Normale weergave

Motion, Colour, Captions, Kit – These Weeks in Firefox: Issue 207

8 September 2026 om 20:38

Highlights

Friends of the Firefox team

Resolved bugs (excluding employees)

Script to find new contributors from bug list

Volunteers that fixed more than one bug

  • :Vincent
  • japandi
  • Nirmal Advani
  • Sebastian Zartner [:sebo]
  • tanvi.manku

New contributors (🌟 = first patch)

Project Updates

Add-ons / Web Extensions

Addon Manager & about:addons
  • As part of Nova about:addons work:
    • Introduced a shared localization module for built-in and curated AMO-hosted theme names, and updated the corresponding about:addons theme test to expect the new “Default” theme name shown when Nova is enabled – Bug 2055936 / Bug 2058235
    • Added a message bar to the about:addons themes picker to surface AMO-hosted Nova theme download and install failures instead of failing silently – Bug 2054548
WebExtensions Framework
  • Fixed a startup race where an extension’s restored dynamic content scripts could be missing from the parent WebExtensionPolicy due to stale shared data – Bug 2058719
WebExtension APIs
  • Fixed publicSuffix.isKnownSuffix() to reject invalid domain-name characters, including wildcard suffixes, that could previously be matched as a known public suffix – Bug 2059819
  • Fixed the frameId reported by webRequest events for requests made from workers, including importScripts()-loaded scripts, which were previously attributed to the wrong frame – Bug 2048884
    • Thanks to Giulio B for the fix to webRequest frameId attribution for worker requests.

DevTools

WebDriver

Fluent

Lint, Docs and Workflow

New Tab Page

Performance Tools (aka Firefox Profiler)

Search and Urlbar

  •  

British Columbia: Whistler

Door: David
8 September 2026 om 17:00

Today, we're excited to take you to Whistler, one of British Columbia's most famous mountain destinations, coming to our upcoming British Columbia DLC for American Truck Simulator!

Located along the scenic Sea-to-Sky Highway north of Vancouver, this vibrant resort town is surrounded by towering peaks, dense forests, and breathtaking alpine landscapes that make every journey through the region unforgettable.

Whistler is world-famous for its outdoor recreation and winter sports, attracting visitors from around the globe year-round. Nestled among the towering peaks of British Columbia's Coast Mountains, it gained international recognition as a host community during the 2010 Winter Olympic and Paralympic Games. Today, the area is renowned for its expansive ski terrain, scenic hiking trails, and impressive network of gondolas and cable cars, which provide breathtaking views of the rugged mountain landscape that surrounds the town.

Our map team has worked hard to capture the unique atmosphere of Whistler, from its distinctive mountain-town architecture to the spectacular scenery that surrounds it. Whether you're delivering supplies to local businesses or simply passing through on your way across British Columbia, this town offers plenty to admire from behind the wheel.

With stunning views around every corner and a rich history tied to one of Canada's most memorable sporting events, Whistler is sure to become a favourite stop for many virtual truckers exploring the British Columbia DLC.

If you're excited to hit the roads of Canada's westernmost mainland province, don't forget to add the British Columbia DLC to your Steam Wishlist! Also, be sure to follow us on X/TwitterFacebookInstagramTikTokBluesky, and YouTube, or sign up for our newsletter so you don't miss any future updates. Until next time, keep on truckin'!

  •  

Minecraft 26.3-pre-3 (snapshot) Released

8 September 2026 om 15:04
26.3 Pre-Release 3 (known as 26.3-pre-3 in the launcher) is the third pre-release for Java Edition 26.3, released on September 8, 2026, which fixes bugs. Full changelog: https://minecraft.wiki/Java_Edition_26.3-pre-3
  •  

v0.20.0-beta.1

8 September 2026 om 16:35

Version 0.20 of the Android TV app is coming. To read more about the release process and follow updates, please see the release plan discussion.

This initial beta will not be released on the app store beta channels.

If you appreciate my work, you can show your support with a donation through Buy Me a Coffee or GitHub sponsors. Your support helps me continue improving and growing the app. Thank you!

🐛 Beta information

Beta versions are not guaranteed to work as expected. We encourage users to create detailed bug reports if any problems arise. Read our blog post for more information about our Android beta programs.

