Strapi

Developer Tools

The leading open-source headless CMS.

Latest v5.51.2 · by StrapiWebsitestrapi/strapi

Release activity

Release activity — 10 releases across 10 days since Jun 9, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jun 9, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026
Tuesday1 release on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
Wednesday1 release on Jun 10, 20261 release on Jun 17, 20261 release on Jun 24, 2026No releases on Jul 1, 20261 release on Jul 8, 20261 release on Jul 15, 2026No releases on Jul 22, 20261 release on Jul 29, 20261 release on Aug 5, 2026
ThursdayNo releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 20261 release on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 20261 release on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

10 releases since Jun 9, 2026

Changelog

v5.51.2

Added 1
  • Add optional component screenshots to DZ picker in content-manager
Changed 4
  • Use radio roles for accessibility and improve aria attributes
  • Support required on relation attributes in content-type-builder
  • Look models up on the registries in getModel in core
  • Reduce per-column work when mapping rows to entities in database
Fixed 15
  • Handle i18n conflict and local rights
  • Interpolate min/max values in validation error messages in admin
  • Pin react-colorful to prevent optimizeDeps include/exclude conflict in admin
  • Relation creation discards parent changes in content-manager
  • Relation order changes after saving dynamic-zone components in content-manager
  • Keep document status accurate on mixed-locale batches in content-manager
5.51.2 (2026-08-05)
🚀 New feature
  • content-manager: add optional component screenshots to DZ picker (#26863)
🔥 Bug fix
  • use radio roles for accessibility and improve aria attributes (#27139)
  • handle i18n conflict and local rights (6519f4d5db)
  • admin: interpolate min/max values in validation error messages (#27172)
  • admin: pin react-colorful to prevent optimizeDeps include/exclude conflict (#27203)
  • content-manager: relation creation discards parent changes (#27081)
  • content-manager: relation order changes after saving dynamic-zone components (#27135)
  • content-manager: keep document status accurate on mixed-locale batches (#27035)
  • core: use configured default pageSize when only page is provided (#27132)
  • database: escape LIKE wildcards in filters and use equality for $eqi/$nei (#26476)
  • i18n: use fractional temp_key when filling from locale (#26296)
  • upload: stream URL imports to disk instead of buffering in memory (#27176)
  • upload: keep cursor position while editing asset details fields (CMS-1536) (2c6edbfacb)
  • upload: apply asset permissions to media library actions (CMS-434) (e8099188e2)
  • upload: keep crop drag tracking on touch devices (CMS-1538) (7807ea83dc)
  • upload: keep asset drawer header visible on mobile (CMS-1539) (4edad7ca75)
  • upload: media library MVP fixes (7a4012c65a)
📚 Documentation Changes
  • add contributor documentation for the MCP server (#27160)
⚙️ Chore
  • deps: bump @hono/node-server from 1.19.14 to 1.19.17 (#27166)
  • deps: bump postcss from 8.5.14 to 8.5.25 (#27195)
  • deps: bump brace-expansion from 1.1.16 to 1.1.18 (#27196)
  • deps: bump js-yaml from 3.15.0 to 3.15.1 (#27197)
  • deps: bump motion from 12.23.24 to 12.40.0 (#27133)
  • deps: bump tar from 7.5.21 to 7.5.22 (#27165)
  • deps: bump react-router-dom from 6.30.3 to 6.30.4 (#27134)
  • deps: bump undici from 6.27.0 to 6.28.0 (#27164)
  • deps: bump axios from 1.18.1 to 1.19.0 (#27198)
  • deps: align app-template react-router-dom with admin 6.30.4 (#27210)
  • jest: run unit/front tests via nx, drop root jest config and dep (#26701)
  • lint: add non-blocking oxlint setup (#26923)
  • users-permissions: move server code into server/src (#26105)
💅 Enhancement
  • content-type-builder: support required on relation attributes (#27080)
  • core: look models up on the registries in getModel (#27143)
  • database: reduce per-column work when mapping rows to entities (#27144)
❤️ Thank You
  • Adrien L @Adzouz
  • Adrien Lepoutre @Adzouz
  • Andrei L @unrevised6419
  • Arthur Moreau
  • Ayoub Hidri @ayhid
  • Bassel Kanso
  • Ben Irvin
  • DMehaffy
  • Dominik Juriga @dominik-juriga
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • magics @hugomagics
  • Mason McElvain @masonmcelvain
  • Nico André
  • Syed Osama Ali Shah @Osamaali313
  • Vansh Parmar @vansh1011
  • Vishal Kumar Singh @singhvishalkr
View originalPermalink
How v5.51.2 went

