<?xml version="1.0"?>
<rdf:RDF
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:foaf="http://xmlns.com/foaf/0.1/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns="http://purl.org/rss/1.0/"
>
<channel rdf:about="https://planet.debian.org/deriv/">
	<title>Planet Debian Derivatives</title>
	<link>https://planet.debian.org/deriv/</link>
	<description>Planet Debian Derivatives - https://planet.debian.org/deriv/</description>

	<items>
		<rdf:Seq> 
		  <rdf:li rdf:resource="https://volumio.com/how-to-organize-digital-music-library/"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39675"/>
		  <rdf:li rdf:resource="https://volumio.com/music-streamer-with-tidal-connect/"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=69620"/>
		  <rdf:li rdf:resource="https://www.univention.de/?p=87975"/>
		  <rdf:li rdf:resource="https://puri.sm/?p=85765"/>
		  <rdf:li rdf:resource="https://volumio.com/stream-local-music-to-hi-fi/"/>
		  <rdf:li rdf:resource="https://tails.net/news/version_7.10.1/"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39662"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39647"/>
		  <rdf:li rdf:resource="https://blog.armbian.com/rss/6a7140f2c90ccb0001dcc1a7"/>
		  <rdf:li rdf:resource="https://volumio.com/best-audio-os-for-raspberry-pi/"/>
		  <rdf:li rdf:resource="http://sinfallas.wordpress.com/?p=5377"/>
		  <rdf:li rdf:resource="https://www.skudonet.com/?p=77977"/>
		  <rdf:li rdf:resource="https://volumio.com/how-to-build-raspberry-pi-music-streamer/"/>
		  <rdf:li rdf:resource="https://sparkylinux.org/?p=14118"/>
		  <rdf:li rdf:resource="https://puri.sm/?p=85732"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=69428"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39629"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39618"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39610"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=69359"/>
		  <rdf:li rdf:resource="https://www.univention.de/?p=87916"/>
		  <rdf:li rdf:resource="https://blog.armbian.com/rss/6a6a15fb0b8ab5000178c729"/>
		  <rdf:li rdf:resource="https://blog.armbian.com/rss/696e316e93dc320001185d5e"/>
		  <rdf:li rdf:resource="https://blog.armbian.com/rss/6a69269d0b8ab5000178c6ee"/>
		  <rdf:li rdf:resource="https://pardus.org.tr/?p=26042"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=69277"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=69031"/>
		  <rdf:li rdf:resource="https://www.univention.de/?p=87838"/>
		  <rdf:li rdf:resource="https://blog.vyos.io/vyos-project-june-july-2026"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39585"/>
		  <rdf:li rdf:resource="https://blog.armbian.com/rss/6a6802210b8ab5000178c6c2"/>
		  <rdf:li rdf:resource="https://www.qubes-os.org/news/2026/07/28/xsas-released-on-2026-07-28/"/>
		  <rdf:li rdf:resource="https://www.qubes-os.org/news/2026/07/28/qsb-116/"/>
		  <rdf:li rdf:resource="https://jonathancarter.org/?p=12034"/>
		  <rdf:li rdf:resource="https://www.skudonet.com/?p=77949"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39561"/>
		  <rdf:li rdf:resource="https://sparkylinux.org/?p=14113"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39549"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68962"/>
		  <rdf:li rdf:resource="https://puri.sm/?p=85705"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39534"/>
		  <rdf:li rdf:resource="https://tails.net/news/version_7.10/"/>
		  <rdf:li rdf:resource="https://www.qubes-os.org/news/2026/07/23/qubes-os-summit-2026-tickets-for-sale-and-speaker-proposals-now-open/"/>
		  <rdf:li rdf:resource="https://www.qubes-os.org/news/2026/07/23/fedora-44-templates-available/"/>
		  <rdf:li rdf:resource="https://www.univention.de/?p=87695"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68913"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68832"/>
		  <rdf:li rdf:resource="https://www.univention.de/?p=87685"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39510"/>
		  <rdf:li rdf:resource="https://blog.armbian.com/rss/6a5e522d0b8ab5000178c68e"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68813"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39493"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68767"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68744"/>
		  <rdf:li rdf:resource="https://www.deepin.org/?p=39454"/>
		  <rdf:li rdf:resource="https://sourceforge.net2cde7ff6f1917ac227d44cdf6a223f9bd43011af"/>
		  <rdf:li rdf:resource="https://www.qubes-os.org/news/2026/07/14/xsas-released-on-2026-07-14/"/>
		  <rdf:li rdf:resource="https://www.greenbone.net/?p=68653"/>
		</rdf:Seq>
	</items>
</channel>


<item rdf:about="https://volumio.com/how-to-organize-digital-music-library/">
	<title>Volumio: How to Organize a Digital Music Library Well</title>
	<link>https://volumio.com/how-to-organize-digital-music-library/</link>
     <content:encoded>&lt;p&gt;A music library becomes frustrating long before it becomes unplayable. It starts with two copies of the same album, an artist filed under three different names, a compilation scattered across the alphabet, or a beautiful high-resolution release that appears with no cover art. Learning &lt;strong&gt;how to organize digital music library&lt;/strong&gt; files is less about making every folder look perfect and more about making every listening session feel effortless.&lt;/p&gt;
&lt;p&gt;For a serious collection, organization also protects the work you have put into acquiring music. Clean metadata makes an artist catalog easy to explore, reliable backups keep rare files safe, and a consistent structure helps a network player index your library correctly. The goal is simple: all your music, ready when you want it, without hunting through file names or switching between sources.&lt;/p&gt;
&lt;h2&gt;Start with one master library&lt;/h2&gt;
&lt;p&gt;Before changing tags or moving folders, decide where the authoritative version of your collection will live. This is your master library: the place you update when you add an album, correct an artist name, or replace a low-resolution file with a better release.&lt;/p&gt;
&lt;p&gt;For a smaller collection, an internal computer drive may be enough. For larger libraries or a system used by more than one listener, a dedicated external drive or network-attached storage device is often the better choice. A network location allows compatible music players to access the same collection without leaving a computer running in the listening room.&lt;/p&gt;
&lt;p&gt;Avoid maintaining several active versions of the library on different drives. It seems convenient until one version has corrected artwork, another has new purchases, and neither is complete. Keep one master, then create backups from it.&lt;/p&gt;
&lt;p&gt;A practical folder structure is straightforward:&lt;/p&gt;
&lt;p&gt;“`text Music/ Artist Name/ 1997 – Album Title/ 01 – Track Title.flac 02 – Track Title.flac “`&lt;/p&gt;
&lt;p&gt;This format is readable, portable, and useful even if you later use different playback software. Including the year before an album title helps distinguish multiple releases with similar names and keeps an artist’s work in a sensible order when browsing folders.&lt;/p&gt;
&lt;p&gt;For box sets, live recordings, and deluxe editions, consistency matters more than a single universal rule. You might use `2019 – Album Title (Deluxe Edition)` or place discs in `CD1` and `CD2` subfolders. Choose a convention you can remember and apply it going forward. You do not need to rebuild your entire library in one weekend.&lt;/p&gt;
&lt;h2&gt;Let metadata do the real organizing&lt;/h2&gt;
&lt;p&gt;Folders provide a foundation, but metadata is what makes digital music enjoyable to browse. Your player uses embedded tags to group tracks into albums, identify artists, sort composers, display artwork, and build views by genre or date. A perfectly named folder cannot compensate for incomplete or conflicting tags.&lt;/p&gt;
&lt;p&gt;At minimum, check these fields for every album: album artist, artist, album title, track title, track number, disc number, release year, genre, and embedded cover art. For classical, jazz, and other repertoire where the performer is not always the primary point of entry, composer, conductor, ensemble, and work tags can be equally valuable.&lt;/p&gt;
&lt;p&gt;The distinction between &lt;strong&gt;Artist&lt;/strong&gt; and &lt;strong&gt;Album Artist&lt;/strong&gt; prevents many common library problems. For a standard studio album, they may be identical. For a guest appearance, the track artist can include both performers while the album artist remains the main artist. For compilations, set the album artist consistently to `Various Artists`. This keeps one soundtrack or anthology together instead of creating a separate album entry for every track performer.&lt;/p&gt;
&lt;p&gt;Be deliberate with artist names. `David Bowie`, `Bowie, David`, and `David Bowie feat. …` can all become separate entries. Use one preferred spelling for the artist field, and reserve featured artists for the track title or a dedicated contributing-artist field if your tagging application supports it.&lt;/p&gt;
&lt;h3&gt;Keep genres useful, not theoretical&lt;/h3&gt;
&lt;p&gt;Genres can either help you choose music or become a cloud of near-duplicates. If your collection includes `Rock`, `Alternative Rock`, `Alt Rock`, `Indie Rock`, and `Indie`, that may be exactly right if you browse by those distinctions. If you never do, it creates noise.&lt;/p&gt;
&lt;p&gt;Use a limited set of genres that matches how you listen. Many collectors are well served by broad categories such as Rock, Jazz, Classical, Electronic, Folk, Soul, Hip-Hop, Pop, Country, and World, with a few carefully chosen subgenres where they matter. The right system depends on your collection and your habits, not on a database’s idea of precision.&lt;/p&gt;
&lt;h2&gt;Choose formats and protect sound quality&lt;/h2&gt;
&lt;p&gt;A library can contain several formats, but it helps to know which files are your archival masters. Lossless formats such as FLAC and ALAC preserve the full audio signal while allowing metadata and artwork to travel with the file. WAV can sound excellent, but its metadata support is less consistent across software and devices. AIFF is another lossless option with stronger tagging support than WAV in many environments.&lt;/p&gt;
&lt;p&gt;Lossy files still have a place. A well-encoded AAC or MP3 file can be useful for a car, portable player, or a legacy device with limited storage. The key is not to confuse a convenience copy with your master. Keep the lossless original, then create portable copies only when you need them.&lt;/p&gt;
&lt;p&gt;Do not upsample or convert a lossy file to a high-resolution format expecting more detail. It produces a larger file, not more musical information. When possible, replace poor-quality files with a genuine lossless or high-resolution source instead.&lt;/p&gt;
&lt;h2&gt;Handle album art with care&lt;/h2&gt;
&lt;p&gt;Album art is part of the pleasure of owning music. It also makes a library far easier to navigate from across the room. Use a square image with enough resolution to look clean on a tablet, television, or music player display. Around 1,000 by 1,000 pixels is a sensible target for most collections.&lt;/p&gt;
&lt;p&gt;Whenever possible, embed the artwork in the audio files themselves. You can also keep a `cover.jpg` file in each album folder as a fallback for systems that read folder art. Embedded art is generally more portable, while a folder image can be simpler to replace across a whole album. Using both is reasonable if storage space is not a concern.&lt;/p&gt;
&lt;p&gt;Avoid placing unrelated scans, PDFs, and image files in the same album directory unless you know your library software handles them well. Booklets can be worth keeping, especially for classical releases and box sets, but a separate `Booklets` folder beside the music library may keep scanning and indexing cleaner.&lt;/p&gt;
&lt;h2&gt;Treat compilations, classical, and multi-disc albums as special cases&lt;/h2&gt;
&lt;p&gt;These are the releases most likely to expose inconsistent tagging. For compilations, use `Various Artists` as the album artist, retain the individual performer in the artist field, and make sure the album title is identical on every track. Include disc numbers for multi-disc sets even when there is only one disc in most of your library. That small habit prevents track 1 from disc two appearing directly after track 1 from disc one.&lt;/p&gt;
&lt;p&gt;Classical organization is more personal. Some listeners browse by composer first, while others choose by performer, conductor, orchestra, or work. There is no wrong answer, but your tags should support the route you actually take. A useful approach is to set the album artist to the principal performer or ensemble, complete the composer field carefully, and format track titles so the work and movement remain clear. Consistent work and movement tags become especially valuable in large collections.&lt;/p&gt;
&lt;p&gt;Live albums deserve equally clear labeling. If an album has both studio and live versions, include the venue, city, or `Live` designation in the album title rather than relying on a vague folder name. Future you will be grateful.&lt;/p&gt;
&lt;h2&gt;Build listening paths, not just a database&lt;/h2&gt;
&lt;p&gt;Once your core tags are clean, add organization that reflects the way you spend time with music. Favorites, recently added albums, five-star records, and playlists can turn a large library from an archive into a living collection.&lt;/p&gt;
&lt;p&gt;Keep playlists purposeful. A playlist for late-night jazz, a Sunday-morning selection, a reference set for evaluating a hi-fi system, or a road-trip sequence is more useful than hundreds of abandoned queues. For long-term portability, consider saving playlists in a widely supported format such as M3U8 and use relative paths when possible. Relative paths are more likely to keep working if the storage device changes location.&lt;/p&gt;
&lt;p&gt;This is also where a unified music-player ecosystem earns its place. A &lt;a href=&quot;https://volumio.com/back-to-basics-volumio/&quot;&gt;platform such as Volumio&lt;/a&gt; can bring local files, connected storage, and supported streaming services into one interface, so browsing a cherished download and playing a new discovery feel like parts of the same experience. Good organization makes that unified view more accurate and more enjoyable.&lt;/p&gt;
&lt;h2&gt;Back up before you trust the cleanup&lt;/h2&gt;
&lt;p&gt;Editing tags is usually safe, but moving folders, batch-renaming files, and replacing artwork can create mistakes quickly. Back up the master library before any major cleanup, then keep at least one additional copy on a separate drive. For truly irreplaceable purchases, recordings, and personal transfers, keep another copy away from the home as well.&lt;/p&gt;
&lt;p&gt;The familiar 3-2-1 approach remains sensible: three copies of your data, on two different types of storage, with one copy stored elsewhere. Your playback library does not need to be complicated, but it should not be the only place your music exists.&lt;/p&gt;
&lt;p&gt;After making changes, rescan your music player and inspect a few problem areas: compilations, albums with featured guests, multi-disc sets, and classical recordings. Correcting a handful of edge cases reveals whether your system is working before you apply it to thousands of tracks.&lt;/p&gt;
&lt;h2&gt;Make organization a small ongoing habit&lt;/h2&gt;
&lt;p&gt;The best library is not the one with the most elaborate taxonomy. It is the one you can maintain. When a new album arrives, check its metadata, artwork, format, and folder placement before adding it to the master collection. That takes a few minutes and prevents a pile of unfinished work months later.&lt;/p&gt;
&lt;p&gt;Leave room for exceptions. A rare bootleg, an archival radio session, or an unusual composer credit may not fit your rules neatly. Give it the clearest information you have, preserve the music, and return to listening. A well-organized library should make the path to a favorite record shorter, then get out of the way.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://volumio.com/how-to-organize-digital-music-library/&quot;&gt;How to Organize a Digital Music Library Well&lt;/a&gt; appeared first on &lt;a href=&quot;https://volumio.com&quot;&gt;Volumio&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-07T00:06:21+00:00</dc:date>
	<dc:creator>Volumio</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39675">
	<title>Deepin: (中文) 7月社区月报｜deepin 25.2.0 镜像发布 &amp; 小U同学定时任务上线</title>
	<link>https://www.deepin.org/en/deepin-community-monthly-report-2026-7/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-08-06T10:31:12+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://volumio.com/music-streamer-with-tidal-connect/">
	<title>Volumio: Choosing a Music Streamer With TIDAL Connect</title>
	<link>https://volumio.com/music-streamer-with-tidal-connect/</link>
     <content:encoded>&lt;p&gt;The appeal of a music streamer with TIDAL Connect is immediate: choose an album in the TIDAL app, select your hi-fi system from the device list, and let the streamer take over playback. Your phone becomes a remote rather than the source of the audio. That distinction matters when your system has been assembled carefully, from the network connection to the DAC, amplifier, and speakers.&lt;/p&gt;
&lt;p&gt;For many listeners, TIDAL Connect is the missing link between the streaming service they enjoy and the listening experience their equipment deserves. But the badge alone does not make every streamer the same. Sound quality, local-library support, control options, hardware design, and the quality of the streaming platform all determine whether a player will feel at home in your system for years.&lt;/p&gt;
&lt;h2&gt;What TIDAL Connect Actually Does&lt;/h2&gt;
&lt;p&gt;TIDAL Connect lets a compatible network player receive music directly from TIDAL’s servers after you initiate playback in the TIDAL app. Once music is playing, the streamer handles the stream itself. You can use your phone for other tasks, leave the room, or even close the app without turning it into an audio transport tethered to your system.&lt;/p&gt;
&lt;p&gt;This is different from basic Bluetooth playback, where the phone remains central to the audio path and may apply its own limitations. It is also different from screen mirroring or a generic cast feature that may not expose the same playback information or sound-quality options. With TIDAL Connect, the familiar TIDAL interface stays in front of you, including its albums, playlists, editorial recommendations, and search, while the dedicated player does the serious work of delivering music to your DAC or integrated amplifier.&lt;/p&gt;
&lt;p&gt;That convenience is valuable, but it should be understood as one part of a streamer rather than the whole product. A great listening system needs more than a good handoff from an app.&lt;/p&gt;
&lt;h2&gt;Choosing a Music Streamer With TIDAL Connect&lt;/h2&gt;
&lt;p&gt;Start with the role the streamer will play. If you already own a DAC you love, a digital transport with a well-implemented USB, coaxial, or optical output may be the right answer. It keeps conversion in the DAC and focuses the streamer on network playback, clocking, power delivery, and a clean digital signal.&lt;/p&gt;
&lt;p&gt;If your current system has open inputs but no DAC, a streamer with a built-in converter can reduce box count and simplify setup. This can be an excellent route for a secondary system, a desktop setup, or a living room where elegance matters as much as capability. The trade-off is flexibility: an external DAC makes later upgrades easier, while an integrated design is often more compact and direct.&lt;/p&gt;
&lt;p&gt;Also consider whether the player supports the connections your system actually uses. USB is common with modern DACs, but coaxial and optical remain useful, particularly with established hi-fi components. Balanced analog outputs can make sense when connecting to a balanced preamp or active speakers, while standard RCA outputs remain the practical choice for many integrated amplifiers. More connections are not automatically better. The right connections are the ones that avoid adapters, work reliably, and suit the equipment you already enjoy.&lt;/p&gt;
&lt;h3&gt;Native TIDAL control and a unified music experience&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;https://volumio.com/tidal-connect-volumio/&quot;&gt;TIDAL Connect&lt;/a&gt; is ideal when you want to browse TIDAL exactly as TIDAL presents it. Yet most serious listeners do not live entirely inside one streaming app. They may have a NAS full of carefully tagged albums, a USB drive of purchases, internet radio favorites, and subscriptions to more than one service.&lt;/p&gt;
&lt;p&gt;A streamer with its own strong music-management environment adds value here. It should make local music feel like a first-class source, not an afterthought hidden behind folders. It should also offer a clear mobile or web interface for times when you want to queue music from several sources, adjust playback settings, or explore your own collection without switching devices.&lt;/p&gt;
&lt;p&gt;This is where ecosystem design becomes personal. Some listeners want the TIDAL app to remain their main command center. Others want one place for TIDAL, local files, web radio, and other services. The best choice is not the one with the longest feature sheet. It is the one that matches the way you discover, organize, and return to music.&lt;/p&gt;
&lt;h3&gt;Sound quality depends on the whole chain&lt;/h3&gt;
&lt;p&gt;A TIDAL Connect logo confirms compatibility, not a guaranteed sonic result. Network hardware, power supply design, digital output implementation, DAC quality, and system matching still matter. So does the recording. A revealing streamer will not turn every master into an audiophile release, but it can make a well-recorded performance more immediate, stable, and emotionally convincing.&lt;/p&gt;
&lt;p&gt;If possible, listen through your own system or one close to it. Pay attention to the qualities that matter over a full album: the natural decay of a piano, the separation of voices in a dense mix, the weight and timing of bass, and whether brighter recordings remain listenable. Quick comparisons can favor exaggerated detail. Long listening often reveals the value of balance, low noise, and freedom from fatigue.&lt;/p&gt;
&lt;p&gt;Resolution support deserves the same clear-eyed approach. TIDAL offers a range of audio formats and quality levels, and compatible playback can vary with the device, subscription, release, and software implementation. A streamer should handle the formats relevant to your listening, but format support should not distract from fundamentals. Reliable playback and musical coherence will matter more than a specification you rarely use.&lt;/p&gt;
&lt;h2&gt;Network Setup Is Part of the Product&lt;/h2&gt;
&lt;p&gt;Streaming is only as dependable as the connection feeding it. Ethernet is usually the straightforward choice for a fixed hi-fi rack, particularly where Wi-Fi signal strength is inconsistent. A wired connection can reduce variables and provides welcome confidence when you are settling in for a long evening of music.&lt;/p&gt;
&lt;p&gt;Wi-Fi can still be an excellent option when running a cable is impractical. Place the streamer where it has a stable signal, avoid crowding it with network hardware or metal obstructions, and make sure the router is capable of serving the rooms where you listen. If playback skips, drops from the device list, or takes too long to start, investigate the network before assuming the audio component is at fault.&lt;/p&gt;
&lt;p&gt;A good streamer should also feel approachable during setup. You should be able to connect it to the network, install updates, name the device, and begin listening without becoming an IT administrator. At the same time, advanced listeners benefit from meaningful settings for output mode, volume behavior, library scanning, and digital processing. The art is making those controls available without making them mandatory.&lt;/p&gt;
&lt;h2&gt;Consider the Life of the Streamer After Purchase&lt;/h2&gt;
&lt;p&gt;Unlike a turntable or a traditional amplifier, a network streamer is partly defined by software that will evolve after it arrives. Streaming services update their requirements. Mobile operating systems change. New playback features appear, while occasional bugs need attention. Look for a platform with a clear history of support, active development, and an engaged user community.&lt;/p&gt;
&lt;p&gt;This is especially relevant for builders using a Raspberry Pi or PC-based player. &lt;a href=&quot;https://volumio.com/category/tutorial/&quot;&gt;DIY can be remarkably rewarding&lt;/a&gt;: it lets you choose your enclosure, power approach, storage, and DAC while learning exactly how the system works. But it also asks for a little patience. A dedicated streamer trades some of that experimentation for a finished, purpose-built component designed to live comfortably in a hi-fi rack.&lt;/p&gt;
&lt;p&gt;Volumio offers both paths, bringing local libraries, streaming services, and connected audio devices into a single music-player ecosystem, whether you prefer to build a player or choose hand-assembled Italian hardware. That flexibility is useful because a first streamer is rarely the last word in a music system. Systems change, collections grow, and listening habits develop.&lt;/p&gt;
&lt;h2&gt;The Small Details That Make Listening Easier&lt;/h2&gt;
&lt;p&gt;Before buying, think about daily use rather than only the first setup. Will the streamer wake quickly? Can everyone in the household select music without asking for help? Does the display, if included, show enough information from across the room? Can you control volume safely if the streamer feeds a power amplifier directly?&lt;/p&gt;
&lt;p&gt;Multiroom capability may matter if you want the kitchen, office, and main system to share music, though it is worth checking how it works with the services you use most. Gapless playback matters for live recordings, classical works, and albums designed as continuous performances. A responsive queue matters whenever an evening moves from intentional listening to spontaneous requests.&lt;/p&gt;
&lt;p&gt;These are not glamorous specifications, but they shape whether a component becomes part of your routine. The finest DAC architecture is less satisfying if the player regularly loses its connection or makes your own library difficult to find.&lt;/p&gt;
&lt;p&gt;Choose the streamer that makes it easier to press play on the records you already love, then leaves enough room for the next musical obsession to find you.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://volumio.com/music-streamer-with-tidal-connect/&quot;&gt;Choosing a Music Streamer With TIDAL Connect&lt;/a&gt; appeared first on &lt;a href=&quot;https://volumio.com&quot;&gt;Volumio&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-06T08:21:48+00:00</dc:date>
	<dc:creator>Volumio</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=69620">
	<title>GreenboneOS: Patch Now! CVE-2026-18577 in N-able N-central Actively Exploited</title>
	<link>https://www.greenbone.net/en/blog/n-central-authentication-bypass/</link>
     <content:encoded>CVE-2026-18577 (CVSS 8.2, EPSS ≥ 71st pctl) and CVE-2026-18556 (CVSS 7.4, EPSS ≥ 19th pctl), published in early August, have both been added to CISA’s Known Exploited Vulnerabilities (KEV) list within days of their disclosure [1][2]. N-able has published Indicators of Compromise (IoC) and post-exploitation activity from successful attacks against its own hosted N-central instances. […]</content:encoded> 
	<dc:date>2026-08-06T06:47:52+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.univention.de/?p=87975">
	<title>Univention Corporate Server: From Nubus to an Automated Linux Desktop: A Case Study from pro mente tirol</title>
	<link>https://www.univention.com/blog-en/2026/08/from-nubus-to-an-automated-linux-desktop-a-case-study-from-pro-mente-tirol/</link>
     <content:encoded>&lt;div class=&quot;wpb-content-wrapper&quot;&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;
	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;&lt;strong&gt;A social services organization in Tyrol, 24 locations, and the conviction that our data belongs in our own network: Here’s how we put that principle into practice with Nubus and Ubuntu.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Since 2014, I have been heading the IT department at &lt;a href=&quot;https://promente-tirol.at/de/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;pro mente tirol&lt;/strong&gt;&lt;/a&gt;, a non-profit organization providing social psychiatric services for people with mental health conditions. We operate 24 locations across Tyrol, employ around 300 people, and are 100% publicly funded. At some point, Windows 7 reached the end of its lifecycle. The question was: Should we move to Windows 10 or should we consider something different for the desktop? I’ve been an open source enthusiast since my university days, so we decided to explore an alternative.&lt;/p&gt;
&lt;p&gt;In this article, I’ll explain how, together with &lt;a href=&quot;https://www.siedl.net/-/home&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Siedl Networks&lt;/strong&gt;&lt;/a&gt;, we made the transition from Windows to Ubuntu, using &lt;strong&gt;Univention Nubus&lt;/strong&gt; as our Identity &amp;amp; Access Management foundation, &lt;strong&gt;Ansible&lt;/strong&gt; for automation, and custom Python scripts to configure network shares. I’ll also explain what the migration cost, how our employees responded, and how we organized support after each site migration.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Our Data, Our Infrastructure&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Before deciding which operating system our employees would use, we first had to answer a much more fundamental question: &lt;strong&gt;Where should our data reside, and who should control it?&lt;/strong&gt; Our management’s answer was clear: As much data as possible should remain within our own network. We do not rule out external solutions, but we carefully evaluate where the servers are located.&lt;/p&gt;
&lt;p&gt;The second strategic decision was not about the infrastructure but about the applications themselves. Early on, we decided to move as many applications as possible into the browser. Today, most of our applications run as web applications, including email, document management, collaboration tools, and client documentation. Locally installed software is essentially limited to a web browser, LibreOffice, and printer drivers. That gave us considerable flexibility when choosing a desktop operating system because the more runs in the browser, the less it depends on the operating system itself.&lt;/p&gt;
&lt;p&gt;That flexibility ultimately became our opportunity. Windows 7 had reached end of support, and around 220 PCs needed to be replaced or upgraded. At standard market prices, new hardware and software would have cost us around &lt;strong&gt;€170,000&lt;/strong&gt;. Even with discounts available to non-profit organizations, the total would still have been approximately €120,000. To be fair, obtaining those discounts involves a significant amount of administrative work: forms, proof of non-profit status, and the same paperwork every year. It all ended up on my desk.&lt;/p&gt;
&lt;p&gt;In the end, our migration to Linux cost around &lt;strong&gt;€15,000&lt;/strong&gt;, including my own working time and the development work carried out by Siedl Networks. And there’s more: We were able to keep around &lt;strong&gt;90% of our existing hardware&lt;/strong&gt;. We installed a few SSDs, added RAM where necessary, and occasionally replaced a power supply.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Ubuntu as Our Linux Desktop: Why We Chose It&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Linux Mint, Zorin OS, and a dozen other distributions, we’re often asked why we didn’t choose one of those instead. As an administrator, one factor stood out above all else: Ubuntu is the most widely used Linux distribution. There’s a good chance that some employees have already encountered it at home. That’s preparation I don’t have to do myself.&lt;/p&gt;
&lt;p&gt;Ubuntu is also backed by a large online community, including a very active German-language forum that provides answers to many user questions. In addition, Ubuntu includes much of what we need out of the box. It was important to me that we install as little additional software as possible.&lt;/p&gt;
&lt;p&gt;For us, 2018 was the year of preparation. We defined the core principles that would guide everything that followed.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  From Nubus and Ansible to an Automated Desktop&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;&lt;strong&gt;At pro mente tirol, &lt;a href=&quot;https://www.univention.com/products/nubus/&quot;&gt;Nubus &lt;/a&gt;is the central control point for desktop management, and LDAP groups are the key to making it work.&lt;/strong&gt; We first create a group in Nubus, then create a network share, and finally assign that share to the group. The reason is simple: We work with team accounts, not individual user accounts. Which network drives someone sees depends on their group membership, not on an individual user account.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.univention.de/wp-content/uploads/2026/08/Mit-Nubus-und-Ansible-zum-automatisierten-Desktop.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;alignright wp-image-87990&quot; height=&quot;435&quot; src=&quot;https://www.univention.de/wp-content/uploads/2026/08/Mit-Nubus-und-Ansible-zum-automatisierten-Desktop.png&quot; width=&quot;350&quot; /&gt;&lt;/a&gt;When setting up a workstation, we still perform several tasks manually: installing the operating system, configuring SSH remote access, setting up printers, and installing remote support software. These tasks cannot be meaningfully automated because they depend on the individual location. We then join the PCs to the UCS domain. Only at that point does the system know that the computer exists and can assign it to the appropriate groups, shares, and permissions.&lt;/p&gt;
&lt;p&gt;After that, Ansible takes over. The playbooks install all required packages, including software for accessing Samba network shares and a LibreOffice build from our own Personal Package Archive (PPA) repository. The Snap version of LibreOffice provided with Ubuntu also includes help and developer files, which noticeably slows startup on older hardware, although this is hardly noticeable on newer machines. Using our own PPA also means we are not dependent on Canonical’s package maintenance and receive updates directly from the software vendor.&lt;/p&gt;
&lt;p&gt;The Ansible playbooks also deploy a variety of configuration settings, including the browser’s home page and extensions, history and cache behavior, and the default application for opening PDF files.&lt;/p&gt;
&lt;p&gt;A custom-developed Python script then reads the directory service to determine which network shares are assigned to which groups. Based on this information, it automatically generates two files: a bookmarks file for the Nautilus file manager so that network drives appear in the sidebar, and a configuration file that automatically mounts the Samba shares when users log in, just as Windows users are accustomed to after signing in to a domain.&lt;/p&gt;
&lt;p&gt;During the very first login, users must sign in twice. The first login checks the network drives; after the second login, everything is in place: bookmarks, application shortcuts, assigned network drives in the file manager, and the taskbar. From then on, everything is configured automatically each time the user signs in. Even if someone rearranges their icons, they’ll be back in the expected places after the next login.&lt;/p&gt;
&lt;p&gt;For asset management, that is, keeping track of our devices, we initially experimented with Landscape, Canonical’s commercial management solution. After two years, we switched to a leaner approach: our own Cockpit server, which provides an overview of all our devices. The same server also runs Ansible for automation.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Linux in Everyday Work: What Our Users Had to Say&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Office compatibility was initially one of the key topics for our support team. During the migration phase, Linux users could access a Windows environment with Office 365 via a Terminal Server if they ran into problems with a document. We have since discontinued this access: users have not needed it for around four years. We now handle the remaining compatibility cases using OnlyOffice in our Nextcloud.&lt;/p&gt;
&lt;p&gt;And we approached the issue from the other direction as well: all Windows PCs now use the ODF open file format as the default, so our Windows colleagues also create ODT and ODS files. For remote access to virtual desktops, we now use KASM, which replaced Guacamole. Since the beginning of 2026, we have no longer provided Windows desktops there either.&lt;/p&gt;
&lt;p&gt;What surprised us positively was the feedback on performance. Logging in is faster and applications start more quickly—even on older hardware. Our users mentioned this repeatedly. One of our employees told us that they no longer go for a coffee while waiting for their PC to boot.&lt;/p&gt;
&lt;p&gt;The look and feel of the new environment was not a problem for most people. One employee, for example, said that the interface felt pleasantly neutral. Another commented that working with it was just like working on her Mac. Of course, there are other opinions as well, and some users still consider Microsoft indispensable, but those critical voices are becoming fewer and fewer.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Rollout Across 24 Locations: Preparation, Support, and Follow-Up&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;We started the first rollouts in 2019. We proceeded one location at a time, from Reutte to Landeck, then Imst and Schwaz, all the way to Kufstein and Lienz. By late summer 2020, all PCs scheduled for migration had been converted. In 2021, we then quickly upgraded all systems from Ubuntu 18.04 to Ubuntu 20.04. Since the end of 2024, all of our Linux PCs have been running Ubuntu 24.04.&lt;/p&gt;
&lt;p&gt;The next Ubuntu upgrade, however, will have to wait a little longer. Ubuntu 26.x uses Wayland by default, and that creates a problem for our support team. When issues arise, we often log in to employees’ desktops unattended in order to investigate them directly. Wayland does not easily allow this: screen sharing and remote input require a consent dialog that the logged-in user must confirm every time. That simply does not work when a workstation is unattended or still at the login screen.&lt;/p&gt;
&lt;p&gt;The rollout process for employees was always essentially the same. Around one month before the migration, we contacted the respective team and scheduled a meeting. Two or three hours in which we explained what they could expect: what the new desktop would look like, which applications they would find, where compatibility issues might occur—and why we were making the change. We showed the cost comparison, talked about data security, and explained the reduced attack surface compared to ransomware. Those are convincing arguments, even for employees who are not particularly interested in IT.&lt;/p&gt;
&lt;p&gt;After the migration, we dedicated ourselves exclusively to that team for two weeks. All other tickets were put on hold so that the priorities were clear. Anyone who encountered a problem contacted us and received immediate support.&lt;/p&gt;
&lt;p&gt;At the same time, we established a tiered support model: first look into the issue yourself, then ask your colleagues, and only then call IT support or open a ticket. In some teams, a technically minded person naturally emerged as the first point of contact, collecting questions and passing them on to support, a welcome side effect. The better a team works together, the more people help one another, and we have experienced that time and again over the years.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  From the Desktop to the Portal: Where the Journey Is Headed&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The move from Windows to Ubuntu was only half the story. Equally important was the parallel transition from locally installed applications to web applications.&lt;/p&gt;
&lt;p&gt;The portal is now the central point of entry: our employees sign in once via Single Sign-on and then have access to all applications assigned to them, regardless of whether those applications are hosted internally or externally.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.univention.de/wp-content/uploads/2026/08/promentetirol-Portal.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-87972 aligncenter&quot; height=&quot;336&quot; src=&quot;https://www.univention.de/wp-content/uploads/2026/08/promentetirol-Portal-1000x701.png&quot; width=&quot;480&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt; &lt;/p&gt;
&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The role-based system behind it makes administration much easier. Which tiles someone sees in the portal depends on their group membership, the very same logic we already use for our network shares. New employees automatically receive access to the right applications without us having to configure every account individually.&lt;/p&gt;
&lt;p&gt;The more applications we can integrate in this way, the less depends on the individual desktop computer. The portal becomes the actual workspace and the operating system underneath becomes secondary.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a href=&quot;https://www.univention.de/wp-content/uploads/2026/08/Mit-Nubus-und-Ansible-zum-automatisierten-Desktop_Gruppen.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;aligncenter wp-image-87989&quot; height=&quot;259&quot; src=&quot;https://www.univention.de/wp-content/uploads/2026/08/Mit-Nubus-und-Ansible-zum-automatisierten-Desktop_Gruppen-1000x518.png&quot; width=&quot;500&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Nubus and Linux Desktops: What We Learned&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The move to Linux desktops for our employees has been a success. I don’t say that because everything went smoothly, but because we were able to deal with the problems that arose. The performance improvements were real and immediately noticeable. The costs were significantly lower than those of a Windows upgrade. And we were able to continue using around 90% of our existing hardware.&lt;/p&gt;
&lt;p&gt;What we underestimated was Office compatibility during the initial rollout phase. We also underestimated the fact that the open source world is constantly evolving something that often remains invisible to users but regularly creates additional work for administrators.&lt;/p&gt;
&lt;p&gt;Our most important lesson, however, is this: If you bring your employees on board before the first PC is migrated, you will face much less resistance later on.&lt;/p&gt;
&lt;p&gt;Our data stays with us. Our infrastructure belongs to us. That was the fundamental decision – and it still is today.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;One open question for the community:&lt;/strong&gt; the Wayland issue is currently preventing us from moving to Ubuntu 26.x. If you manage a similarly distributed Linux environment and have already found a solution without sacrificing security features, we’d be happy to hear from you in the comments below this article.&lt;/em&gt;&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Der Beitrag &lt;a href=&quot;https://www.univention.com/blog-en/2026/08/from-nubus-to-an-automated-linux-desktop-a-case-study-from-pro-mente-tirol/&quot;&gt;From Nubus to an Automated Linux Desktop: A Case Study from pro mente tirol&lt;/a&gt; erschien zuerst auf &lt;a href=&quot;https://www.univention.com&quot;&gt;Univention&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T09:28:03+00:00</dc:date>
	<dc:creator>Vanessa Knoop</dc:creator>
</item> 
<item rdf:about="https://puri.sm/?p=85765">
	<title>Purism PureOS: Making Videos With Absolute Freedom</title>
	<link>https://puri.sm/posts/making-videos-with-absolute-freedom/</link>
     <content:encoded>&lt;p&gt;As with every video that we make at Purism, we have made the Librem 16 launch video in house with Librem hardware running PureOS, and using free software only. This blog post will give a quick overview of the steps that we went through for making this video. It will also show how to run a video project with total freedom, away from proprietary constraints. Finally, it underlines how amazing the Librem laptops are when used in a professional creative environment.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://puri.sm/posts/making-videos-with-absolute-freedom/&quot; rel=&quot;nofollow&quot;&gt;Making Videos With Absolute Freedom&lt;/a&gt; appeared first on &lt;a href=&quot;https://puri.sm/&quot; rel=&quot;nofollow&quot;&gt;Purism&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T07:37:51+00:00</dc:date>
	<dc:creator>Purism</dc:creator>
</item> 
<item rdf:about="https://volumio.com/stream-local-music-to-hi-fi/">
	<title>Volumio: How to Stream Local Music to Hi-Fi Systems</title>
	<link>https://volumio.com/stream-local-music-to-hi-fi/</link>
     <content:encoded>&lt;p&gt;A hard drive full of carefully collected albums should not feel like a relic from the CD-ripping era. Whether your collection lives on a NAS drive, a computer, or a USB disk, you can stream local music to hi-fi equipment with the same ease you expect from a modern streaming service – while keeping the master files, artwork, and listening choices in your hands.&lt;/p&gt;
&lt;p&gt;The difference is not simply getting sound from storage to speakers. A well-built local streaming setup turns your personal library into a living part of your system: searchable from the listening chair, playable in high resolution, and available alongside the services you use every day.&lt;/p&gt;
&lt;h2&gt;Why local music still belongs in a modern hi-fi system&lt;/h2&gt;
&lt;p&gt;Streaming subscriptions are excellent for discovery, but a local library offers something different. It may contain out-of-print releases, live recordings, alternate masters, purchased downloads, or years of music organized with care. It also gives you consistency. The version of an album you choose is the version you hear, without catalog changes or shifting availability.&lt;/p&gt;
&lt;p&gt;For many listeners, sound quality is another reason. Local files can be played in their original resolution, including CD-quality FLAC and high-resolution PCM or DSD files where your hardware supports them. That does not mean every high-resolution file will automatically sound better. The quality of the recording, master, DAC, amplifier, speakers, and room still matter more than a number on a file label. But local playback removes unnecessary compromises between your collection and your system.&lt;/p&gt;
&lt;p&gt;There is also a practical advantage: your music remains available even when internet service is unreliable. The player only needs access to your home network or directly attached storage, depending on how you configure it.&lt;/p&gt;
&lt;h2&gt;What you need to stream local music to hi-fi&lt;/h2&gt;
&lt;p&gt;At its simplest, local streaming requires three things: a place where music files are stored, a network music player that can find and play them, and a connection to your hi-fi system.&lt;/p&gt;
&lt;p&gt;Your storage can be a computer, a network-attached storage device, or a USB drive connected directly to the player. A NAS is often the best long-term choice for larger libraries because it stays on independently of your computer and can serve music to more than one listening zone. A computer is perfectly suitable for a smaller collection or a first setup, especially if it is already on when you listen.&lt;/p&gt;
&lt;p&gt;The music player is the bridge between your library and your stereo. It connects to the network, scans your files into a browsable library, and sends audio to an integrated amplifier, external DAC, or active speakers. Some systems include digital and analog outputs, while others are designed as digital transports for listeners who already own a DAC they love.&lt;/p&gt;
&lt;p&gt;A stable wired Ethernet connection is preferable when possible, particularly for large high-resolution libraries or a busy household network. Good Wi-Fi can work very well, but distance from the router, dense walls, and network congestion can affect reliability. If playback occasionally stops or albums take too long to appear, the network is usually the first place to investigate.&lt;/p&gt;
&lt;h3&gt;Choose files your system can read&lt;/h3&gt;
&lt;p&gt;FLAC is a sensible default for most local libraries. It is lossless, supports metadata and artwork, and is widely compatible. ALAC offers similar benefits for collections built around Apple software. WAV and AIFF can sound excellent but tend to consume more storage space, and WAV metadata support is less consistent across software.&lt;/p&gt;
&lt;p&gt;MP3 and AAC remain useful for casual listening or older collections, though they are lossy formats. There is no need to replace a beloved collection overnight. Start by playing what you own, then use lossless files for new rips and downloads when sound quality and archiving matter to you.&lt;/p&gt;
&lt;h2&gt;Build a library that is satisfying to browse&lt;/h2&gt;
&lt;p&gt;The best player interface cannot rescue a poorly organized library. Before your first scan, spend time on filenames, album folders, artwork, and metadata. This work pays off every time you search for an artist, browse by genre, or select an album without reaching for a keyboard.&lt;/p&gt;
&lt;p&gt;A simple folder structure is usually enough: Artist, then Album, then tracks. Keep multi-disc releases together in a clearly labeled album folder. Use consistent album-artist tags for compilations and box sets, or those releases may be scattered across multiple artist pages.&lt;/p&gt;
&lt;p&gt;Metadata deserves particular attention. Artist, album artist, album title, track number, disc number, release year, genre, and embedded cover art are the fields that most directly improve daily browsing. Classical and jazz listeners may also want to tag composer, conductor, ensemble, soloist, and recording date. The right approach depends on how you actually look for music. A collection organized around composers needs different detail than one centered on performers and albums.&lt;/p&gt;
&lt;p&gt;Artwork should be embedded in the files when possible. Folder images can work, but embedded artwork travels with the music if you later move files to another drive or server. Avoid enormous image files if your library scan becomes slow; a clean square image at a sensible resolution is more than enough for most control screens.&lt;/p&gt;
&lt;h2&gt;Connect the player to the rest of your system&lt;/h2&gt;
&lt;p&gt;The connection you choose depends on the role of your player. If you have an external DAC, use a digital output such as USB, coaxial, or optical, according to the inputs your DAC supports. USB can support very high sample rates and DSD on compatible equipment, while coaxial and optical can be excellent, straightforward choices within their format limits.&lt;/p&gt;
&lt;p&gt;If your streamer has a high-quality built-in DAC and your amplifier accepts analog inputs, connect it with RCA or balanced XLR where available and appropriate. Balanced connections are not automatically superior in every system, but they can help reject noise over longer cable runs and suit components designed for balanced operation.&lt;/p&gt;
&lt;p&gt;Keep the setup honest and simple. Expensive cables will not correct a weak network, messy metadata, or a poor speaker position. Put your attention first on reliable networking, sensible component matching, and a speaker setup that lets the music breathe.&lt;/p&gt;
&lt;h3&gt;Avoid unwanted resampling and volume mistakes&lt;/h3&gt;
&lt;p&gt;For the most direct playback path, configure your player to preserve the source file’s native sample rate when your DAC supports it. This is often called bit-perfect playback. It ensures the player does not resample every track to a fixed rate before output.&lt;/p&gt;
&lt;p&gt;That said, bit-perfect playback is not a requirement for musical enjoyment. Some systems intentionally use DSP, room correction, upsampling, or digital volume control. These can be worthwhile features, especially if they solve a real issue in your room. The key is to understand where processing happens and avoid stacking multiple volume controls at low levels, which can reduce usable resolution or create awkward gain settings.&lt;/p&gt;
&lt;h2&gt;Make local files feel as convenient as streaming&lt;/h2&gt;
&lt;p&gt;Once the music is indexed, local playback should not require a technical ritual. You should be able to open one control interface, browse new additions, search an artist, queue an album, and move from your own files to a streaming service without changing devices or rebuilding playlists.&lt;/p&gt;
&lt;p&gt;This is where a dedicated music-player ecosystem earns its place. Volumio brings local libraries, supported streaming services, internet radio, and connected playback hardware into one focused interface, so the music source does not dictate how you listen. For makers, the same approach can begin with a &lt;a href=&quot;https://volumio.com/amazing-diy-raspberry-pi-audio-player-volumio/&quot;&gt;Raspberry Pi&lt;/a&gt; or PC-based player. For a finished system, a dedicated streamer can provide a more refined physical and electrical foundation.&lt;/p&gt;
&lt;p&gt;Playlists are especially useful for closing the gap between ownership and discovery. Build one around a favorite label, a live set, a particular producer, or a mood that crosses formats. A &lt;a href=&quot;https://volumio.com/hybrid-playlist-sources-volumio/&quot;&gt;local track&lt;/a&gt; can sit next to a streamed album and a radio discovery without turning your evening into an exercise in app switching.&lt;/p&gt;
&lt;h2&gt;Troubleshoot the issues that matter most&lt;/h2&gt;
&lt;p&gt;When local music does not appear, the cause is often basic: the player cannot see the shared folder, login credentials have changed, or the storage device is asleep. Confirm that the folder is shared on the network, that the player has permission to read it, and that both devices are on the same network.&lt;/p&gt;
&lt;p&gt;If an album appears with missing artwork or tracks in the wrong order, inspect the tags before blaming the player. Track and disc numbers, album-artist fields, and embedded cover art solve a surprising number of library problems. After editing metadata, trigger a library rescan so the changes are reflected.&lt;/p&gt;
&lt;p&gt;Dropouts point more often to network conditions than file quality. Try Ethernet, move the player away from sources of wireless interference, or reserve Wi-Fi for lower-demand locations. If you are playing from a USB drive, test another cable or power source before assuming the drive itself has failed.&lt;/p&gt;
&lt;p&gt;A local library is not about rejecting streaming. It is about giving your own music the same care as the rest of your hi-fi system. Put on the album you know by heart, let it play without interruption, and make room for the next record waiting in your collection.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://volumio.com/stream-local-music-to-hi-fi/&quot;&gt;How to Stream Local Music to Hi-Fi Systems&lt;/a&gt; appeared first on &lt;a href=&quot;https://volumio.com&quot;&gt;Volumio&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-05T00:03:47+00:00</dc:date>
	<dc:creator>Volumio</dc:creator>
</item> 
<item rdf:about="https://tails.net/news/version_7.10.1/">
	<title>Tails: Tails 7.10.1</title>
	<link>https://tails.net/news/version_7.10.1/</link>
     <content:encoded>&lt;p&gt;This release is an emergency release to fix critical security vulnerabilities
in the &lt;em&gt;Linux&lt;/em&gt; kernel and the &lt;em&gt;expat&lt;/em&gt; XML library.&lt;/p&gt;