🌟 Highlights

🏗️ Enhancements

💥 Crash fixes

🔧 Bugfixes

🔃 Refactoring

💡 Everything else

📈 Dependency updates

  • Update androidx.window:window by renovate[bot] v1.5.1 #5170, v1.5.0 #4965
  • Update aboutlibraries by renovate[bot] v15.2.0 #5768, v15 #5663, v14.2.1 #5603, v14.2.0 #5583, v14 (major) #5516, v13.2.1 #5258, v13 (major) #5007
  • Update androidx.work:work-runtime by renovate[bot] v2.11.2 #5487, v2.11.1 #5371, v2.11.0 #5043
  • Update Gradle by renovate[bot] v9.7.0 #5742, v9.6.1 #5662, v9.5.1 #5591, v9.5.0 #5558, v9.4.1 #5477, v9.4.0 #5455, v9.3.1 #5374, v9.3.0 #5339, v9.2.1 #5165, v9.2.0 #5065
  • Update github/codeql-action action by renovate[bot] v4.37.9 #5770, v4.37.7 #5758, v4.37.6 #5737, v4.37.4 #5728, v4.36.1 #5615, v4.35.5 #5592, v4.35.4 #5581, v4.35.3 #5565, v4.35.2 #5531, v4.35.1 #5492, v4.35.0 #5478, v4.33.0 #5472, v4.32.6 #5457, v4.32.5 #5451, v4.32.4 #5433, v4.32.2 #5391, v4.32.1 #5383, v4.31.10 #5327, v4.31.9 #5250, v4.31.8 #5241, v4.31.7 #5218, v4.31.6 #5203, v4.31.5 #5167, v4.31.3 #5144, v4.31.2 #5072
  • Update appleboy/ssh-action action by renovate[bot] v1.2.4 #5192, v1.2.3 #5108
  • Update com.android.tools.build:gradle by renovate[bot] v8.13.2 #5235, v8.13.1 #5131
  • Update actions/checkout action by renovate[bot] v7 - autoclosed #5661, v6.0.1 #5209, v6 #5175, v5.0.1 #5163
  • Update org.jellyfin.sdk:jellyfin-core by renovate[bot] v1.8.12 #5713, v1.8.10 #5606, v1.8.9 #5601, v1.8.8 #5514, v1.8.7 #5501, v1.8.6 #5344, v1.8.5 #5244, v1.8.4 #5202, v1.8.3 #5164
  • Update kotest by renovate[bot] v6.2.4 #5752, v6.2.3 #5701, v6.2.2 #5686, v6.2.1 #5653, v6.1.11 #5508, v6.1.10 #5497, v6.1.9 #5484, v6.1.8 #5483, v6.1.7 #5469, v6.1.6 #5463, v6.1.4 - autoclosed #5443, v6.1.3 #5388, v6.1.2 #5367, v6.1.1 #5351, v6.1.0 #5345, v6.0.7 #5201, v6.0.5 - autoclosed #5166
  • Update androidx.compose by renovate[bot] v1.12.0 #5760, v1.11.4 #5676, v1.11.3 #5657, v1.11.2 #5598, v1.11.1 #5580, v1.11.0 #5552, v1.10.6 #5486, v1.10.5 #5466, v1.10.4 #5442, v1.10.3 #5410, v1.10.2 #5372, v1.10.1 #5336, v1.10.0 #5214, v1.9.5 #5169
  • Update androidx.activity by renovate[bot] v1.13.0 #5467, v1.12.4 #5409, v1.12.2 #5254, v1.12.1 #5213, v1.12.0 #5171
  • Update androidx.lifecycle by renovate[bot] v2.11.0 #5659, v2.10.0 #5172
  • Update actions/stale action by renovate[bot] v11 #5721, v10.1.1 #5211
  • Update actions/setup-java action by renovate[bot] v6 #5792, v6 #5775, v5.4.0 #5655, v5.1.0 #5217
  • Update io.mockk:mockk by renovate[bot] v1.14.11 #5612, v1.14.9 #5360, v1.14.7 #5224
  • Update actions/upload-artifact action by renovate[bot] v7.0.1 #5525, v7 #5445, v6 #5242
  • Update Kotlin by renovate[bot] v2.4.20 #5803, v2.4.10 #5695, v2.4.0 #5622, v1.11.0 #5584, v2.3.21 #5553, v2.3.20 #5471, v2.3.10 #5389, v2.3.0 #5246
  • Update androidx.media3 by renovate[bot] v1.11.0 #5741, v1.10.1 #5590, v1.10.0 #5491, v1.9.3 #5473, v1.9.2 #5393, v1.9.1 #5359, v1.9.0 #5255
  • Update dependency org.jellyfin.media3:media3-ffmpeg-decoder to v1.9.0+1 #5288, by renovate[bot]
  • Update org.jetbrains.kotlinx:kotlinx-serialization-json by renovate[bot] v1.11.0 #5524, v1.10.0 #5347
  • Update dependency androidx.activity:activity to v1.12.3 #5373, by renovate[bot]
  • Update androidx.navigation3:navigation3-ui by renovate[bot] v1.1.7 #5778, v1.1.6 #5757, v1.1.5 #5727, v1.1.4 #5678, v1.1.3 #5658, v1.1.2 #5599, v1.1.1 #5551, v1.1.0 #5522, v1.0.1 #5412
  • Update android.gradle by renovate[bot] v9.4.0 #5698, v9.2.1 #5578, v9.2.0 #5549, v9.1.1 #5529, v9.1.0 #5453, v9.0.1 #5416
  • Update gradle/actions action by renovate[bot] v6 #5631, v5.0.2 #5437
  • Update coil by renovate[bot] v3.6.2 #5793, v3.6.1 #5779, v3.5.0 #5643, v3.4.0 #5441
  • Update dependency androidx.core:core-ktx to v1.18.0 #5468, by renovate[bot]
  • Update koin by renovate[bot] v4.2.2 #5650, v4.2.1 #5523, v4.2.0 #5474
  • Update dependency com.mikepenz:aboutlibraries-core to v14.1.0 #5566, by renovate[bot]
  • Update CI dependencies by renovate[bot] v6.2.0 #5640, v4.36.2 #5624, v6.0.3 #5617
  • Update jellyfin.sdk to v1.8.11 #5629, by renovate[bot]
  • Update io.github.peerless2012:ass-media by renovate[bot] v0.5.1 #5750, v0.5.0 #5723
  • Update dependency androidx.constraintlayout:constraintlayout to v2.2.2 #5726, by renovate[bot]
  • Update androidx.fragment to v1.9.0 #5761, by renovate[bot]
  • Update dependency androidx.appcompat:appcompat to v1.8.0 #5762, by renovate[bot]
  • Update CI dependencies #5348, by renovate[bot]
  • Update CI dependencies #5355, by renovate[bot]
  • Update CI dependencies #5415, by renovate[bot]
  • Update CI dependencies #5600, by renovate[bot]
  • Update CI dependencies #5677, by renovate[bot]
  • Update CI dependencies #5690, by renovate[bot]
  • Update CI dependencies #5730, by renovate[bot]

Contributors

  •  

UniFi Network Application 9.0.120

Door: UI-Glenn
8 September 2026 om 14:56

Overview

UniFi Network Application 9.0.120 includes the improvement below.

Improvements

  • Improved application stability.

Additional information

  • This release is only available for the UniFi Express (UX).
  •  

hMailServer 5.7, build 2843

29 Augustus 2026 om 12:20

Installation

  • Bundle libmariadb.dll with the installation (#479)
  • Support for passing in the password during install (#570)
  • Installer now propagates a non-zero exit code when DBSetup fails

Stability fixes

  • Addressed race conditions during IMAP communication
  • Fixed a file received over SMTP being left open
  • Fixed memory leak when reloading and checking event scripts
  • Upgraded to OpenSSL 3.5.8

Other

  • Documentation refresh

  •  

hMailServer 5.7, build 2788

22 Augustus 2026 om 17:09
  • Experimental support for MariaDB Connector (C). To use, put libmariadb.dll in hMailServer\Bin. hMailServer will prefer it over libmysql.dll if both exists.
  • IMAP improvements
    • Removed the ImapAuthAllowPlainText legacy option
    • Fixed invalid "Recent" count in IMAP notifications
    • Fixed FETCH not honoring the start.size partial-fetch clause
  • DKIM improvements
    • DKIM signatures for domain aliases
    • DKIM-sign all email sent from a domain, not just per-account
    • Fixed signing failure for messages >10MB
    • DKIM verification when the published DNS record is a CNAME
    • Signing for NDR/bounce messages
  • Optional X-Original-Rcpt-To header for incoming mail.
  • IMAP improvements: RFC 6154 support - LIST extension for Special-Use Mailboxes (\Sent, \Drafts, \Junk, \Trash, etc.), including auto-creation of special-use folders on account creation.
  • Security: TLS 1.3 support added
  • Security: OpenSSL upgraded to 3.5.7
  • 64-bit only. Support for x86/32-bit dropped.

  •  

BSD Release: FreeBSD 14.5

8 September 2026 om 15:00
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The FreeBSD project has published an update to FreeBSD's 14.x series. The new version, 14.5, provides several fixes and introduces some changes to the userland utilities. "The rc.firewall script now supports reading IP addresses or subnets from on-disk files for the firewall_allowservices and firewall_trusted list variables. Elements that....
  •  

v4.3.18

8 September 2026 om 10:36

Features

  • Added configurable alerts when scheduled database backups missed a set number of days. #11433 closed #11425.
  • Streamed S3-only volume archives directly to S3 so those backups no longer needed temporary local disk space. #11642
  • Added an instance setting for the CDN URL used to serve stored images such as profile avatars and project icons.