v5.51.1

Fixed 8
  • respect field length constraints in AI localizations and isolate
  • wording and merging sort options
  • preserve sorting on view change
  • scope audit logs user filter to log authors
  • homepage recent-documents dates serialize as empty objects
  • enforce required media and relations via api.documents.strictRelations
  • return [] for empty morphMany on read
  • prevent duplicate public assets in Vite builds
5.51.1 (2026-07-29)
🔥 Bug fix
  • respect field length constraints in AI localizations and isolate… (#26880)
  • wording and merging sort options (844c8d625d)
  • preserve sorting on view change (6ed616ab9a)
  • admin: scope audit logs user filter to log authors (#27047)
  • content-manager: homepage recent-documents dates serialize as empty objects (#27066)
  • core: enforce required media and relations via api.documents.strictRelations (#27028)
  • database: return [] for empty morphMany on read (#27090)
  • strapi: prevent duplicate public assets in Vite builds (#27089)
⚙️ Chore
  • admin: allow RFC 6265 control-char regex under develop eslint rules (e8338bb6ba)
  • ci: remove admin bundle-size workflow (#27070)
  • deps: bump brace-expansion from 1.1.14 to 1.1.16 (#27071)
  • deps: bump shell-quote from 1.8.4 to 1.10.0 (#27072)
  • deps: bump body-parser from 1.20.4 to 1.20.6 (#27094)
  • deps: bump dompurify from 3.4.11 to 3.4.12 (#27095)
  • deps: bump fast-uri from 3.1.2 to 3.1.4 (#27098)
  • deps: bump use-context-selector from 1.4.1 to 1.4.4 (#27061)
  • deps: bump cropperjs from 1.6.1 to 1.6.2 (#27060)
  • deps: upgrade handlebars, axios, tar, and related transitive deps (#27091)
  • deps: bump @radix-ui/react-toolbar from 1.0.4 to 1.1.11 (#27059)
  • email-nodemailer: migrate unit tests from jest to vitest (#27074)
  • email-sendmail: migrate unit tests from jest to vitest (#27075)
  • upload-local: migrate unit tests from jest to vitest (#27073)
❤️ Thank You
  • Adrien L @Adzouz
  • Adrien Lepoutre @Adzouz
  • akash-dabhi-qed @akash-dabhi-qed
  • Ben Irvin
  • Giulio Montagner @giu1io
  • Gonzalo Andres Garcia @gonbaum
  • Mehdi Rezaei @mehdiraized
  • Nico André
View originalPermalink
How v5.51.1 went

v5.51.0

Added 2
  • Add exclude/only content type CLI filters to data-transfer
  • Add locale codes for Abkhazian and Circassian (Adyghe and Kabardian) to i18n
Fixed 18
  • Preserve order when reordering a relation to the start of a list
  • Use singleton modules for consistent runtime instances
  • Make admin session token respect configured admin-cookie-path
  • Make plugin/setting Select all work in admin token permissions
  • Revalidate SPA shell to avoid stale chunk imports
  • Expire admin reset-password tokens
5.51.0 (2026-07-23)
🚀 New feature
  • data-transfer: add exclude/only content type CLI filters (#26915)
  • i18n: add locale codes for Abkhazian and Circassian (Adyghe and Kabardian) (#26255)
🔥 Bug fix
  • preserve order when reordering a relation to the start of a list (#26112)
  • singleton modules for consistent runtime instances (#27064)
  • admin: admin session token respects configured admin-cookie-path (#25478, #26300)
  • admin: make plugin/setting "Select all" work in admin token permissions (#27027)
  • admin: revalidate SPA shell to avoid stale chunk imports (#27039)
  • admin: expire admin reset-password tokens (#27020)
  • admin: improve SSO session metadata and logout revocation (#26872)
  • admin: blank admin in develop from prism language prebundle (#27086)
  • admin: SSO remote logout infinite redirect (cookie path) (#27100)
  • content-manager: pre-bundle prism language plugins for all apps (#26978)
  • content-manager: respect disconnected draft relations in publish warning (#26871)
  • content-manager: validate items passed to plugin action APIs (#27008)
  • content-manager: skip blocks editor remount on equal value echoes (#27042)
  • content-manager: keep preview button mounted during document churn (#27043)
  • content-releases: normalise release id so rescheduling cancels the stale job (#27063
  • core: enforce default maxLength 255 for string fields (#26128)
  • core: preserve draft relation order in discard-drafts migration (#26851)
  • core: propagate server updatedAt in addFirstPublishedAtToDraft to avoid false modified flag (#26525)
  • create-strapi-app: npm ci fails on fresh npm scaffold (#27038)
  • create-strapi-app: missing @strapi/database dependency breaks pnpm builds (#27083)
  • database: apply MySQL dialect configure to resolved connection functions (#26646)
  • graphql: include private fields in mutation inputs (#26489)
  • types: update LoadedPlugin type to understand factories (#25298)
  • upload: report real upload progress in the media library (#27045)
  • users-permissions: use correct i18n ids for role notifications (#27044)
  • users-permissions: fix role notification translations (#26933)
⚙️ Chore
  • merge main into develop after 5.50.2 release (9d93244f7e)
  • deps: bump ws from 8.21.0 to 8.21.1 (#27030)
  • deps: bump tar from 7.5.18 to 7.5.20 (#27029)
  • deps: bump linkify-it from 5.0.0 to 5.0.2 (#26886)
  • email-mailgun: migrate unit tests from jest to vitest (#27069)
  • types: per-client database connection types (#26949)
  • users-permissions: replace grant/purest/jwk-to-pem with fetch and crypto (#26820)
  • utils: upgrade preferred-pm to v5 with dynamic import (#26822)
❤️ Thank You
  • Akash Santra @Akash504-ai
  • akash-dabhi-qed @akash-dabhi-qed
  • Akash! @Akash5908
  • Andrei L @unrevised6419
  • Andrew Bone
  • Ben Irvin
  • deferral-opium
  • Dijedon @dijedontahiri
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • jasleenkaur-qed42 @jasleenkaur-qed42
  • KaiNative
  • Maher @abaza738
  • Mohammad Arshid @Mohammadarshid
  • Rowan-Paul
  • Sami Waseem @AbdulSamiWaseem
  • santichausis @santichausis
View originalPermalink
How v5.51.0 went

