Umami - Package Updates
-
[3.22.3]
- Update umami to 3.0.3
- Full Changelog
- Patch release for the latest Next.js security issue. See https://nextjs.org/blog/security-update-2025-12-11
-
[3.23.0]
- Add optional redis
-
[3.24.0]
- Update umami to 3.1.0
- Full Changelog
- Umami
v3.1.0is here with a ton of new features, including the much-anticipated Boards and Session Replay. This release also brings Web Vitals performance tracking, a redesigned share page, and hundreds of fixes and improvements. - Boards are here! Create your own custom dashboards by composing components on a flexible row/column canvas. Pick from charts, tables, and metric components, bind them to any website, and share the finished board with your team.
- Watch real user sessions replayed in the browser. Session Replay is built on rrweb and works alongside your existing tracker.
- Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from your visitors' browsers. The redesigned Performance page shows industry-standard calculations with rating badges for each metric.
- Fixed IDOR vulnerabilities in reports and segments
- Minimum Node.js version bumped to
22(Prisma 7 requirement) - PostgreSQL 12/13 syntax error in Journeys #3970
- Login email case-sensitivity #3981
BASE_PATHsupport #4064- Migrated from
react-intltonext-intlwith all 51 locale files translated
-
[3.24.1]
- Dynamically set max-old-space-size for nodejs
-
P Package Updates locked this topic on
-
[3.25.0]
- Update umami to 3.2.0
- Full Changelog
- Heatmaps are now available as a first-class website report. Use click and scroll heatmaps to understand where visitors interact with each page, with overlays rendered from captured replay snapshots.
- Invalidates authenticated sessions after password changes
- Sanitizes sensitive data in logs
- Hides internal Prisma and database errors from API responses
- Fixes share token confusion vulnerabilities
- Retention report completeness
- Dashboard and Board editing in Firefox #4168
- Funnel alias issues #4144
- Username login case-insensitivity #3981
- Malformed client IP handling in
/api/send
-
[3.26.0]
- Update umami to 3.3.0
- Full Changelog
- Umami now supports TOTP-based two-factor authentication for self-hosted installs.
- Sessions are now stitched together when a visitor is identified, giving you a complete view of activity across devices and visits.
- Filter your data using session and event properties. #2945 #4008
- Boards can now be cloned, making it easy to duplicate and iterate on dashboards.
- Website, Link, and Pixel tables now display sparklines for a quick visual overview of activity.
- Adding a new website now walks you through installing the tracking code.
- Funnel validation #4434
- Revenue query filtering #4286
- Session modal issues on mobile #4358
- Heatmap and session replay mobile layouts #4417
-
[3.26.1]
- Update umami to 3.3.1
- Full Changelog
- Hardened two-factor authentication when TWO_FACTOR_ENCRYPTION_KEY is missing or invalid, with safer API enforcement and clearer configuration feedback. #4443
- Preserved the root path when REMOVE_TRAILING_SLASH is enabled and reset tracker visit state when a session drifts. #4152
- Fixed event property filtering so fields and values respect the selected event name. #4461
- Preserved events without matching session records and stabilized relational event pagination. #4462
- Improved expanded metrics query performance and fixed funnel steps containing null event values.
- Preserved zero and false values in website value responses.
- Improved handling of username conflicts involving deleted users.
- Added broader coverage for 2FA status, setup, verification, disable, admin, team, and login flows.
- Preserved menu item actions in admin dropdowns. #4453
- Fixed expanded-menu spacing and realtime search bar styling.
-
[3.27.0]
- Update umami to 3.4.0
- Full Changelog
- Umami
v3.4.0is here with new Annotations, MCP support, API key management, a typed API client, session property segments, and security, analytics, and UI improvements. - Chart markers for website annotations
- Save session property filters in segments and combine them with active filters. #4507
- Set a visitor identity through the tracker
data-distinct-idattribute. #4421 - PostgreSQL and ClickHouse timezone inconsistencies. #4541 #3810
- Commas in regular-expression filter values are preserved. #4496
- Reject partial 2FA tokens for authenticated API access
- Bind authenticated sessions to password fingerprints
- This release includes schema migrations for annotations and API keys:
- Self-hosted endpoint disabled by default; set
MCP_ENABLED=1to enable/mcp
-
[3.27.1]
- chore(deps): pin cloudron/node-base docker tag to 40086b1
-
[3.27.2]
- fix base image
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login