Blog

What’s new in Eficode ROOT: October 2026

OCT 1, 2026

October is here, the leaves are turning and so is a big part of our toolchain. This month we are rolling out a wide wave of upgrades: Confluence jumps to the 10.2 Long Term Support release, GitHub Enterprise Server moves to 3.21.6, GitLab reaches 19.4, the plugins on all Jenkins instances get a big round of updates, JFrog Artifactory and Xray step up to 7.161.26 and 3.150, SonarQube arrives in three flavours (Server 2026.4, Server LTA 2026.1.5 and Community Build 26.9), and Sonatype Nexus Repository lands on 3.96. Expect stronger security defaults, smarter AI governance, cleaner repository housekeeping and plenty of quality-of-life improvements. Grab a warm drink and dive in!

Jakub Sawczuk

Release Manager

Jakub oversees the software feature releases for Eficode ROOT. He has a background in software development enhanced with release management practices.

Confluence

Confluence advances to version 10.2, the newest Long Term Support release. Moving straight to a new LTS means a whole year of accumulated improvements lands in one step, on a foundation that Atlassian will keep patching for the long haul. For your teams, the upgrade brings a modernized platform (Spring 6, Jakarta EE 10, and Tomcat 10.1 under the hood), tighter security defaults, and a set of practical tools for administrators: app usage insights, bulk content cleanup, and service accounts for automation. Editors will also enjoy blog templates and keyboard shortcuts.

Deprecations and removals

End of support for the Original theme

With the new light and dark themes that brought accessibility and usability improvements, the original theme has been removed from all products.

Rate limiting changes for the content REST API

Starting from 10.2.11, the /rest/api/content endpoint is no longer automatically exempt from rate limiting and now follows the rate limiting settings configured for your instance. If you run high-volume integrations or automations against this endpoint, review them before the upgrade. Should you need the endpoint to stay exempt, reach out to us and we will adjust the configuration for you. Learn more here.

Storage Format Source Editor now bundled

The Storage Format Source Editor now ships with Confluence out of the box. It lets you view and edit the underlying XHTML storage format of a page, which is handy for fixing macro parameters, broken links or formatting problems, and for search-and-replace operations. For security reasons, the editor is disabled for all users by default, including administrators. Access can be granted to selected groups or to everyone. Reach out to us and we will enable it for the groups you choose. Learn more here.

App usage monitoring for installed apps

Administrators can now see how installed apps are actually used, directly from the new App Usage menu under Atlassian Marketplace. The Common Usage Data tab shows REST API calls made by apps and the Active Objects database tables they create, together with their row counts.

Find and sort the most used macros in your site

A dedicated Macro Usage section lists the app-provided macros found in your content, including custom macros shipped by installed apps. For each macro, you can see how many pages use it and when those pages were last modified. This makes it much easier to estimate the impact of removing or replacing an app and to spot the macros your teams rely on most. Learn more here.

Macro Usage tab

Dark features for Labels

The Labels experience has been reworked for better performance, and the new behavior is the default. In the unlikely case that the updated Labels lists behave unexpectedly in your site, two opt-in rollback switches (dark features) can temporarily restore the previous behavior. Let us know if you notice anything unusual, and we will help you evaluate it.

New Space Content Manager tool

Space administrators can now select and delete many pages in a single operation with the new Content Manager. It shows all pages in a space as a tree, displays how many pages (including descendants) will be affected before you confirm, skips pages you do not have permission to delete, and moves the selected content to the space trash, so nothing is lost by accident.

To open it, go to Space tools > Content Manager.

New Global Permission: Browse All Group Members

A new global permission gives administrators control over which users and groups can view the membership of every group in the site. This helps organizations that treat group structures as sensitive information. Learn more here.

Manage your integrations and automations with service accounts

Scripts, scheduled jobs and external integrations can now run through dedicated service accounts instead of real users’ credentials. Service accounts are non-user accounts that access the REST APIs with OAuth 2.0 client credentials, are limited to the scopes and resources you define, and have every action they perform tracked for full visibility.

To set up a service account:

  1. Go to Administration > User management and select Service accounts from the sidebar.

  2. Select Create service account.

  3. Define the account’s details, scopes and resources, then generate its OAuth 2.0 credentials.

  4. Review everything and store the credentials in a safe place.

Learn more here.

Control how many labels display in macros

The Label List, Recently Used Labels and Popular Labels macros now include a Number of Labels to Display field, so you decide how many labels each macro shows. Sites with a very large number of labels also benefit from a configurable processing limit that keeps searches responsive. Learn more here.

Improved performance for adding Jira issue dates in Team Calendars

Adding Jira issue dates to Team Calendars is now noticeably faster, especially when the calendar pulls data from large Jira projects. Learn more here.

Configure OAuth 2.0 for outgoing mail

Confluence can now authenticate to your outgoing mail server with OAuth 2.0 instead of a username and password, which is increasingly required by providers such as Microsoft 365 and Google Workspace. If you would like to switch your outgoing mail to OAuth 2.0, reach out to us and we will configure it for you. Learn more here.

Creating blog posts from templates

Templates are no longer reserved for pages. Just like in Confluence Cloud, you can now use templates when writing blog posts, making recurring announcements and team updates quicker to produce and more consistent. Learn more here.

Aligning editor shortcuts with Confluence Cloud

The editor shortcuts in Confluence Data Center now match Confluence Cloud, which makes life easier for anyone who works in both. The new shortcuts include:

  • # to create headings

  • > to create quotes

  • --- to insert a horizontal rule

  • - to create a round bullet point

  • Cmd + Enter (macOS) or Ctrl + Enter (Windows) to save a page or a comment

Learn more here.


