PackageTrack
Sign in Get early access

github.com/gtsteffaniak/filebrowser

v0.3.4 #513 most downloaded on Go modules gtsteffaniak/filebrowser

What this package is like to depend on

Last release 2 days ago

22 Aug 2026

Ships on a steady schedule

a new release about every 9 days

Nearly every release is documented

notes for 15 of 15 stable releases

Nothing withdrawn

no release was ever pulled

3 years old

345 releases · first in 2023

244 releases in the last 12 months

see the full history below

Release timeline

345 releases · Jun 2023 to Aug 2026
2024 2025 2026
Release Pre-release

Releases

latest 60 of 345
  1. v2.0.1-beta+incompatible 15 Aug 2026 pre-release

    Nothing published for this version

  2. v2.0.0-preview-5+incompatible 05 Aug 2026 pre-release

    Nothing published for this version

  3. v2.0.0-preview-4+incompatible 02 Aug 2026 pre-release

    Nothing published for this version

  4. v2.0.0-preview-3+incompatible 24 Jul 2026 pre-release

    Nothing published for this version

  5. v2.0.0-preview-2+incompatible 24 Jul 2026 pre-release

    Nothing published for this version

  6. v2.0.0-preview-1+incompatible 23 Jul 2026 pre-release

    Nothing published for this version

  7. v2.0.0-beta+incompatible 07 Aug 2026 pre-release

    Nothing published for this version

  8. v1.5.5-beta 07 Aug 2026 pre-release
    Release notes

    What's Changed

    BugFixes:

    • fix uncustomized (minimal) API tokens creation needed by webdav clients (#2503)

    Full Changelog: v1.5.4-beta...v1.5.5-beta

    Open source →
    Release notes

    v1.5.5-beta

    Compare

    Choose a tag to compare

    Open source →
  9. v1.5.4-beta 02 Aug 2026 pre-release
    Release notes

    What's Changed

    Full Changelog: v1.5.3-beta...v1.5.4-beta

    Open source →
    Release notes

    v1.5.4-beta

    Compare

    Choose a tag to compare

    Open source →
  10. v1.5.3-stable 22 Aug 2026 pre-release
    Release notes

    What's Changed

    BugFixes:

    • windows backslash inserted into directory URLs causing malformed paths and path escapes from parent (#2815) (#2816)
    • root download of a shared file/folder returns HTTP 500 (#2807) (#2810) (#2821) (#2818)
    • OnlyOffice is inaccessible if share has optional password (#2811)

    Full Changelog: v1.5.2-stable...v1.5.3-stable

    Open source →
    Release notes

    v1.5.3-stable Latest

    Latest

    Compare

    Choose a tag to compare

    Open source →
  11. v1.5.3-beta 31 Jul 2026 pre-release
    Release notes

    What's Changed

    BugFixes:

    • fix probe canShare with the real file, not a fixed text/plain stand-in (#2664)
    • When the logout button is pressed, the user is redirected to an invalid URL that does not honor baseURL / externalUrl (#2657)
    • fix redirect to login when an authenticated request returns 401 (expired session) (#2679)

    New Contributors

    Full Changelog: v1.5.2-beta...v1.5.3-beta

    Open source →
    Release notes

    v1.5.3-beta

    Compare

    Choose a tag to compare

    Open source →
  12. v1.5.2-stable 15 Aug 2026 pre-release
    Release notes

    What's Changed

    Security:

    • [High] Symlink following on read paths no longer escapes source or user/share scope (GHSA-mgqf-5mf5-prfj) -- thanks @je-lv @KasperBuilds
    • [High] Share create/update could set delete/modify/create flags beyond the owner's permissions; POST /api/share with hash could update another user's share (GHSA-x79q-5hqm-x839) -- thanks @pant0m
    • [High] PATCH /api/share could re-point a share outside the owner's scope (GHSA-wfjp-qhvc-69wp) -- thanks @maximeborges
    • [High] Public upload ACL check used scope-stripped path, bypassing per-folder DENY rules (GHSA-qv53-4557-m65h) -- thanks @hypnguyen1209
    • [Moderate] Absolute paths in API path/file parameters could bypass user scope and read files outside the source mount (GHSA-rqqq-wv83-rp74) -- thanks @Wei-Leo
    • [Moderate] Authenticated upload and pause endpoints checked access rules on scope-relative paths, bypassing per-folder DENY rules (GHSA-cw65-p35p-633w) -- thanks @5ud0er
    • [Moderate] Logout did not invalidate session JWTs with equivalent Base64URL spellings (GHSA-8m35-wcjh-95q7) -- thanks @corbanvilla @soh3e @dderpym (This vulnerability was discovered as part of a U.C. Berkeley security research project by: Corban Villa, Sohee Kim, and Austin Chu)
    • [Moderate] Stored XSS via unsanitized DOCX hyperlink in DocViewer (GHSA-9wm6-jcjh-3m8c) -- thanks @karen93shieh @je-lv @EclipsSec
    • [Moderate] Revoked JWTs could still authenticate on public-share and withOrWithoutUser routes until natural expiry, bypassing logout and Api-permission revocation on that surface (GHSA-4wmj-rq3c-m65v) -- thanks @hypnguyen1209

    Full Changelog: v1.5.1-stable...v1.5.2-stable

    Open source →
    Release notes

    v1.5.2-stable

    Compare

    Choose a tag to compare

    Open source →
  13. v1.5.2-beta 17 Jul 2026 pre-release

    Nothing published for this version

  14. v1.5.1-stable 07 Aug 2026 pre-release
    Release notes

    What's Changed (since the last stable v1.5.0)

    Notes:

    • PWA installation name now capped at 30 characters instead of 12 (#2699)

    BugFixes:

    • fix forward slash blocked in text fields when the search shortcut listener intercepts / (#2696)
    • fix probe canShare with the real file, not a fixed text/plain stand-in (#2664)
    • When the logout button is pressed, the user is redirected to an invalid URL that does not honor baseURL / externalUrl (#2657)
    • fix redirect to login when an authenticated request returns 401 (expired session)
    • fix uncustomized (minimal) API tokens creation needed by webdav clients (#2503)

    Full Changelog: v1.5.0-stable...v1.5.1-stable

    Open source →
    Release notes

    v1.5.1-stable

    Compare

    Choose a tag to compare

    Open source →
  15. v1.5.1-beta 11 Jul 2026 pre-release

    Nothing published for this version

  16. v1.5.0-stable 17 Jul 2026 pre-release

    Nothing published for this version

  17. v1.5.0-beta 13 Jun 2026 pre-release

    Nothing published for this version

  18. v1.4.4-beta 10 Jun 2026 pre-release

    Nothing published for this version

  19. v1.4.3-beta 10 Jun 2026 pre-release

    Nothing published for this version

  20. v1.4.2-beta 22 May 2026 pre-release

    Nothing published for this version

  21. v1.4.1-beta 14 May 2026 pre-release

    Nothing published for this version

  22. v1.4.0-stable 10 Jun 2026 pre-release

    Nothing published for this version

  23. v1.4.0-beta 13 May 2026 pre-release

    Nothing published for this version

  24. v1.3.10-beta 05 May 2026 pre-release

    Nothing published for this version

  25. v1.3.9-beta 01 May 2026 pre-release

    Nothing published for this version

  26. v1.3.8-beta 29 Apr 2026 pre-release

    Nothing published for this version

  27. v1.3.7-beta 25 Apr 2026 pre-release

    Nothing published for this version

  28. v1.3.6-beta 20 Apr 2026 pre-release

    Nothing published for this version

  29. v1.3.5-beta 18 Apr 2026 pre-release

    Nothing published for this version

  30. v1.3.4-beta 11 Apr 2026 pre-release

    Nothing published for this version

  31. v1.3.3-stable 18 May 2026 pre-release

    Nothing published for this version

  32. v1.3.3-beta 02 Apr 2026 pre-release

    Nothing published for this version

  33. v1.3.2-stable 14 May 2026 pre-release

    Nothing published for this version

  34. v1.3.2-beta 21 Mar 2026 pre-release
    Release notes

    Security:

    • Patched Username Enumeration via Authentication Timing Side-Channel GHSA-7789-65hx-f26w

    New Features:

