$ git clone https://github.com/dependabot/dependabot-core.git
What's Changed
- Remove
enable_corepack_for_npm_and_yarnand preserve direct execution by - Remove
enable_private_registry_for_corepackflag and make private-registry corepack env permanent by - Nix: lock the selected revision by
- Remove allow_refresh_for_existing_pr_dependencies feature flag by
- Remove
allow_refresh_group_with_all_dependenciesand make group-refresh behavior permanent by - Remove enhanced updater error details feature flag by
- Remove
enable_exclude_paths_subdirectory_manifest_filesand make exclude-path filtering unconditional by - Add typed pyproject wire models by
- Type Python pyproject parsing by
- Type UV pyproject parsing by
- Skip interpolated Terragrunt sources by
- NuGet: fix inverted caseSensitive flag in PathHelper.GetMatchingDirectoriesUnder by
- Add typed npm registry package model by
- Classify Maven Wrapper subprocess failures for better observability by
- Bump the dev-dependencies group across 1 directory with 2 updates by
- Bump nixos/nix in /nix by
- Type npm registry package details by
- Bump gradle in /gradle by
- Bump the "uv-ecosystem" group with 2 updates across multiple ecosystems by
- docker: skip unparseable YAML files by
- Fix NuGet updated file line endings by
- Update dependency regex to support multiline requirements by
- Handle npm unpublished time metadata by
- Prefer SHA pins for GitHub Actions by
- Bump default Bazel version to 8.5.1 by
- Update SimpleCov to 1.1.1 and refresh RBIs by
- Type Bun registry package details by
- Update Parallel to 2.1.0 and refresh its RBI by
- docker: avoid missing file errors for invalid YAML by
- Report NuGet dependency directories by
- Ignore non-object npm engines metadata by
- Change default SMOKE_TEST_BRANCH back to 'main' by
- Add typed npm package manager config by
- Bump pip from 26.1.2 to 26.2.1 in /python/helpers in the pip group across 1 directory by
- Add test for Docker pre-release to stable version update by
- python: use PEP 691 for private registry metadata by
- Use the registry Last-Modified header as the only Docker cooldown date source by
- Resolve indirect dependency updates in uv.lock by
- Bump composer/composer from 2.9.5 to 2.10.2 in /composer/helpers/v2 by
- bundler: read path-dependency locations verbatim from the lockfile by
- Bump Microsoft.Build.Locator from 1.9.1 to 1.11.2 by
- Bump GuiLabs.Language.Xml from 1.2.93 to 1.2.120 by
- Align vendored NuGet assemblies with the .NET SDK by
- Bump library/golang in /go_modules by
- Bump oras-project/oras from v1.3.3 to v1.3.4 in /helm in the container-tools group across 1 directory by
- Bump library/rust in /cargo by
- Bump Microsoft.NET.Test.Sdk from 17.14.1 to 18.9.0 by
- Bump Microsoft.Extensions.Logging from 10.0.3 to 10.0.11 by
- Bump Microsoft.Extensions.FileProviders.Abstractions from 10.0.3 to 10.0.11 by
- Bump Microsoft.Extensions.FileSystemGlobbing from 10.0.3 to 10.0.11 by
- Bump cython from 3.2.9 to 3.3.0 in /python/helpers in the common group across 1 directory by
- Bump Microsoft.CodeAnalysis.CSharp from 5.0.0 to 5.9.0 by
- Bump friendsofphp/php-cs-fixer from 3.95.21 to 3.95.23 in /composer/helpers/v2 in the dev-dependencies group across 1 directory by
- Bump the all-actions group with 4 updates by
- Bump packageurl-dotnet from 2.0.0 to 2.0.1 by
- Bump OpenTelemetry and OpenTelemetry.Exporter.OpenTelemetryProtocol by
- Bump MSBuild.StructuredLogger from 2.3.17 to 2.3.246 by
- Bump Microsoft.Web.Xdt from 3.2.3 to 3.2.11 by
- v0.394.0 by @dependabot-core-action-automation[bot] in made their first contribution in made their first contribution in ↗ Original-Artikel auf github.com lesenVollständiger Original-BerichtAusführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf github.com.
Wie bewertest du diesen Beitrag?
1 Klick Feedback 122 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:
Hat Ihnen dieser Tipp / Anleitung geholfen?
Community-Analysen & Experten-Meinungen 0
Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf „ Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum 🔴 Akute Relevanz 38%
🟡 In Evaluierung 21%
🟢 Keine Auswirkung 11%
Spannende Innovation 30%
Verwandte Story-Cluster & Quellen (Vektor-KI)
3 Quellen
Using AI to Debug the Linux Kernel - BHIS - Talkin' Bout [infosec] News 2026-08-24
1 Quelle
How North Korean Hackers end up in your Network
1 Quelle
Undetected Steam Malware: Sent by Viewer
Tipp: Mit Pfeiltasten [ ← ] und [ → ] blättern
SOCIAL SHARE CARD GENERATOR