Blog

What’s new in Eficode ROOT: June 2026

MAY 31, 2026

June is here, and our dev tech stack is flexing some serious muscle with major leaps forward to GitLab 19 and GitHub 3.20 taking center stage. While those two heavyweights steal the spotlight, we also gave the rest of the ecosystem its routine seasonal tune-up, including a modest minor bump for Jira to 10.3.21 (plus plugins) and fresh new LTS Jenkins to 2.555.2 with swarms of new plugins versions.

Eficode is the leading DevOps company in Europe, driving and building the future of software development across 10 countries, with 500+ experts in DevOps and sustainable software development. Our Eficode ROOT managed DevOps platform provides centralized access control and real-time visibility of project status, quality, and performance that integrates with 50+ of your preferred tools, including the Atlassian Stack and open-source systems like Jenkins and Kubernetes.

The cleanup crew kept the momentum going by bringing Rocket Chat 7.13.8, Hashicorp Vault 2.0.1, KeyCloak 26.5.7, and Dependency Track 4.14.1 up to their latest stable baselines. Looking ahead, July will be a deployment freeze period—but that doesn’t mean we'll be putting our feet up to work on our tans. Instead, we’ll be focusing on essential backend maintenance, actively monitoring the threat landscape, and precisely implementing CVE patches where they truly impact our environment to keep our customers safe, sound, and securely optimized. Make sure to check out the removals section in the GitLab  and GitHub article section!

GitLab

The journey toward a more powerful, seamless development environment reaches its next milestone with the introduction of GitLab 19. Driven by the need to shift from basic code suggestions to intelligent, agent-driven automation and natively integrated security, this latest evolution focuses entirely on removing friction from daily operations. For everyone interacting with the platform, this means less time spent managing external integration tools and a much faster, highly secure path to production.

Now you gain access to an active AI assistant capable of automatically resolving broken pipelines with one-click fixes,furthermore, advanced software supply chain tracking automatically scans deep-nested dependencies, giving you complete visibility and enterprise-grade compliance without any extra manual effort.

GitHub Enterprise Server

The journey toward a more powerful, seamless development environment reaches its next milestone with the introduction of GitHub Version 3.20. Driven by the need to scale organization management, tighten security administration, and pave the way for upcoming platform capabilities, this latest evolution focuses entirely on removing friction from daily operations. For everyone interacting with the platform, this means a significantly more organized ecosystem where access control and policy oversight are centralized and simplified.

You will immediately benefit from the debut of enterprise teams, which allows for the seamless management of repository permissions and access rules across multiple organizations simultaneously. Furthermore, security leads gain the advantage of a public preview for the dedicated Enterprise Security Manager role to monitor alerts at scale, while a quick structural change reserves the /repos path to prepare your environment for next-generation product features.

Jenkins

Even if GitHub Actions policies at the organization or repository level typically restrict the uploading of workflows, administrators can now utilize default setup to enable code scanning. This update ensures that security scans remain functional and are not obstructed by Actions policy restrictions. Learn morehere.

Shipped with this release is CodeQL CLI version 2.23.9, powering the CodeQL action for advanced code scanning. Since the version provided in GitHub Enterprise Server 3.19, several major enhancements have been introduced:

Language and Framework Enhancements

  • Rust Support: Rust analysis is now generally available, allowing developers to secure libraries and applications against all OWASP Top 10 categories, excluding A06:2021.

  • Swift & Kotlin Updates: CodeQL now includes support for Swift versions 6.2 and 6.2.1, alongside Kotlin releases 2.2.0x and 2.2.2x. Note that support for Kotlin 1.6 and 1.7 is being phased out.

  • C/C++ Buildless Scanning: Analysis for C/C++ projects without requiring builds is now generally available, with a new default "none" build-mode to simplify adoption for new repositories.

Performance and Workflow Improvements

  • Incremental Analysis: To boost performance, CodeQL now supports incremental analysis across all its supported languages.

  • Action v4 Migration: Advanced setup users must transition to CodeQL Action v4 (running on Node.js 24) before v3 is retired in December 2026; default setup users will be migrated automatically.