    • Option in settings userDefaults.preferEditorForMarkdown to prefer editor first for Markdown files (#2136)
    • Copy to clipboard button for code blocks in Markdown Viewer (#2160)
    • Add "Last modified" filter in search dialog (#2157)

    Notes:

    • docs preview for text and pdf has a 2 second timeout. If it hangs for whatever reason, the maximum time would be 2 seconds. (#2105) (#2114)
    • Downloading multiple files streams the archive creation rather than using cacheDir -- thanks @janakoram (#2125) (#2130)
      • server.maxArchiveSizeGB now defaults to 20 (GB) and only applies to archive/unarchive actions (not downloads).
      • browser download progress bar will no longer show for archive downloads. this is the main drawback to the streaming approach.
      • should allow for much higher parallel download support and lower cleanup maintenenance.
    • [docker] ffmpeg version upgraded to 8.1
    • remote ip in logs now prefers X-Forwarded-For if it exists, then X-Real-IP, then lastly the standard RemoteAddr. Useful when running behind a proxy to log the public IP of each request. (#2110)
    • changed loading spinner style to be more compatible with safari browsers.

    BugFixes:

    • Wrong username in share settings (#2147) (#2148)
    • [OnlyOffice] Error when saving a file under a user scope #2133
    • Cannot edit shared file in OnlyOffice #2143
    • PWA install button disappeared (#2086)
    • Deleting a root folder was possible #2128
    • PUT resource api errors if action against a folder (#2153)
    • LDAP authentication issue if a password caontains @ symbol (#2154)
    • Share banner seems to be not working for custom urls (#2120)
    Open source →
  35. v1.3.1-stable 01 May 2026 pre-release

    Nothing published for this version

  36. v1.3.1-beta 07 Mar 2026 pre-release
    Release notes

    Security:

    • Patched Stored XSS in public share page via unsanitized share metadata (text/template misuse) GHSA-r633-fcgp-m532
    • Patched Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info GHSA-525j-95gf-766f

    New Features:

    • More user options for settings (#2072) (#2067):
      • Option to disable thumbnails userDefaults.preview.audio and userDefaults.preview.models for Audio and 3D Models.
      • Option to disable files in the Tree navigation userDefaults.hideFilesInTree
      • Option to disable source files deletion when creating/extracting archives. userDefaults.deleteAfterArchive

    Notes:

    • Share icon does not show in share listing or for shares for other users.
    • File Size Analyzer tool max items increased from 100 to 200.
    • changed symlink detection logic.

    BugFixes:

    • 405 response code error on Webdav in 1.3.0-beta (#2054)
    • Motion Preview setting not saving when changed in profile settings.
    • Context menu on tools not working.
    Open source →
  37. v1.3.0-stable 20 Apr 2026 pre-release

    Nothing published for this version

  38. v1.3.0-beta 27 Feb 2026 pre-release
    Release notes

    Note: a potentially breaking change for docker users: \the default user is now "filebrowser" 1000:1000 instead of root.

    New Features:

    • New Sidebar Features
      • Sidebar tree navigation (#2006) (#350)
      • Source usage to be customized to show os-reported values rather than calculated. This can be changed per source by editing the source link in the sidebar. (#1266) (#982)
    • Archive/Unarchive actions in UI (#1252) (#335) (#1569)
      • new api to archive/unarchive files on the server
      • requires create user permissions
      • archiving actions respect server.maxArchiveSize
    • Added share icon to items that are shared (#1420)
    • Authentication enhancements
      • LDAP login support with OIDC feature parity. (#591)
      • userGroup for OIDC and LDAP, only users in a group will get access. (#1964)
      • Add JWT token authentication support (#1364)
    • Enhanced thumbnail and item previews
      • Added ability to show "motion preview" for folders with multiple child items that have previews. cycles through the first 4 images.
      • support for reading embedded images from raw image or heic/heif files (#215)
      • reorganized and simplified thumbnail settings in profile settings (#1968)
      • removed highQuality thumbnail option which only affected gallery view. Now its always enabled.
      • improved caching for unsupported images, the same file won't be attempted again with the same modtime.
      • supports 3d model previews.
    • FileWatcher also supports watching directories
    • Support previews for 3D model files (STL, OBJ, 3MF, etc.) (#1273)
      • supported formats via threejs: GLTF, GLB, OBJ, STL, PLY, DAE (Collada), 3MF, 3DS, USDZ, USD, USDA, USDC, AMF, VRML, WRL, VTK, VTP, PCD, XYZ, VOX, KMZ
      • supports animations (for formats that contain them)
      • supports embedded textures, external neighboring file textures, or textures in /textures subdirectory
    • Enhanced prompts
      • All prompts have a taskbar with a close button
      • Prompts can be freely moved by dragging taskbar
      • Prompt styling has been updated
      • Clicking outside of prompts no longer automatically closes them.
    • add webdav support (#209) -- thanks to @reddac for (#1764)
      • see docs on how to use
      • requires api an un-customized api token as password
      • respects access rules
      • requires download permission to view and modify/create/delete permission to modify.

    Notes:

    • Docker images default to filebrowser user instead of root
    • reorganized api routes
      • consolidated tags for swagger to be more accurately grouped
      • tools are all behind /api/tools routes
      • /api/raw is deprecated (but functional). The /api/resources/download route will be used instead.
      • /api/preview has been removed and replaced with /api/resources/preview
      • /api/onlyoffice have been replaced with /api/office
      • /api/shares has been moved to /api/share/list
      • /api/auth/tokens has been moved to /api/auth/token/list and /api/auth/token added to get specific token info
      • PUT /api/token has been moved to POST /api/token
      • /public/api/shareinfo has been moved to /public/api/share/info
      • POST /resources/bulk/delete api has been moved to DELETE /resources/bulk (#1984)

    BugFixes:

    • Long folder names get cut off at top navigation bar (#1934)
    Open source →
  39. v1.2.7-beta 23 Feb 2026 pre-release
    Release notes

    BugFixes:

    • head > title > infinitely duplicating titles (#2016)
    • Proxy auth not working with Nginx, stuck at logo (#2013)
    Open source →
  40. v1.2.6-beta 19 Feb 2026 pre-release
    Release notes

    Security:

    • resolves https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-8vrh-3pm2-v4v6
    Open source →
  41. v1.2.5-beta.0.20260222013023-c51b0ee9738f 22 Feb 2026 pre-release

    Nothing published for this version

  42. v1.2.5-beta 19 Feb 2026 pre-release
    Release notes

    Notes:

    • Dependency Updates for frontend and backend packages
    • Upgrade to go 1.26
    • file list prompt interaction behavior, single-click always selects, double-click navigates. (#1911)

    BugFixes:

    • .ssa and .ass subtitle files get their styling removed during conversion (#1933)
    • custom icons issue
    • new database message for noauth (#1935)
    Open source →
  43. v1.2.4-stable 01 Apr 2026 pre-release

    Nothing published for this version

  44. v1.2.4-beta 13 Feb 2026 pre-release
    Release notes

    Notes:

    • Changed /api/media/subtitles api endpoint to better support subtitles.
    • Correcting some errors in French language (#1947)
    • add Dutch nl.json for frontend i18n -- thanks @Stephan-P (#1957)
    • share banner and icon images automatically serve a scaled down 1024x1024

    BugFixes:

    • Can't access directories with space (and possibly other special characters) when browsing a public link share (#1956)
    • External ASS subtitles are not usable in web preview (#1933)
    • Filename blocking rename/move (#1950)
    • enforcedOtp: true blocks all user settings updates with HTTP 400 (#1962)
    • Share favicon URL not showing up and Share description causing endless loading (#1911)
    • folder sizes not updated for changes to filesystem outside of filebrowser (#1974)
    Open source →
  45. v1.2.3-stable 21 Mar 2026 pre-release

    Nothing published for this version

  46. v1.2.3-beta 05 Feb 2026 pre-release
    Release notes

    Notes:

    • Removed upload api behavior to assume paths ending in "/" are folders, strictly uses isDir query param
    • renamed public upload api query param from targetPath to path. see swagger docs.