&lt;h1 id=&quot;changes&quot;&gt;Changes and updates&lt;/h1&gt;


&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Update the &lt;em&gt;Linux&lt;/em&gt; kernel to 6.12.100, which fixes &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64560&quot;&gt;CVE-2026-64560&lt;/a&gt;,
a vulnerability that could allow &lt;em&gt;Tor Browser&lt;/em&gt; in
Tails to gain administrator privileges.&lt;/p&gt;

&lt;p&gt;For example, if a malicious website that you visit is able to exploit
CVE-2026-64560, they might take full control of your Tails and deanonymize
you.&lt;/p&gt;

&lt;div class=&quot;attack&quot;&gt;

&lt;p&gt;This attack is very unlikely but could be performed by a strong attacker,
such as a government or a hacking firm. We are not aware of this attack being
used in practice until now.&lt;/p&gt;

&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Update the &lt;em&gt;expat&lt;/em&gt; XML library to 2.8.2, which fixes
&lt;a href=&quot;https://security-tracker.debian.org/tracker/DSA-6404-1&quot;&gt;DSA-6404-1&lt;/a&gt;, a set
of vulnerabilities that could allow different applications in Tails to gain
administrator privileges.&lt;/p&gt;

&lt;p&gt;For example, if an attacker tricks you into opening a malicious file in an
application that uses &lt;em&gt;expat&lt;/em&gt;, such as &lt;em&gt;LibreOffice&lt;/em&gt;, &lt;em&gt;Audacity&lt;/em&gt;, or &lt;em&gt;Git&lt;/em&gt;,
they might then use one of these vulnerabilities to take full control of your
Tails and deanonymize you.&lt;/p&gt;

&lt;div class=&quot;attack&quot;&gt;

&lt;p&gt;This attack is very unlikely but could be performed by a strong attacker,
such as a government or a hacking firm. We are not aware of this attack being
used in practice until now.&lt;/p&gt;



&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Compress automatic upgrades with &lt;code&gt;zstd&lt;/code&gt; for a faster startup, as we already
did for the USB image in &lt;a href=&quot;https://tails.net/news/version_7.0/&quot;&gt;Tails 7.0&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Make USB images and automatic upgrades 70 MB smaller by removing unused
firmware.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;For more details, read our &lt;a href=&quot;https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog&quot;&gt;changelog&lt;/a&gt;.&lt;/p&gt;

&lt;h1 id=&quot;get&quot;&gt;Get Tails 7.10.1&lt;/h1&gt;


&lt;h2&gt;To upgrade your Tails USB stick and keep your Persistent Storage&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Automatic upgrades are available from Tails 7.0 or later to 7.10.1.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a &lt;a href=&quot;https://tails.net/doc/upgrade/index.en.html#manual&quot;&gt;manual upgrade&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;To install Tails 7.10.1 on a new USB stick&lt;/h2&gt;

&lt;p&gt;Follow our &lt;a href=&quot;https://tails.net/install/index.en.html&quot;&gt;installation instructions&lt;/a&gt;.&lt;/p&gt;

&lt;div class=&quot;caution&quot;&gt;&lt;p&gt;The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.&lt;/p&gt;&lt;/div&gt;


&lt;h2&gt;To download only&lt;/h2&gt;

&lt;p&gt;If you don&#39;t need installation or upgrade instructions, you can download
Tails 7.10.1 directly:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://tails.net/install/download/index.en.html&quot;&gt;For USB sticks (USB image)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://tails.net/install/download-iso/index.en.html&quot;&gt;For DVDs and virtual machines (ISO image)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-05T00:00:00+00:00</dc:date>
	<dc:creator>Tails</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39662">
	<title>Deepin: deepin 25.2.1 Update</title>
	<link>https://www.deepin.org/en/deepin-25-2-1-update-announcement/</link>
     <content:encoded>Learn more about deepin on DistroWatch: https://distrowatch.com/table.php?distribution=deepin The deepin 25.2.1 update is here! This update brings numerous feature optimizations and bug fixes, focusing on file management &amp;amp; search, system upgrade reliability, general application compatibility, and system security. We welcome all deepin community members and open-source enthusiasts to install the latest release and share your feedback! Feel free to discuss and share your thoughts and experiences in the comments — thank you all!   Key Updates Intelligent Search Is Now Available: File Manager and Global Search now support more natural ways to find local files. You can search with phrases such as ...&lt;a href=&quot;https://www.deepin.org/en/deepin-25-2-1-update-announcement/&quot;&gt;Read more&lt;/a&gt;</content:encoded> 
	<dc:date>2026-08-04T03:11:51+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39647">
	<title>Deepin: (中文) 重磅更新！小U同学「全局知识库」上线：你的本地文件，终于&quot;活&quot;起来了</title>
	<link>https://www.deepin.org/en/uos-ai-3-0-2-507/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-08-04T02:04:41+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://blog.armbian.com/rss/6a7140f2c90ccb0001dcc1a7">
	<title>ARMBIAN: Github Highlights</title>
	<link>https://blog.armbian.com/github-highlights-36/</link>
     <content:encoded>&lt;img alt=&quot;Github Highlights&quot; src=&quot;https://blog.armbian.com/content/images/2026/08/aug3_fixed.png&quot; /&gt;&lt;p&gt;This week&amp;amp;aposs work centers on a &lt;strong&gt;consolidated uwe5622 Wi-Fi/Bluetooth driver&lt;/strong&gt;, &lt;strong&gt;CI and repository infrastructure changes&lt;/strong&gt;, and &lt;strong&gt;board and toolchain enablement&lt;/strong&gt; across multiple SoC families.&lt;/p&gt;&lt;p&gt;The uwe5622 driver has been &lt;strong&gt;relocated to a dedicated repository&lt;/strong&gt; and unified across kernel versions. Initial commits address a use-after-free in &lt;code&gt;mtty_probe()&lt;/code&gt;, resolve 157 &lt;code&gt;-Wmissing-prototypes&lt;/code&gt; warnings, correct &lt;code&gt;dev_addr&lt;/code&gt; const guards for kernels 5.17–6.18 under clang, and fix &lt;code&gt;sdio_pub_int_init&lt;/code&gt; for the newer gpiod &lt;code&gt;int_ap&lt;/code&gt; API on GCC 14. The build system now sources the driver from this repository, adds a GitHub Actions test workflow, and refactors the associated DVFS patch and kernel configuration.&lt;/p&gt;&lt;p&gt;CI and publishing pipelines received substantial attention. &lt;strong&gt;Nightly images have moved&lt;/strong&gt; from the &lt;code&gt;os&lt;/code&gt; to the &lt;code&gt;ci&lt;/code&gt; release channel, with the download portal, router, and reporting scripts updated to match. The community build now publishes to its own repository and version series, dispatch inputs have been trimmed, and board/maintainer dropdowns are auto-generated for standard-support builds. Stall recovery gained a &lt;strong&gt;five-attempt budget with a &amp;gt;50% success gate&lt;/strong&gt;, later raised back to ten attempts. On the repository side, &lt;code&gt;repo-reprepro&lt;/code&gt; now skips missing &lt;code&gt;.deb&lt;/code&gt; files rather than aborting and logs a single count of skipped packages.&lt;/p&gt;&lt;p&gt;Platform work spans several architectures. New boards include the &lt;strong&gt;Anbernic RG Vita Pro (RK3576)&lt;/strong&gt; handheld and the Recomputer RK3576 devkit, while EasePi-A2/R2 mainline U-Boot advances to v2026.07. Toolchain fixes enable &lt;strong&gt;imx8ulp libbpf builds on GCC 15&lt;/strong&gt;, fit the AM62P/AM62-LP R5 SPL into SRAM under GCC 13, and correct a sunxi-6.12 Bluetooth quirk for the pre-6.16 API. Additional user-visible changes include a new &lt;code&gt;BTRFS_CHECKSUM&lt;/code&gt; build switch, F2FS enabled across all kernels via a central config hook, and parallelized patch rewriting scaled to &lt;code&gt;nproc&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;#Armbian #EmbeddedLinux #RK3576 #uwe5622 #CI&lt;/p&gt;&lt;h2 id=&quot;changes&quot;&gt;Changes&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Add a BTRFS_CHECKSUM build switch for choosing the checksum algorithm. by &lt;a href=&quot;https://github.com/dlitz?ref=blog.armbian.com&quot;&gt;@dlitz&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10288?ref=blog.armbian.com&quot;&gt;armbian/build#10288&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add board: Anbernic RG Vita Pro (RK3576 gaming handheld). by &lt;a href=&quot;https://github.com/crackerjacques?ref=blog.armbian.com&quot;&gt;@crackerjacques&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10128?ref=blog.armbian.com&quot;&gt;armbian/build#10128&lt;/a&gt;&lt;/li&gt;&lt;li&gt;add parallel patching switches. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/documentation/pull/945?ref=blog.armbian.com&quot;&gt;armbian/documentation#945&lt;/a&gt;&lt;/li&gt;&lt;li&gt;auto-retry-stalled: 5-attempt budget, retry only when &amp;gt;50% of jobs succeed. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/36?ref=blog.armbian.com&quot;&gt;armbian/ci#36&lt;/a&gt;&lt;/li&gt;&lt;li&gt;board: set HAS_VIDEO_OUTPUT at board level so the build-list inventory sees it. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10309?ref=blog.armbian.com&quot;&gt;armbian/build#10309&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Build firmware paths with a single bounded snprintf. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/6?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#6&lt;/a&gt;&lt;/li&gt;&lt;li&gt;build-community: trim dispatch inputs to match nightly. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/37?ref=blog.armbian.com&quot;&gt;armbian/ci#37&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Build-Switches: document BTRFS_CHECKSUM. by &lt;a href=&quot;https://github.com/dlitz?ref=blog.armbian.com&quot;&gt;@dlitz&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/documentation/pull/946?ref=blog.armbian.com&quot;&gt;armbian/documentation#946&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: auto-generated board/maintainer dropdowns for standard-support builds. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/40?ref=blog.armbian.com&quot;&gt;armbian/ci#40&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: community publishes to armbian/community with its own version series. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/38?ref=blog.armbian.com&quot;&gt;armbian/ci#38&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: raise stall-recovery retry budget back to 10 attempts. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/39?ref=blog.armbian.com&quot;&gt;armbian/ci#39&lt;/a&gt;&lt;/li&gt;&lt;li&gt;cix-p1: edge: update patches for 7.1.5, remove version pin. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10297?ref=blog.armbian.com&quot;&gt;armbian/build#10297&lt;/a&gt;&lt;/li&gt;&lt;li&gt;cli-patch: generalize to-git push (PUSH_TO_GITHUB / PUSH_TO_REPO), for u-boot too. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10193?ref=blog.armbian.com&quot;&gt;armbian/build#10193&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docs: document the &lt;code&gt;show-extensions&lt;/code&gt; build command. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/documentation/pull/944?ref=blog.armbian.com&quot;&gt;armbian/documentation#944&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Fix -Wmissing-prototypes warnings (157 → 0). by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/5?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#5&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Fix dev_addr const guards for kernels 5.17-6.18 (clang). by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/3?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Fix use-after-free in mtty_probe() error path. by &lt;a href=&quot;https://github.com/enromytase?ref=blog.armbian.com&quot;&gt;@enromytase&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/4?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#4&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix(sc8280xp-vendor): rebase DP retrain patch onto moving radxa 7.0.11 branch. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10305?ref=blog.armbian.com&quot;&gt;armbian/build#10305&lt;/a&gt;&lt;/li&gt;&lt;li&gt;gha: add test workflow based on armbian. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/7?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;hetzner: stop masking create_servers.py errors on failure. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/34?ref=blog.armbian.com&quot;&gt;armbian/actions#34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;imx8ulp: enable scoped kernel patches so the libbpf/gcc-15 fix applies. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10312?ref=blog.armbian.com&quot;&gt;armbian/build#10312&lt;/a&gt;&lt;/li&gt;&lt;li&gt;imx8ulp: fix libbpf const-discard so resolve_btfids builds on gcc 15. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10310?ref=blog.armbian.com&quot;&gt;armbian/build#10310&lt;/a&gt;&lt;/li&gt;&lt;li&gt;json: fix duplicate and over-length menu IDs. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/configng/pull/957?ref=blog.armbian.com&quot;&gt;armbian/configng#957&lt;/a&gt;&lt;/li&gt;&lt;li&gt;k3: fit am62p/am62-lp R5 SPL into SRAM (GCC 13 + per-SoC size handling), fix tispl rename &amp;amp; u-boot artifact hashing. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10237?ref=blog.armbian.com&quot;&gt;armbian/build#10237&lt;/a&gt;&lt;/li&gt;&lt;li&gt;kernel: enable F2FS on all kernels (central config hook). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10178?ref=blog.armbian.com&quot;&gt;armbian/build#10178&lt;/a&gt;&lt;/li&gt;&lt;li&gt;map: key nightly/ prefix on download_repository &quot;ci&quot; (nightly moved os→ci). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian-router/pull/42?ref=blog.armbian.com&quot;&gt;armbian/armbian-router#42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;recomputer-rk3576-devkit: edge/mainline enablement. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10235?ref=blog.armbian.com&quot;&gt;armbian/build#10235&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Refactor DVFS patch and clean up uwe5622 driver kernel configuration. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10316?ref=blog.armbian.com&quot;&gt;armbian/build#10316&lt;/a&gt;&lt;/li&gt;&lt;li&gt;repo-reprepro: log a count of skipped debs, not one line each. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10303?ref=blog.armbian.com&quot;&gt;armbian/build#10303&lt;/a&gt;&lt;/li&gt;&lt;li&gt;repo-reprepro: skip debs missing on disk instead of aborting the whole repo. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10301?ref=blog.armbian.com&quot;&gt;armbian/build#10301&lt;/a&gt;&lt;/li&gt;&lt;li&gt;reporting: download-images report (versions provided + anomalies) to job summary. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/371?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#371&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rewrite patches: speed up the process up to nproc. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10163?ref=blog.armbian.com&quot;&gt;armbian/build#10163&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64-6.18: overlays: rewrite README.md. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10295?ref=blog.armbian.com&quot;&gt;armbian/build#10295&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64: add NanoPi NEO3 onboard fan (CON4) pwm-fan overlay. by &lt;a href=&quot;https://github.com/tenox7?ref=blog.armbian.com&quot;&gt;@tenox7&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10291?ref=blog.armbian.com&quot;&gt;armbian/build#10291&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rootfs: bump force-rebuild counter to 007. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10311?ref=blog.armbian.com&quot;&gt;armbian/build#10311&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: keep qemu-user-static current (fixes stale-qemu cross-arch failures). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/33?ref=blog.armbian.com&quot;&gt;armbian/actions#33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;scripts: source nightly images from armbian/ci releases (moved from os). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/370?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#370&lt;/a&gt;&lt;/li&gt;&lt;li&gt;software/jellyfin - Add host mounts for music, books. by &lt;a href=&quot;https://github.com/jjg?ref=blog.armbian.com&quot;&gt;@jjg&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/configng/pull/955?ref=blog.armbian.com&quot;&gt;armbian/configng#955&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sun60iw2: enable CONFIG_TUN as module for VPN support (Tailscale/WireGuard). by &lt;a href=&quot;https://github.com/diegodsgarcia?ref=blog.armbian.com&quot;&gt;@diegodsgarcia&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10302?ref=blog.armbian.com&quot;&gt;armbian/build#10302&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sunxi-6.12: fix bluetooth park-link quirk to use pre-6.16 API (test_bit). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10299?ref=blog.armbian.com&quot;&gt;armbian/build#10299&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uboot: bump EasePi-A2/R2 mainline U-Boot to v2026.07 and add resolute release support. by &lt;a href=&quot;https://github.com/ifroncy01?ref=blog.armbian.com&quot;&gt;@ifroncy01&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10274?ref=blog.armbian.com&quot;&gt;armbian/build#10274&lt;/a&gt;&lt;/li&gt;&lt;li&gt;update readme. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/2?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uwe5622: bump driver commit. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10317?ref=blog.armbian.com&quot;&gt;armbian/build#10317&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uwe5622: source the driver from armbian/uwe5622 (incl. the &amp;gt;=7.1 gpiod fix). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10300?ref=blog.armbian.com&quot;&gt;armbian/build#10300&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uwe5622: switch to unified driver in dedicated repo. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10113?ref=blog.armbian.com&quot;&gt;armbian/build#10113&lt;/a&gt;&lt;/li&gt;&lt;li&gt;wcn_boot: fix sdio_pub_int_init for the &amp;gt;=7.1 gpiod int_ap (GCC14 -Wint-conversion). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/uwe5622/pull/1?ref=blog.armbian.com&quot;&gt;armbian/uwe5622#1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-08-04T01:34:40+00:00</dc:date>
	<dc:creator>Michael Robinson</dc:creator>
</item> 
<item rdf:about="https://volumio.com/best-audio-os-for-raspberry-pi/">
	<title>Volumio: Best Audio OS for Raspberry Pi for Hi-Fi Listening</title>
	<link>https://volumio.com/best-audio-os-for-raspberry-pi/</link>
     <content:encoded>&lt;p&gt;A Raspberry Pi behind a good integrated amplifier can become a wonderfully focused music source, or a tiny computer that constantly asks for attention. The difference is the software. Choosing the best audio OS for Raspberry Pi is less about chasing technical jargon and more about creating a player that makes your library, favorite streaming service, and listening room feel connected.&lt;/p&gt;
&lt;p&gt;For a hi-fi system, an audio OS should disappear once the music starts. It should let you browse an album from your own collection, queue a new release, select the right output, and listen without negotiating with a desktop interface, a keyboard, or several disconnected apps. That is the standard worth using when you compare your options.&lt;/p&gt;
&lt;h2&gt;What Makes the Best Audio OS for Raspberry Pi?&lt;/h2&gt;
&lt;p&gt;A general-purpose operating system can play music, but it is not built around listening. It has background tasks, desktop windows, updates meant for office work, and endless ways to interrupt a session. An audio-focused operating system takes a different approach: it turns the Pi into a dedicated network player controlled from a phone, tablet, or browser.&lt;/p&gt;
&lt;p&gt;The best choice should handle the sources you actually use. For some listeners, that means a carefully tagged FLAC library on a network drive. For others, it means TIDAL, Qobuz, Spotify, internet radio, or a combination of all four. A strong audio OS brings those sources into one interface, so choosing music does not begin with deciding which app has it.&lt;/p&gt;
&lt;p&gt;Sound quality matters, but it deserves a clear-eyed view. An operating system cannot repair a poor DAC, noisy power, or a badly matched output. It can, however, provide a stable playback path, support high-resolution formats where your equipment benefits from them, and give you proper control over USB DACs and I2S audio boards. The goal is reliable, bit-perfect playback when appropriate, not a collection of settings that look impressive but add confusion.&lt;/p&gt;
&lt;p&gt;Ease of use is equally important. If other people in your household cannot find an album, start radio, or change volume without calling you, the system is not finished. A Raspberry Pi music player should feel like part of the hi-fi rack, not like a weekend project left open on a workbench.&lt;/p&gt;
&lt;h2&gt;Start With Your Listening System, Not the Pi&lt;/h2&gt;
&lt;p&gt;Before installing anything, decide how the Raspberry Pi will connect to your system. A USB DAC is the most flexible route and works well with a wide range of existing DACs and integrated amplifiers. An I2S DAC board, often called a HAT, can make for a compact all-in-one build with fewer cables. If your amplifier or DAC accepts a digital signal directly, a dedicated digital output board may be the better fit.&lt;/p&gt;
&lt;p&gt;This decision shapes what you need from the OS. It must recognize your chosen output and make switching sample rates predictable. It should also offer clear volume behavior. If your DAC or amplifier has its own high-quality analog volume control, many listeners prefer to run the player at a fixed output level. If you need software volume, use it deliberately and understand where it sits in the signal path.&lt;/p&gt;
&lt;p&gt;Your network deserves the same attention. Wired Ethernet is usually the simplest answer for a stationary hi-fi setup, particularly with high-resolution files stored on a network drive. Wi-Fi can work very well when the signal is strong, but it adds another variable when diagnosing dropouts. A good audio OS should make both options straightforward rather than requiring command-line network setup.&lt;/p&gt;
&lt;h2&gt;Why Volumio OS Fits Most Hi-Fi Builds&lt;/h2&gt;
&lt;p&gt;For most listeners building a Raspberry Pi network player, &lt;a href=&quot;https://volumio.com/introducing-volumio/&quot;&gt;Volumio OS&lt;/a&gt; is the strongest choice because it treats music playback as the whole purpose of the device. It combines local libraries, supported streaming services, web radio, and connected audio hardware in a single music-first environment. The interface is accessible enough for a first build while offering the output configuration and playback controls experienced hobbyists expect.&lt;/p&gt;
&lt;p&gt;That balance matters. A bare-bones player can be satisfying if you only send audio from one app, but it becomes limiting when your collection grows or your listening habits change. A full desktop distribution offers flexibility, yet that flexibility often means more maintenance, more processes running in the background, and less focus at the rack. A dedicated player environment occupies the useful middle ground: purpose-built, approachable, and capable of growing with the system.&lt;/p&gt;
&lt;p&gt;It is especially well suited to listeners with mixed sources. You may own years of &lt;a href=&quot;https://volumio.com/play-rip-cds-external-cd-drive-volumio/&quot;&gt;ripped CDs&lt;/a&gt;, keep a high-resolution download library, and use a streaming subscription to explore new music. Those should not feel like separate systems. A unified library and browsing experience lets the listening session lead, whether you begin with a familiar Miles Davis record or follow a recommendation into something new.&lt;/p&gt;
&lt;p&gt;There is also a practical benefit for builders. A focused audio OS removes much of the work that normally comes after installing a general-purpose computer platform: configuring the player, setting up a control interface, connecting storage, and making audio hardware behave consistently. You still get the pleasure of choosing the Pi, DAC, case, cables, and power arrangement. You simply spend less time maintaining software and more time listening.&lt;/p&gt;
&lt;h2&gt;When Another Type of Audio OS May Make Sense&lt;/h2&gt;
&lt;p&gt;The best answer does depend on the job. If you want the Raspberry Pi only as a lightweight endpoint for a single protocol, a minimal endpoint-focused system may be enough. It can be a sensible choice for a secondary room where another device handles library management and service integration.&lt;/p&gt;
&lt;p&gt;A desktop-based setup may also suit someone who wants the Pi to run unrelated software alongside music playback. That approach is more flexible, but it asks you to accept a computer-like experience. Updates, notifications, and manual configuration can become part of ownership.&lt;/p&gt;
&lt;p&gt;For a primary hi-fi system, those compromises are rarely attractive. Most owners want a player that turns on, reconnects to the network, remembers its library, and remains easy to control months after the original build. The more central the Pi is to your daily listening, the more value there is in choosing an OS designed specifically for that role.&lt;/p&gt;
&lt;h2&gt;Build Details That Affect the Result More Than You Think&lt;/h2&gt;
&lt;p&gt;Once you have selected the software, avoid treating every accessory as equally important. Start with a current Raspberry Pi model that has enough processing headroom for your library and preferred features, a quality power supply, dependable storage, and stable networking. Then choose the output hardware that suits the rest of the system.&lt;/p&gt;
&lt;p&gt;A clean, appropriately rated power supply can be worthwhile, especially in a revealing system, but it is not a substitute for sound setup fundamentals. Put the Pi in a case that protects the board and allows ventilation. Use a short, dependable USB cable if connecting to a DAC. If you are using an I2S board, confirm that the board and selected output driver match before judging sound quality.&lt;/p&gt;
&lt;p&gt;Library organization pays off every time you browse. Consistent artist, album, composer, genre, and artwork metadata makes a large collection inviting instead of frustrating. For classical music, composer and work tags are particularly valuable. For jazz and live recordings, accurate album-artist tags prevent one release from being scattered across multiple artist pages.&lt;/p&gt;
&lt;p&gt;Do not rush past the first listening session. Start with a few recordings you know intimately: a vocal track for presence, an acoustic recording for space, a dense arrangement for separation, and a familiar low-frequency passage for control. Listen at normal levels. The aim is not to hunt for differences between settings, but to verify that the system feels stable, natural, and easy to enjoy.&lt;/p&gt;
&lt;h2&gt;A Better Test Than Comparing Feature Lists&lt;/h2&gt;
&lt;p&gt;Feature lists can make every audio OS look similar. The better test is what happens on an ordinary Tuesday night. Can you find the album you want in seconds? Can you move from your own library to a streaming discovery without changing devices? Does the player remain responsive when a family member uses it? Can you return to the system after an update without relearning it?&lt;/p&gt;
&lt;p&gt;Those small moments determine whether a Raspberry Pi becomes a cherished part of the system or a clever experiment that eventually gets unplugged. Choose the platform that keeps the path from curiosity to music short, then give yourself an evening with a favorite record and no reason to touch a computer.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://volumio.com/best-audio-os-for-raspberry-pi/&quot;&gt;Best Audio OS for Raspberry Pi for Hi-Fi Listening&lt;/a&gt; appeared first on &lt;a href=&quot;https://volumio.com&quot;&gt;Volumio&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-04T00:03:57+00:00</dc:date>
	<dc:creator>Volumio</dc:creator>
</item> 
<item rdf:about="http://sinfallas.wordpress.com/?p=5377">
	<title>Xanadu developers: Protege tu Homelab: SSL Automático con Nginx Proxy Manager y Cloudflare</title>
	<link>https://sinfallas.wordpress.com/2026/08/03/protege-tu-homelab-ssl-automatico-con-nginx-proxy-manager-y-cloudflare/</link>
     <content:encoded>&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;

