NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4006 most downloaded on Packagist
Delightfully simple forum software.
Last release 20 days ago
17 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Most releases are documented
notes for 26 of 42 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
80 releases · first in 2015
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.8/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.8/CHANGELOG.md
cache:clear instead of on the next request by @imorland [#4990]conf.d by @imorland [#4991]ItemList.toArray() coercing null content to an empty object, which crashed PageStructure without a sidebar by @imorland [#5000]One column per quarter.
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.7/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.7/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.6/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.6/CHANGELOG.md
tinker command for an interactive REPL by @imorland [#4829]$onQueue by @imorland [#4853]RoutingQueue when identifying the queue driver by @imorland [#4855]ext:flarum/flags typings path in the realtime tsconfig by @imorland [#4858]DetailedDropdownItem check and option icons overlapping in phone dropdown menus by @karl-bullock [#4822]User instance by @imorland [#4839]queue:resume with no argument clearing every pause by @imorland [#4844]ColorPreviewInput instead of coercing to black by @imorland [#4856]currentTag cache against the current route's slug by @imorland [#4860]user.viewLastSeenAt in the typing indicator by @ekumanov [#4880]ondismiss when an alert is dismissed by @imorland [#4899]Input in the common export manifest by @imorland [#4929]Utf8SlugDriver::fromSlugs() by @imorland [#4940]Button--text dropdown toggles on hover by @imorland [#4950]See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.5/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.5/CHANGELOG.md
show_language_selector setting by @imorland [#4792]page[limit]=0 is requested by @linkrobins [#4775]role attribute to PostStream items by @claudiushenrichs [#4780]See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.4/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.4/CHANGELOG.md
MariaDB to the frontend DatabaseDriver enum by @DavideIadeluca [#4701]TagLinkButton to TSX with an extensible linkItems list by @imorland [#4755]Flag::$reason and $reason_detail as nullable by @imorland [#4760]TypeError when creating a user with a nickname by @imorland [#4734]ExtensionPage by @DavideIadeluca [#4747]editCredentials check by @imorland [#4729]See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.3/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.3/CHANGELOG.md
QueueFactory by @imorland [#4683]img.emoji to avoid layout shift (CLS) by @imorland [#4685]TypeError on a null connection name with illuminate/queue 13.15+ by @imorland [#4700]flarum/realtime as an optional dependency so the realtime extender loads before its consumers, fixing TypeError: mt(...) is not a constructor by @imorland [#4699]group_user queries when serializing users by @imorland [#4696]See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.2/CHANGELOG.md
See the changelog: https://github.com/flarum/framework/blob/v2.0.0-rc.2/CHANGELOG.md
AbstractJob by @imorland [#4656]QueueFactory::getPausedQueues() for illuminate/queue v13.11+ compatibility by @forumaker [#4673]text-overflow: ellipsis on long button labels by @imorland [#4628]UserResource groups relationship to viewable groups by @imorland [#4629]getHidden() to the Log\Context\Repository stub by @imorland [#4633]ModelNotFoundException logs on orphaned queued jobs by @imorland [#4634]VersionerInterface from the container and cache rev-manifest reads by @imorland [#4638]srcsetFor() filesystem calls by @imorland [#4639]flarum-assets disk by @imorland [#4640]NotificationSyncer by @imorland [#4647]TypeError in the Revised event when post content is NULL by @imorland [#4648]UserSecurityPage crash when the user loads asynchronously by @datlechin [#4651]TextEditor.onbuild race against async Mithril redraw by @imorland [#4657]PATCH responses and route title changes via rename() by @imorland [#4658]Extend\SearchDriver class-string types to SearcherInterface by @imorland [#4668]EloquentBuffer against orphaned/mock models by @imorland [#4669]joined_at in realtime:info by @imorland [#4630]lives:2 budget by @ekumanov [#4654]visibilitychange by @imorland [#4662]'undefined' from the Inappropriate reason and lazy-load FlagPostModal by @imorland [#4659]Schema\Str by @imorland [#4599]JsDirectoryCompiler when the file extension already matches by @imorland [#4632]Full Changelog : v2.0.0-beta.7...v2.0.0-rc.1
Full Changelog: v2.0.0-beta.7...v2.0.0-rc.1
DELETE /api/settings and Settings\Event\Reset by @imorland [#4522]forum-widget extension category by @imorland [#4543]avatarSrcset on the user resource by @imorland [#4555]Realtime::authorizePresenceChannel extender for gating presence-channel access by @imorland [#4573]vendor/package format by @imorland [#4510]Api\Serializer attribute fields now run through serializeValue so booleans no longer serialize as strings by @imorland [#4530]PaginatedListState::paramsChanged() uses value comparison so back-navigation preserves loaded pages and scroll by @imorland [#4532]ReplyPlaceholder composing state on mobile by @imorland [#4533]Attribute::serializeValue to avoid "Array to string conversion" for extensions returning arrays from Str-typed attributes by @imorland [#4534]@hasSection directive, Checkbox inputAttrs, FormGroup Switch aria-describedby by @imorland [#4562]UserCard so the mobile controls button is visible by @imorland [#4568]name in FormGroup so multiple radio groups can coexist by @rafaucau [#4571]display on hidden icon elements by @imorland [#4575]AbstractImageValidator by @luceos [#4579]StatusWidget mobile layout on the dashboard by @imorland [#4531]id column in is_unread_sticky subquery so extensions that join discussions no longer break by @imorland [#4520]hasPermission for bypassTagCounts so the permission works for non-admins on restricted tags by @imorland [#4539]_.template code-injection fixes by @dependabot [#4515] [#4516] [#4517] [#4523]notifications to fix slow unread-count queries by @imorland [#4509]fetchpriority, FOUC fix, viewport by @imorland [#4561]TagFilter by @imorland [#4563](realtime) extender API, per-extension integrations, and notification toasts by @imorland [#4473]
IdWithDisplayNameSlugDriver by @imorland [#4470]ResponseFactory by @imorland [#4461]CloseWatcher API for modals and dropdowns by @imorland [#4433]Hero component by @imorland [#4215]EmailSendFailed event by @imorland [#4385]method_not_allowed translation for error view by @imorland [#4418]Less_Tree_Keyword for boolean custom Less functions by @imorland [#4406]Uncaught ReferenceError for async default exports by @imorland [#4397]--page-bottom-padding CSS variable in App by @imorland [#4438]HasFormattedContent and mentions unparsers by @imorland [#4452]src/boostrap/ to src/bootstrap/ and update all imports by @imorland [#4413]DialogMessage after create to resolve number expression by @imorland [#4384]content attr type to Alert component by @rafaucau [#4495]fire ApplicationBooted event after all service provider boot callbacks complete by @imorland [#4366]
ApplicationBooted event after all service provider boot callbacks complete by @imorland [#4366]gotoItem in SearchModal to prevent crash by @imorland [#4376]container prop to fix notification button tooltip positioning by @imorland [#4375]GeneralSearchSource by @imorland [#4373]color-scheme property to root.less for better dark-mode support by @zDaleZ [#4357]highlight abandoned packages, expose PHP info by @imorland [#4323]
(realtime) donate Realtime extension to Flarum Foundation by @luceos [#4295]
DiscussionListItem by @DavideIadeluca [#4303](a11y) improve a11y of avatar with no avatarUrl by @DavideIadeluca [#4248]
PostUser by @imorland [#4252](a11y) misc a11y improvements by @SychO9 [#4211]
PostStreamScrubber to be customized by @DavideIadeluca [#4181]IndexPage by @DavideIadeluca [#4182]PostMeta component by @DavideIadeluca [#4196]Tag (#4170) by @rob006 (15112c2f40656db8c310945e6c7255b90570379f)audit-fix by @SychO9 (fbe7be69ef573d0d39f70454bfd02ab94857db8a)TagHero by @DavideIadeluca [#4198]PostPreview content by @DavideIadeluca [#4197]WelcomeHero by @DavideIadeluca [#4199]unread label is shown in Scrubber by @DavideIadeluca [#4185]aria-posinset by @DavideIadeluca [#4191]a11y warnings in Admin Frontend by @DavideIadeluca [#4184]sendmail driver fails by @SychO9 [#4168]suspended_until serialized as date instead of datetime by @SychO9 [#4169](em) incorrect extension compatibility check [#4155]
Patch vulnerability advisory [#3966]
intervention/image to 3.2 [#3947].fa() mixins and @fa-var vars [#3912]FormModal from Modal [#3922]buildSettingComponent method into a FormGroup component [#3927]HeaderPrimary.js converted to typescript [#4052]format-message [#4088]::class syntax to fetch class name instead of get_class() function [#3910]hex_color rule for color validation [#3936]str_contains instead of strpos [#3841]PostWasApproved event triggered incorrectly [#3930]relationships (1ead69e9b66ae9bc335be663498b7ea706adbf73)::class attribute for schedule [#3903]SettingDropdown and SelectDropdown [#3854]mentionsUsers in extend.php (2b56129d70d18686a73d044ff65b418eef83f388)UserSearchResult to common (35f76bce60361caac8001c41c421de30f567b221)aria-hidden=false might cause inconsistent behavior [#4074]WelcomeHero extensible [#3848]PgSQL [#3985]SQLite [#3984]MariaDB driver [#4132]Notification extender [#3974]whenExtensionDisabled to Conditional extender [#3847]FLARUM_START constant [#4082]flarum/installation-packages on release [#3625]Full Changelog : 1.8.19...v1.8.20
Full Changelog: 1.8.19...v1.8.20
Full Changelog : v1.8.18...1.8.19
Full Changelog: v1.8.18...1.8.19
Full Changelog : v1.8.17...v1.8.18
Full Changelog: v1.8.17...v1.8.18
Full Changelog : v1.8.16...v1.8.17
Full Changelog: v1.8.16...v1.8.17
Full Changelog : v1.8.15...v1.8.16
Full Changelog: v1.8.15...v1.8.16
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
recover temporary solution for html entities in browser title
null as 2nd param in preg_match is deprecated [#3801]
wrote string [#3809]UserSecurityPage not exported (232618a)isDark() utility can receive null value [#3774]comment_count [#3790]preg_match is deprecated [#3801]mentionedBy post relation results [#3780]likes relationship results [#3781]install and update interfaces [#3797]Revised event [#3789]Nothing published for this version
(tags) composer tag selection modal using wrong primary max & min numbers
remove use of deprecated phpunit assertion
Model extender [#3646]id can be ambiguous in group filter with extensions [#3696].Post-actions [#3675]compat.ts [#3683]yarn audit-fix (8ddb0fe)yarn (ee1e04c)Dropdown components to TS [#3608]@flarum/jest-config for release (748cca6)Post mentions can be used to read any post on the forum without access control (ab1c868b978e8b0d09a5d682c54665dae17d0985).
XSS Vulnerability in core (https://github.com/flarum/framework/pull/3684).
JS dependencies update breaks utilities.
