Filter: All Feature UI Bug Fix Backend Integration Frontend Security Content Documentation Analytics API Performance Accessibility Database security
May 28, 2026

Security Advisory Dependency Updates

Security Backend
This release updates several underlying components in response to security advisories. You do not need to take any action, but you should benefit from a safer, more secure experience through updated third party libraries.
May 28, 2026

Safer templates, webhooks, and embeds

Security Bug Fix Integration
This release tightens several security-sensitive flows, including custom template rendering, webhook validation, and redirect handling. It also fixes edge cases around repository slugs and makes background processing more resilient, so updates and notifications are less likely to fail unexpectedly.
March 26, 2026

Security Patch and Redis Compatibility Fixes

Security Bug Fix Backend
This release includes a security-related update to address CVE-2026-33658 affecting file uploads via Active Storage. It also resolves compatibility issues with newer Redis connection pooling behavior, helping rate limiting and caching behave more reliably in production environments.
March 26, 2026

Security patch for password hashing

Security Backend
This release includes a targeted security update to address CVE-2026-33306 related to password hashing. It helps reduce the risk of exposure from the underlying vulnerability, with no expected changes to your day-to-day workflow.
March 21, 2026

Removed Third-Party Tracking Scripts

Security Analytics Frontend
This release removes third-party tracking and feedback scripts from the app and error pages, reducing external requests and tightening the set of allowed connections. It also avoids reporting transient GitHub server errors as alerts, keeping issue reporting focused on problems that need attention.
March 07, 2026

Security Updates and Editor Cleanup

Security Frontend Backend
This release includes targeted security fixes across key libraries to help protect your app from issues like directory traversal, stored XSS, and SSRF. It also removes an unused rich text editor dependency to reduce exposure to a low-severity XSS risk and keep the frontend bundle leaner.