<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: puppet</title>
    <description>The latest articles tagged 'puppet' on DEV Community.</description>
    <link>https://dev.to/t/puppet</link>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/tag/puppet"/>
    <language>en</language>
    <item>
      <title>Where to get your vendors' SOC 2 reports (AWS, Vercel, Supabase, GitHub, Stripe and 25 more)</title>
      <dc:creator>oded moshe</dc:creator>
      <pubDate>Wed, 30 Sep 2026 18:37:25 +0000</pubDate>
      <link>https://dev.to/__56bc6913b1c85e11/where-to-get-your-vendors-soc-2-reports-aws-vercel-supabase-github-stripe-and-25-more-4jg4</link>
      <guid>https://dev.to/__56bc6913b1c85e11/where-to-get-your-vendors-soc-2-reports-aws-vercel-supabase-github-stripe-and-25-more-4jg4</guid>
      <description>&lt;h2&gt;
  
  
  Your SOC 2 auditor will ask how you reviewed your vendors. Here is where 30 common startup vendors publish their SOC 2 report, who can download it, and what to check once you have it.
&lt;/h2&gt;

&lt;p&gt;If you are preparing for SOC 2, sooner or later your auditor asks how you reviewed the vendors that touch customer data. The usual evidence is each vendor's own SOC 2 report, plus a short record of what you checked in it.&lt;/p&gt;

&lt;p&gt;Getting the reports is fiddlier than it should be. Some live in a console, some behind a trust-center request form, and some only on certain plans. A few examples, each checked on the vendor's own pages:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;AWS&lt;/strong&gt;: download from AWS Artifact in the console, at no charge; an NDA acceptance applies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Google Cloud / Google Workspace&lt;/strong&gt;: Compliance Reports Manager, after signing in.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vercel&lt;/strong&gt;: request access through the Vercel Trust Center.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Supabase&lt;/strong&gt;: Team and Enterprise plan customers download it from the organization dashboard.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitHub&lt;/strong&gt;: Enterprise Cloud owners, from the Compliance tab in enterprise settings.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cloudflare&lt;/strong&gt;: Super Administrators, from Compliance Documents in the dashboard, after a confidentiality statement.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Stripe&lt;/strong&gt;: provided on request.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The full table of 30 vendors (Azure, Microsoft 365, Okta, Auth0, Datadog, Sentry, PagerDuty, OpenAI, Anthropic, MongoDB Atlas, Snowflake, Notion, Linear, Slack, HubSpot, Zoom, 1Password, Heroku, Netlify and more) is here, with links to each trust page:&lt;br&gt;
&lt;a href="https://policyseed.vercel.app/guides/vendor-soc-2-reports" rel="noopener noreferrer"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://policyseed.vercel.app/guides/vendor-soc-2-reports" rel="noopener noreferrer"&gt;https://policyseed.vercel.app/guides/vendor-soc-2-reports&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Downloading the PDF is not the review
&lt;/h2&gt;

&lt;p&gt;Read these six parts and write down what you found:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Type and period.&lt;/strong&gt; A Type II covers a period of operation; a Type I is a single date. If the period ended long ago, ask for the newer report or a bridge letter.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scope.&lt;/strong&gt; Make sure the system description covers the product you actually use. Big vendors publish several reports.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The auditor's opinion.&lt;/strong&gt; Unqualified is the expected result. A qualified opinion means a material problem: read which criterion and why.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exceptions in the test results.&lt;/strong&gt; A clean opinion can still come with individual deviations. Decide whether any affect how you use the vendor.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Complementary user entity controls.&lt;/strong&gt; What the vendor expects &lt;em&gt;you&lt;/em&gt; to do: enable MFA, manage your own users, configure encryption. Those become your controls.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subservice organizations.&lt;/strong&gt; The vendor's own vendors (often a cloud provider), usually carved out. Note them as fourth parties.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Record the date, the report period, the reviewer, any exceptions and your decision. That record, not the PDF, is what the auditor samples.&lt;/p&gt;

&lt;h2&gt;
  
  
  Keep it proportionate
&lt;/h2&gt;

&lt;p&gt;A small company can easily use dozens of SaaS tools, and not all of them need a SOC 2 review. Tier vendors by the data they touch: the ones that store or process customer data get a full review with the report; tools with no customer data get a short documented check. Auditors look for a consistent rule applied to the whole inventory.&lt;/p&gt;

&lt;p&gt;If you need the policy that sets those tiers and the review cadence, there is a free, editable Vendor and Third-Party Risk Management Policy template (Word or Markdown, no signup) at &lt;a href="https://policyseed.vercel.app/policies/vendor-and-third-party-risk-policy" rel="noopener noreferrer"&gt;https://policyseed.vercel.app/policies/vendor-and-third-party-risk-policy&lt;/a&gt;. It is part of an open-source (Apache-2.0) set of 22 SOC 2 policies; I built it.&lt;/p&gt;

</description>
      <category>security</category>
      <category>startup</category>
      <category>devops</category>
      <category>puppet</category>
    </item>
    <item>
      <title>Cybersecurity Compliance for Developers: What "Audit-Ready" Really Means</title>
      <dc:creator>Diginatives LLC</dc:creator>
      <pubDate>Mon, 28 Sep 2026 12:27:38 +0000</pubDate>
      <link>https://dev.to/diginatives-llc/cybersecurity-compliance-for-developers-what-audit-ready-really-means-c29</link>
      <guid>https://dev.to/diginatives-llc/cybersecurity-compliance-for-developers-what-audit-ready-really-means-c29</guid>
      <description>&lt;p&gt;If you're a developer, the word "compliance" probably makes your shoulders tense. It sounds like paperwork, meetings, and someone asking you to screenshot a settings page at 5 p.m. on a Friday.&lt;/p&gt;

&lt;p&gt;Fair. But here's the thing: cybersecurity compliance touches your code, your pipelines, and your access controls far more than it touches a spreadsheet. So it's worth understanding, especially when a customer asks, "Do you have a SOC 2 report?" and your manager turns to look at you.&lt;/p&gt;

&lt;p&gt;Let's break it down without the fluff.&lt;/p&gt;

&lt;h2&gt;
  
  
  What compliance actually is
&lt;/h2&gt;

&lt;p&gt;Compliance means proving, with evidence, that you follow a defined set of security practices. Note the word &lt;em&gt;proving&lt;/em&gt;. Doing the right thing isn't enough; you need to show it.&lt;/p&gt;

&lt;p&gt;Common frameworks you'll hear about:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;SOC 2&lt;/strong&gt;: common for SaaS companies; checks controls around security, availability, confidentiality, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ISO 27001&lt;/strong&gt;: an international standard for running an information security management system&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PCI DSS&lt;/strong&gt;: required when you handle card payments&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;HIPAA&lt;/strong&gt;: for healthcare data in the US&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GDPR&lt;/strong&gt;: personal data protection for people in the EU&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Which one you need usually depends on your customers and your industry, not on your preference.&lt;/p&gt;

&lt;h2&gt;
  
  
  So what does "audit-ready" mean?
&lt;/h2&gt;

&lt;p&gt;Being audit-ready means that if an auditor walked in tomorrow, you could show them what you do and prove you've been doing it consistently.&lt;/p&gt;

&lt;p&gt;In practice, that boils down to a few habits:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Written policies that people actually follow.&lt;/strong&gt; A policy nobody reads is decoration.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Access control.&lt;/strong&gt; Who can reach production? Is it reviewed regularly? Do departed employees lose access the same day?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Change management.&lt;/strong&gt; Pull requests, reviews, and approvals leave a trail. Auditors love trails.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Logging and monitoring.&lt;/strong&gt; You can detect and investigate suspicious activity.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Risk assessments.&lt;/strong&gt; You've identified what could go wrong and decided what to do about it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vendor management.&lt;/strong&gt; You know which third parties touch your data.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Notice something? A lot of this is already sitting in Git, your cloud console, and your ticket tracker. The trick is collecting it neatly.&lt;/p&gt;

&lt;h2&gt;
  
  
  The developer-side checklist
&lt;/h2&gt;

&lt;p&gt;Here's what tends to land on an engineering team's plate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Enforce multi-factor authentication everywhere&lt;/li&gt;
&lt;li&gt;Require code review before merging to main&lt;/li&gt;
&lt;li&gt;Keep secrets out of repositories (use a vault or environment-based secrets manager)&lt;/li&gt;
&lt;li&gt;Patch dependencies and track known vulnerabilities&lt;/li&gt;
&lt;li&gt;Encrypt data in transit and at rest&lt;/li&gt;
&lt;li&gt;Back up critical data and test restoring it&lt;/li&gt;
&lt;li&gt;Keep infrastructure defined as code so changes are traceable&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of this is exotic. Most teams do half of it already, just informally.&lt;/p&gt;

&lt;h2&gt;
  
  
  Evidence is the boring, important part
&lt;/h2&gt;

&lt;p&gt;Auditors don't take your word for it. They want samples: a list of employees with production access, a few merged pull requests with approvals, an example of a resolved security incident.&lt;/p&gt;

&lt;p&gt;If you gather this once a year in a panic, it hurts. If you collect it continuously, say a monthly export of access reviews and a saved report from your vulnerability scanner, audit season becomes a non-event.&lt;/p&gt;

&lt;p&gt;Small tip: name and date your files clearly. "access-review-2026-09.pdf" beats "final_v3_new.pdf" every time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Type I vs Type II, quickly
&lt;/h2&gt;

&lt;p&gt;For SOC 2, a Type I report says your controls were designed properly at one moment in time. A Type II report says they actually worked over a period, often several months. Customers usually trust Type II more, but Type I is a reasonable first step for young companies.&lt;/p&gt;

&lt;h2&gt;
  
  
  When to bring in outside help
&lt;/h2&gt;

&lt;p&gt;Not every team has a security specialist. That's normal. Many companies hire external experts to run gap assessments, write policies, and guide them through the audit. If you're weighing that route, reading about &lt;a href="https://diginatives.io/blog/top-cybersecurity-compliance-firms-that-help-you-stay-audit-ready" rel="noopener noreferrer"&gt;cybersecurity compliance firms&lt;/a&gt; can help you understand what these partners typically offer before you start comparing them.&lt;/p&gt;

