❌

Normale weergave

Distribution Release: EmmabuntΓΌs DE6-1.02

28 September 2026 om 22:01
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The EmmabuntΓΌs project has published a new update with a focus on improving accessibility options and features. "Our goal was to preserve the spirit of this approach: making accessibility features immediately available without requiring users to memorize numerous keyboard shortcuts. Easy Menu: one key for simple access to....
  •  

Shoutout to More Layouts – These Weeks in Firefox: Issue 210

28 September 2026 om 21:31

Highlights

  • RΓ©v O’Conner added a settings popup to control the layout of the Inspector. β€œAuto” automatically switches the layout at a given toolbox width.
    • Firefox Developer Tools Inspector showing a layout menu with options β€œAuto,” β€œSide by side,” and β€œStacked.” β€œSide by side” is selected, displaying the HTML markup tree on the left and the CSS Rules panel on the right.
  • The new sidebar (sidebar.revamp) and switcher setting will be enabled by default for users along with Nova in DevEdition, Beta and Release channels. To ease the transition for old sidebar users, the β€œOpen tools from sidebar” option will be unchecked for those users to more closely resemble the old sidebar experience. The migration won’t apply to users who had already tried the new sidebar and reverted back.
  • The custom wallpaper library for the New Tab page is coming along! This allows you to save multiple images to your wallpaper folder, rather than replacing one image at a time. While it’s still in development, you can test it by setting browser.newtabpage.activity-stream.newtabWallpapers.customWallpaper.library.enabled to true, starting in Firefox 157.
    • Firefox New Tab's β€œYour images” customization subpanel showing two uploaded image thumbnails: a city street with a red streetcar and a hummingbird perched on a branch. The first image is selected with a purple outline. A dashed β€œAdd an image” tile with a plus button appears beside them.
  • Mark added an MDN search engine for Nightly and Developer Edition. Select it from the menus, or type @mdn <search term>.
    • Firefox address bar with @mdn typed and highlighted. A suggestion below reads β€œ@mdn – Search with MDN,” demonstrating the MDN search shortcut.
    • Firefox address bar using the MDN search shortcut with β€œmarquee” typed. The suggestion dropdown includes β€œSearch with MDN” and MDN results for the HTML element, the ARIA marquee role, and HTMLMarqueeElement.

Friends of the Firefox team

Resolved bugs (excluding employees)

Script to find new contributors from bug list

Volunteers that fixed more than one bug

  • :Benjamin Peterson
  • Amadi
  • any1here
  • Caleb Pickard
  • Chris Vander Linden
  • Gopalarathnam Venkatesan
  • Igor [:ExplodingJoysticks]
  • Khalid AlHaddad
  • LukΓ‘Ε‘ LipinskΓ½
  • Mayank Bansal
  • Nazeer Ahmed Shaikh
  • Noah Varghese
  • Sameem [:sameembaba]
  • Sebastian Zartner [:sebo]
  • sfshah
  • Xiaosen Zhuang

New contributors (🌟 = first patch)

Project Updates

Add-ons / Web Extensions

Addon Manager & about:addons
  • As part of Project Nova related work:
    • Fixed responsive layout issues that caused horizontal scrolling in about:addons at high zoom levels – Bug 2059864
    • Fixed the β€œDiscover extensions” button appearing multiple times in about:addons – Bug 2070281
    • Added telemetry for theme-picker shown events and for appearance/native-theme changes in about:addons – Bug 2069417 / Bug 2070341
    • Added an accessible name to the themes mode control in about:addons, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel – Bug 2064563
      • Thanks to Mark Kennedy for the help on fixing this accessibility gap
    • Updated the built-in dark and light theme previews to use the nova style – Bug 2070274
      • Thanks to Emilio Cobos Álvarez for the fix to the default light and dark theme previews.
    • Fixed the Nova default and AMO curated theme previews to follow the OS light/dark mode while ignoring the Website appearance setting, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel – Bug 2070562
  • Stopped setting unused taarId session cookies for AMO on startup – Bug 1871561
    • Thanks to Manuel Bucher for helping us to clean up these unused internals.
WebExtension APIs
  • Fixed webRequest requestBody parsing so POST form fields named __proto__ are no longer dropped – Bug 2061470
  • Changed alarms.clearAll() to resolve with undefined instead of a boolean, starting in Firefox 157 – Bug 2067229
    • Thanks to Ollie Hensman-Crook for the fix to the alarms API.
  • Implemented native messaging support via xdg-native-messaging-proxy for Flatpak and Snap builds – Bug 1955255
    • Thanks to Jan Horak for the native messaging work on Linux packaging.
  • As part of Florian QuΓ¨ze effort to investigate and fix intermittent failures:
    • Made windows.update() wait for the window to actually resize or move before resolving, fixing an intermittent Linux test failure – Bug 1307759
    • Fixed a pageAction popup incorrectly opening via a commands API shortcut while the extension was already shutting down – Bug 2039637
    • Fixed action.openPopup() rejecting when a tab hover preview was showing, a regression from Bug 2022281 in Firefox 150, with the fix shipping in Firefox 157 and no uplift planned – Bug 2062229

