Legacy releases
Archived hMailServer builds, from 4.1.1 to 5.6.9 build 2607. These versions are no longer supported and are kept for reference only. Use the latest release for new installations.
Archived hMailServer builds, from 4.1.1 to 5.6.9 build 2607. These versions are no longer supported and are kept for reference only. Use the latest release for new installations.
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.09.28GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.09.28
Thank you to 5 community contributors:
Note
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Full Changelog: v2.19.0...v2.19.1
Note
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
php bin/console partdb:attachments:download-footprint-imagesFull Changelog: v2.18.0...v2.19.0
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.09.27GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.09.27
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
TLSA records are looked up for every MX host, including hosts whose zone is not DNSSEC signed.PushSubscription created within the verification rate limit window of another one on the same account never receives its PushVerification, since the blocked verification is dropped instead of being sent once the window expires.aud claim is derived from a hand-written parse of the push URL, so a crafted push URL can make the server sign a token for a push service other than the one the request is sent to.Email/import rejects a blobId that refers to a Blob/upload creation id in the same request ("#u0") with Invalid blob id..Email/set with a full mailboxIds object identical to the current mailboxes, together with a keyword change, stores the message with IMAP UID 0, so IMAP clients stop seeing it.outboundMta role stops replying to DATA and to JMAP submissions once about 1024 messages have been queued on it.DATA stage Sieve script does not see headers added by milters or MTA hooks, and discards every milter and MTA hook change when it edits the message.DELETE and switch to chunks only after a timeout.COPY and MOVE fail with NO [CONTACTADMIN] when another session changes the same message at the same time.<Encryption>TLS</Encryption>, which Outlook reads as STARTTLS.
This year, we were once again invited by Western Star to take part in their Star Nation Experience along with two members from our American Truck Simulator community. Today, we bring you an SCS On The Road episode where you can watch what the whole amazing event looked like!
Beny and Oscar travelled all the way to Bend, Oregon, to represent SCS at the wonderful Star Nation Experience 2026 in June. There, they met up with two members of our ATS community, Conor and Nathan, who were selected and invited by Western Star for an all-expenses-paid trip and a weekend packed with unforgettable experiences.
From fly fishing and ATV rides to the X-Series Ride & Drive Challenge at the Madras Proving Grounds, they also got to meet the Western Star team and other trucking enthusiasts. So, let's watch together and see how the Star Nation Experience 2026 went!
We would like to say a huge thank you to Western Star for inviting us once again, along with Nathan and Conor, and for giving us the opportunity to take part in such an amazing event. We are also happy that we could capture the experience and share it with our community!
Make sure to follow us on X/Twitter, Facebook, BlueSky, YouTube, and InstagramΒ so you don't miss out on any events, news, and fresh SCS On The Road episodes. Alternatively, you canΒ subscribe to our newsletterΒ to stay informed. Until next time, happy hauling!
Full Changelog: v0.8.8...v0.8.9
1.11.2 fixes the Docker image and the standalone tarballs of 1.11.1, which did not start. It contains all the security fixes from 1.11.1, so please update.
Thank you for your donations:
One-time
Monthly
data/ from the standalone build with a pattern that also dropped Next.js's own metadata modules, so the Docker image and the bulwark-standalone-* tarballs failed on startup. npm start and Bulwark Lite were not affected
1.11.1 is a security and bug-fix release. It fixes four reported vulnerabilities, two of them critical, and the findings of a security audit. Please update.
Thank you for your donations:
One-time
Monthly
/api/ route, not only /api/auth/*. A page on a same-site sibling origin could run arbitrary JMAP as the signed-in user. The gate also decides on the decoded path, so /api/%61uth/... no longer skips it (GHSA-9mvj-98f5-9q6g, thanks @kah-ja)X-Forwarded-For got a fresh per-IP budget when no reverse proxy is in front (GHSA-7pj2-232x-6698, thanks @richardweinberger)Authentication-Results header of their own.eml attachment preview, the quoted original of a reply or forward, the print view, and for URL spellings the filter missed (backslashes, CSS escapes, image-set())<area>) no longer keep window.openermailto: unsubscribe goes to the single address in the link, and the confirmation shows recipient, subject and body before sendingwinmail.dat no longer freezes the tabredirect to the Sieve scripthttp.post can no longer reach the JMAP passthrough, /api/admin/*, /api/settings or other credentialed routes, and plugin storage is kept per account and deleted on sign-outurl(//host), CSS escapes, image-set(), @font-face sources), and theme CSS can only target :root and .dark, also when a plugin transforms ittext/html cannot run script in the webmail origin127.0.0.1, CGNAT, benchmark, multicast and reserved ranges, and NAT64, 6to4 and Teredo addresses that wrap an internal IPv4 address. Telemetry targets are checked at connect time, and OAuth token and revocation requests never follow redirectsjohn@b.example can no longer read the settings of john@a.exampleALLOWED_FRAME_ANCESTORS never applies to the admin dashboard or setup, and sibling subdomains can no longer widen the sidebar-app frame-srcdata/, local-data/, .env) stay out of the standalone build and the image, and the mock JMAP server can no longer be switched on in a release buildsessionStorage.sha256 instead of releases/latestemail:send, and display takeovers need email:render-takeover. Plugins that don't declare them lose those hooks:root and .dark rules plus @font-face, @keyframes, @media and @supports. Every url() except a #fragment is removed/api/health?detailed=true needs a session
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.09.26GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.09.26
P.S.: If you enjoy Dopamine, please consider donating via PayPal or buying me a coffee. Your support keeps the music going!
release: v2.0.18
OBS-Studio-33.0.0-beta4-Sources.tar.gz: 71f33df72e454d53c0eb1e706441e2b24c475acc3ac259b8c071e9707ad10eb7
OBS-Studio-33.0.0-beta4-Ubuntu-26.04-x86_64-dbsym.ddeb: 9be1bbd516cb9b62be1adb381be44c026f197c9c206c90d06381d4eb6baf99d4
OBS-Studio-33.0.0-beta4-Ubuntu-26.04-x86_64.deb: 055db4d5cb1099b106d67645f84bc076ad1409836a0b603a35f393e1aa063a1d
OBS-Studio-33.0.0-beta4-Windows-arm64-PDBs.zip: a1e5095bd3b20bd3703cd2a2e97dc9735f5bb08513218d463edb1e9b88376d10
OBS-Studio-33.0.0-beta4-Windows-arm64.zip: c8bdbd9963e9bbdaf5e8ffaa7536ce6edd4ac583bec560fff69a5dee532ac111
OBS-Studio-33.0.0-beta4-Windows-x64-Installer.exe: 28323560c1585d51a290984777e980ef8788cd3210f150993ccbd9ee62484d8a
OBS-Studio-33.0.0-beta4-Windows-x64-PDBs.zip: 4825a54748ff65dde606537042df5b8eae634e89bb419eb93439907e97963268
OBS-Studio-33.0.0-beta4-Windows-x64.zip: 0a6d97ed2fb4d4c4cd3669eeaf063365e89ce72b602dc101659fc135f047359e
OBS-Studio-33.0.0-beta4-macOS-Apple-dSYMs.tar.xz: 58c55f934334a51e49b26baa627da34ee60909fbc74dc1c10e8f2469b6156c92
OBS-Studio-33.0.0-beta4-macOS-Apple.dmg: ecaba68924c83e96a300ba58412da04f0f469f331f88c10e7a74c6117e6e41f3
OBS-Studio-33.0.0-beta4-macOS-Intel-dSYMs.tar.xz: cadfe8423ba34900543a68b8a394c74efce632395260386c85c3d0ba6fb969cb
OBS-Studio-33.0.0-beta4-macOS-Intel.dmg: 47461ba641b88375da22f1fd74f476277ca5156fbbf54e0536b5f0eae487e2d5
release: v2.0.17
Ready to hit the road? Today, we're taking a closer look at one of the new systems created for our upcoming Coaches DLC for Euro Truck Simulator 2 and Road Trip for American Truck Simulator; Mode Switch. This feature helps bring different types of gameplay together, allowing you to move between your trucking career and new adventures behind the wheel of a car or coach!
ETS2 & ATS are expanding beyond trucking, and with that comes the need to clearly separate the different careers and gameplay experiences available to players. This is why we have divided the game into different modes, Truck Mode, Car Mode and Coach Mode.
Each mode has its own gameplay, progression, and career systems. Truck Mode remains centred around transporting cargo and building your trucking business, while Car Mode, introduced with Road Trip, places a greater emphasis on exploration and building your reputation with customers. Coach Mode will focus on operating routes, providing passengers with a smooth journey, and keeping them satisfied along the way.
Progression is separate between these careers, with Car Mode using reputation rather than traditional experience points. However, some important parts of your profile remain shared. Your money and map exploration carry across all modes, meaning roads discovered while travelling by car will remain explored when you return to your truck, and vice versa.
Separating the experience into different modes also allows us to keep everything relevant to your current career together in one place, including your vehicles, progression, statistics, and other mode-specific information.
Switching between modes is straightforward. You can enter another mode while you're not driving to manage that career, although you cannot have more than one active job across all modes at the same time. The full switch between modes happens once you press the Drive button.
As of right now, the navigation system remains tied to the mode you last drove in, so you wonβt be able to set or adjust a route for the newly selected mode. As soon as you hit the road, the correct navigation and gameplay systems for that mode will kick in. Looking ahead, weβre already looking at ways to make navigation between modes feel even smoother in future updates.Β
Wonder where you last left off in your vehicle? The map will also show the positions of your other vehicle, as well as your current position when undertaking a Quick Job. When you mode switch, you'll continue from the location where you left your truck, coach, or car.
The introduction of multiple modes also played a part in our recent changes to the fatigue system. Fatigue Simulation is now separated into Rest State and Mandatory Breaks. Your Rest State represents how tired your character is and is shared across modes, while Mandatory Breaks represent legally required rest periods. Trucks and coaches are subject to Mandatory Breaks, while cars are not.
The introduction of different modes is an important part of expanding Euro Truck Simulator 2 and American Truck Simulator while keeping their various gameplay experiences connected. Each mode offers its own career and progression, while shared systems such as money and exploration help ensure everything still feels like part of the same world and profile.
We hope this gives you a better understanding of how Mode Switch works and some of the thought process behind the creation of the system. We're looking forward to getting you behind the wheel of some new vehicle types in Euro Truck Simulator 2 and American Truck Simulator!
Docker images have been built and pushed:
Docker Hub:
alexta69/metube:latestalexta69/metube:2026.09.25GitHub Container Registry:
ghcr.io/alexta69/metube:latestghcr.io/alexta69/metube:2026.09.25MeTube now refuses requests sent from other websites unless their origin is listed in CORS_ALLOWED_ORIGINS. This closes a security hole (GHSA-cxj8-27g9-669f). If you use a bookmarklet, add the sites you use it on, e.g. CORS_ALLOWED_ORIGINS=https://www.youtube.com. Details in #1085.
Full Changelog: v0.8.7...v0.8.8