&lt;p&gt;Others prefer to add temporary security engineers to their own team through &lt;a href="https://diginatives.io/blog/staff-augmentation-vs-outsourcing" rel="noopener noreferrer"&gt;staff augmentation&lt;/a&gt;, which keeps day-to-day control in-house while filling the skills gap.&lt;/p&gt;

&lt;h2&gt;
  
  
  Mistakes I see teams make
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Treating compliance as a one-time project instead of an ongoing habit&lt;/li&gt;
&lt;li&gt;Buying tools before understanding the requirements&lt;/li&gt;
&lt;li&gt;Writing policies that describe how they &lt;em&gt;wish&lt;/em&gt; things worked&lt;/li&gt;
&lt;li&gt;Leaving engineers out of the conversation until the last minute&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last one is the big one. Bring developers in early and the controls fit your workflow. Bring them in late and everyone's annoyed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wrapping up
&lt;/h2&gt;

&lt;p&gt;Compliance won't make you unhackable, and it isn't magic. What it does is force you to build consistent, documented, reviewable security habits, and that's valuable whether or not a customer demands a certificate.&lt;/p&gt;

&lt;p&gt;Start small: pick one framework, list your current controls, and find the gaps. You'll likely be closer than you think.&lt;/p&gt;

&lt;p&gt;What's been the most annoying part of compliance on your team? Drop it in the comments.&lt;/p&gt;

</description>
      <category>security</category>
      <category>devops</category>
      <category>puppet</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Nigerian Fintech Architecture — Six Functions CBN Will Ask About in the Sandbox Application</title>
      <dc:creator>zikarelhub</dc:creator>
      <pubDate>Mon, 28 Sep 2026 08:26:23 +0000</pubDate>
      <link>https://dev.to/zikarelhub/nigerian-fintech-architecture-six-functions-cbn-will-ask-about-in-the-sandbox-application-hj3</link>
      <guid>https://dev.to/zikarelhub/nigerian-fintech-architecture-six-functions-cbn-will-ask-about-in-the-sandbox-application-hj3</guid>
      <description>&lt;p&gt;There is one architectural diagnostic that separates CBN Sandbox-ready Nigerian fintech from products that appear ready but have critical gaps.&lt;/p&gt;

&lt;p&gt;Can you name — precisely, with regulatory status — who performs each of these six functions in your product?&lt;/p&gt;

&lt;h2&gt;
  
  
  The Six Functions
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;architectureDiagnostic&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;kyc&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;                &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Named provider + regulatory status + KYC tier satisfied&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;sanctionsScreening&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Automated + onboarding AND ongoing + users AND counterparties&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;fxConversion&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;       &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Named licensed entity — "Paystack" is NOT an FX licence&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;custody&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;            &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Legally segregated — company bank account is NOT segregated custody&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;settlement&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;         &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;T+1 or T+2 — NOT the same as authorization&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;payout&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;             &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Named executor + SLA + failed payout handling + reconciliation&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  The Most Common Gaps
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;commonGaps&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
  &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;gap&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;"We use Paystack" as the FX answer&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;reality&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Paystack is a CBN-licensed PSP. Not an FX licence holder.&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;fix&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Named AFEX-licensed BDC, CBN-licensed IMTO or licensed fintech with FX permissions&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;gap&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;User funds in company bank account&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;reality&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;This is fund commingling — not segregated custody&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;fix&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Trust/escrow account at licensed bank — separate from operational account&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;gap&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Wallet credited on Paystack success&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;reality&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;That is authorization. Settlement is T+1 or T+2.&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;fix&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Credit wallet only on confirmed settlement — not on charge.success webhook&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;gap&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Sanctions screening at onboarding only&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;reality&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Users must be screened on an ongoing basis&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;fix&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Nightly screening job against UN, OFAC, NFIU, PEP lists&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  KYC — Named Provider Required
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Not "some verification service" — a named provider with named status&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;kycSetup&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;bvnVerification&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;NIBSS (Nigerian Inter-Bank Settlement System)&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;idVerification&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Smile Identity / Youverify / Prembly&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;livenessDetection&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;95%+ confidence required — defeats static photo attacks&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;sanctionsAndPEP&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Included in most Nigerian KYC providers&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;

  &lt;span class="c1"&gt;// VASP track additional&lt;/span&gt;
  &lt;span class="na"&gt;blockchainAnalytics&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Chainalysis / Elliptic / TRM Labs — ALL incoming deposits&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Settlement State Machine — Required
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Authorization ≠ Settlement — model this explicitly&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;STATES&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;INITIATED&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;  &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;created — no money moved&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;AUTHORIZED&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;bank approved — NOT settled, NOT available&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;SETTLED&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;in Paystack balance — T+1 or T+2&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;AVAILABLE&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;  &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;credited to user wallet — ready for use&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;

&lt;span class="c1"&gt;// Available balance: only settled credits minus pending debits&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;availableBalance&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;ledger&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`
  SELECT SUM(CASE
    WHEN entry_type = 'CREDIT' AND settlement_status = 'SETTLED' THEN amount
    WHEN entry_type = 'DEBIT' AND settlement_status IN ('PENDING','SETTLED') THEN -amount
    ELSE 0
  END) AS available
  FROM ledger_entries WHERE account_id = $userId
`&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  The Corridor Map
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Required CBN Sandbox document&lt;/span&gt;
&lt;span class="c1"&gt;// Every entity, their regulatory status, data flows, fund flows, failure scenarios&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;corridorMap&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;entities&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Your Platform&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;CBN Sandbox Applicant&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;NIBSS&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;CBN-regulated infrastructure&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Smile Identity&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Licensed KYC provider&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Paystack&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;CBN-licensed PSP&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Partner Bank&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;CBN-licensed commercial bank&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;],&lt;/span&gt;
  &lt;span class="na"&gt;fundFlow&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;User → Paystack (AUTHORIZED)&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Paystack escrow → Paystack balance (SETTLED T+1)&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Paystack → Trust account at Partner Bank (AVAILABLE)&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Trust account → User wallet ledger (CREDITED)&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;User wallet → Recipient via NIP (PAID OUT)&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;],&lt;/span&gt;
  &lt;span class="na"&gt;failureScenarios&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Paystack settlement delayed — do not credit user wallet&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;KYC provider down — queue and retry, do not onboard&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Sanctions match on existing user — suspend account, escalate&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;ZikarelHub LTD is Nigeria's #1 software and digital agency — Nigerian fintech built with the architectural clarity CBN examination requires.&lt;/p&gt;

&lt;p&gt;Which of the six functions does your product have the least clarity on right now? 👇&lt;/p&gt;

</description>
      <category>nigeria</category>
      <category>fintech</category>
      <category>puppet</category>
      <category>javascript</category>
    </item>
    <item>
      <title>Building a Living Case Database: Schema, Human-in-the-Loop AI, and the Math That Kills Most Niche Sites</title>
      <dc:creator>Hossam Saif</dc:creator>
      <pubDate>Thu, 24 Sep 2026 22:31:31 +0000</pubDate>
      <link>https://dev.to/hossam_saif_a73bc1dde9ff9/building-a-living-case-database-schema-human-in-the-loop-ai-and-the-math-that-kills-most-niche-4k5j</link>
      <guid>https://dev.to/hossam_saif_a73bc1dde9ff9/building-a-living-case-database-schema-human-in-the-loop-ai-and-the-math-that-kills-most-niche-4k5j</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnjwsek6b3gksz3i36t1x.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnjwsek6b3gksz3i36t1x.webp" alt=" " width="800" height="537"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Most "build a niche site" posts stop at the content strategy.&lt;br&gt;&lt;br&gt;
This one starts where those posts usually end: the operating model.&lt;/p&gt;

&lt;p&gt;I spent time reverse-engineering what it actually takes to run a site that publishes &lt;em&gt;living case files&lt;/em&gt; instead of one-and-done articles. The full blueprint (architecture, data model, nine-prompt production pipeline, privacy gates, economics, and monetization) is here:&lt;/p&gt;

&lt;p&gt;→ &lt;a href="https://www.moneytraces.com/2026/09/how-to-build-true-crime-case-tracking.html" rel="noopener noreferrer"&gt;How to Build a True-Crime Case-Tracking Website From Scratch&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;What follows is the part I think is most useful for builders: the data and process decisions that determine whether the site survives past the first six months.&lt;/p&gt;
&lt;h3&gt;
  
  
  1. The core unit is not an article — it's a row
&lt;/h3&gt;

&lt;p&gt;Every case is a structured record &lt;em&gt;before&lt;/em&gt; it becomes a page. The schema is deliberately over-normalized from day one:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;defendants&lt;/code&gt;, &lt;code&gt;victims&lt;/code&gt;, &lt;code&gt;attorneys&lt;/code&gt;, &lt;code&gt;judge&lt;/code&gt; are foreign keys (or arrays of FKs), not free-text fields.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;charges&lt;/code&gt; is its own table with per-charge legal status.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;hearings&lt;/code&gt; is an append-only log (newest first).&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;last_verified&lt;/code&gt; is a first-class field that drives the stale-case metric.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Why? Converting flat text into linked entities later is one of the most painful refactors you can do on a live site. Plan for the graph even if the MVP UI still renders everything as plain text.&lt;/p&gt;

&lt;p&gt;The page template is just a view over that schema:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Case Name / Docket
├── Status + Last Updated
├── Summary (2–3 sentences, rewritten as the case evolves)
├── Timeline (dated, newest first)
├── The Money / Harm
├── Key Documents
├── Related Cases
└── Update Log
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  2. The production system is nine prompts + one human gate
&lt;/h3&gt;

&lt;p&gt;This is not an autonomous AI newsroom. It's a research and drafting pipeline with mandatory human sign-off on every legal-status claim, every newly named person, and every publication decision.&lt;/p&gt;

&lt;p&gt;High-level flow:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Signal Hunter&lt;/strong&gt; – monitors new filings, hearings, sealed-to-unsealed changes
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Qualification&lt;/strong&gt; – hard PASS/FAIL gates (primary source exists? trackable docket? privacy risk?)
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source Hunter + Claim Ledger&lt;/strong&gt; – builds a citation table with claim ID, source, page/para, legal status, confidence
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Analysis&lt;/strong&gt; – patterns only if the ledger supports them; alternative explanations required
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Entity Map&lt;/strong&gt; – what lives on the permanent case page vs. what becomes a standalone explainer
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Case File Builder&lt;/strong&gt; – every factual sentence must cite a claim ID
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Accuracy + Privacy Gate&lt;/strong&gt; – the single most important step
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Update Check&lt;/strong&gt; – for already-tracked cases
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Distribution&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The privacy/accuracy gate is non-negotiable. Any open flag (minor identification, sealed records, presumption of guilt, secondary-only sources treated as fact) blocks publication.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. The real constraint is operating capacity, not content ideas
&lt;/h3&gt;

&lt;p&gt;Homicide Watch D.C. peaked at ~500k pageviews/month and still closed. The cost of keeping every active case current was effectively one full-time reporter. When the founders moved and couldn't find a local partner willing to fund that role, the site shut down.&lt;/p&gt;

&lt;p&gt;That is the actual problem this architecture tries to solve.&lt;/p&gt;

&lt;p&gt;Define these metrics &lt;em&gt;before&lt;/em&gt; you publish the first case file:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Target&lt;/th&gt;
&lt;th&gt;Warning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Active cases per editor&lt;/td&gt;
&lt;td&gt;15–25&lt;/td&gt;
&lt;td&gt;&amp;gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;High-activity cadence&lt;/td&gt;
&lt;td&gt;Daily&lt;/td&gt;
&lt;td&gt;&amp;gt;48h&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dormant cadence&lt;/td&gt;
&lt;td&gt;Weekly&lt;/td&gt;
&lt;td&gt;&amp;gt;14 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Stale-case rate&lt;/td&gt;
&lt;td&gt;&amp;lt;5%&lt;/td&gt;
&lt;td&gt;&amp;gt;10%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Correction rate&lt;/td&gt;
&lt;td&gt;&amp;lt;2 / 100&lt;/td&gt;
&lt;td&gt;&amp;gt;5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Site health formula:&lt;br&gt;&lt;br&gt;
&lt;code&gt;stale-case rate &amp;lt; 5% AND correction rate &amp;lt; 2&lt;/code&gt; → the site is delivering what it promised.&lt;br&gt;&lt;br&gt;
&lt;code&gt;stale-case rate &amp;gt; 10%&lt;/code&gt; → it has operationally collapsed, even if traffic looks great.&lt;/p&gt;

&lt;p&gt;Size the number of active cases to what one person can actually sustain, not to what would be editorially interesting.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Why this is interesting for builders
&lt;/h3&gt;

&lt;p&gt;Most AI content systems optimize for volume. This one optimizes for &lt;em&gt;trust under continuous update pressure&lt;/em&gt;. The claim ledger, the hard privacy gate, and the explicit automation boundary (what AI can draft vs. what a human must sign) are the parts that make the difference between a site that can keep running and one that quietly dies when the founder gets busy.&lt;/p&gt;

&lt;p&gt;If you're building anything that needs to stay accurate over time (case tracking, regulatory monitoring, product changelogs, research databases), the same pattern applies:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Structured schema first
&lt;/li&gt;
&lt;li&gt;Provenance on every claim
&lt;/li&gt;
&lt;li&gt;Explicit human gates on the high-risk decisions
&lt;/li&gt;
&lt;li&gt;Metrics that tell you when the operation is failing, not just when traffic is up&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Full write-up with the complete prompt set, site map, monetization layers, and real-world examples (Homicide Watch, DC Witness, CourtWatch, etc.) is here:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.moneytraces.com/2026/09/how-to-build-true-crime-case-tracking.html" rel="noopener noreferrer"&gt;https://www.moneytraces.com/2026/09/how-to-build-true-crime-case-tracking.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Curious what others have found when trying to keep structured "living" data products accurate at low headcount. The operating numbers are the part most architecture posts skip.&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>ai</category>
      <category>puppet</category>
      <category>sideprojects</category>
    </item>
    <item>
      <title>Puppet Core 9.1 and 8.22 adds Debian 12 ARM V7L support</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 22 Sep 2026 12:58:58 +0000</pubDate>
      <link>https://dev.to/puppet/puppet-core-91-and-822-adds-debian-12-arm-v7l-support-478g</link>
      <guid>https://dev.to/puppet/puppet-core-91-and-822-adds-debian-12-arm-v7l-support-478g</guid>
      <description>&lt;p&gt;The latest releases of Puppet Core 9 and Puppet Core 8 are now available! Both releases contain the same types of changes, with minor differences in versions of components that were updated. The new Debian 12 ARM V7L is the only new addition this release while the focus of the changes are on security updates and a pair of compatibility fixes that address issues some users may have encountered in production environments.&lt;/p&gt;

&lt;p&gt;If you're currently running Puppet Core 8.x or 9.x, this is a straightforward update worth planning for.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Changed in Puppet Core 9.1.0 and Puppet Core 8.22.0
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;New agent platform:&lt;/strong&gt; Debian 12 ARM V7L added as a supported agent platform.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Security updates:&lt;/strong&gt; Several bundled components received updates to address recently disclosed vulnerabilities: OpenSSL, curl, libxml2, RubyGems, Ruby's &lt;code&gt;resolv&lt;/code&gt; gem.&lt;/li&gt;
&lt;li&gt;Compatibility fix for &lt;code&gt;hiera-eyaml&lt;/code&gt; and Bouncy Castle&lt;/li&gt;
&lt;li&gt;JSON dependency constraints updated to &lt;code&gt;&amp;gt;=2.0, &amp;lt;4&lt;/code&gt; to prevent compatibility issues with latest JSON releases.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Together these updates address more than a dozen published CVEs. If you track vulnerabilities internally, review the release notes for the complete CVE listing associated with your Puppet version.&lt;/p&gt;

&lt;h2&gt;
  
  
  Notes for Puppet 8 vs Puppet 9 Users
&lt;/h2&gt;

&lt;p&gt;The customer-facing changes are effectively the same in both releases. There are a couple of implementation differences:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Puppet Core 8.22.0 updates OpenSSL 3.0.x, whereas 9.1.0 updates to OpenSSL 3.5.x&lt;/li&gt;
&lt;li&gt;Puppet Core 8.22.0 ships hiera-eyaml 4.3.0, whereas Puppet Core 9.1.0 ships hiera-eyaml 5.0.1&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The fixes and outcomes delivered by these updates are equivalent across both release tracks.&lt;/p&gt;

&lt;h2&gt;
  
  
  Full Release Notes
&lt;/h2&gt;

&lt;p&gt;Before upgrading, make sure to review the release notes for your release track:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/8/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-8-22-0.htm" rel="noopener noreferrer"&gt;Puppet Core 8.22.0 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://help.puppet.com/core/current/Content/PuppetCore/PuppetReleaseNotes/release_notes_puppet_x-9-1-0.htm" rel="noopener noreferrer"&gt;Puppet Core 9.1.0 Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This update is a small one operationally but an important one from a security and maintenance perspective. Make sure to drop any questions you have about the release either here or in the &lt;a href="https://slack.puppet.com" rel="noopener noreferrer"&gt;Puppet community slack&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>devops</category>
      <category>infrastructureascode</category>
      <category>debian</category>
    </item>
    <item>
      <title>A New Beginning This Festive Season: The Aishwaryam Vision for Modern Homeownership</title>
      <dc:creator>Sathish Sundaram</dc:creator>
      <pubDate>Tue, 22 Sep 2026 07:34:06 +0000</pubDate>
      <link>https://dev.to/sathish_sundaram_a32fbfc5/a-new-beginning-this-festive-season-the-aishwaryam-vision-for-modern-homeownership-1ill</link>
      <guid>https://dev.to/sathish_sundaram_a32fbfc5/a-new-beginning-this-festive-season-the-aishwaryam-vision-for-modern-homeownership-1ill</guid>
      <description>&lt;p&gt;The festive season often brings a renewed focus on new beginnings. For many people, that can mean starting a new chapter in their personal lives, reassessing financial goals, or finally exploring the possibility of owning a home.&lt;/p&gt;

&lt;p&gt;Link: &lt;a href="https://www.aishwaryam.com/blog/aishwaryam-vision-festive-season-homeownership/" rel="noopener noreferrer"&gt;https://www.aishwaryam.com/blog/aishwaryam-vision-festive-season-homeownership/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;But modern homeownership is changing. Buyers are increasingly looking beyond the traditional idea of purchasing a house. Location, connectivity, amenities, construction quality, community, convenience and long-term lifestyle requirements are becoming important parts of the decision-making process.&lt;/p&gt;

&lt;p&gt;This shift creates an opportunity to rethink what a new home should represent.&lt;/p&gt;

&lt;p&gt;The Changing Meaning of Homeownership&lt;/p&gt;

&lt;p&gt;A home is no longer evaluated only by its size or number of rooms. Today's buyers often consider how the property fits into their daily routine.&lt;/p&gt;

&lt;p&gt;How long is the commute? Are essential services accessible? Does the neighbourhood support the family's lifestyle? Are the amenities genuinely useful? What will the ownership experience look like several years from now?&lt;/p&gt;

&lt;p&gt;These questions are influencing how people research residential properties.&lt;/p&gt;

&lt;p&gt;The result is a more informed approach to homeownership, where buyers compare the overall living experience rather than focusing exclusively on the property itself.&lt;/p&gt;

&lt;p&gt;Why the Festive Season Can Be a Time for New Beginnings&lt;/p&gt;

&lt;p&gt;The festive season traditionally represents renewal and fresh starts. From a homebuyer's perspective, it can also be a natural point to review long-term plans.&lt;/p&gt;

&lt;p&gt;However, a festive season property investment should still be approached with the same level of due diligence as a property purchase at any other time.&lt;/p&gt;

&lt;p&gt;Festive offers or limited-period incentives should not replace fundamental checks such as:&lt;/p&gt;

&lt;p&gt;Project approvals and documentation&lt;br&gt;
Location and connectivity&lt;br&gt;
Construction quality&lt;br&gt;
Developer track record&lt;br&gt;
Total purchase and ownership costs&lt;br&gt;
Possession timelines&lt;br&gt;
Amenities and maintenance considerations&lt;br&gt;
Suitability for the buyer's long-term needs&lt;/p&gt;

