Linux
LinuxFr.org
Présentation de SlyOS, un système basé sur Arch linux équipé d'OpenRC, ReGreet et niri 02/09

Arch Linux est une distribution très connue pour être une bonne base permettant de créer son propre système Linux personnalisé de fond en comble. La possibilité d’y ajouter des logiciels libres peu connus du grand public via l' AUR est l’une des grandes forces d’Arch Linux.

J’ai donc une vision personnelle assez précise du bureau Linux idéal, et je souhaite la partager ici en vous présentant un projet sur lequel je travaille depuis un peu moins d’un an, presque non-stop. Ma propre distribution Linux : SlyOS, un système d'exploitation libre distribué sous licence GPLv3.

Par exemple, voici quelques logiciels disponibles dans l'AUR : DeaDBeeF, Cine, Warehouse, Carburetor, …

Arch Linux est aussi une distribution valorisée par son choix presque illimité d'environnements de bureau. En effet, on peut prendre l'exemple de mon expérience personnelle sur ce point.

J’ai tout d'abord commencé par découvrir GNOME. Son interface m’a immédiatement convaincu et il reste aujourd’hui l’un de mes environnements de bureau préférés. La principale réserve que j’ai à son sujet concerne sa dépendance trop marquée à plusieurs composants de systemd (j’expliquerai plus tard dans la dépêche ce qui me tracasse vraiment à ce sujet).

J’ai ensuite essayé plusieurs environnements de bureau moins répandus, notamment Pantheon. Je reste particulièrement attaché à son interface, mais j’ai fini par l’abandonner en raison de bugs que j’ai rencontrés avec le compositeur Gala, ainsi que des difficultés liées à la transition de X11 vers Wayland. Cette transition a notamment retiré Plank, que j’appréciais beaucoup, sans vraiment lui apporter de remplaçant…

Ou encore moins connu : herbstluftwm que j'aimais beaucoup mais que j'ai fini par abandonner aussi à cause du manque d'outils de personnalisation sur X11 pour un gestionnaire de fenêtre si minimal.

J'ai aussi testé plein d'autres gestionnaires de fenêtre et de d'environnements de bureau tels que Cinnamon, Xfce, Hyprland, Fluxbox, LXQt, MATE, Sway, IceWM

Avec le temps, j'ai façonné quelques opinions sur les différentes options que nous propose la communauté. Par exemple, cela peut en affecter certains, mais j’essaie d’éviter Qt au maximum et de privilégier GTK. Ma position concerne principalement le modèle économique de Qt : je ne reproche pas à un projet libre de chercher à se financer, mais Qt repose notamment sur les revenus provenant de logiciels propriétaires et de licences commerciales (proposant des offres payantes sur son site web). Je préfère donc soutenir des projets qui privilégient d’autres modèles, comme les dons, à l’image de ce qui existe autour de GTK. Ma position peut paraître controversée, notamment parce que l’écosystème Linux dépend lui aussi largement de grandes entreprises (comme Google, ou même Microsoft qui détient GitHub). Je ne prétends donc pas pouvoir éviter toute dépendance de ce type, mais j’essaie, autant que possible, de privilégier des logiciels et des projets capables de subsister sans être directement financés par le logiciel propriétaire.

De même, je n’aime pas vraiment systemd car c'est de plus en plus un programme qui obtient le monopole, avec une étendue de fonctionnalités et une complexité qui s'éloignent du principe KISS. Surtout que récemment, systemd a été au cœur de débats controversés, notamment à travers une proposition de vérification de l’âge intégrée directement à celui-ci. Le problème n’est pas uniquement l’existence de ce champ optionnel (birthDate), mais le fait que systemd puisse devenir un point central pour intégrer ce type de mécanisme à l’avenir. C'est pourquoi je préfère limiter les composants centraux aux fonctions dont le système a réellement besoin.

Cette problématique de vérification d'âge ne se limite d'ailleurs pas à systemd : le plus gros problème actuel est aussi xdg-desktop-portal. Mais il est à l'heure actuelle compliqué de changer cela, puisque xdg-desktop-portal est une dépendance presque cruciale dans Arch Linux. Un paquet alternatif contenant un patch pourrait être envisageable dans le dépôt de SlyOS via notamment l'alternative de xdg-desktop-portal Ageless Linux, mais je n'ai pas vraiment le temps d'accomplir cela pour l'instant.

J'ai dû parfois remettre en question certaines de mes opinions comme ma préférence à X11. Cela a par exemple opéré quand j'ai découvert niri et la stabilité et fluidité de Wayland nettement supérieure à X11.


SlyOS est basé sur Arch Linux et construit à l’aide d’archiso. Le projet a commencé comme une expérience personnelle pour en apprendre davantage sur Linux. Je me suis rendu compte par la suite qu’il y avait un réel intérêt à proposer ma vision du bureau Linux parfait, car je ne l’avais étrangement vue nulle part ailleurs (par défaut dans un système d'exploitation).

Je sais que les concepts revendiqués par une distribution peuvent paraître flous ou consensuels (moderne, léger, simple à utiliser, intuitive, personnalisable, performant, stable, respectant le principe KISS), mais dans SlyOS, chacun de ces principes correspond à des choix concrets et justifiés qui permettent à SlyOS d'être une distribution :

  • Moderne : SlyOS propose niri, un gestionnaire de fenêtres entièrement basé sur Wayland, relativement récent, qui a déjà fait ses preuves (notamment par sa popularité en croissance exponentielle) et qui bénéficie d’un développement actif.

  • Légère : la version minimale de SlyOS contient moins de 700 paquets, tandis que la version complète en contient moins de 850. Les ISO sont nettement plus légères que celles de nombreuses distributions x86_64, réduisant les composants susceptibles de poser problème, sans pour autant supprimer les fonctionnalités essentielles.

  • Simple d’utilisation et intuitive : SlyOS propose un programme d’accueil dès le live ou après l'installation, présentant les raccourcis principaux. Le système peut être utilisé sans ligne de commande grâce à Pamac. Le bureau minimal et l'accès aux paramètres permettent à un débutant de prendre le système en main rapidement.

  • Performante et stable : SlyOS utilise le noyau linux-cachyos-lts pour un bon compromis performances/stabilité. La consommation de RAM au démarrage est très basse grâce à un nombre limité de services en arrière-plan grâce à l'esprit minimaliste de SlyOS.

  • Personnalisable : SlyOS s’appuie sur des outils Wayland comme Ironbar, Wofi, Hyprlock ou Vibepanel. Ils offrent un environnement complet tout en laissant une grande liberté de modification (ils peuvent être désinstallés et remplacés). Le choix de niri facilite également cette personnalisation profonde puisque largement reconnu dans le domaine du "Rice".

  • Respectueuse de la vie privée : remplacer systemd par OpenRC est une première marche vers une meilleure protection de la vie privée dans un système Linux. De plus, SlyOS contient LibreWolf, un navigateur axé sur la vie privée bloquant le pistage, ainsi que les extensions uBlock Origin (bloqueur de pubs et traqueurs efficace) et Decentraleyes (empêche le suivi par les CDN en servant les ressources localement). Il intègre aussi le DNS Mullvad Base qui chiffre vos requêtes DNS pour empêcher les écoutes et les fuites de données vers votre FAI.

  • Suivre le principe KISS en évitant systemd (plus d'informations ici) : SlyOS utilise OpenRC, un système d'initialisation qui suit une approche plus modulaire et plus proche du principe KISS que systemd, régulièrement critiqué pour son poids et sa complexité. Ce choix permet d'éviter de renforcer la position dominante de systemd tout en limitant les risques de dérive (comme l'intégration d'un champ birthDate).

À ses débuts, la distribution ne respectait pas entièrement tous ces critères. Elle utilisait GNOME / MATE, avec systemd ainsi que le noyau linux-cachyos-lts.

La distribution ressemblait à ceci à ses débuts, dans sa version 0.1 « Dxtrus » (pour "dexterous" en anglais) :

Depuis, le projet a considérablement évolué et est progressivement devenu un système plus complet et abouti, illustrant concrètement la direction prise par SlyOS. La version 0.2 « Invativ » (pour "innovative" en anglais) utilise désormais :

  • niri comme gestionnaire de fenêtres
  • OpenRC comme système d’initialisation
  • ReGreet, une interface de connexion en GTK4 écrite en Rust pour greetd
  • Le noyau linux-cachyos-lts
  • Plymouth pour afficher un écran graphique lors du démarrage et de l’arrêt du système

Voici à quoi ressemble la distribution depuis :

La distribution inclut également un centre de contrôle appelé Thymbr, qui permet de configurer de nombreux aspects du système depuis une interface centralisée. Cela rend SlyOS bien plus intuitif et simple d’utilisation, bien que le caractère intuitif se juge surtout à l'utilisation.

Le site web du projet est disponible ici

Je vous conseille d’y jeter un coup d’œil. Le site propose une version française et fournit des explications plus approfondies sur le projet, notamment à travers les principes présentés sur la page d’accueil ainsi que la FAQ, accessible dans la catégorie « Aide ». Le meilleur moyen de se faire une opinion reste de tester SlyOS, par exemple dans une machine virtuelle.

La configuration archiso est disponible sur Codeberg : https://codeberg.org/Minaucro/SlyOS

Je travaille à rendre SlyOS pratique, optimisé, simple et performant, selon ma propre vision d’un système d’exploitation Linux destiné aux ordinateurs de bureau. Le projet est encore en développement, mais il est déjà suffisamment mature pour être testé et utilisé au quotidien.

Merci d’avoir pris le temps de me lire.

SlyOS a été créé par Minaucro (slyos@minaucro.fr).

Télécharger ce contenu au format EPUB

Commentaires : voir le flux Atom ouvrir dans le navigateur

Revue de presse de l’April pour la semaine 35 de l’année 2026 01/09

Cette revue de presse sur Internet fait partie du travail de veille mené par l’April dans le cadre de son action de défense et de promotion du logiciel libre. Les positions exposées dans les articles sont celles de leurs auteurs et ne rejoignent pas forcément celles de l’April.

[Basta!] «Interdire l'IA»: des développeurs de logiciels libres rejettent l'intelligence artificielle

✍ Rachel Knaebel, le vendredi 28 août 2026.

La vaste communauté de développeurs de logiciels libres de Debian a discuté pendant l’été d’interdire le code produit avec des LLM. Pour certains, il faut bannir l’IA. Pour d’autres, l’IA est certes nuisible, mais incontournable, et, surtout, déjà là.

Note: le vote est clos et c’est la proposition “choix 5: usage responsable de l’IA générative” qui a gagné.

[Le Monde Informatique] AWS annonce le rachat de DuckLabs, le modèle open source sera préservé

✍ Elgodjam Hanna, le jeudi 27 août 2026.

Amazon Web Services va intégrer DuckLabs, l’entreprise d’Amsterdam à l’origine de DuckDB, une base de données analytique open source conçue pour être embarquée directement dans les applications. Annoncée le 26 août, l’opération doit permettre à AWS de renforcer ses capacités dans l’analytique tout en donnant à l’équipe de DuckLabs davantage de moyens pour développer son écosystème.

Et aussi:

[Les Echos] Nvidia continue de bâtir son empire en mettant la main sur la plateforme IA Hugging Face

Le jeudi 27 août 2026.

Selon plusieurs médias américains, le géant des puces électroniques va racheter la plateforme franco-américaine Hugging Face pour 12,9 milliards de dollars. Une acquisition qui constituerait l’une des plus importantes de Nvidia à ce jour.

Et aussi:

[Les Numeriques] Toujours garantie sans IA, la suite bureautique LibreOffice 26.8 fait le plein d'améliorations

✍ Antoine Roche, le jeudi 27 août 2026.

La version 26.8 de LibreOffice est disponible et promet bien des améliorations et correctifs dans trois principaux domaines : la qualité typographique des documents générés, la diversité des systèmes d’écriture qu’elle prend correctement en charge, ainsi que la fidélité avec laquelle les documents conservent leur intégrité lors de leur échange avec d’autres suites bureautiques. Et tout ça, sans intelligence artificielle.

Télécharger ce contenu au format EPUB

Commentaires : voir le flux Atom ouvrir dans le navigateur

Podcast Projets Libres épisode 73 : Kernel Recipes, la conférence technique autour du noyau Linux en France 31/08

Depuis 13 ans, Kernel Recipes est la conférence technique sur le noyau Linux en France.

Nous avons invité Anne Nicolas, créatrice de l'évènement, à venir raconter l'histoire de Kernel Recipes, de son idée née autour d'un barbecue à son édition 2026.
Vous découvrirez aussi ce qui rend cette conférence différente des autres !

L'édition 2026 aura lieu du 21 au 23 septembre 2026.

Une transcription complète, agrémentée de vidéos, est, comme d'habitude disponible pour cet épisode.

Télécharger ce contenu au format EPUB

Commentaires : voir le flux Atom ouvrir dans le navigateur

Agenda du Libre pour la semaine 36 de l'année 2026 30/08

Calendrier Web, regroupant des événements liés au Libre (logiciel, salon, atelier, install party, conférence), annoncés par leurs organisateurs. Voici un récapitulatif de la semaine à venir. Le détail de chacun de ces 37 événements (France: 35, Belgique: 2) est en seconde partie de dépêche.

Sommaire

[FR Saint-Étienne] Permanence de l’association Alolise – Le lundi 31 août 2026 de 19h00 à 22h00.

Tous les lundis soir de 19h à 22h (hors jours fériés) à la Bricoleuse.

Rencontrer les bénévoles, poser des questions sur le libre ou l’informatique, les logiciels, l’hébergement, passer de Windows à Linux.

Pour passer votre ordinateur sous linux, nous vous invitons à nous prévenir avant votre passage: contact@alolise.org.

[FR Saint-Étienne] OpenStreetMap, rencontre Saint-Étienne et sud Loire – Le lundi 31 août 2026 de 19h00 à 21h00.

Depuis la rentrée 2023, les temps de rencontre autour d’OpenStreetMap sont relancés.

L’occasion de se rencontrer (ou de se retrouver), d’échanger sur OpenStreetMap et de lancer des projets en commun.

[FR Chaumont] Permanence Informatique – Le mardi 1 septembre 2026 de 09h00 à 16h30.

REVOL, association engagée dans la promotion des logiciels libres, propose tous les mardis, de 9h à 12h puis de 14h à 16h30, une permanence informatique associative ouverte à toustes, pour se pencher sur les difficultés rencontrées par chacun·e dans son usage de l’outil numérique.

=> Vous avez une question sur le logiciel libre ?
=> Envie de découvrir des alternatives plus respectueuses de votre vie privée ?
=> Vous gérez une association avec Paheko ?
=> Curieuse·x de la modéliation ou de l’impression 3D ?
On prend le temps avec vous pour vous accompagner, simplement.

Les installations de Linux, les réparations matérielles et les remises en état d’ordinateurs sont proposées lors d’install-parties, lors des permanences du samedi matin ou sur rendez-vous, selon les disponibilités des bénévoles.

Et vous pouvez aussi… juste discuter (on a du café et des croissants).
Que ce soit pour poser une question, profitez de notre connexion internet, réfléchir à vos usages ou découvrir le libre tranquillement.

Pas besoin d’être expert·e: venez comme vous êtes.

Nous sommes à notre local, 22 rue de Verdun à Chaumont (52000), en Haute-Marne.

Un monde plus libre, loin des techno-fascistes, ça serait 🦉 quand même, non ?

REVOL est là pour y contribuer !

[FR Dijon] Atelier du mardi – Le mardi 1 septembre 2026 de 15h00 à 19h00.

Présentation de différents outils concernant les logiciels libres.

Assistance technique.

De préférence sur RDV directement sur le site de l’asso

[FR Montpellier] Émission | Radio Aviva | Équilibre | Enregistrement – Le mardi 1 septembre 2026 de 16h00 à 17h00.

Enregistrement de l’émission “Équilibre”.

Montpel'libre enregistre l’émission sur ses activités de promotion du logiciel libre, de la culture libre et des communs numériques pour le mois suivant.

Après le jingle où l’on présente brièvement Montpel'libre, nous donnerons un coup de projecteur sur les activités qui seront proposées prochainement.

Ces émissions seront l’occasion pour les auditeurs de découvrir plus en détails les logiciels libres et de se tenir informés des dernières actualités sur le sujet.

Alors, que vous soyez débutant ou expert en informatique, que vous ayez des connaissances avancées du logiciel libre ou que vous souhaitiez simplement en savoir plus, Montpel'libre, au travers de cette émission, se fera un plaisir pour répondre à vos attentes et vous accompagner dans votre découverte des logiciels libres, de la culture libre et des communs numériques.

