Changelog

v2.29.0

GitHub ↗

Features

  • web: cloud sign-up and onboarding layout: #1832

Bug Fixes

  • deps: migrate Sentry SDKs together to v11 (#1826): #1826
  • ci: grant nightly reusable CI scan permission: 0216067
  • board: allow column moves while sorting by task number: #1816

Documentation

  • update contributors and sponsors: c200d70
  • rebuild guides around current Kaneo workflows: #1814

Credits

Huge thanks to @tinsever and @andrejsshell for helping!

v2.28.0

GitHub ↗

Features

  • gitlab integration: #1727
  • tasks: show subtask progress on cards and list rows: #1703
  • added project backgrounds: #1654
  • multiselect for customfield: #1735
  • ci: discord actions webhook: #1792
  • ci: adding zizmor: #1790
  • project: move a project to another workspace: #1525
  • duplicate a task from the card context menu: #1609
  • allow manual external resource links: #1661
  • ci: trufflehog implementation: #1787
  • task: let images be resized in the task description: #1529
  • web: add a change-password screen under account settings: #1719
  • auth: add password recovery from the login screen: #1773
  • add instance user administration panel: #1400
  • calendar: add label-filtered project calendar feeds: #1763

Bug Fixes

  • security: close permission and integration gaps: #1802
  • project: secure integrations across workspace moves: #1801
  • editor: preserve formatting when pasting Markdown: #1797
  • auth: report invitation email delivery failures: #1798
  • gitea: verify saved repository connections: #1796
  • mcp: keep OAuth requests valid outside UTC: #1795
  • i18n: translate calendar in remaining locales: 1d61ceb
  • ci: zizmor findings: #1791
  • integrations: resolve PRs through linked issue identities: #1739
  • auth: prevent repeated 401s for pending invitations after session expiry: #1715
  • auth: gate sign-in emails to deliverable addresses: #1758
  • web: preserve image uploads across editor recreation: #1738
  • reminders: calculate deadlines from the end of the due day: #1762
  • mcp: support whoami with API keys: #1748
  • web: respect DISABLE_WORKSPACE_CREATION on the onboarding screen: #1744
  • backlog: prevent task remounts during list interactions: #1734
  • auth: prevent role changes from removing the last admin: #1733
  • npm: fixing GHSA-2xp9-vwfh-vxw4: #1777
  • web: guard tiptap setHardBreak against invalid-content schema error: be3ffb5
  • i18n: prevent locale module crash on stale dynamic import: #1775
  • site: improve search metadata and product discovery: 121183e

Performance Improvements

  • project: stop returning tasks with project details: #1800

Documentation

  • update contributors and sponsors: fa07f10
  • site: add Blacksmith partner badge to site and README: 08a93b8
  • update contributors and sponsors: 8432a45

Credits

Huge thanks to @tinsever, @zaralX, @TymekV, @MonsPropre, @randoneering, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!

v2.27.0

GitHub ↗

Features

  • site: bring product preview up to date with current app: dd855f7
  • site: refresh marketing site and interactive product previews: 90aec99

Bug Fixes

  • web: allow non-root runtime configuration writes: #1767
  • site: poof away preview cursor on interaction: 08dcaee
  • nginx: allow larger OAuth session headers: #1761
  • deps: resolve open dependabot advisories: b8432a0
  • web: preserve comment markdown spacing: #1521

Documentation

  • site: refresh press kit with product screenshots: 3470b0a
  • update blog comparisons for current Kaneo features: b97bf7d

Credits

Huge thanks to @tinsever for helping!

v2.26.0

GitHub ↗

Security release: upgrade as soon as you can

This release closes a broad set of security issues across authorization, integrations, notifications, realtime delivery and deployment defaults. Self-hosted instances on 2.25.0 and earlier are affected. Advisories with full details will be published shortly.

Read the breaking changes below before upgrading. Some of them stop the API from starting or change how it is reached.