DevTools

  • The team has a few sizable ongoing projects.
    • Bomsy is working on moving Stylesheets to the Debugger so we can retire the (XUL-based) Style Editor, and turn the Debugger into a β€œSources” panel (keeping all the existing functionality of course).Β  (pref: devtools.debugger.features.stylesheets-in-debugger)
    • Alex is investigating ways to better handle CSS authored text and CSSOM changes in the Inspector, building information directly from the Rust CSS engine, with the hope it will bring performance improvement editing styles in the Rules view.
    • Nicolas is implementing a way to show to the user how the engine goes from a CSS declaration value to the computed value so it’s easier to follow what’s the result of the different call sites, or how the different units (em, %, vmin, …) are computed to their final (e.g. px) values. Β  (pref: devtools.inspector.css-explainers)
External contributions
  • Chris Vander Linden finalized a multi-months project to add a search toolbar in the Netmonitor Raw Response panel, adapting and reusing the component we are using in the Debugger (#1941575)
    • Firefox Developer Tools Network panel showing the Response tab for an HTML request with a new find bar. The response source contains several elements, with matches for β€œscript” highlighted in yellow. The find bar at the bottom shows the search term β€œscript” and indicates β€œ1 of 9 results.”
  • Amadi made the β€œOpen in new tab” context menu entry to open tab next to the selected tab, not at the very end of the tab list (#2059979)
  • Mayank Bansal optimized the performance of console.clear() (#2068156, #2068157, #2067000)
  • Benoit added JSON Lines (JSONL/NDJSON) support in the Netmonitor Response panel (#2059673)
  • Gopalarathnam Venkatesan made the β€œAdd class” button (.cls) to be disabled when a class can’t be added to the selected node (e.g. it’s a text node, or a comment, or the doctype node) (#2000150)
  • K fixed an issue with the β€œGo to line” action in the Debugger (#2064575)
  • Samuel Mbabhazi refactored our CSS codebase to use new color syntax (e.g. rgb(255 0 0) instead of rgb(255, 0, 0)) (#2054228)
  • sfshah turned devtools/client/jsonview/converter-child.js into an ES class (#2004273)
Team/Project Update

WebDriver

Fluent

Lint, Docs and Workflow

  • According to arewemozsrcyet.com, ~59% of our modules are now using moz-src.
  • eslint-plugin-mozilla has switched from using Mocha to Jest for tests.
    • Planning on future updates to investigate getting devtools & newtab to use the jest installed at the top-level, rather than separately installed copies.

Information Management/Sidebar

  • We’re working away on bug fixes for sidebar, vertical tabs, split-view, and Nova
  • Thanks Florian (:fqueze) for landing a set of patches that have markedly reduced test flakiness in the Sidebar component

New Tab Page

Picture-in-Picture

Search and Urlbar

Address Bar
  • Dao and Moritz are working on bringing the full urlbar experience into the newtab page, now enabled on nightly and going through polish and improvements.. (Bug 2068104, Bug 2068633, Bug 2069260, Bug 2064747)
  • Drew enabled AMP and Wikipedia by default in AT, BE, CH, ES, IE, LU, NL, PL, PT and SE. (Bug 2066294)
  • James gated adaptive autofill page results behind a minimum score threshold. (Bug 2066171)
  • any1here stopped disabled Manage AI and Labs quick actions being displayed when disabled. (Bug 2070378)
Search
  • Dale landed the Recent Searches widget which will be be used launched as an experiment (Bug 2063718)
    • The Firefox newtab search widget showing the "Recent searches" tab selected next to a "Trending" tab. Five recent search queries are listed, each with a history icon, including β€œback doune the rabbit hol…,” β€œisthismusic back doune,” β€œwrexham shirt sponsor,” β€œwalt disco album,” and β€œmoz-src.”
  • Caleb fixed the search box eating the first character typed into it. (Bug 1953361)
  • Mark configured Wikipedia search for Sardinian (sc) to use the Sardinian Wikipedia rather than the Italian one. (Bug 2057690)
Places
  • Marco fixed bookmarked Google Maps using Google’s default favicon. (Bug 1575809)
  • Marco fixed the Downloads and History windows going full-screen instead of floating on macOS. (Bug 2058062)

Tests

  •  

Legacy releases

28 September 2026 om 20:32

Archived hMailServer builds, from 4.1.1 to 5.6.9 build 2607. These versions are no longer supported and are kept for reference only. Use the latest release for new installations.

  •  

Release 2026.09.28

28 September 2026 om 19:22

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.28

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.28

Changes

  • fix: confine playlist/channel metadata files to the download directory (098cba4)
  • fix: also prompt in ask mode when only chapter files remain on disk (b2b4908)
  • feat: add an ask mode to DELETE_FILE_ON_TRASHCAN that prompts before deleting files (closes #1012) (52638fa)

  •  

v8.3.1

28 September 2026 om 13:43

SECURITY

  • This release addresses vulnerabilities ranging from medium to critical severity affecting PeerTube. In a week, this changelog will be updated to disclose the vulnerabilities.

