# Postal changelog > A self-hosted mail delivery platform for sending and receiving application email. - Vendor: Postal - Category: Developer Tools - Official site: https://postalserver.io - Tracked by: What's New (https://whatsnew.fyi/product/postal) - Harvested from: GitHub (postalserver/postal) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## Releases ### 3.3.7 — v3.3.7 - Date: 2026-06-03 - Version: 3.3.7 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.7 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.7 - **security** — Prevent SSRF in outbound webhook and HTTP endpoint requests - **security** — Prevent SQL injection via condition keys - **fixed** — Stub IPv6 support in address guard IPv6 literal spec ##### [3.3.7](https://github.com/postalserver/postal/compare/3.3.6...3.3.7) (2026-06-03) ###### Bug Fixes * **http:** prevent SSRF in outbound webhook and HTTP endpoint requests ([11c9814](https://github.com/postalserver/postal/commit/11c9814474f956619da35e8385ef7fab9f304de0)) * **message-db:** prevent SQL injection via condition keys (GHSA-x2hq-rfpg-3xr5) ([4314a6e](https://github.com/postalserver/postal/commit/4314a6ec1e2812daa67dd20effd1db1769c1f8e8)) * **specs:** stub IPv6 support in address guard IPv6 literal spec ([029bfe0](https://github.com/postalserver/postal/commit/029bfe098d9b8c0b5cafc49eac33e767f5748cd3)) ###### Miscellaneous Chores * **deps:** upgrade rack & rails ([0445e5c](https://github.com/postalserver/postal/commit/0445e5c509870dfe9c16366c53dee3fc02ad3904)) * update security vulnerability reporting instructions ([8be1e27](https://github.com/postalserver/postal/commit/8be1e27fec489ab659ef5e909f705932028b1694)) ### 3.3.6 — v3.3.6 - Date: 2026-04-28 - Version: 3.3.6 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.6 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.6 - **security** — Sandbox rendered email HTML as extra XSS defence - **security** — Tighten return_to validation in authentication - **security** — Escape interpolated values in select options - **removed** — Remove unused src image proxy from tracking ##### [3.3.6](https://github.com/postalserver/postal/compare/3.3.5...3.3.6) (2026-04-28) ###### Bug Fixes * **messages:** sandbox rendered email HTML as extra XSS defence ([cad2aa6](https://github.com/postalserver/postal/commit/cad2aa6808519a3ff25215f09f4966d9fa3bb372)) ###### Miscellaneous Chores * ignore node modules and yarn.lock ([b611d57](https://github.com/postalserver/postal/commit/b611d577af79b8e1e75b6d47fa04d1ba03e34eec)) ###### Code Refactoring * **auth:** tighten return_to validation ([84f4e20](https://github.com/postalserver/postal/commit/84f4e20f05db2d11b0144f95960c956f8221e657)) * **helpers:** escape interpolated values in select options ([9243524](https://github.com/postalserver/postal/commit/924352403553dcfcc569876ca76c219493fac9d6)) * **tracking:** remove unused src image proxy ([dca7f90](https://github.com/postalserver/postal/commit/dca7f90b9046247c0d953567be35921167e79d87)) ### 3.3.5 — v3.3.5 - Date: 2026-02-01 - Version: 3.3.5 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.5 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.5 - **security** — Escape delivery details to prevent HTML injection - **fixed** — Use rackup handler instead of rack handler in health_server - **fixed** — Fix invalid OIDC scopes when concatenated - **fixed** — Fix typo in process logging - **fixed** — Fix typo in the credentials page - **fixed** — Update URL for v2 config - **changed** — Upgrade Puma, net-imap and other dependencies - **changed** — Reduce Docker container size - **changed** — Upgrade resolv to 0.6.2 - **changed** — Upgrade to Rails 7.1 and Ruby 3.4 - **changed** — Upgrade URI gem to 1.0.3 ##### [3.3.5](https://github.com/postalserver/postal/compare/3.3.4...3.3.5) (2026-02-01) ###### Bug Fixes * **deliveries:** escape delivery details to prevent HTML injection ([11419f9](https://github.com/postalserver/postal/commit/11419f99140e13688a9613cab3ee03f8d3cbae45)) * **health_server:** use rackup handler instead of rack handler ([7c47422](https://github.com/postalserver/postal/commit/7c47422c865e738c4d6af0fed1cca4405288341f)) * oidc scopes are invalid when concatenated ([#3332](https://github.com/postalserver/postal/issues/3332)) ([9c5f96a](https://github.com/postalserver/postal/commit/9c5f96ae90cf06dcd5db776806865752f667bd95)) * typo in process logging ([#3212](https://github.com/postalserver/postal/issues/3212)) ([b7e5232](https://github.com/postalserver/postal/commit/b7e5232e077b3c9b7a999dcb6676fba0ec61458e)) * typo in the credentials page ([fd3c7cc](https://github.com/postalserver/postal/commit/fd3c7ccdf6dc4ee0a76c9523cbd735159e4b8000)) * update url for v2 config ([#3225](https://github.com/postalserver/postal/issues/3225)) ([e00098b](https://github.com/postalserver/postal/commit/e00098b8003cf37f2708f536871b3ade377aed2d)) ###### Documentation * **process.rb:** add help about time unit used by metric ([#3339](https://github.com/postalserver/postal/issues/3339)) ([f5325c4](https://github.com/postalserver/postal/commit/f5325c49ff1152ad53eaaec98717ad3412d379ae)) ###### Miscellaneous Chores * **deps:** upgrade puma, net-imap and other deps ([c03c44b](https://github.com/postalserver/postal/commit/c03c44b442a29aa9881c1e1aae60bead9776a6b6)) * **dockerfile:** reduce container size ([86de372](https://github.com/postalserver/postal/commit/86de372382bd62bdd5d1372254f8817b0360bd56)) * remove version from docker-compose.yml ([c78000c](https://github.com/postalserver/postal/commit/c78000ca8f2998aa04648f465060768db6467de6)) * upgrade resolv to 0.6.2 ([d00d978](https://github.com/postalserver/postal/commit/d00d978872a96369544303d08f6a9d11cdf56b62)) * upgrade to rails 7.1 and ruby 3.4 ([#3457](https://github.com/postalserver/postal/issues/3457)) ([ab6d443](https://github.com/postalserver/postal/commit/ab6d4430baa33a05f1aa66e776cc2a5bcaa0ede8)) * upgrade uri gem to 1.0.3 ([f193b8e](https://github.com/postalserver/postal/commit/f193b8e77fc096382ab7aaa6a2c29641b4cb12df)) ### 3.3.4 — v3.3.4 - Date: 2024-06-20 - Version: 3.3.4 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.4 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.4 - **fixed** — Fix postal version command - **fixed** — Fix issue running message pruning task - **fixed** — Raise NotImplementedError when no call method on a scheduled task ##### [3.3.4](https://github.com/postalserver/postal/compare/3.3.3...3.3.4) (2024-06-20) ###### Bug Fixes * fix `postal version` command ([4fa88ac](https://github.com/postalserver/postal/commit/4fa88acea0dececd0eae485506a2ad8268fbea59)) * fix issue running message pruning task ([3a33e53](https://github.com/postalserver/postal/commit/3a33e53d843584757bb00898746aa059d7616db4)) * raise NotImplementedError when no call method on a scheduled task ([2b0919c](https://github.com/postalserver/postal/commit/2b0919c1454eabea93db96f50ecbd8e36bb89f1f)) ### 3.3.3 — v3.3.3 - Date: 2024-04-18 - Version: 3.3.3 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.3 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.3 - **fixed** — allow _expansions to be provided as true in legacy API to return all expansions ###### Bug Fixes * **legacy-api:** allow _expansions to be provided as true to return all expansions ([39f704c](https://github.com/postalserver/postal/commit/39f704c256fc3e71a1dc009acc77796a1efffead)), closes [#2932](https://github.com/postalserver/postal/issues/2932) ### 3.3.2 — v3.3.2 - Date: 2024-03-22 - Version: 3.3.2 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.2 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.2 - **changed** — Improve how current version and branch is determined and set ###### Code Refactoring * **versioning:** improve how current version and branch is determined and set ([07c6b31](https://github.com/postalserver/postal/commit/07c6b317f2b9dc04b6a8c88df1e6aa9e54597504)) ### 3.3.1 — v3.3.1 - Date: 2024-03-21 - Version: 3.3.1 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.1 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.1 - **fixed** — Ensure relays without a host are excluded in SMTP sender - **fixed** — Fix SMTPSender.smtp_relays method - **changed** — Remove moonrope but maintain legacy API actions ##### [3.3.1](https://github.com/postalserver/postal/compare/3.3.0...3.3.1) (2024-03-21) ###### Bug Fixes * **smtp-sender:** ensure relays without a host are excluded ([3a56ec8](https://github.com/postalserver/postal/commit/3a56ec8a74950e0162d98f1af5f58a67a82d6455)) * **smtp-sender:** fixes `SMTPSender.smtp_relays` ([b3264b9](https://github.com/postalserver/postal/commit/b3264b942776e254d3c351c94c435d172a514e18)) ###### Miscellaneous Chores * **container:** add the branch name to the container ([bee5098](https://github.com/postalserver/postal/commit/bee509832edc151d97fe5bfc48c4973452873fc8)) * **github-actions:** don't generate commit- tags ([d65bbe0](https://github.com/postalserver/postal/commit/d65bbe0579037c5df962a18134bc007f5159d7e5)) * **github-actions:** don't run for dependabot or release-please PRs and fetch whole repo ([adaf2b0](https://github.com/postalserver/postal/commit/adaf2b07502e9ed91290873ad8465051c6fd814f)) * **github-actions:** include a version string on branch-*/latest images ([64bc7dc](https://github.com/postalserver/postal/commit/64bc7dcf7c0a8e006ab6eb6e8b4a52ad5e7e6528)) * **ui:** display branch in footer if present ([1823617](https://github.com/postalserver/postal/commit/18236171ebc398c157f2e61b15c7df9f91205284)) ###### Code Refactoring * remove moonrope but maintain legacy API actions ([#2889](https://github.com/postalserver/postal/issues/2889)) ([4d9654d](https://github.com/postalserver/postal/commit/4d9654dac47d59c760be96388d0421de74d3e6ac)) ### 3.3.0 — v3.3.0 - Date: 2024-03-18 - Version: 3.3.0 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.0 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.0 - **added** — Add postal_message_queue_latency Prometheus metric - **added** — Allow number of worker threads to be configured - **added** — Scale connection pool with worker threads - **fixed** — Add ability to disable batching in message dequeuer ##### [3.3.0](https://github.com/postalserver/postal/compare/3.2.2...3.3.0) (2024-03-18) ###### Features * **prometheus:** add `postal_message_queue_latency` metric ([ee8d829](https://github.com/postalserver/postal/commit/ee8d829a854f91e476167869cafe35c2d37bb314)) * **worker:** allow number of threads to be configured ([7e2accc](https://github.com/postalserver/postal/commit/7e2acccd1ebd80750a3ebdb96cb5c36b5263cc24)) * **worker:** scale connection pool with worker threads ([ea542a0](https://github.com/postalserver/postal/commit/ea542a0694b3465b04fd3ebc439837df414deb1e)) ###### Bug Fixes * **message-dequeuer:** ability to disable batching ([4fcb9e9](https://github.com/postalserver/postal/commit/4fcb9e9a2e34be5aa4bdf13f0529f40e564b72b4)) ###### Miscellaneous Chores * **config-docs:** update docs for latest oidc defaults ([364eba6](https://github.com/postalserver/postal/commit/364eba6c5fce2f08a36489f42856ad5024a2062c)) * **config-docs:** update proxy protocol to mention v1 ([45dd8aa](https://github.com/postalserver/postal/commit/45dd8aaac56f15481cb7bf9081401cb28dc1e707)) ### 3.2.2 — v3.2.2 - Date: 2024-03-14 - Version: 3.2.2 - Original notes: https://github.com/postalserver/postal/releases/tag/3.2.2 - Permalink: https://whatsnew.fyi/product/postal/releases/3.2.2 - **fixed** — don't use authentication on org & server deletion - **fixed** — fixes proxy protocol in smtp-server - **changed** — allow config location message to be suppressed - **changed** — hide further config messages - **changed** — suppress config location on default-dkim-record ##### [3.2.2](https://github.com/postalserver/postal/compare/3.2.1...3.2.2) (2024-03-14) ###### Bug Fixes * don't use authentication on org & server deletion ([be45652](https://github.com/postalserver/postal/commit/be456523dd3aacb5c3eb45c9261da97ebffe603c)) * **smtp-server:** fixes proxy protocol ([9240612](https://github.com/postalserver/postal/commit/92406129cfcf1a06499a6f5aa18c73f1d6195793)) ###### Miscellaneous Chores * allow config location message to be suppressed ([f760cdb](https://github.com/postalserver/postal/commit/f760cdb5a1d53e9c30ee495d129cbf12603a3cbd)) * hide further config messages ([1c67f72](https://github.com/postalserver/postal/commit/1c67f72209c93404d7024ce3d15f6f54f2d707c4)) * suppress config location on default-dkim-record ([aa76aae](https://github.com/postalserver/postal/commit/aa76aae2322af41af1bd60cfe1d69a11ac76324e)) ###### Tests * add tests for the legacy API ([3d208d6](https://github.com/postalserver/postal/commit/3d208d632f4fc8a4adbfdb2bf4b377271eae6692)) ### 3.2.1 — v3.2.1 - Date: 2024-03-13 - Version: 3.2.1 - Original notes: https://github.com/postalserver/postal/releases/tag/3.2.1 - Permalink: https://whatsnew.fyi/product/postal/releases/3.2.1 - **fixed** — Fix postal default-dkim-record command ###### Bug Fixes * fixes `postal default-dkim-record` ([58dddeb](https://github.com/postalserver/postal/commit/58dddebeb81dc6fab945d2b10a91588eddc471c2))