ST-2026-138Google CloudRuntime floor changed
Python 3.10 minimum active · 27 Jan 2026
Upgrade the interpreter and verify wrapper scripts, virtual environments and installation automation.
Breaking changes, enforcement dates and migration requirements.
Dates that change implementation decisions
Dates are separated into announcements, availability, transition windows, enforcement deadlines and retirement milestones. Unknown dates remain unknown.
ST-2026-138Google CloudRuntime floor changed
Upgrade the interpreter and verify wrapper scripts, virtual environments and installation automation.
ST-2026-133Google CloudNew deployments blocked
Migrate source and build configuration to a supported Go runtime, test compatibility and avoid relying on the former legacy-runtime policy exception.
ST-2026-103CloudflareDeprecated or maintenance
Use the Quick Editor log viewer for supported logging. If remote inspection is required, clone the dashboard project locally with wrangler init --from-dash and continue development with Wrangler.
ST-2026-004KubernetesRetired
Identify affected clusters and plan migration to Gateway API or another maintained ingress controller; continued operation should be treated as unsupported and security-risk-bearing.
ST-2026-137Google CloudCommand deprecated
Migrate automation to BigQuery Export and monitor for a later removal release.
ST-2026-100CloudflareContract changed
Enable Managed OAuth in the Access application or portal settings, or set oauth_configuration.enabled=true through the API; verify client discovery and browser authorization; and ensure an MCP server validates the Cf-Access-Jwt-Assertion that Access forwards to the origin.
ST-2026-015MicrosoftEnforcement active
Inspect service-principal sign-in logs for the all-zero identifier, decide whether each application should retain access, create a service principal in the resource tenant, and verify that later sign-ins carry the new object identifier.
ST-2026-041CloudflareAvailable
Rotate to newly generated token formats where appropriate, enable supported secret scanning and test revocation and replacement runbooks.
ST-2026-028GitHubRemoved
Remove dependencies on the old fields, create and manage Code Security Configurations, set an appropriate default configuration for new repositories and test migration semantics.
ST-2026-085GitHubFields removed
Migrate policy automation to the Code Security Configurations REST API or organisation settings and replace legacy new-repository defaults with a default configuration.
ST-2026-036CloudflareMajor release
Review the v7 migration guide, update types and method calls, and run integration tests before upgrading.
ST-2026-048CloudflareBreaking release
Upgrade the runtime and dependencies, review changed resources and test generated types before adoption.
ST-2026-049CloudflareBreaking release
Review retry timeouts, nullable return handling, environment configuration and URL construction before upgrading.
ST-2026-121AtlassianEnforced
Use the supported API host and Bearer header, stop expecting client-credentials refresh tokens and parse the singular scope property.
ST-2026-016AtlassianExpiration enforced
Inventory account API tokens, identify scripts still using expired or near-expiry credentials, create scoped replacement tokens with an appropriate lifetime, update secret stores, test integrations and revoke replaced credentials.
ST-2026-084GitHubField removed
Remove dependencies on the deleted object and read the core rate-limit resource for code-scanning upload capacity.
ST-2026-033ShopifyRemoved
Upgrade scripts to CLI 4 semantics, replace removed flags, and pin or disable automatic updates where CI reproducibility requires it.
ST-2026-064ShopifyBreaking release
Update scripts, choose the precise replacement flag and disable auto-updates where deterministic environments require it.
ST-2026-119AtlassianAuthentication cutover enforced
Discard stale registration and discovery state, rediscover the protected resource and OAuth server and obtain a registration recognised by the new provider.
ST-2026-067CloudflareRetired with alias
Evaluate K2.6 capability and pricing and update explicit model governance rather than relying silently on the alias.
ST-2026-010Amazon Web ServicesEnd of support
Inventory V3 package references, review the AWS V4 migration guide and breaking changes, update and test non-production workloads, then move production builds to supported V4 packages.
ST-2026-095Amazon Web ServicesRemoved or support ended
Migrate supported scripts and environments to AWS Tools for PowerShell v5 using AWS's migration guide. Test the v5 breaking changes that apply to each workload, including PowerShell/runtime floors, nullable outputs, removed or renamed parameters and cmdlets, credential resolution, and changed serialization behaviour.
ST-2026-129Amazon Web ServicesSupport ended
Assess unsupported-use risk, preserve deployment state, and plan migration to ECS Express Mode, AWS CDK Layer 3 constructs or another maintained workflow.
ST-2026-052ShopifyEnforced
Create definitions, configure access and test each customer-account integration.
ST-2026-097AtlassianContract changed
When creating a new 3LO integration, choose the resource-level grant if site-bounded access is required; exercise the consent flow, call GET /oauth/token/accessible-resources with the issued token, and route Jira or Confluence API requests with a returned cloud ID.
ST-2026-141Google CloudRuntime behaviour rollout
Update retry and alerting logic, test both gateway types and account for a rollout that can vary by zone for up to four weeks.
ST-2026-179CloudflareDefault login changed
Review the default login configuration for newly created Zero Trust organizations and explicitly add OTP or a third-party identity provider where required by the organization’s authentication design.
ST-2026-014GitHubSupport ended
Identify Python 3.9 constraints in project metadata, CI and Dependabot configuration; migrate to a supported Python release; then verify that Dependabot update jobs and pull requests resume successfully.
ST-2026-076GitHubSupport removed
Move the project and Dependabot environment to a supported Python release and verify update pull requests resume.
ST-2026-017AtlassianLegacy keys deprecated
Generate replacement keys, select a bounded expiry, copy each value at creation, move authentication out of URL query parameters, update dependent integrations, verify traffic on the new key and then delete the old credential.
