Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
Mongoose 9.0.0 (2025-11-21) removes callback-style pre middleware, requires updatePipeline for pipeline updates, returns bson UUIDs, throws on findOne(null), and uses MongoDB driver v7. Current release is 9.11.1 (2026-10-07); 8.x is still patched.
Laravel 13 (2026-03-17, PHP 8.3+, now v13.35) adds an AI SDK, vector queries, JSON:API resources and attributes. CSRF middleware is renamed PreventRequestForgery and cache object unserialization is off by default.
graphql 17.0.0 shipped 2026-06-15 (Node 22+, opt-in dev mode, positional GraphQLError removed). Apollo Server 5 still peers on graphql ^16.11.0 and AS4 is EOL since 2026-01-26. Apollo Client 4 needs rxjs and moved hooks to @apollo/client/react.
Hono 4.13.13 (2026-10-04) is current. 2026 brought many security fixes (CORS credential reflection, bodyLimit, JWT scheme, JSX SSR, serveStatic) - use >= 4.13.11. 4.13.0 changed cache keys, CORS default methods and RegExpRouter errors.
Current Stripe API version is 2026-09-30.endive, pinned by stripe-node 23.0.0 (2026-09-30). stripe-node 22 made the client a real ES6 class (`new Stripe()`), removed callbacks, and v23 drops Node 18.
BullMQ 6 (6.0.0 on 2026-07-30, now 6.3.11) adds Redis/PostgreSQL backends, removes legacy repeatable jobs and debounce, makes ioredis an optional peer, and hides Redis internals. Migrate to Job Schedulers on v5 before upgrading.
Flask 3.1.3 (2026-02) and Werkzeug 3.1.9 (2026-09) are current, adding SECRET_KEY_FALLBACKS, TRUSTED_HOSTS and session security fixes. Unreleased Flask 3.2 drops Python 3.9/3.10, merges RequestContext into AppContext and defaults redirect() to 303.
Socket.IO is still v4 (4.8.4, 2026-09-25). 2026 high-severity DoS fixes live in transitive packages: engine.io >= 6.6.10 and socket.io-parser >= 4.2.7. Refresh lockfiles; 4.8.4 rejects stateful regexps for dynamic namespaces.
Fastify 5.12.5 (2026-09-16) is current; v4 LTS ended 2025-06-30. Many 2026 validation-bypass CVEs require >= 5.12.5. New options (handlerTimeout, routerOptions, logController) replace deprecated top-level options removed in v6 alpha.
Redis Open Source 8.10 (latest 8.10.2, a security release) is current. Since 8.0 it is licensed under RSALv2, SSPLv1 or AGPLv3, and Search/JSON/TimeSeries/Bloom are built in. node-redis 6 and ioredis 6 default to RESP3 and need Node 20+.
tRPC 11.19.0 (2026-09-16) is current; v11 shipped 2025-03-21 and needs TypeScript >= 5.7.2 and Node 18+. Transformers moved to links, React Query v5 required, new @trpc/tanstack-react-query client, maxBatchSize since 11.15.
Express 5.2.1 (2025-12-01, Node >= 18) is npm `latest`; 4.22.x is still maintained. Avoid 5.2.0/4.22.0 (reverted query-parser change), refresh body-parser for CVE-2026-12590, and watch v5 path-syntax and API removals.
Zod 4 has been stable since 4.0.0 (2025-07-09); current is 4.6.5 (2026-09-13). Use top-level formats (z.email()), the `error` param, z.treeifyError, two-arg z.record. 4.5 added z.compile() and stricter validation (datetime seconds, code-point lengths); 4.6 added .validate() and lazy error maps.
The settled shape: API gateway → orchestrator (typed tools, retries) → model router (cheap/frontier) → verified structured outputs; Postgres + pgvector for state/memory; OTel genai spans; evals in CI; cost per feature tracked.
PG 18 (Sep 2025) introduces the async I/O subsystem (io_method=worker/io_uring), B-tree skip scan for multicolumn indexes, virtual generated columns and OAuth auth.
.NET 10 LTS (2025-11-11, now 10.0.12) with C# 14 is current. .NET 8 and 9 both lose support 2026-11-10, and .NET 11 is at RC1. Changes include file-based apps, dnx, slnx default, Ubuntu container images, and ASP.NET Core API auth redirect changes.
On Node 25+ the Admin SDK can fail through the buffer-equal-constant-time dependency path; REST (gcloud token + HTTP) is the reliable path for scripts and agents.
FastAPI remains 0.x-versioned but production-boring: the 0.140/0.141 line (mid-2026) is stability + typing polish. Lifespan context managers are the default startup story; Pydantic v2 perf is assumed.