Apache Release Notes

Follow

457 release notes curated from 279 sources by the Releasebot Team. Last updated: Oct 3, 2026

Get this feed:

Apache Products

  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 3, 2026
    Apache logo

    Airflow by Apache

    providers-edge3/5.0.0rc2

    Airflow releases providers update for 2026-10-02.

    Release 2026-10-02 of providers

    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 3, 2026
    Apache logo

    Airflow by Apache

    providers-duckdb/0.2.0rc1

    Airflow releases provider updates for 2026-10-02.

    Release 2026-10-02 of providers

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Apache and hundreds of other software products.

    Create account
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 3, 2026
    Apache logo

    Airflow by Apache

    providers-cncf-kubernetes/10.23.0rc2

    Airflow releases provider updates in Release 2026-10-02 of providers.

    Release 2026-10-02 of providers

    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 3, 2026
    Apache logo

    Airflow by Apache

    providers/2026-10-02

    Airflow tags provider releases for 2026-10-02.

    Tag providers for 2026-10-02

    Original source
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Kafka by Apache

    Apache Kafka 4.2.2 Release Announcement

    Kafka releases Apache Kafka 4.2.2 as a bugfix update with several critical fixes, bringing important maintenance improvements and upgrade guidance for users moving from earlier versions.

    We are proud to announce the release of Apache Kafka 4.2.2. This is a bugfix release that includes several critical fixes. For a full list of changes, be sure to check the release notes.

    See the Upgrading to 4.2.2 from any version 0.8.x through 4.2.1 section in the documentation for the list of notable changes and detailed upgrade steps.

    Summary

    This was a community effort, so thank you to everyone who contributed to this release, including all our users and our 43 contributors: Adam Souquières, Alan Lau, Alieh Saeedi, Alyssa Huang, Andrew Schofield, Apoorv Mittal, Bill Bejeck, Chia-Ping Tsai, Chris Egerton, David Jacot, Dongnuo Lyu, Eswarar Siva, Evan Zhou, Federico Valeri, Gabriella Fu, Gaurav Narula, Gergely Harmadas, Izzy Harker, Kaixuan Li, Ken Huang, Kevin Wu, Kuan-Po Tseng, Lianet Magrans, Lucas Brutschy, Lucy Liu, Luke Chen, Manikumar Reddy, Matthias J. Sax, Mickael Maison, Mingi Cho, Nick Telford, Nilesh Kumar, Omnia Ibrahim, PoAn Yang, Sean Quah, Sepuri Sai Krishna, Shay Elkin, Srinivas Akhil Mallela, TengYao Chi, Truc Nguyen, Uladzislau Blok, Zheguang Zhao, zhiyan-tang

    Original source
  • Similar to Apache with recent updates:

  • Sep 28, 2026
    • Date parsed from source:
      Sep 28, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    Safer file editing, instant workspaces, and GPT-6

    Superset adds safer file editing, instant workspace startup, GPT-6 and Claude Opus 5.5 model support, and Superset Mobile for iPhone. It also improves GitHub repo setup, Slack page links, page watching, and several editor, terminal, and workspace fixes.

    Safer File Editing #7711 #7693 #7692

    Safer File Editing

    Edit files next to your agents without losing work when a script or agent changes the same file.

    • A banner tells you when the file changed on disk, with Compare to see both versions side by side
    • Save conflicts offer Keep editing, Reload from disk, or Overwrite file, instead of silently replacing the newer version
    • Turn on auto save after a delay, on focus change, or on window change in Settings → General, contributed by @theblondealex
    • Double-click to rename and drag to move files in the file tree, contributed by @theblondealex

    Editor banner saying the file changed on disk, with a Compare link

    Docs: Editor.

    Workspaces Start Instantly #7518

    Workspaces Start Instantly

    New workspaces and sessions open in about a second instead of waiting 5 to 20 seconds for an agent to name them. Your agent starts right away, and a name arrives a few seconds later.

    • Linked GitHub issues and pull requests in your prompt help pick the name
    • Questions and short prompts get a name too, refined after the agent's first reply
    • Renaming a workspace yourself always wins

    Docs: Workspaces.

    GPT-6 and Claude Opus 5.5 #7741 #7783 #7894

    GPT-6 and Claude Opus 5.5

    Pick GPT-6 Astra, Sol, or Luna and Claude Opus 5.5 from the model picker when you start an agent, contributed by @haydenfd.

    • GPT-6 works in Codex, OpenCode, and OMP, with Ultra effort on GPT-6 Astra in Codex
    • Usage tracks costs for the new models
    • Retired models no longer show up in the picker

    Superset for iPhone Is on the App Store

    Superset Mobile is live. Check on your agents, review diffs, and read Pages from your phone. Get it from the App Store or read the launch post.

    Superset Mobile running a coding agent on an iPhone

    • Setup in Settings → Mobile is now two steps with Remote Access turned on in place #7697
    • The app tells a computer that never connected apart from one that went offline, and says what to do next #7661
    • The ⋯ menu on a workspace can rename, pin, share, or delete it, and workspace details list its pull requests #7816 #7782

    Mobile settings with a QR code to install the app and a Remote Access toggle

    Improvements

    • Clone from your GitHub repositories - search the repositories your GitHub login can reach when you add a project, contributed by @theblondealex #7694
    • Sign in without leaving Settings - sign in to Claude Code and Codex accounts from a terminal inside Settings → Usage #7740
    • Page links unfurl in Slack - posted page links show a title and preview to people who can open them #7817 #7821
    • Stop a page watcher - stop an agent watching a page from its row in the watcher menu; public pages show a globe on the Share button #7820 #7766
    • Rejoin the leaderboard with your full history - choose to publish everything since launch or the last 30 days #7651
    • Google Calendar triggers removed - nobody used them; Gmail triggers stay #7796
    • Desktop 1.29.0 or later is required - older versions show an update screen #7786

    Bug fixes

    • Continue with another agent now carries over the whole Claude conversation, not only the last few seconds #7825
    • Copying from a rendered preview copies the text instead of Markdown, contributed by @andyst-dev #7591
    • Terminal copies trim trailing whitespace like Ghostty, contributed by @nrutman #7709 #7868
    • Terminal file links jump to their line and column, and URLs stop at their real end #7712 #7717
    • Agents keep paste mode after a host restart #7691
    • The sidebar keeps its order and group members, keyboard navigation includes pinned workspaces (contributed by @Ymirke), and you can drop rows beside workspace pills #7723 #7851 #7833
    • Clicking a tab's close button no longer starts a drag #7714
    • Long session names and dialog text wrap instead of overflowing, contributed by @Official-Krish and @kotaesaki #7707 #7837
    • Links on a page open without blanking it, and opening a page no longer switches workspaces #7718 #7790
    • Symlinked files open in the viewer, and managed configs update the file a symlink points to instead of replacing the link #7696 #7897
    • Diffs no longer run custom Git text filters #7903
    • Team review requests show without extra GitHub permissions #7788
    • Large repositories with many ignore rules load files faster, contributed by @allthehatz #7860
    • Fixed the Notion plugin failing to connect #7727
    Original source
  • Sep 26, 2026
    • Date parsed from source:
      Sep 26, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    fix(host-service): hand the whole Claude conversation to another agent

    Superset improves agent handoffs by carrying full Claude and Codex conversation context from trusted session files instead of just recent terminal output, with safer path lookup, graceful fallbacks, worker-based reads, and updated docs for compatibility and limitations.

    Summary

    • Continue with another agent now carries over the Claude conversation, not just the last ~30 seconds. Reported in Slack; native Fork session was never affected.
    • The host now opens Claude's session file at the path Claude's own hook reports. It falls back to Claude's folder-naming scheme, then to a search by session ID, so a future Claude change degrades gracefully and logs a warning.
    • Documented in docs/agent-session-handoff.md: where transcripts come from, the lookup order, trust rules and compatibility.

    Why / Context

    The handoff prefers Claude's session JSONL and falls back to the terminal's 2 MB output ring. A Claude TUI fills that ring in under a minute. Two bugs sent Claude sources to the ring, or thinned the transcript:

    1. Wrong folder name. We encoded only / and .. Claude Code 2.1.282 (checked in its binary and with real runs) NFC-normalizes the path, resolves symlinks, replaces every non-alphanumeric UTF-16 unit with -, and hashes names past 200 characters. Any worktree with _, a space or @ missed the file. This matches the report: fork preflight treats a missing folder as "unknown" and lets the fork through.
    2. Fixed 4 MB tail. Real sessions run 40–80 MB, mostly tool output and screenshots. A 48 MB session with 25k characters of conversation, well under the 36k budget, handed over only its last 6 of 35 turns.

    How It Works

    • Hook → host: notify hook v20 forwards transcript_path on main-session events. notifications.hook stores it in the new nullable column terminal_agent_bindings.transcript_path, only when isTrustedTranscriptPath accepts it (absolute, .jsonl, under home) and only while the binding still names that session. The endpoint is unauthenticated.
    • Lookup (readHarnessTranscript), in order:
      1. The reported path, used only if the store's isSessionFile says it names the bound session.
      2. The store's files.locate. For Claude that is a copy of its naming scheme (claudeProjectDirName), then a search of projects/*/.jsonl, capped at 5,000 folders.
        • If nothing is found, it logs [harness-sessions] no transcript for … session … .
    • Read: starts with the last 4 MB and widens ×4 until the conversation fills the budget or the file ends. It stops at 128 MB, since it runs synchronously on the host's main loop, and keeps the last good read if a wider one fails.
    • Resume and fork preflight (hasHarnessSession) ignore the reported path and answer only for the env the relaunch will use.

    Code layout (second commit, refactor:)

    All under packages/host-service/src/terminal-agents/:

    File Owns harness-sessions/index.ts The HARNESS_SESSION_STORES registry, the lookup order, the reported-path check, readHarnessTranscript, hasHarnessSession harness-sessions/{claude,codex,opencode,pi}.ts One HarnessSessionStore each, moved out of the old terminal/harness-transcript.ts switch harness-sessions/tail.ts The bounded, widening tail read harness-session-ref.ts terminalHarnessSession: one ref per terminal for the handoff, agents read, and resume. The harness comes from the binding, so a custom agent wrapping claude still reads Claude's store agent-config.ts resolveHostAgentConfig + agentLaunchEnv, moved out of the agents router, so the launch and every lookup share one env. Previously agents read missed per-agent CLAUDE_CONFIG_DIR transcript-path.ts isTrustedTranscriptPath, now shared by the subagent roster and the main session

    To add a transcript reader for another harness (e.g. Codex rollouts), give its store files: { isSessionFile, locate, parseTurns }. The hook already forwards transcript_path, and the trust check, lookup order and bounded read come for free. See "Adding a harness" in the doc.