GitHub Enterprise Server

GitHub Enterprise Server moves to version 3.21. This release is less about one headline feature and more about many steady improvements across governance, security and performance. Day to day, your developers will notice a snappier web interface, organizations can share workflow templates across their teams, and Dependabot now keeps OpenTofu, Bazel, Julia and uv projects up to date. Administrators gain enterprise-wide custom roles, finer control over which actions may run, and new options to scale the platform horizontally.

Deprecations and removals

Password authentication for the GitHub API

Authenticating to the REST API with a username and password is deprecated. Integrations and scripts should use personal access tokens (preferably fine-grained) or GitHub Apps instead. If you are unsure whether any of your automations still rely on passwords, reach out to us and we will help you identify them. Learn more here.

REST API version 2026-03-10 deprecates several endpoints

The new calendar-based REST API version 2026-03-10 introduces breaking changes and deprecates a number of endpoints. Requests without an explicit version header continue to use 2022-11-28, which is now in its closing-down period but will remain supported for at least 24 months. We recommend reviewing the list of breaking changes and planning the migration of your integrations early. Learn more here.

Upcoming: Collectd metrics (from 3.23)

Starting with 3.21, OpenTelemetry metrics are enabled by default and Collectd metrics are disabled. Collectd is scheduled for removal in 3.23, so any external monitoring built on Collectd should move to OpenTelemetry. Learn more here.

Upcoming: Deprecation of LDAP and CAS (from 3.26)

LDAP and CAS authentication are planned to be deprecated in 3.26. Instances using them will need to move to SAML single sign-on with SCIM provisioning (for example with Microsoft Entra ID). There is still time, but we recommend starting the planning now. Reach out to us and we will prepare the migration together with you. Learn more here.

Improved browser performance

Pages across the web interface load and respond faster, with rendering and client-side improvements that are most noticeable on large repositories, long pull requests, and busy issue lists. Learn more here.

Enterprise-level custom roles

Enterprise owners can now define custom roles once at the enterprise level and make them available across all organizations. This keeps permission models consistent everywhere and removes the need to recreate the same roles in every organization. Learn more here.

Shared workflow templates for organizations

Organizations can now publish shared GitHub Actions workflow templates, so teams start new pipelines from approved, ready-made building blocks instead of copying YAML between repositories. Learn more here.

Fine-grained control over permitted actions and reusable workflows

Organization and repository owners can now specify exactly which actions and reusable workflows are allowed to run, across all plan types and repositories. This makes it easier to enforce a trusted set of automation building blocks and to reduce supply chain risk in CI/CD. Learn more here.

Dependabot supports OpenTofu, Bazel, Julia and uv

Dependabot version updates now cover the OpenTofu, Bazel and Julia ecosystems as well as Python’s uv package manager, so even more of your dependencies can be kept up to date automatically. Learn more here.

Code scanning alerts can be assigned to individual users

Assigning code scanning alerts to people is now generally available. Users can assign alerts to themselves or to teammates to track remediation work, receive notifications when an alert is assigned to them, and automate assignment through webhooks and the API. Learn more here.

CodeQL updated to version 2.24.3

The bundled CodeQL engine has been updated to 2.24.3, bringing broader language coverage and new analysis capabilities, including:

  • Analysis of Java 26, Go 1.26, .NET 10 with C# 14, Kotlin up to 2.3.10 and Swift 6.2.x projects

  • New framework models for Next.js 16, Struts 7.x, Couchbase and more

  • A new experimental query that detects prompt injection risks in Python code that uses LLMs

Learn more here.

Exemptions from secret scanning push protection

Teams, GitHub Apps and specific custom roles can now be exempted from push protection enforcement. This gives security teams a controlled way to let trusted automation or designated reviewers push when needed, without switching protection off for everyone. Learn more here.

REST API upgraded to version 2026-03-10

GitHub Enterprise Server now supports the REST API version 2026-03-10, the first calendar-based version. Integrations opt in by sending the X-GitHub-Api-Version header, which lets you migrate at your own pace. Learn more here.

Stateless HA nodes for web and job workload scaling

High-availability deployments can now be extended with additional stateless nodes that take over CPU-intensive web and background job workloads from the primary node. This allows the platform to scale horizontally as usage grows. Contact us if you would like to discuss whether this setup fits your instance. Learn more here.


GitLab

GitLab steps up to version 19.4, bringing together two releases’ worth of improvements focused on making AI automation controllable, affordable and ready for everyday work. The headline for administrators is cost control: GitLab Credits usage caps are now generally available and can be managed from a dedicated page in the UI, no GraphQL required. Developers get two long-awaited GA features, as GitLab Duo can now resolve merge conflicts and review discussions on its own. Reinforcing all of this, new governance controls for AI agents and MCP servers let you decide exactly which tools an agent may use, whether it runs in GitLab, in the IDE or in a third-party client.

Deprecations and removals

Devstral 2 deprecated for GitLab Duo Agent Platform Self-Hosted

Following Mistral’s deprecation of the Devstral 2 model, GitLab has deprecated it for self-hosted Duo Agent Platform deployments. Mistral Medium 3.5 is the suggested alternative. Learn more here.

Administration

Disable OAuth Dynamic Client Registration for MCP (All tiers)

Until now, MCP clients and AI tools could register OAuth applications on your instance automatically through Dynamic Client Registration, and there was no way to switch it off. Administrators can now disable it through the application settings API, so only pre-registered OAuth applications can connect. Learn more here.

