DEV Community

ipt's Open Source Monthly Updates September 2026: OpenBao, Jev, GitLab, OpenTofu, Valkey, and the CRA

Welcome back to our Open Source Monthly Updates!

September brought some interesting developments around technologies we use regularly: OpenBao is becoming increasingly interesting for regulated environments, OpenTofu is experimenting with reusable language primitives, and Valkey continues to diverge technically from Redis.

There was also one AI announcement worth looking at, even though the model itself is not open source.

OpenBao 2.7: Enterprise secrets management keeps getting better

Last month, we looked at namespace sealing in OpenBao 2.6. Version 2.7 continues in much the same direction.

The most interesting addition is External Keys. OpenBao's PKI and Transit engines can now perform cryptographic operations using keys stored in external KMS or HSM systems. OpenBao controls policies and APIs, while the private key can remain inside a separately managed cryptographic boundary.

OpenBao 2.7 also introduces Control Groups, allowing policies to require approval from another identity before executing sensitive operations. Think four-eyes approval for accessing a particularly sensitive secret or issuing a certificate.

Add PostgreSQL-backed read scaling, post-quantum cryptographic primitives, and a collection of security fixes, and OpenBao is becoming increasingly difficult to dismiss as merely a Vault fork.

The upgrade needs some care, though: several previously built-in integrations, including PKCS#11 and cloud KMS seals, have moved to external plugins.

More information can be found on OpenBoa's 2.7.x official release notes.

Jev: What if an AI model did not generate text?

A lot of AI application logic currently works like this: send some context to an LLM, ask it to make a decision, get text or JSON back, parse it, and continue.

TypeSafe AI's Jev, released on September 15, takes a different approach.

Jev does not generate arbitrary text. It takes application state and typed questions and returns decisions with probabilities. TypeSafe describes this as a System One Model: essentially a model designed specifically for fast classification and decision-making rather than conversation.

That could be interesting for tool selection, RAG filtering, routing, policy decisions, and other places where we currently use a general-purpose LLM despite not actually needing language generation.

There is one rather important issue for an open-source update: Jev is proprietary.

What makes the development relevant here is how quickly the idea escaped into the open ecosystem. Kev, for example, is an Apache-2.0 research implementation built on Qwen that reproduces the basic decision-model approach and implements TypeSafe's public System One API. Its first prototype appeared only two days after Jev.

It is far too early to know whether "decision models" will become their own category. But the architectural idea is interesting: maybe we do not need an increasingly large generative model for every fuzzy decision inside an application.

You can find the Kev model cards on GitHub.

GitLab: Patch this one

GitLab released critical security updates on September 10 fixing CVE-2026-85706, a path-traversal vulnerability that can allow an unauthenticated attacker to read arbitrary files from an affected self-managed GitLab server.

More importantly, exploitation has already been observed.

GitLab strongly recommends that affected self-managed installations upgrade immediately. Fixes are available across several maintained release lines.

GitLab is an especially unpleasant place for arbitrary file access: it commonly contains source code, CI/CD configuration, credentials, and integrations into the rest of the software supply chain.

Self-hosting infrastructure gives you control and can be an important part of a sovereignty strategy. It also means that incidents like this become your responsibility.

OpenTofu 1.13: Reusing logic without another module

Terraform-style modules are great for reusing infrastructure.

They are less elegant when all you want to reuse is logic.

OpenTofu 1.13 introduces experimental Symbol Libraries. They can contain reusable functions, types, and constants without defining infrastructure resources themselves.

A platform team could, for example, share naming conventions, validation functions, or organization-specific types without hiding them inside an artificial infrastructure module.

That sounds like a relatively small feature, but for larger IaC estates it could remove quite a bit of duplicated HCL.

The important word is experimental. OpenTofu explicitly wants users to test the feature before it is stabilized, potentially with 1.14.

That makes it an interesting candidate for a small internal experiment rather than something to standardize on immediately.

Valkey 9.2: Changing more than the name

Valkey 9.2 reached its first release candidate in September.

The most interesting addition operationally is forkless RDB snapshotting, providing an alternative to the traditional fork-based persistence mechanism. For large-memory instances, avoiding fork() can potentially remove some unpleasant behaviour around memory pressure and latency.

Valkey is also replacing the skiplist used for large sorted sets with a B+ tree implementation. The project reports lower per-item memory overhead as well as substantially faster rank lookups and iteration in its benchmarks. Those numbers still deserve validation against real workloads.

There are plenty of smaller improvements too, including ACL roles, hot-key detection, replication throttling, and multiple TLS server certificates.

Because this is still an RC, there is little reason to rush it into production. But it is becoming increasingly clear that Valkey is not simply preserving the Redis codebase after the licensing split. It is developing its own technical direction. The release plan states this should become GA in November.

CRA: Vulnerability reporting is now operational

On September 11, another part of the EU Cyber Resilience Act became real rather than theoretical.

Manufacturers of covered products with digital elements must now report certain actively exploited vulnerabilities and severe security incidents using ENISA's new Single Reporting Platform.

For software engineering teams, the interesting consequence is dependency visibility.

If a vulnerability appears in an open-source library, organizations need to know which shipped products contain it, whether affected versions are deployed, who owns the response, and when the organization became aware of the problem.

Suddenly, having an accurate SBOM and a functional vulnerability-management process matters for more than producing a nice security dashboard. If your company is bound by the CRA and you do not have these kinds of controls in place yet, the time has come to act (quickly).

Keycloak: Another month, another security update

August's most urgent story was Keycloak's unauthenticated account-takeover vulnerability.

September brought another security-heavy Keycloak release.

Keycloak 26.7.4 fixes six additional CVEs. The most notable include an unauthenticated denial-of-service vulnerability involving unbounded locale caching and a privilege-escalation issue in the impersonation functionality.

This pattern of rapid security fixes is worth paying attention to. If Keycloak is part of your critical authentication infrastructure, a quarterly patching process is increasingly difficult to justify.

Projects we're watching

Alongside the main updates, here are three open-source projects worth keeping an eye on.

Karmada reached CNCF Graduated status in September. It provides Kubernetes-native scheduling and placement across multiple clusters and clouds. For organizations pursuing hybrid-cloud or sovereign architectures, the interesting part is not simply multi-cluster management: policies can express preferred and fallback placement across different infrastructure environments.

PostgreSQL Migrator reached its first stable 1.0 release. The Go-based tool helps analyze and migrate Oracle and MySQL/MariaDB databases to PostgreSQL. Its current conversion coverage is still incomplete, particularly for the difficult procedural parts of Oracle estates, but an open-source migration stack is strategically interesting wherever PostgreSQL is being considered as part of a database-independence initiative (aka moving away from Oracle).

And wasmCloud continues to move quickly. Releases 2.9 and 2.10 brought enforced memory limits, improved Kubernetes lifecycle behavior, stronger plugin egress controls, standards-compliant OpenTelemetry configuration, and mTLS client identities. We are particularly interested in wasmCloud because of our own contributions to the project. The technical progress is encouraging, although the rapid release cadence also means it remains a technology we would experiment with before making it a default platform choice.

September's common theme is perhaps that open source is moving further into the boring parts of enterprise software.

And that is a compliment.

Four-eyes authorization, vulnerability reporting, ACL management, cryptographic key custody, predictable persistence, and structured AI decisions are not the things that usually make flashy demos.

They are the things that eventually determine whether a technology can survive outside one.

Last but definitely not least: the Open Source Summit Europe will take place next week! We will inform you in the next edition about what was spoken about at the summit.

Top comments (0)