&lt;p&gt;The occasion may create the motivation to explore a home, but research should guide the final decision.&lt;/p&gt;

&lt;p&gt;What Does Modern Homeownership Look Like?&lt;/p&gt;

&lt;p&gt;Modern homeownership increasingly revolves around convenience and adaptability.&lt;/p&gt;

&lt;p&gt;A well-planned residential environment can bring together homes, amenities, open spaces and community-oriented features designed around everyday living.&lt;/p&gt;

&lt;p&gt;For families considering a new home this festive season, the decision can therefore begin with a broader question:&lt;/p&gt;

&lt;p&gt;What kind of everyday life do we want our home to support?&lt;/p&gt;

&lt;p&gt;The answer can help narrow down choices based on location, configuration, amenities and budget.&lt;/p&gt;

&lt;p&gt;The Aishwaryam Vision&lt;/p&gt;

&lt;p&gt;The Aishwaryam vision focuses on creating residential environments that go beyond the basic definition of a house.&lt;/p&gt;

&lt;p&gt;The approach places emphasis on contemporary living, thoughtful planning, quality and the relationship between homes and their surrounding environment.&lt;/p&gt;

&lt;p&gt;For a real-estate developer, this means looking at homeownership from the resident's perspective—not simply as a transaction, but as part of a person's longer-term lifestyle.&lt;/p&gt;

&lt;p&gt;That perspective is particularly relevant as homebuyers become more research-oriented and compare projects across multiple dimensions before making a purchase.&lt;/p&gt;

&lt;p&gt;Technology Is Also Changing the Homebuying Journey&lt;/p&gt;

&lt;p&gt;The way people discover and evaluate properties has changed significantly.&lt;/p&gt;

&lt;p&gt;Buyers can now research projects online, compare locations, examine project information, watch walkthroughs, read reviews and investigate developers before scheduling a site visit.&lt;/p&gt;

&lt;p&gt;Search engines, social platforms and AI-powered discovery tools are also becoming part of the research journey.&lt;/p&gt;

&lt;p&gt;This makes transparency and accessible information increasingly important for real-estate brands.&lt;/p&gt;

&lt;p&gt;A modern homeownership vision therefore extends beyond the physical project. It also includes how clearly a developer communicates information throughout the buyer journey.&lt;/p&gt;

&lt;p&gt;A More Informed Festive-Season Decision&lt;/p&gt;

&lt;p&gt;Buying a home is a significant financial and lifestyle decision. Festive campaigns can encourage people to begin their search, but the decision itself should be based on factors that remain relevant after the celebrations are over.&lt;/p&gt;

&lt;p&gt;For buyers considering a new home this festive season, the process can begin with a simple checklist:&lt;/p&gt;

&lt;p&gt;Define your needs → Research locations → Compare projects → Verify documentation → Evaluate costs → Visit shortlisted properties → Make an informed decision&lt;/p&gt;

&lt;p&gt;A New Beginning, Thoughtfully Planned&lt;/p&gt;

&lt;p&gt;The idea of a new beginning has always been closely connected with the festive season. In the context of homeownership, it can represent more than moving into a new address.&lt;/p&gt;

&lt;p&gt;It can mean creating a space that supports family life, work, relationships, convenience and future aspirations.&lt;/p&gt;

&lt;p&gt;As expectations around residential living continue to evolve, the future of homeownership will likely be shaped by a combination of thoughtful design, accessible information, technology and a deeper understanding of how people actually live.&lt;/p&gt;

&lt;p&gt;For Aishwaryam, that is the larger idea behind its vision for modern homeownership: creating spaces where a new address can become the foundation for a new chapter.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fk90s68jizw40oz90nrpy.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fk90s68jizw40oz90nrpy.jpg" alt=" " width="800" height="370"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>realestate</category>
      <category>puppet</category>
    </item>
    <item>
      <title>CBN Regulatory Sandbox Cohort 2 — Technical Guide for Nigerian Fintech Builders</title>
      <dc:creator>zikarelhub</dc:creator>
      <pubDate>Mon, 21 Sep 2026 11:10:27 +0000</pubDate>
      <link>https://dev.to/zikarelhub/cbn-regulatory-sandbox-cohort-2-technical-guide-for-nigerian-fintech-builders-59fa</link>
      <guid>https://dev.to/zikarelhub/cbn-regulatory-sandbox-cohort-2-technical-guide-for-nigerian-fintech-builders-59fa</guid>
      <description>&lt;p&gt;The CBN has opened Regulatory Sandbox Cohort 2 to unlicensed Nigerian fintech startups for the first time. Here is the technical breakdown of what this means for Nigerian builders.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Sandbox Is and Is Not
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;sandbox&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;IS&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Supervised testing with real users under CBN oversight&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;isNOT&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;A commercial licence or permission to scale&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;duration&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;6-12 months&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;outcome&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;CBN readiness assessment for full licence application&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;cohort2Change&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Unlicensed startups with working MVPs now eligible&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  The Two Tracks
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;tracks&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;VASP&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;for&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Stablecoin settlement&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Crypto on/off-ramps&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Crypto wallets&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Digital asset payments&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
    &lt;span class="na"&gt;cbnChecks&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;AML/CFT for virtual assets&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Blockchain analytics&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Travel Rule&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Cold storage custody&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
    &lt;span class="na"&gt;additionalRegulator&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;SEC Nigeria — digital asset classification&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;

  &lt;span class="na"&gt;NON_VASP&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;for&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Open banking&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Payment initiation&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Fraud detection&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Financial inclusion&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;RegTech&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
    &lt;span class="na"&gt;cbnChecks&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;NDPA compliance&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;API security&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Fraud controls&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Complaints handling&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;

  &lt;span class="na"&gt;confirmWithCBN&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Plain fiat remittance — not explicitly listed in either track&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Eligibility Check
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;checkEligibility&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;startup&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;disqualifiers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;startup&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;hasWorkingMVP&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;No MVP — concept stage not eligible&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;startup&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;hasOutstandingRegulatoryAction&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Outstanding sanctions&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;startup&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;hasInnovationBeyondExisting&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;No meaningful innovation&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nf"&gt;filter&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Boolean&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;missingCompliance&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;amlPolicy&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;sanctionsScreening&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;cdd&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;consumerProtection&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;cybersecurity&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;incidentResponse&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;dataProtection&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;namedComplianceOfficer&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
  &lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nf"&gt;filter&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;item&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;startup&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;item&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;

  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="na"&gt;eligible&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;disqualifiers&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;disqualifiers&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;complianceGaps&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;missingCompliance&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;readinessScore&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Math&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;round&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
      &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="nx"&gt;missingCompliance&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;100&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Don't Force a Track Fit
&lt;/h2&gt;

&lt;p&gt;The most important advice for Nigerian fintech builders evaluating Cohort 2:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do not add digital asset features just to qualify for the VASP track.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;VASP adds: SEC Nigeria jurisdiction, blockchain analytics costs, Travel Rule infrastructure, custody architecture requirements and significant technical complexity. If your product is genuinely payments or open banking — the Non-VASP track is correct. The compliance overhead difference is substantial.&lt;/p&gt;

&lt;p&gt;Tomorrow: The full readiness checklist — what CBN wants to see before you apply.&lt;/p&gt;




&lt;p&gt;ZikarelHub LTD is Nigeria's #1 software and digital agency — CBN-ready fintech platforms built with compliance from the foundation.&lt;/p&gt;

&lt;p&gt;Are you considering CBN Sandbox Cohort 2? Which track fits your product? 👇&lt;/p&gt;

</description>
      <category>nigeria</category>
      <category>fintech</category>
      <category>puppet</category>
      <category>javascript</category>
    </item>
    <item>
      <title>A Guide to Developing HIPAA Compliant Chat for Telemedicine Apps</title>
      <dc:creator>CometChat</dc:creator>
      <pubDate>Sun, 20 Sep 2026 06:16:37 +0000</pubDate>
      <link>https://dev.to/cometchat_original/a-guide-to-developing-hipaa-compliant-chat-for-telemedicine-apps-72a</link>
      <guid>https://dev.to/cometchat_original/a-guide-to-developing-hipaa-compliant-chat-for-telemedicine-apps-72a</guid>
      <description>&lt;p&gt;Violating HIPAA is easier than it should be. One doctor-patient message through non-secure chat is enough to put you in violation and HIPAA's civil penalties run from $50,000 per violation up to $1.5 million a year for repeat offenses. That's enough to close a clinic.&lt;/p&gt;

&lt;p&gt;HIPAA compliant chat for a telemedicine app is patient communication - text, voice, video, file sharing - that meets HIPAA's Security Rule: encrypted in transit and at rest, access-controlled, audit-logged, and covered by a Business Associate Agreement (BAA) with every vendor that touches protected health information (PHI). Miss one of those, and none of it is compliant. This guide covers what HIPAA requires, the features that matter for telemedicine, and how to build it without turning compliance into a second product you maintain forever.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is HIPAA, and how does it apply to chat?
&lt;/h2&gt;

&lt;p&gt;HIPAA - the Health Insurance Portability and Accountability Act, enacted in 1996 is the US federal law that keeps private health information secure. It sets the rules for how healthcare organizations store, manage, and grant access to patient data.&lt;/p&gt;

&lt;p&gt;Chat is squarely in scope. Sensitive information created inside a care relationship - images, file attachments, even IP addresses - moves easily through private messages and group threads. Less-secure chat apps ship with weak encryption, thin authentication, and few controls. That's exactly the gap HIPAA exists to close.&lt;/p&gt;

&lt;h2&gt;
  
  
  Are you subject to HIPAA?
&lt;/h2&gt;

&lt;p&gt;Two roles matter. Covered entities provide treatment, payment, or healthcare operations - hospitals, doctors, pharmacies, insurers. Business associates are the services that transmit, store, or receive PHI on a covered entity's behalf - which, since a 2013 expansion, includes cloud vendors and chat software providers serving healthcare.&lt;/p&gt;

&lt;p&gt;If you're building a telemedicine app that handles PHI, you're a business associate. So is your chat provider. Both are on the hook.&lt;/p&gt;

