<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jason St-Cyr</title>
    <description>The latest articles on DEV Community by Jason St-Cyr (@jasonstcyr).</description>
    <link>https://dev.to/jasonstcyr</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F183204%2Fa798216f-9f66-40cd-9bed-b5193e9afe08.jpg</url>
      <title>DEV Community: Jason St-Cyr</title>
      <link>https://dev.to/jasonstcyr</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/jasonstcyr"/>
    <language>en</language>
    <item>
      <title>Security Compliance Management 3.9.0 now supports Ubuntu 24.04, RHEL 10, Puppet Core 9 and new benchmarks!</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 27 Aug 2026 14:29:27 +0000</pubDate>
      <link>https://dev.to/puppet/security-compliance-management-390-now-supports-ubuntu-2404-rhel-10-puppet-core-9-and-new-ndh</link>
      <guid>https://dev.to/puppet/security-compliance-management-390-now-supports-ubuntu-2404-rhel-10-puppet-core-9-and-new-ndh</guid>
      <description>&lt;p&gt;The latest Security Compliance Management (SCM) 3.9.0 has new supported platforms, improvements for air-gapped environments, benchmark updates, feature improvements, and security updates to address vulnerabilities.&lt;/p&gt;

&lt;h2&gt;
  
  
  Highlights
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Expanded platform support:&lt;/strong&gt; SCM 3.9.0 now supports Ubuntu 24.04, Red Hat Enterprise Linux (RHEL) 10, and Puppet 9&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Private image registry support:&lt;/strong&gt; &lt;code&gt;complyadm&lt;/code&gt; can now pull SCM container images from a private image registry to better support air-gapped and private-registry environments.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;IP-based access restrictions:&lt;/strong&gt; Keycloak Administration Console and Admin REST APIs can now be access restricted to IP addresses defined in the frontdoor allowlist.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Expanded benchmarks:&lt;/strong&gt; CIS-CAT Pro Assessor was updated to 4.65.0,  expanded benchmark support for AlmaLinux and MacOS, and updated coverage on Microsoft Windows.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;119 security vulnerabilities&lt;/strong&gt; addressed via updates and fixes, along with several other security hardening fixes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Below are some other summary details, but you may want to jump straight into the &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" rel="noopener noreferrer"&gt;full release notes&lt;/a&gt; right away! &lt;/p&gt;

&lt;h2&gt;
  
  
  CIS-CAT Pro Assessor Updates
&lt;/h2&gt;

&lt;p&gt;Along with updating to CIS-CAT Pro Assessor 4.65.0, the following benchmarks were added:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;AlmaLinux OS 9 STIG v1.0.0&lt;/li&gt;
&lt;li&gt;Apple macOS 15 (Sequoia) STIG v1.1.0&lt;/li&gt;
&lt;li&gt;Apple macOS 26 Tahoe STIG v1.0.0&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These supported benchmarks were also updated:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Microsoft Windows 11 Enterprise Benchmark v5.1.0&lt;/li&gt;
&lt;li&gt;Microsoft Windows Server 2022 Benchmark v5.1.0&lt;/li&gt;
&lt;li&gt;Microsoft Windows Server 2025 Benchmark v2.1.0&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Operational Improvements and Security updates
&lt;/h2&gt;

&lt;p&gt;There were several changes made to improve behavior and address vulnerabilities in this release, including addressing 119 security reports.&lt;/p&gt;

&lt;p&gt;A few notable changes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SCM handles interrupted scheduled scans after reboots more reliably.&lt;/li&gt;
&lt;li&gt;Default benchmark selection is now more reliable when multiple non-STIG benchmarks are available.&lt;/li&gt;
&lt;li&gt;Hasura GraphQL field suggestions are now disabled to prevent schema enumeration.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;See the full list &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" rel="noopener noreferrer"&gt;in the release notes&lt;/a&gt;!&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Upgrade?
&lt;/h2&gt;

&lt;p&gt;For customers running Ubuntu 24.04, RHEL 10, Puppet 9, private registries, or security-sensitive environments, SCM 3.9.0 delivers meaningful operational, platform, and security improvements. Combined with expanded benchmark coverage and enhanced upgrade behavior, this release helps organizations maintain compliance with greater confidence and less administrative overhead.&lt;/p&gt;


&lt;div class="ltag-offer"&gt;
  &lt;div class="ltag-offer__body"&gt;View the full SCM 3.9.0 release notes!&lt;/div&gt;
    &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" class="ltag-offer__button crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;Read More&lt;/a&gt;
&lt;/div&gt;


&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;This summary was initially drafted by AI and deterministic automation to pull together release notes information from the latest Security Compliance Management 3.9.0 release notes. The draft was then human edited, rewritten, and reviewed before publishing.&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>devops</category>
      <category>security</category>
    </item>
    <item>
      <title>Puppet Core 9.0 and 8.21 Released: Ruby 4.0, OpenSSL 3.5, Platform Changes, and Security Hardening</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 20 Aug 2026 15:26:21 +0000</pubDate>
      <link>https://dev.to/puppet/puppet-core-90-and-821-released-ruby-40-openssl-35-platform-changes-and-security-hardening-4294</link>
      <guid>https://dev.to/puppet/puppet-core-90-and-821-released-ruby-40-openssl-35-platform-changes-and-security-hardening-4294</guid>
      <description>&lt;p&gt;Did you know there's a new major version in town for Puppet Core? You might have heard about it through the grapevine or in the &lt;a href="https://www.puppet.com/resources/events/webinars/puppet-9" rel="noopener noreferrer"&gt;Are You Ready for Puppet 9?&lt;/a&gt; webinar that &lt;a class="mentioned-user" href="https://dev.to/gpatton"&gt;@gpatton&lt;/a&gt; and I recently hosted. The wait is over and Puppet Core 9.0.0 is now available alongside Puppet Core 8.21.0.&lt;/p&gt;

&lt;p&gt;Puppet Core 9 introduces significant runtime and platform changes, moving to Ruby 4.0, OpenSSL 3.5, and other changes, but the essential Puppet under the hood is largely unchanged from Puppet 8. The majority of upgrade effort will center on Ruby 4 compatibility and runtime dependency changes rather than Puppet language changes.&lt;/p&gt;

&lt;p&gt;If you are staying on the Puppet Core 8.x release track, the latest Puppet Core 8.21 delivers the basic support fixes and security improvements you might need without the major dependency changes found in Puppet Core 9.&lt;/p&gt;

&lt;h2&gt;
  
  
  What matters most for the admins
&lt;/h2&gt;

&lt;p&gt;Before upgrading to Puppet Core 9:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Test custom facts, functions, types, and providers against Ruby 4.0.&lt;/li&gt;
&lt;li&gt;Validate any Forge modules you use for Ruby 4 compatibility.&lt;/li&gt;
&lt;li&gt;Review integrations that depend on OpenSSL behavior.&lt;/li&gt;
&lt;li&gt;Verify any workflows that still rely on SHA-1.&lt;/li&gt;
&lt;li&gt;Confirm managed nodes are running supported operating systems.&lt;/li&gt;
&lt;li&gt;Review any custom code that depends on PSON or &lt;code&gt;multi_json&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Check deferred function behavior if you have custom types or providers.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Perforce will be rolling out updates to Puppetlabs modules on the Forge based on their &lt;a href="https://dev.to/puppet/puppetlabs-modules-now-have-tiered-review-cycles-42ob"&gt;priority tier&lt;/a&gt; and dependencies. The first batch of these should be rolling out soon.&lt;/p&gt;




&lt;h2&gt;
  
  
  Puppet Core 9.0 highlights
&lt;/h2&gt;

&lt;p&gt;These are a few highlights I pulled from the release notes. Make sure to reference the &lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-9-0-0.htm" rel="noopener noreferrer"&gt;full 9.0 release notes&lt;/a&gt; to get all the details about what has changed!&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Ruby updated to 4.0.5:&lt;/strong&gt; With a new Ruby baseline some deprecated syntax from older Ruby versions will no longer be compatible. This is the primary focus area for upgrades as you will want to validate your custom code and modules. The latest &lt;a href="https://help.puppet.com/pdk/current/topics/release_notes_pdk.htm#PDK380" rel="noopener noreferrer"&gt;PDK 3.8.0&lt;/a&gt; introduced some Ruby 4 validators to help you update your syntax while you are still on Puppet Core 8, before upgrading to Puppet Core 9. &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;OpenSSL updated to 3.5.7:&lt;/strong&gt; This lays the groundwork for supporting post-quantum cryptography (PQC) and moves to TLS 1.3 as the default protocol version. This upgrade will resolve several OpenSSL-related CVEs.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Puppet Server has updated baseline components:&lt;/strong&gt; As part of the move to JRuby 10.1, Puppet Server is now updated to require minimum JDK 21. The embedded web server is now using Jetty 12. &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;PSON support removed:&lt;/strong&gt; You will need to migrate to a supported data format if your code has relied on PSON.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Deferred functions return to Puppet 7 behavior:&lt;/strong&gt; While Puppet Core 9 largely keeps the same underlying behavior as Puppet Core 8.x, there is one change worth noting about deferred functions. In older versions (like Puppet 7), &lt;code&gt;preprocess_deferred&lt;/code&gt; was enabled by default, but this was disabled by default in Puppet 8. In Puppet Core 9, &lt;code&gt;preprocess_deferred&lt;/code&gt; is now enabled by default again.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;UTF-8 encoding now used on Windows:&lt;/strong&gt; Puppet Core now uses UTF-8 as the default external encoding on Windows. You will want to look for any configuration files encoded in non-UTF-8 before upgrading.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;These are just some highlights I pulled from the full list, I really recommend taking a look at the release notes to get a full picture.&lt;/p&gt;




&lt;h2&gt;
  
  
  Security hardening
&lt;/h2&gt;

&lt;p&gt;Both the 9.0 and 8.21 releases contain security-related fixes.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Stricter SSH key validation:&lt;/strong&gt; Puppet now rejects malformed SSH keys that previously passed validation. This includes invalid inputs such as embedded newline characters. The goal is to prevent unsafe content from being written to managed files.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Improved autoloader validation:&lt;/strong&gt; The &lt;code&gt;puppet resource&lt;/code&gt; command now performs stricter validation of autoloader inputs. This change helps prevent unintended code loading through user-controlled values.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;curl updated to 8.21.0:&lt;/strong&gt; Both Puppet Core 9.0 and Puppet Core 8.21 update curl from 8.20.0 to 8.21.0. The update addresses numerous curl CVEs. &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Admins who track dependency risk should review the release notes for the complete CVE list:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-9-0-0.htm" rel="noopener noreferrer"&gt;Puppet Core 9.0 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/8/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-8-21-0.htm" rel="noopener noreferrer"&gt;Puppet Core 8.21 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Platform updates
&lt;/h2&gt;

&lt;h3&gt;
  
  
  New agent platforms
&lt;/h3&gt;

&lt;p&gt;The following agent platforms are now supported in both Puppet Core 9.0 and 8.21:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Rocky Linux 10 (x86_64)&lt;/li&gt;
&lt;li&gt;Alma Linux 10 (x86_64)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Operating systems removed from support
&lt;/h3&gt;

&lt;p&gt;Several end-of-life operating systems have been removed: Debian 10, macOS 13, RHEL 7, Ubuntu 18.04 and 20.04, and others. &lt;/p&gt;

&lt;p&gt;The official full list is &lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-9-0-0.htm#Deprecations" rel="noopener noreferrer"&gt;in the docs&lt;/a&gt;. The list in this article is not complete, so make sure to reference those notes to check your systems! &lt;/p&gt;

&lt;p&gt;If you need to keep using a platform that has been removed you should know there is an extended support option. Migrating to a more modern OS is likely the best path, but if you can't migrate just yet, make sure to &lt;a href="https://www.puppet.com/extended-agent-support" rel="noopener noreferrer"&gt;reach out to the team to get help with extended platform support&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Upgrade resources
&lt;/h2&gt;

&lt;p&gt;Before moving to Puppet Core 9, review the official upgrade documentation and release notes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/upgrading-from-puppet8-to-puppet9.htm" rel="noopener noreferrer"&gt;Puppet Core 9 upgrade documentation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-9-0-0.htm" rel="noopener noreferrer"&gt;Puppet Core 9.0.0 release notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/8/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-8-21-0.htm" rel="noopener noreferrer"&gt;Puppet Core 8.21.0 release notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.puppet.com/products/puppet-core/support-lifecycle" rel="noopener noreferrer"&gt;Puppet Core platform support lifecycle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/pdk/current/topics/release_notes_pdk.htm#PDK380" rel="noopener noreferrer"&gt;PDK 3.8.0 compatibility testing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Make sure to start your Puppet Core 9 compatibility testing early and send over any questions as you encounter issues so that the team can help!&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>devops</category>
      <category>infrastructureascode</category>
    </item>
    <item>
      <title>PDK 3.8.0 now has Ruby validation to prepare for Puppet 9!</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 11 Aug 2026 12:53:45 +0000</pubDate>
      <link>https://dev.to/puppet/pdk-380-now-has-ruby-validation-to-prepare-for-puppet-9-2ici</link>
      <guid>https://dev.to/puppet/pdk-380-now-has-ruby-validation-to-prepare-for-puppet-9-2ici</guid>
      <description>&lt;p&gt;A new release is out for the Puppet Development Kit and it has some new additions like Debian 13 support, some security-related updates, and some new validation for Ruby syntax to help you get yourself ready for Puppet Core 9!&lt;/p&gt;

&lt;p&gt;The next releases of Puppet Core 9 and Puppet Enterprise 2026, due out soon, will be moving to Ruby 4. To help you get ready, you can start using this new version of PDK on your Puppet 8 installation to look for areas that might need updates.&lt;/p&gt;

&lt;p&gt;When you run &lt;code&gt;pdk validate&lt;/code&gt;, it can now identify changes you can make that will be safe to run on Puppet 8, but also will prepare your codebase for Puppet Core 9:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Code that uses legacy Ruby Hash#inspect formatting, for example &lt;code&gt;{:x=&amp;gt;1, "baz"=&amp;gt;3}&lt;/code&gt; . Legacy formatting can cause module code to fail after you upgrade to Puppet Core 9.&lt;/li&gt;
&lt;li&gt;Ruby 4 syntax compatibility checks.&lt;/li&gt;
&lt;li&gt;The Security/Open Rubocop flags Ruby patterns associated with &lt;code&gt;Kernel#open&lt;/code&gt; and &lt;code&gt;IO.open&lt;/code&gt; invocation that are no longer valid in Ruby 4. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Once Puppet Core 9 is out, you'll be able to do additional validation, but this should help you get started finding those places where the syntax might need some updates.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Full release notes:&lt;/strong&gt; &lt;a href="https://help.puppet.com/pdk/current/topics/release_notes_pdk.htm#PDK380" rel="noopener noreferrer"&gt;https://help.puppet.com/pdk/current/topics/release_notes_pdk.htm#PDK380&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Download PDK:&lt;/strong&gt; &lt;a href="https://forge.puppet.com/resources/pdk" rel="noopener noreferrer"&gt;https://forge.puppet.com/resources/pdk&lt;/a&gt;&lt;/p&gt;

</description>
      <category>puppet</category>
    </item>
    <item>
      <title>Puppetlabs Modules Roundup - July 2026</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 06 Aug 2026 12:19:41 +0000</pubDate>
      <link>https://dev.to/puppet/puppetlabs-modules-roundup-july-2026-3325</link>
      <guid>https://dev.to/puppet/puppetlabs-modules-roundup-july-2026-3325</guid>
      <description>&lt;p&gt;July 2026 brought 17 Puppetlabs module releases, headlined by a fairly large Continuous Delivery release. cd4peadm 5.16.0 added external PostgreSQL database support and a configurable image pull policy, and closes 11 CVEs, alongside a breaking change to commit status contexts. More modules dropped Puppet 7 support, some others picked up stdlib 10, and Windows Server 2025 support started rolling out into the modules. This roundup pulls the most important changes into one place.&lt;/p&gt;

&lt;h2&gt;
  
  
  Highlighted Updates
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Continuous Delivery Adds External Databases, Configurable Image Pull Policies, and Closes 11 CVEs
&lt;/h3&gt;

&lt;p&gt;cd4peadm 5.16.0 is the biggest release of the month. It adds support for pointing Continuous Delivery at an externally managed PostgreSQL database. That could be a self-managed instance, Amazon RDS for PostgreSQL, or Amazon Aurora. This externally managed db can be used instead of the database CD manages internally, giving operators control over durability, backups, and high availability. It also adds a configurable &lt;code&gt;image_pull_policy&lt;/code&gt; option for job templates (&lt;code&gt;Always&lt;/code&gt;/&lt;code&gt;IfNotPresent&lt;/code&gt;/&lt;code&gt;Never&lt;/code&gt;) and removes the &lt;code&gt;docker.io&lt;/code&gt; fallback when using Podman; the matching cd4pe_jobs 1.7.4 release adds the same task parameter and fallback removal, so upgrade both together.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;BREAKING:&lt;/strong&gt; Commit status contexts now include the pipeline name (&lt;code&gt;cd-pe/&amp;lt;pipelineName&amp;gt;/stage-&amp;lt;N&amp;gt;&lt;/code&gt; instead of &lt;code&gt;cd-pe/stage-&amp;lt;N&amp;gt;&lt;/code&gt;). Review any branch protection rules or required status checks that reference the old format.&lt;/li&gt;
&lt;li&gt;This release also closed 11 CVEs across opentelemetry, NGINX, jetty, jackson, log4j, postgresql, golang.org/x/sys, and react-router.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Puppet 7 Support Dropped
&lt;/h3&gt;

&lt;p&gt;Five modules dropped Puppet 7 support in major version bumps: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;haproxy, iis, mount_iso, scheduled_task, sslcertificate.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There were all released as major version bumps to ensure that users still working on upgrading from Puppet 7 can stay pinned on the previous major version releases. &lt;/p&gt;

&lt;p&gt;In related news, postgresql 10.6.3 restored the Puppet 7 support that 10.6.2 broke in a previous release; see its entry below.&lt;/p&gt;

&lt;h3&gt;
  
  
  stdlib 10.x Rollout Continues
&lt;/h3&gt;

&lt;p&gt;Following June's stdlib 10.x rollout, four more modules now allow the puppetlabs-stdlib dependency to move to 10.x: haproxy, mount_iso, puppet_authorization, and sslcertificate. haproxy also widens its concat constraint to 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Affected modules: haproxy, mount_iso, puppet_authorization, sslcertificate.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Windows Server 2025 Support Added
&lt;/h3&gt;

&lt;p&gt;Three Windows-focused modules added support for Windows Server 2025 this month: scheduled_task, windows_env, and windows_eventlog. These now all run acceptance testing against the 2025 version of the OS, in addition to other supported Windows versions.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Updates Happened to Puppetlabs Modules in July 2026?
&lt;/h2&gt;

&lt;p&gt;The following is an alphabetical listing of modules which received updates in July 2026. If a module had multiple versions released, the updates are collected together, numbered with the "latest" version available.&lt;/p&gt;




&lt;h3&gt;
  
  
  apache 13.3.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-23 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/apache" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Added OWASP CRS v4 support on modern Enterprise Linux (EL10) while preserving existing EL7/8/9 behaviour.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11857) Scaffold OWASP CRS v4 support on EL10 via crs_source enum &lt;a href="https://github.com/puppetlabs/puppetlabs-apache/pull/2637" rel="noopener noreferrer"&gt;#2637&lt;/a&gt; (&lt;a href="https://github.com/SugatD" rel="noopener noreferrer"&gt;SugatD&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  cd4pe_jobs 1.7.4
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-28 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/cd4pe_jobs" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds the same configurable &lt;code&gt;image_pull_policy&lt;/code&gt; task parameter and Podman fallback removal shipping in cd4peadm 5.16.0 — upgrade both together to get matching behavior.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A new optional &lt;code&gt;image_pull_policy&lt;/code&gt; task parameter controls whether the container image is pulled before a job runs: &lt;code&gt;Always&lt;/code&gt; (the default, and the previous behavior) pulls on every run; &lt;code&gt;IfNotPresent&lt;/code&gt; pulls only when the image is absent from the local runtime; &lt;code&gt;Never&lt;/code&gt; skips the pull entirely and relies on the locally present image. Presence is checked with &lt;code&gt;docker image inspect&lt;/code&gt; / &lt;code&gt;podman image exists&lt;/code&gt;. Omitting the parameter keeps the existing pull-every-run behavior.&lt;/li&gt;
&lt;li&gt;The module no longer retries a failed image pull against &lt;code&gt;docker.io&lt;/code&gt;. Image names are now pulled exactly as given. If you rely on unqualified image names (e.g. &lt;code&gt;nginx&lt;/code&gt;, &lt;code&gt;myuser/myimage&lt;/code&gt;) on a Podman host, add &lt;code&gt;docker.io&lt;/code&gt; to &lt;code&gt;unqualified-search-registries&lt;/code&gt; in &lt;code&gt;registries.conf&lt;/code&gt;, or use a fully-qualified name.&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  cd4peadm 5.16.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/cd4peadm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;The changes this month added external PostgreSQL database support, a configurable image pull policy, source control token management improvements, and closed 11 CVEs. There is also a breaking change to commit status contexts — see below (and the linked release notes).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Added support for external databases. You can now point Continuous Delivery at a PostgreSQL instance you operate yourself, Amazon RDS for PostgreSQL, Amazon Aurora (PostgreSQL-compatible), or a self-managed PostgreSQL server, instead of the database CD manages for you. This gives you control over durability, backups, and high availability. You can configure external mode on a fresh install or migrate an existing managed install.&lt;/li&gt;
&lt;li&gt;Added a feature to Continuous Delivery job templates so you can set an image pull policy per job (&lt;code&gt;Always&lt;/code&gt;, &lt;code&gt;IfNotPresent&lt;/code&gt;, or &lt;code&gt;Never&lt;/code&gt;). In an air-gapped environment, for example, setting the policy to &lt;code&gt;Never&lt;/code&gt; stops Continuous Delivery's attempts to reach out to the internet for the image.&lt;/li&gt;
&lt;li&gt;Updated the &lt;strong&gt;Source Control&lt;/strong&gt; settings page to show when a configured Personal Access Token (PAT) expires on each connected GitHub, GitHub Enterprise, and GitLab integration card. Tokens that have already expired or will expire within 30 days are clearly flagged so you can renew them before they cause failures.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;BREAKING:&lt;/strong&gt; Commit status contexts now include the pipeline name (&lt;code&gt;cd-pe/&amp;lt;pipelineName&amp;gt;/stage-&amp;lt;N&amp;gt;&lt;/code&gt; instead of &lt;code&gt;cd-pe/stage-&amp;lt;N&amp;gt;&lt;/code&gt;), which prevents collisions when multiple pipelines report status for the same commit. Review any branch protection rules or required status checks that reference the old format.&lt;/li&gt;
&lt;li&gt;11 CVEs addressed, including opentelemetry, NGINX, jetty, jackson, log4j, postgresql, golang.org/x/sys, and react-router.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/cdpe/current/Content/UserGuide/CDPE/ReleaseNotes/cd_release_notes.htm#Version5160" rel="noopener noreferrer"&gt;release notes for cd4peadm 5.16.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  comply 3.8.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-03 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/comply" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;A Security Compliance Management maintenance release that did not have any new CVE fixes this time and was mostly operational and licensing improvements.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Increased the CIS-CAT Pro Assessor license expiry time; licenses are now good for a full year.&lt;/li&gt;
&lt;li&gt;Added a &lt;code&gt;license_path&lt;/code&gt; parameter to update the CIS-CAT Pro Assessor license without upgrading SCM.&lt;/li&gt;
&lt;li&gt;Added an &lt;code&gt;assessor_scan_timeout&lt;/code&gt; option to control the task timeout for Windows 2022 domain controllers.&lt;/li&gt;
&lt;li&gt;Added a background scan sweeper that detects and cancels scans stuck in a "running" state.&lt;/li&gt;
&lt;li&gt;Increased the default &lt;strong&gt;Max graphql requests limit&lt;/strong&gt; to 300 requests per window; use the &lt;code&gt;complyadm::configure&lt;/code&gt; Bolt plan to customize.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement381" rel="noopener noreferrer"&gt;release notes for comply 3.8.1&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  haproxy 9.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-28 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/haproxy" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Two releases this month: 9.0.0 dropped Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) and added &lt;code&gt;cache&lt;/code&gt; resource support, while 9.1.0 removed a sensitive-data workaround and allows both stdlib and concat to move to their 10.x releases.&lt;/p&gt;

