Normale weergave
-
QNAP
- [Aankondiging] QNAP ID wordt officieel hernoemd naar "QNAP-account": Diensten en instellingen blijven ongewijzigd
Counter-Strike 2 Update
- [p]Updated the map selection process to give players more opportunities to play maps they've been learning.[/p][/*]
- [p]Map selection process:[/p]
- [p]Team 1 picks one map[/p][/*]
- [p]Team 2 picks two maps[/p][/*]
- [p]Team 1 picks a final map.Β [/p][/*]
- [p]One of the four maps will be randomly selected and the match will begin.[/p][/*]
- [p]Rush is a fast-paced queued 3v3 game mode.Β [/p][/*]
- [p]Players battle through a series of battle arenas to reach the opponent's castle and win the match.[/p][/*]
- [p]Battle arenas are randomly selected for each match, so no two matches are the same.[/p][/*]
- [p]Control the tower when you eliminate the enemy team (or time expires) to win the round.[/p][/*]
- [p]Players can now reload silently (but slowly) by pressing and holding the reload key.[/p][/*]
- [p]Un-scoping a sniper weapon no longer produces a sound.[/p][/*]
- [p]Globally increased visual clarity and improved fidelity of bullet impact decals.[/p][/*]
- [p]ammo_grenade_limit_total setting now also enforces the total number of grenades a player is allowed to purchase in a round.[/p][/*]
- [p]Chickens now take damage from the Zeus x27.
[/p][/*]
- [p]Crosshairs have been updated to be resolution independent.[/p]
- [p]A new "Crosshair/Scopes" tab is available in the Settings menu, and includes updated crosshair settings.[/p][/*]
- [p]Added new crosshair styles[/p][/*]
- [p]Updated the default crosshair to "Dynamic Quad," which better represents weapon accuracy.[/p][/*]
- [p]Updated engine code to the latest version of Source 2.[/p][/*]
- [p]Fixed holes in world in Long A Main Hall.[/p][/*]
- [p]Adjusted door geometry and grenade clipping inside Jaguar.[/p][/*]
- [p]Some gap fixes and clipping adjustments around the blue doors in Mid.[/p][/*]
- [p]Reinforced scaffolding by balcony in A site.[/p][/*]
- [p]Blocked pixel gap in crates on bombsite A.[/p][/*]
- [p]Added ability to set a "Clan Tag" for players who are members of Steam Community Groups. You can adjust your Clan Tag from your Player Profile.[/p][/*]
- [p]Added support for applying stickers to C4.[/p][/*]
- [p]The Starjunk 95, Industrial Sunset Memories Music Kit is now available for purchase in standard and StatTrak versions through the STORE tab.[/p][/*]
- [p]Halftime scoreboard stats should now fully reflect the results of the previous round.[/p][/*]
- [p]Fixed a case where players could avoid a kick ban.[/p][/*]
- [p]Players can now adjust music volume per game-mode.[/p][/*]
- [p]Added "minimap_volume" entity which enables a custom minimap image when a player is within the volume.[/p][/*]
- [p]Added "sky_camera_volume" and "sky_camera_volume_target", which enable custom location-specific skybox rendering.[/p][/*]
- [p]Added "point_deathcam_bounds" entity that constrains the player death camera.[/p][/*]
- [p]Added "env_shake_volume" entity that allows camera shake only within a specified volume.[/p][/*]
- [p]Added CSRadarPoint entity.[/p][/*]
- [p]Added CSObservablePoint entity.[/p][/*]
- [p]Added AddTeamMoney API method.[/p][/*]
- [p]Added OnPlayerTeamChanged callback.[/p][/*]
- [p]SetDialogVariableString now accepts a localization string.[/p][/*]
Extended Stable Update for Desktop
The Extended Stable channel has been updated to 152.0.7977.140Β for Windows and Mac which will roll out over the coming days/weeks.
Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 154 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.
Chrome 154.0.8037.57 (Linux)Β 154.0.8037.57/.58Β Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 154.
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but havenβt yet fixed.
This update includes 108 security fixes. Please see the Chrome Security Page for more information.
[$5,000][551573368] Critical CVE-2026-95350: Buffer overflow in ANGLE. Reported by Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR Labs SG Pte. LTd. on 2026-08-24
[$2,500][530045332] Critical CVE-2026-95357: Out of bounds write in GPU. Reported by Anymous on 2026-07-01
[TBD][548585299] Critical CVE-2026-95339: Use after free in ServiceWorker. Reported by Andrew Boni on 2026-08-18
[TBD][551708184] Critical CVE-2026-95281: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. on 2026-08-24
[TBD][552665794] Critical CVE-2026-95313: Use after free in Fullscreen. Reported by WinD39 - Huynh Dinh Vu on 2026-08-26
[N/A][553172761] Critical CVE-2026-95349: Buffer overflow in WebGL. Reported by Google on 2026-08-27
[TBD][556435507] Critical CVE-2026-95284: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan (STARLABS SG) on 2026-09-03
[TBD][556576992] Critical CVE-2026-95322: Out of bounds write in GPU. Reported by David Sievers (@loknop) on 2026-09-03
[N/A][559320837] Critical CVE-2026-95329: Out of bounds write in WebGL. Reported by Google on 2026-09-09
[TBD][560439699] Critical CVE-2026-95356: Use after free in WindowDialog. Reported by Xinyang Ge on 2026-09-12
[TBD][562151598] Critical CVE-2026-95310: Use after free in AdFilter. Reported by Xinyang Ge on 2026-09-16
[$5,000][540265100] High CVE-2026-95301: Missing authorization in Extensions. Reported by OGINOME Tomohito on 2026-07-29
[$5,000][543471693] High CVE-2026-95291: UI misrepresentation in SecurityIndicators. Reported by NH DEV on 2026-08-07
[N/A][508462481] High CVE-2026-95355: Incorrect authorization in Navigation. Reported by Google on 2026-05-01
[N/A][517661385] High CVE-2026-95315: Use after free in Aura. Reported by Google on 2026-05-29
[N/A][520516206] High CVE-2026-95298: Use after free in Browser. Reported by Google on 2026-06-05
[N/A][534997484] High CVE-2026-95372: Use after free in Chromecast. Reported by Google on 2026-07-15
[N/A][537857253] High CVE-2026-95324: Uninitialized resource in GPU. Reported by Google on 2026-07-22
[N/A][543141419] High CVE-2026-95283: Buffer overflow in Tint. Reported by Google on 2026-08-06
[TBD][550953039] High CVE-2026-95293: Uninitialized resource in GPU. Reported by TienPA - NGS Holdings on 2026-08-22
[N/A][553116160] High CVE-2026-95274: Improper output encoding in DevTools. Reported by Google on 2026-08-26
[N/A][553129513] High CVE-2026-95282: Use after free in Platform. Reported by Google on 2026-08-26
[N/A][553130481] High CVE-2026-95373: Use after free in DevTools. Reported by Google on 2026-08-26
[N/A][553136141] High CVE-2026-95277: Use after free in Views. Reported by Google on 2026-08-26
[N/A][554558320] High CVE-2026-95348: Use after free in Bluetooth. Reported by Google on 2026-08-29
[TBD][555299641] High CVE-2026-95335: Use after free in HID. Reported by WinD39 - Huynh Dinh Vu on 2026-09-01
[TBD][556535630] High CVE-2026-95338: Use after free in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-03
[TBD][556576976] High CVE-2026-95318: Buffer overflow in Video. Reported by alex.laboirie on 2026-09-03
[TBD][557523002] High CVE-2026-95286: Type confusion in Bindings. Reported by @bean5oup on 2026-09-05
[TBD][558764482] High CVE-2026-95365: Type confusion in IndexedDB. Reported by HoneyBee on 2026-09-08
[TBD][559815527] High CVE-2026-95343: Use after free in WebAudio. Reported by HoneyBee on 2026-09-11
[N/A][560406548] High CVE-2026-95280: Race condition in V8. Reported by Google on 2026-09-12
[TBD][560536731] High CVE-2026-95304: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[TBD][560536735] High CVE-2026-95306: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[N/A][561997427] High CVE-2026-95299: Use after free in GPU. Reported by Google on 2026-09-15
[TBD][562242429] High CVE-2026-95351: Use after free in Views. Reported by Xinyang Ge on 2026-09-16
[N/A][495529018] Medium CVE-2026-95287: Missing authorization in Navigation. Reported by Google on 2026-03-23
[N/A][497204165] Medium CVE-2026-95366: Use of released resource in Core. Reported by Google on 2026-03-28
[N/A][497212105] Medium CVE-2026-95382: Improper input validation in Auth. Reported by Google on 2026-03-28
[N/A][497603247] Medium CVE-2026-95381: Improper input validation in Printing. Reported by Google on 2026-03-30
[N/A][500127519] Medium CVE-2026-95331: Out of bounds write in ANGLE. Reported by Google on 2026-04-06
[N/A][501648493] Medium CVE-2026-95297: Missing authorization in Contextual Tasks. Reported by Google on 2026-04-11
[N/A][502179319] Medium CVE-2026-95375: Incorrect authorization in BrowserTag. Reported by Google on 2026-04-13
[N/A][502242455] Medium CVE-2026-95302: Incorrect authorization in WebAPKs. Reported by Google on 2026-04-13
[N/A][511791538] Medium CVE-2026-95362: Cross-site request forgery in DevTools. Reported by Google on 2026-05-10
[N/A][513049042] Medium CVE-2026-95369: Inappropriate implementation in XML. Reported by Google on 2026-05-14
[N/A][513134076] Medium CVE-2026-95376: Externally controlled reference in DevTools. Reported by Google on 2026-05-14
[N/A][513162143] Medium CVE-2026-95359: Uninitialized resource in GPU. Reported by Google on 2026-05-14
[N/A][513992281] Medium CVE-2026-95294: UI misrepresentation in Browser. Reported by Google on 2026-05-17
[N/A][514019137] Medium CVE-2026-95337: UI misrepresentation in Messages. Reported by Google on 2026-05-17
[N/A][514059630] Medium CVE-2026-95346: UI misrepresentation in Chromoting. Reported by Google on 2026-05-17
[N/A][514072284] Medium CVE-2026-95320: Missing authorization in Navigation. Reported by Google on 2026-05-17
[N/A][514487499] Medium CVE-2026-95317: Incorrect authorization in MediaCapture. Reported by Google on 2026-05-19
[N/A][516404074] Medium CVE-2026-95345: Use after free in Actor. Reported by Google on 2026-05-25
[N/A][517163294] Medium CVE-2026-95330: Improper state validation in Downloads. Reported by Google on 2026-05-27
[N/A][517417437] Medium CVE-2026-95370: Inappropriate implementation in NFC. Reported by Google on 2026-05-28
[N/A][517442714] Medium CVE-2026-95303: Incomplete cleanup in SmartCard. Reported by Google on 2026-05-28
[N/A][517584808] Medium CVE-2026-95360: Race condition in Editing. Reported by Google on 2026-05-28
[N/A][517596255] Medium CVE-2026-95295: Information leak in Mobile. Reported by Google on 2026-05-28
[N/A][517730821] Medium CVE-2026-95276: Improper input validation in Themes. Reported by Google on 2026-05-29
[N/A][517802696] Medium CVE-2026-95314: Incorrect authorization in HID. Reported by Google on 2026-05-29
[N/A][520504291] Medium CVE-2026-95371: Missing authorization in Views. Reported by Google on 2026-06-05
[N/A][522061704] Medium CVE-2026-95353: Use after free in Bindings. Reported by Google on 2026-06-10
[N/A][522344883] Medium CVE-2026-95363: UI misrepresentation in FileSystem. Reported by Google on 2026-06-10
[N/A][523719002] Medium CVE-2026-95341: Improper input validation in Desktop. Reported by Google on 2026-06-14
[N/A][524582798] Medium CVE-2026-95354: Use after free in Verifier. Reported by Google on 2026-06-16
[N/A][526550688] Medium CVE-2026-95384: Race condition in Transactions Platform. Reported by Google on 2026-06-22
[N/A][532962621] Medium CVE-2026-95336: Information leak in Transactions Platform. Reported by Google on 2026-07-09
[N/A][536161355] Medium CVE-2026-95290: Missing authorization in NFC. Reported by Google on 2026-07-18
[N/A][536648933] Medium CVE-2026-95325: Use after free in ANGLE. Reported by Google on 2026-07-19
[TBD][542926849] Medium CVE-2026-95275: Incorrect reference resolution in MediaStream. Reported by Zabith Mohammed (@nmzabith) on 2026-08-05
[TBD][543464436] Medium CVE-2026-95374: Incorrect authorization in Network. Reported by NH DEV on 2026-08-07
[N/A][545449081] Medium CVE-2026-95300: Missing authorization in DevTools. Reported by Google on 2026-08-12
[TBD][545879261] Medium CVE-2026-95321: UI misrepresentation in Payments. Reported by jodyritonga on 2026-08-13
[TBD][546438368] Medium CVE-2026-95323: UI misrepresentation in Chromium. Reported by Wihdatu Nuuro Ahmadi on 2026-08-14
[N/A][546639650] Medium CVE-2026-95332: Use of uninitialized variable in Tint. Reported by Google on 2026-08-14
[N/A][547832510] Medium CVE-2026-95312: Information leak in Passwords. Reported by Google on 2026-08-17
[TBD][548611433] Medium CVE-2026-95344: Race condition in DevTools. Reported by @bean5oup on 2026-08-18
[TBD][549911100] Medium CVE-2026-95289: Incorrect authorization in Scroll. Reported by Vu Van Tien (@n0_Be3r) on 2026-08-21
[TBD][550181232] Medium CVE-2026-95347: Use after free in Updater. Reported by a45hif on 2026-08-21
[N/A][553123003] Medium CVE-2026-95311: Free of non-heap memory in Fonts. Reported by Google on 2026-08-26
[N/A][553141660] Medium CVE-2026-95358: Incorrect authorization in Mobile. Reported by Google on 2026-08-26
[TBD][559682346] Medium CVE-2026-95333: Use after free in Metrics. Reported by sean geofrey on 2026-09-10
[$500][423956129] Low CVE-2026-95307: UI misrepresentation in ExtensionsMenu. Reported by Hafiizh on 2025-06-11
[N/A][497094708] Low CVE-2026-95285: Missing authorization in WebView. Reported by Google on 2026-03-28
[N/A][497344014] Low CVE-2026-95278: Missing authorization in WakeLock. Reported by Google on 2026-03-29
[N/A][502077689] Low CVE-2026-95327: Information leak in Networking. Reported by Google on 2026-04-13
[N/A][513403696] Low CVE-2026-95334: Incorrect reference resolution in WebProtect. Reported by Google on 2026-05-15
[N/A][513714849] Low CVE-2026-95308: Integer overflow in Metrics. Reported by Google on 2026-05-16
[N/A][513781838] Low CVE-2026-95292: Incorrect authorization in Safebrowsing. Reported by Google on 2026-05-16
[N/A][513791872] Low CVE-2026-95352: Incorrect authorization in DevTools. Reported by Google on 2026-05-16
[N/A][514012689] Low CVE-2026-95279: UI misrepresentation in Omnibox. Reported by Google on 2026-05-17
[N/A][514524620] Low CVE-2026-95367: Information leak in DataTransfer. Reported by Google on 2026-05-19
[N/A][517192965] Low CVE-2026-95385: Inappropriate implementation in PlatformIntegration. Reported by Google on 2026-05-27
[N/A][522413520] Low CVE-2026-95368: Incorrect authorization in DevTools. Reported by Google on 2026-06-10
[N/A][523765972] Low CVE-2026-95319: Use after free in Printing. Reported by Google on 2026-06-14
[N/A][533041383] Low CVE-2026-95326: Incomplete cleanup in Bluetooth. Reported by Google on 2026-07-09
[N/A][533074595] Low CVE-2026-95309: UI misrepresentation in Mobile. Reported by Google on 2026-07-09
[N/A][533095855] Low CVE-2026-95361: Confused deputy in DevTools. Reported by Google on 2026-07-09
[N/A][533102653] Low CVE-2026-95288: UI misrepresentation in Mobile. Reported by Google on 2026-07-09
[N/A][534579660] Low CVE-2026-95380: Type confusion in V8. Reported by Google on 2026-07-14
[TBD][547027738] Low CVE-2026-95342: Missing authorization in V8. Reported by Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo on 2026-08-16
[TBD][551296612] Low CVE-2026-95296: Missing authorization in Core. Reported by Quyα»n SΖ‘n (@zer0qs1337) on 2026-08-23
[N/A][552023752] Low CVE-2026-95316: Unchecked return value in Performance. Reported by Google on 2026-08-24
[N/A][553148673] Low CVE-2026-95328: Confused deputy in Mobile. Reported by Google on 2026-08-26
[N/A][553268567] Low CVE-2026-95340: Incorrect authorization in PictureInPicture. Reported by Google on 2026-08-27
[N/A][553271219] Low CVE-2026-95364: Improper input validation in Passwords. Reported by Google on 2026-08-27
[N/A][553921181] Low CVE-2026-95305: UI misrepresentation in Chromoting. Reported by Google on 2026-08-28
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.
Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Srinivas Sista
Google Chrome
v12.4.0
β οΈ Potential Breaking Changes
Updated MapLibre GL JS from 1.15.3 to 6.9.0 (#28216)
The map layout and the geometry interface now require WebGL2, which MapLibre has mandated since v3. Browsers that only support WebGL1, chiefly Safari 14 and earlier and older Android devices, will no longer render maps.
Dragging with a pointer or a mouse wheel keeps the hovered item popup pinned to the cursor as before. Touch drags no longer reposition it, since the underlying touch event carries no cursor coordinates.
Updated Unhead from 1.11.20 to 3.4.1 (#28248)
@directus/themes now requires @unhead/vue 3.x as a peer dependency. Projects that pair it with their own Unhead instance need to upgrade and follow the v2 and v3 migration guides.
Updated outdated type definitions for directus_comments, directus_flows, directus_operations, directus_presets, directus_roles, and directus_versions (#27956)
The following fields are now correctly marked as nullable:
@directus/types:Comment.user_created,Comment.user_updated,FlowRaw.user_created,OperationRaw.options,OperationRaw.user_created,Preset.collection,Role.description, andContentVersion.hash@directus/sdk:DirectusRole.parentandDirectusVersion.hash
Updated outdated type definitions for directus_relations, directus_policies, directus_shares, directus_access, directus_comments, and directus_versions (#27970)
Breaking changes in @directus/sdk:
DirectusRelation.metaandDirectusRelation.schemaare now nullableDirectusPolicy.ip_accessandDirectusRelation.meta.one_allowed_collectionsare now correctly typed asstring[]
Breaking changes in @directus/types:
Policy.enforce_tfais no longer nullableShare.name,role,password,user_created,date_createdandtimes_usedare now nullable
Fixed read permissions not enforced when resolving item keys for updateByQuery and deleteByQuery (#28143)
Update/delete by query now resolves the affected items with the read permissions enforced:
- Read access to the collection's primary key field is now required.
- The affected items are scoped to what the role can read, irrespective of update rights.
- Nested o2m saves require read access on the child collection.
Added native mailtrap email transport support via EMAIL_TRANSPORT=mailtrap (#27873)
The transport is configured through the following environment variables:
-
EMAIL_MAILTRAP_TOKENβ an API token from https://mailtrap.io/api-tokens. Required. -
EMAIL_MAILTRAP_SANDBOXβ send to the testing inbox instead of real recipients. -
EMAIL_MAILTRAP_TEST_INBOX_IDβ which testing inbox to send to. Required in sandbox mode. -
EMAIL_MAILTRAP_BULKβ send via the bulk stream. Cannot be combined with sandbox mode. -
@directus/app
- Updated MapLibre GL JS from 1.15.3 to 6.9.0 (#28216 by @br41nslug)
-
@directus/themes
- Updated Unhead from 1.11.20 to 3.4.1 (#28248 by @br41nslug)
-
@directus/types
-
@directus/sdk
β¨ New Features & Improvements
- @directus/app
- Disabled inactive collections in the Studio, preventing them from being selected or used while being viewable (#27792 by @br41nslug)
- Moved Flows into its own module and improved how they're organized and managed, including folders, search and filtering, import and export, and duplication (#28206 by @robluton)
- Added support for hiding a manual Flow's own button, so it runs only from a Manual Flow field (#28206 by @robluton)
- Added support for setting the From Name in the Send Email operation (#28206 by @robluton)
- @directus/api
- Moved Flows into its own module and improved how they're organized and managed, including folders, search and filtering, import and export, and duplication (#28206 by @robluton)
- Added support for hiding a manual Flow's own button, so it runs only from a Manual Flow field (#28206 by @robluton)
- Added support for setting the From Name in the Send Email operation (#28206 by @robluton)
- Added native
mailtrapemail transport support viaEMAIL_TRANSPORT=mailtrap(#27873 by @tsokolovs)
- @directus/system-data
- @directus/specs
- @directus/types
- @directus/cli
- @directus/sdk
- @directus/env
- Added native
mailtrapemail transport support viaEMAIL_TRANSPORT=mailtrap(#27873 by @tsokolovs)
- Added native
π Bug Fixes & Optimizations
- @directus/app
- Fixed the image editor's error notice rendering as an unstyled info message instead of an error (#28245 by @Nitwel)
- Updated Unhead from 1.11.20 to 3.4.1 (#28248 by @br41nslug)
- Fixed relational edits made in quick succession saving duplicate create or update entries for the same row, which made the stale entry win and dropped block editor changes inside translations (#28247 by @alvarosabu)
- Fixed the filter delete (x) button in the search bar's filter popover becoming unclickable on hover. (#28114 by @aniruddhav25)
- Fixed table row context menus staying open when opening the menu on another row (#28191 by @robluton)
- Updated outdated type definitions for
directus_comments,directus_flows,directus_operations,directus_presets,directus_roles, anddirectus_versions(#27956 by @kheiner) - Updated outdated type definitions for
directus_relations,directus_policies,directus_shares,directus_access,directus_comments, anddirectus_versions(#27970 by @kheiner) - Blocked crud usage for inactive collections and added a
COLLECTION_INACTIVEerror (#27792 by @br41nslug) - Updated dompurify, joi, express, qs, uuid, diff, pm2, OpenTelemetry and AI SDK dependencies to address CVEs (#28242 by @br41nslug)
- Fixed the date picker calendar showing English weekday names and starting the week on Sunday regardless of the user language (#28147 by @lazerg)
- Replaced
lodashwithlodash-esin the Studio (#28245 by @Nitwel) - Added new DEV_APP_PORT env var for setting the app port while in development mode (#28112 by @robluton)
- @directus/api
- Updated outdated type definitions for
directus_comments,directus_flows,directus_operations,directus_presets,directus_roles, anddirectus_versions(#27956 by @kheiner) - Updated outdated type definitions for
directus_relations,directus_policies,directus_shares,directus_access,directus_comments, anddirectus_versions(#27970 by @kheiner) - Blocked crud usage for inactive collections and added a
COLLECTION_INACTIVEerror (#27792 by @br41nslug) - Updated dompurify, joi, express, qs, uuid, diff, pm2, OpenTelemetry and AI SDK dependencies to address CVEs (#28242 by @br41nslug)
- Updated stream-json from 1.9.1 to 3.6.0 (#28251 by @br41nslug)
- Fixed read permissions not enforced when resolving item keys for
updateByQueryanddeleteByQuery(#28143 by @br41nslug) - Fixed relational fields ordering to align with the order of fields in query parameters. (#28197 by @wakqasahmed)
- Fixed Oracle JSON filtering and
json()function returning quoted strings for scalar string values (#28264 by @wofiporia) - Fixed schema cache synchronization timeouts leaving stale bus subscriptions and pending timers behind (#28178 by @lazerg)
- Fixed the global access cache ignoring the client IP (#28190 by @br41nslug)
- Updated sharp, nodemailer, tiptap, js-yaml and mysql2 dependencies (#28219 by @br41nslug)
- Fixed the block editor flickering and losing its controls while editing a version (#28105 by @alvarosabu)
- Fixed schema diff generation for nested metadata additions and removals (#27880 by @thribhuvan003)
- Fixed
FilesService.uploadOneto prevent client payloads from overwriting system fields (e.g.,uploaded_by,created_onetc) (#28208 by @br41nslug) - Fixed
year()function on Oracle returning the ISO week-numbering year instead of the calendar year, and made the Oracle date part functions (year,month,week,day,weekday,hour,minute,second) return numbers instead of zero padded strings (#28257 by @galshir) - Fixed
uploaded_onnot being set for TUS uploads (#28043 by @kheiner) - Fixed comment updates and deletes enforcement (#28162 by @kheiner)
- Fixed foreign key constraints being dropped when updating a relation with a partial payload (#28137 by @lazerg)
- Updated Flows and Operations tools to automatically fix incorrect X/Y positions for flow operations when used through (#28159 by @bryantgillespie)
MCP and AI Assistant
- Updated outdated type definitions for
- @directus/types
- Updated outdated type definitions for
directus_comments,directus_flows,directus_operations,directus_presets,directus_roles, anddirectus_versions(#27956 by @kheiner) - Blocked crud usage for inactive collections and added a
COLLECTION_INACTIVEerror (#27792 by @br41nslug)
- Updated outdated type definitions for
- @directus/sdk
- Updated outdated type definitions for
directus_comments,directus_flows,directus_operations,directus_presets,directus_roles, anddirectus_versions(#27956 by @kheiner) - Added missing empty-parameter validation to
readRelationByCollection,createField,deleteCollection,utilsExport,utilsImport,utilitySort,triggerFlow, andreadShareInfo(#27970 by @kheiner) - Updated known-but-not-enforced string fields on
directus_users,directus_settings,directus_deployment_runs(#28129 by @kheiner)
- Updated outdated type definitions for
- @directus/errors
- Blocked crud usage for inactive collections and added a
COLLECTION_INACTIVEerror (#27792 by @br41nslug)
- Blocked crud usage for inactive collections and added a
- @directus/schema-builder
- Blocked crud usage for inactive collections and added a
COLLECTION_INACTIVEerror (#27792 by @br41nslug)
- Blocked crud usage for inactive collections and added a
- @directus/utils
- Blocked crud usage for inactive collections and added a
COLLECTION_INACTIVEerror (#27792 by @br41nslug)
- Blocked crud usage for inactive collections and added a
- @directus/memory
- Fixed the local key-value store treating equal
setMaxvalues as updates (#28172 by @jashkarangiya) - Fixed concurrent local KV updates losing increments or overwriting larger values in
setMax. (#28194 by @jashkarangiya)
- Fixed the local key-value store treating equal
- @directus/release-notes-generator
π¦ Published Versions
@directus/app@18.0.0@directus/api@39.2.0@directus/cli@12.3.0@directus/composables@11.6.3create-directus-extension@12.1.5@directus/env@6.3.0@directus/errors@2.5.2@directus/extensions@4.0.5@directus/extensions-registry@4.0.4@directus/extensions-sdk@18.0.5@directus/memory@4.0.5@directus/pressure@4.0.5@directus/release-notes-generator@3.0.2@directus/schema-builder@1.0.3@directus/specs@15.2.0@directus/storage-driver-azure@13.0.5@directus/storage-driver-cloudinary@14.0.2@directus/storage-driver-gcs@13.0.5@directus/storage-driver-s3@14.0.2@directus/storage-driver-supabase@5.0.2@directus/system-data@4.7.0@directus/themes@3.0.0@directus/types@17.0.0@directus/utils@13.5.5@directus/validation@3.0.5@directus/sdk@26.0.0
Minecraft 26.4-snapshot-1 (snapshot) Released
BSD Release: NetBSD 10.2
Distribution Release: Univention Corporate Server 5.2-7
NVIDIA Driver 617.14
Although GeForce Game Ready Drivers and NVIDIA Studio Drivers can be installed on supported notebook GPUs, the original equipment manufacturer (OEM) provides certified drivers for your specific notebook on their website. NVIDIA recommends that you check with your notebook OEM for recommended software updates for your notebook.
Game Ready for CONTROL Resonant, Gears of War: E-Day, The Witcher 3: Wild Hunt β Remastered & AION 2
This new Game Ready Driver provides the best gaming experience for the latest new games supporting DLSS and RTX technologies including CONTROL Resonant, Gears of War: E-Day, The Witcher 3: Wild Hunt β Remastered and AION 2.
Fixed Gaming Bugs
- Judgement/Lost Judgement/ Virtua Fighter 5 R.E.V.O. may fail to launch after updating to driver 616.56 [6681537]
Fixed General Bugs
- No picture on Samsung Odyssey G95NC monitor when connected via HDMI after updating to R615 drivers [6771206]
- Certain monitors may not wake from sleep when connected via DisplayPort after updating to R615 drivers [6757568]
Learn more in our Game Ready Driver article here.
![]()
The new Mac mini and Mac Studio are available today

Firefox 156.0.1
Fixed
Fixed the NVDA screen reader not announcing address bar buttons when the mouse pointer moves over them. (Bug 2069276)
Fixed elements inside a link not showing their CSS
:activestyles while being clicked. (Bug 2067272)Fixed Firefox becoming unresponsive on some pages that use CSS anchor positioning. (Bug 2070171)
Fixed Firefox windows on macOS 27 immediately returning to maximized after being restored by double-clicking the title bar. (Bug 2066632)
Fixed Firefox leaking system handles on Windows as content processes were started and stopped. (Bug 2069644)
Reference link to 156.0 release notes.
Apple opens Apple Music Hall, a state-of-the-art live music venue in London

v1.18.32
v1.11.0-beta.2 - Bulwark Lite (Pre-release)
Pre-release. This is a test build for Bulwark Lite. Not recommended for production. The
latestDocker tag stays on 1.10.0. To try the server build, useghcr.io/bulwarkmail/webmail:1.11.0-beta.2.
Bulwark Lite
bulwark-lite-1.11.0-beta.2.zip: unpack it on any static web host and set your JMAP server inconfig.json. The JMAP server must allow CORS from the webmail origin.bulwark-lite-stalwart.zip: a StalwartApplicationbundle that serves itself under the configured prefix (e.g./webmail).
The Lite zips are attached once the Build Static Lite workflow finishes (a few minutes after publishing).
Changes since beta.1
- Toasts for mail actions that had no feedback, plus an "email sent" toast after immediate sends
- Toasts show again
- Deep links resolve to the local instance
- A staged attachment is kept until its upload finishes
Please report problems in the issue tracker.
macOS 27.2 beta 2 (26B5091g)
iOS 27.2 beta 2 (24B5089g)
uNmINeD 0.20.10-dev
New uNmINeD development snapshot is available for download!
Changes:
- Fixed Bedrock LevelDB parsing errors
- (GUI) Fixed random black isometric tiles
v0.16.23
[0.16.23] - 2026-09-21
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
- Expressions:
bit_andfunction.
Changed
Fixed
- MTA:
- A mailing list whose recipients include another mailing list is accepted at
RCPT TOand then rejected at local delivery with550 5.5.0 Mailbox not found. - DMARC aggregate reports carry two
spfelements per record and theversionelement of a DMARC aggregate report is written as1instead of1.0. - DSNs generated for an alias rewrite or a list expansion emit a doubled
addr-typeinOriginal-Recipient(rfc822;rfc822;user@example.org). - DSNs that cannot be written to the store are discarded, the recipients are flagged as notified and the original message is removed from the queue, losing both the bounce and the message.
- A mailing list whose recipients include another mailing list is accepted at
- POP3:
TOP msg ncounts thenlines from the first byte of the message instead of from the first byte of the body.- A message whose very first line begins with
.is not byte-stuffed.
- Spam filter: Moving or copying a message from one account into another creates no training sample, so the classifier never learns from it.
- Sieve:
envelope "orcpt"yields the bare address for anORCPTsupplied over SMTP. It now carries theaddr-typeprefix in every case, as required by RFC 6009. - ACME: The
_acme-challengeTXT records published for a DNS-01 authorization are never removed. - DNS: The DNSSEC resolver queries a single nameserver at a time, working around a
hickory-resolverrace that cancels the TCP retry when two nameservers return a truncated response in parallel. - Troubleshoot tool:
- MX records are resolved through the DNSSEC-validating resolver, matching the resolver used by the delivery path.
- A TLSA lookup that fails or returns bogus records stops the delivery attempt for that host, instead of continuing without DANE.
- OIDC: Bearer tokens that carry no
email,preferred_usernameorupnclaim are always authenticated against the default directory. - Meilisearch: A confirmation timeout is treated as a failed write even when
failOnTimeoutis disabled, so an index whose batches take longer thanpollIntervalxmaxRetriesnever completes an indexing task and resubmits the same batch indefinitely. - WebUI: A failed update no longer takes an
Applicationoffline. - FoundationDB: The cached read version is invalidated when any broadcast is received from another node.
- Redis:
- On a cluster, the rate limiter and the blob upload quota issue
INCRandEXPIREas aMULTI/EXECtransaction, whoseMOVEDredirects collapse into a singleEXECABORTthat never refreshes the slot map. - A connection that fails because it is addressing the wrong server is returned to the pool and reused, since the recycle check only issues
PING.
