Pick the tools you run. Once a week you get one short brief: what shipped, what breaks, what's dying, what's now paid. Every line links to the source.
Every change is read once, given a type, summarized in two sentences and a one-line action. The ones that can hurt you sit at the top and don't wait for Monday.
Removed flags, renamed resources, upgrades that need hands. Flagged from the notes, not guessed from the version number.
CVEs and advisories with the fixed version and whether it takes a login to exploit.
Support windows and retirements. The clock starts the day it's announced, not the day it expires.
License switches, tier changes, price rises. Nobody publishes a feed for these, so we watch.
Defaults that moved and removals with a date on them.
New minors and patches in two lines. Filed under everything else so they never bury the rest.
No page scraping, no guessing from screenshots of a keynote. If a vendor has no feed, we say so instead of pretending.
Email or a Slack channel, Monday morning in your time zone. Daily if you insist. Breaking changes and CVEs that match your stack go out the moment they're seen.
A model, once per change, for everyone. It writes two sentences and an action, and it never gets to invent a version or a CVE that isn't in the source.
Stackdiff is one person's project and it runs on one small server. It costs about $15 a month, so it's free while it's small and it stays free for individuals. No tiers, no trial that expires, no card.
If it saves you one bad upgrade, you can buy the next month of server time.
Because a daily everything-email gets unsubscribed. Most of what vendors ship is routine. Weekly is the default, daily is a switch, and anything that can break you or matches a CVE goes out right away.
Yes. Once per change, for everyone, into a fixed shape: what changed, version, breaking or not, severity, link. Two factual sentences that always point at the vendor's own text. We never republish release notes.
Keep them. They open pull requests for the dependencies in a repo. They don't tell you a managed service changed its pricing, a runner image is retiring, or a keynote just announced the thing you were about to build. This is for the stack, not the lockfile.
Your email, your vendor list, your delivery settings, an encrypted Slack webhook if you add one. No trackers. Delete it with one email. The whole privacy page fits on a screen.