Pre-register MCP OAuth applications (All tiers)

The mcp scope is now available when creating OAuth applications in the Admin area. You can create one shared application for your MCP clients, give users a stable client ID to reuse, and avoid dynamic registration rate limits on shared networks. Learn more here.

Restrict access to MCP servers (beta) (Premium, Ultimate)

You can now allow or deny access to entire external MCP servers or to individual tools they expose. The rules apply wherever GitLab Duo agents run, including Agentic Chat, flows, the IDE, and the CLI, so agents can only reach the tools that are within their scope. Learn more here.

LDAP group sync can now manage the Auditor role (Premium, Ultimate)

A new audit_group setting maps an LDAP group to the Auditor role, so auditor access is granted and revoked automatically based on directory membership, just like administrator access. Learn more here.

Set credit caps without the GraphQL API (Premium, Ultimate)

A new Credit caps page lets administrators set a default cap on how many GitLab Credits each user can consume and add per-user overrides through a searchable picker. The GraphQL mutations still work for those who prefer scripting. Learn more here.

Included credits are used before evaluation credits (Premium, Ultimate)

When a subscription has temporary evaluation credits, each user’s included monthly credits are now consumed first, and the shared evaluation pool is used only afterward. Previously, the order was reversed, which left the included credits unused. Billing is not affected. Learn more here.

Per-capability spend caps for GitLab Flex (Premium, Ultimate)

With GitLab Flex, you can now set a separate spend cap for each capability when adjusting your reservation: no overage, a bounded overage, or unlimited. When a capped capability hits its limit, only that capability stops for the rest of the billing period, while the others keep running. Learn more here.

Early warnings for GitLab Flex spend caps (Premium, Ultimate)

Billing account managers now receive an email when a capability’s on-demand usage reaches 50% or 80% of its monthly spend cap, so there is time to react before usage is cut off. Learn more here.

AI

Resolve merge conflicts with GitLab Duo is generally available (Premium, Ultimate)

Instead of resolving conflicts by hand, you can now ask GitLab Duo to do it. Start from the merge widget or the Resolve conflicts page, and Duo analyzes the conflicts, commits the resolution to the source branch, and posts a summary of what changed. Learn more here.

Resolve review discussions with GitLab Duo is generally available (Premium, Ultimate)

Introduced as a beta last month, this feature is now generally available. Select Resolve with GitLab Duo on a review thread, and Duo implements the requested change, commits it, replies with a short summary, and resolves the thread. You or the reviewer can always reopen it. Learn more here.

Governance for GitLab MCP server tools (All tiers)

Tools exposed through the GitLab MCP server can now be governed from the same place as internal Duo Agent Platform tools. For each tool, you choose a mode: read-only tools default to Always Allow, while write and delete tools default to Always Ask, giving reviewers a checkpoint before an agent changes anything. Learn more here.

New GitLab MCP server tools (All tiers)

The GitLab MCP server gains a large set of new tools, letting agents in any MCP client work across GitLab under the governance rules you define:

  • CI/CD tools: run, retry or cancel pipelines and read job logs to diagnose failed builds

  • Merge request tools: open, update, review, approve and merge merge requests

  • Project and user tools: discover projects and look up users for assignments and mentions

  • Repository tools: browse files, tags, releases and commit history, commit changes and fork projects

  • Work item tools: search, read, create and update issues, epics, tasks and other work items, and comment on them

  • Semantic search: the semantic code search tool is renamed and prepared for more content types

Learn more here.

/goal command in GitLab Duo CLI (Premium, Ultimate)

The new /goal slash command lets you hand an open-ended objective to a governed flow that runs locally. GitLab Duo implements and verifies the work, while you stay in control and can pause, update or redirect it at any time. Learn more here.

GitLab Duo CLI plugins and marketplaces (Experiment) (Premium, Ultimate)

GitLab Duo CLI can now install plugins that bundle skills, custom slash commands and MCP server configurations. An official marketplace is registered automatically and already includes skills for reviewing merge requests, splitting large changes into stacked merge requests and drafting issues. Learn more here.

Flow Creator foundational agent (Premium, Ultimate)

The Flow Creator agent in the AI Catalog builds custom flows from a plain-language conversation. Describe what the flow should do, and it produces a runnable flow definition you can register straight away. It can also help debug existing flows. Learn more here.

GitLab flow builder for custom flows (Beta) (All tiers)

A new visual editor in the GitLab for VS Code extension lets you compose custom flows from components or edit the underlying YAML, test them from an execution console and publish them to the AI Catalog. Learn more here.

Merge request created event trigger (Premium, Ultimate)

Flows and external agents can now start the moment a merge request is opened. Select Created as the trigger action to run a first-pass review or to enrich the merge request with context from related issues. Learn more here.

Turn flow triggers off without deletion (Premium, Ultimate)

Flow triggers can now be switched off and back on with a toggle, keeping their filter configuration intact instead of forcing you to delete and recreate them. Learn more here.

Model selection for the Developer Flow (Premium, Ultimate)

Administrators can now choose a specific AI model for the Developer Flow, independently of the models used by other Duo Agent Platform features. Learn more here.

Support for GLM 5.3, Kimi K3 and MiniMax M3 (Premium, Ultimate)

Three open-weight models are now available in the Duo Agent Platform. Users can pick them in Agentic Chat, and group owners and administrators can set them as defaults for chat, agents and flows, matching model cost to task complexity. Learn more here.

New Agentic Chat UI in VS Code and JetBrains IDEs (Beta) (Premium, Ultimate)

Agentic Chat in the GitLab for VS Code extension and the GitLab Duo plugin for JetBrains IDEs has a redesigned interface with the same capabilities underneath. You can switch between the new and the classic UI at any time. Learn more here.

GitLab Duo Slack integration (Experimental) (Premium, Ultimate)

Mention @GitLab in any Slack channel or thread to trigger agent flows, get answers about your codebase or create issues from conversations. Progress is streamed back into the thread in real time. Learn more here.

Support for Amazon Bedrock Mantle (Beta) (Premium, Ultimate)

Self-managed instances using self-hosted models can now use Amazon Bedrock Mantle, an OpenAI-compatible inference engine for Bedrock, as a model provider. Learn more here.

UI/UX

Redesigned session details panel for the GitLab Duo Agent Platform (All tiers)

Agent session details are now far easier to scan: status, timestamps and the triggering user appear in an overview bar, and a new Linked items section separates what started the session from what it produced. Learn more here.

View agent task plan in session detail sidebar (Premium, Ultimate)

The session detail sidebar now shows the agent’s latest plan automatically, with the status of each task and a progress summary, so you no longer have to dig through the activity log. Learn more here.

See who locked a file or directory (Premium, Ultimate)

When a file is locked, a popover next to the Locked label now shows who locked it and, if you have permission, offers an unlock action. For locked directories, it points you directly to the file that blocks your change. Learn more here.

Improved table pasting in rich text editor (All tiers)

When pasting a table into a table cell, you can now choose between inserting it as a nested table and merging its cells into the existing table. Learn more here.

More ways to filter and manage through the API (All tiers)

Several REST and GraphQL API improvements arrive, including new group filters, merged_after and merged_before parameters for merge requests, SCIM token reset for administrators, and support for fetching repository archives with CI_JOB_TOKEN. Learn more here.

Other additions to the interface (All tiers)

A collection of smaller but welcome improvements, many of them community contributions:

  • Filtering the issue list by created, closed, due and updated date is now generally available

  • /internal_note marks a comment as internal while you create it, and /type Epic promotes an issue to an epic

  • Pipeline test report columns are sortable, and a list item drag can be cancelled with Esc

  • Links in Mermaid flowcharts now open correctly

Learn more here.

Reporting

GitLab Credits usage caps are generally available (Premium, Ultimate)

Usage caps help you avoid unplanned overage charges. Set a subscription-level cap for on-demand credits in the Customers Portal and default or per-user caps in GitLab. When a cap is reached, credit-consuming features such as the Duo Agent Platform pause until the next billing period or until an administrator raises the cap. Learn more here.

Per-event detail in the credit usage export (Premium, Ultimate)

The credit usage export now includes, next to the daily summary, a per-event file with one row for each billable event, including the flow type, user, project and credits used. Attributing AI costs to teams or individual automations no longer requires guesswork. Learn more here.

Email notifications for GitLab Flex usage (Premium, Ultimate)

Billing account managers receive an email when a product reaches 50%, 80% or 100% of its monthly Flex reservation, and when a capped product reaches its spend cap. Learn more here.

See which user authorized each MCP OAuth application (All tiers)

Dynamically registered MCP OAuth applications now include the name of the user who authorized them, so administrators can see at a glance who is behind each connection. Learn more here.

Restricted visibility for custom agents and flows (All tiers)

Custom agents and flows can now be set to Restricted visibility, making them available to every group and project in your top-level group while keeping them hidden from everyone else. Learn more here.

Project development

Enforce merge trains (Premium, Ultimate)

A single project setting now prevents anyone from bypassing the merge train through the UI or the API. This avoids merges that cancel and restart every pipeline in the train, while Owners and administrators can still override it when necessary. Learn more here.

Secret detection scans commit history on default branch pushes (All tiers)

Secret detection on the default branch now scans every commit in a push, not just the latest state of the files. Secrets that were added and removed within the same push are no longer missed. Learn more here.

Two new CI/CD variables: retry count and job tags (All tiers)

CI_JOB_RETRY_COUNT tells your scripts how many times the current job has been retried, and CI_JOB_TAGS exposes the job’s own configured tags. Learn more here.

Webhooks for merge request reviews and deployment approvals (All tiers)

Submitting a merge request review now fires a webhook, and deployment webhooks report blocked, approved, and rejected statuses, so external tools can follow reviews and approvals end to end. Learn more here.

Branch names can carry the name of whoever created the branch (All tiers)

Branch name templates support a new %{branch_creator} variable, so branches created from issues can show who created them. Learn more here.

New MCP tools for reading and searching merge requests (All tiers)

AI agents can now fetch a merge request together with its diffs, commits, notes, pipelines, or discussions in a single call, and search merge requests by author, reviewer, state, labels, or free text. Learn more here.

Ultimate only

Malicious package detection in Dependency Scanning (Beta)

Dependency Scanning now checks your dependencies against GitLab malware advisories. Malicious packages appear in the Dependency List and Vulnerability Report with a Malware badge and Critical severity, and they can be blocked before merging with a merge request approval policy. Learn more here.

Advanced SAST for iOS, Kotlin, Dart, and Scala

Advanced SAST now covers Objective-C and Swift (beta), including taint paths that cross between the two languages, as well as Kotlin, Dart and Scala with framework-aware detection for Android, Flutter, Play and Akka code. Learn more here.

GitLab Secret Scanning for Source Code (Beta)

A new GitLab-built analyzer detects passwords and other unstructured secrets that pattern-based rules miss, while using heuristics to keep false positives low. Learn more here.

Automatic revocation for routable personal access tokens

When a leaked GitLab personal access token is found in a public project, automatic revocation now covers all current token formats, not only the legacy one. No configuration change is needed. Learn more here.

Audit events for secret push protection fail-open scenarios

Whenever secret push protection cannot complete a scan and lets a push through, GitLab now records an audit event that can be forwarded to your monitoring tools. Learn more here.

Vulnerability Context Flow

A new flow enriches vulnerabilities with triage context: whether exploitation requires authentication, whether it needs elevated privileges, and whether the affected code handles sensitive data. Learn more here.

Automated Triage and Remediation profile

Instead of enabling false positive detection, vulnerability resolution, and dependency auto-remediation project by project, you can now apply a single profile to a group or project, starting from Conservative, Standard, or Proactive presets. Profiles are currently managed through the GraphQL API. Learn more here.

Execute SAST false positive and vulnerability resolution flows in bulk

Select multiple vulnerabilities in the Vulnerability Report and run SAST Vulnerability Resolution and False Positive Analysis on all of them at once. Learn more here.

Vulnerability tools added to the GitLab MCP server

AI agents can now list and inspect vulnerabilities, dismiss or confirm them, override severity, and create linked issues through the GitLab MCP server. Learn more here.

SAST triage and remediation funnel

A new Security Dashboard funnel shows how critical and high SAST findings move from detection through AI-assisted triage and fix merge requests to resolution over 30, 60, or 90 days. Learn more here.

Redesigned vulnerability details page

The vulnerability details page has a refreshed design that makes reviewing and triaging findings quicker. Learn more here.

Aggregated scanner coverage in the security inventory

The Security Inventory now shows scanner coverage for an entire group hierarchy in one widget, so you can quickly find projects where a scanner is missing, failing, or stale. Learn more here.

Vulnerability Due Date API

Security teams can assign, update, or remove due dates for up to 1,000 vulnerability findings in a single GraphQL request, connecting remediation timelines with existing SLA automation. Learn more here.

SPDX license expressions in dependency and license scanning

Composite licenses such as MIT OR Apache-2.0 are no longer reported as unknown. They are read from CycloneDX SBOMs, included in GitLab’s license data, shown in the Dependency List, and can be allowed or denied by license approval policies. Learn more here.

Dependency scanning support for Bun

Projects using the Bun runtime and package manager are now covered by dependency scanning through their bun.lock files. Learn more here.


Jenkins

This month, the Jenkins core stays on its current version, but under the hood, a lot is happening. As part of our regular plugin maintenance, the plugins on every customer instance move to their latest supported versions: around 150 updates across our managed catalog. For your teams, this means a more secure and stable build environment without any change to how you work day to day. We are also retiring plugins that are deprecated or have known security vulnerabilities without an available fix, including the Blue Ocean plugin family. Your service manager has contacted you, or will contact you shortly, with the details for your instance, the planned dates, and the recommended replacements.


JFrog Artifactory

JFrog Artifactory steps up to version 7.161. This update puts security first, closing several vulnerabilities and tightening access controls, while opening the door to a new generation of AI-related repository types for agent plugins and agent packages. Storage housekeeping also becomes far more precise, with retention policies that can target specific lifecycle stages and paths. On top of that, a new automatic load protection mechanism helps keep the instance responsive when a single client or workload misbehaves.

Deprecations and breaking changes

Breaking change for remote Terraform repositories

Artifactory has hardened the controls on external Terraform URLs. As a result, remote Terraform repositories may return External URL is not allowed errors. If you see this error for a trusted URL, external dependency rewrite has to be enabled for it in the remote repository settings. Reach out to us and we will adjust the configuration for you. Learn more here.

Security hardening for the Docker and OCI Referrers API

The OCI Referrers API now returns 403 Forbidden when the requesting user does not have read permission on the subject image. Automations that relied on retrieving referrers without that permission need read access to the relevant repository path. Learn more here.

Artifactory Access APIs deprecation

The Artifactory REST APIs for managing users, groups, tokens and permissions are being deprecated in favour of the Access REST APIs. The final removal date will be announced later, but we recommend reviewing any automations that use these endpoints now. Learn more here.

AI and new repository types

Support for Agent Plugins repositories

Agent Plugins repositories provide a secure, private registry for plugins used by AI coding agents such as Claude, Cursor and Codex. You can store plugin archives, serve marketplace files and install plugins through the JFrog CLI, keeping AI tooling under the same governance as the rest of your artifacts. Learn more here.

Support for Agent Packages repositories

Agent Packages repositories let teams publish and install agent building blocks, such as skills, prompts, hooks, instructions and MCP server definitions, with the Agent Package Manager client, from one governed location. Learn more here.

Support for LuaRocks repositories

Artifactory now supports LuaRocks in local, remote and virtual repositories, so Lua dependencies can be centralized and resolved from the same platform as everything else. Learn more here.

Retention and cleanup

More precise retention policies

Cleanup and Smart Archiving policies have become much more flexible:

  • Stages: limit a policy to specific lifecycle stages, for example removing old images only from DEV

  • Path patterns: narrow a policy to selected paths within the matching repositories

  • Combined conditions: mix time, property and version criteria in a single policy, so outdated packages are removed while the latest versions are always kept

Learn more here.

Cleanup policies performance improvements for Conan repositories

Cleanup runs on Conan repositories now handle duplicate packages properly and complete reliably instead of stopping midway. Learn more here.

Release Lifecycle Management

Enhanced evidence table and evidence improvements

The evidence table for Release Bundle v2 versions now also shows evidence attached to the artifacts inside the bundle, not only to the bundle itself. Evidence can now be attached to artifacts in remote repositories as well, and a new option controls how conflicts between identical source artifacts are resolved when a Release Bundle is created. Learn more here.