ST-2026-026AtlassianRemoved
Replace v1 calls with the v2 invite API, confirm the organization meets the paid-subscription prerequisite and test invitation workflows and error handling.
ST-2026-027AtlassianRemoved
Inventory every /rest/2/ call, map it to V3, test production permissions and response contracts, and escalate any missing V3 equivalent to Atlassian.
ST-2026-068AtlassianRemoved
Inventory V2 calls, map V3 equivalents and validate production authentication, pagination and response contracts.
ST-2026-069AtlassianRemoved
Map each operation to the documented replacement and retest licensing and SCIM-managed membership constraints.
ST-2026-099Amazon Web ServicesContract changed
Have a management-account or delegated IAM Identity Center administrator explicitly enable the sso:account:access scope for each eligible application; keep exchanged tokens and credentials on the backend; then test CreateTokenWithIAM and the account, role and temporary-credential portal API calls.
ST-2026-079ShopifyRemoved
Remove calls to inventorySetScheduledChanges and redesign scheduling behaviour rather than treating immediate quantity adjustment as equivalent.
ST-2026-167VercelBeta available
Evaluate Service Bindings for internal service calls and account for Service Requests and Fast Origin Transfer billing dimensions.
ST-2026-060CloudflareBreaking release
Replace dated package imports with generated runtime types before upgrading.
ST-2026-013GitHubBreaking defaults active
Run installs on npm 11.16 or later to review warnings, use npm approve-scripts to create a committed allowlist, inventory Git and remote dependencies, and test clean CI builds before adopting npm v12.
ST-2026-034CloudflarePhased removal
Audit SDK transport and session assumptions, migrate to RPC and supported tunnel patterns, and test against a post-cutoff release.
ST-2026-058CloudflareDefault enforced
Use new_sqlite_classes for new deployments and test account-specific compatibility before rollout.
ST-2026-143Google CloudPreview feature shut down
Remove dependencies on the standalone Preview and use retained incident data and supported security workflows.
ST-2026-120MicrosoftEncryption disabled
Enable security audits, identify RC4 ticket use and migrate affected accounts and workloads to supported AES encryption.
ST-2026-139CloudflarePermission model available
Reduce read-only integrations to Admin Read and retain write permission only where mutation is required.
ST-2026-152AtlassianAPIs removed
Move reads and writes to the documented bulk workflow APIs and test transition-property handling.
ST-2026-037GoogleDeprecated
Move to a current IMA Android SDK and test ad playback, consent and measurement integrations.
ST-2026-096GitHubContract changed
Preview the immutable subject-claim prefix in the repository or organization OIDC settings UI or API, update the corresponding AWS, Azure, GCP, or other identity-provider trust policy to match the owner@ID/repository@ID format, and verify token exchange before opting in or completing a rename or transfer.
ST-2026-107CloudflareRemoved or support ended
Inventory any remaining audit_ssh network-policy rules, replace their SSH access and auditing workflow with Access for Infrastructure, and verify that the replacement provides the required access controls and session visibility.
ST-2026-168GitHubPublic preview
Opt into an Xcode 27 runner label only where public-preview and arm64-only constraints are acceptable, and validate tool-version differences from earlier images.
ST-2026-106CloudflareDeprecated or maintenance
Query the Permission Groups API for replacement IDs, remap persisted legacy Role assignments, update Account Members policy requests to use Permission Group IDs, and adapt response parsing to meta.label and meta.scopes without expecting individual permissions.
ST-2026-134AtlassianLegacy editor removed
Update administrator guidance, test workflow-editing procedures and document any feature differences in the new editor.
ST-2026-166Google CloudRuntime in Preview
Use the `nodejs26` runtime only where Preview status is acceptable and keep deployment policies aligned with the runtime support schedule.
ST-2026-102GitHubContract changed
No protection setup is required. When GitHub holds a run, a collaborator with write access must inspect it and submit approval through an authenticated web session before any job executes.
ST-2026-104Google CloudRemoved or support ended
Inventory functions that use runtime ID go122, move their code and deployment configuration to a supported Go runtime, and redeploy on that supported runtime; new and updated workloads can no longer select Go 1.22.
ST-2026-145AtlassianCredential type removed
Create least-privilege API tokens, rotate stored credentials and update Basic-authentication usernames and secrets where required.
ST-2026-158Google CloudDefault changed
Add --no-auto-commit where review-before-commit semantics are required and test on CLI 578 or later.
ST-2026-169GitHubApproval gate enforced
Account for held runs in CI operations and ensure an authorised collaborator can review and approve a legitimate held run through an authenticated web session.
ST-2026-006GitHubRetirement scheduled
Inventory GitHub Models usage, move model-access workloads to a supported alternative, test failure handling during the announced brownouts, and remove dependencies on the inference API and BYOK endpoints before retirement.
ST-2026-089Google CloudRemoved or support ended
Stop relying on the retired MCP management operations. For supported MCP services, enable the underlying API or service and use the supported MCP endpoint path. The cited release notes do not establish a replacement for Service Usage v2beta consumer-policy management.
ST-2026-162Google CloudLocation constraint enforced
Keep allowedLocations in the job region and audit qualifying older projects before their later enforcement date.
ST-2026-012GitHubEnforcement scheduled
Audit runner versions, update images and installation automation, enable or operationalise regular upgrades, test brownout exposure, and avoid pinning fleets permanently to the registration minimum.
ST-2026-174GoogleCreation deprecated
Remove or redirect Smart Campaign creation workflows, preserve supported update operations for existing campaigns, and test any replacement campaign-creation path before relying on it.
ST-2026-155Google CloudOutput column removed
Remove dependencies on the PRESERVED_STATE output column before adopting CLI 579.
ST-2026-156Google CloudFlag renamed
Replace the renamed flag and validate cluster-creation automation on CLI 579.
ST-2026-165Google CloudPreview expanded
Re-evaluate sandbox coverage where jobs or worker pools were previously excluded, while preserving Preview qualification in production decisions.
ST-2026-178GoogleVersion sunset enforced
Identify any remaining v21 request paths, migrate them to a newer supported Google Ads API version, and verify production traffic no longer depends on v21.
ST-2026-126ZendeskBreaking response change
Update response models, schema validators, persistence and downstream calculations to handle the amount-and-currency object before 6 August 2026.
ST-2026-173GitHubDefault configuration changed
If automatic Copilot code review is still desired, explicitly add or edit a repository- or organization-level ruleset to enable it rather than relying on Code Quality enablement.
ST-2026-127ContentfulBreaking response change
Test affected integrations with non-admin credentials, remove assumptions about unavailable fields and update response handling before enforcement.
ST-2026-128ContentfulBreaking pagination change
Replace skip-based iteration with pageNext/pagePrev cursor handling and update response models before 14 August 2026.
ST-2026-101OktaChange scheduled or previewed
Model and approve each requesting-to-resource application connection in Okta, set the required tokenType and connectionType values in API-managed configurations, validate the allowed user actions, and reconfigure earlier Delegation-tab access in the User access tab where Okta’s migration guidance applies.
ST-2026-074GitHubEnforcement scheduled
Patch GHES to at least the named release level before submitting support bundles through the affected commands.
ST-2026-170Google CloudDecommission scheduled
Inventory `go123` workloads and migrate them to a supported newer Go runtime before the current decommission boundary, while rechecking Google's live schedule for any postponement.
ST-2026-022Google CloudDecommissioning active
Locate workloads using go122 or go123, upgrade to a supported Go runtime, rebuild and redeploy before the applicable decommission date, and verify that deployment automation and base-image references no longer pin the retired runtime IDs.
ST-2026-098Google CloudContract changed
Inventory IAM Connectors API usage, verify automatically mirrored auth providers in the V2 authProviders resource hierarchy, and migrate IAM policies, agent code and client applications to the Agent Identity APIs before relying on the replacement path.
ST-2026-181GitHubRetention change scheduled
Before 25 August, identify UI or API workflows that rely on Dependabot alerts closed at least two years ago and prepare to use the downloadable archive for that historical data.
ST-2026-190GitHubSupport discontinuation scheduled
Plan and validate an upgrade from GitHub Enterprise Server 3.17 to a supported release before 25 August, following GitHub's supported upgrade path and prerequisites.
ST-2026-146ShopifyLegacy extension shutdown scheduled
Rebuild functionality with UI extensions and/or web pixel extensions and help merchants upgrade their pages.
ST-2026-171GitHubRetirement underway
Export existing Spark app code before 31 August 2026 if future editing is required, and treat any `llm()` dependency as a separate GitHub Models migration because that inference service already retired on 30 July.
ST-2026-177GoogleVersion sunset and deprecation scheduled
Move v202508 integrations to a supported version before 31 August, inventory v202511 usage, and plan the next upgrade before v202511's November sunset.
ST-2026-223MicrosoftRetirement scheduled
Replace manifest environment-variable dependencies before 31 August 2026 and use separate app registrations or manifests for each required environment as directed by Microsoft.
ST-2026-110ShopifyDeprecated or maintenance
Move cart calls to /api/ucp/mcp; include meta.ucp-agent.profile on every request; send a UUID meta["idempotency-key"] for cancel_cart; send the complete line_items array on each update_cart call; and validate against the updated request and response schemas.
ST-2026-071AtlassianRemoval scheduled
Remove currentVersion dependencies, update types and test against the supported fields before September.
ST-2026-172GitHubModel deprecations scheduled
Inventory explicit selection of the named models, enable and test an appropriate supported alternative before 1 September where needed, and preserve the stated Sonnet 4.6 annual-individual-plan exception.
ST-2026-230AtlassianDeprecated · parameter removal scheduled
Remove use of ?merge=true before 4 September 2026 and adopt Atlassian's supported alternative for retrieving merge-conflict information where that capability is required.
ST-2026-115GitHubAction required
Rerun GitHub's current Linux installation steps for the relevant distribution before 5 September 2026 and update container build instructions where applicable.
ST-2026-242GitHubSigning-key transition at first post-expiry release
Verify that the replacement key is trusted and refresh pre-8-April APT or RPM setup before consuming the first post-expiry release; Windows, macOS, source builds, community package managers, direct .deb files and standalone archives are outside this change.
ST-2026-225CloudflareDeprecation deadline scheduled
Migrate the Microsoft Sentinel integration to Cloudflare's Codeless Connector Framework connector before 14 September 2026 and validate the replacement ingestion path before retiring the old connector.
ST-2026-114GitHubRetirement scheduled
Upgrade browsers, Git, operating-system TLS libraries and API frameworks and verify connectivity against github.dev, where SHA-1 is already disabled.
ST-2026-236RelativityPackage removal scheduled
Migrate package references and integration testing to Relativity.ObjectManager.SDK before the scheduled 21 September 2026 removal.
ST-2026-234GitHubNode 20 removal scheduled
Validate affected actions and self-hosted runners on Node 24 before 23 September 2026 and remove dependencies on the temporary Node 20 opt-out.
