Last 7 days
8
Features: 0
Changes: 0
Fixes: 8
Deprecations: 0
Omnichannel communications and secure team collaboration platform.
Latest Rocket.Chat changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Rocket.Chat release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
8
9
31
105
Bumped @rocket.chat/meteor version.
Added per‑client rate limiting to the unauthenticated `sendForgotPasswordEmail` method, aligning it with the REST `users.forgotPassword` endpoint.
Added per-client rate limiting to the unauthenticated sendForgotPasswordEmail method, matching the REST endpoint
Updated @rocket.chat/meteor and core/rest typings to version 8.4.6.
Updated @rocket.chat/meteor and core/rest typings dependencies.
Added per‑client rate limiting to the unauthenticated sendForgotPasswordEmail method and replaced http with serverFetch in downloadPublicImportFile to mitigate SSRF, delivering a security hotfix.
Added per‑client rate limiting to unauthenticated `sendForgotPasswordEmail` method and switched to `serverFetch` for SSRF protection
Updated @rocket.chat/meteor and core typings dependencies
Enhanced OAuth security with a fully server‑side flow, built‑in CSRF/state/PKCE protection, mandatory 2FA for provider logins and a toggleable modern flow setting.
Updated @rocket.chat/meteor and numerous internal dependencies
Updated @rocket.chat/meteor and core dependencies to latest versions.
Updated dependencies and bumped @rocket.chat/meteor version.
Bumped @rocket.chat/meteor version and updated numerous @rocket.chat dependencies.
Bumped @rocket.chat/meteor version and updated a wide range of internal dependencies.
Updated @rocket.chat/meteor and related dependencies
Updated @rocket.chat/meteor package and core dependencies.
Bumped the @rocket.chat/meteor dependency to the latest version.
Added Virtru as an external attribute store for ABAC, introduced a unified presence sync engine, and a new rooms.join API to join any room type
Bumped @rocket.chat/meteor version.
Bumped @rocket.chat/meteor version and updated related dependencies.
Updated @rocket.chat/meteor and core/rest typings dependencies
Bumped the @rocket.chat/meteor version and updated numerous internal dependencies.
Bumped @rocket.chat/meteor and updated core/rest typings to version 8.3.6.
Bumped @rocket.chat/meteor version and updated numerous internal dependencies.
Bumped @rocket.chat/meteor and updated numerous internal dependencies.
Updated Meteor package and numerous internal dependencies
Tightened security across authentication and data handling: OAuth tokens revoked on user deactivation, visitor tokens removed from livechat info, image URLs sanitized, and stricter validation for SAML, OAuth scopes, and file uploads.
Updated @rocket.chat/meteor and related typings to version 8.3.5
Updated @rocket.chat/meteor to the latest version
Bump @rocket.chat/meteor package to latest version
Clean up OAuth and login tokens after user deactivation, remove visitor tokens from API responses, and enforce access checks on translation endpoints
Clean up OAuth and login tokens on user deactivation and ensure related endpoints validate access
Clean up OAuth and login tokens after user deactivation, including deactivateidle, to improve security.
Clean up OAuth and login tokens for deactivated users and idle sessions
Clean up OAuth and login tokens for deactivated users; remove visitor token from visitor info responses.
OAuth and login tokens are now cleaned up when users are deactivated (including users.deactivateidle and OAuth cleanup).
Clean up OAuth and login tokens for deactivated users and hide visitor tokens in responses
Bumped @rocket.chat/meteor version and updated many internal dependencies.
Updated @rocket.chat/meteor and dozens of internal dependencies to latest versions
Bumped @rocket.chat/meteor to the latest version.
Bumped @rocket.chat/meteor version and updated numerous internal dependencies
Bumped @rocket.chat/meteor to the latest version.
Updated @rocket.chat/meteor to the latest version.
Bumped @rocket.chat/meteor to latest version
Enhanced security with SAML logout validation, sensitive data redaction in logs, and a fix to RBAC that prevented broader access to app log endpoints.
Bumped @rocket.chat/meteor to the latest version.
Bumped @rocket.chat/meteor to the latest version
Bumped @rocket.chat/meteor version and updated a wide range of Rocket.Chat packages.
Bumped @rocket.chat/meteor to the latest version as part of the patch release.
Bumped @rocket.chat/meteor to the latest version.
Bumped @rocket.chat/meteor to the latest version.
Bumped the @rocket.chat/meteor package version (patch update).
Updated @rocket.chat/meteor to the latest version and applied a security hotfix.
Upgrade @rocket.chat/meteor to the latest version.
Critical security patches: GitHub OAuth now reliably fetches user email, a token query‑parameter bypass vulnerability is fixed, federation domain allow‑list enforcement corrected, and a security hotfix released.
Applied security hotfix and bumped @rocket.chat/meteor version
Security hotfix applied (refer to docs)
Applied security hotfix and upgraded @rocket.chat/meteor version.
Applied a security hotfix to address vulnerabilities
Applied a security hotfix and updated the @rocket.chat/meteor package version.
Apply security hotfix fixing SSRF validation for OAuth endpoints
Security hotfix applied to address vulnerabilities
Bumped @rocket.chat/meteor to the latest version
Bumped the @rocket.chat/meteor package to the latest version.
Updated @rocket.chat/meteor package to the latest version
Fixed integration save error caused by missing Babel dependencies in the Docker container.
Fixed integration saving error caused by missing Babel dependencies in the Docker container.
Implemented configurable SSRF validation with internal IP/DNS rebinding protection, workspace allowlist, and tighter federation email‑domain checks; added 2FA/account‑status enforcement for enterprise DDP login and other security hardeni...
Bumped @rocket.chat/meteor to the latest version
Enabled a default strong password policy for new installations, with admin‑customizable settings (security).
Bumped @rocket.chat/meteor and updated core and related @rocket.chat packages to latest 7.8.6/0.x releases.
Upgrade @rocket.chat/meteor to the latest version.
Bumped @rocket.chat/meteor version
Bumped @rocket.chat/meteor version to align with latest releases
Bumped @rocket.chat/meteor version to the latest release.
Bumped @rocket.chat/meteor version.
Bumped the @rocket.chat/meteor dependency to the latest version.
Major breaking release: drops MongoDB 5/6 support, removes dozens of deprecated services, APIs, and integrations (e.g., Streamhub, FreeSwitch, second‑layer encryption) and mandates MongoDB 8.2 with full backup.
Updated engine versions and bumped @rocket.chat/meteor, along with many package dependencies.
Bumped @rocket.chat/meteor version.
Updated @rocket.chat/meteor package and refreshed numerous internal dependencies.
Updated the @rocket.chat/meteor package version
Updated the @rocket.chat/meteor package version
Bumped the @rocket.chat/meteor package and refreshed many core dependencies.
Bump @rocket.chat/meteor package to the latest version
Introduced foundational ABAC infrastructure for admin-managed room attributes and a unified v2 encryption model with stronger password policies and authenticated encryption for new data.
Updated @rocket.chat/meteor and numerous related packages to newer versions
Updated @rocket.chat/meteor package version
Bumped @rocket.chat/meteor version
Bumped @rocket.chat/meteor to the latest version.
Fixed lead capture to correctly store email or phone when the visitor had no prior data.
Updated @rocket.chat/meteor and numerous related packages to newer versions
Updated @rocket.chat/meteor and a range of package dependencies.
Added a new RangeSettingInput component, an experimental Apps Engine API for retrieving a user’s room list, and a preview mode for the message composer.
Updated @rocket.chat/meteor and related UI dependencies to newer versions
Introduced Alpha Native Federation, new Voice call architecture with permission prompts, and Omnichannel Outbound Messages for proactive outreach.
Bumped the @rocket.chat/meteor package version.
Bump @rocket.chat/meteor to the latest version
Fixed iframe authentication login issue and applied a security hotfix.
Updated @rocket.chat/meteor package and numerous internal dependencies
Bumped @rocket.chat/meteor to the latest version
Bumped @rocket.chat/meteor package version.
Bumped the @rocket.chat/meteor version.
Bumped @rocket.chat/meteor and refreshed numerous internal dependencies to their latest versions.
Introduced new @rocket.chat/desktop API package, expanded OpenAPI 3.0 coverage for numerous endpoints, and added Omnichannel microservice features like outbound messaging and default agent queue.
Bumped @rocket.chat/meteor version
Fixed /api/v1/users.update to merge customFields instead of overwriting, preserving existing values.
Bumped the @rocket.chat/meteor package to the latest version.
Fixed /api/v1/users.update to merge customFields rather than replace the entire object, preserving existing fields.
Bumped the @rocket.chat/meteor package version.
Bump @rocket.chat/meteor to the latest version.
Fixed issue where rooms transferred to a department queue could become stuck marked as taken with no assigned agent.
- Apps Engine now provides searchable, filterable, paginated logs with export options and a new multi‑instance status API/UI for better troubleshooting.
Fixed SLA policy bug where an inquiry disappeared after its SLA was updated
Fixed SLA policy issue where inquiries disappeared after SLA update.
