Last 7 days
1
Features: 0
Changes: 0
Fixes: 1
Deprecations: 0
Headless CMS and managed cloud platform for APIs and structured content.
Latest Strapi changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Strapi release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
1
4
14
63
Fix admin permission checks that incorrectly blocked page access
Introduced a new feature to record MCP actions in audit logs and added Corsican locale support.
Add optional component screenshots to the Dynamic Zone picker and enable required flag on relation attributes in the content type builder, expanding content manager capabilities.
- Fixed AI localization field length constraints and sorting issues, preserving sort order on view changes
Introduce data transfer CLI filters (exclude/only content types) and add Abkhazian and Circassian locale codes.
Admin auth cookie name is now configurable via admin.auth.cookie.name, allowing custom token cookie names.
Added complete Japanese i18n support and updated other translation files.
Added active devices session management in Admin, introduced security defaults for CLI app templates, and hardened JWT verification to HS256.
Added MCP export builders (defineTool/defineResource/definePrompt) and an optional replace method for upload providers.
Added Billing Portal linking feature with optional OpenAPI spec route and a new paginated GET /api/upload/files/page endpoint for uploads.
Add optional OpenAPI spec route and gate endpoint access via config (new feature)
Fix critical relational filtering vulnerability (CVE‑2026‑27886) and upgrade tar to v7 for security hardening
Fixed deleteMany to respect relation filters and addressed several content manager crashes and validation issues.
Add BETA MCP server and new publicationFilter parameter for REST and document services
Fix FK violation when publishing self‑related parent/child entries and correct content manager context handling.
Added a close button to the trial banner with sticky behavior and updated design, plus preview support for images/videos and customizable content manager blocks.
Fix crash caused by single type switch
Added new plugin and admin API capabilities such as extended CTB API with publish‑status sorting, admin token admin‑permissions, dynamic rate‑limit prefix keys, and a new addMenuLink type for menu‑only links.
Added a new “Deploy to Cloud” homepage widget and extended document service with delete‑selection parameters and self‑referential relation handling
Added a new `strapi.ai` core namespace, CLI commands for listing/deleting admin users, and AWS S3 root‑level credential support with SDK update.
Fixed numerous typos in Russian, Polish, Finnish translations and documentation.
Remove unused A/B testing opt‑in from the CLI and hide legacy options.
Fix async loading issue in Inquirer
- Fixed validation and upload bugs, including remote uploads, attribute‑named filters errors, and empty MIME‑type handling.
Added a package manager dropdown before the version field in the bug report template (new feature).
New feature: accordion expands by default when inserting a new component and content manager can filter list view by publication status.
This release was superseded due to a versioning mistake; it should not be used.
Added `relationOpenMode` setting (modal/page/newTab) to the Content Manager and upgraded email integration to Nodemailer v8 with new UI capabilities.
Fixed core issue preserving component clone integrity during discard drafts migration.
Fixed mobile subnav and layout page issues, improving mobile UX and list view.
Fix undefined tours property and improve validation for number fields
Added persistent list view settings, new Strapi config types, extended AWS S3 provider support, and CLI non‑interactive mode for CI scripts.
Added a focal point picker to the image upload UI.
Added German translations, retroactive AI metadata generation for uploads, and external link rendering in menus.
Fixed async map awaiting in v5 release actions migration and corrected component structure handling for conditional fields.
Added token refresh logic for React Query and improved env helper typings
Patched a security vulnerability (details undisclosed pending upgrade)
Patched a security vulnerability (details undisclosed) – users should upgrade.
Fixed several UI and performance bugs (header height, subnav clipping, globe icon visibility, hidden fields validation, excessive rerenders, cloud request limit).
Added extensive i18n support: new ISO locale variants, Russian translations, and Luxembourgish locale.
Added a clear button to boolean toggles and introduced refresh/logout actions to default user permissions
Fix enter‑key trigger in edit view form
Reverts the recent drafts migration to undo changes
Added accessibility enhancements to the media library (ARIA selection and click handlers) and new locale-aware UI features such as per‑locale relations and improved combobox handling.
Add upload file type restriction feature
Add support for new icon components in the design system
Added new link attributes to Rich Text JSON blocks and a dynamic zone to the About schema (feature).
Backported database hash algorithm from MD5 to SHA‑256 for v4
Added a new upload feature that resolves ordering issues
Added homepage customization feature.
Added responsive navigation and AI-generated image metadata features.
Added AI Chat for schema creation
Fix unique index recreation bug.
Added new homepage API endpoints for widget move and resize actions
Security warning: patched a critical vulnerability; users urged to upgrade before disclosure.
Added Advanced Session Configuration feature for customizing session handling.
Added Advanced Session Configuration feature for the Admin Panel.
Fixed UID generation to use the singular name instead of the display name when creating UIDs
Fix: track only API requests to improve logging accuracy
Fix support for custom field attributes in schema mapping
Fixed component synchronization issue in draft and publish relations.
Fixed route serialization utility to correctly handle non‑array values.
Fixed missing userId in Amplitude events and corrected validation index issues when reordering dynamic zones
Added conditional fields form to Custom Fields advanced settings
Added new “last activity” homepage widget
Added new homepage widgets for key statistics and upcoming releases, plus a firstPublishedAt field for content timestamps.
Security vulnerability patched with delayed public disclosure to allow users to upgrade safely.
Upgraded koa to version 2.16.1, addressing security dependencies.
Added preview device selector and async project creation notifications to the cloud CLI.
Added a homepage widget entries chart.
Added a new homepage widget profile feature with associated UI updates
Added conditional fields feature to the content manager
Fixes search field not closing and resolves GraphQL draft/publish argument forwarding issue
Added regex attribute to UID fields and introduced a DidUpdateCTBSchema event for the content type builder.
Fixed repeatable components loading relations, corrected one‑to‑many relation version handling, and resolved default timezone release issue; also fixed several UI bugs in content manager and pagination tab switching
Added Growth Trial prompt to the CLI and enhanced core store getter typings, permission field validation, and document ID uniqueness checks
Revamped Content Type Builder with undo/redo, drag‑and‑drop attributes, collapsible sections, concurrent editing, and new shortcuts
Fixed model reference update in FormLayout for consistent localization
Added a stable Widgets API and a new “future branch create relations” feature for widgets.
Fixed bug where widget type was not exported from core.
Fix rich text editor focus mode modal behavior
Fix relation icons shape in the relation modal
Fixed form reset bug on publishing and resolved several flaky/unit test failures
Fixes incorrect path to codemods, resolving related errors.
Fixed relation menu link and ensured update responses include nested data when user permissions apply.
Fix broken SSO login introduced in v5.12.0
Added on‑the‑fly relation editing in modals with a preview side‑editor and a Chargebee seat‑management link for growth/EE users.
Upgraded axios to v1.8.2 to address CVE‑2025‑27152.
Fixed UI bugs including preview tab switching, purchase page UI, and webhook details page
Fixed bug in bidirectional relations synchronization.
Fixed error in Content Manager when deleting components from dynamic zones.
Fixed TypeScript failure caused by a missing mock function and disabled preview form when status changes
Introduced a preview feature that refreshes the iframe when Strapi updates
Introduced preview features for saving/publishing documents and added a review workflow injection zone.
Patched a security vulnerability (details withheld) and added email rate‑limit middleware for admin password resets.
Fixed duplicate dependency issue (commit 7896ed8da1).
Fix bugs introduced in 5.10.0.
Introduced a responsive blocks editor toolbar, made the markdown editor responsive, and prepared side‑editor layout with UI refinements
Added multiple Content Manager enhancements (getters for useDocument, container queries for form fields, bulk publish overview) and a new Plan label for the Growth plan.
Fixed deletion of orphan component data when schemas change.
Fixed i18n handling to allow unique and unlocalized fields on i18n content types
Fixed number field clearing to send null and added missing name to ColorPickerInput.
Fix logging data transfer functionality
Add content preview feature with syntax highlighting and back‑button handling.
Added a content preview feature and syntax highlighting for code blocks in the content manager.
Patched a security vulnerability (details undisclosed per policy).
Fix reverse proxy support and correct polymorphic relation encoding/index mapping.
Added Mux video player support and a new documentId field to the Me GraphQL query
Added preview allowed origins config and diagnostics for data transfer providers
Added new cloud CLI commands to link projects with environments and show warnings on deploy usage
Fixed core bugs: loading order, media population, database migration query ambiguity, and review workflow stage status handling.
Add native language names for Uzbek and Romanian in admin UI
Add environment flag to CLI deploy command; integrate review workflows with releases and enable iframe preview of content.
Fixed ordering when loading more than 10 relations and corrected several e2e test failures.
Fix API state not cleared on logout
Fixed Attribute.column type definition issue in strapi/types
Added DTS item count assertion and sorted generated schema definitions for better type safety.
Fixed empty component wording, ensured relation IDs are sent on updates, and made i18n locales private for non‑localized content types.
Fixed broken list view pagination.
Fixed sending IDs when connecting relations to update user & permission roles.
Introduce preview support: base files, config, and endpoint for static previews.
Fixed v5 migration issue caused by incorrect enum values.
Resolved multiple CVEs in project dependencies by updating affected packages
Added MariaDB support for unique indexes and introduced preview feature boilerplate
Upgrade build tooling (Vite, Webpack dev middleware, Yarn, tar) and update security documentation
Updated CLI to use a dynamic deployment URL and added Croatian language support for Admin & Upload plugins.
Introduced major V5 features: internal database migrations, Document Service, Draft & Publish V5, content history/versioning UI, CLI testing & upgrade tool overhaul, Vite as default admin bundler, fetch API for strapi.fetch, and mysql2 +...
Fixed marketplace UI to hide the install button for incompatible plugins.
Fix content releases to await release status update after createMany actions
Updated axios to 1.7.4, addressing a security vulnerability.
Added RBAC Action Aliases v4 to core admin.
Updated tooling to shard EE tests and aggregate test results for a single required status check.
Fix custom email provider test issue in core:email module.
Fixed CLI deploy command to avoid blocking the event loop.
Added a new `projects:list` command to the CLI
Updated glob dependency to 10.4.2 in core, addressing security concerns.
⚠️ Security: patched an undisclosed vulnerability and advise immediate upgrade.
Enhance core admin NPS by increasing its update frequency
Added new cloud CLI commands (v4) for managing Strapi services
Bumped @strapi/design-system dependency to version 1.19.0.
Fix validation in content type builder to correctly compare pluralName and collectionName
Fix admin core to replace useContext selector with React Context
Patched a critical security vulnerability (details withheld until users upgrade).
Fixed admin rendering issue in EE mode by waiting for EE routes to load before rendering.
Fixed issue #20138 as addressed in PR #20231
Fixed core bugs in admin EE export handling, content manager undefined content, and database join column name conflicts.
Added Local Search plugin to contributor documentation.
Updated core dependencies (vite, webpack dev middleware, sharp) and tooling scripts (Nx cache ignore, watch script).
Reverted the @koa/cors upgrade to version 5.0.0.
Patched a security vulnerability (details withheld) to protect users before public disclosure.
Added bulk actions renderer for content manager releases.
Added Keycloak native users permissions provider for the users‑permissions plugin.
Fixed min‑date selection limit for scheduling content releases and removed console errors when deleting releases.
Added support for models and content types in data transfer (DTS).
Fixed data transfer pull getting stuck/skipping the assets step.
Fix strange behavior when repositioning items in Dynamic Zones in the content manager.
Added a new purchase content releases page (feature)
Fixed numerous bugs across admin, content manager, content releases, data transfer, and database modules.
Patched a security vulnerability and advised immediate upgrade.
Added Content Releases feature, experimental `plugin:watch:link` CLI command, and Vite integration for the admin UI.
Fix content manager handling when creating entries derivatively.
• Fixed numerous UI and permission bugs in Content Releases and Content Manager (padding, refresh button, navigation, borders, permissions, memoization).
Fixed duplicated @strapi/strapi dependency in @strapi/data-transfer causing resolution errors.
Fixed a dependency error affecting data transfer
Fixed case‑sensitive email handling for SSO providers, deep query populate in dynamic zones, logger middleware ordering, and other helper/test issues.
Fix multiple admin UI issues including build errors, missing app.js checks, password input restoration, and Windows path handling
Fix peer dependency handling with strict constraints in core.
Fixed numerous admin UI bugs (toolbar padding, export/settings links, env utilities, webpack watch handling, Document import, JSX/TSX loader selection, typo in website link) and corrected upload signed URL caching and GraphQL repeatable ...
Fixed core data transfer bug by removing erroneous process.nexttick usage
Add the Strapi Cloud plugin to the CMS for marketing purposes
Introduced several new features: stable‑release badge for blocks, theme synchronization with system theme, new `plugin:watch` command, config‑driven plugin loading, and migrated many admin components to TypeScript.
Migrated core admin components, database, email, and utilities to TypeScript and introduced Redux Toolkit in the admin UI.
Fixed several bugs: typo causing missing action button in Content Manager, proper protocol selection in Data Transfer, custom HTTP timeout for connections, and corrected media file replacement in upload.
Fix relations input search not found in admin UI
Re-published v4.14.2 without code changes to resolve NPM publishing issues.
Implemented stage permissions for review workflows and introduced an alpha Blocks rich text editor in the admin UI.
Migrate core helper plugin and TypeScript project builds to full TypeScript support;
Added experimental `plugin:build` command to core Strapi
Fix admin core bug by adding a fallback for missing window.strapi.backendURL
Fix relative URL handling in upload module by correcting appendSearchParamsToUrl behavior
Fix Strapi import failure caused by corrupted asset metadata.
Fixed JSON parsing and bulk publish validation in the content manager, including layout sizing and UI adjustments
Breaking change: Content API now validates query parameters and returns errors for invalid ones.
Revert to v4.12.5 to address a high severity issue
Add Valencian locale support and reorganize enterprise/admin hooks with refactoring of admin app entries
Fixed numerous bugs in admin, content manager, and helper plugins (e.g., disabled noImplicitAny, ensured fresh data for list/edit views, corrected navigation and date field handling)
Fixed several UI and backend bugs, including bulk publish count, ListView cell formatter support, component view configuration saving, native fetch for file download, Media Library navigation, and TypeScript query types
Patched multiple security vulnerabilities with a delayed public disclosure.
Added support for multiple review workflows with new RBAC permissions and expanded bulk‑publish UI and behavior
Fixed multiple admin and content manager bugs, including cellFormatter support, Babel plugin removal, i18n locale actions, RBAC helper recalculation, duplicate routes, and i18n endpoint handling.
Refactored the license‑limit hook and added a getFeature convenience method plus an “any” type for the admin API.
Fixed multiple admin and content‑manager bugs including 403 permissions error, settings save issues, user detail saving, and missing review‑workflow column
Replaced EE/CE imports with useEnterprise in admin settings and auth for a cleaner codebase.
Fixed multiple bugs including admin webhook dirty detection, RBAC conditions with relations, undefined route handling, removal of didReceiveAPIRequest event, and allowed unsafe abstract service calls.
Fix several core bugs including SSO lockout handling, dynamic zone component data, private S3 bucket uploads, and webhook utils
Added date/time picker improvements, dynamic component placement, bulk publish/unpublish in list view, and an icon picker for component icons
Patched two vulnerabilities (one high, one medium) by removing a getter for private attributes and tightening query sanitization.
Fixed various bugs including data transfer schema caching, entity/link filtering, textarea events, documentation component replacement, and i18n findMany decorator.
Updated documentation and migration guides, removing Airtable references and adding API reference and license updates.
Fix toOne sorting in Content Manager list view
Improved MySQL concurrency performance and added admin route registration feature
Added experimental automatic TypeScript type generation in development mode.
Fix regression introduced in v4.10.0 that blocked yarn build execution.
Introduced Review Workflows feature, modularized the Strapi CLI, added custom field input sizing, morph table indexes, and proxy support for internal requests.
Fixed numerous bugs across admin, content manager, database, and data‑transfer modules (e.g., admin build, role access crashes, audit‑log permissions, relation ordering, websocket sync, transaction handling).
Added CLI debug command, new Asturian and Lao i18n locales, and MySQL2 as a supported database client option
Added Data Transfer core feature and a private S3 bucket provider for uploads.
Fixed disabled property handling for JSONInput (GenericInput) and corrected populate traversal when no fragment is provided.
Fix invalid action mapping using an unknown action in core Strapi
Critical security vulnerability patched – users should upgrade to v4.8.0 immediately.
Optimized password sanitization performance in core utils
Fixed audit logs username/email display, corrected admin translations, and added a media attribute validator.
Fixed multiple bugs across admin, content manager, upload, utils, and database (e.g., mail icon on Windows, list view ordering, Postgres JSON field handling, upload folder updates, async forEach).
Replaced axiosInstance with getFetchClient in admin, upload, and users‑permissions packages and added a new useInjectReducer() hook for the admin UI.
Added major core features such as EE Audit Logs, relations & Dynamic Zones reordering, data import/export, online license verification, auth logo customization, and async admin reducer injection.
Critical security vulnerability patched; users urged to upgrade immediately.
Add configurable list and grid views to the Media Library, including a new view configuration feature
Added enhancements such as a new useFetchClient hook, native lodash replacements, Turkish translation, tracking for content type builder, and UI tweaks in admin and upload modules.
Added new core features: DB config generation for all clients, polymorphic relation fragment population, default values for custom field options, and improved upload asset card UI
Fixed numerous bugs in core modules (content manager JSON handling, UI wrapping, MySQL relations, Postgres raw queries, API tests, and core JS polyfills)
Updated numerous v3 dependencies (e.g., koa, passport, moment, sharp) with security and version patches
Added FriendlyName MainValue support to DynamicZone in the content manager
Added content manager improvements: relations now displayed in the main view with faster loading and UI tweaks such as status badges and custom react‑select messages
Fix core admin by bumping @strapi/design-system to 1.2.7.
Bug fixes across core modules: favicon middleware PNG compatibility, inline relations selection, bulk delete with empty components, AWS provider URL protocol, utils file import, and tooling webpack exclude handling for TSX plugins.
Swedish translations added for the Content Type Builder
Added dark‑theme customization for the admin panel and a Czech translation for the color‑picker plugin.
Fix broken dependency in the create‑strapi app that forced generated projects to reference Strapi 4.4.1
Fixed multiple bugs: case‑insensitive select autocomplete, router link handling in Content Manager, search query encoding, API token v2 DB performance, initializer prop assignment, and users‑permissions e2e test updates.
Security fix in users‑permissions plugin: corrected wrong filter param used with entityService.
Introduced API token v2 and added support for custom fields in the core;
Add a new request context core feature and store app theme support
Fixed core database issue by making the ID column nullable to prevent conflicts with default null values.
Fixed numerous bugs including admin translation, content manager component deletion, relation handling of zero values, loadingMessage prop types, database primary keys, SQLite RETURNING support, GraphQL i18n locale queries, i18n LocalePi...
Fixed core Strapi bug by verifying plugin presence before usage.
Multiple bug fixes across core, upload, and plugins (CLI Node version check, bulk delete webhook, Cloudinary promise handling, scalar attribute population, type generation, and translation updates).
Fix users‑permissions plugin issue with third‑party provider connections.
Deprecated the Rackspace upload provider, removing it from the core and potentially breaking projects that depend on it.