&lt;p&gt;Includes monthly releases: 9.1.0 (2026-07-28), 9.0.0 (2026-07-20).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Eliminate Workaround for Sensitive Data; raises minimum &lt;code&gt;puppetlabs/concat&lt;/code&gt; requirement to &lt;code&gt;7.4.0&lt;/code&gt; &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/607" rel="noopener noreferrer"&gt;#607&lt;/a&gt; (&lt;a href="https://github.com/cocker-cc" rel="noopener noreferrer"&gt;cocker-cc&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Add support for running programs &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/604" rel="noopener noreferrer"&gt;#604&lt;/a&gt; (&lt;a href="https://github.com/deric" rel="noopener noreferrer"&gt;deric&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Pass install_options to package installer &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/603" rel="noopener noreferrer"&gt;#603&lt;/a&gt; (&lt;a href="https://github.com/deric" rel="noopener noreferrer"&gt;deric&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;examples: disable default stats listener &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/640" rel="noopener noreferrer"&gt;#640&lt;/a&gt; (&lt;a href="https://github.com/bastelfreak" rel="noopener noreferrer"&gt;bastelfreak&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;make picking haproxy::globals::sort_options_alphabetic work &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/573" rel="noopener noreferrer"&gt;#573&lt;/a&gt; (&lt;a href="https://github.com/trefzer" rel="noopener noreferrer"&gt;trefzer&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remove Puppet 7 support (BREAKING); the module now requires &lt;code&gt;puppet &amp;gt;= 8.0.0 &amp;lt; 9.0.0&lt;/code&gt;&lt;/strong&gt; &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/631" rel="noopener noreferrer"&gt;#631&lt;/a&gt; (&lt;a href="https://github.com/gavindidrichsen" rel="noopener noreferrer"&gt;gavindidrichsen&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Add support for &lt;code&gt;cache&lt;/code&gt; resource, extra backend options, and docs &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/626" rel="noopener noreferrer"&gt;#626&lt;/a&gt; (&lt;a href="https://github.com/matejzero" rel="noopener noreferrer"&gt;matejzero&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/642" rel="noopener noreferrer"&gt;#642&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Allow puppetlabs/concat 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/641" rel="noopener noreferrer"&gt;#641&lt;/a&gt; (&lt;a href="https://github.com/bastelfreak" rel="noopener noreferrer"&gt;bastelfreak&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;dependency: create mapfile before configfile &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/572" rel="noopener noreferrer"&gt;#572&lt;/a&gt; (&lt;a href="https://github.com/trefzer" rel="noopener noreferrer"&gt;trefzer&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  iis 11.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-01 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/iis" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Dropped Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) as part of ongoing modernization efforts, and marked the &lt;code&gt;iis_application_pool&lt;/code&gt; password parameter as sensitive so it no longer leaks into Puppet reports.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2374) Puppet Core update (BREAKING) — drops Puppet 7 support &lt;a href="https://github.com/puppetlabs/puppetlabs-iis/pull/414" rel="noopener noreferrer"&gt;#414&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11595) Mark iis_application_pool password as sensitive to stop report leak &lt;a href="https://github.com/puppetlabs/puppetlabs-iis/pull/418" rel="noopener noreferrer"&gt;#418&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  mount_iso 5.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-22 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/mount_iso" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Dropped Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) and allowed the stdlib dependency to move to 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2380) Update for Puppet Core / Drop Support for Puppet 7 (BREAKING) &lt;a href="https://github.com/puppetlabs/puppetlabs-mount_iso/pull/58" rel="noopener noreferrer"&gt;#58&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-mount_iso/pull/59" rel="noopener noreferrer"&gt;#59&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  mysql 17.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-02 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/mysql" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This month was a small update but important as RHEL 10 support was added.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11802) Add support for RHEL 10 &lt;a href="https://github.com/puppetlabs/puppetlabs-mysql/pull/1712" rel="noopener noreferrer"&gt;#1712&lt;/a&gt; (&lt;a href="https://github.com/skyamgarp" rel="noopener noreferrer"&gt;skyamgarp&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  node_encrypt 3.2.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-22 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/node_encrypt" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Ubuntu 24 and Debian 12 support, and upgrades rexml to address a CVE.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2124) Add support for Ubuntu 24 &lt;a href="https://github.com/puppetlabs/puppetlabs-node_encrypt/pull/120" rel="noopener noreferrer"&gt;#120&lt;/a&gt; (&lt;a href="https://github.com/skyamgarp" rel="noopener noreferrer"&gt;skyamgarp&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2100) Add Debian 12 support &lt;a href="https://github.com/puppetlabs/puppetlabs-node_encrypt/pull/119" rel="noopener noreferrer"&gt;#119&lt;/a&gt; (&lt;a href="https://github.com/shubhamshinde360" rel="noopener noreferrer"&gt;shubhamshinde360&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2158) Upgrade rexml to address CVE-2024-49761 &lt;a href="https://github.com/puppetlabs/puppetlabs-node_encrypt/pull/121" rel="noopener noreferrer"&gt;#121&lt;/a&gt; (&lt;a href="https://github.com/amitkarsale" rel="noopener noreferrer"&gt;amitkarsale&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  peadm 3.38.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-08 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/peadm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Restores public-schema privileges on PostgreSQL 15+ in &lt;code&gt;restore.pp&lt;/code&gt;, fixing a bug that could affect PE restores on newer PostgreSQL versions.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(PE-44867) Restore public-schema privileges on PostgreSQL 15+ in restore.pp &lt;a href="https://github.com/puppetlabs/puppetlabs-peadm/pull/676" rel="noopener noreferrer"&gt;#676&lt;/a&gt; (&lt;a href="https://github.com/CharithaDunuwille" rel="noopener noreferrer"&gt;CharithaDunuwille&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  postgresql 10.6.3
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-07 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/postgresql" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Restores Puppet 7 support that was unintentionally dropped in the 10.6.2 patch release last month.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;NOTE:&lt;/strong&gt; As flagged in June's roundup, the Puppet 7 removal in 10.6.2 shipped in a patch release rather than a major one. 10.6.3 restores Puppet 7 support; the removal will happen again, correctly, in a future major release.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11858) Restore Puppet 7 support broken by 10.6.2 &lt;a href="https://github.com/puppetlabs/puppetlabs-postgresql/pull/1686" rel="noopener noreferrer"&gt;#1686&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  puppet_authorization 1.0.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-21 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/puppet_authorization" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;A maintenance release: allows both the stdlib and concat dependencies to move to 10.x, tweaks a CI workflow flag, and adds a LICENSE file.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Change flag option in CI workflow &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_authorization/pull/56" rel="noopener noreferrer"&gt;#56&lt;/a&gt; (&lt;a href="https://github.com/zaben903" rel="noopener noreferrer"&gt;zaben903&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_authorization/pull/57" rel="noopener noreferrer"&gt;#57&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;puppetlabs/concat: Allow 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_authorization/pull/55" rel="noopener noreferrer"&gt;#55&lt;/a&gt; (&lt;a href="https://github.com/bastelfreak" rel="noopener noreferrer"&gt;bastelfreak&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Create LICENSE &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_authorization/pull/52" rel="noopener noreferrer"&gt;#52&lt;/a&gt; (&lt;a href="https://github.com/binford2k" rel="noopener noreferrer"&gt;binford2k&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  sce_linux 2.8.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-28 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/sce_linux" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Updates CIS Benchmarks from v3.0.0 to v4.0.0 for RHEL 8, AlmaLinux 8, and Oracle Linux 8, with matching control updates for each, and fixes three bugs affecting benchmark enforcement.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Updated CIS Benchmarks.&lt;/strong&gt; RHEL 8, AlmaLinux 8, and Oracle Linux 8 move from CIS Benchmark v3.0.0 to v4.0.0, with matching control updates for each operating system.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Updated dependency.&lt;/strong&gt; SCE for Linux now supports puppetlabs-stdlib &amp;gt;= 9.2.0 &amp;lt; 11.0.0; avoid using earlier stdlib versions.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fixed:&lt;/strong&gt; the user-specified &lt;code&gt;default_zone&lt;/code&gt; setting was not enforced for CIS control 3.4.1.2; it is now enforced correctly.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fixed:&lt;/strong&gt; &lt;code&gt;aide --init&lt;/code&gt; failed on RHEL/AlmaLinux/Oracle Linux/Rocky Linux 8 hosts shipping AIDE 0.17.x, which renamed the &lt;code&gt;database=&lt;/code&gt; directive to &lt;code&gt;database_in=&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fixed:&lt;/strong&gt; CIS control 6.2.2.2 (journald log-forwarding) did not work as designed on RHEL/AlmaLinux/Oracle Linux/Rocky Linux 9 and 10; control 6.2.3.3 was also added.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/sce/current/linux/scel_relnotes_280.htm" rel="noopener noreferrer"&gt;release notes for sce_linux 2.8.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  scheduled_task 5.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-13 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/scheduled_task" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) and also adds Windows Server 2025 support.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2391) Puppet Core upgrade (BREAKING) — drops Puppet 7 support &lt;a href="https://github.com/puppetlabs/puppetlabs-scheduled_task/pull/271" rel="noopener noreferrer"&gt;#271&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;[MODULES-11616] Adding Windows 2025 support to module &lt;a href="https://github.com/puppetlabs/puppetlabs-scheduled_task/pull/275" rel="noopener noreferrer"&gt;#275&lt;/a&gt; (&lt;a href="https://github.com/jst-cyr" rel="noopener noreferrer"&gt;jst-cyr&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Update link to contributing documentation &lt;a href="https://github.com/puppetlabs/puppetlabs-scheduled_task/pull/273" rel="noopener noreferrer"&gt;#273&lt;/a&gt; (&lt;a href="https://github.com/jst-cyr" rel="noopener noreferrer"&gt;jst-cyr&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  sslcertificate 6.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-22 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/sslcertificate" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) and allows the stdlib dependency to move to 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2394) Puppet Core update (BREAKING) — drops Puppet 7 support &lt;a href="https://github.com/puppetlabs/puppetlabs-sslcertificate/pull/142" rel="noopener noreferrer"&gt;#142&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-sslcertificate/pull/143" rel="noopener noreferrer"&gt;#143&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  windows_env 6.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-21 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/windows_env" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Windows Server 2025 support.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11891) Add Windows Server 2025 support &lt;a href="https://github.com/puppetlabs/puppetlabs-windows_env/pull/115" rel="noopener noreferrer"&gt;#115&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  windows_eventlog 5.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-07-22 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/windows_eventlog" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Windows Server 2025 support.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11892) Add Windows Server 2025 support &lt;a href="https://github.com/puppetlabs/puppetlabs-windows_eventlog/pull/98" rel="noopener noreferrer"&gt;#98&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Until Next Time!
&lt;/h2&gt;

&lt;p&gt;That wraps up the July 2026 roundup. If any of these modules intersect with your environment. especially the cd4peadm breaking change to commit status contexts and the Puppet 7 removals, the linked Forge pages and release notes are worth a closer look before upgrading.&lt;/p&gt;

&lt;p&gt;Feedback on the series is always useful, especially if there are module families or release-note patterns that deserve more attention in future editions!&lt;/p&gt;

&lt;p&gt;More updates coming next month when the August 2026 releases land.&lt;/p&gt;

&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;This roundup is produced by a mostly-automated pipeline, with some AI sprinkled in for orchestration and enrichment (or 'Combobulating' and 'Finagling'), followed by a human review (that would be me) before publishing.&lt;/p&gt;

&lt;p&gt;The automation is an &lt;a href="https://github.com/jst-cyr/puppetlabs-modules-roundup-writer" rel="noopener noreferrer"&gt;open-source project&lt;/a&gt; with deterministic python scripts to crawl the Forge and determine which &lt;code&gt;puppetlabs&lt;/code&gt; modules were released during a specific month (and catching when a module gets more than one release in a month). By combining a template, automation scripts, and some AI orchestration the content all gets pulled together for a structured markdown document. I then jump in to double-check the content and update any wording that seems repetitive or irrelevant (and sometimes I need to add some extra context that isn't in the changelog notes).&lt;/p&gt;

</description>
      <category>puppet</category>
    </item>
    <item>
      <title>New Benchmarks now Available for Puppet SCE for Linux</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 30 Jul 2026 11:49:16 +0000</pubDate>
      <link>https://dev.to/puppet/new-benchmarks-now-available-for-puppet-sce-for-linux-34jf</link>
      <guid>https://dev.to/puppet/new-benchmarks-now-available-for-puppet-sce-for-linux-34jf</guid>
      <description>&lt;p&gt;Security Compliance Enforcement (SCE) for Linux 2.8.0 is now available, delivering updated CIS Benchmark coverage along with improvements to policy enforcement, auditing, and logging reliability. These updates help organizations strengthen compliance programs, reduce operational risk, and maintain confidence that Linux systems remain aligned with security and governance requirements.&amp;nbsp;SCE for Linux is available as part of Puppet Core and Puppet Enterprise Advanced.  &lt;/p&gt;

&lt;h2&gt;
  
  
  Why Upgrade?
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  Stay aligned with current CIS guidance&amp;nbsp;through updated benchmark coverage for major enterprise Linux distributions.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Improve audit readiness&amp;nbsp;with expanded benchmark coverage and updated compliance checks.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Reduce operational risk&amp;nbsp;through fixes that improve firewall, integrity monitoring, and logging behavior.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Increase confidence in enforcement&amp;nbsp;by addressing issues that could prevent configurations from being applied as intended.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What's New?
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  Updated CIS Benchmark support for RHEL 8, AlmaLinux 8, Oracle Linux 8, and Rocky Linux 8.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Enhancements that improve alignment with current benchmark recommendations across system hardening, auditing, networking, and account management.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Reliability improvements for firewall zone enforcement, AIDE-based integrity monitoring, and log forwarding.&lt;/li&gt;
&lt;li&gt;  Updated platform dependencies to support ongoing compatibility and maintainability.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Security and Maintenance Updates
&lt;/h2&gt;

&lt;p&gt;This release includes maintenance updates and issue resolutions that help improve platform stability, reduce security risk, and support more reliable compliance operations.&lt;/p&gt;

&lt;h2&gt;
  
  
  Next Steps
&lt;/h2&gt;

&lt;p&gt;Review the release notes for complete details and upgrade guidance, then plan your upgrade to take advantage of the latest benchmark coverage and reliability improvements.&lt;/p&gt;

&lt;p&gt;If you're new to SCE, visit the documentation page to learn how it helps automate compliance assessments, policy enforcement, and ongoing audit readiness across enterprise Linux environments.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/sce/current/linux/scel_relnotes_280.htm" rel="noopener noreferrer"&gt;SCE for Linux Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/sce/current/intro/sce_intro.htm" rel="noopener noreferrer"&gt;Learn more about SCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>puppet</category>
      <category>security</category>
      <category>linux</category>
    </item>
    <item>
      <title>Building with AI: Our Approach to Responsible Agentic Development in Open Source</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 28 Jul 2026 12:36:14 +0000</pubDate>
      <link>https://dev.to/puppet/building-with-ai-our-approach-to-responsible-agentic-development-in-open-source-5f2b</link>
      <guid>https://dev.to/puppet/building-with-ai-our-approach-to-responsible-agentic-development-in-open-source-5f2b</guid>
      <description>&lt;p&gt;The tech world has been building up towards the shift to a&amp;nbsp;&lt;strong&gt;fully agentic development life cycle&lt;/strong&gt;&amp;nbsp;for a few years now. AI is changing how software gets built.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Across the Puppet ecosystem, we're seeing a shift toward more agentic engineering workflows. AI helps generate code, shape documentation, and accelerate how Puppet modules evolve. This brings real benefits in speed and consistency, but it also raises important questions from the community:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  How are AI-generated changes validated?&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  How do you ensure consistency across modules?&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  What does this mean for contributors and maintainers?&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These are exactly the kinds of questions we should be asking! This article will outline how Perforce and the Puppet team are approaching the use of AI in our open source modules and repositories.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  How We Build Trust in AI-Assisted Contributions&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;At Perforce, AI is a core part of our process and our teams operate within a&amp;nbsp;&lt;strong&gt;defined, governed framework&lt;/strong&gt;&amp;nbsp;for development. We don’t rely on trust in the tool itself. We rely on the processes around it.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Whether a change is written by a person, generated with AI, or some mix of both, they are held to the same standards before it’s accepted and released.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In practice, that means:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Human review is always the gate:&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
Every change is reviewed by maintainers. AI can assist, but it doesn’t replace accountability.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;AI works within established patterns:&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
AI-generated code isn’t created in isolation. It’s guided by the same module structures, conventions, and expectations that already exist across the ecosystem.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Validation is continuous and enforced:&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
AI doesn’t change our standards. It reinforces them. AI-generated changes go through the same checks as any other contribution:&amp;nbsp;

&lt;ul&gt;
&lt;li&gt;  Test suites&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Integration validation&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Functional verification&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;AI output is a starting point, not a final artifact:&lt;/strong&gt;&amp;nbsp;
Generated code is iterated on, refined, and aligned before acceptance. We treat AI as an accelerator, not an authority.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;The community plays an important role&lt;/strong&gt;&amp;nbsp;
Open source means visibility. The community can review changes, raise issues, and contribute ideas. That feedback loop adds another layer of resilience and helps shape how these workflows evolve.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;At a high level, our approach is simple:&amp;nbsp;&lt;strong&gt;the outcome matters more than how the code was created.&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Community Contributions and AI&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;Community members are not required to use code assist tools when providing contributions to Puppet open source projects, even when those projects contain frameworks or files designed to support coding agents.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Contributions can be made using any tools or workflows that work best for you and there is no expectation to match the Perforce technology stack. While the Puppet team will be adding instructions, skills, and other artifacts to support agentic workflows, including tools like Claude Code, these are provided as optional enhancements, not requirements.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;When contributions are reviewed, the same standards apply regardless of how they were created. This includes contributions that contain AI-generated code, are submitted by AI agents, or have been tested or reviewed using AI tools. We welcome contributions in any form, but all submissions go through the same review and approval process before they are accepted and released.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Maintaining Consistency Across the Ecosystem&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;Another important question we hear is how we avoid duplication or inconsistency as AI becomes part of the workflow. This is where&amp;nbsp;&lt;strong&gt;ecosystem-level thinking and governance&lt;/strong&gt;&amp;nbsp;matter most and where we will be incrementally improving our engineering patterns.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Here’s how we approach that:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Changes are evaluated in context&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
We don’t review contributions in isolation. We look at how they relate to existing modules and whether similar functionality already exists.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Reuse is prioritized over duplication&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
When reviewing changes, we actively ask whether something can be reused instead of reimplemented. This helps maintain DRY principles across the ecosystem—not just within a single module.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Shared patterns guide development&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
AI-assisted changes are aligned to standard module structures, established design patterns, and proven implementation approaches. This helps ensure consistency even as contribution velocity increases.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Documentation is treated as part of the system&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
Generated documentation and supporting artifacts are treated as first-class components. This improves clarity, supports reuse, and helps maintain long-term consistency across modules.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Governance Is Built In, Not Bolted On&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;Building with AI tools is not left to individual discretion. AI usage at Perforce follows&amp;nbsp;&lt;a href="https://trust.perforce.com/resources?s=h4ucgvqdld3suqiwml8o4d&amp;amp;name=ai-governance-at-perforce" rel="noopener noreferrer"&gt;structured processes&lt;/a&gt;&amp;nbsp;designed to ensure quality, security, and accountability across the lifecycle.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Here’s what that looks like for Puppet open source teams:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;AI tools and workflows are intentionally reviewed&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
We evaluate how AI tools are used within our development process, including how they interact with existing systems and patterns. Only tools approved for use by the Perforce AI governance team can be used for agentic development by Perforce employees.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Risks and dependencies are actively managed&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
Using agentic development flows introduces new considerations from code duplication to unintended behaviors. These are identified, reviewed, and addressed as part of normal development workflows.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Security and compliance are built into the process&lt;/strong&gt;&amp;nbsp;&amp;nbsp;
AI-assisted development operates within the same security, permission, and compliance boundaries as any other contribution.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;AI usage is part of a broader&amp;nbsp;&lt;a href="https://www.perforce.com/press-releases/%20ISO-42001-Certification" rel="noopener noreferrer"&gt;&lt;strong&gt;AI management system aligned with ISO 42001&lt;/strong&gt;,&lt;/a&gt;&amp;nbsp;ensuring responsible use across the lifecycle.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;We also recognize the broader concerns around AI. We're deliberate about how and where AI is used. At its core, governance is about maintaining control while enabling progress. AI should operate within the systems teams already trust, not bypass them.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Our Commitment to the Open Source Community &amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;This evolution isn’t happening in isolation. The Puppet modules team works within an open source ecosystem and it’s important that the community is informed about AI usage and included so that all members of the community are able to provide feedback as these processes evolve.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Our goal is to provide:&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Clear communication about AI-assisted changes&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Transparency in how contributions are reviewed&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  Ongoing dialogue as workflows evolve&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is a new world of software delivery that we all maintainers and contributors are collaborating in, and we'll need to work together to find the right process for everyone.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  What This Means Going Forward&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;The agentic software development lifecycle is going to continue to shift and grow. AI will continue to play a growing role in how modules are developed and maintained.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;In your favorite Puppetlabs modules, you are going to see:&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Structural documentation, skills, instructions, and other frameworks to support agentic development&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  More AI-assisted contributions to open source repos&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  More structured documentation that aligns across the ecosystem&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  An increase in iteration cycles as agentic workflows grow and stabilize&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There is one thing that won't change:&amp;nbsp;&lt;strong&gt;Every contribution will be held to the same standards of quality, consistency, and trust.&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In the end, trust in AI doesn’t come from the model. It comes from the systems, processes, and people behind it.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;We want to hear from the community as we continue to evolve these practices and develop a solid agentic-supported workflow for our open source community. We’d love your feedback, so please share your thoughts here or in the Puppet Community Slack.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Additional Resources&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;These additional resources could be helpful if you are interested in this topic and want to learn more!&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://trust.perforce.com/resources?s=h4ucgvqdld3suqiwml8o4d&amp;amp;name=ai-governance-at-perforce" rel="noopener noreferrer"&gt;AI Governance at Perforce&lt;/a&gt;&amp;nbsp;(trust.perforce.com)&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.perforce.com/press-releases/%20ISO-42001-Certification" rel="noopener noreferrer"&gt;Perforce AI Products and Features Achive ISO 42001 Certification&lt;/a&gt;&amp;nbsp;(perforce.com)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;You'll probably notice a few tell-tale structural suggestions from AI on this one. I experimented with drafting with AI on this one, using our AI Governance documentation and some context I provided about how we work on the Puppet team. From that draft, it has gone through multiple human reviews and a LOT of editing and rework, with a final review by an AI agent for brand voice alignment. &lt;/p&gt;

