Weekly FOSS Release Digest — October 2026, Week 1
Notable FOSS Releases This Week
Our RSS monitoring caught a busy run of releases at the end of September and start of October. This week’s roundup leads with a genuine language milestone — Rust 1.99.0 stabilizes C-ABI variadic functions, meaning variadic functions can now be written in Rust rather than only called. Alongside it we have fresh releases from the Selenium browser-automation project, a new Quarkus LTS, the largest KrakenD gateway release since the project launched, and a self-hosted enterprise agent platform from the OpenClaw Foundation. If you build software, test it, or route API traffic at scale, there is something for you this week.
1. Rust 1.99.0 — C-ABI Variadics Land on Stable
Rust 1.99.0 shipped on 1 October 2026. The headline stabilization is defining C-ABI variadic functions with the "C" and "C-unwind" ABIs. Rust has long been able to call externally-defined variadic functions such as libc::printf; with 1.99 those functions can be written in Rust itself, using a variable argument list and the standard ... parameter syntax. The ... argument is typed as VaList, which is ABI-compatible with the C va_list across targets, and the set of types that may be read from it is guarded by the VaArgSafe trait. The release also stabilizes defining naked variadic functions with non-"C" ABIs, which must be written via inline assembly.
The second notable change settles the safety requirements for retrieving size and alignment from raw pointers to non-Sized types, stabilizing Layout::for_value_raw, mem::size_of_val_raw, and mem::align_of_val_raw. Rust 1.99 also updates the documentation for Box::leak to recommend against round-trip unleaking — patterns that later deallocate leaked memory were found to interact badly with current and future compiler optimizations, and are especially problematic alongside the upcoming stabilization of custom allocators. Use Box::into_non_null or Box::into_raw instead. A further seventeen APIs were stabilized, including VecDeque::retain_back, Vec::into_parts, and String::from_utf8_lossy_owned.
Upgrade with:
rustup update stable
Rust has a home in our directory — browse the Rust listing — or read the full announcement on the Rust Blog.
2. Selenium 4.50 — Relative Locators for Shadow DOM, BiDi Additions
Selenium 4.50 arrived on 30 September 2026 across JavaScript, Ruby, Python, .NET, Java, and the Grid. The most useful change for people writing real-world tests: relative locators in the Java and .NET bindings can now be anchored to arbitrary elements and shadow roots rather than only to the driver. Shadow DOM is increasingly common in modern front-ends, so this closes a long-standing gap between what Selenium could target and what the page actually renders.
The release also strips out deprecated Firefox profile-extension and certificate methods from every binding, with the Java, Python, and .NET bindings now declaring Firefox default preferences internally. On the WebDriver BiDi side, .NET gains screenshot image size, a screencast destination folder, Emulation.SetTextLayoutModeOverride, and activity source monitoring, while Ruby can install and uninstall web extensions through BiDi and Java now parses each BiDi command response only once. Build infrastructure also moved: releases are now built on remote build execution, Selenium Manager can be cross-compiled for all platforms from Linux or macOS, and the BiDi schema is generated from more upstream sources, including Mozilla’s Firefox CDDL.
Full details are on the Selenium project blog. Selenium does not yet have a listing in our directory — it is a strong candidate for a future addition alongside the other developer tools we track.
3. Quarkus 3.40 LTS — A New Long-Term Support Line
Quarkus 3.40 was announced on 30 September 2026 as the project’s new LTS release, built on top of Quarkus 3.39. LTS releases are supported for twelve months, which makes this the version to standardize on if you are running Quarkus in production and do not want to chase the six-week cadence. A first Beta of Quarkus 4 is separately in the works.
Because 3.40 is a direct continuation of 3.39, upgrading from 3.39 requires no migration work — the 3.40 migration guide is intentionally empty. Coming from the previous LTS (3.33), the project recommends reading the intervening release announcements carefully, since a lot of features have landed. The platform component set was refreshed in step, including Camel Quarkus to 3.40.0, Quarkus CXF to 3.40.0, Quarkus LangChain4j to 1.13.3, the Quarkus MCP Server to 2.0.1, Debezium to 3.6.3.Final, and Quarkus Vault to 4.10.0. JobRunr 9 shipped with day-one support for the new LTS, which is a good sign for the surrounding ecosystem.
Update with:
quarkus update
The command can move an application to 3.40 LTS from any prior version, including 2.x. Read the release announcement for the upgrade notes. Quarkus is not yet listed in our directory — worth flagging as a gap.
4. KrakenD 3.0 — AI Router, Semantic Cache, Streaming Manipulation
KrakenD 3.0, released on 30 September 2026, opens what the project calls Series 3 — described as the biggest jump in the gateway’s capabilities since launch. The unifying theme is that a gateway which already sat in front of your services now also sits in front of your LLM traffic, applying the same quota, security, and observability controls to it.
Streaming becomes a first-class part of the gateway core: streamed responses integrate with native features, so quota rules can read from them and modifiers can edit messages on the fly as they flow to the client, rather than buffering an entire completion. LLM token streams pass through without being buffered. The AI Router selects a model per request, either through header/CEL expression gates or through a prompt classifier integration with Not Diamond, and falls back to a configured provider when nothing matches. The Semantic Cache returns a stored answer when a new prompt means the same thing as a previous one, using a local ONNX embedding model with Redis as vector storage — every cache hit is a call you do not pay for. Prompt Guard blocks prompt injection and unsafe inputs at the gateway using regexes, CEL policies, or an external classifier, and the MCP Server gains authorization-spec authentication plus per-audience tool filtering.
Community Edition users get a real 3.0 too, though a leaner one: wildcards and array indexes in JWT claims, the HTTP method included in endpoint logs, and a substantially smaller dependency tree after deprecated components were removed. The one change to plan for is that plugin support moves to the Enterprise Edition, so Community Edition deployments relying on plugins need a migration path. Configuration files must now declare "version": 4 instead of "version": 3, or KrakenD refuses to start.
See the KrakenD 3.0 announcement for the full walkthrough. KrakenD is not yet in our directory, though it belongs in the API management category.
5. OpenClaw Enterprise — Self-Hosted Agent Control Plane
The OpenClaw Foundation announced OpenClaw Enterprise (OCE) on 30 September 2026 — an open source, self-hosted platform for running persistent AI agents in sensitive environments. The project began at OpenAI and is now developed with Red Hat and NVIDIA. It is available for self-hosting today, ahead of a 1.0 release later this year, with Docker Compose for local development and Kubernetes for internal deployments. OpenAI and Red Hat are already piloting it internally.
The problem OCE targets is candid: most IT departments currently ban agentic platforms outright, and the Foundation says the strongest feedback from organizations is that security, safety, and governance standards must improve before agents can be adopted at scale. OCE answers with an enterprise control plane on top of the original OpenClaw platform — multi-tenancy, hard security boundaries between trusted and untrusted workloads, sandboxing, LLM-based reviews, fine-grained permissions, and governance and auditability across the full agent lifecycle. The harness, model, and sandbox components can be swapped for third-party or internal implementations to keep the platform vendor-neutral, and the project will remain free to use on your own infrastructure.
Full details are in the launch coverage. There is no OpenClaw listing in our directory yet — with agents moving into enterprise infrastructure, that is a gap worth revisiting.
That’s the Week
Rust’s variadics stabilization is the release most likely to still matter in five years, but KrakenD 3.0 is the one that could quietly change how teams pay for and govern LLM traffic. If you are running any of the projects above, patch early — and if you spot a tool that should be in our directory and is not, you can submit a tool for review. Browse the full catalogue at All Tools, or catch up on last week’s digest.