Vous vous demandez peut-être ce qu’est un logiciel libre. Il s’agit simplement d’un logiciel dont l’utilisation, l’étude, la modification et la diffusion sont autorisées par une licence qui garantit les libertés fondamentales des utilisateurs. Ces libertés incluent la possibilité d’exécuter, d’étudier, de copier, d’améliorer et de redistribuer le logiciel selon vos besoins.

Inscription | GPS 43.618048/3.878543

https://montpellibre.fr/fiches\_activites/Fiche\_017\_Montpellibre\_Emission\_Radio.pdf

[CA-QC Montréal] Rencontres Linux au Québec – Le mardi 1 septembre 2026 de 17h00 à 17h00.

Local de la rencontre: École de Technologie Supérieure [A|B]-????
Rencontre virtuelle: https://bbb3.services-conseils-linux.org/Linux-Meetup

17:00 à 19:00 – 5 à 7 virtuel et en présentiel

Rejoignez-nous pour un moment de détente et de convivialité lors de notre 5 à 7. Que vous préfériez nous retrouver au Resto-Pub 100 Génies de l’ÉTS ou en ligne sur BigBlueButton (BBB), l’essentiel est de partager un moment agréable. Si vous avez l’intention de venir en personne, veuillez nous en informer afin de pouvoir réserver suffisamment de place pour vous.

18:30 à 19:00 – Installation et tests de l’environnement hybride (tests de son et vidéo)

19:00 à 21:30 – Programmation de la rencontre

  1. Accueil et mot de bienvenue [Martial Bigras]
  2. Capsule éducative sur Linux [Martial Bigras]
    • Gestion des tâches en Linux
  3. Présentation de trucs et astuces sous Linux  [un volontaire]
  4. Présentation de [Prénom Nom]
  5. Une période d’échange de trucs et astuces sous Linux, où chacun est encouragé à partager ses connaissances.

Extras

Que vous soyez débutant ou expert, étudiant ou professionnel, cette réunion est ouverte à tous. Elle réunit une diversité de personnes, allant des gestionnaires aux programmeurs, des professeurs aux retraités, unissant ainsi des esprits passionnés par les logiciels libres, quel que soit votre domaine d’expertise.

Rejoignez-nous pour cette opportunité exceptionnelle de socialiser, d’apprendre, et de tisser des liens avec d’autres passionnés. Ensemble, nous pouvons approfondir notre compréhension des logiciels libres et contribuer à une communauté dynamique.

La participation est gratuite, et nous avons hâte de vous rencontrer, que ce soit en personne ou en ligne. Inscrivez-vous dès maintenant pour recevoir le lien de la réunion virtuelle, et pensez à nous informer si vous prévoyez de vous joindre à nous au Resto-Pub 100 Génies de l’ÉTS.

Au plaisir de partager cette soirée exceptionnelle avec vous!

Cordialement,

Martial

P.S.: Pour le transport en commun : Station de métro Bonaventure

[FR Le Mans] Permanence du mercredi – Le mercredi 2 septembre 2026 de 12h30 à 17h00.

Assistance technique et démonstration concernant les logiciels libres.

Il est préférable de réserver votre place à contact (at) linuxmaine (point) org 

Planning des réservations consultable ici.

[FR Gond-Pontouvre] Permanence du mercredi – Le mercredi 2 septembre 2026 de 14h00 à 18h00.

Nous sommes convaincus depuis le début qu’un ordinateur n’est pas un consommable jetable et qu’on a tous le droit de comprendre et de maîtriser nos outils numériques. C’est de là qu’est née l’asso, à Gond-Pontouvre: un repaire de passionnés du libre et du bidouillage, où l’on défend les logiciels libres, la souveraineté technologique et le bon vieux plaisir de mettre les mains dans le cambouis. Au fil du temps, on a élargi le terrain de jeu, mais l’esprit reste le même: on apprend, on partage, on transmet.

Le cœur historique, c’est le reconditionnement. On collecte des machines en fin de vie, on les teste sous toutes les coutures, et on leur offre une seconde jeunesse: passage en SSD pour réveiller les plus poussives, installation de Linux Mint pour un système libre, léger et accessible, et hop – un PC qu’on croyait bon pour la benne repart pour plusieurs années.

Vous avez un vieux portable qui rame ou une tour oubliée au grenier? Apportez-la, on regarde ensemble.

Côté fabrication numérique, le FabLab ouvre ses portes: venez concevoir et fabriquer vos projets sur nos machines – impression 3D (Creality K1 Max & K2 Plus), découpe et gravure laser (Falcon 2 Pro 60W), et de quoi toucher à
l’électronique embarquée. Les bénévoles sont là pour vous guider – l’idée n’est pas de faire à votre place, mais de vous apprendre à faire.

Entrée libre, esprit d’entraide et de partage des savoirs. Apportez vos questions, vos machines ou simplement votre curiosité.

[BE Liege] Café Crypté – Le mercredi 2 septembre 2026 de 17h00 à 20h00.

Le Café crypté est un moment collectif durant lequel nous tentons résolument de limiter la casse dans notre utilisation des outils numériques et connectés face à la surveillance numérique et la privatisation des données privées.

Le Café tente de rendre compréhensible les motifs et techniques de vol et d’exploitation de nos données par la surveillance de masse des multinationales numériques (GAFAM) et des états.

Le Café cherche à partager et construire des stratégies et pratiques d’autodéfense numérique saines afin de se prémunir de ces intrusions diverses et de rappeler que le droit à l’anonymat est un droit qui ne se négocie pas.

Le Café peut être technique mais pas excluant, il est politique mais pas partisan, il est complexe mais pas (trop) compliqué et il essaie de rester collaboratif sans être contraignant.

Cette année, les cafés cryptés se produisent le premier mercredi du mois, de septembre 2026 à juin 2027 entre 17h et 20h dans les locaux de Barricade (Rue Pierreuse 21 à 4000 Liege)

Comme vous le voyez sur l’affiche, l’atelier se compose de 2h d’atelier libre, de partage d’outils, de réflexions, de pratiques et de théories. Vous pouvez manger dans le même temps bien sûr, et le bar sera ouvert. A 19h, on fera une présentation sur un thème à chaque fois différent.

Prochaines dates: le 2 septembre 2026, le 7 octobre 2026, le 4 novembre 2026, le 2 décembre 2026, le 6 janvier 2027, le 3 février 2027, le 3 mars 2027, le 7 avril 2027, le 5 mai 2027 et le 2 juin 2027.

Venez quand vous voulez et n’oubliez pas de prendre votre ou vos machines (ordinateur, smartphone ou tablette), l’espace et le bar sont ouverts.

Si vous voulez continuer à discuter de tout ça hors des cafés, vous pouvez envoyer un courriel à cette adresse crypto@bawet.org

Retrouvez toutes nos dates sur démosphere, l’agenda alternatif liégeois: https://liege.demosphere.net/

Si vous voulez continuer à discuter de tout ça hors des cafés, vous pouvez envoyer un courriel à cette adresse crypto@bawet.org

Et, tous les documents que les cafés produisent, ainsi que les notes des cafés se trouvent ici : https://nuages.bawet.org/s/aq4GPibwDPrWA7G ou directement le guide introductif à l’autodéfense numérique : https://nuages.bawet.org/s/NLk6CJo5M9y7nDN

Vous pouvez nous suivre sur le fediverse via notre compte Mastodon sur le Fédiverse : https://tchafia.be/@crypto

[FR Beauvais] Sensibilisation et partage autour du Libre – Le mercredi 2 septembre 2026 de 18h00 à 20h00.

Chaque mercredi soir, l’association propose une rencontre pour partager des connaissances, des savoir-faire, des questions autour de l’utilisation des logiciels libres, que ce soit à propos du système d’exploitation Linux, des applications libres ou des services en ligne libres.

C’est l’occasion aussi de mettre en avant l’action des associations fédératrices telles que l’April ou Framasoft, dont nous sommes adhérents et dont nous soutenons les initiatives avec grande reconnaissance.

[CA-QC Montréal] Mesh night – Le mercredi 2 septembre 2026 de 19h00 à 22h00.

Les soirées “mesh” sont un événement récurrent se produisant tous les premiers Mercredi du mois. Nous parlerons et expérimenterons avec les technologies maillées telles que Meshtastic, Meshcore et Reticulum.

Les néophytes sont bienvenu·e·s, nous serons heureux de répondre à vos questions et vous présenter les différents routeurs et relais.

Mesh Nights are a recurring monthly event, hosted on the first Wednesday of each month. We will be talking about and experimenting with mesh networking technologies such as Meshtastic, MeshCore, and Reticulum.

Beginners are welcome to drop by, we are happy to answer your questions and demo our devices for you.

[FR Paris] Tech Care #5 – Le jeudi 3 septembre 2026 de 12h00 à 14h00.

Venez reprendre en main vos données, vos apps, vos alter-ego digitaux ou tout ce qui vous gratte dans votre vie numérique. Nous serons disponibles pour prendre soin de vos activités numériques et vous permettre de les vivre plus sereinement ! Nous proposons notamment de vous aider à:

- Migrer hors des tech américaines ;
- Parler d’IA responsable ;
- Installer linux sur votre ordinateur ;
- Installer un android sans Google services sur votre mobile ;
- Migrer votre compte Gmail sur un service européen ;
- Mettre en place des filtres de tri pour vos mails ;
- Trouver un drive sûr pour vos données ;
- Vous expliquer un peu comment tout ça fonctionne sous le capot ;
- Vous outiller pour prendre vous-même des décisions éclairées sur votre vie numérique ;
- Et bien d’autres sujets !

Nous vous promettons une aide sincère et sans jugement, indépendamment de là où vous en êtes de votre vie numérique. Et si on n’a pas la solution on essaiera de la trouver ensemble:)

Nous vous attendons dans la petite salle de travail entre 12h et 14h chaque premier jeudi du mois.

[FR Angers] Rencontre mensuelle OpenStreetMap – Le jeudi 3 septembre 2026 de 18h00 à 19h00.

Déjà fan d’OpenStreetMap ou envie de découvrir cette cartographie libre, de contribuer à l’enrichissement de la cartographie locale angevine, de mettre à jour des données qui vous tiennent à cœur (pistes cyclables, environnement, facilitation des parcours PMR, bâti, etc.) ?

Les cartographes bénévoles angevins se rencontrent les premiers jeudis de chaque mois pour échanger des astuces, faire découvrir les outils disponibles (sur ordiphone ou PC) et organiser des actions collectives.

Vous n’y connaissez rien ? Pas grave, on vous apprendra autour d’une pression, d’un thé ou d’un jus de fruit !

[BE Lessines] Permanence Les Co-Libristes – Le jeudi 3 septembre 2026 de 18h00 à 21h30.

Atelier sur les logiciels libres.

Installation et configuration.

Hygiène numérique.

[FR Bordeaux] Rentrée bordelaise du groupe local OpenStreetMap – Le jeudi 3 septembre 2026 de 18h00 à 18h00.

Rejoignez-nous le jeudi 3 septembre à 18h autour d’un pique-nique pour fêter la rentrée du groupe local OSM ! 🗺️

Cet évènement sera l’occasion de discuter des modalités des futures rencontres et du contenu de celles-ci (cartopartie, tutoriels, mapathon, etc.).

Chaque participant est invité à apporter quelque chose à manger ou à boire pour contribuer au bon déroulement du pique-nique. 🥪

Bonnes vacances à toutes et tous et au plaisir de vous voir !

Pour en savoir plus 👉 https://forum.openstreetmap.fr/t/rentree-bordelaise-osm/44457

[FR Béziers] Permanence | Linuxerie | GNU/Linux et Logiciels Libres – Le jeudi 3 septembre 2026 de 18h30 à 21h00.

Vous avez des questions, des demandes, des propositions sur GNU/Linux et les Logiciels Libres, nous vous proposons les créneaux suivants pour l’animation d’ateliers de prises en mains et d’accompagnements à GNU/Linux et aux Logiciels Libres.

Cet atelier a pour but de vous familiariser avec l’environnement de travail Linux et la ligne de commande.

À l’IUT de Béziers, le 1er jeudi de chaque mois, venez donc nous raconter des histoires de manchots… sur la banquise ou sur la plage, échanges, informations, conseils, entre-aides! GNU/Linux, Gnome, KDE… nous ne sommes pas sectaires à partir du moment que l’outil est libre. Il peut même s’agir de BSD, Haïku, c’est vous dire!
Linux est un système d’exploitation libre, qui convient à tous les ordinateurs anciens ou récents. Vous y trouverez tous les outils nécessaires à votre émancipation informatique!

Entrée libre et gratuite sur inscription. Une simple adhésion à l’association est possible. Rejoindre le groupe Montpel’libre sur Telegram S’inscrire à la Newsletter de Montpel’libre.

Bus ligne 3, arrêt Trinité

Inscription | GPS 43.34691/3.22206
Carte OpenStreetMap

https://montpellibre.fr/fiches\_activites/Fiche\_002\_Montpellibre\_Permanence\_Linuxerie\_GNULinux.pdf

[FR Montrouge] Rencontre contributeurs OpenStreetMap Sud de Paris – Le jeudi 3 septembre 2026 de 19h00 à 21h30.

La rencontre mensuelle des contributeurs habitants Montrouge et alentours aura lieu le jeudi 3 septembre 2026 au  Schmilblick à partir de 19h.

Ce bar solidaire est situé au 94 avenue Henri Ginoux (station Vélib juste en face, bus 68 et 128, métro 4 station « Mairie de Montrouge »).

Cette rencontre mensuelle nous permettra de discuter de nos projets de cartographie dans OpenStreetMap à Montrouge, au Sud de Paris et au-delà. Comme d’habitude, nous prenons un pot et dînons sur place pour ceux qui le souhaitent.

Comme toujours, les débutants et simples curieux sont les bienvenus.

Si vous avez des sujets à proposer, animer, ou que vous aimeriez approfondir, dites-le dans le sujet du forum https://forum.openstreetmap.fr/c/regions/ile-de-france/32

[FR Villeneuve d’Ascq] Repair'Lab numérique solidaire – Le vendredi 4 septembre 2026 de 09h00 à 12h00.

Le Repair'Lab numérique solidaire de l’Université de Lille propose un accompagnement numérique pour les étudiants et personnels disposant d’ordinateurs portables anciens ou rencontrant des difficultés techniques.

Une équipe de bénévoles vous aide à diagnostiquer, réparer ou optimiser vos équipements, notamment par l’installation de logiciels libres et de systèmes plus légers comme Linux.

L’accueil se fait tous les vendredis (en période universitaire) sur le campus Cité Scientifique.

Sur rendez-vous par email à repairlab@univ-lille.fr.

[FR Marseille] Apéro mensuel Aïolibre et PLUG, spécial « obsolescence logicielle » – Le vendredi 4 septembre 2026 de 19h00 à 23h00.

Le PLUG organise sa soirée mensuelle vendredi 4 septembre 2026 à La Base.

Le thème de la soirée sera « l’obsolescence logicielle »

Eda viendra nous présenter la thèse qu’elle a faite (et récemment soutenue) sur ce sujet.

La réunion rassemble des associations du collectif AïoLibre: Provence Linux User Group, OpenStreetMap Marseille, La Quadrature du Net, Technopolice, l’APRIL, Wikipedia Projet Les sans pagEs Méditerranée, etc.

Les participant·e·s sont invité·e·s à apporter quelque chose à grignoter.
Il est possible de commander des pizzas au cours de la soirée.
Il n’est PAS possible d’apporter des boissons alcoolisées.
Des boissons (vins, bières, cidres, jus, etc.) seront en vente au bar à La Base.

Attention, c’est un bar associatif, donc il faut adhérer à La Base pour consommer. Si vous ne l’avez pas encore fait, faites le en ligne avant de venir via:
https://www.helloasso.com/associations/la-base-marseille/adhesions/adhesion-a-la-base-marseille-2026

Venez nombreuses et nombreux et faites passer le mot, cet évènement est ouvert à tous et toutes.

[FR Paris] Soirée « radio ouverte » au studio de Cause Commune – Le vendredi 4 septembre 2026 de 19h30 à 22h00.

Libre à vous !, l’émission de radio de l’April sur les libertés informatiques, est diffusée sur la radio associative Cause Commune, la voix des possibles.

La radio propose un rendez-vous convivial chaque premier vendredi du mois à partir de 19 h 30 dans ses locaux à Paris: une soirée « radio ouverte » avec apéro participatif à la clé. Occasion de découvrir le studio et de rencontrer les personnes qui animent les émissions.

La prochaine soirée-rencontre aura lieu vendredi 4 septembre 2026 à partir de 19 h 30 au studio de la radio: 22 rue Bernard Dimey 75018 Paris. Inscription (non obligatoire, mais cela facilite l’organisation) sur le bloc-notes.  Julie Chaumard, administratrice de l’April et Frédéric Couchet, délégué général de l’April, participeront à la soirée.