Improvements

  • Refreshed the UI with WCAG-compliant contrast, a unified surface system, a full-height settings rail, and a rebuilt mobile navigation drawer. #11659 closed #11532.
  • Preserved in-progress domain edits across refreshes, stacked domain rows on small screens, and moved preview deployment settings onto the Previews page.
  • Paginated service backup history, showed S3 destination details, disabled Backup Now unless the database was running, added search on server resources, and let operators enable Sentinel from its logs page.

Fixes

  • Allowed General application settings to be saved when an existing domain used a wildcard. #11683 closed #11641.
  • Prevented duplicate Coolify Cloud subscription checkouts and recovered subscriptions after missed or out-of-order Stripe webhooks. #11666
  • Preserved PATH in terminal sessions so SSH proxy commands such as cloudflared worked. #11638 closed #11611.
  • Stopped the persistent storage PR suffix dropdown from clipping inside the volumes table. #11637 closed #11605.
  • Returned scheduled task execution duration as a JSON number so the CLI could parse listings. #11636 closed #11616.
  • Persisted S3 storage settings when creating a new volume backup schedule. #11635 closed #11627.
  • Cleaned up preview deployments when a pull request closed after its base branch changed. #11634 closed #11609.
  • Persisted the Make publicly available setting for service databases. #11633 closed #11345.
  • Restored webhook delivery for always-send notifications, including SSL renewal, API token expiry, server force-enable/disable, and Hetzner deletion failures. #11528 closed #11507.
  • Raised nginx request header buffers so large Cookie headers no longer returned HTTP 400 before reaching Coolify. #11404 closed #11403.
  • Kept modal contents intact across Livewire re-renders instead of dropping the body and leaving a click-blocking overlay. #11294
  • Routed Docker Compose domains using each service's ports, stored explicit ports as overrides through the API, and stopped multi-service Compose domains from inheriting the application port.
  • Applied the same domain validation rules to the service API as the UI, including wildcards and oversized URLs.
  • Limited instance public IP DNS hints to the localhost server so remote servers showed their own addresses.
  • Preserved shell negation in sudo-wrapped commands on servers that use a non-root SSH user.
  • Deferred inspection of PostgreSQL custom-format backup archives to pg_restore so valid dumps were not rejected.

What's Changed

New Contributors

Full Changelog: v4.3.17...v4.3.18

  •  

12.0

8 September 2026 om 03:38

🚀 Jellyfin Web 12.0

We are pleased to announce the latest stable release of Jellyfin, version 12.0! This major release brings many new features, improvements, and bugfixes to improve your Jellyfin experience. As always, please ensure you take a full backup before upgrading!

Discuss this release further on our forums.

Changelog (264)

🔒 Security

🏗️ Enhancements

📈 General Changes

  •  

12.0

8 September 2026 om 09:50

🚀 Release notes for 12.0

Notes on Updating

Before upgrading from an earlier version, a full backup of the data directory is strongly recommended, as this release includes database changes that prevent rolling back without a full restore.

Direct upgrades from 10.10.7 and 10.11.x to 12.0 are supported; intermediate upgrades are not required. Users running releases older than 10.10.7 are strongly encouraged to upgrade to 10.10.7 before migrating to 12.0.

Installed repository plugins (anything not built-in) should also be removed before migrating. Plugins will likely need time to adapt to the new database changes, so re-adding them afterward is the safest approach for testing.

Official plugins compatible with Jellyfin are available through the stable plugin repository. If you have changed to the unstable plugin repository please change it back.

After migrating please perform the following steps.

  • Perform a full library scan to restore alternative versions

If you run into issues, please prefix bug reports with "[12.0]".

Packaging

  • Debian Bullseye and Ubuntu Focal packages are no longer built

Server

  • Performance PR implications #16062
    • We're running a full path-based check on all library items to clean up left overs. Depending on size this can take some time
    • Alternative versions of media that were auto resolved (not manually merged) will be removed due to data type issues -> A full library scan will fix this again and is therefore REQUIRED AFTER UPGRADE
    • First scan will take significantly longer than normal and some movies might appear as newly added due to type issues that got fixed on-scan
  • Multiple versions for episodes
  • Similarity & recommendation providers
  • Search providers, letting plugins extend or replace how search results are produced
  • SchedulesDirect and EPG refresh fixes
  • Fixes to the parental rating system
  • Proper data pruning on file replacement/deletion
  • Support triple+ digit episode numbers
  • Add library-specific BoxSet and Playlist filtering, allowing per-library collection and playlist views
  • CACHEDIR.tag support
  • Accept-Language header support
  • Add VideoRotation profile condition for Android TVs that do not support rotation metadata
  • Parse provider IDs from season and episode folder/file names
  • Allow tmdb, tvdb, and imdb as aliases for the tmdbid, tvdbid, and imdbid provider IDs
  • Add curly brace and parentheses support for parsing attribute values
  • Add NameStartsWith and NameLessThan filters to Person search
  • Add new filters for audio and subtitle languages
  • Add OriginalLanguage as option to PreferredAudioLanguage
  • Add a collection API for Included In feature
  • Add support for VobSub subtitle streams
  • Add Tmdb missing episode provider

Breaking and behavior changes

  • Legacy route prefixes removed (/emby/* and /mediabrowser/*). Old third-party clients that rely on them will stop working
  • Legacy authorization is now disabled by default, and a migration disables it on existing installs as well
  • Removed obsolete API routes: POST /Users/{userId}/EasyPassword (the EasyPassword feature is gone), GET /Items/{itemId}/CriticReviews, GET /Environment/NetworkShares, POST /System/MediaEncoder/Path, GET /LiveTv/Recordings/Groups/{groupId}, and GET /QuickConnect/Initiate
  • The global subtitle configuration has been removed, subtitle settings are configured per library
  • .ogg is no longer treated as a video extension and is audio only, .aifc is now recognized as audio, and .aiff is no longer treated as an image
  • Symlinks are only resolved at playback time
  • Sorting by name now uses SortName and CleanName, and the same cleaning logic is applied to ForcedSortName. Library ordering may change compared to 10.11
  • Image endpoints no longer upscale beyond the source resolution, so low resolution artwork renders at its real size instead of being enlarged
  • Username capitalization can now be changed. Usernames are stored in a normalized column with a unique index, so installs with usernames that differ only by case need to be corrected before upgrading

Database and performance

  • Playlists and collections are now properly relational, using a new LinkedChildren table instead of serialized child lists. OwnerId and PrimaryVersionId are real GUID foreign keys, and ExtraIds has been dropped
  • Many tuning migrations covering item counts, item names, type and clean name, latest items, image info, and primary version id
  • Migration routines clean up existing data on first boot: duplicate music artists and people are merged, orphaned extras and external data are removed, incorrect owner relationships are repaired, and clean names, forced sort names, and series presentation keys are recomputed
  • Heavy database tasks no longer run while a library scan is in progress
  • Faster queries for Resume, Next Up, rewatching, Latest Items for music, playlists and collections, artist lookup, and item counts
  • Item deletion is batched, which fixes "too many SQL variables" failures when deleting large numbers of items
  • jellyfin.db can now be stored at a custom path

Operations

  • New --mode startup flag with MediaServer, MigrateSystem, and SeedSystem, allowing migrations or database seeding to be run without starting the server. This is useful for containerized and orchestrated deployments and for controlled upgrades
  • The startup interface has been restyled and now shows version and activity information
  • Disabled plugins are no longer re-enabled on restart
  • Full system backups skip corrupt keyframe rows instead of failing

Media and subtitles

  • Subtitle writing now goes through SubtitleEdit, which is what avoids the SSA to ASS conversion and loss of styles
  • External subtitles can be embedded into MKV when transcoding
  • The subtitle extraction timeout is now configurable
  • Client-rendered graphical subtitles are allowed during remux
  • Fixes for races in concurrent subtitle conversion, cache invalidation when a subtitle is replaced, and ffmpeg hangs during extraction
  • New HlsAudioSeekStrategy configuration option
  • Trickplay: existing files are discovered during a scan, duplicates from interlaced video are fixed, invalid PTS values from containers are normalized, and the cache is cleaned up after a failure

Live TV

  • Live TV no longer returns unreachable "server-local" streaming URLs to clients
  • XMLTV background images and episode thumbnails are now imported
  • XMLTV guide imports skip programs whose data has not changed, using an ETag computed from the fields the server actually consumes, which makes repeat guide refreshes considerably cheaper. Other listings providers stay on the existing field-by-field update path

Metadata and providers

  • ListenBrainz is now bundled with the server and provides similar artist data with a selectable similarity algorithm
  • TVDB provider IDs are supported for movies
  • AudioDb artist search
  • ReplayGain album gain is parsed
  • MusicBrainz lookups are more resilient
  • WEB-DL release tags are recognized in file names
  • Hyphenated numbers in episode titles are no longer parsed as multi-episode files
  • 3D format detection works when the tag is the last token of the path
  • Person metadata refreshes are queued instead of blocking the request

Transcoder

  • New upstream version of FFmpeg 8.1
  • Optimized CUDA transposing filter performance
  • Optimized OCL scaling filter performance
  • Optimized OCL tonemapping filter performance on Mali GPU
  • Use EOTF from BT 2446 Method B for HLG tonemapping
  • Fix potential A/V desync in HLS when transcoding video while remuxing audio
  • Avoid SSA to ASS conversion and loss of styles
  • Add spec-compliant dvh1 HLS variant for DoVi P5 for compatibility

Web

  • The Modern layout is now the default, the previous layout is now called Legacy
  • Updated Music Videos view
  • Updated Mixed Media view
  • Updated Collections & Playlists view
  • Updated Books view
  • Add still watching prompt
  • Add delay setting for photo slideshow
  • Add caching of queries to indexed db for the tanstack query client for improved loading performance
  • Add watch feature to log viewer
  • Add , and . as controls to scrub frame-by-frame
  • Add filters for audio and subtitle languages (modern layout only)
  • Add Collections and playlist tab to all libraries
  • Add collections to item details page
  • Replace libpgs with libbitsub and adds support for vobsub rendering
  • Merge cards for crew with multiple roles

Layout and themes

  • All themes now derive from a shared base theme built on CSS variables, including Dark, Light, WMC, Blue Radiance, Apple TV, and Purple Haze. Custom themes may need to be adjusted
  • The library toolbar has been merged into the app bar, with a sticky library header and design polish throughout the library
  • Custom links can be added to the Modern layout
  • The screensaver time setting is now available in the Modern layout

Libraries and browsing

  • Collections and folders tabs for book libraries, and a folder view in the Modern home videos layout
  • Default tab options for Home Videos and Photos libraries
  • Studio search, and an extended Studios tab
  • Play All and Shuffle buttons on the series library. Both are disabled rather than hidden when no items are available
  • Improved Upcoming view
  • Sorting and filtering on the Activity page
  • A Reset Filters button in the filter dropdown
  • Folders can be marked as played
  • TV show creators are shown on item details
  • Similarity providers can be configured per library
  • Pagination controls are hidden when paging is disabled

Playback

  • The playback info overlay is more compact and shows more detail
  • Chapter names are shown in the OSD slider bubble
  • Bitrate detection now runs in web
  • Dolby Vision in MKV on webOS 25 and newer
  • AV1 fMP4 stream copy on TV clients
  • Direct play of anamorphic video on Tizen, and loosened anamorphic restrictions for browser device profiles
  • On iOS, background playback continues when the screen is turned off, and audio normalization is disabled to fix pitch and speed issues
  • libbitsub updated to v1.11.0 with an HLS offset fix
  • The screensaver is suppressed while viewing photos or reading

TV and remote

  • Game controller navigation fixes, and the gamepad repeat rate is no longer tied to framerate
  • Keyboard controls work on non-Latin keyboard layouts, with additional fixes for older browsers
  • Rewind and FastForward play state commands are handled
  • SyncPlay menu update, and the SyncPlay ping is now reported to the server
  • Focused and checked checkbox styling in the TV layout

Under the hood

  • WebSockets have been migrated to SDK subscriptions
  • The React and TypeScript migration continues with the libraries, Live TV, and networking pages, and the dashboard user pages now use the TS SDK
  • TanStack Query now backs user settings and home screen sections, and the query cache is cleared when the server restarts

Notable fixes

  • Blurry card images on high DPI displays, and card image sizes are rounded up
  • Duplicate /socket connections
  • Login loop, connecting to the wrong server when several are configured, and native shell server selection when signing out
  • An invalid request for all items on page load
  • The Live TV default landing tab
  • Holding and dragging on media no longer activates multi-select
  • A warning is shown before restoring a version, a warning is shown when starting a backup while a scan is running, and a library scan starts automatically when folders are added to a library

Security

Server:

  • Path validation has been added to the legacy HLS segment endpoints and to the plugin image endpoint, so a requested file must resolve inside the transcode directory
  • Path traversal hardening has been extended to the image and plugin endpoints and to username path handling, building on the fixes released in 10.11.x
  • The startup wizard can no longer be re-run without authentication on a misconfigured server
  • Unsafe plugin package names are rejected by the plugin installer
  • Parental filtering is enforced on additional endpoints, playlist visibility has been corrected, non-admin access to additional parts has been fixed, and people are exempt from the allowed tags visibility check

Web:

  • Cross-site scripting via person roles
  • Auth parameters are encoded when creating API clients
  • The login disclaimer only allows common link protocol schemes

Books

Books have often taken a backseat in favor of video playback in Jellyfin, but this should no longer be the case.
We have started a concerted effort to improve book support across the API and our official clients.
eBook and comic support is still maturing, but the ODPS plugin allows for direct access from a wide range of popular self-hosted programs.
Correspondingly, contributions in any repository are extremely welcome from the wider community.
That includes server improvements, documentation changes, and third-party clients for book playback.
A combination of eBook, comic, and audiobook support is available on the following clients.

