❌

Normale weergave

Stable Channel Update for Desktop

29 September 2026 om 23:18

The Stable channel has been updated to 154.0.8037.92/.93 for Windows and Mac and 154.0.8037.92 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 32 security fixes. Please see the Chrome Security Page for more information.

[TBD][551673541] Critical CVE-2026-102331: Buffer overflow in ANGLE. Reported by @mfx on 2026-08-24
[N/A][517312707] High CVE-2026-102317: Improper privilege management in Mojo. Reported by Google on 2026-05-28
[TBD][551668264] High CVE-2026-102312: UI misrepresentation in Omnibox. Reported by jodyritonga on 2026-08-24
[N/A][556789073] High CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google on 2026-09-03
[TBD][556908674] High CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni on 2026-09-04
[N/A][556926296] High CVE-2026-102306: Use after free in Bluetooth. Reported by Google on 2026-09-04
[N/A][556959073] High CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google on 2026-09-04
[TBD][559266114] High CVE-2026-102323: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-10
[N/A][559727039] High CVE-2026-102303: Uninitialized resource in GPU. Reported by Google on 2026-09-10
[N/A][559737160] High CVE-2026-102311: Uninitialized resource in GPU. Reported by Google on 2026-09-10
[TBD][560062638] High CVE-2026-102300: Uninitialized resource in WebGPU. Reported by Arni Hardarson (Neonix Security) on 2026-09-11
[TBD][560233248] High CVE-2026-102326: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-11
[TBD][560238698] High CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge on 2026-09-11
[TBD][560251736] High CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge on 2026-09-11
[TBD][560536732] High CVE-2026-102328: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[TBD][560867085] High CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey on 2026-09-13
[N/A][561994362] High CVE-2026-102325: Uninitialized resource in Skia. Reported by Google on 2026-09-15
[N/A][561997480] High CVE-2026-102308: Use after free in Views. Reported by Google on 2026-09-15
[N/A][562004351] High CVE-2026-102301: Out of bounds write in GPU. Reported by Google on 2026-09-15
[N/A][562042411] High CVE-2026-102319: Uninitialized resource in GPU. Reported by Google on 2026-09-15
[TBD][562174487] High CVE-2026-102324: Use after free in PictureInPicture. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-15
[N/A][562279351] High CVE-2026-102318: Out of bounds read in WebGL. Reported by Google on 2026-09-16
[TBD][563297615] High CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec on 2026-09-18
[N/A][563351482] High CVE-2026-102315: Uninitialized resource in Media. Reported by Google on 2026-09-18
[N/A][563716534] High CVE-2026-102302: Buffer overflow in V8. Reported by Google on 2026-09-19
[TBD][565328105] High CVE-2026-102321: Type confusion in V8. Reported by Taisic Yun (@taisic_) of Theori, with Xint on 2026-09-23
[TBD][554038924] Medium CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous on 2026-08-28
[$1,000][477726837] Low CVE-2026-102310: Missing authorization in Payments. Reported by Autodidact on 2026-01-22
[N/A][496212975] Low CVE-2026-102327: Incorrect authorization in WebView. Reported by Google on 2026-03-25
[N/A][498793976] Low CVE-2026-102330: Incorrect authorization in SiteIsolation. Reported by Google on 2026-04-02
[N/A][514059780] Low CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google on 2026-05-17
[N/A][533021953] Low CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google on 2026-07-09

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome
  •  

Extended Stable Update for Desktop

29 September 2026 om 20:38

The Extended Stable channel has been updated to 152.0.7977.149Β for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  

Release 2026.09.29

29 September 2026 om 19:26

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.29

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.29

Changes

  • fix: apply the connect-time address guard to playlist/channel metadata files (a389660)

  •  

BookStack v26.09.1

29 September 2026 om 16:24

Links

Full List of Changes

This release contains the following fixes and changes:

  • Updated audit log to use the configured display timezone. Thanks to @assyrus-favolo. (#6170)
  • Updated translations with latest changes from Crowdin. (#6229)
  • Updated ZIP import handling to verify the actual uncompressed size before extraction.
  • Updated PHP package versions.
  • Fixed page permissions not being regenerated on chapter promotion. (#6226)
  • Fixed API attachment list endpoint showing attachments for pages in the recycle bin. (#6194)

Thanks to ma4ter (GitHub) for responsibly reporting the ZIP import scenario.

  •  

Minecraft 26.4-snapshot-2 (snapshot) Released

29 September 2026 om 13:32
26.4 Snapshot 2 (known as 26.4-snapshot-2 in the launcher) is the second snapshot for Java Edition 26.4, released on September 29, 2026, which fixes bugs, brings changes to render distance fog and redesigns the debug screen. Full changelog: https://minecraft.wiki/Java_Edition_26.4-snapshot-2
  •  

Firefox 157.0

29 September 2026 om 16:10

New

  • Screenshot of Firefox visual refresh

    Firefox's biggest visual refresh in years is now available, with a modernized look across the browser toolbars, sidebar, menus and individual features, built with our updated design system. It also includes:

    • New built-in themes with light and dark versions, to personalize the look of Firefox in one click.
    • A new compact mode that reduces toolbar and tab spacing to leave more room for web content, useful on smaller screens and in split-screen layouts.
  • WebRTC video calls can now use hardware AV1 decoding on devices that support it, instead of always decoding AV1 video in software.

  • Firefox now shows a warning in the site information panel (the shield icon in the address bar) and in Settings when it has been set up to record its encryption keys, which could let other software on the computer read encrypted web traffic.
    Screenshot of TLS interception UI

  • Firefox Suggest now offers suggestions in the address bar in Austria, Belgium, Czech Republic, Denmark, Finland, Hungary, Ireland, Luxembourg, Netherlands, Norway, Poland, Portugal, Slovakia, Spain, Sweden, and Switzerland. They can be controlled in the Firefox Suggest settings. Learn more.

Fixed

  • Fixed video from phones and tablets appearing sideways or upside down in WebRTC calls.

  • Fixed the address bar searching for the typed text instead of opening the selected suggestion when a page was still loading, such as shortly after Firefox started.

  • Fixed some HDR videos encoded in 8-bit color formats looking dull and gray on Windows instead of displaying in HDR.

  • Improved audio and video synchronization when repeatedly changing the playback speed of videos, for example on YouTube.

  • Fixed the Vertical Tabs sidebar not reappearing when the cursor moves to the edge of the screen in full screen mode.

  • Fixed an issue on Windows where making a video full screen would leave the Windows taskbar showing over the video.

  • Various security fixes.

Changed

  • Pressing Tab now moves focus straight to the text field of the address bar and search bar instead of stopping on the search engine button first. The button can still be reached with Shift+Tab.

  • Amazon is no longer included as a built-in search engine. It can still be added as a custom search engine in the search settings. Learn more.

  • The updated sidebar is now enabled for everyone. Anyone still using the previous sidebar will keep a similar layout, with the panel switcher at the top of the sidebar. Additionally, the β€œShow sidebar” option has been removed from Settings.

    While we continue to refine the new design, the previous sidebar version can still be restored by setting sidebar.revamp to false in about:config. This also turns off vertical tabs. The preference will remain available until the end of 2027.

  • Web page alert(), confirm() and prompt() dialogs, the color and date pickers, and form autocomplete drop-downs now match the page's light or dark color scheme.

Enterprise

Developer

Web Platform

  • Firefox now supports the at-rule() function for @supports. This allows authors to detect browser support for specific at-rules, such as @supports at-rule(@scope).

  • Firefox now supports the chain value for the CSS overscroll-behavior property.

Community Contributions

  •  

v0.20.0-rc.7

29 September 2026 om 13:54

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix: restore code block legibility and text crispness (#5539) by @Jocs in #5553
  • test: fold the two #5539 specs into one by @Jocs in #5557
  • fix(muya): keep a hard line break's glyph on the line it ends (#2094) by @Jocs in #5556
  • revert: keep grayscale antialiasing on editor text (#5539) by @Jocs in #5558
  • fix(muya): keep sequence diagram arrowheads in exported PDFs (#2423) by @Jocs in #5561
  • fix(muya): pair emphasis delimiters the way CommonMark does (#2086) by @Jocs in #5555
  • fix(muya): parse link destinations the way CommonMark does (#2377) by @Jocs in #5562
  • Add a zoom/pan viewer and image export for rendered diagrams by @Jocs in #5554
  • fix: give the editor and Preferences windows their own menu bar (#2245) by @Jocs in #5560
  • perf(muya): re-render only the two affected blocks when stepping through search (#5580) by @ycyc0421 in #5569

New Contributors

Full Changelog: v0.20.0-rc.6...v0.20.0-rc.7

  •  

Road Trip: Ford DLC Release

Door: Petr
29 September 2026 om 10:00

We are super excited that the day many of you have been waiting for has finally arrived. Today, you can get ready to drive a new set of vehicles with the release of the Road Trip: Ford DLC for American Truck Simulator!

The Road Trip: Ford DLC is now released and available on Steam!


We first announced project Road Trip in April last year, and since then, it has been eagerly awaited by our #BestCommunityEver. A dedicated team was formed to bring this brand-new experience to American Truck Simulator, working closely with our vehicle team, programmers, testers, and many other colleagues across the company. The Ford DLC is the first release from the Road Trip project, and we're incredibly happy to finally bring it to our community!

Now, you can hit the open roads of American Truck Simulator like never before with this DLC as you take the wheel of:

  • The iconic 1967 Ford Mustang Fastback
  • The all-purpose 2023 Ford F-150
  • The modern 2023 Ford Bronco
  • and the legendary 1998–2012 Ford Crown Victoria

With the Road Trip: Ford DLC, you will unlock Car Mode, its related features, and all of these personal cars, which you can take out on the road and experience American Truck Simulator from a whole new perspective. Customise your vehicles with a variety of accessories and paint options, then hit the road and explore at your own pace.

Looking for something to do along the way? Take on smaller deliveries through Quick Jobs or the Dispatch Market and build your courier reputation, or discover the world around you with the new Atlas feature. Visit iconic locations, learn more about them, and collect beautifully designed postcards as you explore.

At release, the Atlas feature and its Tourist Boards will be available in California, and in the Oregon, Washington, Idaho, Montana, Wyoming, and South Dakota DLCs. The remaining states will be gradually included in future updates.

Step away from your big rig and get behind the wheel of iconic Ford vehicles, a fresh way to explore the world of American Truck Simulator. You can also team up with your friends in Convoy mode and hit the road together, with trucks and cars sharing the highways! And don't forget that if you own this DLC, you can also enjoy the Atlas feature from behind the wheel of a truck.

We're happy to have partnered with Ford to bring these iconic vehicles to life in American Truck Simulator, and we would like to thank them very much for their cooperation in making this possible.Β 

But now, it's all up to you - we can't wait to see where your next road trip takes you!

Release Live Stream

As we always do with our map expansions, we also plan to introduce the new Road Trip: Ford DLC to our community with a special release stream! Starting today at 3 pm CEST, we'll be joined by guests who worked on the DLC's development, chatting with them about the process while taking Ford cars out on the roads of American Truck Simulator. And at the end of the stream, we'll officially release the DLC together with you!

Make sure to share photos or videos from your road trip journeys with us on social media by tagging us onΒ X/Twitter, Facebook, BlueSky, and Instagram. For more news from American Truck Simulator and further Road Trip development, don't forget toΒ subscribe to our newsletter or follow us on our social media accounts. We will see you on the road!

  •  

hMailServer 5.7.1, build 3116

29 September 2026 om 08:55

Security:

  • Fixed script injection in event scripts. With JScript, untrusted values passed to event handlers (such as the logon password in OnClientValidatePassword, or error text and UIDs sent by remote servers) could break out of their string. With either script language, a rule's "Run function" name could carry code. This would allow an attacker to run arbitrary code in the hMailServer process. Values are now escaped, and rule function names may only contain letters, digits and underscores.

If you are unable to install this version, disable JScript execution and do not give end-users access to the hMailServer COM API.