À partir de 20 h il y aura en direct une émission intitulée « Comm'un vendredi » consacrée aux coulisses de la radio. Le principe général est de réunir des animatrices et animateurs d’émissions de la radio pour parler de leurs émissions, de la radio, de leurs expériences. Mais aussi donner la parole aux auditrices et aux auditeurs.

[FR La Ferté Saint-Aubin] Réunion mensuelle de l’association Re-Boot – Le vendredi 4 septembre 2026 de 20h30 à 23h30.

Re-Boot est une association qui s’inscrit dans le mouvement de l’économie sociale et solidaire dans le domaine informatique, engagée dans la promotion des logiciels libres et de Linux. L’association est basée dans le Loiret (45) à La Ferté Saint-Aubin. Nous sommes heureux d’accueillir toutes les personnes qui souhaitent découvrir les logiciels libres.

Réunion mensuelle de l’association: allez voir sur notre site pour connaître les thématiques du jour.

https://rebootinformatique.org/reunions-mensuelles--les-thematiques

Venez nombreuses et nombreux pour découvrir des logiciels, poser vos questions, rencontrer d’autres utilisateurices de Linux.

Le bureau.

[Internet] Comité logiciels libres et standards ouverts pour la feuille de route de Données Souveraines Québec (DSQ) – Le vendredi 4 septembre 2026 de 08h00 à 09h00.

Description

Bonjour! Nous allons travailler sur la Feuille de route pour Données Souveraines Québec (DSQ) https://www.donneessouveraines.quebec/feuille-de-route Spécifiquement, nous allons travailler sur la section Logiciels libres et standards ouverts.   Ceci est une invitation pour les réunions récurrentes pour se coordonner et travailler sur le contenu lié à notre partie de la Feuille de Route. Nos réunions seront avec BigBlueButton, hébergé par EvoluData:   https://meet.evoludata.com/rooms/4ua-hnq-cgc-plm   Voici déjà une salle pour le clavardage avec Mattermost, hébergé par Framasoft: https://framateam.org/linuxmeetup-mtl/channels/dsq-feuille-de-route   SVP vous créer un compte et m’indiquer votre nom d’usager: https://framateam.org/signup_user_complete   Merci!

[Internet] Pause Café Linux : Votre rendez-vous hebdomadaire – Le vendredi 4 septembre 2026 de 11h45 à 13h00.

Pause Café Linux: Votre rendez-vous hebdomadaire

Est-ce que Linux vous passionne ? Vous voulez simplement jaser de logiciels libres dans une ambiance décontractée ? Rejoignez-nous pour la Pause Café Linux, un rendez-vous unique dans la francophonie Linuxienne ! C’est le moment idéal pour briser l’isolement, partager vos découvertes et rencontrer d’autres passionnés de l’écosystème Linux au Québec.

C’est quand ?

Tous les vendredis midis (12h00 HAE, Québec).

Apportez votre lunch, nous fournissons le café… virtuellement !

Au programme

  • Discussion libre: Pas d’ordre du jour rigide, on parle de ce qui vous anime.
  • Tour de table rapide: Afin de mieux se connaître.
  • Le Brise-Glace: Une question thématique différente pour lancer la conversation.
  • Entraide et partage: Un espace bienveillant pour tous les niveaux, du débutant à l’expert.

Comment participer ?

  • Échangez avec nous: Rejoignez notre canal de discussion sur Framateam pour vous présenter et rester informé. Rejoindre le canal Pause Café
  • Connectez-vous à la rencontre: Tous les vendredis midis, cliquez simplement sur le lien ci-dessous pour accéder à notre salon de visioconférence (BigBlueButton). Accéder au salon virtuel (BBB)

Venez avec votre lunch, votre café, et surtout votre curiosité !

La participation est gratuite, ouvert à tous!

Notre réunion accueille une diversité de profils: étudiants, professionnels, gestionnaires, programmeurs, professeurs, ou retraités. Que votre passion soit l’administration système, le développement, ou la simple utilisation quotidienne, votre expérience est précieuse. Ensemble, nous pouvons approfondir notre compréhension des logiciels libres et contribuer à une communauté dynamique.

Rejoignez-nous pour cette opportunité exceptionnelle de socialiser, d’apprendre, et de tisser des liens !

Nous avons hâte de vous y accueillir.

Le Comité organisateur des Rencontres Linux au Québec

[FR Contamine sur Arve] Bidouille Informatique – Le samedi 5 septembre 2026 de 09h00 à 12h00.

Le point de rencontre mensuel dédié à l’informatique à Contamine sur Arve. Un moment d’échange autour d’un café pour partager des astuces, des nouvelles, des techniques, des idées et des connaissances à propos du numérique.
Venez avec votre ordinateur, tablette et / ou téléphone pour approfondir vos connaissances, dépanner / améliorer vos équipements, installer / découvrir des solutions informatiques alternatives et fonctionnelles.

[FR Villeneuve d’Ascq] Libre à Vous – Le samedi 5 septembre 2026 de 09h00 à 12h00.

L'OMJC organise, en collaboration avec l’Association Club Linux Nord Pas-de-Calais, chaque samedi, une permanence dédiée au numérique. Nous vous proposons des logiciels libres, fiables et gratuits pour vos appareils (ordis de bureau, ordis portables, tablettes ou smartphone), comme Firefox, Thunderbird, LibreOffice et bien d’autres.

Vous pouvez également découvrir Linux, apprendre à protéger vos données sur internet et même publier des informations sur le web.

Cette rencontre est ouverte à tous, débutants, simples curieux ou déjà utilisateurs afin d’apprendre, partager votre pratique, répondre à vos questions, résoudre vos problèmes et développer des solutions libres.

Entrée payante à l’ordre de l’OMJC. Réservation obligatoire de créneau d’1 heure au 03 28 80 54 25 ou au 07 49 83 35 53 (pas de rendez-vous par SMS).

[FR Vanves] Braderie d’automne – Le samedi 5 septembre 2026 de 09h00 à 18h00.

À la Braderie d’automne, nous proposerons des éléments d’informatique et accessoires. Elle se tiendra sur l’ensemble des pelouses annexes.

Le forum des associations se tiendra sur la pelouse centrale.

Plan: https://www.vanves.fr/news/journee-au-parc-pic/  (en bas de page)

Nous acceptons le don de Matériel informatique (surtout portable), Tablette et Smartphone, de préférence avec leur alimentation / chargeur.

[FR Lannion] Participation d’INFOTHEMA au forum des associations de Lannion – Le samedi 5 septembre 2026 de 09h00 à 17h30.

L’association INFOTHEMA participera au Forum des Associations de Lannion 2026 au stand 31, le samedi 5 septembre de 9h00 à 17h30 à la salle des Ursulines.

Programme: Présentation du potentiel de GNU/Linux et des logiciels libres

[FR Nantes] Forum Associatif avec Linux-Nantes – Le samedi 5 septembre 2026 de 09h30 à 13h00.

Linux Nantes vous convie à nous rencontrer à notre stand et assister à une présentation de notre association Samedi 05 septembre de 09H30 à 13H00

au Forum Associatif

Quartier Malakoff – Saint-Donatien

Place Rosa Parks – Boulevard de Berlin

44000 Nantes

Pour plus d’informations sur l’association: voir notre site.

[FR Vandœuvre-lès-Nancy] Installons Linux ! spécial jeux vidéo – Du samedi 5 septembre 2026 à 10h00 au dimanche 6 septembre 2026 à 19h00.

Windows 10 n’est plus supporté ? Votre PC s’essouffle ? Donnez-lui un coup de jeune !

Installons y Linux !

Le prolongement de la prise en charge de Windows 10 se termine le 14 octobre 2026. Microsoft veut que vous achetiez un nouvel ordinateur.

Mais que se passerait-il si vous pouviez encore utiliser votre ordinateur actuel pour jouer ?

Si vous avez acheté un bon ordinateur après 2010, il n’y a probablement aucune raison de le jeter. En installant simplement un système d’exploitation Linux récent, vous pouvez continuer à l’utiliser pour des années.
L’installation d’un système d’exploitation peut sembler difficile. Mais, vous n’avez pas à vous lancer tout seul ! Il y a des personnes prêtes à vous aider !

Au programme

  • Découverte de Linux et comment jouer avec
  • Installation de Linux sur votre ordinateur les après-midi (inscription obligatoire)

Accès

Payant: à partir de 3 € dans le cadre de l’événement Vandœuvre in Game.

[FR Lagny-sur-Marne] Install Party – Logiciels libres et Linux – Le samedi 5 septembre 2026 de 10h00 à 13h00.

La Médiathèque intercommunale Gérard-Billy (Lagny-sur-Marne) organise une Install Party le samedi 5 septembre 2026 de 10h à 13h, dédiée à l’installation de logiciels libres et de systèmes d’exploitation alternatifs (comme Fedora).

Pourquoi participer ?

  • Votre matériel est obsolète ou incompatible avec les dernières mises à jour propriétaires ?
  • Vous souhaitez découvrir des outils gratuits, documentés et respectueux de vos données ?
  • Vous voulez apprendre à sauvegarder vos données et installer un nouveau système en toute sécurité ?

Au programme

  1. Échanges conviviaux: Présentation des besoins et des attentes de chacun.
  2. Sauvegarde des données: Conseils pour sécuriser vos fichiers avant toute installation.
  3. Installation guidée:
    • Systèmes d’exploitation (ex. Fedora)
    • Logiciels libres: LibreOffice (bureautique), Firefox (navigateur), Thunderbird (messagerie), GIMP (retouche d’images), KDenLive (montage vidéo), Inkscape (dessin vectoriel), Scribus (PAO).
  4. Premiers pas: Accompagnement pour prendre en main les nouveaux outils.

Public visé

Tout public, débutants bienvenus ! Aucune compétence technique requise.

Infos pratiques

[FR Lille] Numérique libre à la Braderie de Lille – Du samedi 5 septembre 2026 à 10h00 au dimanche 6 septembre 2026 à 17h00.

Le collectif Chtinux œuvrant pour les libertés numériques dans la métropole lilloise tiendra un stand d’informations à côté du Café Citoyen durant la grande braderie, qui aura lieu le week-end du 05 et 06 septembre, sur la Place du Vieux Marché aux Chevaux. Parmi les associations présentes à notre stand:

  • ClissXXI: coopérative d’informatique libre, social et solidaire
  • CLX: groupe d’utilisateurs et utilisatrices de logiciels libres
  • Mycélium: association travaillant à la mise en place d’un Fournisseur d’Accès Internet, membre de la Fédération FFDN
  • Raoull: association œuvrant à la mise en place de services internet éthiques, membre du collectif CHATONS
  • Deuxfleurs: fournisseur de services en ligne libres, sobres et non-marchands, membre du collectif CHATONS
  • Les Ordis du Cœur:  réemploi du matériel informatique en faveur de l’inclusion numérique
  • Et quelques invités…

Cette année, nous porterons comme l’année dernière  bien haut les sujets:

  Que vous soyez un(e) geek déjà convaincu(e), ou au contraire que vous trouviez l’outil trop emprisonnant et cherchiez des échappatoires, n’hésitez pas à passer à notre stand pour vous informer, nous rencontrer en chair et en os, voire récupérer quelques goodies (On aura des nouveaux T-Shirt).               Bonne braderie!

[FR Fontenay Le Fleury] Forum des associations – Le samedi 5 septembre 2026 de 10h00 à 16h00.

Retrouvez notre association Root66 aux Forums des associations – samedi 5 septembre

Cette année encore, nous serons présents sur deux stands !

Saint-Cyr-l’École

Lieu: Maison des Associations Simone-Veil
           14 avenue Tom Morel, 78210 Saint-Cyr-l’École
Horaires: 10h à 16h

Fontenay-le-Fleury

Lieu: Mairie de Fontenay-le-Fleury
Horaires: de 10h à 16h

N’hésitez pas à venir nombreux pour nous rencontrer sur place ! Nous profiterons de ce moment pour vous présenter les différentes activités de notre association et répondre à toutes vos questions.

Root66 défend et promeut les logiciels libres pour tous les âges et tous les niveaux, à travers des conférences grand public et des ateliers et des évènements

En adhérant à Root66, vous pourrez notamment:

  • bénéficier de nos permanences, organisées trois samedis par mois: venez avec votre ordinateur pour obtenir de l’aide, installer Linux, résoudre un problème ou simplement poser vos questions ;
  • assister à des conférences autour des logiciels libres, du numérique et des sujets qui les entourent
  • participer aux Smartphone Party, durant lesquelles nous vous aidons à reprendre le contrôle de votre téléphone et à réduire votre dépendance aux GAFAM ;
  • suivre des formations: initiation à Linux, ligne de commande, ateliers cybersécurité, installation et administration d’un serveur web, et bien d’autres sujets.

N’hésitez pas à passer nous voir sur l’un de nos 2 stands !

[FR Saint-Cyr-l’École] Forum des associations – Le samedi 5 septembre 2026 de 10h00 à 16h00.

Retrouvez notre association Root66 aux Forums des associations – samedi 5 septembre

Cette année encore, nous serons présents sur deux stands !

Saint-Cyr-l’École

Lieu: Maison des Associations Simone-Veil
           14 avenue Tom Morel, 78210 Saint-Cyr-l’École
Horaires: 10h à 16h

Fontenay-le-Fleury

Lieu: Mairie de Fontenay-le-Fleury
Horaires: de 10h à 16h

N’hésitez pas à venir nombreux pour nous rencontrer sur place ! Nous profiterons de ce moment pour vous présenter les différentes activités de notre association et répondre à toutes vos questions.

Root66 défend et promeut les logiciels libres pour tous les âges et tous les niveaux, à travers des conférences grand public et des ateliers et des évènements

En adhérant à Root66, vous pourrez notamment:

  • bénéficier de nos permanences, organisées trois samedis par mois: venez avec votre ordinateur pour obtenir de l’aide, installer Linux, résoudre un problème ou simplement poser vos questions ;
  • assister à des conférences autour des logiciels libres, du numérique et des sujets qui les entourent
  • participer aux Smartphone Party, durant lesquelles nous vous aidons à reprendre le contrôle de votre téléphone et à réduire votre dépendance aux GAFAM ;
  • suivre des formations: initiation à Linux, ligne de commande, ateliers cybersécurité, installation et administration d’un serveur web, et bien d’autres sujets.

N’hésitez pas à passer nous voir sur l’un de nos 2 stands !

[FR Wintzenheim] Réunion du Club Linux – Le samedi 5 septembre 2026 de 13h30 à 19h00.

Le samedi 5 septembre 2026 de 13h30 à 19h00.

MJC-EVS du Cheval Blanc, 1 faubourg des Vosges, Wintzenheim, Grand Est

                  Leaflet | © OpenStreetMap Rencontre du Club Linux de la MJC-EVS du Cheval Blanc qui se réunit toutes les 3 semaines (environ) et accueille toutes les personnes qui souhaitent découvrir ou approfondir Linux et les Logiciels Libres. Aucune compétence n’est demandée.

Pendant ces rencontres, informelles,

  • nous accueillons celles et ceux qui cherchent une réponse ou souhaitent découvrir Linux et les Logiciels Libres,
  • nous installons Linux sur des ordinateurs, la plupart des fois en "dual boot"(*), ce qui permet de conserver l’ancien système (par exemple Windows) et d’utiliser quand même Linux, en choisissant au démarrage,
  • nous partageons nos recherches (nos difficultés aussi) et nos découvertes, les nouveautés.

Le Club Linux est également impliqué dans une démarche de libération des GAFAM (Google Apple Facebook Amazon Microsoft) et de promotion de solutions libres comme, entre autres, Wikipedia, OpenStreetMap, les Framatrucs (*), les C.H.A.T.O.N.S (*) et beaucoup d’autres.

(*): mais on vous expliquera

[FR Le Mans] Permanence mensuelle du samedi – Le samedi 5 septembre 2026 de 14h00 à 18h00.

Assistance technique et démonstration concernant les logiciels libres.

Il est préférable de réserver votre place à contact (at) linuxmaine (point) org 

Planning des réservations consultable ici.

[FR Paris] Atelier de sensibilisation et essais téléphones à OS libéré – Le samedi 5 septembre 2026 de 14h00 à 17h30.

Votre téléphone rame, est encombré ou certaines applis ne fonctionnent plus? Vous cherchez un 1er téléphone pour vos jeunes, un téléphone simple ou un téléphone débarrassé des applications qu’on ne peut supprimer et qui récupèrent vos données personnelles?

Venez nous retrouver à la Cité des Sciences, en classe numérique, où nous animons un petit atelier sur le sujet et vous ferons tester de vieux (mais pas que;)…) téléphones qui refonctionnent très bien après leur passage à un OS ‘libéré’. L’atelier est désormais organisé en 2 volets avec une partie Opérateurs, après la partie OS alternatifs.

L’association Electrocycle https://electrocycle.co œuvre sur la réutilisation de vieux (plus de 4 ans) matériels électroniques: ainsi, de même qu’en passant son PC sous Linux on réutilise très bien parfois de très anciens PC, en passant son smartphone sous OS libre on peut prolonger de façon très importante sa durée de vie.

Nous vous attendons nombreux, mais si vous ne pouvez vous déplacer et souhaitez essayer un de nos téléphones, n’hésitez pas à renseigner le sondage de la page https://www.electrocycle.co/vivez-lexperience-de-prolonger-la-vie-de-vos-smartphones-en-passant-sous-os-alternatif/:)!

[FR Nantes] Permanence Linux-Nantes – Le samedi 5 septembre 2026 de 15h00 à 18h00.

Linux Nantes tient à vous informer de sa prochaine permanence. Nous vous proposons:

  • de vous faire découvrir Linux et les logiciels libres.
  • de vous aider à installer Linux sur votre ordinateur ou votre portable.
  • de vous informer sur l’utilisation de votre version de Linux et des logiciels libres.
  • de voir avec vous les problèmes rencontrés.

Pour plus d’informations sur l’association: voir notre site.

Avertissement ! Pour des raisons pratiques, nous vous remercions de bien vouloir effectuer les sauvegardes de vos données personnelles avant de venir si une installation doit être effectuée.

[FR Le Tholonet] Matinée des associations – Le dimanche 6 septembre 2026 de 09h00 à 12h00.

L’Axul (Association du Pays d’Aix des Utilisateurs de Linux et des Logiciels libres) tiendra un stand lors de la MATINÉE DES ASSOCIATIONS du Tholonet au parc des Rapegons (complexe sportif) allée Louis Philibert  

INFORMATIONS GÉNÉRALES:

Évènements ultérieurs: voir l'Agenda du Libre

[FR Beauvais] Stand lors la journée « L’Ecospace fait sa rentrée » – Le dimanche 6 septembre 2026 de 09h30 à 17h30.

Plusieurs organisations participent dont Oisux.

Stand d’information pendant toute la journée. Présentation des Logiciels libres, des distributions Xubuntu, Manjaro et Primtux.

Sujets proposés:

  • Installation du système d’exploitation Linux et des applications pour la bureautique sur du matériel obsolescent pour lui donner une nouvelle vie.
  • Configuration de services en ligne de proximité et à faible consommation (cloud, données personnelles, agenda, contacts…)
  • Réalisation de supports graphiques avec des logiciels libres: retouche d’image, création de logos, flyers, magazines.

  • Ecospace de la Mie au Roy, Ecospace de la Mie au Roy, 136 rue de la Mie au Roy, Beauvais, Hauts-de-France, France

  • https://www.oisux.org

  • linux, logiciels_libres, primtux, graphisme, obsolescence, réemploi, xubuntu, debian, oisux, mint, adieu-windows

[FR Montpellier] Rencontre | Antigone des Assos – Le dimanche 6 septembre 2026 de 09h30 à 17h30.

Rencontre | Antigone des Assos

Dimanche 06 septembre 2026 de 9h30 à 17h30Stand 52, Place du Nombre d’Or, 34000 Montpellier.

Le rendez-vous des associations de Montpellier.Inscriptions | Plan | Fiche | Info | GPS 43.608500/3.887444

[FR Rouen] Vente d’ordinateurs et de Fairphones reconditionnés – Le dimanche 6 septembre 2026 de 14h00 à 16h00.

L’association « Libérons nos ordis » organise une vente exceptionnelle d’ordinateurs reconditionnés, à destination des particuliers et des associations.

Nous vendons des ordinateurs portables et fixes (avec ou sans écran) et divers accessoires. Ainsi que des smartphones éthiques et durables de marque Fairphone. Détail de l’offre sur notre site web.

Le matériel est garanti 1 an (sauf les batteries). Le matériel n’est pas emballé. Amenez vos sacs ou cartons.

Le règlement se fait par chèque ou en espèces (prévoyez des petites coupures: 5, 10 €).

Télécharger ce contenu au format EPUB

Commentaires : voir le flux Atom ouvrir dans le navigateur

Compute! Paris 2026 29/08

Nous sommes ravis d’annoncer la première édition de la conférence Compute! Paris, qui se tiendra les 25 et 26 novembre 2026 à Sorbonne Université.

Organisé par l’équipe de PyData Paris 2024 et 2025, Compute! Paris 2026 est le rassemblement de la communauté open-source de la science des données et de l’IA/ML. Compute! élargit le spectre de PyData pour embrasser l’ensemble des langages de programmation et technologies libres pour la science des données et l’IA/ML.

Si vous souhaitez rencontrer des mainteneurs de Jupyter, SciPy, Scikit-learn, R, Mamba, Apache Arrow, SymPy, conda-forge, Pixi, c’est la bonne conférence !

La conférence inaugurera la nouvelle série Compute! Le programme comprend quatre keynotes par :


Fernando Pérez (Jupyter, UC Berkeley)


Mackenzie Mathis (DeepLabCut, EPFL)


Wolf Vollprecht (Pixi, Prefix.dev)


Ines Montani (SpaCy, explosion.ai)

Pour plus d’informations sur la conférence, rendez-vous sur notre site Web.

Vous pouvez aussi suivre Compute! Paris sur:

Mastodon : @ComputeParis@mastodon.social
Bluesky : @computeparis.bsky.social
LinkedIn : compute-paris

Si vous êtes intéressé·e·s par cette communauté open-source, n’hésitez-pas à rejoindre notre groupe Meetup, qui compte aujourd’hui plus de 5 000 membres.

Télécharger ce contenu au format EPUB

Commentaires : voir le flux Atom ouvrir dans le navigateur

It's FOSS
FOSS Weekly #26.36: Debian CERN Win, Faster Firefox, Free Bash Course, Grub Customization and More Linux Stuff hier

Firefox 155 has arrived quietly, speeding up page loads with Happy Eyeballs v3 and QUIC v2. And the timing is perfect for you to switch. Google just removed uBlock Origin from the Chrome Web Store, leaving Firefox one of the last non-Chromium browsers still supporting it.

EndeavourOS 'Triton' is running late, so instead of that, the developers have introduced 'Titan Nova' as a release mostly packed with hardware support enablement, misc fixes, Linux 7.1.8, and more.

Vanilla OS 3 'Reunion' is out with first-class ARM64 support, reproducible images, and GNOME 50. New default apps include Ptyxis, Papers, and Resources, while snapshot backups come via the new Vanilla Continuity tool.

Virtual machines add a layer; containers share one kernel, but Multikernel's approach avoids both. It gives each workload its own full kernel on real hardware. The first public release targets servers and SRE teams.

Do you own an Apple iPhone? Well, then you might be missing the Continuity feature on Linux. Luckily, a developer has managed to bring a comparable experience with Tether, an open source app that carries iMessage, SMS, and OTP codes to Linux over Bluetooth.

Debian 11 "Bullseye" has reached end-of-life, which means you have to either upgrade to a newer supported release, or stay on it, manually managing the security of your system.

Speaking of Debian, the CERN lab is migrating 2200 of its control systems to Debian 13. That's a massive win for all of us Linux users.

LibreOffice 26.8 contains no AI features, on purpose. TDF proudly markets its stance, promising that its office suite doesn't need to contact a server.

Germany's Sovereign Tech Agency is putting €508,640 into Flatpak over two years, involving a few other stakeholders. Seems like Flatpak is going to get stronger and more widespread.

This edition of FOSS Weekly is supported by privacy service provider, AdGuard.

SPONSORED

If you do not want to set up and maintain Pi-hole, AdGuard is a better choice than browser-based ad blockers. It blocks ads on your device, not just your browser. Imagine using Android ad-free.

They are running a 'Back to School' promo and you get 40% off a 1-year license or 30% off a lifetime one. One subscription protects up to 9 devices and you enjoy a clean, distraction-free Web. There is also a 60-day money-back guarantee (in case you do not like it).

Offer ends on 3rd Sep. That is today. So hurry up ⌛

Get AdGuard

🧠 What We’re Thinking About

AI crawlers are scraping the Linux kernel repo in a way that results in unnecessary compute usage, burning ~4.6 million times more compute for a worse copy of data that was always free to grab.

A community leader in open source, Debian, has voted to allow AI-assisted contributions, and the community response has been predictably split. One long-time Debian developer even quit over it.

That's not the only divide. Omarchy is now a foundation backed by several tech leaders, 1Password CEO being one of them. And that has created a divide in both its employees and users. This article provides context.

🧮 Linux Tips, Tutorials, and Learnings

How often do you think about which filesystem to install your OS on? Or swapping your kernel for a real-time build when you need it? Or moving your whole install to a different machine without a license headache?

We list ten things Linux does casually that Windows either can't do or actively prevents.

Ubuntu's built-in tiling is more capable than most people realize. We explore the various keyboard shortcuts, window gaps, and active window hints in the default Ubuntu Tiling Assistant, then go further into the Tiling Shell extension for proper layout management.

If you are absolutely new to bash shell scripting, we have a 10-part, hands-on bash learning series for you. Good starting point for Linux users.

Grub Customizer is a handy tool that lets you change boot order in a multi-boot system.

Desktop Linux is mostly neglected by the industry but loved by the community. For the past 14 years, It's FOSS has been helping people use Linux on their personal computers. And we are now facing the existential threat from AI models stealing our content.

If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get an ad-free reading experience with the satisfaction of helping the desktop Linux community. And there are also free Linux ebooks.

Join It's FOSS Plus

👷 AI, Homelab and Hardware Corner

Switched routers, and now your headless Raspberry Pi can't go online? Pull the SD card, mount it on your Linux machine, then follow these steps. 👇

Canonical has joined NVIDIA's Open Secure AI Alliance, a coalition focused on building open tools for securing AI agents and the software stacks they run on.

✨ Apps and Projects Highlights

Image Toolbox is the app for you if your life revolves around creating and posting content on social media. It is fully open source, doesn't sell you ads, and also has AI powers.

📽️ Videos for You

KDE's default terminal Konsole is an underrated but capable terminal emulator. Check out this video and learn a few new tips.

Subscribe to It's FOSS YouTube Channel

💡 Quick Handy Tip

If you are using the Nautilus file manager (aka GNOME Files), in the "Icon" options menu (downwards arrow button), go into "Captions..." and select "Size" and "Detailed File Type" captions for the "First" and "Second" options.

This way, you will be shown essential folder/file information without needing to go into the property view or the terminal.

🎋 Fun in the FOSSverse

Seeing that Linux recently turned 35, why not try your hand at a history trivia quiz?

Firefox is still a strong force againsta everything Chrome.

🗓️ Tech Trivia: Happy 34th birthday to SUSE! 🎂💚

Founded on September 2, 1992, SUSE made history as the world’s first provider of an Enterprise Linux distribution.

💡 Fun fact: The original name, S.u.S.E. GmbH, stood for "Software- und System-Entwicklung" (Software and Systems Development).

🧑‍🤝‍🧑 From the Community: An old thread on the topic of Linux distros that still support 32-bit has gone active again. Got any missing ones to add to the list?

1Password Just Pledged $300,000 to DHH's Omarchy, and its Own Employees Aren't Happy hier

Omarchy has been on something of a roll now. Funding for its foundation has been climbing fast, from an $8 million launch to $10 million a few weeks later, and now crossing $13 million with the most recent pledge.

What's drawn my attention are the first two Corporate Patrons, 1Password and 37signals, both of whom have decided to pitch $100,000 a year for the next three years. Now, 37signals I get; DHH is heavily involved there, but 1Password was a surprise entry.

Naturally, not everyone's onboard with their pledge.

Signs of disagreement

This has not gone well with employees working at 1Password, with company leadership having to take certain damage control measures to assure their staff.

An internal Slack message has surfaced (courtesy of The Verge), which shows cofounder Roustem Karimov downplaying the criticism, telling team members that:

people have different personal opinions. You believe in your heart that DHH is evil, that you have the moral high ground, and that nothing will change your mind.

However, not everyone believes that. It is not fair to claim a monopoly and ostracize team members who might disagree with you. There are people who are afraid to speak up simply because they will be personally attacked.

CEO David Faugno responded on a different note, telling employees the company doesn't endorse DHH's views, while also noting that Omarchy is the second most used Linux distribution among 1Password's own users.

Why the backlash?

DHH is known to be someone who firmly falls on the "right" side of the political spectrum, someone who doesn't shy away from putting his opinions in public view.

He regularly posts blogs that show where he stands on certain societal issues, and some of his recent writeups are what's fueling this particular backlash.

His recent July post, titled "Wolves, sheep, and gypsies," compares Denmark's wolf population with the Romani people camping in Copenhagen parks, where he argues: "When gypsies take over public spaces, you deport them."

Then there's "As I remember London" from September 2025, where he laments about London losing its native Brit majority and a nod of approval for a Tommy Robinson march.

Of course, these aren't the only factors behind his disapproval, but you get the gist of it, right?

Users could jump ship

How 1Password currently pitches its personal plans to new sign-ups.

If you search for the terms "1Password" and "Omarchy" right now, you are bound to run into the many comments made by disgruntled 1Password users on Reddit and Hacker News.

They are calling the choice tone-deaf, given how many smaller open source projects could've benefited from the money. Some are already jumping to alternatives like Bitwarden, while others suggest self-hosting Vaultwarden or going with KeePass and its forks instead.

I see the issue compounding too. Back in February, 1Password raised subscription prices, taking effect at renewals from March 27. Individual plans went up 33 percent from $35.88 to $47.88 a year, and family plans went up 20 percent from $59.88 to $71.88.

Its community forum already has a long thread full of longtime users saying they were leaving over it. If 1Password continues playing with its users' trust like this, who knows what kind of exodus it will see next?

Good News! CERN is Migrating Over 2,200 Control Systems to Debian 13 hier

Debian has gotten some good press thanks to Federico Vaga and Nikos Tsipinakis, who presented a talk at MiniDebConf Winterthur this past weekend.

The two CERN engineers laid out why the organization is moving its particle accelerator control computers onto Debian 13, with more than 2,200 industrial computers and embedded systems set to run it by the end of 2026.

Though this doesn't mean that the whole CERN IT infrastructure is being moved. The migration is specific to the accelerator control layer—the front-end computers that talk directly to the equipment running the beam.

Why move?

The multi-tiered infrastructure they are aiming for.

CERN ran a risk analysis in the second quarter of 2023, putting a number on what staying in the Red Hat ecosystem would cost them. The estimate came out to roughly CHF 5.4 million, with around 11 hardware boards needing a full redesign, plus hiring two electronic engineers, two software engineers, and two technicians just to handle it.

Racks would need reorganizing and rewiring, and most systems would be affected during commissioning. Even assuming bug-free replacements, CERN's own estimate put the odds of success at an optimistic 20 percent.

The reason for all that was a compiler flag. When Red Hat builds RHEL, it picks a minimum CPU generation the software will run on. RHEL 9's cutoff already excludes CERN's oldest boards, the kind running chips like Intel's old Core 2 Duo, which comprises about 47 percent of their fleet.

RHEL 10 raises that cutoff again, and this time even newer Ivy Bridge-generation boards, another 17 percent, fall on the wrong side of it.

The release strategy

CERN weighed two paths for keeping Debian aligned with its accelerator schedule. Plan A develops on Bookworm through 2026, deploys Trixie as the long-term support release from 2026 to 2030, then moves to Debian 15 "Duke."

Plan B skips that last jump, staying on Trixie under extended long-term support (ELTS) out to 2033 instead. A third option, running Bookworm itself under extended support the whole way, got ruled out.

Either path depends on Debian's LTS and ELTS programs staying healthy, which is part of why CERN has started sponsoring Freexian, the Debian-focused services company behind those support programs.

How it will be built

The old setup ran on NFS and tftpd, a bootserver model that traces back to around 2005.

The new one decouples the bootloader, kernel, init RAM disk, and userspace into separate pieces, then rebuilds delivery around Kubernetes.

A controller compares the configuration CERN wants against what's actually deployed and redeploys automatically when the two fall out of sync, instead of relying on someone pushing files over NFS by hand.

None of this touches CERN's data centers; this is specifically about the machines that keep the accelerator itself running. By the time the last quarter of 2026 closes out, CERN expects to have completed the migration.

An Honorless Move! Ubisoft Decides Linux isn't Worth the Effort 02/09

Gaming on Linux keeps getting better, Wine and the Proton compatibility layer keep opening up more of the Windows catalog, and community projects continue filling the gaps that big publishers leave behind.

Take Xodus, for instance. The open source effort is looking to bring Xbox and Game Pass titles to Linux. Even though there are no playable builds yet, its direction says a lot about where Linux gaming is headed.

The money aspect of the equation is catching up too. While not strictly a gaming-focused move, the recently launched Omacom Foundation, which backs Omarchy and the open source projects it relies on, already has $12 million in funding.

Then you have Ubisoft, fresh off the success of Assassin's Creed Black Flag Resynced (a mouthful, I know), who are going the other way, breaking something that worked just fine before their meddling.

They kicked out Linux

A placeholder video embed to show you what For Honor recently introduced.

Ubisoft has announced that For Honor is leaving the Linux platform. Starting September 10, the game will no longer be playable on Linux desktops or the Steam Deck. The removal of support lands the same day its Ranked Dominion and Ranked Duel modes go live.

They are calling it a move intended to safeguard players by introducing additional measures for ranked play to ensure a fair competitive environment, adding that they "cannot meaningfully deploy protection on this platform."

Ubisoft goes on to say that they:

will continue to investigate different ways to improve our anti-cheat with the possibility of reopening the platform in the future.

Which is PR speak for. This has been put on the back burner and is not a priority for us.

That makes me think that they would rather push out new pricey skins than support a minority portion of their player base.

The same old shenanigans

If you have been following Linux gaming-focused news, you might already know the script such big game publishers follow.

Roblox blocked Wine users in 2023, while GTA V Online barred Linux players in 2024, and Apex Legends kicked out Steam Deck owners the same year. For Honor is the newest name on a list that keeps growing, and the provided rationale never really changes.

What makes this one different is that Ubisoft once opened the same door it is closing.

The company enabled Easy Anti-Cheat support for the Steam Deck back in July 2023, and the game has been playable there since. Now it is closing that door, saying protection cannot be meaningfully deployed on Linux, even though Easy Anti-Cheat has supported the platform for years.

Heck, even Electronic Arts seemed to be coming around earlier this year when a job listing outlining a path for its Javelin anti-cheat to support Linux and Proton appeared.

Though it is unclear how the new owners and leadership will steer the company, that plan may not survive in the end. Meanwhile, the handheld market keeps getting stronger, with SteamOS spreading to more devices than just the Deck.

And you know what's the more troubling thing here?

Cheaters always find a way in, on Windows or anywhere else.

How to Change Raspberry Pi Wi-Fi Details From the SD Card 02/09

If your Raspberry Pi can no longer connect to Wi-Fi because the SSID or password changed, you can update the Wi-Fi configuration directly from its SD card. This helps when you cannot connect the device to a monitor and keyboard.

That's what I did. I had switched to a different internet provider, and that changed the router, its SSID and the password. I was using a Raspberry Pi Pico W in my Pi Dog. Connecting it to a screen and keyboard would have been a pain.

The easier option was to just take out the SD card and edit the WiFi details directly there. The entire process is composed of the following step:

  • Insert the SD card with Raspberry Pi OS on it on your (Linux) computer
  • Go to the mounted rootfs partition and go to /etc/NetworkManager/system-connections/ location
  • Here, either create or edit .nmconnection file and enter the wifi name (SSID) and password

Let me show that in detail for you.

🚧Older Raspberry Pi OS releases may use wpa_supplicant.conf instead of NetworkManager. In that case, this method may not entirely be applicable. I have tested it on Raspberry Pi 5 running Raspberry Pi OS based on Debian Trixie.

Step 1: Connect the SD card to your computer

Shut down the Raspberry Pi, remove the microSD card, and insert it into your Linux laptop or desktop using an SD card reader.

Raspberry Pi OS usually has two partitions:

bootfs
rootfs

The Wi-Fi configuration is stored inside the rootfs partition.

Step 2. Find the SD card mount points

Open a terminal and run:

lsblk -f

You should see something similar to:

sda
├─sda1   vfat     FAT32 bootfs B2F0-82D2                             438.1M    13% /run/media/abhishek/bootfs
└─sda2   ext4     1.0   rootfs 15f4c6be-1102-4331-9904-f78e78afd1fd   21.9G    18% /run/media/abhishek/rootfs

If you only see bootfs, mounted, you can mount rootfs from the file explorer.

As you can see, for me, the Raspberry Pi root filesystem is available at:

/run/media/abhishek/rootfs

You can also confirm it with:

mount | grep rootfs
/dev/sda2 on /run/media/abhishek/rootfs type ext4 (rw,nosuid,nodev,relatime,errors=remount-ro,uhelper=udisks2

Step 3. Check the existing Wi-Fi configuration

Recent Raspberry Pi OS releases store NetworkManager connection profiles here:

/etc/NetworkManager/system-connections/
🚧Make sure to use your own username and the correct path of rootfs and files by replacing them in the command examples. You can also keep on using $USER as this environment variable automatically uses your username.

Since we are accessing Raspberry Pi OS through its SD card, run:

sudo ls -la /run/media/$USER/rootfs/etc/NetworkManager/system-connections/

If you already see a .nmconnection file, you can edit that file.

No nmconnection file? Create one

If the directory is empty, create a new Wi-Fi profile.

touch /run/media/$USER/rootfs/etc/NetworkManager/system-connections/home-wifi.nmconnection

And then use a terminal-based text editor like Nano or even Micro and add the following details:

🚧In the text below, change the value of ssid and psk with your wifi access point name and its password.
[connection]
id=home-wifi
type=wifi
interface-name=wlan0
autoconnect=true

[wifi]
mode=infrastructure
ssid=YOUR-WIFI-SSID

[wifi-security]
key-mgmt=wpa-psk
psk=YOUR-WIFI-PASSWORD

[ipv4]
method=auto

[ipv6]
method=auto
EOF

Step 4. Set the correct file permissions

Your work is almost done. You just need to set the correct file permissions. That's because NetworkManager expects connection files to be readable only by root.

To give it the correct file permissions, use the following command:

sudo chmod 600 /run/media/$USER/rootfs/etc/NetworkManager/system-connections/home-wifi.nmconnection

Verify the permissions:

sudo ls -l /run/media/$USER/rootfs/etc/NetworkManager/system-connections/

The file should look something like:

-rw------- 1 root root ... home-wifi.nmconnection
📋Before going further, double ensure that you have used the correct WiFi SSID and the password. Any typo and you will have to repeat the process. You won't want that to happen.

Step 5. Flush the changes to the SD card before removing

This is an important step. After making all the changes, run this command:

sync

The sync command makes sure any pending writes cached in memory are actually written to the SD card.

And then you can either unmount from the file explorer or use the umount command for both partitions:

sudo umount /run/media/$USER/rootfs
sudo umount /run/media/$USER/bootfs

You can now safely remove the SD card.

Step 6. Verifying the connection

Insert the card back into the Raspberry Pi and power it on. After it boots, check the devices connected on your network to find the Raspberry Pi's IP address.

The simplest way would be to log in to your router and see the connected devices.

Otherwise, Angry IP Scanner is a good graphical tool for scanning your network. Command line tool nmap also does the job:

sudo nmap -sn 192.168.0.0/24

Normally, it should show your Raspberry Pi's hostname. You can also try to run scan before turning on Pi and a few minutes after turning it on. This should show the new devices that turn up between the two scans.

Finally, check the connectivity with:

ping RASPBERRY_PI_IP

Or, if SSH is enabled on your Raspberry Pi, connect to it:

ssh username@RASPBERRY_PI_IP

By the way, if you have forgotten the user password of your Raspberry Pi, that can be easily reset too.

Pironman 5 Case With Tower Cooler and Fan

This dope Raspberry Pi 5 case has a tower cooler and dual RGB fans to keep the device cool. It also extends your Pi 5 with M.2 SSD slot and 2 standard HDMI ports.

Explore Pironman 5

Enjoy your Raspberry Pi 😄

Debian
Debian 11 Long Term Support reaches end-of-life 31/08
The Debian Long Term Support (LTS) Team hereby announces that Debian 11 bullseye support has reached its end-of-life today, 31 August 2026, five years after its initial release on 14 August 2021.
DebConf26 closes in Santa Fe and DebConf27 announced 07/08
On Saturday 25 July 2026, the annual Debian Developers and Contributors Conference came to a close.
Security support for Bookworm handed over to the LTS team 12/07
On 12 July 2026, three years after the initial release, the regular support for Debian 12, alias bookworm, has come to an end. The Debian Long Term Support (LTS) Team is taking over security support from the Security and Release Teams.
Updated Debian 12: 12.15 released 11/07
The Debian project is pleased to announce the fifteenth and final update of its oldstable distribution Debian 12 (codename bookworm). This point release mainly adds corrections for security issues, along with a few adjustments for serious problems. Security advisories have already been published separately and are referenced where available.
Updated Debian 13: 13.6 released 11/07
The Debian project is pleased to announce the sixth update of its stable distribution Debian 13 (codename trixie). This point release mainly adds corrections for security issues, along with a few adjustments for serious problems. Security advisories have already been published separately and are referenced where available.
PHP
PHP.net
PHP 8.6.0 Beta 2 available for testing 27/08
The PHP team is pleased to announce a new beta release of PHP 8.6.0, Beta 2. This continues the PHP 8.6 release cycle, the rough outline of which is specified in the PHP Wiki.For source downloads of PHP 8.6.0 Beta 2 please visit the download page.Please carefully test this version and report any issues found on GitHub.Please DO NOT use this version in production, it is an early test version.For more information on the new features and other changes, you can read the NEWS file, or the UPGRADING file for a complete list of upgrading notes. These files can also be found in the release archive.The next release will be Beta 3, planned for 10 Sep 2026.The signatures for the release can be found in the manifest or on the Release Candidates page.Thank you for helping us make PHP better.
Last Call for the State of PHP Survey 25/08
The State of PHP survey is still open, but not for much longer. It asks how PHP is working for you: what you build with, what is painful, and what you think PHP should focus on next. It takes around 15 minutes. The survey is run by The PHP Foundation in partnership with PhpStorm by JetBrains. The aggregated results will be published later this year as the State of PHP 2026 report. The anonymized raw dataset will be released along with it, so anyone in the community can check the numbers or run their own analysis. More responses mean a better picture of what matters to PHP users. If you have not filled it in yet, please do, and share it with your colleagues and user groups.
PHP 8.6.0 Beta 1 is available for testing 13/08
The PHP team is pleased to announce the first beta release of PHP 8.6.0, Beta 1. This continues the PHP 8.6 release cycle, the rough outline of which is specified in the PHP Wiki.For source downloads of PHP 8.6.0 Beta 1 please visit the download page.Please carefully test this version and report any issues found on GitHub.Please DO NOT use this version in production, it is an early test version.For more information on the new features and other changes, you can read the NEWS file, or the UPGRADING file for a complete list of upgrading notes. These files can also be found in the release archive.The next release will be Beta 2, planned for 27 Aug 2026.The signatures for the release can be found in the manifest or on the Release Candidates page.Thank you for helping us make PHP better.
PHP 8.6.0 Alpha 3 available for testing 30/07
The PHP team is pleased to announce the second testing release of PHP 8.6.0, Alpha 3. This continues the PHP 8.6 release cycle, the rough outline of which is specified in the PHP Wiki.For source downloads of PHP 8.6.0 Alpha 3 please visit the download page.Please carefully test this version and report any issues found in the GitHub Issues.Please DO NOT use this version in production, it is an early test version.For more information on the new features and other changes, you can read the NEWS file, or the UPGRADING file for a complete list of upgrading notes. These files can also be found in the release archive.The next release will be Beta 1, planned for 13 August 2026.The signatures for the release can be found in the manifest or on the pre-release builds page.Thank you for helping us make PHP better.
PHP 8.6.0 Alpha 2 available for testing 16/07
The PHP team is pleased to announce the second testing release of PHP 8.6.0, Alpha 2. This continues the PHP 8.6 release cycle, the rough outline of which is specified in the PHP Wiki.For source downloads of PHP 8.6.0 Alpha 2 please visit the download page.Please carefully test this version and report any issues found in the GitHub Issues.Please DO NOT use this version in production, it is an early test version.For more information on the new features and other changes, you can read the NEWS file, or the UPGRADING file for a complete list of upgrading notes. These files can also be found in the release archive.The next release will be Alpha 3, planned for 30 July 2026.The signatures for the release can be found in the manifest or on the pre-release builds page.Thank you for helping us make PHP better.
Journal du Hacker
Three.js, WebGPU et IA : où en est la 3D sur le web ? il y a 9h
Veille #72 - 17 actus qu'il ne fallait pas rater cette semaine il y a 14h
Comment j’ai ressuscité une Lenovo Tab P11 Pro brickée avec Fastboot, une GSI et beaucoup trop de temps libre hier
Actualité Cybersécurité de la semaine du 01/09/2026 hier

Erreur 403 | #92 - 0-days chez SonicWall et Papercut et ZeroBytes frappe à nouveau

Le modèle Astra d’OpenAI classé « risque cyber critique », zero-days activement exploitées (SonicWall SMA 1000, PaperCut), démantèlement du botnet Sality après vingt ans, fuite massive chez Zéro Logement Vacant revendiquée par ZeroBytes, détournement BGP livrant une mise à jour piégée aux clients Virtualizor, premier malware Android visant les systèmes embarqués automobiles, etc.

Comments

Une vulnérabilité sur Grafikart.fr hier
Externals.io
[RFC] [Discussion] array_str_contains() for PHP 8.7 il y a 3h

Hi

Thanks for the reminder! I will add the RFC to the overview page shortly.

It appears this hasn't happened yet.

Best regards
Tim Düsterhus

[RFC] Scan results for array_str_contains il y a 4h

‪On Fri, 4 Sept 2026 at 19:03, ‫سپهر محمودی‬‎ sepehrphpr@gmail.com wrote:‬

در تاریخ جمعه ۴ سپتامبر ۲۰۲۶، ۲۱:۱۳ David CARLIER devnexen@gmail.com نوشت:

Hi,

‪On Thu, 3 Sept 2026 at 17:21, ‫سپهر محمودی‬‎ sepehrphpr@gmail.com wrote:‬

Hey internals,

Just wanted to follow up with the real-world data I promised for array_str_contains().

I scanned the top 200 Composer packages (around 21,000 PHP files) to see how people currently handle array substring searches. Here is what I found (32 matches total):

  • array_filter with str_contains: 8
  • array_filter with strpos: 8
  • array_filter with stripos: 6
  • foreach with str_contains: 6
  • array_filter with preg_match: 4

All these different (and sometimes verbose) approaches can simply be replaced with a single, clean, and fast native call:
array_str_contains($haystack, $needle)

I’ve updated the RFC with these findings:
https://wiki.php.net/rfc/array_str_contains

If you want to check out the script or raw JSON results, I uploaded them here:
https://gist.github.com/sepehrphpr/d4d371ba682cc43c4f258de94684cc91

Let me know what you think!

Cheers,
Sepehr

quick look in the RFC about this

"Non-string values in the array are implicitly cast to strings before
the check".

Is actually the case implementation wise ?

Hi David,

Yes, non-string scalar values (like integers or floats) can be cast/treated as strings during the search (similar to how some string-matching functions handle scalar inputs), or skipped if not convertible.

I will make sure the wording in the RFC clearly explains how non-string values within the array are handled.

Best regards,
Sepehr

you probably need to update your test to demonstrate it.

[RFC] Scan results for array_str_contains il y a 4h

در تاریخ جمعه ۴ سپتامبر ۲۰۲۶، ۲۱:۱۳ David CARLIER devnexen@gmail.com نوشت:

Hi,

‪On Thu, 3 Sept 2026 at 17:21, ‫سپهر محمودی‬‎ sepehrphpr@gmail.com
wrote:‬

Hey internals,

Just wanted to follow up with the real-world data I promised for
array_str_contains().

I scanned the top 200 Composer packages (around 21,000 PHP files) to see
how people currently handle array substring searches. Here is what I found
(32 matches total):

  • array_filter with str_contains: 8
  • array_filter with strpos: 8
  • array_filter with stripos: 6
  • foreach with str_contains: 6
  • array_filter with preg_match: 4

All these different (and sometimes verbose) approaches can simply be
replaced with a single, clean, and fast native call:
array_str_contains($haystack, $needle)

I’ve updated the RFC with these findings:
https://wiki.php.net/rfc/array_str_contains

If you want to check out the script or raw JSON results, I uploaded them
here:
https://gist.github.com/sepehrphpr/d4d371ba682cc43c4f258de94684cc91

Let me know what you think!

Cheers,
Sepehr

quick look in the RFC about this

"Non-string values in the array are implicitly cast to strings before
the check".

Is actually the case implementation wise ?

Hi David,

Yes, non-string scalar values (like integers or floats) can be cast/treated
as strings during the search (similar to how some string-matching functions
handle scalar inputs), or skipped if not convertible.

I will make sure the wording in the RFC clearly explains how non-string
values within the array are handled.

Best regards,
Sepehr

[DISCUSS] Should RFCs for new functions include a userland polyfill/reference implementation? il y a 4h

Hi

And that is also independent of whether it’s stdlib or a language
feature (such as erased generics, which are fast, but have language
design arguments against).

Or in short: Performance is a property of the implementation, not a
property of the feature.

I think we're saying almost the same thing, from different directions. Performance alone is not an argument for a feature, but can be a contributing factor. Performance alone MAY be an argument against a feature, depending on the feature, but there are still many other factors to consider.

The “almost” does some heavy lifting there, I believe.

I disagree that performance should be a contributing factor to whether
or not a proposal is good, because performance is a property of the
implementation and implementation is not what is being discussed and
voted on as part of the RFC process.

knowing the relative performance difference is a useful data point to have
I disagree, because it rarely is an apples to apples comparison (bad
userland vs good internal implementation and vice versa) and it ignores
other possible solutions to fix a performance problem, for example
improving the Optimizer to detect specific patterns and to transform
them into equivalent, but faster code.

Using the featured RFC which proposes a function that effectively just does:

 array_filter($values, str_contains(?, 'foo'));

as an example, an alternative improvement to investigate would be
replacing calls to array_filter() with PFA by a foreach loop:

 $result = [];
 foreach ($values as $key => $val) {
     if (str_contains($val, 'foo')) $result[$key] = $val;
 }

similarly to the array_map() transform that is already included in PHP
8.6.

Best regards
Tim Düsterhus

[RFC] [VOTE] PREG_THROW_ON_ERROR il y a 4h

Hi

The discussion period for PREG_THROW_ON_ERROR has passed with no open
issues, so I'm opening the vote.

Recap: the RFC adds an opt-in PREG_THROW_ON_ERROR flag.
Pass it to any preg_* matching function and any PCRE error the call
records is additionally thrown as a \PregException, so you can catch it
instead of checking the return value.
The exception's code and message match preg_last_error() and
preg_last_error_msg() exactly, and a call without the flag behaves
exactly as it does today.

RFC: https://wiki.php.net/rfc/preg_throw_on_error
PR: https://github.com/php/php-src/pull/22797

Voting is open now and closes on 2026-09-18 17:00:00 UTC.

I regretfully were not able to work through the list backlog after my
summer vacation and thus also missed the intent to vote. I have just
read through the RFC and voted against it, despite being in agreement of
the general concept.

Specifically:

  1. I disagree with keeping the Warning on compilation errors. This
    feature is entirely new and opt-in, thus there are no backwards
    compatibility expectations or considerations. The $e->getMessage() === preg_last_error_msg()`` guarantee makes the feature much worse than it
    could be for compilation errors. Including all necessary information in
    the Exception is a must for me.

  2. I disagree with the behavior of not wrapping Exceptions thrown in
    user callbacks: I believe the correct choice is to throw a
    \PregException with the Exception thrown in the callback as the
    ->previous exception. Not wrapping the user callback exception means
    that one needs a catch(Exception) with a try just around the preg_
    call to reliably handle all errors during regular expression execution,
    which nullifies much of the benefit of having a dedicated exception
    class in the first place.

It also violates the exception policy in
https://github.com/php/policies/blob/main/coding-standards-and-naming.rst#throwables,
which states:

If an extension uses external functionality that may throw an exception it MUST wrap any exception thrown by that functionality into an appropriate exception of its own. It MUST set the $previous property to the original exception when doing so.

Best regards
Tim Düsterhus

Symfony Blog
Meet the Symfony Core Team at the API Platform Conference 2026! 02/09

The API Platform Conference, the international event dedicated to the API Platform framework and its ecosystem, will take place in two weeks in Lille, France, on September 17–18, 2026. Nearly 30 talks are scheduled, in both French and English, covering case studies around API Platform as well as tools and frameworks related to this project, created in 2015 and now a leading solution for building modern and efficient APIs. This year again, Symfony is a proud community partner of the event: meet us on the exhibition floor!

Among all the speakers and sessions planned during these two days, seven Symfony Core Team members will once again take the stage:

More information about the speakers and schedule can be found on the event's website.

The program leans hard into where PHP is heading next: FrankenPHP performance and tooling, AI agents and MCP as new API consumers, and honest feedback from teams running API Platform in production. Don't miss your chance to attend this incredible event, and make sure to secure your seat before tickets run out.

Any questions about the API Platform Conference 2026? Get in touch with Les-Tilleuls.coop, the event organizers.

Sponsor the Symfony project.
Introducing symfony lsp:check: Symfony-Aware Diagnostics in Your CI 31/08

A Symfony application is full of strings that mean something: route names, template paths, translation keys, service ids, bundle configuration keys. To PHP, they are strings like any others. Your CI pipeline verifies types with PHPStan or Psalm, style with PHP-CS-Fixer and behavior with PHPUnit, but nothing alerts you if you make a typo like redirectToRoute('order_confirmaton').

The latest version of the Symfony Language Tools closes that gap. The new check command runs a headless version of the Symfony-aware diagnostics from the editor integrations: against saved files, from the command line, in CI. It works for every Symfony application, whether or not anyone on the team uses an editor integration.

Your CI Doesn't Know Symfony

Symfony reports these mistakes late, or never: mistyped route names, missing templates, missing translation keys. They survive static analysis and code review because, as far as types are concerned, everything is fine. Even the PHPStan Symfony extension, which makes PHP analysis container-aware, works at the type level and inside PHP files; templates, translations, routes and configuration files stay out of its reach.

The editor integrations catch these mistakes while you type, but an editor does not review a pull request and is not attached when a script or a coding agent modifies the application. These checks belong in CI, next to the tools you already run.

One Command in Symfony CLI

If you use the Symfony CLI (version 5.20.0 or newer), you already have the checker. Run it from the root of your workspace:

$ symfony lsp:check

Project .: runtime metadata, environment dev, complete
.:src/Controller/CheckoutController.php:14:40: error [route.not_found] Route "order_confirmaton" does not exist in the selected environment.
.:templates/checkout/confirmation.html.twig:1:8: error [translation.not_found] Translation "checkout.confirmed" does not exist in domain "messages".
.:templates/checkout/confirmation.html.twig:2:13: error [template.not_found] Template "checkout/summary.html.twig" does not exist in the selected environment.
Summary: 3 diagnostics, 3 active, 0 baseline matches, 0 stale baseline entries, 3 blocking

Symfony CLI downloads the latest stable Symfony Language Tools automatically or you can download it from GitHub Releases and run symfony-lsp check; both invocations accept the same options.

Without arguments, the command discovers Symfony applications and checks all supported project files; pass files, directories or patterns to focus the analysis:

$ symfony lsp:check src/ templates/
$ symfony lsp:check 'config/**/*.yaml'

The command reports Symfony-specific problems only, 30 diagnostic codes today (symfony lsp:check --list-codes):

  • unknown routes and missing required route parameters;
  • missing templates and Twig components;
  • unknown arguments of Twig functions and filters;
  • missing translation keys, domains and message placeholders;
  • unknown services and parameters;
  • unknown console argument and option names;
  • invalid bundle configuration keys, types and enums;
  • unknown or incompatible environment variable processors;
  • unknown Messenger buses and transports, and invalid handler signatures;
  • unknown validation constraint options;
  • unknown Stimulus controllers and importmap entrypoints;
  • unknown security firewalls and user providers;
  • unknown form options and invalid event listener methods.

Runtime analysis is enabled by default: the checker boots each application in the selected Symfony environment and loads the same routes, services, bundle configuration and other runtime metadata as the editor integrations, so diagnostics reflect your real application, not a guess based on conventions. Through Symfony CLI, it also inherits the project-aware symfony php selection of PHP version and configuration. When a CI job must not execute application code, use source-only mode:

$ symfony lsp:check --source-only

Reports say which analysis mode was used, and a runtime or indexing failure marks the result as incomplete instead of silently falling back to source-only analysis.

Reports Built for CI

The default report is a deterministic, human-readable list of projects, diagnostics and summary counts; three structured formats target other tools:

$ symfony lsp:check --format=json > diagnostics.json
$ symfony lsp:check --format=github
$ symfony lsp:check --format=sarif > symfony-lsp.sarif

The GitHub format emits workflow annotations directly on files and lines. A minimal GitHub Actions job:

# .github/workflows/symfony-diagnostics.yaml
name: Symfony diagnostics

on: [push, pull_request]

jobs:
    check:
        runs-on: ubuntu-latest
        steps:
            - uses: actions/checkout@v7
            - uses: shivammathur/setup-php@v2
              with:
                  php-version: '8.4'
                  tools: symfony-cli
            - run: composer install --no-progress
            - run: symfony lsp:check --format=github

The SARIF 2.1 report can be uploaded to code-scanning systems and includes stable fingerprints, so findings can be tracked between runs.

Exit statuses distinguish findings from failures in the checker itself:

  • 0: analysis completed without blocking diagnostics;
  • 10: analysis completed with blocking diagnostics;
  • 11: invocation, configuration, selection, code policy or baseline is invalid;
  • 12: analysis is incomplete because of an indexing, timeout, process or internal failure.

A failing diagnostic provider does not discard the other providers' findings: the partial report remains available, but the incomplete status and exit code 12 prevent CI from treating it as clean.

Adopt the Checker Gradually

An existing application may already contain known diagnostics. An occurrence-specific baseline enforces new findings without hiding the existing ones:

$ symfony lsp:check --generate-baseline
$ symfony lsp:check --baseline=.symfony-lsp-baseline.json

Matches remain visible but do not block, survive unrelated line movement and distinguish repeated occurrences of the same diagnostic. Refresh the baseline explicitly with --refresh-baseline, or add --strict-baseline to require stale entries to be removed.

You can also choose which diagnostic codes block CI without filtering the report:

$ symfony lsp:check --fail-on=route.not_found,translation.not_found

Unknown codes are rejected, so a renamed or removed code cannot silently weaken the policy.

The checker and the editor integrations share the .symfony-lsp.json project configuration. Path exclusions are useful for embedded fixtures and generated sources, and missing-translation diagnostics are opt-in, as in the editor:

{
    "version": 1,
    "translationDiagnostics": true,
    "excludePaths": [
        "tests/Fixtures/**",
        "generated/"
    ]
}

See the headless diagnostics guide for output schemas, baseline behavior, privacy guarantees, caching and the complete command-line reference, and the project configuration guide for the shared settings.

Built for Agents Too

Coding agents write a growing share of your Symfony code, and they work the way CI does: no editor attached, validating their changes with command-line tools. Give them this one. An agent that runs symfony lsp:check after each change catches its own invented route names, stale template references and broken configuration before a human reviews the diff.

The command is designed for that loop: deterministic reports, stable exit codes, machine-readable formats with precise positions and a discoverable diagnostic contract. A human and an agent running the same check see exactly the same findings.

Add It to Your Pipeline

Start with a local symfony lsp:check, add a baseline if the application needs one, then choose the output format and blocking policy that fit your pipeline. Editor users keep the diagnostics they already have; now the rest of the team, the CI and your agents get them too.

If the checker reports something it should not, misses a Symfony pattern used by your application or cannot boot the project reliably, report it on the issue tracker.

Sponsor the Symfony project.
Symfony 8.1.6 released 30/08

Symfony 8.1.6 has just been released.

Read the Symfony upgrade guide to learn more about upgrading Symfony and use the SymfonyInsight upgrade reports to detect the code you will need to change in your project.

Tip

Want to be notified whenever a new Symfony release is published? Or when a version is not maintained anymore? Or only when a security issue is fixed? Consider subscribing to the Symfony Roadmap Notifications.

Changelog Since Symfony 8.1.5

  • bug #65754 [PhpUnitBridge] Fix ClockMock::hrtime() when the clock is not mocked and when the nanoseconds have leading zeros (@nicolas-grekas)
  • bug #65751 [HttpClient] Reject decompression bombs (@nicolas-grekas)
  • bug #65753 [HttpFoundation] Combine trusted host patterns into a single regexp (@nicolas-grekas)
  • bug #65748 [PropertyInfo] Read only the doc block of a promoted property in getTypeFromConstructor() (@nicolas-grekas)
  • bug #65749 [Serializer] Enforce the element type of nested scalar collections (@nicolas-grekas)
  • bug #65740 [HttpClient] Reject https:// proxies that curl would connect to in cleartext (@nicolas-grekas)
  • bug #65747 [RateLimiter] Cap the burst size and the duration computed from it (@cs278, @nicolas-grekas)
  • bug #65731 [HttpClient] Don't send the original Host header on cross-authority redirects (@nicolas-grekas)
  • bug #65742 [HttpClient] Reject 3xx pushed responses (@nicolas-grekas)
  • bug #65746 [Messenger] Drop trace args from FlattenException normalization (@ousamabenyounes, @nicolas-grekas)
  • bug #65744 [Mime] Reject an unquoted "@" in the local part of an email address (@nicolas-grekas)
  • bug #65739 [Process] Ignore invalid env var names and non-scalar env values (@nicolas-grekas, @dionisvl)
  • bug #65738 [Process] Stop leaking CGI/FastCGI request-context vars to subprocesses (@nicolas-grekas)
  • bug #65735 [Security] Avoid failing when PersistentRememberMeHandler handles a malformed cookie (@Seldaek)
  • bug #65734 [Security] Reject malformed login link parameters instead of throwing a TypeError (@davidszkiba, @nicolas-grekas)
  • bug #65733 [Security] Remove the legacy nested unserialize() call from token and exception classes (@nicolas-grekas)
  • bug #65732 [SecurityBundle] Restrict redirections to the current host when sessions are disabled (@nicolas-grekas)
  • bug #65737 [HttpKernel][Security] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store (@XananasX7)
  • bug #65736 [HttpKernel] Ignore the session id that PHP kept from a previous request (@nicolas-grekas)
  • bug #65730 [HttpKernel] Fix TypeError in UriSigner when the hash parameter is not a string (@nicolas-grekas)
  • bug #65743 [HttpFoundation] Encode the path in the X-Accel-Redirect header (@Athorcis)
  • bug #65729 [HttpFoundation] Reject reserved characters in the cookie path and domain (@nicolas-grekas)
  • bug #65728 [Routing] Fix matching the "0" URL (@cs278)
  • bug #65727 [Yaml] Fix a TypeError when "!!binary" is given an unparsable value (@nicolas-grekas)
  • bug #65745 [Filesystem] Keep tempnam() files private when a suffix is given (@iliaal)
  • bug #65726 [Filesystem] preserve source mode when copying files (@nicolas-grekas)
  • bug #65741 [HttpFoundation] Reject invalid paths (@nicolas-grekas)
  • bug #65725 [HttpFoundation] Fix parsing hosts and schemes in URLs (@nicolas-grekas)
  • minor #65724 Declare the polyfills needed by the code on PHP 7.2 (@nicolas-grekas)
  • bug #65721 [Lock] Never take the reserved "__write__" member as a Redis lock token (@nicolas-grekas)
  • bug #65718 [VarDumper] Escape UTF-8 encoded C1 control characters (@nicolas-grekas)
  • bug #65706 [Mailer][Mailchimp] Sign the webhook URL as sent and reject a non-string mandrill_events parameter (@nicolas-grekas)
  • bug #65704 [HttpClient] Drop credentials when a redirect changes the scheme (@nicolas-grekas)
  • bug #65693 [Messenger] Restrict what "X-Message-Stamp-*" headers can put in an envelope (@nicolas-grekas)
  • bug #65692 [Console][MonologBridge][VarDumper] Escape context strings written to the terminal (@nicolas-grekas)
  • bug #65691 [VarDumper] Escape context strings in HtmlDescriptor (@nicolas-grekas)
  • bug #65690 [ExpressionLanguage] Bound the nesting level of parsed expressions (@nicolas-grekas)
  • bug #65689 [SecurityBundle] Use a lock for login throttling by default (@nicolas-grekas)
  • bug #65686 [Serializer] Check the denormalized class is a Mime part in MimeMessageNormalizer (@nicolas-grekas)
  • bug #65688 [Yaml] Bound recursion depth in the inline lexer (@nicolas-grekas)
  • bug #65687 [HttpKernel] Validate the profiler token before using it as a file name (@nicolas-grekas)
  • bug #65709 [Mailer][Mailgun] Reject non-string signature fields instead of throwing a TypeError (@nicolas-grekas)
  • bug #65710 [Notifier][Twilio] Sign the query string as sent instead of the normalized one (@nicolas-grekas)
  • bug #65716 [Notifier][Lox24] Match JSON webhook requests only (@nicolas-grekas)
  • bug #65708 [Mailer][Resend] Reject a versioned signature entry without a value instead of raising a warning (@nicolas-grekas)
  • bug #65712 [Notifier][Lox24] Read the webhook payload from the JSON body (@nicolas-grekas)
  • bug #65675 [Mailer][Notifier] Reject webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65670 [Serializer] Fix deep_object_to_populate for collections of objects (@lazerg)
  • bug #65700 [Mailer][Notifier] Reject Mailgun, SendGrid and Vonage webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65701 [DoctrineBridge] Restore the tolerance for outdated remember-me tokens after concurrent requests (@nicolas-grekas)
  • bug #65702 [HtmlSanitizer] Compare schemes and hosts case-insensitively (@nicolas-grekas)
  • bug #65677 [Security] Reject OIDC discovery endpoints that downgrade to plain HTTP (@nicolas-grekas)
  • minor #65705 [Translation] Fix Persian (fa) translations for Form and Validator components (@amirreza-khaleghverdi)
  • bug #65684 [Cache][HttpFoundation] Do not unmarshall values that SodiumMarshaller cannot decrypt (@nicolas-grekas)
  • bug #65685 [Security] Narrow the race that lets a login link exceed max_uses (@nicolas-grekas)
  • bug #65699 [Mailer] Reject Mailomat webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65683 [HttpFoundation] Allow-list the values of the "X-Sendfile-Type" header (@nicolas-grekas)
  • bug #65682 [HttpFoundation] Ignore session ids that are not usable as file names in MockFileSessionStorage (@nicolas-grekas)
  • bug #65681 [HttpKernel] Strip cache-internal headers from backend responses in HttpCache (@nicolas-grekas)
  • bug #65655 [Security] Apply "signature_properties" when a remember-me token provider is used (@nicolas-grekas)
  • bug #65664 [HtmlSanitizer] Keep rejecting denied URL characters when percent-decoding yields malformed UTF-8 (@nicolas-grekas)
  • bug #65679 [Messenger] Cover the headers that describe the message with the SigningSerializer signature (@nicolas-grekas)
  • bug #65678 [SecurityBundle] Make the remember-me cookie follow the session cookie defaults (@nicolas-grekas)
  • bug #65676 [Lock] Delete a DynamoDb lock only when the caller holds it (@nicolas-grekas)
  • bug #65674 [Mailer] Use the configured secret to authenticate Postmark webhooks (@nicolas-grekas)
  • bug #65666 [VarDumper] Account for PHP 8.6 deprecating SplFileObject::getCsvControl() (@nicolas-grekas)
  • bug #65697 [VarExporter] Fix fatal error when loading code exported by versions < 8.1 (@nicolas-grekas)
  • minor #65695 [Validator] Review and finalize Indonesian (id) translation messages (@VernSG)
  • minor #65671 [Form][Validator] Review Dutch (nl) translations (@andrewo0)
  • minor #65680 [Lock] Declare symfony/http-client in the DynamoDb bridge (@nicolas-grekas)
  • minor #65665 [Validator] fix comment for Url requireTld argument (@dmitryuk)
  • bug #65662 [HtmlSanitizer] Accept percent-encoded line breaks and tabs in the query of hostless URLs (@webdevsamran)
  • bug #65660 [Cache] Respect max_execution_time in LockRegistry's wait loop (@uncaught)
  • minor #65657 [Security] Clarify AuthenticatorManager constructor docblock for deprecated eraseCredentials argument (@webdevsamran)
  • bug #65656 [Tui] Fix Tailwind font-weight and font-family utilities being treated as FIGlet fonts (@sadiqk2)
  • minor #65653 [Validator] Remove needs-review-translation state from Spanish translations (@reiarseni)
  • bug #65647 [Serializer] Fix max depth counting for subclasses that inherit MaxDepth metadata (@oliinykdm)
  • minor #65646 Review translations for Estonian (et) (@erkia)
  • bug #65651 [Yaml] Quote strings that look like octal numbers when dumping (@lazerg)
  • minor #65645 [Validator] Review Bulgarian (bg) translations (@alkinbg)
  • bug #65644 [Notifier] Fix escaping of MarkdownV2 markup in TelegramTransport (@nicolas-grekas)
  • bug #65640 [Serializer] Let DISABLE_TYPE_ENFORCEMENT keep strings that cannot be converted (@nicolas-grekas)
  • bug #65637 [Console][FrameworkBundle] Fix profiling a command stopped at ConsoleEvents::COMMAND (@Spomky)
  • minor #65593 [Validator] Improve Serbian translation messages (@kaznovac)
  • minor #65629 [Validator] #65566 Review Turkish (tr) translations (@mmustafaAydogan)
  • minor #65634 [Validator] reviewed Polish translation units 147 and 148 (@thunderer)
  • bug #65632 [HttpClient] Fix GuzzleHttpHandler consuming responses out of band (@peter17)
  • bug #65630 [HttpKernel] Fix regression when a locale aware service is never initialized (@lazerg)
  • bug #65636 [Cache] Fix authenticating to the master when using Redis Sentinel (@nicolas-grekas)
  • bug #65621 [PropertyInfo] Do not prefer a static named constructor as the property mutator (@nicolas-grekas)
  • bug #65619 [PropertyInfo] Do not prefer a static named constructor as the property accessor (@lazerg)
  • bug #65613 [Console] Fix service arguments not resolved when a command is invoked by alias or abbreviation (@lazerg)
  • minor #65615 [Validator] Review translations for Russian (ru) (@bifidokk)
  • bug #65607 [HttpKernel] Capture flushed content in HttpKernelBrowser (@vencakrecl)
  • bug #65599 [CssSelector] Fix quadratic token probing in Reader::findPattern() (@iliaal)
  • bug #65601 [VarExporter] Fix export of string parameter defaults containing escaped quotes (@iliaal)
  • bug #65598 [Filesystem] Fix makeRelative() stripping leading dots when the base path is a root (@iliaal)
  • minor #65594 [Validator] Improve Serbian (Cyrillic) translation messages (@kaznovac, @nicolas-grekas)
  • minor #65587 [Validator] Review Urdu translations (@UmairRathore)
  • bug #65597 [Filesystem] Keep tempnam() files private when a suffix is given (@iliaal)
  • bug #65596 [CssSelector] Cap the nesting depth of :is() and :where() (@iliaal)
  • bug #65589 [Mailer] Handle MailerSend webhooks version 2 (@ovgray)
  • data #64370 Release v5.4.53
Sponsor the Symfony project.
Symfony 7.4.18 released 30/08

Symfony 7.4.18 has just been released.

Read the Symfony upgrade guide to learn more about upgrading Symfony and use the SymfonyInsight upgrade reports to detect the code you will need to change in your project.

Tip

Want to be notified whenever a new Symfony release is published? Or when a version is not maintained anymore? Or only when a security issue is fixed? Consider subscribing to the Symfony Roadmap Notifications.

Changelog Since Symfony 7.4.17

  • bug #65754 [PhpUnitBridge] Fix ClockMock::hrtime() when the clock is not mocked and when the nanoseconds have leading zeros (@nicolas-grekas)
  • bug #65751 [HttpClient] Reject decompression bombs (@nicolas-grekas)
  • bug #65753 [HttpFoundation] Combine trusted host patterns into a single regexp (@nicolas-grekas)
  • bug #65740 [HttpClient] Reject https:// proxies that curl would connect to in cleartext (@nicolas-grekas)
  • bug #65747 [RateLimiter] Cap the burst size and the duration computed from it (@cs278, @nicolas-grekas)
  • bug #65731 [HttpClient] Don't send the original Host header on cross-authority redirects (@nicolas-grekas)
  • bug #65742 [HttpClient] Reject 3xx pushed responses (@nicolas-grekas)
  • bug #65746 [Messenger] Drop trace args from FlattenException normalization (@ousamabenyounes, @nicolas-grekas)
  • bug #65744 [Mime] Reject an unquoted "@" in the local part of an email address (@nicolas-grekas)
  • bug #65739 [Process] Ignore invalid env var names and non-scalar env values (@nicolas-grekas, @dionisvl)
  • bug #65738 [Process] Stop leaking CGI/FastCGI request-context vars to subprocesses (@nicolas-grekas)
  • bug #65735 [Security] Avoid failing when PersistentRememberMeHandler handles a malformed cookie (@Seldaek)
  • bug #65734 [Security] Reject malformed login link parameters instead of throwing a TypeError (@davidszkiba, @nicolas-grekas)
  • bug #65733 [Security] Remove the legacy nested unserialize() call from token and exception classes (@nicolas-grekas)
  • bug #65732 [SecurityBundle] Restrict redirections to the current host when sessions are disabled (@nicolas-grekas)
  • bug #65737 [HttpKernel][Security] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store (@XananasX7)
  • bug #65736 [HttpKernel] Ignore the session id that PHP kept from a previous request (@nicolas-grekas)
  • bug #65730 [HttpKernel] Fix TypeError in UriSigner when the hash parameter is not a string (@nicolas-grekas)
  • bug #65743 [HttpFoundation] Encode the path in the X-Accel-Redirect header (@Athorcis)
  • bug #65729 [HttpFoundation] Reject reserved characters in the cookie path and domain (@nicolas-grekas)
  • bug #65728 [Routing] Fix matching the "0" URL (@cs278)
  • bug #65727 [Yaml] Fix a TypeError when "!!binary" is given an unparsable value (@nicolas-grekas)
  • bug #65745 [Filesystem] Keep tempnam() files private when a suffix is given (@iliaal)
  • bug #65726 [Filesystem] preserve source mode when copying files (@nicolas-grekas)
  • bug #65741 [HttpFoundation] Reject invalid paths (@nicolas-grekas)
  • bug #65725 [HttpFoundation] Fix parsing hosts and schemes in URLs (@nicolas-grekas)
  • minor #65724 Declare the polyfills needed by the code on PHP 7.2 (@nicolas-grekas)
  • bug #65721 [Lock] Never take the reserved "__write__" member as a Redis lock token (@nicolas-grekas)
  • bug #65718 [VarDumper] Escape UTF-8 encoded C1 control characters (@nicolas-grekas)
  • bug #65706 [Mailer][Mailchimp] Sign the webhook URL as sent and reject a non-string mandrill_events parameter (@nicolas-grekas)
  • bug #65704 [HttpClient] Drop credentials when a redirect changes the scheme (@nicolas-grekas)
  • bug #65693 [Messenger] Restrict what "X-Message-Stamp-*" headers can put in an envelope (@nicolas-grekas)
  • bug #65692 [Console][MonologBridge][VarDumper] Escape context strings written to the terminal (@nicolas-grekas)
  • bug #65691 [VarDumper] Escape context strings in HtmlDescriptor (@nicolas-grekas)
  • bug #65690 [ExpressionLanguage] Bound the nesting level of parsed expressions (@nicolas-grekas)
  • bug #65689 [SecurityBundle] Use a lock for login throttling by default (@nicolas-grekas)
  • bug #65686 [Serializer] Check the denormalized class is a Mime part in MimeMessageNormalizer (@nicolas-grekas)
  • bug #65688 [Yaml] Bound recursion depth in the inline lexer (@nicolas-grekas)
  • bug #65687 [HttpKernel] Validate the profiler token before using it as a file name (@nicolas-grekas)
  • bug #65709 [Mailer][Mailgun] Reject non-string signature fields instead of throwing a TypeError (@nicolas-grekas)
  • bug #65710 [Notifier][Twilio] Sign the query string as sent instead of the normalized one (@nicolas-grekas)
  • bug #65716 [Notifier][Lox24] Match JSON webhook requests only (@nicolas-grekas)
  • bug #65708 [Mailer][Resend] Reject a versioned signature entry without a value instead of raising a warning (@nicolas-grekas)
  • bug #65712 [Notifier][Lox24] Read the webhook payload from the JSON body (@nicolas-grekas)
  • bug #65675 [Mailer][Notifier] Reject webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65670 [Serializer] Fix deep_object_to_populate for collections of objects (@lazerg)
  • bug #65700 [Mailer][Notifier] Reject Mailgun, SendGrid and Vonage webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65701 [DoctrineBridge] Restore the tolerance for outdated remember-me tokens after concurrent requests (@nicolas-grekas)
  • bug #65702 [HtmlSanitizer] Compare schemes and hosts case-insensitively (@nicolas-grekas)
  • bug #65677 [Security] Reject OIDC discovery endpoints that downgrade to plain HTTP (@nicolas-grekas)
  • minor #65705 [Translation] Fix Persian (fa) translations for Form and Validator components (@amirreza-khaleghverdi)
  • bug #65684 [Cache][HttpFoundation] Do not unmarshall values that SodiumMarshaller cannot decrypt (@nicolas-grekas)
  • bug #65685 [Security] Narrow the race that lets a login link exceed max_uses (@nicolas-grekas)
  • bug #65699 [Mailer] Reject Mailomat webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65683 [HttpFoundation] Allow-list the values of the "X-Sendfile-Type" header (@nicolas-grekas)
  • bug #65682 [HttpFoundation] Ignore session ids that are not usable as file names in MockFileSessionStorage (@nicolas-grekas)
  • bug #65681 [HttpKernel] Strip cache-internal headers from backend responses in HttpCache (@nicolas-grekas)
  • bug #65655 [Security] Apply "signature_properties" when a remember-me token provider is used (@nicolas-grekas)
  • bug #65664 [HtmlSanitizer] Keep rejecting denied URL characters when percent-decoding yields malformed UTF-8 (@nicolas-grekas)
  • bug #65679 [Messenger] Cover the headers that describe the message with the SigningSerializer signature (@nicolas-grekas)
  • bug #65678 [SecurityBundle] Make the remember-me cookie follow the session cookie defaults (@nicolas-grekas)
  • bug #65676 [Lock] Delete a DynamoDb lock only when the caller holds it (@nicolas-grekas)
  • bug #65674 [Mailer] Use the configured secret to authenticate Postmark webhooks (@nicolas-grekas)
  • bug #65666 [VarDumper] Account for PHP 8.6 deprecating SplFileObject::getCsvControl() (@nicolas-grekas)
  • minor #65695 [Validator] Review and finalize Indonesian (id) translation messages (@VernSG)
  • minor #65671 [Form][Validator] Review Dutch (nl) translations (@andrewo0)
  • minor #65680 [Lock] Declare symfony/http-client in the DynamoDb bridge (@nicolas-grekas)
  • bug #65662 [HtmlSanitizer] Accept percent-encoded line breaks and tabs in the query of hostless URLs (@webdevsamran)
  • bug #65660 [Cache] Respect max_execution_time in LockRegistry's wait loop (@uncaught)
  • minor #65653 [Validator] Remove needs-review-translation state from Spanish translations (@reiarseni)
  • bug #65647 [Serializer] Fix max depth counting for subclasses that inherit MaxDepth metadata (@oliinykdm)
  • minor #65646 Review translations for Estonian (et) (@erkia)
  • bug #65651 [Yaml] Quote strings that look like octal numbers when dumping (@lazerg)
  • minor #65645 [Validator] Review Bulgarian (bg) translations (@alkinbg)
  • bug #65644 [Notifier] Fix escaping of MarkdownV2 markup in TelegramTransport (@nicolas-grekas)
  • bug #65637 [Console][FrameworkBundle] Fix profiling a command stopped at ConsoleEvents::COMMAND (@Spomky)
  • minor #65593 [Validator] Improve Serbian translation messages (@kaznovac)
  • minor #65629 [Validator] #65566 Review Turkish (tr) translations (@mmustafaAydogan)
  • minor #65634 [Validator] reviewed Polish translation units 147 and 148 (@thunderer)
  • bug #65630 [HttpKernel] Fix regression when a locale aware service is never initialized (@lazerg)
  • bug #65636 [Cache] Fix authenticating to the master when using Redis Sentinel (@nicolas-grekas)
  • bug #65621 [PropertyInfo] Do not prefer a static named constructor as the property mutator (@nicolas-grekas)
  • bug #65619 [PropertyInfo] Do not prefer a static named constructor as the property accessor (@lazerg)
  • minor #65615 [Validator] Review translations for Russian (ru) (@bifidokk)
  • bug #65607 [HttpKernel] Capture flushed content in HttpKernelBrowser (@vencakrecl)
  • bug #65599 [CssSelector] Fix quadratic token probing in Reader::findPattern() (@iliaal)
  • bug #65601 [VarExporter] Fix export of string parameter defaults containing escaped quotes (@iliaal)
  • bug #65598 [Filesystem] Fix makeRelative() stripping leading dots when the base path is a root (@iliaal)
  • minor #65594 [Validator] Improve Serbian (Cyrillic) translation messages (@kaznovac, @nicolas-grekas)
  • minor #65587 [Validator] Review Urdu translations (@UmairRathore)
  • bug #65597 [Filesystem] Keep tempnam() files private when a suffix is given (@iliaal)
  • bug #65596 [CssSelector] Cap the nesting depth of :is() and :where() (@iliaal)
  • bug #65589 [Mailer] Handle MailerSend webhooks version 2 (@ovgray)
  • data #64370 Release v5.4.53
Sponsor the Symfony project.
Symfony 6.4.45 released 30/08

Symfony 6.4.45 has just been released.

Read the Symfony upgrade guide to learn more about upgrading Symfony and use the SymfonyInsight upgrade reports to detect the code you will need to change in your project.

Tip

Want to be notified whenever a new Symfony release is published? Or when a version is not maintained anymore? Or only when a security issue is fixed? Consider subscribing to the Symfony Roadmap Notifications.

Changelog Since Symfony 6.4.44

  • bug #65754 [PhpUnitBridge] Fix ClockMock::hrtime() when the clock is not mocked and when the nanoseconds have leading zeros (@nicolas-grekas)
  • bug #65751 [HttpClient] Reject decompression bombs (@nicolas-grekas)
  • bug #65753 [HttpFoundation] Combine trusted host patterns into a single regexp (@nicolas-grekas)
  • bug #65740 [HttpClient] Reject https:// proxies that curl would connect to in cleartext (@nicolas-grekas)
  • bug #65747 [RateLimiter] Cap the burst size and the duration computed from it (@cs278, @nicolas-grekas)
  • bug #65731 [HttpClient] Don't send the original Host header on cross-authority redirects (@nicolas-grekas)
  • bug #65742 [HttpClient] Reject 3xx pushed responses (@nicolas-grekas)
  • bug #65746 [Messenger] Drop trace args from FlattenException normalization (@ousamabenyounes, @nicolas-grekas)
  • bug #65744 [Mime] Reject an unquoted "@" in the local part of an email address (@nicolas-grekas)
  • bug #65739 [Process] Ignore invalid env var names and non-scalar env values (@nicolas-grekas, @dionisvl)
  • bug #65738 [Process] Stop leaking CGI/FastCGI request-context vars to subprocesses (@nicolas-grekas)
  • bug #65735 [Security] Avoid failing when PersistentRememberMeHandler handles a malformed cookie (@Seldaek)
  • bug #65734 [Security] Reject malformed login link parameters instead of throwing a TypeError (@davidszkiba, @nicolas-grekas)
  • bug #65733 [Security] Remove the legacy nested unserialize() call from token and exception classes (@nicolas-grekas)
  • bug #65732 [SecurityBundle] Restrict redirections to the current host when sessions are disabled (@nicolas-grekas)
  • bug #65737 [HttpKernel][Security] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store (@XananasX7)
  • bug #65736 [HttpKernel] Ignore the session id that PHP kept from a previous request (@nicolas-grekas)
  • bug #65730 [HttpKernel] Fix TypeError in UriSigner when the hash parameter is not a string (@nicolas-grekas)
  • bug #65743 [HttpFoundation] Encode the path in the X-Accel-Redirect header (@Athorcis)
  • bug #65729 [HttpFoundation] Reject reserved characters in the cookie path and domain (@nicolas-grekas)
  • bug #65728 [Routing] Fix matching the "0" URL (@cs278)
  • bug #65727 [Yaml] Fix a TypeError when "!!binary" is given an unparsable value (@nicolas-grekas)
  • bug #65745 [Filesystem] Keep tempnam() files private when a suffix is given (@iliaal)
  • bug #65726 [Filesystem] preserve source mode when copying files (@nicolas-grekas)
  • bug #65741 [HttpFoundation] Reject invalid paths (@nicolas-grekas)
  • bug #65725 [HttpFoundation] Fix parsing hosts and schemes in URLs (@nicolas-grekas)
  • minor #65724 Declare the polyfills needed by the code on PHP 7.2 (@nicolas-grekas)
  • bug #65721 [Lock] Never take the reserved "__write__" member as a Redis lock token (@nicolas-grekas)
  • bug #65718 [VarDumper] Escape UTF-8 encoded C1 control characters (@nicolas-grekas)
  • bug #65704 [HttpClient] Drop credentials when a redirect changes the scheme (@nicolas-grekas)
  • bug #65693 [Messenger] Restrict what "X-Message-Stamp-*" headers can put in an envelope (@nicolas-grekas)
  • bug #65692 [Console][MonologBridge][VarDumper] Escape context strings written to the terminal (@nicolas-grekas)
  • bug #65691 [VarDumper] Escape context strings in HtmlDescriptor (@nicolas-grekas)
  • bug #65690 [ExpressionLanguage] Bound the nesting level of parsed expressions (@nicolas-grekas)
  • bug #65689 [SecurityBundle] Use a lock for login throttling by default (@nicolas-grekas)
  • bug #65686 [Serializer] Check the denormalized class is a Mime part in MimeMessageNormalizer (@nicolas-grekas)
  • bug #65688 [Yaml] Bound recursion depth in the inline lexer (@nicolas-grekas)
  • bug #65687 [HttpKernel] Validate the profiler token before using it as a file name (@nicolas-grekas)
  • bug #65709 [Mailer][Mailgun] Reject non-string signature fields instead of throwing a TypeError (@nicolas-grekas)
  • bug #65710 [Notifier][Twilio] Sign the query string as sent instead of the normalized one (@nicolas-grekas)
  • bug #65670 [Serializer] Fix deep_object_to_populate for collections of objects (@lazerg)
  • bug #65700 [Mailer][Notifier] Reject Mailgun, SendGrid and Vonage webhook requests with a stale timestamp (@nicolas-grekas)
  • bug #65701 [DoctrineBridge] Restore the tolerance for outdated remember-me tokens after concurrent requests (@nicolas-grekas)
  • bug #65702 [HtmlSanitizer] Compare schemes and hosts case-insensitively (@nicolas-grekas)
  • minor #65705 [Translation] Fix Persian (fa) translations for Form and Validator components (@amirreza-khaleghverdi)
  • bug #65684 [Cache][HttpFoundation] Do not unmarshall values that SodiumMarshaller cannot decrypt (@nicolas-grekas)
  • bug #65685 [Security] Narrow the race that lets a login link exceed max_uses (@nicolas-grekas)
  • bug #65683 [HttpFoundation] Allow-list the values of the "X-Sendfile-Type" header (@nicolas-grekas)
  • bug #65682 [HttpFoundation] Ignore session ids that are not usable as file names in MockFileSessionStorage (@nicolas-grekas)
  • bug #65681 [HttpKernel] Strip cache-internal headers from backend responses in HttpCache (@nicolas-grekas)
  • bug #65655 [Security] Apply "signature_properties" when a remember-me token provider is used (@nicolas-grekas)
  • bug #65664 [HtmlSanitizer] Keep rejecting denied URL characters when percent-decoding yields malformed UTF-8 (@nicolas-grekas)
  • bug #65674 [Mailer] Use the configured secret to authenticate Postmark webhooks (@nicolas-grekas)
  • bug #65666 [VarDumper] Account for PHP 8.6 deprecating SplFileObject::getCsvControl() (@nicolas-grekas)
  • minor #65695 [Validator] Review and finalize Indonesian (id) translation messages (@VernSG)
  • minor #65671 [Form][Validator] Review Dutch (nl) translations (@andrewo0)
  • bug #65662 [HtmlSanitizer] Accept percent-encoded line breaks and tabs in the query of hostless URLs (@webdevsamran)
  • bug #65660 [Cache] Respect max_execution_time in LockRegistry's wait loop (@uncaught)
  • minor #65653 [Validator] Remove needs-review-translation state from Spanish translations (@reiarseni)
  • bug #65647 [Serializer] Fix max depth counting for subclasses that inherit MaxDepth metadata (@oliinykdm)
  • minor #65646 Review translations for Estonian (et) (@erkia)
  • bug #65651 [Yaml] Quote strings that look like octal numbers when dumping (@lazerg)
  • minor #65645 [Validator] Review Bulgarian (bg) translations (@alkinbg)
  • bug #65644 [Notifier] Fix escaping of MarkdownV2 markup in TelegramTransport (@nicolas-grekas)
  • bug #65637 [Console][FrameworkBundle] Fix profiling a command stopped at ConsoleEvents::COMMAND (@Spomky)
  • minor #65593 [Validator] Improve Serbian translation messages (@kaznovac)
  • minor #65629 [Validator] #65566 Review Turkish (tr) translations (@mmustafaAydogan)
  • minor #65634 [Validator] reviewed Polish translation units 147 and 148 (@thunderer)
  • bug #65630 [HttpKernel] Fix regression when a locale aware service is never initialized (@lazerg)
  • bug #65636 [Cache] Fix authenticating to the master when using Redis Sentinel (@nicolas-grekas)
  • bug #65621 [PropertyInfo] Do not prefer a static named constructor as the property mutator (@nicolas-grekas)
  • bug #65619 [PropertyInfo] Do not prefer a static named constructor as the property accessor (@lazerg)
  • minor #65615 [Validator] Review translations for Russian (ru) (@bifidokk)
  • bug #65607 [HttpKernel] Capture flushed content in HttpKernelBrowser (@vencakrecl)
  • bug #65599 [CssSelector] Fix quadratic token probing in Reader::findPattern() (@iliaal)
  • bug #65601 [VarExporter] Fix export of string parameter defaults containing escaped quotes (@iliaal)
  • bug #65598 [Filesystem] Fix makeRelative() stripping leading dots when the base path is a root (@iliaal)
  • minor #65594 [Validator] Improve Serbian (Cyrillic) translation messages (@kaznovac, @nicolas-grekas)
  • minor #65587 [Validator] Review Urdu translations (@UmairRathore)
  • bug #65597 [Filesystem] Keep tempnam() files private when a suffix is given (@iliaal)
  • data #64370 Release v5.4.53
Sponsor the Symfony project.
Actualités
Sud Ouest - Périgny
Rachida Dati, bientôt jugée pour corruption, va réintégrer à sa demande la magistrature il y a 1h
L’ancienne garde des Sceaux Rachida Dati, bientôt jugée pour corruption, a demandé à réintégrer la magistrature, ce qui sera fait après l’avis du Conseil supérieur de la magistrature
Le youtubeur et humoriste Greg Guillotin visé par une plainte pour violences conjugales il y a 1h
La plaignante, âgée de 27 ans aujourd’hui, accuse Grégory Guillotin de violences physiques et psychologiques répétées entre 2019 et 2026, au moment de leur relation. Elle décrit des coups mais aussi un
Affaire McKinsey : la justice fait saisir 65 millions d’euros dans l’enquête pour fraude fiscale contre le cabinet de conseil il y a 2h
Cela correspond à la quasi-totalité de la somme qu’aurait pu soustraire aux impôts en France le géant du conseil américain, visé depuis quatre ans par une enquête pour blanchiment de fraude fiscale aggravée.
Guerre en Ukraine : Trump affirme que ses émissaires se rendent à Moscou et à Kiev avec un plan « visant à mettre fin à la guerre » il y a 2h
Jared Kushner et Steve Witkoff se rendent à Moscou et à Kiev pour réaliser des entretiens avec Vladimir Poutine et Volodymyr Zelensky dans le but de « faire avancer les choses »
Crise du logement : l’Union européenne va proposer plusieurs mesures pour faciliter les restrictions anti-Airbnb il y a 3h
Le projet de loi européenne pour le logement abordable vise à donner des bases juridiques solides aux autorités locales afin de limiter le développement des locations de type Airbnb
Ouest-France
CARTE. Canicule : plusieurs records de chaleur pour un mois de septembre battus en France ce vendredi après-midi il y a 1h
Météo France a enregistré plusieurs records de chaleur pour un mois de septembre dans plusieurs stations de France. Et ce, alors que les températures devraient continuer d’augmenter ce week-end.
Des frappes israéliennes font trois morts et plus de 20 blessés dans le sud et l’est du Liban il y a 1h
Trois personnes ont été tuées vendredi par des frappes israéliennes dans le sud et l’est du Liban. Malgré la trêve en vigueur, l’armée de l’État hébreu a intensifié ses frappes après avoir annoncé jeudi la prise de la crête montagneuse Ali Taher, une position stratégique.
EN IMAGES. Lio et Ethan Hawke stars du tapis rouge, les moments marquants à soirée d’ouverture du festival de Deauville il y a 1h
C’est parti pour la 52e édition du Festival du cinéma américain à Deauville (Calvados). Revivez, minute par minute ou presque, cette première soirée.
« Il est urgent d’agir » contre les algues vertes : la famille du joggeur décédé interpelle les élus bretons il y a 2h
Jean-René Auffray est décédé il y a dix ans dans une vasière d’algues vertes à Hillion (Côtes-d’Armor). Les mots de ses proches, lus dans l’hémicycle du conseil régional, valent mieux qu’un long discours sur les algues vertes. « Agissez », exhorte sa famille.
INFO OUEST FRANCE. Une famille séquestrée par erreur pour des cryptomonnaies près de Rennes : une enquête ouverte il y a 2h
Le 22 août dernier, les locataires d’une habitation, installée dans une commune périphérique de Rennes (Ille-et-Vilaine), ont été agressés et séquestrés par un groupe d’individus. Les victimes semblent avoir été prises pour cible par erreur par les suspects, qui en voulaient aux cryptomonnaies du propriétaire des lieux. Une enquête a été ouverte.
Le Monde
Piratage du site des impôts : l’ombre de « ChatNoir », un jeune homme de 18 ans plusieurs fois mis en examen il y a 7h
Un suspect a été mis en examen le 20 août et placé en détention provisoire dans l’enquête sur les attaques informatiques ayant visé la direction générale des finances publiques. Il est déjà poursuivi dans plusieurs affaires retentissantes de piratage et de vol de données.
Rachida Dati réintègre la magistrature et se voit proposer un poste par le ministère de la justice, une semaine avant son procès pour « corruption » dans l’affaire Renault il y a 4h
Selon les informations du « Monde », un poste de premier substitut en administration centrale a été proposé à l’ancienne ministre de la culture. Une offre qui tombe quelques jours avant son renvoi devant le tribunal correctionnel à Paris.
EN DIRECT, guerre en Ukraine : Donald Trump affirme que ses émissaires se rendent à Moscou et à Kiev avec un plan « visant à mettre fin à la guerre » il y a 3h
Un drone russe a frappé vendredi après-midi le siège du service de sécurité d’Ukraine, dans le centre de Kiev. Une « escalade majeure », selon la diplomatie ukrainienne. Volodymyr Zelensky a annoncé la préparation d’une riposte.
Aide aux agriculteurs : le milliard d’euros du plan Genevard, une première réponse en attendant une vraie relance du secteur il y a 7h
Présenté comme une « réponse forte » à la sécheresse exceptionnelle de l’été 2026, le plan d’aide gouvernemental est critiqué par les syndicats agricoles. Les discussions doivent se poursuivre, notamment sur l’adaptation du secteur au changement climatique
« Mercator » : l’ONU encourage l’abandon de la projection pour l’utilisation d’une représentation cartographique plus réaliste il y a 5h
Cette réforme d’ampleur, adoptée vendredi, incite les organisations internationales et les Etats à utiliser des représentations du type « Equal Earth », plus fidèle à la taille réelle des continents.
France Info
Plus de 39°C relevés dans l'Aude, 37,2°C à Toulouse, 31,9°C en Haute-Savoie... Des températures "inédites" au mois de septembre il y a 6h
Les très fortes chaleurs observées dans le sud de la France devraient persister jusqu’à dimanche, affirme Météo-France.
Découvrez le parcours que va emprunter le pape Léon XIV lors de sa visite historique à Paris il y a 5h
Le souverain pontife doit traverser une partie de la rive gauche en papamobile vendredi 25 septembre, avant de rejoindre Notre-Dame de Paris, révèle France Télévisions.
Un homme tue par balle une femme dans le Finistère avant d'être héliporté dans un état "très critique" il y a 3h
L'homme, armé, a tué une voisine et blessé son compagnon, vendredi, à Plourin-lès-Morlaix (Finistère), selon le procureur de la République de Brest.
"Dans la vallée engloutie" : regardez le documentaire de franceinfo consacré aux crues meurtrières au Népal et au Tibet il y a 2h
Le bilan toujours provisoire de la catastrophe est de 1 308 morts et 5 624 disparus entre la Chine et le Népal.
L'ancienne ministre de la Justice Rachida Dati, bientôt jugée pour corruption, a demandé à redevenir magistrate il y a 2h
"Elle sera prochainement affectée dans le cadre de la procédure de transparence classique des magistrats", a précisé le ministère de la Justice, sollicité par franceinfo.
Météo
Périgny
Charente-Maritime (17)
17°
Nuit claire
9 km/h · 92% · 1019.1 hPa
Ven.
28° 15°
Sam.
33° 16°
Dim.
31° 19°
Lun.
24° 18°
Mar.
19° 15°
Triaize
Vendée (85)
16°
Nuit claire
10 km/h · 93% · 1019.1 hPa
Ven.
32° 14°
Sam.
33° 15°
Dim.
32° 18°
Lun.
27° 17°
Mar.
19° 14°
Dernière mise à jour : 05/09/2026 à 00:30:20 · Cache : 1h · Auto-refresh : 30 min