ST-2026-066GitHubEnforcement phased
Upgrade registration hosts to v2.329.0 or later and operationalise installation of each release within 30 days.
ST-2026-122MicrosoftRetirement scheduled
Add the resourceType request dimension, migrate the endpoint and validate supported resource types before the retirement date.
ST-2026-185MicrosoftEndpoint retirement scheduled
Move inventory calls to /v1/extensions/product/checkinventorybyresourcetype, provide the required resourceType parameter, and validate the replacement flow before 25 September.
ST-2026-045CloudflareRetirement scheduled
Inventory legacy endpoint calls, map non-equivalent operations and test the newer API before the cutoff.
ST-2026-073CloudflareEnforcement scheduled
Validate and shorten account names before calling POST /accounts, and handle the HTTP 400 response.
ST-2026-023MicrosoftService stop scheduled
Inventory Linux Consumption function apps targeting v3, validate language and extension compatibility, migrate to Functions v4, redeploy and perform production verification before 30 September 2026.
ST-2026-030MicrosoftRetirement scheduled
Assess data volume and architecture, deploy Azure Health Data Services FHIR service, migrate data and applications, reconfigure identity and endpoints, test cutover, and separately replace SMART on FHIR proxy before its September cutoff.
ST-2026-148CloudflareAuthentication retirement scheduled
Replace X-Auth-User-Service-Key with a least-privilege API Token and update affected supporting software before the deadline.
ST-2026-163AtlassianModules scheduled for deprecation
Migrate manifests, compatibility declarations and internal links to global:fullPage before 30 September 2026.
ST-2026-220GitHubAvailable with migration scheduled
Test arm64 workflows explicitly on `windows-11-vs2026-arm`, identify Visual Studio 2022 dependencies, and prepare for the scheduled `windows-11-arm` default-image migration before the September rollout window.
ST-2026-002Google CloudEnforcement scheduled
Complete Stage 1 first, migrate permissions to IAM, map legacy API calls to Chronicle API, update webhook domains and formats, and upgrade Remote Agents to service-account authentication before the final deadline.
ST-2026-020VercelEnforcement scheduled
Inventory affected projects, upgrade runtime pins to Node.js 24, reinstall dependencies, run build and test suites, deploy and verify process.version. Use a container only as a bounded temporary alternative and assume responsibility for its Node.js security updates.
ST-2026-108ShopifyRemoval scheduled
Remove Customer.lastIncompleteCheckout and nested Checkout selections before upgrading to 2026-10. Use Storefront API cart flows for active buyer cart or checkout state, or Customer.orders for completed purchase history, according to the required workload.
ST-2026-111ShopifyContract changed
Inventory Admin GraphQL queries that filter by metafields; confirm each metafield has a definition, allows filtering and supports the comparison used; correct invalid predicates; and test against API 2026-10 before upgrading. Keep affected queries on 2026-07 or earlier until the filter is valid.
ST-2026-233GitHubRetention enforcement scheduled
Review repository, organisation or enterprise Actions retention settings and preserve any historical checks, workflow-run or status data that must remain available beyond the configured period before 1 October 2026.
ST-2026-090CloudflareDeprecated · EOL scheduled
Before 5 October 2026, migrate route operations to the route_id-based endpoints, update route-management tooling as Cloudflare directs, and change Tunnel/Mesh connection readers to the dedicated /connections endpoints; test workflows that depend on the deprecated request paths or embedded response field.
ST-2026-144CloudflareBreaking API removal scheduled
Migrate route operations to route_id endpoints and query the dedicated connections endpoint before 5 October 2026.
ST-2026-032CloudflareRetirement scheduled
Inventory legacy route calls, replace the path prefix, and test create, list, get and delete workflows before the cutoff.
ST-2026-038ShopifyEnforcement scheduled
Provision the certificate, implement annual rotation, test mTLS handshakes and monitor expiry before the enforcement date.
ST-2026-164Google CloudEndpoints scheduled for retirement
Inventory the named IDs and migrate to an appropriate supported managed model or separately deploy a documented alternative before retirement.
ST-2026-184Auth0Default transition scheduled
Audit third-party application provisioning before 23 October, explicitly set the intended security mode where workflow compatibility requires it, and test new-application creation under the strict default.
ST-2026-105Google CloudDeprecated or maintenance
Inventory functions and deployment configuration that use nodejs20, migrate them to a supported Node.js runtime, and redeploy before 30 October 2026; after decommission, new creation and updates stop and remaining workloads may be disabled.
ST-2026-011Amazon Web ServicesDefault change scheduled
Identify SDK and tool versions, opt in with AWS_NEW_RETRIES_2026 in non-production, test failure latency and retry-dependent workflows, set explicit max-attempt or retry-mode overrides where required, and deploy supported versions before the default rollout.
ST-2026-135AtlassianRetirement scheduled
Inventory calls, monitor the changelog for the replacement API and migrate before 1 November 2026.
ST-2026-154AtlassianEndpoints deprecated
Migrate each endpoint to its enhanced token-pagination replacement and remove parallel random-page assumptions.
ST-2026-024MicrosoftSupport end scheduled
Identify in-process applications, assess extension and binding compatibility, migrate projects to the isolated worker model, run functional and performance tests, and deploy before the support deadline.
ST-2026-176MicrosoftSupport end scheduled
Inventory PowerShell 7.4 installations and automation, test compatibility with a supported later release such as PowerShell 7.6 LTS, and complete controlled upgrades before the support boundary where continued support is required.
ST-2026-007GitHubRemoval scheduled
Replace the old endpoint, implement polling and retry logic for the returned report URL, validate caching and error handling, and deploy the integration change before 13 November 2026.