  •  

Part-DB 2.19.2

Door: jbtronics
29 September 2026 om 01:01

Note

If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8

Part-DB 2.19.2

Bug fix

  • Fixed step 3D model viewer colors when one part contains multiple colors

Various changes

  • Update KiCad symbols and footprints lists by @jbtronics in #1562
  • Updated translations
  • Updated dependencies

Full Changelog: v2.19.1...v2.19.2

  •  

Counter-Strike 2 Update

29 September 2026 om 00:38
[p]\[ MISC ][/p]
  • [p]Fixed pixel-gaps in various Rush rooms.[/p][/*]
  • [p]Clipping adjustments in T/CT Castle rooms.[/p][/*]
  •  

Distribution Release: EmmabuntΓΌs DE6-1.03

28 September 2026 om 22:01
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The EmmabuntΓΌs project has published a new update with a focus on improving accessibility options and features. "Our goal was to preserve the spirit of this approach: making accessibility features immediately available without requiring users to memorize numerous keyboard shortcuts. Easy Menu: one key for simple access to....
  •  

Shoutout to More Layouts – These Weeks in Firefox: Issue 210

28 September 2026 om 21:31

Highlights

  • RΓ©v O’Conner added a settings popup to control the layout of the Inspector. β€œAuto” automatically switches the layout at a given toolbox width.
    • Firefox Developer Tools Inspector showing a layout menu with options β€œAuto,” β€œSide by side,” and β€œStacked.” β€œSide by side” is selected, displaying the HTML markup tree on the left and the CSS Rules panel on the right.
  • The new sidebar (sidebar.revamp) and switcher setting will be enabled by default for users along with Nova in DevEdition, Beta and Release channels. To ease the transition for old sidebar users, the β€œOpen tools from sidebar” option will be unchecked for those users to more closely resemble the old sidebar experience. The migration won’t apply to users who had already tried the new sidebar and reverted back.
  • The custom wallpaper library for the New Tab page is coming along! This allows you to save multiple images to your wallpaper folder, rather than replacing one image at a time. While it’s still in development, you can test it by setting browser.newtabpage.activity-stream.newtabWallpapers.customWallpaper.library.enabled to true, starting in Firefox 157.
    • Firefox New Tab's β€œYour images” customization subpanel showing two uploaded image thumbnails: a city street with a red streetcar and a hummingbird perched on a branch. The first image is selected with a purple outline. A dashed β€œAdd an image” tile with a plus button appears beside them.
  • Mark added an MDN search engine for Nightly and Developer Edition. Select it from the menus, or type @mdn <search term>.
    • Firefox address bar with @mdn typed and highlighted. A suggestion below reads β€œ@mdn – Search with MDN,” demonstrating the MDN search shortcut.
    • Firefox address bar using the MDN search shortcut with β€œmarquee” typed. The suggestion dropdown includes β€œSearch with MDN” and MDN results for the HTML element, the ARIA marquee role, and HTMLMarqueeElement.

Friends of the Firefox team

Resolved bugs (excluding employees)

Script to find new contributors from bug list

Volunteers that fixed more than one bug

  • :Benjamin Peterson
  • Amadi
  • any1here
  • Caleb Pickard
  • Chris Vander Linden
  • Gopalarathnam Venkatesan
  • Igor [:ExplodingJoysticks]
  • Khalid AlHaddad
  • LukΓ‘Ε‘ LipinskΓ½
  • Mayank Bansal
  • Nazeer Ahmed Shaikh
  • Noah Varghese
  • Sameem [:sameembaba]
  • Sebastian Zartner [:sebo]
  • sfshah
  • Xiaosen Zhuang

New contributors (🌟 = first patch)

Project Updates

Add-ons / Web Extensions

Addon Manager & about:addons
  • As part of Project Nova related work:
    • Fixed responsive layout issues that caused horizontal scrolling in about:addons at high zoom levels – Bug 2059864
    • Fixed the β€œDiscover extensions” button appearing multiple times in about:addons – Bug 2070281
    • Added telemetry for theme-picker shown events and for appearance/native-theme changes in about:addons – Bug 2069417 / Bug 2070341
    • Added an accessible name to the themes mode control in about:addons, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel – Bug 2064563
      • Thanks to Mark Kennedy for the help on fixing this accessibility gap
    • Updated the built-in dark and light theme previews to use the nova style – Bug 2070274
      • Thanks to Emilio Cobos Álvarez for the fix to the default light and dark theme previews.
    • Fixed the Nova default and AMO curated theme previews to follow the OS light/dark mode while ignoring the Website appearance setting, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel – Bug 2070562
  • Stopped setting unused taarId session cookies for AMO on startup – Bug 1871561
    • Thanks to Manuel Bucher for helping us to clean up these unused internals.
WebExtension APIs
  • Fixed webRequest requestBody parsing so POST form fields named __proto__ are no longer dropped – Bug 2061470
  • Changed alarms.clearAll() to resolve with undefined instead of a boolean, starting in Firefox 157 – Bug 2067229
    • Thanks to Ollie Hensman-Crook for the fix to the alarms API.
  • Implemented native messaging support via xdg-native-messaging-proxy for Flatpak and Snap builds – Bug 1955255
    • Thanks to Jan Horak for the native messaging work on Linux packaging.
  • As part of Florian QuΓ¨ze effort to investigate and fix intermittent failures:
    • Made windows.update() wait for the window to actually resize or move before resolving, fixing an intermittent Linux test failure – Bug 1307759
    • Fixed a pageAction popup incorrectly opening via a commands API shortcut while the extension was already shutting down – Bug 2039637
    • Fixed action.openPopup() rejecting when a tab hover preview was showing, a regression from Bug 2022281 in Firefox 150, with the fix shipping in Firefox 157 and no uplift planned – Bug 2062229

DevTools

  • The team has a few sizable ongoing projects.
    • Bomsy is working on moving Stylesheets to the Debugger so we can retire the (XUL-based) Style Editor, and turn the Debugger into a β€œSources” panel (keeping all the existing functionality of course).Β  (pref: devtools.debugger.features.stylesheets-in-debugger)
    • Alex is investigating ways to better handle CSS authored text and CSSOM changes in the Inspector, building information directly from the Rust CSS engine, with the hope it will bring performance improvement editing styles in the Rules view.
    • Nicolas is implementing a way to show to the user how the engine goes from a CSS declaration value to the computed value so it’s easier to follow what’s the result of the different call sites, or how the different units (em, %, vmin, …) are computed to their final (e.g. px) values. Β  (pref: devtools.inspector.css-explainers)
External contributions
  • Chris Vander Linden finalized a multi-months project to add a search toolbar in the Netmonitor Raw Response panel, adapting and reusing the component we are using in the Debugger (#1941575)
    • Firefox Developer Tools Network panel showing the Response tab for an HTML request with a new find bar. The response source contains several elements, with matches for β€œscript” highlighted in yellow. The find bar at the bottom shows the search term β€œscript” and indicates β€œ1 of 9 results.”
  • Amadi made the β€œOpen in new tab” context menu entry to open tab next to the selected tab, not at the very end of the tab list (#2059979)
  • Mayank Bansal optimized the performance of console.clear() (#2068156, #2068157, #2067000)
  • Benoit added JSON Lines (JSONL/NDJSON) support in the Netmonitor Response panel (#2059673)
  • Gopalarathnam Venkatesan made the β€œAdd class” button (.cls) to be disabled when a class can’t be added to the selected node (e.g. it’s a text node, or a comment, or the doctype node) (#2000150)
  • K fixed an issue with the β€œGo to line” action in the Debugger (#2064575)
  • Samuel Mbabhazi refactored our CSS codebase to use new color syntax (e.g. rgb(255 0 0) instead of rgb(255, 0, 0)) (#2054228)
  • sfshah turned devtools/client/jsonview/converter-child.js into an ES class (#2004273)
Team/Project Update

WebDriver

Fluent

Lint, Docs and Workflow

  • According to arewemozsrcyet.com, ~59% of our modules are now using moz-src.
  • eslint-plugin-mozilla has switched from using Mocha to Jest for tests.
    • Planning on future updates to investigate getting devtools & newtab to use the jest installed at the top-level, rather than separately installed copies.