Bug fixes

  • Force video encoding if there are rotation info
  • Fix broken studio on only intro/outro/cut task
  • Fix broken sorts/invalid sort checkers for channel syncs and ownership changes
  • Fix downloading a download-protected video for admins
  • Fix broken email title in some emails
  • Fix broken notification window if the list contains a broken change ownership notification
  • Fix table pagination after a search
  • Include muted muted videos when admins/moderators display all videos of an account/channel

  •  

Development Release: openSUSE 16.1 RC

28 September 2026 om 11:59
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The openSUSE project has published a new release candidate for the upcoming Leap 16.1 release. Among the various changes is a new immutable mode for Leap: "Leap 16.1 is the first Leap release to offer an Immutable Mode, a transactionally updated system with a read-only root filesystem. This....
  •  

v1.18.33

28 September 2026 om 06:22

Core

Bugfixes

  • Cloudflare AI Gateway models now honor provider response and stream timeouts. (@danlapid)
  • MCP browser launch failures are now reported when the launcher exits immediately.
  • Debug configuration output now redacts credentials and sensitive headers.
  • Gemini thinking defaults and effort options now match the supported controls across model generations. (@markmcd)

Thank you to 5 community contributors:

  • @dc85:
    • docs(web): add Claude Opus 5.5, GPT 6 Sol, and GPT 6 Luna to Zen (#50708)
  • @vglafirov:
    • maint(gitlab): bump gitlab-ai-provider to 6.16.0 (#50742)
  • @markmcd:
    • fix(gemini): switch thinking default logic (#50841)
  • @remorses:
    • docs(web): link kimaki to product website (#49735)
  • @danlapid:
    • fix(opencode): apply provider timeouts to Cloudflare AI Gateway models (#51549)

  •  

DistroWatch Weekly, Issue 1192

28 September 2026 om 02:13
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: ReactOS 0.4.16
News: Garuda offers NixOS-based edition, KDE turns 30, NetBSD polishes Enlightenment port, Q4OS offers Breeze theme for Trinity, Canonical speeds up kernel patches, postmarketOS becomes Nura
Questions and answers: Identifying the video card
Released last week: Univention Corporate Server 5.2-7, NetBSD 10.2
Torrent corner:....
  •  

Version 2.19.0

Door: jbtronics
27 September 2026 om 23:39

Note

If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8

Part-DB 2.19.0

New features

  • Added 3D model viewer, with support of STL, 3MF, OBJ, STEP, and more
image
  • Improved builtin footprint gallery viewer
image
  • Support to add custom "builtin footprints"
  • Added additional footprint images based on KiCad 3D models. You can download them with php bin/console partdb:attachments:download-footprint-images

Improvements

  • Optimized performance of part table views

Bugfixes

  • Fix remembered tabs hiding validation errors by @LMatt08 in #1559

Various changes

  • Updated dependencies
  • Updated KiCad symbols and footprints
  • Updated translations

New Contributors

Full Changelog: v2.18.0...v2.19.0

  •  

Release 2026.09.27

27 September 2026 om 18:50

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.27

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.27

Changes

  • feat: pair the video password with presets, give custom yt-dlp options a full row (345b8ae)
  • feat: add per-download video password for protected videos (closes #670) (080dcea)
  • ci: install corepack instead of relying on the copy bundled with Node (47553e8)
  • build: ship Python 3.14 in the image (be1d349)
  • build: move the frontend to pnpm 12 (2ffb718)
  • fix: let a cancel's SIGINT actually stop the download (c86f351)
  • ci: sync the Docker Hub description with a maintained action (aecd86d)

  •  

v0.16.24

27 September 2026 om 20:28

[0.16.24] - 2026-09-27

If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.

Added

  • DNS: PowerDNS Authoritative provider for automatic DNS record management.