- On a cluster, the rate limiter and the blob upload quota issue
Check binary attestation here
DistroWatch Weekly, Issue 1191
Review: Command line shells
News: Orphaned Void packages, Ubuntu finishes migration from GNU to Rust Coreutils, new CoW filesystem for OpenBSD, new features in GNU Coreutils
Questions and answers: The legacy of filenames on Linux
Released last week: Raspberry Pi OS 2026-09-15, Parted Magic 26.09, Clonezilla....
Distribution Release: MX Linux 25.3
Part-DB 2.18.0
Warning
After upgrade, you need to run php bin/console doctrine:migrations:migrate (or equivalent) as webserver user after upgrade.. If you are running a docker container, use sudo docker exec --user=www-data partdb php bin/console doctrine:migrations:migrate, or sudo -E inside the docker container, to ensure that the migrations are applied to the correct database.
Note
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Part-DB 2.18.0
New features
- Added generic AI client, that can be used for any OpenAI compatible LLM API (#1551)
- Allow to specify a color for custom part states by @killecaptron in #1537
- Retrieve and store stock levels from info providers for parts by @killecaptron in #1538
- Allow to configure which field groups are exported to KiCad by @lukas-runge in #1533
- Show DEFAULT_URI value in server info page
- Report an AI provider error instead of ending the request with a 500 by @killecaptron in #1539
- Added an
debug_vars()twig functions in the twig label sandbox to list all available variables - Do not download non-downloadable attachments and improve handling changing URLs on attachment merge by @killecaptron in #1531
- Rate limit requests to info providers by @killecaptron in #1536
- Allow direct refreshing parts from the info provider they were created with & batch refreshing by @killecaptron in #1532
Bug fixes
- fix(mcp): gate the read-only get_part_details tool with read permission by @wangzhengzhuo05 in #1546
- Fixed compatibility of AI extractor with OpenAI LLMs @killecaptron in #1540
- Version the cache keys of the info provider DTOs to avoid exceptions after upgrade by @killecaptron in #1530
- Fix stale KiCad category listing after EDA settings change by @lukas-runge in #1534
- fix(eda): inherit KiCad reference prefix from ancestor categories by @wangzhengzhuo05 in #1547
- Correctly reset collection forms on form reset (thanks @LMatt08)
- Fixed error that unique entitity validation failed, even when one of two duplicate entries should be deleted
Other changes
- Updated dependencies
- Updated translations
- Removed jquery dependency
- Updated KiCAD symbols and footprints
- Fixed deprecations & code structure
New Contributors
- @wangzhengzhuo05 made their first contribution in #1546
Full Changelog: v2.17.0...v2.18.0
Development build
Below are development builds for testing purposes.
Latest development build: 2.8.2.10 (September 21st 2026)
Latest stable release build: 2.8.2
https://github.com/clsid2/mpc-hc/releases/tag/2.8.2
Road Trip: Ford Release Date & Video Trailer Reveal
Get ready for a brand-new experience in American Truck Simulator! It's time to grab a different set of keys and hit the road in amazing vehicles that are a little different than what you've been used to. We're excited to announce that the
Road Trip: Ford DLC for American Truck Simulator will be released on September 29th, 2026!
We are so excited to be almost finished with this upcoming DLC and that our #BestCommunityEver will be able to enjoy it too! To get you in the mood for driving the stunning cars from Ford, our talented video team has put together an official video trailer. Watch it below to see all that is coming!
Road Trip will bring a whole new experience for players of American Truck Simulator. Not only will you be able to drive in completely different types of vehicles than before, but you will also have the opportunity to complete smaller delivery jobs, customize your cars with accessories, paint them in different colors, or explore the vast landscapes of the U.S. from a completely new perspective while also discovering and learning about beautiful landmarks with the new Atlas feature!
Just imagine driving legendary cars like theΒ 1967 Ford Mustang Fastback,Β 2023 Ford F-150,Β 2023 Ford Bronco, andΒ 1998β2012 Ford Crown Victoria on Route 66 from Chicago to Los Angeles, through the rolling hills of the Midwest, or over the beautiful mountains in Montana from the comfort of your home.
And if you are a pure truck driver and don't feel like ever leaving your decked-out rig, don't forget that the Atlas feature available with Road Trip DLCs is not just for cars.Β You can still enjoy the feature behind the wheel of an 18-wheeler - just make sure to own the Road Trip: Ford DLC so this feature is unlocked for you right after its release.Β
We would like to thank FordΒ for their cooperation in bringing their amazing vehicles into our game! If you are looking forward to hitting the road in a Ford, make sure to add the Road Trip: Ford DLC for American Truck Simulator to your Steam Wishlist.Β
Remember to stay up to date with the latest American Truck Simulator news by subscribing to our newsletter or following us on X/Twitter, Facebook, BlueSky, and Instagram. Until next time, we wish you happy journeys!
v1.21.1
Fixes and improvements
General
- require browser POST requests to have an allowed origin (#6238) Browsers can send POST requests without performing any preflight request and without checking whether the request origin is present in Access-Control-Allow-Origin. Intercept these requests and check server-side whether the origin is allowed, blocking the request if it is not.
- conf: fix comparison and sharing of the default authInternalUsers (#6205)
- h265: fix DTS extraction of streams with long-term reference pictures (bluenviron/mediacommon#371)
- pmp4: support stsz with a constant sample size (#5803) (bluenviron/mediacommon#373)
- pmp4, fmp4: restore check on inbound H265 SPS (bluenviron/mediacommon#374) A valid H265 SPS is required for marshaling back an MP4, so we have to resume checking them.
- pmp4: support tracks without edts (bluenviron/mediacommon#375) The edit box is optional (ISO/IEC 14496-12, 8.6.5), but tracks without it were rejected with "unexpected box 'mdia'".
