Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

Packages

6.0k Topics 57.9k Posts

Questions about packages in the App Store

Subcategories


  • 9 75
    9 Topics
    75 Posts
    Package UpdatesP
    [1.20.2] Update 2FAuth to 8.0.2 Full Changelog issue #563 API tokens does not works on OpenID accounts issue #565 Trailing slash "/" needed for extension to work issue #569 Server error page shown after sharing with no email configured
  • 10 86
    10 Topics
    86 Posts
    Package UpdatesP
    [1.8.1] Update Ackee to 3.6.1 Full Changelog Action values can now be omitted or set to null when creating actions, matching the existing support for resetting values on update HTTP responses now include security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, etc.) via helmet The Time-Zone request header is now validated before use; invalid values fall back to the server timezone silently Free-text fields in the database (source, deviceName, deviceManufacturer, osName, osVersion, browserName, browserVersion, title, key, details) now enforce maximum length limits to prevent storage abuse
  • 7 62
    7 Topics
    62 Posts
    Package UpdatesP
    [1.29.0] Update actual to 26.9.0 Full Changelog View release notes
  • 41 437
    41 Topics
    437 Posts
    Package UpdatesP
    [1.14.19] Update AdGuardHome to 0.107.79 Full Changelog Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in [1.26.6][go-1.26.6]. AdGuard Home is now more resistant to resource exhaustion attacks when using DNS-over-QUIC. Bootstrap servers configuration now supports comments. New property "language" in POST /control/install/check_config and POST /control/install/configure HTTP APIs. The user is able to remove the static lease's hostname via the HTTP API. The edge channel has been switched to the new UI and versioning scheme. strict_sni_check is now deprecated. DNS64 treating unresolved CNAME/DNAME answers as the end of resolution chain (#7514). Blocked requests without an EDNS(0) OPT record (#8183).
  • 12 115
    12 Topics
    115 Posts
    S
    This look like a good replacement for Alltube (which we were using) https://github.com/alexta69/metube
  • 4 8
    4 Topics
    8 Posts
    O
    Hello I tried installing AFFiNE, and it looks like it works well. However, I am struggling to install/set up AFFiNE with a local LLM provider. Context: My backend is a Mac (not the Cloudron server) that runs a local LLM (via KoboldCPP), and other Cloudron apps (++) can access this perfectly well via the LAN IP. Not so with AFFiNE. For some reason, I first struggled to get anything other than error messages, and now, I get the following error message: You've reached the current usage cap for AFFiNE AI. You can subscribe to AFFiNE AI(with free 7-day-trial) to continue the AI experience! This error message persists even if I followed AI advice to set the env variable to self hosted: cloudron env set selfhosted=true Has anyone successfully set up AFFiNE with a local LLM, like my setup? Anyone have any advice for me?
  • 16 194
    16 Topics
    194 Posts
    Package UpdatesP
    [1.30.0] Update ampache to 8.1.0 Full Changelog Proof of work checks in front of the endpoints bots hammer Database 810011: New album.enabled and artist.enabled, so a release can be withdrawn without deleting it and losing its playlist entries, ratings and play history New album_grouping_fields option controlling which fields decide whether two songs share an album row Drawn cover art for items that have none: an album gets a record, an artist a medallion, an orphaned song a waveform, a playlist a tracklist The OPML export of podcast subscriptions read every podcast in the system regardless of the caller's catalog filter, letting a restricted user enumerate the subscriptions of catalogs they cannot browse A username was used raw as an upload folder name, so ../.. escaped the catalog. Path segments are no longer allowed in username A disabled user account could still authenticate through Subsonic and an RSS feed token Password/token comparisons in the API handshake, the session_remember cookie MAC, and API key/stream token lookups used ===/!= instead of hash_equals() Ldap::auth() concatenated the raw username into the LDAP search filter and group-membership regex with no escaping Private playlists and searches leaked through several endpoints: web smartlist, Subsonic getPlaylist/getPlaylists
  • 7 Topics
    68 Posts
    Package UpdatesP
    [1.7.2] Update answer to 2.0.2 Full Changelog Add reasoning content support in AI conversation records and chat UI to preserve model thinking output across follow-up rounds (@hgaol #1530) Allow disabling email verification from site settings for deployments that do not require mandatory email confirmation (@AsyncAssassin #1540) Add recovery middleware to handle unexpected panics more gracefully in HTTP requests (@hhc7 #1537) Add interval support for new question email notifications (@AsyncAssassin #1545) Move new question email throttling to a dedicated worker and make the email queue configurable for better operational control (@AsyncAssassin) Fix edit question failing when short links are enabled (@LinkinStars #1554) Fix missing license entry for mozillazg-go-unidecode (@LinkinStars #1552) Prevent incorrect external login account binding during connector sign-in flows (@LinkinStars) Align revision audit permission checks for both approve and reject actions (@LinkinStars) Preserve accepted answer operations when short links are enabled (@hgaol #1541)
  • 6 28
    6 Topics
    28 Posts
    K
    @girish I understand. Thanks!
  • 4 25
    4 Topics
    25 Posts
    jamesJ
    Hello @andreasdueren Thanks for the report. Fixing it right now.
  • 8 Topics
    122 Posts
    Package UpdatesP
    [1.100.1] Update audiobookshelf to 2.36.1 Full Changelog Collapse series not working when filters are enabled #2807 #3049 by @schummar in #5280 Podcast rescan emitting stale episodes on item_updated by @mikiher in #5409 Updating or deleting a narrator in one library applying the change to all libraries Author endpoints not checking user can access the author's library Share endpoints not sending 404 status Upload endpoint not handling directory creation errors sqlite3 bindings not installing when using npm v12 #5412 by @Vito0912 in #5429 API: Settings PATCH endpoint only accepts a fixed set of general settings (auth settings must go through the auth-settings endpoint) API: Cover endpoints only allow webp, jpeg and png as optional format param API: Library item media update no longer accepts ebookFile, chapters and audioFiles in request body
  • 10 35
    10 Topics
    35 Posts
    girishG
    Thanks for reporting here @gardinermichael . We have in fact hidden the app package because there were many issues with it and we couldn't manage to get it to be stable . Maybe we should revisit this.
  • 40 411
    40 Topics
    411 Posts
    Package UpdatesP
    [1.39.1] Update baserow to 2.3.4 Full Changelog [Database] Fixed a bug where column resizes and other field option changes weren't shown to other users in real time #5827 [Database] Fixed missing row update permission check when importing rows with upsert configuration. #5916 [Database] Write-only data sync fields are excluded from workspace exports #5918 [Database] Restricted ad hoc filters on publicly shared calendar views to the view's visible fields. #6080 [Database] Resolved a bug which caused an AI field self-referencing to recurse indefinitely.
  • 5 67
    5 Topics
    67 Posts
    Package UpdatesP
    [1.8.0] Update beszel to 0.20.0 Full Changelog Add network monitoring from agents (#2266, #1911) Add container image update available flag (#2211) Add btrfs filesystem reporting as storage pools (#2315) Add persistence of view preferences and language to user settings (#1831) Add TRUSTED_PROXY_IPS allowlist for TRUSTED_AUTH_HEADER (#2327) Revert SMART warnings for certain attributes (#2296, #2308, #2347) Improve NVMe data units display as human-readable GB/TB (#2303) Fix agent disconnects during slow collections by extending WebSocket deadline (#2294) Fix false RAID health warnings during healthy data scrubbing (#2109) Fix session handling to clear auth store after token expiry (#2310)
  • 13 260
    13 Topics
    260 Posts
    Package UpdatesP
    [2.1.5] Update BookStack to 26.05.5 Full Changelog Updated social logins to scope social account queries to social system. Updated PHP package versions.
  • 1 10
    1 Topics
    10 Posts
    Package UpdatesP
    [1.1.0] Update bugsink to 2.6.0 Full Changelog Users can now create personal API tokens that follow their current permissions, optionally limited to one project. Each token has an explicit set of capabilities, such as reading issues, triaging them or uploading debug files. Superusers can also create service tokens for integrations that should operate independently of a user account. These limits are enforced in both the canonical and Sentry-compatible APIs, and endpoint requirements are included in the OpenAPI documentation. See #216. Existing tokens keep their full installation-wide access after upgrading. Tokens can be revoked from the token list. Issue and event searches can now filter by request URL, for example url:"https://example.org/checkout". URLs are stored as tags for newly ingested events, with query strings and fragments removed so equivalent pages share a value. See #269. Alerts can now be sent to Google Chat spaces using incoming webhooks. See #326. Show newest events first in an issue's event list, including filtered results, see #485. Show friendly issue IDs in project issue lists, see #509. Parse quoted search terms consistently, including colons in values and escaped quotes, see #501.
  • 11 130
    11 Topics
    130 Posts
    Package UpdatesP
    [2.10.3] fix: update doc links from /apps/ to /packages/
  • 56 712
    56 Topics
    712 Posts
    jdaviescoatesJ
    @Mathieu I don't think going to an old version would be wise - very likely to have security flaws (it was AI based attacks which led them to close their code). I've not tried it at all yet (I'm just using the free hosted version of Cal.com as I don't need teams etc), but perhaps see if @ekevu123 could (or already has) add team functions to Tymeslot?
  • 19 93
    19 Topics
    93 Posts
    L
    Currently when sharing a calendar, we can only share with other Calendar users. I'd like to share my profesionnal calendar with, eg., family members via a link. So that anyone with the link can view events. Ideally with two modes: only show free/busy show full event details Is that something that could be considered for the roadmap? Thank you (edit: wording)
  • 35 335
    35 Topics
    335 Posts
    Package UpdatesP
    [1.42.0] Update calibre to 9.15.0 Full Changelog
  • 18 157
    18 Topics
    157 Posts
    jamesJ
    Hello @luckow This is not documented very well. Had to look into the Castopod code to find the URL path to the API. https://github.com/ad-aures/castopod/blob/bc041702dd8058ae8e1831b9609827c911a5a626/modules/Api/Rest/V1/Config/RestApi.php#L35 public string $gateway = 'api/rest/v1/'; So the full URL would be https://castopod.cloudron.dev/api/rest/v1/podcasts curl https://castopod.cloudron.dev/api/rest/v1/podcasts [] After creating one: curl https://castopod.cloudron.dev/api/rest/v1/podcasts [{"id":1,"guid":"2bdee7b8-8131-5888-b4da-713d7b3a124a","actor_id":1,"handle":"demopadcast","title":"Demo Podcast","description_markdown":"DESC","description_html":"<p>DESC</p>\n","cover_id":3,"banner_id":null,"language_code":"en","category_id":1,"parental_advisory":null,"owner_name":"james","owner_email":"james@cloudron.example","is_owner_email_removed_from_feed":true,"publisher":"","type":"episodic","medium":"podcast","copyright":"","episode_description_footer_markdown":null,"episode_description_footer_html":null,"is_blocked":false,"is_completed":false,"is_locked":true,"imported_feed_url":null,"new_feed_url":null,"payment_pointer":null,"location_name":null,"location_geo":null,"location_osm":null,"verify_txt":"","custom_rss":null,"is_published_on_hubs":false,"partner_id":null,"partner_link_url":null,"partner_image_url":null,"is_premium_by_default":false,"created_by":1,"updated_by":1,"published_at":null,"created_at":{"date":"2026-03-03 11:06:44.000000","timezone_type":3,"timezone":"UTC"},"updated_at":{"date":"2026-03-03 11:06:44.000000","timezone_type":3,"timezone":"UTC"},"feed_url":"https://castopod.cloudron.dev/@demopadcast/feed.xml","actor_display_name":"Demo Podcast","cover_url":"https://castopod.cloudron.dev/media/podcasts/demopadcast/cover.jpg","categories":[{"id":1,"parent_id":null,"code":"arts","apple_category":"Arts","google_category":"Arts","translated":"Arts"}]}]
  • 28 Topics
    388 Posts
    Package UpdatesP
    [1.35.2] Update changedetection.io to 0.60.7 Full Changelog Fetch favicon candidates in parallel under one deadline, and fix two ways it could hang by @dgtlmoon in #4435 Keep history diff title and controls visible while scrolling by @jhedlund in #4412 Add watch UI tweaks by @dgtlmoon in #4446 fix(http): send a single Date header on werkzeug built-in server by @Huang-404-Q in #4372 UI - Make the 'share watch' optional, reduces visual noise, not really used by non-power users by @dgtlmoon in #4448 Set Cache-Control: no-store on dynamic responses by default by @DennisGaida in #4319
  • 62 460
    62 Topics
    460 Posts
    Package UpdatesP
    [1.56.0] Update chatwoot to 4.18.0 Full Changelog Captain assignment, scenario and tool controls, and improved playground testing. [Enterprise] Guided WhatsApp setup and clearer account health. WhatsApp campaigns and calls for BSUID-only contacts. Per-inbox call recording and transcription settings. [Enterprise] Additional conditions for delayed automations. Alerts-only mode for Slack. Conversation history navigation and sorting in filtered views. Improved Help Center media uploads and previews. Message deletion audits, IP masking, and location details. [Enterprise] SMTP configuration independent of IMAP.