    The subagent pane keeps its own parsers in subagent-harnesses/. They clip each entry for display, which a handoff must not do.

    Compatibility

    Combination Behaviour Old hook (≤ v19) → new host No path sent. Lookup starts at the store's locate New hook → old host zod strips the unknown field. No change Rows created before migration 0036 Column is null until that session's next hook event Migration ALTER TABLE … ADD transcript_path text: nullable, no rebuild, no backfill

    Manual QA Checklist

    • Real sessions under ~/.claude/projects (39–81 MB): 11–69 ms per read. Sessions whose conversation is under 36k characters come through complete from the first turn.
    • Real claude -p runs in folders with _, spaces, @, é, CJK, emoji, a decomposed accent, a symlink, and a path over 200 characters. Our folder names matched Claude's, and the reader found each session. Test folders were cleaned up.
    • Not done: an end-to-end handoff in the desktop app over CDP.

    Testing

    • bun test src in host-service: 1,755 pass, 0 fail. Repo-wide lint and typecheck (42/42 packages) pass.
    • bun test src in shared: 1,110 pass.
    • bun test in agent-setup: 373 pass. Five tests fail inside a Superset terminal because SUPERSET_ACCOUNT_ATTRIBUTION_TOKEN and SUPERSET_AGENT_LAUNCH_ID leak in from the environment. This predates the PR; they pass with those unset.
    • bun run typecheck passes in host-service and agent-setup.
    • bunx biome check is clean on all changed files.
    • New tests: lookup order; folder-name encoding (non-English characters, the 200/201 boundary, symlinks); widening past megabytes of tool output; cuts through multi-byte characters; files that shrink during a read; a failed wider read; stored-path trust and session scoping; the stored path surviving later events; the hook payload. Each safeguard was reverted once to confirm its test fails.

    Checked against Orca's tests

    Compared with Orca's tested equivalents: claude-project-dir-encoding, session-file-resolver and its Claude-roots suite, and agent-session-fork-context. The third commit closes the gaps:

    • The hook's transcript_path wins even when the file UUID differs from session_id: Fixed. We no longer require .jsonl. The stored path is cleared when the binding's session changes and re-checked as trusted when read. Your 400 most recent Claude files all match their id, so this guards other versions
    • Search CLAUDE_CONFIG_DIR, then the default ~/.claude; prefer the config dir; de-dupe: Fixed for reading. The resume/fork check keeps to the relaunch's folder, matching Orca's "explicit root, no fallback" rule
    • Trailing separators dropped, a bare root kept: Fixed
    • A blank CLAUDE_CONFIG_DIR counts as unset: Already handled; test added
    • Glob .jsonl across project folders; a missing or non-.jsonl reported path falls back: Already handled; tests added
    • Keep the newest text, fence collisions, empty after cleanup, large captures: Already covered
    • A cut must not split a character: Fixed: a cut inside one long line no longer starts on half of an emoji
    • Prompt size: Checked that the worst case (CJK) is 107,592 bytes, under Linux's 131,072-byte per-argument limit, and pinned it with a test
    • Workspace forks, SSH/WSL quoting, clipboard fallback: Not applicable: Superset has no such paths

    Each fix has a test that fails without it.

    Codex sources (fourth commit)

    A handoff from a Codex terminal used to read the 2 MB terminal buffer, so it also got only ~30 seconds. The Codex store can now be read too. Its native hooks already report transcript_path, so the reported path is used first. Without one, locate walks sessions/YYYY/MM/DD newest first for rollout-*-.jsonl (Orca's id-suffix rule), checking CODEX_HOME and then ~/.codex.

    parseTurns reads both rollout layouts: items wrapped in response_item, and the bare items 2025 rollouts wrote. It skips the setup Codex sends as user messages. A survey of 300 real rollouts found four kinds: AGENTS.md, , and . is also skipped.

    Real rollouts of 123, 106 and 89 MB read in 78, 65 and 51 ms, each starting at the first real prompt. Each safeguard has a test that fails without it.

    Review hardening (fifth commit)

    • The reported file must name its session. The hook endpoint is unauthenticated, so a reported path is read only when its first megabyte contains the bound session ID. Every Claude line and Codex's session_meta line carry it. This stops a caller that knows a binding from pointing a handoff at another transcript.
    • An unreadable store no longer fails the dialog. If the lookup throws, it's logged and the handoff falls back to the terminal buffer.
    • One file descriptor per read. Widening now reads through a single descriptor and stops on a short read, so a file rewritten mid-read can't splice two files into one line.
    • Codex revert files. Rollouts named _.jsonl are matched, and the newest one is read.

    Off the event loop (latest commit)

    The session read now runs as a host worker task, harness/readTranscript. transcriptSession and agents read await it, and a failure answers null, so the handoff falls back to the terminal buffer.

    The resume and fork check stays on the event loop, because OpenCode's store is SQLite, a native module. A test walks the task's import graph so that no native module can reach the worker.

    On a real 123 MB Codex rollout:

    • On the worker, the read took 104 ms, and the main thread's longest stall was 11 ms.
    • Run inline, it blocked the main thread for the full 74 ms.

    End-to-end in the desktop app

    The dev desktop app ran on this branch, driven over CDP with real mouse clicks and key presses. The agents were real: Claude Code 2.1.283 and Codex. The workspace path was /private/tmp/…/handoff_e2e repo, which has a space and an underscore and resolves through the /tmp symlink.

    1. Claude turns. Turn 1 set the code word PELICAN-7731. Turn 2 wrote notes.txt (GRANITE-4402) and ran a Bash command.
      • The binding's transcript_path was filled by Claude's hook through notify v20.
      • Claude wrote the session under …-handoff-e2e-repo. The old encoding would have looked in …-handoff_e2e repo, which does not exist, and fallen back to the terminal buffer.
    2. Claude → Codex, through the fork menu, Continue with another agent…, Codex, Split pane.
      • The dialog showed "Sends 325 characters". terminal.transcript answered source: "harness" with both turns from the first prompt.
      • Codex's pane received the full prompt and verified notes.txt. Asked "What was the code word?", it answered PELICAN-7731, which exists only in the carried context.
    3. Codex → Claude, from the Codex pane.
      • The Codex binding carried its hook-reported rollout path, and the new Codex reader answered source: "harness" (1,405 characters).
      • The transcript left out the block that the rollout contains.
      • The new Claude pane received it and summarised the earlier sessions, including PELICAN-7731.

    The host log shows no inline-worker fallback. The test workspace and project were destroyed afterwards.

    Known Limitations

    • Handoffs are still capped at 36,000 characters (about 10k tokens), so very long conversations keep only their recent part. A larger inline prompt runs into Linux's 128 KB limit on a single argument. Handing over everything would mean writing the transcript to a file for the new agent to read.
    • OpenCode, pi and other agents have no session-file reader and still hand off from the terminal buffer. A compressed Codex rollout (.jsonl.zst) counts as the session for resume and fork, but a handoff can't read it.
    • Resume and fork preflight deliberately ignore the stored path (see How It Works).

    Risks / Rollout

    • Risk: conflicts with fix(desktop): recover Codex fork sessions and preserve source accounts #7687.
      • Migration 0036 collides with its 0036_persist_terminal_session_home. Whichever PR merges second must regenerate its migration with drizzle-kit, not hand-edit it.
      • Its .jsonl.zst change to hasCodexRollout now belongs in harness-sessions/codex.ts.
      • Its fork-preflight edits in agents.ts should call agentLaunchEnv.
    • Rollback: revert the PR. The column is nullable and unused by older code, so leaving it behind is harmless.

    Summary by cubic

    Fixes the "Continue with another agent" handoff so Claude and Codex terminals carry the full conversation from the harness's own session file, up to the 36,000-character cap, instead of only the last ~30 seconds of terminal output.

    • Two bugs thinned or skipped Claude transcripts: folder-name encoding replaced only / and . (so worktrees with spaces, @, or _ missed the file), and a fixed 4 MB tail dropped most turns behind tool output in 40–80 MB sessions. The read now widens until the budget is met, reads each byte once, keeps one file descriptor, and never splits a multi-byte character.
    • The notify hook (v20) forwards transcript_path; the host stores it in the new nullable terminal_agent_bindings.transcript_path (migration 0036) only under home and only while the binding still names that session. A reported path is read only when its first megabyte names the bound session id, and a lookup that throws falls back to the terminal stream.
    • Session lookup is one store per harness (claude, codex, opencode, pi) behind a shared lookup, so a custom agent wrapping claude still reads Claude's store and adding a reader is one file. Launch and session lookups share one resolved agent config and env, so the CLI now reads per-agent CLAUDE_CONFIG_DIR and CODEX_HOME; fork preflight never refuses on a capped scan.
    • A Codex store walks CODEX_HOME sessions newest first for rollout-*-.jsonl, handles both rollout layouts, and skips the setup Codex sends as user turns.
    • The session read runs on a host worker (harness/readTranscript); on a 123 MB Codex rollout it took 104 ms with the main thread's longest stall at 11 ms, against a 74 ms full block inline when run on the event loop.

    Written for commit 2daffbc. Summary will update on new commits.

    Summary by CodeRabbit

    • New Features
      • Agent handoffs can include recent conversation transcript context for supported harnesses, up to 400,000 characters.
      • Transcript lookup uses trusted paths reported by the agent or searches known session locations. Unavailable or untrusted transcripts are omitted.
      • Main-session notifications can pass along transcript paths for session-specific lookup.
    • Bug Fixes
      • Transcript excerpts and handoff prompts avoid cutting emoji in half and stay within the handoff size limit.
    • Documentation
      • Added guidance on transcript context in agent handoffs, supported harnesses, compatibility, and limitations.
    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    feat(mobile): workspace header ⋯ is a menu, with Delete back in it - #7816

    Superset restores the mobile workspace header ⋯ as a native menu, bringing back Delete workspace and grouping details, rename, pin or unpin, mark unread, copy link or ID, and share. It also swaps the unread icon to a bell in the menu and home row.