&lt;h2&gt;
  
  
  What counts as PHI in a telemedicine app?
&lt;/h2&gt;

&lt;p&gt;PHI is any information that identifies a patient and relates to their health, care, or payment for care. In a chat context that's broad:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Medical records, from an MRI scan to blood test results&lt;/li&gt;
&lt;li&gt;Billing records and payment methods&lt;/li&gt;
&lt;li&gt;Conversations between patient and doctor, or between clinicians&lt;/li&gt;
&lt;li&gt;Any message, note, image, voicemail, or video created inside the care relationship plus metadata that ties a person to a treatment&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Assume more PHI than you'd expect, and protect accordingly.&lt;/p&gt;

&lt;h2&gt;
  
  
  What HIPAA actually requires from your chat
&lt;/h2&gt;

&lt;p&gt;The Security Rule splits into administrative, physical, and technical safeguards. For messaging, these are the ones you implement in code and contracts:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Requirement&lt;/th&gt;
&lt;th&gt;What HIPAA expects&lt;/th&gt;
&lt;th&gt;What it looks like in practice&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Encryption&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;PHI protected in transit and at rest&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;AES-256 at rest, TLS 1.2 in transit&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Access controls&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Only authorized users reach PHI&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Role-based permissions, MFA, SSO&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Audit controls&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;A record of who accessed what, when&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Logs of message and data access&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Integrity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;PHI can't be improperly altered or destroyed&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Message integrity, retention controls&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Transmission security&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;PHI is safe as it moves across networks&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Encrypted channels for chat, calls, files&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;BAA&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Contract making the vendor liable for PHI&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;A signed BAA with every processor&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Two things people get wrong here.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The BAA is the one that gets skipped.&lt;/strong&gt; A covered entity or business associate must have a signed, executed BAA with every service provider that touches PHI. If a vendor handles PHI and won't sign one, you cannot use them for a compliant workflow - no matter how good their encryption is. The Department of Health and Human Services publishes a sample BAA if you need a starting point.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;There is no official HIPAA certification.&lt;/strong&gt; No government body stamps a product 'HIPAA approved.' Compliance is a shared responsibility between you and your vendors, established through safeguards and BAAs - not a certificate. Anyone selling you a 'HIPAA certificate' is selling you a PDF. (SOC 2 and HITRUST are real certifications, and they overlap heavily with HIPAA's safeguards, being SOC 2 compliant puts you most of the way there.)&lt;/p&gt;

&lt;p&gt;One myth worth retiring: HIPAA does not require PHI to stay on US servers. There's no data-residency rule in the law. Safeguards and a BAA are what matter though some providers still prefer US-based data centers for their own policy reasons.&lt;/p&gt;

&lt;h2&gt;
  
  
  Must-have vs. nice-to-have chat features for telemedicine
&lt;/h2&gt;

&lt;p&gt;Requirements get you compliant. Features get you adopted. Here's the split for a telemedicine chat client.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Non-negotiable, across text and video:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Enterprise-grade encryption&lt;/strong&gt;. All data, in transit or at rest, encrypted at AES-256 or higher.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Strong authentication&lt;/strong&gt;. MFA plus unique credentials before anyone reaches PHI.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Automatic logoff&lt;/strong&gt;. Doctors set devices down mid-shift. Auto-logoff keeps an unattended screen from becoming a breach.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Nice-to-have, and worth it for adoption:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Notifications and reminders&lt;/strong&gt;. Pre- and post-care reminders cut no-shows and improve follow-through.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Rich media&lt;/strong&gt;. Audio, video, and images together make a virtual visit feel closer to an in-person one.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Secure file sharing&lt;/strong&gt;. Lab results and diagnostic scans move between doctor and patient without leaving the compliant channel.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For text chat, add saved history, presence, typing indicators, and multi-device sync. For video, add screen sharing, group calls (when you need a specialist), and secure recording. All of it inside the same compliant infrastructure because HIPAA covers every channel, not just the text box.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to build HIPAA compliant chat into a telemedicine app
&lt;/h2&gt;

&lt;p&gt;Building it in-house is a real option and it's a serious engineering lift plus a compliance posture you now own forever. The faster path uses infrastructure already built for it.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Run a risk assessment first. Find the security and privacy gaps before you write code. A HIPAA compliance checklist speeds this up.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Sign the BAA. Before a single message carries PHI, get the BAA in place. CometChat signs BAAs covering chat, voice, video, and notifications, so you're not chasing a separate agreement per channel.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Turn on the technical safeguards. Encryption in transit and at rest; role-based access for patients, clinicians, and care teams; MFA; and SSO. CometChat ships these rather than leaving you to assemble them.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Integrate the SDK or UI Kit. Drop in pre-built UI Kits for React, React Native, Flutter, iOS, or Android, or go lower-level with the SDKs. We've also published step-by-step tutorials for iOS and Android telehealth apps.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Confirm audit logging covers PHI access, across every channel. You need a record of who accessed what for both security and any future audit and it has to include voice, video, and files, not just text.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If you're mapping the bigger picture, &lt;a href="https://www.cometchat.com/blog/telemedicine-app-development" rel="noopener noreferrer"&gt;our guide to telemedicine app development&lt;/a&gt; covers the full build, and the telehealth trends piece has the industry numbers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Is CometChat HIPAA compliant?
&lt;/h2&gt;

&lt;p&gt;Yes. CometChat is HIPAA-compliant and signs BAAs to protect PHI, and is independently certified for SOC 2 and HITRUST. It uses AES-256 and TLS 1.2 encryption, role-based access with MFA and SSO, and secure audit logs - across chat, voice, video, and notifications. Infrastructure runs on a 35+ location edge network with a 99.999% uptime SLA.&lt;/p&gt;

&lt;p&gt;That last part matters more than it sounds. Compliance that falls over under load isn't compliance - it's a demo. Patient communication has to hold when the clinic is busy, not just when you're showing it to a stakeholder. CometChat gives you text, voice, and video ready to integrate into a telemedicine app, with the must-have and nice-to-have features already there. See the healthcare solution for the full picture.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Is there an official HIPAA certification? No. Unlike SOC 2 or ISO 27001, HIPAA has no certifying body. Compliance is a shared responsibility between covered entities and their vendors, established through safeguards and BAAs - not a certificate.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Do I need a BAA for a telemedicine chat feature? Yes, if the chat vendor stores, processes, or transmits PHI. Without a signed BAA, using that vendor for patient communication is itself a HIPAA violation, regardless of how strong the encryption is.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Does HIPAA require end-to-end encryption specifically? Not by that name. The Security Rule requires PHI to be encrypted in transit and at rest using recognized standards - AES-256 at rest and TLS 1.2 in transit are the common bar. The rule cares about the protection, not the label.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Does HIPAA apply to video visits and voice calls, not just text? Yes. Any channel carrying PHI is in scope - voice, video, file sharing, notifications, all of it. Keeping every channel inside one compliant platform is simpler than securing each separately.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Does PHI have to stay on US servers? No. HIPAA has no data-residency requirement. Proper safeguards and a signed BAA are what keep PHI protected, wherever it's stored.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Can I build HIPAA compliant chat myself? You can, and it's a large, ongoing commitment - you own the encryption, access controls, audit logging, and compliance posture forever. Most telemedicine teams use compliant infrastructure so their engineers can build the care experience instead of maintaining a messaging stack.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Get started
&lt;/h2&gt;

&lt;p&gt;Chat looks simple right up until PHI touches it. If you're building a telemedicine app and want the compliance groundwork handled before it becomes a second product to maintain, that's what CometChat is built for. Sign up and start building, or talk to our team first.&lt;/p&gt;

</description>
      <category>hipaa</category>
      <category>cometchat</category>
      <category>appconfig</category>
      <category>puppet</category>
    </item>
    <item>
      <title>SCE for Linux: now with Debian 12 and Puppet 9 support</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 15 Sep 2026 11:44:00 +0000</pubDate>
      <link>https://dev.to/puppet/sce-for-linux-now-with-debian-12-and-puppet-9-support-4jc</link>
      <guid>https://dev.to/puppet/sce-for-linux-now-with-debian-12-and-puppet-9-support-4jc</guid>
      <description>&lt;p&gt;Debian 12 support and Puppet 9 compatibility are now available in version 2.9.0 of Security Compliance Enforcement (SCE) for Linux!&lt;/p&gt;

&lt;p&gt;For teams already using SCE, this release adds CIS Benchmark enforcement for Debian Linux 12 (Bookworm) and ensures SCE can run on Puppet 9, making it easier to keep compliance automation aligned across more Linux deployments and Puppet deployments.&lt;/p&gt;

&lt;p&gt;Other notable updates include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Fixes for Ubuntu authentication hardening where profiles were enabled but not always applied correctly&lt;/li&gt;
&lt;li&gt;Updates to strong cryptography enforcement on Rocky Linux 8&lt;/li&gt;
&lt;li&gt;Resolution for file integrity monitoring initialization issues on Ubuntu&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check out the full release notes for these and other details!&lt;br&gt;
➡️ &lt;a href="https://help.puppet.com/sce/current/linux/scel_relnotes_v290.htm" rel="noopener noreferrer"&gt;SCE for Linux v2.9.0 Release Notes&lt;/a&gt;&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>security</category>
      <category>devops</category>
      <category>linux</category>
    </item>
    <item>
      <title>Puppetlabs Modules Roundup – August 2026</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Tue, 08 Sep 2026 18:54:01 +0000</pubDate>
      <link>https://dev.to/puppet/puppetlabs-modules-roundup-august-2026-38ch</link>
      <guid>https://dev.to/puppet/puppetlabs-modules-roundup-august-2026-38ch</guid>
      <description>&lt;p&gt;August 2026 brought 24 releases across 22 Puppetlabs modules (puppet_metrics_collector and cd4peadm each shipped twice), headlined by a broad Puppet Core 9 compatibility rollout. Continuous Delivery for PE also shipped a required upgrade, Security Compliance Management 3.9.0 closed out 117 CVEs, and a few community contributions were rolled into modules as well. This roundup pulls the most important changes into one place.&lt;/p&gt;

&lt;h2&gt;
  