</description>
      <category>ai</category>
      <category>puppet</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Puppetlabs Modules Now Have Tiered Review Cycles</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 14 Jul 2026 14:16:39 +0000</pubDate>
      <link>https://dev.to/puppet/puppetlabs-modules-now-have-tiered-review-cycles-42ob</link>
      <guid>https://dev.to/puppet/puppetlabs-modules-now-have-tiered-review-cycles-42ob</guid>
      <description>&lt;p&gt;If you've been watching the&amp;nbsp;&lt;a href="https://forge.puppet.com/modules/puppetlabs?utm_medium=social&amp;amp;utm_source=linkedin&amp;amp;utm_campaign=2026-puppet-cloud-repatriation-trends-2026&amp;amp;utm_content=blog&amp;amp;limit=25&amp;amp;sort_by=latest_release&amp;amp;module_groups=base%20pe_only" rel="noopener noreferrer"&gt;Puppetlabs namespace on the Forge&lt;/a&gt;&amp;nbsp;(or waiting on a pull request you opened) you've likely noticed that the pace of inclusion of community pull requests and fixes into the module releases has slowed over the last several cycles. That isn't how we want to serve the community that built these modules with us. The team has been reviewing how we can improve and this post is our commitment to do better. Here are the steps we're taking now:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Clear tiers with review cadences.&lt;/strong&gt;&amp;nbsp;Modules in the puppetlabs namespace will be grouped into three tiers, each with a defined review schedule (weekly, monthly, or quarterly).&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Defining what “review cadence” means in practice.&lt;/strong&gt;&amp;nbsp;Every community PR gets engineering review in the next scheduled cycle for that module’s tier. &amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Showing progress monthly.&lt;/strong&gt;&amp;nbsp;We’ll continue to publish the monthly Modules Roundup covering what was released.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  A Tiered Approach to Priorities&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;We've categorized supported modules in the puppetlabs namespace into three tiers, each with a defined community review cadence:&amp;nbsp;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;strong&gt;Tier&lt;/strong&gt;&lt;/th&gt;
&lt;th&gt;&lt;strong&gt;Count&lt;/strong&gt;&lt;/th&gt;
&lt;th&gt;&lt;strong&gt;Community review cadence&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Tier 1:&lt;/strong&gt; core, business-critical modules&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Weekly&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Tier 2:&lt;/strong&gt; important, meaningfully used modules&lt;/td&gt;
&lt;td&gt;19&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Monthly&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Tier 3:&lt;/strong&gt; niche or low-usage modules&lt;/td&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Quarterly&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  What a Review Cadence Means
&lt;/h3&gt;

&lt;p&gt;Every community pull request (PR) on a module in the puppetlabs namespace gets engineering review during the next scheduled cycle for that module's tier. This doesn’t mean that every PR will be accepted. Sometimes a pull request needs feedback or changes, some pull requests won't fit a module's direction, but the cadence is intended to make sure that PRs will no longer sit quietly in a queue. That is the baseline we're holding ourselves to with these tiers and review cadences.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;We do have a backlog of requests over the years and we will be working through that backlog as well, but priority will be given to active contributions for the purposes of our review cadence.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Tier 1: Our highest-priority modules&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;The following modules are our committed Tier 1 set. These modules will get a weekly review, with nightly CI coverage, and get priority on maintenance capacity:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  puppetlabs-apache&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-apt&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-augeas_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-concat&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-cron_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-docker&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-firewall&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-haproxy&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-inifile&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-java&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-java_ks&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-lvm&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-mount_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-mysql&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-ntp&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-package&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-postgresql&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-powershell&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-reboot&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-registry&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-ruby_task_helper&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-service&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-sshkeys_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-stdlib&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-vcsrepo&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Tier 2: Monthly reviews&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;The following modules have currently been assigned to our Tier 2 for prioritization. These modules will get a monthly review.&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &amp;nbsp;puppetlabs-accounts&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-acl&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-bolt_shim&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-chocolatey&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-facter_task&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-iis&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-kubernetes&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-motd&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-mount_iso&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-node_encrypt&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-puppet_conf&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-satellite_pe_tools&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-scheduled_task&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-sqlserver&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-sslcertificate&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-tomcat&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-windows_env&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-windows_eventlog&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-wsus_client&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Tier 3: Quarterly reviews&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;The modules assigned to Tier 3 are still supported but will not generally be getting a high degree of priority. These modules will be reviewed quarterly and released as needed.&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  ca_extend&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  influxdb&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppet_operational_dashboards&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-bash_task_helper&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-dropsonde&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-dsc_lite&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-facts&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-host_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-node_manager&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-pe_databases&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-pe_event_forwarding&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-pe_status_check&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-puppet_bolt_server&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-puppet_metrics_collector&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-puppet_status_check&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-selinux_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-splunk_hec&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-yumrepo_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-zfs_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  puppetlabs-zone_core&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  ruby-pwsh&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  support-tasks&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The Product and Engineering teams are still reviewing the puppetlabs modules for final placement in Tier 2 or Tier 3 and will follow the cadence associated with their tier once that placement is confirmed. Ultimately, the lists above might shift slightly as the team finds that some modules might need more attention than others.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  What has already shipped?&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;It is one thing to say you will do better and quite another to follow through. We’re sharing this now because we have tangible changes already underway. In a focused sprint on Tier 1 modules, the team &lt;strong&gt;triaged and actioned several open community pull requests,&lt;/strong&gt;&amp;nbsp;some merged after review, some closed after discussion, others consolidated with newer work. You’ll see several modules released this month and next with these merged changes on the Forge. Keep an eye on the&amp;nbsp;&lt;a href="https://forge.puppet.com/modules/puppetlabs?utm_medium=social&amp;amp;utm_source=linkedin&amp;amp;utm_campaign=2026-puppet-cloud-repatriation-trends-2026&amp;amp;utm_content=blog&amp;amp;limit=25&amp;amp;sort_by=latest_release&amp;amp;module_groups=base%20pe_only" rel="noopener noreferrer"&gt;Forge modules list&lt;/a&gt;&amp;nbsp;or check out the next&amp;nbsp;&lt;a href="https://dev.to/jasonstcyr/series/34389"&gt;Puppet Modules Roundup&lt;/a&gt;&amp;nbsp;post for a summary!&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  On the Issues With CI for community PRs&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;We're aware that testing community contributions has been harder than it should be. The current pull request model makes it difficult to run the full acceptance test suite against a contributor's PR without manual effort by Perforce employees, which slows reviews and discourages contributions. Solving this is a priority for the team and we have been prototyping an improved approach that will meet both user expectations and maintaining a secure infrastructure. We’ll share specifics once it's working end-to-end. This is a known gap we're committed to closing.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  How We'll Show Our Work&amp;nbsp;
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Monthly Modules Roundup.&lt;/strong&gt; We publish a roundup each month covering what &amp;nbsp;modules have been released, who contributed, and what’s next. You can follow the series here: Puppetlabs Modules Roundup on dev.to.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Contributor recognition.&lt;/strong&gt; The release notes on the Forge and in the monthly roundup will call out merged community PRs by name.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Public GitHub transparency.&lt;/strong&gt;&amp;nbsp;We will be following up with contributors directly in pull requests and issues in our open source modules. In advance of a release, we will continue to merge and close PRs so that you can see what will be included in an upcoming release.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How can you help?&amp;nbsp;
&lt;/h2&gt;

&lt;p&gt;Keep contributing! Keep filing issues. Keep telling us when a module is in your way. If a PR of yours has stalled out, please rebase it or comment on the PR. And if the tiering above looks wrong for how &lt;em&gt;you&lt;/em&gt; use Puppet day-to-day, let us know! The whole point of publishing this article is so that the community can understand what is changing and also to invite you to shape where the priority goes.&amp;nbsp;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Tiering is not a one-way decision.&lt;/strong&gt; &amp;nbsp;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The tiers outlined here have been based on the activity we have observed in our analytics and the importance identified by customers. If a module you depend on isn't in the tier you think it should be, or perhaps a long-waiting PR or issue is blocking you, reach out via the Puppet Community Slack or leave a comment on the monthly Puppet Modules Roundup posts. We want your input to make sure the tiering meet the needs of all our users.&lt;/p&gt;

</description>
      <category>puppet</category>
    </item>
    <item>
      <title>Puppetlabs Modules Roundup – June 2026</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 09 Jul 2026 19:38:46 +0000</pubDate>
      <link>https://dev.to/puppet/puppetlabs-modules-roundup-june-2026-23da</link>
      <guid>https://dev.to/puppet/puppetlabs-modules-roundup-june-2026-23da</guid>
      <description>&lt;p&gt;In June 2026 we saw the release of a new &lt;code&gt;stdlib 10&lt;/code&gt; that was mentioned &lt;a href="https://dev.to/puppet/what-you-need-to-know-about-the-new-puppetlabs-stdlib-10-in-june-2026-1jah"&gt;in an earlier article&lt;/a&gt; along with numerous modules bumped to use the new stdlib 10. In total, 24 Puppetlabs modules were released to the Forge, ranging from a brand-new Windows security policy module to a large batch of third-party CVE fixes in Security Compliance Management. This roundup pulls the most important changes into one place.&lt;/p&gt;

&lt;h2&gt;
  
  
  Highlighted Updates
&lt;/h2&gt;

&lt;h3&gt;
  
  
  New Module: Windows Local Security Policy Management
&lt;/h3&gt;

&lt;p&gt;The new &lt;a href="https://forge.puppet.com/modules/puppetlabs/security_policy/readme" rel="noopener noreferrer"&gt;security_policy module&lt;/a&gt; manages Windows local security policy using the Puppet Resource API, replacing manual &lt;code&gt;secedit&lt;/code&gt;/Local Security Policy editor work.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Provides the &lt;code&gt;security_option&lt;/code&gt; and &lt;code&gt;user_right_assignment&lt;/code&gt; resource types, covering all 45 Windows Privilege Rights and the System Access settings.&lt;/li&gt;
&lt;li&gt;Ships a well-known SID map with a PowerShell fallback for domain and custom accounts.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  stdlib 10.x Compatibility Pass
&lt;/h3&gt;

&lt;p&gt;A coordinated maintenance pass loosened the puppetlabs/stdlib dependency constraint across the module set to allow stdlib 10.x, clearing the way for downstream modules to pick up stdlib's latest release.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Affected modules: accounts, apache, apt, chocolatey, concat, docker, firewall, haproxy, inifile, lvm, motd, mysql, ntp, postgresql, wsus_client.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;More modules will be released in July as we roll out the support for stdlib 10.x.&lt;/p&gt;

&lt;h3&gt;
  
  
  Puppet Core Alignment / Puppet 7 Support Dropped
&lt;/h3&gt;

&lt;p&gt;Several modules completed their Puppet Core alignment pass this month, dropping Puppet 7 support in favor of Puppet 8 as Puppet 7 reaches end-of-life.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Affected modules: accounts, chocolatey, haproxy, java, motd, mysql, postgresql, stdlib.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A note that the change to drop Puppet 7 in postgresql was done in a patch release, instead of a major release. This has been corrected in postgresql 10.6.3 and the change will be done again in a major release of that module.&lt;/p&gt;

&lt;h3&gt;
  
  
  Security Compliance Management Patches ~40 CVEs
&lt;/h3&gt;

&lt;p&gt;Security Compliance Management 3.8.0, shipped as both &lt;code&gt;comply&lt;/code&gt; and &lt;code&gt;complyadm&lt;/code&gt;, updates a long list of bundled third-party components — Gorm.io, Protobuf, several Netty codec libraries, react-router, and KeyCloak — to close out roughly 40 CVEs.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Also updates the bundled CIS-CAT Pro Assessor to v4.63.0, adding new STIG benchmarks for Amazon Linux 2023, Windows 11, Oracle Linux 9, and RHEL 10.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What Updates Happened to Puppetlabs Modules in June 2026?
&lt;/h2&gt;

&lt;p&gt;The following is an alphabetical listing of modules which received updates in June 2026. If a module had multiple versions released, the updates are collected together, numbered with the "latest" version available.&lt;/p&gt;




&lt;h3&gt;
  
  
  accounts 9.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/accounts" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This release drops Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) as part of the module's Puppet Core alignment work, and allows the stdlib dependency to move to 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2352) Drop Puppet 7 support (BREAKING) — Puppet Core alignment &lt;a href="https://github.com/puppetlabs/puppetlabs-accounts/pull/509" rel="noopener noreferrer"&gt;#509&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-accounts/pull/513" rel="noopener noreferrer"&gt;#513&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  apache 13.2.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-28 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/apache" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds RHEL 10 support, restores the ModSecurity engine on RHEL 10 via EPEL, and allows both stdlib and concat to move to their 10.x releases.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Add missing parameters to mod_md &lt;a href="https://github.com/puppetlabs/puppetlabs-apache/pull/2621" rel="noopener noreferrer"&gt;#2621&lt;/a&gt; (&lt;a href="https://github.com/smortex" rel="noopener noreferrer"&gt;smortex&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11851) Restore ModSecurity engine on RHEL 10 via EPEL &lt;a href="https://github.com/puppetlabs/puppetlabs-apache/pull/2635" rel="noopener noreferrer"&gt;#2635&lt;/a&gt; (&lt;a href="https://github.com/SugatD" rel="noopener noreferrer"&gt;SugatD&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11739) Add RHEL 10 support &lt;a href="https://github.com/puppetlabs/puppetlabs-apache/pull/2629" rel="noopener noreferrer"&gt;#2629&lt;/a&gt; (&lt;a href="https://github.com/SugatD" rel="noopener noreferrer"&gt;SugatD&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-apache/pull/2632" rel="noopener noreferrer"&gt;#2632&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;puppetlabs/concat: Allow 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-apache/pull/2630" rel="noopener noreferrer"&gt;#2630&lt;/a&gt; (&lt;a href="https://github.com/bastelfreak" rel="noopener noreferrer"&gt;bastelfreak&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  apt 11.3.2
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-26 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/apt" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;A small release that only bumps the stdlib dependency to allow 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-apt/pull/1288" rel="noopener noreferrer"&gt;#1288&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  aws_inventory 0.8.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-17 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/aws_inventory" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This release allows the ruby_task_helper dependency to move to 1.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Allow ruby_task_helper 1.x &lt;a href="https://github.com/puppetlabs/puppetlabs-aws_inventory/pull/25" rel="noopener noreferrer"&gt;#25&lt;/a&gt; (&lt;a href="https://github.com/bastelfreak" rel="noopener noreferrer"&gt;bastelfreak&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  chocolatey 9.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/chocolatey" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Completes its Puppet Core alignment pass, improves package prefetch caching with case-insensitive matching, and allows stdlib 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2369) Puppet Core update &lt;a href="https://github.com/puppetlabs/puppetlabs-chocolatey/pull/378" rel="noopener noreferrer"&gt;#378&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11769) Cache prefetch results and match packages case-insensitively &lt;a href="https://github.com/puppetlabs/puppetlabs-chocolatey/pull/388" rel="noopener noreferrer"&gt;#388&lt;/a&gt; (&lt;a href="https://github.com/skyamgarp" rel="noopener noreferrer"&gt;skyamgarp&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-chocolatey/pull/387" rel="noopener noreferrer"&gt;#387&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  comply 3.8.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-12 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/comply" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Security Compliance Management 3.8.0 addresses roughly 40 CVEs across bundled third-party components, alongside operational fixes and licensing improvements.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Increased the CIS-CAT Pro Assessor license expiry time to a full year.&lt;/li&gt;
&lt;li&gt;Added a &lt;code&gt;license_path&lt;/code&gt; parameter to update the CIS-CAT Pro Assessor license without upgrading SCM.&lt;/li&gt;
&lt;li&gt;Added an &lt;code&gt;assessor_scan_timeout&lt;/code&gt; option to control the task timeout for Windows 2022 domain controllers.&lt;/li&gt;
&lt;li&gt;Added a background scan sweeper to detect and cancel scans stuck in the "running" state.&lt;/li&gt;
&lt;li&gt;Fixed a race condition where timed-out PE job status polls could leave scans permanently stuck.&lt;/li&gt;
&lt;li&gt;Updated Gorm.io, Protobuf, multiple Netty codec libraries, react-router, and KeyCloak to address roughly 40 CVEs.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement380" rel="noopener noreferrer"&gt;release notes for comply 3.8.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  complyadm 3.8.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-12 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/complyadm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Ships the same Security Compliance Management 3.8.0 update as &lt;code&gt;comply&lt;/code&gt;, covering the same ~40 CVE remediations and operational fixes.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Increased the CIS-CAT Pro Assessor license expiry time to a full year.&lt;/li&gt;
&lt;li&gt;Added a &lt;code&gt;license_path&lt;/code&gt; parameter to update the CIS-CAT Pro Assessor license without upgrading SCM.&lt;/li&gt;
&lt;li&gt;Added an &lt;code&gt;assessor_scan_timeout&lt;/code&gt; option to control the task timeout for Windows 2022 domain controllers.&lt;/li&gt;
&lt;li&gt;Added a background scan sweeper to detect and cancel scans stuck in the "running" state.&lt;/li&gt;
&lt;li&gt;Fixed a race condition where timed-out PE job status polls could leave scans permanently stuck.&lt;/li&gt;
&lt;li&gt;Updated Gorm.io, Protobuf, multiple Netty codec libraries, react-router, and KeyCloak to address roughly 40 CVEs.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement380" rel="noopener noreferrer"&gt;release notes for complyadm 3.8.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  concat 10.0.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-25 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/concat" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This targeted release was part of the wave of bumps for the stdlib dependency to allow 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-concat/pull/837" rel="noopener noreferrer"&gt;#837&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  docker 10.4.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-28 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/docker" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Removes the upper version limit on the puppetlabs/apt dependency, fixes &lt;code&gt;compose up&lt;/code&gt; argument ordering, and allows stdlib 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Do not limit puppetlabs/apt requirement &amp;lt; v12 &lt;a href="https://github.com/puppetlabs/puppetlabs-docker/pull/1056" rel="noopener noreferrer"&gt;#1056&lt;/a&gt; (&lt;a href="https://github.com/mpdude" rel="noopener noreferrer"&gt;mpdude&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fix argument order on compose up &lt;a href="https://github.com/puppetlabs/puppetlabs-docker/pull/1037" rel="noopener noreferrer"&gt;#1037&lt;/a&gt; (&lt;a href="https://github.com/deligatedgeek" rel="noopener noreferrer"&gt;deligatedgeek&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-docker/pull/1057" rel="noopener noreferrer"&gt;#1057&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  edgeops 1.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-25 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/edgeops" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds host key fingerprint verification for Bolt 5.1.0+ targets, along with a batch of NETCONF/SSH hardening fixes.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(PE-43703) Verify host key fingerprints supplied as &lt;code&gt;host-key-fingerprint&lt;/code&gt; in the target hash; takes precedence over &lt;code&gt;host-key-check&lt;/code&gt; and requires Bolt 5.1.0+. &lt;a href="https://github.com/puppetlabs/puppetlabs-edgeops/pull/38" rel="noopener noreferrer"&gt;#38&lt;/a&gt; (&lt;a href="https://github.com/owenbeckles" rel="noopener noreferrer"&gt;owenbeckles&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-42584) Correctly handle host key verification parameter &lt;a href="https://github.com/puppetlabs/puppetlabs-edgeops/pull/23" rel="noopener noreferrer"&gt;#23&lt;/a&gt; (&lt;a href="https://github.com/Ziaunys" rel="noopener noreferrer"&gt;Ziaunys&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-43619) Clean up SSH on timeout and always raise instead of returning partial data &lt;a href="https://github.com/puppetlabs/puppetlabs-edgeops/pull/33" rel="noopener noreferrer"&gt;#33&lt;/a&gt; (&lt;a href="https://github.com/Ziaunys" rel="noopener noreferrer"&gt;Ziaunys&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-43614) Add mutex synchronization for RPC message ID allocation &lt;a href="https://github.com/puppetlabs/puppetlabs-edgeops/pull/29" rel="noopener noreferrer"&gt;#29&lt;/a&gt; (&lt;a href="https://github.com/Ziaunys" rel="noopener noreferrer"&gt;Ziaunys&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-43652) Rename netconf_lock task to netconf_check_lock &lt;a href="https://github.com/puppetlabs/puppetlabs-edgeops/pull/35" rel="noopener noreferrer"&gt;#35&lt;/a&gt; (&lt;a href="https://github.com/Ziaunys" rel="noopener noreferrer"&gt;Ziaunys&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  firewall 8.5.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-25 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/firewall" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Two releases this month: 8.4.0 added CONNMARK-based policy routing support and several bugfixes, while 8.5.0 allows stdlib 10.x, drops &lt;code&gt;iptables-services&lt;/code&gt; from EL9+ package defaults, and fixes several ipset and chain-detection edge cases.&lt;/p&gt;

&lt;p&gt;Includes monthly releases: 8.5.0 (2026-06-25), 8.4.0 (2026-06-10).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-firewall/pull/1288" rel="noopener noreferrer"&gt;#1288&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(#1254) Remove iptables-services from EL9+ package defaults &lt;a href="https://github.com/puppetlabs/puppetlabs-firewall/pull/1296" rel="noopener noreferrer"&gt;#1296&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(feat) Add restore_mark, nfmask, ctmask support for CONNMARK-based policy routing &lt;a href="https://github.com/puppetlabs/puppetlabs-firewall/pull/1291" rel="noopener noreferrer"&gt;#1291&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(bugfix) Fix ipset idempotency: single-element array not in sync with String equivalent &lt;a href="https://github.com/puppetlabs/puppetlabs-firewall/pull/1286" rel="noopener noreferrer"&gt;#1286&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(bugfix) Fix log_level idempotency when explicitly setting the iptables default value &lt;a href="https://github.com/puppetlabs/puppetlabs-firewall/pull/1284" rel="noopener noreferrer"&gt;#1284&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  haproxy 8.2.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/haproxy" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Completes the module's Puppet 8 upgrade work, drops Puppet 7 support, and allows stdlib 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/642" rel="noopener noreferrer"&gt;#642&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2373) Remove puppet 7 &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/631" rel="noopener noreferrer"&gt;#631&lt;/a&gt; (&lt;a href="https://github.com/gavindidrichsen" rel="noopener noreferrer"&gt;gavindidrichsen&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2373)(02) Upgrade module to puppet 8 &lt;a href="https://github.com/puppetlabs/puppetlabs-haproxy/pull/629" rel="noopener noreferrer"&gt;#629&lt;/a&gt; (&lt;a href="https://github.com/gavindidrichsen" rel="noopener noreferrer"&gt;gavindidrichsen&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  inifile 6.4.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-25 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/inifile" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;A small release to allow stdlib 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-inifile/pull/570" rel="noopener noreferrer"&gt;#570&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  java 12.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/java" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds CentOS 9 and Debian 13 support, allows stdlib 10.x, and adds support for downloading from a login/password-protected URL.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2376) Puppet Core update &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/614" rel="noopener noreferrer"&gt;#614&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2152) Add support for CentOS 9 &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/606" rel="noopener noreferrer"&gt;#606&lt;/a&gt; (&lt;a href="https://github.com/skyamgarp" rel="noopener noreferrer"&gt;skyamgarp&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Add support for Debian 13 (trixie) &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/613" rel="noopener noreferrer"&gt;#613&lt;/a&gt; (&lt;a href="https://github.com/mika" rel="noopener noreferrer"&gt;mika&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Feat: Allow downloading from a login/password protected URL &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/588" rel="noopener noreferrer"&gt;#588&lt;/a&gt; (&lt;a href="https://github.com/JGodin-C2C" rel="noopener noreferrer"&gt;JGodin-C2C&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/626" rel="noopener noreferrer"&gt;#626&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  lvm 4.0.2
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-28 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/lvm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This lvm release bumps the stdlib dependency to allow 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-lvm/pull/384" rel="noopener noreferrer"&gt;#384&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  motd 8.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/motd" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Bolt 5.0 support, and allows stdlib 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2352) Puppet Core update &lt;a href="https://github.com/puppetlabs/puppetlabs-motd/pull/531" rel="noopener noreferrer"&gt;#531&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2463) Add bolt 5.0 support &lt;a href="https://github.com/puppetlabs/puppetlabs-motd/pull/535" rel="noopener noreferrer"&gt;#535&lt;/a&gt; (&lt;a href="https://github.com/gavindidrichsen" rel="noopener noreferrer"&gt;gavindidrichsen&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-motd/pull/558" rel="noopener noreferrer"&gt;#558&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  mysql 17.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/mysql" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Fixes the RHEL/CentOS Stream 10 version check, and allows stdlib 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2381) Puppet Core update &lt;a href="https://github.com/puppetlabs/puppetlabs-mysql/pull/1688" rel="noopener noreferrer"&gt;#1688&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fix version check for RHEL/CentOS Stream 10 &lt;a href="https://github.com/puppetlabs/puppetlabs-mysql/pull/1686" rel="noopener noreferrer"&gt;#1686&lt;/a&gt; (&lt;a href="https://github.com/kajinamit" rel="noopener noreferrer"&gt;kajinamit&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-mysql/pull/1707" rel="noopener noreferrer"&gt;#1707&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  ntp 11.1.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/ntp" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;A small release that only bumps the stdlib dependency to allow 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-ntp/pull/742" rel="noopener noreferrer"&gt;#742&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  peadm 3.38.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-30 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/peadm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds support for installing and upgrading to Puppet Enterprise 2023.8.10 and 2025.11.0, along with a cloud_database_host parameter for cloud-DB-backed installs.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Adding support for PE 2023.8.10 and 2025.11.0 &lt;a href="https://github.com/puppetlabs/puppetlabs-peadm/pull/673" rel="noopener noreferrer"&gt;#673&lt;/a&gt; (&lt;a href="https://github.com/CharithaDunuwille" rel="noopener noreferrer"&gt;CharithaDunuwille&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-44022) Add cloud_database_host parameter for cloud-DB-backed installs &lt;a href="https://github.com/puppetlabs/puppetlabs-peadm/pull/665" rel="noopener noreferrer"&gt;#665&lt;/a&gt; (&lt;a href="https://github.com/mcdonaldseanp" rel="noopener noreferrer"&gt;mcdonaldseanp&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-44247) Add peadm-path PG-major HA upgrade coverage for replica pe-puppetdb &lt;a href="https://github.com/puppetlabs/puppetlabs-peadm/pull/666" rel="noopener noreferrer"&gt;#666&lt;/a&gt; (&lt;a href="https://github.com/steveax" rel="noopener noreferrer"&gt;steveax&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(PE-44595) Don't emit empty dns_alt_names flag in subplans::install &lt;a href="https://github.com/puppetlabs/puppetlabs-peadm/pull/672" rel="noopener noreferrer"&gt;#672&lt;/a&gt; (&lt;a href="https://github.com/steveax" rel="noopener noreferrer"&gt;steveax&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  postgresql 10.6.2
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-29 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/postgresql" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds basic EL10 support, allows both stdlib and concat to move to their 10.x releases, and fixes a bug where &lt;code&gt;postgresql_conf&lt;/code&gt; resources set to absent were handled incorrectly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;NOTE:&lt;/strong&gt; This release also incorrectly removed Puppet 7 support as a breaking change in a patch release. This has since been rolled back in 10.6.3. Removing Puppet 7 support will happen in a future major release.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;add EL10 basic support - align EL10 PGSQL 16 default package version &lt;a href="https://github.com/puppetlabs/puppetlabs-postgresql/pull/1650" rel="noopener noreferrer"&gt;#1650&lt;/a&gt; (&lt;a href="https://github.com/ikonia" rel="noopener noreferrer"&gt;ikonia&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;fix: ignore postgresql_conf resource value when set to absent &lt;a href="https://github.com/puppetlabs/puppetlabs-postgresql/pull/1657" rel="noopener noreferrer"&gt;#1657&lt;/a&gt; (&lt;a href="https://github.com/davidassigbi" rel="noopener noreferrer"&gt;davidassigbi&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;grant creation via hiera through server::grant.pp &lt;a href="https://github.com/puppetlabs/puppetlabs-postgresql/pull/1668" rel="noopener noreferrer"&gt;#1668&lt;/a&gt; (&lt;a href="https://github.com/ikonia" rel="noopener noreferrer"&gt;ikonia&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-postgresql/pull/1681" rel="noopener noreferrer"&gt;#1681&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;puppetlabs/concat: Allow 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-postgresql/pull/1669" rel="noopener noreferrer"&gt;#1669&lt;/a&gt; (&lt;a href="https://github.com/bastelfreak" rel="noopener noreferrer"&gt;bastelfreak&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  sce_linux 2.7.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-16 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/sce_linux" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds CIS Benchmark support for the RHEL 10 family, fixes an rsyslog configuration file that was unconditionally overwritten, and drops RHEL 7 now that it's end of life.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Support for RHEL 10, AlmaLinux 10, Oracle Linux 10, and Rocky Linux 10.&lt;/strong&gt; Enforces the CIS Benchmark for RHEL 10 (v1.0.1, Server Levels 1 and 2) and CIS Benchmark v1.0.0 for AlmaLinux 10, Oracle Linux 10, and Rocky Linux 10.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;rsyslog.conf file unconditionally overwritten.&lt;/strong&gt; Previously overwritten on every Puppet run even when logging configuration was set to ignore, affecting RHEL 7/8/9 and derivatives. No action required from users.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Advanced Intrusion Detection Environment (AIDE) utility class.&lt;/strong&gt; Fixed incorrect configuration options generated for AIDE 0.19.x on RHEL 9 that caused &lt;code&gt;aide --init&lt;/code&gt; to fail.&lt;/li&gt;
&lt;li&gt;RHEL &lt;strong&gt;7.&lt;/strong&gt; RHEL 7 is end of life and no longer supported.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/sce/current/linux/scel_relnotes_270.htm" rel="noopener noreferrer"&gt;release notes for sce_linux 2.7.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  security_policy 1.0.0
&lt;/h3&gt;

&lt;p&gt;🌟 &lt;strong&gt;&lt;em&gt;New Module:&lt;/em&gt;&lt;/strong&gt; 2026-06-25 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/security_policy" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Brand-new module for managing Windows local security policy. Provides the &lt;code&gt;security_option&lt;/code&gt; and &lt;code&gt;user_right_assignment&lt;/code&gt; resource types (Puppet Resource API), covering all 45 Windows Privilege Rights and System Access settings. Initial release contains:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;security_option&lt;/code&gt; and &lt;code&gt;user_right_assignment&lt;/code&gt; resource types for managing Windows local security policy settings via &lt;code&gt;secedit&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;security_policy&lt;/code&gt; class exposing 45 &lt;code&gt;Optional[Array[String]]&lt;/code&gt; parameters (one per privilege right), matching the layout of the legacy &lt;code&gt;dsc/securitypolicydsc&lt;/code&gt; module.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;PuppetX::Sid&lt;/code&gt; module: a static well-known SID map covering the 19 standard SIDs, with a PowerShell fallback via &lt;code&gt;Pwsh::Manager&lt;/code&gt; for domain and custom accounts.&lt;/li&gt;
&lt;li&gt;YAML-driven setting metadata loader (&lt;code&gt;PuppetX::SecurityPolicy.all_settings&lt;/code&gt;) instead of a hardcoded settings hash.&lt;/li&gt;
&lt;li&gt;Puppet requirement pinned to &amp;gt;= 8.0.0 &amp;lt; 9.0.0.&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  stdlib 10.0.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-30 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/stdlib" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops Puppet 7 support, adds CentOS 9 support, extends Sensitive value support to more functions, and fixes &lt;code&gt;has_ip_address&lt;/code&gt;/&lt;code&gt;has_ip_network&lt;/code&gt;.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2395) Puppet Core upgrade - drop support for Puppet 7 &lt;a href="https://github.com/puppetlabs/puppetlabs-stdlib/pull/1457" rel="noopener noreferrer"&gt;#1457&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2152) Add support for CentOS 9 &lt;a href="https://github.com/puppetlabs/puppetlabs-stdlib/pull/1442" rel="noopener noreferrer"&gt;#1442&lt;/a&gt; (&lt;a href="https://github.com/skyamgarp" rel="noopener noreferrer"&gt;skyamgarp&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Support &lt;code&gt;Sensitive&lt;/code&gt; values in more functions &lt;a href="https://github.com/puppetlabs/puppetlabs-stdlib/pull/1463" rel="noopener noreferrer"&gt;#1463&lt;/a&gt; (&lt;a href="https://github.com/alexjfisher" rel="noopener noreferrer"&gt;alexjfisher&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Support sensitive values in &lt;code&gt;to_json_pretty&lt;/code&gt; &lt;a href="https://github.com/puppetlabs/puppetlabs-stdlib/pull/1418" rel="noopener noreferrer"&gt;#1418&lt;/a&gt; (&lt;a href="https://github.com/alexjfisher" rel="noopener noreferrer"&gt;alexjfisher&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fix &lt;code&gt;has_ip_address&lt;/code&gt; and &lt;code&gt;has_ip_network&lt;/code&gt; functions &lt;a href="https://github.com/puppetlabs/puppetlabs-stdlib/pull/1448" rel="noopener noreferrer"&gt;#1448&lt;/a&gt; (&lt;a href="https://github.com/alexjfisher" rel="noopener noreferrer"&gt;alexjfisher&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  wsus_client 6.3.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-06-25 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/wsus_client" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;stdlib 10.x now allowed as part of the dependency range bump.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-wsus_client/pull/238" rel="noopener noreferrer"&gt;#238&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Until Next Time!
&lt;/h2&gt;

&lt;p&gt;That wraps up the June 2026 roundup. If any of these modules intersect with your environment — especially the Security Compliance Management CVE fixes — the linked Forge pages and release notes are worth a closer look.&lt;/p&gt;

&lt;p&gt;Feedback on the series is always useful, especially if there are module families or release-note patterns that deserve more attention in future editions.&lt;/p&gt;

&lt;p&gt;More updates coming next month when the July 2026 releases land.&lt;/p&gt;

&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;This roundup is produced by a mostly-automated pipeline, with some AI sprinkled in for orchestration and enrichment (or 'Combobulating' and 'Finagling'), followed by a human review (that would be me) before publishing.&lt;/p&gt;

&lt;p&gt;The automation is an &lt;a href="https://github.com/jst-cyr/puppetlabs-modules-roundup-writer" rel="noopener noreferrer"&gt;open-source project&lt;/a&gt; with deterministic python scripts to crawl the Forge and determine which &lt;code&gt;puppetlabs&lt;/code&gt; modules were released during a specific month (and catching when a module gets more than one release in a month). By combining a template, automation scripts, and some AI orchestration the content all gets pulled together for a structured markdown document. I then jump in to double-check the content and update any wording that seems repetitive or irrelevant (and sometimes I need to add some extra context that isn't in the changelog notes).&lt;/p&gt;

</description>
      <category>puppet</category>
    </item>
    <item>
      <title>Puppet Core 8.20 adds Ubuntu 26.04 and Security Fixes</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Mon, 06 Jul 2026 12:15:19 +0000</pubDate>
      <link>https://dev.to/puppet/puppet-core-820-adds-ubuntu-2604-and-security-fixes-1d84</link>
      <guid>https://dev.to/puppet/puppet-core-820-adds-ubuntu-2604-and-security-fixes-1d84</guid>
      <description>&lt;p&gt;The latest release of Puppet Core was targeted at addressing reported CVEs and adding agent support for Ubuntu 26.04, along with some other items that might be of interest to you! Here's a quick rundown on the highlights:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Ubuntu 26.04 (x86_64 and ARM) support added for Puppet agents&lt;/li&gt;
&lt;li&gt;Updated components for OpenSSL, net-imap, and concurrent-Ruby to address 13 CVEs&lt;/li&gt;
&lt;li&gt;Sensitive values are now handled correctly in &lt;code&gt;transactionstore.yaml&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;On macOS, &lt;code&gt;plist&lt;/code&gt; files are now written atomically to prevent partial or zero-length reads.&lt;/li&gt;
&lt;li&gt;PXP agent metadata now uses uniquely named temporary files to resolve file-rename race conditions that were happening for Windows tasks.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This was just my quick summary of the notes, so make sure to read the &lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-8-20-0.htm" rel="noopener noreferrer"&gt;full release notes for Puppet Core 8.20&lt;/a&gt; to get all the details before you upgrade!&lt;/p&gt;

</description>
      <category>devops</category>
      <category>puppet</category>
      <category>ubuntu</category>
    </item>
    <item>
      <title>Puppet Enterprise Introduces Database-Backed CA Storage in 2025.11 release</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 02 Jul 2026 15:32:28 +0000</pubDate>
      <link>https://dev.to/puppet/puppet-enterprise-introduces-database-backed-ca-storage-in-202511-release-epl</link>
      <guid>https://dev.to/puppet/puppet-enterprise-introduces-database-backed-ca-storage-in-202511-release-epl</guid>
      <description>&lt;p&gt;The latest Puppet Enterprise releases are out and this one has a huge load of improvements, fixes, and security patches included!&lt;/p&gt;

&lt;h2&gt;
  
  
  Puppet Enterprise (PE) 2025.11 released!
&lt;/h2&gt;

&lt;p&gt;The full &lt;a href="https://help.puppet.com/pe/current/topics/release-notes-pe-x-11.htm" rel="noopener noreferrer"&gt;PE 2025.11 release notes&lt;/a&gt; are always the best way to get a full detail on what has changed, but here are some highlights of PE 2025.11!&lt;/p&gt;

&lt;h3&gt;
  
  
  Certificate Authority (CA): Database-backed Storage
&lt;/h3&gt;

&lt;p&gt;This new optional feature adds support for storing CA data in a PostgreSQL database instead of the file system. This improves performance and reliability and introduces API-driven capabilities and enhanced backup and recovery handling.&lt;/p&gt;

&lt;h3&gt;
  
  
  PostgreSQL 17 Supported
&lt;/h3&gt;

&lt;p&gt;PE-managed installations will automatically upgrade from verson 14 to 17 as part of the upgrade process, or you can update yourself before upgrading to PE 2025.11&lt;/p&gt;

&lt;h3&gt;
  
  
  Infra Assistant Goes GPT-5
&lt;/h3&gt;

&lt;p&gt;GPT-5 series models are now running under the hood of Infra Assistant, improving the quality of responses and the consistency for queries.&lt;/p&gt;

&lt;h3&gt;
  
  
  Advanced Patching Enhancements
&lt;/h3&gt;

&lt;p&gt;The advanced patching feature now has improvements across a variety of areas&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;New &lt;code&gt;puppet_run_concurrency&lt;/code&gt; setting allows you to get better performance out of patch group enrollment&lt;/li&gt;
&lt;li&gt;Improved validation of scheduled and immediate jobs to reduce risk of unintended or skipped executions.&lt;/li&gt;
&lt;li&gt;Cron scheduling has better user experience and improved validation across features.&lt;/li&gt;
&lt;li&gt;New configurable option to enable Puppet to run after patch jobs to refresh &lt;code&gt;pe_patch&lt;/code&gt; facts &lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  New Endpoints for Classifier and Activity Service APIs
&lt;/h3&gt;

&lt;p&gt;The Classifier API introduced new &lt;code&gt;tags&lt;/code&gt;, &lt;code&gt;add-tags&lt;/code&gt; and &lt;code&gt;remove-tags&lt;/code&gt; endpoints to manage node group tags. The Activity service API now has &lt;code&gt;subscriptions&lt;/code&gt; endpoints to create subscriptions, list subscriptions, or fetch/delete a specific subscription.&lt;/p&gt;

&lt;h3&gt;
  
  
  Agent Platform Updates, Resolved Issues, and Security Fixes
&lt;/h3&gt;

&lt;p&gt;The macOS 26 platform is now supported for both ARM and x86_64, while support has been removed for Ubuntu 18.04 and Ubuntu 20.04.&lt;/p&gt;

&lt;p&gt;Nearly 60 CVEs were addressed in this release, along with many resolved issues. You should definitely check out the &lt;a href="https://help.puppet.com/pe/current/topics/release-notes-pe-x-11.htm" rel="noopener noreferrer"&gt;release notes&lt;/a&gt; for the full list of fixes! &lt;/p&gt;

&lt;h2&gt;
  
  
  PE 2023.8.10 Released
&lt;/h2&gt;

&lt;p&gt;Along with the new 2025.11 release, the latest patches for the LTS version PE 2023.8 has also been put out. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Agent platforms&lt;/strong&gt; were a big change, as macOS 26 was added, along with removing support for Ubuntu 18 and Ubuntu 20.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Nearly 60 CVEs resolved&lt;/strong&gt; in this release, many by component updates.&lt;/li&gt;
&lt;li&gt;Some additional fixes made in 2025.11 have also been inherited for the Activity service API and LDAP group attributes handling.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Official Release Notes
&lt;/h2&gt;

&lt;p&gt;Read more in the full release notes on help.puppet.com ⬇️&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/pe/current/topics/release-notes-pe-x-11.htm" rel="noopener noreferrer"&gt;PE 2025.11 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://help.puppet.com/pe/2023.8/topics/release-notes-pe-x-y-10.htm" rel="noopener noreferrer"&gt;PE 2023.8.10 Release Notes&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://www.puppet.com/downloads/puppet-enterprise" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;Download Puppet Enterprise&lt;/a&gt;
&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>devops</category>
    </item>
    <item>
      <title>RHEL 10 support now available in Puppet SCE for Linux</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 18 Jun 2026 16:16:41 +0000</pubDate>
      <link>https://dev.to/puppet/rhel-10-support-now-available-in-puppet-sce-for-linux-4opi</link>
      <guid>https://dev.to/puppet/rhel-10-support-now-available-in-puppet-sce-for-linux-4opi</guid>
      <description>&lt;p&gt;Version 2.7.0 of Security Compliance Enforcement (SCE) for Linux is now &lt;a href="https://forge.puppet.com/modules/puppetlabs/sce_linux/readme" rel="noopener noreferrer"&gt;available for download from the Forge&lt;/a&gt;!&lt;/p&gt;

&lt;h2&gt;
  
  
  Support for the RHEL 10 family
&lt;/h2&gt;

&lt;p&gt;This release adds Red Hat Enterprise Linux (RHEL) 10 CIS benchmarks (v1.0.1, Server Levels 1 and 2). Teams adopting RHEL 10 or a compatible platform can bring those systems into compliance using the same trusted standards already in place across earlier RHEL versions.&lt;/p&gt;

&lt;h2&gt;
  
  
  Other improvements
&lt;/h2&gt;

&lt;p&gt;Some other issues were also addressed, including logging issues with the rsyslog configuration file and intrusion detection on RHEL 9.&lt;/p&gt;

&lt;p&gt;For all the details, make sure to read the &lt;a href="https://help.puppet.com/sce/current/linux/scel_relnotes_270.htm" rel="noopener noreferrer"&gt;full release notes&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://forge.puppet.com/modules/puppetlabs/sce_linux/readme" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;SCE Module on Puppet Forge&lt;/a&gt;
&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>security</category>
      <category>devops</category>
    </item>
    <item>
      <title>Security Compliance Management 3.8.0 Is Now Available</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 16 Jun 2026 13:31:38 +0000</pubDate>
      <link>https://dev.to/puppet/security-compliance-management-380-is-now-available-1o26</link>
      <guid>https://dev.to/puppet/security-compliance-management-380-is-now-available-1o26</guid>
      <description>&lt;p&gt;Security Compliance Management (SCM) 3.8.0 is here, with updates focused on keeping compliance scans running reliably with less manual intervention and &lt;strong&gt;an important license update&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This release introduces automatic cleanup for stuck scans, improved control over scan behavior with configurable timeouts, extended CIS-CAT® Pro Assessor license support, and updated benchmark content. It also includes important security fixes across core components.&lt;/p&gt;

&lt;p&gt;⚠️ We recommend upgrading to SCM 3.8.0 before &lt;strong&gt;June 21, 2026&lt;/strong&gt; to avoid disruption, as the CIS-CAT Pro Assessor license included in SCM 3.7.1 expires on that date.&lt;/p&gt;




&lt;h2&gt;
  
  
  What’s changing in SCM 3.8.0
&lt;/h2&gt;

&lt;h3&gt;
  
  
  CIS-CAT Pro Assessor licensing and version
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SCM 3.8.0 now contains CIS-CAT Pro Assessor v4.63.0&lt;/li&gt;
&lt;li&gt;The bundled &lt;strong&gt;CIS-CAT® Pro Assessor license&lt;/strong&gt; is now valid for &lt;strong&gt;one year&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;The license shipped with SCM 3.8.0 is valid until &lt;strong&gt;June 2027&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;The license included in &lt;strong&gt;SCM 3.7.1 expires on June 21, 2026&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can now also update the license without upgrading SCM:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;New &lt;code&gt;license_path&lt;/code&gt; parameter

&lt;ul&gt;
&lt;li&gt;Allows updating the CIS-CAT Pro Assessor license independently
&lt;/li&gt;
&lt;li&gt;Documentation: &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/update_assessor_license.htm" rel="noopener noreferrer"&gt;https://help.puppet.com/scm/current/Content/UserGuide/SCM/update_assessor_license.htm&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  Scan management, configuration, and reliability
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Added a &lt;strong&gt;background scan sweeper&lt;/strong&gt; to detect and cancel scans stuck in a "running" state&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed a race condition where timed-out Puppet Enterprise job status polls could leave scans permanently stuck&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New &lt;code&gt;assessor_scan_timeout&lt;/code&gt; option controls task timeout for &lt;strong&gt;Windows Server 2022 domain controllers&lt;/strong&gt; (Note: this isn't set by default)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Increased default &lt;strong&gt;Max GraphQL requests limit&lt;/strong&gt; to &lt;strong&gt;300 requests&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Benchmark coverage updates
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;New benchmarks added for Amazon Linux 2023 STIG, Microsoft Windows 11 STIG, Oracle Linux 9 STIG, RHEL 10 STIG, and SUSE 16&lt;/li&gt;
&lt;li&gt;Updated benchmarks for: Amazon Linux 2, macOS, Debian, Windows, and Ubuntu (see the release notes for specific benchmark updates)&lt;/li&gt;
&lt;li&gt;Removed benchmarks for:

&lt;ul&gt;
&lt;li&gt;Azure Compute Windows Server 2019 v1.0.1
&lt;/li&gt;
&lt;li&gt;Azure Compute Windows Server 2022 v1.0.0
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Security fixes
&lt;/h2&gt;

&lt;p&gt;This release includes updates to address 40 vulnerabilities across several components. The following components were updated to address the vulnerabilities:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Gorm.io&lt;/li&gt;
&lt;li&gt;Keycloak&lt;/li&gt;
&lt;li&gt;netty-codec&lt;/li&gt;
&lt;li&gt;netty-codec-http&lt;/li&gt;
&lt;li&gt;netty-codec-http2&lt;/li&gt;
&lt;li&gt;netty-codec-haproxy&lt;/li&gt;
&lt;li&gt;netty-handler&lt;/li&gt;
&lt;li&gt;Protobuf&lt;/li&gt;
&lt;li&gt;react-router&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Refer to the full release notes for the complete list of CVEs.&lt;/p&gt;




&lt;h2&gt;
  
  
  Upgrade guidance
&lt;/h2&gt;

&lt;p&gt;To avoid scan interruptions, upgrade to &lt;strong&gt;SCM 3.8.0 before June 21, 2026&lt;/strong&gt;. This ensures continued use of the CIS-CAT Pro Assessor, access to updated benchmark content, improved security posture, and improvements in scan processing.&lt;/p&gt;




&lt;h2&gt;
  
  
  Learn more
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Full release notes:
&lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement380" rel="noopener noreferrer"&gt;https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement380&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you have questions or need assistance upgrading, reach out to Puppet Support.&lt;/p&gt;

&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;This article was written and reviewed by the author, with the help of AI to assist in pulling together the details from multiple sources and general brand voice alignment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How did I do that?&lt;/strong&gt; For this particular article, I provided Microsoft 365 Copilot with the original release notes, my previous release announcement for 3.7.0, our company brand voice guidelines, and the official product release announcement that went out to customers. The LLM can then pull together the list of things that were updated and create a skeleton of an article. I then rewrite the content as needed to meet with my own tone of voice and get rid of the over-list-based approach that LLMs often take. It's also important to actually check back against the original release notes because sometimes the LLM will change certain words or remove words that change the meaning of what was in the release. I hope this helps if you are also writing with LLMs!&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>security</category>
      <category>devops</category>
      <category>infrastructureascode</category>
    </item>
  </channel>
</rss>