Information Management/Sidebar

  • We’re working away on bug fixes for sidebar, vertical tabs, split-view, and Nova
  • Thanks Florian (:fqueze) for landing a set of patches that have markedly reduced test flakiness in the Sidebar component

New Tab Page

Picture-in-Picture

Search and Urlbar

Address Bar
  • Dao and Moritz are working on bringing the full urlbar experience into the newtab page, now enabled on nightly and going through polish and improvements.. (Bug 2068104, Bug 2068633, Bug 2069260, Bug 2064747)
  • Drew enabled AMP and Wikipedia by default in AT, BE, CH, ES, IE, LU, NL, PL, PT and SE. (Bug 2066294)
  • James gated adaptive autofill page results behind a minimum score threshold. (Bug 2066171)
  • any1here stopped disabled Manage AI and Labs quick actions being displayed when disabled. (Bug 2070378)
Search
  • Dale landed the Recent Searches widget which will be be used launched as an experiment (Bug 2063718)
    • The Firefox newtab search widget showing the "Recent searches" tab selected next to a "Trending" tab. Five recent search queries are listed, each with a history icon, including β€œback doune the rabbit hol…,” β€œisthismusic back doune,” β€œwrexham shirt sponsor,” β€œwalt disco album,” and β€œmoz-src.”
  • Caleb fixed the search box eating the first character typed into it. (Bug 1953361)
  • Mark configured Wikipedia search for Sardinian (sc) to use the Sardinian Wikipedia rather than the Italian one. (Bug 2057690)
Places
  • Marco fixed bookmarked Google Maps using Google’s default favicon. (Bug 1575809)
  • Marco fixed the Downloads and History windows going full-screen instead of floating on macOS. (Bug 2058062)

Tests

  •  

Legacy releases

28 September 2026 om 20:32

Archived hMailServer builds, from 4.1.1 to 5.6.9 build 2607. These versions are no longer supported and are kept for reference only. Use the latest release for new installations.

  •  

Release 2026.09.28

28 September 2026 om 19:22

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.28

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.28

Changes

  • fix: confine playlist/channel metadata files to the download directory (098cba4)
  • fix: also prompt in ask mode when only chapter files remain on disk (b2b4908)
  • feat: add an ask mode to DELETE_FILE_ON_TRASHCAN that prompts before deleting files (closes #1012) (52638fa)

  •  

v8.3.1

28 September 2026 om 13:43

SECURITY

  • This release addresses vulnerabilities ranging from medium to critical severity affecting PeerTube. In a week, this changelog will be updated to disclose the vulnerabilities.

Bug fixes

  • Force video encoding if there are rotation info
  • Fix broken studio on only intro/outro/cut task
  • Fix broken sorts/invalid sort checkers for channel syncs and ownership changes
  • Fix downloading a download-protected video for admins
  • Fix broken email title in some emails
  • Fix broken notification window if the list contains a broken change ownership notification
  • Fix table pagination after a search
  • Include muted muted videos when admins/moderators display all videos of an account/channel

  •  

Development Release: openSUSE 16.1 RC

28 September 2026 om 11:59
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The openSUSE project has published a new release candidate for the upcoming Leap 16.1 release. Among the various changes is a new immutable mode for Leap: "Leap 16.1 is the first Leap release to offer an Immutable Mode, a transactionally updated system with a read-only root filesystem. This....
  •  

v1.18.33

28 September 2026 om 06:22

Core

Bugfixes

  • Cloudflare AI Gateway models now honor provider response and stream timeouts. (@danlapid)
  • MCP browser launch failures are now reported when the launcher exits immediately.
  • Debug configuration output now redacts credentials and sensitive headers.
  • Gemini thinking defaults and effort options now match the supported controls across model generations. (@markmcd)

Thank you to 5 community contributors:

  • @dc85:
    • docs(web): add Claude Opus 5.5, GPT 6 Sol, and GPT 6 Luna to Zen (#50708)
  • @vglafirov:
    • maint(gitlab): bump gitlab-ai-provider to 6.16.0 (#50742)
  • @markmcd:
    • fix(gemini): switch thinking default logic (#50841)
  • @remorses:
    • docs(web): link kimaki to product website (#49735)
  • @danlapid:
    • fix(opencode): apply provider timeouts to Cloudflare AI Gateway models (#51549)

  •  

DistroWatch Weekly, Issue 1192

28 September 2026 om 02:13
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: ReactOS 0.4.16
News: Garuda offers NixOS-based edition, KDE turns 30, NetBSD polishes Enlightenment port, Q4OS offers Breeze theme for Trinity, Canonical speeds up kernel patches, postmarketOS becomes Nura
Questions and answers: Identifying the video card
Released last week: Univention Corporate Server 5.2-7, NetBSD 10.2
Torrent corner:....
  •  