(approval) posts approved for deleted users error
yarn format (c5c312d)LogInValidator [#3670]ForgotPasswordValidator [#3671]ColorPreviewInput for GroupModal color input [#3650]remove deprecation warning for decoding null values
aria-busy when editing a post stream item [#3521]id of null user relation [#3618]$events property declared dynamically [#3598]src folder [#3549].fa() mixin usage with .fas() [#3537]loading="lazy" attribute for avatars [#3578]AlertManager IndexPage and UserPage components to TS [#3536]Badge Checkbox and Navigation components to TS [#3532]push and pull_request actions at the same time [#3597]MySQL 8.0 & PHP 7.3 to workflows [#3595]flarum/action-build) [#3573]isCollapsed instead of rangeCount [#3581]Nothing published for this version
created_at and updated_at columns added to several tables
created_at and updated_at columns added to several tables (https://github.com/flarum/framework/pull/3435)app.translator allows retrieving and setting locale (https://github.com/flarum/framework/pull/3451)buildSettingComponent (https://github.com/flarum/framework/pull/3494)rel and target attributes on links (https://github.com/flarum/framework/pull/3455)assertAdmin tests access based on wrong gate ability (https://github.com/flarum/framework/pull/3501)created_at (https://github.com/flarum/framework/pull/3506)UserCard now has ItemList for easier extending
<!-- One-time commit-based diff due to monorepo rework. Diffing against the 1.2.1 tag doesn't work due to unrelated histories. -->
Deprecations are triggered on PHP 8.1
From v1.2.1 on all bundled Flarum extensions and flarum/core are merged into one monorepo. As a result of this, the full code diff linked above
looks rather complex and messy compared to the full list of changes made for this release.
Post--by-start-user CSS class is not added to post html (https://github.com/flarum/framework/pull/3356)Don't escape single quotes in discussion title meta tags
View README documentation in extension pages (https://github.com/flarum/framework/pull/3094).
README documentation in extension pages (https://github.com/flarum/framework/pull/3094).textarea setting type to admin pages (https://github.com/flarum/framework/pull/3141).Less config vars through Settings Extender (https://github.com/flarum/framework/pull/3011).Less custom function extender with a is-extension-enabled function (https://github.com/flarum/framework/pull/3190).few in ICU Message syntax (https://github.com/flarum/framework/pull/3122).loadWhere relation eager loading extender (https://github.com/flarum/framework/pull/3116).StatusWidget tools extensibility (https://github.com/flarum/framework/pull/3189).ImageManager driver (https://github.com/flarum/framework/pull/3195).listItems helper (https://github.com/flarum/framework/pull/3147).for ... in with Array.reduce (https://github.com/flarum/framework/pull/3149).aria-label attribute to the navigation drawer button (https://github.com/flarum/framework/pull/3157).ItemList typings (https://github.com/flarum/framework/pull/3005).@php in Blade templates (https://github.com/flarum/framework/pull/3172).colorItems to an ItemList (https://github.com/flarum/framework/pull/3186).primaryControl items to an ItemList (https://github.com/flarum/framework/pull/3204).aria-live regions to focus screenreader attention on alerts as they appear (https://github.com/flarum/framework/pull/3237).a11y warnings on custom Button subclasses (https://github.com/flarum/framework/pull/3238).typeof this not recognized by some IDEs (https://github.com/flarum/framework/pull/3142).Model.save() cannot save null hasOne relationship (https://github.com/flarum/framework/pull/3131).until reply policy broken on PHP 8 (https://github.com/flarum/framework/pull/3145).Component.component argument typings (https://github.com/flarum/framework/pull/3148).maxfiles argument incorrectly (bfd81a83cfd0fa8125395a147ff0c9ce622f38e3).Activated event is sent every time an email is confirmed instead of just once (https://github.com/flarum/framework/pull/3163).Post--by-actor not showing when comparing user instances (https://github.com/flarum/framework/pull/3170).hide() method (https://github.com/flarum/framework/pull/3180).Post-actions (https://github.com/flarum/framework/pull/3185).getPlainContent() causes external content to be fetched (https://github.com/flarum/framework/pull/3193).listItems not accepting all Mithril.Children (https://github.com/flarum/framework/pull/3176).WelcomeHero is displayed when content is empty (https://github.com/flarum/framework/pull/3219).last_activity_at, last_seen_at updated on all API requests (https://github.com/flarum/framework/pull/3231).RememberMe access token updated twice in API requests (https://github.com/flarum/framework/pull/3233).funding item in composer.json bricks the frontend (https://github.com/flarum/framework/pull/3239).schedule:list command fails due to missing timezone configuration.evented utility (https://github.com/flarum/framework/pull/3125).Performance issue with very large communities.
