Rallly - Package Updates
-
[2.12.1]
- Update rallly to 4.12.1
- Full Changelog
- Prevent false success screen when participant submission fails (#2849)
- Show participant friendly error messages on failed submissions (#2850)
- Fix icon hover color in space settings sidebar menus (#2856)
- Reset participant selection when a participant is deleted on mobile poll (#2862)
- Pass i18n to server-side Trans to prevent cross-request language leaks (#2871)
-
[2.12.2]
- Update rallly to 4.12.2
- Full Changelog
- Fix internal server error when re-activating an installed license key (#2883)
- Close the license dialog when a key is activated (#2884)
- Keep focus in the document after activating a license, instead of dropping it to the page body (#2884)
-
[2.12.3]
- Update rallly to 4.12.3
- Full Changelog
- Honor HTTP_PROXY/HTTPS_PROXY for outbound fetch (#2897)
- Never proxy loopback traffic and exempt the container healthcheck (#2901)
- Assemble calendar dates from formatToParts for small-ICU builds (#2900)
- Fix doubled "v" prefix on the control panel version tile (#2887)
-
[2.13.0]
- Update rallly to 4.13.0
- Full Changelog
- Custom branding from the control panel: upload your logo and wordmark (SVG supported) through a new branding page. Settings are stored in the database, with existing env vars as fallback. White-labeling docs updated to match. (#2916, #2918, #2946, #2951)
- Configurable footer links: instance admins can add custom links (imprint, privacy policy, etc.) that appear on auth, poll and invite pages. (#3030)
- Mobile voting redesign: new voting footer with explicit "no" responses, redesigned vote icons, and comments moved into a sheet opened from a floating trigger. (#2903, #2893, #2879)
- Calendar and ICS download on the events page: add scheduled events to your calendar or download an ICS file. (#3024)
- Channel-aware update check: the version check now respects release channels and shows a notice when a new major version is available. (#2983)
- Members page redesign: members moved from settings into the main navigation with a new list design. (#2923, #2929)
- Reject
localhost, IP addresses and dotless hostnames as the cookie domain, preventing a class of login loops on misconfigured instances. (#2941) - Restored 6 missing time zones and updated the time zone picker to show modern city names. (#3035)
- Public calendar feeds no longer include stale, deleted or cancelled events. (#3027)
- Changing your email no longer fails silently when the address is already in use. (#2970)
-
[2.13.1]
- Update rallly to 4.13.1
- Full Changelog
- Upgrade Next.js to 16.3.3 for the August 2026 security release (#3073)
-
[2.14.0]
- Update rallly to 4.14.0
- Full Changelog
- Enforce instance branding when the white label add-on is active (#3125)
- Add List-Unsubscribe headers and tokenized per-poll unsubscribe (#3148)
- Show role permissions in the invite member dialog (#3116)
- Activity log: event vocabulary and writes from every poll mutation (#3076)
- Add cookie consent banner, shown only when analytics are configured (#3114)
- Require both
SMTP_USERandSMTP_PWDfor authenticated SMTP (#3064) - Unshare single-member spaces wrongly marked shared by backfill (#3118)
- Restore dark mode muted text hierarchy on popover surfaces (#3084)
- Fix muted icon color on the invite member button (#3097)
- Comments: fix mobile footer overlap and polish the sheet (#3082)
-
[2.15.0]
- Update rallly to 4.15.0
- Full Changelog
- Who this affects: instances using Microsoft sign-in on a multi-tenant endpoint which is the default.
MICROSOFT_TENANT_IDdefaults tocommon, so this applies unless you have set it to your own tenant ID. Instances set to a single tenant are unaffected, as are OIDC and Google. - On a multi-tenant endpoint any tenant can assert any email address, so Rallly now needs Microsoft to confirm an address before creating an account from it. Microsoft only sends that confirmation if the app registration asks for it.
- This release does not break these sign-ins. If the claims are missing, Rallly still creates the account and logs a warning. A future release will refuse them. Add the claims now so that release is uneventful:
- Full instructions: https://support.rallly.co/self-hosting/single-sign-on#microsoft
- In previous versions, responses were soft-deleted. In this release responses are hard-deleted and previously soft-deleted responses are purged. Back up before upgrading.
- This release contains several security fixes. Upgrading is recommended. Advisories with full details, affected versions and credit to the reporters will follow shortly.
- Hosts can now invite participants by email from the Share dialog: send personal invite links, copy an invitee's link, remove a pending invite, and see when a link has been opened.
- Every response now carries an edit token, so the link in a confirmation email edits exactly the response it names. Hosts can still copy the invite link and hand it to someone who responded without leaving an email address.
- Full Changelog: https://github.com/lukevella/rallly/compare/v4.14.0...v4.15.0
-
[2.15.1]
- Update rallly to 4.15.1
- Full Changelog
- Send login code emails in the requester's language (#3275)
-
[2.15.2]
- Update rallly to 4.15.2
- Full Changelog
- Decouple registration from email login (#3337)
-
[2.15.3]
- Update rallly to 4.15.3
- Full Changelog
- Resolve Alberta, Manitoba and BC time zones consistently across engines (#3396)
- Link OIDC sign-ins to existing users by email (#3407)
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login