    BugFixes:

    • fix stuck motion preview popup window issue
    • Chunked uploads ignore User Scope and are saved to Source Root (#1894)
    • share delete with user scope issue
    • fix favicon pwa icon, having the PWA respect the favicon/loginIcon (#1899)
    • delete prompt icons show image previews
    Open source →
  47. v1.2.2-stable 07 Mar 2026 pre-release
    Release notes

    Security:

    • Patched Stored XSS in public share page via unsanitized share metadata (text/template misuse)

    New Features:

    • "Divider" option in sidebar links to add a text or divider between links ()
    • shares offer a "go to source Location" sidebar link and button when editing a share.

    Notes:

    • Share edit/delete permissions are scoped to the user's shares rather than global (#2050)

    BugFixes:

    • fixed the requirement that the database path needed to be set in the config file, now it loads FILEBROWSER_DATABASE value by default, fallback to config file property.
    • Error downloading zipped directory: no such file or directory (users with scope) #2015
    Open source →
  48. v1.2.2-beta 03 Feb 2026 pre-release
    Release notes

    New Features:

    • Resizable sidebar (#1896)
    • OIDC Authentication: Change Button Text via frontend.oidcLoginButtonText (#1708)
    • improved favicon processing (#1899)
      • supports more formats
      • supports larger images
      • automatcially generates multiple favicon sizes on startup for non-svg images. Custom svg favicons need a companion *.png to exist broad compatibilty
      • Enhanced media playback: Ability to control the queue from your device's lock screen and notification panel - Will also show metadata of the current playing media if available (#1917)

    Notes:

    • Better text file content detection (#1726)
    • More url encoding changes for API which should make things more consistent. Open issues if you see path/source not found errors.
    • adjustments to the startup behavior for sqlite index for reusing the previous database on startup
    • CTRL + B disables sticky sidebar forever (#1869)
    • added context menu back to duplicate finder
    • Sharing a link for uploads - folder/file access and UX polishing (#1902)
    • improved listing view and scrolling performance
    • improved image viewer which will utilize recent thumbnails as a placeholder when loading the full image.
    • Small reorganization of "Share" settings to make the popup clear (#1826)

    BugFixes:

    • Added docker default FILEBROWSER_CONFIG="/home/filebrowser/data/config.yaml" back -- mistakenly removed. see https://filebrowserquantum.com/en/docs/getting-started/config/#3-default-locations. (#1891)
    • Fix brand text in login screen (#1898)
    • Sidebar links cointains urls with 2x repeated source name (#1847)
    • 2 factor auth getting overwritten if you edit the auth from admin (#1819)
    • New created user's files are listing error, Probably related with language setting. (#1565)
    • thumbnail generation cpu/memory and concurrency bug.
      • added 75MB filesize limit for image previews
      • optimized concurrency for large vs small images
    Open source →
  49. v1.2.1-stable.0.20260807212525-29f9055db96d 07 Aug 2026 pre-release

    Nothing published for this version

  50. v1.2.1-stable.0.20260807185336-8c5c92bef059 07 Aug 2026 pre-release

    Nothing published for this version

  51. v1.2.1-stable.0.20260802173944-b6c9cc976250 02 Aug 2026 pre-release

    Nothing published for this version

  52. v1.2.1-stable.0.20260718010928-9503b532e1a5 18 Jul 2026 pre-release

    Nothing published for this version

  53. v1.2.1-stable.0.20260713165151-da085bca696a 13 Jul 2026 pre-release

    Nothing published for this version

  54. v1.2.1-stable.0.20260705131828-64250ffff076 05 Jul 2026 pre-release

    Nothing published for this version

  55. v1.2.1-stable.0.20260623151823-0bc8889c002b 23 Jun 2026 pre-release

    Nothing published for this version

  56. v1.2.1-stable.0.20260619161757-6eaead073a62 19 Jun 2026 pre-release

    Nothing published for this version

  57. v1.2.1-stable.0.20260611155201-826b060bb101 11 Jun 2026 pre-release

    Nothing published for this version

  58. v1.2.1-stable.0.20260610173610-21dfc6169ea8 10 Jun 2026 pre-release

    Nothing published for this version

  59. v1.2.1-stable.0.20260609194804-4708faec5f28 09 Jun 2026 pre-release

    Nothing published for this version

  60. v1.2.1-stable.0.20260522161427-fa5abc8c67f3 22 May 2026 pre-release

    Nothing published for this version

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive