A Monday brief for people who run things

Your stack changed. Read the diff.

Pick the tools you run. Once a week you get one short brief: what shipped, what breaks, what's dying, what's now paid. Every line links to the source.

Get your first brief How it reads Open beta, no account needed.
Live · the last 7 days for Kubernetes, Terraform, Helm, Argo CD, PostgreSQL, GitHub Actions 30 changes · checked 23:33 UTC
GitHub ActionsSecurityWed, Sep 9
npm extends recovery-code security holds to all accounts
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to...
Kubernetes1.34End of lifeFri, Sep 11
Kubernetes 1.34 reaches end of life on 2026-10-27
Kubernetes 1.34 reaches end of life on 2026-10-27. Released 2025-08-27, latest patch 1.34.11 on 2026-08-20. Active support: 2026-08-27. Source: endoflife.date/kubernetes.
PostgreSQL14End of lifeFri, Sep 11
PostgreSQL 14 reaches end of life on 2026-11-12
PostgreSQL 14 reaches end of life on 2026-11-12. Released 2021-09-30, latest patch 14.24 on 2026-08-10. Active support: unknown. Source: endoflife.date/postgresql.
GitHub Actions22.04DeprecatedFri, Sep 11
Ubuntu 22.04 (20260907) Image Update
Announcements [Ubuntu] PostgreSQL is now available on the Ubuntu Arm64 images [Ubuntu] Podman will be downgraded on Ubuntu 22.04 and 24.04 runner images [Ubuntu] The...
GitHub Actions24.04DeprecatedFri, Sep 11
Ubuntu 24.04 (20260907) Image Update
Announcements [Ubuntu] PostgreSQL is now available on the Ubuntu Arm64 images [Ubuntu] Podman will be downgraded on Ubuntu 22.04 and 24.04 runner images [Ubuntu] The...
GitHub Actions26.04DeprecatedFri, Sep 11
Ubuntu 26.04 Arm64 (20260907) Image Update
Announcements [Ubuntu] PostgreSQL is now available on the Ubuntu Arm64 images [Ubuntu] Podman will be downgraded on Ubuntu 22.04 and 24.04 runner images [Ubuntu] The...
Read from the vendors' own feeds. Nothing scraped. See it for your stack →
01

Feeds tell you a number went up. The brief tells you what moved.

Every change is read once, given a type, summarized in two sentences and a one-line action. The ones that can hurt you sit at the top and don't wait for Monday.

  • 01Breaking

    Removed flags, renamed resources, upgrades that need hands. Flagged from the notes, not guessed from the version number.

  • 02Security

    CVEs and advisories with the fixed version and whether it takes a login to exploit.

  • 03End of life

    Support windows and retirements. The clock starts the day it's announced, not the day it expires.

  • 04License and pricing

    License switches, tier changes, price rises. Nobody publishes a feed for these, so we watch.

  • 05Changed, deprecated

    Defaults that moved and removals with a date on them.

  • 06Releases and fixes

    New minors and patches in two lines. Filed under everything else so they never bury the rest.

02

Only what the vendors publish for machines.

No page scraping, no guessing from screenshots of a keynote. If a vendor has no feed, we say so instead of pretending.

Where it comes from

  • GitHub releases and vendor changelogs
  • OSV and vendor security advisories
  • endoflife.date support windows
  • HashiCorp's release API, license class included
  • Hacker News, for what people are actually arguing about

Where it goes

Email or a Slack channel, Monday morning in your time zone. Daily if you insist. Breaking changes and CVEs that match your stack go out the moment they're seen.

Who reads the raw notes so you don't have to

A model, once per change, for everyone. It writes two sentences and an action, and it never gets to invent a version or a CVE that isn't in the source.

AWSAWS CLIAlertmanagerAnsibleApache KafkaArgo CDArgo RolloutsAzureAzure CLICalicoCiliumCloudflareConsulCrossplaneDockerDocker ComposeEnvoyExternal SecretsExternalDNSFluent BitFluxGitHub ActionsGitHub CLIGitLabGoogle CloudGrafanaHelmIstioJenkinsKEDAKarpenterKubernetesKustomizeLinkerdLokiNGINXNode.jsNomadOpenSearchOpenTelemetryOpenTofuPackerPodmanPostgreSQLPrometheusPulumiRabbitMQRedisTailscaleTerraformTraefikTrivyValkeyVaultVectorVeleroVictoriaMetricscert-managereksctlgcloud CLIjqk3sk9sn8nyq
03

Free. Actually free.

Stackdiff is one person's project and it runs on one small server. It costs about $15 a month, so it's free while it's small and it stays free for individuals. No tiers, no trial that expires, no card.

If it saves you one bad upgrade, you can buy the next month of server time.

04

Fair questions.

Why weekly and not daily?

Because a daily everything-email gets unsubscribed. Most of what vendors ship is routine. Weekly is the default, daily is a switch, and anything that can break you or matches a CVE goes out right away.

Is the summary written by an AI?

Yes. Once per change, for everyone, into a fixed shape: what changed, version, breaking or not, severity, link. Two factual sentences that always point at the vendor's own text. We never republish release notes.

We already run Renovate and Dependabot.

Keep them. They open pull requests for the dependencies in a repo. They don't tell you a managed service changed its pricing, a runner image is retiring, or a keynote just announced the thing you were about to build. This is for the stack, not the lockfile.

What about my data?

Your email, your vendor list, your delivery settings, an encrypted Slack webhook if you add one. No trackers. Delete it with one email. The whole privacy page fits on a screen.