Updated @rocket.chat/meteor version and many internal packages
Bump @rocket.chat/meteor to the latest version
Fixed v1/updateOwnBasicInfo to trigger the user stream and resolved race‑condition issues affecting subscription updates
Fix v1/updateOwnBasicInfo not triggering user stream
Livechat widget now auto‑assigns the first available agent when no department/default agent is set and adds an option to hide the “Expand chat” button via the setTheme API
Upgrade Node to 22.13.1 and add support for MongoDB 5.0/6.0/7.0
Bumped @rocket.chat/meteor to the latest version
Bumped @rocket.chat/meteor to the latest version.
Updated @rocket.chat/meteor version and many core packages to 7.6.4 releases
Bumped the @rocket.chat/meteor version.
Bumped the @rocket.chat/meteor version to the latest release
Fixed DDP streamer crash when presence service communication is interrupted
Fix issue that prevented saving an agent when editing a department
Updated @rocket.chat/meteor to the latest version
- Fixed a permission bug where incoming webhooks could post to public channels in private teams by non‑members.
Update @rocket.chat/meteor and many related dependencies to their latest versions.
Updated @rocket.chat/meteor and numerous package dependencies.
Updated @rocket.chat/meteor and numerous internal packages to the latest versions
Upgrade @rocket.chat/meteor to the latest version
Added draggable VoIP call widget for repositioning during calls (feature).
Bumped the @rocket.chat/meteor package version.
Bumped @rocket.chat/meteor version to the latest release
Added LDAP sync support for federated users, comprehensive audit‑log events, and custom LDAP variable manipulation.
Updated @rocket.chat/meteor and many related package dependencies
Bumped @rocket.chat/meteor version in the Apps Engine.
Added Outlook Calendar presence sync, OpenAPI support, audit.settings endpoint, new Apps Engine hook, Unit field for departments, Unicode avatar support and replaced rc scrollbars with overlayscrollbars for RTL accessibility.
Fix videoconference call ringing issue after a temporary disconnection.
Fixed intermittent video conference call ringing failures after temporary disconnections.
Added rooms.hide endpoint, multi‑department/unit filtering on livechat/rooms, and a setting to exclude bot messages from average response time metrics.
Upgrade @rocket.chat/meteor package to latest version
Bumped the @rocket.chat/meteor package.
Bumped the @rocket.chat/meteor package version.
Updated @rocket.chat/meteor and a wide range of package dependencies
Updated @rocket.chat/meteor and a wide set of package dependencies to their latest versions.
Bumped the @rocket.chat/meteor package to the latest version.
Bumped the @rocket.chat/meteor package version.
Updated @rocket.chat/meteor and related dependencies
Bumped the @rocket.chat/meteor package version.
Bump @rocket.chat/meteor to the latest version
Bumped @rocket.chat/meteor version.
Updated @rocket.chat/meteor and related dependencies;
Updated @rocket.chat/meteor to the latest version.
Bumped the @rocket.chat/meteor package version
Bumped @rocket.chat/meteor and updated numerous package dependencies.
Added MAC calculation using Contact entity, VOIP call statistics, role‑based room member display, and new Livechat department forwarding controls.
Bumped @rocket.chat/meteor to the latest version.
Improved engine subprocess handling by fixing retry logic, restart routines, and communication reestablishment with subprocesses.
Bump @rocket.chat/meteor and update dozens of related package dependencies.
Bumped @rocket.chat/meteor version and refreshed a wide set of internal dependencies.
Added a contacts.checkExistence endpoint for verifying existing contacts and new call event storage with detailed contact‑identification statistics.
Fixed engine not retrying subprocess restart after failure and improved communication re‑establishment with subprocesses.
Bumped the @rocket.chat/meteor package version.
Bumped the @rocket.chat/meteor package version
Bumped @rocket.chat/meteor to the latest version.
Removed restrictive validation for E2EE room key propagation, allowing non‑creator contexts to generate keys
Upgrade @rocket.chat/meteor to the latest version.
Bumped @rocket.chat/meteor to the latest version
Bumped the @rocket.chat/meteor package version.
Introduces the Single Contact ID add‑on to unify contact identities across email, chat and social channels, enabling communication with verified contacts only.
Bumped @rocket.chat/meteor to the latest version
Update @rocket.chat/meteor to latest patch version
Bumped @rocket.chat/meteor to the latest version
Bumped @rocket.chat/meteor package version.
Added enterprise add‑ons (RC AI, VoIP for Team Collaboration beta, WhatsApp 360 Dialog) and expanded the Starter plan to 50 users; private app uploads and air‑gapped mode are now limited to premium plans.
Fix visitor creation failure when GDPR is enabled and guest is created via Apps Engine or deprecated livechat:registerGuest method
Added mentions support in end‑to‑end encrypted rooms and a setting to disable email two‑factor authentication for OAuth users.
Allow using the room.v token for transcript requests, fixing token mismatch issues.