&lt;/div&gt;&lt;/figure&gt;</content:encoded> 
	<dc:date>2026-08-03T23:29:14+00:00</dc:date>
	<dc:creator>Jesus Palencia</dc:creator>
</item> 
<item rdf:about="https://www.skudonet.com/?p=77977">
	<title>ZEVENET: Why Vendor Dependency Is Becoming a Strategic Infrastructure Risk</title>
	<link>https://www.skudonet.com/blog/vendor-dependency-infrastructure-risk/</link>
     <content:encoded>&lt;p&gt;&lt;em&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;What we are seeing across enterprise ADC projects, and why more infrastructure teams are re-evaluating long-term vendor dependency.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;For years, infrastructure decisions were assessed through a familiar set of criteria: performance, availability, security, compatibility and cost.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Those factors still matter. But conversations around critical infrastructure are becoming broader.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;In discussions with customers, partners and infrastructure teams, another question is appearing more frequently:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;How much operational and strategic dependency are we creating when a critical part of our infrastructure relies on a single vendor?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Vendor dependency becomes a strategic infrastructure risk when relying on a provider starts to limit an organization’s ability to control costs, change deployment models, evolve its architecture or respond to new operational requirements. The risk lies not in the relationship itself, but in the loss of practical alternatives.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;&lt;a href=&quot;https://www.skudonet.com/blog/how-to-choose-application-delivery-controller/?utm_source=chatgpt.com&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;This question is particularly relevant for Application Delivery Controllers&lt;/a&gt;. Sitting directly in the path of application traffic, ADCs have evolved far beyond load balancing. Today, they combine traffic management, high availability, application security and policy enforcement, making them one of the most critical layers of enterprise infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;As a result, choosing an ADC influences far more than technical performance. It can affect how easily infrastructure evolves, how predictable future costs remain, how quickly teams respond to change and, ultimately, how much control an organization retains over its own architecture.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Vendor dependency is not inherently a problem. Every organization relies on strategic technology providers. The challenge begins when that dependency becomes difficult to measure, expensive to change or no longer aligns with the organization’s long-term infrastructure strategy.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Five signs vendor dependency is becoming an infrastructure risk&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Organizations rarely review an ADC platform because of a single failure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;More often, the conversation begins as infrastructure evolves, operational demands increase or commercial conditions change. Over time, a series of small decisions can lead teams to question whether the platform they selected years ago still supports the way they want to operate today.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Across enterprise ADC projects, these are the five signals we encounter most often.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;These are qualitative patterns from projects and conversations with infrastructure teams and partners, not the results of a formal survey — but they are the signals that come up most consistently when organizations reassess their ADC strategy. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;1. ADC licensing becomes harder to predict&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Licensing is often treated as a commercial issue. In reality, it can have a significant impact on infrastructure strategy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A platform may initially meet every technical and financial requirement, but as environments grow, the commercial model can become increasingly difficult to forecast.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;This may happen when capabilities are divided across multiple editions, additional modules are required for security or management, support levels change, or infrastructure growth introduces new licensing requirements.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The question is not simply whether the platform is expensive.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;It is whether the organization can confidently predict the cost of operating and expanding it over the coming years.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;For CIOs, that affects budgeting and long-term planning. For infrastructure teams, it can influence architectural decisions by discouraging new deployments, delaying expansion or limiting the adoption of capabilities that are technically available but commercially difficult to justify.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;It also makes the total cost of ownership harder to assess. Licensing fees may be only one part of the equation. Additional management products, security modules, specialist skills, support contracts and migration costs can all affect the long-term economics of the platform.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;When licensing begins to shape infrastructure decisions more than technical requirements, vendor dependency becomes a strategic concern rather than a procurement issue.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;2. Deployment flexibility across hybrid infrastructure starts to decline&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Enterprise infrastructure no longer follows a single deployment model.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Many organizations now operate across a combination of on-premises systems, virtualized environments, private cloud, public cloud and geographically distributed data centers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;While many ADC platforms support these environments, support alone does not guarantee operational consistency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The more important questions are:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can the same operating model be maintained across different environments?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can configurations move without redesigning the architecture?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Does the organization remain free to choose where workloads run?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Will future cloud or virtualization decisions force a change in ADC strategy?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Configuration portability is particularly important. An ADC configuration may include virtual services, health checks, persistence policies, traffic-management rules, TLS certificates, WAF policies and automation scripts. If those elements depend heavily on proprietary formats or interfaces, moving to another environment or platform can require more than deploying a replacement appliance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Infrastructure teams increasingly value platforms that adapt to different deployment models instead of encouraging a single infrastructure path.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;This matters because an ADC is rarely deployed for only a few years. The environment around it will almost certainly evolve, and today’s platform decision should not unnecessarily restrict tomorrow’s architecture.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;3. Innovation begins to follow the vendor’s roadmap, not the organization’s&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Every technology vendor has its own product roadmap.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The challenge arises when an organization’s priorities begin to diverge from it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Perhaps the business needs support for a new deployment model, deeper automation, a different licensing approach or faster access to technical expertise. None of these requests may be strategically important to the vendor, even though they are important to the customer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;This is a natural consequence of large product portfolios serving thousands of organizations with different priorities.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The question is not whether the vendor continues to innovate.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The question is whether that innovation is aligned with the direction in which the customer’s infrastructure is actually moving.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;When that alignment weakens, organizations can find themselves delaying projects, adapting their own plans or accepting compromises simply because changing direction has become increasingly difficult.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;4. Operational complexity continues to grow&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Infrastructure complexity rarely appears overnight.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;It accumulates over time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A platform that was straightforward to manage a few years ago can become increasingly difficult to operate as organizations add new applications, expand into different environments, strengthen security controls or introduce additional management tools.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;For technical teams, the consequences are practical rather than theoretical.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Routine changes may require multiple interfaces. Troubleshooting can involve different products or support channels. Knowledge becomes concentrated in a small number of specialists, making day-to-day operations harder to maintain and scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Automation can become another source of dependency. APIs, configuration models and orchestration workflows may be closely tied to a particular platform. The more operational processes depend on proprietary implementations, the higher the switching costs become.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;This affects more than operational efficiency. It can increase configuration risk, extend troubleshooting times and make even simple changes more difficult than they need to be.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;For many infrastructure teams, simplicity is no longer a “nice to have”. It has become an operational requirement. A platform that is easier to understand, monitor and manage allows teams to spend less time maintaining infrastructure and more time improving it.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;5. Business resilience depends on more than high availability&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;High availability has always been one of the primary reasons for deploying an ADC.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;But resilience extends beyond keeping applications online during a technical failure. It also includes the organization’s ability to adapt when infrastructure, business priorities or commercial conditions change.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A highly available platform can still create strategic constraints if workloads are difficult to move, costs are unpredictable, expertise is hard to access or the architecture cannot evolve without significant redesign.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;True resilience is therefore not simply the ability to withstand failure. It is the ability to continue operating and evolving without being unnecessarily constrained by decisions made years earlier.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;When an infrastructure project triggers an ADC strategy review&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;One of the misconceptions surrounding ADC migrations is that they happen because an existing platform has failed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;In reality, that is rarely what we see.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;More often, an unrelated infrastructure project creates an opportunity to revisit decisions that may have remained unchanged for years:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A hardware refresh.&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A cloud migration.&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A licensing renewal.&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;An infrastructure modernization initiative.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A good example&lt;a href=&quot;https://www.skudonet.com/success-stories/f5-migration-case-study/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt; is the migration carried out by Pablo de Olavide University&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;What initially began as a hardware renewal became a broader assessment of the organization’s ADC strategy. Rather than simply replacing appliances, the team evaluated operational complexity, long-term costs, support and whether the existing platform still aligned with its current infrastructure objectives.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The result was a migration to SKUDONET.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Not because the previous platform had stopped working.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;But because the organization concluded that a different operational model was better suited to where its infrastructure was heading.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;It is a pattern we are seeing more frequently across enterprise ADC projects.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Organizations rarely migrate because yesterday’s decision was wrong. They migrate because today’s requirements are different from those that shaped the original decision.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Questions worth asking before the next ADC decision&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Reviewing an ADC platform does not necessarily mean planning a migration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Sometimes the conclusion will be that the current platform remains the right choice.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The value lies in asking whether that choice still aligns with the organization’s future direction.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;A structured review should consider five areas.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Commercial predictability&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can we predict the cost of operating and scaling the platform over the next three to five years?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Are core capabilities included, or do they depend on additional products, modules or licenses?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;How could future changes to licensing or support affect the architecture?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;Deployment and configuration portability&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can we deploy consistently across physical, virtual, cloud and hybrid environments?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can configurations, policies and operational processes move between environments?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Are we dependent on proprietary formats or platform-specific tooling?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;Operational maintainability&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;How easy is it for our teams to monitor, troubleshoot and evolve the platform?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Is operational knowledge distributed across the team or concentrated in a few specialists?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can the platform integrate with our existing automation and observability workflows?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;Roadmap alignment&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Does the current ADC still support our infrastructure roadmap?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Is the vendor’s product direction aligned with our automation, security and deployment requirements?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can we access technical expertise quickly when it matters most?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;Exit readiness&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Do we understand the technical and operational cost of changing platforms?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Can configurations and policies be documented or exported in a usable format?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Is there a realistic migration path if the platform no longer meets our requirements?&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;font-weight: 400;&quot;&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Would we make the same decision if we were selecting an ADC today?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;These questions are not intended to create dissatisfaction with an existing vendor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;They are intended to determine whether the current platform continues to create more value than constraint.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;An exit strategy does not mean an organization expects to leave its provider. It means the organization understands what would be required if circumstances changed. That knowledge makes vendor dependency measurable rather than assumed.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Looking beyond the next renewal&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Organizations do not need to eliminate vendor dependency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;In practice, every enterprise depends on strategic technology partners.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The goal is to understand where that dependency exists, whether it remains acceptable and how it might affect future infrastructure decisions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;That means looking beyond current availability and performance. Organizations should also consider switching costs, configuration portability, interoperability, roadmap alignment and whether a practical exit strategy exists.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The EU’s NIS2 Directive is a useful external reference point here: &lt;a class=&quot;underline underline underline-offset-2 decoration-1 decoration-current/40 hover:decoration-current focus:decoration-current&quot; href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&quot; rel=&quot;noopener nofollow&quot; target=&quot;_blank&quot;&gt;recital 90&lt;/a&gt; calls for coordinated supply chain risk assessments to identify critical dependencies and single points of failure, the same concern this article addresses at the ADC layer.&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;The best time to ask these questions is not when an urgent migration becomes unavoidable. It is during the routine planning cycles in which architecture, costs and operational requirements are already being reviewed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;By treating vendor dependency as a strategic consideration rather than simply a procurement issue, organizations give themselves more options for the future. &lt;a href=&quot;https://www.skudonet.com/blog/application-delivery-controller-adc-resilience/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;That optionality is one of the most valuable forms of infrastructure resilience.&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Frequently Asked Questions About Vendor Dependency&lt;/b&gt;&lt;/h2&gt;
&lt;h3&gt;&lt;b&gt;What is vendor dependency?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Vendor dependency refers to the degree to which an organization’s operations, infrastructure or business strategy rely on a specific technology provider.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Dependency itself is not necessarily a risk. It becomes a concern when it limits flexibility, makes costs difficult to predict, restricts architectural decisions or makes it difficult for the organization to adapt as infrastructure and business requirements evolve.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;What is the difference between vendor dependency and vendor lock-in?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Vendor dependency is a natural outcome of working with strategic technology providers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Vendor lock-in occurs when changing provider becomes technically, operationally or commercially difficult. This may be caused by proprietary technologies, non-portable configurations, specialist knowledge requirements, contractual conditions or high migration costs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;All organizations have some level of vendor dependency, but not all experience vendor lock-in.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;When does vendor dependency become a strategic infrastructure risk?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Vendor dependency becomes a strategic infrastructure risk when it starts to influence decisions that should be based on technical or business requirements.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Warning signs include unpredictable licensing, declining deployment flexibility, increasing operational complexity, misalignment with the vendor’s roadmap and the absence of a realistic exit strategy.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;How can organizations reduce vendor dependency in an ADC strategy?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Organizations can reduce vendor dependency by prioritizing deployment flexibility, configuration portability, documented APIs, interoperability and predictable licensing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;They should also understand switching costs, document operational processes and periodically test whether the platform continues to support their infrastructure roadmap.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Using multiple vendors is not the only option. The objective is to preserve practical alternatives and avoid unnecessary constraints.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Continue the conversation&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;Every ADC evaluation starts for a different reason, but the objective is the same: ensuring today’s infrastructure decisions continue to support tomorrow’s requirements.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-weight: 400;&quot;&gt;If your team is reviewing its ADC strategy—or simply wants a second technical perspective—we would be happy to share our experience and discuss the architectural considerations that typically emerge during these evaluations.&lt;/span&gt;&lt;/p&gt;
&lt;div align=&quot;center&quot; style=&quot;margin-top: 30px;&quot;&gt;&lt;a class=&quot;brxe-button bricks-button red-btn&quot; href=&quot;https://www.skudonet.com/about-us/contact/&quot;&gt;Talk to our engineering team&lt;/a&gt;&lt;/div&gt;</content:encoded> 
	<dc:date>2026-08-03T10:56:17+00:00</dc:date>
	<dc:creator>Isabel Perez</dc:creator>
</item> 
<item rdf:about="https://volumio.com/how-to-build-raspberry-pi-music-streamer/">
	<title>Volumio: How to Build a Raspberry Pi Music Streamer</title>
	<link>https://volumio.com/how-to-build-raspberry-pi-music-streamer/</link>
     <content:encoded>&lt;p&gt;A Raspberry Pi can become far more than a small computer tucked behind a television. Connected thoughtfully to your hi-fi, it can be a focused network music player: one place to browse a personal library, play music from streaming services, and send a clean digital signal to the rest of your system. If you are searching for “how to build raspberry pi music streamer,” the good news is that the project is approachable. The more important news is that a few decisions made before you start will have a real effect on sound quality, everyday convenience, and how long the player remains useful.&lt;/p&gt;
&lt;h2&gt;How to Build a Raspberry Pi Music Streamer That Fits Your System&lt;/h2&gt;
&lt;p&gt;Start with the role the streamer will play. A Raspberry Pi music streamer does not need to replace every component in your system. It may feed an existing DAC, connect directly to an integrated amplifier with digital inputs, or serve as an all-in-one digital source when paired with a DAC expansion board.&lt;/p&gt;
&lt;p&gt;That decision determines the connection path. If you already own a DAC you enjoy, USB output is often the simplest route. It keeps the Raspberry Pi separate from digital-to-analog conversion and gives you flexibility to change DACs later. If your amplifier or DAC accepts S/PDIF, an add-on board can provide coaxial or optical output. If you want the smallest possible system, a DAC HAT can sit directly on the Pi’s GPIO header and provide analog outputs.&lt;/p&gt;
&lt;p&gt;There is no universally superior option. A good USB DAC may be the right match for one system, while a quality DAC HAT can be wonderfully compact and satisfying in another. Let the inputs on the equipment you already own guide the build instead of buying parts simply because they are popular.&lt;/p&gt;
&lt;h3&gt;Choose the core hardware&lt;/h3&gt;
&lt;p&gt;For most listeners, a Raspberry Pi 4 provides more than enough performance for music playback. It has dependable networking, USB ports for a DAC or storage drive, and broad support across audio software. A Raspberry Pi 5 offers more processing headroom, but a music streamer rarely needs its extra power. It can also run warmer, so it is not automatically the better listening-room choice.&lt;/p&gt;
&lt;p&gt;A practical parts list includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A Raspberry Pi 4 or Raspberry Pi 5, plus its official or high-quality power supply&lt;/li&gt;
&lt;li&gt;A microSD card from a reliable manufacturer, ideally 16 GB or larger&lt;/li&gt;
&lt;li&gt;A case that leaves room for your selected output board, if using one&lt;/li&gt;
&lt;li&gt;An Ethernet cable or a stable Wi-Fi connection&lt;/li&gt;
&lt;li&gt;A USB DAC, digital-output HAT, or DAC HAT suited to your system&lt;/li&gt;
&lt;li&gt;A phone, tablet, or computer for initial setup and everyday control&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If your music library is stored locally, you may also need a USB hard drive, SSD, or network-attached storage. An SSD is quiet, fast, and generally a better fit for a listening room than a spinning drive, though either can work well.&lt;/p&gt;
&lt;p&gt;Do not treat the power supply as an afterthought. The Pi itself is sensitive to insufficient power, and voltage instability can cause dropouts, storage corruption, or inconsistent behavior. Use a supply designed for the model you choose. Once the system is working, you can decide whether an upgraded low-noise power supply makes sense in the context of the whole system.&lt;/p&gt;
&lt;h2&gt;Build the Signal Path Before Installing Software&lt;/h2&gt;
&lt;p&gt;Assemble the hardware with the Raspberry Pi powered off. Install a DAC HAT or digital-output HAT carefully, ensuring its GPIO pins are aligned before applying pressure. Fit the Pi into its case, connect Ethernet if possible, then attach the chosen audio output to your DAC, amplifier, or active speakers.&lt;/p&gt;
&lt;p&gt;Wired Ethernet is the sensible default for a fixed hi-fi installation. It avoids the occasional uncertainty of Wi-Fi and is particularly worthwhile with high-resolution files or busy home networks. Wi-Fi can still be an excellent choice when the router is nearby and running a cable would compromise the room. The best network connection is the one that stays stable while you listen.&lt;/p&gt;
&lt;p&gt;For USB audio, connect the DAC directly to the Pi at first. Avoid adding USB hubs until the basic system is confirmed to work. For a coaxial or optical HAT, use a properly terminated cable and select the appropriate input on your downstream component. With an analog DAC HAT, connect its RCA outputs to a line-level input, never a phono input.&lt;/p&gt;
&lt;p&gt;Keep volume control intentional. If your integrated amplifier or preamp is the best volume control in the system, set the streamer to fixed output where appropriate and control level downstream. If you are connecting directly to active speakers or a power amplifier, use the streamer’s volume control carefully and begin playback at a low level.&lt;/p&gt;
&lt;h2&gt;Install a Music-Focused Operating System&lt;/h2&gt;
&lt;p&gt;A general desktop operating system can play music, but it adds complexity you do not need in a dedicated player. A purpose-built audio operating system starts directly into a music interface, manages audio devices, and makes playback control available from a browser or companion app.&lt;/p&gt;
&lt;p&gt;Write the chosen operating-system image to the microSD card using an imaging tool on your computer. Insert the card into the Pi, connect the network and audio hardware, then switch on the power. Give the system a few minutes for its first startup.&lt;/p&gt;
&lt;p&gt;From a phone, tablet, or computer on the same network, open the player’s setup interface. You will typically select the active output, set network preferences, name the device, and configure your library. In Volumio, this process is designed around the listening experience rather than command-line administration, so a DIY player can feel at home beside a serious hi-fi component.&lt;/p&gt;
&lt;p&gt;If you are using a DAC HAT or digital-output HAT, enable its specific driver in the audio settings. This step matters. The Pi may otherwise default to an output you are not using, or fail to recognize the board correctly. With a USB DAC, select it from the list of detected audio devices and confirm the supported sample rates.&lt;/p&gt;
&lt;h3&gt;Add local music and streaming services&lt;/h3&gt;
&lt;p&gt;For local files, point the streamer to a shared folder on a computer or network storage device, or connect a USB drive directly to the Pi. Organize music with clear album folders and accurate metadata before scanning. A beautiful player interface can only work with the information in your files, so clean artist names, album titles, artwork, and track numbers pay off every time you browse.&lt;/p&gt;
&lt;p&gt;Then connect the services you use. Depending on your subscriptions and the software features available to you, this may include high-resolution streaming, internet radio, and other music sources. The goal is not to collect every possible service. It is to make the music you return to easy to find, whether it lives on a drive in your home or in a streaming catalog.&lt;/p&gt;
&lt;p&gt;Take a moment to set library scan behavior, favorites, and playback queue preferences. These small choices turn a project into an appliance. When guests can find an album, when a late-night listening session begins without troubleshooting, and when your collection sits alongside the &lt;a href=&quot;https://volumio.com/hybrid-playlist-sources-volumio/&quot;&gt;music you stream&lt;/a&gt;, the system is doing its job.&lt;/p&gt;
&lt;h2&gt;Set Up for Better Listening, Not Just Successful Playback&lt;/h2&gt;
&lt;p&gt;Once music plays, resist the urge to change ten settings at once. Begin with a familiar recording and verify the basics: left and right channels are correct, the output sample rate is as expected, and there are no clicks, dropouts, or sudden volume changes.&lt;/p&gt;
&lt;p&gt;If playback is unreliable, work through the simplest causes first. Confirm that the power supply is sufficient, test Ethernet instead of Wi-Fi, try another USB cable, and make sure the DAC is selected as the active output. A large library may also take time to index, especially over a network share. These are usually setup issues, not signs that the Pi lacks the ability to be an excellent source.&lt;/p&gt;
&lt;p&gt;Avoid unnecessary digital processing if your priority is faithful playback. Upsampling, equalization, and software volume control can all be useful in the right system, but they are choices rather than mandatory upgrades. Room correction or EQ may improve a difficult room dramatically. In a well-balanced system, a direct signal path may be preferable. Listen, compare, and keep the settings that serve your music.&lt;/p&gt;
&lt;p&gt;A separate linear power supply, premium cables, and elaborate cases can be rewarding refinements, but they should come after reliability, correct configuration, and a sound output stage that matches your system. Put the budget where it makes the largest difference for your setup, whether that is a better DAC, speaker placement, room treatment, or simply more music.&lt;/p&gt;
&lt;h2&gt;Give the Project a Place in Your Listening Life&lt;/h2&gt;
&lt;p&gt;A Raspberry Pi streamer is especially compelling because it can grow with you. Start with USB into the DAC you already own. Add network storage when the library expands. Move to a different output board if your system changes. The software interface, playlists, and habits you build can remain at the center.&lt;/p&gt;
&lt;p&gt;The best DIY streamer is not the one with the longest parts list. It is the one that disappears when the first notes begin, leaving your collection, your favorite services, and the pleasure of listening in one place.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://volumio.com/how-to-build-raspberry-pi-music-streamer/&quot;&gt;How to Build a Raspberry Pi Music Streamer&lt;/a&gt; appeared first on &lt;a href=&quot;https://volumio.com&quot;&gt;Volumio&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-03T09:03:10+00:00</dc:date>
	<dc:creator>Volumio</dc:creator>
</item> 
<item rdf:about="https://sparkylinux.org/?p=14118">
	<title>SparkyLinux: Sparky news 2026/07</title>
	<link>https://sparkylinux.org/sparky-news-2026-07/</link>
     <content:encoded>&lt;p&gt;The 7th monthly Sparky project and donate report of the 2026: – Linux kernel updated up to 7.1.5, 6.18.41-LTS, 6.12.100-LTS – added to our repos: Fooyin audio player Many thanks to all of you for supporting our open-source projects. Your donations help keeping them and us alive. Don’t forget to send a small tip in August too, please. * Keep in mind that some amounts coming to us…&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://sparkylinux.org/sparky-news-2026-07/&quot; rel=&quot;nofollow&quot;&gt;Source&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-08-01T17:25:15+00:00</dc:date>
	<dc:creator>pavroo</dc:creator>
</item> 
<item rdf:about="https://puri.sm/?p=85732">
	<title>Purism PureOS: PureOS Development Report: June 2026</title>
	<link>https://puri.sm/posts/pureos-development-report-june-2026/</link>
     <content:encoded>&lt;p&gt;Thanks for joining us again!  In our May update, we mentioned that we&#39;re bringing in updated dependencies as part of the goal to ship the latest Phosh desktop environment in PureOS Dawn.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://puri.sm/posts/pureos-development-report-june-2026/&quot; rel=&quot;nofollow&quot;&gt;PureOS Development Report: June 2026&lt;/a&gt; appeared first on &lt;a href=&quot;https://puri.sm/&quot; rel=&quot;nofollow&quot;&gt;Purism&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-31T22:48:51+00:00</dc:date>
	<dc:creator>Purism</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=69428">
	<title>GreenboneOS: CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!</title>
	<link>https://www.greenbone.net/en/blog/cis-benchmark-windows-server/</link>
     <content:encoded>Microsoft technologies are foundational to enterprise IT globally, providing the backbone for operation-critical databases, identity services, core server workloads, and daily productivity applications at many organizations. Greenbone is happy to announce new compliance scans aligned with four CIS Benchmarks for Microsoft environments. CIS Benchmarks provide prescriptive guidance for establishing secure configurations and complement essential security […]</content:encoded> 
	<dc:date>2026-07-31T12:03:42+00:00</dc:date>
	<dc:creator>Greenbone AG</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39629">
	<title>Deepin: (中文) 从XDG标准到全球共建：如意玲珑迎来首个海外开源贡献</title>
	<link>https://www.deepin.org/en/flutter-linglong-store-espanol/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-31T10:13:32+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39618">
	<title>Deepin: deepin-skills Officially Open-Sourced: Four Core Skills for deepin Developers</title>
	<link>https://www.deepin.org/en/deepin-skills/</link>
     <content:encoded>SUMMARY The deepin community has officially open-sourced deepin-skills, an AI-oriented development resource library for deepin 25. It includes four core skills: DTK application development, DDE Shell extension development, DDE Control Center plugin development, and DDE tray plugin development. This toolkit integrates official documentation, specifications and test cases. Compatible with AI programming Agents, it enables developers to acquire targeted technical guidance through natural language prompts and simplifies native desktop development within the deepin ecosystem. What is open-sourced deepin-skills project? It is a curated repository of developer skill sets built for native application and desktop plugin development on deepin. Whether you are new to ...&lt;a href=&quot;https://www.deepin.org/en/deepin-skills/&quot;&gt;Read more&lt;/a&gt;</content:encoded> 
	<dc:date>2026-07-31T02:55:08+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39610">
	<title>Deepin: deepin社区2026上半年AI辅助开发产品大盘点：社区创造力大爆发！</title>
	<link>https://www.deepin.org/en/2026-h1-roundup-of-ai-assisted-development-products/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-31T02:40:29+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=69359">
	<title>GreenboneOS: Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water</title>
	<link>https://www.greenbone.net/en/blog/linux-vulnerabilities-2026/</link>
     <content:encoded>Several concerning vulnerabilities affecting Linux have emerged in recent months. The vulnerabilities include CISA Known Exploited Vulnerabilities (KEV) entries for CVE-2026-31431 (aka Copy Fail) [1], and an older flaw, CVE-2022-0492 [2]. However, a wave of concerning new vulnerabilities are associated with publicly available exploits or proof-of-concept (PoC) code. Collectively, the flaws represent local privilege escalation, […]</content:encoded> 
	<dc:date>2026-07-30T12:08:53+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.univention.de/?p=87916">
	<title>Univention Corporate Server: Introducing the Univention Integration Catalog: One Home for Every Integration</title>
	<link>https://www.univention.com/blog-en/2026/07/univention-integration-catalog-nubus/</link>
     <content:encoded>&lt;div class=&quot;wpb-content-wrapper&quot;&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;
	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;p&gt;If you know Univention, you know the App Center. For years, it has been the go-to place for selecting and installing applications on Nubus for virtual machines (UCS). It has served its purpose well and that is exactly the point: our integration ecosystem has long outgrown installable apps.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Identity connectors, groupware integrations, ISV applications via the ID Broker, packaged integrations for cloud-native environments running Univention Nubus&lt;/strong&gt;, the list is long. And it kept growing, while the individual scenarios remained scattered across different web pages, documentation and forum howtos. Administrators had to hunt for what they needed; partners struggled to make their solutions visible.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;That changes now. The new Integration Catalog brings everything together in one place.&lt;/strong&gt;&lt;/p&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Everything in One Place – Searchable and Filterable&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;p&gt;The &lt;a href=&quot;https://www.univention.com/products/integration-catalog/&quot;&gt;Integration Catalog&lt;/a&gt; is the single entry point for every type of integration with Univention Nubus: App Center applications, identity and groupware connectors, ID Broker connections for the education sector, openDesk components – all in one searchable overview.&lt;/p&gt;
&lt;p&gt;What works with our products? How do I get started? The catalog answers these questions directly – with filters by integration type, functionality and compatible product.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.univention.de/wp-content/uploads/2026/07/screencapture-univention-products-integration-catalog-2026-07-30-09_21_47.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;alignleft wp-image-87920&quot; height=&quot;350&quot; src=&quot;https://www.univention.de/wp-content/uploads/2026/07/screencapture-univention-products-integration-catalog-2026-07-30-09_21_47-1000x976.png&quot; width=&quot;358&quot; /&gt;&lt;/a&gt;&lt;a href=&quot;https://www.univention.de/wp-content/uploads/2026/07/screencapture-univention-products-integration-catalog-active-directory-takeover-2026-07-30-09_22_09.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;alignright wp-image-87921&quot; height=&quot;350&quot; src=&quot;https://www.univention.de/wp-content/uploads/2026/07/screencapture-univention-products-integration-catalog-active-directory-takeover-2026-07-30-09_22_09-1000x809.png&quot; width=&quot;433&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  The Next Evolution of the App Center&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;p&gt;The Integration Catalog does not replace the App Center, it builds on it. While the Univention App Center focuses on apps that are installed directly on &lt;a href=&quot;https://www.univention.com/products/ucs/&quot;&gt;Nubus for virtual machines (UCS)&lt;/a&gt;, the catalog opens up the view to the entire integration ecosystem around &lt;a href=&quot;https://www.univention.com/products/nubus/&quot;&gt;Nubus&lt;/a&gt;. The familiar, curated experience stays the same.&lt;/p&gt;
&lt;p&gt;Once the catalog goes live, it becomes the new central entry point and replaces the previous App Center catalog on our website.&lt;/p&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  And Sometimes No Software Is Needed At All&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;p&gt;One insight the catalog makes properly visible for the first time: many applications work with Nubus without any additional software. Nubus is built on open standards, LDAP, SAML, OpenID Connect, and often a simple configuration is all it takes.&lt;/p&gt;
&lt;p&gt;Take GitLab as an example: a community howto walks you through connecting a self-hosted GitLab to Nubus via LDAP and OIDC – without a single additional package. The catalog now showcases these documentation-based integrations on equal footing with installable apps and packaged integrations.&lt;/p&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Open, Diverse and Always Up to Date&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Diversity and flexibility:&lt;/strong&gt; The catalog reflects the true breadth of the ecosystem – covering integrations for on-premises environments with UCS, cloud-native deployments with Nubus on Kubernetes, and solutions for education and the public sector.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Open and community-driven:&lt;/strong&gt; All catalog entries are maintained as simple YAML files in a public &lt;a href=&quot;http://github.com/univention/integration-catalog&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;GitHub repository&lt;/a&gt;. Partners, ISVs and community members can contribute new entries or update existing ones via pull request at any time.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Always up to date:&lt;/strong&gt; The website syncs automatically with the repository. The catalog always reflects the latest state of the ecosystem – not a one-off snapshot, but a living picture of what is available.&lt;/li&gt;
&lt;/ul&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  What Does This Mean In Practice?&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;For decision-makers:&lt;/strong&gt; See at a glance how many applications already connect to Nubus – and how low the barrier is for the next one.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;For administrators:&lt;/strong&gt; Find, evaluate and adopt integrations across schools, municipalities, enterprises and cloud-native environments faster with technical details such as protocols, supported deployments and direct links to documentation for every entry.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;For partners and ISVs:&lt;/strong&gt; Greater visibility for your integration with your own entry, logo and links, right where customers start their search.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;For the ecosystem as a whole:&lt;/strong&gt; More integrations, easier adoption, greater transparency, a healthier ecosystem around Nubus.&lt;/li&gt;
&lt;/ul&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Explore It Now&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;p&gt;The Integration Catalog is live at &lt;a href=&quot;https://www.univention.com/products/integration-catalog/&quot;&gt;https://www.univention.com/products/integration-catalog/&lt;/a&gt;. More than 90 integrations are already listed – and the number keeps growing.&lt;/p&gt;
&lt;p&gt;Take a look. And if you build integrations for our products, get in touch or open a pull request. We look forward to seeing your solution in the catalog.&lt;/p&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Der Beitrag &lt;a href=&quot;https://www.univention.com/blog-en/2026/07/univention-integration-catalog-nubus/&quot;&gt;Introducing the Univention Integration Catalog: One Home for Every Integration&lt;/a&gt; erschien zuerst auf &lt;a href=&quot;https://www.univention.com&quot;&gt;Univention&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-30T08:35:17+00:00</dc:date>
	<dc:creator>Vanessa Knoop</dc:creator>
</item> 
<item rdf:about="https://blog.armbian.com/rss/6a6a15fb0b8ab5000178c729">
	<title>ARMBIAN: Armbian Newsletter July 2026</title>
	<link>https://blog.armbian.com/armbian-newsletter-july-2026/</link>
     <content:encoded>&lt;img alt=&quot;Armbian Newsletter July 2026&quot; src=&quot;https://blog.armbian.com/content/images/2026/07/armbian_wide.png&quot; /&gt;&lt;p&gt;Welcome to the latest Armbian Newsletter: your source for the latest developments, community highlights, and behind-the-scenes updates from the world of open-source ARM and RISC-V computing.&lt;/p&gt;&lt;p&gt;The upcoming Armbian release 26.08 will be based on Linux 6.18 LTS, giving users the benefits of a long-term support kernel with improved hardware compatibility, security updates, and ongoing upstream maintenance. This provides a solid foundation for future development while keeping systems stable and reliable.&lt;/p&gt;&lt;div class=&quot;kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal  kg-cta-has-img  &quot;&gt;
            