Official: Web, iOS, Android, Desktop, Roku, Kodi, JMP
Community: JellyBook, Symfonium, Jellium, Plappa

One notable omission from the server is book series as unique entities, which didn't make the cut for this release.
If you would like to bridge the gap until they are added, feel free to use the Folio plugin to display them as collections.
It functions very similar to the TMDb Box Sets plugin but only applies to eBooks.

Another in-flight feature is audiobook chapters, which are only available from the API at present.
Luckily, this means client support is now possible, so you should see them appear in your favorite audiobook client before our next server release.

NOTE: The Bookshelf plugin has been deprecated and its features have been merged into server or extracted into the ComicVine and GoogleBooks providers.

Server Changes

  • Bookshelf has been split into separate GoogleBooks and ComicVine providers
  • Local book parsing has been improved and is available without plugins
    • Book metadata is extracted directly from OPF and ComicInfo files or ComicBookInfo comments
    • External covers are now supported for audiobook files
    • Posters are generated for EPUBs and all supported comic archives
    • Name, index, year, and series are parsed from book filenames
    • Both volume and chapter will be available in the API when present in comic filenames
    • Page counts are extracted from comic archives and PDFs
    • Creator names from OPF data are normalized to a common format
  • A new OpenLibrary plugin has been created for metadata and images
  • ISBN external IDs and links are supported
  • Chapters are now extracted from audiobooks

Web Changes

  • Modern book library layout has been added with view types and paging
  • Books display information about their authors and vice versa
  • Playback interface has been redesigned and standardized across all book types
  • Progress indicator is enabled again for supported eBooks
  • Sorting books by index number, release date, etc is now available
  • Font size selection has been improved for EPUB files
  • Background audiobook playback is working on iOS devices
  • Authors, collections, and folders tabs have been added to book libraries, and audiobooks appear under authors
  • Fullscreen behavior is unified across all book players, and PDFs support swipe navigation

Developers

API Changes

The API no longer allows the use of deprecated authorization mechanisms by default.
Clients and tooling need to migrate if they haven't done so already. See #15559 for details.

There have been a number of other changes to the SDK libraries and API as part of an ongoing effort to better document the API for client use.
Please note the following with regards to API support.
A full explanation of our policy for API changes will be added to the developer documentation in the coming months.

  • If an endpoint isn't listed in the OpenAPI specification it should not be used by clients.
    • There are certain endpoints that are still exposed for legacy reasons despite being excluded from the OpenAPI spec.
    • These can be removed in any major release without warning
  • If an endpoint or parameter is marked as obsolete in the OpenAPI specification it should not be used by clients.
    • Same explanation as above.
  • As a general rule, any deprecations will be marked as such for an entire (major) release cycle before the deprecated endpoint or parameter is liable for removal.

Behavior changes clients should be aware of:

  • GetItems is now asynchronous and applies recursive when filters are requested, limited to requests that include includeItemTypes. The same query can return a different result set than it did on 10.11
  • ItemByName responses are restricted and people are deduplicated
  • Newly obsolete but still functional, with replacements:
    • GetTrailers -> use GetItems with includeItemTypes=Trailer
    • GetArtists and GetAlbumArtists -> use GetPersons
    • GetArtistByName -> use GetPerson
    • GetMusicGenre -> use GetGenre
    • GetInstantMixFromMusicGenreById and GetInstantMixFromMusicGenreByName -> use GetInstantMixFromItem
    • GetStartupConfiguration, UpdateInitialConfiguration, and SetRemoteAccess -> use the configuration endpoints
    • GetRecordingsSeries
    • UserDto.HasPassword is marked obsolete and no longer provides useful information
  • The HLS controllers are hidden from the specification

Platform

  • The server now targets .NET 10. Plugins have to be retargeted and rebuilt
  • Swashbuckle has been updated to v10, which changes the generated OpenAPI document, so SDKs need to be regenerated
  • jellyfin-web now builds with Node 24 LTS and npm 11

Plugin changes

  • ISearchEngine has been replaced by ISearchManager, and SearchEngine has been replaced by SearchManager together with SqlSearchProvider
  • Removed: NowPlayingQueueFullItems, DtoExtensions.AddClientFields, Jellyfin.Extensions.AlphanumericComparator, the ISubtitleWriter family of subtitle writers, and SubtitleOptions with SubtitleConfigurationFactory
  • ServerConfiguration.EncoderPreset is no longer nullable
  • IAuthenticationProvider.HasPassword has been removed
  • IPasswordResetProvider.StartForgotPasswordProcess takes the entered username and a nullable user
  • IUserManager: the Users and UsersIds properties are now the GetUsers and GetUsersIds methods, and RenameUser, ResetPassword, and ChangePassword take a user id instead of a User. GetFirstUser has been added
  • Several IItemRepository members moved to the new services: item saving and deletion and UpdateInheritedValues to IItemPersistenceService, counts to IItemCountService, and Next Up series keys to INextUpService
  • IPeopleRepository.GetPeople and ILibraryManager.GetPeopleItems return a QueryResult, and IDtoService.GetBaseItemDtos and ILibraryManager.DeleteItemsUnsafeFast have new signatures
  • IDirectoryService.GetFilePaths no longer takes a sort argument, and the IPathManager subtitle and attachment path getters are now nullable

New plugin APIs

This release adds several extension points that plugins could not hook into before.