- pmp4: return seek errors from GetPayload (bluenviron/mediacommon#376) GetPayload checked the wrong variable after seeking, therefore a failed seek was ignored and the payload was read from the current position of the reader.
- pmp4, fmp4: correctly fill HvcC NumTemporalLayers / TemporalIdNested from SPS (bluenviron/mediacommon#379)
- pmp4: support tracks longer than 2^32 ticks (bluenviron/mediacommon#377)
RTSP
- rtpmjpeg: reject reserved quantization value 127 (bluenviron/gortsplib#1161) RFC 2435 reserves quantization values 100-127, but the guard used
Quantization < 127 - mpeg4audiolatm: don't panic on a layer that reuses the config (bluenviron/gortsplib#1162)
- sdp: support oversized numbers in origin (#5949) (bluenviron/gortsplib#1171)
RTMP
- correctly fill HvcC NumTemporalLayers / TemporalIdNested from SPS (bluenviron/gortmplib#129)
- reader: support standalone SEIs from DJI drones (#5221) (bluenviron/gortmplib#130)
HLS
- make the server manage sessions (#6239) Sessions are now managed by the HLS server, detaching their lifecycle from muxers. This also comes with a performance improvement, since finding a session now traverses a single mutex, and not two channels like before.
- return 404 when a session is valid but muxer is closed (#5736) (#6240) HLS sessions are now kept open for up to 30 seconds after a muxer is closed. This allows the server to handle incoming requests belonging to these sessions and to classify then as 404 rather than 401.
- change error returned in case session is not found (#6241) match the RTSP behavior and return a "session not found" message rather than an "authentication error", which is reserved for creating sessions, not for using them.
- muxer: return 404 when closed (bluenviron/gohlslib#394)
WebRTC
- fix AV1 getting stuck by stripping padding (#5632) (#5774) (#6242) AV1 OBU padding is generated by several encoders. Stripping it has been demonstrated to solve most situations in which browsers get stuck when playing such streams.
- fix stuck decoding with DJI drones (#5221) (#6051) (#6243) Streams from DJI drones contain SEI units with payload type 5 and a specific UUID that seem to cause stuck videos on Chrome and Firefox. Filter out these units.
- add ability to exclude interfaces (#5788)
Dependencies
- code.cloudfoundry.org/bytefmt updated from v0.88.0 to v0.90.0
- github.com/MicahParks/keyfunc/v3 updated from v3.8.1 to v3.8.2
- github.com/abema/go-mp4 updated from v1.7.1 to v1.7.3
- github.com/bluenviron/gohlslib/v2 updated from v2.4.4 to v2.4.5
- github.com/bluenviron/gortmplib updated from v1.0.2 to v1.0.3
- github.com/bluenviron/gortsplib/v5 updated from v5.6.5 to v5.6.6
- github.com/bluenviron/mediacommon/v2 updated from v2.9.4 to v2.9.5
- github.com/gin-contrib/pprof updated from v1.5.4 to v1.5.5
- github.com/matthewhartstonge/argon2 updated from v1.5.7 to v1.6.3
- github.com/pion/ice/v4 updated from v4.4.1 to v4.4.2
- github.com/pion/interceptor updated from v0.1.47 to v0.1.48
- github.com/pion/sdp/v3 updated from v3.0.19 to v3.0.20
- github.com/pion/transport/v4 updated from v4.1.0 to v4.1.1
- github.com/pion/webrtc/v4 updated from v4.2.19 to v4.2.20
- golang.org/x/crypto updated from v0.55.0 to v0.57.0
- golang.org/x/net updated from v0.58.0 to v0.59.0
- golang.org/x/sync updated from v0.22.0 to v0.23.0
- golang.org/x/sys updated from v0.47.0 to v0.48.0
- golang.org/x/term updated from v0.45.0 to v0.46.0
- github.com/bytedance/gopkg updated from v0.1.3 to v0.1.4
- github.com/bytedance/sonic updated from v1.15.0 to v1.15.2
- github.com/bytedance/sonic/loader updated from v0.5.0 to v0.5.1
- github.com/cloudwego/base64x updated from v0.1.6 to v0.1.7
- github.com/gabriel-vasile/mimetype updated from v1.4.12 to v1.4.13
- github.com/gin-contrib/sse updated from v1.1.0 to v1.1.1
- github.com/go-playground/validator/v10 updated from v10.30.1 to v10.30.3
- github.com/goccy/go-json updated from v0.10.5 to v0.10.6
- github.com/klauspost/cpuid/v2 updated from v2.3.0 to v2.4.0
- github.com/mattn/go-isatty updated from v0.0.20 to v0.0.23
- github.com/pelletier/go-toml/v2 updated from v2.2.4 to v2.4.3
- github.com/pion/dtls/v3 updated from v3.1.5 to v3.1.8
- github.com/pion/mdns/v2 updated from v2.1.0 to v2.2.0
- github.com/pion/srtp/v3 updated from v3.0.13 to v3.0.15
- github.com/pion/stun/v3 removed
- github.com/pion/turn/v5 updated from v5.0.13 to v5.1.0
- go.mongodb.org/mongo-driver/v2 updated from v2.5.0 to v2.8.0
- golang.org/x/arch updated from v0.22.0 to v0.29.0
- golang.org/x/text updated from v0.41.0 to v0.42.0
- google.golang.org/protobuf updated from v1.36.10 to v1.36.11
- github.com/pion/stun/v4 v4.0.0 added
- hls.js updated from v1.7.2 to v1.7.3
Security
Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.
Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
You can verify checksums of binaries by downloading checksums.sha256 and running:
cat checksums.sha256 | grep "$(ls mediamtx_*)" | sha256sum --check