  • 40 Topics
    519 Posts
    Package UpdatesP
    [1.59.0] Update code to 26.04.4.1.1 Full Changelog
  • 3 31
    3 Topics
    31 Posts
    Package UpdatesP
    [1.9.0] Update comentario to 3.18.0 Full Changelog Add Sign in with Apple as first-class identity provider (#231, !33, !34) by Tim Oliver - 5f8b319, 6991f31, 304f949, b1529c5, c740ea6, b167450 Add spoiler markdown (>!), with a toolbar button and a dynamic config parameter (#112) - d65d747, f62308e, 03f2736, fefe20a, c94c517 Embed: react to on-the-fly attribute changes on <comentario-comments> (#140) - b640934, f003453, 33ecb73 Implement domain user deletion (#165) - b3e570e, ae13a67 Admin UI: Dashboard: add Top performing domains (#167) - 7f0f05a, c9c4b75 Backend: support secrets from environment (#220) - eaba5ec, a4cf3e5, 8ab3029 Embed: fix comment draft not cleaned up after submission (#223) - 6e21af3 Backend: fix new comment email unsubscribe - e49e90d Backend: swap out gorilla/csrf for http.CrossOriginProtection (CVE-2025-47909) - 8d3d496 I18n: add Polish translation (pl) by @MrBoombastic (!31) - e32f572
  • 12 81
    12 Topics
    81 Posts
    girishG
    @gh0stface yup, they made a release yesterday it seems and it should have the PRs we made upstream. @vladimir-d is checking the package again.
  • 20 127
    20 Topics
    127 Posts
    U
    @girish Yep, exactly that. AnyType and Appflowy are growing in popularity. Would be nice to see them
  • 8 48
    8 Topics
    48 Posts
    nebulonN
    This is now implemented in the latest version
  • 2 Topics
    20 Posts
    E
    Right, that makes sense!
  • 4 Topics
    25 Posts
    girishG
    @atridad Thanks for the heads up, the app is gone from our library as well.
  • 16 111
    16 Topics
    111 Posts
    B
    Thank you! FWIW, my issue was caused by using ssh to navigate the app's data directory on my server, when I needed to be using the Web Terminal. I added all three of these lines: AppConfig.registeredOnlyTypes = AppConfig.availablePadTypes; AppConfig.disableAnonymousPadCreation = true; AppConfig.disableAnonymousStore = true;
  • 6 97
    6 Topics
    97 Posts
    Package UpdatesP
    [1.30.0] Update ctfreak to 1.40.0 Full Changelog
  • 59 444
    59 Topics
    444 Posts
    nebulonN
    This is now fixed with latest update.
  • 13 132
    13 Topics
    132 Posts
    Package UpdatesP
    [1.20.2] Update dawarich to 1.15.2 Full Changelog Add an experimental read-only MCP endpoint at /api/v1/mcp for Pro and Family plans (and every self-hosted user), authenticated with the existing API key as a bearer token. MCP clients can read a timeline of up to 7 days, the latest location, and search visits by place, city, country or area name. See the MCP documentation. Exploration achievements: every country gets a collectible card, and 183 of them a grid of their first-level regions. A region counts as explored once time spent inside it passes your "minimum minutes spent in city" setting, so pass-throughs don't count. Earned regions are never revoked. Behind the achievements feature flag. (#3121) Updating a point's coordinates through PUT /api/v1/points/:id refreshes its country and looks its address up again, as moving it on the map already does, instead of keeping the old city. (#3121) Point uploads now accept Unix timestamps and return a validation error for malformed timestamps instead of failing internally. Account deletion no longer fails when saved posters, route videos, flights, notes, service settings, or suggested-place links remain. SMTP delivery and other outgoing connections now use a host's IPv4 address when it has one, so they work on servers where IPv6 is configured but not routable. Integration URLs are checked against every address their host resolves to, and integration URLs with a bracketed IPv6 address such as http://[fd00::5]:2283 are accepted (#3591). Map v2 route-gap settings now accept custom distances and durations above the former 5,000m and 180-minute slider limits. Trip maps and shared trip links split day routes by your saved time gap instead of a fixed 60 minutes. (#3381)
  • 65 649
    65 Topics
    649 Posts
    Package UpdatesP
    [3.4.0] Update directus to 12.4.1 Full Changelog Fixed reading from folders endpoint as non admin (#28286 by @Nitwel) Updated MapLibre GL JS from 1.15.3 to 6.9.0 (#28216 by @br41nslug) Updated Unhead from 1.11.20 to 3.4.1 (#28248 by @br41nslug) Fixed read permissions not enforced when resolving item keys for updateByQuery and deleteByQuery (#28143 by @br41nslug) Added native mailtrap email transport support via EMAIL_TRANSPORT=mailtrap (#27873 by @tsokolovs) Disabled inactive collections in the Studio, preventing them from being selected or used while being viewable (#27792 by @br41nslug) Moved Flows into its own module and improved how they're organized and managed, including folders, search and filtering, import and export, and duplication (#28206 by @robluton) Added support for hiding a manual Flow's own button, so it runs only from a Manual Flow field (#28206 by @robluton) Added support for setting the From Name in the Send Email operation (#28206 by @robluton) Updated dompurify, joi, express, qs, uuid, diff, pm2, OpenTelemetry and AI SDK dependencies to address CVEs (#28242 by @br41nslug)
  • 91 784
    91 Topics
    784 Posts
    Package UpdatesP
    [2.18.0] Update discourse to 2026.9.0 Full Changelog
  • 24 Topics
    266 Posts
    Package UpdatesP
    [2.7.2] Add timestamp argumens to registry-client script
  • 5 46
    5 Topics
    46 Posts
    Package UpdatesP
    [1.4.0] Update docmost to 0.96.0 Full Changelog feat: collab hocuspocus v4 upgrade by @Philipinho in #2351 fix: toolbar flicker on navigation by @Philipinho in #2352 fix: increase s3 client max socket limit by @Philipinho in #2355 feat: footnotes by @Philipinho in #2384 feat: compare two page versions by @Philipinho in #2385 feat: page attachments endpoint and modal by @Philipinho in #2386 feat(editor): auto-detect text direction for RTL support by @Philipinho in #2389 fix: handle empty password, missing port, and TLS in Redis URL parsing by @michidk in #2021 feat: enhanced search filters by @salihudickson in #2398 feat: jump to search by @salihudickson in #2453
  • 13 124
    13 Topics
    124 Posts
    Package UpdatesP
    [1.29.1] Update sockpuppetbrowser to d6c1681
  • 12 63
    12 Topics
    63 Posts
    Package UpdatesP
    [1.12.0] Update community to 5.14.0 Full Changelog Added Spanish language support
  • 17 278
    17 Topics
    278 Posts
    Package UpdatesP
    [1.19.1] Update docuseal to 3.2.6 Full Changelog This release includes various bug fixes and security improvemens We recommend all self-hosted users to update to the latest version It's now possible to collect payments with PayPal: https://www.docuseal.com/blog/accept-paypal-payments-and-request-signatures-with-ease
  • 17 136
    17 Topics
    136 Posts
    Package UpdatesP
    [1.30.0] Update dokuwiki to 2026-07-14c Full Changelog
  • 41 359
    41 Topics
    359 Posts
    Package UpdatesP
    [1.15.1] Update dolibarr to 24.0.1 Full Changelog FIX: $arrayfields used before definition in don/list.php FIX: #38963 enforce website write right on legacy filemanager (v18) (#39731) FIX: #39053 + compatibility with multicompany (#39648) prevent non-admin users deleting admin accounts (backport MR #39119) FIX: #39396 Reject enclosing leave requests (#39798) FIX: #39658 shorten accounting template FK name (#39688) FIX: #39690 Division by zero in turnover collected report (#39706) FIX: #39733 Map variant attribute elements (#39755) FIX: #39756 Use configured printer for template test (#39900) FIX: #39763 Default for product is "no template/doc" generated. FIX: Mo::processBOM() ignores qty value for qty_frozen BOM lines (#39941)
  • 13 Topics
    89 Posts
    Package UpdatesP
    [1.8.0] Update easyappointments to 1.6.0 Full Changelog Added request method check on each request so that only allowed methods are accepted Add Jitsi integration and link generation for appointments made via the public page ALTCHA integration added as an alternative CAPTCHA step (#1155) When someone clicks on password reset, implement a link delivery and not just change the password directly Implementation of additional GDPR features in Easy!Appointments (#535) Add CAPTCHA support for all the public forms in order to block abusive requests (#1754) Replace the availabilities type with the new slot interval field Fixed a security issue where an administrator could inject scripts into the "booking disabled" message that would then run for every visitor of the public booking page Fixed a security issue where a provider could create or modify appointments under another provider's account Webhooks are now triggered only for the exact actions they are subscribed to, instead of matching similarly named actions by substring
  • 12 100
    12 Topics
    100 Posts
    Package UpdatesP
    [1.19.0] Update Emby.Releases to 4.10.0.40 Full Changelog Fix cases where transcoding processes that complete very quickly are treated as an error Fix startup wizard regression Fix playback failures with dvd and bluray folders containing a dot in the folder name Fix regression related to adding a library with an SMB path fix regression causing episodes without season folders to not display Add new home screen section type called dynamic media with sorting and filtering functions Fix Hardware Transcoding for HDR Video when Tone Mapping is enabled Fix regression with hiding users from login screens on remote connections Revamp home screen section options with new section editor Add subtitles to stats for nerds
  • 52 519
    52 Topics
    519 Posts
    Package UpdatesP
    [3.0.8] Update espocrm to 10.0.8 Full Changelog Phone number search without country code #3781
  • 31 289
    31 Topics
    289 Posts
    Package UpdatesP
    [4.10.5] Update etherpad-lite to 3.3.6 Full Changelog 3.3.6 is a security and bug-fix release. It closes an OIDC login bypass for accounts configured without a password (GHSA-62cj-9j72-mfrh), and fixes a batch of reported defects across the installer, the admin settings editor, session transfer, the welcome screen, accessibility and plugin configuration. OIDC refuse interactive logins for accounts without a password (GHSA-62cj-9j72-mfrh, #8247). PDF export honours font-family without LibreOffice (#8245, #8249). Installer the Node version check no longer fails under Windows PowerShell 5.1 (#8214, #8235). Admin settings form fields honour escape sequences (#8211, #8239). Session transfer preferences survive the transfer, and the cookie is no longer double-encoded (#8171, #8238). Session transfer the dialog describes what actually happens (#8173, #8236). Welcome screen deleted pads leave the recent list (#8201, #8237). Accessibility screen readers can move through a pad line by line (#7778, #8240). Plugins settings.ep_<plugin> config blocks are reachable again from require() (#8109, #8110).
  • 4 Topics
    15 Posts
    nebulonN
    Thanks for the pointer, I am fixing the readme there then.
  • 2 126
    2 Topics
    126 Posts
    Package UpdatesP
    [1.31.1] Update evcc to 0.315.2 Full Changelog Modbus proxy: keep default device port after serial round-trip (#33745)
  • 7 45
    7 Topics
    45 Posts
    Package UpdatesP
    [3.3.0] Update fider to 0.37.0 Full Changelog Stop retrying Let's Encrypt for hosts that just failed by @mattwoberts in #1616 Improvements to tiptap editor by @mattwoberts in #1604 Plural vote translations by @mattwoberts in #1605 Issues with the share feedback page by @mattwoberts in #1617 fix(locale): register and polish Korean (ko) translations by @Cynn in #1619 Fix cross-tenant auth takeover via tenant-unbound user lookup by @mattwoberts in #1623 Update Italian translation by @albanobattistella in #1592 Bind OAuth sign-in to the tenant's canonical origin by @mattwoberts in #1626 Support for deleting accounts from support tools by @mattwoberts in #1671 Sanitize backend markdown output and filter URL schemes by @mattwoberts in #1673
  • 5 36
    5 Topics
    36 Posts
    robiR
    Yes please, who is doing the community app?
  • 2 Topics
    16 Posts
    Package UpdatesP
    [1.4.0] Update fmd-server to 0.17.0 Full Changelog FMD Server API v2 and Protocol v2 (#172) OpenAPI specification (#40) Delete individual locations/pictures (#107) Detect browser language on first load (#158) Show push URL and key fingerprint (!248) Fix PWA installation broken when hosted in subpath (#174) New translation: Russian (ru) (!257) Remove server-side username generation (#169) Replace unmaintained glebarez/sqlite driver with gormlite (!251), thanks to @spwoodcock Create database checkpoint at shutdown (!268)
  • 23 279
    23 Topics
    279 Posts
    Package UpdatesP
    [3.13.2] Update firefly-iii to 6.7.3 Full Changelog Discussion 12760 (419 Page expired when selecting a different date range) started by @wecoyote5 Issue 12779 ("Create new ..." button on homepage doesn't pre-fill the corresponding account field) reported by @leppa Issue 12781 (When mass editing transactions, only the last tag is kept) reported by @bertille-ddp Issue 12782 (accounts with attachement in show page returns 500 error page) reported by @SL1c3R57 Issue 12783 (Clone / Clone & Edit doesn't work) reported by @gthbusrr Issue 12784 (Creating a transaction doesn't put the focus into the title field) reported by @ThibaultNocchi Issue 12789 (Text in table cells is vertically off-center) reported by @davidschlachter Issue 12794 (Mobile layout: Budget and Spending chart is not displayed) reported by @MaxMapo Issue 12803 (Error "The description.xxxxxx field is required." when mass updating transactions) reported by @andyesten Issue 12815 (Reports shows disabled accounts) reported by @jlauwers
  • 6 128
    6 Topics
    128 Posts
    Package UpdatesP
    [2.12.2] Update formbricks to 5.4.3 Full Changelog fix(security): bump next to 16.3.3 for two critical RCE advisories (backport #9225 to release/5.4) by @xernobyl in #9266 fix(responses): bound the "Other" response filter instead of permuting every subset (backport #9253 to release/5.4) by @xernobyl in #9256 fix(helm): support Gateway API v1.5 clusters (backport #9291 to release/5.4) by @BhagyaAmarasinghe in #9293 Full Changelog: https://github.com/formbricks/formbricks/compare/5.4.2...5.4.3
  • 6 35
    6 Topics
    35 Posts
    Package UpdatesP
    [1.3.5] Update forgejo to 16.0.5 Full Changelog
  • 76 844
    76 Topics
    844 Posts
    Package UpdatesP
    [1.16.33] Update freescout to 1.8.241 Full Changelog Added "Paste as Plain Text" button to the editor (#5627) Auto link last entered link in the editor (#5280) Updated German translation. Fixed "Show Original" on IMAP servers which reject searching by Message-ID (#5633) Do not show .env file content on the final step of Installation Wizard (GHSA-3gv6-4vmm-79pj) Check if mailbox is active in Mailbox::userHasAccess() (GHSA-59v9-2qvg-cxw8) Do not allow to convert existing conversations into drafts (GHSA-6ff4-3w2c-mjj8) Check user access to conversation in SendNotificationToUsers job (GHSA-2j2c-g32w-96vm) Retry "connection failed - SSL operation failed" error on fetching (#5623) Hide bell notifications text when user loses access to mailbox or conversation (GHSA-6545-8c3f-pp6w)
  • 21 162
    21 Topics
    162 Posts
    Package UpdatesP
    [1.29.0] Update FreshRSS to 1.30.0 Full Changelog SSRF mitigation: disallow access to local networks such as 127.0.0.1 by default, for security reasons (breaking change) #8400, #8950, #9195 Filter global view feed list by state and search #9132 New option to hide badges showing number of unread articles (Phantom Obligation) #8844 Refresh only feeds in the current view #9060 New per-feed option to show or hide enclosures (attachments) #9015 Fix lost elements while parsing search query #8884 Fix "mark as read older than" widening the active search #9173 Fix SQL errors breaking some regex searches with MySQL / MariaDB #9036 Fix marking filtered label articles as read in SQLite and PostgreSQL #9264 Fix auth CSRFs (login and register actions) #9171
  • 2 18
    2 Topics
    18 Posts
    Package UpdatesP
    [1.1.2] Update funkwhale to 2.0.11 Full Changelog
  • 83 1k
    83 Topics
    1k Posts
    Package UpdatesP
    [4.197.0] Update ghost to 6.65.0 Full Changelog Improved site responsiveness while the sitemap rebuilds (#30839) - Austin Burdine Improved sitemap memory use on sites with many posts (#30838) - Austin Burdine Fixed the API pipeline cloning its cache adapter - Austin Burdine Fixed comments on gated posts being hidden from readers without access (#30857) - Austin Burdine Fixed footer action icons wrapping in Firefox (#30827) - Weyland Swart Fixed incomplete subscriptions being counted as paid conversions - Aileen Booker Fixed activate theme replacement race (#30788) - Austin Burdine Fixed analytics breaking layout on mobile devices (#30605) - Zach
  • 51 455
    51 Topics
    455 Posts
    Package UpdatesP
    [1.40.2] Update gitea to 1.27.3 Full Changelog fix(packages): restrict/limited/token-scope access (#39041, #39043, #39044, #39047, #39046) (#39058) fix(actions): enforce fork pull request trust boundaries (#39005) (#39018) fix(git): restrict hook permissions (#39008) (#39016) fix: avoid enumerating every public repository in issue search (#38992) (#39000) enhance: add permalinks to pull request reviews (#38849) (#39036) fix(actions): keep step-level continue-on-error expressions unevaluated (#39141) (#39148) fix(pull): keep the merged state in sync with git (#39062) (#39118) fix: resolve YAML anchors and aliases in Actions workflows (#38984) (#38996) fix(indexer): correct bleve indexer token filters (#38853) (#38951) fix(ui): respect FEED_PAGING_NUM on the dashboard feed (#38935) (#38936)
  • 21 151
    21 Topics
    151 Posts
    nebulonN
    Not sure I fully understand the target setup you intend to have. But to enable CORS on the github pages app is only really useful if some code running in another domain would call the REST API of the github pages app, which I am not sure it even has. But I might be misunderstanding here. If CORS is indeed needed, then the app coder (github pages) would need to support responding those pre-flight OPTIONS check queries by the browser.
  • 67 683
    67 Topics
    683 Posts
    girishG
    For the moment, you can ignore the warning. Our gitlab shows the same warning. @jayonrails the new postgres is via the new ubuntu image, which is part of our 10.1 roadmap
  • 2 14
    2 Topics
    14 Posts
    Package UpdatesP
    [1.1.6] Update glpi to 11.0.9 Full Changelog System requirements now check that the security key files (glpicrypt.key, oauth.pem and oauth.pub) can be read, or created when missing. Fixed searching values with multiple concurrent spaces. Fixed import of exported forms containing a condition on an item dropdown with no item selected. Duplicate spaces in some SQL queries, including values, (usually ones that used subqueries) no longer removed.
  • 7 61
    7 Topics
    61 Posts
    Package UpdatesP
    [1.24.0] Update base | final to 5.1.0
  • 22 259
    22 Topics
    259 Posts
    Package UpdatesP
    [2.8.2] Update grafana to 13.2.2 Full Changelog Security: Fix CVE-2026-15815 Security: Fix CVE-2026-76154 Security: Fix CVE-2026-79656 Dashboards: Preserve query variable refresh setting on v2 dashboard import #132089, @grafana-writer[bot] Provisioning: Fix folder rename UID collision during full sync #132157, @grafana-writer[bot]
  • 15 196
    15 Topics
    196 Posts
    Package UpdatesP
    [2.2.0] Update grav to 2.2.0 Full Changelog Rebuilding the pages cache no longer writes a compiled file for every page, so the first request after a cache clear is much faster on large sites. A new pages.frontmatter.native_yaml setting reads page frontmatter with the much faster YAML extension when the server has it installed. It is off by default because the extension reads unquoted dates and yes/no differently. pages.lazy_index now defaults to auto, which uses the page index on sites with 1,000 pages or more and the classic pages cache on smaller ones, so large sites load pages faster and use far less memory without any setup. CSS minification now uses wikimedia/minify, which understands modern CSS and is about 15 to 25 times faster on real stylesheets. Sites on Apache older than 2.4.8, common on Plesk and CentOS 7 hosts, no longer answer 500 for everything under user/ after upgrading, and upgrading fixes the .htaccess files earlier releases wrote there (grav-plugin-admin2#179) Plugins' onShutdown work runs again after Admin Next saves on sites with session.read_and_close on, when another plugin had already finished the response. Deleting or renaming a page folder is now picked up without clearing the cache. The file change check no longer counts files that only contain .md somewhere in their name, such as page.md.bak, or whose name merely ends in yaml. Searching Flex pages now matches a page's route as well as its title, slug and menu. calc() inside @media, @supports and @container conditions keeps its spacing when CSS is minified, so browsers no longer drop those blocks.
  • 19 168
    19 Topics
    168 Posts
    Package UpdatesP
    [1.12.0] Update greenlight to 3.9.0.1 Full Changelog Add missing library that caused app to crash on startup URL_HOST is now a required .env variable. Any deployment that does not have it set, will not start up. Multiple security fixes (will be made public sometime in the future) Multiple gem updates Fixed issue with Maintenance Banner not showing correctly on smaller screens Fixed issue with user signup failing if avatar is too big Increased timeout for connecting to email server
  • 9 64
    9 Topics
    64 Posts
    Package UpdatesP
    [1.2.9] fix base image
  • 55 318
    55 Topics
    318 Posts
    jamesJ
    Hello @albertbeaufrand and welcome to the Cloudron Forum This topic is a duplication of https://forum.cloudron.io/post/97415 and will be merged into it. Please read the responses above to get the full answer to your question.
  • 4 23
    4 Topics
    23 Posts
    girishG
    App discontinued due to no upstream updates.
  • 18 147
    18 Topics
    147 Posts
    Package UpdatesP
    [1.23.0] Update hedgedoc to 1.12.0 Full Changelog HedgeDoc 1.12.0 and onwards will require Node 20.17 or later in order to run. Some syntax highlighting languages have been removed and/or changed. You can find more information in the highlight.js docs. Automatically skip the login modal if no form-based login and exactly one external login provider is configured All links will be opened in new tabs instead of the same tab as the note. This was changed when the external link warning was implemented and now the old behavior is restored Fixed multiple bugs in the realtime connection handling that could lead to data-loss of users with a flaky connection
  • 13 Topics
    169 Posts
    Package UpdatesP
    [1.23.4] Update core to 2026.9.3 Full Changelog Fix EnergyZero market price regression (@klaasnicolaas - #181230) (energyzero docs) Require the IRK in the Private BLE Device config flow (@frenck - #181969) (private_ble_device docs) Keep the known Bond host when zeroconf still announces it (@frenck - #181975) (bond docs) Fix function name in external statistics mean_type message (@Booyaka101 - #182031) (recorder docs) Fix Matter cover entity not created when tilt attribute is null for Shelly devices (@jowi24 - #182042) (matter docs) Make Nest climate turn_on idempotent (@allenporter - #182086) (nest docs) Fix Google Tasks error handling on DNS failure (@joostlek - #182195) (google_tasks docs) Fix Alexa doorbell raises error in state report becase the return status is NO_CONTENT (@jbouwh - #182209) (alexa docs) Encrypt and decrypt supervisor.tar in backup rewrites (@agners - #182220) (backup docs) Fix Spotify reauth crash when config entry data lacks "id" (@joostlek - #182290) (spotify docs)
  • 27 254
    27 Topics
    254 Posts
    Package UpdatesP
    [1.9.6] Update humhub to 1.18.6 Full Changelog Fix #8409: Add :focus styles for Administration left navigation menu items Fix #8420: Fix hover flicker and keyboard focus on profile image upload buttons Fix #8439: Fix editing file-only Posts and clear fileList[] after posting so it isn't reused on the next post Enh #8440: Add the user ID as tie-breaker to the default user list sorting for stable ordering and pagination Fix #8445: Restrict direct space joins to free-join spaces, so "Invite and request" spaces require admin approval instead of instant membership Fix #8446: Restrict Topic management (create/rename/delete) on user profiles to the profile owner or users with full content management permissions Fix #8443: Prevent silent demotion of public content to private when saved by an editor lacking CreatePublicContent permission Fix #8456: Block delegated admins from self-granting admin permissions and from editing/impersonating the System Administrator account Fix #8486: Enforce InviteUsers permission on space membership search-invite to prevent member user enumeration Fix #8490: Prevent private Content changes and comments from being emailed to subscribers who can no longer view them
  • 76 714
    76 Topics
    714 Posts
    Package UpdatesP
    [1.102.2] Update immich to 3.2.2 Full Changelog fix: skip faces of other users when reassigning faces by @immich-push-o-matic[bot] in #31586
  • 6 Topics
    47 Posts
    Package UpdatesP
    [1.3.1] Update ip2location to 1.4.0 Fix width and height of the map
  • 5 70
    5 Topics
    70 Posts
    Package UpdatesP
    [1.11.0] Update it-tools to 2026.7.11 Full Changelog mobile UX overhaul, theme flash prevention and build cleanup (#474) (239c69e) Base64 String Converter: handle text encoding other than utf8 (7460423) new tool: Keyboard Tester (dfa836b) new tool: Cron Expression Generator (b016d34) new tool: DNS/RDAP queries (37cc92f) new tool: CSS/JS Prettify & Minify (45ed4a7) Fitness Computer: Change arguments order to fix wrong BMI calculation (#407) (eaea6e9) Data Storage Units Converter: fix b/iB/B conversion (102bb99) Speed Converter: wrong m/h is in fact mi/h (miles) (dfb92f2) overhaul startup performance, dependencies and UI responsiveness (#419) (bad27cf)
  • 4 33
    4 Topics
    33 Posts
    Package UpdatesP
    [1.0.3] Update infisical to v0.165.16 Full Changelog feat: block certificate deletion until expiry by @carlosmonastyrski in #8213 fix: prevent renewal identity bypass via ambiguous DN comparison by @carlosmonastyrski in #8223 feature(gateway): gcp enrollment by @bernie-g in #8143 improvement(secrets): simplify resource creation menu by @andrewhuhh in #8206 improvement(ui): simplify secret name sort trigger by @andrewhuhh in #8260 fix(secrets): use eye icon for generated credentials by @andrewhuhh in #8258 improvement(ui): show root slash in folder breadcrumb by @andrewhuhh in #8259 feat: secret scanning batching by @mathnogueira in #8186 fix: resovled an bug in secret fetch by @akhilmhdh in #8264 feat(pam): clickhouse by @lb-vn in #8185
  • 18 196
    18 Topics
    196 Posts
    Package UpdatesP
    [1.12.8] Update invidous and companion
  • 71 Topics
    1k Posts
    Package UpdatesP
    [1.22.34] Update invoiceninja to 5.13.43 Full Changelog Fixes for build pipeline. Fixes for Email Settings page on React Application Short circuit consent screen by @beganovich in #12264
  • 44 349
    44 Topics
    349 Posts
    necrevistonnezrN
    No worries - and 12.1 with a lot of fixes is out: https://github.com/jellyfin/jellyfin/releases/tag/v12.1
  • 4 18
    4 Topics
    18 Posts
    girishG
    App discontinued due to no upstream updates.
  • 13 107
    13 Topics
    107 Posts
    Package UpdatesP
    [1.12.3] Update Jirafeau to 4.7.2 Full Changelog Added a button for showing the download password before uploading the file Favicon was missing in the modern theme Download passwords are now stored as SHA256 hashes Downloading encrypted files uploaded using "classic upload" (using just plain HTTP POST without the HTML5 file API) could not be downloaded. This was caused by not correctly marking the files as encrypted. Few more little fixes
  • 34 375
    34 Topics
    375 Posts
    jamesJ
    Hello @stoccafisso Not by default, no. You could build the jitsi app yourself and install it or maybe someone will make it a community app.
  • 12 117
    12 Topics
    117 Posts
    Package UpdatesP
    [2.6.1] Update joplin to 3.7.2 Full Changelog The Release Notes section contains no breaking changes, features, or bug fixes it is empty (only a compare link is present with no changelog entries).
  • 12 149
    12 Topics
    149 Posts
    Package UpdatesP
    [1.63.1] Update jupyterhub to 6.0.1 Full Changelog
  • 8 75
    8 Topics
    75 Posts
    Package UpdatesP
    [1.17.10] Update kanboard to 1.2.54 Full Changelog fix(user): invalidate existing sessions when the password changes fix(project): check permissions in the project creation handler fix(file): check the project of the task when fetching a task file fix(api): check task and project binding in setTaskTags fix(csv): escape exported values starting with a special character fix(api): return only public user columns fix(subtask): reject assignees outside of the project fix(notification): scope unread notification lookup to its owner fix: scope custom filter changes to their project and owner fix: validate request tokens for tag, board, and comment actions
  • 8 58
    8 Topics
    58 Posts
    Package UpdatesP
    [1.14.0] Update Kavita to 0.9.1.4 Full Changelog Added: (Kavita+) Added support for loading recommendations from Hardcover. These will be the books linked to the first book in the series. Added: (Kavita+) Added Hardcover OAuth support (PAT tokens will still work) Added: Added support for Mangabaka's new URL structure (released 8/31/2026) Changed: Opening a completed chapter while reading places you on the first page, but your reading progress won't reset unless you page forward. Fixed: (Kavita+) Fixes chapter cover images sometimes being removed when Kavita+ writes a volume image Fixed: Fixed black & white lists not being available for non Kavita+ users Fixed: Fixed series age rating not being derived from tags on first scan and from updated tags in consecutive scans Fixed: Fixed settings not saving for some users Fixed: Fixed chapters with one page not saving progress while paging (Thanks @333fred) Fixed: Fixed a bug where users couldn't update reading profile from the reader due to Breakpoint enum values changing when we streamlined the breakpoint service in v0.9.1.
  • 8 112
    8 Topics
    112 Posts
    Package UpdatesP
    [1.7.4] Update keycloak to 26.7.4 Full Changelog #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [CVE-2026-79651] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [CVE-2026-74909] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher #52837 [CVE-2026-19607] Username Takeover Leading to Account Lockout #52838 [CVE-2026-17526] Privilege escalation: the "impersonation" role can impersonate a realm administrator #52839 [CVE-2026-18212] SAML Redirect DEFLATE helpers leak native zlib state #52354 Upgrade to Quarkus 3.33.3.2 dist/quarkus #49635 Performance issue with 26.6.2 dist/quarkus #52172 Cached RealmAdapter.isUserManagedAccessAllowed() returns isEnabled() infinispan #52241 Clicking on a sub group in the admin console throws an exception admin/ui
  • 5 37
    5 Topics
    37 Posts
    Package UpdatesP
    [1.2.4] Update keila to 0.30.3 Full Changelog Campaign ID is now available as {{ campaign.id }} in email templates (implements #559, thanks @Phobetor) New MAILER_SMTP_TLS_MODE and MAILER_SMTP_AUTH_METHOD environment variables for configuring TLS/STARTTLS and authentication method for the system mailer fixes #536 and #554, thanks @castellinosviluppo and @saz for reporting) Shift+Enter now creates a line break instead of a new paragraph in the block editor Added cache for parsing Liquid templates, significantly improving campaign render performance, especially for campaigns with large HTML bodies Improved speed for many queries in large projects such as campaign stats and contact counts Deleting contacts by external_id from the API now works correctly (fixes #548, thanks @castellinosviluppo for reporting and @JoeJoeflyn for implementing) Fixed the Resend verification email button on the sender edit page Fixed MJML error messages caused by CRLF line breaks (fixes #567, thanks @Twilight-Computer for reporting)
  • 16 261
    16 Topics
    261 Posts
    Package UpdatesP
    [2.59.0] Update kimai to 2.67.0 Full Changelog Use timeout in network call, fixes Doctor screen in airgapped environments (#6172) Do not hijack the export form for submitting the actual export request, use JS for it (#6172) Fix broken redirect on missing permission edit_team after using create_team (#6172) Remove legacy code and deprecate form option (#6172) Fix NelmioApiDocBundle warning (#6172) Translations update from Hosted Weblate (#6163) API: validate recent activity collection limit (#6171) Use only translated locales for routes and cache warming (#6148)
  • 16 233
    16 Topics
    233 Posts
    Package UpdatesP
    [1.48.0] Update koel to 9.13.0 Full Changelog feat: encrypt Last.fm and ListenBrainz tokens at rest by @phanan in #2681 fix: show album grids at the intended column width by @phanan in #2682 feat: link albums, artists and songs to MusicBrainz by @phanan in #2684 feat: fetch album covers from the Cover Art Archive by @phanan in #2685 fix: match the styles of the two Disconnect buttons by @phanan in #2686 fix: use the standard button style across Profile & Preferences by @phanan in #2687 feat: fetch artist images from Wikidata by @phanan in #2688 feat: fill in missing album release years from MusicBrainz by @phanan in #2689 fix: fetch Wikidata artist images whichever encyclopedia is active by @phanan in #2692 fix: ask again when MusicBrainz or Wikimedia is unavailable by @phanan in #2694
  • 11 132
    11 Topics
    132 Posts
    girishG
    Running TURN server on port 443 only matters for setups where a Client is unable to contact the server on non-port 443. This is only common in some ultra locked down intranet setups.
  • 5 67
    5 Topics
    67 Posts
    Package UpdatesP
    [1.9.1] Update komga to 1.27.1 Full Changelog add missing restrictions checks (7f71808) allow proxy requests without raw sync token (c21dbad) prevent Kobo from re-downloading books if the metadata changed (725443d), closes #2426 better justify poster on entity view page (e7e08ca), closes #2454 wrap long names in import book table (4afa57e) properly close menus on click (3161c48) display file format in book view (0523038) display sharing labels in Book and Series view (7719362) edit sharing labels for oneshots (4bde978) hide number fields and show title sort field when editing one shot (fe1e072)
  • 24 188
    24 Topics
    188 Posts
    I
    Thanks so much @girish! That did the trick.
  • 144 1k
    144 Topics
    1k Posts
    Package UpdatesP
    [5.2.6] Update php-src to 8.5.11
  • 18 193
    18 Topics
    193 Posts
    Package UpdatesP
    [1.63.0] Update languagetool to 6fc5a1f
  • 23 240
    23 Topics
    240 Posts
    Package UpdatesP
    [1.14.6] Update leantime to 3.9.8 Full Changelog Milestones - Fixed reports showing 0% completion and the timeline "Show Tasks" view displaying nothing (#3624, #3625, #3628) Milestone Modal - Resolved focus loss, restored save-and-close, and fixed a 500 error when saving goals (#3605) To-Dos - Kept To-Dos from closed projects browsable once the project is reopened (#3626, #3627) Post-3.9.7 Regressions - Fixed a file browser out-of-memory issue, strategy grouping, and 403 errors for legacy roles (#3621) MCP Endpoint - The /mcp endpoint now accepts Leantime API keys, and a shim for the removed php-mcp provider lets in-place upgrades boot (#3601, #3602, #3607) Program Board - Moved the card status dropdown below the field row (#3599) Sessions - Isolated sessions into their own Redis database to avoid clashes with other cached data (#3604) Bumped the McpServer submodule to include the bulkAddTasks fix (#3620, #3622) Synced composer.lock content hash with composer.json (#3603)
  • 19 164
    19 Topics
    164 Posts
    necrevistonnezrN
    The right combination: DON'T LOGIN WITH CLOUDRON the first time, instead create a user the "classic way" via mail & password --> This is the admin. After validation and setting up MFA, logout. Now log in via Cloudron, then you are the "normal user". If you want to block every login except via Cloudron, set up the env as follows (took me some trial & error): ALLOW_EMAIL_LOGIN=false ALLOW_REGISTRATION=false ALLOW_SOCIAL_LOGIN=true ALLOW_SOCIAL_REGISTRATION=false ALLOW_PASSWORD_RESET=false # ALLOW_ACCOUNT_DELETION=true # note: enabled by default if omitted/commented out ALLOW_UNVERIFIED_EMAIL_LOGIN=false Note: "SOCIAL_LOGIN" means Cloudron LDAP. If new Cloudron User should be allowed, set ALLOW_SOCIAL_REGISTRATION to true
  • 18 434
    18 Topics
    434 Posts
    Package UpdatesP
    [1.60.2] Update LimeSurvey to 7.1.2+260917 Full Changelog Compare Source
  • 16 139
    16 Topics
    139 Posts
    Package UpdatesP
    [1.28.0] Update linkding to 1.47.0 Full Changelog Only schedule snapshot tasks when there are pending snapshots by @sissbruecker in #1480 Add CORS support for the REST API by @sissbruecker in #1487 Add SSRF protection for server-side requests by @sissbruecker in #1488 Avoid reading assets into memory in full when viewing them in the UI by @sissbruecker in #1482 Fix custom CSS not working in sandboxed reader view by @sissbruecker in #1481
  • 15 182
    15 Topics
    182 Posts
    Package UpdatesP
    [1.24.1] Bundle Meilisearch to enable full-text search on archived content
  • 31 233
    31 Topics
    233 Posts
    Package UpdatesP
    [1.17.0] Update listmonk to 6.2.0 Full Changelog feat(i18n): add Arabic (ar) translation by @imohad in #2977 Fixs #2987 - Prevent confirmed subscriber becoming unconfirmed when re-subscribing. by @blu3id in #2996 fix(analytics): correct per-campaign unique view counting by @wucm667 in #3024 fix: prevent nil pointer crash in BounceWebhook when bounce processing disabled by @Koushik-1729 in #2993 Add per-domain SMTP routing by @jaymzh in #2953 Fix: ZIP Slip path traversal in CSV import by @Yunkaiwjs in #3065 fix: protect SES cert cache map with sync.RWMutex to prevent concurrent map writes crash by @Abzaek in #3050 Add Azure ACS bounce webhooks and settings support by @oskari in #3001 Add support for embedding images (inline attachments) via CID in campaign bodies by @knadh in #3034 Fix api tokens hashing by @knadh in #3114
  • 8 149
    8 Topics
    149 Posts
    Package UpdatesP
    [1.25.0] Update loomio to 3.9.0 Full Changelog New: Sign in with a passkey without entering an email address, and manage passkeys from your profile Fix: Prevent account enumeration through ordinary sign-in, sign-in code requests, and account-merge verification Fix: Block deactivated sessions, enforce password attempt limits, and protect pending SSO identity links Fix: Show moved poll comments immediately when opening their destination discussion
  • 19 235
    19 Topics
    235 Posts
    Package UpdatesP
    [2.47.3] Update Lychee to 7.8.5 Full Changelog Fix language by @ildyria in #4757 Trivy ignore CVE-2026-84304 by @ildyria in #4714 Ergonomic update with escape and space keys by @jphuguet in #4707 Trivy ignore CVE-2026-84445 by @ildyria in #4727 Show album cover art while password-protected by @matthewbolding in #4704 Improve Ux by @ildyria in #4730 Fix cves by updating dependencies by @ildyria in #4737 Fix folder multi processing by @ildyria in #4736 Send the origin on openstreetmap.org by @ildyria in #4739 Fix dock on smart album by @ildyria in #4741
  • 17 60
    17 Topics
    60 Posts
    Package UpdatesP
    [1.0.0] Update mail to 1.0.0 marking the first stable release Add collected address lists to suggest email addresses of previous conversations when composing Fix app state when the user does not have access to any mailboxes
  • 10 61
    10 Topics
    61 Posts
    marcusquinnM
    @girish That is a super handy feature!
  • 149 1k
    149 Topics
    1k Posts
    Package UpdatesP
    [1.19.2] Update mastodon to 4.7.2 Full Changelog Temporarily disable HEIF support Fix relative privacy policy links in subscription emails (#40486 by @crafkaz) Fix canonical email blocks interfering with freezing or approving users (#40463 by @ClearlyClaire) Fix 500 error when trying to upload a non-custom-filter JSON import (#40449 and #40451 by @ClearlyClaire) Fix 500 error when submitting a status twice (#40439 by @ClearlyClaire) Fix self-deleted accounts not being un-deleted when using tootctl accounts create --reattach (#40430 by @mjankowski) Fix account deletion not deleting generated annual reports (#40394 by @ClearlyClaire) Fix notifications not being cleaned up when notification requests are deleted in bulk (#40393 by @ClearlyClaire)
  • 53 447
    53 Topics
    447 Posts
    Package UpdatesP
    [1.61.0] Update matomo to 5.14.0 Full Changelog The interface Piwik\Settings\Interfaces\PolicyComparisonInterface gained four methods used by the granular compliance dashboard: getPolicySettingId(), isExternallyManagedByPolicyPage(), getWhatItDoes() and getImpact(). Plugins that implement the interface directly must implement them. Plugins using Piwik\Settings\Interfaces\Traits\PolicyComparisonTrait (as all known implementers do) inherit default implementations and are not affected. Exporting a report for a single goal (a goals table or a bar/pie/evolution chart showing one goal's conversions or revenue) now returns only the columns shown in the UI, by adding showColumns to the export request. Previously the export returned the aggregated all-goals columns and every other goal's columns as well. Integrations that reuse an export URL copied from the UI will receive a narrower set of columns than before. The Referrers_distinctWebsitesUrls metric is now listed among the metrics of the Referrers.get report, carries the label Distinct website URLs, and is declared as a numeric metric. The UserCountry_distinctCountries metric, returned by UserCountry.getNumberOfDistinctCountries and plotted by the distinct-countries sparkline widget on the Locations page, is now declared as a numeric metric and is therefore subject to CNIL data rounding. The Marketplace.searchPlugins controller action now returns only the fields the plugin cards render, and the plugins template variable the Marketplace.GetNewPlugins and Marketplace.GetPremiumFeatures widgets pass to their templates has been reduced the same way. Tooltip content - the title of the hovered element, or the data-tooltip a report cell carries - may only use simple inline formatting (b, br, em, i, small, span, strong, u, without attributes). The new Piwik\Http\SecurityHeaders::sendForDataResponse() sends the header set for a response that is data rather than application UI: X-Content-Type-Options: nosniff, Referrer-Policy: no-referrer, X-Frame-Options: deny unless [General] enable_framed_pages allows embedding, and a Content-Security-Policy that allows no scripts, forms or base URI, only inline styles and images from Matomo itself (built by the new Piwik\View\SecurityPolicy::restrictToDataResponse()). Two new events let plugins customise the "No data has been recorded yet" page, on both the standalone page and its embedding in the reporting UI: The new CoreHome.tooltipContent renders the title of the hovered element as the content of a jQuery UI tooltip, and window.vueSanitizeTooltip() does the same for a value at hand in plain JavaScript. A new keep_flattened_dimension_columns parameter keeps the columns a flattened report adds for its dimensions when the request also restricts columns with showColumns.
  • 133 Topics
    1k Posts
    Package UpdatesP
    [1.11.31] Update element-web to 1.12.29 Full Changelog
  • 60 658
    60 Topics
    658 Posts
    Package UpdatesP
    [1.32.0] Update mattermost to 11.11.0 Full Changelog Mattermost Platform Release 11.11.0 contains multiple new quality of life improvements, including Data Spillage: Exposure Radius Report.
  • 66 517
    66 Topics
    517 Posts
    Package UpdatesP
    [6.2.1] Update mautic to 7.2.1 Full Changelog Theme ZIP files that wrap everything in a single folder now install correctly by @santhiprakash in #16877 Campaign emails now arrive at the intended local time for contacts in timezones ahead of UTC by @escopecz in #17283 Scheduled campaign events no longer repeat forever when their log is already locked by @aleksandrovpa in #17146 Changing the redirect on a campaign event is now recorded correctly by @escopecz in #17420 Company and contact names containing "&" no longer appear as "&" in lists by @peculiaruc in #17266 Dynamic web content tokens now work inside links and buttons by @patrykgruszka in #17495 Sorting form results no longer switches to a different form and hides most of the entries by @athomas321 in #17403 Two forms from different Mautic instances can now be embedded on the same website by @escopecz in #17354 Restore internal service names that an earlier refactor removed, which some plugins depend on by @escopecz in #17251 Reports filtered by tag now return the right results by @kah-ja in #17129
  • 9 115
    9 Topics
    115 Posts
    Package UpdatesP
    [1.50.0] Update mealie to 3.27.0 Full Changelog feat: add connectivity test for AI providers @elliot-ultra (#8123) fix: forward attributes to recipe info card image @nzyz995 (#8399) fix: avoid useAsyncData in recipe timeline scroll handler @nzyz995 (#8400) fix: prevent recipe card tags from overlapping title @vmiwa (#8416) fix: respect household recipeDisableComments preference on recipe page @Luna-81 (#8424) fix: cURL fails when IPv6 isn't supported @michael-genson (#8425) fix: fall back to servings for recipe yield display @Tsuji-Hub (#7881) fix: prevent duplicate iOS camera photos from overwriting recipe step assets @RisonG (#8111) fix: replace "mealplan" with "meal plan" @michael-genson (#8427) fix: keep instruction section and step headings when importing @Rouzax (#8331)
  • 9 95
    9 Topics
    95 Posts
    Package UpdatesP
    [3.7.0] Update mediawiki to 1.46.0 Full Changelog
  • 14 104
    14 Topics
    104 Posts
    Package UpdatesP
    [1.25.1] Update meemo to 1.25.1 Fix OpenID login bug Update dependencies
  • 6 51
    6 Topics
    51 Posts
    Package UpdatesP
    [2.3.0] Update memos to 0.31.0 Full Changelog Spaces: Organize memos in shared Spaces, invite people through their inbox, move memos between Spaces, and choose custom icons or emoji. Space-only visibility limits a memo's audience to active Space members, with the administrator access described below. (#6228, #6266, #6285, #6287) Calendar and Map: Browse memos by month, open a day to read or add notes for that date, and explore memos with location data on a dedicated map. (#6277, #6280, map page) Views and search: Save reusable filters as Views with custom icons. Filter by Space or location, find memos outside any Space, use expressions in Quick Find, and see search matches highlighted in memo content. (#6167, #6181, #6267, #6276, #6305, #6335) Export and import: Move your memos between instances from Settings Export & Import using Memos Export Format (ZIP). Exports include archived memos, comments you wrote, and attachment files. Older export files remain importable. This is a personal export; instance settings and other users' data are not included. (#6334, export format) Attachments: Configure multiple named storage backends, insert attachment images into memo content, upload files in smaller chunks, and see your attachment storage usage in account settings. (#6184, #6172, chunked uploads, #6326) Editor: Improved IME and Windows emoji input, restored native mobile text assistance, attached pasted files correctly, preserved timestamp edits, and expanded tag autocomplete to more editing contexts. (IME input, emoji input, #6248, pasted files, timestamp edits, #6327) Markdown: Improved tag recognition, stopped currency amounts from being interpreted as inline math, fixed numbered task-list toggles, and enabled telephone and SMS links. (#6132, #6216, #6346, #6341) Views and API clients: Existing Shortcuts are migrated to Views. Integrations using the old Shortcut API must move to the UserService View operations under /api/v1/users/{user}/views. The reaction API also removes contentId; reactions remain scoped to their memo. (#6167, View operations, #6221) Account email: Email remains optional. Addresses are trimmed, lowercased, and unique per instance. Upgrades clear invalid addresses and keep a duplicate address only on the oldest account; affected usernames are logged. (#6314) RSS: RSS feed support has been removed. Existing feed URLs no longer provide feeds. (#6243)
  • 20 736
    20 Topics
    736 Posts
    Package UpdatesP
    [3.26.1] Update metabase to 0.63.18.1 Full Changelog
  • 2 7
    2 Topics
    7 Posts
    J
    @jendrik the ui is a bit confusing. You have to switch the mode to Private . Ideally, that password field should be disabled or hidden when 'Public'. [image: 67cd6c39-a43e-4446-9f92-fe1d26f59591-image.jpeg]
  • 52 523
    52 Topics
    523 Posts
    Package UpdatesP
    [2.38.11] Update bedrock to 1.26.51.1 Full Changelog
  • 11 100
    11 Topics
    100 Posts
    Package UpdatesP
    [1.7.3] Update v2 to 2.3.3 Full Changelog Feed and entry language detection: Miniflux now reads the language declared by feeds and entries and stores it on both feeds and entries. Feed discovery now finds the feeds offered by GitHub pages. TLS certificates are reloaded when the process receives SIGHUP, so renewed certificates can be picked up without a restart. Fixed an information disclosure issue where any authenticated user could read favicons belonging to other users' feeds through GET /v1/icons/{iconID}. Unix sockets are now created with 0660 permissions instead of being world-writable. Deployments where the reverse proxy runs as a different user now require that user to share a group with the Miniflux process. Fixed a crash caused by concurrent writes to the translation catalog when several requests used a not-yet-loaded language. Fixed a race condition during template rendering that could return a page translated in another user's language. Fixed "Mark all as read" on the unread page, which marked entries from categories hidden from the global unread list. Fixed pagination in the Entries API: the total count is now correct when the requested offset is past the last entry. Fixed the remove_tables rewrite rule reordering article content.
  • 54 704
    54 Topics
    704 Posts
    A
    version Minio RELEASE.2025-10-15T17-29-55Z io.minio.cloudronapp@5.3.0-1 automatic updates are on, the check for updates runs without finding anything new, and last updated 4 months ago.
  • 49 1k
    49 Topics
    1k Posts
    Package UpdatesP
    [2.9.15] Update mirotalksfu to 2.4.81
  • 16 103
    16 Topics
    103 Posts
    nebulonN
    The app package runs the cron job as outlined in https://github.com/monicahq/monica/blob/4.x/docs/installation/providers/generic.md#4-configure-cron-job Can you open a webterminal into the app and run it manually via: sudo -E -u www-data php /app/code/artisan schedule:run and see if it shows an error or sends the mails then?
  • 42 345
    42 Topics
    345 Posts
    Package UpdatesP
    [4.1.3] Update moodle to 5.2.3 Full Changelog Compare v5.2.2...v5.2.3
  • 162 2k
    162 Topics
    2k Posts
    Package UpdatesP
    [4.44.0] Update n8n to 2.40.5 Full Changelog Limit declarative routing during base URL ownership checks (#39147) core: Tear down workflow triggers when publication meets a node type the instance cannot load (#39056) core: Stop loading project members when listing credentials (#39095) core: Repair data-encryption keys stored as the raw instance key (#38910) editor: Fix blank workflow previews in AI Assistant (#38914) core: Keep breaking change detection running when a rule throws (#38789) editor: Send number values in credential inputs (#38880) Add Microsoft Dataverse core node (#34286) HTTP Request Node: Add support for PROPFIND, MKCOL, MOVE, COPY and REPORT methods (#24151) Rename AI Assistant to n8n Assistant (#38065)
  • 19 173
    19 Topics
    173 Posts
    Package UpdatesP
    [1.31.1] Update navidrome to 0.64.1 Full Changelog Unauthenticated password brute-force through the Subsonic API. Failed Subsonic logins were never throttled, so an attacker could guess passwords at full speed. Navidrome now rate limits failed authentication attempts. High, CVSS 7.4. (GHSA-p994-r776-mw52, #6185) Reported by @osageling. Authenticated SSRF through M3U external album artwork. A playlist could point #EXTALBUMARTURL at a private or loopback address, turning the server into a probe for internal network services. Navidrome now blocks private and loopback addresses in remote image fetches. Medium, CVSS 6.5. (GHSA-8hjf-6h34-82hr, #6181) Reported by @kaardeco. Cross-library file read through the M3U playlist cover. #EXTALBUMARTURL also accepted a local path, so a playlist could serve any file the server can read as its cover image. Only real image files are accepted as local artwork sources now. Medium, CVSS 6.5. (GHSA-vwq6-xrw5-phpg, #6180) Reported by @qrn12580. Player takeover by any authenticated user. Creating a player could overwrite an existing record and reassign its owner, and device registration reused another user's player without an ownership check. Both paths now check the owner. Medium, CVSS 6.4. (GHSA-37h4-53gj-cw8m, #6184) Reported by @RealFakeAccount and @qrn12580. Library filter skipped on bookmarks, playlist tracks and now-playing. These three endpoints ignored the libraries a user is allowed to see, leaking track metadata from other libraries. The filter now applies to all of them. Medium, CVSS 4.3. (GHSA-pcjv-h48m-833g, #6179) Reported by @sondt99. Add Quick Connect sign-in. The client shows a short code, and you approve it from a session that is already signed in, so the client never sees your password. (#6174 by @deluan) Add opt-in LAN auto-discovery, so Jellyfin clients find the server without you typing its address. Docker users need host networking for the UDP broadcast to reach the container. (#6169 by @deluan) Format dates using the language selected in Personal settings, instead of always following the browser locale. (#6160 by @deluan) Reference another playlist by its path in a smart playlist rule, instead of by id. (#5187 by @davidvedvick) Double-encode plus signs in artist and track names sent to Last.fm, so tracks with a + in the name scrobble correctly. (#6158 by @deluan)
  • 410 3k
    410 Topics
    3k Posts
    Package UpdatesP
    [5.8.8] Update server to 34.0.4 Full Changelog v34.0.4
  • 31 309
    31 Topics
    309 Posts
    Package UpdatesP
    [1.49.0] Update nocodb | stage to 2026.09.0 Full Changelog
  • 65 568
    65 Topics
    568 Posts
    Package UpdatesP
    [2.33.0] Update NodeBB to 4.16.0 Full Changelog allow admins to hide topic event types (#14824) add Messaging.isRoomMember() (#14779) add action:messaging.markRead hook with previous read timestamp (#14777) update chat room url with message index on scroll (#14738) expose category privilege copying via v3 API (#14670) add full name to ACP user search (#14671) add case-sensitive tag support with caseSensitiveTags config (#14690) prevent caching of responses carrying a CSRF token (#14787) ask for the current password when an admin changes their own password from ACP (#14790) skip existing members in addUidsToRoom to preserve join timestamps
  • 14 119
    14 Topics
    119 Posts
    Package UpdatesP
    [1.32.0] Update ntfy to 2.28.0 Full Changelog Fix messages being returned out of publish order when polling or replaying several topics at once (/topic1,topic2/json?poll=1, #1297) Limit the message title to 1 KB and all tags combined to 512 bytes, rejecting larger requests with HTTP 400 (error codes 40057 and 40058). Neither field had a size limit before, unlike the message body; on ntfy.sh the 99.9th percentile is 212 bytes for titles and 244 for tags Cap a single cache replay at 10 MB of messages per topic. A poll without a since cursor returns a topic's entire cache, which was previously unbounded and could reach tens of megabytes on a busy topic, so one request could allocate that much on the server. The newest messages that fit are kept and a truncated response carries an X-Messages-Truncated: 1 header visitor-attachment-daily-bandwidth-limit now also covers messages replayed from the message cache by poll requests, not just attachment traffic. A poll without a since cursor returns a topic's entire cache, so a topic that is cheap to fill can be re-read for many times its own size; polls beyond the budget are rejected with HTTP 429 (error code 42905) before anything is written. Note that heavy pollers now consume the same budget as attachment downloads, so operators serving both may want to raise the limit
  • 6 115
    6 Topics
    115 Posts
    Package UpdatesP
    [1.17.3] Update ollama to 0.34.3 Full Changelog GET /api/show now advertises each model's thinking controls and default: Nemotron H vision models are now supported on Apple Silicon with MLX Ollama's macOS app will now no longer reopen windows you've closed when activating it Fix for model pulls from HuggingFace Full Changelog: https://github.com/ollama/ollama/compare/v0.34.2...v0.34.3
  • 5 46
    5 Topics
    46 Posts
    Package UpdatesP
    [1.5.1] Update omeka-s to 4.2.1 Full Changelog Block titles for the IIIF page blocks were not properly escaped The IIIF presentation page block did not respect the site's configured IIIF viewer setting for the Mirador theme Some fields were not aligned properly on the admin advanced search Themes could not use the Ckeditor form elements to allow HTML input for theme settings Unnecessary spacing when listing data types in resource template browse Modules using older code for database queries could encounter errors related to core events like those used for processing fulltext search The Asset add form only allowed a fixed list of file types regardless of what types were specified in config The confirm password check did not properly run when the confirm box was left blank
  • 52 436
    52 Topics
    436 Posts
    M
    Thank you very much.
  • 6 42
    6 Topics
    42 Posts
    Package UpdatesP
    [0.9.0] Update opencloud to 6.1.0 Full Changelog Add a flag to the reindex command to force a full reindex [#2606] proxy: Allow mapping from an external tenant id to the internal id [#2569] feat: enable EnableInsertRemoteFile WOPI flag for Collabora [#2555] feat(multi-tenancy): verify tenant via OIDC claim [#2559] Fix race conditions in the hybrid metadata backend [#594] fix: error handling in upload session cleanup [#582] experimental: add darwin watchfs support [#471] Tracing [#596] fix: favorites list, undo delte doesn't return item to the favorites [#2382] feat: handle UI_InsertFile postMessage from Collabora [#2270]
  • 4 52
    4 Topics
    52 Posts
    Package UpdatesP
    [1.9.1] Update openhab-distro to 5.2.1 Full Changelog Make context information available for rules/scripts (5607) Add more commands/abilities to DSL scripts/rules (5727) Fix potential NPE in ScriptTransformationServiceFactory (5702) Fix YAML Thing TEXT configuration parameter processing to support list (5705) Fix chart not being rendered if item has no label (5722) VoiceResource: Select all available LLM tools by default (5749) ecoflow: Fix possible deadlock upon connection (21232) enphase: Fix connection stability (21100) gemini: Switch default model to 3.1-flash-lite (21239) hccrubbishcollection: Update API URL (21159)
  • 24 295
    24 Topics
    295 Posts
    Package UpdatesP
    [3.53.0] Update openproject to 17.8.0 Full Changelog Feature: Sprints and backlog buckets can be updated on bulk updating work packages [#73103] Feature: Add create_work_package MCP tool [#75408] Feature: Introduce target versions replacing version [#76181] Feature: Global restrictions/limits for time entries [#78132] Feature: Display relations in the work package table to the community edition [#78598] Feature: Add milestones to the project lifecycle widget [#76749] Feature: Activity tab: Journalise and add information about when a work package is added or discussed in a meeting [#61057] Bugfix: Both "Target version" and "Version" filters are present when target versions is enabled [#78408] Bugfix: Meeting invitation email shows event shifted by +1 hour for dates between 2026-09-29 and 2026-10-24 [#77624] Bugfix: Sprint names and assignments leaking through activity without view_sprints permission [#78436]
  • 4 Topics
    34 Posts
    J
    Hi @girish so I learned something while setting up my Radicale and OWC. It seems like the calendar client publishing in to the ICS in Radicale (or wherever your ICS source lives) can matter. When I used the Calendar app on macOS I saw no descriptions. When I used Thunderbird I do. You can see it on my live page that has the OWC page in an iframe https://kb.filewave.com/books/community-engagement/page/customer-event-schedule and if you click on events in the agenda then the description shows. I think initially I was also hoping to show description on the Agenda page without clicking on an event but originally I was bothered that I just couldn't get description to show up. So now it does at least show up when you click an event. I haven't looked at why Calendar doesn't make a summary that shows and Thunderbird does but I'm fine using Thunderbird to put events in my calendar feed.
  • 80 740
    80 Topics
    740 Posts
    Package UpdatesP
    [3.5.4] Update uv to 0.12.18 Full Changelog
  • 3 15
    3 Topics
    15 Posts
    Package UpdatesP
    [1.2.0] Update opodsync to 0.6.0 Full Changelog New: Add in-browser player that remembers position (thanks @debenore) New: display play progress in list of episodes New: Use relative date for listing last updated feeds Move list of episodes actions to a separate page Fix issues with feed updates reaching max_execution_time (thanks @MartinCa) Fix: durations were wrongly stored when they were in the HH:MM:SS format in feeds Fix: all feeds were always updated, now they're only updated if they have new actions Fix: set timeout for fetching a feed to 5 seconds (should be plenty enough)
  • 15 94
    15 Topics
    94 Posts
    Package UpdatesP
    [2.4.3] Update osTicket to 1.18.4 Full Changelog security: Latest Patches 06/2026 (52c366f, 5afdf54, c54a6ac, 1e39bf1, feccb6a, 6eb6b98, 078516e, 98abb05, e52e010, fd96bba, 7bbd8ab, ba6217a, 580e1c8, b535782, 5963797, d590a97, eaebe01, b4cc092, d457c14, 5600f94, 5ff9795, 119cefe, b4ede88, 2a0c388, 6558b33)
  • 30 204
    30 Topics
    204 Posts
    Package UpdatesP
    [1.25.1] Update outline to 1.10.1 Full Changelog Added WebMCP support in #13576, allowing agents in Chrome and ChatGPT to programmatically control Outline through the browser. Alt/Mod-click toggle disclosure folds nested or all toggle blocks in #13678 Keep editor "find and replace" panel open in #13643 Added Open Knowledge Format (OKF) export in #13644 Allowed editing webhooks without signing secrets in #13622 Escaped MCP attachment PUT upload command arguments in #13613 Fixed manual sizing of embedded PDFs in #13645 Fixed Mermaid diagram rendering size issue in #13648 Tighten authentication on views.create endpoint in #13663 Validate API key and OAuth scopes at the model layer in #13664
  • 17 105
    17 Topics
    105 Posts
    Package UpdatesP
    [1.7.0] Update owncast to 0.3.0 Full Changelog Featured Streams: Allow an Owncast instance to follow other instances #1676 Support simple display name setting on user registration via query param #5032 Allow binding rtmp to specific interface/localhost #4808 Enable autoplay when first enter the stream #1602 Plugin support #1736 Fediverse follow webhook event now has status and serverURL fields #4881 Re-enable the stream latency compensator #5001 Limit failed Fediverse OTP attempts to prevent brute-force guessing #5133 Bug report: USER_JOINED webhook doesn't fire when "Join Messages" is disabled in admin. #4950 Protect admin requests from cross-site attacks #5047
  • 3 16
    3 Topics
    16 Posts
    Package UpdatesP
    [1.3.0] Update base image to 5.0.0
  • 68 583
    68 Topics
    583 Posts
    Package UpdatesP
    [1.65.1] Update paperless-ngx to 3.2.1 Full Changelog Fix: only pass --conf to flower when flowerconfig.py exists @bitfoo1 (#14182) Fix: replace stale mail-fetch overlap check with a self-expiring lock @stumpylog (#14189) Fix: bump ocrmypdf to 17.12 to pick up the ligature text-layer fix @stumpylog (#14190) Fix: rebuild the search index automatically when it is missing Tantivy files @stumpylog (#14180)
  • 2 11
    2 Topics
    11 Posts
    girishG
    You can still install it like this https://my.<cloudron>/#/appstore/rocks.paperwork.cloudronapp . But note that it was last updated 3 years ago. I tried to build a new version with latest with PHP a year ago and the app was not even building anymore. They have been re-writing a new version for a couple of years now.
  • 107 926
    107 Topics
    926 Posts
    J
    It's out now!
  • 22 199
    22 Topics
    199 Posts
    Package UpdatesP
    [1.20.0] Update penpot to 2.18.0 Full Changelog Group toolbar drawing tools into shape and free-draw flyouts #9316 (MR: #9480, #10354) Add dedicated Line and Arrow drawing tools (by @davidv399) #9145 (MR: #9146) Show and manage comments while designing in the workspace #10239 (MR: #10275) Add outline stroke to Paths #9961 (MR: #8677) Add a grid/list view toggle for files in the dashboard #10691 (MR: #10692) Add multi-selection and bulk delete support to pages in the workspace sitemap #10580 (MR: #10581) Fix LDAP authentication storing client-supplied email instead of directory email and not escaping filter special characters #11084 (MR: #11085) Fix sessions remaining active on other devices after account deletion #11114 (MR: #11115) Fix backend session remaining valid after logout when the auth-token cookie is replayed #11316 (MR: #11317) Sanitize embedded scripts in SVG uploads #11043 (MR: #11044)
  • 6 Topics
    24 Posts
    girishG
    App discontinued due to no upstream updates.
  • 4 Topics
    12 Posts
    girishG
    The upstream project has not released in almost 3 years now. We had to build from develop to get some PHP 8 support going, but there are bugs like https://github.com/phpservermon/phpservermon/issues/1196 , https://github.com/phpservermon/phpservermon/issues/1232 . There's also a bunch of basic issues: Normal user cannot login after admin user logs in. Some issue related to service worker. LDAP functionality is incomplete
  • 5 63
    5 Topics
    63 Posts
    Package UpdatesP
    [3.4.0] Update Piwigo to 16.4.0 Full Changelog Release note
  • 80 679
    80 Topics
    679 Posts
    Package UpdatesP
    [1.24.2] Update pixelfed to 0.14.3 Full Changelog
  • 4 19
    4 Topics
    19 Posts
    Package UpdatesP
    [2.0.0] Update planka to 2.2.1 Full Changelog IMPORTANT: OIDC/SSO has been removed from PLANKA Community. After updating, all SSO-based users are deactivated, because they no longer have a password login. If your only admin account is SSO-based, you will be locked out. Create a new admin user first (via script or environment variables) before updating: https://docs.planka.cloud/docs/configuration/admin-user The Cloudron package has removed OIDC integration as part of this major update
  • 9 165
    9 Topics
    165 Posts
    Package UpdatesP
    [1.18.4] Update pocketbase to 0.40.4 Full Changelog Fixed migration deadlock if a logs db write happens to run while the migration is still executing (#7836). app.ResetBootstrapState() was soft-deprecated in favour of app.ClearBootstrap(). Additionally a new app.OnClearBootstrap() hook was added to allow clearing custom allocated OnBootstrap resources in case the app uses a non-standard initialization (e.g. doesn't call Start() or intentionally skip the OnTerminate hook). Bumped golang.org/x/* dependencies.
  • 22 222
    22 Topics
    222 Posts
    robiR
    Here's the video:
  • 9 82
    9 Topics
    82 Posts
    Package UpdatesP
    [1.10.0] Update pretix to 2026.7.0 Full Changelog
  • 8 60
    8 Topics
    60 Posts
    Package UpdatesP
    [1.11.6] Update PrivateBin to 2.0.6 Full Changelog CHANGED: Upgrading libraries to: DOMpurify 3.4.12 CHANGED: Switch to PHP native JsonException type FIXED: Gracefully handle YOURLS replies with a 200 status code but no shorturl, instead of raising a TypeError FIXED: Return "Invalid data." instead of HTTP 500 on malformed v2 JSON payloads (#1883) FIXED: Dead PATH validation guard in Controller, the check for a missing trailing directory separator never ran (#1887)
  • 20 234
    20 Topics
    234 Posts
    Package UpdatesP
    [1.17.2] Update alertmanager to 0.34.1 Full Changelog [BUGFIX] inhibit: Fix several issues related to inhibitions that caused alerts to be improperly un-muted in some cases. #5542, #5449, #5559
  • 6 107
    6 Topics
    107 Posts
    Package UpdatesP
    [2.29.0] Update VueTorrent to 2.35.0 Full Changelog show raw data values on hover (#2867) (e92249f) capitalize language names in locale switcher (#2903) (f47c1d2) Improve network sync reliability (559919e) Repair broken desktop layout (9e2b435) Settings: API key copy not working in insecure contexts (#2880) (ec39bbd) Improve chunking for better app load time (#2881) (b0eff6c) links: Add mouse middle click support to open in new tab (#2902) (38ca598) Pause network requests on tab change (6a42b7b)
  • 15 165
    15 Topics
    165 Posts
    Package UpdatesP
    [2.16.0] chore(deps): update dependency radicale to v3.8.0
  • 16 205
    16 Topics
    205 Posts
    Package UpdatesP
    [2.15.2] Update rallly to 4.15.2 Full Changelog Decouple registration from email login (#3337)
  • 9 75
    9 Topics
    75 Posts
    girishG
    App discontinued due to no upstream updates.