Platform and user experience

Load Healer (automatic load protection)

Load Healer protects Artifactory from overload caused by a single activity, such as one user, one package type, or one API, monopolizing the available worker threads. It monitors thread consumption and, when enabled in reactive mode, throttles only the offending activity with HTTP 429 so that everyone else can keep working. On self-managed deployments, it starts in simulation mode, recording what would have been throttled without blocking anything. We will review the results with you before any protection is switched on. Learn more here.

Increased access control for anonymous users

Administrators can now select exactly which actions non-admin users with manage permissions may grant to anonymous users, helping prevent accidental exposure or privilege escalation. Learn more here.

Markdown view in the Artifacts page

Markdown files can now be viewed rendered directly on the Artifacts page. Learn more here.

All Projects and Set Me Up views show only relevant virtual repositories

The All Projects and Set Me Up views now list only the virtual repositories from your own projects plus global ones, making the lists much shorter and easier to navigate. Permissions are not affected. Learn more here.

Migration tool for NuGet repository normalization

A new Migration Tool moves existing NuGet local, remote and smart remote repositories to the new naming and normalization standards. Each migration starts with a dry run and a report of compliant and non-compliant packages, so nothing changes until you are ready. Learn more here.

Option to change Block Download behavior when Curation is unavailable

A new UI setting lets you choose whether downloads from remote repositories should continue or be blocked when JFrog Curation cannot be reached, balancing business continuity against strict enforcement. Learn more here.

Xray configuration synchronization for Federated repositories

When a new member joins an existing Federated repository, its Xray configuration, including indexing, is now copied from the source repository automatically. Learn more here.

Other improvements to package support

  • Debian remote repositories revalidate cached component files, preventing stale data and hash mismatches

  • Remote NuGet v3 repositories support repository signatures when the upstream registry provides them

  • CocoaPods packages fetched from remote repositories can now use Git submodules

Learn more here.

JFrog Xray

JFrog Xray and Curation advance to version 3.150. The focus of this release is on stopping risky open source packages before they ever reach your developers. Compliant Version Selection is now enabled by default for npm, automatically steering clients towards safe versions instead of simply blocking them, and the new Curation MCP brings this intelligence straight into AI-assisted coding in the IDE. Curation also covers more ecosystems and gains new ways to manage exceptions, while Xray’s scanning and reporting become faster and more informative.

Curation

Compliant Version Selection is now enabled by default for npm

Compliant Version Selection inspects package metadata and automatically resolves npm clients to a version that complies with your policies. It also protects against malicious metadata that could otherwise be downloaded before the package itself. When metadata is blocked, clients receive a 403 error instead of a 404. Learn more here.

Compliant Version Selection for more ecosystems

Compliant Version Selection now also supports:

  • Composer packages

  • Gradle repositories

  • Alpine packages

  • Simple Build Tool (SBT) configurations

Learn more here.

JFrog Curation MCP and waiver management tools

The new JFrog Curation MCP brings security-aware dependency intelligence into AI-assisted coding, helping developers choose safe open source packages while they write code. Additional MCP tools let developers request waivers for blocked packages and check their status from their AI agent, without leaving the IDE. Learn more here.

Time-based waivers

Approved exceptions can now carry an expiration period after which they are revoked automatically, so temporary exceptions no longer linger forever. Learn more here.

Block deprecated or outdated packages

A new Curation condition automatically blocks packages that their upstream repositories mark as deprecated or end of life. It currently supports PyPI, Cargo, RubyGems, Composer, npm, NuGet, Conan and CRAN. Learn more here.

Wider ecosystem coverage

  • Curation now supports Docker Hardened Images (DHI) and Conan 2.0 repositories

  • NVIDIA NIM models are supported in Catalog and Curation policies

  • Maven repositories pointing to Chainguard hardened libraries are recognized automatically and evaluated against Chainguard’s vulnerability data

Learn more here.

Assign custom licenses to packages

You can now assign custom, non-public licenses to packages and package versions, so proprietary or commercially licensed software is classified correctly and license policies apply consistently. Learn more here.

Compliant Version Selection audit enabled by default

The CVS Audit tab is now on by default. It lets you review which packages were evaluated by Compliant Version Selection and request a waiver for required versions that were excluded. Learn more here.

Source code scanning

Managing centralized Git integrations has become simpler: custom profiles can be removed from the UI, GitHub App repository lists use a paginated table that scales to large organizations, Source Code APIs return findings from the latest scan of each repository, branch or commit, and Frogbot scan settings can be configured per repository. Learn more here.

Xray scanning and UI improvements

  • Impact Search supports package-name-only queries, version ranges, Catalog labels and autocomplete for CVE and Xray IDs

  • Helm OCI repositories can now be indexed and scanned

  • Base image tag information is included in SBOM and security reports, and base image components can be excluded from exports and policy violations

  • Vulnerability report exports include publisher date and JFrog Research severity justification

  • Faster vulnerability matching and impact analysis, plus accessibility improvements across the UI

Learn more here.

SonarQube Community Build

SonarQube Community Build moves to version 26.9, and yes, dark mode has finally arrived! Beyond the new look, this release adds support for Go 1.27, sharper Infrastructure as Code and secrets detection, and a new metric that shows how much new code each change really contains. It also rolls up last month’s 26.8 release, which brought a large batch of new rules for Java, JavaScript/TypeScript, Vue and Python.

Deprecations and removals

Migration of existing Security Hotspots to issues

Security Hotspots are being phased out. Rules that used to raise hotspots now raise vulnerabilities (Standard Experience) or security issues (MQR Mode), and existing hotspots can be converted in place, keeping their history, comments and assignees. In a future release, this migration will run automatically during the upgrade. We will plan the conversion of your existing hotspots with you ahead of time. Learn more here.

