What pulumi/pulumi shipped
Written by FoxPlug from public releases; not affiliated with Pulumi. An automatic summary of the public release, pull request and commit data of github.com/pulumi/pulumi. Pulumi did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- v3.265.0 released with pulumi logout --all --delete-credentials-key to remove encryption keys from the OS credential store and fixes for Python output-dependent resource ranges. Release
- Windows binaries are now Authenticode-signed in release builds to prevent false malware detection by Defender. Release
- Added model.Compare for structural ordering of model types by kind, name, value, and element types. Pull request #24804
- Added rapidmodel package to generate PCL model types for property-based testing with opaque types, constants, enums, and nested collections. Pull request #24803
- Fixed Python code generation for output-dependent resource ranges to avoid syntax errors in loop variables. Pull request #24474
- Fixed closure serialization of import-star cached modules in TypeScript to properly serialize CommonJS dependencies. Pull request #24797
- Implemented pluginstorage package with atomicinstall to consolidate plugin installation logic and fix Ctrl-C cancellation of file-based locks. Pull request #24711
- Policy packs now install using the same robust plugin installation strategy via atomicinstall. Pull request #24705
- Fixed pulumi logout and login to preserve shared credentials encryption key across PULUMI_HOME and credential file instances. Pull request #24764
- Fixed self-referencing resource imports in Node.js SDKs to prevent circular import issues. Pull request #24752
Why it matters
v3.265.0 brings security improvements for Windows binaries, fixes for Python code generation in complex scenarios, and better credential handling across multiple authentication contexts. The PCL interpreter and type system also received multiple correctness fixes for edge cases in tuple indexing, constant handling, and closure serialization.
Changelog entry
- Add pulumi logout --all --delete-credentials-key to delete credentials encryption key from OS credential store Release
- Generate valid Python for output-dependent resource ranges Pull request #24474
- Authenticode-sign Windows binaries in release builds Release
- Keep shared credentials key on logout and login Pull request #24764
- Add model.Compare for structural ordering of model types Pull request #24804
- Add rapidmodel package to generate PCL model types for property-based tests Pull request #24803
- Implement pluginstorage package with atomicinstall for unified plugin installation Pull request #24711
- Install policy packs using plugin installation strategy Pull request #24705
- Fix closure serialization of import-star cached modules in TypeScript Pull request #24797
- Fix self-referencing resource imports in Node.js SDKs Pull request #24752
v3.265.0 is out. Windows binaries now Authenticode-signed, Python output-dependent ranges fixed, and credentials key stays shared across logout/login cycles.
v3.265.0 released with Authenticode-signed Windows binaries to address Defender false positives, fixes for Python code generation with output-dependent resource ranges, improved credential handling across login/logout operations, and plugin/policy installation using unified atomicinstall logic.
Week of September 14, 2026
What shipped
- v3.263.0 released with fixes for deployment settings, state migrations, and dependency upgrades. Release
pulumi logscommand now prints a deprecation warning when run, with an environment variable to disable the warning. Pull request #24722pulumi watchcommand deprecated. Pull request #24720pulumi neo'spulumi_uptool no longer runs an implicit preview before updates since the user has already approved a preview. Pull request #24719- State migrations now reported through user-facing diagnostics during deployments. Pull request #24713
- Resources in
PendingReplacementstate are no longer retried for deletion, avoiding failures mid-operation. Pull request #24588 - Stacks configured with a repository URL can now migrate to a VCS integration from the CLI. Pull request #24529
pulumi deployment settings editnow accepts git authentication flags for private repositories on non-GitHub providers. Pull request #24528pulumi deployment settings editno longer overwrites a non-GitHub stack's source when run with GitHub flags. Pull request #24526- Resources retained by
pulumi state promoteare now protected from accidental deletion. Pull request #24640
Why it matters
v3.263.0 improves deployment settings management by adding authentication options for private repositories and preventing unintended overwrites when migrating between VCS providers. The release also fixes state handling during partial creates and protects promoted resources, while deprecating legacy commands like pulumi logs and pulumi watch.
Changelog entry
- Deprecate
pulumi logscommand with removal warning Pull request #24722 - Deprecate
pulumi watchcommand Pull request #24720 - Skip implicit preview in
pulumi neo'spulumi_uptool Pull request #24719 - Report state migrations through user-facing diagnostics Pull request #24713
- Avoid retrying deletion of resources in PendingReplacement state Pull request #24588
- Allow stacks with repository URL to migrate to VCS integration Pull request #24529
- Add git authentication and cache flags to
pulumi deployment settings editPull request #24528 - Add VCS trigger flags and integration ID support to
pulumi deployment settings editPull request #24527 - Update resources instead of recreating on OnError retries after partial create Pull request #24684
- Stop
pulumi deployment settings editfrom overwriting non-GitHub stack source Pull request #24526 - Protect resources retained by
pulumi state promotePull request #24640
v3.263.0 is out. Deployment settings now support git auth for private repos, state migrations are reported, and promoted resources are protected. pulumi logs and pulumi watch are deprecated.
v3.263.0 released: deployment settings add git authentication flags for private repositories on any provider, state migrations are now visible in diagnostics, resources in PendingReplacement state skip deletion retries, and stacks can migrate from repo URLs to VCS integrations. We're also deprecating pulumi logs and pulumi watch commands.