  • 14 106
    14 Topics
    106 Posts
    Package UpdatesP
    [5.4.0] Update redash to 26.3.0 Full Changelog
  • 18 175
    18 Topics
    175 Posts
    Package UpdatesP
    [3.20.3] Update redmine oauth to 7.0.1
  • 19 125
    19 Topics
    125 Posts
    Package UpdatesP
    [1.13.2] Update releasebell to 1.13.2 Fix to scope project updates to the owner user
  • 71 790
    71 Topics
    790 Posts
    Package UpdatesP
    [3.7.1] Update Rocket.Chat to 8.8.1 Full Changelog Fixes Omnichannel rooms failing to register agent responses (and showing send errors on messages and file uploads that were actually delivered) when the room carried corrupted visitor activity data created by older app integrations
  • 55 380
    55 Topics
    380 Posts
    C
    Understood, thank you for testing that for me! Guess I will have to take the plunge to get things going
  • 9 62
    9 Topics
    62 Posts
    O
    @girish said: @rmdes @odie I have updated the app to use symlinks under /app/data/bridges. You can add new bridges there or delete some symlink and add your own. Thank you! Works excellent!
  • 2 44
    2 Topics
    44 Posts
    Package UpdatesP
    [0.23.0] Update rustfs to 1.0.1-preview.10 Full Changelog feat(nightly): publish packages as assets of the rolling 'nightly' release (sync from release) by @majinghe in #7593 fix(ecstore): stop pruning at nonempty directories by @marshawcoco in #7616 fix(replication): close the pre-stable convergence gaps from backlog#2367 by @reatang in #7626 feat(console): support a configurable console URL prefix by @overtrue in #7634 feat: configure the console base path at build time by @cxymds in #7636 fix(heal): preserve retryable batch failures during recovery by @overtrue in #7642 fix(s3): reject oversize single PUT early and map body errors to 4xx by @reatang in #7635 fix(ecstore): make directory mtime fixture portable by @marshawcoco in #7623 fix(storage): prevent readiness after native migration failures by @rjregenold in #7652 fix(admin): expose OIDC account display fields by @GatewayJ in #7654
  • 4 15
    4 Topics
    15 Posts
    girishG
    Given that the upstream project is not maintained anymore, we have hidden this in the appstore. I had also submitted a PR upstream for a basic issue which is ignored - https://github.com/aliasaria/scrumblr/pull/161
  • 18 264
    18 Topics
    264 Posts
    Package UpdatesP
    [2.112.0] Update searxng to 2e624be
  • 2 33
    2 Topics
    33 Posts
    Package UpdatesP
    [1.24.0] Update seaweedfs to 4.47 Full Changelog [Mount] Add ChunkGroup seeking tests and fix boundary handling by @ssshr-66 in #11223 fix(mount): bound reader cache memory across open files by @chrislusf in #11220 fix(s3api): evaluate aws:SourceIp from the direct TCP peer, not forwarded headers by @chrislusf in #11231 filer/postgres: create filemeta table on startup via createTable config by @chrislusf in #11229 fix(volume): handle faulty storage media (Go + Rust) by @chrislusf in #11233 fix(filer): use path.Split instead of filepath.Split for filer paths by @chrislusf in #11246 s3: bucket-policy Allow must not override an identity explicit Deny by @chrislusf in #11256 feat(s3api): add bucket quota S3 extension via ?seaweedfs-quota by @chrislusf in #11279 fix(master): stop goraft server on shutdown and bump raft to v1.2.1 by @chrislusf in #11284 filer: apply SSRF guard to the lazy-remote fetch/list/delete paths by @chrislusf in #11294
  • 5 35
    5 Topics
    35 Posts
    Package UpdatesP
    [1.4.0] Update serpbear to 3.1.0 Full Changelog add subdomain matching functionality (4533737), closes #​324 enhance error handling and response structure in scraper functions (4f394c2) minor ui issue (eecf88a) prevent corrupt failed queue file to reset the app settings (c306fa0), closes #​328 resolves broken google ads oauth of instances behind reverse proxy (a988b13), closes #​326 resolves cron issue with certain port mapping config (d86616a) resolves issue that prevents refreshing all keywords when one fails (77cfa2f)
  • 14 87
    14 Topics
    87 Posts
    Package UpdatesP
    [1.4.5] Update sftpgo to 2.7.6 Full Changelog WebDAV: return the correct ETag after an upload, or no ETag when it is unavailable. An instance that starts with an empty admins table kept serving the setup page until restart; instances backed by a shared SQL provider now re-check the database. OIDC: bound the authorization request to the user agent. Share links were not revoked when the owning account was disabled or expired. GHSA-5jhj-cjcp-jr8r. Unbounded memory allocation when parsing SCP protocol records. GHSA-j4w8-6gjf-fqvg. WebClient: Stored cross-site scripting through directory names. Reported by ERNW. GHSA-f9qc-3v4f-32w3. File pattern filters were not evaluated on the source of a copy. GHSA-wwv9-g5x4-966q. Downloading a share restricted to a single directory as a ZIP archive could extend the share to the owner's entire file system; this affects only the in-memory data provider, while other data providers are not impacted. Thanks to Yutaka Sasaki (@SAYUTIM) for the report. SFTP: computing a file hash reads the whole file and now requires the download permission; it previously accepted list. Reported by @cyny666. httpd: JWT invalidation is now keyed on the token ID. Invalidation was keyed on the exact token text, so an equivalent Base64URL spelling of the same signed token did not match the stored entry and kept working after a logout. Reported by Corban Villa (@corbanvilla), Sohee Kim (@soh3e) and Austin Chu (@dderpym).
  • 5 49
    5 Topics
    49 Posts
    Package UpdatesP
    [2.18.5] Update Shaarli to 0.16.7 Full Changelog fix: prevent stored XSS in Picture Wall via bookmark title tests: cleanup: remove obsolete test Dockerfiles and documentation Full Changelog: https://github.com/shaarli/Shaarli/compare/v0.16.6...v0.17.0
  • 7 50
    7 Topics
    50 Posts
    jdaviescoatesJ
    @girish said in SickChill unlisted from app store: I hope they atleast bring back the issue tracker Out of interest, why does this matter for Cloudron? BTW, someone has replied to the thread I started on Discord informing me that the master releases are these https://pypi.org/project/sickchill/ Doesn't look like there has been a new one since March though.
  • 2 15
    2 Topics
    15 Posts
    Package UpdatesP
    [1.3.0] Update shiori to 1.8.0 Full Changelog feat(apiv1): refactor tags api (#1075) feat: add PWA support share functionality (#1060) feat: add apis to handle bookmark tags (#1081) feat: allow tag filtering and count retrieval via api v1 (#1079) feat: improve SQLite performance (#1024) feat: reverts message in json output and allows configuration (#1082) feat: support proxy forward headers authentication (#1105) fix: auth validation on existing sessions, rely on token only (#1069) fix: incorrectly set cookie's expires value in login.js (#1049) fix: parse pocket new CSV format (#1112
  • 4 Topics
    41 Posts
    girishG
    The upstream project is archived - https://github.com/boypt/simple-torrent/ . There has been no changes in 2 years and modules are not updated.
  • 33 363
    33 Topics
    363 Posts
    necrevistonnezrN
    This is GREAT news! 🥰
  • 23 227
    23 Topics
    227 Posts
    jamesJ
    Hello @günter In the future you can use https://paste.cloudron.io/ Thanks for reporting this issue, we will have to look into it.
  • 60 430
    60 Topics
    430 Posts
    Package UpdatesP
    [2.18.11] Update sogo to 5.12.11 Full Changelog junk: add junk action on mail view (3f4f949) core: keep the @import cleanup working in stringWithoutHTMLInjection (8813677) db: release db channel after using them (152f44b) db: release db channel after using them part 2 (089b50c) junk: extend list of junk icon available (012e6ef) mail: escape mail data placed in attributes of a compiled part (045a0b9), closes #115 mail: stop interpreting iMIP card text fields as markup (0d66d75) pwd: use the proper url for reset password mail (382118a) pwd: use the proper url for reset password mail part2 (04a3e98) sanitization: update regex for html sanitization (10dc173)
  • 13 104
    13 Topics
    104 Posts
    girishG
    Just checked on this again but it seems statping-ng is not going forward much . https://github.com/statping-ng/statping-ng/tags says the release was almost a year ago.
  • 44 470
    44 Topics
    470 Posts
    Package UpdatesP
    [3.15.3] Update Stirling-PDF to 2.14.3 Full Changelog Redact: clear error instead of a 500 when no text patterns are given (cherrypicked) by @jbrunton96 in #6972 fix(temp-files): prevent cleanup of active registered directories by @Ludy87 in #7006 fix(admin-settings): correctly mask Telegram bot tokens in settings output by @Ludy87 in #6822 fix(admin-settings): prevent hydration error in the Admin General section by @Ludy87 in #6823 fix(editor): respect no-login settings visibility in config navigation by @Ludy87 in #6807 fix(licenses): fall back to license URL for backend dependency links by @Ludy87 in #7046 fix(sign): preserve PNG signature placement and page content by @Ludy87 in #7093 fix(viewer): dynamic page number input width based on total page count by @balazs-szucs in #6607 Avoid renderer OOM when adding large PDFs to the workbench by @Frooodle in #7175 fix(search): Fix PDF viewer search showing 0 of 0 results by @balazs-szucs in #7228
  • 15 145
    15 Topics
    145 Posts
    Package UpdatesP
    [1.12.1] update apache-superset to v6.1.0
  • 107 797
    107 Topics
    797 Posts
    robiR
    I thought App passwords were now API keys.
  • 32 243
    32 Topics
    243 Posts
    Package UpdatesP
    [1.34.4] Update syncthing to 2.1.5 Full Changelog Devices and folders can now be grouped in the GUI by setting the new group attribute. HTTP and HTTPS proxies with support for CONNECT can now be used, in addition to the existing support for SOCKS proxies (the environment variable all_proxy=https://...). Block indexing can be turned off for folders where it's more desirable to optimise for reduced database size and overhead than minimal transfer size (the blockIndexing attribute on folder configuration). GUI login session duration can be configured to be longer or shorter than the default one week, or set to infinitely long. The cookie path can also be adjusted. (The sessionCookieDurationS and sessionCookiePath attributes in the GUI configuration.) APT repository: https://apt.syncthing.net/ Full Changelog: https://github.com/syncthing/syncthing/compare/v2.1.4...v2.1.5
  • 21 204
    21 Topics
    204 Posts
    Package UpdatesP
    [2.19.5] Update taiga-back to 6.10.2 Full Changelog fix: enforce permission check on create_default due date endpoints
  • 6 101
    6 Topics
    101 Posts
    Package UpdatesP
    [1.12.14] Update recipes to 2.6.15 Full Changelog added pestle import support (thanks to LLf13 #4637) added AI based step sorter to recipe import (thanks to sadSanta-07 #4799) improved adding multiple recipes to a book at the same time (thanks to ujjwalv01 #4610) fixed group permission caching issue accross spaces GHSA-29pm-4vh2-f8mp fixed recipe export not respecting private flag of recipes GHSA-gh65-4455-65vg fixed possible to add other space member private recipes to book via api and see overview GHSA-gh65-4455-65vg fixed file path of recipe could be changed to show a different file GHSA-8635-c66p-9cwm fixed fixed batch update allowing recipe shares accross spaces GHSA-5mw3-c978-gc6w fixed image rotation sometimes lost when uploading to tandoor #4765 (thanks to @agross #4769) changed cook logs to only be editable by the creator or admins of a space GHSA-g378-5m3q-p58q
  • 10 69
    10 Topics
    69 Posts
    Package UpdatesP
    [1.5.2] Fixup doc URL
  • 9 79
    9 Topics
    79 Posts
    timconsidineT
    @timconsidine said in Teddit Subscriptions no longer working: Just FYI - my LibReddit - selfhosted as Docker on another VPS = is still working. But now it is down. Maybe they have caught up with me.
  • 5 52
    5 Topics
    52 Posts
    Package UpdatesP
    [1.23.2] Update thelounge to 4.5.2 Full Changelog include the version script in the NPM package (#5115) (833a8bb by @deltamualpha)
  • 10 67
    10 Topics
    67 Posts
    girishG
    @Sam_uk we have unlisted TLDraw by now. Please see https://forum.cloudron.io/topic/10806/no-more-updates-to-tldraw . The license and company direction has changed.
