • Type UV pyproject parsing by

  • Skip interpolated Terragrunt sources by

  • NuGet: fix inverted caseSensitive flag in PathHelper.GetMatchingDirectoriesUnder by

  • Add typed npm registry package model by

  • Classify Maven Wrapper subprocess failures for better observability by

  • Bump the dev-dependencies group across 1 directory with 2 updates by

  • Bump nixos/nix in /nix by

  • Type npm registry package details by

  • Bump gradle in /gradle by

  • Bump the "uv-ecosystem" group with 2 updates across multiple ecosystems by

  • docker: skip unparseable YAML files by

  • Fix NuGet updated file line endings by

  • Update dependency regex to support multiline requirements by

  • Handle npm unpublished time metadata by

  • Prefer SHA pins for GitHub Actions by

  • Bump default Bazel version to 8.5.1 by

  • Update SimpleCov to 1.1.1 and refresh RBIs by

  • Type Bun registry package details by

  • Update Parallel to 2.1.0 and refresh its RBI by

  • docker: avoid missing file errors for invalid YAML by

  • Report NuGet dependency directories by

  • Ignore non-object npm engines metadata by

  • Change default SMOKE_TEST_BRANCH back to 'main' by

  • Add typed npm package manager config by

  • Bump pip from 26.1.2 to 26.2.1 in /python/helpers in the pip group across 1 directory by

  • Add test for Docker pre-release to stable version update by

  • python: use PEP 691 for private registry metadata by

  • Use the registry Last-Modified header as the only Docker cooldown date source by

  • Resolve indirect dependency updates in uv.lock by @v-HaripriyaC in [bot] in in [bot] in [bot] in in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in [bot] in


New Contributors






Full Changelog: v0.393.0...v0.394.0

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 53%
🟡 In Evaluierung 25%
🟢 Keine Auswirkung 17%
Spannende Innovation 5%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Jetzt patchen! Angreifer attackieren JFrog Artifactory und machen sich zu Admins
1 Quelle
OpenAI’s new Astra model is finally here – why safety experts are worried
1 Quelle
WhatsApp-Schwachstelle: Zugriff auf Fotos bei gesperrtem Android-Handy