    Why

    #7782 dropped Delete from the workspace sheet, which left no way to delete a workspace from its own screen on mobile. The header's ⋯ button only opened the sheet, so the menu it should have been was sparse.

    What

    The ⋯ in the workspace header is now a native menu, grouped like the reference (Cursor's chat menu):

    • Workspace details, Rename, Pin / Unpin, Mark as Unread
    • Copy (submenu: Copy link, Copy ID), Share
    • Delete workspace (destructive)

    Every item reuses a handler that already exists. Rename, share, copy and delete come from useWorkspaceHeaderActions; deleteWorkspace is the handler #7782 removed, restored as it was. Pin reads the pinned store. Mark as Unread sets the manual mark, which opening the screen normally clears, so it holds until you leave. Copies thread the screen's onCopied so the header's "Copied" pill confirms them.

    The unread icon is a bell on this menu and on the home row's long-press menu, in place of the envelope.

    Verified

    iPhone 17 Pro Max simulator, iOS 26, against production, driven by Maestro through the real menu:

    • Menu and Copy submenu render with the separators.
    • Pin flips the item to Unpin and back.
    • Copy link and Copy ID put the right values on the pasteboard, with the "Copied" pill.
    • Delete workspace shows its confirm (cancelled, nothing deleted).

    Screenshots:
    https://app.superset.sh/page/mobile-workspace-delete-is-back-63kapj

    The home row's bell swap is an icon-name change only and was not rendered.

    Lint, typecheck (all packages), mobile tests via turbo, and check:i18n are clean; every string already had translations.

    Summary by cubic

    Turns the workspace header ⋯ into a native menu, restoring Delete workspace on mobile.

    • Groups actions like Cursor's chat menu: details, rename, pin/unpin, mark unread, copy (link/ID) and share, then delete.
    • Restores the deleteWorkspace handler that #7782 removed; delete leaves for the list once confirmed.
    • Copy actions thread the screen's copied callback so the "Copied" pill confirms them.
    • Marks the unread icon as a bell in both the header menu and the home row's long-press menu.

    Written for commit 89e012e. Summary will update on new commits.

    Review in cubic

    Summary by CodeRabbit

    • New Features
      • Expanded the workspace toolbar menu with shortcuts to view details, rename, pin or unpin, mark as unread, copy the workspace link or ID, share, and delete the workspace.
    • Updates
      • Updated the Mark as Read/Unread menu icons to use bell icons instead of envelope icons.

    Additional notes from review comments:

    • Navigate home only after deletion succeeds. The base WorkspaceActionsSheet did not expose a Delete action. The new toolbar Delete action calls useDeleteWorkspace with router.dismissTo(...) as its confirmation callback. useDeleteWorkspace invokes that callback before destroy(false) runs. If the host deletion fails while the workspace remains in the list, the hook shows “Delete failed” after the user has already returned home. Invoke navigation only after the deletion path establishes success.
    • Provide an Android icon for the workspace menu. On Android, Expo Router 57 silently drops the SF Symbol string used for this menu’s ellipsis icon. The new toolbar control therefore has no visible icon. Its action icons also disappear. Supply Android image sources for the menu root and action icons while keeping SF Symbols on iOS. (https://docs.expo.dev)
    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    feat(slack): unfurl page links as the poster

    Superset now previews shared page links in Slack instead of dropping them, showing a work object with thumbnail, description, creator, and update time. Access-aware unfurls work for public, org, and just_me pages, and linked setup now reconnects non-public page shares smoothly.

    Why

    The Superset Slack app registers app.superset.sh in unfurl_domains, so Slack suppresses its own OpenGraph preview for every link on that domain and sends the app link_shared instead. The handler only recognised /tasks/ ; page links were logged and dropped (confirmed in prod logs for team T09Q9C3Q41Y). That is why neither org pages nor public pages unfurl in Slack today, regardless of the og tags the web app serves.

    What

    • @superset/trpc/page-preview : pagePreview({ slug, organizationId, userId? }) resolves what a link may show outside the app. Public pages preview for anyone; org pages need the poster's linked Superset user and org membership; just_me pages need the creator. Anything else is missing , never the title. The thumbnail URL carries a version-bound ticket so org pages work without opening the usercontent origin.
    • page-work-object : a slack#/entities/content_item Work Object with preview image, description, created_by and date_updated .
    • process-link-shared : unfurlLinks() handles tasks and pages in one pass. An unlinked poster who shares a non-public page gets Slack's user_auth_required prompt pointing at the existing connect URL, which now carries { channel, ts, url } ; the link route unfurls that message right after upsertIdentity .
    • Home tab copy mentions page links.

    Verification

    • bun run typecheck in apps/api and packages/trpc : clean.
    • bun test for the Slack handlers plus the new preview.test.ts and page-work-object.test.ts : 129 pass.
    • Not yet verified in Slack: Slack posts events to the production API, so this needs a deploy. Two things to watch on the first real unfurl: whether the content_item preview image renders, and whether Slack accepts unfurls: {} alongside user_auth_required . If the image does not render, the fallback is a legacy unfurls blocks payload with an image block.

    Summary by cubic

    Pages shared in Slack now unfurl with a preview instead of being dropped. Previously the link_shared handler only recognized task links and logged page links away, which is why even public pages showed as bare URLs. Pages now render as a slack#/entities/content_item work object with the captured thumbnail, description, creator, and last update.

    New Features

    • Preview access is per poster: public pages unfurl for anyone, org pages for organization members, and just_me pages for their creator; everything else stays missing.
    • Unlinked posters sharing a non-public page get Slack's account-connect prompt; the connect URL now carries { channel, ts, url } so the link route unfurls that message right after linking.
    • Page thumbnail URLs carry a version-bound ticket so org pages render without opening the usercontent origin.

    Summary by CodeRabbit

    • New Features
      • Slack now previews shared Superset page links alongside task links, with page details shown when the viewer has access.
      • When a page requires sign-in, Slack provides a connection link and displays its preview after the account is linked.
    • Improvements
      • Updated Slack’s Getting Started guidance to mention both Superset task and page links.
    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    feat(desktop): stop an agent watching a page from its row in the watcher menu - #7820

    Superset adds a stop-watching action to each page watcher menu row, so agents can be stopped directly from the list without opening their terminal. It also keeps unknown-workspace rows visible, routes the stop to the correct host, and restores stop-watching translations across locales.

    Summary

    • • The page watcher menu ended each agent row with an arrow that only opened the terminal. Each row now ends with an X (hover/focus revealed, styled like the sidebar's close button) that stops that agent watching on whichever host owns it. Clicking the row still opens the terminal.
    • • Rows carry their host URL so the stop reaches the right host. Rows whose workspace this machine does not know are no longer rendered disabled (the disabled style blocks pointer events and would hide the X); they just do not navigate.
    • • "Stop watching" / "Could not stop watching" translations restored into every locale catalog from git history.
    • This restores what the original menu in #6952 had before the per-agent rewrite dropped it.

    Verification

    Screenshots and measurements: https://app.superset.sh/page/page-watcher-stop-button-n59eeh

    Driven over CDP in the dev desktop app with real mouse input: after clicking the X the header badge and the terminal's eye chip disappear, the host lists no watchers, the page's cloud watch flag is false, the route is unchanged, and no console errors fire. The watch itself was assigned through the host API rather than a real pages publish.

    • • Menu tests: 13 pass (3 new: stop on own host without navigating, stop for an unknown-workspace row, stop only the clicked row).
    • • lint, sherif, typecheck, check:i18n clean. Turbo test green except desktop git/shell fixture suites that pass when rerun alone and do not touch this code.

    🤖 Generated with Claude Code

    Summary by cubic

    Adds a stop-watching button to each agent row in the page watcher menu, letting you stop an agent from watching a page directly without opening its terminal. Each row now ends with an X (revealed on hover/focus) that calls pageWatch.unwatch on the host that owns the watcher; clicking the row still opens the terminal.

    Rows now carry their host URL so the stop reaches the right host. Rows whose workspace isn't known locally are no longer rendered disabled (the disabled style blocked pointer events and hid the X); they just don't navigate. Restores the "Stop watching" and "Could not stop watching" translations to every locale catalog.

    Written for commit 26e04d4. Summary will update on new commits.

    Summary by CodeRabbit

    • • New Features
      • ◦ Stop watching a page directly from its watcher menu. The action targets the selected watcher's host, so other watchers remain active.
      • ◦ Watcher entries remain available when a workspace name is missing, though they cannot be selected for navigation.
    • • Bug Fixes
      • ◦ Failed stop-watching actions now display an error message.
    • • Localization
      • ◦ Added translated stop-watching actions and error messages in supported languages.
    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    chore(api): require desktop 1.29.0

    Superset raises the desktop minimum version to 1.29.0, routing older clients to the existing Update Required screen and stopping legacy v2Host.list polling. The change reduces old-host API traffic while leaving mobile version gating untouched.

    Raises MINIMUM_DESKTOP_VERSION from 1.5.0 to 1.29.0.

    Desktops older than 1.29 still poll v2Host.list, the old name for the hosts list, and that polling is ~14% of all api requests (from a sample of production request logs). 1.29 (#7442) moved host presence to realtime nudges and stopped polling. Gated clients render the Update Required screen instead of the app, so their polling stops.

    Who's affected: about 36% of weekly-active desktop users (3,568 of 9,910 with a known desktop_version, PostHog, last 7 days) are below 1.29. They get the existing Update Required screen, which installs the update in one click and says terminal sessions won't be interrupted. The client compares with semver.lt, so exactly the pre-1.29 builds are gated.

    Old mobile builds also call v2Host.list; /api/mobile/version is a separate gate and isn't touched here.

    How I tested it:

    One constant; the gate itself (useDesktopNotices synthesizing a blocking notice from minimumVersion, rendered by UpdateRequiredPage) is unchanged. Not exercised against a pre-1.29 build.

    Checklist:

    • PR title follows conventional commits (type(scope): subject)
    • bun run lint and bun run typecheck pass (CI fails on lint warnings too)
    • "Allow edits from maintainers" is checked on fork PRs (Incomplete task)

    Summary by cubic:

    Raises the desktop minimum version from 1.5.0 to 1.29.0 so pre-1.29 clients stop polling v2Host.list, the legacy hosts endpoint that accounts for ~14% of API requests.

