Elestio Release Notes
30 release notes curated from 125 sources by the Releasebot Team. Last updated: Sep 1, 2026
- Aug 30, 2026
- Date parsed from source:Aug 30, 2026
- First seen by Releasebot:Sep 1, 2026
Elestio Catalog Updates: 117 New Releases This Week (August 23-29, 2026)
Elestio releases a weekly roundup of 117 stable updates across 47 services, led by urgent security fixes in BookStack, Gitea, Penpot and others. It also highlights new AI sandboxing in Dify, tool approval in Open WebUI, a revamped Portainer API flow, and fresh app and infrastructure patches.
One hundred and seventeen stable releases landed across 47 services in the Elestio catalog between August 23 and 29. Six of them are security fixes you should not sit on, and one patches a remote-code-execution path. Here is the week, sorted so you can find your stack fast.
Security Alerts
Patch these first.
- BookStack v26.05.4 (Aug 24): Dedicated security release. ZIP imports with certain content could reach remote code execution, drawing endpoints could be turned into cross-site-scripting, and several permission checks could be bypassed to edit attachments and non-draft pages. Update this one today.
- Gitea v1.27.3 (Aug 29): Security fixes tightening restricted, limited and token-scope access on the packages API.
- Penpot 2.17.2 (Aug 27): Fixes a command injection in the SVG exporter via legacy fill-color.
- Hoppscotch 2026.8.0 (Aug 28): Ships security patches alongside the feature work below.
- Dify v1.16.1 (Aug 25): Bug fixes and security hardening on the 1.16 line.
- Vaultwarden 1.37.2 (Aug 24): Required for Bitwarden clients on 2026.8.0 and later. Update the server before your clients auto-update, or logins will break.
Databases
- ClickHouse 26.3.25.2-lts (Aug 24-28): six releases in five days, five of them LTS patches across the 26.3 and 25.8 lines.
- MariaDB 12.3.3 (Aug 24): Quarterly maintenance across four branches at once: 12.3.3, 11.8.9, 11.4.13 and 10.11.19.
- Weaviate v1.39.2 (Aug 25-27): Five releases across three branches. Highlights: database user API-key export and import, a new generative-digitalocean module, an MCP stateless endpoint fix, and async replication work.
- Milvus 2.6.23 (Aug 28): Maintenance release.
AI and GPU
- Ollama v0.33.2 (Aug 26-28): Three releases. The 0.33.0 headline is that Claude Desktop can now be pointed at Ollama as a third-party gateway provider.
- Dify v1.17.0 (Aug 25): Agent shell and code execution can now run on E2B cloud sandboxes instead of the local sandbox. Pick the backend with DIFY_AGENT_RUNTIME_BACKEND, and a docker-compose.e2b.yaml ships the stack. Also adds home snapshots and skill management.
- Open WebUI v0.11.1 (Aug 25): Human-in-the-loop tool approval. Admins can flip a conversation from running tools freely to asking first, one call at a time, with the choice remembered.
- RAGFlow v0.27.1 (Aug 26-28): Document-level and dataset-level knowledge compilation, supporting Wiki, Graph, Tree, Page Index, Mind Map and Timeline structures.
- ComfyUI v0.34.2 (Aug 24-27): Four releases, including MiniMax fixes on non-dynamic VRAM.
- Langflow v1.12.0 (Aug 29): New minor, with 1.11.5 as the maintenance drop.
- Also shipped: AnythingLLM v1.16.1 (Aug 27), InvokeAI 6.14.0 (Aug 25), Gradio 6.26.0 (Aug 24), Zep ingest 0.3.0 (Aug 28).
Development
- n8n 2.37.4 (Aug 25-28): Seven releases in four days across the 2.36 and 2.37 lines.
- Hoppscotch 2026.8.0 (Aug 28): REST and GraphQL in a single workspace, data-driven collection runs from CSV or JSON files, and a new Hoppscotch MCP server.
- Strapi v5.52.2 (Aug 27): Fully revamped Media Library behind an opt-in flag. Set future.betaMediaLibrary: true to try it.
- PocketBase v0.40.0 (Aug 23-24): Heads up on a small breaking change: console command errors and recovered panics now propagate to app.Start(), so failed commands exit non-zero. If you chain commands with &&, re-check your scripts.
- ToolJet v3.20.218-lts (Aug 25-26): Four LTS patches.
- Also shipped: Jenkins 2.579 (Aug 25), Directus v12.3.1 (Aug 25), Budibase v3.43.0 (Aug 24), Huginn v2026.08.27 (Aug 27), plus five Airflow provider package releases between Aug 23 and 29.
Hosting and Infrastructure
- Portainer 2.45.0 LTS (Aug 27): native Portainer APIs for writing Kubernetes secrets, configmaps, deployments and PVCs, replacing direct kube-apiserver proxy calls. Adds advanced node drain with agent failover.
- K3s v1.36.4+k3s1 (Aug 28): Patches across three supported lines: 1.36.4, 1.35.8 and 1.34.11.
- RabbitMQ 4.3.4 (Aug 26): Maintenance release. Note the floor: nodes will not start on Erlang older than 27.0.
- Zabbix 7.4.14 (Aug 25): Plus 7.0.30 on the LTS line.
- Loki v3.7.7 (Aug 27): Alongside v3.6.16.
- Also shipped: SigNoz v0.139.0 (Aug 26), Uptime Kuma 2.5.3 (Aug 24, a version-numbering fix on top of 2.5.1).
Applications
- Nextcloud v34.0.3 (Aug 24): Maintenance. Worth knowing: Nextcloud 35 hit RC2 on Aug 27, so a major is close.
- Paperless-ngx v3.1.0 (Aug 27): Adds an "apply AI suggestions" workflow action.
- Ghost v6.61.0 (Aug 25-27): Emailable gift subscriptions and Portal gift links, plus 6.60.0.
- Metabase v0.63.15.5 (Aug 29): Patches backported across four supported branches, including a fix to never encrypt the app DB on startup.
- Mattermost v11.10.1 (Aug 25-26): Plus v11.7.10 on the older line.
- Chatwoot v4.17.1 (Aug 27): Restores Instagram login, fixes duplicate Facebook messages, improves Captain analytics.
- Discourse v2026.9.0 (Aug 25): Five branches patched in one day.
- Wekan v11.28 (Aug 28-29): ten point releases, v11.19 through v11.28, in two days.
- Also shipped: ERPNext v16.33.0 and v15.120.0 (Aug 25), Invoice Ninja v5.13.36 (Aug 25-27), Zammad 7.1.3 (Aug 25), BookStack v26.05.4 (Aug 24), Jitsi Meet builds 9407-9411 (Aug 27).
What Stood Out This Week
Sandboxing stopped being optional.
Dify 1.17 lets you run agent code execution in E2B cloud sandboxes rather than a local one, and Open WebUI 0.11.1 added human-in-the-loop tool approval. Two of the most-deployed AI tools in the catalog independently shipped "do not let the model do whatever it wants" features in the same week. If you are running agents against anything real, both are worth turning on.
BookStack is the patch that actually matters.
Everything else here is convenience. A ZIP import path reaching remote code execution on a self-hosted wiki, where users routinely have upload rights, is the kind of thing that gets found later in your logs.
Portainer 2.45 quietly changed its architecture.
Moving from direct kube-apiserver proxy calls to native Portainer APIs for writing secrets, configmaps, deployments and PVCs is a real shift in how it talks to your cluster. Read the release notes before upgrading a production instance.
PocketBase 0.40.0 has a breaking change hiding in a patch-sized release.
Failed commands now exit non-zero. That is correct behavior, and it will also break any script that relied on the old always-zero exit status.
Every service above is available as a one-click managed deploy on Elestio, with updates, backups and monitoring handled for you. Browse the full catalog of 400+ open source services to see what you can run.
See you next Sunday 👋
Thanks for reading ❤️
Original source - Aug 24, 2026
- Date parsed from source:Aug 24, 2026
- First seen by Releasebot:Aug 24, 2026
WG-Easy: Set Up a WireGuard VPN with a Web UI in 10 Minutes
Elestio highlights WG-Easy v15 with a browser-based setup wizard, QR-code client onboarding, two-factor auth, a Prometheus metrics endpoint, a REST API and a CLI, while noting the rewrite requires a fresh install and new migration steps.
Read This Before You Start
There's a moment every self-hoster hits. You've got Grafana, a Postgres admin panel, maybe an internal dashboard or two, and none of them should ever face the public internet. So you start down the rabbit hole: reverse proxy, basic auth, IP allowlists, a Cloudflare tunnel, and somewhere in there you've built a security posture out of duct tape.
The cleaner answer is a VPN. And WireGuard is the right VPN, except configuring it by hand means editing
.conf
files, generating keypairs on both ends, and explaining to a colleague over Slack why their phone won't connect.
WG-Easy is WireGuard with a web UI on top. You click "new client," it hands you a QR code, and the phone is on the VPN. That's the whole pitch, and it's a good one.
WG-Easy v15 is a full rewrite, and I want to put this up front because it's where people lose an afternoon.
If you're running v14, you cannot upgrade in place. The data model, the API and the configuration approach all changed. Every
WG_*
environment variable you carefully set in v14 is ignored in v15. Configuration now happens through a setup wizard in the browser on first boot, including the host address and the admin password that used to be
WG_HOST
and
PASSWORD_HASH
.
The migration path is: hit Backup in the v14 UI to download
wg0.json
, run
docker compose down
(not
stop
, or you'll leave inconsistent state behind), start v15 fresh, and upload that file when the wizard asks whether you have an existing config.
Also worth knowing: v15 dropped ARMv6, and v15.2.0 dropped ARMv7. If your VPN box is an older Raspberry Pi, check before you pull.
The Compose File
Here's the current setup, straight from upstream:
volumes: etc_wireguard: services: wg-easy: image: ghcr.io/wg-easy/wg-easy:15 container_name: wg-easy networks: wg: ipv4_address: 10.42.42.42 ipv6_address: fdcc:ad94:bacf:61a3::2a volumes: - etc_wireguard:/etc/wireguard - /lib/modules:/lib/modules:ro ports: - "51820:51820/udp" - "51821:51821/tcp" restart: unless-stopped cap_add: - NET_ADMIN - SYS_MODULE # - NET_RAW # uncomment if using Podman sysctls: - net.ipv4.ip_forward=1 - net.ipv4.conf.all.src_valid_mark=1 - net.ipv6.conf.all.disable_ipv6=0 - net.ipv6.conf.all.forwarding=1 - net.ipv6.conf.default.forwarding=1 networks: wg: driver: bridge enable_ipv6: true ipam: driver: default config: - subnet: 10.42.42.0/24 - subnet: fdcc:ad94:bacf:61a3::/64docker compose up -d, then open port 51821 in your browser.Two ports, two jobs:
PORT PROTOCOL WHAT IT DOES 51820 UDP The actual WireGuard tunnel. Must be reachable from the internet. 51821 TCP The admin web UI. Should not be reachable from the internet.That second row is the part people get wrong. Once the VPN is up, restrict the UI to the VPN subnet or put it behind your reverse proxy with real auth. An admin panel that mints VPN credentials is not something you leave open on a public IP.
The Capabilities Are Not Optional
NET_ADMIN lets the container manage network interfaces and routing.
