$ cat google/month/2026-09-01.log
the month in review · September 2026
JAX free-threading push reshapes 0.11.2 and 0.12 cleanup
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
google-auth 2.59.0 declares Python 3.15 support while python-genai ships four releases and XLA:GPU flips its default dot precision.
JAX v0.11.2 google/jax
The September 18 release adds jnp.minmax, matching NumPy 2.3+, and makes log2 a first-class primitive with jax.lax.log2_p, so jax.numpy.log2 now lowers through it rather than through a decomposition. Removing the legacy IFRT device APIs in the same window is the part that will bite code still holding those device handles.
Add jax::ft_mutex and jax::ft_lock_guard with thread-safety annotations. google/jax
The wrappers in jaxlib/ft_mutex.h sit around nanobind::ft_mutex and nanobind::ft_lock_guard with Abseil thread-safety annotations, and jaxlib now uses them throughout. This is the groundwork for running JAX under Python free threading: annotations only, but the kind you want in place before anything is frozen into an ABI.
Add `PyArray::ifrt_array_ref()`, which returns `xla::ifrt::ArrayRef` instead of a raw pointer. google/jax
PyArray::ifrt_array_ref() returns an xla::ifrt::ArrayRef instead of a raw pointer, and callers were updated to use it. The old ifrt_array() is still around, so extension code keeps compiling, but new code should take the ref-counted path; it exists specifically so Array objects stay safe when the GIL is not.
feat(django-google-spanner): support Django 6.0 googleapis/google-cloud-python
django-google-spanner now targets Django 6.0 while keeping backwards compatibility with 5.2, and adds covering index support. If your ORM migrations carry explicit index configuration, the STORING/include clause generation is the piece to re-check before you turn Django 6 loose on it.
feat(firestore): configure gRPC message length limits for large documents googleapis/google-cloud-python
The Firestore client now sets grpc.max_send_message_length and grpc.max_receive_message_length on production and emulator channels, with system tests covering large-document CRUD across both sync and async paths. Documents that used to fail the channel limit now have an explicit ceiling rather than a default one.
google-auth: v2.59.0 googleapis/google-cloud-python
by release-please[bot]
The release note is a single line: "declare Python3.15 support". Nothing else changed, which is exactly what you want from an auth library on the eve of an interpreter upgrade. Pair it with 2.58.0, which added mTLS reconfiguration when the aiohttp client hits a certificate mismatch.
v2.21.0 googleapis/python-genai
by release-please[bot]
client.files.download takes a destination parameter, so downloads stream to disk or a file-like object instead of materializing in memory. This is the 2.21.0 feature at the head of the month's python-genai line, which ran through 2.25.0 and its Voices API resource in the GAOS SDK.
Reject malformed PyTreeDefProto instead of crashing google/jax
Flattening a malformed PyTreeDefProto previously assumed the post-order traversal always had enough finished subtrees on the stack; PyTreeDef::SetNumLeavesAndNumNodes now rejects the input instead of crashing. Relevant if you deserialize pytrees from anything you did not produce yourself.
$ ls google/month/ # the briefings behind this review
Keep up with Google in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.