BREAKING CHANGES

  • AUTH_SECRET is now required. It previously fell back to an empty value, which Better Auth replaced with a publicly known default secret, making every session cookie forgeable offline. The API now refuses to start without a secret of at least 32 characters. The Docker entrypoint still generates one when unset, so Compose and the published images keep working; deployments that bypass the entrypoint must set it. Generate one with openssl rand -hex 32.
  • project:share is now enforced. Holding project:update no longer lets a user publish or unpublish a project. Grant project:share to any role that should manage project visibility.
  • API and web must be upgraded together. Task lists are now bounded and paginated. Custom clients must follow pagination.totalPages, follow relatedPage through pagination.relatedTotalPages, and treat a deferred description as "not loaded" rather than empty.
  • TRUSTED_PROXIES now defaults to loopback only. Set it to your actual immediate proxy addresses or CIDRs, or client IPs will be attributed to the proxy.
  • Compose no longer publishes PostgreSQL on the host. Port 5432 is no longer bound to all interfaces. Connect over the Docker network instead.
  • GitHub integrations need reverifying. Bindings without a verified numeric repository and installation stop syncing until a repository admin reconnects them.
  • WebSocket clients must send an Origin or explicit credentials. Cookie-only native clients are now rejected.
  • SMTP_IGNORE_TLS=true is no longer supported. It disabled STARTTLS rather than certificate validation. Trust your SMTP CA with NODE_EXTRA_CA_CERTS, or for an intentionally unencrypted local relay set SMTP_SECURE=false and SMTP_REQUIRE_TLS=false explicitly.
  • The Helm chart now requires kaneo.env.clientUrl. It must be the public HTTP(S) origin, with no credentials, path, query or fragment. AUTH_SECRET is now read from a Secret; prefer kaneo.env.existingSecret so it is not retained in your values.

Before you upgrade

Back up PostgreSQL and verify the restore. Migrations 0046 through 0050 run on start; 0047 deletes API keys that have no owner, so reissue any key that stops working rather than restoring it. Rotate AUTH_SECRET if it was previously readable in Helm values or a Deployment manifest.


Features

  • add maintainer-triggered Peekareview code reviews: 65bb146
  • peekareq: add budgeted private code-review evaluation: a8151a8

Bug Fixes

  • require AUTH_SECRET and gate project visibility changes: 156b72b
  • enforce security boundaries and bound integration workloads: 71bd198
  • handle review relay redirects and explicit reruns: a6ea057
  • web: use HttpError across fetchers: #1751
  • web: prevent 404 on activity query when taskId is undefined: #1750

Reverts

  • remove Peekareq code-review experiment: 4169b98

Documentation

  • update contributors and sponsors: 0982593
  • update contributors and sponsors: f94a27e

Credits

Huge thanks to @randoneering for helping!

v2.25.0

GitHub ↗

Features

  • add focused Peekareq previews and accessibility findings: 6e01c0f
  • ci: add maintainer-triggered Peekareq screenshots: 2d8a4c6

Bug Fixes

  • billing: keep cancelled subscriptions entitled until the paid period ends: #1741
  • fall back when Peekareq's model provider is throttled: 145c13a
  • ground Peekareq custom-field screenshots in fixtures: 4b684e7
  • ci: use Cloudflare-compatible GitHub requests: 9740bf8
  • ci: filter Peekareq commands with a Cloudflare webhook: 34ee59e

Documentation

  • update contributors and sponsors: 508bd4b
  • update contributors and sponsors: a750d01
  • update contributors and sponsors: 16fcd5f
  • update contributors and sponsors: 93cb471

Credits

Huge thanks to @andrejsshell for helping!

v2.24.0

GitHub ↗

Features

  • custom fields configuration: #1542
  • redirect to default project: #1640
  • i18n: add Azerbaijani (az-AZ) translation: #1704

Bug Fixes

  • web: defer Shiki highlighter loading on task page: #1713
  • i18n: restore Simplified Chinese translations for Mattermost integration: #1701
  • i18n: sync Mattermost keys across locales: #1710
  • npm: fixing CVE-2026-75604: #1709
  • api: skip archived tasks in due date reminders: #1702

Documentation

  • update contributors and sponsors: d7f1c46
  • update contributors and sponsors: 243f9d8
  • update contributors and sponsors: 41b72df

Credits

Huge thanks to @MonsPropre, @ApplesBear-X, @randoneering, @jamalkamaladdin, and @mmilanovic4 for helping!

Keyboard shortcuts

Anywhere

Go to requests
gh
Go to changelog
gc
Go to notifications
gn
Next or previous page
norp
Leave a text field or close a menu
Esc
Show this list
?

Requests

Move to the next or previous request
jork
Open the selected request
oorEnter
Vote on the selected request
v
Search
/
New request
c

Request

Vote
v
Write a comment
c
Edit
e