Blog

blog title

OCT 1, 2026

Jess Fraser-Darling

Director of Atlassian Solutions and People & Business Transformation Lead

As Director of Atlassian Solutions and People & Business Transformation Lead at Eficode, Jess brings 16 years of digital financial services experience across both the UK and Sweden. She specializes in bridging the gap between C-suite vision and frontline execution across cloud, agile, and AI transformation. Also a high-energy speaker known for healthy provocation, Jess’s core philosophy is simple: people first, tools later. You can’t automate your way out of a deep cultural problem.

Confluence

Confluence advances to version

Learn about Ai native organizations

learn more

10.2, the newest Long Term Support release. Moving straight to a new LTS means a whole year of accumulated improvements lands in one step, on a foundation that Atlassian will keep patching for the long haul. For your teams, the upgrade brings a modernized platform (Spring 6, Jakarta EE 10 and Tomcat 10.1 under the hood), tighter security defaults and a set of practical tools for administrators: app usage insights, bulk content cleanup and service accounts for automation. Editors will also enjoy blog templates and keyboard shortcuts.

Deprecations and removals

End of support for the Original theme

With the new light and dark themes that brought accessibility and usability improvements, the original theme has been removed from all products.

Rate limiting changes for the content REST API

Starting from 10.2.11, the /rest/api/content endpoint is no longer automatically exempt from rate limiting and now follows the rate limiting settings configured for your instance. If you run high-volume integrations or automations against this endpoint, review them before the upgrade. Should you need the endpoint to stay exempt, reach out to us and we will adjust the configuration for you. Learn more here.

Storage Format Source Editor now bundled

The Storage Format Source Editor now ships with Confluence out of the box. It lets you view and edit the underlying XHTML storage format of a page, which is handy for fixing macro parameters, broken links or formatting problems, and for search-and-replace operations. For security reasons, the editor is disabled for all users by default, including administrators. Access can be granted to selected groups or to everyone. Reach out to us and we will enable it for the groups you choose. Learn more here.

App usage monitoring for installed apps

Administrators can now see how installed apps are actually used, directly from the new App Usage menu under Atlassian Marketplace. The Common Usage Data tab shows REST API calls made by apps and the Active Objects database tables they create, together with their row counts.

Find and sort the most used macros in your site

A dedicated Macro Usage section lists the app-provided macros found in your content, including custom macros shipped by installed apps. For each macro you can see how many pages use it and when those pages were last modified. This makes it much easier to estimate the impact of removing or replacing an app and to spot the macros your teams rely on most. Learn more here.

Macro Usage tab

Dark features for Labels

The Labels experience has been reworked for better performance, and the new behaviour is the default. In the unlikely case that the updated Labels lists behave unexpectedly in your site, two opt-in rollback switches (dark features) can temporarily restore the previous behaviour. Let us know if you notice anything unusual and we will help you evaluate it.

New Space Content Manager tool

Space administrators can now select and delete many pages in a single operation with the new Content Manager. It shows all pages in a space as a tree, displays how many pages (including descendants) will be affected before you confirm, skips pages you do not have permission to delete, and moves the selected content to the space trash, so nothing is lost by accident.

To open it, go to Space tools > Content Manager.

New Global Permission: Browse All Group Members

A new global permission gives administrators control over which users and groups can view the membership of every group in the site. This helps organizations that treat group structures as sensitive information. Learn more here.

Manage your integrations and automations with service accounts

Scripts, scheduled jobs and external integrations can now run through dedicated service accounts instead of real users’ credentials. Service accounts are non-user accounts that access the REST APIs with OAuth 2.0 client credentials, are limited to the scopes and resources you define, and have every action they perform tracked for full visibility.

To set up a service account:

  1. Go to Administration > User management and select Service accounts from the sidebar.

  2. Select Create service account.

  3. Define the account’s details, scopes and resources, then generate its OAuth 2.0 credentials.

  4. Review everything and store the credentials in a safe place.

Learn more here.

Control how many labels display in macros

The Label List, Recently Used Labels and Popular Labels macros now include a Number of Labels to Display field, so you decide how many labels each macro shows. Sites with a very large number of labels also benefit from a configurable processing limit that keeps searches responsive. Learn more here.

Improved performance for adding Jira issue dates in Team Calendars

Adding Jira issue dates to Team Calendars is now noticeably faster, especially when the calendar pulls data from large Jira projects. Learn more here.

Configure OAuth 2.0 for outgoing mail

Confluence can now authenticate to your outgoing mail server with OAuth 2.0 instead of a username and password, which is increasingly required by providers such as Microsoft 365 and Google Workspace. If you would like to switch your outgoing mail to OAuth 2.0, reach out to us and we will configure it for you. Learn more here.

Creating blog posts from templates

Templates are no longer reserved for pages. Just like in Confluence Cloud, you can now use templates when writing blog posts, making recurring announcements and team updates quicker to produce and more consistent. Learn more here.