ST-2026-221SnowflakePhased migration pending and in progress
Inventory Cortex workloads that still depend on the allowlist, validate model-role grants and the one-time mapping in each account, explicitly grant required model roles in execution contexts where PUBLIC is not active, and test before setting the allowlist to `None` or before the scheduled enforcement phases.
ST-2026-140MicrosoftAuthentication migration scheduled
Configure the workload identity, test token exchange and remove Basic-authentication dependencies before 20 November 2026.
ST-2026-044CloudflareRemoval scheduled
Replace the boolean field, map both supported nameserver types and test read and update behaviour before the rollout window.
ST-2026-238AtlassianAnonymous-user support removal scheduled
Detect the absence of accountId and use a deliberate default for anonymous users, or move anonymous flag logic to the server-side SDK using installContext before 1 December 2026.
ST-2026-094Google CloudDeprecated or maintenance
Move Ruby workloads from google-cloud-pubsub v2.x to v3 now. Plan and test the Go v1-to-v2 migration before 31 December 2026, using Google's migration guide and accounting for the v2 client changes before updating the module dependency.
ST-2026-019ShopifyMigration required
Implement refresh-token storage and rotation, exchange each existing installation’s non-expiring credential without requiring merchant reinstall, update persistent secret state atomically, refresh proactively and on authentication failure, and monitor API Health for migration status.
ST-2026-093Amazon Web ServicesContract changed
Inventory the TypeScript compiler used by each SDK v3 project and upgrade to a supported version before its boundary, then run the project type check and address new diagnostics. If an immediate compiler upgrade is not possible, pin @aws-sdk/* packages to the last compatible release while accepting that newer SDK updates, security patches and features will not be received.
ST-2026-086OpenAIRemoval scheduled
Inventory affected model identifiers, select the documented replacement for each one and complete compatibility and quality testing before 20 January 2027.
ST-2026-062AtlassianEnd of support extended
Use the extension as bounded migration time, respond to Atlassian outreach and complete the move to Forge-supported architecture before 31 January 2027.
ST-2026-116MicrosoftPhased retirement
Export blueprint data and migrate governance deployments to Azure Deployment Stacks with template specs or Git-based templates before retirement.
ST-2026-083MicrosoftTemporary beta opt-out documented
Use the beta request only after testing and appropriate approval, confirm Policy.ReadWrite.AuthenticationMethod permissions and an Authentication Policy Administrator or equivalent role, and complete migration before 1 February 2027.
ST-2026-175MicrosoftAuthentication transition scheduled
Identify SMS and voice users, move them to phishing-resistant methods such as passkeys, test registration and support flows, and evaluate a customer-managed telecom provider only where a continuing operational or regulatory need exists.
ST-2026-245AtlassianRovo MCP v2 generally available; v1 tool transition scheduled
Adopt the v2 endpoint for new integrations, verify client compatibility and update existing integrations before the stated v1 tool-surface transition; affected clients may need cached tool identifiers or .well-known credentials cleared.
ST-2026-021Amazon Web ServicesDeprecation scheduled
Identify provided.al2 functions, migrate and test them on provided.al2023 or another supported runtime, preserve safe rollback through versions and aliases, and finish before updates to the deprecated runtime are blocked.
ST-2026-091CloudflareDeprecated · EOL scheduled
Migrate to the per-setting GET /zones/{zone_id}/settings/{setting_id} and PATCH /zones/{zone_id}/settings/{setting_id} endpoints before 31 March 2027, and test multi-setting workflows against the resulting per-setting request pattern.
ST-2026-136CloudflareEnd-of-life date extended
Replace batch reads and writes with per-setting endpoint calls and complete migration before the revised date.
ST-2026-088XeroRetirement scheduled
Move integrations to Practice Manager 3.1 and test its content-negotiation, response-format and field-selection behaviour before 30 April 2027.
ST-2026-125ZendeskRetirement scheduled
Inventory token-authenticated integrations, migrate them to OAuth, rotate or remove unused credentials and complete cutover before 30 April 2027.
ST-2026-018AtlassianExpiry rollout
Check the provisioning page for each directory’s key expiry, schedule overlap rotation before the displayed date, update the identity provider immediately after regeneration, test provisioning and de-provisioning, and securely retire the old key.
ST-2026-025HerokuDeprecated
List all heroku-22 applications, move each to a newer supported stack, rebuild dependencies and native extensions, run release and application tests, and deploy before builds are blocked.
ST-2026-113AtlassianRetirement scheduled
Inventory both GET calls, migrate filters and pagination to the corresponding v2 POST search contracts and test before the cutoff.
ST-2026-008AtlassianRemoval scheduled
Locate calls to the two deprecated endpoints, map query and pagination behavior to the new search APIs, test result differences, and deploy the replacement before the June 2027 cutoff.
ST-2026-092Amazon Web ServicesDeprecated or maintenance
Migrate supported workflows to AWS CLI v2; test scripts with AWS's v1-to-v2 migration guidance or tooling, and where other applications share the Python environment, explicitly manage botocore or s3transfer versions rather than relying on the copies bundled with CLI v1.
ST-2026-009Google CloudDeprecation active
Audit legacy endpoint use, enable and authenticate to Chronicle API, map each programmatic call to its modern equivalent, test custom integrations and feeds, and complete migration before the applicable instance cutoff.
ST-2026-153AtlassianField deprecated
Replace workflowId dependencies with workflowEntityId or the source-supported workflowName before removal.