Changed

Fixed

  • Troubleshoot tool: TLSA records are looked up for every MX host, including hosts whose zone is not DNSSEC signed.
  • Spam filter:
    • OpenPhish and PhishTank entries containing uppercase characters never match, since message URLs are lowercased while HTTP lookup entries keep their original case. HTTP lookups now match keys case-insensitively.
    • URL shortener links are followed using the lowercased URL, so case-sensitive short links resolve to the wrong destination or not at all.
    • Incremental training never advances its position past the first run, so every retained sample added since then is trained again, and counted again in the reservoir, on each run until it expires.
    • Updating the rules only adds new objects, so upstream changes to existing rules, DNSBL servers, HTTP lookups, lookup keys and file extensions never reach an existing installation.
    • Updating the rules reports success when objects fail to import, or when a configuration error stops the updated settings from being activated.
  • JMAP:
    • A PushSubscription created within the verification rate limit window of another one on the same account never receives its PushVerification, since the blocked verification is dropped instead of being sent once the window expires.
    • A push notification retried after a failed delivery can report an older state than a change queued during the failed attempt, since the older state changes are merged last and overwrite the newer ones.
    • Changes made while a push request is in flight are not delivered until the next change reaches the same subscription, since a successful delivery cancels the pending retry.
    • The VAPID aud claim is derived from a hand-written parse of the push URL, so a crafted push URL can make the server sign a token for a push service other than the one the request is sent to.
    • Email/import rejects a blobId that refers to a Blob/upload creation id in the same request ("#u0") with Invalid blob id..
    • Email/set with a full mailboxIds object identical to the current mailboxes, together with a keyword change, stores the message with IMAP UID 0, so IMAP clients stop seeing it.
  • MTA:
    • A node without the outboundMta role stops replying to DATA and to JMAP submissions once about 1024 messages have been queued on it.
    • MX records are resolved through the DNSSEC-validating resolver even when DANE is disabled.
    • A DATA stage Sieve script does not see headers added by milters or MTA hooks, and discards every milter and MTA hook change when it edits the message.
  • MySQL: Range deletions and search index removals start with a single unbounded DELETE and switch to chunks only after a timeout.
  • IMAP: COPY and MOVE fail with NO [CONTACTADMIN] when another session changes the same message at the same time.
  • Autodiscover: Implicit TLS ports (993, 995, 465) are advertised with <Encryption>TLS</Encryption>, which Outlook reads as STARTTLS.
  • HTTP: Idle keep-alive connections are never closed.

Check binary attestation here

  •  

SCS On The Road: Star Nation Experience 2026

Door: Petr
27 September 2026 om 17:00

This year, we were once again invited by Western Star to take part in their Star Nation Experience along with two members from our American Truck Simulator community. Today, we bring you an SCS On The Road episode where you can watch what the whole amazing event looked like!

Beny and Oscar travelled all the way to Bend, Oregon, to represent SCS at the wonderful Star Nation Experience 2026 in June. There, they met up with two members of our ATS community, Conor and Nathan, who were selected and invited by Western Star for an all-expenses-paid trip and a weekend packed with unforgettable experiences.

From fly fishing and ATV rides to the X-Series Ride & Drive Challenge at the Madras Proving Grounds, they also got to meet the Western Star team and other trucking enthusiasts. So, let's watch together and see how the Star Nation Experience 2026 went!


We would like to say a huge thank you to Western Star for inviting us once again, along with Nathan and Conor, and for giving us the opportunity to take part in such an amazing event. We are also happy that we could capture the experience and share it with our community!

Make sure to follow us on X/Twitter, Facebook, BlueSky, YouTube, and InstagramΒ so you don't miss out on any events, news, and fresh SCS On The Road episodes. Alternatively, you canΒ subscribe to our newsletterΒ to stay informed. Until next time, happy hauling!

  •  

v0.8.9

27 September 2026 om 15:23

What's Changed

  • fix(gui): swap the thumb-wheel volume preset labels onto the pairing they describe by @4ni1ak in #1436
  • fix(hook): stop the GNOME frontmost observer leaking a socket per renewal by @sungyongcho in #1418
  • fix(gui): rebuild the agent's launchd registration when its job is gone by @raphaeljostan in #1303
  • fix(hook): hit-test the window under the pointer through AppKit by @pseudoseed in #1568
  • chore: release v0.8.9 by @AprilNEA[bot] in #1599

New Contributors

Full Changelog: v0.8.8...v0.8.9

  •  

v1.11.2 - Docker Fix

Door: rathlinus
26 September 2026 om 22:21

1.11.2 (2026-09-26)

1.11.2 fixes the Docker image and the standalone tarballs of 1.11.1, which did not start. It contains all the security fixes from 1.11.1, so please update.

Thank you for your donations:

One-time

Monthly

Fixes

  • Docker: The server starts again. 1.11.1 excluded data/ from the standalone build with a pattern that also dropped Next.js's own metadata modules, so the Docker image and the bulwark-standalone-* tarballs failed on startup. npm start and Bulwark Lite were not affected

  •  

v1.11.1 - Security Hardening, Tasks in Month View & Multi-Account Fixes

Door: rathlinus
26 September 2026 om 21:59

1.11.1 (2026-09-26)

1.11.1 is a security and bug-fix release. It fixes four reported vulnerabilities, two of them critical, and the findings of a security audit. Please update.

Thank you for your donations:

One-time

Monthly

Security

  • Admin: Only a Stalwart superuser gets into the admin dashboard. The admin probe accepted Stalwart's default tenant-admin role, so the administrator of a single tenant was signed into a dashboard that configures the whole instance (GHSA-v6hr-cmxm-pv73, thanks @douwezijlstra-frl)
  • Admin: Admin status is only taken from an admin-configured server. A context cookie minted while custom JMAP endpoints were allowed let a user-chosen server keep answering the admin probe after the switch was turned off (GHSA-j867-89p4-v8hm, thanks @Vip3r-MC)
  • API: Cross-origin writes are refused on the JMAP passthrough and every other cookie-authenticated /api/ route, not only /api/auth/*. A page on a same-site sibling origin could run arbitrary JMAP as the signed-in user. The gate also decides on the decoded path, so /api/%61uth/... no longer skips it (GHSA-9mvj-98f5-9q6g, thanks @kah-ja)
  • Admin: Admin sign-in attempts are also capped at 50 per 15 minutes across all clients, because a forged X-Forwarded-For got a fresh per-IP budget when no reverse proxy is in front (GHSA-7pj2-232x-6698, thanks @richardweinberger)
  • Admin: Impersonation no longer puts the Stalwart master password into the session cookie. The webmail creates an app password on the target mailbox that expires after 8 hours and is revoked on sign-out, and a used impersonation link is refused after a restart or on another replica
  • Mail: A sender can no longer fake a DMARC or DKIM pass in the security badges, with a crafted envelope address or an Authentication-Results header of their own
  • Mail: Opening an SVG attachment's thumbnail on its own no longer runs the sender's script in the webmail origin
  • Mail: Remote content stays blocked in the mobile conversation view, the .eml attachment preview, the quoted original of a reply or forward, the print view, and for URL spellings the filter missed (backslashes, CSS escapes, image-set())
  • Mail: Links in image maps (<area>) no longer keep window.opener
  • Mail: A mailto: unsubscribe goes to the single address in the link, and the confirmation shows recipient, subject and body before sending
  • Mail: A crafted winmail.dat no longer freezes the tab
  • Composer: A sender name containing a quote can no longer add a recipient to a draft
  • Filters: Rule names, header names and sizes are escaped, so rules from plugins or imported filter sets cannot add commands such as redirect to the Sieve script
  • Plugins: Hooks and slots need a declared permission, like the host API does. http.post can no longer reach the JMAP passthrough, /api/admin/*, /api/settings or other credentialed routes, and plugin storage is kept per account and deleted on sign-out
  • Themes: The theme CSS sanitizer no longer lets remote resources through (url(//host), CSS escapes, image-set(), @font-face sources), and theme CSS can only target :root and .dark, also when a plugin transforms it
  • Files: WOPI file downloads are always served as inert attachments, so a blob typed text/html cannot run script in the webmail origin
  • Server: The SSRF guard also blocks loopback beyond 127.0.0.1, CGNAT, benchmark, multicast and reserved ranges, and NAT64, 6to4 and Teredo addresses that wrap an internal IPv4 address. Telemetry targets are checked at connect time, and OAuth token and revocation requests never follow redirects
  • Auth: Synced settings are keyed on the account a bearer token belongs to, so on a multi-domain server john@b.example can no longer read the settings of john@a.example
  • Auth: Wrong passwords tried through the login pre-check are limited, so the route can no longer be used as a password oracle or trip Stalwart's ban against the webmail itself
  • Auth: Signing out ends office editor sessions opened in that browser, and a full sign-out clears search history, open tabs, Files recents, staged plugin uploads and the other accounts' leftovers, also in other open tabs
  • Auth: Signing out when another account's restore had failed no longer leaves that account resumable
  • Auth: The failed TOTP login no longer passes on a user-chosen server's error body
  • Server: Visitors who are not signed in no longer get detailed health data, the pending advisory text, the plugin list, the full admin policy or every server's domain list
  • Server: The setup token is passed in the URL fragment, so it stays out of access logs, referers and history
  • Server: Not-found pages outside the app tree cannot be framed, ALLOWED_FRAME_ANCESTORS never applies to the admin dashboard or setup, and sibling subdomains can no longer widen the sidebar-app frame-src
  • Server: Favicons are only served as raster images
  • Docker: Runtime state and secrets (data/, local-data/, .env) stay out of the standalone build and the image, and the mock JMAP server can no longer be switched on in a release build
  • Lite: Sign-out revokes the refresh token, and a failed token login no longer keeps the password in sessionStorage
  • Lite: Every static page gets a CSP that allows only its own inline scripts, the Stalwart bundle refuses to run inside a foreign frame, and the Stalwart install instructions use a tagged release with a published .sha256 instead of releases/latest

Features

  • Calendar: Tasks with a due date show in the month view (#1107)

Changes

  • Plugins: Hooks that change outgoing mail need email:send, and display takeovers need email:render-takeover. Plugins that don't declare them lose those hooks
  • Themes: Theme CSS keeps only :root and .dark rules plus @font-face, @keyframes, @media and @supports. Every url() except a #fragment is removed
  • Admin: Impersonated sessions end after 8 hours, and sessions minted by earlier versions are signed out
  • Server: /api/health?detailed=true needs a session

Fixes

  • Mail: The inbox keeps rendering when a message has an unparsable date (#1099)
  • Mail: A folder no longer switches back to the unified inbox while it loads (#1102, thanks @guisea)
  • Mail: Replies in the unified inbox come from the identity of the account that received the mail (#1104)
  • Mail: Mail deleted during a list refresh no longer reappears (#966)
  • Mail: The message list no longer jumps while attachment chips load
  • Mail: Scrolling the unified inbox, cross-account views, tag views and "All folders" search no longer skips messages
  • Mail: A failed message-list read keeps the list on screen instead of showing an empty folder
  • Mail: Marking read, starring, tagging, emptying a folder and cancelling a scheduled send report it when the server refuses them
  • Mail: Tagging and pinning write only the keywords that change, so they no longer mark mail unread that was read on another device
  • Mail: New mail and folder changes keep arriving for users with seven or more shared accounts
  • Send: A dropped connection can no longer send a message twice
  • Send: Undo and edit of a message sent from a group identity act in the group's own account
  • Composer: A reply draft stays in its thread when it is re-opened or undone
  • Composer: An open draft stays on its own account across an account switch
  • Accounts: Quick account switches no longer mix up identities, so replies go out with the right From address
  • Accounts: Folders, filters and the account security page no longer show the previous account's data after a switch
  • Accounts: Settings sync turns back on after signing out of one of several accounts
  • Push: A notification opens its message in the account it came from
  • Calendar: Events you declined show struck through (#1110)
  • Calendar: Daily recurring events keep going past a DST gap
  • Calendar: iCal subscriptions stay with the login that created them, so refreshing or removing one no longer touches a calendar of another login
  • Auth: SSO sign-in behind nginx no longer fails with a 502 when the cookies would overflow its header buffer (#1096)
  • Auth: Sign-in and addresses work on internationalized domains (#1100)
  • Lite: A rate-limited token endpoint no longer signs you out
  • i18n: The dark/light mode titles and the "Themes" settings tab are translated in every language (#1105, #1106, thanks @dulinux), and so is the themes settings panel
  • i18n: Updated Portuguese (Brazil) translation (#1106, thanks @dulinux)

  •  

Release 2026.09.26

26 September 2026 om 09:50

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.26

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.26

Changes

  • chore: upgrade Python and frontend dependencies (f5e5ab3)
  • fix: say when an add is skipped because the video is in the download archive (98b0b10)
  • feat: Auto audio format and a Tags choice for what gets written into the file (ee2bb0b)
  • docs: reword the contribution guidance (d959cbc)
  • ci: warn when the README passes a 15,000-byte budget (04ebfb8)
  • docs: restructure the README as a landing page and variable reference (d310bcc)
  • docs: state in SECURITY.md that MeTube does not request CVEs (f319b26)

  •  

Dopamine 3.0.11

Door: digimezzo
26 September 2026 om 12:15

[3.0.11] - 2026-09-25

Added

  • Added optional wave progress bar
  • Ctrl+F now selects all text in the search box for quick replacement
  • Added optional Stop button (Hidden by default, but can be enabled in the settings.)
  • Scroll position is now remembered when switching screens
  • Added buttons to the playback queue to clear the queue and to add the queued songs to a playlist
  • Added album release date to album image tooltips and optionally on the nog playing page
  • Added a playback speed control (Thank you @henryshuen)

Changed

  • Updated the Simplified Chinese translation (Thank you @jeremyooh)
  • Updated the Vietnamese translation (Thank you @honhatduy)

Fixed

  • Adding artist image doesn't always work
  • Crash when displaying rich lyrics of songs with a lot of artists
  • On KDE, Dopamine appears under "Lost & Found" in the application menu instead of "Multimedia" (Thank you @adem4ik).
  • Failure to index files with malformed TXXX frames

P.S.: If you enjoy Dopamine, please consider donating via PayPal or buying me a coffee. Your support keeps the music going!

  •  

OBS Studio 33.0.0-beta4

26 September 2026 om 00:29

Beta 4 Changes

  • Fixed a CI and packaging issue. There are no application changes since Beta 1.

Beta 3 Changes

  • Fixed a CI issue. There are no application changes since Beta 1.

Beta 2 Changes

  • Fixed a versioning issue. There are no application changes since Beta 1.

33.0 New Features

  • Updated CEF from 127/6533 to 150/7871 [WizardCM] (#13900)
    • This is a massive update to the underlying framework used for browser sources and docks from the July 2024 release to September 2026
    • All of this work is on the backend and should be invisible to users. Please be sure to report any new weirdness or problems you run into with browser sources!
  • Complete overhaul to plugin loading [FiniteSingularity/PatTheMav] (#13594)
    • First-party plugins are now in a new folder named core
    • Third-party plugins have an updated installation location and folder structure
    • Existing third-party plugins will continue to load from the legacy locations until OBS Studio 34.0
    • More information is available in our knowledge base article.
  • Improved how source snapping works in the preview [Warchamp7] (#12298)
    • New visual indicator added
    • Sources now snap along the entire axis instead of only when directly touching
    • Sources no longer snap to hidden sources
  • Improved behavior of spinboxes for number values [Warchamp7] (#12337)
    • Typing is no longer mysteriously blocked in some situations
    • Numbers are no longer cut off in some situations
    • Values now update only after pressing Enter and Enter does not close the window
    • Holding Shift + Up/Down now advances multiple steps at a time
    • Dragging the cursor inside the input but outside the text itself now works properly
  • Enabled NVENC on Arm64 [RytoEX] (#13827)

33.0 Changes

  • Added a check for encoders being missing when loading a profile [derrod] (#11340)
  • Added support for newest NVIDIA Broadcast SDKs for NVIDIA Audio Effects and Video Effects [pkviet] (#13838)
  • Added hotkeys for controlling audio monitoring of a source [Warchamp7] (#13599)
  • Fixed issues with groups in Studio Mode [Warchamp7] (#11092)
    • Fixed moving sources inside a group causing them to glitch out in Program
    • Fixed moving sources inside a group showing up live in Program
  • Adjusted naming of Window Capture methods on Windows [Penwy] (#12047)
  • Improved detection of fullscreen games for Game Capture [Kira-NT] (#10880)
  • Improved transparency handling for macOS Screen Capture [jcm93] (#13030)
  • Scaled simple output recording audio bitrate by channel count [nickvonkaenel] (#13311)
  • Removed support for Ubuntu 24.04

33.0 Bug Fixes

  • Added a startup error if obs-transitions failed to load [notr1ch] (#13321)
  • Improved file splitting for Hybrid MP4/MOV [derrod] (#13386)
  • Fixed outputs getting stuck running when a bad rescale output resolution is set [suogesi] (#13375)
  • Fixed monitoring icon state getting desynced when using third-party tools or websockets [prgmitchell] (#13822)
  • Fixed potential crash when shader cache file is invalid [notr1ch] (#13538)
  • Fixed a potential crash on Linux when USB mic is removed [R0te/RytoEX] (#13922)
  • Fixed a potential crash when renaming a source with the Add Source window open [Warchamp7] (#13800)
  • Fixed a potential deadlock during video/audio tasks [exeldro] (#13579)
  • Fixed an issue with B-frame offset calculation in AMF that could cause streams to disconnect [lexano-ivs] (#13762)
  • Fixed PipeWire screencast sources being duplicated in studio mode [tytan652] (#13673)
  • Fixed a potential crash when switching off a newly created profile [Warchamp7] (#13182)
  • Fixed a source toolbar crash when source type is missing [Penwy] (#13539)

33.0 Developer Information

  • Added frontend event and output signal for replay buffer saving [Penwy] (#8955)
  • Added guidance regarding the theme system to the top of all theme files [Warchamp7] (#13733)
  • Added ability to set a file extension filter for OBS_PATH_FILE_SAVE path types [FiniteSingularity] (#10190)
  • Added obs_frontend_is_safe_mode for first-party plugins
    • Third-party plugins are not loaded at all in Safe Mode
  • Added versions to Flatpak plugin extension point [tytan652] (#13735)
  • Updated libnsgif to 1.0.0 [RytoEX] (#11178)
    • This is a breaking change for any plugins using libobs/graphics gs_image_file
  • Clarified documentation for obs_module_unload [notr1ch] (#13327)
  • Required MbedTLS 3 and exclude 4 or later [tytan652] (#13799)
  • Fixed repeated preview enable/disables not working [WarmUpTill] (#12580)
  • Only emit core signal handlers for public canvases [tt2468] (#13574)
  • Deprecated unused hidden API for sources [derrod] (#13122)
  • Deprecated APIs for audio source monitoring_type [Warchamp7] (#13599)
    • This is replaced by a new monitoring_enabled boolean

Checksums

OBS-Studio-33.0.0-beta4-Sources.tar.gz: 71f33df72e454d53c0eb1e706441e2b24c475acc3ac259b8c071e9707ad10eb7
OBS-Studio-33.0.0-beta4-Ubuntu-26.04-x86_64-dbsym.ddeb: 9be1bbd516cb9b62be1adb381be44c026f197c9c206c90d06381d4eb6baf99d4
OBS-Studio-33.0.0-beta4-Ubuntu-26.04-x86_64.deb: 055db4d5cb1099b106d67645f84bc076ad1409836a0b603a35f393e1aa063a1d
OBS-Studio-33.0.0-beta4-Windows-arm64-PDBs.zip: a1e5095bd3b20bd3703cd2a2e97dc9735f5bb08513218d463edb1e9b88376d10
OBS-Studio-33.0.0-beta4-Windows-arm64.zip: c8bdbd9963e9bbdaf5e8ffaa7536ce6edd4ac583bec560fff69a5dee532ac111
OBS-Studio-33.0.0-beta4-Windows-x64-Installer.exe: 28323560c1585d51a290984777e980ef8788cd3210f150993ccbd9ee62484d8a
OBS-Studio-33.0.0-beta4-Windows-x64-PDBs.zip: 4825a54748ff65dde606537042df5b8eae634e89bb419eb93439907e97963268
OBS-Studio-33.0.0-beta4-Windows-x64.zip: 0a6d97ed2fb4d4c4cd3669eeaf063365e89ce72b602dc101659fc135f047359e
OBS-Studio-33.0.0-beta4-macOS-Apple-dSYMs.tar.xz: 58c55f934334a51e49b26baa627da34ee60909fbc74dc1c10e8f2469b6156c92
OBS-Studio-33.0.0-beta4-macOS-Apple.dmg: ecaba68924c83e96a300ba58412da04f0f469f331f88c10e7a74c6117e6e41f3
OBS-Studio-33.0.0-beta4-macOS-Intel-dSYMs.tar.xz: cadfe8423ba34900543a68b8a394c74efce632395260386c85c3d0ba6fb969cb
OBS-Studio-33.0.0-beta4-macOS-Intel.dmg: 47461ba641b88375da22f1fd74f476277ca5156fbbf54e0536b5f0eae487e2d5

