Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

Packages

6.0k Topics 57.6k Posts

Questions about packages in the App Store

Subcategories


  • 9 75
    9 Topics
    75 Posts
    Package UpdatesP
    [1.20.2] Update 2FAuth to 8.0.2 Full Changelog issue #563 API tokens does not works on OpenID accounts issue #565 Trailing slash "/" needed for extension to work issue #569 Server error page shown after sharing with no email configured
  • 10 85
    10 Topics
    85 Posts
    J
    @oneinterweb you have to change the credentials in /app/data/env ACKEE_USERNAME=admin ACKEE_PASSWORD=supersecret This works fine.
  • 7 62
    7 Topics
    62 Posts
    Package UpdatesP
    [1.29.0] Update actual to 26.9.0 Full Changelog View release notes
  • 41 437
    41 Topics
    437 Posts
    Package UpdatesP
    [1.14.19] Update AdGuardHome to 0.107.79 Full Changelog Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in [1.26.6][go-1.26.6]. AdGuard Home is now more resistant to resource exhaustion attacks when using DNS-over-QUIC. Bootstrap servers configuration now supports comments. New property "language" in POST /control/install/check_config and POST /control/install/configure HTTP APIs. The user is able to remove the static lease's hostname via the HTTP API. The edge channel has been switched to the new UI and versioning scheme. strict_sni_check is now deprecated. DNS64 treating unresolved CNAME/DNAME answers as the end of resolution chain (#7514). Blocked requests without an EDNS(0) OPT record (#8183).
  • 12 115
    12 Topics
    115 Posts
    S
    This look like a good replacement for Alltube (which we were using) https://github.com/alexta69/metube
  • 3 7
    3 Topics
    7 Posts
    jamesJ
    Hello @umnz Yes, this means that the app is a new addition and considered unstable. You can use it, but it could be that a future update might break something.
  • 16 194
    16 Topics
    194 Posts
    Package UpdatesP
    [1.30.0] Update ampache to 8.1.0 Full Changelog Proof of work checks in front of the endpoints bots hammer Database 810011: New album.enabled and artist.enabled, so a release can be withdrawn without deleting it and losing its playlist entries, ratings and play history New album_grouping_fields option controlling which fields decide whether two songs share an album row Drawn cover art for items that have none: an album gets a record, an artist a medallion, an orphaned song a waveform, a playlist a tracklist The OPML export of podcast subscriptions read every podcast in the system regardless of the caller's catalog filter, letting a restricted user enumerate the subscriptions of catalogs they cannot browse A username was used raw as an upload folder name, so ../.. escaped the catalog. Path segments are no longer allowed in username A disabled user account could still authenticate through Subsonic and an RSS feed token Password/token comparisons in the API handshake, the session_remember cookie MAC, and API key/stream token lookups used ===/!= instead of hash_equals() Ldap::auth() concatenated the raw username into the LDAP search filter and group-membership regex with no escaping Private playlists and searches leaked through several endpoints: web smartlist, Subsonic getPlaylist/getPlaylists
  • 7 Topics
    68 Posts
    Package UpdatesP
    [1.7.2] Update answer to 2.0.2 Full Changelog Add reasoning content support in AI conversation records and chat UI to preserve model thinking output across follow-up rounds (@hgaol #1530) Allow disabling email verification from site settings for deployments that do not require mandatory email confirmation (@AsyncAssassin #1540) Add recovery middleware to handle unexpected panics more gracefully in HTTP requests (@hhc7 #1537) Add interval support for new question email notifications (@AsyncAssassin #1545) Move new question email throttling to a dedicated worker and make the email queue configurable for better operational control (@AsyncAssassin) Fix edit question failing when short links are enabled (@LinkinStars #1554) Fix missing license entry for mozillazg-go-unidecode (@LinkinStars #1552) Prevent incorrect external login account binding during connector sign-in flows (@LinkinStars) Align revision audit permission checks for both approve and reject actions (@LinkinStars) Preserve accepted answer operations when short links are enabled (@hgaol #1541)
  • 6 28
    6 Topics
    28 Posts
    K
    @girish I understand. Thanks!
  • 4 25
    4 Topics
    25 Posts
    jamesJ
    Hello @andreasdueren Thanks for the report. Fixing it right now.
  • 8 Topics
    121 Posts
    Package UpdatesP
    [1.100.0] Update audiobookshelf to 2.36.0 Full Changelog Logout all devices button on account page (in #5395) Auth sessions table on account page w/ ability to logout of individual sessions (in #5400) Weak protocol validation for OIDC post-login callback URL by @mikiher in #5386 User delete endpoint allowing for root account deletion by @mikiher in #5370 API and websocket authentication allowing refresh tokens by @mikiher in #5387 Bulk library item download endpoint not checking access on individual items by @mikiher in #5388 Manual podcast episode match not setting the enclosure url #5317 by @mikiher in #5318 Changing user password invalidates all auth sessions (in #5393) Extend refresh token grace period to 10 minutes and allow REFRESH_TOKEN_GRACE_PERIOD env variable override #5281 by @DanielAshley in #5376 API: New GET endpoints /api/me/progress, /api/me/bookmarks, /api/me/bookmarks/:libraryItemId by @Vito0912 in #5363
  • 10 35
    10 Topics
    35 Posts
    girishG
    Thanks for reporting here @gardinermichael . We have in fact hidden the app package because there were many issues with it and we couldn't manage to get it to be stable . Maybe we should revisit this.
  • 40 410
    40 Topics
    410 Posts
    Package UpdatesP
    [1.39.0] Update uv to 0.12.0
  • 5 66
    5 Topics
    66 Posts
    Package UpdatesP
    [1.7.0] Update beszel to 0.19.0 Full Changelog Potential breaking change: Agents now verify HTTPS certificates. If an agent connects to a hub using a self-signed or otherwise untrusted certificate, configure CA_CERT_FILE with the appropriate CA certificate or the connection will be rejected. Add ZFS pool and dataset monitoring (#2209) Add container health alerts with log excerpts in notifications (#2225) Add alerts for failed systemd services (#2173) Add alerts for CPU I/O wait and steal time (#2249) Add cumulative disk read and write totals to the Disk I/O sheet (#2179) Add Greek and Uzbek translations (#2034) Add custom root disk names and sort disks alphabetically (#2006) Improve alert security by enforcing system ownership and blocking additional internal notification URL ranges Fix a hub crash caused by concurrent SSH client shutdown (#2277)
  • 13 259
    13 Topics
    259 Posts
    Package UpdatesP
    [2.1.4] Update BookStack to 26.05.4 Full Changelog Updated image serving with additional MIME-based content type check. Updated PHP package versions. Updated translations with the latest Crowdin changes. Fixed issue where anchor links would be removed or be made invalid. (#6178) Fixed issue where sftp links would be removed from content. (#6186) Fixed lack of content validation when storing base64 drawing content. Fixed lack of permission check on draft endpoints. Fixed lacking content validation checks on book covers during ZIP imports. Fixed missing update permission check on attachment API. Fixed scenario where joint permission table would not be updated for chapter pages which are in the recycle bin.
  • 1 9
    1 Topics
    9 Posts
    Package UpdatesP
    [1.0.0] Update bugsink to 2.5.1 Full Changelog Some very ancient migration files, long since squashed and replaced, have been removed. In the unlikely event that you are running a pre-1.2.0 release and have not yet run migrations, you will need to upgrade to any release from 1.2.0 to 2.5.0 and run migrations before upgrading to 2.5.1 or later. See #470. Fix: enforce the configured lifetime for email verification, password-reset and new-user setup links. Fix: reject webhook targets with non-global IPv4 addresses embedded in IPv6 destinations. Alerts can now be sent to Telegram, Microsoft Teams and custom webhook endpoints. Telegram supports channels, groups and topics, Microsoft Teams uses Power Automate Workflows, and custom webhooks receive a payload based on the canonical issue API. See #368, #433 and #461. Log-message issues now use the actual message as their title instead of the generic "Log Message" label, including the formatted message when an SDK provides one. See #111 and #364. Stacktrace views now render thread-based stacktraces from message and log events, show multiple threads alongside exceptions, and support the deprecated top-level event stacktrace. See #471 and #482. Accept events that do not specify a platform, see #474. Remove the broken, Python-specific plain-text event view; the Markdown view remains available, see #473. Only accepted team members can join team projects, and send issue alerts only to accepted, active members, see #481. Hide raw exception details from production error responses when MINIMIZE_INFORMATION_EXPOSURE is enabled, see #481.
  • 11 130
    11 Topics
    130 Posts
    Package UpdatesP
    [2.10.3] fix: update doc links from /apps/ to /packages/
  • 56 712
    56 Topics
    712 Posts
    jdaviescoatesJ
    @Mathieu I don't think going to an old version would be wise - very likely to have security flaws (it was AI based attacks which led them to close their code). I've not tried it at all yet (I'm just using the free hosted version of Cal.com as I don't need teams etc), but perhaps see if @ekevu123 could (or already has) add team functions to Tymeslot?
  • 18 90
    18 Topics
    90 Posts
    Package UpdatesP
    [1.3.0] Update calendar to 1.3.0 Booking pages now can have multiple members Refactor the bookin page settings page Timezone fixes for booking events Add new options to present the public booking page Update dependencies
  • 35 334
    35 Topics
    334 Posts
    Package UpdatesP
    [1.41.0] Update calibre to 9.14.0
  • 18 157
    18 Topics
    157 Posts
    jamesJ
    Hello @luckow This is not documented very well. Had to look into the Castopod code to find the URL path to the API. https://github.com/ad-aures/castopod/blob/bc041702dd8058ae8e1831b9609827c911a5a626/modules/Api/Rest/V1/Config/RestApi.php#L35 public string $gateway = 'api/rest/v1/'; So the full URL would be https://castopod.cloudron.dev/api/rest/v1/podcasts curl https://castopod.cloudron.dev/api/rest/v1/podcasts [] After creating one: curl https://castopod.cloudron.dev/api/rest/v1/podcasts [{"id":1,"guid":"2bdee7b8-8131-5888-b4da-713d7b3a124a","actor_id":1,"handle":"demopadcast","title":"Demo Podcast","description_markdown":"DESC","description_html":"<p>DESC</p>\n","cover_id":3,"banner_id":null,"language_code":"en","category_id":1,"parental_advisory":null,"owner_name":"james","owner_email":"james@cloudron.example","is_owner_email_removed_from_feed":true,"publisher":"","type":"episodic","medium":"podcast","copyright":"","episode_description_footer_markdown":null,"episode_description_footer_html":null,"is_blocked":false,"is_completed":false,"is_locked":true,"imported_feed_url":null,"new_feed_url":null,"payment_pointer":null,"location_name":null,"location_geo":null,"location_osm":null,"verify_txt":"","custom_rss":null,"is_published_on_hubs":false,"partner_id":null,"partner_link_url":null,"partner_image_url":null,"is_premium_by_default":false,"created_by":1,"updated_by":1,"published_at":null,"created_at":{"date":"2026-03-03 11:06:44.000000","timezone_type":3,"timezone":"UTC"},"updated_at":{"date":"2026-03-03 11:06:44.000000","timezone_type":3,"timezone":"UTC"},"feed_url":"https://castopod.cloudron.dev/@demopadcast/feed.xml","actor_display_name":"Demo Podcast","cover_url":"https://castopod.cloudron.dev/media/podcasts/demopadcast/cover.jpg","categories":[{"id":1,"parent_id":null,"code":"arts","apple_category":"Arts","google_category":"Arts","translated":"Arts"}]}]
  • 28 Topics
    383 Posts
    Package UpdatesP
    [1.33.0] Update sockpuppetbrowser to a4a9ee3
  • 62 459
    62 Topics
    459 Posts
    Package UpdatesP
    [1.55.1] Update chatwoot to 4.17.1 Full Changelog Restored Instagram login and fixed duplicate Facebook messages. Improved WhatsApp account health and business profile visibility. Improved Captain analytics, reasoning, and conversation context. Reduced SDK size and improved widget contact refreshes. Improved sign-in performance for multi-account users. Fixed automation filters containing commas. Preserved call records when merging contacts. Numerous bug fixes and performance improvements. Thanks to @AdityaAudi, @jaroenchai-t, @williambsm9 for the contributions.
  • 40 Topics
    518 Posts
    Package UpdatesP
    [1.58.0] Update code to 26.04.3.2.1
  • 3 31
    3 Topics
    31 Posts
    Package UpdatesP
    [1.9.0] Update comentario to 3.18.0 Full Changelog Add Sign in with Apple as first-class identity provider (#231, !33, !34) by Tim Oliver - 5f8b319, 6991f31, 304f949, b1529c5, c740ea6, b167450 Add spoiler markdown (>!), with a toolbar button and a dynamic config parameter (#112) - d65d747, f62308e, 03f2736, fefe20a, c94c517 Embed: react to on-the-fly attribute changes on <comentario-comments> (#140) - b640934, f003453, 33ecb73 Implement domain user deletion (#165) - b3e570e, ae13a67 Admin UI: Dashboard: add Top performing domains (#167) - 7f0f05a, c9c4b75 Backend: support secrets from environment (#220) - eaba5ec, a4cf3e5, 8ab3029 Embed: fix comment draft not cleaned up after submission (#223) - 6e21af3 Backend: fix new comment email unsubscribe - e49e90d Backend: swap out gorilla/csrf for http.CrossOriginProtection (CVE-2025-47909) - 8d3d496 I18n: add Polish translation (pl) by @MrBoombastic (!31) - e32f572
  • 12 81
    12 Topics
    81 Posts
    girishG
    @gh0stface yup, they made a release yesterday it seems and it should have the PRs we made upstream. @vladimir-d is checking the package again.
  • 20 127
    20 Topics
    127 Posts
    U
    @girish Yep, exactly that. AnyType and Appflowy are growing in popularity. Would be nice to see them
  • 8 45
    8 Topics
    45 Posts
    nebulonN
    This should be fixed with latest contact app release.
  • 1 Topics
    17 Posts
    Package UpdatesP
    [1.1.0] Update docker-registry to 1.1.0
  • 4 Topics
    25 Posts
    girishG
    @atridad Thanks for the heads up, the app is gone from our library as well.
  • 16 111
    16 Topics
    111 Posts
    B
    Thank you! FWIW, my issue was caused by using ssh to navigate the app's data directory on my server, when I needed to be using the Web Terminal. I added all three of these lines: AppConfig.registeredOnlyTypes = AppConfig.availablePadTypes; AppConfig.disableAnonymousPadCreation = true; AppConfig.disableAnonymousStore = true;
  • 6 97
    6 Topics
    97 Posts
    Package UpdatesP
    [1.30.0] Update ctfreak to 1.40.0 Full Changelog
  • 58 437
    58 Topics
    437 Posts
    nebulonN
    Ah we used to have that but removed it do declutter the UI, I guess we can bring it back
  • 13 128
    13 Topics
    128 Posts
    Package UpdatesP
    [1.19.3] Update dawarich to 1.14.4 Full Changelog Manual OIDC endpoints and signing keys can be configured without changing existing discovery setups. Place tag filters remain applied after returning to the map or reloading it. Statistics include valid segments crossing midnight and older calculations are scheduled for repair. Dawarich can now be used in Simplified Chinese: pick it under Settings General. Thanks @AwHsR15 for the translation! (#3354) TeslaMateApi can now sync completed-drive positions from every configured car into Dawarich, manually or once a day. GET /api/v1/users/me now returns a top-level features object, and GET /api/v1/families/mine answers 200 with lapsed: true when a family membership outlives its entitlement. Stored monthly and daily stats are now rebuilt automatically after a calculation change, so historical distances no longer need a manual Update all stats. Changing your timezone rebuilds them too. (#2069) Traccar latitude/longitude form uploads now save points, including Unix timestamps in seconds or milliseconds. (#3299) Speed coloring in tiled maps now reflects individual route segments when zoomed in, instead of the average speed of the whole track. (#3425) Pages no longer wait for GitHub when checking for a newer version; update checks now run only in the background and ignore stale releases cached before an upgrade (#3485)
  • 65 648
    65 Topics
    648 Posts
    Package UpdatesP
    [3.3.2] Update directus to 12.3.1 Full Changelog Added countFilterListeners, countActionListeners, and countInitListeners methods to the emitter, exposing the number of registered handlers for each event (#28117 by @ComfortablyCoding) Fixed MCP OAuth clients settings pages concatenating breadcrumbs into the page title (#28115 by @MHJahanbakhsh) Fixed the WebSocket heartbeat leaking a websocket.message listener on each ping when a client failed to respond in time (#28117 by @ComfortablyCoding) Fixed GraphQL query fragments returning null fields (#28128 by @ComfortablyCoding) Fixed public registration verification using the provided email instead of the stored one (#28144 by @br41nslug) Removed user_created and date_created for update from recommended permissions for directus_shares (#28145 by @br41nslug) Updated storage driver dependencies (#28119 by @ComfortablyCoding) Stripped project_id when pulling settings, so a sync no longer copies one instance's identity onto another (#28132 by @lazerg) Fixed unsubscribe() not removing subscriptions, causing them to persist across reconnects and accumulate for the lifetime of the client (#28117 by @ComfortablyCoding)
  • 91 782
    91 Topics
    782 Posts
    Package UpdatesP
    [2.17.0] Update discourse to 2026.8.0 Full Changelog
  • 24 Topics
    266 Posts
    Package UpdatesP
    [2.7.2] Add timestamp argumens to registry-client script
  • 5 46
    5 Topics
    46 Posts
    Package UpdatesP
    [1.4.0] Update docmost to 0.96.0 Full Changelog feat: collab hocuspocus v4 upgrade by @Philipinho in #2351 fix: toolbar flicker on navigation by @Philipinho in #2352 fix: increase s3 client max socket limit by @Philipinho in #2355 feat: footnotes by @Philipinho in #2384 feat: compare two page versions by @Philipinho in #2385 feat: page attachments endpoint and modal by @Philipinho in #2386 feat(editor): auto-detect text direction for RTL support by @Philipinho in #2389 fix: handle empty password, missing port, and TLS in Redis URL parsing by @michidk in #2021 feat: enhanced search filters by @salihudickson in #2398 feat: jump to search by @salihudickson in #2453
  • 13 122
    13 Topics
    122 Posts
    Package UpdatesP
    [1.28.0] Update sockpuppetbrowser to a4a9ee3
  • 12 63
    12 Topics
    63 Posts
    Package UpdatesP
    [1.12.0] Update community to 5.14.0 Full Changelog Added Spanish language support
  • 17 275
    17 Topics
    275 Posts
    Package UpdatesP
    [1.18.4] Update docuseal to 3.2.4 Full Changelog It's now possible to set message subject without body via API Bug fixes, performance improvements, and security hardening Field detection and undo/redo now works with embedded builder autosave=false
  • 17 136
    17 Topics
    136 Posts
    Package UpdatesP
    [1.30.0] Update dokuwiki to 2026-07-14c Full Changelog
  • 41 359
    41 Topics
    359 Posts
    Package UpdatesP
    [1.15.1] Update dolibarr to 24.0.1 Full Changelog FIX: $arrayfields used before definition in don/list.php FIX: #38963 enforce website write right on legacy filemanager (v18) (#39731) FIX: #39053 + compatibility with multicompany (#39648) prevent non-admin users deleting admin accounts (backport MR #39119) FIX: #39396 Reject enclosing leave requests (#39798) FIX: #39658 shorten accounting template FK name (#39688) FIX: #39690 Division by zero in turnover collected report (#39706) FIX: #39733 Map variant attribute elements (#39755) FIX: #39756 Use configured printer for template test (#39900) FIX: #39763 Default for product is "no template/doc" generated. FIX: Mo::processBOM() ignores qty value for qty_frozen BOM lines (#39941)
  • 13 Topics
    89 Posts
    Package UpdatesP
    [1.8.0] Update easyappointments to 1.6.0 Full Changelog Added request method check on each request so that only allowed methods are accepted Add Jitsi integration and link generation for appointments made via the public page ALTCHA integration added as an alternative CAPTCHA step (#1155) When someone clicks on password reset, implement a link delivery and not just change the password directly Implementation of additional GDPR features in Easy!Appointments (#535) Add CAPTCHA support for all the public forms in order to block abusive requests (#1754) Replace the availabilities type with the new slot interval field Fixed a security issue where an administrator could inject scripts into the "booking disabled" message that would then run for every visitor of the public booking page Fixed a security issue where a provider could create or modify appointments under another provider's account Webhooks are now triggered only for the exact actions they are subscribed to, instead of matching similarly named actions by substring
  • 12 100
    12 Topics
    100 Posts
    Package UpdatesP
    [1.19.0] Update Emby.Releases to 4.10.0.40 Full Changelog Fix cases where transcoding processes that complete very quickly are treated as an error Fix startup wizard regression Fix playback failures with dvd and bluray folders containing a dot in the folder name Fix regression related to adding a library with an SMB path fix regression causing episodes without season folders to not display Add new home screen section type called dynamic media with sorting and filtering functions Fix Hardware Transcoding for HDR Video when Tone Mapping is enabled Fix regression with hiding users from login screens on remote connections Revamp home screen section options with new section editor Add subtitles to stats for nerds
  • 52 519
    52 Topics
    519 Posts
    Package UpdatesP
    [3.0.8] Update espocrm to 10.0.8 Full Changelog Phone number search without country code #3781
  • 31 287
    31 Topics
    287 Posts
    Package UpdatesP
    [4.10.3] Update etherpad-lite to 3.3.3 Full Changelog Prevent pre-auth path traversal / arbitrary file read in /static/* (GHSA-mc8w-wjhw-45x5, #8081). Stop shipping a hardcoded OIDC cookie key and reflecting arbitrary CORS origins (GHSA-pp5v-mvwg-76mp, #8070, #8071, #8072). Regenerate the session id on authentication (GHSA-73h9-c5xp-gfg4, #8074). Apply queued USER_CHANGES to the enqueue-time pad (GHSA-6mcx-x5h6-rpw2, #8075). Reject the ueberdb key delimiter : in copyPad/movePad destination ids (GHSA-wg58-mhwv-35pq, #8073). Migrate the server build to TypeScript 7 / tsgo (#8039). Editor PageDown/PageUp now advance across consecutive long wrapped lines (#7555). Docker make the plugin_packages volume mountpoint writable (#8042).
  • 1 Topics
    2 Posts
    Package UpdatesP
    [1.0.1] Update DocumentServer to 9.3.4 Full Changelog
  • 2 125
    2 Topics
    125 Posts
    Package UpdatesP
    [1.31.0] Update evcc to 0.315.0 Full Changelog Curtailment devices: new device class for feed-in limitation (BC) (#32416) Mqtt: always render preset timeout (BC) (#33084) Add SENEC.Connect cloud API (#33029) Marstek: add discharge and optimise batterymode (#32571) UI: Add date format preference in user interface settings (#29321) koda: add Mykoda public api vehicle (#33234) Cardata: fix retrying failed container setup (#33243) Fix site.pvPower estimation for battery without pv (#32930) UI: fix blurred energy flow bar labels in Safari (#33144) Zaptec: fix nil pointer panic when Capabilities observation is missing (#33304)
  • 7 44
    7 Topics
    44 Posts
    J
    I guess it's a bit late now since 3.0.0 is already out but thanks for the write up.
  • 5 36
    5 Topics
    36 Posts
    robiR
    Yes please, who is doing the community app?
  • 2 Topics
    15 Posts
    Package UpdatesP
    [1.3.0] Update fmd-server to 0.16.0 Full Changelog Ability to listen on a specific IP address, instead of 0.0.0.0 (#153) Collapsible groups in web UI sidebar (!235) New languages: cs, hu, it, pt. Thank you translators! Bug fixes
  • 23 276
    23 Topics
    276 Posts
    Package UpdatesP
    [3.12.4] Update firefly-iii to 6.6.6 Full Changelog Issue 12426 (Important: The latest version removed all references to foreign currency in income) reported by @jgmm81
  • 6 127
    6 Topics
    127 Posts
    Package UpdatesP
    [2.12.1] Update formbricks to 5.4.2 Full Changelog fix: keep Redis connections alive (backport #9124 to release/5.4) by @BhagyaAmarasinghe in #9127 fix: fall back to database for Redis session errors (backport #9125 to release/5.4) by @BhagyaAmarasinghe in #9126 fix: support Redis 6 verification token consumption (backport #9129) by @BhagyaAmarasinghe in #9130 fix: make CSAT and CES scale labels translatable (backport #9136 to release/5.4) by @Dhruwang in #9142
  • 6 34
    6 Topics
    34 Posts
    Package UpdatesP
    [1.3.4] Update forgejo to 16.0.4 Full Changelog
  • 76 843
    76 Topics
    843 Posts
    Package UpdatesP
    [1.16.31] Update freescout to 1.8.239 Full Changelog Removed black outline when clicking on links in Chrome. Disabled support of legacy attachment URLs with MD5 tokens (GHSA-89ww-mfww-5vr6) Fixed linking messages into conversations in Outlook (#4922) Take into account IPv6 transition addresses in Helper::sanitizeRemoteUrl() (GHSA-v5xm-qw3f-qm98) Fixed preserving CSS custom properties during minification (#5611) Fixed emails sometimes being sent as raw MIME source when sending via mail() function (#5615)
  • 21 159
    21 Topics
    159 Posts
    necrevistonnezrN
    https://github.com/FreshRSS/FreshRSS/releases/tag/1.30.0 Just FYI: This is a security-oriented major release with several important security patches, so users are encouraged to update without delay. From this release, we are also making it clear that our rolling-release channel (edge) is recommended for faster security patches.
  • 2 17
    2 Topics
    17 Posts
    Package UpdatesP
    [1.1.1] Update funkwhale to 2.0.10 Full Changelog
  • 83 1k
    83 Topics
    1k Posts
    Package UpdatesP
    [4.195.0] Update ghost to 6.63.0 Full Changelog Added Node 24 to the supported engines range (#30466) - Austin Burdine Improved focus when adding a filter (#30394) - Zach Fixed Portal reporting a refused plan change as a successful one - Rob Lester Fixed tag results in admin search not opening the tag (#30518) - Steve Larson Fixed LinkedIn company and school URLs with underscores being rejected as invalid (#30490) - louisghost Fixed saving account preferences failing for some members - Rob Lester
  • 51 455
    51 Topics
    455 Posts
    Package UpdatesP
    [1.40.2] Update gitea to 1.27.3 Full Changelog fix(packages): restrict/limited/token-scope access (#39041, #39043, #39044, #39047, #39046) (#39058) fix(actions): enforce fork pull request trust boundaries (#39005) (#39018) fix(git): restrict hook permissions (#39008) (#39016) fix: avoid enumerating every public repository in issue search (#38992) (#39000) enhance: add permalinks to pull request reviews (#38849) (#39036) fix(actions): keep step-level continue-on-error expressions unevaluated (#39141) (#39148) fix(pull): keep the merged state in sync with git (#39062) (#39118) fix: resolve YAML anchors and aliases in Actions workflows (#38984) (#38996) fix(indexer): correct bleve indexer token filters (#38853) (#38951) fix(ui): respect FEED_PAGING_NUM on the dashboard feed (#38935) (#38936)
  • 21 151
    21 Topics
    151 Posts
    nebulonN
    Not sure I fully understand the target setup you intend to have. But to enable CORS on the github pages app is only really useful if some code running in another domain would call the REST API of the github pages app, which I am not sure it even has. But I might be misunderstanding here. If CORS is indeed needed, then the app coder (github pages) would need to support responding those pre-flight OPTIONS check queries by the browser.
  • 65 677
    65 Topics
    677 Posts
    Package UpdatesP
    [1.119.1] Update gitlab-foss to 19.3.1 Full Changelog Provision inherited foundational flows without user elevation (commit) Gate tracked ref filter on advanced vulnerability management (commit) Fix Compliance Framework Cross-Namespace Assignment on self-managed instances (commit) (merge request) Reject overflow username length in SCIM and OAuth sign-in (commit) (merge request) Prevent Sidekiq exhaustion via unbounded import jobs (commit) (merge request) Ignore Claude project settings in Claude agent (commit) (merge request) Check :update_approvers before resetting MR approval rules (commit) (merge request) Prevent policy job needs from resolving to untrusted jobs (commit) (merge request) Enforce protected environment check on terminal websocket auth (commit) (merge request)
  • 2 13
    2 Topics
    13 Posts
    Package UpdatesP
    [1.1.5] Update glpi to 11.0.8 Full Changelog
  • 7 61
    7 Topics
    61 Posts
    Package UpdatesP
    [1.24.0] Update base | final to 5.1.0
  • 22 258
    22 Topics
    258 Posts
    Package UpdatesP
    [2.8.1] Update grafana to 13.2.1 Full Changelog Security: Fix CVE-2026-12704 Security: Fix CVE-2026-14199 Dashboards: Fix adhoc and groupby variable datasource on UI import #131819, @grafana-writer[bot] Packaging: Fix issue with bundled plugins not being moved properly #131037, @grafana-writer[bot] PanelEditor: Fix options pane not resizable beyond the preview's content width #131608, @grafana-writer[bot]
  • 15 188
    15 Topics
    188 Posts
    Package UpdatesP
    [2.0.2] Update grav to 2.0.26 Full Changelog Plain text that happens to contain a word ending in data, feed or another URI scheme name no longer blocks a page from saving with "Potential XSS issues detected". The check matched the scheme anywhere inside a word, so a Hungarian sentence ending in "mondata:" or an English one mentioning "metadata:" was read as a data: URI. Thanks to @csbrny #619 A new pages.media_route_urls setting in system.yaml, off by default, links a page's media by its page route instead of its path on disk, so plugins can apply the page's access rules to media requests. Resized images keep serving from the image cache Every web server config now carries a commented rule for denying direct access to user/pages, which only becomes safe to enable once pages.media_route_urls is on Now depends on a released rockettheme/toolbox 2.0 rather than tracking its development branch, so a build always resolves to the same code An operator who manages users can no longer give themselves full admin rights. Permission fields that only a super admin may write were guarded by name, and writing the same field under its flattened name slipped past that guard. Thanks to @movon-ava Twig in page content can no longer read the site's configuration through the array filter. The |array cast was the one conversion that never asked the sandbox whether it was allowed, so it could turn Grav's internal service registry into a plain list and read the settings the sandbox exists to keep out of page content, including plugin passwords and API keys. Thanks to @1diot9 and @AlpetGexha A page can no longer capture the session of an administrator who views it. Page content could read the visitor's cookies, and the finished page was stored in a cache shared by everyone, so an administrator's session could be handed to the next visitor. Cookie reading is no longer available to page content, and pages that run editor-written code are no longer cached after that code runs. Thanks to @canhieu The bundled IIS and lighttpd configs now block sensitive files whatever the capitalisation of the request. Only the Apache and PHP rules were corrected when this was last fixed. Anyone serving Grav with the bundled web.config or lighttpd.conf should re-copy the sample, as the updater only heals .htaccess. Thanks to @movon-ava onShutdown now fires after a request that ended through close() or redirect(), not only after a rendered page. Those requests echoed their response and exited before the shutdown handler was registered, so a plugin doing slow work after the response (sending queued mail, warming a cache) never ran on a form submit that redirected. The non-FastCGI fallback also stops trying to set headers once they have been sent A page dated with an unquoted date: 2022-01-06 header no longer lands in the year 7200. The YAML parser reads an unquoted date as a date and hands over a timestamp rather than a string, which the date parsing then misread. Thanks to @wakqasahmed #3812
  • 19 167
    19 Topics
    167 Posts
    Package UpdatesP
    [1.11.3] Update greenlight to 3.8.2.4 Full Changelog Multiple gem updates Language Updates
  • 9 56
    9 Topics
    56 Posts
    Package UpdatesP
    [1.2.7] Update grist-core to 1.7.19 Full Changelog The calendar is now a widget type of its own rather than a custom widget bundled with Grist, and existing calendar pages move to it automatically. Only the events in view are drawn, so editing one cell no longer redraws them all. Double-clicking an event opens the Grist record card, as does dragging on empty space to create one, and Day and Week views cap at 20 events per day with a "+N more" label. GRIST_SKIP_BUNDLED_WIDGETS no longer does anything (#2457) The formula editor now completes the looked-up table's column names inside lookupOne() and lookupRecords(). After a comma it offers the columns not yet used, plus order_by (#2530) A confirmation for an action that cannot be undone now defaults to canceling. Cancel is highlighted and answers Enter, and the action button is red (commit) The "Invite people" dialog now says when invitation emails are not enabled on the installation. Install admins get a link to turn them on, and everyone else a button to ask an admin (#2482) POST /api/users/:userId/disable now accepts a reason, shown to the user when they try to sign in. Contributed by @fflorent (#2526) The details of a formula error were unreadable in dark mode, light text on a light background. Contributed by @Federicorao (#2394) Grist reported a meaningless exit code when shut down by a signal, showing up as a failed unit under systemd. Contributed by @Mrmaxmeier (#2555) With GRIST_PERSONAL_ORGS=false, a user who belongs to no team site was sent to a welcome page that listed no sites and offered nothing to do. It now says there are no sites available, with a button for install admins to create the first team site. Signed-out visitors get a sign-in prompt (commit) When the full edition is turned on by environment variable, the Admin Panel stopped showing the activation key section, leaving no way to enter or change a key (commit) A table or column named after a built-in JavaScript property, such as constructor, was not recorded correctly in document history and comparisons (commit)
  • 55 318
    55 Topics
    318 Posts
    jamesJ
    Hello @albertbeaufrand and welcome to the Cloudron Forum This topic is a duplication of https://forum.cloudron.io/post/97415 and will be merged into it. Please read the responses above to get the full answer to your question.
  • 4 23
    4 Topics
    23 Posts
    girishG
    App discontinued due to no upstream updates.
  • 18 147
    18 Topics
    147 Posts
    Package UpdatesP
    [1.23.0] Update hedgedoc to 1.12.0 Full Changelog HedgeDoc 1.12.0 and onwards will require Node 20.17 or later in order to run. Some syntax highlighting languages have been removed and/or changed. You can find more information in the highlight.js docs. Automatically skip the login modal if no form-based login and exactly one external login provider is configured All links will be opened in new tabs instead of the same tab as the note. This was changed when the external link warning was implemented and now the old behavior is restored Fixed multiple bugs in the realtime connection handling that could lead to data-loss of users with a flaky connection
  • 12 Topics
    164 Posts
    Package UpdatesP
    [1.23.1] Update core to 2026.9.1 Full Changelog Fix SMTP attaching valid images as files when content sniffing fails (@Chang-Jin-Lee - #176774) Fix receive backup streaming (@MartinHjelmare - #181012) Fix potential deadlock in receive_file backup util (@emontnemery - #181070) Add missing state_class for miele filling level sensors (@astrandb - #181093) Stop rounding Amber Electric prices to 2 decimal places (@romeovan - #181157) Fix host override ignored in UniFi Protect public-only mode (@RaHehl - #181176) Purge unreachable deleted devices on device registry load (@emontnemery - #181207) Fix Besen config flow schema serialization (@moryoav - #181223) Allow empty motionEye usernames (@frenck - #181270) Handle Tradfri devices without a firmware version (@frenck - #181276)
  • 27 253
    27 Topics
    253 Posts
    Package UpdatesP
    [1.9.5] Update humhub to 1.18.5 Full Changelog Fix #8340: Defer module update opcache_reset() to the end of the request to avoid interrupting the update in worker runtimes (e.g. FrankenPHP) Fix #8357: Cast app name to string (This fixes the issue of instances with names consisting of numbers not being able to be added to the mobile app) Enh #8346: Force Select2 dropdowns to always open below the field instead of flipping above when there's not enough space Fix #8359: Display user sub name on invite after space creating Fix #8361: Prevent non-creators from attaching or deleting another user's unassigned file Fix #8365: Encode deletion reason in comment and content deletion notifications Fix #8374: Ensure adding group members is restricted to groups the current user manages Fix #8373: Ensure the oEmbed consent prompt encodes the requested URL so embedded markup stays inert Fix #8381: Limit request supplied membership and friendship button options to presentation values, so titles, urls and action attributes stay server generated, and encode the membership button markup in the membership request response so it cannot break out of the script context Fix #8376: Ensure space member role changes are limited to assignable roles
  • 76 711
    76 Topics
    711 Posts
    Package UpdatesP
    [1.101.0] Update immich to 3.1.0 Full Changelog feat(cli): Add --visibility flag to immich CLI upload subcommand by @yuxincs in #29614 feat(mobile): custom date range for map by @YarosMallorca in #26205 feat(web): Keep show more open on duplicates by @MontejoJorge in #29734 fix(server/workflow): add trigger for external libraries AssetCreate by @cratoo in #29597 feat(web): add wake lock when uploading assets by @diogotcorreia in #29820 feat(web): undo archive from toast by @YarosMallorca in #27061 feat: workflow filter assets by upload path by @benbeckford in #30000 feat(web): add maintenance link to command palette by @yamishi13 in #30016 fix: re-evaluate OIDC role claim on every login and support array values by @ImperatorRuscal in #29991 feat: password invalidate sessions by @jrasm91 in #30125
  • 6 Topics
    47 Posts
    Package UpdatesP
    [1.3.1] Update ip2location to 1.4.0 Fix width and height of the map
  • 5 70
    5 Topics
    70 Posts
    Package UpdatesP
    [1.11.0] Update it-tools to 2026.7.11 Full Changelog mobile UX overhaul, theme flash prevention and build cleanup (#474) (239c69e) Base64 String Converter: handle text encoding other than utf8 (7460423) new tool: Keyboard Tester (dfa836b) new tool: Cron Expression Generator (b016d34) new tool: DNS/RDAP queries (37cc92f) new tool: CSS/JS Prettify & Minify (45ed4a7) Fitness Computer: Change arguments order to fix wrong BMI calculation (#407) (eaea6e9) Data Storage Units Converter: fix b/iB/B conversion (102bb99) Speed Converter: wrong m/h is in fact mi/h (miles) (dfb92f2) overhaul startup performance, dependencies and UI responsiveness (#419) (bad27cf)
  • 4 26
    4 Topics
    26 Posts
    Package UpdatesP
    [0.8.5] Update infisical to v0.165.9 Full Changelog fix(dynamic-secrets): add missing provider logos by @andrewhuhh in #8032 improvement(security): derive cookie signing key from KMS root key by @victorvhs017 in #8029 feat(secret-sync): detect duplicate Daytona syncs by organization by @lobocv in #7994 fix(github-org-sync): safely sync teams for large orgs by @scott-ray-wilson in #7998 fix(secrets-access-requests): auto open review sheet when request ID present by @varonix0 in #8041 feat(ui): add global command menu by @andrewhuhh in #7877 feat: add pki license gating by @sheensantoscapadngan in #7939 feat: introduce INFISICAL_RUN_MODES by @mathnogueira in #8031 fix: allow read operations in cross project secret sharing by @mathnogueira in #7966 fix(pki): set intermediate CA parentCaId to null instead of cascading on parent delete by @carlosmonastyrski in #8063
  • 18 196
    18 Topics
    196 Posts
    Package UpdatesP
    [1.12.8] Update invidous and companion
  • 71 Topics
    1k Posts
    Package UpdatesP
    [1.22.31] Update invoiceninja to 5.13.37 Full Changelog Fixes for Forte service fee. Updates for client portal client switcher * autosizing + scrollbar Fixes for vendor upload validation Fixes for contact password reset validation Set expiry for password reset tokens Updated logic for refund form request Fixes for tax summary report Updates for login permissions / token filtering Fixes for payment dates on client portal list Add Daily Task Digest notification
  • 43 346
    43 Topics
    346 Posts
    Package UpdatesP
    [1.13.8] Update jellyfin to 10.11.11 Full Changelog Add lockhelper for UserManager MR #16944, by @JPVenson
  • 4 18
    4 Topics
    18 Posts
    girishG
    App discontinued due to no upstream updates.
  • 13 107
    13 Topics
    107 Posts
    Package UpdatesP
    [1.12.3] Update Jirafeau to 4.7.2 Full Changelog Added a button for showing the download password before uploading the file Favicon was missing in the modern theme Download passwords are now stored as SHA256 hashes Downloading encrypted files uploaded using "classic upload" (using just plain HTTP POST without the HTML5 file API) could not be downloaded. This was caused by not correctly marking the files as encrypted. Few more little fixes
  • 34 375
    34 Topics
    375 Posts
    jamesJ
    Hello @stoccafisso Not by default, no. You could build the jitsi app yourself and install it or maybe someone will make it a community app.
  • 12 117
    12 Topics
    117 Posts
    Package UpdatesP
    [2.6.1] Update joplin to 3.7.2 Full Changelog The Release Notes section contains no breaking changes, features, or bug fixes it is empty (only a compare link is present with no changelog entries).
  • 12 148
    12 Topics
    148 Posts
    Package UpdatesP
    [1.63.0] Update jupyterhub to 6.0.0 Full Changelog
  • 8 75
    8 Topics
    75 Posts
    Package UpdatesP
    [1.17.10] Update kanboard to 1.2.54 Full Changelog fix(user): invalidate existing sessions when the password changes fix(project): check permissions in the project creation handler fix(file): check the project of the task when fetching a task file fix(api): check task and project binding in setTaskTags fix(csv): escape exported values starting with a special character fix(api): return only public user columns fix(subtask): reject assignees outside of the project fix(notification): scope unread notification lookup to its owner fix: scope custom filter changes to their project and owner fix: validate request tokens for tag, board, and comment actions
  • 8 58
    8 Topics
    58 Posts
    Package UpdatesP
    [1.14.0] Update Kavita to 0.9.1.4 Full Changelog Added: (Kavita+) Added support for loading recommendations from Hardcover. These will be the books linked to the first book in the series. Added: (Kavita+) Added Hardcover OAuth support (PAT tokens will still work) Added: Added support for Mangabaka's new URL structure (released 8/31/2026) Changed: Opening a completed chapter while reading places you on the first page, but your reading progress won't reset unless you page forward. Fixed: (Kavita+) Fixes chapter cover images sometimes being removed when Kavita+ writes a volume image Fixed: Fixed black & white lists not being available for non Kavita+ users Fixed: Fixed series age rating not being derived from tags on first scan and from updated tags in consecutive scans Fixed: Fixed settings not saving for some users Fixed: Fixed chapters with one page not saving progress while paging (Thanks @333fred) Fixed: Fixed a bug where users couldn't update reading profile from the reader due to Breakpoint enum values changing when we streamlined the breakpoint service in v0.9.1.
  • 8 111
    8 Topics
    111 Posts
    Package UpdatesP
    [1.7.3] Update keycloak to 26.7.3 Full Changelog #50785 CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname ldap #50997 [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers oidc #51003 [CVE-2026-16089] Authorization codes can be retargeted to another client session oidc #51745 [CVE-2026-19729] Incomplete fix for CVE-2026-9083 relative path traversal still enables filesystem probing in 26.6.4 core #50825 Creating an organization without a domain leads to an error organizations #50963 V1 token-exchange strips the DPoP sender-constraint from a bound access token token-exchange #51510 SQLGrammarException: The incoming request has too many parameters core #51523 Sustained high CPU on all nodes after upgrade admin/api #51554 Admin API per-request cost grows super-linearly with realm count since 26.7.1 admin/api #51589 NPE in RoleUtils.expandCompositeRoles when a cached client scope references a deleted role core
  • 5 36
    5 Topics
    36 Posts
    girishG
    The new update should fix the problem.
  • 16 260
    16 Topics
    260 Posts
    Package UpdatesP
    [2.58.0] Update kimai to 2.66.0 Full Changelog Added a lock date to active projects to limit timesheet editing for past periods - read docs (#6103) Activity listing now allows to use "create timesheet" for users with create_own_timesheet only (#6151) Improve documentation link with higher contrast and page title (#6129) Adds budget, timeBudget and budgetType to customer, project and activity collection endpoints (#6140) New API endpoint to delete invoices (#6141) Timesheet API improvements (#6139) New "favorites" endpoints (#6143) Fix weekly invoice grouping merging the same week from different years (#6134) Two-factor (2FA) form was not visible with SAML and deactivated login form (#6136) This release contains several security fixes, you are advised to upgrade your system ASAP.
  • 16 231
    16 Topics
    231 Posts
    Package UpdatesP
    [1.46.2] fix job scheduling, dead vars, and lib watcher
  • 11 132
    11 Topics
    132 Posts
    girishG
    Running TURN server on port 443 only matters for setups where a Client is unable to contact the server on non-port 443. This is only common in some ultra locked down intranet setups.
  • 5 65
    5 Topics
    65 Posts
    Package UpdatesP
    [1.8.1] Update komga to 1.26.3 Full Changelog translated using Weblate (Korean) (ad7caf6) use BCP tags for translation files (0ccf132) translated using Weblate (Japanese) (80393c1) translated using Weblate (German) (a9c6f17)
  • 24 188
    24 Topics
    188 Posts
    I
    Thanks so much @girish! That did the trick.
  • 144 1k
    144 Topics
    1k Posts
    Package UpdatesP
    [5.2.5] Update php-src to 8.5.10
  • 18 191
    18 Topics
    191 Posts
    Package UpdatesP
    [1.61.0] Update languagetool to 5dcf9d2
  • 23 240
    23 Topics
    240 Posts
    Package UpdatesP
    [1.14.6] Update leantime to 3.9.8 Full Changelog Milestones - Fixed reports showing 0% completion and the timeline "Show Tasks" view displaying nothing (#3624, #3625, #3628) Milestone Modal - Resolved focus loss, restored save-and-close, and fixed a 500 error when saving goals (#3605) To-Dos - Kept To-Dos from closed projects browsable once the project is reopened (#3626, #3627) Post-3.9.7 Regressions - Fixed a file browser out-of-memory issue, strategy grouping, and 403 errors for legacy roles (#3621) MCP Endpoint - The /mcp endpoint now accepts Leantime API keys, and a shim for the removed php-mcp provider lets in-place upgrades boot (#3601, #3602, #3607) Program Board - Moved the card status dropdown below the field row (#3599) Sessions - Isolated sessions into their own Redis database to avoid clashes with other cached data (#3604) Bumped the McpServer submodule to include the bulkAddTasks fix (#3620, #3622) Synced composer.lock content hash with composer.json (#3603)
  • 19 164
    19 Topics
    164 Posts
    necrevistonnezrN
    The right combination: DON'T LOGIN WITH CLOUDRON the first time, instead create a user the "classic way" via mail & password --> This is the admin. After validation and setting up MFA, logout. Now log in via Cloudron, then you are the "normal user". If you want to block every login except via Cloudron, set up the env as follows (took me some trial & error): ALLOW_EMAIL_LOGIN=false ALLOW_REGISTRATION=false ALLOW_SOCIAL_LOGIN=true ALLOW_SOCIAL_REGISTRATION=false ALLOW_PASSWORD_RESET=false # ALLOW_ACCOUNT_DELETION=true # note: enabled by default if omitted/commented out ALLOW_UNVERIFIED_EMAIL_LOGIN=false Note: "SOCIAL_LOGIN" means Cloudron LDAP. If new Cloudron User should be allowed, set ALLOW_SOCIAL_REGISTRATION to true
  • 18 430
    18 Topics
    430 Posts
    Package UpdatesP
    [1.59.10] Update LimeSurvey to 7.0.14+260904
  • 16 138
    16 Topics
    138 Posts
    Package UpdatesP
    [1.27.2] Update linkding to 1.46.2 Full Changelog Render tag hash character with CSS so it can be hidden by @sissbruecker in #1447 Fix tag management not correctly linking to bookmarks page by @sissbruecker in #1452
  • 15 177
    15 Topics
    177 Posts
    Package UpdatesP
    [1.23.3] Update linkwarden to 2.16.3 Full Changelog Significantly improved the performance of link, search, tag, collection, and dashboard queries at scale.
  • 31 233
    31 Topics
    233 Posts
    Package UpdatesP
    [1.17.0] Update listmonk to 6.2.0 Full Changelog feat(i18n): add Arabic (ar) translation by @imohad in #2977 Fixs #2987 - Prevent confirmed subscriber becoming unconfirmed when re-subscribing. by @blu3id in #2996 fix(analytics): correct per-campaign unique view counting by @wucm667 in #3024 fix: prevent nil pointer crash in BounceWebhook when bounce processing disabled by @Koushik-1729 in #2993 Add per-domain SMTP routing by @jaymzh in #2953 Fix: ZIP Slip path traversal in CSV import by @Yunkaiwjs in #3065 fix: protect SES cert cache map with sync.RWMutex to prevent concurrent map writes crash by @Abzaek in #3050 Add Azure ACS bounce webhooks and settings support by @oskari in #3001 Add support for embedding images (inline attachments) via CID in campaign bodies by @knadh in #3034 Fix api tokens hashing by @knadh in #3114
  • 8 145
    8 Topics
    145 Posts
    Package UpdatesP
    [1.23.0] Update loomio to 3.6.0 Full Changelog Fix: Escape user-controlled notification values in email, Matrix, Slack, and Markdown chatbot output Fix: Reject unsafe URL schemes produced by server-rendered Markdown Fix: Limit stored reaction values while retaining complex Unicode emoji sequences Fix: Keep web push available without promoting app installation or reload prompts New: Create a complete Oatmilk Cooperative demo workspace when demo groups are enabled New: Show recent visible activity on user profiles Fix: Stop discarded groups pending permanent deletion from accepting activity or delivering pending notifications Fix: Make group deletion, account merging, and legacy-data cleanup safer and more recoverable Fix: Support Safari 16 in current client builds There are no intended breaking B2 or B3 API changes. Operators with custom database maintenance or reporting that refers directly to removed legacy tables or the old groups.archived_at column must update it before deployment.
  • 19 234
    19 Topics
    234 Posts
    Package UpdatesP
    [2.47.2] Update Lychee to 7.8.3 Full Changelog Avoid naughty pdf uploaders by @ildyria in #4687 Trivy ignore CVE-2026-56854 by @ildyria in #4701 Fix replay upload in the same chunk by @ildyria in #4696 Avoid email oracle on registration by @ildyria in #4698 Prevent editing pictures if they are not validated yet by @ildyria in #4700 Version 7.8.3 by @ildyria in #4703 Full Changelog: https://github.com/LycheeOrg/Lychee/compare/v7.8.2...v7.8.3
  • 16 51
    16 Topics
    51 Posts
    d19dotcaD
    @nebulon It isn’t even so much complicated filters as it is dozens of filters. If I were to move my clients to the new webmail client for example today, they’d have no ability to edit their existing filters at all because it doesn’t expose the sieve filters in the UI like Roundcube does. As an example, one of my clients is a doctors office and they have roughly 30-50 folders (for different doctors, test types, digital faxes, etc), and there are almost just as many filters, because much of it is automated for them. There’s just no way I can have them use the new webmail app right now because they have no way to make changes to their existing filters if they needed to. I hope that helps paint the picture a bit better.
  • 10 61
    10 Topics
    61 Posts
    marcusquinnM
    @girish That is a super handy feature!