Version 2.19.0

Door: jbtronics
27 September 2026 om 23:39

Note

If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8

Part-DB 2.19.0

New features

  • Added 3D model viewer, with support of STL, 3MF, OBJ, STEP, and more
image
  • Improved builtin footprint gallery viewer
image
  • Support to add custom "builtin footprints"
  • Added additional footprint images based on KiCad 3D models. You can download them with php bin/console partdb:attachments:download-footprint-images

Improvements

  • Optimized performance of part table views

Bugfixes

  • Fix remembered tabs hiding validation errors by @LMatt08 in #1559

Various changes

  • Updated dependencies
  • Updated KiCad symbols and footprints
  • Updated translations

New Contributors

Full Changelog: v2.18.0...v2.19.0

  •  

Release 2026.09.27

27 September 2026 om 18:50

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.27

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.27

Changes

  • feat: pair the video password with presets, give custom yt-dlp options a full row (345b8ae)
  • feat: add per-download video password for protected videos (closes #670) (080dcea)
  • ci: install corepack instead of relying on the copy bundled with Node (47553e8)
  • build: ship Python 3.14 in the image (be1d349)
  • build: move the frontend to pnpm 12 (2ffb718)
  • fix: let a cancel's SIGINT actually stop the download (c86f351)
  • ci: sync the Docker Hub description with a maintained action (aecd86d)

  •  

v0.16.24

27 September 2026 om 20:28

[0.16.24] - 2026-09-27

If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.

Added

  • DNS: PowerDNS Authoritative provider for automatic DNS record management.

Changed

Fixed

  • Troubleshoot tool: TLSA records are looked up for every MX host, including hosts whose zone is not DNSSEC signed.
  • Spam filter:
    • OpenPhish and PhishTank entries containing uppercase characters never match, since message URLs are lowercased while HTTP lookup entries keep their original case. HTTP lookups now match keys case-insensitively.
    • URL shortener links are followed using the lowercased URL, so case-sensitive short links resolve to the wrong destination or not at all.
    • Incremental training never advances its position past the first run, so every retained sample added since then is trained again, and counted again in the reservoir, on each run until it expires.
    • Updating the rules only adds new objects, so upstream changes to existing rules, DNSBL servers, HTTP lookups, lookup keys and file extensions never reach an existing installation.
    • Updating the rules reports success when objects fail to import, or when a configuration error stops the updated settings from being activated.
  • JMAP:
    • A PushSubscription created within the verification rate limit window of another one on the same account never receives its PushVerification, since the blocked verification is dropped instead of being sent once the window expires.
    • A push notification retried after a failed delivery can report an older state than a change queued during the failed attempt, since the older state changes are merged last and overwrite the newer ones.
    • Changes made while a push request is in flight are not delivered until the next change reaches the same subscription, since a successful delivery cancels the pending retry.
    • The VAPID aud claim is derived from a hand-written parse of the push URL, so a crafted push URL can make the server sign a token for a push service other than the one the request is sent to.
    • Email/import rejects a blobId that refers to a Blob/upload creation id in the same request ("#u0") with Invalid blob id..
    • Email/set with a full mailboxIds object identical to the current mailboxes, together with a keyword change, stores the message with IMAP UID 0, so IMAP clients stop seeing it.
  • MTA:
    • A node without the outboundMta role stops replying to DATA and to JMAP submissions once about 1024 messages have been queued on it.
    • MX records are resolved through the DNSSEC-validating resolver even when DANE is disabled.
    • A DATA stage Sieve script does not see headers added by milters or MTA hooks, and discards every milter and MTA hook change when it edits the message.
  • MySQL: Range deletions and search index removals start with a single unbounded DELETE and switch to chunks only after a timeout.
  • IMAP: COPY and MOVE fail with NO [CONTACTADMIN] when another session changes the same message at the same time.
  • Autodiscover: Implicit TLS ports (993, 995, 465) are advertised with <Encryption>TLS</Encryption>, which Outlook reads as STARTTLS.
  • HTTP: Idle keep-alive connections are never closed.

Check binary attestation here

  •  
❌