ST-2026-046MicrosoftRetirement scheduled
Inventory calls, preserve the month-level deadline exactly and redesign affected features without assuming an undocumented replacement.
ST-2026-244CloudflareMiniflare v5 breaking transition announced
Direct Miniflare consumers should audit the documented breaking changes and update integrations when adopting v5; users of higher-level Cloudflare tools should follow those tools' release guidance.
ST-2026-241GitHubRunner deprecation visibility API available
Query the endpoint for deployed runner versions and use the returned registration and runtime timestamps to plan upgrades before the applicable support boundary.
ST-2026-243AtlassianRebalanced user-led invocation limits available
Recalculate throttling and load-test assumptions against both installation windows, preserve the unchanged per-user guard, and stop relying on the removed environment-wide limit.
ST-2026-237CloudflareContent-use boundary enforced
Set contentUse to the maximum intended use level, handle HTTP 400 policy rejections, and avoid treating a rejected crawl as a transport or authentication failure.
ST-2026-229CloudflareRuntime updated
Include V8 15.3 in runtime compatibility testing for Workers applications and investigate any application-specific differences before attributing behaviour changes to the engine update.
ST-2026-235AtlassianExperimental endpoint added
Use the experimental opt-in header, required CSM agent/edit permission and documented OAuth scope, and handle the documented default-form and HTTP 409 behaviour before adopting the endpoint.
ST-2026-240AtlassianThird-party vendor use removed in affected majors
Replace direct marketplace-client-java dependencies with Marketplace REST v4 integration before shipping or upgrading vendor plugins for the affected Data Center majors.
ST-2026-239OktaBeta in Preview
Treat the capability as Beta in Preview, supply the three documented endpoint properties, preserve issuer immutability, and validate update behavior before production adoption.
ST-2026-222AWSPublic preview available
Treat preview managed runtimes as non-production, test workload and tooling compatibility before GA, report issues during preview, and do not infer production support or SLA coverage until AWS announces GA.
ST-2026-224CloudflareLifecycle controls available
Review service-token disable and rotation procedures, choose a grace period appropriate to the workload, update consumers to the new secret within that window, and revoke or disable credentials promptly where continued authentication is not intended.
ST-2026-231AtlassianPreview · A2A v1.0 required
Set protocols.agent2Agent.version to 1.0, migrate the JSON-RPC implementation to A2A v1.0, and use Forge CLI v13.3 or later before deploying an affected connector app.
ST-2026-219OktaGenerally available
Inventory supported AI-agent and application combinations, verify Cross App Access support, define agent identity and access policy in Okta, and validate token and audit behavior before production rollout.
ST-2026-208CloudflareGenerally Available
Review configured client scopes, mark only genuinely optional permissions as optional, and ensure applications tolerate a narrower granted scope set instead of assuming every requested optional scope was approved.
ST-2026-218GitHubIdentifier path changed
Update reporting, billing analysis, automation and dashboard filters that identify Code Quality runs so they recognize `dynamic/github-code-quality/codeql` and `github-code-quality`, then verify continuity against current repository activity.
ST-2026-226AtlassianEndpoints removed
Remove dependencies on the retired native Issue Tracker endpoints and migrate issue-tracking workflows to a supported alternative before making further API calls.
ST-2026-232OktaGA · authentication methods available
Use the documented API-key or static-JWKS mechanism where it matches the workload-connection design, and validate configuration against Okta's current Privileged Access guidance.
ST-2026-209CloudflareAvailable
Reassess permission policies that added broad account-read roles only to enable Access listing, and validate that scoped members now see exactly the intended resources.
ST-2026-212CloudflarePackage transition available
Rename the dependency and imports to @cloudflare/vitest-plugin, update TypeScript types entries, and validate tests; Cloudflare provides a codemod for the migration.
ST-2026-216GitHubRemoved
Search custom CodeQL query packs for SelfHostedQuery, remove or replace that dependency, and validate the updated queries against CodeQL 2.26.3 before relying on them in code scanning.
ST-2026-211CloudflareRuntime updated
Run compatibility-sensitive test suites where application behavior depends on V8 engine semantics, but do not infer undocumented breaking changes from the version update alone.
ST-2026-217GitHubAvailable
Review incident-response runbooks and automation so credential containment targets the intended token types and verify delegated permissions and audit logging before use.
ST-2026-207CloudflareAvailable
Choose Worker-level or account-wide Access scope deliberately, review sign-in policies and bypass exceptions, and test preview and production behavior before changing access defaults.
ST-2026-210GitHubAvailable
Add refresh-token handling before forcing short-lived tokens, register only required callback URIs, review legacy wildcard behavior, and disable wildcard matching where application routing does not require it.
ST-2026-182Auth0Generally available
Update connection-management automation to use options.password_options for new Flexible Password Policy configuration and avoid sending the current and legacy password-policy fields together in one update.
ST-2026-202CloudflareAvailable
Review supported key types, enrollment flow, and application or policy MFA settings before enabling FIDO2 for infrastructure access.
ST-2026-215Amazon Web ServicesGenerally Available
Review AWS-managed role templates before use, confirm the generated or reused role grants only the intended permissions, and disable IAM Role Manager where centralized role creation is not wanted.
ST-2026-213Amazon Web ServicesGenerally Available
Evaluate the new centralized assignment surface against existing Identity Center and IAM role governance, and verify role permissions and account scope before delegating access.
ST-2026-161CloudflareUnified entrypoints available
Evaluate the unified binding or REST entrypoints and explicitly configure gateway and billing settings where adopted.
ST-2026-191Auth0Open Early Access
Treat the capability as Open Early Access and validate delegation policy, audit events and session guardrails before depending on it in production workflows.