SYS_MODULE plus the read-only
/lib/modules
mount let it load the WireGuard kernel module if your host hasn't already. The
sysctls
block turns on IP forwarding, which is what actually makes traffic move from the tunnel to the rest of your network.
Strip any of those out because they look scary and you get a container that starts cleanly, shows a healthy UI, completes a handshake, and passes exactly zero packets. Which is a genuinely annoying way to spend an evening.
Adding Clients
The wizard walks you through the admin account and the public host address. After that, adding a client is one button. WG-Easy generates the keypair, assigns an IP from the pool, and renders a QR code.
On a phone: install the official WireGuard app, scan the code, toggle on. On a laptop: download the
.conf
and import it. That's it, and it's the reason this tool exists. Handing a non-technical colleague a QR code is a completely different experience from walking them through key generation.
Beyond the basics, v15 ships two-factor auth on the admin panel, a Prometheus metrics endpoint, a proper REST API, and a CLI.
Troubleshooting
Handshake succeeds but no traffic flows.
Almost always IP forwarding. Confirm the
sysctls
block is present and check
sysctl net.ipv4.ip_forward
on the host reads 1.
Client never connects at all.
WireGuard is UDP, and plenty of corporate and hotel networks block outbound UDP on non-standard ports. Test from mobile data first to isolate it. If UDP is genuinely blocked, no amount of config will fix it.
Container starts, UI works, tunnel doesn't.
Check the WireGuard module loaded:
lsmod | grep wireguardon the host. Any kernel from 5.6 onward has it built in.
Running Podman instead of Docker.
Uncomment
NET_RAW
in
cap_add
. Podman's default capability set is narrower.
Upgraded from v14 and everything is gone.
Your old config wasn't migrated, because it can't be. Restore the
wg0.json
backup through the setup wizard.
Running It Somewhere That Isn't Your Laptop
A VPN gateway needs a stable public IP and needs to actually stay up, which rules out the box under your desk. The resource footprint is small since WireGuard runs in kernel space, so a modest VM handles a team comfortably.
If you'd rather not maintain the host yourself,
WG-Easy on Elestio
starts at $11/month fully managed, with SSL, automated backups, monitoring and updates handled for you, across Hetzner, DigitalOcean, Vultr, Linode, Scaleway, Netcup, AWS or your own VM.
Either way, the payoff is the same: your internal services stop needing a public door, and onboarding someone becomes a QR code instead of a support ticket.
Thanks for reading ❤️ See you in the next one 👋
Original source All of your release notes in one feed
Join Releasebot and get updates from Elestio and hundreds of other software products.
- Aug 23, 2026
- Date parsed from source:Aug 23, 2026
- First seen by Releasebot:Aug 23, 2026
Elestio Catalog Updates: 47 New Releases This Week (August 16-22, 2026)
Elestio ships a packed weekly update with major security fixes for Keycloak, Redis, Grafana and Rocket.Chat, plus standout feature releases like RAGFlow’s Go-based executor, WordPress 7.1’s browser-side image resizing, and new capabilities in GitLab, Authentik and NocoDB.
Security Alerts
Keycloak 26.7.2 (August 19) is the one to patch first. It closes eight vulnerabilities, including CVE-2026-18963, an unauthenticated account takeover via a reset-credentials flow bypass, and CVE-2026-15571, a predictable account-linking hash that lets a malicious OIDC client hijack accounts. Three more cover leaked client secrets, an admin permissions bypass, and hidden parent groups disclosed under FGAP v2. If Keycloak is your identity provider, upgrade today.
Redis 8.10.1 (August 17) is flagged SECURITY urgency and was backported across every supported branch at once, down to 6.2.24. The headline is a malicious RDB payload with an out-of-range SLOT_INFO slot id that corrupts memory during loading and may lead to remote code execution. Also fixed: CVE-2026-62356 (heap out-of-bounds write in CMSketch RDB loading), a TLS certificate authentication bypass via an embedded NUL byte in the Common Name, and three Vector Sets memory-safety bugs.
Grafana 13.2.0 (August 19) carries a fix for CVE-2026-17183, backported the day before to 13.1.4, 13.0.7, 12.4.9 and 12.3.11. Every supported branch has a patch.
Rocket.Chat 8.7.1 (August 19) ships a security hotfix alongside per-client rate limiting on the unauthenticated password recovery endpoint and improved SSRF protection in file downloads. It landed on seven other branches the same day, back to 7.10.15.
Databases
Redis 8.10.1 (August 17). A SECURITY-urgency release fixing an RDB parsing path that can reach remote code execution.
ClickHouse 26.7.5.10 (August 21). Stable bumps on the 26.5, 26.6 and 26.7 lines plus LTS patches for 26.3 and 25.8.
InfluxDB 3.11.2 (August 20). Maintenance patch on 3.x.
TimescaleDB 2.29.2 (August 18). Bug fixes for the hypertable and continuous aggregate paths.
Weaviate 1.38.11 (August 20). Async replication fixes, following 1.38.10 two days earlier with search REST endpoint improvements.
AI & GPU
RAGFlow 0.27.0 (August 19). The biggest AI release of the week by some distance. Over 700 pull requests merged, the task executor migrated to Go, a new model provider abstraction, ClickHouse integration, Mistral OCR and PowerPoint parsing, and an agentic search framework wired to Tavily, PubMed and ArXiv. Several CVEs fixed too.
Ollama 0.32.15 (August 20). Caches resolved model metadata between requests, cutting time to first token roughly in half. Version 0.33.0 is tagged but still a release candidate, so hold off unless you want the Claude Desktop integration early.
Langflow 1.11.4 (August 19). Stable patch while 1.12.0 stays in dev builds.
Gradio 6.25.0 (August 19). Component updates across the dataframe, image and 3D widgets.
Development
GitLab 19.3.0 (August 20). GitLab Secret Manager enters limited availability with secrets scoped by environment, branch and protection status, plus Kubernetes and Terraform support. Duo can now resolve merge conflicts on its own, and merge trains can be enforced project-wide from one setting.
Keycloak 26.7.2 (August 19). Eight CVEs, 19 bug fixes, Quarkus bumped to 3.33.3.1. See the alerts above.
Authentik 2026.8.0 (August 18). Sessions are now deleted when a user is deactivated, with back-channel logout sent automatically. Also fixes SCIM group membership removal and closes a CSRF exemption in dynamic client registration.
NocoDB 2026.08.1 (August 19). Realtime Presence gives every collaborator a colour that follows them cell to cell, with presence badges on open records. Folders group tables, documents and dashboards into collapsible sets. Both on self-hosted.
Directus 12.3.0 (August 18). New @directus/cli for syncing schema and config between instances, search-first AI tool discovery for chat and MCP, and a fix for storage connection leaks.
n8n 2.36.5 (August 21). Rapid patch cadence continued all week, with the 1.123.75 LTS line updated in parallel.
Maintenance updates landed for Strapi 5.52.1 (August 19), Hasura 2.50.1 (August 18), Jenkins 2.578 (August 18), ToolJet 3.20.214 LTS (August 19) and Budibase 3.42.0 (August 17).
Hosting & Infrastructure
Grafana 13.2.0 (August 19). Beyond the CVE, a real feature release: an import tab for alerting settings and notification templates, Git Sync webhooks with user attribution, and Redis TLS connections via rediss://.
Prometheus 3.14.0 (August 17). PromQL duration expressions are on by default and first_over_time graduates to stable. Adds Oracle Cloud service discovery, plus fixes for TSDB data loss and native histogram corruption after restart.
VictoriaMetrics 1.150.0 (August 17), SigNoz 0.138.0 (August 19) and Loki Operator 0.11.0 (August 18) round out observability.
Elsewhere, RabbitMQ 4.3.5 (August 17), Traefik 3.7.11 (August 21, with 2.11.55 alongside) and Uptime Kuma 2.5.3 (August 22) all shipped patches, the last correcting a version numbering slip in 2.5.1 and 2.5.2.
In object storage, SeaweedFS 4.44 (August 22) capped three releases in six days, and RustFS 1.0.0-rc.3 (August 21) moved the S3-compatible newcomer nearer 1.0.
Applications
WordPress 7.1 "Mary Lou" (August 19). Interactive state styling is the headline: hover, focus and active states configurable from the Site Editor without writing CSS. Two new core blocks arrive (Tabs and Playlist), Notes gain inline comments with @mentions, and image resizing moves from the server into the browser before upload.
Mastodon 4.7.0 (August 20). Local users' keypairs are now encrypted at rest, with RFC9421 HTTP Message Signatures and FEP-8b32 object integrity proofs. Remote accounts can change handles without creating duplicates. Plan the window carefully: migrations can run up to two hours on large servers, and dropping pre-4.3.0 cookies logs out older sessions.
Rocket.Chat 8.7.1 (August 19). Security hotfix plus SSRF hardening, backported to seven branches.
Chatwoot 4.17.0 (August 20). WhatsApp Cloud API and Twilio template management moves into Chatwoot and the API, macros run from the reply editor and command bar, and a Freshdesk importer arrives for contacts, tickets and notes.
Wekan 11.00 through 11.07 (August 17 to 21). A major version bump plus seven patches in five days. Fixes RouteBleed, an incompletely escaped dynamic regex, and makes Helm containers read Node.js heap limits from their cgroup.
Umami 3.3.1 (August 20). Hardens two-factor authentication when TWO_FACTOR_ENCRYPTION_KEY is missing or invalid, plus a migration normalizing legacy usernames.
Ghost 6.59.0 (August 19), Metabase 0.63.14.2 (August 21), Element Web 1.12.26 (August 18), Matomo 5.13.0 (August 16), Penpot 2.17.1 (August 17), Documenso 2.17.0 (August 19), ERPNext 16.32.3 (August 18), Invoice Ninja 5.13.33 (August 17), Vaultwarden 1.37.2 (August 22, required for Bitwarden clients on 2026.8.0 and later), Nextcloud AIO 13.5.0 (August 17) and Jitsi Meet stable-11189 (August 20) complete the list.
What Stood Out This Week
Keycloak 26.7.2 is not optional. An unauthenticated account takeover in the reset-credentials flow means an attacker needs nothing but network access to your login page. If Keycloak fronts your internal tooling, treat this as an incident, not a maintenance item.
Redis patched eight branches on one day. When a project backports all the way to 6.2, the underlying bug is serious. Anyone loading RDB files from a source they do not fully control, including a restored backup, is in scope.
RAGFlow 0.27.0 is a genuine architectural release. Moving the task executor to Go changes how the system scales, and the agentic search tooling turns it from a document Q&A app into something closer to a research agent.
WordPress 7.1 moved image resizing to the browser. Server-side resizing has been a quiet source of PHP memory exhaustion on small instances for years. Doing it client-side before upload removes a whole class of failed-upload support tickets.
Every service above is available as a fully managed deployment on Elestio, with updates, backups and monitoring handled for you. Browse the catalog at elest.io/fully-managed-services.
See you next Sunday for the next round 👋
Original source - Aug 16, 2026
- Date parsed from source:Aug 16, 2026
- First seen by Releasebot:Aug 18, 2026
Elestio Catalog Updates: 45 New Releases This Week (August 9-15, 2026)
Elestio highlights a busy week of catalog updates, led by urgent security releases for WordPress, Gitea, Portainer, and Nextcloud. The roundup also spotlights new features in Umami and Rocket.Chat, plus fresh minor and patch updates across databases, AI tools, apps, and Helm charts.
Forty-five services in the Elestio catalog published new releases between August 9 and 15, two of which are Helm chart updates rather than new application versions. It was a heavier security week than usual: WordPress patched a remote code execution flaw serious enough to backport across ten branches, and Gitea, Portainer, and Nextcloud all shipped fixes of their own. Here's everything worth knowing, sorted by category.
Security Alerts
WordPress 7.0.4 (August 12) is the one to act on. It patches CVE-2026-65640, a High-severity authenticated remote code execution bug. An attacker with Author-level access or higher could upload a malicious PostScript file and get code execution, but only on installations using Imagick together with Ghostscript. The fix checks file contents before handing them to Imagick. WordPress backported it across every branch to 4.7, which tells you how seriously they took it.
Gitea 1.27.2 (August 13) leads its changelog with a security fix to collaborator access mode and httpsign handling, plus a WebAuthn fix that sets user verification per request.
Portainer 2.39.6 LTS (August 13) adds SSRF protection with a configurable allow-list (off, audit, or enforce modes) and fixes a path traversal in the Swarm compose deployer where config and secret file paths could escape the project root.
Nextcloud 34.0.3, 33.0.8, and 32.0.14 (August 13) are maintenance releases across three supported Hub branches carrying stability and security fixes, several sourced through Nextcloud's HackerOne program.
Databases
MariaDB 10.6.28 (August 13). Maintenance on the 10.6 LTS branch.
A quiet week otherwise. PostgreSQL, Redis, and ClickHouse held steady.
AI & GPU
Ollama 0.32.13 (August 14). Adds developer instruction support for qwen3.8. Ollama shipped seven point releases across the week, so pin a version if you need reproducible behavior.
ComfyUI 0.33.1 (August 13). Two releases in one day, following 0.33.0.
AnythingLLM 1.16.0 (August 13). New minor version.
InvokeAI 6.13.8 (August 13). Patch release.
Gradio 6.24.0 (August 12). Core bumped to 1.11.0 and the client to 2.5.0 alongside it.
Zep ingest 0.2.0 (August 12). New ingest component.
Langflow 1.11.3 (August 11). Patch release.
JupyterLab 4.6.3 (August 10). Patch on the 4.6 line.
JupyterHub 5.5.1 (August 10). Stable patch, with 6.0.0 betas later in the week.
Development
Gitea 1.27.2 (August 13). Covered in Security Alerts above.
n8n 2.34.6 (August 14). Stability work on the 2.34 line. The 2.35 branch is in prerelease.
PocketBase 0.39.11 (August 14). Patch release, with 0.22.52 shipped for the older branch the same day.
Zitadel 4.17.1 (August 14). Follows 4.17.0 two days earlier, which fixed invite codes for users whose auth methods were all removed and stopped Postgres logging a password during role creation.
ToolJet 3.20.212 LTS (August 14). Four LTS patches across the week.
Meilisearch 1.53.1 (August 13). The 1.53.0 release adds sharding for foreign filters and raises the foreign filter document limit from 100 to 1,000, plus new indexSize and usedIndexSize stats fields.
Appsmith 2.3 (August 13). New minor version.
Apache Airflow 3.3.1 (August 12). Note the pandas 3 change: DataFrame XComs now record pandas.DataFrame rather than pandas.core.frame.DataFrame, so the name written to the metadata database depends on your pandas version. Read that one before upgrading a busy scheduler.
Strapi 5.52.0 (August 12). MCP actions now get recorded in audit logs, Corsican locale codes added, and proxy settings improved in the Koa server config.
Supabase self-hosted 0.8.0 (August 11). New self-hosted bundle.
Budibase 3.42.0 (August 10). New minor version.
Authentik 2026.8.0 RC7 (August 10). Release candidate; 2026.8 stable should land shortly.
Hosting & Infrastructure
SigNoz 0.137.1 (August 14). 0.137.0 brought a GCP cloud integration, an AI explorer tab, member role assignment through the user_roles API, and a v2 reset-password endpoint.
WG-Easy 15.4.0 (August 14). Adds OAuth integration for external authentication, general security hardening, improved TOTP handling, and Japanese, Hindi, and Korean translations.
Portainer 2.39.6 LTS (August 13). Covered in Security Alerts above.
Nomad 2.0.5 (August 13). Patch on the 2.0 line.
Mailu 2024.06.58 (August 12). Maintenance release.
Loki Helm chart 7.3.0 (August 10). Chart update for Kubernetes deployments.
Prometheus 3.14.0 entered release candidate on August 11 but has not gone stable yet.
Applications
Wekan 10.95 (August 15). Eight point releases across the week, normal cadence here.
Invoice Ninja 5.13.32 (August 15). Patch release.
Mattermost 11.10.0 (August 14). New minor, shipped alongside patches for the 11.7, 11.8, 11.9, and 10.11 branches.
Discourse (August 14). Rolling release. Stable, beta, and ESR channels all refreshed.
ERPNext 16.32.1 (August 14). Two releases on both the 16 and 15 branches this week.
Nextcloud 34.0.3 (August 13). Covered in Security Alerts above. Nextcloud 35 also entered beta.
Mastodon 4.6.6 (August 13). Fixes connection errors when processing fediverse:creator that blocked preview card creation, and a bug making the web UI inaccessible on URLs ending in .zip. Requires asset recompilation, so read the upgrade notes. Patches also went out for 4.5.16 and 4.4.23, with 4.7.0 in release candidate.
Jitsi Meet 9384 (August 13). Six builds across the week on the project's usual rapid cadence.
OpenProject 17.7.2 (August 13). Bug fixes including hourly rates that couldn't be adjusted per project, and seeded custom styles getting lost when multiple were in use.
Superset Helm chart 0.22.6 (August 13). Chart update.
WordPress 7.0.4 (August 12). Covered in Security Alerts above.
PeerTube 8.2.4 (August 12). Patch release.
Umami 3.3.0 (August 12). The standout of the week. Adds TOTP two-factor authentication for self-hosted installs with QR setup, backup codes, team-level enforcement, admin 2FA reset, and rate limiting on repeated failures. Also brings session identity stitching, property filtering, board cloning, sparklines, and better bounce detection.
Jellyfin 12.0 RC5 (August 11). Fifth release candidate for the version that drops the long-standing 10. prefix. Check any automation pinned to 10.* tags before this goes stable.
Ghost 6.57.1 (August 10). Patch release.
Rocket.Chat 8.7.0 (August 10). Adds phishing-resistant MFA and a server-side OAuth flow with CSRF protection, state validation, and PKCE, enabled via Accounts_OAuth_Use_Modern_Flow. FIPS 140-3 compliant Docker images are now published. Supported until February 28, 2027.
Zulip Server 12.2 (August 10). Point release on the 12.x line.
What Stood Out This Week
WordPress 7.0.4 is the one with a deadline.
A backport reaching all the way to the 4.7 branch is not routine. The mitigating factor is that you need both Imagick and Ghostscript installed and an attacker with Author-level access, which rules out a lot of small sites. If you run a multi-author WordPress install, patch it today.
Umami 3.3.0 finally brings 2FA to self-hosted analytics.
Umami holds traffic data for every site you track, and until now the only thing standing between an attacker and that dashboard was a password. TOTP with backup codes and team-level enforcement closes a real gap. If you self-host Umami, this upgrade is worth doing before your next reporting cycle.
Rocket.Chat 8.7.0 is a serious authentication release.
Moving OAuth fully server-side with PKCE and CSRF protection, plus phishing-resistant MFA and FIPS 140-3 images, is the kind of work that matters if you're running chat in a regulated environment. Note that the modern flow is opt-in behind a setting rather than the default.
Management UIs had a rough week.
Portainer's Swarm compose deployer path traversal and new SSRF allow-list, alongside Gitea's collaborator access fix, are a reminder that these sit closer to your infrastructure than the workloads they manage. Patch them before the apps behind them.
All 45 of these services are available as one-click deployments with automated updates and backups on Elestio's managed catalog, so you can skip the upgrade sequencing entirely if you'd rather.
Thanks for reading ❤️ See you in the next one 👋
Original source - Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 14, 2026
Self-Hosted Weekly: Week 33, 2026. Jellyfin Exodus, rsync 33 CVEs, Podman 6.1
Elestio highlights a busy week of open source releases, from rsync 3.5.0’s major security fixes and Podman 6.1’s Quadlet patch to Uptime Kuma, Paperless-ngx, Caddy, and Immich updates, plus Jellyfin’s versioning change and upcoming 12.0.
This was a rough week for the software most of us actually run. Jellyfin lost three of its most senior people in a matter of days. The rsync project shipped a release fixing 33 security issues at once, which is not a number you see on a 30-year-old backup tool. Podman patched a Quadlet bug that quietly left old content inside files you thought you'd replaced.
Here's what shipped, what broke, and what it means for your stack.
1. Jellyfin Lost Three Core Leaders in One Week
Project leader Joshua Boniface stepped down after 7.5 years, citing burnout and mental health. Co-founder Andrew Rabert left after disagreements over his desktop client rewrite, including pushback on his use of AI-assisted tooling. Core team member Anthony Lavado is leaving over shifting personal priorities and has offered to help with the transition.
None of this came out of nowhere. The team's "State of the Fin" post back in May flagged burnout as a growing problem, and named one specific cause: a flood of AI-generated pull requests that added review load without adding much value.
Hot take: The code isn't going anywhere and your server will keep transcoding on Monday. But institutional knowledge doesn't survive a departure, and Jellyfin just lost three people who held a lot of it. This is the honest risk profile of self-hosting community software. Your dependency runs through volunteers who can run out of energy, which behaves very differently from a vendor that can raise prices. The mitigation isn't running back to Plex. Keep your library metadata portable and your config in version control, so that whatever the project looks like in two years, your data isn't hostage to it. If you want the boring version, Jellyfin runs on Elestio with updates and backups handled.
2. Jellyfin Drops the "10." Prefix, Next Release Is 12.0
Amid all that, the project also settled a long-running versioning question. Jellyfin confirmed that 10.11.x is the last branch using the old scheme. The next major release goes straight to 12.0, skipping 11 to match internal sequencing. Release candidates are already out.
The reasoning: the project no longer expects the hard API break that the permanent 10. prefix was reserving space for, and users kept misreading what counted as a major release. Under the new scheme the first digit means significant changes, the second means bug and security fixes.
Hot take: Version numbers are documentation, and a prefix that never changes is documentation that lies. Good change. The practical warning is for anyone with automation pinned to 10.* tags, because that pattern stops matching once 12.0 ships. Check your Watchtower rules and Compose tags now rather than during an upgrade.
3. rsync 3.5.0 Fixes 33 Security Issues at Once
rsync 3.5.0 landed August 13 and the project's own NEWS file calls it an "extraordinary release." All 33 issues were found through a focused audit of path handling and the daemon protocol, a fuzzing pass against that protocol, and external researcher reports.
The pattern underneath most of them is symlinks: arbitrary file read via symlinked input files, arbitrary file write and privilege escalation via symlinked output paths. The fix is a hardened path-resolution framework, secure_relative_open(), which pins directory file descriptors and blocks out-of-tree symlink hops. Backports for the 3.4.1 and 3.2.7 branches are rolling out alongside it.
# Check what you're running rsync --version | head -1 # Debian/Ubuntu sudo apt update && sudo apt install --only-upgrade rsyncHot take: If your backup script runs rsync as root over SSH, and most do, this is your weekend. The symlink class of bug is exactly the kind that sits unnoticed for years in a tool nobody thinks of as an attack surface, because rsync feels like plumbing rather than software. Finding 33 at once also tells you something encouraging: somebody finally sat down and audited it properly.
4. Podman 6.1 Adds Volume Rename and Patches a Quadlet File Bug
Podman 6.1 landed August 13 with podman volume rename, a podman machine restart command, and a new ImageVolume= key for Quadlet .container units.
The security note matters more than the features. CVE-2026-19730 meant podman quadlet install --replace didn't truncate the file it was replacing, so swapping a long unit file for a shorter one left trailing content from the original behind. A race condition that could corrupt systemd units also got fixed.
# Rename a volume (fails if a container is using it) podman volume rename old-data-vol app-data-volHot take: The --replace truncation bug is nastier than its CVE number suggests, because the failure is silent and your unit file looks fine until you read it closely. If you've been iterating on Quadlet units in place, go check your generated files against what you actually wrote before assuming they match.
5. Uptime Kuma 2.5.0 Waits Two Weeks Before Trusting Any npm Package
Uptime Kuma 2.5.0 adds an NTP monitor type, unlimited check intervals, a rootless Docker tag, and new notification providers. The change with the widest blast radius is a build policy: the project now applies a 14-day cooldown on npm dependency updates.
The logic is that when someone publishes a hijacked version of a package, it usually gets yanked within days of discovery. The projects that get burned are the ones pulling the newest version the moment it appears. Waiting two weeks means most poisoned releases are gone before the build ever sees them.
Hot take: This is the most quietly interesting thing any self-hosted project shipped this week. Uptime Kuma sits inside your network and holds credentials for the ninety-plus notification services it can reach, which makes its dependency tree a genuinely attractive target. Trading two weeks of dependency freshness for that much supply-chain surface reduction is a good deal, and patience is the only thing it spends. You can deploy Uptime Kuma on Elestio if you'd rather not manage the stack.
6. Paperless-ngx 3.0.5 Cleans Up After the 3.0 Release
Paperless-ngx 3.0.5 is a broad bug-fix and performance pass across search, custom fields, AI suggestions, PDF handling, email sending, and database behavior.
Two fixes stand out for anyone using the newer AI features: the AI suggestion cache is now keyed by model and endpoint, and custom field values are validated in bulk operations. There are also performance improvements to the vector store.
Hot take: Keying a suggestion cache by model and endpoint is the kind of fix that only exists because someone swapped their Ollama model and kept getting suggestions from the old one. That's a healthy 3.0.x line: the interesting features shipped, and now the team grinds through the consequences. Good time to upgrade if you sat out the 3.0 excitement. Paperless-ngx on Elestio if you want it managed.
7. Caddy 2.11.2 Adds zstd Log Rolling
Caddy 2.11.2 adds zstd compression for log rolling and deprecates roll_gzip in favor of a roll_compression directive that takes none, gzip, or zstd.
log { output file /var/log/caddy/access.log { roll_compression zstd } }Hot take: Small release, but roll_gzip is deprecated rather than removed, which means your config keeps working while quietly accumulating a warning nobody reads. Migrate now while it's a two-word change. Zstd at comparable ratios is meaningfully faster than gzip, which matters more than it sounds when you're rotating access logs on a busy reverse proxy.
8. Immich v3.1.0 Continues the Post-v3 Cleanup
Immich v3.1.0 is another round of quality-of-life improvements and bug fixes following the v3.0 major release in July.
Worth repeating the project's own upgrade guidance, because it catches people every cycle: the server is only compatible with the matching major version, so upgrade mobile clients first. And read release notes before updating if you run Watchtower, because Immich ships breaking changes at a pace automated updaters don't respect.
Hot take: "Point Watchtower at Immich and forget about it" remains bad advice, and the project says so itself. Pin to a major-version metatag like :v3 instead of :latest. That gets you patches without waking up to an unplanned schema migration. Immich runs on Elestio if you'd rather someone else sequence those upgrades.
What We're Watching Next Week
Who picks up Jellyfin's project lead role. Boniface held it for 7.5 years. How the team handles succession will say more about the project's next two years than any release note.
Distro backports of rsync 3.5. A fix list that long means a long tail of stable-branch backports. On Debian stable or an LTS Ubuntu, watch for the security advisory rather than waiting on 3.5.0 itself.
Whether the npm cooldown idea spreads. Uptime Kuma is small enough to change its build policy overnight. Watch whether anything larger follows.
Jellyfin 12.0 leaving RC. Release candidates are out. Check your version pins before it lands.
The Bottom Line
Patch rsync. That's the one item this week touching nearly everyone reading this, and running it as root over SSH is the default for most backup scripts.
The wider theme is maintainer sustainability, and Jellyfin is the visible case rather than the unusual one. A flood of low-quality AI-generated pull requests has become a real operational burden on volunteer projects, and it surfaces as burnout in the people who review them. The useful response isn't anxiety about your media server. It's keeping your data portable and, where it matters, putting money or contribution time behind the projects you depend on.
Elestio runs 400+ open source services fully managed, with patching and backups handled, if you'd rather spend your weekend on something other than CVE triage.
Thanks for reading ❤️ See you in the next one 👋
Original source Similar to Elestio with recent updates:
- Smokeball release notes144 release notes · Latest Sep 4, 2026
- Cosmolex release notes20 release notes · Latest Jul 30, 2025
- PracticePanther release notes36 release notes · Latest Aug 11, 2026
- Salesforce release notes71 release notes · Latest Sep 1, 2026
- Microsoft release notes820 release notes · Latest Sep 4, 2026
- Zoom release notes210 release notes · Latest Aug 31, 2026
- Aug 10, 2026
- Date parsed from source:Aug 10, 2026
- First seen by Releasebot:Aug 11, 2026
Milvus 3.0 Went Lake-Native: What Actually Changed
Elestio shares a Milvus 3.0 release overview covering lake-native External Collection, live schema backfill, a rebuilt sparse index, first-class long text, Woodpecker as a separate service, and opt-in Storage V3.
Lake-native means your data stops moving
The old deal with a vector database was simple and annoying. Your data lives in object storage as Parquet. To search it, you copy it into the vector database. Now you own two copies, a sync job, and an argument about which one is correct.
External Collection breaks that. Milvus references lake files in place, builds indexes over them, and searches them without ingesting anything. Parquet, Lance, Iceberg and Vortex are all supported, read-only, kept current with incremental refresh.
3.0.0 pushes it further than the beta did. External fields can now feed function output fields, so BM25 sparse vectors, MinHash signatures and text embeddings get built inside Milvus without copying the source table. Refresh handles additive schema evolution too: when the external table gains a column, Milvus patches the affected segments instead of rebuilding the whole collection.
Underneath sits Storage V3, codenamed Loon, which is manifest-based columnar storage on object storage. Remember that name, because it's the thing that's off by default.
The feature that will actually save you a weekend
Schemas don't hold still. Embedding models get replaced, features iterate, fields get deprecated. Historically each of those meant a full-collection rebuild with downtime, or a double-write scheme somebody had to babysit.
3.0.0 lets you add, backfill and drop columns while the collection keeps serving.
Backfill works in both directions, and the external path is the interesting one. Add a column, snapshot the collection as a consistent starting point, run your job offline, write the values back, and Milvus indexes the new column incrementally. That turns an embedding-model upgrade across hundreds of millions of rows into a hot-path operation instead of a migration weekend.
Inner backfill covers the values Milvus can compute itself. Attach a BM25 or MinHash function to an existing collection and the output field gets computed over existing data automatically.
Sparse search got a real overhaul
If you run hybrid or full-text search, this is the part that matters.
The sparse index was rebuilt around SINDI, with Block-Max WAND and Block-Max MaxScore alongside it, plus inverted-list compression and configurable quantization. Zilliz's internal benchmarks put the compressed BM25 index at roughly 3x smaller than the 2.6 sparse index at comparable recall, and SINDI at up to about 10x the QPS of MaxScore on learned sparse embeddings.
Those are vendor numbers on vendor workloads, so treat them as direction rather than a promise. The architectural change is real either way.
TEXT fields are the other retrieval change worth knowing. Long text is now first-class with no storage-side length limit. Values under 64 KB stay inline, larger ones go to partition-level LOB files in Vortex format with the column holding only a file reference. LOB files are shared across segments, so compaction moves references rather than rewriting text. For RAG that means you fetch vectors and source text from the same store in one IO, and you stop operating a separate blob store next to it.
What you have to turn on, and what you can't turn off
This is the section I'd read twice.
CHANGE DEFAULT HOW TO ENABLE Storage V3 (Loon), needed for Snapshot and TEXT Disabled common.storage.useLoonFFI New vector index algorithms Opt-in dataCoord.targetVecIndexVersion=10 New scalar index algorithms Opt-in dataCoord.targetScalarIndexVersion=4Now the part that bites. Milvus guarantees 2.6 to 3.0 compatibility and rollback, so you can go back. But once you enable a feature that changes the serialized data format, rollback is gone. Storage V3 is exactly such a feature. So the safe sequence is: upgrade, run on 3.0 for a while with the old format, confirm your workload is healthy, and only then flip Loon on. If you enable everything on day one you have thrown away your escape hatch to save a week.
One more: GPU images moved to CUDA 12.9 and no longer preserve Ubuntu 20.04 GPU compatibility. Check your base image before you schedule the upgrade, not after.
Also in the box
Woodpecker, the write-ahead log at the core of the streaming write path, can now run as its own service rather than embedded in other nodes. That means independent scaling, fault isolation and its own observability, which matters mostly for large clusters and write-heavy workloads.
Faceted search landed on the search path, so you specify a facet field at search time and get top facet values back with COUNT and AVG annotations, instead of over-fetching and counting client-side. There's also a Function Chain API for composable reranking, and a FAISS passthrough index that accepts arbitrary index-factory strings so existing Faiss recipes reproduce directly.
Should you upgrade?
If you're on 2.6 and content, there's no fire. Nothing is being taken away from you this quarter.
Upgrade when one of these is true: you're paying to keep a second copy of lake data inside Milvus, you have an embedding-model migration coming and no appetite for downtime, or your sparse and full-text indexes are eating more RAM and disk than you'd like.
Just do it in stages. Upgrade first, enable Loon second, raise index versions third, and leave time between each.
You can run managed Milvus on Elestio if you'd rather not operate the coordinator, query nodes and object storage yourself. Vector workloads are memory-hungry, so size honestly rather than starting at the entry config: VMs begin at $16/month for 2 vCPU and 4 GB RAM, but anything at real scale wants considerably more.
Thanks for reading ❤️ See you in the next one 👋
Original source - Aug 9, 2026
- Date parsed from source:Aug 9, 2026
- First seen by Releasebot:Aug 10, 2026
Elestio Catalog Updates: 44 New Releases This Week (August 2-8, 2026)
Elestio highlights a busy week of shipped updates across its catalog, including urgent security patches for WordPress, Keycloak and Vault, plus major releases like Milvus 3.0.0, NocoDB Interfaces, and new features in Rocket.Chat, Qdrant, Meilisearch and Ollama.
Busy week across the catalog. Forty-four services shipped stable releases between August 2 and 8, and three of them are security updates you'll want to apply before anything else. Milvus also crossed a major version line, and NocoDB shipped the biggest single feature of the week.
Security Alerts
WordPress 7.0.3 (Aug 6) fixes 12 vulnerabilities, including CVE-2026-64638, a pre-auth reflected XSS on the login screen with potential for PHP code execution. There's also a multisite privilege escalation and several stored XSS flaws. Backports landed simultaneously for 6.9.6, 6.8.7, 6.7.6, 6.6.6, 6.5.9, 6.4.9, 6.3.9, 6.2.10 and 6.1.11, so there's a patch for whatever branch you're on. Update today.
Keycloak 26.7.1 (Aug 5) resolves five CVEs. CVE-2026-4629 is privilege escalation via hardcoded role mapper injection in manage-clients. CVE-2026-9793 lets a JWE request object bypass requestObjectSignatureAlg enforcement. The remaining three (CVE-2026-14209, CVE-2026-14614, CVE-2026-14615) are all Fine-Grained Admin Permissions bypasses, so if you run FGAP v2 this one is aimed squarely at you.
Vault 2.0.4 (Aug 4) patches a privilege escalation where a denied_parameters constraint on the policies field could be bypassed by submitting a mixed-case policy name. Vault now normalizes to lowercase before evaluating constraints. Note the breaking change too: gnupg, openssl and procps were removed from the UBI container images.
Databases
- Milvus 3.0.0 (published Aug 4, notes dated Jul 29) completes the lake-native architecture from the 3.0 beta: External Collection covers more lakehouse workflows, schemas support online add, backfill and drop, the sparse index is rebuilt around SINDI, and Woodpecker runs standalone. 2.6.22 also shipped Aug 5 for anyone staying put.
- OpenSearch 3.8.0 (Aug 5) adds an API to modify a data stream's backing indices, a multivalue_doc_count aggregation, and pull-based ingestion from Hive tables.
- ClickHouse 26.7.3.19 (Aug 6), with 26.6.2, 26.3.17-lts and 25.8.29-lts patched the same week.
- Apache Cassandra 5.0.9 (Aug 7), alongside 4.1.12 and 4.0.21.
- Weaviate 1.38.9 (Aug 6) fixes backup chunk integrity and async replication.
- Neo4j 2026.07.1 (Aug 6), plus 5.26.29 on the LTS line.
- InfluxDB 3.11.1 (Aug 6).
- TimescaleDB 2.29.1 (Aug 4).
AI and GPU
- Ollama 0.32.6 (Aug 5) makes Qwen3.5 faster on Apple GPUs by using the model's MTP head for speculative decoding automatically. The bigger deal for anyone building against it: /v1/chat/completions streaming now matches OpenAI's wire format properly, with role only on the first chunk, finish_reason on its own chunk, and usage in a separate chunk.
- Langflow 1.11.3 (Aug 8) is a test-stability release ahead of the 1.12 line.
Development
- NocoDB 2026.08.0 (Aug 5) introduces Interfaces, letting you build focused apps on top of base data instead of handing everyone the full base. Available on the free tier.
- Qdrant 1.19.0 (Aug 5) adds TurboQuant 4-bit as a primary vector storage datatype, so you can store only the quantized vectors and skip the originals on disk. Memory behaviour per collection component is now unified under cold, cached and pinned.
- Meilisearch 1.52.0 (Aug 6) adds experimental /tasks/stream and /batches/stream SSE routes, replacing long polling with push-based progress.
- Hasura 2.50.0 (Aug 6), with 2.49.5 patched alongside.
- Jenkins 2.576 (Aug 5) weekly, plus LTS 2.568.1 and 2.568.2.
- Zitadel 4.16.3 (Aug 7).
- n8n 2.34.4 (Aug 8), with 2.33.7 on the previous line.
- SonarQube 26.8.0 (Aug 7).
- Strapi 5.51.2 (Aug 5).
- Supabase self-hosted 0.7.2 (Aug 4).
- Budibase 3.41.3 (Aug 4).
- ToolJet 3.20.208-lts (Aug 5).
Hosting and Infrastructure
- VictoriaMetrics 1.149.0 (Aug 5), with 1.136.15 backported for the older line.
- Grafana 13.1.3 (Aug 7), alongside 13.0.6 and 12.4.8. Routine maintenance, no advisory attached.
- K3s 1.36.3 (Aug 5), with 1.35.7, 1.34.10 and 1.33.13 patched across supported lines.
- Loki 3.7.6 (Aug 6), plus 3.6.15.
- SigNoz 0.136.1 (Aug 5).
Applications
- Rocket.Chat 8.7.0 (Aug 7) introduces phishing-resistant multi-factor authentication and lets the sessions endpoint flag the caller's own active session.
- Syncthing 2.1.3 (Aug 5) carries the 2.1 line's device and folder grouping in the GUI, HTTP and HTTPS proxy support via CONNECT, and optional block indexing for folders where database size matters more.
- Moodle 5.2.2 (Aug 8), with 5.1.6, 5.0.9 and 4.5.13 across supported branches.
- Mastodon 4.6.5 (Aug 6) fixes collection item limits and an off-by-one allowing up to five attachments on updated remote posts. Requires asset recompilation. Also 4.5.15 and 4.4.22.
- Ghost 6.57.0 (Aug 7) adds analytics for email sequences and speeds up production Docker boot.
- Mattermost 11.10.0 (Aug 4).
- Element Web 1.12.25 (Aug 5).
- OpenProject 17.7.1 (Aug 6).
- ERPNext 16.31.1 (Aug 6), plus 15.119.0.
- PeerTube 8.2.4 (Aug 4).
- Zammad 7.1.2 (Aug 4).
- Wekan 10.73 (Aug 8).
- Invoice Ninja 5.13.30 (Aug 6).
- Jitsi Meet build 11164 (Aug 7).
What Stood Out This Week
Keycloak's FGAP problem. Three of the five CVEs are Fine-Grained Admin Permissions bypasses. FGAP v2 is relatively new, and a cluster of bypasses in one release suggests the feature is still settling. If you adopted it early to delegate admin rights, audit what those delegated admins can actually reach.
Milvus 3.0.0 is a real architecture shift. Lake-native storage, standalone Woodpecker, online schema changes. This isn't a version bump you take on a Friday afternoon. Read the migration notes properly.
Qdrant's TurboQuant 4-bit. Storing only 4-bit quantized vectors and dropping the originals is a serious disk saving for large collections. The trade-off is recall, so benchmark against your own data before committing.
WordPress patched ten branches at once. Nine backports alongside 7.0.3 tells you the maintainers considered this urgent enough to reach installs running four-year-old majors. Treat it accordingly.
All of these run as managed deployments on Elestio, where updates, backups and SSL are handled for you. VMs start at $16/month for the entry NETCUP config (2 vCPU, 4 GB RAM, 60 GB NVMe).
Thanks for reading ❤️ See you next Sunday 👋
Original source - Aug 4, 2026
- Date parsed from source:Aug 4, 2026
- First seen by Releasebot:Aug 5, 2026
Introducing Historical Metrics: Look Back Up to 31 Days in Your Dashboard
Elestio adds Historical metrics to every service dashboard, giving users a live and past view of server performance. The new Metrics tab lets teams scroll back 6 hours to 31 days and review CPU, disk I/O, network bytes, and packets for faster incident checks and planning.
What just shipped
You know the feeling. Someone pings you: "the app felt slow around 2 AM last night." You open your dashboard, and the live graph shows you exactly one thing: right now, everything is fine. The moment you needed is gone, because a live chart only ever knows the present. You are left guessing whether it was a CPU spike, a traffic surge, or nothing at all.
We built Historical metrics to end the guessing. It is now live in every Elestio service dashboard, and it lets you scroll back in time to see exactly what your server was doing when it mattered.
Open any service, go to the Metrics tab, and you will find a toggle between Live and Historical. Live mode still does what it always did, streaming real-time performance as it happens, including live memory usage.
Flip the toggle to Historical and you can look back across four time ranges:
- 6 hours
- 24 hours
- 7 days
- 31 days
Historical mode is the new part: a recorded view of the past, so "what happened last night" becomes a question you can actually answer.
The metrics you can look back on
Historical mode tracks four measurements over your selected window:
METRIC WHAT IT TELLS YOU CPU Usage Processor utilization over time Disk I/O Read and write throughput in KB/s Network Bytes Inbound and outbound data transfer Network Packets Inbound and outbound packets per secondPut together, those four give you a real picture of a moment in the past, not just a number but the shape of what led up to it. Memory usage stays in the Live view, so you still get real-time RAM at a glance.
Why this actually helps
Incident forensics.
This is the obvious one. When something went sideways at 2 AM, switch to the 24-hour view and look for the spike. Was the CPU pinned? Did disk I/O jump? Did network traffic surge right before the slowdown? The answer is usually sitting right there in the graph.
Capacity planning.
The 31-day view is where the slow-burning problems show up. A CPU baseline that keeps climbing week over week is your app telling you it is outgrowing its VM, and disk I/O that trends steadily upward is often the same story. You cannot see either of those in a live chart.
Right-sizing your server.
Before you upgrade (or downgrade) a VM, look at the real numbers over a week or a month. If your CPU never crosses 30 percent, you might be paying for headroom you do not use. If it is regularly redlining, it is time to scale up before your users feel it.
Spotting patterns.
Traffic that spikes every day at the same hour, a backup job that hammers disk I/O every night, a report that doubles network transfer on a schedule: these repeat, and the historical view makes them obvious.
A couple of honest notes
Metric availability depends on your infrastructure provider, so it is worth knowing the edges:
- Scaleway and BYOVM (bring your own VM): live metrics only, with no historical data at this time.
- Vultr: only bandwidth data is available through its API, so CPU and disk metrics are not. That bandwidth data also updates periodically and is grouped by full UTC calendar day, so recent intervals may take some time to appear.
On every other supported provider, you get the full set of historical metrics described above. We would rather tell you this up front than have you go looking for a graph that is not there.
Go look at last night
The best part is that there is nothing to set up. If you run a service on Elestio, Historical metrics is already in your dashboard waiting for you. Open the Metrics tab, flip to Historical, and pick a range.
For the full details, including the per-provider specifics, see the Historical metrics documentation. And if you are not on Elestio yet, this is the kind of thing that comes standard with fully managed hosting: the monitoring is just there, no Grafana stack to wire up yourself.
Go pull up last night. We think you will like finally being able to see it.
Thanks for reading ❤️ See you in the next one 👋
Original source - Aug 2, 2026
- Date parsed from source:Aug 2, 2026
- First seen by Releasebot:Aug 2, 2026
Elestio Catalog Updates: 13 New Releases This Week (July 26 - August 1, 2026)
Elestio highlights a busy open-source release week with major updates across n8n, Supabase, Paperless-ngx, Immich, and more. The standout themes are AI-ready workflow tools, a new Envoy-based Supabase gateway, smoother document handling, and broader self-hosted deployment options.
It was a busy week across the Elestio catalog, with releases landing everywhere from databases to document management. This roundup covers the notable open-source updates from July 26 to August 1, 2026, so you can see what changed in the tools you actually run. No critical CVEs hit catalog services this week, which is the kind of quiet we like.
Databases
- Valkey 9.1.1 (late July): the community-run, Redis-compatible fork shipped a maintenance release with stability fixes. If you moved off Redis after the relicensing, this is a clean, low-risk bump to stay current on.
Development
- n8n (July 29): the headline release of the week. n8n added an AI workflow builder, a workflow review feature, native MCP support, expanded API capabilities, and stronger admin-managed credentials with better OAuth handling. Native MCP turns your workflows into tools an AI agent can call directly, which is a real shift in what n8n is for.
- Supabase (late July): the self-hosted stack switched its default API gateway from Kong to Envoy, bringing a hardened, HTTP-first setup with config-as-code routing. Wrappers v0.6.2 also lets you query and join MongoDB collections straight from Postgres.
- Authentik 2026.5.3 (late July): a maintenance update for the identity provider, flagged as a safe upgrade. Auth is the one service you never let fall behind, so take it.
Hosting & Infrastructure
- Grafana 13.0.3 (late July): a maintenance point release for the observability layer, marked safe to update. Boring, which on the dashboard you stare at during incidents is exactly what you want.
- Uptime Kuma 2.4.0 (late July): the default self-hosted monitoring and status-page tool shipped a new 2.x release with fixes and refinements. A low-risk upgrade for anyone running it.
Applications
- Paperless-ngx 3.0.4 (July 29): following 3.0.3, this release polished OCR, search indexing, permissions, previews, email parsing, and the LLM workflows. Document handling is smoother and live updates are more reliable.
- Immich v3 (late July): the self-hosted photo app continued its 3.x line and began publishing its Android app to FUTO's official F-Droid repository, so you can install the client without going through the Play Store.
- Nextcloud 34.0.2 (July): maintenance updates landed across the supported lines, with recommended versions 32.0.13, 33.0.7, and 34.0.2 for Hub 25 Autumn, 26 Winter, and 26 Spring. Routine, but worth applying if you run the productivity suite.
- Vaultwarden (late July): worth a mention because the Bitwarden clients hit 2026.7 on July 28 with direct KeePass import, which pairs nicely with a self-hosted Vaultwarden server for anyone migrating off a local .kdbx file.
- Discourse 2026.7 (late July): the forum platform shipped its monthly release with the usual round of improvements and fixes.
- Metabase 63 (July): a new major version of the open-source BI tool, continuing its steady cadence of dashboard and querying improvements.
- Rocket.Chat 8.6.1 (July): a maintenance release for the team chat platform with stability and security fixes.
What Stood Out This Week
n8n going full agent platform. The native MCP support is the release that matters most. It turns n8n from "self-hosted Zapier" into a control plane your AI agents can call into, and the new AI builder lowers the barrier for everyone else. If you run one upgrade this week, run this one.
Supabase swapping Kong for Envoy. Changing the default API gateway on the self-hosted stack is a bigger deal than a version bump. It is a more hardened, config-as-code foundation, and it signals Supabase taking self-hosters seriously rather than treating the open stack as an afterthought.
Paperless-ngx sharpening its LLM workflows. The OCR and search fixes are nice, but the LLM workflow polish is the story. Your document archive is quietly becoming something an AI agent can query, which is a very different product than a place to dump scans.
Immich reaching people outside the Play Store. Shipping to F-Droid is a small change with a big message: a project built to get your photos off Google should not make you install its app through Google. The 3.x line is the most polished Immich has been.
Also Brewing
A couple of big ones are still in beta and worth watching, though they did not ship stable this week. PostgreSQL 19 is in Beta 2 and marching toward general availability later this year, and it underpins a large chunk of the catalog. WordPress 7.1 is in its beta cycle with a final release targeted for August 19. If either is core to your stack, now is the time to test against the betas.
Deploy Any of These in One Click
Every tool above is available as a fully managed, one-click deployment on Elestio, with updates, backups, and TLS handled for you, so patch week stops being your problem. Browse the full catalog of 400+ open-source services at elest.io.
That is the week. See you in the next one 👋
Original source - Jul 31, 2026
- Date parsed from source:Jul 31, 2026
- First seen by Releasebot:Aug 1, 2026
Self-Hosted Weekly: Week 31, 2026. n8n AI Builder, Immich 3, Paperless-ngx 3.0.4
Elestio highlights a busy patch week across its self-hosted catalog, led by n8n’s AI builder and native MCP support plus Immich 3’s polished update and F-Droid availability. The rest of the lineup focused on safe maintenance upgrades for core self-hosted tools.
This was a patch-and-polish week across the self-hosted catalog. No dramatic launches, but two projects we care about shipped real upgrades, and a whole stack of tools you probably run pushed point releases worth taking. Here are the eight updates from the Elestio catalog that mattered this week, with a hot take on each so you know what to upgrade and what can wait.
1. n8n ships an AI builder, workflow review, and MCP support
The July 29 n8n release is the big one. It adds an AI workflow builder, a workflow review feature, native MCP support, expanded API capabilities, and stronger admin-managed credentials with better OAuth handling. MCP is the headline: n8n can now sit in the middle of your agent tooling instead of beside it.
Hot take: This is the release that turns n8n from "Zapier you host yourself" into a control plane for AI agents. Native MCP means your workflows become callable tools, and the AI builder drops the barrier for non-developers. If you run n8n, this is the upgrade to prioritize.
2. Immich 3 is here, and it's on F-Droid now
Immich crossed the 3.x line this month (v3.0.0 shipped July 1, with 3.0.x patches and 3.1.0 following), and the Android app started publishing to FUTO's official F-Droid repository. You can now install the client without going anywhere near the Play Store.
Hot take: Distribution is sovereignty too. A project whose entire pitch is getting your photos off Google has no business making you install its app through Google. The v3 line is the most polished Immich has ever been, and Immich remains the self-hosted photo app to beat.
3. Paperless-ngx 3.0.4 polishes OCR, search, and LLM workflows
Paperless-ngx pushed 3.0.4 (following 3.0.3) with fixes across OCR, search indexing, permissions, previews, email parsing, and its LLM workflows. Document handling is smoother, filtering is better, and live updates are more reliable.
Hot take: The LLM workflow fixes are the part to watch. Paperless is quietly turning your document pile into something an AI agent can query, which is a very different product than "a place to dump scans." If you run Paperless-ngx, 3.0.4 is a clean upgrade.
4. Uptime Kuma 2.4.0 keeps the status page honest
Uptime Kuma reached 2.4.0 this cycle. The 2.x line has settled into being the default self-hosted monitoring and status-page tool, and this is a low-risk maintenance bump.
Hot take: Uptime Kuma wins because it does one thing and never gets in your way. There is no reason to pay for a hosted status page when Uptime Kuma gives you the same thing on a tiny VM. Upgrade and forget about it.
5. Authentik 2026.5.3 lands as a safe update
The identity provider shipped 2026.5.3, flagged as a safe update. Authentik keeps closing the gap with the heavyweight SSO options while staying far easier to run.
Hot take: Your identity provider is the one service you never let fall behind on patches, because it is the front door to everything else. If Authentik is your SSO layer, take this update sooner rather than later.
6. Grafana 13.0.3 is a quiet, take-it-now point release
Grafana pushed 13.0.3, a maintenance release marked safe to update. Nothing flashy, which on your observability layer is exactly what you want.
Hot take: Boring point releases on the tool you stare at during an incident are a gift. There is no upside to running an old Grafana. Patch it during business hours and move on.
7. Valkey 9.1.1 keeps the Redis fork marching
Valkey, the community-run Redis fork that emerged after the Redis relicensing drama, shipped 9.1.1. It stays drop-in compatible while being governed in the open under a permissive license.
Hot take: Valkey is now the safe default for a Redis-compatible cache or queue. You get the same API with none of the license risk that pushed everyone to fork in the first place. If you are standing up something new, reach for Valkey instead of worrying about what Redis relicenses next.
8. Nextcloud 34.0.2 rounds out the productivity suite
Nextcloud shipped 34.0.2, the current supported release of the self-hosted file, calendar, and collaboration suite. It is a maintenance update on an already mature line.
Hot take: If you are running Nextcloud as a Google Workspace replacement, 34.x is the stable base you want under it. Nextcloud is not exciting anymore, and that is the whole point when it is holding your team's files.
What We're Watching Next Week
- Whether n8n's new MCP support kicks off a wave of agent-driven automation templates from the community.
- PostgreSQL 19, now in Beta 2, as it marches toward a GA later this year. It underpins half the catalog, so its release matters to everyone.
- Mattermost v10.11 ESR hits end of life on August 15, so if you are on it, plan the upgrade now rather than in two weeks.
The Bottom Line
Two real headliners this week: n8n turning into an agent control plane with native MCP, and Immich 3 landing with proper Google-free distribution. Everything else was the unglamorous heart of self-hosting, keeping the tools you already run current and patched. That maintenance work is boring right up until the day it is not.
The nice part about running these on Elestio is that the point releases land for you automatically, so patch week stops being your problem.
Thanks for reading ❤️ See you next week 👋
Original source - Jul 26, 2026
- Date parsed from source:Jul 26, 2026
- First seen by Releasebot:Jul 27, 2026
Elestio Catalog Updates: 23 New Releases This Week (July 19-25, 2026)
Elestio highlights a busy weekly release roundup led by Paperless-ngx 3.0.0, which brings a major search rewrite, Paperless AI, remote OCR, and document versioning. Vaultwarden, Meilisearch, ClickHouse, and several other apps also ship important updates.
Another busy week across the catalog, and this one leans heavily on security and one genuinely big rewrite. Paperless-ngx shipped a major version, Vaultwarden patched a stack of vulnerabilities, and the usual suspects in databases and observability kept the version numbers climbing. Here is everything worth knowing from July 19-25, 2026.
Security Alerts
Patch these first.
- Vaultwarden 1.37.0 (July 24): Addresses eight medium-severity issues, including SSRF via the icon endpoint, cross-organization cipher access, and unauthenticated WebSocket flooding. This release is also required for compatibility with Bitwarden clients 2026.7.0 and later. Update as soon as you can.
- Grafana 13.1.1 (July 21): Lands during a month of Grafana security disclosures, including high-severity issues around SQL Expressions and public dashboards. If you expose dashboards to the internet, update promptly and review your public dashboard settings.
- Nextcloud 34.0.2 / 33.0.7 / 32.0.13 (July 23): Keeps all three maintained lines current. The recent 2FA bypass tracked as CVE-2026-45690 was fixed in the 32.0.9 and 33.0.3 line, so staying on these patch releases matters if you rely on two-factor auth.
Databases
- ClickHouse 26.7.1 (July 22): A fresh feature release on the fast-moving 26.x line, with backported stability fixes also shipping to the 26.3 LTS, 26.4, and 26.6 branches the same week.
- Valkey 9.1.1 (July 21): Coordinated maintenance across every supported line, with matching patches landing for 9.0.5, 8.1.9, 8.0.10, and 7.2.14 on the same day. A good week to update whichever line you run.
AI / GPU
- Ollama 0.32.4 (July 25): Two releases this week (0.32.3 on July 23, then 0.32.4), continuing the steady cadence of model support and runtime fixes.
- Langflow 1.11.0 (July 23): A new minor for the visual LLM app builder, shipping the same day as the 1.10.3 patch.
Development
- n8n 2.31.6 (July 24): Rolls up editor, core, and AI-builder fixes, with improvements to credential handling and node stability across popular integrations.
- Meilisearch 1.50.0 (July 20): Search rules now scale to 75K without hurting query performance, document fetch endpoints pull from all shards in networked setups, and the facets parameter accepts wildcard patterns like dogs.*.
- Strapi 5.51.0 (July 23): A new minor for the headless CMS with the usual mix of features and fixes.
- Appwrite 1.9.6 (July 22): Maintenance patch for the backend-as-a-service platform.
- Authentik 2026.5.6 (July 22): Maintenance release for the identity provider. Worth staying current on anything guarding your logins.
- Budibase 3.40.1 (July 22): New 3.40 line for the low-code builder, plus a same-week patch.
- Baserow 2.3.3 (July 21): Patch release for the open-source Airtable alternative.
- PocketBase 0.39.9 (July 22): Continued fixes across both the 0.39 and 0.22 lines.
Hosting & Infrastructure
- VictoriaMetrics 1.148.0 (July 20): New minor for the resource-efficient Prometheus alternative, with backports to the 1.136 and 1.122 lines.
- SigNoz 0.134.0 (July 22): Another step forward for the open-source observability stack.
- RabbitMQ 4.3.4 (July 23): Patch release on the 4.3 line, with 4.2.9 also shipping for the older branch.
Applications
- Paperless-ngx 3.0.0 (July 22): The headline release of the week. More on this below. Three quick patches (3.0.1 through 3.0.3) followed through July 25.
- Ghost 6.54.0 (July 24): New minor for the publishing platform.
- Metabase 0.63.1 (July 21): Patch on the v63 line that brought treemaps, two-factor auth, and PDF attachments in dashboard subscriptions.
- Chatwoot 4.16.1 (July 23): Patch for the customer engagement suite.
- Penpot 2.17.0 (July 22): New minor for the open-source design and prototyping tool.
What Stood Out This Week
Paperless-ngx 3.0.0 is the big one. It swaps the old Whoosh search engine for a tantivy backend (faster search and better query support), adds a Paperless AI feature for document suggestions and chat plus remote OCR options like Azure AI, and introduces document versioning so you can keep and revert multiple file versions. A major version with real architectural change, so back up before you upgrade and test on a copy first.
Vaultwarden 1.37.0 is the patch-now story. Eight security fixes in a password manager is not something to schedule for next quarter. If you self-host it, this is today's job.
Meilisearch 1.50.0 quietly shipped serious scaling work. Search rules to 75K and federated fetch across shards are the kind of features that matter a lot once your index grows past a hobby project.
ClickHouse 26.7 keeps the analytics database moving at its usual relentless pace, with fixes flowing to the LTS line too so you do not have to chase the bleeding edge to stay patched.
Every service above is available as a managed, auto-updated deployment on Elestio. If keeping up with this many releases sounds exhausting, that is exactly the point of letting someone else handle the patching.
Thanks for reading ❤️. See you next week 👋
Original source - Jul 24, 2026
- Date parsed from source:Jul 24, 2026
- First seen by Releasebot:Jul 25, 2026
AFFiNE 0.27: New Importers, Calendar View, and a Sync Warning
Elestio highlights AFFiNE 0.27 with native imports for OneNote, Obsidian, Bear, and Notion, a new Calendar view for databases, experimental AI BYOK, faster canvas performance, steadier mobile use, and important server-client compatibility changes.
New importers: OneNote, Obsidian, Bear, and Notion
If you have ever tried to move years of notes out of Notion or Obsidian, you know the feeling. Your knowledge is right there, but it is locked inside someone else's app, and getting it out cleanly feels like defusing a bomb. AFFiNE has always pitched itself as the escape hatch: an open-source, local-first workspace that folds docs, whiteboards, and databases into one tool you can actually self-host. The new 0.27 release, shipped in July 2026, leans hard into that promise.
If you are new here: AFFiNE is a single app that behaves like Notion and a Miro-style infinite canvas at the same time, with your data living on your own server instead of someone else's cloud. Let's walk through what 0.27 changes, and the one thing you need to know before you upgrade.
This is the headline for most people. AFFiNE 0.27 adds native importers for OneNote, Obsidian, Bear, and Notion. If you have been waiting for a clean migration path off a proprietary notes app, this is it. Instead of exporting to Markdown and praying your links survive, you point AFFiNE at your existing workspace and pull it in directly.
Migration is usually the single biggest reason people stay locked into a tool they have outgrown. Making it a first-class feature is exactly the right move for a project whose whole reason to exist is data ownership.
Calendar view for databases
AFFiNE's Database blocks already gave you table and kanban views. Now there is a proper Calendar view. Anything with a date property (deadlines, content schedules, tasks) can be laid out on a real calendar without exporting to a separate app.
Alongside it, 0.27 fixes a batch of Database annoyances: display glitches, sorting behavior, and keyboard shortcuts for table cells that did not always cooperate.
Bring your own AI key (experimental)
0.27 adds an experimental AI BYOK (bring your own key) feature. Instead of being tied to AFFiNE's hosted AI, you can plug in your own provider key. For a self-hoster this matters: it means the AI features can run through an account you control, which is far more comfortable than routing your private notes through a default cloud endpoint. It is flagged experimental, so treat it as a preview, not a production guarantee.
Technical writers get some love too: Code Block, LaTeX, Mermaid, and Typst rendering all behave better in this release.
Faster canvas and steadier mobile
The Edgeless (whiteboard) mode got a performance pass: better rendering, lower memory use, and improved touch responsiveness. On iOS, the whiteboard now shows a zoom percentage, switches faster, and a nagging image-insertion bug is fixed. Mobile input stability and recording were tightened up as well.
On the backend, AFFiNE now automatically cleans up blobs you delete from clients, and the CalDAV sync queue and task queue got compatibility and stability fixes.
The one thing to know before you upgrade
Here is the part you cannot skip. AFFiNE 0.27 ships a breaking change:
Starting from server version 0.27, only clients at version 0.26 or higher can connect and sync.
In plain terms: if you update your self-hosted AFFiNE server to 0.27 while your desktop or mobile apps are still on 0.25 or older, those clients will stop syncing. Update your clients to 0.26 or later first, then upgrade the server. If you manage a team, send that note around before you touch the server.
Running AFFiNE 0.27 on Elestio
You can self-host AFFiNE on Elestio starting around $11/month for the managed VM, with TLS, backups, and updates handled for you. That "no license fees, just infrastructure" model is the whole appeal of self-hosting a Notion alternative: you pay for a server, not per seat.
A few things worth doing right after you deploy or upgrade:
STEP WHY IT MATTERS Update every client to 0.26+ first Older clients cannot sync with a 0.27 server Take a backup before upgrading Elestio snapshots let you roll back if a migration goes sideways Test one importer at a time Confirm your OneNote or Notion structure comes across as expectedTroubleshooting
- Clients stopped syncing after the upgrade: almost always the breaking change. The affected client is below 0.26. Update it and sync resumes.
- An importer brought content in but the structure looks off: re-run it on a smaller subset first, and check that nested pages and attachments exist in the source export.
- AI BYOK is not responding: confirm the key is valid and has quota with your provider, and remember the feature is experimental in this release.
- CalDAV events are not appearing: the sync queue changed in 0.27, so give it a full sync cycle and verify your CalDAV credentials after the upgrade.
Should you upgrade?
If you self-host AFFiNE, 0.27 is an easy yes, as long as you handle the client-version order. The importers alone make it worth it if you still have notes trapped somewhere else, and the Calendar view plus the Edgeless performance work make the daily experience noticeably smoother.
Want to try it without the setup overhead? Spin up AFFiNE on Elestio and you can have your own private workspace running in a few minutes.
Thanks for reading ❤️. See you in the next one 👋
Original source - Jul 19, 2026
- Date parsed from source:Jul 19, 2026
- First seen by Releasebot:Jul 20, 2026
Elestio Catalog Updates: 26 New Releases This Week (July 12-18, 2026)
Elestio ships a busy weekly catalog update with 26 stable releases across identity, databases, AI, dev tools, and apps, led by Gitea security hardening, NocoDB Calendar Sync, and Chatwoot help center upgrades.
Another busy week across the Elestio catalog. Twenty-six stable releases landed between July 12 and 18, with a heavy run of identity and database updates, a fresh Ghost, and a major Paperless-ngx beta on the horizon. Here's everything worth updating for, grouped by category.
Security note
Gitea 1.27.0 ships several security hardening fixes this week, including stricter public-only token scopes, hardened access checks, and proof-of-possession requirements for cross-repo objects. If you self-host Gitea, treat this as a priority update rather than a routine one.
Databases
- InfluxDB v3.10.3 (July 15): Point release for the 3.x time-series engine with bug fixes and stability improvements.
- Milvus 2.6.20 (July 15): Maintenance release for the vector database, with fixes across the query and index paths.
- Weaviate v1.38.5 (July 16): LSM store performance improvements, a fix for potential deadlocks in batch vectorization, and a leaner reference cacher. Backports also landed for the 1.37 and 1.36 lines.
- TimescaleDB 2.28.3 (July 16): Patch release for the Postgres time-series extension.
AI/GPU
- Ollama v0.32.1 (July 16): Follows the 0.32.0 feature release with fixes for model loading and runtime stability.
- Dify v1.16.0 (July 17): New minor release for the LLM app platform, continuing work on workflows and the plugin ecosystem.
- Langflow v1.11.0 (July 17): Feature release for the visual agent builder, arriving alongside a 1.10.3 security fix that isolates serve request logs.
Development
- Gitea 1.27.0 (July 13): Owner-level and global scoped Actions workflows, the security hardening noted above, plus token introspection and an OpenAPI 3.0 spec.
- n8n 2.31.3 (July 17): The automation platform kept up its rapid cadence, shipping patches across both the 2.x and 1.x lines through the week.
- Strapi v5.50.2 (July 15): Patch release for the headless CMS with bug fixes and dependency updates.
- NocoDB 2026.07.0 (July 14): Calendar Sync pulls Google, Outlook, or CalDAV events into a read-only table, plus image annotations and a new comment-based workflow trigger.
- Directus v12.1.1 (July 13): The 12.1 line brings fixes and refinements on top of the 12.0 major, landing several point releases in a single day.
- Authentik 2026.5.5 (July 15): Maintenance releases across the 2026.5 and 2026.2 lines for the identity provider.
- PocketBase v0.39.7 (July 16): Patch release for the single-binary backend, with a matching 0.22 backport.
- Zitadel v4.16.1 (July 17): Fixes for the cloud-native identity platform across the 4.x and 3.x lines.
- Qdrant v1.18.3 (July 17): Patch release for the vector search engine.
- Budibase 3.39.31 (July 15): Two point releases for the low-code app builder with bug fixes.
Hosting & Infrastructure
- Portainer 2.39.5 LTS (July 13): LTS maintenance release for the container management UI.
- VictoriaMetrics v1.147.0 (July 16): New minor for the time-series database and monitoring stack, following 1.146.0 earlier in the week.
- SigNoz v0.133.0 (July 15): Fresh release for the OpenTelemetry-native observability platform.
Applications
- Ghost v6.53.0 (July 17): Latest weekly release for the publishing platform (yes, this blog runs on it).
- Immich v3.0.3 (July 15): Point release settling the big 3.0 line, which brought Workflows, HLS transcoding, a rebuilt mobile editor, and integrity reports.
- Mattermost v11.9.0 (July 16): Feature release for the team messaging platform, alongside security-focused patch releases across older supported lines.
- Metabase v0.63.1.2 (July 17): Patch releases across the 0.63, 0.62, and 0.61 lines for the BI tool.
- Chatwoot v4.16.0 (July 18): Help Center staged edits and reordering, report drilldowns, and an Intercom import workflow. Note the video-call integration moved from Dyte to Cloudflare RealtimeKit, so existing setups need reconfiguring.
- ERPNext v16.28.0 (July 15): Feature and fix releases across the 16.x and 15.x lines of the ERP suite.
What stood out this week
NocoDB's Calendar Sync is the most genuinely new feature of the week. Pulling Google, Outlook, or CalDAV events into a live read-only table turns NocoDB into a place where scheduling data and your own records finally sit side by side, without a brittle Zapier chain in between.
Gitea 1.27.0 matters for two reasons: the security hardening is not optional given the rough month self-hosted Git has had, and owner-level scoped Actions workflows are a real quality-of-life win for anyone running CI on their own instance.
Chatwoot 4.16.0 is worth a careful read before you upgrade. The Help Center improvements are great, but the video-call backend swapping from Dyte to Cloudflare RealtimeKit means you'll need to reconfigure calls, so don't run this one blind on a Friday.
And keep an eye on the horizon: Paperless-ngx tagged a 3.0.0 beta on July 18. It's not production-ready yet, but a major version of one of the most-loved document management tools is worth watching over the coming weeks.
Every service above is available as a fully managed, one-click deployment on Elestio, with backups, SSL, and updates handled for you. Browse the full catalog at elest.io/fully-managed-services.
Thanks for reading ❤️ See you next Sunday 👋
Original source - Jul 12, 2026
- Date parsed from source:Jul 12, 2026
- First seen by Releasebot:Jul 13, 2026
Elestio Catalog Updates: 12 New Releases This Week (July 5-11, 2026)
Elestio ships a busy week of catalog updates with stronger security, better observability, and faster search. Highlights include Keycloak’s SCIM preview, SigNoz’s dashboard overhaul, Meilisearch’s synonym performance boost, and fresh releases for Immich, n8n, Langflow, and VictoriaMetrics.
Another busy week across the catalog. Twelve services in the Elestio catalog shipped new versions between July 5 and July 11, and this batch leans heavily toward security hardening and observability. Keycloak added a preview SCIM API, SigNoz pushed a big dashboard overhaul, and Immich kept its rapid v3 cadence going. Here is everything worth knowing, grouped by category.
Databases
ClickHouse v25.8.28.1-lts (July 5): A new long-term-support build in the 25.8 line, published across 52 distribution assets covering AMD64 and ARM64 as archives, RPM, and DEB packages. If you run ClickHouse in production, the LTS track is the one to pin to for predictable maintenance.
AI / GPU
Langflow v1.10.2 (July 7): This one is security-forward. It adds global variable model overrides so you can swap models across flows in one place, and it hardens the code-execution path by blocking public builds of code-execution agents and restricting MCP stdio access. Python 3.14 compatibility landed too.
Development
Keycloak 26.7.0 (July 9): The headline is a preview SCIM API for automated user provisioning and deprovisioning with standard tooling. It also ships a simplified multi-cluster HA setup that drops the external cache requirement (preview), step-up authentication for SAML clients, and cleaner reverse-proxy blueprints for HAProxy and Traefik.
n8n 2.29.10 (July 10): Capping a steady week of releases (2.29.7 through 2.29.10), this stream focused on reliability: AI Agent and Code node fixes when workflows contain AI tools, safer expression handling, and Postgres-only connection recovery. Boring in the best way.
Meilisearch v1.49.0 (July 6): Reworked synonym storage with lazy loading delivers up to a 13x performance gain depending on how many synonyms you run. If your search config leans on large synonym lists, this is a free speedup.
PocketBase v0.39.6 (July 8): Adds Cc and Bcc recipients to the dev sendmail command, hardens the Microsoft OAuth2 provider with safer email extraction, and bumps the minimum Go version to 1.26.5 along with a WeakMap regression fix.
Hosting & Infrastructure
SigNoz v0.132.2 (July 8-10): A three-release sprint (v0.132.0 to v0.132.2) that overhauls dashboards. You get v2 Perses-spec public dashboards, dashboard variables with dynamic panel substitution, a new Kubernetes container monitoring API, and reworked trace details with a width-driven layout and shared metadata. The observability crowd should upgrade.
VictoriaMetrics v1.147.0 (July 6): Security and efficiency in one release. vmauth now adds a 2-3 second delay on failed auth attempts per OWASP guidance to blunt brute-force attacks, vmagent cuts CPU usage by roughly 10% for remote-storage sharding, and stream aggregation handling for out-of-order samples improved.
Applications
Immich v3.0.2 (July 9): The photo-management juggernaut keeps moving. This patch adds HLS variant configuration for more flexible video streaming, a date-based filter for the Workflows automation system, and 24-plus bug fixes covering mobile video playback, OAuth account linking, and search visibility.
Mattermost v11.9.0 (July 8): A fresh stable minor release following three release candidates, arriving right after the v11.8.3 bug-fix patch on July 6. If you self-host team chat, this is the current stable to target.
Metabase 61.7 (July 9): A stable maintenance release on the 61 line, shipped alongside a 60.12 patch for older deployments and a 63.0-beta for anyone who likes living on the edge (not in production, please).
Ghost v6.52.1 (July 10): The v6.52 line adds tax ID collection to Stripe checkout when automatic tax is enabled, retires the outdated Tenor GIF provider, and fixes mobile display plus color-accessibility issues. The v6.52.1 patch cleaned up link selection in the automations email editor.
What stood out this week
A few releases are worth more than a line:
- Keycloak's SCIM preview is the big one for anyone managing identity at scale. Automated provisioning and deprovisioning through a standard API is the feature enterprises keep asking for, and the simplified HA path is a nice bonus for multi-region setups.
- SigNoz's dashboard overhaul signals it is serious about being a real Grafana-adjacent observability platform, not just a tracing tool. Public v2 dashboards and Kubernetes container monitoring close real gaps.
- Meilisearch's 13x synonym speedup is the kind of quiet performance win you get for free just by upgrading. No config changes, just faster search.
- Langflow and VictoriaMetrics both shipped security hardening this week (agent code-execution restrictions and OWASP brute-force delays, respectively). A good reminder that "upgrade regularly" is itself a security practice.
Every one of these runs on Elestio as a fully managed, one-click deployment with automated backups and updates. Browse the full Elestio catalog to spin one up, or if you already run these, your managed instances will pick up the new versions on the standard update cycle.
Thanks for reading ❤️ See you next week 👋
Original source - Jul 5, 2026
- Date parsed from source:Jul 5, 2026
- First seen by Releasebot:Jul 6, 2026
Elestio Catalog Updates: 9 New Releases This Week (June 29 - July 5, 2026)
Elestio highlights a busy weekly release roundup with Immich v3, Ollama speed boosts for Gemma 4 on Apple Silicon, and notable security and feature updates across Directus, Open WebUI, Appwrite, Grafana, n8n, ClickHouse, and Rocket.Chat.
A quieter week than the last, but a meaningful one. Immich shipped its long-awaited v3, Ollama made Gemma 4 dramatically faster on Apple Silicon, and a handful of developer platforms landed security hardening worth applying. Here's everything that shipped across the Elestio catalog from June 29 to July 5, 2026.
Security Notes
No headline CVE numbers this week, but three releases carry security fixes you shouldn't sit on:
- Directus 12.1.1 hardened its GraphQL layer (single-use sensitive mutations), removed the hash utility endpoints, and moved to distroless Docker images.
- Open WebUI 0.10.2 ships access-control and security improvements; prioritize this one on production instances.
- Rocket.Chat 8.6.0 bundles security, authentication, and data-protection changes.
If you run any of these, upgrade sooner rather than later.
Databases
ClickHouse 26.5.5.8-stable and 25.8.25.37-lts (June 30 to July 1) - Two branch releases this week: a fresh stable in the 26.5 line and a long-term-support build in the 25.8 line for teams that stay on LTS. Both ship the usual signed packages across amd64 and arm64. If you value stability over new features, the LTS bump is the one to track.
AI / GPU
Ollama 0.31.1 (June 30) - The headline is speed: Gemma 4 now runs nearly 90% faster on Apple Silicon thanks to multi-token prediction and a new small-batch matmul kernel in the MLX engine. The bundled llama.cpp engine was also bumped. If you self-host Gemma 4 on Mac hardware, this is a free performance win.
Open WebUI 0.10.2 (July 1) - Reasoning models now stream their thinking content live and render it correctly in the chat overview and exported conversations. Dragging a folder into a knowledge base finally preserves the subfolder structure instead of flattening everything. Plus the security fixes noted above.
Development
n8n 2.28.6 (July 3) - A stability-focused week for n8n. This build fixes duplicate zod instances that were breaking npm installs, cleans up parameter input alignment in the editor, and stops duplicate AI Gateway notices from appearing. Several pre-release 2.29.x builds are also in flight if you like living on the edge.
Directus 12.1.1 (July 1) - Beyond the security hardening, this release adds a PROJECT_OWNER_ENABLED option, updates Vite to 8.1.2 across app and API, and ships distroless Docker image variants. A small but sensible maintenance release for a fast-moving headless CMS.
Appwrite 1.9.5 (July 1) - A big one for the backend-as-a-service crowd. Public APIs now cover project variables, keys, SMTP, auth methods, platforms, and OAuth2 providers. The database layer gains BigInt support and JSON import/export for DocumentsDB and VectorsDB, and auth picks up disposable-email blocking, password policies, and impersonation support.
Hosting & Infrastructure
Grafana 13.1.0 (July 1) - Annotations clustering reached general availability, so busy dashboards stop drowning in overlapping markers. Alerting gained Rules API v2 support in the panel alert rule drawer, and JWT auth now accepts inline public keys. A solid feature release on the heels of last week's security patch.
Applications
Immich 3.0.0 and 3.0.1 (July 2) - The big one. Immich v3.0.0 landed with non-destructive mobile editing, a workflows preview, and improved background backup. The same-day v3.0.1 patch quickly fixed a bug where albums weren't showing up in the mobile app and added a recently-added link to the web sidebar. If you self-host your photos, this is the most significant update in months, though as always, wait for your backup to complete before jumping on a brand-new major.
Rocket.Chat 8.6.0 (July 3) - A security-and-compliance release with authentication changes and data-protection improvements, supported through January 2027. Worth planning an upgrade for any team running Rocket.Chat in a regulated environment.
What Stood Out This Week
Immich v3 is the obvious standout. Non-destructive mobile editing and workflows push it further into "genuinely better than the SaaS it replaces" territory, and the fact that v3.0.1 followed v3.0.0 within hours shows a team that watches its release channel closely.
Ollama's Gemma 4 speedup is quietly huge for anyone running local models on Mac hardware. A ~90% throughput jump from an engine-level optimization, with zero changes to your setup, is exactly the kind of free win self-hosters love.
Appwrite 1.9.5 meaningfully expands what you can automate through its public APIs, which matters if you're building agents or infrastructure-as-code around it. Combined with Grafana 13.1.0's annotations clustering going GA, it was a good week for developer-facing polish.
Deploy Any of These on Elestio
Every service above is available as a fully-managed, one-click deployment on Elestio, with automated backups, SSL, and updates handled for you. Browse the full catalog of 400+ open-source services at elest.io and have the latest version running in minutes.
Thanks for reading ❤️ See you next week 👋
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.