FreshRSS - Package Updates
- 
[1.21.3] - Update FreshRSS to 1.24.3
- Full Changelog
- Fix mark-as-read from user query #6738
- Fix regression for shortcut to move between categories #6741
- Fix feed title option #6771
- Fix XPath for HTML documents with broken root (used by CSS selectors to fetch full content) #6774
- Fix UI regression in Mapco/Ansum themes #6740
- Fix minor style bug with some themes #6746
- Fix export of OPML information for date format of JSON and HTML+XPath feeds #6779
- OpenID Connect better definition of session parameters #6730
 
- 
[1.22.0] - checklist added to CloudronManifest
 
- 
[1.23.0] - Update FreshRSS to 1.25.0
- Full Changelog
- Features
- Bug fixing
- API
- Compatibility
- Deployment
- SimplePie
- Security
- UI
- Extensions
- I18n
- Misc.
 
- 
[1.24.0] - Update FreshRSS to 1.26.0
- Full Changelog
- Add order-by options to sort articles by received date (existing, default), publication date, title, link, random
- Allow searching in all feeds, also feeds only visible at category level with &get=A, and also those archived with &get=Z
- UI accessible from user-query view
- New shortcuts for adding user labels to articles
- Several improvements and bug fixes
 
- 
[1.24.1] - Update FreshRSS to 1.26.1
- Full Changelog
- Fix back-compatibility with cURL 7.51 (we require cURL 7.52+ for CURLPROXY_HTTPS)
- Add cURL version to page about system information
- Fix regression with cURL HTTP headers breaking conditional HTTP requests
- Fix regression with saving states of user queries
- Fix regression with dynamic OPML
- Fix update of the users last activity on login action
- Fix setting category option Maximum number of articles to keep per feed
- Fix priority field when processing a new feed from an extension
- Use case-insensitive sort for categories
- Improve dark mode of Origine theme
 
- 
[1.25.0] - Update base image to 5.0.0
 
- 
[1.25.1] - Update FreshRSS to 1.26.2
- Full Changelog
- Implement JSON string concatenation with & operator #7414
- Support multiple JSON fragments in HTML+XPath+JSON mode #7369
- Fix escaping of tag search #7468
- Fix CLI parsing of Boolean flags #7430
- Fix API for labels with slash #7437
- Fix support for feeds with XML preamble + DTD #7515, simplepie#914
- Disallow <iframe srcdoc="">#7494, CVE-2025-32015
- Disallow <button formaction="">#7506
- Improve favicons hash to avoid favicon pollution #7505, CVE-2025-46339
- Add Content-Security-PolicyHTTP headers to favicons #7471, CVE-2025-31136
 
- 
[1.25.2] - Update FreshRSS to 1.26.3
- Full Changelog
- Keep sort and order criteria during navigation #7585
- Add info about PDO::ATTR_CLIENT_VERSION(relevant for MySQL / MariaDB with obsolete driver) #7591
- Fix SQL request for user labels with custom sort (affecting PostgreSQL) #7588
- Fix regression for favicon in GReader and Fever APIs #7573
- Fix newest articles (within last second) not shown #7577
- Fix duplicate HTTP header for POST #7556
- Fix important articles on reader view #7602
- Fix remove last share method #7613
- Fix API handling of default category #7610
- Fix user self-deletion #7626
 
- 
[1.26.0] - Update FreshRSS to 1.27.0
- Full Changelog
- Implement support for HTTP 429 Too Many Requestsand503 Service Unavailable, obeyRetry-After#7760
- Add sort by category title, or by feed title #7702
- Add search operator c:for categories likec:23,34or!c:45,56#7696
- Custom feed favicons #7646, #7704, #7717, #7792
- Rework fetch favicons for fewer HTTP requests #7767
- Add more unicity criteria based on title and/or content #7789
- Automatically restore user configuration from backup #7682
- API add support for states in sparameter ofstreamId#7695
- Improve sharing via Print #7728
- Redirect to the login page from bookmarklet instead of 403 #7782
 
- 
[1.26.1] - Update FreshRSS to 1.27.1
- Full Changelog
- Automatic database recovery: skip broken entries during CLI export/import #7949
- Add security option for CSP frame-ancestors#7857, #8021
- Lazy-load <track src>#7997
- Regenerate session ID on login #7829
- Disallow setting non-existent language #7878, #7934
- Safer calling of install.php#7971
- Prevent log CR/LF injection #7883
- Restrict allowed cURL parameters #7979, #8009
- Fix reauthentication while updating #7989
- Fix some CSRFs #8000
 
 
