Zum Hauptinhalt springen
IT Security NachrichtenSoftcat to acquire North American technology solutions provider GDT(18.09.2026 um 16:49 Uhr)
IT Security NachrichtenLocal AI is getting small enough to make every app multilingual(18.09.2026 um 16:51 Uhr)
Malware / Trojaner / VirenFake LastPass Authenticator GitHub repos push new Rapuncel infostealer(18.09.2026 um 17:19 Uhr)
Sichere ProgrammierungUbuntu 26.10 ersetzt letzte GNU-Coreutils durch Rust(18.09.2026 um 17:07 Uhr)
Sichere ProgrammierungWenn Open-Source-Pakete zur Hintertür werden(18.09.2026 um 16:00 Uhr)
Sichere ProgrammierungRust is Now a 'Tier One' Language at Microsoft(18.09.2026 um 16:34 Uhr)
IT Security NachrichtenSoftcat to acquire North American technology solutions provider GDT(18.09.2026 um 16:49 Uhr)
IT Security NachrichtenLocal AI is getting small enough to make every app multilingual(18.09.2026 um 16:51 Uhr)
Malware / Trojaner / VirenFake LastPass Authenticator GitHub repos push new Rapuncel infostealer(18.09.2026 um 17:19 Uhr)
Sichere ProgrammierungUbuntu 26.10 ersetzt letzte GNU-Coreutils durch Rust(18.09.2026 um 17:07 Uhr)
Sichere ProgrammierungWenn Open-Source-Pakete zur Hintertür werden(18.09.2026 um 16:00 Uhr)
Sichere ProgrammierungRust is Now a 'Tier One' Language at Microsoft(18.09.2026 um 16:34 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

GitHub Release: dependabot/dependabot-core v0.395.0 (07.09.2026)

dependabot/dependabot-corev0.395.007.09.2026@markhallen

What's Changed

  • fix: handle nil hash results from unavailable Python package indexes by @sachin-sandhu in #16078
  • Skip unsupported Maven wrappers instead of failing the Maven job by @kbukum1 in #16090
  • Migrate test runner to turbo_tests2 by @jeffwidman in #15991
  • Bump the dev-dependencies group across 2 directories with 5 updates by @dependabot[bot] in #16085
  • Bump the prod-dependencies group across 2 directories with 13 updates by @dependabot[bot] in #16072
  • Bump gradle in /gradle by @dependabot[bot] in #16098
  • Bump the "uv-ecosystem" group with 2 updates across multiple ecosystems by @dependabot[bot] in #16082
  • Bump OpenTelemetry.Exporter.Console from 1.15.3 to 1.18.0 by @dependabot[bot] in #16116
  • Fix gradle bumping dependency substitutions issue by @AbhishekBhaskar in #16042
  • Bump System.Security.Cryptography.Pkcs from 10.0.10 to 10.0.11 by @dependabot[bot] in #16119
  • Bump System.CommandLine from 2.0.3 to 2.0.11 by @dependabot[bot] in #16117
  • Bump System.Security.Cryptography.ProtectedData from 10.0.8 to 10.0.11 by @dependabot[bot] in #16120
  • Bump System.ComponentModel.Composition from 10.0.3 to 10.0.11 by @dependabot[bot] in #16118
  • Bump System.Text.Json from 10.0.3 to 10.0.11 by @dependabot[bot] in #16122
  • Bump System.Threading.Tasks.Dataflow from 10.0.3 to 10.0.11 by @dependabot[bot] in #16123
  • Bump xunit.runner.visualstudio from 3.1.5 to 4.0.0 by @dependabot[bot] in #16124
  • npm_and_yarn: read the last document of multi-document pnpm lockfiles in the dependency grapher by @Stanzilla in #15968
  • Bump postcss-selector-parser from 7.1.1 to 7.1.5 in /npm_and_yarn/helpers by @dependabot[bot] in #16135
  • Handle legacy npm repository arrays by @robaiken in #16147
  • Speed up NuGet CI tests by @JamieMagee in #16149
  • Speed up the common RSpec suite by @JamieMagee in #16148
  • Type npm package manager config by @JamieMagee in #16068
  • Type Bun package manager config by @JamieMagee in #16069
  • helm: fix scalar image tag updates and dropped trailing newline by @sachin-sandhu in #16152
  • Fix Maven property requirement selection by @thavaahariharangit in #16141
  • Fix Maven Wrapper regeneration hanging behind private registries by @kbukum1 in #16153
  • Bump postcss-selector-parser from 6.1.2 to 6.1.4 in /bun/helpers by @dependabot[bot] in #16137
  • Group Excon EOF errors by call site by @robaiken in #16167
  • Cargo: force --precise fallback for lockstep family updates by @kbukum1 in #16115
  • Fix grouped PR creation crash when no directory produces a change by @kbukum1 in #16172
  • Fix grouped PR refresh crash when no directory produces a change by @kbukum1 in #16171
  • Fix spurious security_update_not_possible for multi-range npm advisories by @kasperg in #15761
  • Type Julia RegistryClient helper results by @JamieMagee in #16165
  • Type Python and UV library detection metadata by @JamieMagee in #16177
  • Type UV dynamic version configuration reads by @JamieMagee in #16178
  • v0.395.0 by @dependabot-core-action-automation[bot] in #16207

New Contributors

Full Changelog: v0.394.0...v0.395.0

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
Hoch: nächster Artikel Runter: zurück / schließen
News ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick