What chef/chef shipped
Written by FoxPlug from public releases; not affiliated with Chef. An automatic summary of the public release, pull request and commit data of github.com/chef/chef. Chef did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Solaris mount provider now works in Target Mode, fixing Chef::Exceptions::ProviderNotFound errors when running mount resources against Solaris targets. Pull request #16383
- Fixed flaky Kitchen Test failures in the snap-change-conflict test by resolving snap package installation conflicts during end-to-end testing on Ubuntu. Pull request #16384
- Updated OpenSSL test specs to account for OpenSSL 3.5.8, which was updated to address CVE-2026-2673 and CVE-2026-31790. Pull request #16387
- Updated mixlib-archive dependency from 1.3.3 to 1.3.6. Pull request #16381
- Updated version resolution for SBOMs to use patch version in CI workflows and automated version updates. Pull request #16379
Why it matters
This week includes fixes for Solaris target support and flaky tests that improve reliability for users running Chef in different environments. Security-related dependency updates for OpenSSL ensure Chef stays current with critical fixes.
Changelog entry
- Solaris mount provider now supports Target Mode Pull request #16383
- Updated test specs to work with OpenSSL 3.5.8 Pull request #16387
- Fixed flaky snap-change-conflict test in Kitchen end-to-end tests Pull request #16384
- Updated mixlib-archive to 1.3.6 Pull request #16381
Chef 19.4 releases this week include Solaris mount provider Target Mode support, fixes for flaky snap package tests, and OpenSSL 3.5.8 updates.
Chef releases this week bring Solaris mount provider support for Target Mode, resolving errors when managing mount resources on Solaris targets. We also fixed flaky Kitchen tests for snap packages and updated OpenSSL dependencies to address recent CVEs. These changes improve reliability for Chef users across different platforms and security posture.
Week of September 14, 2026
What shipped
- Chef 19.4.36 released [0]. Release
- Fixed sensitive properties leaking values to logs when validation fails with regex constraints [1]. Pull request #16300
- Chef 18.11.24 released [2]. Release
- Fixed Target Mode to use remote target's tmp directory instead of local host's for privileged file operations [8]. Pull request #16354
- Fixed
homebrew_tapresource to work with Homebrew's Tap Trust enforcement on macOS [12]. Pull request #16367 - Fixed dscl group provider from overwriting the desired gid state [13]. Pull request #16326
- Fixed
homebrew_packageto respect the timeout property [15]. Pull request #16328 - Fixed undefined method error in Target Mode's FileUtils.chmod_R for recursive chmod operations [17]. Pull request #16355
- Updated Chef 18 SBOM generation pipeline with Habitat integration [3]. Pull request #16378
- Updated to Cookstyle 9.0 and resolved new linter offenses [16]. Pull request #16329
Why it matters
Multiple bug fixes improve stability across Target Mode operations, package management, and resource state handling. Critical security fix prevents sensitive data leakage in logs. Infrastructure updates ensure CI reliability and maintainability.
Changelog entry
- Chef 19.4.36 Release
- Fix sensitive properties leaking values to stdout/logs on validation failure Pull request #16300
- Chef 18.11.24 Release
- Chef 18.11.23 Release
- Fix debian-11 kitchen test apt-get update failure from expired bullseye-security suite Pull request #16374
- Trust Homebrew tap before tapping to work with Homebrew 6.0+ tap trust requirement Pull request #16373
- Chef 19.4.35 Release
- Fix Target Mode Dir.tmpdir to resolve remote target's tmp directory instead of local host Pull request #16354
- Chef 19.4.34 Release
- Stabilize intermittent Bundler git-clone hardlink race in GitHub Actions Pull request #16372
- Chef 19.4.33 Release
- Trust Homebrew tap before tapping so
homebrew_tapsurvives Homebrew's Tap Trust enforcement Pull request #16367 - Stop dscl group provider from mutating
new_resource.giddesired state Pull request #16326 - Fix debian/RHEL CI ruby build failure by adding pkg-config for fiddle/psych extensions Pull request #16366
- Respect timeout property in
homebrew_packageresource Pull request #16328 - Update to Cookstyle 9.0 and fix new offenses Pull request #16329
- Fix undefined method
mode_to_sin Target Mode FileUtils.chmod_R Pull request #16355
Chef 19.4.36 and 18.11.24 ship this week with fixes for sensitive property logging, Target Mode tmp directories, and Homebrew tap trust.
New releases of Chef (19.4.36, 18.11.24) include important fixes: sensitive properties no longer leak to logs on validation failure, Target Mode correctly resolves remote tmp directories for privileged operations, and homebrew_tap works with Homebrew's Tap Trust enforcement. Additional fixes improve group provider state handling and homebrew_package timeout support.