Aligning editor shortcuts with Confluence Cloud

The editor shortcuts in Confluence Data Center now match Confluence Cloud, which makes life easier for anyone who works in both. The new shortcuts include:

  • # to create headings

  • > to create quotes

  • --- to insert a horizontal rule

  • - to create a round bullet point

  • Cmd + Enter (macOS) or Ctrl + Enter (Windows) to save a page or a comment

Learn more here.


GitHub Enterprise Server

GitHub Enterprise Server moves to version 3.21. This release is less about one headline feature and more about many steady improvements across governance, security and performance. Day to day, your developers will notice a snappier web interface, organizations can share workflow templates across their teams, and Dependabot now keeps OpenTofu, Bazel, Julia and uv projects up to date. Administrators gain enterprise-wide custom roles, finer control over which actions may run, and new options to scale the platform horizontally.

Deprecations and removals

Password authentication for the GitHub API

Authenticating to the REST API with a username and password is deprecated. Integrations and scripts should use personal access tokens (preferably fine-grained) or GitHub Apps instead. If you are unsure whether any of your automations still rely on passwords, reach out to us and we will help you identify them. Learn more here.

REST API version 2026-03-10 deprecates several endpoints

The new calendar-based REST API version 2026-03-10 introduces breaking changes and deprecates a number of endpoints. Requests without an explicit version header continue to use 2022-11-28, which is now in its closing-down period but will remain supported for at least 24 months. We recommend reviewing the list of breaking changes and planning the migration of your integrations early. Learn more here.

Upcoming: Collectd metrics (from 3.23)

Starting with 3.21, OpenTelemetry metrics are enabled by default and Collectd metrics are disabled. Collectd is scheduled for removal in 3.23, so any external monitoring built on Collectd should move to OpenTelemetry. Learn more here.

Upcoming: Deprecation of LDAP and CAS (from 3.26)

LDAP and CAS authentication are planned to be deprecated in 3.26. Instances using them will need to move to SAML single sign-on with SCIM provisioning (for example with Microsoft Entra ID). There is still time, but we recommend starting the planning now. Reach out to us and we will prepare the migration together with you. Learn more here.

Improved browser performance

Pages across the web interface load and respond faster, with rendering and client-side improvements that are most noticeable on large repositories, long pull requests and busy issue lists. Learn more here.

Enterprise-level custom roles

Enterprise owners can now define custom roles once at enterprise level and make them available across all organizations. This keeps permission models consistent everywhere and removes the need to recreate the same roles in every organization. Learn more here.

Shared workflow templates for organizations

Organizations can now publish shared GitHub Actions workflow templates, so teams start new pipelines from approved, ready-made building blocks instead of copying YAML between repositories. Learn more here.

Fine-grained control over permitted actions and reusable workflows

Organization and repository owners can now specify exactly which actions and reusable workflows are allowed to run, across all plan types and repositories. This makes it easier to enforce a trusted set of automation building blocks and to reduce supply chain risk in CI/CD. Learn more here.

Dependabot supports OpenTofu, Bazel, Julia and uv

Dependabot version updates now cover the OpenTofu, Bazel and Julia ecosystems as well as Python’s uv package manager, so even more of your dependencies can be kept up to date automatically. Learn more here.

Code scanning alerts can be assigned to individual users

Assigning code scanning alerts to people is now generally available. Users can assign alerts to themselves or to teammates to track remediation work, receive notifications when an alert is assigned to them, and automate assignment through webhooks and the API. Learn more here.

CodeQL updated to version 2.24.3

The bundled CodeQL engine has been updated to 2.24.3, bringing broader language coverage and new analysis capabilities, including:

  • Analysis of Java 26, Go 1.26, .NET 10 with C# 14, Kotlin up to 2.3.10 and Swift 6.2.x projects

  • New framework models for Next.js 16, Struts 7.x, Couchbase and more

  • A new experimental query that detects prompt injection risks in Python code that uses LLMs

Learn more here.

Exemptions from secret scanning push protection

Teams, GitHub Apps and specific custom roles can now be exempted from push protection enforcement. This gives security teams a controlled way to let trusted automation or designated reviewers push when needed, without switching protection off for everyone. Learn more here.

REST API upgraded to version 2026-03-10

GitHub Enterprise Server now supports the REST API version 2026-03-10, the first calendar-based version. Integrations opt in by sending the X-GitHub-Api-Version header, which lets you migrate at your own pace. Learn more here.

Stateless HA nodes for web and job workload scaling

High-availability deployments can now be extended with additional stateless nodes that take over CPU-intensive web and background job workloads from the primary node. This allows the platform to scale horizontally as usage grows. Contact us if you would like to discuss whether this setup fits your instance. Learn more here.

  • Atlassian
  • AI

Subscribe to our newsletter