# changedetection.io 0.60.2 - Product: changedetection.io (https://whatsnew.fyi/product/changedetection-io) - Vendor: changedetection.io - Date: 2026-09-03 - Version: 0.60.2 - Original notes: https://github.com/dgtlmoon/changedetection.io/releases/tag/0.60.2 - Permalink: https://whatsnew.fyi/product/changedetection-io/releases/0.60.2 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Report the actual 1-based failed browser-step number - **changed** — UI medium refactor - **changed** — Show regex-tagged watches under their group tab - **fixed** — Watch history fix for restock.previous_price returning the first-ever price once a watch has 3+ snapshots - **fixed** — Fix LLM token counter race condition - **fixed** — Visual Selector renders scraped selectors as text, not markup - **fixed** — Sanitize lone unicode surrogates before filtering JSON - **fixed** — Invalidate favicon cache when clearing watch history - **fixed** — Avoid division by zero when logging watch load rate - **changed** — Move rendering of each watchlist row out of the watchlist main template so it can be re-used by the realtime update - **security** — Hide the running version from anonymous visitors when a password is set - **changed** — Move development tools out of runtime requirements - **added** — Allow a watch or group to append to the inherited AI Change Summary prompt - **fixed** — RSS pubDate is wrong on any non-UTC container: local time is relabelled as UTC - **security** — Improved URL filtering - **security** — Improved validation Stored CSS Injection via tag_colour Field - **security** — Reflected XSS in /diff//download-patch via from_version - Using built-in plain text response instead - **fixed** — LIBXML Data integrity fix, libxml must be locked across threads for any XML parsing - **added** — Add Polish translation - **added** — Add Ukrainian support for the 'In stock'/'Not in stock' status ##### What's Changed * fix: report the actual 1-based failed browser-step number (#4200) by @ebarkhordar in https://github.com/dgtlmoon/changedetection.io/pull/4258 * UI medium refactor by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4183 * Show regex-tagged watches under their group tab by @willyjfarrell in https://github.com/dgtlmoon/changedetection.io/pull/4267 * Watch history - fix for restock.previous_price returns the first-ever price once a watch has 3+ snapshots by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4268 * Fix LLM token counter race condition by @honma89 in https://github.com/dgtlmoon/changedetection.io/pull/4276 * fix: Visual Selector renders scraped selectors as text, not markup by @kah-ja in https://github.com/dgtlmoon/changedetection.io/pull/4282 * fix: sanitize lone unicode surrogates before filtering JSON by @snowyukitty in https://github.com/dgtlmoon/changedetection.io/pull/4293 * fix: invalidate favicon cache when clearing watch history by @snowyukitty in https://github.com/dgtlmoon/changedetection.io/pull/4286 * fix: avoid division by zero when logging watch load rate by @snowyukitty in https://github.com/dgtlmoon/changedetection.io/pull/4289 * UI - Move rendering of each watchlist row out of the watchlist main template so it can be re-used by the realtime update by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4305 * Security: hide the running version from anonymous visitors when a password is set (#2190) by @pongoe in https://github.com/dgtlmoon/changedetection.io/pull/4306 * Move development tools out of runtime requirements by @Nameless-Monster-Nerd in https://github.com/dgtlmoon/changedetection.io/pull/4280 * CSRF - Test fix by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4316 * feature: allow a watch or group to append to the inherited AI Change Summary prompt by @snowyukitty in https://github.com/dgtlmoon/changedetection.io/pull/4294 * RSS - RSS pubDate is wrong on any non-UTC container: local time is relabelled as UTC - #4309 by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4314 * GHSA-56fq-63vj-9992 Improved URL filtering by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4315 * GHSA-4j9m-cxq4-9c36 - Improved validation Stored CSS Injection via `tag_colour` Field by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4317 * Bump actions/setup-python from 6 to 7 in the all group across 1 directory by @dependabot[bot] in https://github.com/dgtlmoon/changedetection.io/pull/4291 * GHSA-23mp-8222-96fr - reflected XSS in /diff//download-patch via from_version - Using built-in plain text response instead. Reported-by: Mayssare Amakhtari (@cy3erm) Co-Authored-By: Claude Opus 5 (1M context) by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4324 * LIBXML Data integrity fix, libxml must be locked across threads for any XML parsing by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4325 * Add Polish translation by @osaczony30 in https://github.com/dgtlmoon/changedetection.io/pull/4329 * Add Ukrainian support for the 'In stock'/'Not in stock' status by @iG8R in https://github.com/dgtlmoon/changedetection.io/pull/4330 * Add watch UI should show which browser(s) are available and set default browser by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4334 * feat: make Playwright CSP bypass configurable by @kquinsland in https://github.com/dgtlmoon/changedetection.io/pull/4298 * Restock detection - fix inverted condition that skipped the OpenGraph availability fallback by @TowyTowy in https://github.com/dgtlmoon/changedetection.io/pull/4262 * Add watch UI default browser by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4335 * fix: Browser Steps picker cannot select a