Was ist neu?
Aktuelle Beta- und Stable-Releases, automatisch aus den GitHub-Releases generiert.
Stand: 08. Sept. 2026Alle Release-Notes auf GitHub ↗
Aktuelles Stable-Release
v3.46.10
07. Sept. 2026- security: bump sanitize-html to 2.17.7 (0f426ef)
- security: bump sanitize-html to 2.17.7 (stable) (95e3af0)
- setup: require Node 22.12 for sanitize-html (8421b7b)
Aktuelle Beta (main)
v3.130.2-beta.0
08. Sept. 2026- enforce gallery access and consolidate gallery workflows (#1357) (f0e6d2d)
Alle Releases
v3.130.2-beta.0
Beta08. Sept. 2026- enforce gallery access and consolidate gallery workflows (#1357) (f0e6d2d)
v3.130.1-beta.0
Beta08. Sept. 2026- images: probe and clean up preview tiers under the extension the encoder actually wrote (#1355) (acb25a9)
- images: single-flight lazy rendition generation and keep the old rendition during replacement (#1350) (c97341e)
- define security support across stable and main (#1351) (0e459b3)
- refresh repository support and community links (#1349) (f83cbe9)
v3.130.0-beta.0
Beta07. Sept. 2026- watch reference folders and import new files automatically
- external-media: watch reference folders and import new files automatically (#1345) (8cc7d7d)
- events: drop non-canonical keys from the event update before any check runs (#1346) (810801a)
v3.129.0-beta.0
Beta07. Sept. 2026- keep the editor toolbar in reach on long pages
- opt-in recoverable gallery passwords
- cms: keep the editor toolbar in reach on long pages (#1335) (d6a0c4a)
- security: opt-in recoverable gallery passwords (#1341) (fb9da72)
v3.128.0-beta.0
Beta07. Sept. 2026- expose the API rate limiter in the Security tab
- distinguish real edits and template delivery with v5 consent
- settings: expose the API rate limiter in the Security tab (#1338) (8017370)
- usage: distinguish real edits and template delivery with v5 consent (#1339) (5c1e38d)
- email: scrub gallery passwords from the sent-mail archive (#1340) (69754f8)
v3.127.2-beta.0
Beta07. Sept. 2026- security: correct the rate limiter defaults and how they are set (#1336) (9bbdca9)
v3.127.1-beta.0
Beta07. Sept. 2026- usage: stop WebKit collapsing the consent dialog to its header and footer (79eb6d7)
- usage: stop WebKit collapsing the consent dialog to its header and footer (9d18868)
v3.127.0-beta.0
Beta07. Sept. 2026- open the portal signed in, and rewrite the German copy
- open the portal signed in, with the credential never in a served URL
- plain link to the public usage portal, German opt-in copy
- usage: open the portal signed in, and rewrite the German copy (a02fa08)
- usage: open the portal signed in, with the credential never in a served URL (f114f3e)
- usage: plain link to the public usage portal, German opt-in copy (a16ff85)
v3.46.10
Stable07. Sept. 2026- security: bump sanitize-html to 2.17.7 (0f426ef)
- security: bump sanitize-html to 2.17.7 (stable) (95e3af0)
- setup: require Node 22.12 for sanitize-html (8421b7b)
v3.126.3-beta.0
Beta06. Sept. 2026- usage: introduce consented v4 download restriction reporting (5306fe3)
- usage: introduce consented v4 without changing historical reports (ef8a52f)
v3.126.2-beta.0
Beta06. Sept. 2026- gallery: release grid tiles once they are far enough out of view (b3937d0)
- gallery: retry a failed image fetch once the tile is back on screen (c4b03a8)
- gallery: retry a failed image fetch once the tile is back on screen (77ae94e)
v3.126.1-beta.0
Beta06. Sept. 2026- usage: preserve compatibility with old and partial reports (b801f3a)
- usage: preserve report contracts with compatible receiver validation (7ca783f)
v3.126.0-beta.0
Beta06. Sept. 2026- add beta capabilities and gallery/photo totals with explicit consent
- usage: add beta capabilities and gallery/photo totals with explicit consent (b0bb65d)
v3.125.0-beta.0
Beta06. Sept. 2026- add opt-in product usage and feedback
- expand opt-in capability coverage with versioned consent
- add opt-in product usage and feedback (#1110) (35b42bb)
- expand opt-in capability coverage with versioned consent (a738259)
