Bitwarden Confirms Short-Lived npm Compromise Affecting CLI Package
Bitwarden has confirmed a brief supply-chain compromise of its CLI 2026.4.0 npm package, with no evidence of vault data exposure.
Explore the latest in free and open-source software with our news and articles. From software releases to community insights, stay ahead in the FOSS world.
Bitwarden has confirmed a brief supply-chain compromise of its CLI 2026.4.0 npm package, with no evidence of vault data exposure.
WSL9x is not Microsoft WSL, but a retro Windows 95 and 98 project that makes Linux run where nobody expected it.
Ventoy 1.1.12 fixes Ubuntu 24.04.4 LTS install failures, resolves VirtualBox UEFI display issues, and improves Windows and WinPE boot handling.
OpenVPN 2.7.2 fixes two security flaws, adds long password support in the management interface, and includes several bugfixes for Windows users.
The Linux kernel may drop 18 old Ethernet drivers for ISA- and PCMCIA-era hardware as maintainers question whether the aging code still has active users.
PipeWire 1.6.4 is now available, addressing JACK glitches, Bluetooth issues, ALSA sequencer crashes, and LADSPA plugin loading problems.
COSMIC Desktop 1.0.11 brings fixes for Files, Settings, Terminal, and the Compositor, along with translation and dependency updates.
Mozilla Thunderbird 150 email client adds custom accent colors, encrypted message search, PDF page reordering, and more.
QEMU 11.0 drops all 32-bit host support, adds a Diamond Rapids CPU model for x86, and brings broad changes across ARM, RISC-V, KVM, and migration.
VirtualBox 7.2.8 is out with Linux 6.19 and 7.0 host support, Wayland fixes, Windows 11 improvements, and updated Guest Additions.