  • Search providers. Plugins can now take part in search itself rather than only in metadata lookup. ISearchProvider exposes Name, Type, Priority, and CanSearch(SearchProviderQuery), with IInternalSearchProvider for providers that search the local library and IExternalSearchProvider for providers that stream SearchResult items from a remote service. Providers are registered through ISearchManager.AddParts and are consulted in priority order, so a plugin can extend or take over from the built-in SqlSearchProvider
  • Similarity and recommendation providers. ISimilarItemsProvider is split inherited by ILocalSimilarItemsProvider, IRemoteSimilarItemsProvider, and IBatchLocalSimilarItemsProvider, each with a generic variant so a provider can declare the item type it handles. Providers are selected and ordered per library through LibraryOptions.SimilarItemProviders and SimilarItemProviderOrder, and ISimilarItemsManager also pulls movie recommendations. The bundled ListenBrainz provider is built on this
  • Comic metadata providers. IComicProvider (ReadMetadata and HasItemChanged) lets a plugin supply comic metadata alongside the built-in ComicInfo and ComicBookInfo readers
  • Chapters for any item type. IChapterManager.SaveChapters now takes a BaseItem rather than a Video, and gained a Supports(BaseItem) check. This is what makes audiobook chapters possible, and it lets plugins save chapters for non-video items
  • Password resets for unknown users. IPasswordResetProvider.StartForgotPasswordProcess now receives the entered username along with a nullable user, so a provider can handle a request for a username the server does not know or hand the reset off to an external provider
  • Media segment cleanup. IMediaSegmentProvider.CleanupExtractedData is called when an item's data is pruned, so segment providers can remove their own extracted files
  • Schedules Direct. ISchedulesDirectService exposes available countries, service availability, and the image daily limit state, so Live TV plugins no longer need to reimplement them. ITunerHostManager.DeleteTunerHost allows removing a tuner
  • Alternate versions and linked children. Now that linked children are relational, ILibraryManager exposes ResolveAlternateVersion, GetLocalAlternateVersionIds, GetLinkedAlternateVersions, GetItemIdsWithAlternateVersions, and UpsertLinkedChild. Plugins that manipulated version links through serialized item data need to move to these
  • Batch APIs for bulk work. IUserDataManager gained GetUserDataBatch, GetResumeUserData, GetResumeUserDataBatch, and ResetPlaybackStreamSelections. ILibraryManager gained GetPeopleByItems, GetPeopleNamesByItems, and GetNextUpEpisodesBatch. IItemCountService offers batched child and played/total counts
  • Localization. ILocalizationManager.GetServerLocalizedString and GetLanguageDisplayName let plugins localize against the server locale
  • ICollectionManager.GetCollectionsContainingItem backs the Included In feature, and IPlaylistManager.AddItemToPlaylistAsync takes a position so items can be inserted at the top of a playlist

IHasEmbeddedImage is also new, but it is only for plugins compiled into the server; external plugins should keep declaring their image with imagePath in meta.json.

TLS Configuration

In the previous release notes 10.11.0 we announced the deprecation of the built-in TLS certificate handling for this version. This change has been postponed to a future version.


Discuss this release further on our forums.

Changelog (460)

🔒 Security

🌟 Highlights

🏗️ Enhancements

📈 General Changes

  •  

Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, 3.8.21, 3.7.23, 3.6.21, 3.5.28

7 September 2026 om 23:55

Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, 3.8.21, 3.7.23, 3.6.21, 3.5.28

[An on-line version of this announcement will be available at https://www.postfix.org/announcements/postfix-3.11.7.html]

This release addresses medium-impact problems that need to be fixed as some enable remote DOS or policy bypass.

The fixes below, and more, are also released in the unstable version postfix-3.12-20260902.

In addition to updated releases for the supported Postfix versions 3.8-3.11, releases will also be available for the out-of-support Postfix versions 3.5-3.7. NOTE: these do not include the patches for out-of-support Postfix versions that have been issued for "large SMTP inputs (June 2026)", and for "TLSA parsing (June 2026)". Those patches still need to be applied.

These defects were found by "Qualys assisted by Claude Mythos Preview", and by "OpenAI Security"; three date from 20 or more years ago.

SMTP smuggling:

  • Bug (introduced: Postfix 3.9, date: 20240106) SMTP smuggling was still possible with smtpd_proxy_filter (disabled by default) when the after-filter SMTP server used the default policy settings "smtpd_forbid_bare_newline_exclusions = $mynetworks" and "smtpd_forbid_bare_newline = normalize". Reported by OpenAI Security. Fix by Wietse.

    As suggested by OpenAI Security, eliminate stray CR characters from the smtpd_proxy_filter input stream. The before-proxy-filter SMTP server already eliminated stray LF.

  • Bug (introduced: Postfix 3.11, date: 20250917): SMTP smuggling was possible with smtpd_proxy_filter (disabled by default) when the before-filter SMTP server added a "Require-TLS-ESMTP: yes" message header, due to implementation edge cases. Adding this header is enabled with the "requiretls_esmtp_header = yes" default setting. Reported by OpenAI Security. Fix by Wietse.

Server crashes and panic()s:

  • Bug (defect introduced: Postfix 3.0, date: 20140707): null pointer read error after receiving MAIL FROM, RCPT TO, and VRFY with an UTF8 address but no SMTPUTF8 parameter. This requires "smtputf8_enable = yes" (the default) and "strict_smtputf8 = yes" (not default). With this, the SMTP server did an unnecessary MAIL FROM reset without RCPT TO reset. A crafted remote SMTP client could then send a DATA command and crash a Postfix SMTP server process with a null pointer read error. Reported by Wonyoung Jung (정원영).

Other bugs

  • Bug (defect introduced: Postfix 3.4, date: 20180303): the MySQL client setting "tls_verify_cert = yes" had no effect with Oracle MySQL 8 and later. Report and fix by OpenAI Security.

  • Bug (defect introduced: Postfix-beta, date: 19990119): the pipe(8) delivery agent deleted a command-line argument if the argument contained $user AND $user expanded to an empty string, breaking the positional order of arguments. This was a workaround for a problem that hopefully no longer exists. Reported by Qualys, assisted by Claude Mythos Preview.

  • Bug (defect introduced: Postfix 2.3, date: 20050323): the SMTP client enhanced status code parser could process stale data when a remote SMTP server sent a three-digit reply. Reported by Qualys, assisted by Claude Mythos Preview.

TLS

  • Isolation: stamp Postfix SMTP server TLS session tickets with their master.cf service name. With this, an SMTP server defined in master.cf will no longer accept tickets issued by a different SMTP server defined in the same master.cf file. Fix by OpenAI security.

Configuration safety

  • The postmap and postalias commands now log a warning when creating a root-owned database file in a directory that is not owned by root. They log that the database source file, indexed file(s), and parent directory should have the same owner, to prevent a privilege-escalation attack. Problem reported by OpenAI Security, remediation strategy (don't break production deployment) by Wietse.

Read after free, memory over-read

  • Bug (introduced: Postfix 2.3, date: 20060629): a malicious Milter or attacker-in-the-middle could trigger a null-terminated heap memory overread in the SMTP daemon while formatting a malformed multiline response. Fix from OpenAI Security adopted with minor changes.

  • Bug (defect introduced: Postfix 3.0, date: 20141117): in the postqueue command don't free() text before logging a fatal error message. Reported by Qualys, assisted by Claude Mythos Preview.

  • Code hygiene: in the SMTP client protocol engine, evaluate a RETURN() macro argument before freeing resources. Reported by Qualys, assisted by Claude Mythos Preview.

