Two very widely used automation tools have had changes that affect their dependencies: ansible-core 2.21 and Jenkins LTS 2.580.1. In both cases the upgrade is simple only if you take an inventory first.
ansible-core 2.21
Released on 18 May 2026 (latest confirmed patch: 2.21.3 of 10 August). Source: changelog and maintenance cycle.
- Python on the controller: 3.12-3.14. On managed nodes: 3.9-3.14.
- Support: critical fixes until November 2026, security until May 2027, end of support in November 2027. 2.20 ends in May 2027.
- New features: variables registered with “projections” (fewer
set_fact), a new implicit_taskobject, PowerShell 7 modules on POSIX hosts. - Breaking change: the default PSRP negotiate service changes from WSMAN to
host; to revert, setansible_psrp_negotiate_service=WSMAN. - Removed: the
paramikoconnection plugin and some interpreter discovery options (auto_legacy). - Deprecated:
ansible.module_utils.six, theapt_keyandapt_repositorymodules (replaced bydeb822_repository) and inferring failure from the return code without afailedkey. - Security (2.21.1):
ansible-galaxy installpasses role requirements as positional arguments to prevent injection through malicious git configurations. - Collections: the Ansible 14 community package is based on 2.21; Galaxy excludes collections with an incompatible
requires_ansibleby default.community.generalno longer supports 2.17.
The migration guide for playbooks and the command line reports no significant changes. It has not been verified whether ansible-lint and ansible-navigator are compatible with 2.21 and Python 3.12-3.14: test them in your own workflow.
Jenkins LTS 2.580.1
Released on 30 September 2026; it requires Java 21 or 25. Java 17 has not been valid since the 2.555 line (April 2026). Source: LTS changelog and Java policy.
- Main risk: nine plugins are no longer bundled in the controller package (including BouncyCastle API, JAXB, SSH server, JavaMail) and, when jumping from very old versions, also JUnit, Mailer, Matrix Authorization Strategy, Matrix Project and OWASP Markup Formatter. Configurations that use them (matrix security, multi-configuration jobs, test results, email) may fail to load. Source: 2.580 upgrade guide.
- With access to the update centre, missing plugins are resolved as dependencies; without it, they must be copied manually before the upgrade.
- Security: the September 2026 advisories (2 and 16) concern the core and many plugins, with issues such as sandbox bypass, XSS and exposed credentials. Stay on a recent LTS with up-to-date plugins.
Upgrade best practices
- Inventory: Jenkins version, Java on the controller and agents, installed plugins, ansible-core and Python versions, collections in use.
- Back up
JENKINS_HOMEand test the upgrade on a copy. - Order for Jenkins: install the new Java, upgrade the controller, then the plugins; agents must have at least the controller’s minimum Java.
- Order for Ansible: upgrade Python on the controller, then ansible-core, then the collections; run the playbooks in check mode.
- Version jumps: read the guides for all the LTS versions skipped.
- Rollback: keep the backup and the previous version ready.
What has not been verified
The exact number of plugins and vulnerabilities in the advisories, the compatibility of ansible-lint and ansible-navigator, the date of ansible-core 2.21.4 and any LTS 2.580.2 have not been confirmed.
To put pipelines in code and automate releases, see Orchestration and automation.