Java 17 support for SonarScanners has been removed

Scanners now require Java 21 or newer. Pipelines that use JRE auto-provisioning (the default for supported scanners) need no changes, but builds that run scanners on a fixed Java 17 runtime must be upgraded. Learn more here.

Languages

Go

Go 1.27 is now supported, and the Cognitive Complexity rule now understands Go’s idiomatic error-checking pattern. Learn more here.

Infrastructure as Code

False positives have been reduced for Terraform resources declared with count or for_each and for several Azure and Google Cloud configurations, and clear-text protocol detection for Kubernetes has been refined. Learn more here.

Secrets

Secret detection now also finds JSON Web Tokens, HTTP authentication credentials, and private keys without standard PEM armor, with fewer false positives on test tokens and encrypted values. In addition, detected secret values are now masked in Web API responses, so the secret itself is no longer exposed when source code is viewed through the API. Learn more here.

Language improvements from 26.8

Version 26.8 brought improvements across many languages:

  • Java: new rules for Jakarta EE, JPA, Quarkus, Spring and Mockito

  • JavaScript, TypeScript and CSS: new rules for Testing Library, Vitest and browser-driven UI tests, and extended Vue support

  • Python: new rules for Pydantic and for test code

  • .NET / C#: selected rules now also detect issues in Entity Framework query chains

  • HTML, IaC, Secrets and XML: fewer false positives and improved detection in existing rules

Learn more here.

New lines of code metric

A new New lines of code measure reports the size of the new code period. It appears on project cards, in pull request and branch summaries and on the Measures page, and it sizes the new code treemaps, making it easier to judge how big a change really is. Learn more here.

Dark mode

Dark mode is now available. To switch it on:

  1. Open your account menu and go to My account > Appearance.

  2. Select Dark theme, Light theme or Sync with system.

Learn more here.

Project history storage

SonarQube Community Build now stores project history to support upcoming features. The retention period can be adjusted in Administration > Configuration > General settings > Housekeeping. Learn more here.

SonarQube Server

SonarQube Server advances to version 2026.4, a release built for a world where more and more code is written with the help of AI. A new built-in quality gate is tuned specifically for agentic development, severity-based conditions let you stop risky changes precisely, and a quality gate history shows whether your gates are really holding release after release. Compliance-minded teams get a dedicated EU Cyber Resilience Act report, while architecture analysis, faster pull request scans and a long list of improved rules round out the package.

Deprecations and removals

Deprecation of Security Hotspots

Security Hotspots are deprecated to simplify how findings are classified. Rules that previously raised hotspots now raise vulnerabilities (Standard Experience) or security issues (MQR Mode). Existing hotspots remain visible on the Security Hotspots page for now, and we will plan their migration with you. Learn more here.

Java 17 support for SonarScanners has been removed

Scanners now require Java 21 or newer. If you use JRE auto-provisioning (enabled by default on supported scanners), no action is needed. Otherwise, the scanner runtime in your pipelines must be upgraded. Learn more here.

Sonar way for agentic AI quality gate

A new built-in quality gate, Sonar way for agentic AI, is calibrated for AI-assisted and agentic development. It is stricter on security, reliability and risky new dependencies, and more relaxed on minor maintainability issues that do not carry real risk. The previous Sonar way for AI Code gate is kept as a custom gate with its existing assignments. Learn more here.

Quality gate history

A new Quality gate history page shows how a project’s quality gate verdict evolved across released versions on the main branch. Each release is marked as safe or risky, so you can see immediately when code shipped despite a failing gate. Learn more here.

Severity-based quality gate conditions for new code

Quality gates can now fail when new code introduces an issue at or above a chosen severity. The underlying metrics update live when issue severities change, without a re-analysis. Learn more here.

EU Cyber Resilience Act security report

A new security report maps findings to the requirements of the EU Cyber Resilience Act and adds a matching entry to the Security Category facet, helping teams demonstrate compliance directly from SonarQube. Available in Enterprise edition and higher. Learn more here.

Software architecture analysis

Architecture analysis is now part of SonarQube Server and runs with every scan, with no extra configuration, for Java, C#, JavaScript, TypeScript and Python. It covers:

  • Current architecture: a visual model of your project’s structure and dependencies

  • Intended architecture: rules for which components may depend on each other, with deviations raised as issues

  • Structural problems: automatic detection of tangles, oversized components and split responsibilities

Learn more here.

Automated GitHub App creation

Connecting SonarQube to GitHub no longer requires creating a GitHub App by hand. A guided flow pre-configures the required permissions, webhook and callback URLs and saves the resulting credentials automatically. It works with both GitHub.com and GitHub Enterprise Server. Learn more here.

Consistent new code fallback for reference branch analysis

When the reference branch's new code definition is used, and Git history is missing, for example, on shallow clones, new code is now calculated consistently from the first analysis onwards, removing fluctuating results between runs. Learn more here.

Faster pull request analysis for large Java and C# projects

Incremental taint analysis considerably shortens pull request analysis on large and complex Java and C# projects, which previously took the longest to scan. Learn more here.

New MISRA C compliance quality profiles

New Sonar MISRA compliance quality profiles combine Sonar way with rules mapped one-to-one to the MISRA C:2012 (including amendments) and MISRA C:2023 guidelines. New rule tags make it easy to build your own MISRA profiles. Available in Enterprise edition and higher. Learn more here.

External issue import with overlapping start and end locations

Externally generated reports that point to a single position in the code, with the same start and end columns, can now be imported and displayed correctly. Learn more here.