  • 22 243
    22 Topics
    243 Posts
    Package UpdatesP
    [1.28.1] Update traccar to 6.15.3 Full Changelog
  • 10 103
    10 Topics
    103 Posts
    Package UpdatesP
    [2.7.4] Update libretranslate to 1.9.6 Full Changelog Turkish UI
  • 12 81
    12 Topics
    81 Posts
    Package UpdatesP
    [2.5.3] Update transmission to 4.1.3 Full Changelog Fixed a CORS bug that leaked the anti-CSRF nonce. (#8938) Fixed a use-after-free bug in peer code. (#8921) Fixed build error when compiling with fmt 12.2.0. (#8942) Fixed a 4.1.2 build error in tests. (#8881)
  • 13 162
    13 Topics
    162 Posts
    Package UpdatesP
    [1.31.0] Update Trilium to 0.105.0 Full Changelog MCP now requires authentication and can optionally be accessed over the network. Reconfigure your existing MCP clients with credentials. General HTML support in text notes is now disabled by default. This makes copy-paste from websites behave well, without grabbing unwanted tags such as input boxes. Re-enable via Options Text notes Preserve unsupported HTML tags. <div>s in text notes are now unwrapped instead of being preserved as-is, regardless of settings. This prevents broken behaviour when entering new paragraphs, and bugs such as being unable to exit a code block. Single-tilde strikethrough is no longer supported, to avoid issues with ~ used for number approximations. Affects existing notes and import pipelines; use ~~text~~. Database actions have moved to Options Database. Cleanup, space analysis, integrity checks, compaction and anonymized copies are no longer under Options Advanced, which now holds the experimental features and the two advanced sync actions alone. On Linux, the native title bar is now disabled by default, since rounded corners are supported for the custom frame, with native window buttons. Fixed an important memory leak that accumulated components and event listeners due to improper component cleanup. Consistency checks no longer take a long time to run on large databases (20k+ notes). Inline Mermaid diagrams remember their display mode. Multiple inline Mermaid diagrams don't render without making a change
  • 37 424
    37 Topics
    424 Posts
    Package UpdatesP
    [2.102.0] Update tt-rss to 820aeae
  • 3 52
    3 Topics
    52 Posts
    Package UpdatesP
    [1.13.0] Update tymeslot to 1.17.0 Full Changelog booking: Ask for a policy acknowledgement again when rescheduling booking: Stop offering times the host has already booked Stop "Schedule Another Meeting" moving a just-rescheduled booking scheduling: Keep a reschedule on the meeting type it booked Deliver email to SMTP relays that negotiate TLS 1.3 scheduling: Carry a booking's answers into its reschedule Save the booker as an attendee on CalDAV calendars Create the video room when a calendar event's provider is chosen Stop CalDAV colour and offline changes being rejected mailer: Let SMTP reach relays behind a middlebox that blocks TLS 1.3
  • 13 106
    13 Topics
    106 Posts
    Package UpdatesP
    [1.18.0] Update twenty to 2.41.0 Full Changelog Let every application admin manage a workspace-shared connection (#25773) by @abdulrahmancodes feat(server): validate workflow versions through exceptions, malformed at write and non-activable on activate or validate (#24964) by @charlesBochet feat(messaging): let apps own message channels (#25903) by @FelixMalfait feat(messaging): let apps ingest messages into their channels (#25905) by @FelixMalfait feat(messaging): resolve identity for non-email participants (#25906) by @FelixMalfait fix(server): backfill workflow rich text record fields (2.41 upgrade command) (#24965) by @charlesBochet fix(currency): prevent dropping decimal separator and multiplying amount on 0-decimal fields (#25870) (#25904) by @Dewin fix(billing): restore the credit-package match on an interval switch (#25919) by @FelixMalfait fix(record-form): render rich text fields with the BlockNote editor (#25920) by @thomtrp fix(messaging): enforce CRLF line endings on raw outbound messages and surface IMAP append error responseText (#26011) (#26017) by @Dewin
  • 43 305
    43 Topics
    305 Posts
    Package UpdatesP
    [1.27.0] Update typebot.io to 3.19.0 Full Changelog If you use Webhook blocks, you must now set WEBHOOK_RELAY_SECRET to the same secret in builder, viewer and your PartyKit server. This also applies to Webhook blocks used in previews and WhatsApp flows. Missing or mismatched secrets prevent Webhook responses from resuming conversations. The first URL in NEXT_PUBLIC_VIEWER_URL must use a different hostname from NEXTAUTH_URL. Different ports on the same hostname are insufficient. Configure a separate viewer hostname before upgrading so builder previews remain available. SMTP configuration tests now validate destinations and pin the connection to a validated IP address. Private SMTP servers require an exact hostname entry in SSRF_ALLOWED_HOSTS; this instance-wide allowlist permits RFC1918 addresses only. Loopback, link-local and metadata endpoints remain blocked. Resolve variables in Forge option arrays. Strengthen preview isolation, linked draft permissions and preview session creation. Restrict WhatsApp sessions to internal runtime access. Authenticate webhook responses and relay subscriptions, and enforce webhook ownership and write access. Protect SMTP configuration tests and special-use IP ranges against SSRF. Block external sign-in redirects and serialize concurrent email verification attempts. Restrict guest workspace access and prevent writes during read-only typebot migrations.
  • 33 290
    33 Topics
    290 Posts
    J
    @ekevu123 said: Can Cloudron change the build process and perhaps have fewer workers run in parallel, and perhaps not rebuild the app with every restart? Apps are not rebuilt on every restart. Do you mean creating a container ?
  • 39 360
    39 Topics
    360 Posts
    Package UpdatesP
    [2.8.4] fix base image
  • 20 130
    20 Topics
    130 Posts
    nebulonN
    At least in the passt this was more like a rolling release on upstream side, but haven't closely followed the recent developments. However since we cannot lock down specific versions anyways since by design everytime the valheim server restarts, it checks and may or may not update itself, we can also not really release new package versions on our side as they become meaningless. The whole valheim server/client contract seems to be evergreen. So essentially as soon as the game client reports old server version, just restart that valheim app on your cloudron and it should be on latest again.
  • 4 121
    4 Topics
    121 Posts
    Package UpdatesP
    [1.84.1] Update vault to 2.1.1 Full Changelog
  • 99 854
    99 Topics
    854 Posts
    Package UpdatesP
    [1.26.3] Update vaultwarden to 1.37.3 Full Changelog Fix password change with newer web-vault by @BlackDex in #7634 Ignore reset-password auto-enroll when mail is disabled by @xhon-pelushi in #7585 Fix migration for MariaDB 12.2.2 by @Timshel in #7265 Add SSO_SIGNUPS_ALLOWED by @Timshel in #7272 Fix organization import failing with missing field groups by @tom27052006 in #7699 Add pm-32413-multi-client-password-management feature flag by @tom27052006 in #7677 Log IP/username on two-factor email-login credential failures by @crahn in #7654 Support admin reset 2fa by @Timshel in #7435 fix(security): revoke 2FA remember tokens when credentials or 2FA change by @BryanFRD in #7682 fix(security): rate limit prelogin and auth request endpoints by @BryanFRD in #7681
  • 1 1
    1 Topics
    1 Posts
    Package UpdatesP
    You can use this thread to track updates to the Versitygw package. Please open issues in a separate topic instead of replying here.
  • 9 176
    9 Topics
    176 Posts
    Package UpdatesP
    [1.84.1] Update verdaccio to 6.10.4 Full Changelog 7730e60: Update express to 4.22.3 directly and through @verdaccio/middleware 8.1.4, verdaccio-audit 13.1.4 and @verdaccio/test-helper 4.1.4 so the registry's entire HTTP stack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string handling: a remotely triggerable crash in qs.stringify (TypeError on crafted input), an arrayLimit bypass through bracket-key comma parsing that allows memory exhaustion, and a DoS via an attacker-controlled isBuffer check (GHSA-4mjr-xmp4-gh2g). A body-parser/qs resolution covers the one remaining consumer that pins qs below the fix. Query-string parsing behaviour is otherwise unchanged and no configuration change is needed. aabb0b4: Fix npm publish failing with request size did not match content length when authenticating with a token created by npm token create. e2602b3: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9
  • 39 282
    39 Topics
    282 Posts
    Package UpdatesP
    [1.26.0] Update vikunja to 2.6.0 Full Changelog Enforce token scopes for task expansions Don't duplicate a task when a client PUTs a stale href Encode task uids in hrefs instead of interpolating them raw (#3560) Don't wrap reminders into the past when repeating from current date Reuse existing labels in the desktop quick entry window (#3533) Add default due time settings (#3433) (d71301f) Filter tasks by creator username (#2916) (07927c5) Add clearing stored notifications (#2735) Add planka migration form Add --config flag to pin the config file (#3652)
  • 69 529
    69 Topics
    529 Posts
    Package UpdatesP
    [2.23.3] Update vpn to 2.23.3 Fix settings UI
  • 20 169
    20 Topics
    169 Posts
    Package UpdatesP
    [2.5.6] Update wallabag to 2.6.14 Full Changelog Change version in wallabag.yml by @nicosomb in #8251 Fix deprecation by @j0k3r in #8267 Add annotations filter to entries API endpoint by @skn in #8346 Update dependencies by @yguedidi in #8435 Bump deps (mostly for siteconfig) by @j0k3r in #8489 Fix reading time computation for short entries by @andreadecorte in #8332 Fix urls parameter when sending many urls to be stored using the API by @j0k3r in #8488 Prepare 2.6.14 by @j0k3r in #8494
  • 5 95
    5 Topics
    95 Posts
    Package UpdatesP
    [1.30.0] Update Wallos to 5.8.1 Full Changelog buttons position for push notifications (#1226) (9e2ad14) add push notifications (ece43eb) admin: let the deployment own the instance SMTP settings and the server URL (1ea12e6) currency: add frankfurter.dev as a provider that needs no account (dd7cf87) admin: let the SMTP test button see a managed password (cbd4ec1) categories: recognise the no-category placeholder by language (1f27e7a) i18n: a new account's categories are in the language it was created with (9dd66f4) i18n: an account an identity provider creates is in the language it named (5b3f445) notifications: ask the SSRF check about the account, not the last payer (4d24ccc) push: stop reloading the page to subscribe or remove a device (b308da0)
  • 5 80
    5 Topics
    80 Posts
    Package UpdatesP
    [1.43.1] Update whitebophir to 2.17.1 Full Changelog
  • 8 160
    8 Topics
    160 Posts
    Package UpdatesP
    [1.50.0] Update weblate to 2026.9.1 Full Changelog Added per-user notification diagnostics for users and administrators, with compact explanations of matching subscriptions for object paths. Prevented repeated authenticator app registration from creating duplicate devices and allowing reuse of one-time codes. Existing equivalent duplicate devices are merged while preserving consumed codes. Engage pages and status widgets no longer disclose Private or Custom projects unless Public sharing is enabled. Fixed the approved-only commit policy blocking commits for languages with reviews disabled by workflow settings. Restored DeepL API v1 translation support while retaining modern API language discovery and glossary improvements. REST API unit updates now enforce the same translation text length limit as the web editor. Anonymous access to engage pages and status widgets is now disabled by default for Private and Custom projects. Enable Public sharing to preserve existing shared links after upgrading. Public and Protected projects are unchanged. Authenticator app registrations started before this upgrade must be restarted. Sessions referencing a removed duplicate device may require two-factor verification again. Docker deployments now default to the combined Celery worker mode. If your deployment relies on separate workers for each queue or configures them using CELERY_MAIN_OPTIONS, CELERY_NOTIFY_OPTIONS, CELERY_MEMORY_OPTIONS, CELERY_TRANSLATE_OPTIONS, or CELERY_BACKUP_OPTIONS, set CELERY_WORKER_MODE=split to preserve the previous behavior. All changes in detail.
  • 25 579
    25 Topics
    579 Posts
    Package UpdatesP
    [4.180.0] Update wekan to 11.93 Full Changelog Bound OAuth fixture parsing and hide login exception details. Thanks to GitHub CodeQL and xet7. Refresh reviewed telemetry inventory and detect stale reviews locally. Thanks to xet7. Distinguish known dependency keyword false positives from new findings. Thanks to xet7. Update release runtime discovery and fix Windows source resolution. Thanks to xet7. Accept valid GitHub SSH origins in release launchers. Thanks to xet7. Add release menus and automated dependency risk checks. Thanks to xet7.
  • 16 140
    16 Topics
    140 Posts
    Package UpdatesP
    [1.13.8] Update wiki to 2.5.315 Full Changelog 2df962c - prevent manage:users users from editing manage:system users (commit by @NGPixel) fixes GHSA-45cp-v5ph-2jhm reported by @chimmeee 1161ddc - prevent user-provided v-slot content (commit by @NGPixel) fixes GHSA-98c8-px3r-68c6 reported by @chimmeee
  • 4 73
    4 Topics
    73 Posts
    Package UpdatesP
    [2.20.1] Update woodpecker to 3.18.1 Full Changelog Add timezone data to docker images [#7093] Log an expected log-stream close failure at debug instead of error [#7117] Log a filtered webhook at debug instead of error [#7116] Fix workflow-level when.status so a failure-only workflow does not run on success [#7091] Speedup migration "deduplicate-log-entries" [#7068] fix(forge/gitlab): use group Path instead of Name for membership lookup [#7086] Fix injecting additional variables for substituting [#7077]
  • 116 Topics
    887 Posts
    jamesJ
    Hello @milohiss The @wordpress-managed version 3.20.3 had an issue where old installations did not set HTTPS=on correctly and 3.20.3-1 fixes this issue. From a SemVer standpoint 3.20.3-1 is lower than 3.20.3 so adding a changelog entry for 3.20.3-1 after 3.20.3 would be considered wrong. A long time ago we decided to use the $VERSION-X format as means for the Cloudron app store to directly offer the -X version instead of the $VERSION so the faulty version is skipped. Please apologize this confusion.
  • 227 Topics
    2k Posts
    Package UpdatesP
    [3.16.3] Update WordPress to 7.1.2 Full Changelog Important security fix: please update your WP installation immediately. Note: This WP is the developer edition, you have to update WP in the WP admin panel. Updating this package, does not update WP. An unauthenticated path traversal issue in page-template resolution leading to conditional remote code execution reported by Robert Ressl
  • 14 71
    14 Topics
    71 Posts
    S
    @james Just installed the updated package and tried it out. Seems to be working without issues, so far. Thanks!
  • 20 138
    20 Topics
    138 Posts
    Package UpdatesP
    [1.12.3] Update YOURLS to 1.10.6 Full Changelog fixed: the version number. It's just 1.10.5, without the -dev, as 1.10.5 should have been. Sorry
  • 2 Topics
    26 Posts
    Package UpdatesP
    [1.8.1] Update urlaubsverwaltung to 6.13.1 Full Changelog Appointing the initial office user rewrites the person from the caller's entity #6685 NullPointerException when unmarking a session that no longer exists #6686 Settings-Cache ist nicht multi-instance-sicher #6683