  
  Highlighted Updates
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Puppet Core 9 Support Continues to be Added Across Modules
&lt;/h3&gt;

&lt;p&gt;Fourteen &lt;code&gt;puppetlabs&lt;/code&gt; modules added Puppet Core 9 compatibility this month, continuing the ongoing Puppet 9 rollout. Five of them (&lt;code&gt;package&lt;/code&gt;, &lt;code&gt;node_encrypt&lt;/code&gt;, &lt;code&gt;service&lt;/code&gt;, &lt;code&gt;reboot&lt;/code&gt;, and &lt;code&gt;tomcat&lt;/code&gt;) paired the Puppet Core 9 addition with dropping Puppet 7 support in major version bumps as part of a broader Puppet Core modernization pass; see below.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Affected modules: exec, package, node_encrypt, mount_iso, lvm, service, java, inifile, reboot, windows_eventlog, cd4pe, cd4pe_jobs, cd4peadm, tomcat.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Puppet 7 Support Dropped
&lt;/h3&gt;

&lt;p&gt;Five modules dropped Puppet 7 support in major version bumps this month as part of the same Puppet Core modernization pass: &lt;code&gt;package&lt;/code&gt;, &lt;code&gt;node_encrypt&lt;/code&gt;, &lt;code&gt;service&lt;/code&gt;, &lt;code&gt;reboot&lt;/code&gt;, and &lt;code&gt;tomcat&lt;/code&gt;. &lt;code&gt;reboot&lt;/code&gt; also picked up CentOS 9 support in the same release.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Affected modules: package, node_encrypt, service, reboot, tomcat.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Continuous Delivery for PE: Required Upgrade for Newer PE Versions
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;cd4peadm&lt;/code&gt; 5.17.0 is a required upgrade if you're integrating with PE 2023.8.11, 2025.12.0, or 2026.0.0+. Those PE versions now require cert-based auth on puppetserver's &lt;code&gt;/status/v1/services&lt;/code&gt; endpoint, and CD's older unauthenticated calls to it fail with a 403 until you upgrade.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The same release also adds Puppet 9 support and closes a second batch of CVEs (bouncycastle, react-router, nanoid, and others).&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Security Compliance Management Patches 117 CVEs
&lt;/h3&gt;

&lt;p&gt;Security Compliance Management 3.9.0, shipped as both &lt;code&gt;comply&lt;/code&gt; and &lt;code&gt;complyadm&lt;/code&gt;, updates roughly 20 bundled third-party components to address 117 CVEs. These included curl/libcurl, OpenSSL, the Netty codec family, Jackson Databind, Keycloak services, and libxml2. — .&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Also restricts the Keycloak administration console and Admin REST API from public access by default, and adds support for pulling container images from a private or air-gapped registry instead of only the public default.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What Updates Happened to Puppetlabs Modules in August 2026?
&lt;/h2&gt;

&lt;p&gt;The following is an alphabetical listing of modules which received updates in August 2026. If a module had multiple versions released, the updates are collected together, numbered with the "latest" version available.&lt;/p&gt;




&lt;h3&gt;
  
  
  cd4pe 3.4.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-13 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/cd4pe" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Puppet version 9 to the version requirements and updates the module with PDK 3.8.0, along with allowing the stdlib dependency to move to 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Added version 9 to the Puppet version range.&lt;/li&gt;
&lt;li&gt;Updated module with PDK 3.8.0.&lt;/li&gt;
&lt;li&gt;Expanded the puppetlabs-stdlib dependency to allow stdlib 10.x.&lt;/li&gt;
&lt;li&gt;Removed unused/dead methods from cd4pe_client.rb.&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  cd4pe_jobs 1.7.5
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-12 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/cd4pe_jobs" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Puppet version 9 support without dropping Puppet 7.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Support for Puppet 9. The &lt;code&gt;puppet&lt;/code&gt; requirement in &lt;code&gt;metadata.json&lt;/code&gt; is now &lt;code&gt;&amp;gt;= 7.24 &amp;lt; 10.0.0&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  cd4peadm 5.18.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-26 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/cd4peadm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Two releases this month for Continuous Delivery for PE: 5.17.0 is a &lt;strong&gt;required upgrade&lt;/strong&gt; for anyone integrating with PE 2023.8.11, 2025.12.0, or 2026.0.0+ — those PE versions require cert-based auth on puppetserver's &lt;code&gt;/status/v1/services&lt;/code&gt; endpoint, which CD previously called unauthenticated, and integration fails with a 403 until you upgrade. 5.17.0 also adds Puppet version 9 support. 5.18.0 follows up with a smaller set of fixes: ssl_cert_chain and ssl_crl in common.yaml can now reference file paths instead of requiring inline PEM contents, and several UI rendering bugs are fixed. Combined, the two releases close 42 CVEs.&lt;/p&gt;

&lt;p&gt;Includes monthly releases: 5.18.0 (2026-08-26), 5.17.0 (2026-08-18).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Added support for version 9 of Puppet.&lt;/li&gt;
&lt;li&gt;Fixed an issue where lastLoginTime data might not be current in some situations. The lastLoginTime field of the user details response from GET /v1/users/{userID} is now correctly updated for LDAP and SAML logins, as well as the initial login after account creation.&lt;/li&gt;
&lt;li&gt;Fixed an issue where some upgraded environments could show a blank Pipelines as Code view and a blank approval details page for module repo pipelines. These pages now render properly without recreating the pipeline.&lt;/li&gt;
&lt;li&gt;42 CVEs addressed.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/cdpe/current/Content/UserGuide/CDPE/ReleaseNotes/cd_release_notes.htm#Version5180" rel="noopener noreferrer"&gt;release notes for cd4peadm 5.18.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  comply 3.9.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-21 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/comply" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Security Compliance Management 3.9.0 addresses 117 CVEs across bundled third-party components, adds support for a private or air-gapped image registry, and restricts the Keycloak administration console and Admin REST API from public access by default.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Supported benchmarks updated in this release: Microsoft Windows 11 Enterprise Benchmark v5.1.0 Microsoft Windows Server 2022 Benchmark v5.1.0 Microsoft Windows Server 2025 Benchmark v2.1.0.&lt;/li&gt;
&lt;li&gt;Fixed an issue where Assessor CLI downloads could fail if the assessor files were added after the comply-ui container started. Downloads now work after the files are deployed without requiring a manual container restart.&lt;/li&gt;
&lt;li&gt;Fixed an issue where default desired compliance could select different non-STIG benchmarks for the same operating system and version depending on database query ordering. SCM now uses a deterministic selection rule so the default benchmark is chosen consistently.&lt;/li&gt;
&lt;li&gt;117 CVEs addressed.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" rel="noopener noreferrer"&gt;release notes for comply 3.9.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  complyadm 3.9.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-21 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/complyadm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Ships the same Security Compliance Management 3.9.0 update as comply, covering the same 117 CVE remediations, the new private/air-gapped image registry option, and the Keycloak admin console/API restriction.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Supported benchmarks updated in this release: Microsoft Windows 11 Enterprise Benchmark v5.1.0 Microsoft Windows Server 2022 Benchmark v5.1.0 Microsoft Windows Server 2025 Benchmark v2.1.0.&lt;/li&gt;
&lt;li&gt;Fixed an issue where Assessor CLI downloads could fail if the assessor files were added after the comply-ui container started. Downloads now work after the files are deployed without requiring a manual container restart.&lt;/li&gt;
&lt;li&gt;Fixed an issue where default desired compliance could select different non-STIG benchmarks for the same operating system and version depending on database query ordering. SCM now uses a deterministic selection rule so the default benchmark is chosen consistently.&lt;/li&gt;
&lt;li&gt;117 CVEs addressed.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Check the official &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" rel="noopener noreferrer"&gt;release notes for complyadm 3.9.0&lt;/a&gt; for the full details.&lt;/p&gt;




&lt;h3&gt;
  
