NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #410 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 15 of 15 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
393 releases · first in 2023
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Note Supersedes v1.5.7-stable, so including its release notes for visibility.
Note
Supersedes v1.5.7-stable, so including its release notes for visibility.
Security:
POST /api/auth/otp/generate and POST /api/auth/otp/verify no longer allows anonymous callers to replace an existing second factor using only the account password; reset or replace requires an authenticated self or admin session (first-time enrollment without MFA unchanged) (GHSA-qx86-4v5r-26g5) -- thanks @tao0845.Notes:
Full Changelog: v1.5.7-stable...v1.5.8-stable
Warning This release has been superseded by v1.5.8-stable, as it introudces a TOTP login change that prevented login in some circumstances.
Warning
This release has been superseded by v1.5.8-stable, as it introudces a TOTP login change that prevented login in some circumstances.
Security:
POST /api/auth/otp/generate and POST /api/auth/otp/verify no longer allows anonymous callers to replace an existing second factor using only the account password; reset or replace requires an authenticated self or admin session (first-time enrollment without MFA unchanged) (GHSA-qx86-4v5r-26g5) -- thanks @tao0845.Notes:
Full Changelog: v1.5.6-stable...v1.5.7-stable
[Moderate] public metadata api returns file content to anonymous share visitors, ignoring the share's download limit and file-viewer setting ( GHSA-55
Security:
BugFixes:
/ and /login after CSP security hardening (#2886, #2890)Full Changelog: v1.5.5-stable...v1.5.6-stable
Fixes onlyoffice failing to load due to strict csp security requirement introduced in v1.5.4
Fixes onlyoffice failing to load due to strict csp security requirement introduced in v1.5.4
Full Changelog: v1.5.4-stable...v1.5.5-stable
fix uncustomized (minimal) API tokens creation needed by webdav clients
BugFixes:
Full Changelog: v1.5.4-beta...v1.5.5-beta
[High] Stored XSS via HTML preview: <script> is no longer preserved in srcdoc, the preview iframe is opaque-origin (no allow-same-origin ), the sessio
Security:
<script> is no longer preserved in srcdoc, the preview iframe is opaque-origin (no allow-same-origin), the session cookie is HttpOnly, and the SPA shell sends a script-src CSP inherited by srcdoc frames (GHSA-vvm6-jwrf-hgmg) -- thanks @qrn12580New Features:
frontend.disablePWAInstallNotes:
BugFixes:
0 to disable chunking as documented (#2202); workaround for iOS 26 multi-chunk upload stalls (#2734).Full Changelog: v1.5.3-stable...v1.5.4-stable
remove pwa short name and use 30 char name cap by @gtsteffaniak in #2701
Full Changelog: v1.5.3-beta...v1.5.4-beta
windows backslash inserted into directory URLs causing malformed paths and path escapes from parent
BugFixes:
Full Changelog: v1.5.2-stable...v1.5.3-stable
fix probe canShare with the real file, not a fixed text/plain stand-in
BugFixes:
Full Changelog: v1.5.2-beta...v1.5.3-beta
…) -- thanks @corbanvilla @soh3e @dderpym (This vulnerability was discovered as part of a U.C. Berkeley security research project by: Corban Villa, Soh…
Security:
Full Changelog: v1.5.1-stable...v1.5.2-stable
Nothing published for this version
What's Changed (since the last stable v1.5.0)
Notes:
BugFixes:
/ (#2696)Full Changelog: v1.5.0-stable...v1.5.1-stable
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →