Freshrss Release Notes

Follow

30 release notes curated from 2 sources by the Releasebot Team. Last updated: Sep 9, 2026

Get this feed:
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.30.0

    Freshrss releases a major security-focused update with critical patches and a new default block on local network access. It also adds stronger feed filtering, smarter unread badge controls, refreshed current-view feeds, and many fixes across search, UI, API, and imports.

    Milestone

    This is a security-oriented major release with several important security patches, so users are encouraged to update without delay.

    From this release, we are also making it clear that our rolling-release channel (edge) is recommended for faster security patches.

    Breaking change 💥:

    Disallow access to local networks such as 127.0.0.1 by default, for security reasons

    Feature highlights✨:

    Filter global view feed list by state and search

    New option to hide badges showing number of unread articles (Phantom Obligation)

    Refresh only feeds in the current view

    Offer to add a prefix when re-sharing user labels

    Bug fixes highlights 🐛:

    Several security attack scenarios patched

    Fix lost elements while parsing search query

    Fix “mark as read older than…” widening the active search

    Fix saving user queries

    Fix SQL errors breaking some regex searches with MySQL / MariaDB

    This release has been made by @Alkarex, @andris155, @ColonelMoutarde, @Frenzie, @IEEE-754, @Inverle, @math-GH, @nykula, @polybjorn, @Stunkymonkey and newcomers @0xdeadrelay, @AdamKorcz, @aligundogar, @bossaarebecca-alt, @Cactys12, @chrislongros, @Divinelink, @Elgeryy1, @featurecreep-cron, @Fripix, @fzlzjerry, @georatas, @gshimo, @iatman ,@ihsanarifr, @jamalkamaladdin, @JamBalaya56562, @jbrayton, @jeremy-code, @juherr, @kobihikri, @LeeXiaolan, @masskrdjn, @mohammadlashkari, @nathanpixodeo, @Otolock, @payaci, @salvador-castro, @SamCyber001, @satyvm, @senti-man, @simitana, @ThomasVermeer, @Totara-thib, @TowyTowy, @utkutibet, @XiaoSong1223

    Full changelog

    Security

    💥 Disallow access to local networks such as 127.0.0.1 by default, for security reasons (breaking change) #8400, #9195

    Selected local networks can be allowed under System configuration or using the INTERNAL_HOST_ALLOWLIST environment variable

    Passing * allows all networks like before (unsafe)

    Improve SSRF mitigations by restricting CURLOPT_PROXY #8950

    Fix auth CSRFs (login and register actions) #9171

    Log invalid challenge and ignore JSON error during login #9278

    Disallow fetching of non remote URI #9215

    Only allow HTTP/HTTPS schemes for enclosure and thumbnail URLs #9272

    Fix access control in rss and opml actions #8912

    Refactor to use CSRF field directly instead of borrowing it from a form #9169, #9205

    Cleaner limit anonymous mode to default user #9235

    Fix HTML ingestions in templates #9146, #9170

    Fix bad header filtering bypass #8964

    Sanitize all fields during JSON import #9168

    Gate greader (JSON) user query share format behind Share by OPML #9248

    Public OPML should not contain cURL parameters #9070

    Ignore security-relevant OPML attributes for dynamic OPML sources #9276

    Strip feed URL credentials from anonymous user query output #9246

    Set limits for regex during search #8913

    Fix path disclosure in cache error message #9206

    Limit the length and parentheses nesting depth of a search query #9277

    Use timing-safe comparison for tokens #8945

    Use hash_equals() for GReader API token comparison #9183

    Mailer: allow disabling SMTPAutoTLS via config #9026

    Warn during install if document root does not point to ./p/ #9010

    Stop the unread-count poller after the session ends #9065

    Add remote IP address to warning on form login #8942

    Pin the GitHub actions using SHA #9200

    Harden cache and SimplePie cache deserialization #9273

    SimplePie

    Security: Disallow javascript: URI scheme (protocol) #8263

    Fix wrong player parent logic leading to invalid type #8893, simplepie#978

    Consistently enable XML_OPTION_PARSE_HUGE #8894, simplepie#977

    Fix null warning in IRI for PHP 8.5+ #8918, simplepie#979

    Fix sanitizer whitelist stripping order #9066

    Show only one representation per media:group #9009

    Bump upstream SimplePie #8947

    Features

    Filter global view feed list by state and search #9132

    Use global view when searching from subscription page #9144

    New option to hide badges showing number of unread articles (Phantom Obligation) #8844

    Refresh only feeds in the current view #9060

    Offer to add a prefix when resharing user labels #9236

    Add log search to the logs page #9059

    Add configurable log_level system setting #9185

    New option to keep or not the custom sort order when navigating between categories and feeds #8969

    New per-feed option to show or hide enclosures (attachments) #9015

    Detect JSON feeds from URLs containing json #9058

    Also when subscribing via the API #9167

    Order categories during OPML import/export according to position #9203

    OPML: include each feed’s refresh interval (TTL) in export/import #8982

    Log failed CSS content retrieval (Web scraping) #9077

    Allow providing a category when adding a feed by bookmarklet #9047

    Add LinkAce sharing service #9024

    Add Nextcloud Bookmarks sharing service #9032

    Bug fixing

    Fix lost elements while parsing search query #8884

    Fix “mark as read older than…” widening the active search #9173

    Fix saving user queries #9190

    Fix SQL errors breaking some regex searches with MySQL / MariaDB #9036

    Fix marking filtered label articles as read in SQLite and PostgreSQL #9264

    Fix tagging an already-tagged entry on PostgreSQL raising a SQL error instead of being a no-op #9136

    PostgreSQL: make committing new entries resilient to duplicate keys #9231

    Preserve negative timezone offsets in date intervals #9071

    Fix feed dropdown bugs due to hash desync #8949

    Fix slider not reinitializing after form submit #8973

    Minz: Skip loading duplicated JS/CSS assets #9000

    Respect simplepie_syslog_enabled for the uses cache logs #8986

    Fix statistics repartition averages #8996

    Fix article hover date visibility #8997

    Keep search and state filters when marking articles as read #9007

    Fix --db-prefix silently drops following CLI flags #9042

    Remove stale dynamic favicon links #9127

    Fix desync between favicon and title unread counters #9262

    Fix outdated username length hint on registration and install forms #9013

    Redirect away from wrong URL paths #9075

    Fix auto-share shortcut on first use #9072

    Exclude hidden feeds from global view counts #9152

    Fix only the last <media:credit> being written to the RSS output #9174

    CLI

    New cli/reconfigure-user.php to read/write per-user config attributes #8873

    Report new articles count per feed in app/actualize_script.php output #8948

    Output a diagnostic when the cli/health.php check fails #8980

    API

    Add a warning message to the API password section and a log warning when a client uses GET instead of recommended POST #8845

    Fever API: log the client IP address on authentication failure #8981

    WebSub: ignore HTTP/HTTPS scheme difference in Self URL comparison #9005

    Deployment

    Docker alternative image updated to Alpine 3.24 with PHP 8.5.7 and Apache 2.4.67 #8916

    Start supporting PHP 8.6+

    Docker dev :newest with PHP 8.6 #9155

    Docker: attach provenance and SBOM attestations to the published image #9150

    Apache use only CONN_REMOTE_ADDR in logs when mod_remoteip is available, for compatibility with LiteSpeed Web Server #8890

    Fix .dockerignore being ignored during build in CI #9001

    New ENABLE_ACCESS_LOG environment variable to disable access logs #9191

    Check GMP during 32-bit installation #9046

    Improve actualize mutex to allow multiple instances #9045

    OIDC: redirect to a default URL on expired auth state instead of 400 #9143

    UI

    Always jump article to top when header is offscreen, also when Stick the article to the top when opened is disabled #8870

    Move article header/footer options (feed title, authors and date, icons position, tags) from Reading to Display configuration #9139

    Move disable button before remove button in user management #8944

    Keep scroll position of slider after form submit #8974

    Group export feeds by category #9079, #9154

    Sort feed names with locale-aware collation #8985

    Sort labels with locale-aware collation #9023

    Format unread counter in title on page load #9263

    Display slider after submit for all buttons in feed update UI #8999

    Improve aside keyboard navigation #9202

    Allows usage of Ctrl/Shift keys with the open website shortcut #9186

    Fix padding for .nav_menu in Alternative-Dark, Flat, and Nord themes #8901

    Fix typo in alert error border color variable #9266

    Use JavaScript Event() constructor instead of deprecated initEvent() #9035

    Use :user-invalid instead of :invalid for CSS form field styling #9025

    Remove unused simple layout #8998

    Various UI and style improvements: #8823, #8824, #9140, #9145

    Extensions

    Minor Minz_Extension typing #8952

    Improve extension list fetch diagnostics #9055

    Fix a PHP warning in Serve action #9267

    Fix extension settings cancel action #9053

    Fix sharing menu conflicts with extensions #9074

    Add read status hook for entries #8995

    Dispatch a new JavaScript event freshrss:entryStateChange when an entry finishes being marked read/unread #9031

    Redirect after saving user CSS/JS so changes apply immediately #9006

    I18n

    New plural system #8988

    Pluralize the new articles count message

    Prefer OS-bundled Japanese fonts when UI language is Japanese #9002

    Add Azerbaijani #9269

    Add Lithuanian #9201, #9213

    Improve Brazilian Portuguese #9240, #9242

    Improve German #9149

    Improve Greek #8977, #9038

    Improve Hungarian #8879

    Improve Indonesian (Bahasa Indonesia) #9220

    Improve Italian #8880

    Improve Japanese #9064

    Improve Persian #8923

    Improve Spanish #8878, #9245

    Improve Traditional Chinese #9037, #9069, #9223

    Improve Turkish #8966, #8971, #8970, #8989

    Improve Ukrainian #8871

    Refactor user query translation keys #9049

    Misc.

    Update to PHPMailer 7.1.1 #8907

    Improve PHP code #8906, #9156

    Fix PHPStan 2.2.2 in CLI #8911

    Migrate markdownlint-cli to markdownlint-cli2 #8987

    Update dev dependencies #8904, #8905, #8926, #8939, #8940, #8963, #8961, #8959, #8958, #8962, #8960, #9148, #9162, #9165, #9158, #9159, #9176, #9178, #9179, #9219, #9253, #9254, #9255, #9257

    Original source
  • May 20, 2026
    • Date parsed from source:
      May 20, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.29.1

    Freshrss releases a bug-fix update for 1.29.0 with easier feed imports, a new CLI for periodic SQLite exports, richer feed details, and improved browser compatibility. It also fixes cookie, search, OPML, and mark-as-read issues while polishing themes and translations.

    Milestone

    This is bug-fix release for 1.29.0.

    Feature highlights✨:

    Accept .txt import of feed URLs in additional to e.g. OPML

    New CLI for automatic periodic SQLite export with retention

    More feed info: last received date, publication date

    Bug fixes highlights 🐛:

    Fix cookies with some browsers

    Fix search in shared user queries with empty results

    UI highlights 🖼:

    Improve Web browsers compatibility

    This release has been made by @Alkarex, @Frenzie, @IEEE-754, @Inverle, @McFev, @ciro-mota, @cweiske, @polybjorn and newcomer @mzl2233

    Full changelog:

    Features

    Accept .txt import of feed URLs in additional to e.g. OPML #8818, #8837

    New CLI for automatic periodic SQLite export with retention #8819

    More feed info: last received date, publication date #8799

    Bug fixing

    Fix cookies with some browsers #8867

    Fix search in shared user queries with empty results #8863

    Fix XML errors with loading invalid OPML in lib_opml library #8652, #8853,
    lib_opml#48, lib_opml#51

    Fix ensure maximum number of feeds also with Dynamic OPML #8832

    Fix click mark as read #8817

    UI

    Improve browser compatibility to keep mobile navigation at the bottom #8833

    Improve support of older/simpler Web browsers/engines such as SeaMonkey #8810,
    #8811, #8813,

    Improve Swage theme #8842

    Rename Nord theme to Nord #8805

    Replace GIF spinner by CSS spinner #8804, #8812

    Various UI and style improvements: #8800, #8816,

    I18n

    Improve Brazilian Portuguese #8846

    Improve Dutch #8868

    Improve German #8840

    Improve Polish #8854

    Improve Russian #8861

    Improve Traditional Chinese #8849

    Misc.

    Update dev dependencies #8858, #8864

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Freshrss and hundreds of other software products.

    Create account
  • May 10, 2026
    • Date parsed from source:
      May 10, 2026
    • First seen by Releasebot:
      May 11, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.29.0

    Freshrss releases a major update with new sort preferences, feed icons, sidebar controls, better mobile viewing, and fresh webhook and LLM classification extensions. It also improves security, PHP 8.5+ support, search behavior, and many themes and translations.

    Milestone

    This is a major release.

    Feature highlights✨:

    • New sort order preferences at global, category, and feed levels
    • Use feed-provided icon
    • New option to hide sidebar by default
    • Show time since when a feed has problems
    • New functions to handle plural in internationalisation
    • New cli/purge.php to apply purge policy from command line

    Bug fixes highlights 🐛:

    • Improve support of PHP 8.5+
    • Several fixes related to searches

    Security highlights 🛡:

    • Limit cURL to protocols HTTP, HTTPS

    UI highlights 🖼:

    • Improve mobile view with multiple lines when thumbnails and summaries are shown
    • Several themes improved

    Extensions highlights 🧩:

    • New Webhook extension for automated RSS notifications
    • New LLM Classification extension to automatically tag incoming articles based on a prompt sent to an LLM

    This release has been made by @Alkarex, @Inverle, @Kiblyn11, @math-GH, @rupakbajgain, @xtmd and newcomers @polybjorn, @olivluca, @tomasodehnal, @PeterVavercak, @mrtnrdl, @ale-rt, @cweiske, @rid3r45, @gabbihive, @drosell271, @Kachelkaiser, @zanivann, @nanos, @bowencool, @pe1uca, @matheusroberson, @DenuxPlays, @rlrs, @chanse-syres, @IEEE-754, @umaidshahid, @michi-onl

    Full changelog:

    Features

    • New sort order preferences at global, category, and feed levels #8234
    • New filtering by date of Server modification date #8131, #8576
    • Corresponding search operator, e.g. mdate:P1D for finding articles modified by the author / server during the past day.
    • Especially useful for optimising the API synchronisation.
    • Use feed-provided icon #8633
    • New option to automatically mark new articles as read if an identical GUID already exists in the same category #8673
    • Automatic feed visibility/priority during search #8609
    • Add feed visibility filter to statistics view unread dates #8489
    • Add option to enable/disable notifications, also for PWA #8458
    • Add a form to create new user queries on the User Queries page #8623
    • Allow WebSub hub push from same private network #8450
    • Support category field in JSON feed import #8786

    Bug fixing

    • Fix wrong search toString in case of regex-looking string #8479
    • Fix article last seen date in case of feed errors #8646
    • Fix search expansion with backslash #8497
    • Fix user query parsing #8543
    • Fix search in shared user queries #8789
    • Fix redirect to wrong view after mark as read in reader and global views #8552
    • Fix SQLite paging when sorting by article length #8594
    • Fix change sorting during paging #8688
    • Fix SQL keyset pagination when sorting by category name #8597
    • Fix SQL duplicates in the user labels when sorting randomly #8626
    • Fix wrong error redirect in subscription management #8625
    • Fix do not include hidden feeds when counting total number of unread articles #8715
    • Update user modify date when changing extensions UserJS / UserCSS #8607
    • Non-strict OPML export #eedefb

    Security

    • Limit cURL to protocols HTTP, HTTPS #8713
    • Better sanitise favicon URLs #8714
    • New setting for <iframe> referrer allow list #8672
    • Fix email validation and allow error page for unverified email users #8582
    • Add allowfullscreen to <iframe> #8467
    • Rewrite Set-Cookie using native PHP support of SameSite #8447, #8778
    • Sanitize lifetime of session cookies from session.cookie-lifetime in php.ini
    • Update to <meta name="referrer" content="no-referrer" /> from deprecated never #8725
    • Preventive measure against search ingestion #8777

    UI

    • New option to hide sidebar by default #8528
    • Improve mobile view with multiple lines when thumbnails and summaries are shown #8631
    • New option to disable unread counter in tab title and favicon #8728
    • Show time since when a feed has problems #8670
    • Improve add feed UI #8683
    • Improve slider behaviour when using navigate back button #8496, #8524
    • Improve consistency of slider behaviour after submitting form #8612
    • Create dynamic favicons from SVG instead of PNG canvas #8577, #8588
    • Only display scrollbar everywhere if there's an overflow (especially for Chromium) #8542
    • Fix CSS padding of .content pre code #8620
    • Fix wrong navigation buttons layout on Chromium #8606
    • Fix don’t mark as read if middle click is outside of article link #8553
    • More robust JS #8595
    • Fix sidebar slide animation at narrow viewports #8747
    • Visually dim disabled users in user management table #8768
    • Improve multiple UI themes #8711, #8732,
      #8733, #8734, #8735,
      #8736, #8737, #8738,
      #8739, #8743, #8746,
      #8749, #8761, #8781,
      #8784, #8785
    • Various UI and style improvements: #8537, #8538,
      #8541, #8624, #8731,
      #8774

    Deployment

    • Also push Docker images to GitHub registry #8669
    • Improve support of PHP 8.5+ using Pdo\Mysql #8526
    • Add support for Podman in Makefile #8456
    • Re-add database status in installation check #8510
    • Docker / CLI: Allow chown/chmod to fail with warning #8635

    Extensions

    • New Webhook extension for automated RSS notifications Extensions#456
    • New LLM Classification extension to automatically tag incoming articles based on a prompt sent to an LLM Extensions#458
    • New extension methods to get typed configuration values #8696
    • New hook: Minz_HookType::ActionExecute #8599, #8603
    • New hook to modify the list of feeds to actualize #8655, #8675
    • Allow passing Minz_HookType as hook name in registerHook() #8600
    • Return more info and status from httpGet() #8700
    • Make httpGet() cache nullable #8705
    • Allow extensions’ configuration UI to use select-input-changer JavaScript helper #8721

    SimplePie

    • Bump upstream #8628, simplepie#71
    • New function get_icon_url() for feed favicon simplepie#974
    • Fix Undefined array key in get_thumbnail() #8634, simplepie#970
    • Fix int types for enclosures #8702, simplepie#975
    • Fix HTTPS headers given to SimplePie, e.g. for some HTTP/2 cases #8742

    CLI

    • New cli/purge.php to apply purge policy #8740

    I18n

    • CLI validate language directory names #8767
    • New functions to handle plural, and new timeago() #8670
    • Improve German #8491, #8557, #8689,
      #8704
    • Improve Italian #8517, #8519, #8554,
      #8555, #8556, #8566
    • Improve Latvian #6553
    • Improve Polish #8536
    • Improve Portuguese #8649
    • Improve Simplified Chinese #8474, #8475, #8476
    • Improve Traditional Chinese #8709, #8716, #8723,
      #8730, #8748
    • Improve Spanish #8572

    Misc.

    • Initial conventions for AI agents and humans: AGENTS.md, SKILLS.md, instructions.md #8478
    • Update to CSSXPath 1.5.0 #8642
    • Update to PHPMailer 7.0.2 #8483
    • SQL improve PHP syntax uniformity #8604
    • Trim SQL whitespace before parenthesis #8522
    • Improve PHP code #8627, #8644, #8753,
      #8697
    • Add dev legacy rules PHPCS 3 #8645
    • Update dev dependencies #8469, #8480, #8499,
      #8545, #8546, #8547,
      #8617, #8638, #8660,
      #8661, #8662, #8663,
      #8664, #8665, #8666,
      #8667, #8668, #8685,
      #8752, #8754, #8755,
      #8756, #8757, #8758,
      #8772, #8798
    Original source
  • February 2026
    • No date parsed from source.
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Mar 22, 2026
    Freshrss logo

    Freshrss

    2026-0X-XX FreshRSS 1.29.0-dev

    Freshrss adds new sorting, date-based filtering and search options, plus better feed visibility controls, notifications and WebSub support. This release also brings security hardening, UI polish, bug fixes, PHP 8.5+ support and updated translation, deployment and extension improvements.

    Features

    • New sort order preferences at global, category, and feed levels (#8234)
    • New filtering by date of Server modification date (#8131, #8576)
      • Corresponding search operator, e.g. mdate:P1D for finding articles modified by the author / server during the past day.
      • Especially useful for optimising the API synchronisation.
    • Automatic feed visibility/priority during search (#8609)
    • Add feed visibility filter to statistics view unread dates (#8489)
    • Add option to enable/disable notifications, also for PWA (#8458)
    • Allow WebSub hub push from same private network (#8450)

    Bug fixing

    • Fix wrong search toString in case of regex-looking string (#8479)
    • Fix search expansion with backslash (#8497)
    • Fix user query parsing (#8543)
    • Fix redirect to wrong view after mark as read in reader and global views (#8552)
    • Fix SQLite paging when sorting by article length (#8594)
    • Fix SQL keyset pagination when sorting by category name (#8597)
    • Update user modify date when changing UserJS/UserCSS (#8607)
    • Non-strict OPML export (#eedefb)

    Security

    • Fix email validation and allow error page for unverified email users (#8582)
    • Add allowfullscreen to (#8467)
    • Rewrite Set-Cookie using native PHP support of SameSite (#8447)
      • Sanitize lifetime of session cookies from session.cookie-lifetime in php.ini

    UI

    • Add option to hide sidebar by default (#8528)
    • Improve slider behaviour when using navigate back button (#8496, #8524)
    • Improve consistency of slider behaviour after submitting form (#8612)
    • Create dynamic favicons from SVG instead of PNG canvas (#8577, #8588)
    • Only display scrollbar everywhere if there's an overflow (especially for Chromium) (#8542)
    • Fix CSS padding of .content pre code (#8620)
    • Fix wrong navigation buttons layout on Chromium (#8606)
    • More robust JS (#8595)
    • Various UI and style improvements: (#8537, #8538, #8541)

    Deployment

    • Improve support of PHP 8.5+ using Pdo\Mysql (#8526)
    • Add support for Podman in Makefile (#8456)
    • Re-add database status in installation check (#8510)

    Extensions

    • Add new hook: Minz_HookType::ActionExecute (#8599, #8603)
    • Allow passing Minz_HookType as hook name in registerHook() (#8600)

    I18n

    • Improve German (#8491, #8557)
    • Improve Italian (#8517, #8519, #8554, #8555, #8556, #8566)
    • Improve Polish (#8536)
    • Improve Simplified Chinese (#8474, #8475, #8476)
    • Improve Spanish (#8572)

    Misc.

    • Initial conventions for AI agents and humans: AGENTS.md, SKILLS.md, instructions.md (#8478)
    • Update to PHPMailer 7.0.2 (#8483)
    • SQL improve PHP syntax uniformity (#8604)
    • Trim SQL whitespace before parenthesis (#8522)
    • Update dev dependencies (#8469, #8480, #8499, #8545, #8546, #8547, #8617)
    Original source
  • Jan 25, 2026
    • Date parsed from source:
      Jan 25, 2026
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Apr 12, 2026
    Freshrss logo

    Freshrss

    2026-01-25 FreshRSS 1.28.1

    Freshrss adds web scraping support for plain text, a customizable closed-registration message, and broad fixes for searches, feeds, labels, tokens, and UI polish, while also improving security, performance, deployment logs, and translations.

    Features

    • Handle Web scraping of text/plain as
       (#8340)
    • New customisable message for closed registrations (#8462)

    Bug fixing

    • Fix unwanted expansion of user queries (saved searches) applied to filters (#8395)
    • Fix encoding of filter actions for labels (#8368)
    • Fix searching of tags (#8425)
    • Fix refreshing feeds with token while anonymous refresh is disabled (#8371)
    • Fix RSS and OPML access by token (#8434)
    • Fix MySQL/MariaDB transliterator_transliterate fallback (when the php-intl extension is unavailable) (#8427)
    • Fix regression with MySQL/MariaDB index hint (#8460)
    • Auto-add lastUserModified database column also during mark-as-read action (#8346)
    • Do not include hidden feeds when counting unread articles in categories (#8357)
    • Remove wrong PHP deprecation of OPML export action (#8399)
    • Fix shortcut for next unread article (#8466)
    • Fix custom session.cookie-lifetime (#8446)
    • Fix feed validator button when changing the feed URL (#8436)

    Performance

    • Disable counting articles in user labels for Ajax requests (unused) (#8352)

    Security

    • Change Content-Disposition: inline to attachment in f.php (#8344)
    • Hardened user methods exists, mtime, ctime (#26c1102)

    Deployment

    • Add username in Apache access logs (also in Docker logs): for GReader API, and for HTTP Basic Auth from reverse proxy (#8392)

    SimplePie

    • Update of CURLOPT_ACCEPT_ENCODING (#8376, simplepie#960, simplepie#962)
    • Fix don’t preserve children inside disallowed element (#8443)
    • Fixes before PHPStan 2 (#8445, simplepie#957)

    Extensions

    • Update .gitignore to ignore installed extensions (#8372)

    UI

    • Add data-category="3" to ease custom CSS styling of articles (#8397)
    • Fix space between By: and the author’s name (#8422)

    I18n

    • Improve Brazilian Portuguese (#8411)
    • Improve Dutch (#8403)
    • Improve German (#8402)
    • Improve Polish (#8408)
    • Improve Spanish (#8464)

    Misc.

    • Update dev dependencies (#8387, #8388, #8389, #8390, #8391, #8393, #8453)
    Original source
  • Similar to Freshrss with recent updates:

  • Jan 25, 2026
    • Date parsed from source:
      Jan 25, 2026
    • First seen by Releasebot:
      Feb 12, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.28.1

    A focused release fixes regressions from 1.28.0 and adds new features like a customisable message for closed registrations and extra logging. It also improves performance and security while addressing a broad set of bug fixes and UI tweaks.

    Milestone

    This is a release focussing on bug fixing, in particular regressions from the release 1.28.0.

    Selected new features

    • New customisable message for closed registrations
    • Add username in Apache access logs (also in Docker logs): for GReader API, and for HTTP Basic Auth from reverse proxy
    • Improved performance 🏎️:
    • Disable counting articles in user labels for Ajax requests (unused)
    • Many bug fixes 🐛

    This release has been made by @Alkarex, @Frenzie, @Inverle and newcomers @ciro-mota, @eveiscoull, @hackerman70000, @Hufschmidt, @johan456789, @martgnz, @mmeier86, @netsho, @neuhaus, @RobLoach, @rupakbajgain.

    Full changelog:

    Features

    • Handle Web scraping of text/plain as <pre class="text-plain"> #8340
    • New customisable message for closed registrations #8462

    Bug fixing

    • Fix unwanted expansion of user queries (saved searches) applied to filters #8395
    • Fix encoding of filter actions for labels #8368
    • Fix searching of tags #8425
    • Fix refreshing feeds with token while anonymous refresh is disabled #8371
    • Fix RSS and OPML access by token #8434
    • Fix MySQL/MariaDB transliterator_transliterate fallback (when the php-intl extension is unavailable) #8427
    • Fix regression with MySQL/MariaDB index hint #8460
    • Auto-add lastUserModified database column also during mark-as-read action #8346
    • Do not include hidden feeds when counting unread articles in categories #8357
    • Remove wrong PHP deprecation of OPML export action #8399
    • Fix shortcut for next unread article #8466
    • Fix custom session.cookie-lifetime #8446
    • Fix feed validator button when changing the feed URL #8436

    Performance

    • Disable counting articles in user labels for Ajax requests (unused) #8352

    Security

    • Change Content-Disposition: inline to attachment in f.php #8344
    • Hardened user methods exists, mtime, ctime #26c1102

    Deployment

    • Add username in Apache access logs (also in Docker logs): for GReader API, and for HTTP Basic Auth from reverse proxy #8392

    SimplePie

    • Update of CURLOPT_ACCEPT_ENCODING #8376, simplepie#960, simplepie#962
    • Fix don’t preserve children inside disallowed <template> element #8443
    • Fixes before PHPStan 2 #8445, simplepie#957

    Extensions

    • Update .gitignore to ignore installed extensions #8372

    UI

    • Add data-category="3" to ease custom CSS styling of articles #8397
    • Fix space between By: and the author’s name #8422

    I18n

    • Improve Brazilian Portuguese #8411
    • Improve Dutch #8403
    • Improve German #8402
    • Improve Polish #8408
    • Improve Spanish #8464

    Misc.

    • Update dev dependencies #8387, #8388, #8389,

    #8390, #8391, #8393,
    #8453

    Original source
  • Dec 24, 2025
    • Date parsed from source:
      Dec 24, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Mar 17, 2026
    Freshrss logo

    Freshrss

    2025-12-24 FreshRSS 1.28.0

    Freshrss releases a comprehensive update with advanced search and sorting by user date and article length, new search form, PCRE word boundaries, uniform SQL search, feed visibility and sharing via API, plus performance, security, UI tweaks, API enhancements, and deployment refinements.

    Features

    • New sorting and filtering by User modification date (#7886, #8090, #8118, #8130)
      • Corresponding search operator, e.g. userdate:PT1H for the past hour (#8093)
      • Allows finding articles marked by the local user as read/unread or starred/unstarred at specific dates for e.g. undo action.
    • New sorting by article length (#8119)
    • New advanced search form (#8103, #8122, #8226)
    • Add compatibility with PCRE word boundary \b and \B for regex search using PostgreSQL (#8141)
    • More uniform SQL search and PHP search for accents and case-sensitivity (e.g. for automatically marking as read) (#8329)
    • New overview of dates with most unread articles (#8089)
    • Allow marking as read articles older than 1 or 7 days also when sorting by publication date (#8163)
    • New option to show user labels instead of tags in RSS share (#8112)
    • Add new feed visibility (priority) Show in its feed (#7972)
    • New ability to share feed visibility through API (implemented by e.g. Capy Reader) (#7583, #8158)
    • Configurable notification timeout (#7942)
    • OPML export/import of unicity criteria (#8243)
    • Ensure stable IDs (categories, feeds, labels) during export/import (#7988)
    • Add username and timestamp to SQLite export from Web UI (#8169)
    • Add option to apply filter actions to existing articles (#7959, #8259)
    • Support CSS selector ~ subsequent-sibling (#8154) (Upstream PR phpgt/CssXPath#231)
    • Rework saving of configuration files for more reliability in case of e.g. full disk (#8220)
    • Web scraping support date format as milliseconds for Unix epoch (#8266)
    • Allow negative category sort numbers (#8330)

    Performance

    • Improve SQL speed for updating cached information (#6957, #8207, #8255, #8254)
    • Fix SQL performance issue with MySQL, using an index hint (#8211)
    • Scaling of user statistics in Web UI and CLI, to help instances with 1k+ users (#8277)
    • API streaming of large responses for reducing memory consumption and increasing speed (#8041)

    Security

    • 💥 Move unsafe autologin to an extension (#7958)
    • Fix some CSRFs (#8035)
    • Strengthen some crypto (login, tokens, nonces) (#8061, #8320)
    • Create separate HTTP Retry-After rules for proxies (#8029, #8218)
    • Add data: to CSP in subscription controller (#8253)
    • Improve anonymous authentication logic (#8165)
    • Enable GitHub release immutability (#8205)

    Bug fixing

    • Exclude local networks for domain-wide HTTP Retry-After (#8195)
    • Fix OpenID Connect with Debian 13 (#8032)
    • Fix MySQL / MariaDB bug wrongly sorting new articles (#8223)
    • Fix MySQL / MariaDB database size calculation (#8282)
    • Fix SQLite bind bug when adding user label (#8101)
    • Fix SQL auto-update of field f.kind to ease migrations from FreshRSS versions older than 1.20.0 (#8148)
    • Fix search encoding and quoting (#8311, #8324, #8338)
    • Fix handling of database unexpected null content (during migrations) (#8319, #8321)
    • Fix drag & drop of user query losing information (#8113)
    • Fix DOM error while filtering retrieved full content (#8132, #8161)
    • Fix config.custom.php during install (#8033)
    • Fix do not mark important feeds as read from category (#8067)
    • Fix regression of warnings in Web browser console due to lack of window.bcrypt object (#8166)
    • Fix chart resize regression due to chart.js v4 update (#8298)
    • Fix CLI user creation warning when language is not given (#8283)
    • Fix merging of custom HTTP headers (#8251)
    • Fix bug in the case of duplicated mark-as-read filters (#8322)

    SimplePie

    • Fix support of HTTP trailer headers (#7983, simplepie#943)
    • Apply HTTPS policy also on GUIDs and permalinks (#8037, simplepie#951)
      • Fix WordPress.com HTTP duplicates with WebSub (Automattic/pushpress#16)
    • Implement HTML whitelist for SimplePie sanitizer (#7924, simplepie#947)
    • Various upstream contributions (simplepie#940, #944)
    • Implement other fixes before PHPStan 2 (simplepie#957)

    Deployment

    • Docker default image updated to Debian 13 Trixie with PHP 8.4.11 and Apache 2.4.65 (#8032)
    • Docker alternative image updated to Alpine 3.23 with PHP 8.4.15 and Apache 2.4.65 (#8285)
    • Fix Docker healthcheck cli/health.php compatibility with OpenID Connect (#8040)
    • Improve Docker for compatibility with other base images such as Arch Linux (#8299)
      • Improve cli/access-permissions.sh to detect the correct permission Web group such as www-data, apache, or http (#8228)
    • Update PostgreSQL volume for Docker (#8216, #8224)
    • Catch lack of exec() function for git update (#8228)
    • Work around DOMDocument::saveHTML() scrambling charset encoding in some versions of libxml2 (#8296)
    • Improve configuration checks for PHP extensions (in Web UI and CLI), including recommending e.g. php-intl (#8334)

    UI

    • New button for toggling sidebar on desktop view (#8201, #8286)
    • Better transitions between groups of articles (#8174)
    • New links in transitions and jump ⏭ to next transition (#8294)
    • More visible selected article (#8230)
    • Show the parsed search query instead of the original user input (#8293, #8306, #8341)
    • Show search query in the page title (#8217)
    • Scroll into filtered feed/category on page load in the sidebar (#8281, #8307)
    • Fix autocomplete issues in change password form (#7812)
    • Fix navigating between read feeds using shortcut shift + j / k (#8057)
    • Dark background in Web app manifest to avoid white flash when opening (#8140)
    • Increase button visibility in UI to change theme (#8149)
    • Replace arrow navigation in theme switcher with (#8190)
    • Improve scroll of article after load of user labels (#7962)
    • Keep scroll state of page when closing the slider (#8295, #8301)
    • Display sidebar dropdowns above if no space below (#8335, #8336)
    • Use native CSS instead of SCSS (#8200, #8241) (Using CSS nesting and relative colours.)
    • Various UI and style improvements (#8171, #8185, #8196)
    • JavaScript finalise migration from Promise to async/await (#8182)

    API

    • API performance optimisation: streaming of large responses (#8041)
    • Fever API: Add with_ids parameter to mass-change read/unread/saved/unsaved on lists of articles (#8312)
    • Misc API: better REST error semantics (#8232)

    Extensions

    • Add support for extension priority (#8038)
    • Add support for extension compatibility (#8081)
    • Improve PHP code with hook enums (#8036)
    • New hook nav_entries (#8054)
    • Rename Extensions default branch from master to main (#8194)

    I18n

    • Translation status as text in README (#7842)
    • Add new translate CLI commands move (#8214)
    • Change some regional language codes to comply with RFC 5646 / IETF BCP 47 / ISO 3166 / ISO 639-1 (#8065)
    • Improve German (#8028)
    • Improve Greek (#8146)
    • Improve Finnish (#8073, #8092)
    • Improve Hungarian (#8244)
    • Improve Italian (#8115, #8186)
    • Improve Polish (#8134, #8135)
    • Improve Russian (#8155, #8197)
    • Improve Simplified Chinese (#8308, #8313)

    Misc.

    • Add code to modify a search expression (#8293)
    • Remove Pocket sharing service (#8127, #8128)
    • Update to PHPMailer 7.0.1 (#8048, #8180, #8272)
    • 💥 Housekeeping of lib_rss.php with potential breaking changes for some extensions (#8193)
    • Use native PHP #[Deprecated] (#8325)
    • Improve PHP code (#8156, #8203, #8284, #8292, #8297)
    • GitHub Actions: --no-progress (#8315)
    • Update dev dependencies (#8043, #8044, #8045, #8046, #8047, #8052, #8176, #8177, #8178, #8179, #8210, #8270, #8271, #8273, #8274, #8275, #8276)

    Bug fixes and other details omitted for brevity.

    Original source
  • Dec 24, 2025
    • Date parsed from source:
      Dec 24, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.28.0

    Major holiday release brings advanced search and sorting, new feed visibility sharing via API, UI refinements, performance boosts and a long list of bug fixes. Includes Debian 13 updates and broader platform polish.

    Milestone

    This is a major release, just in time for the holidays 🎄

    Selected new features

    • New sorting and filtering by date of User modified, with corresponding search operator, e.g. userdate:PT1H for the past hour
    • New sorting by article length
    • New advanced search form
    • New overview of dates with most unread articles
    • New ability to share feed visibility through API (implemented by e.g. Capy Reader)
    • Bonus: Capy Reader is also the first open source Android app to support user labels
    • Better transitions UI between groups of articles
    • New links in UI for transitions between groups of articles, and jump to next transition
    • Docker default image updated to Debian 13 Trixie with PHP 8.4.11
    • And much more…

    Improved performance 🏎️

    • Scaling of user statistics in Web UI and CLI, to help instances with 1k+ users
    • Improve SQL speed for some critical requests for large databases
    • API performance optimisation thanks to streaming of large responses

    Selected bug fixes 🐛

    • Fix OpenID Connect with Debian 13
    • Fix MySQL / MariaDB bug wrongly sorting new articles
    • Fix SQLite bind bug when adding tag

    Breaking changes 💥

    • Move unsafe autologin to an extension
    • Potential breaking changes for some extensions (which have to rename some old functions)

    This release has been made by @Alkarex, @Frenzie, @Inverle, @aledeg, @andris155, @horvi28, @math-GH, @minna-xD and newcomers @Darkentia, @FollowTheWizard, @GreyChame1eon, @McFev, @jocmp, @larsks, @martinhartmann, @matthew-neavling, @pudymody, @raspo, @scharmach, @scollovati, @stag-enterprises, @vandys, @xtmd, @yzx9.

    Full changelog

    Features

    • New sorting and filtering by date of User modified #7886, #8090,

    #8105, #8118, #8130

    • Corresponding search operator, e.g. userdate:PT1H for the past hour #8093
    • Allows finding articles marked by the local user as read/unread or starred/unstarred at specific dates for e.g. undo action.
    • New sorting by article length #8119
    • New advanced search form #8103, #8122, #8226
    • Add compatibility with PCRE word boundary \b and \B for regex search using PostgreSQL #8141
    • More uniform SQL search and PHP search for accents and case-sensitivity (e.g. for automatically marking as read) #8329
    • New overview of dates with most unread articles #8089
    • Allow marking as read articles older than 1 or 7 days also when sorting by publication date #8163
    • New option to show user labels instead of tags in RSS share #8112
    • Add new feed visibility (priority) Show in its feed #7972
    • New ability to share feed visibility through API (implemented by e.g. Capy Reader) #7583, #8158
    • Configurable notification timeout #7942
    • OPML export/import of unicity criteria #8243
    • Ensure stable IDs (categories, feeds, labels) during export/import #7988
    • Add username and timestamp to SQLite export from Web UI #8169
    • Add option to apply filter actions to existing articles #7959, #8259
    • Support CSS selector ~ subsequent-sibling #8154
    • Upstream PR phpgt/CssXPath#231
    • Rework saving of configuration files for more reliability in case of e.g. full disk #8220
    • Web scraping support date format as milliseconds for Unix epoch #8266
    • Allow negative category sort numbers #8330

    Performance

    • Improve SQL speed for updating cached information #6957, #8207,

    #8255, #8254, #8255

    • Fix SQL performance issue with MySQL, using an index hint #8211
    • Scaling of user statistics in Web UI and CLI, to help instances with 1k+ users #8277
    • API streaming of large responses for reducing memory consumption and increasing speed #8041

    Security

    • 💥 Move unsafe autologin to an extension #7958
    • Fix some CSRFs #8035
    • Strengthen some crypto (login, tokens, nonces) #8061, #8320
    • Create separate HTTP Retry-After rules for proxies #8029, #8218
    • Add data: to CSP in subscription controller #8253
    • Improve anonymous authentication logic #8165
    • Enable GitHub release immutability #8205

    Bug fixing

    • Exclude local networks for domain-wide HTTP Retry-After #8195
    • Fix OpenID Connect with Debian 13 #8032
    • Fix MySQL / MariaDB bug wrongly sorting new articles #8223
    • Fix MySQL / MariaDB database size calculation #8282
    • Fix SQLite bind bug when adding tag #8101
    • Fix SQL auto-update of field f.kind to ease migrations from FreshRSS versions older than 1.20.0 #8148
    • Fix search encoding and quoting #8311, #8324, #8338
    • Fix handling of database unexpected null content (during migrations) #8319, #8321
    • Fix drag & drop of user query losing information #8113
    • Fix DOM error while filtering retrieved full content #8132, #8161
    • Fix config.custom.php during install #8033
    • Fix do not mark important feeds as read from category #8067
    • Fix regression of warnings in Web browser console due to lack of window.bcrypt object #8166
    • Fix chart resize regression due to chart.js v4 update #8298
    • Fix CLI user creation warning when language is not given #8283
    • Fix merging of custom HTTP headers #8251
    • Fix bug in the case of duplicated mark-as-read filters #8322
    SimplePie
    • Fix support of HTTP trailer headers #7983, simplepie#943
    • Apply HTTPS policy also on GUIDs and permalinks #8037, simplepie#951
    • Fix WordPress.com HTTP duplicates with WebSub Automattic/pushpress#16
    • Implement HTML whitelist for SimplePie sanitizer #7924, simplepie#947
    • Various upstream contributions simplepie#940, simplepie#944

    Deployment

    • Docker default image updated to Debian 13 Trixie with PHP 8.4.11 and Apache 2.4.65 #8032
    • Docker alternative image updated to Alpine 3.23 with PHP 8.4.15 and Apache 2.4.65 #8285
    • Fix Docker healthcheck cli/health.php compatibility with OpenID Connect #8040
    • Improve Docker for compatibility with other base images such as Arch Linux #8299
    • Improve cli/access-permissions.sh to detect the correct permission Web group such as www-data, apache, or http
    • Update PostgreSQL volume for Docker #8216, #8224
    • Catch lack of exec() function for git update #8228
    • Work around DOMDocument::saveHTML() scrambling charset encoding in some versions of libxml2 #8296
    • Improve configuration checks for PHP extensions (in Web UI and CLI), including recommending e.g. php-intl #8334

    UI

    • New button for toggling sidebar on desktop view #8201, #8286
    • Better transitions between groups of articles #8174
    • New links in transitions and jump to next transition #8294
    • More visible selected article #8230
    • Show the parsed search query instead of the original user input #8293,

    #8306, #8341

    • Show search query in the page title #8217
    • Scroll into filtered feed/category on page load in the sidebar #8281, #8307
    • Fix autocomplete issues in change password form #7812
    • Fix navigating between read feeds using shortcut shift+j/k #8057
    • Dark background in Web app manifest to avoid white flash when opening #8140
    • Increase button visibility in UI to change theme #8149
    • Replace arrow navigation in theme switcher with <select> #8190
    • Improve scroll of article after load of user labels #7962
    • Keep scroll state of page when closing the slider #8295, #8301
    • Scroll into filtered feed/category on page load #8281
    • Display sidebar dropdowns above if no space below #8335, #8336
    • Use native CSS instead of SCSS #8200, #8241
    • Using CSS nesting and relative colours.
    • Various UI and style improvements: #8171, #8185, #8196
    • JavaScript finalise migration from Promise to async/await: #8182

    API

    • API performance optimisation: streaming of large responses #8041
    • Fever API: Add with_ids parameter to mass-change read/unread/saved/unsaved on lists of articles #8312
    • Misc API: better REST error semantics #8232

    Extensions

    • Add support for extension priority #8038
    • Add support for extension compatibility #8081
    • Improve PHP code with hook enums #8036
    • New hook nav_entries #8054
    • Rename Extensions default branch from master to main #8194

    I18n

    • Translation status as text in README #7842
    • Add new translate CLI commands move #8214
    • Change some regional language codes to comply with RFC 5646 / IETF BCP 47 / ISO 3166 / ISO 639-1 #8065
    • Improve German #8028
    • Improve Greek #8146
    • Improve Finnish #8073, #8092
    • Improve Hungarian #8244
    • Improve Italian #8115, #8186
    • Improve Polish #8134, #8135
    • Improve Russian #8155, #8197
    • Improve Simplified Chinese #8308, #8313

    Misc.

    • Add code to modify a search expression #8293
    • Remove Pocket sharing service #8127, #8128
    • Update to PHPMailer 7.0.1 #8048, #8180, #8272
    • 💥 Housekeeping of lib_rss.php with potential breaking changes for some extensions #8193,
    • Use native PHP #[Deprecated] #8325
    • Improve PHP code #8156, #8203, #8284,

    #8292, #8297

    • GitHub Actions: --no-progress #8315
    • Update dev dependencies #8043, #8044,

    #8045, #8046, #8047,
    #8052, #8176, #8177,
    #8178, #8179, #8210,
    #8270, #8271, #8273,
    #8274, #8275, #8276

    Original source
  • Sep 27, 2025
    • Date parsed from source:
      Sep 27, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Mar 17, 2026
    Freshrss logo

    Freshrss

    2025-09-27 FreshRSS 1.27.1

    Freshrss releases a comprehensive update introducing automatic database recovery during export/import, stronger CSP frame-ancestors options, lazy-loaded tracks, session ID regeneration on login, safer install.php, CSRF fixes, and broad UI, i18n, and deployment improvements that boost security and performance.

    Features

    • Automatic database recovery: skip broken entries during CLI export/import (#7949)
    • Add security option for CSP frame-ancestors (#7857, #8021)
    • Lazy-load (#7997)

    Security

    • Regenerate session ID on login (#7829)
    • Disallow setting non-existent language (#7878, #7934)
    • Safer calling of install.php (#7971)
    • Prevent log CR/LF injection (#7883)
    • Restrict allowed cURL parameters (#7979, #8009)
    • Fix reauthentication while updating (#7989)
    • Fix some CSRFs (#8000)

    Bug fixing

    • Include port number for HTTP Retry-After (#7875)
    • Fix logic for searching labels (#7863)
    • Fix cURL response parsing for HTTP redirections (#7866)
    • Fix fetching OPML URL with special characters (#7843)
    • Fix validation when creating a new user label (#7890)
    • Fix bug in user self-deletion (#7877)
    • Fix displaying of current date in main statistics (#7892)
    • Fix default values on stat processing (#7891)
    • Fix UI JavaScript error when navigating to last article with keyboard (#7957)
    • Fix some links in anonymous mode (#8011, #8012)
    • Fixes for no-cache.txt (#7907)
    • Fix Docker Traefik .yml and SERVER_DNS example (#7858)

    SimplePie

    • Upstream contribution: Normalize encoding uppercase (simplepie#936, #7967)
    • Sync upstream, including bump to 1.9.0 with better PHP 8.5+ support (#7955)

    Deployment

    • Docker improve CMD compatibility (#7861)
    • Add possibility of Docker healthcheck (#7945)

    UI

    • Keep sort and order after marking as read (#7974)
    • Improve leave validation (#7830)
    • Improve Origine theme visibility of toggle buttons (#7956)
    • Improve Dark pink theme (#8020)
    • Improve Mapco and Ansum themes: read all button in mobile view (#7873)
    • Improve Swage theme (#7608)
    • Use standard CSS overflow-wrap instead of word-wrap (#7898)
    • Various UI and style improvements (#7868, #7872, #7882, #7893, #7904, #7952)

    I18n

    • Clarify the concepts of visibility hidden vs. archived in feeds settings (#7970)
    • Translate the API information page (#7922)
    • Add a default language constant (#7933)
    • Label config delete label (#7871)
    • Add Ukrainian (#7961)
    • Improve Dutch (#7940)
    • Improve German (#7833)
    • Improve Hungarian (#7986)
    • Improve Japanese (#7903, #7918)
    • Improve Polish (#7963)
    • Improve Simplified Chinese (#8308, #8313)

    Extensions

    • Add entry_before_update and entry_before_add hooks for extensions (#7977)

    Misc.

    • Improve make (#7901)
    • Improve PHP code (#7906, #7916, #7939, #7941, #7960, #7991)
    • Upgrade to PHP_CodeSniffer 4 (#7993)
    • Update dev dependencies (#7902, #7895, #7896, #7899, #7966, #7969)
    Original source
  • Sep 27, 2025
    • Date parsed from source:
      Sep 27, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.27.1

    FreshRSS 1.27.x arrives with security and bug fixes. Highlights include automatic database recovery, Docker healthcheck, CSP frame-ancestors option, and stability fixes. It also enhances translations, themes, and UI reliability.

    Milestone

    This is a security-fix and bug-fix release for FreshRSS 1.27.x.

    A few highlights ✨:

    • Keep sort and order criteria after marking as read
    • Automatic database recovery: skip broken entries during CLI export/import
    • Add possibility of Docker healthcheck
    • Add security option for CSP frame-ancestors
    • Several security fixes
    • Several bug fixes
    • New translation to Ukrainian
    • Improvements of some themes
    • And much more…

    This release has been made by @Alkarex, @Frenzie, @Inverle, @aledeg, @math-GH and newcomers @beerisgood, @nykula, @horvi28, @nhirokinet, @rnkln, @scmaybee.

    Full changelog

    Features

    • Automatic database recovery: skip broken entries during CLI export/import #7949
    • Add security option for CSP frame-ancestors #7857, #8021
    • Lazy-load <track src> #7997

    Security

    • Regenerate session ID on login #7829
    • Disallow setting non-existent language #7878, #7934
    • Safer calling of install.php #7971
    • Prevent log CR/LF injection #7883
    • Restrict allowed cURL parameters #7979, #8009
    • Fix reauthentication while updating #7989
    • Fix some CSRFs #8000

    Bug fixing

    • Include port number for HTTP Retry-After #7875
    • Fix logic for searching labels #7863
    • Fix cURL response parsing for HTTP redirections #7866
    • Fix fetching OPML URL with special characters #7843
    • Fix validation when creating a new user label #7890
    • Fix bug in user self-deletion #7877
    • Fix displaying of current date in main statistics #7892
    • Fix default values on stat processing #7891
    • Fix UI JavaScript error when navigating to last article with keyboard #7957
    • Fix some links in anonymous mode #8011, #8012
    • Fixes for no-cache.txt #7907
    • Fix Docker Traefik .yml and SERVER_DNS example #7858

    SimplePie

    • Upstream contribution: Normalize encoding uppercase simplepie#936, #7967
    • Sync upstream, including bump to 1.9.0 with better PHP 8.5+ support #7955

    Deployment

    • Docker improve CMD compatibility #7861
    • Add possibility of Docker healthcheck #7945

    UI

    • Keep sort and order after marking as read #7974
    • Improve leave validation #7830
    • Improve Origine theme visibility of toggle buttons #7956
    • Improve Dark pink theme #8020
    • Improve Mapco and Ansum themes: read all button in mobile view #7873
    • Improve Swage theme #7608
    • Use standard CSS overflow-wrap instead of word-wrap #7898
    • Various UI and style improvements: #7868, #7872,

    #7882, #7893, #7904,
    #7952

    I18n

    • Clarify the concepts of visibility hidden vs. archived in feeds settings #7970
    • Translate the API information page #7922
    • Add a default language constant #7933
    • Label config delete label #7871
    • Add Ukrainian #7961
    • Improve Dutch #7940
    • Improve German #7833
    • Improve Hungarian #7986
    • Improve Japanese #7903, #7918
    • Improve Polish #7963
    • Improve Simplified Chinese #7943, #7944
    • Minor improvements #7881
    • Add CLI command to add i18n file #7917
    • Add make target to generate the translation progress #7905

    Extensions

    • Add entry_before_update and entry_before_add hooks for extensions #7977

    Misc.

    • Improve make #7901
    • Improve PHP code #7906, #7916, #7939,

    #7941, #7960, #7991

    • Upgrade to PHP_CodeSniffer 4 #7993
    • Update dev dependencies #7902, #7895, #7896,

    #7899, #7966, #7969

    Original source
  • Aug 18, 2025
    • Date parsed from source:
      Aug 18, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Mar 17, 2026
    Freshrss logo

    Freshrss

    2025-08-18 FreshRSS 1.27.0

    Freshrss releases a comprehensive update with stronger reliability and security. It adds HTTP 429/503 handling, smarter cache and favicon changes, category and feed search enhancements, auto-restore of user config, and expanded API support. The release also tightens CSP, fixes numerous bugs, and updates deployment stacks.

    Features

    • Implement support for HTTP 429 Too Many Requests and 503 Service Unavailable, obey Retry-After (#7760)
    • Add sort by category title, or by feed title (#7702)
    • Add search operator c: for categories like c:23,34 or !c:45,56 (#7696)
    • Custom feed favicons (#7646, #7704, #7717, #7792)
    • Rework fetch favicons for fewer HTTP requests (#7767)
    • Add more unicity criteria based on title and/or content (#7789)
    • Automatically restore user configuration from backup (#7682)
    • API add support for states in s parameter of streamId (#7695)
    • Improve sharing via Print (#7728)
    • Redirect to the login page from bookmarklet instead of 403 (#7782)
    • Clean local cache more often, when refreshing feeds (#7827)

    Security

    • Implement reauthentication (sudo mode) (#7753)
    • Add Content-Security-Policy: frame-ancestors (#7677)
    • Ensure CSP everywhere (#7810)
    • Show warning when unsafe CSP policy is in use (#7804)
    • Fix access rights when creating a new user (#7783)
    • Improve security of form for user details (#7771, #7786)
    • Disallow setting non-existent theme (#7722)
    • Regenerate cookie ID after logging out (#7762)
    • Require current password when setting new password (#7763)
    • Add missing access checks for feed-related actions (#7768)
    • Strip more unsafe attributes such as referrerpolicy, ping (#7770)
    • Remove unneeded execution permissions (#7802)

    Bug fixing

    • Fix redirections when scraping from HTML (#7654, #7741)
    • Fix multiple authentication HTTP headers (#7703)
    • Fix HTML queries with a single feed (#7730)
    • WebSub: only perform a redirection when coming from WebSub (#7738)
    • Include enclosures in entries’ hash (#7719)
      ■ Negative side-effect: users of the option to automatically mark updated articles as unread will once have some articles with enclosures re-appear as unread
    • Fix cancellation of slider exit UI (#7705)
    • Honor disable update on update page (#7733)
    • Fix no registration limit setting (#7751)
    • Fix XML encoding of sharing functions (#7822)

    SimplePie

    • Fix propagation of HTTP error codes (#7670)
    • Fix support for XML feeds with HTML entities (#7689, simplepie#915)
    • Fix feeds encoded in UTF-16LE (#7691, simplepie#916)
    • Various upstream contributions (simplepie#917, #924, #926, #932, #933)
    • Fix regex Backtrack limit was exhausted in clean_hash() (#7813, FreshRSS/simplepie#48)

    Deployment

    • Docker default image (Debian 12 Bookworm) updated to PHP 8.2.29 (#7805)
    • Docker alternative image updated to Alpine 3.22 with PHP 8.4.11 and Apache 2.4.65 (#7740)
    • Start supporting PHP 8.5+ (#7787, #7826)
      ■ Docker Alpine dev image :newest updated to PHP 8.5-alpha and Apache 2.4.65 (#7773)
    • Docker: interpolate FRESHRSS_INSTALL and FRESHRSS_USER variables (#7725)
    • Docker: Reduce how much data needs to be chown/chmod’ed on container startup (#7793)
    • Test for database PDO typing support during install (relevant for MySQL / MariaDB with obsolete driver) (#7651)

    Extensions

    • Add API endpoint for extensions (#7576)
    • Expose the reading modes for extensions (#7668, #7688)
    • New extension hook before_login_btn (#7761)

    UI

    • Improve mark as read request showing popup due to onbeforeunload (#7554)
    • Fix lazy-loading for and (#7636)
    • Avoid styling inside of
       (#7797)
    • Improve confirmation logic with data-auto-leave-validation (#7785)
    • Update chart.js to 4.5.0 (#7752, #7816)
    • Various UI and style improvements (#7616, #7811)
    • Improve scroll state, transitions, shortcuts, themes, and other UI items (multiple fixes)

    I18n

    • Show translation status in README (#7715)
    • Improve Indonesian (#7654, #7721)
    • Improve Persian (#7795)

    Misc.

    • Improve PHP code (#7642, #7665, #7761, #7781, #7794)
    • Update dev dependencies (#7708, #7709, #7710, #7711, #7776, #7777)
    Original source
  • Aug 18, 2025
    • Date parsed from source:
      Aug 18, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.27.0

    FreshRSS rolls out improved reliability with HTTP 429/503 handling, reauthentication, and tighter security including CSP. It also brings bug fixes, Docker and PHP upgrades, UI tweaks, extension API boosts, and broader upstream synchronization for a smoother, safer feed experience.

    Milestone

    A few highlights ✨:

    • Implement support for HTTP 429 Too Many Requests and 503 Service Unavailable, obey Retry-After
    • Add sort by category title, or by feed title
    • Add search operator c: for categories like c:23,34 or !c:45,56
    • Custom feed favicons
    • Several security improvements, such as:
      • Implement reauthentication (sudo mode)
      • Add Content-Security-Policy: frame-ancestors
      • Ensure CSP everywhere
      • Fix access rights when creating a new user
    • Several bug fixes, such as:
      • Fix redirections when scraping from HTML
      • Fix feed redirection when coming from WebSub
      • Fix support for XML feeds with HTML entities, or encoded in UTF-16LE
    • Docker alternative image updated to Alpine 3.22 with PHP 8.4 (PHP 8.4 for default Debian image coming soon)
    • Start supporting PHP 8.5+
    • And much more…
      This release has been made by @Alkarex, @Inverle, @the7thNightmare and newcomers @Deioces120, @Fraetor, @Tarow, @dotsam, @hilariousperson, @pR0Ps, @triatic, @tryallthethings

    Full changelog:

    Features
    • Implement support for HTTP 429 Too Many Requests and 503 Service Unavailable, obey Retry-After #7760
    • Add sort by category title, or by feed title #7702
    • Add search operator c: for categories like c:23,34 or !c:45,56 #7696
    • Custom feed favicons #7646, #7704, #7717,

    #7792

    • Rework fetch favicons for fewer HTTP requests #7767
    • Add more unicity criteria based on title and/or content #7789
    • Automatically restore user configuration from backup #7682
    • API add support for states in s parameter of streamId #7695
    • Improve sharing via Print #7728
    • Redirect to the login page from bookmarklet instead of 403 #7782
    • Clean local cache more often, when refreshing feeds #7827
    Security
    • Implement reauthentication (sudo mode) #7753
    • Add Content-Security-Policy: frame-ancestors #7677
    • Ensure CSP everywhere #7810
    • Show warning when unsafe CSP policy is in use #7804
    • Fix access rights when creating a new user #7783
    • Improve security of form for user details #7771, #7786
    • Disallow setting non-existent theme #7722
    • Regenerate cookie ID after logging out #7762
    • Require current password when setting new password #7763
    • Add missing access checks for feed-related actions #7768
    • Strip more unsafe attributes such as referrerpolicy, ping #7770
    • Remove unneeded execution permissions #7802
    Bug fixing
    • Fix redirections when scraping from HTML #7654, #7741
    • Fix multiple authentication HTTP headers #7703
    • Fix HTML queries with a single feed #7730
    • WebSub: only perform a redirection when coming from WebSub #7738
    • Include enclosures in entries’ hash #7719
    • Negative side-effect: users of the option to automatically mark updated articles as unread will once have some articles with enclosures re-appear as unread
    • Fix cancellation of slider exit UI #7705
    • Honor disable update on update page #7733
    • Fix no registration limit setting #7751
    • Fix XML encoding of sharing functions #7822
    SimplePie
    • Fix propagation of HTTP error codes #7670
    • Fix support for XML feeds with HTML entities #7689, simplepie#915
    • Fix feeds encoded in UTF-16LE #7691, simplepie#916
    • Various upstream contributions simplepie#917, simplepie#924,
      simplepie#926, simplepie#932, simplepie#933
    • Sync upstream #7706, FreshRSS/simplepie#45, #7775,
      FreshRSS/simplepie#50, #7824, #7825,
    • Fix regex Backtrack limit was exhausted in clean_hash() #7813, FreshRSS/simplepie#48
    Deployment
    • Docker default image (Debian 12 Bookworm) updated to PHP 8.2.29 #7805
    • Docker alternative image updated to Alpine 3.22 with PHP 8.4.11 and Apache 2.4.65 #7740, #7740,

    #7803

    • Start supporting PHP 8.5+ #7787, #7826
    • Docker Alpine dev image :newest updated to PHP 8.5-alpha and Apache 2.4.65 #7773
    • Docker: interpolate FRESHRSS_INSTALL and FRESHRSS_USER variables #7725
    • Docker: Reduce how much data needs to be chown/chmod’ed on container startup #7793
    • Test for database PDO typing support during install (relevant for MySQL / MariaDB with obsolete driver) #7651
    Extensions
    • Add API endpoint for extensions #7576
    • Expose the reading modes for extensions #7668, #7688
    • New extension hook before_login_btn #7761
    UI
    • Improve mark as read request showing popup due to onbeforeunload #7554
    • Fix lazy-loading for and #7636
    • Avoid styling inside of
       #7797
    • Improve confirmation logic with data-auto-leave-validation #7785
    • Update chart.js to 4.5.0 #7752, #7816
    • Various UI and style improvements: #7616, #7811
    I18n
    • Show translation status in README #7715
    • Improve Indonesian #7654, #7721
    • Improve Persian #7795
    Misc.
    • Improve PHP code #7642, #7665, #7761,

    #7781, #7794

    • Update dev dependencies #7708, #7709, #7710,

    #7711, #7776, #7777

    Original source
  • Jun 2, 2025
    • Date parsed from source:
      Jun 2, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Mar 17, 2026
    Freshrss logo

    Freshrss

    2025-06-02 FreshRSS 1.26.3

    Freshrss releases a comprehensive update with feature tweaks like preserving sort criteria during navigation and exposing PDO::ATTR_CLIENT_VERSION, plus numerous bug fixes across readers and APIs. It tightens security, adds a loading indicator, UI theming, and updates dependencies.

    Features

    • Keep sort and order criteria during navigation (#7585)
    • Add info about PDO::ATTR_CLIENT_VERSION (relevant for MySQL / MariaDB with obsolete driver) (#7591)

    Bug fixing

    • Fix SQL request for user labels with custom sort (affecting PostgreSQL) (#7588)
    • Fix regression for favicon in GReader and Fever APIs (#7573)
    • Fix newest articles (within last second) not shown (#7577)
    • Fix duplicate HTTP header for POST (#7556)
    • Fix important articles on reader view (#7602)
    • Fix remove last share method (#7613)
    • Fix API handling of default category (#7610)
    • Fix user self-deletion (#7626)
    • Move PHP minimum version check (#7560)

    Security

    • Fix encoding of themes (#7565)
    • Fix .htaccess.dist for access to /scripts/vendor/ (#7598)

    SimplePie

    • Strip more HTML deprecated styles attributes: bgcolor, text, background, link, alink, vlink (#7606)

    UI

    • Implement loading spinner for marking as favourite/read (#7564)
    • Provide theme class for CSS (#7559)

    Deployment

    • Use HTTP Cache-Control: immutable for some files (#7552)
    • Drop Apache 2.2 (only support Apache 2.4+) (#7561)

    I18n

    • Improve Indonesian (#7622)
    • Improve Polish (#7587)

    Misc.

    • Update to PHPMailer 6.10.0 (#7542)
    • Update dev dependencies (#7630, #7631, #7632, #7633, #7634, #7635)
    Original source
  • Jun 2, 2025
    • Date parsed from source:
      Jun 2, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    Freshrss logo

    Freshrss

    FreshRSS 1.26.3

    FreshRSS 1.26.x ships a bug‑fix release with quality of life boosts like preserving sort criteria during navigation and a new loading spinner for marking items. It also fixes API, SQL, and UI glitches and tightens security.

    Milestone

    This is a bug-fix release for FreshRSS 1.26.x

    A few highlights ✨:

    • Keep sort and order criteria during navigation
    • Implement loading spinner for marking as favourite/read
    • Many bug fixes

    This release has been made by @Alkarex, @Inverle and newcomers @CarelessCaution, @the7thNightmare

    Full changelog:

    Features

    • Keep sort and order criteria during navigation #7585
    • Add info about PDO::ATTR_CLIENT_VERSION (relevant for MySQL / MariaDB with obsolete driver) #7591

    Bug fixing

    • Fix SQL request for user labels with custom sort (affecting PostgreSQL) #7588
    • Fix regression for favicon in GReader and Fever APIs #7573
    • Fix newest articles (within last second) not shown #7577
    • Fix duplicate HTTP header for POST #7556
    • Fix important articles on reader view #7602
    • Fix remove last share method #7613
    • Fix API handling of default category #7610
    • Fix user self-deletion #7626
    • Move PHP minimum version check #7560

    Security

    • Fix encoding of themes #7565
    • Fix .htaccess.dist for access to /scripts/vendor/ #7598

    SimplePie

    • Strip more HTML deprecated styles attributes: bgcolor, text, background, link, alink, vlink #7606

    UI

    • Implement loading spinner for marking as favourite/read #7564
    • Provide theme class for CSS #7559

    Deployment

    • Use HTTP Cache-Control: immutable for some files #7552
    • Drop Apache 2.2 (only support Apache 2.4+) #7561

    I18n

    • Improve Indonesian #7622
    • Improve Polish #7587

    Misc.

    • Update to PHPMailer 6.10.0 #7542
    • Update dev dependencies #7630, #7631, #7632
    • #7633, #7634, #7635
    Original source
  • May 3, 2025
    • Date parsed from source:
      May 3, 2025
    • First seen by Releasebot:
      Feb 12, 2026
    • Modified by Releasebot:
      Mar 17, 2026
    Freshrss logo

    Freshrss

    2025-05-03 FreshRSS 1.26.2

    Freshrss releases a comprehensive update that adds JSON string concatenation with the & operator, supports multiple JSON fragments in HTML+XPath+JSON mode, fixes tag search escaping and CLI boolean parsing, and expands SimplePie support. Security hardening includes CSP headers, iframe avoidance, and POST logout, plus UI, i18n, and dependency refinements.

    Features

    • Implement JSON string concatenation with & operator (#7414)
    • Support multiple JSON fragments in HTML+XPath+JSON mode (#7369)

    Bug fixing

    • Fix escaping of tag search (#7468)
    • Fix CLI parsing of Boolean flags (#7430)
    • Fix API for labels with slash (#7437)

    SimplePie

    • Fix support for feeds with XML preamble + DTD (#7515, simplepie#914)
    • Merged upstream (#7434) (Upstream fix simplepie#912)

    Security

    • Disallow (#7494, CVE-2025-32015)
    • Disallow (#7506)
    • Improve favicons hash to avoid favicon pollution (#7505, CVE-2025-46339)
    • Add Content-Security-Policy HTTP headers to favicons (#7471, CVE-2025-31136)
    • Web scraping forbid security HTTP headers in cURL (#7496, CVE-2025-46341)
    • Add some HTTP headers Referrer-Policy: same-origin (#6303, #7478)
    • Use HTTP POST for logout (#7489, CVE-2025-31482)
    • Make update URL read-only (#7477)
    • Fix for extensions: Restrict valid paths in ext.php (#7479, CVE-2025-31134)
    • Fix for extensions: Secure serving of user files (#7495)

    Extensions

    • Fix file serving for symlinked extensions (#7545)
    • Catch extension exceptions in override (#7475)
    • JavaScript: new event to detect context loaded (#7452)

    Deployment

    • Apache: add check for mod_filter to ensure that AddOutputFilterByType works (#7419)

    UI

    • Accessibility: Add :focus style to some dropdown menus (#7491)
    • New size option for the Mark as read button (#7314)
    • Update bcrypt.js from 2.4.4 to 3.0.2 (#7449)
    • Various UI and style improvements (#7168, #7526)

    I18n

    • Rework credits (#7426)
    • Improve French (#7432)
    • Improve Italian (#7540)
    • Improve Polish (#7508)
    • Improve Turkish (#7442)

    Misc.

    • Improve PHP code (#7431, #7488, #7534)
    • Update dev dependencies (#7480, #7482, #7483, #7484, #7485, #7486, #7487, #7533, #7535, #7536, #7537, #7538)
    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.