Code hardening (defense in depth, prevention)

  • (Postfix 3.11) Hardening: in the non-BerkeleyDB migration service, delay the decision between running postmap or postalias until after the database file/directory owner/permission checks. The benefit from making the decision early (better error messages) was not worth the risk. Qualys, assisted by Claude Mythos Preview.

  • (Postfix 3.11) Hardened the database parent directory permission checks for automatic re-indexing with the non-Berkeley-DB migration service.

  • Hardening command-line email submission: the postdrop command now disallows null and line-break characters in queue file envelope records (line-break characters in non-envelope queue file records are already neutralized by default with "cleanup_replace_stray_cr_lf = yes").

    The new constraint not only eliminates line-break injection into local mailbox files as reported by OpenAI Security, but also prevents other forms of misuse. Later, this constraint may be moved into the Postfix core. Fix by Wietse.

  • Shut up nagging from multiple AIs and harden the virtual delivery agent against an evil (LDAP or SQL) database.

  • Code hygiene: myrealloc(ptr, 0) still resulted in a panic. Reported by Qualys, assisted by Claude Mythos Preview. Also adopt a mystrndup() fix from Postfix 3.12.

Other:

  • Portability: OpenBSD does not define NS_INT16SZ. Brad Smith.

You can find the updated Postfix source code on the mirrors listed at https://www.postfix.org/.

  •  

South Dakota: Pierre

Door: Petr
7 September 2026 om 17:00

Welcome to the capital city of the Mount Rushmore State, Pierre! In today's blog, we will be sharing a preview of our version of this beautiful town and its sister city, Fort Pierre, which are eagerly waiting to welcome their first truckers with the imminent release of the South Dakota DLC.

While being a relatively small town with just around 14,000 residents, Pierre is a hidden gem waiting to be explored. Welcoming nearly 3 million visitors each year, it is a destination for outdoor enthusiasts, offering world-class fishing, scenic trails, and endless opportunities for water recreation. This is made possible by its location along the banks of the Missouri River, set between Lake Oahe and Lake Sharpe, both created by dams.

But it's not just outdoor activities that draw visitors to Pierre. The city is also home to plenty of stunning historic landmarks, some of which we have recreated in our map. One of them is the South Dakota State Capitol Building, constructed in 1910. Keep an eye out for this architectural gem when driving through the city, as it can be spotted from a distance.

When arriving to the Pierre area from the south, you'll first pass through Fort Pierre, the oldest established settlement in the state, dating back more than 200 years. Here, you'll be able to spot a school building featuring a beautiful bison mural, as well as Fort Volunteer, a fort built to honor the volunteers who came to help during the 2011 flood.

Across from it, you'll find the courthouse with its stone monument featuring another bison. Further down the road, you'll also be able to spot the Casey Tibbs Rodeo Center Museum up on the hill, which is a multipurpose conference center and historical museum dedicated to the legendary sport of South Dakota rodeo.

Then, crossing the Missouri River over a newly built bridge, you'll be greeted by the "Welcome to Pierre" sign, followed by the Discovery Center building, an interactive, hands-on science museum for families and children.

And if you are driving to Pierre not just for sightseeing, but also to pick up a job, there are also plenty of industries that will need your help transporting their products, such as the shopping center, landscape supplies, and roadwork depots. We have also included the Pierre Airport on the outskirts of the city into the map, where you will be able to deliver cargo to and from. On the other side of the river in Fort Pierre, you will find a local truck dealer, livestock auction, mining machinery service, and truck stop depot.

We hope you are looking forward to exploring the wonderful capital of the Mount Rushmore State. If you do, make sure to add the South Dakota DLC to your Steam wishlist

Don't forget to follow us on X/Twitter, Facebook, Instagram, Bluesky, and YouTube for all the latest news from this map expansion and other American Truck Simulator content, or sign up for our newsletter to stay informed. Until next time, we will see you on the road!

  •  

DistroWatch Weekly, Issue 1189

7 September 2026 om 02:18
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: Genuen 6.0.0
News: Multikernel Linux, bots swarm the kernel repository, Debian being deployed at CERN, Debian 11 reaches its end of life
Questions and answers: Avoiding LLM-written code
Released last week: Linux From Scratch 13.1, Grml 2026.09, Talos Linux 1.14.0, Zenwalk GNU Linux 260905, NetBSD....
  •  

Part-DB 2.17.0

Door: jbtronics
7 September 2026 om 00:18

Note

If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8

Part-DB 2.17.0

New features

  • Support stateless MCP version 2026-07-28, alongside old stateful versions, improved MCP metadata
  • Added an advanced part search MCP tool, for more detailed part searches
  • Add TrustedParts.com (ECIA) info provider by @killecaptron in #1519
  • Use a proper HTML / twig code editor for labels in twig mode, instead of the CKEDITOR that messes up the twig templates
image

Bug fixes

Various changes

  • Updated dependencies
  • Improved translations
  • Improved code quality

New Contributors

Full Changelog: v2.16.1...v2.17.0

  •  

IAA TRANSPORTATION 2026

Door: Alex
6 September 2026 om 17:00

From the 14th to the 20th of September, members of our team will once again be heading to Hannover, Germany, for IAA TRANSPORTATION 2026, one of the world's leading events for logistics, commercial vehicles, and the transport industry.

Having attended IAA in previous years, we’re excited to return in 2026 and meet with many of our friends and partners from across the automotive industry. We’ll also be working alongside a few of our valued partners to bring our truck simulation experience to the DAF Trucks, MAN and Scania booths throughout the event!


At the Scania booth, visitors will have the opportunity to experience a special Euro Truck Simulator 2 demonstration running on Scania's own motion simulator setup. Our team has been happy to work closely with Scania to develop the software and a specially prepared demo experience for their simulator, and we're looking forward to seeing visitors get behind the virtual wheel and try it out for themselves during the show.

Our friends at DAF and MAN will also both be bringing Euro Truck Simulator 2 to their booths, as we're lending them our very own 4D motion simulators, giving visitors another opportunity to experience our virtual trucking world. We're very happy to support our partners at DAF & MAN for this year's event and to see our motion rigs become part of their presence at the show.

Attending IAA is much more than what visitors will see on the show floor for us. Bringing together manufacturers, suppliers, technology providers, and many other representatives from across the transport industry makes an event of this scale an invaluable opportunity for our team.

Throughout the week, we plan to meet with a number of our existing partners, continue building the relationships which help us bring the world of trucking into Euro Truck Simulator 2 and American Truck Simulator, and hopefully make some new connections along the way. Events such as IAA also provide our teams with a valuable opportunity to research the latest developments within the transport industry, see new vehicles and technologies up close, and gather useful references and knowledge for our future work.

We're very much looking forward to returning to Hannover and meeting so many familiar faces from across the industry. If you're attending the event yourself, be sure to stop by and check out the simulators; or if you happen to spot some of our team attending, wearing a SCS Software, ETS2 or ATS T-shirt, be sure to stop them and say hello! 

As always, keep an eye on our social media channels for updates from the show floor, as we will be bringing you some cool photos from the event. We hope to see some of you there! Until till next time, keep on truckin'! 

  •  

v0.16.21

6 September 2026 om 18:48

[0.16.21] - 2026-09-06

If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.

Added

Changed

  • Sieve: Messages generated by user scripts are DKIM signed through the new SieveUserInterpreter.dkimSignDomain setting, which defaults to the account's own domain.

Fixed

  • JMAP:
    • CalendarEvent/set requests that ask for scheduling messages are rejected with a forbidden error when the account cannot send them.
    • Calendar/get and AddressBook/get return every property when the properties argument is omitted or null.
    • EventSource ping events advertise the interval in seconds rather than milliseconds.
    • Calendar synthetic ids returned when expanding recurrences identify an occurrence by its recurrence id.
  • IMAP: Every command in a pipelined STATUS or FETCH batch receives its tagged completion, instead of the first failing command dropping the responses for all commands queued behind it.
  • WebDAV: Accounts without a storage quota no longer advertise a 4 GiB limit in DAV:quota-available-bytes.
  • MTA: Inbound DMARC and TLS aggregate reports that a reporter sends more than once are imported again as a duplicate entry.
  • Spam filter: Domain and URL blocklists are queried only for text written as a link.
  • iTIP: Detaching an occurrence that the recurrence rule already generates is sent as a METHOD:REQUEST carrying the RECURRENCE-ID instead of a METHOD:ADD.
  • Sieve: fileinto :specialuse and specialuse_exists accept special-use attributes in the \Trash form.
  • LDAP: Active Directory servers that answer an unauthenticated bind (a non-empty DN with a zero-length password) with success no longer authenticate accounts without a password.
  • Network: Listeners bound to the unspecified IPv6 address ([::]) fall back to IPv4 when socket creation fails with EPROTONOSUPPORT.
  • OpenTelemetry: log exporter does not include the parent span's attributes.

Check binary attestation here

  •  

BSD Release: NetBSD 9.5

6 September 2026 om 14:46
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The NetBSD project has announced the fifth and final update to the NetBSD 9.x series. The NetBSD 9 series will no longer receive security updates. "Announcing NetBSD 9.5. Note: this will be the final release from the netbsd-9 stable branch and also marks the end-of-support for this branch.....
  •  

v1.18.29

5 September 2026 om 01:47

Core

Bugfixes

  • Allow Codex OAuth model filtering to recognize integer GPT versions like gpt-6
  • Fixes issue of gpt-6-astra not showing up for openai subscription users

Thank you to 2 community contributors:

  •  

v1.18.28

4 September 2026 om 17:38

Core

Improvements

  • Send the session ID as GitHub Copilot's interaction header to improve request tracking across a session.

Desktop

Bugfixes

  • Use the desktop client ID during OpenCode account device authentication.
  • Increase the open-in app icon size for better visibility.

Thank you to 1 community contributor:

  •  

v1.18.27

2 September 2026 om 23:41

Core

Bugfixes

  • Default provider header timeouts to five minutes so slow model startups fail less often.
  • Default streamed chunk timeouts to five minutes, with false supported to disable them.
  • Let Anthropic thinking.blockBinding opt out via config when you need to keep the provider default. (@dkindlund)
  • Limit Anthropic thinking block binding to Claude 5.1+ models so older deployments do not reject requests.
  • Avoid unhandled errors when canceling timed-out SSE reads. (@AlexanderWillner)

Thank you to 2 community contributors:

  •  

v1.18.26

1 September 2026 om 23:52

Core

Bugfixes

  • Claude 5 sessions now tolerate stale thinking blocks instead of failing after prompt or tool changes.
  • Bedrock GPT-5.6 models now accept none reasoning effort.
  • Bedrock reasoning and replay handling is more reliable. (@pengzh1)
  • Tool call timing now stays accurate when tools update their metadata while still running. (@bartlettroscoe)
  • apply_patch no longer emits an empty move path in permission metadata. (@altendky)

Improvements

  • Azure CLI sign-in now asks for the resource name directly instead of querying Azure management APIs.

Desktop

Bugfixes

  • Session renames now save reliably from the title editor and tab context menu.

Thank you to 3 community contributors:

  •  

v1.18.25

28 Augustus 2026 om 07:58

Core

Bugfixes

  • Fixed Azure authentication so Azure CLI sign-in works without requiring Bun.

  •  

v1.18.24

28 Augustus 2026 om 06:10

Core

Bugfixes

  • Bedrock reasoning responses no longer get cached into unreplayable empty messages.

Improvements

  • Azure providers can now sign in with Microsoft Entra ID through the Azure CLI instead of requiring an API key.
  • V1 now reads supported V2 config fields so newer config files keep working in more mixed setups.

Desktop

Bugfixes

  • Archived sessions disappear from the Home list immediately. (@NathanTCode)

Thank you to 3 community contributors:

  •  

v1.18.23

25 Augustus 2026 om 08:30

Core

Bugfixes

  • Fixed Cloudflare AI Gateway routing for third-party providers so non-Workers models work through the gateway's REST API. (@superhighfives)
  • Fixed Anthropic models through Cloudflare AI Gateway by converting dotted model IDs like claude-haiku-4.5 to the dashed slug Anthropic expects. (@superhighfives)
  • Fixed parent session IDs being sent in request headers for session-aware providers.

TUI

Bugfixes

  • Fixed GitHub auth for immutable OIDC subject tokens.

Thank you to 1 community contributor:

  • @superhighfives:
    • fix(provider): send Anthropic's dashed native slug through the AI Gateway (#44281)
    • fix(provider): route non-native Cloudflare AI Gateway providers via the REST API (#44828)

  •  

v1.18.22

24 Augustus 2026 om 16:43

Core

Bugfixes

  • Removed outdated OpenCode Go first-month discount messaging and pricing.
  • Fixed OpenCode device login links when servers return relative verification URLs or use a base path.
  • Fixed textVerbosity being sent to OpenAI-compatible providers that do not support it. (@joelstucki-taulia)
  • Updated the Amazon Bedrock provider for compatibility fixes.

Desktop

Bugfixes

  • Keep model provider headers visible while scrolling the model picker.

Thank you to 1 community contributor:

  •  

v1.18.21

21 Augustus 2026 om 16:51

Core

Bugfixes

  • Continue responses when a model reports an unknown finish reason instead of stopping early
  • Route Vertex AI eu and us multi-region Gemini requests through REP endpoints

Desktop

Bugfixes

  • Keep file search results visible while the next search is loading
  • Register the archive session command in both desktop layouts (@NathanTCode)

Thank you to 1 community contributor:

  •  
❌