  
  cron_core 2.0.3
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-12 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/cron_core" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Fixes a bug where &lt;code&gt;CronParam#numfix&lt;/code&gt; used the &lt;code&gt;=~&lt;/code&gt; operator on non-String values, and updates the related spec tests.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(PE-45112) Don't use =~ on non-String in CronParam#numfix and update spec tests &lt;a href="https://github.com/puppetlabs/puppetlabs-cron_core/pull/94" rel="noopener noreferrer"&gt;#94&lt;/a&gt; (&lt;a href="https://github.com/AriaXLi" rel="noopener noreferrer"&gt;AriaXLi&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  exec 4.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/exec" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds support for Puppet Core 9.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11713) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-exec/pull/250" rel="noopener noreferrer"&gt;#250&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  inifile 6.5.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/inifile" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Puppet Core 9 support, and fixes &lt;code&gt;array_matching&lt;/code&gt; to return the first element when it isn't set to &lt;code&gt;:all&lt;/code&gt;.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11703) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-inifile/pull/573" rel="noopener noreferrer"&gt;#573&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Return the first element if &lt;code&gt;array_matching&lt;/code&gt; is not &lt;code&gt;:all&lt;/code&gt; &lt;a href="https://github.com/puppetlabs/puppetlabs-inifile/pull/571" rel="noopener noreferrer"&gt;#571&lt;/a&gt; (&lt;a href="https://github.com/bwitt" rel="noopener noreferrer"&gt;bwitt&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  java 12.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/java" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Puppet Core 9 support and defaults RHEL 10 nodes to OpenJDK 21.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11704) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/630" rel="noopener noreferrer"&gt;#630&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11917) Default RHEL 10 to OpenJDK 21 &lt;a href="https://github.com/puppetlabs/puppetlabs-java/pull/631" rel="noopener noreferrer"&gt;#631&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  kubernetes 8.1.1
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-11 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/kubernetes" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Bumps several dependency constraints (augeasproviders_sysctl, augeas core, stdlib) and moves the module to Puppet Core 8, alongside a fix for &lt;code&gt;kubernetes_version&lt;/code&gt; matching and a batch of CI/environment maintenance work.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;fix(MODULES-11856): Bump augeasproviders_sysctl to &amp;lt;5.0.0 and core to &amp;lt;6.0.0 &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/722" rel="noopener noreferrer"&gt;#722&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/718" rel="noopener noreferrer"&gt;#718&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;CAT-2378: Update puppetlabs-kubernetes to use Puppet Core 8 &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/712" rel="noopener noreferrer"&gt;#712&lt;/a&gt; (&lt;a href="https://github.com/span786" rel="noopener noreferrer"&gt;span786&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fix kubernetes_version matching &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/705" rel="noopener noreferrer"&gt;#705&lt;/a&gt; (&lt;a href="https://github.com/xbulat" rel="noopener noreferrer"&gt;xbulat&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;ci(MODULES-11557): add Twingate setup step to GitHub Actions workflow &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/704" rel="noopener noreferrer"&gt;#704&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;MODULES-11577 chore(ruby): upgrade Ruby from 2.7 to 3.1 &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/702" rel="noopener noreferrer"&gt;#702&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MAINT): Updated the version for puppetlabs-apt module in metadata.json file &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/698" rel="noopener noreferrer"&gt;#698&lt;/a&gt; (&lt;a href="https://github.com/span786" rel="noopener noreferrer"&gt;span786&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2193): Fixed kubernetes environment setup for Debian. &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/694" rel="noopener noreferrer"&gt;#694&lt;/a&gt; (&lt;a href="https://github.com/span786" rel="noopener noreferrer"&gt;span786&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2095): Fixed puppetlabs-kubernetes modules CI &amp;amp; nightly failures &lt;a href="https://github.com/puppetlabs/puppetlabs-kubernetes/pull/693" rel="noopener noreferrer"&gt;#693&lt;/a&gt; (&lt;a href="https://github.com/span786" rel="noopener noreferrer"&gt;span786&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  lvm 4.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/lvm" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Now supports Puppet Core 9.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11719) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-lvm/pull/391" rel="noopener noreferrer"&gt;#391&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  mount_iso 5.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/mount_iso" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Puppet Core 9 is now supported.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11723) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-mount_iso/pull/61" rel="noopener noreferrer"&gt;#61&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  node_encrypt 4.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/node_encrypt" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) as part of a Puppet Core update, and adds version 9 support in the same release.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2382) Update for Puppet Core / Drop Support for Puppet 7 &lt;a href="https://github.com/puppetlabs/puppetlabs-node_encrypt/pull/125" rel="noopener noreferrer"&gt;#125&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11724) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-node_encrypt/pull/126" rel="noopener noreferrer"&gt;#126&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  package 4.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/package" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Puppet 7 support gets dropped (&lt;strong&gt;BREAKING&lt;/strong&gt;) as part of a Puppet Core update and also adds Puppet Core 9 support. Also, Chocolatey bootstrap failures are now surfaced more clearly in Windows acceptance testing.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2384) Prepare module for Puppet Core / Drop Support for Puppet 7 &lt;a href="https://github.com/puppetlabs/puppetlabs-package/pull/346" rel="noopener noreferrer"&gt;#346&lt;/a&gt; (&lt;a href="https://github.com/shubhamshinde360" rel="noopener noreferrer"&gt;shubhamshinde360&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11927) Surface chocolatey bootstrap failures in Windows acceptance &lt;a href="https://github.com/puppetlabs/puppetlabs-package/pull/354" rel="noopener noreferrer"&gt;#354&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11730) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-package/pull/353" rel="noopener noreferrer"&gt;#353&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2296) Update github runner image to ubuntu-24.04 &lt;a href="https://github.com/puppetlabs/puppetlabs-package/pull/345" rel="noopener noreferrer"&gt;#345&lt;/a&gt; (&lt;a href="https://github.com/shubhamshinde360" rel="noopener noreferrer"&gt;shubhamshinde360&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  puppet_metrics_collector 8.2.3
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-14 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/puppet_metrics_collector" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Fixes a PostgreSQL 17 checkpoints query and hardens version parsing, cleans up puppet-lint warnings, and removes a broken plaintext-port fallback in PuppetDB metrics collection.&lt;/p&gt;

&lt;p&gt;Includes monthly releases: 8.2.3 (2026-08-14), 8.2.2 (2026-08-07).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(PE-45849) Fix PG17 checkpoints query and harden version parsing &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_metrics_collector/pull/213" rel="noopener noreferrer"&gt;#213&lt;/a&gt; (&lt;a href="https://github.com/beechtom" rel="noopener noreferrer"&gt;beechtom&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fix puppet-lint space_before_arrow and 140chars warnings &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_metrics_collector/pull/210" rel="noopener noreferrer"&gt;#210&lt;/a&gt; (&lt;a href="https://github.com/jonathannewman" rel="noopener noreferrer"&gt;jonathannewman&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Remove broken plaintext-port fallback in PuppetDB metrics collection &lt;a href="https://github.com/puppetlabs/puppetlabs-puppet_metrics_collector/pull/209" rel="noopener noreferrer"&gt;#209&lt;/a&gt; (&lt;a href="https://github.com/jonathannewman" rel="noopener noreferrer"&gt;jonathannewman&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  reboot 6.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-26 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/reboot" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops Puppet 7 (&lt;strong&gt;BREAKING&lt;/strong&gt;) amd adds support for Puppet Core 9 and CentOS 9.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2388) Puppet Core update and Remove Puppet 7 support &lt;a href="https://github.com/puppetlabs/puppetlabs-reboot/pull/378" rel="noopener noreferrer"&gt;#378&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11707) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-reboot/pull/381" rel="noopener noreferrer"&gt;#381&lt;/a&gt; (&lt;a href="https://github.com/skyamgarp" rel="noopener noreferrer"&gt;skyamgarp&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-7110) Add CentOS 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-reboot/pull/373" rel="noopener noreferrer"&gt;#373&lt;/a&gt; (&lt;a href="https://github.com/shubhamshinde360" rel="noopener noreferrer"&gt;shubhamshinde360&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  security_policy 1.1.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-04 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/security_policy" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;A &lt;code&gt;kerberos_policy&lt;/code&gt; type/provider and a &lt;code&gt;new_guest_name&lt;/code&gt; class parameter are added, expanding the module's native parity coverage ahead of SCE integration. &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;[MODULES-11883/MODULES-11884] Epic F: kerberos_policy type/provider (F.1) + new_guest_name parameter (F.2) &lt;a href="https://github.com/puppetlabs/puppetlabs-security_policy/pull/45" rel="noopener noreferrer"&gt;#45&lt;/a&gt; (&lt;a href="https://github.com/mehul-jain1" rel="noopener noreferrer"&gt;mehul-jain1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;[MODULES-11884] Add new_guest_name class parameter (Epic F.2) &lt;a href="https://github.com/puppetlabs/puppetlabs-security_policy/pull/44" rel="noopener noreferrer"&gt;#44&lt;/a&gt; (&lt;a href="https://github.com/mehul-jain1" rel="noopener noreferrer"&gt;mehul-jain1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;[MODULES-11848] plan: add Epic F (native parity superset for SCE integration) &lt;a href="https://github.com/puppetlabs/puppetlabs-security_policy/pull/43" rel="noopener noreferrer"&gt;#43&lt;/a&gt; (&lt;a href="https://github.com/mehul-jain1" rel="noopener noreferrer"&gt;mehul-jain1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;plan/: post-release cleanup — Epics A/B/D/E done, Epic C transferred to puppetlabs-sce_windows &lt;a href="https://github.com/puppetlabs/puppetlabs-security_policy/pull/42" rel="noopener noreferrer"&gt;#42&lt;/a&gt; (&lt;a href="https://github.com/mehul-jain1" rel="noopener noreferrer"&gt;mehul-jain1&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;[MODULES-11804] CHANGELOG: rename Breaking Changes -&amp;gt; Changed (release-blocker) &lt;a href="https://github.com/puppetlabs/puppetlabs-security_policy/pull/41" rel="noopener noreferrer"&gt;#41&lt;/a&gt; (&lt;a href="https://github.com/mehul-jain1" rel="noopener noreferrer"&gt;mehul-jain1&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  service 4.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/service" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops support for Puppet version 7 (&lt;strong&gt;BREAKING&lt;/strong&gt;) and adds version 9 support.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2392) Puppet Core update / Drop support for puppet 7 &lt;a href="https://github.com/puppetlabs/puppetlabs-service/pull/263" rel="noopener noreferrer"&gt;#263&lt;/a&gt; (&lt;a href="https://github.com/LukasAud" rel="noopener noreferrer"&gt;LukasAud&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11709) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-service/pull/268" rel="noopener noreferrer"&gt;#268&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Update link for contributing documentation &lt;a href="https://github.com/puppetlabs/puppetlabs-service/pull/264" rel="noopener noreferrer"&gt;#264&lt;/a&gt; (&lt;a href="https://github.com/jst-cyr" rel="noopener noreferrer"&gt;jst-cyr&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2296) Update github runner image to ubuntu-24.04 &lt;a href="https://github.com/puppetlabs/puppetlabs-service/pull/262" rel="noopener noreferrer"&gt;#262&lt;/a&gt; (&lt;a href="https://github.com/shubhamshinde360" rel="noopener noreferrer"&gt;shubhamshinde360&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  sshkeys_core 3.0.2
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-05 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/sshkeys_core" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Hardens the sshkey type by rejecting key values that contain embedded whitespace, preventing malformed authorized_keys entries.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(PA-8911) Reject embedded whitespace in sshkey key &lt;a href="https://github.com/puppetlabs/puppetlabs-sshkeys_core-private/pull/1" rel="noopener noreferrer"&gt;#1&lt;/a&gt; (&lt;a href="https://github.com/mhashizume" rel="noopener noreferrer"&gt;mhashizume&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  stdlib 10.0.2
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-06 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/stdlib" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Fixes a &lt;code&gt;stdlib::manage&lt;/code&gt; parser bug that failed to parse &lt;code&gt;$type&lt;/code&gt; resources.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;fix(stdlib::manage) parser fails &lt;code&gt;$type&lt;/code&gt; resources &lt;a href="https://github.com/puppetlabs/puppetlabs-stdlib/pull/1477" rel="noopener noreferrer"&gt;#1477&lt;/a&gt; (&lt;a href="https://github.com/jcpunk" rel="noopener noreferrer"&gt;jcpunk&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  tomcat 8.0.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-11 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/tomcat" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Drops Puppet 7 support (&lt;strong&gt;BREAKING&lt;/strong&gt;) as part of a Puppet Core update, and allows the stdlib dependency to move to 10.x.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(CAT-2396) Prepare module for Puppet Core / Drop Support for Puppet 7 &lt;a href="https://github.com/puppetlabs/puppetlabs-tomcat/pull/580" rel="noopener noreferrer"&gt;#580&lt;/a&gt; (&lt;a href="https://github.com/david22swan" rel="noopener noreferrer"&gt;david22swan&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(MODULES-11840) Allow puppetlabs/stdlib 10.x &lt;a href="https://github.com/puppetlabs/puppetlabs-tomcat/pull/584" rel="noopener noreferrer"&gt;#584&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Update link for contributing documentation &lt;a href="https://github.com/puppetlabs/puppetlabs-tomcat/pull/583" rel="noopener noreferrer"&gt;#583&lt;/a&gt; (&lt;a href="https://github.com/jst-cyr" rel="noopener noreferrer"&gt;jst-cyr&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;(CAT-2296) Update github runner image to ubuntu-24.04 &lt;a href="https://github.com/puppetlabs/puppetlabs-tomcat/pull/579" rel="noopener noreferrer"&gt;#579&lt;/a&gt; (&lt;a href="https://github.com/shubhamshinde360" rel="noopener noreferrer"&gt;shubhamshinde360&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  windows_eventlog 5.2.0
&lt;/h3&gt;