Query Optimizations: A broad range of refinements and changes have been applied to CodeQL queries for every supported language.

Jira

The journey toward a more powerful, seamless development environment reaches its next milestone with an ecosystem maintenance upgrade to Jira version 10.3.21. Driven by the commitment to keep your primary project management workspace aligned with the highest enterprise standards, this maintenance release consolidates critical background bug fixes while bringing all foundational marketplace plugins to their absolute latest versions. For everyone interacting with the platform, this translates directly into an interruption-free, rock-solid daily workspace where workflows run smoothly and data is consistently structured.

You will immediately benefit from major stability fixes that eliminate frustrating platform bugs, such as resolving the issue where closed tasks would incorrectly populate Advanced Roadmaps plans despite strict exclusion rules. Furthermore, the combined force of the latest plugin versions ensures seamless tool integrations, faster dashboard loading times, and peak tracking performance to keep your projects moving without a hitch.

Key Maintenance Fixes Included in this Cycle:

  • Advanced Roadmaps Integrity: Fixes a critical regression where resolved and closed issues would unexpectedly bypass exclusion rules and display inside Advanced Roadmaps plans.

  • Plugin Ecosystem Update: Synchronizes all installed app add-ons to their most modern versions, reducing integration errors and securing custom field behaviors.

System Performance Stability: Resolves UI navigation latency issues, specifically targeting desktop view rendering glitches and filtering hiccups to guarantee a snappier user experience.

Rocket Chat

A vital evolution in team communication arrives with the transition to Rocket.Chat version 7.13.8. This targeted update addresses the critical need for a more secure, memory-efficient infrastructure while resolving specific performance bottlenecks in audio and video calling. For the entire organization, this means a significantly more dependable workspace where conversations happen instantly and data sharing remains strictly protected.

The communication experience becomes immediately smoother thanks to a rewritten media engine that prevents dropped calls and ensures audio alerts ring through flawlessly every time. Additionally, behind-the-scenes system optimizations completely eliminate server crashes during heavy file transfers and enforce bulletproof session security, giving you a completely frictionless environment to collaborate.

Key Maintenance Fixes Included in this Cycle:

  • Resource Optimization: Fixes a backend streaming bug where large file uploads would cause excessive CPU and memory spikes, ensuring server stability during heavy asset transfers.

  • Call & Audio Reliability: Resolves communication glitches by introducing robust audio device handling and fixed notification triggers, preventing dropped connections or silent ringers.

  • Session & Token Governance: Patches enterprise authentication pathways to guarantee that deactivated user sessions and idle OAuth tokens are completely purged upon dismissal.

Strict Upload Validation: Hardens internal file filtering to block unauthorized file types from bypassing system security restrictions if renamed mid-upload.

Hashicorp Vault

An essential lifecycle maintenance patch arrives with the progression to HashiCorp Vault version 2.0.1. Driven by the critical necessity to eliminate initial platform regressions, patch foundational security libraries, and stabilize user management hooks, this minor release ensures the newly deployed v2 architecture runs at peak efficiency. For the engineering teams relying on the cluster, this translates into a highly resilient cryptographic boundary with completely reliable identity syncing and zero interface friction.

You will immediately benefit from a collection of crucial stability fixes, including the resolution of a critical bug where removing a user from an Okta group failed to revoke their corresponding access privileges within Vault. Furthermore, your administrative workflows are significantly improved by a patched user interface that eliminates sidebar navigation reloads and fixes empty result tables when adjusting secret engine pagination, ensuring a fast and trustworthy management experience.

Key Maintenance Fixes Included in this Cycle:

  • Okta SCIM Synchronization: Fixes an enterprise identity bug where an Okta group push removal failed to cascade, ensuring that revoked group memberships successfully strip user access within Vault.

  • UI Stability and Navigation: Resolves multiple GUI layout glitches, specifically fixing an annoying sidebar menu flicker/reload during engine-scoped routing and fixing broken table pagination on the Secrets Engine page.

  • Storage Write Protection: Adds critical validation checks to prevent core storage write failures during the generation and handling of Time-Based One-Time Password (TOTP) keys.

