DepLog.dev weekly dependency digest: Apr 20, 2026 to Apr 26, 2026
Weekly digest for Apr 20, 2026 to Apr 26, 2026. We tracked 17 package updates, linked the notable packages and sorted the list by risk.
Week overview
This weekly dependency digest covers Apr 20, 2026 to Apr 26, 2026 and tracks 17 package updates across nuget (4), gradle (4), maven (3), rubygems (2), pypi (2), npm (1).
Open org.springframework.boot:spring-boot-starter-data-jpa (maven) first. R80 means a risk score of 80 out of 100, so it is a fast way to sort upgrades from low review effort to urgent review.
High risk updates
Start the review queue with org.springframework.boot:spring-boot-starter-data-jpa (maven) R80, org.springframework.boot:spring-boot-starter-web (maven) R80, and org.springframework.boot:spring-boot-gradle-plugin (gradle) R80. These packages are the best candidates for a human changelog read before you move them into an upgrade PR.
DepLog combines release type, version delta and changelog signals into one score. Use the score to sort the queue, then open the linked package page for the actual release details.
- org.springframework.boot:spring-boot-starter-data-jpa (maven) sits at R80/100. Latest stable release:
3.5.14. Review the package page before moving it into an upgrade PR. - org.springframework.boot:spring-boot-starter-web (maven) sits at R80/100. Latest stable release:
3.5.14. Review the package page before moving it into an upgrade PR. - org.springframework.boot:spring-boot-gradle-plugin (gradle) sits at R80/100. Latest stable release:
3.5.14. Review the package page before moving it into an upgrade PR. - org.jetbrains.kotlin:kotlin-reflect (gradle) sits at R50/100. Latest stable release:
2.3.21. Review the package page before moving it into an upgrade PR. - org.jetbrains.kotlin:kotlin-stdlib (gradle) sits at R50/100. Latest stable release:
2.3.21. Review the package page before moving it into an upgrade PR.
Fresh releases this week
The most recent releases we saw were puma (rubygems), sorbet (rubygems), and github.com/gofiber/fiber/v2 (go). This section is the fastest way to understand what shipped most recently across your monitored ecosystems.
- puma (rubygems) published
8.0.1on 2026-04-26. Use the package page to scan changelog highlights and version delta. - sorbet (rubygems) published
0.6.13185on 2026-04-26. Use the package page to scan changelog highlights and version delta. - github.com/gofiber/fiber/v2 (go) published
2.52.13on 2026-04-25. Use the package page to scan changelog highlights and version delta. - org.projectlombok:lombok (maven) published
1.18.46on 2026-04-24. Use the package page to scan changelog highlights and version delta. - fastapi (pypi) published
0.136.1on 2026-04-23. Use the package page to scan changelog highlights and version delta.