    • Desktops below 1.29 (about 36% of weekly-active users) will see the existing one-click Update Required screen, which halts their polling.
    • Mobile versioning is gated separately and is unaffected.

    Summary by CodeRabbit:

    • Updates: Desktop versions older than 1.29.0 are now required to update before continuing.
    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    fix(desktop): copy rendered text instead of Markdown (#7454)

    Superset fixes Markdown copy behavior so Cmd/Ctrl+C now copies rendered plain text instead of leaking Markdown syntax, while a new Copy as Markdown option preserves formatted output. The update also adds translations for the new action.

    Fixes #7454

    Rendered Markdown used the Markdown serializer for the clipboard text/plain payload. As a result, copying inline code or a fenced block into a plain-text destination included backticks and fences.

    Cmd/Ctrl+C now copies the rendered text instead. Markdown remains available explicitly through Copy as Markdown in the selection context menu, including in editable Markdown views. The TipTap Markdown extension's second copied-text serializer is disabled so it cannot overwrite the plain-text result. Added translations for the new action.

    How I tested it

    • bun test apps/desktop/src/renderer/components/MarkdownRenderer/components/TipTapMarkdownRenderer/serializeMarkdownTable.test.ts — 14 pass. The regression test was RED before the change (hi returned) and GREEN after (hi). Existing whole-table GFM and partial-table plain-text cases remain covered.
    • bun run lint — pass (7,919 files).
    • bun run check:i18n — pass for all locales.
    • bun run typecheck cannot complete in this isolated worktree because its package-local dependencies are absent (@superset/typescript/internal-package.json, bun-types). A desktop tsc check from the available dependency-bearing checkout has existing unrelated errors, but none in the five modified Markdown files.

    Checklist

    • PR title follows conventional commits (type(scope): subject)
    • bun run lint passes
    • bun run typecheck passes (blocked by the isolated worktree dependency layout above)
    • "Allow edits from maintainers" is checked on this fork PR

    Summary by cubic

    Fixes copying in rendered Markdown so Cmd/Ctrl+C copies visible text instead of Markdown source (e.g. hi → hi); previously backticks and fences leaked into plain-text destinations. Markdown remains available through a new "Copy as Markdown" item in the selection context menu on read-only views.

    • The context menu stays off editable Markdown views so they keep the native Paste/Cut/Undo menu and spellcheck.
    • Whole-table copies still produce GFM Markdown; all other table-touching selections produce plain text.
    • Disabled the TipTap Markdown extension's transformCopiedText so it can't override the plain-text clipboard payload.
    • Added translations for "Copy as Markdown" across all locales.

    Summary by CodeRabbit

    • New Features
      • Added a Copy as Markdown option to the text selection menu.
      • Use it to copy selected content with Markdown formatting. Standard copy continues to copy plain text outside tables; complete table selections are copied as Markdown.
    • Localization
      • Added translations for Copy as Markdown across supported languages.
    Original source
  • Sep 24, 2026
    • Date parsed from source:
      Sep 24, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    feat(mobile): full-height workspace sheet with a PR section, no Delete - #7782

    Superset now opens the workspace sheet at full height, removes the Delete workspace button there, and adds a Pull Requests section showing linked PRs with status badges and tap-to-open links.

    Summary

    • The workspace sheet opens at the full detent (sheetAllowedDetents: [1.0], was [0.65, 1.0]). The grabber and drag-to-dismiss still work.
    • Removes the Delete workspace button from the sheet, plus its handler in useWorkspaceHeaderActions, which had no other caller. useDeleteWorkspace is untouched and still backs the home row's delete.
    • Adds a PR section between Info and Pages. It lists every PR the workspace has been linked to (useWorkspacePullRequests, current first), with the same status glyphs as the home list and the Pull Requests sheet. Tapping a row opens the PR through openUrl. With no PRs the section is hidden.

    Verification

    Ran this branch's JS on the iPhone 17 Pro Max simulator (iOS 26) against production with real workspaces. Screenshots: https://app.superset.sh/page/workspace-sheet-pr-section-wt1y5g

    • One open PR: full-height sheet, title wraps to two lines with a muted #7776
    • Four-PR history: open is green, merged is purple
    • A workspace with no PR: section hidden
    • Tapping a row with Maestro opened the PR on github.com

    Not checked: other locales, large text sizes, an offline host.

    Known follow-up

    When a title fills both lines, the ellipsis cuts off the trailing #number. The fix is to give the number its own non-truncating slot.

    Summary by cubic

    The workspace sheet now opens at full height, drops the Delete button, and gains a PR section listing linked pull requests.

    • The sheet opens at the full detent (was a partial height) with the grabber and drag-to-dismiss still working.
    • The Delete workspace button and its handler in useWorkspaceHeaderActions are removed; useDeleteWorkspace still backs the home row's delete.
    • A PR section between Info and Pages lists linked pull requests (newest first) with the same status glyphs as the home list; tapping a row opens the PR, and the section is hidden when there are none.
    • PR rows now carry an accessibility label so VoiceOver announces their title instead of just the number.

    Summary by CodeRabbit

    New Features

    • Workspace action sheets show the workspace’s pull requests, including their status and number. Tap a pull request to open it.

    Updates

    • The workspace action sheet opens at full height.
    • The “Delete workspace” action is no longer available in the workspace action sheet.
    Original source
  • Sep 24, 2026
    • Date parsed from source:
      Sep 24, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Apache logo

    Superset by Apache

    feat(integrations)!: remove Google Calendar triggers, keep Gmail

    Superset removes the Google Calendar trigger integration end to end while keeping Google Gmail automation intact. The update drops calendar scheduling and watch handling, narrows Google connections to Gmail access only, and leaves message received triggers and mailbox watches in place.

    Why / Context

    Removes the Google Calendar trigger integration end to end: push/scheduled routes, the sync (sync tokens, watch channels, recurring-instance expansion), fire scheduling and its sweep job, the calendar tRPC client, the desktop provider and grammar, the shared trigger schema and matcher, and the calendar.readonly OAuth scope.

    Keeps the Google connector for Gmail: OAuth, connection state, the mailbox watch and its daily renewal, and the message.received trigger.

    50 files, +216 / −2,863.

    Measured on production on 2026-09-24: zero calendar triggers have ever been created (including on since-deleted automations) and zero runs, while all 28 Google connections watched their calendars and produced ~21,600 automation_events rows a day that nothing consumed — plus Google push traffic, channel renewals and a 15-minute scheduling sweep.

    The one thing the trigger did that a schedule cannot is fire minutes before a meeting. An agent on a schedule with calendar access through the Google tools covers that without any of the state, and generalises ("look at my calendar and prep me") instead of a bespoke event model. The sync also read automation_events history back to classify edits vs creations, which was the reason that table could not be put on a retention window; the follow-up swap PR depends on this landing first.

    How It Works

    Deleted outright: google/calendar/**, google/jobs/sweep-schedules, lib/{syncCalendar,calendarEvents,scheduleCalendarFires}.ts, trpc/.../google/calendar.ts, providers/google/googleCalendar.tsx.

    Edited to Gmail-only: reconcileWatches, the Google tRPC router's disconnect (no channels to stop), trigger options (labels + people), connection state helpers, scopes/constants, the shared trigger schema, matcher union and launched-kinds list, billing plan map, desktop grammar/provider registry/settings search, the web integration page copy, and the callback's required scopes.

    google_calendar stays in the automation_trigger_kind Postgres enum (values cannot be dropped) with a comment; the satisfies check that every enum value is a live kind is relaxed to the one direction that still holds. No migration.

    prune-payloads loses its calendar exclusion (the only provider it excluded).

    Rollout

    • PostHog flag automation-event-triggers (829320) already updated (v7): payload no longer lists google_calendar, targeting unchanged. Clients read the payload, so the trigger and the Google integration card behave correctly the moment this deploys; older desktop builds ignore a kind absent from the payload.
    • Existing connections keep their calendar scope until they reconnect; new connects request gmail.readonly only.
    • Existing calendar watch channels keep pushing to the removed route until they expire (≤ 7 days) and get a 404. Harmless.
    • After deploy, delete the QStash schedule google/sweep-schedules (and anything targeting google/calendar/scheduled) in the Upstash console — schedules are console-only.
    • The google_calendar rows in automation_events (347k) are removed by the follow-up swap.

    Testing

    • bunx turbo typecheck for shared, db, trpc, api, desktop, web — all green
    • bunx biome check on every touched directory
    • bun test: shared 34, trpc 42, api 267, desktop 268 — all pass
    • bun run check:i18n — the four re-keyed strings are translated in all 16 locales and every catalog compiles
    • Not exercised in a running app: the Gmail connect flow after the scope change. The callback's scope check and reconcileWatches are the two code paths that changed there, both covered by typecheck and unchanged in shape.

    Summary by cubic

    Removes the Google Calendar trigger integration end to end while keeping the Google connector for Gmail. No calendar trigger was ever created in production, yet all Google connections still watched their calendars and produced ~21,600 automation_events rows a day that nothing consumed, plus Google push traffic, channel renewals, and a 15-minute fire-scheduling sweep.

    Rollout

    • After deploy, delete the QStash schedules google/sweep-schedules and whatever targets google/calendar/scheduled in the Upstash console — schedules are console-only.
    • Existing connections keep their calendar scope until they reconnect; new connects request gmail.readonly only.
    • Existing calendar watch channels keep pushing to the removed route until they expire (≤ 7 days) and get a 404.
    • The google_calendar value stays in the automation_trigger_kind Postgres enum (values cannot be dropped) with a comment; no migration is needed.

    Summary by CodeRabbit

    • Removed Features
      • Google Calendar integration and Calendar-based automation triggers are no longer available. This includes Calendar event notifications, scheduling, and calendar selection in automation settings.
    • Updates
      • Google account connections now request Gmail access only. Integration descriptions clarify that mailbox access is read-only and automations can be triggered by arriving email.
      • Gmail watch management continues without Calendar channel management.
      • Google Calendar event payloads are now cleared during retention sweeps.
    Original source
  • Sep 24, 2026
    • Date parsed from source:
      Sep 24, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    • Modified by Releasebot:
      Sep 24, 2026
    Apache logo

    Airflow by Apache

    providers-weaviate/3.5.0rc1

    Airflow releases providers 2026-09-22 update.

    Release 2026-09-22 of providers

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.