Security Dependency Patches: Upgrades fundamental cryptographic and transit engine dependencies to resolve vulnerabilities across core JSON Web Signing (JOSE) and transport protocols.

KeyCloak

The continuous refinement of our central authentication barrier takes a definitive step forward with the deployment of Keycloak Version 26.5.7. Driven by the crucial necessity to patch deep-seated transport vulnerabilities, resolve application-level denial of service risks, and eliminate cross-user session leaks during re-authentication, this lifecycle update brings your identity server up to the highest security posture. For the entire organization, this means absolute trust in user privacy, bulletproof access control boundaries, and completely predictable authentication patterns across all linked microservices.

You will immediately benefit from fixed OpenID Connect (OIDC) endpoints that properly enforce strict path-traversal validation, stopping malicious actors from bypassing redirect rules and forging authorization tokens. Furthermore, backend data streams have been optimized to ensure that authentication cookies are entirely isolated during concurrent login cycles, completely shielding your digital identity from cross-contamination while you work.

Key Maintenance Fixes Included in this Cycle:

  • Session Contamination Fix: Resolves a major session reuse bug where overlapping authentication tokens could lead to cross-user account exposure during rapid re-authentication.

  • OIDC Path Bypasses: Patches critical redirect URI endpoints to neutralize path-traversal exploits that could trick the system into leaking active authorization codes to external domains.

  • Scope Processing Stabilization: Eliminates an application-level denial of service vulnerability caused by erratic server processing loops during extensive API scope evaluations.

Access Control Integrity: Touches up internal admin REST endpoints and UMA 2.0 layers to prevent unprivileged clients from enumerating organization memberships or reading sensitive role metadata.

Dependency Track

We are updating our software security and transparency platform, Dependency-Track, from version 4.13.6 to version 4.14.2. With this major upgrade, you will experience a significantly more precise risk evaluation framework and greater control over your software supply chain. Security and compliance teams can now reduce background noise and enhance focus by leveraging platform-native rule sets, modern threat metrics, and more intelligent automation. This ensures your developers spend less time auditing false alarms and more time delivering secure value to your customers.

Here are the key highlights of this release:

  • Ecosystem-Aware Vulnerability Matching. The platform now tracks and evaluates software version numbers using the native rule sets unique to specific programming languages and operating systems (such as Alpine Linux, Debian, Ubuntu, NPM, and Maven). It also understands when OS developers "backport" security fixes to older versions. The Benefit: This feature drastically reduces false positives. Your teams will no longer waste time chasing phantom alerts for vulnerabilities that have already been fixed or don’t apply to your specific environment.

  • Next-Generation Risk Framework (CVSSv4 Support). Dependency-Track now ingests and displays the latest industry-standard risk scoring framework, CVSSv4, alongside existing data. The Benefit: You will benefit from a more refined and multidimensional calculation of vulnerability severities, giving you the most up-to-date, comprehensive view of your actual threat posture.

  • Expanded EPSS Threat Intelligence. Exploit Prediction Scoring System (EPSS) scores—which estimate the real-world likelihood of a security flaw being weaponized by bad actors—have now been extended to cover vulnerabilities sourced from GitHub Advisories. The Benefit: This empowers your security team to instinctively prioritize remediation workflows, focusing instantly on the threats that are actively being abused in the wild.

  • Automated Software Aging and Health Policies. The policy engine has been expanded to support rules based on a component's operational age and "version distance" (how many updates a component has fallen behind). The Benefit: You can easily establish baseline guardrails to identify outdated software, systematically preventing "software rot" and keeping your digital products modern, maintainable, and resilient.

  • Performance Boosts and Search Optimization. Under-the-hood optimization has improved database mirroring speeds, introduced project-specific filters to the component search view, and refined international localization (including German and Chinese language updates). The Benefit: You will enjoy a smoother, more responsive user interface and faster data synchronization, reducing the time spent navigating dashboards.

____________________________________________________________________________

That’s all for June! See you in August!

  • Eficode ROOT

Subscribe to our newsletter