ST-2026-160CloudflareOptional authentication available
Adopt a custom domain and Access only where endpoint authentication is required.
ST-2026-192Auth0General Availability
Review group-selection and self-service configuration if group membership synchronization is needed, and validate the resulting mappings before operational reliance.
ST-2026-204Amazon Web ServicesGenerally Available
Evaluate runtime instances when agent workloads need persistent EC2-backed capacity or sessions beyond the microVM runtime profile, and validate supported instance types, regions, and cost model before adoption.
ST-2026-159CloudflareOpt-in controls available
Configure an Access-protected custom domain when identity-aware controls are required and validate policy scope.
ST-2026-214Amazon Web ServicesConfiguration option available
Choose the initial account-access setting deliberately, document whether application-only mode is intended, and enable account access later only when its service-linked role and account-management behavior are required.
ST-2026-227OktaEarly Access in Preview
For Preview testing, review app-specific sign-in requirements and update policy automation to use USER_IDENTIFICATION rules where per-app FastPass button control is needed; do not assume Production availability.
ST-2026-228OktaGenerally available in Production
Review current breached-credential detection settings and, where the premium feed is licensed, integrate the GA retrieve/replace configuration endpoints into governed security administration and change control.
ST-2026-157Google CloudField deprecated
Inventory the field and follow replacement guidance when Google publishes it; do not assume an unstated removal date.
ST-2026-201Amazon Web ServicesGenerally Available
Evaluate Installer V2 for installation and update workflows where reduced download and extraction overhead is useful; validate existing module-management assumptions before changing established automation.
ST-2026-203CloudflareAvailable
Test dependencies and runtime behavior before advancing a Worker's compatibility date; use the documented opt-out flags if Node.js compatibility should remain disabled.
ST-2026-197CloudflareAvailable
Review the Eager redirect setting for new or existing multi-domain Access applications and validate redirect and cookie behaviour against the intended user flow before changing an established configuration.
ST-2026-198CloudflareEarly Preview
Treat the runtime as Early Preview and validate compatibility, persistence and isolation assumptions before depending on it for production workloads.
ST-2026-199CloudflareAvailable
Validate service-binding interfaces, serializable value shapes and cross-language error handling before relying on the new interoperability in production workflows.
ST-2026-206Amazon Web ServicesGenerally Available
Review GA breaking changes from the Developer Preview and validate generated schemas, converter changes and application behavior before upgrading existing preview integrations.
ST-2026-040GitHubPhased restriction
Inventory bypass-enabled tokens, move sensitive workflows to supported authentication and prepare publishing automation for the later restriction.
ST-2026-029SlackOn hold
Continue migration planning and inventory classic-app dependencies, but do not represent a final shutdown date as fixed until Slack publishes a replacement schedule.
ST-2026-193Auth0Early Access
Treat the capability as Early Access, request enablement through the Auth0 account team where available, and constrain worker credentials to the minimum required connections and scopes.
ST-2026-194Auth0Beta
Treat Enterprise Connect as Beta, contact Auth0 to evaluate it, and validate federation, claims, provisioning and connection lifecycle behavior before production dependency.
ST-2026-195Auth0Early Access
Treat the capability as Early Access, request enablement through the Auth0 account team where available, and validate agent identity and delegation semantics before operational reliance.
ST-2026-186Amazon Web ServicesTarget-framework update planned
Inventory AWS SDK for .NET consumers still relying on .NET Core 3.1 and plan a supported target before the V4.1 update; validate .NET 10 adoption where relevant.
ST-2026-196Auth0Early Access
Treat organization-level roles as Early Access and validate role definitions, permissions and invitation/group assignment behavior before replacing established authorization logic.
ST-2026-147CloudflareBreaking representation rollout
Accept both documented JSON representations during rollout, or move schema-sensitive integrations to DoH wire format.
ST-2026-188CloudflareProtocol update effective
Validate MCP clients against the stateless Streamable HTTP behaviour and prefer /mcp for current integrations while preserving compatibility handling where /sse is still used.
ST-2026-042CloudflareDeprecated
Adopt MCP SDK v2 patterns, isolate legacy bridge use and test sessionful and stateless behaviour before the next major release.
ST-2026-051AtlassianAvailable
Declare required scopes, redeploy, validate portal-only permissions and avoid treating the user as a licensed account.
ST-2026-078CloudflareMigration introduced
Adopt the v2 server form, test stateless routes and retain a bounded dual-route path where sessionful features are still required.
ST-2026-123ShopifyAvailable; prior API deprecated
Adopt shopify.printing when moving to API 2026-07, handle an empty printer list and retain the system dialog fallback, especially for PDFs.
ST-2026-187Auth0Open Early Access
Treat the capability as early-access rather than generally available, validate tenant and plan eligibility, and test authorization flows before production dependency.
ST-2026-205Amazon Web ServicesGenerally Available
Evaluate the generally available .NET SDK where Lambda durable functions fit application requirements, and validate regional availability, pricing and workflow behavior before production adoption.
ST-2026-149Google CloudFlags deprecated
Inventory use of the named flags, follow Google Cloud replacement guidance as it becomes available and avoid assuming an unstated removal deadline.
ST-2026-053CloudflareAvailable
Test browser redirection and token handling while retaining One Client for private-network routing.
ST-2026-035GoogleDeprecated
Replace integer constants with AudioGuidanceSettings and test all guidance-output combinations.
ST-2026-072AtlassianUnavailable
Suspend dependent automation, preserve failure handling and monitor the official changelog for restoration or a changed contract.
ST-2026-150Google CloudDownload default changed
Test rsync workflows on 576.0.0 or later and add --do-not-decompress wherever compressed output must be retained.
ST-2026-039ShopifyStaged enforcement
Complete verification when prompted, update onboarding instructions and plan for mandatory enforcement.
ST-2026-061CloudflareDefault changed
Review metadata-governance requirements and opt out explicitly where needed.
ST-2026-189Auth0Early Access
Treat the capability as Early Access, follow Auth0's Google social connection enablement guidance, and validate the resulting Universal Login flow before production dependency.
ST-2026-063AtlassianPhased rollout
Wait for app-specific notice, retest versioning behaviour and retain bulk-upgrade controls where needed.
ST-2026-183Auth0Session-expiry control available
Validate upstream session_expiry claims and downstream session behaviour for applicable Okta or OIDC enterprise connections before relying on the new expiry ceiling in access-control workflows.
ST-2026-050ShopifyCompatibility changed
Handle optional, extra and legacy fields defensively and continue treating field-type changes as breaking.
ST-2026-065ShopifyRuntime changed
Treat endpoint deployment as affecting existing workflows and validate backward-compatible request handling.
ST-2026-059CloudflareAvailable
Choose either exports or migrations, model renames and transfers explicitly and validate deployment output.
ST-2026-077GitHubAuthentication path changed
Update Copilot CLI, enable the organisation policy, grant copilot-requests: write and remove obsolete stored PATs after testing.
ST-2026-081ShopifyDeprecated
Move merchant rules to validation Functions and discount rejection to discount Functions before adopting later API versions.
ST-2026-080ShopifyDeprecated
Identify market-driven shipping shops, stop relying on deprecated merchant-owned profile writes and preserve app-owned profile behaviour separately.
ST-2026-109ShopifyDeprecated or maintenance
Change engagement submissions and any upstream aggregation logic to send non-cumulative values, remove reliance on isCumulative=true, and verify downstream measurement before adopting the new behavior.
ST-2026-124ShopifyField deprecated
Update GraphQL selections and downstream semantics to use approximateDiscountedUnitPrice and preserve its approximate calculation boundary.
ST-2026-180CloudflareAvailable
Enroll the required PIV keys, configure independent MFA only on the intended infrastructure applications or policies, set an appropriate MFA session duration, and validate the SSH client flow before relying on the control.
ST-2026-031GitHubPhased restriction with aggregate-history alternative
Handle empty and 403 responses explicitly, remove assumptions of public identity enumerability, migrate star-growth analytics to GitHub's privacy-safe aggregate history endpoint where appropriate, and continue monitoring for the final subscriptions-endpoint removal date.
ST-2026-070AtlassianConditional extension
Document the blocker, engage through ECOHELP and maintain a migration plan; new submissions must already comply.
ST-2026-142Google CloudCompatibility boundary documented
Upgrade the mesh CNI to 1.23.x or later before moving the cluster to the affected GKE version, or delay the GKE upgrade.
ST-2026-057GitHubAvailable
Delegate the manager role carefully, integrate audit receipts and distinguish revocation from deletion.
ST-2026-054CloudflareDefault changed
Review the default identity provider and restrict login to appropriate account members where required.
ST-2026-005SplunkTransition available
Inventory signalfx.com endpoint use, adopt the new realm-specific domains for current deployments, update RUM CSP directives and use versioned CDN URLs where required.
ST-2026-043GitHubTransition active
Test actions on Node.js 24, update unsupported hosts and remove reliance on the temporary Node.js 20 escape hatch.
ST-2026-151AtlassianAuthentication option available
Evaluate OAuth 2LO for new or rotating service-account credentials and retain existing API-token handling unless a separately evidenced migration is chosen.
ST-2026-055CloudflareAvailable
Choose a source account, govern recipient membership and test lifecycle behaviour as accounts join or leave.
ST-2026-056CloudflareAvailable
Enable and test encryption per IdP and plan certificate rollover.
ST-2026-118CloudflareAvailable
Register a client, minimise scopes, implement consent and redirect handling and complete client-domain verification before requesting public visibility.
ST-2026-001GitHubPublic preview
Evaluate ELM for repositories where downtime or large monorepo scale makes a traditional cutover difficult; confirm the supported GHES patch level and keep GitHub Enterprise Importer in the tool-selection decision.
ST-2026-130Google CloudCommand group deprecated
Move scripts and operational documentation to the agent-registry mcp-servers command group and monitor for a future removal version or date.
ST-2026-087TwilioDeprecation active
Follow the Twilio API Domain Migration Guide, update API and SDK configuration and permit api.twilio.com in network controls.
ST-2026-131GitHubToken format transition
Remove fixed-length and format validation, enlarge storage and transport fields, redact tokens robustly, and test both formats using the documented override.
ST-2026-132Google CloudCommand group deprecated
Inventory saas-runtime commands, migrate automation to app-lifecycle-manager and monitor release notes for a later removal boundary.
ST-2026-117AtlassianRe-authorisation required
Upgrade the site-admin installation, run acli jira auth login with the Web option and re-approve every affected site.
ST-2026-200GitHubAvailable
Review the documented breaking changes and test integration compatibility before opting into 2026-03-10; no immediate migration is required.
ST-2026-003SAPPhased migration
Monitor the assigned migration date, configure required new SAP Cloud Connector subaccounts, and add the new URLs to IP allow lists before the instance migration.
ST-2026-112VercelDeprecated for new projects
Move new implementations to Routing Middleware and Vercel Functions, test runtime differences, and monitor Vercel for any later removal or end-of-support date.