Info command now displays MySQL version, queue driver, mail driver
preload extender (https://github.com/flarum/framework/pull/3057)<Select> to be passed through to the DOM element (https://github.com/flarum/framework/pull/2959)ItemList for DiscussionPage content (https://github.com/flarum/framework/pull/3004)@lhsazevedo, @Ornanovitch, @pierres, @the-turk, @iPurpl3x
@uamv, @dannyuk1982, @BurnNoticeSpy, @haarp, @peopleinside, @matteocontrini
Upgrade to v1.0 resets the "view" permission on all tags
Adopt huntr.dev for handling our security vulnerability reports
### Fixed - Critical XSS vulnerability
Installation fails on environments without proc_* functions enabled or mysql client binary
load() method on ApiController extender to allow eager loading of relations
load() method on ApiController extender to allow eager loading of relations (https://github.com/flarum/framework/pull/2724)unparse method to allow extensions to hook into the unparsing of content (https://github.com/flarum/framework/pull/2780)insertText and styleSelectedText from markdown to core (https://github.com/flarum/framework/pull/2826)migrations table now has an Auto Increment ID (https://github.com/flarum/framework/pull/2794)php flarum assets:publish) from migrating (https://github.com/flarum/framework/pull/2731)<asset>-<revision>.<js|css>, this is now <asset>.<js|css>?v=<revision> (https://github.com/flarum/framework/pull/2805)headers (https://github.com/flarum/framework/pull/2777)viewDiscussions to viewForum and viewUserList to searchUsers (https://github.com/flarum/framework/pull/2854)Component.$() isn't really required (https://github.com/flarum/framework/pull/2844)make:migration command has been removed (https://github.com/flarum/framework/pull/2686)mail key is removed from the laravel related config (https://github.com/flarum/framework/pull/2796)Deprecated CSRF wildcard path match
X-Powered-By header added to allow indexers easier data aggregation of Flarum adoption (https://github.com/flarum/framework/pull/2618)mutate method on ApiSerializer extender to attributes (https://github.com/flarum/framework/pull/2578)TextEditor is moved to the common namespace for use in the admin frontend (https://github.com/flarum/framework/pull/2649)user gambit with author gambit (612a57c)disallowed (https://github.com/flarum/framework/pull/2585)AccessToken::find, use AccessToken::findValid instead (https://github.com/flarum/framework/pull/2651)GetModelIsPrivate event (https://github.com/flarum/framework/pull/2587)CheckingPassword event (https://github.com/flarum/framework/pull/2176)event() helper (https://github.com/flarum/framework/pull/2608)AccessToken::generate argument $lifetime (https://github.com/flarum/framework/pull/2651)Rememberer::remember argument $token should receive an instance of RememberAccessToken with AccessToken being deprecated (https://github.com/flarum/framework/pull/2651)Rememberer::rememberUser (https://github.com/flarum/framework/pull/2651)SessionAuthenticator::logIn argument $userId, should be replaced with AccessToken (https://github.com/flarum/framework/pull/2651)TextEditor has been moved to common (https://github.com/flarum/framework/pull/2649)UserFilter (91e8b56)Deprecated user events GetDisplayName and PrepareUserGroups (https://github.com/flarum/framework/pull/2428).
app.discussions being empty (https://github.com/flarum/framework/commit/102e76b084bf47fdfb4c73f95e1fbb322537f7aa).goToIndex in PostStream does not trigger an xhr to retrieve new data (https://github.com/flarum/framework/commit/09e2736cbcc267594b660beabbd001d9030f9880).GetDisplayName and PrepareUserGroups (https://github.com/flarum/framework/pull/2428).CheckingForFlooding (https://github.com/flarum/framework/commit/8e25bcb68f86cc992c46dfa70368419fe9f936ac).Your coding agent can read these notes before it upgrades. Set up the MCP server →