  • 149 1k
    149 Topics
    1k Posts
    Package UpdatesP
    [1.19.1] Update mastodon to 4.7.1 Full Changelog
  • 53 446
    53 Topics
    446 Posts
    Package UpdatesP
    [1.60.0] Update matomo to 5.13.0 Full Changelog
  • 133 Topics
    1k Posts
    Package UpdatesP
    [1.142.0] Update synapse to 1.160.0 Full Changelog
  • 60 656
    60 Topics
    656 Posts
    Package UpdatesP
    [1.31.1] Update mattermost to 11.10.1 Full Changelog Mattermost Platform Release 11.10.1 contains various bug fixes.
  • 66 516
    66 Topics
    516 Posts
    Package UpdatesP
    [6.2.0] Update mautic to 7.2.0 Full Changelog Add truly transactional emails by @escopecz in #15995 Add A/B testing for segment emails by @kuzmany in #15897 Split mtc.js into essential and tracking scripts by @patrykgruszka in #16660 Add dedicated permissions for contact notes and migrate existing roles by @shinde-rahul in #16067 Restore VERP bounce routing broken by the Sender header in 7.1 by @EnableServices in #16152 Fix inconsistent URL filter matching across campaign decisions and points by @shinde-rahul in #15979 Prevent deleting a segment that a campaign still uses by @escopecz in #16013 Add point insights by @JonasLudwig1998 in #15359 Find and replace contact and company field values in bulk by @andersonjeccel in #16207 Invite users by email by @andersonjeccel in #15401
  • 9 113
    9 Topics
    113 Posts
    Package UpdatesP
    [1.48.0] Update mealie to 3.25.0 Full Changelog feat: add token refresh, fix remember me, and fix Safari token expiration @michael-genson (#8200) feat: organizer improvements recipeCount, merge endpoint, delete unused UI @bferd (#7829) feat: add rating as a query filter field @dominikrein (#7966) feat: click-to-expand lightbox for recipe hero image and asset images @bferd (#7933) feat: Meal Planner UI Improvements @miah120 (#7946) fix: fallback to regular HTML if video download fails @michael-genson (#8203) fix: allow deleting a user who both rated and favorited a recipe (#8121) @chiliec (#8131) fix: Account for on hand items when adding a recipe to a shopping list @miah120 (#7912) fix: repoint shopping list items when merging a food or unit @henry1113nz (#8146) fix: resize images before AI import to avoid provider size limits @chiliec (#8241)
  • 9 95
    9 Topics
    95 Posts
    Package UpdatesP
    [3.7.0] Update mediawiki to 1.46.0 Full Changelog
  • 14 104
    14 Topics
    104 Posts
    Package UpdatesP
    [1.25.1] Update meemo to 1.25.1 Fix OpenID login bug Update dependencies
  • 6 50
    6 Topics
    50 Posts
    Package UpdatesP
    [2.2.0] Update memos to 0.30.0 Full Changelog Access control: Instances without --instance-url (or MEMOS_INSTANCE_URL) now run in private mode. Anonymous visitors are sent to sign-in, anonymous API access is limited to setup, authentication, and shared-memo routes, and RSS feeds are unavailable. Set the instance URL to retain the previous public behavior. (d1cef7a) (415a3ec) Shared memo API: GetMemoByShare and GET /api/v1/shares/{share_id} have been replaced by GetSharedMemo and GET /api/v1/shares/{share_token}/memo. API clients must update the RPC, request type, field name, and REST path. Share-token responses are limited to the shared memo and its attachments and no longer expose the surrounding parent, comments, or relation graph. (0d2cbd4) (415a3ec) Filters: now() has been replaced by the now timestamp variable, and time fields now use CEL timestamps. Update saved shortcuts to use expressions such as created_ts >= now - duration("24h") or timestamp(<epoch>) instead of comparing time fields with bare epoch values. (26f4b73) MCP: The MCP server is now a stateless, tools-only endpoint generated from the OpenAPI schema. The previous prompts, resources, tool-filtering headers and route aliases, and unprefixed tool names have been removed. Clients must switch to /mcp and the new service-prefixed tool names. Tool errors now use isError and text content rather than a non-standard structuredContent.error payload. (#6026) (03e34bd) Webhooks: Added Standard Webhooks HMAC-SHA256 signing secrets, webhook editing, and a signing-status indicator. Secrets are generated server-side, shown after creation, and can be revealed later from the edit dialog; malformed secrets now fail validation. (#6013) (#6027) Markdown and storage: Added GFM footnote rendering and navigation, plus an insecure_skip_tls_verify option for S3-compatible storage with self-signed certificates. (1020060) (#6039) Tags: Tags inside links are no longer parsed as memo tags, literal tags can be escaped with a backslash, and tag names support Unicode combining marks. (a50ce09) (#6051) API and security: Cross-origin API requests now work with bearer tokens while cookie authentication remains same-origin, and ListUsers returns consistent paginated results. (385fa22) (4bc3928) Container: Prevented the entrypoint from restarting indefinitely when MEMOS_UID=0. (#6061) Filters and tag settings: Expanded CEL shortcuts with string matching, regular expressions, collection predicates, timestamp accessors, set operations, and an untagged-memos example. Tag colors and content-blur rules are now per-user, with existing instance tag settings copied during migration. (f0e4a56) (b787bfa) (#6017)
  • 20 733
    20 Topics
    733 Posts
    Package UpdatesP
    [3.25.0] Update metabase to 0.63.17.1 Full Changelog
  • 2 7
    2 Topics
    7 Posts
    J
    @jendrik the ui is a bit confusing. You have to switch the mode to Private . Ideally, that password field should be disabled or hidden when 'Public'. [image: 67cd6c39-a43e-4446-9f92-fe1d26f59591-image.jpeg]
  • 52 522
    52 Topics
    522 Posts
    E
    Thanks a lot for looking into this. Looking forward to the update.
  • 11 100
    11 Topics
    100 Posts
    Package UpdatesP
    [1.7.3] Update v2 to 2.3.3 Full Changelog Feed and entry language detection: Miniflux now reads the language declared by feeds and entries and stores it on both feeds and entries. Feed discovery now finds the feeds offered by GitHub pages. TLS certificates are reloaded when the process receives SIGHUP, so renewed certificates can be picked up without a restart. Fixed an information disclosure issue where any authenticated user could read favicons belonging to other users' feeds through GET /v1/icons/{iconID}. Unix sockets are now created with 0660 permissions instead of being world-writable. Deployments where the reverse proxy runs as a different user now require that user to share a group with the Miniflux process. Fixed a crash caused by concurrent writes to the translation catalog when several requests used a not-yet-loaded language. Fixed a race condition during template rendering that could return a page translated in another user's language. Fixed "Mark all as read" on the unread page, which marked entries from categories hidden from the global unread list. Fixed pagination in the Entries API: the total count is now correct when the requested offset is past the last entry. Fixed the remove_tables rewrite rule reordering article content.
  • 54 704
    54 Topics
    704 Posts
    A
    version Minio RELEASE.2025-10-15T17-29-55Z io.minio.cloudronapp@5.3.0-1 automatic updates are on, the check for updates runs without finding anything new, and last updated 4 months ago.
  • 49 1k
    49 Topics
    1k Posts
    Package UpdatesP
    [1.20.13] Update mirotalkp2p to 1.9.63
  • 16 103
    16 Topics
    103 Posts
    nebulonN
    The app package runs the cron job as outlined in https://github.com/monicahq/monica/blob/4.x/docs/installation/providers/generic.md#4-configure-cron-job Can you open a webterminal into the app and run it manually via: sudo -E -u www-data php /app/code/artisan schedule:run and see if it shows an error or sends the mails then?
  • 42 344
    42 Topics
    344 Posts
    Package UpdatesP
    [4.1.2] Update moodle to 5.2.2 Full Changelog
  • 161 2k
    161 Topics
    2k Posts
    Package UpdatesP
    [4.42.2] Update n8n to 2.38.6 Full Changelog core: Bound peak memory during source control push (#37975) (b3c32da)
  • 19 171
    19 Topics
    171 Posts
    Package UpdatesP
    [1.30.2] Update navidrome to 0.63.2 Full Changelog fix(plugins): surface host service failures when loading plugins (#5756) (@deluan) fix(scanner): resolve file symlinks with the production local storage FS (#5755) (@deluan) fix(smartplaylist): reject NSP mixing top-level 'any' and 'all' (#5759) (@deluan)
  • 410 3k
    410 Topics
    3k Posts
    Package UpdatesP
    [5.8.8] Update server to 34.0.4 Full Changelog v34.0.4
  • 31 309
    31 Topics
    309 Posts
    Package UpdatesP
    [1.49.0] Update nocodb | stage to 2026.09.0 Full Changelog
  • 65 567
    65 Topics
    567 Posts
    Package UpdatesP
    [2.32.4] set minBoxVersion version to Cloudron 10 and redis maxmemoryPolicy to volatile-lru
  • 14 119
    14 Topics
    119 Posts
    Package UpdatesP
    [1.32.0] Update ntfy to 2.28.0 Full Changelog Fix messages being returned out of publish order when polling or replaying several topics at once (/topic1,topic2/json?poll=1, #1297) Limit the message title to 1 KB and all tags combined to 512 bytes, rejecting larger requests with HTTP 400 (error codes 40057 and 40058). Neither field had a size limit before, unlike the message body; on ntfy.sh the 99.9th percentile is 212 bytes for titles and 244 for tags Cap a single cache replay at 10 MB of messages per topic. A poll without a since cursor returns a topic's entire cache, which was previously unbounded and could reach tens of megabytes on a busy topic, so one request could allocate that much on the server. The newest messages that fit are kept and a truncated response carries an X-Messages-Truncated: 1 header visitor-attachment-daily-bandwidth-limit now also covers messages replayed from the message cache by poll requests, not just attachment traffic. A poll without a since cursor returns a topic's entire cache, so a topic that is cheap to fill can be re-read for many times its own size; polls beyond the budget are rejected with HTTP 429 (error code 42905) before anything is written. Note that heavy pollers now consume the same budget as attachment downloads, so operators serving both may want to raise the limit
  • 6 112
    6 Topics
    112 Posts
    Package UpdatesP
    [1.17.0] Update ollama to 0.34.0 Full Changelog Ollama models can now be used directly in ChatGPT Desktop, so you can keep your existing workflow while running open models. Setup is available from the Ollama app on MacOS. This release also improves structured output performance on Apple Silicon, adds support for OpenAI-compatible client tool search and response compaction. Full Changelog: https://github.com/ollama/ollama/compare/v0.33.3...v0.34.0
  • 5 46
    5 Topics
    46 Posts
    Package UpdatesP
    [1.5.1] Update omeka-s to 4.2.1 Full Changelog Block titles for the IIIF page blocks were not properly escaped The IIIF presentation page block did not respect the site's configured IIIF viewer setting for the Mirador theme Some fields were not aligned properly on the admin advanced search Themes could not use the Ckeditor form elements to allow HTML input for theme settings Unnecessary spacing when listing data types in resource template browse Modules using older code for database queries could encounter errors related to core events like those used for processing fulltext search The Asset add form only allowed a fixed list of file types regardless of what types were specified in config The confirm password check did not properly run when the confirm box was left blank
  • 52 436
    52 Topics
    436 Posts
    M
    Thank you very much.
  • 6 42
    6 Topics
    42 Posts
    Package UpdatesP
    [0.9.0] Update opencloud to 6.1.0 Full Changelog Add a flag to the reindex command to force a full reindex [#2606] proxy: Allow mapping from an external tenant id to the internal id [#2569] feat: enable EnableInsertRemoteFile WOPI flag for Collabora [#2555] feat(multi-tenancy): verify tenant via OIDC claim [#2559] Fix race conditions in the hybrid metadata backend [#594] fix: error handling in upload session cleanup [#582] experimental: add darwin watchfs support [#471] Tracing [#596] fix: favorites list, undo delte doesn't return item to the favorites [#2382] feat: handle UI_InsertFile postMessage from Collabora [#2270]
  • 4 52
    4 Topics
    52 Posts
    Package UpdatesP
    [1.9.1] Update openhab-distro to 5.2.1 Full Changelog Make context information available for rules/scripts (5607) Add more commands/abilities to DSL scripts/rules (5727) Fix potential NPE in ScriptTransformationServiceFactory (5702) Fix YAML Thing TEXT configuration parameter processing to support list (5705) Fix chart not being rendered if item has no label (5722) VoiceResource: Select all available LLM tools by default (5749) ecoflow: Fix possible deadlock upon connection (21232) enphase: Fix connection stability (21100) gemini: Switch default model to 3.1-flash-lite (21239) hccrubbishcollection: Update API URL (21159)
  • 24 295
    24 Topics
    295 Posts
    Package UpdatesP
    [3.53.0] Update openproject to 17.8.0 Full Changelog Feature: Sprints and backlog buckets can be updated on bulk updating work packages [#73103] Feature: Add create_work_package MCP tool [#75408] Feature: Introduce target versions replacing version [#76181] Feature: Global restrictions/limits for time entries [#78132] Feature: Display relations in the work package table to the community edition [#78598] Feature: Add milestones to the project lifecycle widget [#76749] Feature: Activity tab: Journalise and add information about when a work package is added or discussed in a meeting [#61057] Bugfix: Both "Target version" and "Version" filters are present when target versions is enabled [#78408] Bugfix: Meeting invitation email shows event shifted by +1 hour for dates between 2026-09-29 and 2026-10-24 [#77624] Bugfix: Sprint names and assignments leaking through activity without view_sprints permission [#78436]
  • 4 Topics
    34 Posts
    J
    Hi @girish so I learned something while setting up my Radicale and OWC. It seems like the calendar client publishing in to the ICS in Radicale (or wherever your ICS source lives) can matter. When I used the Calendar app on macOS I saw no descriptions. When I used Thunderbird I do. You can see it on my live page that has the OWC page in an iframe https://kb.filewave.com/books/community-engagement/page/customer-event-schedule and if you click on events in the agenda then the description shows. I think initially I was also hoping to show description on the Agenda page without clicking on an event but originally I was bothered that I just couldn't get description to show up. So now it does at least show up when you click an event. I haven't looked at why Calendar doesn't make a summary that shows and Thunderbird does but I'm fine using Thunderbird to put events in my calendar feed.