&lt;p&gt;📅 Latest release: 2026-08-31 (🌐 &lt;a href="https://forge.puppet.com/modules/puppetlabs/windows_eventlog" rel="noopener noreferrer"&gt;View on the Forge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;Adds Puppet Core 9 support to the module.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;(MODULES-11729) Add Puppet 9 support &lt;a href="https://github.com/puppetlabs/puppetlabs-windows_eventlog/pull/100" rel="noopener noreferrer"&gt;#100&lt;/a&gt; (&lt;a href="https://github.com/imaqsood" rel="noopener noreferrer"&gt;imaqsood&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Until Next Time!
&lt;/h2&gt;

&lt;p&gt;That wraps up the August 2026 roundup. If any of these modules intersect with your environment,  especially the five modules that removed Puppet 7 support (&lt;code&gt;package&lt;/code&gt;, &lt;code&gt;node_encrypt&lt;/code&gt;, &lt;code&gt;service&lt;/code&gt;, &lt;code&gt;reboot&lt;/code&gt;, and &lt;code&gt;tomcat&lt;/code&gt;), or some of the other breaking or required changes, the linked Forge pages and release notes are worth a closer look before upgrading.&lt;/p&gt;

&lt;p&gt;Feedback on the series is always useful, especially if there are module families or release-note patterns that deserve more attention in future editions.&lt;/p&gt;

&lt;p&gt;More updates coming next month when the September 2026 releases land, and you should expect to see continued Puppet Core 9 support rolling out across September!&lt;/p&gt;

&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;This roundup is produced by a mostly-automated pipeline, with some AI sprinkled in for orchestration and enrichment (or 'Combobulating' and 'Finagling'), followed by a human review (that would be me) before publishing.&lt;/p&gt;

&lt;p&gt;The automation is an &lt;a href="https://github.com/jst-cyr/puppetlabs-modules-roundup-writer" rel="noopener noreferrer"&gt;open-source project&lt;/a&gt; with deterministic python scripts to crawl the Forge and determine which &lt;code&gt;puppetlabs&lt;/code&gt; modules were released during a specific month (and catching when a module gets more than one release in a month). By combining a template, automation scripts, and some AI orchestration the content all gets pulled together for a structured markdown document. I then jump in to double-check the content and update any wording that seems repetitive or irrelevant (and sometimes I need to add some extra context that isn't in the changelog notes).&lt;/p&gt;

</description>
      <category>puppet</category>
    </item>
    <item>
      <title>Automating 204 Lighthouse Audits to find the fastest Shopify Theme</title>
      <dc:creator>Deepak Jangra</dc:creator>
      <pubDate>Thu, 03 Sep 2026 15:25:58 +0000</pubDate>
      <link>https://dev.to/ivewor/automating-204-lighthouse-audits-to-find-the-fastest-shopify-theme-514n</link>
      <guid>https://dev.to/ivewor/automating-204-lighthouse-audits-to-find-the-fastest-shopify-theme-514n</guid>
      <description>&lt;p&gt;I needed to find the actual baseline speed of popular Shopify themes. Since dev stores are password-protected, manual PageSpeed Insights URLs don't work.&lt;/p&gt;

&lt;p&gt;I wrote a Node.js script using Puppeteer to bypass the storefront password, and hooked it into the Lighthouse CLI to audit 17 themes across mobile and desktop viewports, running 3 passes each to get the median.&lt;/p&gt;

&lt;p&gt;It turns out that while Shopify's default free themes are highly optimized, a few premium themes (like Broadcast and Expanse) manage to keep a perfect 100 score even with heavy UI components.&lt;/p&gt;

&lt;p&gt;I published my methodology, the full dataset, and the raw JSON reports on my blog. If you do Shopify dev work, you can check the baseline numbers. You check more about the &lt;a href="https://deepakj.dev/blog/fastest-shopify-themes" rel="noopener noreferrer"&gt;fastest shopify theme here&lt;/a&gt;&lt;/p&gt;

</description>
      <category>performance</category>
      <category>puppet</category>
      <category>staticwebapps</category>
      <category>ai</category>
    </item>
    <item>
      <title>Security Compliance Management 3.9.0 now supports Ubuntu 24.04, RHEL 10, Puppet Core 9 and new benchmarks!</title>
      <dc:creator>Jason St-Cyr</dc:creator>
      <pubDate>Thu, 27 Aug 2026 14:29:27 +0000</pubDate>
      <link>https://dev.to/puppet/security-compliance-management-390-now-supports-ubuntu-2404-rhel-10-puppet-core-9-and-new-ndh</link>
      <guid>https://dev.to/puppet/security-compliance-management-390-now-supports-ubuntu-2404-rhel-10-puppet-core-9-and-new-ndh</guid>
      <description>&lt;p&gt;The latest Security Compliance Management (SCM) 3.9.0 has new supported platforms, improvements for air-gapped environments, benchmark updates, feature improvements, and security updates to address vulnerabilities.&lt;/p&gt;

&lt;h2&gt;
  
  
  Highlights
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Expanded platform support:&lt;/strong&gt; SCM 3.9.0 now supports Ubuntu 24.04, Red Hat Enterprise Linux (RHEL) 10, and Puppet 9&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Private image registry support:&lt;/strong&gt; &lt;code&gt;complyadm&lt;/code&gt; can now pull SCM container images from a private image registry to better support air-gapped and private-registry environments.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;IP-based access restrictions:&lt;/strong&gt; Keycloak Administration Console and Admin REST APIs can now be access restricted to IP addresses defined in the frontdoor allowlist.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Expanded benchmarks:&lt;/strong&gt; CIS-CAT Pro Assessor was updated to 4.65.0,  expanded benchmark support for AlmaLinux and MacOS, and updated coverage on Microsoft Windows.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;119 security vulnerabilities&lt;/strong&gt; addressed via updates and fixes, along with several other security hardening fixes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Below are some other summary details, but you may want to jump straight into the &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" rel="noopener noreferrer"&gt;full release notes&lt;/a&gt; right away! &lt;/p&gt;

&lt;h2&gt;
  
  
  CIS-CAT Pro Assessor Updates
&lt;/h2&gt;

&lt;p&gt;Along with updating to CIS-CAT Pro Assessor 4.65.0, the following benchmarks were added:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;AlmaLinux OS 9 STIG v1.0.0&lt;/li&gt;
&lt;li&gt;Apple macOS 15 (Sequoia) STIG v1.1.0&lt;/li&gt;
&lt;li&gt;Apple macOS 26 Tahoe STIG v1.0.0&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These supported benchmarks were also updated:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Microsoft Windows 11 Enterprise Benchmark v5.1.0&lt;/li&gt;
&lt;li&gt;Microsoft Windows Server 2022 Benchmark v5.1.0&lt;/li&gt;
&lt;li&gt;Microsoft Windows Server 2025 Benchmark v2.1.0&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Operational Improvements and Security updates
&lt;/h2&gt;

&lt;p&gt;There were several changes made to improve behavior and address vulnerabilities in this release, including addressing 119 security reports.&lt;/p&gt;

&lt;p&gt;A few notable changes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SCM handles interrupted scheduled scans after reboots more reliably.&lt;/li&gt;
&lt;li&gt;Default benchmark selection is now more reliable when multiple non-STIG benchmarks are available.&lt;/li&gt;
&lt;li&gt;Hasura GraphQL field suggestions are now disabled to prevent schema enumeration.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;See the full list &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" rel="noopener noreferrer"&gt;in the release notes&lt;/a&gt;!&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Upgrade?
&lt;/h2&gt;

&lt;p&gt;For customers running Ubuntu 24.04, RHEL 10, Puppet 9, private registries, or security-sensitive environments, SCM 3.9.0 delivers meaningful operational, platform, and security improvements. Combined with expanded benchmark coverage and enhanced upgrade behavior, this release helps organizations maintain compliance with greater confidence and less administrative overhead.&lt;/p&gt;


&lt;div class="ltag-offer"&gt;
  &lt;div class="ltag-offer__body"&gt;View the full SCM 3.9.0 release notes!&lt;/div&gt;
    &lt;a href="https://help.puppet.com/scm/current/Content/UserGuide/SCM/Release_notes/release_notes.htm#SecurityComplianceManagement390" class="ltag-offer__button crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;Read More&lt;/a&gt;
&lt;/div&gt;


&lt;h2&gt;
  
  
  🤖 AI Disclosure
&lt;/h2&gt;

&lt;p&gt;This summary was initially drafted by AI and deterministic automation to pull together release notes information from the latest Security Compliance Management 3.9.0 release notes. The draft was then human edited, rewritten, and reviewed before publishing.&lt;/p&gt;

</description>
      <category>puppet</category>
      <category>devops</category>
      <category>security</category>
    </item>
  </channel>
</rss>