                &lt;div class=&quot;kg-cta-sponsor-label-wrapper&quot;&gt;
                    &lt;div class=&quot;kg-cta-sponsor-label&quot;&gt;
                        &lt;span style=&quot;white-space: pre-wrap;&quot;&gt;SPONSORED&lt;/span&gt;
                    &lt;/div&gt;
                &lt;/div&gt;
            
            &lt;div class=&quot;kg-cta-content&quot;&gt;
                
                    &lt;div class=&quot;kg-cta-image-container&quot;&gt;
                        &lt;img alt=&quot;Armbian Newsletter July 2026&quot; src=&quot;https://blog.armbian.com/content/images/2025/10/ChatGPT-Image-Oct-17--2025--07_29_49-AM.png&quot; /&gt;
                    &lt;/div&gt;
                
                
                    &lt;div class=&quot;kg-cta-content-inner&quot;&gt;
                    
                        &lt;div class=&quot;kg-cta-text&quot;&gt;
                            &lt;p&gt;&lt;a class=&quot;cta-link-color&quot; href=&quot;https://www.armbian.com/donate/?ref=blog.armbian.com&quot; rel=&quot;noreferrer&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;Join us in making open source better&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;! Every donation helps Armbian improve &lt;/span&gt;&lt;b&gt;&lt;strong style=&quot;white-space: pre-wrap;&quot;&gt;security&lt;/strong&gt;&lt;/b&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;, &lt;/span&gt;&lt;b&gt;&lt;strong style=&quot;white-space: pre-wrap;&quot;&gt;performance&lt;/strong&gt;&lt;/b&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;, and &lt;/span&gt;&lt;b&gt;&lt;strong style=&quot;white-space: pre-wrap;&quot;&gt;reliability&lt;/strong&gt;&lt;/b&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt; so everyone can enjoy a solid foundation for their devices.&lt;/span&gt;&lt;/p&gt;
                        &lt;/div&gt;
                    
                    
                    &lt;/div&gt;
                
            &lt;/div&gt;
        &lt;/div&gt;&lt;figure class=&quot;kg-card kg-bookmark-card&quot;&gt;&lt;a class=&quot;kg-bookmark-container&quot; href=&quot;https://blog.armbian.com/github-highlights-35/&quot;&gt;&lt;div class=&quot;kg-bookmark-content&quot;&gt;&lt;div class=&quot;kg-bookmark-title&quot;&gt;Github Highlights&lt;/div&gt;&lt;small&gt;&lt;div class=&quot;kg-bookmark-description&quot;&gt;This week’s work centers on new board enablement and platform maintenance, kernel and U-Boot refresh across Rockchip and Sunxi, and CI/build infrastructure improvements. Board support expanded with the addition of Sovol Zero, SV08, and SV08 Max on the H616 platform, alongside mainline and edge enablement for the&lt;/div&gt;&lt;/small&gt;&lt;/div&gt;&lt;/a&gt;&lt;/figure&gt;&lt;figure class=&quot;kg-card kg-bookmark-card&quot;&gt;&lt;a class=&quot;kg-bookmark-container&quot; href=&quot;https://blog.armbian.com/beat-the-heat/&quot;&gt;&lt;div class=&quot;kg-bookmark-content&quot;&gt;&lt;div class=&quot;kg-bookmark-title&quot;&gt;Beat the heat&lt;/div&gt;&lt;small&gt;&lt;div class=&quot;kg-bookmark-description&quot;&gt;Rising summer ambient temperatures erode the thermal headroom SBCs rely on, causing silent throttling and instability. Here’s why high-density SoCs like the RK3588 are most at risk, and how to pick the right cooling strategy to stay stable.&lt;/div&gt;&lt;/small&gt;&lt;/div&gt;&lt;/a&gt;&lt;/figure&gt;&lt;figure class=&quot;kg-card kg-bookmark-card&quot;&gt;&lt;a class=&quot;kg-bookmark-container&quot; href=&quot;https://blog.armbian.com/the-factory-behind-armbian/&quot;&gt;&lt;div class=&quot;kg-bookmark-content&quot;&gt;&lt;div class=&quot;kg-bookmark-title&quot;&gt;The factory behind Armbian&lt;/div&gt;&lt;small&gt;&lt;div class=&quot;kg-bookmark-description&quot;&gt;When you download an Armbian image, flash it to your SD card or SSD, and boot your board, a huge amount of automation has already happened behind the scenes.
That invisible engine is what you can see at https://actions.armbian.com. Think of it as the mission control center&lt;/div&gt;&lt;/small&gt;&lt;/div&gt;&lt;/a&gt;&lt;/figure&gt;</content:encoded> 
	<dc:date>2026-07-29T15:29:43+00:00</dc:date>
	<dc:creator>Michael Robinson</dc:creator>
</item> 
<item rdf:about="https://blog.armbian.com/rss/696e316e93dc320001185d5e">
	<title>ARMBIAN: The factory behind Armbian</title>
	<link>https://blog.armbian.com/the-factory-behind-armbian/</link>
     <content:encoded>&lt;img alt=&quot;The factory behind Armbian&quot; src=&quot;https://blog.armbian.com/content/images/2026/01/armbian-factory-1.jpg&quot; /&gt;&lt;p&gt;When you download an Armbian image, flash it to your SD card or SSD, and boot your board, a huge amount of automation has already happened behind the scenes.&lt;br /&gt;That invisible engine is what you can see at &lt;a href=&quot;https://actions.armbian.com/?utm_source=chatgpt.com&quot; rel=&quot;noopener&quot;&gt;&lt;strong&gt;https://actions.armbian.com&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Think of it as the mission control center of Armbian’s infrastructure.&lt;/p&gt;&lt;p&gt;It doesn’t look flashy, but it represents one of the most important parts of the project: the system that builds, tests, validates, and maintains Armbian for hundreds of boards, kernels, and configurations.&lt;/p&gt;&lt;blockquote&gt;&lt;em&gt;Armbian isn’t just an operating system. It’s an automated production platform for embedded Linux.&lt;/em&gt;&lt;/blockquote&gt;&lt;h2 id=&quot;what-is-actionsarmbiancom&quot;&gt;What is actions.armbian.com?&lt;/h2&gt;&lt;p&gt;actions.armbian.com is Armbian’s public automation dashboard. It shows the real-time status of the workflows that power the project:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Image builds&lt;/li&gt;&lt;li&gt;Infrastructure maintenance&lt;/li&gt;&lt;li&gt;Package and repository updates&lt;/li&gt;&lt;li&gt;Testing and validation&lt;/li&gt;&lt;li&gt;Data generation for tools and download pages&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;All of this is driven by GitHub Actions, running on Armbian’s own infrastructure and cloud runners.&lt;/p&gt;&lt;p&gt;In simple terms:&lt;/p&gt;&lt;blockquote&gt;If Armbian were a factory, actions.armbian.com would be the live dashboard showing which machines are running, which are done, and which need attention.&lt;/blockquote&gt;&lt;h2 id=&quot;why-does-this-matter-to-end-users&quot;&gt;Why does this matter to end users?&lt;/h2&gt;&lt;p&gt;Even if you never write code, this system directly impacts you:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Reliability: Builds are reproducible and verified automatically&lt;/li&gt;&lt;li&gt;Fresh images: New kernels, fixes, and board support are rolled out faster&lt;/li&gt;&lt;li&gt;Stability: Failures are detected early, before broken images reach users&lt;/li&gt;&lt;li&gt;Scale: Armbian can support hundreds of boards without manual work&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Without this automation, Armbian simply couldn’t exist in its current form.&lt;/p&gt;&lt;h2 id=&quot;what-can-you-see-on-the-site&quot;&gt;What can you see on the site?&lt;/h2&gt;&lt;p&gt;When you open actions.armbian.com, you’ll find:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;A list of workflows and jobs&lt;/li&gt;&lt;li&gt;Their current state (success, failed, running)&lt;/li&gt;&lt;li&gt;Execution time and timestamps&lt;/li&gt;&lt;li&gt;Links to detailed logs and JSON outputs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This transparency is rare in open-source OS projects. You are literally watching Armbian being built in real time.&lt;/p&gt;&lt;h2 id=&quot;from-code-to-your-sd-card&quot;&gt;From code to your SD card&lt;/h2&gt;&lt;p&gt;Here’s what typically happens behind the scenes:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;A developer updates code (kernel patches, board definitions, build scripts)&lt;/li&gt;&lt;li&gt;A workflow starts automatically&lt;/li&gt;&lt;li&gt;The system prepares a build environment&lt;/li&gt;&lt;li&gt;Kernels and packages are compiled&lt;/li&gt;&lt;li&gt;OS images are built&lt;/li&gt;&lt;li&gt;Checks and validations are executed&lt;/li&gt;&lt;li&gt;Results appear on actions.armbian.com&lt;/li&gt;&lt;li&gt;If certain processes are green, images are published&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;This process runs thousands of times per month and is fully automated. From another perspective, our servers perform the equivalent of &lt;strong&gt;ten years of continuous compute time in a single calendar year&lt;/strong&gt;.&lt;/p&gt;&lt;h2 id=&quot;why-armbian-needs-this-level-of-automation&quot;&gt;Why Armbian needs this level of automation&lt;/h2&gt;&lt;p&gt;Armbian is not a single OS for one device. It supports:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ARM, RISC-V, and x86&lt;/li&gt;&lt;li&gt;Dozens of SoCs&lt;/li&gt;&lt;li&gt;Hundreds of boards&lt;/li&gt;&lt;li&gt;Multiple kernels (legacy, current, edge)&lt;/li&gt;&lt;li&gt;Multiple Debian and Ubuntu releases&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Manually maintaining this would be impossible. Action script behind is what makes Armbian scalable.&lt;/p&gt;&lt;h2 id=&quot;not-just-builds-%E2%80%93-a-full-ecosystem&quot;&gt;Not just builds – a full ecosystem&lt;/h2&gt;&lt;p&gt;The automation system also handles:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Generation of download metadata&lt;/li&gt;&lt;li&gt;Repository synchronization&lt;/li&gt;&lt;li&gt;Mirror health checks&lt;/li&gt;&lt;li&gt;Infrastructure housekeeping&lt;/li&gt;&lt;li&gt;Statistics and reporting&lt;/li&gt;&lt;li&gt;Future tools like Armbian Imager integration&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;It is the backbone of Armbian’s modern platform approach.&lt;/p&gt;&lt;h2 id=&quot;should-users-look-at-it&quot;&gt;Should users look at it?&lt;/h2&gt;&lt;p&gt;Most users don’t need to.&lt;br /&gt;But when something goes wrong, it becomes incredibly valuable:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Why is my board image missing?&lt;/li&gt;&lt;li&gt;Why did today’s build fail?&lt;/li&gt;&lt;li&gt;Is Armbian currently building new images?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The answers are often already visible there.&lt;/p&gt;&lt;h2 id=&quot;in-short&quot;&gt;In short&lt;/h2&gt;&lt;p&gt;actions.armbian.com is the heart of Armbian’s automation.&lt;/p&gt;&lt;p&gt;It represents:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Transparency&lt;/li&gt;&lt;li&gt;Quality control&lt;/li&gt;&lt;li&gt;Engineering discipline&lt;/li&gt;&lt;li&gt;And the reason Armbian can support such a massive hardware ecosystem&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;You may never interact with it directly, but every Armbian image you use was born there.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-29T15:16:29+00:00</dc:date>
	<dc:creator>Igor Pecovnik</dc:creator>
</item> 
<item rdf:about="https://blog.armbian.com/rss/6a69269d0b8ab5000178c6ee">
	<title>ARMBIAN: Beat the heat</title>
	<link>https://blog.armbian.com/beat-the-heat/</link>
     <content:encoded>&lt;h2 id=&quot;why-thermal-management-is-non-negotiable-for-modern-sbcs&quot;&gt;Why thermal management is non-negotiable for modern SBCs&lt;/h2&gt;&lt;img alt=&quot;Beat the heat&quot; src=&quot;https://blog.armbian.com/content/images/2026/07/armbian_wide-1.png&quot; /&gt;&lt;p&gt;&lt;strong&gt;By Michael Robinson&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;As Western Europe endures severe summer conditions with climate monitors at the Copernicus Climate Change Service reporting unprecedented regional heatwaves and extreme highs stretching across the continent ambient indoor conditions are testing the limits of self-hosted edge hardware.&lt;/p&gt;&lt;p&gt;In unconditioned workspaces, home server racks, and industrial enclosures, rising ambient air temperatures erode the thermal headroom that single-board computers (SBCs) rely on. Modern System-on-Chips (SoCs) such as the Rockchip RK3588, Allwinner, and Broadcom platforms integrate high-performance CPUs, GPUs, and neural processing units on a single piece of silicon. When summer weather drives up ambient baselines, that extreme component density makes uncooled hardware uniquely vulnerable to severe throttling and instability.&lt;/p&gt;&lt;h2 id=&quot;why-ambient-heat-hits-sbcs-harder&quot;&gt;Why ambient heat hits SBCs harder&lt;/h2&gt;&lt;p&gt;Unlike desktop workstations equipped with liquid cooling loops or expansive fan arrays, small form-factor boards operate under strict physical constraints:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;High component density:&lt;/strong&gt; High-performance SoCs integrate the processor cores, graphics processing unit, memory controller, and power management IC onto a compact footprint.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bare-board defaults:&lt;/strong&gt; Most SBCs ship without pre-mounted thermal hardware, depending almost entirely on passive air movement around the bare board.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Eroded thermal headroom:&lt;/strong&gt; Passive cooling relies on heat transferring from the warm chip into cooler surrounding air. As room temperatures climb during a heatwave, that temperature gap shrinks, causing the board&amp;amp;aposs baseline resting temperature to rise right along with the room.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;When workload demands push internal silicon temperatures past safety limits, the hardware triggers automatic protective mechanisms. The system governor scales down operating frequencies and voltages to protect the silicon from permanent damage a process known as &lt;strong&gt;thermal throttling&lt;/strong&gt;.&lt;/p&gt;&lt;h2 id=&quot;thermal-throttling-the-silent-bottleneck&quot;&gt;Thermal throttling: The silent bottleneck&lt;/h2&gt;&lt;p&gt;Thermal throttling rarely triggers explicit desktop warnings or system crashes. Instead, it degrades board behavior behind the scenes:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Degraded throughput:&lt;/strong&gt; Code compilation, container builds, and database queries take significantly longer as clock speeds drop under sustained load.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Latency spikes and stutter:&lt;/strong&gt; Frame drops occur during media playback, desktop rendering, or video stream processing.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;System instability:&lt;/strong&gt; Prolonged high-temperature operation can destabilize power delivery components, causing unexpected kernel panics or filesystem corruption.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;When a self-hosted node or edge gateway exhibits sluggish performance on hot summer afternoons, reduced thermal headroom rather than a software bug is frequently the root cause.&lt;/p&gt;&lt;h2 id=&quot;real-world-impact-high-performance-socs&quot;&gt;Real-world impact: High-performance SoCs&lt;/h2&gt;&lt;p&gt;Under sustained computational workloads, powerful SBCs like the &lt;strong&gt;Orange Pi 5&lt;/strong&gt; (powered by the Rockchip RK3588S SoC) clearly demonstrate the need for thermal dissipation hardware:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Without thermal protection:&lt;/strong&gt; Operating as a bare board under full CPU or NPU load, the SoC quickly reaches its built-in thermal threshold, forcing steep frequency cuts within seconds.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;With passive cooling:&lt;/strong&gt; Mounting a finned aluminum heatsink provides the added surface area needed to dissipate heat into ambient air, helping the board sustain target frequencies through typical day-to-day tasks.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;With active cooling:&lt;/strong&gt; Adding forced airflow via a low-noise fan sweeps hot air clear of the heatsink fins, completely eliminating throttling even during multi-threaded stress testing or local AI workloads.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;choosing-the-right-thermal-strategy&quot;&gt;Choosing the right thermal strategy&lt;/h2&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Passive radiative heatsinks:&lt;/strong&gt; Extruded aluminum or copper blocks rely on natural air convection. They are silent and durable, making them ideal for headless servers provided the board isn&amp;amp;apost trapped in a sealed plastic case that acts as an insulator.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Active cooling (heatsink + fan):&lt;/strong&gt; Combining a heatsink with a dedicated fan uses forced air to clear heat buildup. This approach is recommended for heavy continuous workloads like video encoding, local machine learning models, or continuous software builds.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Full-body aluminum enclosures:&lt;/strong&gt; These designs turn the entire outer chassis into a heat sink, using internal thermal pads to transfer heat directly away from the SoC.&lt;/li&gt;&lt;/ol&gt;&lt;h2 id=&quot;mounting-best-practices&quot;&gt;Mounting best practices&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Always use thermal interface material (TIM):&lt;/strong&gt; Microscopic air gaps between metal and silicon trap heat. Apply a thin thermal pad or an even layer of thermal paste to establish proper conductive contact.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Clean contact surfaces:&lt;/strong&gt; Clear away oils or residue on the SoC die using high-purity isopropyl alcohol before mounting hardware.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Ensure even pressure:&lt;/strong&gt; Verify that the heatsink sits flat and makes uniform contact across the top of the chip.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cool secondary heat sources:&lt;/strong&gt; Under heavy continuous operation, secondary components such as power management ICs (PMICs), system RAM, and NVMe drives also benefit from smaller passive heatsinks.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;&lt;p&gt;As seasonal temperature extremes become more common, proactive thermal management is essential for maintaining server stability and device longevity. Adding proper cooling hardware protects your single-board computers from silent performance bottlenecks and ensures reliable operation through summer heatwaves.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-29T15:13:05+00:00</dc:date>
	<dc:creator>Michael Robinson</dc:creator>
</item> 
<item rdf:about="https://pardus.org.tr/?p=26042">
	<title>Pardus: Pardus 25.2 Sürümü Yayınlandı!</title>
	<link>https://pardus.org.tr/pardus-25-2-surumu-yayimlandi/</link>
     <content:encoded>TÜBİTAK BİLGEM tarafından geliştirilen Pardus’un 25.2 sürümü yayınlandı. Bu sürüm, Pardus 25 ailesinin ikinci ara güncellemesi olarak kullanıcılarla buluşuyor.</content:encoded> 
	<dc:date>2026-07-29T13:35:01+00:00</dc:date>
	<dc:creator>Mohammad Niaei</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=69277">
	<title>GreenboneOS: Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities</title>
	<link>https://www.greenbone.net/en/blog/zimbra-security-patches-july-2026/</link>
     <content:encoded>In July 2026, Zimbra released two security patches for multiple vulnerabilities affecting the Classic Web Client and other components of Zimbra Collaboration Suite (ZCS). Version 10.1.19 addressed a stored cross-site scripting (XSS) flaw that has not been assigned a CVE. Version 10.1.20 fixed a command-injection issue in the SNMP monitoring component, four additional stored XSS […]</content:encoded> 
	<dc:date>2026-07-29T12:31:09+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=69031">
	<title>GreenboneOS: CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More</title>
	<link>https://www.greenbone.net/en/blog/check-point-smartconsole-vulnerability/</link>
     <content:encoded>Check Point has published three new security advisories addressing flaws in Security Management Server (SMS), Multi-Domain Management (MDM), and other Gaia-related components. The highest-priority issue, CVE-2026-16232 (CVSS 9.1), is an actively exploited authentication bypass affecting Check Point SmartConsole in SMS and MDM products. CVE-2026-16232 was published on July 22nd, 2026, and added to CISA’s Known […]</content:encoded> 
	<dc:date>2026-07-28T13:58:10+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.univention.de/?p=87838">
	<title>Univention Corporate Server: UCS 5.3 Alpha Release: A Preview of the Updated Operating Environment for Univention Nubus on Debian 13 “Trixie”</title>
	<link>https://www.univention.com/blog-en/2026/07/ucs-5-3-alpha-release-debian-13-trixie-nubus/</link>
     <content:encoded>&lt;div class=&quot;wpb-content-wrapper&quot;&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;
	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The first&lt;strong&gt; alpha release of UCS 5.3&lt;/strong&gt; is now available, making the next version of the operating environment for Nubus tangible. The focus of this release is on updating the Debian base. At the same time, an important organizational milestone is being prepared: the entry into force of the&lt;strong&gt; separate maintenance cycles for Nubus and UCS&lt;/strong&gt;. This article provides an overview of the current status, the planned next steps, and the path to the stable release.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Debian 13 ``Trixie`` as the New Base&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;With&lt;strong&gt; UCS 5.3, the operating environment for Nubus is being updated to Debian 13 “Trixie”&lt;/strong&gt;, the central technical change of this release. No further major technical adjustments to the operating environment are planned for UCS 5.3 itself. Instead, new features and further developments at the IAM level will be provided, as intended in the course of the new maintenance separation – through independent Nubus updates, regardless of the release rhythm of the operating environment.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Separate Maintenance Cycles Take Effect&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;With the release of UCS 5.3, the announced separation of the maintenance commitments for Nubus and UCS officially takes effect: Instead of a coupled maintenance for the operating environment and IAM functionality, there will in future be two independent cycles. Both continue to apply with the promise of stable, backward-compatible maintenance and optionally long durations (LTS), but they follow the independent release rhythms of UCS and Nubus respectively. This makes updates to the operating environment more predictable and, at the same time, allows new Nubus features to become available faster, without having to wait for major UCS releases. The background and details on this can be found in the article &lt;a href=&quot;https://www.univention.com/blog-en/2026/07/ucs-5-3-separate-maintenance-cycles-nubus-iam-operating-environment/&quot;&gt;“Separate maintenance cycles for Nubus and UCS”.&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Status of the Alpha Release&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The development status of UCS 5.3 is already advanced: All components can be installed and tested. This makes the alpha release well suited for gaining initial experience with Debian 13 as the new base and for reviewing your own extensions or integrations.&lt;/p&gt;
&lt;p&gt;It is important to classify this correctly: This is an alpha release. &lt;strong&gt;It is expressly not intended for productive use, and there will be no update path to a later stable version&lt;/strong&gt;. Installations of the alpha release serve exclusively for testing and evaluation purposes.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Outlook: Further Alpha and Beta Releases&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Over the coming months, further alpha releases and subsequently beta releases of UCS 5.3 are planned, with which the level of maturity will gradually increase. The exact schedule for the stable release will be communicated together with one of the upcoming releases.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Download and Further Information&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;UCS 5.3 Alpha is now available for &lt;a href=&quot;https://updates.software-univention.de/download/ucs-cds/ucs5.3-0-alpha-1/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;download&lt;/a&gt;. For more information about the included changes, please refer to the &lt;a href=&quot;https://help.univention.com/t/ucs-5-3-alpha-available-on-our-testing-mirror/25423&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;help article&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Feedback on the alpha release is expressly welcome – via &lt;a href=&quot;https://help.univention.com/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;help.univention.com&lt;/a&gt; or your respective contact person at Univention.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Der Beitrag &lt;a href=&quot;https://www.univention.com/blog-en/2026/07/ucs-5-3-alpha-release-debian-13-trixie-nubus/&quot;&gt;UCS 5.3 Alpha Release: A Preview of the Updated Operating Environment for Univention Nubus on Debian 13 “Trixie”&lt;/a&gt; erschien zuerst auf &lt;a href=&quot;https://www.univention.com&quot;&gt;Univention&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-28T11:43:44+00:00</dc:date>
	<dc:creator>Ingo Steuwer</dc:creator>
</item> 
<item rdf:about="https://blog.vyos.io/vyos-project-june-july-2026">
	<title>VyOS: VyOS Project June &amp; July 2026 Update</title>
	<link>https://blog.vyos.io/vyos-project-june-july-2026</link>
     <content:encoded>&lt;div class=&quot;hs-featured-image-wrapper&quot;&gt; 
 &lt;a class=&quot;hs-featured-image-link&quot; href=&quot;https://blog.vyos.io/vyos-project-june-july-2026&quot; title=&quot;&quot;&gt; &lt;img alt=&quot;VyOS Project June &amp;amp; July 2026 Update&quot; class=&quot;hs-featured-image&quot; src=&quot;https://blog.vyos.io/hubfs/vyos_mothly_update_june-july2026_blogpost.png&quot; style=&quot;width: auto !important; float: left; margin: 0 15px 15px 0;&quot; /&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;The June and July development update is here. Over the past two months, the VyOS team focused on security and compliance enhancements, community-driven improvements, platform updates, and customer engagement. &lt;/p&gt; 
&lt;p&gt;On the security side, we laid the groundwork for FIPS compliance, added post-quantum key exchange to IPsec, and started publishing SBOM artifacts for full supply-chain transparency. The community also stepped in with some hard-won fixes, from a zone-based firewall bug in VRF configurations to a route-target quirk that was causing needless traffic interruptions on every commit. &lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-28T10:45:00+00:00</dc:date>
	<dc:creator>Daniil Baturin</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39585">
	<title>Deepin: 独立开发者又一力作！微信「分身大师」上线，电脑微信一键多开</title>
	<link>https://www.deepin.org/en/deepin-appclone/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-28T02:07:52+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://blog.armbian.com/rss/6a6802210b8ab5000178c6c2">
	<title>ARMBIAN: Github Highlights</title>
	<link>https://blog.armbian.com/github-highlights-35/</link>
     <content:encoded>&lt;img alt=&quot;Github Highlights&quot; src=&quot;https://blog.armbian.com/content/images/2026/07/july28_fixed.png&quot; /&gt;&lt;p&gt;This week&amp;amp;aposs work centers on &lt;strong&gt;new board enablement and platform maintenance&lt;/strong&gt;, &lt;strong&gt;kernel and U-Boot refresh across Rockchip and Sunxi&lt;/strong&gt;, and &lt;strong&gt;CI/build infrastructure improvements&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;Board support expanded with the addition of &lt;strong&gt;Sovol Zero, SV08, and SV08 Max&lt;/strong&gt; on the H616 platform, alongside mainline and edge enablement for the &lt;strong&gt;Recomputer RK3576 devkit&lt;/strong&gt;. BeagleY-AI features were forward-ported through kernel 7.2, the Mekotronics R58S2 gained rockusb recovery-key support, and the NanoPi R3S received an ethernet alias. Vendor logos and board imagery were also refreshed on the website.&lt;/p&gt;&lt;p&gt;On the kernel and bootloader side, the &lt;strong&gt;cix-p1 edge kernel&lt;/strong&gt; moved to 7.1.5 with refreshed patches, meson64 dropped multiple upstreamed patches, and rk3328 DMC was repaired for newer kernels. U-Boot bumps landed for &lt;strong&gt;Rockpi-4A and EasePi-A2/R2 at v2026.07&lt;/strong&gt;, rk35xx vendor patches were isolated from 2024.03 boards, and Rockchip vendor UFS support was corrected. Several BigTreeTech CB1 and sunxi issues were resolved, including WiFi power sequencing and PWM driver race conditions.&lt;/p&gt;&lt;p&gt;Infrastructure changes introduced a &lt;strong&gt;BTRFS_CHECKSUM build switch&lt;/strong&gt; and a &lt;code&gt;DOCKER_FORCE_PULL&lt;/code&gt; option, parallelized patch rewriting up to nproc, and raised the CI artifact build timeout from 60 to 120 minutes. Runner cleanup logic now installs and selects &lt;strong&gt;docker buildx&lt;/strong&gt; by flavor, stable-track dispatch inputs were trimmed, and the AI README generator was made feedback-aware while forbidden from inventing paths.&lt;/p&gt;&lt;p&gt;#Armbian #EmbeddedLinux #Rockchip #Sunxi #UBoot #CI&lt;/p&gt;&lt;h2 id=&quot;changes&quot;&gt;Changes&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Add a BTRFS_CHECKSUM build switch for choosing the checksum algorithm. by &lt;a href=&quot;https://github.com/dlitz?ref=blog.armbian.com&quot;&gt;@dlitz&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10288?ref=blog.armbian.com&quot;&gt;armbian/build#10288&lt;/a&gt;&lt;/li&gt;&lt;li&gt;add parallel patching switches. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/documentation/pull/945?ref=blog.armbian.com&quot;&gt;armbian/documentation#945&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add Sovol vendor logo and board images (Zero, SV08, SV08 Max). by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/366?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#366&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add support for Sovol Zero, SV08 and SV08 Max (H616). by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10255?ref=blog.armbian.com&quot;&gt;armbian/build#10255&lt;/a&gt;&lt;/li&gt;&lt;li&gt;arduino: fetch qcombin at image-build time, not config time. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10226?ref=blog.armbian.com&quot;&gt;armbian/build#10226&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Build-Switches: document BTRFS_CHECKSUM. by &lt;a href=&quot;https://github.com/dlitz?ref=blog.armbian.com&quot;&gt;@dlitz&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/documentation/pull/946?ref=blog.armbian.com&quot;&gt;armbian/documentation#946&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Build-Switches: document DOCKER_FORCE_PULL. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/documentation/pull/943?ref=blog.armbian.com&quot;&gt;armbian/documentation#943&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: force a fresh Docker image pull on manual builds (default yes). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/30?ref=blog.armbian.com&quot;&gt;armbian/ci#30&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: raise artifact build timeout 60 -&amp;gt; 120 minutes. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/33?ref=blog.armbian.com&quot;&gt;armbian/ci#33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: stable-track cleanup — reuse version + trim dispatch inputs. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/31?ref=blog.armbian.com&quot;&gt;armbian/ci#31&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci: unite &amp;amp; clean the armbian-* build configs (fix apps OCI cache). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/32?ref=blog.armbian.com&quot;&gt;armbian/ci#32&lt;/a&gt;&lt;/li&gt;&lt;li&gt;cix-p1: edge: update patches for 7.1.5, remove version pin. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10297?ref=blog.armbian.com&quot;&gt;armbian/build#10297&lt;/a&gt;&lt;/li&gt;&lt;li&gt;cix-p1: pin edge kernel to v7.1.4 (Panthor patchset breaks on 7.1.5). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10282?ref=blog.armbian.com&quot;&gt;armbian/build#10282&lt;/a&gt;&lt;/li&gt;&lt;li&gt;cli-patch: generalize to-git push (PUSH_TO_GITHUB / PUSH_TO_REPO), for u-boot too. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10193?ref=blog.armbian.com&quot;&gt;armbian/build#10193&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docker: add DOCKER_FORCE_PULL=yes to bypass the base-image pull cache. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10251?ref=blog.armbian.com&quot;&gt;armbian/build#10251&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docker: warn when buildx is missing, and reap leftover per-build images. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10239?ref=blog.armbian.com&quot;&gt;armbian/build#10239&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Fix Darwin Docker Host Arch. by &lt;a href=&quot;https://github.com/Grippy98?ref=blog.armbian.com&quot;&gt;@Grippy98&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10279?ref=blog.armbian.com&quot;&gt;armbian/build#10279&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix(patching): render patch summary tables at the reader&amp;amp;aposs real terminal width. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10262?ref=blog.armbian.com&quot;&gt;armbian/build#10262&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix(sovol): reuse CB1 u-boot board patches on Sovol H616 boards. by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10285?ref=blog.armbian.com&quot;&gt;armbian/build#10285&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix(sunxi): use named i2c-gpio properties on BigTreeTech CB1. by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10287?ref=blog.armbian.com&quot;&gt;armbian/build#10287&lt;/a&gt;&lt;/li&gt;&lt;li&gt;generate_targets: build rootfs-riscv64 on the native ubuntu-24.04-riscv runner. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/363?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#363&lt;/a&gt;&lt;/li&gt;&lt;li&gt;k3-beagle: forward port BeagleY-AI features through 7.2. by &lt;a href=&quot;https://github.com/Grippy98?ref=blog.armbian.com&quot;&gt;@Grippy98&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10266?ref=blog.armbian.com&quot;&gt;armbian/build#10266&lt;/a&gt;&lt;/li&gt;&lt;li&gt;k3: handle optional boot firmware artifacts cleanly. by &lt;a href=&quot;https://github.com/Grippy98?ref=blog.armbian.com&quot;&gt;@Grippy98&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10272?ref=blog.armbian.com&quot;&gt;armbian/build#10272&lt;/a&gt;&lt;/li&gt;&lt;li&gt;k3: restore required edge platform drivers. by &lt;a href=&quot;https://github.com/Grippy98?ref=blog.armbian.com&quot;&gt;@Grippy98&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10273?ref=blog.armbian.com&quot;&gt;armbian/build#10273&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mainline: bump &lt;code&gt;bleedingedge&lt;/code&gt; to 7.2-rc4. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10253?ref=blog.armbian.com&quot;&gt;armbian/build#10253&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mekotronics-r58s2: Make recovery key enter rockusb mode. by &lt;a href=&quot;https://github.com/HeyMeco?ref=blog.armbian.com&quot;&gt;@HeyMeco&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10257?ref=blog.armbian.com&quot;&gt;armbian/build#10257&lt;/a&gt;&lt;/li&gt;&lt;li&gt;meson64-6.18: drop upstreamed pinctrl-meson can_sleep patch. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10277?ref=blog.armbian.com&quot;&gt;armbian/build#10277&lt;/a&gt;&lt;/li&gt;&lt;li&gt;meson64-7.1: drop 2 upstreamed patches + rebase aiu HDMI fix onto v7.1.5. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10278?ref=blog.armbian.com&quot;&gt;armbian/build#10278&lt;/a&gt;&lt;/li&gt;&lt;li&gt;nanopi-r3s: Add &quot;ethernet1&quot; alias for the LAN port. by &lt;a href=&quot;https://github.com/dlitz?ref=blog.armbian.com&quot;&gt;@dlitz&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10275?ref=blog.armbian.com&quot;&gt;armbian/build#10275&lt;/a&gt;&lt;/li&gt;&lt;li&gt;orangepi5: add AP6275P support to non-vendor kernels. by &lt;a href=&quot;https://github.com/efectn?ref=blog.armbian.com&quot;&gt;@efectn&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10289?ref=blog.armbian.com&quot;&gt;armbian/build#10289&lt;/a&gt;&lt;/li&gt;&lt;li&gt;readme-updater: forbid inventing directory/file paths in generated README. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/369?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#369&lt;/a&gt;&lt;/li&gt;&lt;li&gt;readme-updater: make the AI README generator feedback-aware. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/365?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#365&lt;/a&gt;&lt;/li&gt;&lt;li&gt;realtek-rtd1619b: don&amp;amp;apost error on int/pointer conversions (gcc &amp;gt;= 14). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10283?ref=blog.armbian.com&quot;&gt;armbian/build#10283&lt;/a&gt;&lt;/li&gt;&lt;li&gt;recomputer-rk3576-devkit: edge/mainline enablement. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10235?ref=blog.armbian.com&quot;&gt;armbian/build#10235&lt;/a&gt;&lt;/li&gt;&lt;li&gt;recomputer: drop &amp;amp;aposDevkit&amp;amp;apos from BOARD_NAME. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10256?ref=blog.armbian.com&quot;&gt;armbian/build#10256&lt;/a&gt;&lt;/li&gt;&lt;li&gt;release-targets: blacklist sk-am62-lp from stable builds. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/368?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#368&lt;/a&gt;&lt;/li&gt;&lt;li&gt;release-targets: drop deprecated DESKTOP_ENVIRONMENT_CONFIG_NAME / DESKTOP_APPGROUPS_SELECTED. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/362?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#362&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Revert &quot;&lt;code&gt;odroidc2&lt;/code&gt;: u-boot: use minimal patchset for v22.01 u-boot&quot;. by &lt;a href=&quot;https://github.com/ssilnicki-dev?ref=blog.armbian.com&quot;&gt;@ssilnicki-dev&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10265?ref=blog.armbian.com&quot;&gt;armbian/build#10265&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rewrite patches: speed up the process up to nproc. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10163?ref=blog.armbian.com&quot;&gt;armbian/build#10163&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rk35xx u-boot: isolate 2024.10-only vendor patches from the 2024.03 boards. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10281?ref=blog.armbian.com&quot;&gt;armbian/build#10281&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64-6.18: overlays: rewrite README.md. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10295?ref=blog.armbian.com&quot;&gt;armbian/build#10295&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64: add NanoPi NEO3 onboard fan (CON4) pwm-fan overlay. by &lt;a href=&quot;https://github.com/tenox7?ref=blog.armbian.com&quot;&gt;@tenox7&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10291?ref=blog.armbian.com&quot;&gt;armbian/build#10291&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64: fix rk3328 dmc driver on newer kernels. by &lt;a href=&quot;https://github.com/paolosabatino?ref=blog.armbian.com&quot;&gt;@paolosabatino&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10261?ref=blog.armbian.com&quot;&gt;armbian/build#10261&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockpi-4a: bump u-boot to v2026.07 with btrfs root and working SPI. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10260?ref=blog.armbian.com&quot;&gt;armbian/build#10260&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: install docker buildx if not present. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/30?ref=blog.armbian.com&quot;&gt;armbian/actions#30&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: pick buildx package by docker flavor (docker-ce vs docker.io). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/32?ref=blog.armbian.com&quot;&gt;armbian/actions#32&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: simplify buildx install to docker-buildx only (drop jammy). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/31?ref=blog.armbian.com&quot;&gt;armbian/actions#31&lt;/a&gt;&lt;/li&gt;&lt;li&gt;SpacemiT K1: Enable PCIe on OrangePi R2S and add other misc thermal spi and pcie fixups. by &lt;a href=&quot;https://github.com/pyavitz?ref=blog.armbian.com&quot;&gt;@pyavitz&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10269?ref=blog.armbian.com&quot;&gt;armbian/build#10269&lt;/a&gt;&lt;/li&gt;&lt;li&gt;starfive2-vendor: fix img-rogue build on GNU Make 4.4 (trixie). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10286?ref=blog.armbian.com&quot;&gt;armbian/build#10286&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sunxi64: build sunxi pwm driver in to fix ac300 EPHY probe race. by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10242?ref=blog.armbian.com&quot;&gt;armbian/build#10242&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sunxi: cb1: fix wifi pwrseq clock name so the 32k LPO is actually enabled. by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10240?ref=blog.armbian.com&quot;&gt;armbian/build#10240&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sunxi: cb1: stop exposing wifi power lines as gpio LEDs. by &lt;a href=&quot;https://github.com/lexfrei?ref=blog.armbian.com&quot;&gt;@lexfrei&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10241?ref=blog.armbian.com&quot;&gt;armbian/build#10241&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sunxi: drop upstreamed kernel patches failing as &amp;amp;apospreviously applied&amp;amp;apos (6.12/6.18/7.0). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10276?ref=blog.armbian.com&quot;&gt;armbian/build#10276&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sunxi: fix BigTreeTech CB1 patches failing to apply (all kernel branches). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10252?ref=blog.armbian.com&quot;&gt;armbian/build#10252&lt;/a&gt;&lt;/li&gt;&lt;li&gt;u-boot: Rockchip vendor u-boot fix UFS being utterly broken. by &lt;a href=&quot;https://github.com/HeyMeco?ref=blog.armbian.com&quot;&gt;@HeyMeco&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10254?ref=blog.armbian.com&quot;&gt;armbian/build#10254&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uboot: bump EasePi-A2/R2 mainline U-Boot to v2026.07 and add resolute release support. by &lt;a href=&quot;https://github.com/ifroncy01?ref=blog.armbian.com&quot;&gt;@ifroncy01&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10274?ref=blog.armbian.com&quot;&gt;armbian/build#10274&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Update vendor logo. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/364?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#364&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uwe5622: switch to unified driver in dedicated repo. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10113?ref=blog.armbian.com&quot;&gt;armbian/build#10113&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;hr /&gt;</content:encoded> 
	<dc:date>2026-07-28T01:16:05+00:00</dc:date>
	<dc:creator>Michael Robinson</dc:creator>
</item> 
<item rdf:about="https://www.qubes-os.org/news/2026/07/28/xsas-released-on-2026-07-28/">
	<title>Qubes: XSAs released on 2026-07-28</title>
	<link>https://www.qubes-os.org/news/2026/07/28/xsas-released-on-2026-07-28/</link>
     <content:encoded>&lt;p&gt;The &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; has released one or more &lt;a href=&quot;https://xenbits.xen.org/xsa/&quot;&gt;Xen security advisories (XSAs)&lt;/a&gt;.
The security of Qubes OS &lt;strong&gt;is affected&lt;/strong&gt;.&lt;/p&gt;

&lt;h2 id=&quot;xsas-that-do-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do affect&lt;/strong&gt; the security of Qubes OS:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-500.html&quot;&gt;XSA-500&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-505.html&quot;&gt;XSA-505&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-506.html&quot;&gt;XSA-506&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-507.html&quot;&gt;XSA-507&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;xsas-that-do-not-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO NOT affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do not affect&lt;/strong&gt; the security of Qubes OS, and no user action is necessary:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-495.html&quot;&gt;XSA-495&lt;/a&gt;: Denial of service only. Shadow paging is disabled in Qubes OS at build time.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-496.html&quot;&gt;XSA-496&lt;/a&gt;: Denial of service only. Affects only Xen 4.21 and higher; Qubes OS 4.3 uses Xen 4.19.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-497.html&quot;&gt;XSA-497&lt;/a&gt;: Qubes OS does not use pygrub.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-499.html&quot;&gt;XSA-499&lt;/a&gt;: Denial of service only.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-501.html&quot;&gt;XSA-501&lt;/a&gt;: Qubes OS has grant tables v2 disabled.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-502.html&quot;&gt;XSA-502&lt;/a&gt;: Qubes OS does not use vnuma.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-503.html&quot;&gt;XSA-503&lt;/a&gt;: Allows leaking internal information about a qube only to itself, not other qubes.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-504.html&quot;&gt;XSA-504&lt;/a&gt;: Viridian is not enabled in Qubes OS.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-508.html&quot;&gt;XSA-508&lt;/a&gt;: Qubes OS does not use pygrub.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;about-this-announcement&quot;&gt;About this announcement&lt;/h2&gt;

&lt;p&gt;Qubes OS uses the &lt;a href=&quot;https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview&quot;&gt;Xen hypervisor&lt;/a&gt; as part of its &lt;a href=&quot;https://doc.qubes-os.org/en/latest/developer/system/architecture.html&quot;&gt;architecture&lt;/a&gt;. When the &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a &lt;a href=&quot;https://xenproject.org/developers/security-policy/&quot;&gt;Xen security advisory (XSA)&lt;/a&gt;. Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a &lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Qubes security bulletin (QSB)&lt;/a&gt;. (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only &lt;em&gt;positive&lt;/em&gt; confirmation that certain XSAs &lt;em&gt;do&lt;/em&gt; affect the security of Qubes OS. QSBs cannot provide &lt;em&gt;negative&lt;/em&gt; confirmation that other XSAs do &lt;em&gt;not&lt;/em&gt; affect the security of Qubes OS. Therefore, we also maintain an &lt;a href=&quot;https://www.qubes-os.org/security/xsa/&quot;&gt;XSA tracker&lt;/a&gt;, which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-28T00:00:00+00:00</dc:date>
	<dc:creator>Qubes</dc:creator>
</item> 
<item rdf:about="https://www.qubes-os.org/news/2026/07/28/qsb-116/">
	<title>Qubes: QSB-116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)</title>
	<link>https://www.qubes-os.org/news/2026/07/28/qsb-116/</link>
     <content:encoded>&lt;p&gt;We have published &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt&quot;&gt;Qubes Security Bulletin (QSB) 116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)&lt;/a&gt;. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.&lt;/p&gt;

&lt;h2 id=&quot;qubes-security-bulletin-116&quot;&gt;Qubes Security Bulletin 116&lt;/h2&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;
             ---===[ Qubes Security Bulletin 116 ]===---

                              2026-07-28

       Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)

User action
------------

Continue to update normally [1] in order to receive the security updates
described in the &quot;Patching&quot; section below. No other user action is
required in response to this QSB.

Summary
--------

On 2026-07-28, the Xen Project published the security advisories below.

XSA-500 [3] &quot;grant-table: type confusion in grant-copy&quot;:

| When grant-copy operations are processed, the respective grant may or
| may not already be in use by another operation (a mapping or another
| copy). For all copy operations the referenced guest frame is looked
| up. When another operation is already active for the grant (the grant
| is &quot;pinned&quot;), what is being supplied back to actually carry out
| permission checks and copy operation may not be consistent: The
| permission check may be carried out on a page different from the one
| involved in the copy.


XSA-505 [4] &quot;evtchn: Race between FIFO expand and reset&quot;:

| The EVTCHNOP_expand_array hypercall checks for whether FIFO event
| channels are enabled, but without holding the correct lock. It can
| race with EVTCHNOP_reset, resulting in deferencing a NULL pointer.


XSA-506 [5] &quot;correct buffer checks for DM_OP hypercalls&quot;:

| Parts of the DM_OP handling code assumes the caller has provided the
| required number of buffers for the given operation without any
| checking being done. As a result, certain operations might access
| stack rubble as structures are possibly uninitialized.

XSA-507 [6] &quot;PoD: Don&#39;t try to reclaim special pages&quot;:

| A guest started with Populated on Demand enabled (PoD) can attempt to
| reclaim pages which aren&#39;t regular guest RAM. This can cause
| corruption of memory management state in Xen.

Impact
-------

XSA-500 and XSA-507: A malicious qube may be able to compromise
Qubes OS.

XSA-505: A malicious PV qube [7] may be able to compromise Qubes OS. The
same impact applies to stubdomains for HVM qubes [8], but in this case
an attacker would first have to discover and exploit an independent
vulnerability (in QEMU) in order to gain access to the stubdomain.

XSA-506: The stubdomain for an HVM qube may be able to leak data from
other qubes in the system. In order to exploit this vulnerability, an
attacker would first have to discover and exploit an independent
vulnerability (in QEMU) in order to gain access to the stubdomain.

Affected systems
-----------------

XSA-500: All systems are affected.

XSA-505: Systems with either PV qubes or stubdomains for HVM qubes (or
both) are affected, but the vulnerability is easier to exploit on
systems with PV qubes. In the default Qubes OS configuration, there are
no PV qubes, but sys-net and sys-usb are HVM qubes that have
stubdomains. This means that the vulnerability is more difficult to
exploit in the default Qubes OS configuration, but if a user has
manually created PV qubes in a particular system, the vulnerability will
be easier to exploit on that system.

XSA-506: Systems with untrusted HVM qubes are affected. In the default
configuration of Qubes OS, sys-net and sys-usb are HVM qubes and are
considered to be untrusted.

XSA-507: Systems are affected if they have qubes that are included in
memory balancing but that don&#39;t advertise memory hotplug support. This
includes malicious HVM qubes with memory balancing enabled, as well as
templates and standalones that use in-qube kernels and that have memory
balancing enabled. The default Qubes OS configuration is not affected,
nor are commonly-used HVM qubes like Windows, since they don&#39;t have
memory balancing enabled.

Patching
---------

The following packages contain security updates that address the
vulnerabilities described in this bulletin:

  For Qubes 4.3, in dom0:
  - Xen packages, version 4.19.5-2

These packages will migrate from the security-testing repository to the
current (stable) repository over the next two weeks after being tested
by the community. [2] Once available, the packages should be installed
via the Qubes Update tool or its command-line equivalents. [1]

Dom0 must be restarted afterward in order for the updates to take
effect.

If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new Xen
binaries.

Credits
--------

See the original Xen Security Advisories. [3][4][5][6]

References
-----------

[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://xenbits.xen.org/xsa/advisory-500.html
[4] https://xenbits.xen.org/xsa/advisory-505.html
[5] https://xenbits.xen.org/xsa/advisory-506.html
[6] https://xenbits.xen.org/xsa/advisory-507.html
[7] A PV qube is a qube that is running with virt_mode set to &quot;pv.&quot;
[8] For each qube that is running with virt_mode set to &quot;hvm,&quot; there&#39;s a
    small Xen-internal helper VM running alongside it, in which QEMU is
    executed to provide device emulation for that qube. This helper VM
    runs in PV mode and is called a &quot;stubdomain.&quot;

--
The Qubes Security Team
https://www.qubes-os.org/security/

&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt&quot;&gt;qsb-116-2026.txt&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;marek-marczykowski-góreckis-pgp-signature&quot;&gt;&lt;a href=&quot;https://www.qubes-os.org/team/#marek-marczykowski-górecki&quot;&gt;Marek Marczykowski-Górecki&lt;/a&gt;’s PGP signature&lt;/h2&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmpoeyMACgkQ1lWk8hgw
4GqUjw//brO4x3oOygOpewPqcjgYqohh4qPu5Dpm6JBvtxiIZQWEv9UZg0RqfMVc
omoalUCQhoTPu8QYnXu3HKo87LGcrUKKf2KeRx4CyT8LsZCQufA25uWD3Sr6eVsA
38Q/Znq3VyUpa5tMQm28JIIA9m2PMAMaXu5ElZVAw5kvcRncwRh8WDOrkVOO97ll
gSfBo3SJ0OfSUDcQvGa8f5+4Jx/SPoJn5zLo3Ott4tT7Tz2NAfE2Xlxl7karasY/
vCY+Lo8ACN+0ShELslGKYZnNdwLuwkz3lVN+FqDbLrHauBUjDLH7+yTXJvO9ZoXq
3LTpHopzv8oSJJyhq0YeO4XlKt+USn2HbIMqhJ9ON8aHHVE3/YhVJume4RuxSlHx
WAStN0bYH/NqSywYB3wWmGEho9wRw8bxLrOBIuZO3V63HpMJnCL412F7RFA2/9iS
muq3Iix9YpqfI/Q1Q18JSnYYLlWaphMtc/OJki5FAzp1B5DtQtPcQtg/vcy9tsrX
P9zrK4j3Dj/vPzZd6DwDmTBPxuiLQX79TQojl7NClVatkULfdHQGDKogfPmsJng9
IpKMBkMZ85QVv+DG/XFtXpynBdeg/6eTeWiexC7WF3HgILkhy2RadQz0eHsEwCmp
fIeVYQ2Es3eVH7aNaPHwaAcklNP+7yppgw5O81PGOlbD3Z9a15Y=
=vPOZ
-----END PGP SIGNATURE-----
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt.sig.marmarek&quot;&gt;qsb-116-2026.txt.sig.marmarek&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;simon-gaiser-aka-hw42s-pgp-signature&quot;&gt;&lt;a href=&quot;https://www.qubes-os.org/team/#simon-gaiser-aka-hw42&quot;&gt;Simon Gaiser (aka HW42)&lt;/a&gt;’s PGP signature&lt;/h2&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmpoh00ACgkQSsGN4REu
FJCSVhAApAdVntLjACF7SJ9h7SF4M1IiDKKUQRnUhwEa06d/qDjFg/aVlsL6LghW
+cKpPdjSDWwGPhAsJhbxTeiSSAkX300qJuqX3/K0h6iw7jaQkqb6kmwaAhK7J8Ym
9F5LvcP8Vvx3G0Gi4YogNzrwA+AMlfCgKLgp7MsHKumE1TY0pp5dI6DMqz2/EasV
ODrppsfXkMMmES5aR8C6Pxe51pfBbXVqVmffjYxaz/C9VvcfGbHja8OdnOuNeqmo
yzR2pP6BGdIl2KGfq1GzuuYWtitIcrG8aEnYfcmhiHbHkTIObNwHo7MOwBT2Q9H4
ALJfuBfC1ChBvmmzRIPgOzPbiz0MLIWcjFvKRmXW8azTTQOyRQQbG5lDGeu+aJm0
ZRdyXPQh2294MmmL3r+xtyFJTFw5WABdxjZa10nlB5B5JQ8FrV7koNc4quXhCS4U
ceAwpvCuRKTX1Lg+NDaPFtxAmYX98QkLT09V34vyqksOcMR+DY7stHol8T+hYIMM
8DXZDBdndUMkU/DU5xfj4Z/wtgkB66eLKBypxqibiPx33vkBZOIAYtNYK7zFnrTk
HnrHAGpm0sLlNdLzNA4XQ7yMTdDwzxW6GeYacYWxDT3t9Qc9vroGVju3CExQtljs
4znS5FAHrlPSv4xi7aWiypVwB/MsMbrdNcd0/g9px6RbszpNGpA=
=BjeB
-----END PGP SIGNATURE-----
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt.sig.simon&quot;&gt;qsb-116-2026.txt.sig.simon&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;what-is-the-purpose-of-this-announcement&quot;&gt;What is the purpose of this announcement?&lt;/h2&gt;

&lt;p&gt;The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.&lt;/p&gt;

&lt;h2 id=&quot;what-is-a-qubes-security-bulletin-qsb&quot;&gt;What is a Qubes security bulletin (QSB)?&lt;/h2&gt;

&lt;p&gt;A &lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Qubes security bulletin (QSB)&lt;/a&gt; is a security announcement issued by the &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team&quot;&gt;Qubes security team&lt;/a&gt;. A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them.&lt;/p&gt;

&lt;h2 id=&quot;why-should-i-care-about-qsbs&quot;&gt;Why should I care about QSBs?&lt;/h2&gt;

&lt;p&gt;QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html&quot;&gt;updating normally&lt;/a&gt;. However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.&lt;/p&gt;

&lt;h2 id=&quot;what-are-the-pgp-signatures-that-accompany-qsbs&quot;&gt;What are the PGP signatures that accompany QSBs?&lt;/h2&gt;

&lt;p&gt;A &lt;a href=&quot;https://en.wikipedia.org/wiki/Pretty_Good_Privacy&quot;&gt;PGP&lt;/a&gt; signature is a cryptographic &lt;a href=&quot;https://en.wikipedia.org/wiki/Digital_signature&quot;&gt;digital signature&lt;/a&gt; made in accordance with the &lt;a href=&quot;https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP&quot;&gt;OpenPGP&lt;/a&gt; standard. PGP signatures can be cryptographically verified with programs like &lt;a href=&quot;https://gnupg.org/&quot;&gt;GNU Privacy Guard (GPG)&lt;/a&gt;. The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.&lt;/p&gt;

&lt;h2 id=&quot;why-should-i-care-whether-a-qsb-is-authentic&quot;&gt;Why should I care whether a QSB is authentic?&lt;/h2&gt;

&lt;p&gt;A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.&lt;/p&gt;

&lt;h2 id=&quot;how-do-i-verify-the-pgp-signatures-on-a-qsb&quot;&gt;How do I verify the PGP signatures on a QSB?&lt;/h2&gt;

&lt;p&gt;The following command-line instructions assume a Linux system with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;git&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg&lt;/code&gt; installed. (For Windows and Mac options, see &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software&quot;&gt;OpenPGP software&lt;/a&gt;.)&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;
    &lt;p&gt;Obtain the Qubes Master Signing Key (QMSK), e.g.:&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--fetch-keys&lt;/span&gt; https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
&lt;span class=&quot;go&quot;&gt;gpg: directory &#39;/home/user/.gnupg&#39; created
gpg: keybox &#39;/home/user/.gnupg/pubring.kbx&#39; created
gpg: requesting key from &#39;https://keys.qubes-os.org/keys/qubes-master-signing-key.asc&#39;
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: key DDFA1A3E36879494: public key &quot;Qubes Master Signing Key&quot; imported
gpg: Total number processed: 1
gpg:               imported: 1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;

    &lt;p&gt;(For more ways to obtain the QMSK, see &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key&quot;&gt;How to import and authenticate the Qubes Master Signing Key&lt;/a&gt;.)&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;View the fingerprint of the PGP key you just imported. (Note: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg&amp;gt;&lt;/code&gt; indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--edit-key&lt;/span&gt; 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
&lt;span class=&quot;gp&quot;&gt;gpg (GnuPG) 2.2.27;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;Copyright &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;C&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; 2021 Free Software Foundation, Inc.
&lt;span class=&quot;go&quot;&gt;This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
   
   
pub  rsa4096/DDFA1A3E36879494
     created: 2010-04-01  expires: never       usage: SC
     trust: unknown       validity: unknown
[ unknown] (1). Qubes Master Signing Key
   
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;gpg&amp;gt;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;fpr
&lt;span class=&quot;go&quot;&gt;pub   rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
 Primary key fingerprint: 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt; At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you &lt;em&gt;must&lt;/em&gt; authenticate the QMSK out-of-band. &lt;strong&gt;Do not skip this step!&lt;/strong&gt; The standard method is to obtain the QMSK fingerprint from &lt;em&gt;multiple independent sources in several different ways&lt;/em&gt; and check to see whether they match the key you just imported. For more information, see &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key&quot;&gt;How to import and authenticate the Qubes Master Signing Key&lt;/a&gt;.&lt;/p&gt;

    &lt;p&gt;&lt;strong&gt;Tip:&lt;/strong&gt; After you have authenticated the QMSK out-of-band to your satisfaction, record the QMSK fingerprint in a safe place (or several) so that you don’t have to repeat this step in the future.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Once you are satisfied that you have the genuine QMSK, set its trust level to 5 (“ultimate”), then quit GnuPG with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;q&lt;/code&gt;.&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;gpg&amp;gt;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;trust
&lt;span class=&quot;go&quot;&gt;pub  rsa4096/DDFA1A3E36879494
     created: 2010-04-01  expires: never       usage: SC
     trust: unknown       validity: unknown
[ unknown] (1). Qubes Master Signing Key
   
Please decide how far you trust this user to correctly verify other users&#39; keys
(by looking at passports, checking fingerprints from different sources, etc.)
   
  1 = I don&#39;t know or won&#39;t say
  2 = I do NOT trust
  3 = I trust marginally
  4 = I trust fully
  5 = I trust ultimately
  m = back to the main menu
   
Your decision? 5
Do you really want to set this key to ultimate trust? (y/N) y
   
pub  rsa4096/DDFA1A3E36879494
     created: 2010-04-01  expires: never       usage: SC
     trust: ultimate      validity: unknown
[ unknown] (1). Qubes Master Signing Key
Please note that the shown key validity is not necessarily correct
unless you restart the program.
   
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;gpg&amp;gt;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;q
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Use Git to clone the qubes-secpack repo.&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;git clone https://github.com/QubesOS/qubes-secpack.git
&lt;span class=&quot;go&quot;&gt;Cloning into &#39;qubes-secpack&#39;...
remote: Enumerating objects: 4065, done.
remote: Counting objects: 100% (1474/1474), done.
remote: Compressing objects: 100% (742/742), done.
remote: Total 4065 (delta 743), reused 1413 (delta 731), pack-reused 2591
Receiving objects: 100% (4065/4065), 1.64 MiB | 2.53 MiB/s, done.
Resolving deltas: 100% (1910/1910), done.
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Import the included PGP keys. (See our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/security-pack.html#pgp-key-policies&quot;&gt;PGP key policies&lt;/a&gt; for important information about these keys.)&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--import&lt;/span&gt; qubes-secpack/keys/&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;/&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;
&lt;span class=&quot;go&quot;&gt;gpg: key 063938BA42CFA724: public key &quot;Marek Marczykowski-Górecki (Qubes OS signing key)&quot; imported
gpg: qubes-secpack/keys/core-devs/retired: read error: Is a directory
gpg: no valid OpenPGP data found.
gpg: key 8C05216CE09C093C: 1 signature not checked due to a missing key
gpg: key 8C05216CE09C093C: public key &quot;HW42 (Qubes Signing Key)&quot; imported
gpg: key DA0434BC706E1FCF: public key &quot;Simon Gaiser (Qubes OS signing key)&quot; imported
gpg: key 8CE137352A019A17: 2 signatures not checked due to missing keys
gpg: key 8CE137352A019A17: public key &quot;Andrew David Wong (Qubes Documentation Signing Key)&quot; imported
gpg: key AAA743B42FBC07A9: public key &quot;Brennan Novak (Qubes Website &amp;amp; Documentation Signing)&quot; imported
gpg: key B6A0BB95CA74A5C3: public key &quot;Joanna Rutkowska (Qubes Documentation Signing Key)&quot; imported
gpg: key F32894BE9684938A: public key &quot;Marek Marczykowski-Górecki (Qubes Documentation Signing Key)&quot; imported
gpg: key 6E7A27B909DAFB92: public key &quot;Hakisho Nukama (Qubes Documentation Signing Key)&quot; imported
gpg: key 485C7504F27D0A72: 1 signature not checked due to a missing key
gpg: key 485C7504F27D0A72: public key &quot;Sven Semmler (Qubes Documentation Signing Key)&quot; imported
gpg: key BB52274595B71262: public key &quot;unman (Qubes Documentation Signing Key)&quot; imported
gpg: key DC2F3678D272F2A8: 1 signature not checked due to a missing key
gpg: key DC2F3678D272F2A8: public key &quot;Wojtek Porczyk (Qubes OS documentation signing key)&quot; imported
gpg: key FD64F4F9E9720C4D: 1 signature not checked due to a missing key
gpg: key FD64F4F9E9720C4D: public key &quot;Zrubi (Qubes Documentation Signing Key)&quot; imported
gpg: key DDFA1A3E36879494: &quot;Qubes Master Signing Key&quot; not changed
gpg: key 1848792F9E2795E9: public key &quot;Qubes OS Release 4 Signing Key&quot; imported
gpg: qubes-secpack/keys/release-keys/retired: read error: Is a directory
gpg: no valid OpenPGP data found.
gpg: key D655A4F21830E06A: public key &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; imported
gpg: key ACC2602F3F48CB21: public key &quot;Qubes OS Security Team&quot; imported
gpg: qubes-secpack/keys/security-team/retired: read error: Is a directory
gpg: no valid OpenPGP data found.
gpg: key 4AC18DE1112E1490: public key &quot;Simon Gaiser (Qubes Security Pack signing key)&quot; imported
gpg: Total number processed: 17
gpg:               imported: 16
gpg:              unchanged: 1
gpg: marginals needed: 3  completes needed: 1  trust model: pgp
gpg: depth: 0  valid:   1  signed:   6  trust: 0-, 0q, 0n, 0m, 0f, 1u
gpg: depth: 1  valid:   6  signed:   0  trust: 6-, 0q, 0n, 0m, 0f, 0u
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Verify signed Git tags.&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;qubes-secpack/
&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;git tag &lt;span class=&quot;nt&quot;&gt;-v&lt;/span&gt; &lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;git describe&lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;
&lt;span class=&quot;go&quot;&gt;object 266e14a6fae57c9a91362c9ac784d3a891f4d351
type commit
tag marmarek_sec_266e14a6
tagger Marek Marczykowski-Górecki 1677757924 +0100
   
Tag for commit 266e14a6fae57c9a91362c9ac784d3a891f4d351
gpg: Signature made Thu 02 Mar 2023 03:52:04 AM PST
gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
gpg: Good signature from &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; [full]
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;

    &lt;p&gt;The exact output will differ, but the final line should always start with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg: Good signature from...&lt;/code&gt; followed by an appropriate key. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[full]&lt;/code&gt; indicates full trust, which this key inherits in virtue of being validly signed by the QMSK.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Verify PGP signatures, e.g.:&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;QSBs/
&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; qsb-087-2022.txt.sig.marmarek qsb-087-2022.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Wed 23 Nov 2022 04:05:51 AM PST
gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
gpg: Good signature from &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; [full]
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; qsb-087-2022.txt.sig.simon qsb-087-2022.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Wed 23 Nov 2022 03:50:42 AM PST
gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
gpg: Good signature from &quot;Simon Gaiser (Qubes Security Pack signing key)&quot; [full]
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd&lt;/span&gt; ../canaries/
&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; canary-034-2023.txt.sig.marmarek canary-034-2023.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Thu 02 Mar 2023 03:51:48 AM PST
gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
gpg: Good signature from &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; [full]
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; canary-034-2023.txt.sig.simon canary-034-2023.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Thu 02 Mar 2023 01:47:52 AM PST
gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
gpg: Good signature from &quot;Simon Gaiser (Qubes Security Pack signing key)&quot; [full]
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;

    &lt;p&gt;Again, the exact output will differ, but the final line of output from each &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg --verify&lt;/code&gt; command should always start with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg: Good signature from...&lt;/code&gt; followed by an appropriate key.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For this announcement (QSB-116), the commands are:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;$ gpg --verify qsb-116-2026.txt.sig.marmarek qsb-116-2026.txt
$ gpg --verify qsb-116-2026.txt.sig.simon qsb-116-2026.txt
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You can also verify the signatures directly from this announcement in addition to or instead of verifying the files from the qubes-secpack. Simply copy and paste the QSB-116 text into a plain text file and do the same for both signature files. Then, perform the same authentication steps as listed above, substituting the filenames above with the names of the files you just created.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-28T00:00:00+00:00</dc:date>
	<dc:creator>Qubes</dc:creator>
</item> 
<item rdf:about="https://jonathancarter.org/?p=12034">
	<title>AIMS Desktop developers: DebConf26 – Santa Fe, Argentina</title>
	<link>https://jonathancarter.org/2026/07/27/debconf26-santa-fe-argentina/</link>
     <content:encoded>&lt;p class=&quot;wp-block-paragraph&quot;&gt;TL;DR: What a great DebConf! I managed to recharge my Debian batteries, and my talks / BoF sessions all went fine. Already looking forward to DebConf in Japan next year!&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;DebCamp&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The evening before DebCamp started, we had a nice bbq (we taught some locals to call it a “braai” at an organiser’s house and went for a walk around the river as the sun set. It was a very peaceful lead-in to DebCamp.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12057&quot; height=&quot;450&quot; src=&quot;https://jonathancarter.org/files/images/bbq.jpg&quot; width=&quot;800&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12042&quot; height=&quot;452&quot; src=&quot;https://jonathancarter.org/files/images/dc26_blog_river.jpg&quot; width=&quot;800&quot; /&gt;&lt;/figure&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;I set up and sent out the call for Forky desktop artwork:
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://lists.debian.org/msgid-search/910906f3-7ce4-4884-a49f-4b4a5975471b@debian.org&quot;&gt;https://lists.debian.org/msgid-search/910906f3-7ce4-4884-a49f-4b4a5975471b@debian.org&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;Had many nice discussions about various Debian topics with all the Debian people around. It’s really fun being around people who are natural problem solvers who care deeply about both technical and social issues. At one point Jonas told me “Holy shit, these people are motivated!” and I appreciate that so much too!&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12064&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/ltswine-1024x576.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Debian LTS wine&lt;/em&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Most of my DebCamp was dedicated to preparing for my demo and main talk that followed at DebConf.&lt;/li&gt;



&lt;li&gt;Sadly, we had no loopy this year, I just didn’t have the time, and the people who stepped up to help last year were either overwhelmed with other issues or couldn’t make it. I’ll try to make it happen again for next year by kicking it off long before DC27.&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12059&quot; height=&quot;640&quot; src=&quot;https://jonathancarter.org/files/images/santafe-1024x640.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;View of Santa Fe city from hotel&lt;/em&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;DebConf&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Talk – Is it even possible to build a truly universal system installer?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In &lt;a href=&quot;https://debconf26.debconf.org/talks/6-is-it-even-possible-to-build-a-truly-universal-system-installer/&quot;&gt;this talk&lt;/a&gt; I do a very quick comparison of system installers based on my experience with them. It’s hard to directly compare all of them, since there are so many, and each have their own niche that they attempt to satisfy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I also introduce &lt;a href=&quot;https://salsa.debian.org/yasi-team/yasi-daemon&quot;&gt;Yasi&lt;/a&gt; – my attempt to answer the question of whether we could build a universal installer, which can also better cover advanced installations, automated installations and niche setups.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s very early days for the project, and I didn’t quite feel ready to share the code with the world, but it was nice that I did a quick demo where I could install a Debian system… and the resulting system actually booted up. *phew*.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is also going to be my main focus for the mid-term future. I aim to have all the basic partitioning options working by the time Debian 14 (Forky) is released, and by the time Debian 15 is released, I have a long list of features that I aim to have working. So, my timeline for having something that’s generally useful is around a year from now, and in around 3 years it should be a fully fledged installer that should cover a very large amount of Debian use cases and architectures. &lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12048&quot; height=&quot;646&quot; src=&quot;https://jonathancarter.org/files/images/image-30-1024x646.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Day Trip&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For the day trip, we did a tour across Santa Fe, visited &lt;a href=&quot;https://www.museodelaconstitucion.org/&quot;&gt;Constitución de la Nación Argentina&lt;/a&gt;, had lunch where we tried various dishes based on local fish from the river, and then went on a boat ride on the river.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12078&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/churchbells.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12090&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/image-32-1024x574.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12092&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/image-33-1024x574.png&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;BoF Sessions:&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Funding in Free Software Projects:&lt;/strong&gt; I initially registered this BoF because I’m increasingly concerned about how upstreams are asking for donations in their software. I increased the scope to talk about funding in free software in general. It followed Marga’s talk about funding, which focussed more about how developers are funded in general. We didn’t dive very deep into this, but we certainly need some further discussion (and action) on this within Debian.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Debian Social Team:&lt;/strong&gt; My most important issue for this team is a carry-over from last year, I want to set up &lt;a href=&quot;https://pgbarman.org/&quot;&gt;barman&lt;/a&gt; (packaged in Debian) for live postgres syncing for our larger databases. For the smaller DBs, doing a daily dump is quite cheap. But for Matrix, it’s very expensive in terms if i/o and CPU, so it would be ideal to do less regular complete dumps and use live replication for the first line of redundancy instead.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Images Team: &lt;/strong&gt;I wasn’t initially planning to say much during this session, I have some ideas to reduce both size and count of images, without losing any benefits, but I don’t have any work to show for that yet. I ended up talking a lot more than I anticipated, the topics covered were quite good and representative of the current state of Debian images built. I don’t have time to create a full summary, so I suggest checking the etherpad / video recording if you’re interested.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12079&quot; height=&quot;576&quot; src=&quot;https://jonathancarter.org/files/images/cwstablewine.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Some more wine variety during the conference dinner&lt;/em&gt;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12066&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/busyhacklap-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Debianites in the main hacklab&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Rosario&lt;/h3&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12076&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/rosario-1-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;I’m spending two days in Rosario before I head home. Exploring a bit, catching up with sleep, finishing this blog post, signing keys and exploring some ideas I made note of during DebConf.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Thank you to the DebConf26 Team!&lt;/h3&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;wp-image-12073&quot; height=&quot;574&quot; src=&quot;https://jonathancarter.org/files/images/dc-team-1024x574.jpg&quot; width=&quot;1024&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It was a little surreal not being part of any DebConf team for the first time ever, I’ve just been too focussed on getting Yasi ready for my talk (no regrets!). I hope to be more involved again next year, in the meantime, I’m very grateful to everyone who has made this happen, you did a stellar job! I hope to see many of you again next year in Japan!&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-27T20:12:18+00:00</dc:date>
	<dc:creator>jonathan</dc:creator>
</item> 
<item rdf:about="https://www.skudonet.com/?p=77949">
	<title>ZEVENET: How to Load Balance Moodle for High Availability: Architecture, Sessions, and Security</title>
	<link>https://www.skudonet.com/blog/how-to-load-balance-moodle/</link>
     <content:encoded>&lt;p class=&quot;PDq2pG_selectionAnchorContainer&quot;&gt;A Moodle deployment that performs flawlessly with 20,000 users can easily collapse under the load of 100,000 users on exam day or when course registration opens. The issue isn’t Moodle itself. It’s that, in a single-server deployment, everything (the web application, user sessions, database, and uploaded files) runs on the same machine. Once that server runs out of CPU or memory, or simply goes offline for maintenance, there’s nowhere else for the workload to go.&lt;/p&gt;
&lt;p&gt;The obvious answer is to add a load balancer. The correct answer, however, is more nuanced. A load balancer distributes incoming connections, but it doesn’t automatically turn Moodle into a highly available platform. Unless every server shares the same sessions, database, and file storage, all you’ve really done is spread the problem across multiple machines.&lt;/p&gt;
&lt;h2 class=&quot;PDq2pG_selectionAnchorContainer&quot;&gt;What Is Load Balancing in Moodle?&lt;/h2&gt;
&lt;p&gt;Load balancing in Moodle is the process of distributing user requests across multiple Moodle web servers through a single virtual IP address. The load balancer continuously checks the health of each node and sends traffic only to servers that are available, ensuring that a failed or overloaded server doesn’t interrupt access for students and teachers.&lt;/p&gt;
&lt;h2&gt;Why Moodle Needs Load Balancing&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Traffic spikes:&lt;/strong&gt; Exams with a common start time, enrollment periods, and grade publication can generate sudden bursts of concurrent traffic.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Zero-downtime maintenance:&lt;/strong&gt; Updating or patching a server shouldn’t require taking the entire learning platform offline.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Growing numbers of concurrent users:&lt;/strong&gt; A single server can only handle a finite number of simultaneous connections.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;TLS encryption:&lt;/strong&gt; Managing certificates and TLS decryption on every web server adds unnecessary overhead that can be centralized at the load balancer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;The Real Architecture Behind a Highly Available Moodle Deployment&lt;/h2&gt;
&lt;p&gt;Moodle’s own documentation explicitly states that, in a multi-server deployment, all web servers must share the same cache, database, and file storage. If any of these components is missing, high availability exists only in theory.&lt;/p&gt;
&lt;h3&gt;The Load Balancer (ADC)&lt;/h3&gt;
&lt;p&gt;The Application Delivery Controller (ADC) accepts incoming connections through a virtual IP address, performs health checks on every Moodle node, and decides which server should handle each request. It is also the natural place to terminate TLS connections and enforce security policies before traffic reaches the Moodle application.&lt;/p&gt;
&lt;h3&gt;Multiple Moodle Web Servers&lt;/h3&gt;
&lt;p&gt;Every node must run the same Moodle version, include the same plugins, and use an identical configuration. If one server contains plugins or configuration that another does not, user experience becomes unpredictable depending on which node handles the request.&lt;/p&gt;
&lt;h3&gt;Shared Database&lt;/h3&gt;
&lt;p&gt;All Moodle web servers must connect to the same database, or to a clustered database infrastructure with failover capabilities. While the load balancer eliminates the single point of failure at the web layer, it does not remove the database as a potential single point of failure.&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;Shared &lt;em&gt;moodledata&lt;/em&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;The &lt;strong&gt;moodledata&lt;/strong&gt; directory stores uploaded files, backups, and generated content. It must reside on shared storage that is accessible from every web server. Otherwise, a file uploaded through one node won’t exist when the user’s next request is served by another node.&lt;/p&gt;
&lt;h3&gt;Shared Sessions and Cache&lt;/h3&gt;
&lt;p&gt;This is where many deployments fail.&lt;/p&gt;
&lt;p&gt;Moodle supports Redis and Memcached as shared session stores across multiple nodes. Without shared sessions, users may appear to be logged out simply because their next request is handled by a different server. Redis Cluster also allows this layer to scale horizontally while providing its own built-in failover capabilities.&lt;/p&gt;
&lt;h2&gt;Why the Load Balancer Isn’t the Whole Solution&lt;/h2&gt;
&lt;p&gt;Removing the single point of failure from the web layer is only the first step. If the database, Redis, or &lt;strong&gt;moodledata&lt;/strong&gt; still relies on a single server, that server remains the weak link capable of bringing down the entire platform.&lt;/p&gt;
&lt;h2&gt;How to Implement Load Balancing in Moodle&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Prepare identical Moodle nodes using the same version, plugins, and configuration.&lt;/li&gt;
&lt;li&gt;Configure a shared database and shared &lt;strong&gt;moodledata&lt;/strong&gt; storage.&lt;/li&gt;
&lt;li&gt;Create an HTTPS virtual service using the public IP address and port that users will access.&lt;/li&gt;
&lt;li&gt;Add the Moodle servers as backend nodes for the virtual service.&lt;/li&gt;
&lt;li&gt;Configure application-level health checks rather than relying solely on open-port checks.&lt;/li&gt;
&lt;li&gt;Choose the appropriate load-balancing algorithm:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Round Robin&lt;/strong&gt; for identical servers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Least Connections&lt;/strong&gt; when request duration varies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Weighted&lt;/strong&gt; when backend servers have different capacities.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Enable session persistence (sticky sessions) to reduce contention in the shared session store and keep each user’s requests on the same node.&lt;/li&gt;
&lt;li&gt;Configure SSL offloading. When TLS is terminated at the load balancer, Moodle requires &lt;code&gt;$CFG-&amp;gt;sslproxy&lt;/code&gt; If the internal and external URLs differ, &lt;code&gt;$CFG-&amp;gt;reverseproxy&lt;/code&gt; must also be configured. Every node should use the same public URL in &lt;code&gt;$CFG-&amp;gt;wwwroot&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Preserve the client’s real IP address using &lt;strong&gt;X-Forwarded-For&lt;/strong&gt;, while maintaining a well-defined list of trusted proxies.&lt;/li&gt;
&lt;li&gt;Make the load balancer itself highly available by deploying it as a two-node cluster with a shared virtual IP and synchronized configuration. Otherwise, the load balancer simply becomes the new single point of failure.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;What Load Balancing Alone Doesn’t Solve&lt;/h2&gt;
&lt;p&gt;Distributing traffic across multiple servers doesn’t protect those servers from attacks. Adding that protection separately also introduces costs that are often underestimated.&lt;/p&gt;
&lt;p&gt;A production Moodle deployment requires more than load balancing alone:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Centralized TLS certificate management.&lt;/li&gt;
&lt;li&gt;A Web Application Firewall (WAF) for HTTP and HTTPS traffic.&lt;/li&gt;
&lt;li&gt;Protection against &lt;strong&gt;OWASP Top 10&lt;/strong&gt; attack patterns.&lt;/li&gt;
&lt;li&gt;Bot and brute-force protection for the login page.&lt;/li&gt;
&lt;li&gt;Rate limiting for login requests and file uploads.&lt;/li&gt;
&lt;li&gt;DDoS mitigation.&lt;/li&gt;
&lt;li&gt;Centralized logging and traffic visibility across all nodes.&lt;/li&gt;
&lt;li&gt;High availability for the load balancer itself, preventing it from becoming the new single point of failure.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In practice, each of these capabilities typically means deploying, managing, and maintaining a separate tool, console, and operational workflow if they’re implemented independently.&lt;/p&gt;
&lt;h2&gt;Why an ADC with an Integrated WAF Changes the Equation&lt;/h2&gt;
&lt;p&gt;When you consider everything required to support the architecture above, building a highly available Moodle deployment with standalone tools means operating, at a minimum, a load balancer, a certificate management solution, a WAF, a rate-limiting service, and a centralized logging platform—each with its own learning curve, update cycle, and potential point of failure if left unattended.&lt;/p&gt;
&lt;p&gt;SKUDONET delivers the same architecture as a single integrated platform:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Load balancing and application-aware health checks for Moodle nodes, supporting the algorithms described above (Round Robin, Least Connections, and Weighted).&lt;/li&gt;
&lt;li&gt;Centralized SSL offloading, allowing certificates to be managed from a single location instead of on every web server.&lt;/li&gt;
&lt;li&gt;An integrated WAF that protects against the OWASP Top 10, bots, and brute-force attacks without requiring a separate security product.&lt;/li&gt;
&lt;li&gt;Built-in rate limiting that can be applied directly to login endpoints and file uploads, the most exposed components of any public Moodle deployment.&lt;/li&gt;
&lt;li&gt;Native high availability for the ADC itself through clustering, ensuring that the availability layer doesn’t become the weakest link.&lt;/li&gt;
&lt;li&gt;A single pane of glass for monitoring traffic, blocked threats, and node health, eliminating the need to correlate logs from multiple systems during an incident.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The advantage isn’t that SKUDONET performs load balancing better than HAProxy or NGINX—both are technically robust solutions that have been powering Moodle deployments for years. The difference is that, with SKUDONET, load balancing, security, and high availability for the load balancer itself are built into the same platform from day one.&lt;/p&gt;
&lt;p&gt;For teams that don’t want to become infrastructure integrators in addition to Moodle administrators, that translates into significantly less operational overhead and a much smaller maintenance burden.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.skudonet.com/wp-content/uploads/2026/07/Moodle-with-Skudonet.jpg&quot;&gt;&lt;img alt=&quot;Moodle-with-Skudonet&quot; class=&quot;alignnone size-full wp-image-77951&quot; height=&quot;1190&quot; src=&quot;https://www.skudonet.com/wp-content/uploads/2026/07/Moodle-with-Skudonet.jpg&quot; width=&quot;1322&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Comparing Moodle Load Balancing Approaches&lt;/strong&gt;&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;/th&gt;
&lt;th&gt;&lt;strong&gt;What It Provides&lt;/strong&gt;&lt;/th&gt;
&lt;th&gt;&lt;strong&gt;What Still Needs to Be Added&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;HAProxy or NGINX&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Load balancing, basic health checks, and traffic distribution.&lt;/td&gt;
&lt;td&gt;WAF, centralized certificate management, rate limiting, high availability for the load balancer itself, and unified observability.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Native Cloud Load Balancer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Fast deployment within a specific cloud provider.&lt;/td&gt;
&lt;td&gt;Portability outside that cloud platform. Advanced security features are often sold as additional managed services.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;SKUDONET Enterprise Edition&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Load balancing, TLS, WAF, rate limiting, high availability for the ADC itself, and centralized visibility in a single platform. Deployable as a virtual appliance, hardware appliance, bare metal installation, or cloud instance.&lt;/td&gt;
&lt;td&gt;The appliance still needs to be sized and deployed within the chosen infrastructure.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;SkudoCloud&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;The same feature set—load balancing, TLS, WAF, high availability, and observability—delivered as a SaaS platform with instant provisioning and no installation required.&lt;/td&gt;
&lt;td&gt;Less direct control over the underlying infrastructure, since it is a fully managed service.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p class=&quot;PDq2pG_selectionAnchorContainer&quot;&gt;For organizations with the time, expertise, and resources to maintain every component separately, HAProxy and NGINX remain excellent technical foundations.&lt;/p&gt;
&lt;p&gt;For teams that need Moodle’s availability and security to work without turning infrastructure into an ongoing integration project, &lt;strong&gt;SKUDONET&lt;/strong&gt; delivers the same capabilities as a single platform: &lt;a href=&quot;https://www.skudonet.com/load-balancing-solutions/enterprise/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Enterprise Edition&lt;/strong&gt; for organizations that prefer full control over where and how the solution is deployed&lt;/a&gt;, or&lt;a href=&quot;https://www.skudonet.com/skudocloud/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt; &lt;strong&gt;SkudoCloud&lt;/strong&gt; for those who would rather not deploy any infrastructure at all.&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;SKUDONET Deployment Options for Moodle&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Virtual Appliance:&lt;/strong&gt; Deploy on VMware, Hyper-V, Proxmox, KVM, or any other supported hypervisor.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hardware Appliance:&lt;/strong&gt; Designed for universities, public-sector organizations, and training centers that require dedicated physical infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bare Metal:&lt;/strong&gt; Install the ADC directly on existing hardware.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud Instance:&lt;/strong&gt; Ideal for Moodle deployments running in public cloud or hybrid environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SkudoCloud:&lt;/strong&gt; SKUDONET’s SaaS platform. Instant provisioning with no installation or long-term commitment required, including Layer 4/Layer 7 load balancing, an integrated WAF, and automatic TLS certificate management from day one. It’s the fastest way to place a highly available, secure application delivery layer in front of an existing Moodle deployment without deploying or maintaining your own appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Load balancing Moodle isn’t simply about distributing traffic, it’s about designing the entire architecture for resilience.&lt;/p&gt;
&lt;p&gt;User sessions, the database, shared storage, and security all need to be addressed together. Otherwise, the availability gained at the web layer can easily be lost elsewhere in the stack.&lt;/p&gt;
&lt;p&gt;Building that architecture with separate tools is entirely possible, but it also means operating and maintaining multiple independent components.&lt;/p&gt;
&lt;p&gt;An ADC with an integrated WAF doesn’t eliminate those architectural decisions, but it does consolidate them into a single platform that needs to be managed instead of five different ones.&lt;/p&gt;
&lt;h2 class=&quot;PDq2pG_selectionAnchorContainer&quot;&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3&gt;What Is Load Balancing in Moodle?&lt;/h3&gt;
&lt;p&gt;Load balancing distributes user requests across multiple Moodle web servers. It prevents a single server from becoming overloaded, eliminates the web layer as a single point of failure, and allows maintenance to be performed without disrupting access to courses, exams, or learning resources.&lt;/p&gt;
&lt;h3&gt;Does Moodle Support Load Balancing Natively?&lt;/h3&gt;
&lt;p&gt;Yes. Moodle supports deployments with multiple load-balanced web servers connected to a shared database, shared storage, and shared session store. Moodle’s official documentation describes architectures that include multiple web servers, clustered databases, and shared file storage.&lt;/p&gt;
&lt;h3&gt;What Are the Best Load Balancing Solutions for Moodle?&lt;/h3&gt;
&lt;p&gt;The answer depends on how much of the infrastructure your team wants to manage.&lt;/p&gt;
&lt;p&gt;HAProxy and NGINX provide reliable traffic distribution but leave WAF protection, certificate management, and high availability for the load balancer itself to be implemented separately.&lt;/p&gt;
&lt;p&gt;SKUDONET integrates all three capabilities into a single platform, available as &lt;strong&gt;Enterprise Edition&lt;/strong&gt; for organizations that prefer to deploy it within their own infrastructure, or as &lt;strong&gt;SkudoCloud&lt;/strong&gt; for those looking for an instantly provisioned SaaS solution.&lt;/p&gt;
&lt;h3&gt;Which Companies Offer Scalable Moodle Hosting with Built-In Load Balancing?&lt;/h3&gt;
&lt;p&gt;It’s important to distinguish between two different types of providers.&lt;/p&gt;
&lt;p&gt;Some vendors manage the entire Moodle environment, including application hosting. Others—such as SKUDONET—do not host Moodle itself, but instead provide the load balancing, availability, and security layer that sits in front of an existing Moodle deployment, whether it’s running on-premises, in the cloud, or in a hybrid environment.&lt;/p&gt;
&lt;h3&gt;Where Can I Find Managed Load Balancing Services for Moodle Hosting?&lt;/h3&gt;
&lt;p&gt;SkudoCloud, SKUDONET’s SaaS platform, provides application load balancing and security with instant provisioning for existing Moodle deployments.&lt;/p&gt;
&lt;p&gt;It doesn’t replace your Moodle hosting provider. Instead, it sits in front of your infrastructure, managing high availability, TLS termination, and WAF protection without requiring your team to deploy or operate that layer themselves.&lt;/p&gt;
&lt;h3&gt;When Should an Organization Load Balance Moodle?&lt;/h3&gt;
&lt;p&gt;Organizations should consider load balancing Moodle whenever the platform supports mission-critical education or training services, experiences significant traffic spikes, requires maintenance without downtime, or has reached the point where relying on a single web server represents an unacceptable availability risk.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-27T12:13:27+00:00</dc:date>
	<dc:creator>Isabel Perez</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39561">
	<title>Deepin: Linyaps Store V3.5: Full Flutter Rewrite with Zero-CLI Automated Environment Configuration</title>
	<link>https://www.deepin.org/en/english-linyaps-store-v3-5-full-flutter-rewrite-with-zero-cli-automated-environment-configuration/</link>
     <content:encoded>Summary: Linyaps — an open-source, containerized package management toolkit that isolates applications from the host OS to eliminate dependency conflicts — today released version 3.5 of its desktop store client. The new edition completes a full architectural shift from Tauri to Flutter, delivering pixel-perfect UI consistency across AMD64, ARM64, and the emerging LoongArch (Loong64) architecture. It also introduces a one-click environment initializer and shareable app installation links, directly addressing two long-standing pain points in Linux software deployment. Full Flutter Migration: Why It Matters Linyaps Store v3.5 fully rebuilds the client stack on Flutter Desktop, resolving long-standing cross-platform inconsistencies present in ...&lt;a href=&quot;https://www.deepin.org/en/english-linyaps-store-v3-5-full-flutter-rewrite-with-zero-cli-automated-environment-configuration/&quot;&gt;Read more&lt;/a&gt;</content:encoded> 
	<dc:date>2026-07-27T09:15:35+00:00</dc:date>
	<dc:creator>guoxinzhu</dc:creator>
</item> 
<item rdf:about="https://sparkylinux.org/?p=14113">
	<title>SparkyLinux: Fooyin</title>
	<link>https://sparkylinux.org/fooyin/</link>
     <content:encoded>&lt;p&gt;There is a new application available for Sparkers: Fooyin What is Fooyin? Features: – Support for major formats including FLAC, MP3, MP4, Vorbis, Opus, WavPack, WAV, AIFF, MKA, Musepack, and Monkey’s Audio – Native support for VGM and tracker/module formats through optional plugins – Playback of files directly from archives – Internet radio discovery and remote audio stream playback …&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://sparkylinux.org/fooyin/&quot; rel=&quot;nofollow&quot;&gt;Source&lt;/a&gt;&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-26T09:18:29+00:00</dc:date>
	<dc:creator>pavroo</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39549">
	<title>Deepin: (中文) 独立开发者自制 PDF 批量打印工具，已上架应用商店！</title>
	<link>https://www.deepin.org/en/batch-print-pdf/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-24T02:00:25+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68962">
	<title>GreenboneOS: CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86</title>
	<link>https://www.greenbone.net/en/blog/cve-2026-53359-januscape-kvm-vulnerability/</link>
     <content:encoded>Januscape, tracked as CVE-2026-53359 (CVSS 8.8), is a use-after-free vulnerability [CWE-825] in the Linux kernel KVM/x86 that can let a guest crash its host and potentially break guest-host isolation. The highest-risk targets are Intel and AMD x86_64 KVM hosts that expose nested virtualization, especially in environments that accept untrusted guests or allow users to create […]</content:encoded> 
	<dc:date>2026-07-23T14:59:13+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://puri.sm/?p=85705">
	<title>Purism PureOS: A STEP ahead for customization with the Librem 16</title>
	<link>https://puri.sm/posts/a-step-ahead-for-customization-with-the-librem-16/</link>
     <content:encoded>&lt;p&gt;Today, Purism is proud to release CAD models for the Librem 16 in both the widely used STEP and FreeCAD formats.  Under the terms of the Creative Commons BY-SA 4.0 license, you are free to reproduce, modify, and integrate these components as you like, including commercially.&lt;/p&gt;
&lt;p&gt;The post &lt;a href=&quot;https://puri.sm/posts/a-step-ahead-for-customization-with-the-librem-16/&quot; rel=&quot;nofollow&quot;&gt;A STEP ahead for customization with the Librem 16&lt;/a&gt; appeared first on &lt;a href=&quot;https://puri.sm/&quot; rel=&quot;nofollow&quot;&gt;Purism&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-23T13:46:11+00:00</dc:date>
	<dc:creator>Jonathon Hall</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39534">
	<title>Deepin: Linyaps Store V3.5: Full Flutter Rewrite with Zero-CLI Automated Environment Configuration</title>
	<link>https://www.deepin.org/en/linyaps-appstore-v3-5/</link>
     <content:encoded>Summary: Linyaps — an open-source, containerized package management toolkit that isolates applications from the host OS to eliminate dependency conflicts — today released version 3.5 of its desktop store client. The new edition completes a full architectural shift from Tauri to Flutter, delivering pixel-perfect UI consistency across AMD64, ARM64, and the emerging LoongArch (Loong64) architecture. It also introduces a one-click environment initializer and shareable app installation links, directly addressing two long-standing pain points in Linux software deployment. Full Flutter Migration: Why It Matters Linyaps Store v3.5 fully rebuilds the client stack on Flutter Desktop, resolving long-standing cross-platform inconsistencies present in ...&lt;a href=&quot;https://www.deepin.org/en/linyaps-appstore-v3-5/&quot;&gt;Read more&lt;/a&gt;</content:encoded> 
	<dc:date>2026-07-23T11:29:22+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://tails.net/news/version_7.10/">
	<title>Tails: Tails 7.10</title>
	<link>https://tails.net/news/version_7.10/</link>
     <content:encoded>&lt;h1 id=&quot;features&quot;&gt;New features&lt;/h1&gt;


&lt;h2&gt;New shutdown procedure&lt;/h2&gt;

&lt;p&gt;Tails now uses the standard shutdown procedure from GNOME.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://tails.net/doc/first_steps/shutdown/index.en.html&quot;&gt;standard shutdown&lt;/a&gt; procedure is a bit slower,
but better prevents data loss.&lt;/p&gt;

&lt;p&gt;For example, the &lt;strong&gt;Power Off&lt;/strong&gt; confirmation dialog informs you if an
application needs to be closed or an open document needs to be saved before
shutting down.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;screenshot&quot; height=&quot;406&quot; src=&quot;https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png&quot; width=&quot;472&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Even without confirming or saving the open documents, Tails will shut down
after 60 seconds.&lt;/p&gt;

&lt;p&gt;You can still use the faster &lt;a href=&quot;https://tails.net/doc/first_steps/shutdown/index.en.html#emergency&quot;&gt;emergency
shutdown&lt;/a&gt; as before.&lt;/p&gt;

&lt;h2&gt;&lt;em&gt;Celluloid&lt;/em&gt; video player&lt;/h2&gt;

&lt;p&gt;We replaced &lt;em&gt;GNOME Videos&lt;/em&gt; with &lt;em&gt;Celluloid&lt;/em&gt;, a more modern and reliable video
player.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://tails.net/news/version_7.10/celluloid.png&quot;&gt;&lt;img alt=&quot;&quot; class=&quot;screenshot&quot; height=&quot;675&quot; src=&quot;https://tails.net/news/version_7.10/celluloid.png&quot; width=&quot;751&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;div class=&quot;note&quot;&gt;

&lt;p&gt;For added security, &lt;i&gt;Celluloid&lt;/i&gt; cannot access the network. You can
either:&lt;/p&gt;

&lt;ul&gt;

  &lt;li&gt;Open online videos, like MP4 and AVI files, in &lt;i&gt;Tor Browser&lt;/i&gt;.

  &lt;/li&gt;&lt;li&gt;Open online streaming addresses, like IPTV and HLS addresses, in
  &lt;i&gt;VLC&lt;/i&gt;, installed as &lt;a href=&quot;https://tails.net/doc/persistent_storage/additional_software/index.en.html&quot;&gt;additional
  software&lt;/a&gt;.&lt;/li&gt;

&lt;/ul&gt;

&lt;/div&gt;




&lt;div class=&quot;bug&quot;&gt;

&lt;p&gt;&lt;i&gt;Celluloid&lt;/i&gt; doesn&#39;t work on some computers from 2011 or earlier.&lt;/p&gt;

&lt;p&gt;You can use &lt;i&gt;VLC&lt;/i&gt; instead, installed as &lt;a href=&quot;https://tails.net/doc/persistent_storage/additional_software/index.en.html&quot;&gt;additional
software&lt;/a&gt;.&lt;/p&gt;

&lt;/div&gt;




&lt;h1 id=&quot;changes&quot;&gt;Changes and updates&lt;/h1&gt;


&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Update &lt;em&gt;Tor Browser&lt;/em&gt; to &lt;a href=&quot;https://blog.torproject.org/new-release-tor-browser-15019/&quot;&gt;15.0.19&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Update some firmware packages. This improves support for newer
hardware: graphics, Wi-Fi, and so on.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;For more details, read our &lt;a href=&quot;https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog&quot;&gt;changelog&lt;/a&gt;.&lt;/p&gt;

&lt;h1 id=&quot;get&quot;&gt;Get Tails 7.10&lt;/h1&gt;


&lt;h2&gt;To upgrade your Tails USB stick and keep your Persistent Storage&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Automatic upgrades are available from Tails 7.0 or later to 7.10.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a &lt;a href=&quot;https://tails.net/doc/upgrade/index.en.html#manual&quot;&gt;manual upgrade&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;To install Tails 7.10 on a new USB stick&lt;/h2&gt;

&lt;p&gt;Follow our &lt;a href=&quot;https://tails.net/install/index.en.html&quot;&gt;installation instructions&lt;/a&gt;.&lt;/p&gt;

&lt;div class=&quot;caution&quot;&gt;&lt;p&gt;The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.&lt;/p&gt;&lt;/div&gt;


&lt;h2&gt;To download only&lt;/h2&gt;

&lt;p&gt;If you don&#39;t need installation or upgrade instructions, you can download
Tails 7.10 directly:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://tails.net/install/download/index.en.html&quot;&gt;For USB sticks (USB image)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://tails.net/install/download-iso/index.en.html&quot;&gt;For DVDs and virtual machines (ISO image)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-23T00:00:00+00:00</dc:date>
	<dc:creator>Tails</dc:creator>
</item> 
<item rdf:about="https://www.qubes-os.org/news/2026/07/23/qubes-os-summit-2026-tickets-for-sale-and-speaker-proposals-now-open/">
	<title>Qubes: Qubes OS Summit 2026: Tickets for sale and speaker proposals now open!</title>
	<link>https://www.qubes-os.org/news/2026/07/23/qubes-os-summit-2026-tickets-for-sale-and-speaker-proposals-now-open/</link>
     <content:encoded>&lt;p&gt;&lt;a href=&quot;https://pretix.eu/qubes/summit2026/&quot;&gt;Qubes OS Summit 2026&lt;/a&gt; is a three-day gathering of security enthusiasts, open-source developers, and digital privacy experts.&lt;/p&gt;

&lt;h2 id=&quot;when-and-where&quot;&gt;When and where&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Friday, October 30 @ 9:30 AM — Sunday, November 1 @ 3:00 PM (GMT+1)&lt;/strong&gt;&lt;br /&gt;
(A more specific schedule will be published after the speaker lineup is finalized.)&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://refugio.berlin/&quot;&gt;Refugio Berlin&lt;/a&gt;&lt;br /&gt;
Lenaustraße 3-4&lt;br /&gt;
12047 Berlin&lt;br /&gt;
&lt;a href=&quot;https://www.openstreetmap.org/way/263350430&quot;&gt;View on OpenStreetMap&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;attend-in-person-or-online&quot;&gt;Attend in person or online&lt;/h2&gt;

&lt;p&gt;There are three ways to attend the Summit:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;strong&gt;In person at &lt;a href=&quot;https://refugio.berlin/&quot;&gt;Refugio Berlin&lt;/a&gt;&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;Requires a &lt;a href=&quot;https://pretix.eu/qubes/summit2026/&quot;&gt;paid on-site ticket&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;Grants access to the hackathon (including interactive workshops) and any design sessions (depending on conference schedule)&lt;/li&gt;
      &lt;li&gt;Provides the opportunity to socialize, network, and mingle with like-minded individuals who are passionate about secure computing&lt;/li&gt;
      &lt;li&gt;Grants exclusive access to any non-livestreamed, non-recorded presentations (see below)&lt;/li&gt;
      &lt;li&gt;Grants access to attend presentations and participate as a live audience member&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Actively participate online&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;Requires a &lt;a href=&quot;https://pretix.eu/qubes/summit2026/&quot;&gt;free virtual ticket&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;For those who are presenting remotely&lt;/li&gt;
      &lt;li&gt;For those who are attending presentations remotely and wish to ask questions or engage in active discussion in a live chat during the presentations&lt;/li&gt;
      &lt;li&gt;Does not grant access to the hackathon or any design sessions&lt;/li&gt;
      &lt;li&gt;Does not provide the opportunity to socialize, network, or mingle with like-minded individuals who are passionate about secure computing&lt;/li&gt;
      &lt;li&gt;Does not grant access to any non-livestreamed, non-recorded presentations (see below)&lt;/li&gt;
      &lt;li&gt;Does not grant access to attend presentations as a live audience member&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Passively view online&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;No ticket or registration required&lt;/li&gt;
      &lt;li&gt;For those who simply wish to watch the presentations via the public livestream and recorded videos&lt;/li&gt;
      &lt;li&gt;Does not provide the ability to ask questions or engage in active discussion during the presentations&lt;/li&gt;
      &lt;li&gt;Does not grant access to the hackathon or any design sessions&lt;/li&gt;
      &lt;li&gt;Does not provide the opportunity to socialize, network, or mingle with like-minded individuals who are passionate about secure computing&lt;/li&gt;
      &lt;li&gt;Does not grant access to any non-livestreamed, non-recorded presentations (see below)&lt;/li&gt;
      &lt;li&gt;Does not grant access to attend presentations as a live audience member&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Presenters have the option to request that their presentations not be recorded. If a presenter opts out of recording, there will be a “no recording” icon next to that presentation in the conference schedule. Only on-site attendees will be able to view that presentation. It will not be livestreamed or recorded for later viewing.&lt;/p&gt;

&lt;h2 id=&quot;become-a-presenter&quot;&gt;Become a presenter&lt;/h2&gt;

&lt;p&gt;If you’d like to present at the Summit, please &lt;a href=&quot;https://pretalx.com/qubes-os-summit-2026/cfp&quot;&gt;submit your proposal&lt;/a&gt; by 2026-08-31.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;You may present either on site or virtually from anywhere in the world.&lt;/li&gt;
  &lt;li&gt;If your proposal is accepted and you wish to present in person, you’ll be issued an on-site ticket free of charge, no purchase necessary.&lt;/li&gt;
  &lt;li&gt;If you select “Don’t record this session” when submitting your proposal, your presentation will not be livestreamed or recorded. Online attendees will not be able to view it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;conference-schedule&quot;&gt;Conference schedule&lt;/h2&gt;

&lt;p&gt;We’re still reviewing proposals from prospective presenters, so the list of talks has not been decided yet. We’ll publish a detailed conference schedule after the speaker lineup has been finalized.&lt;/p&gt;

&lt;h2 id=&quot;become-a-sponsor&quot;&gt;Become a sponsor&lt;/h2&gt;

&lt;p&gt;If you or your organization are interested in sponsoring Qubes OS Summit 2026 or becoming a &lt;a href=&quot;https://www.qubes-os.org/partners/&quot;&gt;Qubes Partner&lt;/a&gt;, please contact us at &lt;a href=&quot;mailto:funding@qubes-os.org&quot;&gt;funding@qubes-os.org&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;code-of-conduct&quot;&gt;Code of conduct&lt;/h2&gt;

&lt;p&gt;This event is covered by the Qubes OS Project’s &lt;a href=&quot;https://doc.qubes-os.org/en/latest/introduction/code-of-conduct.html&quot;&gt;code of conduct&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-23T00:00:00+00:00</dc:date>
	<dc:creator>Qubes</dc:creator>
</item> 
<item rdf:about="https://www.qubes-os.org/news/2026/07/23/fedora-44-templates-available/">
	<title>Qubes: Fedora 44 templates available</title>
	<link>https://www.qubes-os.org/news/2026/07/23/fedora-44-templates-available/</link>
     <content:encoded>&lt;p&gt;The following new &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/fedora/fedora.html&quot;&gt;Fedora 44 templates&lt;/a&gt; are now available for Qubes OS 4.3:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fedora-44-xfce&lt;/code&gt; — default Fedora template with the &lt;a href=&quot;https://xfce.org/&quot;&gt;Xfce&lt;/a&gt; desktop environment&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fedora-44-gnome&lt;/code&gt; — alternative Fedora template with the &lt;a href=&quot;https://www.gnome.org/&quot;&gt;GNOME&lt;/a&gt; desktop environment&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fedora-44-minimal&lt;/code&gt; — &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/minimal-templates.html&quot;&gt;minimal template&lt;/a&gt; for advanced users&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There are two ways to upgrade a template to a new Fedora release:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Recommended:&lt;/strong&gt; &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/fedora/fedora.html#installing&quot;&gt;Install a fresh template to replace an existing one.&lt;/a&gt; This option is simpler for less experienced users, but it won’t preserve any modifications you’ve made to your template. After you install the new template, you’ll have to redo your desired template modifications (if any) and &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/templates.html#switching&quot;&gt;switch everything that was set to the old template to the new template&lt;/a&gt;. If you choose to modify your template, you may wish to write those modifications down so that you remember what to redo on each fresh install. To see a log of package manager actions, open a terminal in the template and use the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dnf history&lt;/code&gt; command.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Advanced:&lt;/strong&gt; &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/fedora/fedora-upgrade.html&quot;&gt;Perform an in-place upgrade of an existing Fedora template.&lt;/a&gt; This option will preserve any modifications you’ve made to the template, but it may be more complicated for less experienced users.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; No user action is required regarding the OS version in dom0 (see our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html#note-on-dom0-and-eol&quot;&gt;note on dom0 and EOL&lt;/a&gt;).&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-23T00:00:00+00:00</dc:date>
	<dc:creator>Qubes</dc:creator>
</item> 
<item rdf:about="https://www.univention.de/?p=87695">
	<title>Univention Corporate Server: Nubus for Kubernetes 1.21: Faster Provisioning, More Robust Health Checks, and a More User-Friendly Portal</title>
	<link>https://www.univention.com/blog-en/2026/07/nubus-for-kubernetes-1-21/</link>
     <content:encoded>&lt;div class=&quot;wpb-content-wrapper&quot;&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;
	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The latest release of Nubus for Kubernetes puts operational stability front and center: The Provisioning Service now delivers changes from the directory service to downstream systems significantly faster. Many liveness and readiness probes have been reworked so that Kubernetes can assess the state of components more accurately. Additionally, the portal now prevents content from being visible before login. Rounding out the release is a comprehensive set of security updates – most notably an upgrade to Keycloak 26.7.0.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Provisioning Performance Improvements&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The Provisioning Service distributes changes from the directory service as events to all connected consumers. If a consumer did not acknowledge an event – for example because it was restarting or temporarily unreachable – redelivery previously had to wait up to 30 seconds. In practice, this led to noticeable delays before downstream services saw the current state of the directory.&lt;/p&gt;
&lt;p&gt;With Nubus 1.21, unacknowledged events are redelivered within approximately one second. After an interruption, consumers are therefore back up to date much faster. As part of these changes, the embedded NATS message broker has also been updated to version 2.14.3.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Comprehensive Security Updates for Containers and Keycloak&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;A major focus of this release is on security updates. Keycloak is upgraded to version 26.7.0, closing a significant number of CVEs. In addition to the version upgrade, two functional bugs in the Keycloak service were fixed that are also security-relevant:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LDAP connection was unnecessarily re-established:&lt;/strong&gt; A regression bug caused Keycloak to open a new LDAP connection for every operation instead of reusing the existing one. Under load, this resulted in a flood of BIND requests against the LDAP server. Keycloak now binds once and continues to use the established connection. The required patch was developed by Univention and contributed upstream to the Keycloak project.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Login failures after username case changes:&lt;/strong&gt; After changing the capitalization of a username – for example from FOO to foo – login to the portal and UMC sometimes failed with HTTP 401. The cause was that Keycloak continued to use the cached value until the internal user cache expired. The LDAP User Federation no longer caches imported users and instead reads the UID directly from the LDAP server on every login. As a result, renamed users can log in again immediately. This setting takes effect automatically with the upgrade.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Beyond that, this release includes an extensive set of errata updates for numerous libraries and components contained in the container images – including critical and high-severity CVEs in golang.org/x/crypto, golang.org/x/net, containerd, cryptography, and several Netty modules. The complete list of all resolved CVEs can be found in the release notes.&lt;/p&gt;
&lt;p&gt;This continuous maintenance of the container base is part of the strategy to identify and close security vulnerabilities in upstream components as quickly as possible.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  New and Improved Liveness and Readiness Probes&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Kubernetes relies on liveness and readiness probes to decide whether a pod should receive traffic or needs to be restarted. In several Nubus for Kubernetes components, these probes previously provided limited insight.&lt;/p&gt;
&lt;p&gt;With version 1.21, the probes for the &lt;strong&gt;UDM REST API&lt;/strong&gt; containers (for API-based administration) and the &lt;strong&gt;UMC Server&lt;/strong&gt; (for graphical administration) have been significantly reworked. They now also detect runtime issues within the containers, providing more reliable feedback on the health of the services.&lt;/p&gt;
&lt;p&gt;For operators, this means: Kubernetes detects unhealthy components more reliably while cleanly distinguishing between a truly non-functional pod and a temporary disruption of a backend such as LDAP – thereby avoiding unnecessary restarts of healthy pods.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Portal: No More Content Before Enforced Login&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;When the &lt;em&gt;Users are required to login&lt;/em&gt; option is enabled for a portal, anonymous visitors should only see the login page. Previously, however, the portal briefly displayed content that was available to anonymous visitors before redirecting to the login page. This affected tiles without group restrictions that are visible to all users by default and were therefore also shown to anonymous visitors.&lt;/p&gt;
&lt;p&gt;With Nubus 1.21, this behavior is corrected: When login is enforced, anonymous visitors are redirected directly to the login page without the portal rendering or delivering categories, tiles, folders, or menu entries beforehand. For all deployments that intend to make portal content accessible exclusively to authenticated users, this update improves the end-user experience and closes a potential data exposure gap.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Bits &amp;amp; Pieces&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;In addition to the highlights above, Nubus 1.21 includes several smaller adjustments. Notably, the &lt;strong&gt;Guardian&lt;/strong&gt; component, including its container images, has been temporarily removed from the Nubus umbrella chart. This step prepares for an upcoming backend change and has no impact on the behavior of existing deployments.&lt;/p&gt;
&lt;p&gt;As always, the &lt;a href=&quot;https://docs.software-univention.de/nubus-kubernetes-release-notes/1.x/en/1.21.html#v1-21-0&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Release Notes&lt;/a&gt; contain all the details, and the installation is described in the &lt;a href=&quot;https://docs.software-univention.de/nubus-kubernetes-operation/latest/en/index.html&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Nubus Operations Manual&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Der Beitrag &lt;a href=&quot;https://www.univention.com/blog-en/2026/07/nubus-for-kubernetes-1-21/&quot;&gt;Nubus for Kubernetes 1.21: Faster Provisioning, More Robust Health Checks, and a More User-Friendly Portal&lt;/a&gt; erschien zuerst auf &lt;a href=&quot;https://www.univention.com&quot;&gt;Univention&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-22T11:08:09+00:00</dc:date>
	<dc:creator>Ingo Steuwer</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68913">
	<title>GreenboneOS: wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress</title>
	<link>https://www.greenbone.net/en/blog/wp2shell-wordpress-rce/</link>
     <content:encoded>A WordPress Core vulnerability chain, publicly nicknamed wp2shell, combines CVE-2026-63030 (CVSS 9.8) and CVE-2026-60137 (CVSS 5.9) for pre-authentication remote code execution (RCE). The exploit chain affects WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. WordPress 6.8.x before 6.8.6 is affected by CVE-2026-60137 alone. Dozens of proof-of-concept (PoC) exploits have been published for the full exploit […]</content:encoded> 
	<dc:date>2026-07-22T10:53:46+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68832">
	<title>GreenboneOS: TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4</title>
	<link>https://www.greenbone.net/en/blog/bsi-standards-tls-ssh-tr03116-4-tr02102-4/</link>
     <content:encoded>Technical guidelines published by government bodies define the highest security standards for protecting the national IT infrastructure. As the cyber security landscape becomes more perilous, it’s even more important for organizations to be diligent about implementing the strictest security standards. Government organizations need to ensure compliance, while private-sector entities can use the standards as benchmarks […]</content:encoded> 
	<dc:date>2026-07-21T11:49:06+00:00</dc:date>
	<dc:creator>Greenbone AG</dc:creator>
</item> 
<item rdf:about="https://www.univention.de/?p=87685">
	<title>Univention Corporate Server: More Speed for Nubus, More Predictability for UCS: Separate Maintenance Cycles for IAM and Operating Environment</title>
	<link>https://www.univention.com/blog-en/2026/07/ucs-5-3-separate-maintenance-cycles-nubus-iam-operating-environment/</link>
     <content:encoded>&lt;div class=&quot;wpb-content-wrapper&quot;&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;
	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;With UCS 5.3, we are introducing an important structural change to our maintenance concept: We are following our product structure and splitting the previously shared maintenance commitment for the combination of &lt;b&gt;Nubus as an Identity &amp;amp; Access Management solution (IAM) &lt;/b&gt;and &lt;b&gt;UCS as the operating environment &lt;/b&gt;into two independent commitments.&lt;/p&gt;
&lt;p&gt;What may initially sound like an internal restructuring has practical benefits for operators: more predictable updates at the operating level (UCS) and faster access to new features at the IAM level (Nubus).&lt;/p&gt;
&lt;p&gt;In this article, we explain why we are taking this step, what specifically is changing – and what stays the same.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  How Maintenance Worked with UCS Until Now&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Until now, the maintenance commitment for Nubus and the underlying UCS operating environment was jointly tied to the release cycle of UCS. This meant: A shared commitment for stable, backward-compatible maintenance, with optionally long durations (LTS), covered both the IAM functionality of Nubus and the technical operating environment UCS.&lt;/p&gt;
&lt;p&gt;Larger, potentially incompatible changes, for example new features affecting existing configurations, the switch to a new major version of an upstream component such as a new Debian version, or the deprecation of individual features, were generally tied to UCS minor or major releases.&lt;/p&gt;
&lt;p&gt;This model was common practice for many years: Within a minor release, the environment remains stable, and larger changes are bundled and announced.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  The Disadvantages of the Shared Commitment&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;With Nubus as an independent product that can be operated both on UCS and on Kubernetes, the limits of this tight coupling to exactly one release rhythm became apparent. The different requirements of IAM functionality and operating platform can be better represented through separate release and maintenance cycles.&lt;/p&gt;
&lt;p&gt;Two challenges have become particularly evident in this regard:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;b&gt;New features had to wait for the next release: &lt;/b&gt;A planned change, for example a new Nubus feature or an update of an IAM component, could not be released as soon as it was ready. Instead, it had to wait for the next minor release of UCS. As a result, new features were unnecessarily delayed.&lt;/li&gt;
&lt;/ol&gt;
&lt;ol start=&quot;2&quot;&gt;
&lt;li&gt;&lt;b&gt;Too many changes came at once: &lt;/b&gt;When a minor or major release was published, it inevitably contained both changes to the operating environment (for example the Debian base or system services) and changes at the IAM level, such as the switch to Keycloak in UCS 5.2.&lt;br /&gt;
For operators, this meant: A single update event that simultaneously involved infrastructure testing, adjustments to connected applications, as well as coordination with various responsible parties and stakeholders.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As a result, updates became more extensive than they needed to be. In practice, this often led to rollouts taking longer, because many different tasks had to be taken into account at the same time.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  What Is Changing Now&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;With UCS 5.3, we are splitting the maintenance commitment into two independent lines:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;UCS as the operating environment&lt;/b&gt; receives its own maintenance commitment for the underlying distribution, system services, and operation in virtual machines or on hardware.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Nubus as the IAM solution &lt;/b&gt;receives its own maintenance commitment for directory service, single sign-on, portal, and the features built upon them, regardless of whether Nubus is operated under UCS or under Kubernetes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Both commitments continue to follow the proven principle of stable, backward-compatible maintenance with optionally long durations (LTS). The change does not mean a reduction in maintenance, but rather a better alignment with the actual product structure.&lt;/p&gt;
&lt;p&gt;Larger, potentially incompatible changes will in future be tied to the respective release cycle of each individual level, no longer automatically to one another.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;

	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;Specifically, this means:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;New Nubus features&lt;/b&gt; can be released independently of the release cycle of the UCS operating environment, without having to wait for the next minor release of UCS.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Updates to the UCS operating environment&lt;/b&gt; can be planned without automatically including larger changes to the IAM functionality.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Operators can manage testing effort and stakeholder involvement in a more targeted way:&lt;/b&gt; A UCS update primarily affects administrators and infrastructure managers. A Nubus update primarily affects application owners and teams that manage connected applications.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This makes operations overall simpler and more predictable and new features can be provided faster.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  What Stays the Same&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;As important as this structural change is: The fundamental promise does not change.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;The maintenance commitments remain comprehensive.&lt;/b&gt; For both UCS as the operating environment and Nubus as the IAM solution, the following continues to apply: stable, backward-compatible maintenance, optionally with long durations (LTS). We are splitting the commitment across two levels, we are not reducing it.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;The scope of contracts does not change. &lt;/b&gt;There are no changes to our fundamental customer promise within existing subscription contracts.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Nubus remains flexible to operate.&lt;/b&gt; The separate maintenance commitment applies to Nubus regardless of the operating form, both for Nubus on UCS as a virtual machine and for Nubus for Kubernetes.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Schedule: UCS 5.3&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;The new, separate maintenance policy takes effect with the stable release of UCS 5.3.&lt;/p&gt;
&lt;p&gt;The exact details, for example specific durations, affected components, and the precise delineation between the UCS operating environment and the Nubus level, will be discussed with interested customers and communicated in good time before the availability of UCS 5.3.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;uni-section uni-section--pt-0 uni-section--pb-8 &quot;&gt;&lt;div class=&quot;uni-container uni-container--sm&quot;&gt;&lt;div class=&quot;vc_row wpb_row vc_row-fluid&quot;&gt;&lt;div class=&quot;wpb_column vc_column_container vc_col-sm-12&quot;&gt;&lt;div class=&quot;vc_column-inner&quot;&gt;&lt;div class=&quot;wpb_wrapper&quot;&gt;

&lt;h2&gt;
  Feedback and Contact&lt;/h2&gt;


	&lt;div class=&quot;wpb_text_column wpb_content_element&quot;&gt;
		&lt;div class=&quot;wpb_wrapper&quot;&gt;
			&lt;div id=&quot;meta-origin&quot;&gt;
&lt;p&gt;This change is a direct result of the feedback we have received from operators and IT decision-makers regarding the previous update rhythm. If you are interested in being involved in the further discussion, please feel free to get in touch with us!&lt;/p&gt;
&lt;p&gt;We look forward to your feedback, here, at &lt;a href=&quot;https://help.univention.com/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;help.univention.com&lt;/a&gt;, or with your contact person at Univention.&lt;/p&gt;
&lt;/div&gt;

		&lt;/div&gt;
	&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Der Beitrag &lt;a href=&quot;https://www.univention.com/blog-en/2026/07/ucs-5-3-separate-maintenance-cycles-nubus-iam-operating-environment/&quot;&gt;More Speed for Nubus, More Predictability for UCS: Separate Maintenance Cycles for IAM and Operating Environment&lt;/a&gt; erschien zuerst auf &lt;a href=&quot;https://www.univention.com&quot;&gt;Univention&lt;/a&gt;.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-21T06:38:43+00:00</dc:date>
	<dc:creator>Ingo Steuwer</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39510">
	<title>Deepin: (中文) 应用商店｜时隔三年，百度网盘Linux版迎来重磅更新！</title>
	<link>https://www.deepin.org/en/baidunetdisk-v8-6-0/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-21T02:00:36+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://blog.armbian.com/rss/6a5e522d0b8ab5000178c68e">
	<title>ARMBIAN: Github Highlights</title>
	<link>https://blog.armbian.com/github-highlights-34/</link>
     <content:encoded>&lt;img alt=&quot;Github Highlights&quot; src=&quot;https://blog.armbian.com/content/images/2026/07/july20_fixed.png&quot; /&gt;&lt;p&gt;This week&amp;amp;aposs updates center on &lt;strong&gt;new hardware enablement&lt;/strong&gt;, a &lt;strong&gt;broad U-Boot v2026.07 modernization&lt;/strong&gt;, and &lt;strong&gt;build system hardening&lt;/strong&gt; for toolchain and infrastructure changes.&lt;/p&gt;&lt;p&gt;Board support expanded across multiple SoC families, including the &lt;strong&gt;X88 PRO RK3566 TV box&lt;/strong&gt;, &lt;strong&gt;Avnet MaaXBoard 8ULP (i.MX8ULP)&lt;/strong&gt;, &lt;strong&gt;EASY EAI Nano (RV1126)&lt;/strong&gt;, and the &lt;strong&gt;AYN Odin3&lt;/strong&gt;. The &lt;strong&gt;Youyeetoo R1 v3&lt;/strong&gt; was promoted to standard support with named audio outputs, while the Radxa Dragon Q8B gained an edge kernel (7.1) target. Rockchip work included &lt;strong&gt;RK3588 CAN support&lt;/strong&gt; for kernels 6.18/7.1/7.2, HDMI-RX fixes on the OrangePi 5 Ultra, and Mixtile Blade3 refinements on the 7.2 bleeding edge.&lt;/p&gt;&lt;p&gt;A coordinated &lt;strong&gt;U-Boot bump to v2026.07&lt;/strong&gt; landed across Helios4, Odroid HC4/M1, Turing RK1, Radxa E52C, Qidi X6, Mekotronics R58X-Pro, and the Espressobin/Macchiatobin (paired with TF-A 2.14.0). This surfaced toolchain issues on Trixie, addressed through &lt;strong&gt;SWIG 4.3 pylibfdt compatibility&lt;/strong&gt;, demotion of gcc 14 int-conversion and implicit-declaration errors to warnings, and related pin cleanups.&lt;/p&gt;&lt;p&gt;Infrastructure work strengthened build reliability and CI. The rootfs stage gained &lt;strong&gt;DNS fallback and apt retry hardening&lt;/strong&gt; for chroot operations, &lt;code&gt;armbian-firstlogin&lt;/code&gt; received power-loss recovery with atomic writes, and &lt;code&gt;armbian-install&lt;/code&gt; now reports bootloader write failures explicitly. Docker framework updates enable &lt;strong&gt;native riscv64 image generation&lt;/strong&gt; on trixie and noble runners, while new extensions introduce &lt;strong&gt;sysrq serial trigger&lt;/strong&gt;, kernel-debug tiers, ram-boot via &lt;code&gt;rkusbboot&lt;/code&gt;, and generic &lt;strong&gt;SATA park-on-shutdown&lt;/strong&gt; enabled by default on the Odroid HC4.&lt;/p&gt;&lt;p&gt;#Armbian #EmbeddedLinux #UBoot #Rockchip #RISCV&lt;/p&gt;&lt;h2 id=&quot;changes&quot;&gt;Changes&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Add support for X88 PRO RK3566 TV box. by &lt;a href=&quot;https://github.com/Ovaday?ref=blog.armbian.com&quot;&gt;@Ovaday&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/linux-rockchip/pull/500?ref=blog.armbian.com&quot;&gt;armbian/linux-rockchip#500&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add AI-driven README updater (central, cross-repo). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/359?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#359&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add Avnet MaaXBoard 8ULP (i.MX8ULP) support. by &lt;a href=&quot;https://github.com/govindsi?ref=blog.armbian.com&quot;&gt;@govindsi&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9991?ref=blog.armbian.com&quot;&gt;armbian/build#9991&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add AYN Odin3 firmware. by &lt;a href=&quot;https://github.com/kasimling?ref=blog.armbian.com&quot;&gt;@kasimling&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/firmware/pull/136?ref=blog.armbian.com&quot;&gt;armbian/firmware#136&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add ayn-odin3 board image. by &lt;a href=&quot;https://github.com/kasimling?ref=blog.armbian.com&quot;&gt;@kasimling&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/armbian.github.io/pull/358?ref=blog.armbian.com&quot;&gt;armbian/armbian.github.io#358&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add board: EASY EAI Nano RV1126. by &lt;a href=&quot;https://github.com/hqnicolas?ref=blog.armbian.com&quot;&gt;@hqnicolas&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10154?ref=blog.armbian.com&quot;&gt;armbian/build#10154&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Add minimal SWT6621S firmware support for KICKPI K3B. by &lt;a href=&quot;https://github.com/retro98boy?ref=blog.armbian.com&quot;&gt;@retro98boy&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/firmware/pull/134?ref=blog.armbian.com&quot;&gt;armbian/firmware#134&lt;/a&gt;&lt;/li&gt;&lt;li&gt;armbian-firstlogin: power-loss recovery and atomic writes. by &lt;a href=&quot;https://github.com/mingzhangqun?ref=blog.armbian.com&quot;&gt;@mingzhangqun&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9954?ref=blog.armbian.com&quot;&gt;armbian/build#9954&lt;/a&gt;&lt;/li&gt;&lt;li&gt;armbian-install: report bootloader write failures instead of &quot;Done.&quot;. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10204?ref=blog.armbian.com&quot;&gt;armbian/build#10204&lt;/a&gt;&lt;/li&gt;&lt;li&gt;artifact-rootfs: surface git-log failure when computing configng hash. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9849?ref=blog.armbian.com&quot;&gt;armbian/build#9849&lt;/a&gt;&lt;/li&gt;&lt;li&gt;board: aml-c400-plus: Fix eMMC boot format and partition layout. by &lt;a href=&quot;https://github.com/jomadeto?ref=blog.armbian.com&quot;&gt;@jomadeto&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9911?ref=blog.armbian.com&quot;&gt;armbian/build#9911&lt;/a&gt;&lt;/li&gt;&lt;li&gt;boards/easy-eai-nano: enable usb and brcm wifi. by &lt;a href=&quot;https://github.com/hqnicolas?ref=blog.armbian.com&quot;&gt;@hqnicolas&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10177?ref=blog.armbian.com&quot;&gt;armbian/build#10177&lt;/a&gt;&lt;/li&gt;&lt;li&gt;brcm: add brcmfmac firmware aliases for easy-eai nano (rv1126). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/firmware/pull/133?ref=blog.armbian.com&quot;&gt;armbian/firmware#133&lt;/a&gt;&lt;/li&gt;&lt;li&gt;bsp: generic SATA park-on-shutdown (HDD_PARK_ON_SHUTDOWN), enable on Odroid HC4. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10191?ref=blog.armbian.com&quot;&gt;armbian/build#10191&lt;/a&gt;&lt;/li&gt;&lt;li&gt;bsp: use kernel version argument in ABL postinst scripts (fixes &lt;a href=&quot;https://github.com/armbian/build/issues/10108?ref=blog.armbian.com&quot;&gt;#10108&lt;/a&gt;). by &lt;a href=&quot;https://github.com/rorystandley?ref=blog.armbian.com&quot;&gt;@rorystandley&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10109?ref=blog.armbian.com&quot;&gt;armbian/build#10109&lt;/a&gt;&lt;/li&gt;&lt;li&gt;can: rockchip: add RK3588 CAN support (for kernel v6.18 / v7.1 / v7.2). by &lt;a href=&quot;https://github.com/lch08?ref=blog.armbian.com&quot;&gt;@lch08&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10184?ref=blog.armbian.com&quot;&gt;armbian/build#10184&lt;/a&gt;&lt;/li&gt;&lt;li&gt;ci(board-assets): don&amp;amp;apost check out fork head under pull_request_target. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10194?ref=blog.armbian.com&quot;&gt;armbian/build#10194&lt;/a&gt;&lt;/li&gt;&lt;li&gt;cix-acpi: bump &lt;code&gt;edge&lt;/code&gt; to 7.1.y. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10167?ref=blog.armbian.com&quot;&gt;armbian/build#10167&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Cleanup patches. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10174?ref=blog.armbian.com&quot;&gt;armbian/build#10174&lt;/a&gt;&lt;/li&gt;&lt;li&gt;csc board: NORCO EMB-3531: Do not reset LTE moden. by &lt;a href=&quot;https://github.com/retro98boy?ref=blog.armbian.com&quot;&gt;@retro98boy&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10222?ref=blog.armbian.com&quot;&gt;armbian/build#10222&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docker/framework: build riscv64 images on native runners (trixie, noble). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/docker-armbian-build/pull/34?ref=blog.armbian.com&quot;&gt;armbian/docker-armbian-build#34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docker/framework: generate riscv64 images (trixie, noble, resolute). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/docker-armbian-build/pull/33?ref=blog.armbian.com&quot;&gt;armbian/docker-armbian-build#33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docker/riscv64: fix cross-compiler availability for generate-dockerfile. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9589?ref=blog.armbian.com&quot;&gt;armbian/build#9589&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docker: allow overriding host_arch for foreign-arch Dockerfile generation. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10211?ref=blog.armbian.com&quot;&gt;armbian/build#10211&lt;/a&gt;&lt;/li&gt;&lt;li&gt;docs: refresh README (AI-assisted). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/29?ref=blog.armbian.com&quot;&gt;armbian/ci#29&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Enable memory compaction and RK630 PHY on Rockchip vendor kernels . by &lt;a href=&quot;https://github.com/lukaszsobala?ref=blog.armbian.com&quot;&gt;@lukaszsobala&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10175?ref=blog.armbian.com&quot;&gt;armbian/build#10175&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Enable pwm gpio. by &lt;a href=&quot;https://github.com/frank-f?ref=blog.armbian.com&quot;&gt;@frank-f&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10238?ref=blog.armbian.com&quot;&gt;armbian/build#10238&lt;/a&gt;&lt;/li&gt;&lt;li&gt;extensions/nvidia: per-distro version detection + runtime auto-disable on no-GPU hosts. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9845?ref=blog.armbian.com&quot;&gt;armbian/build#9845&lt;/a&gt;&lt;/li&gt;&lt;li&gt;extensions/radxa-aic8800: use local dir as download cache. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10156?ref=blog.armbian.com&quot;&gt;armbian/build#10156&lt;/a&gt;&lt;/li&gt;&lt;li&gt;extensions/rkusbboot: easy ramboot mainline u-boot on Rockchip devices. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10158?ref=blog.armbian.com&quot;&gt;armbian/build#10158&lt;/a&gt;&lt;/li&gt;&lt;li&gt;feat(extensions): sysrq-serial-trigger + kernel-debug-tiers (on-device kernel debugging via serial console). by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9776?ref=blog.armbian.com&quot;&gt;armbian/build#9776&lt;/a&gt;&lt;/li&gt;&lt;li&gt;feat(flash): keep the success screen when verification is cancelled. by &lt;a href=&quot;https://github.com/SuperKali?ref=blog.armbian.com&quot;&gt;@SuperKali&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/imager/pull/166?ref=blog.armbian.com&quot;&gt;armbian/imager#166&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Fix build for Linux 7.1. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/bcmdhd-dkms/pull/7?ref=blog.armbian.com&quot;&gt;armbian/bcmdhd-dkms#7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix hdmi rx on orangepi5 ultra by adding hpd-gpios. by &lt;a href=&quot;https://github.com/pdapandapda?ref=blog.armbian.com&quot;&gt;@pdapandapda&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10172?ref=blog.armbian.com&quot;&gt;armbian/build#10172&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix Radxa U-Boot ITB dependency. by &lt;a href=&quot;https://github.com/yisding?ref=blog.armbian.com&quot;&gt;@yisding&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10196?ref=blog.armbian.com&quot;&gt;armbian/build#10196&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Fix sata2 target-supply for Orange Pi 3B and Station M2. by &lt;a href=&quot;https://github.com/dust-7?ref=blog.armbian.com&quot;&gt;@dust-7&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10137?ref=blog.armbian.com&quot;&gt;armbian/build#10137&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix the hdmirx HPD patch against kernel6.18 &amp;amp; kernel 7.1. by &lt;a href=&quot;https://github.com/pdapandapda?ref=blog.armbian.com&quot;&gt;@pdapandapda&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10180?ref=blog.armbian.com&quot;&gt;armbian/build#10180&lt;/a&gt;&lt;/li&gt;&lt;li&gt;fix(offline): honor OFFLINE_WORK in git-ref2info and memoize TTL. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9797?ref=blog.armbian.com&quot;&gt;armbian/build#9797&lt;/a&gt;&lt;/li&gt;&lt;li&gt;gha: disable build cronjobs (moved to armbian/ci). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/os/pull/482?ref=blog.armbian.com&quot;&gt;armbian/os#482&lt;/a&gt;&lt;/li&gt;&lt;li&gt;git: match safe.directory literally, not as a regex. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10223?ref=blog.armbian.com&quot;&gt;armbian/build#10223&lt;/a&gt;&lt;/li&gt;&lt;li&gt;git: silence spurious SUBSHELL error annotation from safe.directory check. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10225?ref=blog.armbian.com&quot;&gt;armbian/build#10225&lt;/a&gt;&lt;/li&gt;&lt;li&gt;helios4: bump u-boot to v2026.07. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10183?ref=blog.armbian.com&quot;&gt;armbian/build#10183&lt;/a&gt;&lt;/li&gt;&lt;li&gt;helios4: drop stale u-boot patch dir v2025.10/board_helios4. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10189?ref=blog.armbian.com&quot;&gt;armbian/build#10189&lt;/a&gt;&lt;/li&gt;&lt;li&gt;input: remotectl: rockchip-pwm: prefer dedicated channel-3 IRQ. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/linux-rockchip/pull/503?ref=blog.armbian.com&quot;&gt;armbian/linux-rockchip#503&lt;/a&gt;&lt;/li&gt;&lt;li&gt;k3: sk-am62-lp: shrink R5 SPL to fit SRAM + silence k3 cp noise. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10230?ref=blog.armbian.com&quot;&gt;armbian/build#10230&lt;/a&gt;&lt;/li&gt;&lt;li&gt;luckfox-lyra-ultra-w: Add spidev overlay with 2 CS. by &lt;a href=&quot;https://github.com/vidplace7?ref=blog.armbian.com&quot;&gt;@vidplace7&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/linux-rockchip/pull/505?ref=blog.armbian.com&quot;&gt;armbian/linux-rockchip#505&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mainline: bump &lt;code&gt;bleedingedge&lt;/code&gt; to v7.2-rc3. by &lt;a href=&quot;https://github.com/EvilOlaf?ref=blog.armbian.com&quot;&gt;@EvilOlaf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10181?ref=blog.armbian.com&quot;&gt;armbian/build#10181&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mekotronics-r58x-pro: u-boot: bump to v2026.07. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10232?ref=blog.armbian.com&quot;&gt;armbian/build#10232&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mixtile-blade3: edge: u-boot: fancy it up (lwIP, mbedTLS, efi, btrfs, etc). by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10234?ref=blog.armbian.com&quot;&gt;armbian/build#10234&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mvebu64: modernize EspressoBin/MacchiatoBin firmware (u-boot 2026.07 + TF-A 2.14.0 + A3720 fixes). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10213?ref=blog.armbian.com&quot;&gt;armbian/build#10213&lt;/a&gt;&lt;/li&gt;&lt;li&gt;odroidhc4: u-boot: bump to v2026.07, drop upstreamed patch. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10233?ref=blog.armbian.com&quot;&gt;armbian/build#10233&lt;/a&gt;&lt;/li&gt;&lt;li&gt;odroidm1: bump u-boot to v2026.07. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10201?ref=blog.armbian.com&quot;&gt;armbian/build#10201&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Qidi X6: update to u-boot 2026.07. by &lt;a href=&quot;https://github.com/Shadowrom2020?ref=blog.armbian.com&quot;&gt;@Shadowrom2020&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10228?ref=blog.armbian.com&quot;&gt;armbian/build#10228&lt;/a&gt;&lt;/li&gt;&lt;li&gt;radxa-dragon-q8b: add edge kernel (7.1) target. by &lt;a href=&quot;https://github.com/SuperKali?ref=blog.armbian.com&quot;&gt;@SuperKali&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10215?ref=blog.armbian.com&quot;&gt;armbian/build#10215&lt;/a&gt;&lt;/li&gt;&lt;li&gt;radxa-e52c: bump uboot to v2026.07. by &lt;a href=&quot;https://github.com/okrc?ref=blog.armbian.com&quot;&gt;@okrc&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10135?ref=blog.armbian.com&quot;&gt;armbian/build#10135&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rk3588 es8388 codec silence log. by &lt;a href=&quot;https://github.com/CT1IQI?ref=blog.armbian.com&quot;&gt;@CT1IQI&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10198?ref=blog.armbian.com&quot;&gt;armbian/build#10198&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64-6.18: rework &lt;code&gt;rk3588-0010-fix-clk-divisions&lt;/code&gt; to avoid patching &lt;code&gt;include/linux/math.h&lt;/code&gt;. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10207?ref=blog.armbian.com&quot;&gt;armbian/build#10207&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64-7.2: bleedingedge: enable &lt;code&gt;REALTEK_PHY_HWMON&lt;/code&gt;. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10206?ref=blog.armbian.com&quot;&gt;armbian/build#10206&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rockchip64-7.2: rk3588-mixtile-blade3, many fixes and additions. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10203?ref=blog.armbian.com&quot;&gt;armbian/build#10203&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rootfs-image: move &lt;code&gt;pre_install_distribution_specific&lt;/code&gt; inside &lt;code&gt;install_distribution_specific()&lt;/code&gt;. by &lt;a href=&quot;https://github.com/rpardini?ref=blog.armbian.com&quot;&gt;@rpardini&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10157?ref=blog.armbian.com&quot;&gt;armbian/build#10157&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rootfs: DNS fallback for build-time chroot resolv.conf. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10205?ref=blog.armbian.com&quot;&gt;armbian/build#10205&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rootfs: harden chroot apt against transient fetch failures (retries + fail-fast update). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10202?ref=blog.armbian.com&quot;&gt;armbian/build#10202&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rootfs: pin tar for resolute kernel deb install (all families). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10187?ref=blog.armbian.com&quot;&gt;armbian/build#10187&lt;/a&gt;&lt;/li&gt;&lt;li&gt;rootfs: revert resolute tar pin (&lt;a href=&quot;https://github.com/armbian/build/pull/10187?ref=blog.armbian.com&quot;&gt;#10187&lt;/a&gt;) — fixed upstream. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10209?ref=blog.armbian.com&quot;&gt;armbian/build#10209&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: drop stale amlogic FIP source caches. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/28?ref=blog.armbian.com&quot;&gt;armbian/actions#28&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: ensure &lt;code&gt;tree&lt;/code&gt; is installed on the host. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/27?ref=blog.armbian.com&quot;&gt;armbian/actions#27&lt;/a&gt;&lt;/li&gt;&lt;li&gt;runner-clean: register qemu binfmt handlers on the host. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/actions/pull/26?ref=blog.armbian.com&quot;&gt;armbian/actions#26&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sc8280xp: fix wrong LINUXCONFIG name for the sc8280xp branch. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10227?ref=blog.armbian.com&quot;&gt;armbian/build#10227&lt;/a&gt;&lt;/li&gt;&lt;li&gt;SpacemiT: Defconfig: Enable CONFIG_PWM_PXA. by &lt;a href=&quot;https://github.com/fkpwolf?ref=blog.armbian.com&quot;&gt;@fkpwolf&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10182?ref=blog.armbian.com&quot;&gt;armbian/build#10182&lt;/a&gt;&lt;/li&gt;&lt;li&gt;sun55iw3-syterkit: skip TF-A build (SyterKit is self-contained). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10214?ref=blog.armbian.com&quot;&gt;armbian/build#10214&lt;/a&gt;&lt;/li&gt;&lt;li&gt;targets: drop resolute from riscv64 userspace builds (RVA23 vs RV64GC). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/27?ref=blog.armbian.com&quot;&gt;armbian/ci#27&lt;/a&gt;&lt;/li&gt;&lt;li&gt;turing-rk1: bump u-boot v2024.04 → v2026.07 (fix SWIG 4.3 build break on trixie). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10216?ref=blog.armbian.com&quot;&gt;armbian/build#10216&lt;/a&gt;&lt;/li&gt;&lt;li&gt;u-boot: bump 2026.07-rc4/rc5 pins to final v2026.07. by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10186?ref=blog.armbian.com&quot;&gt;armbian/build#10186&lt;/a&gt;&lt;/li&gt;&lt;li&gt;u-boot: don&amp;amp;apost error on implicit declarations (gcc ≥ 14 / trixie). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10221?ref=blog.armbian.com&quot;&gt;armbian/build#10221&lt;/a&gt;&lt;/li&gt;&lt;li&gt;u-boot: fix old pylibfdt build against SWIG ≥ 4.3 (trixie). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10217?ref=blog.armbian.com&quot;&gt;armbian/build#10217&lt;/a&gt;&lt;/li&gt;&lt;li&gt;u-boot: sync btrfs zstd short-extent fix into shadowed board/pool copies. by &lt;a href=&quot;https://github.com/iav?ref=blog.armbian.com&quot;&gt;@iav&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10208?ref=blog.armbian.com&quot;&gt;armbian/build#10208&lt;/a&gt;&lt;/li&gt;&lt;li&gt;uboot: demote int-conversion &amp;amp; incompatible-pointer-types to warnings (gcc 14). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10224?ref=blog.armbian.com&quot;&gt;armbian/build#10224&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Up rtw8822b to v30.20.0. by &lt;a href=&quot;https://github.com/farwayer?ref=blog.armbian.com&quot;&gt;@farwayer&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/firmware/pull/135?ref=blog.armbian.com&quot;&gt;armbian/firmware#135&lt;/a&gt;&lt;/li&gt;&lt;li&gt;update Helios4 BSP postinst. by &lt;a href=&quot;https://github.com/leggewie?ref=blog.armbian.com&quot;&gt;@leggewie&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/9065?ref=blog.armbian.com&quot;&gt;armbian/build#9065&lt;/a&gt;&lt;/li&gt;&lt;li&gt;workflows: add Delete Old Releases (copied from os). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/26?ref=blog.armbian.com&quot;&gt;armbian/ci#26&lt;/a&gt;&lt;/li&gt;&lt;li&gt;workflows: enable build cronjobs (taking over from armbian/os). by &lt;a href=&quot;https://github.com/igorpecovnik?ref=blog.armbian.com&quot;&gt;@igorpecovnik&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/ci/pull/25?ref=blog.armbian.com&quot;&gt;armbian/ci#25&lt;/a&gt;&lt;/li&gt;&lt;li&gt;youyeetoo-r1-v3: bump mainline u-boot to v2026.04. by &lt;a href=&quot;https://github.com/SuperKali?ref=blog.armbian.com&quot;&gt;@SuperKali&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10219?ref=blog.armbian.com&quot;&gt;armbian/build#10219&lt;/a&gt;&lt;/li&gt;&lt;li&gt;youyeetoo-r1-v3: promote to standard support and name audio outputs. by &lt;a href=&quot;https://github.com/SuperKali?ref=blog.armbian.com&quot;&gt;@SuperKali&lt;/a&gt; in &lt;a href=&quot;https://github.com/armbian/build/pull/10220?ref=blog.armbian.com&quot;&gt;armbian/build#10220&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded> 
	<dc:date>2026-07-20T16:56:55+00:00</dc:date>
	<dc:creator>Michael Robinson</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68813">
	<title>GreenboneOS: Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor</title>
	<link>https://www.greenbone.net/en/blog/openvas-scan-nutanix-ahv-hypervisor-support/</link>
     <content:encoded>Users appreciate when software can easily integrate into their existing IT environment. For vendors, this means supporting a cross-platform mix of operating systems and infrastructure. Greenbone is excited to expand our virtualization platform support, bringing Nutanix AHV into our family of supported hypervisors. This addition adds flexibility for deploying OPENVAS SCAN and extends Greenbone’s already […]</content:encoded> 
	<dc:date>2026-07-20T12:29:33+00:00</dc:date>
	<dc:creator>Greenbone AG</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39493">
	<title>Deepin: (中文) 应用商店来了音视频神器——小丸工具箱Linux版上架！</title>
	<link>https://www.deepin.org/en/appstore-marukotoolbox-rewrite-linux/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-17T02:30:53+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68767">
	<title>GreenboneOS: CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway</title>
	<link>https://www.greenbone.net/en/blog/citrix-netscaler-ctx696604-vulnerabilities/</link>
     <content:encoded>Citrix security advisory CTX696604 covers six vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. NetScaler Gateway is used to authenticate remote users and connect them to internal network resources, and NetScaler ADC load balancing is a core feature used to distribute requests and improve availability. The highest-risk issues in the bulletin can lead to memory […]</content:encoded> 
	<dc:date>2026-07-16T13:43:26+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68744">
	<title>GreenboneOS: BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access</title>
	<link>https://www.greenbone.net/en/blog/beyondtrust-bt26-03-vulnerabilities-rs-pra/</link>
     <content:encoded>BeyondTrust advisory BT26-03, issued on July 6th, 2026, describes multiple new vulnerabilities in BeyondTrust Remote Support (RS) and BeyondTrust Privileged Remote Access (PRA). The vulnerabilities include two critical flaws exploitable without authentication and additional high-severity issues in network communication and web application components. All the flaws require specific configurations for exploitation, but BeyondTrust has not […]</content:encoded> 
	<dc:date>2026-07-15T08:59:03+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 
<item rdf:about="https://www.deepin.org/?p=39454">
	<title>Deepin: (中文) 多款主流 Coding Agent 组团登陆 deepin 应用商店！</title>
	<link>https://www.deepin.org/en/appstore-coding-agent/</link>
     <content:encoded>Sorry, this entry is only available in 中文.</content:encoded> 
	<dc:date>2026-07-15T01:43:26+00:00</dc:date>
	<dc:creator>xiaofei</dc:creator>
</item> 
<item rdf:about="https://sourceforge.net2cde7ff6f1917ac227d44cdf6a223f9bd43011af">
	<title>Clonezilla live: Stable Clonezilla live 3.3.3-15 Released</title>
	<link>https://sourceforge.net/p/clonezilla/news/2026/07/stable-clonezilla-live-333-15-released/</link>
     <content:encoded>&lt;div class=&quot;markdown_content&quot;&gt;&lt;h1 id=&quot;h-this-release-of-clonezilla-live-333-15-includes-major-enhancements-and-bug-fixes&quot;&gt;This release of Clonezilla live (3.3.3-15) includes major enhancements and bug fixes.&lt;/h1&gt;
&lt;h2 id=&quot;h-enhancements-and-changes-since-332-31&quot;&gt;ENHANCEMENTS AND CHANGES SINCE 3.3.2-31&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The underlying GNU/Linux operating system was upgraded. This release is based on the Debian Sid repository (as of 2026/Jul/05).&lt;/li&gt;
&lt;li&gt;The Linux kernel was updated to 7.0.14-1.&lt;/li&gt;
&lt;li&gt;Added package network-manager-tui in the live system. Thanks to Sammie Lee Walker.&lt;/li&gt;
&lt;li&gt;Made the variable supp_boot_param_ocs_live_extra available to be used for netboot clients. Thanks to haifeng.&lt;/li&gt;
&lt;li&gt;ocs-onthefly: Added Reverse-Connection Network Cloning. Thanks to Hell Gate for this suggestion.&lt;/li&gt;
&lt;li&gt;Introduced new programs: cnvt-ocsiso-qcow2 &amp;amp; ocs-check-initrd-module.&lt;/li&gt;
&lt;li&gt;Improved check_source_and_target_type in ocs-onthefly so that it can deal with multiple disks which have existing partitions.&lt;/li&gt;
&lt;li&gt;Implemented a better way for function disable_sudo_use_pty in ocs-live-hook-functions.&lt;/li&gt;
&lt;li&gt;Memtest86+ was updated to 8.10.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;h-bug-fixes&quot;&gt;BUG FIXES&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Wrong result when using ntfsclone to save a partition as Ctrl-C is pressed. Thanks to nicdai for reporting this issue.&lt;/li&gt;
&lt;li&gt;Fixed: protected device name &quot;ask_user&quot; in ocs-onthefly. Ref: &lt;a href=&quot;https://sourceforge.net/p/clonezilla/bugs/440&quot;&gt;https://sourceforge.net/p/clonezilla/bugs/440&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content:encoded> 
	<dc:date>2026-07-14T12:54:46+00:00</dc:date>
	<dc:creator>Steven Shiau</dc:creator>
</item> 
<item rdf:about="https://www.qubes-os.org/news/2026/07/14/xsas-released-on-2026-07-14/">
	<title>Qubes: XSAs released on 2026-07-14</title>
	<link>https://www.qubes-os.org/news/2026/07/14/xsas-released-on-2026-07-14/</link>
     <content:encoded>&lt;p&gt;The &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; has released one or more &lt;a href=&quot;https://xenbits.xen.org/xsa/&quot;&gt;Xen security advisories (XSAs)&lt;/a&gt;.
The security of Qubes OS is &lt;strong&gt;not&lt;/strong&gt; affected.&lt;/p&gt;

&lt;h2 id=&quot;xsas-that-do-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do affect&lt;/strong&gt; the security of Qubes OS:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;(none)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;xsas-that-do-not-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO NOT affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do not affect&lt;/strong&gt; the security of Qubes OS, and no user action is necessary:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-498.html&quot;&gt;XSA-498&lt;/a&gt;: Qubes OS does not use XAPI.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;about-this-announcement&quot;&gt;About this announcement&lt;/h2&gt;

&lt;p&gt;Qubes OS uses the &lt;a href=&quot;https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview&quot;&gt;Xen hypervisor&lt;/a&gt; as part of its &lt;a href=&quot;https://doc.qubes-os.org/en/latest/developer/system/architecture.html&quot;&gt;architecture&lt;/a&gt;. When the &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a &lt;a href=&quot;https://xenproject.org/developers/security-policy/&quot;&gt;Xen security advisory (XSA)&lt;/a&gt;. Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a &lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Qubes security bulletin (QSB)&lt;/a&gt;. (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only &lt;em&gt;positive&lt;/em&gt; confirmation that certain XSAs &lt;em&gt;do&lt;/em&gt; affect the security of Qubes OS. QSBs cannot provide &lt;em&gt;negative&lt;/em&gt; confirmation that other XSAs do &lt;em&gt;not&lt;/em&gt; affect the security of Qubes OS. Therefore, we also maintain an &lt;a href=&quot;https://www.qubes-os.org/security/xsa/&quot;&gt;XSA tracker&lt;/a&gt;, which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.&lt;/p&gt;</content:encoded> 
	<dc:date>2026-07-14T00:00:00+00:00</dc:date>
	<dc:creator>Qubes</dc:creator>
</item> 
<item rdf:about="https://www.greenbone.net/?p=68653">
	<title>GreenboneOS: CVE-2026-48282: CVSS 10 Flaw in Adobe ColdFusion Is Actively Exploited and More</title>
	<link>https://www.greenbone.net/en/blog/cve-2026-48282-adobe-coldfusion-actively-exploited/</link>
     <content:encoded>CVE-2026-48282 (CVSS 10) is a critical path traversal vulnerability [CWE-22] in Adobe ColdFusion. According to Adobe’s Security Bulletin [APSB26-68], the issue affects ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. Exploitation is network-based, which increases the risk to exposed ColdFusion instances, and exploitation does not require authentication. A successful attack […]</content:encoded> 
	<dc:date>2026-07-13T12:55:49+00:00</dc:date>
	<dc:creator>Joseph Lee</dc:creator>
</item> 

</rdf:RDF>