Languages

Gosu (new)

SonarQube Server now supports Gosu, the language of the Guidewire platform widely used in the insurance sector, with parsing, syntax highlighting, metrics and an initial set of rules. Learn more here.

PostgreSQL (new)

The PostgreSQL SQL dialect, including PL/pgSQL, can now be analysed with an initial set of rules covering correctness, security and maintainability. Learn more here.

Improvements to other languages

  • Java: new rules for date and time APIs, Quarkus, JPA and Bean Validation; analysis no longer fails when binaries are missing

  • JavaScript, TypeScript and CSS: new rules for testing practices, Lodash and Vue, plus detection of generated code

  • Python: new rules for testing, Pydantic and Beautiful Soup, and fewer main-code issues raised on test files

  • C# and VB.NET: a new rule and improvements to existing ones

  • HTML: a new rule to enforce allowed values of the lang attribute

  • PL/SQL and T-SQL: settings grouped under a shared SQL category

  • Secrets: customizable file exclusions, better test-file detection and performance

  • Infrastructure as Code: new rules for AWS RDS, Azure Key Vault and Google Cloud Storage

Learn more here.

SonarQube Server LTA

Customers on the Long-Term Active release move to version 2026.1.5. This is a maintenance update that contains security fixes only, keeping your LTA installation protected without any functional changes. Learn more here.

Sonatype Nexus Repository

Sonatype Nexus Repository advances to version 3.96, rolling up three releases of improvements. The most visible change is the modern Nexus One UI, which now covers almost every administrative task, from security settings and LDAP to audit logs and user management. Docker users benefit from native OCI repositories, private Amazon ECR proxying and faster handling of large image catalogs. Add support for new formats, direct downloads from Azure Blob Storage and smaller npm metadata responses, and the result is a noticeably faster and more capable repository manager.

Nexus One UI

Improvements to the Nexus One UI

The Nexus One UI now fully supports task management, so all supported task types can be configured, scheduled, run and monitored without switching back to the classic interface. Navigation, search, dashboards, browsing and accessibility have also been refined throughout. Learn more here.

Administration and security in the Nexus One UI

Version 3.96 moves a large set of administration workflows into the Nexus One UI:

  • OAuth2 and SSL certificate management, with better validation and certificate inspection

  • LDAP and Atlassian Crowd configuration, including connection testing and user mapping checks

  • Streamlined user management, combining profile, roles and an interactive view of effective privileges on one page

  • Audit log, a dedicated page to browse and filter configuration and security events, with configurable retention

  • Component details, with faster version browsing and format-aware dependency snippets

  • Community Edition usage visibility, with clearer usage alerts and metrics

Learn more here.

Docker and OCI

Support for OCI repositories

Nexus Repository now supports native Open Container Initiative (OCI) repositories for storing and proxying OCI artifacts alongside Docker images. Learn more here.

Proxy private Amazon ECR registries

Docker proxy repositories can now proxy private Amazon Elastic Container Registry (ECR) registries. Since 3.95, they also accept temporary AWS credentials issued by AWS STS or IAM Identity Center, in addition to long-lived access keys. Learn more here.

Improved Docker repository management and performance

Managing Docker repositories has become easier, the Docker registry experience has been polished, and Docker proxy repositories handle very large image catalogs noticeably faster. Learn more here.

Repository formats

Composer hosted and group repositories

Alongside proxy support, you can now host your own PHP Composer packages and combine hosted and proxy repositories behind a single group repository. Learn more here.

NuGet support for Chocolatey and Microsoft Symbol Server

NuGet repositories can now host and proxy Chocolatey packages and serve .NET symbol packages through the Microsoft Symbol Server protocol, so debuggers can download PDB files on demand. Learn more here.

Hugging Face and PyPI improvements

Hugging Face proxy repositories support the latest huggingface_hub client workflows and Bearer token authentication. PyPI proxy repositories gain repository-specific URL encoding and preemptive authentication, which makes proxying private registries, such as GitLab-hosted PyPI repositories, much more reliable. Learn more here.

Improved chained proxy support

OCI, Pub, Ansible Galaxy, Hugging Face, Terraform and Conda repositories now work more reliably when one Nexus instance proxies content through another, which is common in tiered or air-gapped networks. Learn more here.

Updated defaults for Conan and better Terraform compatibility

Conan proxy repositories come with updated default settings, and Terraform proxy repositories offer improved compatibility with upstream registries. Learn more here.

Simplified URL encoding configuration for proxy repositories

URL encoding for proxy repositories is now simpler to configure, which helps with upstream registries that expect special characters to be encoded in a particular way. Learn more here.

Performance and storage

Azure Direct Download for Azure Blob Stores

Nexus Repository Pro can now redirect clients to download artifacts directly from Azure Blob Storage using short-lived SAS URLs, reducing load on the Nexus server and improving throughput. If a direct link cannot be created, downloads automatically fall back to the standard path. Learn more here.

npm abbreviated packument support for faster installs

npm clients can now receive the abbreviated package metadata format, and npm JSON responses can be gzip-compressed. For packages with many versions, metadata payloads shrink by up to 89%, speeding up installs and reducing bandwidth. Learn more here.

POM metadata size protection for Maven repositories

The name and description fields stored from Maven POM files are now limited to 10,000 characters, protecting repository metadata from excessively large values. Learn more here.

Security and platform

Immediate session invalidation on password change

When a user’s password is changed, all of their existing sessions are now invalidated immediately. Learn more here.

Java EE 10 upgrade

The platform has been upgraded to Java EE 10, modernizing the underlying infrastructure and keeping its dependencies supported and secure. Learn more here.


That’s all for October! See you in November!

  • Eficode ROOT

Subscribe to our newsletter