  •  

Counter-Strike 2 Update

25 September 2026 om 23:54
[p]\[ RUSH ][/p]
  • [p]Various gap fixes and clipping adjustments.[/p][/*]
[p][/p][p]\[ GAMEPLAY ][/p]
  • [p]Fixed some cases where loud reloads would persist while trying to stealth reload.[/p][/*]
[p][/p][p]\[ MISC ][/p]
  • [p]Added sv_clantags_enabled option so custom servers can disable clan tags.[/p][/*]
  • [p]The eggs of background players in main menu lobbies now rest in nests.[/p][/*]
  •  

Coaches & Road Trip: Mode Switch

Door: Alex
25 September 2026 om 17:00

Ready to hit the road? Today, we're taking a closer look at one of the new systems created for our upcoming Coaches DLC for Euro Truck Simulator 2 and Road Trip for American Truck Simulator; Mode Switch. This feature helps bring different types of gameplay together, allowing you to move between your trucking career and new adventures behind the wheel of a car or coach!

ETS2 & ATS are expanding beyond trucking, and with that comes the need to clearly separate the different careers and gameplay experiences available to players. This is why we have divided the game into different modes, Truck Mode, Car Mode and Coach Mode.

Each mode has its own gameplay, progression, and career systems. Truck Mode remains centred around transporting cargo and building your trucking business, while Car Mode, introduced with Road Trip, places a greater emphasis on exploration and building your reputation with customers. Coach Mode will focus on operating routes, providing passengers with a smooth journey, and keeping them satisfied along the way.

Progression is separate between these careers, with Car Mode using reputation rather than traditional experience points. However, some important parts of your profile remain shared. Your money and map exploration carry across all modes, meaning roads discovered while travelling by car will remain explored when you return to your truck, and vice versa.

Separating the experience into different modes also allows us to keep everything relevant to your current career together in one place, including your vehicles, progression, statistics, and other mode-specific information.

Switching between modes is straightforward. You can enter another mode while you're not driving to manage that career, although you cannot have more than one active job across all modes at the same time. The full switch between modes happens once you press the Drive button.

As of right now, the navigation system remains tied to the mode you last drove in, so you won’t be able to set or adjust a route for the newly selected mode. As soon as you hit the road, the correct navigation and gameplay systems for that mode will kick in. Looking ahead, we’re already looking at ways to make navigation between modes feel even smoother in future updates.Β 

Wonder where you last left off in your vehicle? The map will also show the positions of your other vehicle, as well as your current position when undertaking a Quick Job. When you mode switch, you'll continue from the location where you left your truck, coach, or car.

The introduction of multiple modes also played a part in our recent changes to the fatigue system. Fatigue Simulation is now separated into Rest State and Mandatory Breaks. Your Rest State represents how tired your character is and is shared across modes, while Mandatory Breaks represent legally required rest periods. Trucks and coaches are subject to Mandatory Breaks, while cars are not.

The introduction of different modes is an important part of expanding Euro Truck Simulator 2 and American Truck Simulator while keeping their various gameplay experiences connected. Each mode offers its own career and progression, while shared systems such as money and exploration help ensure everything still feels like part of the same world and profile.

We hope this gives you a better understanding of how Mode Switch works and some of the thought process behind the creation of the system. We're looking forward to getting you behind the wheel of some new vehicle types in Euro Truck Simulator 2 and American Truck Simulator!

Until next time, keep an eye on our blog and social media for all the latest news, and we’ll see you on the road!

  •  

Release 2026.09.25

25 September 2026 om 09:03

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.25

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.25

⚠️ Action needed for bookmarklet users

MeTube now refuses requests sent from other websites unless their origin is listed in CORS_ALLOWED_ORIGINS. This closes a security hole (GHSA-cxj8-27g9-669f). If you use a bookmarklet, add the sites you use it on, e.g. CORS_ALLOWED_ORIGINS=https://www.youtube.com. Details in #1085.

Changes

  • docs: point readers at the wiki from the README top and the issue forms (dfe3daa)
  • fix: let a refused bookmarklet see why it was refused (e165b36)
  • test: pin that scheme-less internal URLs are refused before any fetch (2979e3a)
  • fix: refuse state-changing requests and socket connections from other sites (772a16c)

  •  
❌