- usage: close the QA findings on opt-in product usage (1e8b6f1)
- usage: let an operator clear a participation the collector never accepted (e40bc47)
v3.124.1-beta.0
Beta05. Sept. 2026- remove the fragmentation handling stranded by #1303 (5dda14f)
v3.124.0-beta.0
Beta05. Sept. 2026- warn about deliverability before a large send
- newsletters: warn about deliverability before a large send (0536c86)
- newsletters: warn about deliverability before a large send (49197be)
- gallery: give the Grid layout a lazy-loading pre-load band (#1287) (b1e5287)
- gallery: image-loading follow-ups — pre-load band, decode release, sanitizer dedup (905fc59)
- gallery: release the canvas decode when it is drawn, not at unmount (fbe9757), closes #1287
v3.123.0-beta.0
Beta04. Sept. 2026- newsletter campaigns behind a newsletters flag
- global signature footer from the business profile
- crm: newsletter campaigns behind a newsletters flag (#1264) (fc59540)
- email: global signature footer from the business profile (#1264) (b6e40b9)
- cms: enable the Tailwind typography plugin so prose classes work (#1288) (de3a7f7)
- gallery: bound concurrent image fetches and abort them on unmount (#1287) (4afe7a6)
v3.122.7-beta.0
Beta03. Sept. 2026- security: batch 1 — zxcvbn DoS, revocation forgery, unlink traversals, stored Content-Type, edge middleware (ea394b5)
- security: bound password input before zxcvbn, and drop the legacy media mounts (14cd5ea)
- security: chunked-upload init checks the size cap before the type allow-list (0ac006b)
- security: close four middleware gaps around the API edge (839bf4e)
- security: contain logo, favicon and PDF-logo unlinks to their upload directories (3e46530)
- security: enforce the strength-endpoint validators, and stop the generator spinning (054cd6f)
v3.122.6-beta.0
Beta03. Sept. 2026- gallery: follow the input in use, not the device's primary pointer (#1275) (a87e688)
v3.46.9
Stable03. Sept. 2026- security: batch 1 (stable) — zxcvbn DoS, revocation forgery, unlink traversals, stored Content-Type, edge middleware (3f90221)
- security: bound password input before zxcvbn, and drop the legacy media mounts (ed08ff8)
- security: close three middleware gaps around the API edge (b136906)
- security: contain logo, favicon and PDF-logo unlinks to their upload directories (882101b)
- security: enforce the strength-endpoint validators, and stop the generator spinning (706d402)
- security: harden four smaller gallery and contract paths, drop the unmounted photo auth middleware (d81cade)
v3.122.5-beta.0
Beta02. Sept. 2026- crm: label the two invitation conflicts and stop guessing after a 5xx (bc90b4d)
- crm: stop the invitation UI claiming more than it can know (6bb12c6)
- crm: tell the admin whether a customer's invitation actually went out (1b8e5f8)
- crm: tell the admin whether a customer's invitation actually went out (#1261) (b9c29fc)
- email: compare queue timestamps in JS, and make retry actually send (89db469)
- email: make waiting rows read-only, and time the grace from when due (4deac22)
v3.122.4-beta.0
Beta02. Sept. 2026- guests: keep guest identity across a tab close (#1265) (f722bda)
v3.122.3-beta.0
Beta02. Sept. 2026- accounting: allow creating a customer from the picker (be39929)
- accounting: let "bill to a customer" work with the portal off (3790156)
- admin: interpolate activity and notification message values (78b1ddd)
- admin: portal the update-available modal to document.body (ac50f0b)
- analytics: serve self-hosted trackers same-origin so CSP stops blocking (3468550)
- analytics: warn about the CSP allowlist on every tracker provider (3489610)
v3.122.2-beta.0
Beta01. Sept. 2026- upload: let Android guests reach the camera without breaking video (#1244) (66989d7)
v3.122.1-beta.0
Beta01. Sept. 2026- archives: restore categories for original-filename archives on main too (#1252) (a35d2ba)
- events: apply the gallery password policy to publish and send-later (#1253) (6938bad)