  • 80 738
    80 Topics
    738 Posts
    Package UpdatesP
    [3.5.2] Update open-webui to 0.11.3 Full Changelog Accessibility mode reaches the menus. Accessibility mode now marks the menu entry you are pointing at and the model already chosen with a stronger background, across the dropdown menus, their submenus, and the model picker together with its filter and compare controls, so those cues carry the contrast the accessibility guidelines ask for in both themes. Commit, Commit General improvements. Various improvements were implemented across the application to enhance performance, stability, and security. Translation updates. Translations for Indonesian were enhanced and expanded. Chat branches stay connected after reloads. A reply saved under an earlier message now stays listed under that message, so branch arrows, exports, reloads, and later edits keep the whole conversation in view, and chats already saved with that link missing are repaired when opened. #29299 Upgrades fail clearly instead of starting half updated. A failed database upgrade now stops at the migration error that caused it, instead of starting anyway and reporting a missing table or column such as 'chat.timer_at' later, which is the upgrade failure seen after moving from 0.11.0, 0.11.1, or 0.11.2. #29280 Custom interface fonts reach more of the app. The font chosen in interface settings now applies to dropdowns and other interface text that previously fell back to the standard font. Commit Disconnect OAuth only where there is OAuth. The disconnect control on a tool server reached over MCP now appears only where that server signs in through OAuth and an account is connected, rather than on servers that use no sign-in at all. #29296
  • 3 14
    3 Topics
    14 Posts
    Package UpdatesP
    [1.1.4] Fixup docs link
  • 15 94
    15 Topics
    94 Posts
    Package UpdatesP
    [2.4.3] Update osTicket to 1.18.4 Full Changelog security: Latest Patches 06/2026 (52c366f, 5afdf54, c54a6ac, 1e39bf1, feccb6a, 6eb6b98, 078516e, 98abb05, e52e010, fd96bba, 7bbd8ab, ba6217a, 580e1c8, b535782, 5963797, d590a97, eaebe01, b4cc092, d457c14, 5600f94, 5ff9795, 119cefe, b4ede88, 2a0c388, 6558b33)
  • 30 204
    30 Topics
    204 Posts
    Package UpdatesP
    [1.25.1] Update outline to 1.10.1 Full Changelog Added WebMCP support in #13576, allowing agents in Chrome and ChatGPT to programmatically control Outline through the browser. Alt/Mod-click toggle disclosure folds nested or all toggle blocks in #13678 Keep editor "find and replace" panel open in #13643 Added Open Knowledge Format (OKF) export in #13644 Allowed editing webhooks without signing secrets in #13622 Escaped MCP attachment PUT upload command arguments in #13613 Fixed manual sizing of embedded PDFs in #13645 Fixed Mermaid diagram rendering size issue in #13648 Tighten authentication on views.create endpoint in #13663 Validate API key and OAuth scopes at the model layer in #13664
  • 17 105
    17 Topics
    105 Posts
    Package UpdatesP
    [1.7.0] Update owncast to 0.3.0 Full Changelog Featured Streams: Allow an Owncast instance to follow other instances #1676 Support simple display name setting on user registration via query param #5032 Allow binding rtmp to specific interface/localhost #4808 Enable autoplay when first enter the stream #1602 Plugin support #1736 Fediverse follow webhook event now has status and serverURL fields #4881 Re-enable the stream latency compensator #5001 Limit failed Fediverse OTP attempts to prevent brute-force guessing #5133 Bug report: USER_JOINED webhook doesn't fire when "Join Messages" is disabled in admin. #4950 Protect admin requests from cross-site attacks #5047
  • 3 16
    3 Topics
    16 Posts
    Package UpdatesP
    [1.3.0] Update base image to 5.0.0
  • 68 580
    68 Topics
    580 Posts
    Package UpdatesP
    [1.63.3] Update paperless-ngx to 3.1.3 Full Changelog Fix: use the header loading indicator on tasks page @shamoon (#13949) Fix: fix load sidebar size animating @shamoon (#13947) Fix: wrap long words without spaces in dropdowns @shamoon (#13945) Fix: tweak tool calling localzation prompt @shamoon (#13943) Fix: skip vector store document id filter for unrestricted chat users @stumpylog (#13937) Fix: adopt the request stream when pinning an outbound host @ThomasSteinbach (#13927) Fix: ensure apply ai suggestions always runs after document created @shamoon (#13940) Fix: Handle failures when enqueuing files for consumption @stumpylog (#13935) Fix: Handle Celery mail task chord errors @stumpylog (#13936) Fix: use root doc metadata for filename generation @shamoon (#13893)
  • 2 11
    2 Topics
    11 Posts
    girishG
    You can still install it like this https://my.<cloudron>/#/appstore/rocks.paperwork.cloudronapp . But note that it was last updated 3 years ago. I tried to build a new version with latest with PHP a year ago and the app was not even building anymore. They have been re-writing a new version for a couple of years now.
  • 106 923
    106 Topics
    923 Posts
    Package UpdatesP
    [4.8.4] Update PeerTube to 8.2.4 Full Changelog
  • 22 198
    22 Topics
    198 Posts
    Package UpdatesP
    [1.19.3] Update penpot to 2.17.2 Full Changelog Fix linear gradients in SVG text exports being emitted as radial gradients #5972 (MR: #11272) Fix typography token becoming detached when editing text content #11362 (MR: #11366) Fix command injection in SVG exporter via legacy fill-color (https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86)
  • 6 Topics
    24 Posts
    girishG
    App discontinued due to no upstream updates.
  • 4 Topics
    12 Posts
    girishG
    The upstream project has not released in almost 3 years now. We had to build from develop to get some PHP 8 support going, but there are bugs like https://github.com/phpservermon/phpservermon/issues/1196 , https://github.com/phpservermon/phpservermon/issues/1232 . There's also a bunch of basic issues: Normal user cannot login after admin user logs in. Some issue related to service worker. LDAP functionality is incomplete
  • 5 63
    5 Topics
    63 Posts
    Package UpdatesP
    [3.4.0] Update Piwigo to 16.4.0 Full Changelog Release note
  • 80 672
    80 Topics
    672 Posts
    Package UpdatesP
    [1.22.5] Update pixelfed to 0.12.9 Full Changelog Account Migration fix (2fd3162f404) Fix post likes modal (d1b11e2a8) Refactor UserFilterService (ecb04f3ab3) Add alt tag to avatars (5e79dbd3321)
  • 4 19
    4 Topics
    19 Posts
    Package UpdatesP
    [2.0.0] Update planka to 2.2.1 Full Changelog IMPORTANT: OIDC/SSO has been removed from PLANKA Community. After updating, all SSO-based users are deactivated, because they no longer have a password login. If your only admin account is SSO-based, you will be locked out. Create a new admin user first (via script or environment variables) before updating: https://docs.planka.cloud/docs/configuration/admin-user The Cloudron package has removed OIDC integration as part of this major update
  • 9 164
    9 Topics
    164 Posts
    Package UpdatesP
    [1.18.3] Update pocketbase to 0.40.3 Full Changelog Write the status header for JSON responses only if the fields picker succeed or has acceptable fallback. Fixed collection index validator to allow expressions with parenthesis in the optional WHERE clause. Clamped arccosine to [-1,1] in the Harvesine formula for the geoDistance() filter function to workaround edge case related to float rounding errors for some coordinates. Prevent unnecessary body chunk read if we already known that we are beyond the allowed limit. Updated the json field validator to check the encoding/json/v2 semantics and allow duplicated keys on record marshalize for compliance with old jsonv1 data. Fixed nested cascade delete of self-referenced relation records. Minor UI fixes (updated dark primary btn color contrast, force reload the records list if the deleted record has self-referenced cascade relation field, etc.). Changed JSVM $app variable definition from TS type to interface (#7834). Bumped golang.org/x/* dependencies to silence security scanners (#7829).
  • 22 222
    22 Topics
    222 Posts
    robiR
    Here's the video:
  • 9 82
    9 Topics
    82 Posts
    Package UpdatesP
    [1.10.0] Update pretix to 2026.7.0 Full Changelog
  • 8 60
    8 Topics
    60 Posts
    Package UpdatesP
    [1.11.6] Update PrivateBin to 2.0.6 Full Changelog CHANGED: Upgrading libraries to: DOMpurify 3.4.12 CHANGED: Switch to PHP native JsonException type FIXED: Gracefully handle YOURLS replies with a 200 status code but no shorturl, instead of raising a TypeError FIXED: Return "Invalid data." instead of HTTP 500 on malformed v2 JSON payloads (#1883) FIXED: Dead PATH validation guard in Controller, the check for a missing trailing directory separator never ran (#1887)
  • 20 233
    20 Topics
    233 Posts
    jamesJ
    Hello @arnaudguy We will add basicAuth to the app. An app update will be available soon.
  • 6 107
    6 Topics
    107 Posts
    Package UpdatesP
    [2.29.0] Update VueTorrent to 2.35.0 Full Changelog show raw data values on hover (#2867) (e92249f) capitalize language names in locale switcher (#2903) (f47c1d2) Improve network sync reliability (559919e) Repair broken desktop layout (9e2b435) Settings: API key copy not working in insecure contexts (#2880) (ec39bbd) Improve chunking for better app load time (#2881) (b0eff6c) links: Add mouse middle click support to open in new tab (#2902) (38ca598) Pause network requests on tab change (6a42b7b)
  • 15 165
    15 Topics
    165 Posts
    Package UpdatesP
    [2.16.0] chore(deps): update dependency radicale to v3.8.0
  • 16 202
    16 Topics
    202 Posts
    Package UpdatesP
    [2.14.0] Update rallly to 4.14.0 Full Changelog Enforce instance branding when the white label add-on is active (#3125) Add List-Unsubscribe headers and tokenized per-poll unsubscribe (#3148) Show role permissions in the invite member dialog (#3116) Activity log: event vocabulary and writes from every poll mutation (#3076) Add cookie consent banner, shown only when analytics are configured (#3114) Require both SMTP_USER and SMTP_PWD for authenticated SMTP (#3064) Unshare single-member spaces wrongly marked shared by backfill (#3118) Restore dark mode muted text hierarchy on popover surfaces (#3084) Fix muted icon color on the invite member button (#3097) Comments: fix mobile footer overlap and polish the sheet (#3082)
  • 9 75
    9 Topics
    75 Posts
    girishG
    App discontinued due to no upstream updates.
  • 14 106
    14 Topics
    106 Posts
    Package UpdatesP
    [5.4.0] Update redash to 26.3.0 Full Changelog
  • 18 175
    18 Topics
    175 Posts
    Package UpdatesP
    [3.20.3] Update redmine oauth to 7.0.1
  • 19 125
    19 Topics
    125 Posts
    Package UpdatesP
    [1.13.2] Update releasebell to 1.13.2 Fix to scope project updates to the owner user
  • 71 790
    71 Topics
    790 Posts
    Package UpdatesP
    [3.7.1] Update Rocket.Chat to 8.8.1 Full Changelog Fixes Omnichannel rooms failing to register agent responses (and showing send errors on messages and file uploads that were actually delivered) when the room carried corrupted visitor activity data created by older app integrations
  • 54 371
    54 Topics
    371 Posts
    Package UpdatesP
    [2.10.4] Update roundcubemail to 1.7.4 Full Changelog Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308) zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325) Security: Fix CSS declaration smuggling via un-encoded ampersand emission Security: Fix CSS property injection via body background attribute Security: Fix email header injection via bare CR in the subject field Security: Fix email header injection via C-escape \r in the recipient display name Security: Fix email header injection via identity's organization field Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL Security: Fix XSS in the HTML editor using text/enriched part content Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • 9 62
    9 Topics
    62 Posts
    O
    @girish said: @rmdes @odie I have updated the app to use symlinks under /app/data/bridges. You can add new bridges there or delete some symlink and add your own. Thank you! Works excellent!
  • 2 39
    2 Topics
    39 Posts
    Package UpdatesP
    [0.21.0] Update rustfs to 1.0.0-rc.5-preview.2 Full Changelog fix(api): preserve server-side storage error surface by @houseme in #6753 fix(deps): move off the yanked chacha20 0.10.1 by @overtrue in #6768 fix(tier): validate outbound URLs for all warm backend providers by @overtrue in #6764 fix(s3): round-trip null-version delete-marker identity by @overtrue in #6765 fix(startup): never panic when the system CA bundle is absent by @overtrue in #6769 perf(storage): optimize small-object GET/PUT paths by @houseme in #6770 fix(s3): preserve atomic 1 MiB conditional writes by @overtrue in #6798 feat(nix): add NixOS service module and client package by @houseme in #6856 feat(replication): support temporary target credentials by @cxymds in #6860 feat(s3select): support compressed CSV and JSON input by @GatewayJ in #6915
  • 4 15
    4 Topics
    15 Posts
    girishG
    Given that the upstream project is not maintained anymore, we have hidden this in the appstore. I had also submitted a PR upstream for a basic issue which is ignored - https://github.com/aliasaria/scrumblr/pull/161
  • 18 262
    18 Topics
    262 Posts
    Package UpdatesP
    [2.110.0] Update searxng to c7f3080
  • 2 32
    2 Topics
    32 Posts
    Package UpdatesP
    [1.23.0] Update seaweedfs to 4.46 Full Changelog master: scope the startup capacity shed to a truly empty topology by @chrislusf in #11058 filer.sync: export replication lag, event counters, and in-flight jobs by @chrislusf in #11069 fix(mount): make a concurrent duplicate mkdir fail with EEXIST instead of both succeeding by @kisow in #11079 Remove the RDMA sidecar prototype and its mount client by @chrislusf in #11119 deps: update golang.org/x/image to v0.45.0 for CVE-2026-46603 by @lucasmellofred in #11164 fix(chart): add missing [grpc.s3] TLS section S3 internal gRPC served plaintext while peers dial mTLS by @MorezMartin in #11157 admin: bind to loopback by default, guard public unauthenticated bind by @chrislusf in #11185 s3: gate IAM-cache gRPC RPCs behind admin Bearer auth by @chrislusf in #11190 topology: fix fatal concurrent map read/write on VolumeLayout.crowded by @chrislusf in #11216 [Filer] Parallelize Chunk Manifest Resolution to Reduce Large File Read Latency by @ssshr-66 in #11215
  • 5 35
    5 Topics
    35 Posts
    Package UpdatesP
    [1.4.0] Update serpbear to 3.1.0 Full Changelog add subdomain matching functionality (4533737), closes #​324 enhance error handling and response structure in scraper functions (4f394c2) minor ui issue (eecf88a) prevent corrupt failed queue file to reset the app settings (c306fa0), closes #​328 resolves broken google ads oauth of instances behind reverse proxy (a988b13), closes #​326 resolves cron issue with certain port mapping config (d86616a) resolves issue that prevents refreshing all keywords when one fails (77cfa2f)
  • 14 86
    14 Topics
    86 Posts
    Package UpdatesP
    [1.4.4] Update sftpgo to 2.7.5 Full Changelog httpd: make sure to always close connection for shares. Improper handling of malformed SSH channel requests. GHSA-q7pc-356p-hggc.
  • 5 48
    5 Topics
    48 Posts
    Package UpdatesP
    [2.18.4] Update Shaarli to 0.16.5 Full Changelog fix wrong token error when saving links after metadata retrieval Full Changelog: https://github.com/shaarli/Shaarli/compare/v0.16.4...v0.16.5 fix wrong token error when saving links after metadata retrieval Full Changelog: https://github.com/shaarli/Shaarli/compare/v0.16.4...v0.16.5
  • 7 50
    7 Topics
    50 Posts
    jdaviescoatesJ
    @girish said in SickChill unlisted from app store: I hope they atleast bring back the issue tracker Out of interest, why does this matter for Cloudron? BTW, someone has replied to the thread I started on Discord informing me that the master releases are these https://pypi.org/project/sickchill/ Doesn't look like there has been a new one since March though.
  • 2 15
    2 Topics
    15 Posts
    Package UpdatesP
    [1.3.0] Update shiori to 1.8.0 Full Changelog feat(apiv1): refactor tags api (#1075) feat: add PWA support share functionality (#1060) feat: add apis to handle bookmark tags (#1081) feat: allow tag filtering and count retrieval via api v1 (#1079) feat: improve SQLite performance (#1024) feat: reverts message in json output and allows configuration (#1082) feat: support proxy forward headers authentication (#1105) fix: auth validation on existing sessions, rely on token only (#1069) fix: incorrectly set cookie's expires value in login.js (#1049) fix: parse pocket new CSV format (#1112
  • 4 Topics
    41 Posts
    girishG
    The upstream project is archived - https://github.com/boypt/simple-torrent/ . There has been no changes in 2 years and modules are not updated.
  • 33 363
    33 Topics
    363 Posts
    necrevistonnezrN
    This is GREAT news! 🥰
  • 22 224
    22 Topics
    224 Posts
    Package UpdatesP
    [1.22.2] Update snipe-it to 8.7.2 Full Changelog API+UI: Use observers to prevent double logging on restores by @snipe in #19500 Custom Consumables Report: Fixed #15586 - Added custom consumables report by @snipe in #19502 Backup/Restore: Fixed #19506 and #19506 - MariaDB executable/path change by @snipe in #19507 LDAP Wizard: Fixed #19519 - better handle mTLS by @snipe in #19523 Restore SSL database keys within tests by @marcusmoore in #19522 Asset Checkin Notification: [FD-55583] Fix Null location bug by @Godmartinz in #19520 Fixed --force not skipping the PHP version prompt in ldap:troubleshoot by @kratos0718 in #19514 Improve Boost settings by @marcusmoore in #19508 Importer: Small UI improvements, send welcome email if user created by @snipe in #19525 Added #10606: support shift-click checkbox range selection by @DanielDavis05 in #19509
  • 60 429
    60 Topics
    429 Posts
    Package UpdatesP
    [2.18.10] Update sogo to 5.12.10 Full Changelog sogo-tool: add init-user command to create a user's personal folders and preferences without a login (aefc14b) bug: escape angularJS only if needed to keep legitimate directive (41e2b7b) bug: incorrect method called (1caa257) calendar: do not transmit og http status to external calendar (3a78a3b) ckeditor: Sync resized image width/height into style and HTML attributes so Outlook and other mail clients ignoring CSS aspect-ratio render the correct dimensions. Closes #6169. (39a3583) dav: properly parse MKCOL request (78807d0) mail: escape angularJS directive for description (47133fd) mail: escape References/Organization/Newsgroups headers in HTML forward so message-id chevrons aren't parsed as HTML tags hiding the quoted body. Closes #6046. (f11f34c) mail: Some links broken in HTML rendering due to libxml2 (SOPE) only supporting HTML4 when an anchor has no content between its opening and closing tags, store it and re-open it around the next element, closing </a> after that element's end tag. Closes #5961. Closes #6172. (6904911) passwordRecoveyr: get the domain from the user mail (a156f4c)
  • 13 104
    13 Topics
    104 Posts
    girishG
    Just checked on this again but it seems statping-ng is not going forward much . https://github.com/statping-ng/statping-ng/tags says the release was almost a year ago.
  • 44 470
    44 Topics
    470 Posts
    Package UpdatesP
    [3.15.3] Update Stirling-PDF to 2.14.3 Full Changelog Redact: clear error instead of a 500 when no text patterns are given (cherrypicked) by @jbrunton96 in #6972 fix(temp-files): prevent cleanup of active registered directories by @Ludy87 in #7006 fix(admin-settings): correctly mask Telegram bot tokens in settings output by @Ludy87 in #6822 fix(admin-settings): prevent hydration error in the Admin General section by @Ludy87 in #6823 fix(editor): respect no-login settings visibility in config navigation by @Ludy87 in #6807 fix(licenses): fall back to license URL for backend dependency links by @Ludy87 in #7046 fix(sign): preserve PNG signature placement and page content by @Ludy87 in #7093 fix(viewer): dynamic page number input width based on total page count by @balazs-szucs in #6607 Avoid renderer OOM when adding large PDFs to the workbench by @Frooodle in #7175 fix(search): Fix PDF viewer search showing 0 of 0 results by @balazs-szucs in #7228
  • 15 145
    15 Topics
    145 Posts
    Package UpdatesP
    [1.12.1] update apache-superset to v6.1.0
  • 106 787
    106 Topics
    787 Posts
    luckowL
    In the app's file manager, I can browse and edit files. However, doing the same via /_admin doesn't allow for editing. This inconsistency is quite confusing.
  • 32 243
    32 Topics
    243 Posts
    Package UpdatesP
    [1.34.4] Update syncthing to 2.1.5 Full Changelog Devices and folders can now be grouped in the GUI by setting the new group attribute. HTTP and HTTPS proxies with support for CONNECT can now be used, in addition to the existing support for SOCKS proxies (the environment variable all_proxy=https://...). Block indexing can be turned off for folders where it's more desirable to optimise for reduced database size and overhead than minimal transfer size (the blockIndexing attribute on folder configuration). GUI login session duration can be configured to be longer or shorter than the default one week, or set to infinitely long. The cookie path can also be adjusted. (The sessionCookieDurationS and sessionCookiePath attributes in the GUI configuration.) APT repository: https://apt.syncthing.net/ Full Changelog: https://github.com/syncthing/syncthing/compare/v2.1.4...v2.1.5
  • 21 204
    21 Topics
    204 Posts
    Package UpdatesP
    [2.19.5] Update taiga-back to 6.10.2 Full Changelog fix: enforce permission check on create_default due date endpoints
  • 6 101
    6 Topics
    101 Posts
    Package UpdatesP
    [1.12.14] Update recipes to 2.6.15 Full Changelog added pestle import support (thanks to LLf13 #4637) added AI based step sorter to recipe import (thanks to sadSanta-07 #4799) improved adding multiple recipes to a book at the same time (thanks to ujjwalv01 #4610) fixed group permission caching issue accross spaces GHSA-29pm-4vh2-f8mp fixed recipe export not respecting private flag of recipes GHSA-gh65-4455-65vg fixed possible to add other space member private recipes to book via api and see overview GHSA-gh65-4455-65vg fixed file path of recipe could be changed to show a different file GHSA-8635-c66p-9cwm fixed fixed batch update allowing recipe shares accross spaces GHSA-5mw3-c978-gc6w fixed image rotation sometimes lost when uploading to tandoor #4765 (thanks to @agross #4769) changed cook logs to only be editable by the creator or admins of a space GHSA-g378-5m3q-p58q
  • 10 69
    10 Topics
    69 Posts
    Package UpdatesP
    [1.5.2] Fixup doc URL
  • 9 79
    9 Topics
    79 Posts
    timconsidineT
    @timconsidine said in Teddit Subscriptions no longer working: Just FYI - my LibReddit - selfhosted as Docker on another VPS = is still working. But now it is down. Maybe they have caught up with me.
  • 5 52
    5 Topics
    52 Posts
    Package UpdatesP
    [1.23.2] Update thelounge to 4.5.2 Full Changelog include the version script in the NPM package (#5115) (833a8bb by @deltamualpha)
  • 10 67
    10 Topics
    67 Posts
    girishG
    @Sam_uk we have unlisted TLDraw by now. Please see https://forum.cloudron.io/topic/10806/no-more-updates-to-tldraw . The license and company direction has changed.
  • 22 243
    22 Topics
    243 Posts
    Package UpdatesP
    [1.28.1] Update traccar to 6.15.3 Full Changelog
  • 10 103
    10 Topics
    103 Posts
    Package UpdatesP
    [2.7.4] Update libretranslate to 1.9.6 Full Changelog Turkish UI
  • 12 81
    12 Topics
    81 Posts
    Package UpdatesP
    [2.5.3] Update transmission to 4.1.3 Full Changelog Fixed a CORS bug that leaked the anti-CSRF nonce. (#8938) Fixed a use-after-free bug in peer code. (#8921) Fixed build error when compiling with fmt 12.2.0. (#8942) Fixed a 4.1.2 build error in tests. (#8881)
  • 13 162
    13 Topics
    162 Posts
    Package UpdatesP
    [1.31.0] Update Trilium to 0.105.0 Full Changelog MCP now requires authentication and can optionally be accessed over the network. Reconfigure your existing MCP clients with credentials. General HTML support in text notes is now disabled by default. This makes copy-paste from websites behave well, without grabbing unwanted tags such as input boxes. Re-enable via Options Text notes Preserve unsupported HTML tags. <div>s in text notes are now unwrapped instead of being preserved as-is, regardless of settings. This prevents broken behaviour when entering new paragraphs, and bugs such as being unable to exit a code block. Single-tilde strikethrough is no longer supported, to avoid issues with ~ used for number approximations. Affects existing notes and import pipelines; use ~~text~~. Database actions have moved to Options Database. Cleanup, space analysis, integrity checks, compaction and anonymized copies are no longer under Options Advanced, which now holds the experimental features and the two advanced sync actions alone. On Linux, the native title bar is now disabled by default, since rounded corners are supported for the custom frame, with native window buttons. Fixed an important memory leak that accumulated components and event listeners due to improper component cleanup. Consistency checks no longer take a long time to run on large databases (20k+ notes). Inline Mermaid diagrams remember their display mode. Multiple inline Mermaid diagrams don't render without making a change
  • 37 422
    37 Topics
    422 Posts
    Package UpdatesP
    [2.100.0] Update tt-rss to 542d07b
  • 3 44
    3 Topics
    44 Posts
    Package UpdatesP
    [1.11.4] Update tymeslot to 1.15.4 Full Changelog Keep calendar deletion working when two calendars are removed at once Stop the popup and floating previews creating real bookings Restore a CalDAV booking the server no longer has Refuse a CalDAV connection that discovers no calendars Stop the booking rate limit refusing legitimate bookings Let the live preview complete a test booking Keep the organiser signed in when an embedded booking page loads Write through outbound calendar updates to the local event cache
  • 13 104
    13 Topics
    104 Posts
    Package UpdatesP
    [1.16.0] Update twenty to 2.39.0 Full Changelog Generate the twenty-ui theme artifacts from a single design-tokens source (#24375) by @bosiraphael feat(call-recorder): custom settings tab with grouped sections (#24913) by @ehconitin feat(workflow): honor retryOnFailure in the executor (#25248) by @thomtrp feat(usage-limit): gate intra-workspace limits behind the Organization entitlement (#25292) by @etiennejouan feat(workflow): Node settings page for step error handling (#25314) by @thomtrp Fix: Calendar drop issue & drop target resolution at list extremes (#24082) by @git-init-priyanshu fix(workflow): blank step-editor tabs in the side panel (#25318) by @thomtrp fix(workflow): stop corrupting run state when a loop resets a deleted step (#25352) by @thomtrp fix(server): ship ClickHouse migrations in the server build (#25357) by @etiennejouan fix: quarantine direct uploads until completion has validated them (#25342) by @FelixMalfait
  • 43 304
    43 Topics
    304 Posts
    Package UpdatesP
    [1.26.0] Update typebot.io to 3.18.0 Full Changelog Add camera capture options to file uploads (#2560) [512c988] Add a separator label for date range answers (#2573) [6e6b0b2] Fix stored WhatsApp phone lookup fallback (#2531) [f00ccba] Fix embed video overlay in preview (#2532) [9224f4f] Fix S3 operations without full config (#2533) [248f751] Fix WhatsApp audio file upload URLs (#2539) [54e1fa1] Fix Android camera for image extension uploads (#2558) [e7be877] Honor the DATABASE_URL schema parameter in the Prisma PostgreSQL adapter (#2582) [f9a57c4] Fix sidebar block drag on Android touch devices (#2569) [6796f58] Fix custom domain deletion ownership checks (#2541) [06575df]
  • 33 281
    33 Topics
    281 Posts
    Package UpdatesP
    [3.26.1] Update umami to 3.3.1 Full Changelog Hardened two-factor authentication when TWO_FACTOR_ENCRYPTION_KEY is missing or invalid, with safer API enforcement and clearer configuration feedback. #4443 Preserved the root path when REMOVE_TRAILING_SLASH is enabled and reset tracker visit state when a session drifts. #4152 Fixed event property filtering so fields and values respect the selected event name. #4461 Preserved events without matching session records and stabilized relational event pagination. #4462 Improved expanded metrics query performance and fixed funnel steps containing null event values. Preserved zero and false values in website value responses. Improved handling of username conflicts involving deleted users. Added broader coverage for 2FA status, setup, verification, disable, admin, team, and login flows. Preserved menu item actions in admin dropdowns. #4453 Fixed expanded-menu spacing and realtime search bar styling.
  • 39 356
    39 Topics
    356 Posts
    Package UpdatesP
    [2.8.0] Update cloudflared to 2026.9.0
  • 19 126
    19 Topics
    126 Posts
    Package UpdatesP
    [1.6.1] fix: Mod support
  • 4 120
    4 Topics
    120 Posts
    Package UpdatesP
    [1.84.0] Update vault to 2.1.0 Full Changelog core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107. core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052. Agent Registry UI (enterprise): Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status. Automatic DNS-01 Challenge Fulfillment for PKI External CA: Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers. PKI PKCS#12 and JKS Support: Adds support for PKCS#12 (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files. SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise): Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and Ed25519. agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where ca_chain field was always empty in templates due to incorrect type handling of array responses api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire. core/login: Fix panic on malformed login requests. Vault now returns an error for malformed login payloads instead of dropping the client connection (no data loss). secrets/database: Sanitize the caller-controlled DisplayName before it is used in generated usernames to prevent SQL injection via username templates. Adds a configuration warning when a username_template references DisplayName without a truncate function.
  • 99 853
    99 Topics
    853 Posts
    J
    Yeah, the double login is not great especially if you store your SSO credentials in bitwarden itself
  • 1 1
    1 Topics
    1 Posts
    Package UpdatesP
    You can use this thread to track updates to the Versitygw package. Please open issues in a separate topic instead of replying here.
  • 9 174
    9 Topics
    174 Posts
    Package UpdatesP
    [1.83.3] Update verdaccio to 6.10.3 Full Changelog fix: do not fetch client-controlled dist.tarball urls off-uplink
  • 39 282
    39 Topics
    282 Posts
    Package UpdatesP
    [1.26.0] Update vikunja to 2.6.0 Full Changelog Enforce token scopes for task expansions Don't duplicate a task when a client PUTs a stale href Encode task uids in hrefs instead of interpolating them raw (#3560) Don't wrap reminders into the past when repeating from current date Reuse existing labels in the desktop quick entry window (#3533) Add default due time settings (#3433) (d71301f) Filter tasks by creator username (#2916) (07927c5) Add clearing stored notifications (#2735) Add planka migration form Add --config flag to pin the config file (#3652)
  • 69 529
    69 Topics
    529 Posts
    Package UpdatesP
    [2.23.3] Update vpn to 2.23.3 Fix settings UI
  • 20 169
    20 Topics
    169 Posts
    Package UpdatesP
    [2.5.6] Update wallabag to 2.6.14 Full Changelog Change version in wallabag.yml by @nicosomb in #8251 Fix deprecation by @j0k3r in #8267 Add annotations filter to entries API endpoint by @skn in #8346 Update dependencies by @yguedidi in #8435 Bump deps (mostly for siteconfig) by @j0k3r in #8489 Fix reading time computation for short entries by @andreadecorte in #8332 Fix urls parameter when sending many urls to be stored using the API by @j0k3r in #8488 Prepare 2.6.14 by @j0k3r in #8494
  • 5 94
    5 Topics
    94 Posts
    Package UpdatesP
    [1.29.0] Update Wallos to 5.7.1 Full Changelog bump version (6d6d1f0) bump version (d84fdd4) cancellation in dashboard & general statistics (#1207) (e38403d) support Markdown notes with safe rendering (5a92009) pwa: offline mode, icons and background (5ffa841)
  • 5 79
    5 Topics
    79 Posts
    Package UpdatesP
    [1.43.0] Update whitebophir to 2.17.0 Compare Source
  • 8 160
    8 Topics
    160 Posts
    Package UpdatesP
    [1.50.0] Update weblate to 2026.9.1 Full Changelog Added per-user notification diagnostics for users and administrators, with compact explanations of matching subscriptions for object paths. Prevented repeated authenticator app registration from creating duplicate devices and allowing reuse of one-time codes. Existing equivalent duplicate devices are merged while preserving consumed codes. Engage pages and status widgets no longer disclose Private or Custom projects unless Public sharing is enabled. Fixed the approved-only commit policy blocking commits for languages with reviews disabled by workflow settings. Restored DeepL API v1 translation support while retaining modern API language discovery and glossary improvements. REST API unit updates now enforce the same translation text length limit as the web editor. Anonymous access to engage pages and status widgets is now disabled by default for Private and Custom projects. Enable Public sharing to preserve existing shared links after upgrading. Public and Protected projects are unchanged. Authenticator app registrations started before this upgrade must be restarted. Sessions referencing a removed duplicate device may require two-factor verification again. Docker deployments now default to the combined Celery worker mode. If your deployment relies on separate workers for each queue or configures them using CELERY_MAIN_OPTIONS, CELERY_NOTIFY_OPTIONS, CELERY_MEMORY_OPTIONS, CELERY_TRANSLATE_OPTIONS, or CELERY_BACKUP_OPTIONS, set CELERY_WORKER_MODE=split to preserve the previous behavior. All changes in detail.
  • 25 570
    25 Topics
    570 Posts
    Package UpdatesP
    [4.171.0] Update wekan to 11.67 Board export to .zip (with attachments) answered a bare 500 error on every request; the archiver dependency's v8 API change was missed in one of the two places WeKan builds a zip on the server. Issue #6681 (OIDC redirect-style login loop) is confirmed already fixed and closed. Unauthenticated Arbitrary File Write via Path Traversal in Attachment Upload namingFunction. Thanks to xet7. Unauthenticated DDP Methods Allow Instance-Wide Deletion of Attachments and Avatars. Thanks to xet7. Add the protected callback the download library needs to gate them. Thanks to xet7. serveLegacyAvatar Serves Legacy CollectionFS Avatars Without Any Authentication. Thanks to xet7. Relocate the AppImage's own mount from /tmp to WRITABLE_PATH/app. Thanks to xet7. Revert "Hardcode list width to 240px and remove the width/height set-value popups". Thanks to xet7. Add board-wide list-width/swimlane-height resize locks (#6680). Thanks to Hallsie and xet7. Add a header-icons collapse toggle beside the board title (#6680 follow-up). Thanks to xet7. Allow storing Infinity/-Infinity doubles, matching MongoDB. Thanks to xet7.
  • 16 139
    16 Topics
    139 Posts
    Package UpdatesP
    [1.13.7] Update wiki to 2.5.314 Full Changelog ec36eb2 - update arm docker base to node 24 (commit by @NGPixel) da64dcd - fix windows build missing migration file during tarball creation (commit by @NGPixel)
  • 4 73
    4 Topics
    73 Posts
    Package UpdatesP
    [2.20.1] Update woodpecker to 3.18.1 Full Changelog Add timezone data to docker images [#7093] Log an expected log-stream close failure at debug instead of error [#7117] Log a filtered webhook at debug instead of error [#7116] Fix workflow-level when.status so a failure-only workflow does not run on success [#7091] Speedup migration "deduplicate-log-entries" [#7068] fix(forge/gitlab): use group Path instead of Name for membership lookup [#7086] Fix injecting additional variables for substituting [#7077]
  • 115 Topics
    881 Posts
    jamesJ
    Hello @stirchley.coop Apologies that you are experiencing this issue. This happened because we did release a @wordpress-managed with version 4.0.0 which was the wrong version number. To resolve this issue you need to run a command with the cloudron cli cloudron update -app $YOUR_LOCATION_OR_APPID --appstore-id org.wordpress.cloudronapp@3.17.0 --force After that is finished, your app will get updated again.
  • 227 Topics
    2k Posts
    Package UpdatesP
    [3.16.0] Update WordPress to 7.1 Full Changelog The Release Notes section contains no breaking changes, features, or bug fixes listed.
  • 14 71
    14 Topics
    71 Posts
    S
    @james Just installed the updated package and tried it out. Seems to be working without issues, so far. Thanks!
  • 20 138
    20 Topics
    138 Posts
    Package UpdatesP
    [1.12.3] Update YOURLS to 1.10.6 Full Changelog fixed: the version number. It's just 1.10.5, without the -dev, as 1.10.5 should have been. Sorry
  • 2 Topics
    22 Posts
    Package UpdatesP
    [1.6.0] Update urlaubsverwaltung to 6.11.0 Full Changelog Analyse: Zahlen auf den Balken in allen Statistik-Diagrammen einheitlich anzeigen oder nicht #6592 Berechtigungsregeln fr berstunden in einem OvertimePermissionEvaluator bndeln #6611 Schriftgren der drei Statistik-Seiten vereinheitlichen #6588 Stichtag "Stand: 01.09.2026" auch in berstunden- und Abwesenheitsstatistik anzeigen #6591 berstundenstatistik fr Abteilungsleiter und Freigabe-Verantwortliche #6624 berstundenstatistik: globale Personensuche fehlt #6622