v5.50.2

Added 2
  • Make admin auth cookie name configurable via admin.auth.cookie.name config
  • Complete Korean (ko) translation for i18n
Fixed 15
  • Prevent deprecated CJS Vite Node API warning on startup
  • Fix pre-commit failing when staging files ignored by ESLint
  • Show plan label instead of edition in dashboard
  • Restore runtime default for context helper
  • Clear stale Blocks editor selection on external value change
  • Reject 'status' attribute when draftAndPublish is enabled for backward compatibility
Security 1
  • Bump ws to 8.21.0 to fix CVE-2026-48779
5.50.2 (2026-07-15)
🚀 New feature
  • admin: make admin auth cookie name configurable (#26931)
  • i18n: complete Korean (ko) translation (#26941)
🔥 Bug fix
  • admin: prevent deprecated CJS Vite Node API warning on startup (#26947)
  • admin: pre-commit fails when staging files ignored by ESLint (#26958)
  • admin: show plan label instead of edition in dashboard (#26891)
  • admin: restore runtime default for context helper (#26809)
  • ci: reduce false positives in issue template checker (#26955)
  • ci: use npm install in issue template checker workflow (#26974)
  • content-manager: clear stale Blocks editor selection on external value change (#26959)
  • core: backward compat - reject 'status' attribute when draftAndPublish is enabled (#26890)
  • core: validate license registry responses with zod (#26935)
  • core: preserve duplicate form relation edits when cloning (#26961)
  • data-transfer: bump ws to 8.21.0 to fix CVE-2026-48779 (#26898)
  • database: include status sort expression in SELECT when using DISTINCT (#26751)
  • database: lint script does not run type check (#26819)
  • email: only warn about sendmail provider in development (#26893)
  • openapi: add bearerAuth and bracket pagination query params (#26948)
  • strapi: auto-exclude pre-built plugin UI libs from Vite optimizeDeps (#26944)
  • strapi: fix develop blank admin from optimizeDeps auto-exclude (#27014)
  • upgrade: prompt to pin ranged @strapi/* dependencies before upgrading (#26929)
  • upload: load remote asset thumbnails with crossOrigin to prevent CORS preview failures (#26581, #26901)
  • utils: align remaining convert-query-params errors with ValidationError (#26908)
⚙️ Chore
  • ai-tooling: sync skills when cursor sets up a new worktree (#26954)
  • data-transfer: clarify --exclude files CLI messaging (#26914)
  • deps: patch/minor dependency bumps (#26823)
  • deps: bump @xhmikosr/decompress from 10.2.0 to 10.2.1 (#26928)
  • deps: bump sharp from 0.33.5 to 0.34.5 (#26993)
  • deps: bump @internationalized/date from 3.5.4 to 3.12.1 (#26994)
  • deps: bump design-system and icons to v2.2.3 (#27002)
  • eslint: enforce zero warnings in package lint scripts (#26922)
  • husky: run git hooks through yarn exec (#27006)
  • tooling: remove unused find-up after lint-staged 16 (#26792)
  • types: drop CommonJS tsconfig overrides, build JS via rollup (#26934)
  • typescript: scope tsconfig types per workspace (#26699)
  • typescript-utils: migrate to typescript (#26811)
  • typescript-utils: bump internal deps to 5.50.1 (#26946)
⚠️ Changes to be aware of
Admin auth cookie name

You can set admin.auth.cookie.name in admin config to rename the access-token cookie (default remains jwtToken). Useful when another app on a shared parent domain sets a jwtToken cookie and breaks admin login.

(#26931)

status attribute with Draft & Publish

In v5, status is reserved for draft/published filtering. If a content type has Draft & Publish enabled and a custom status field, Strapi now logs a startup warning instead of failing boot. The Content-Type Builder still blocks adding status or enabling D&P when status already exists.

(#26890)

Upgrade tool and ranged @strapi/* versions

@strapi/upgrade now warns and offers to pin ranged @strapi/* dependencies (e.g. ^5.50.0) before upgrading, so upgrades don't silently report "already up-to-date" when node_modules resolved ahead of package.json.

(#26929)

❤️ Thank You
  • Abdallah M. @abdallahmz
  • akash-dabhi-qed @akash-dabhi-qed
  • Ali Ataf @aliataf
  • Andrei L @unrevised6419
  • arun @aun009
  • Bassel Kanso
  • Ben Irvin
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • jasleenkaur-qed42
  • moduvoice
  • Monu Meena @Monu01123
  • Nico André
View originalPermalink
How v5.50.2 went

v5.50.1

Added 2
  • Complete Japanese (ja) translations
  • Update Polish translation
Changed 1
  • Emit namespace keyword instead of deprecated module
Fixed 17
  • Give the ability to open a list item in a new tab
  • Translate enumeration option labels in the content manager
  • Seat limit billing links
  • Hide deploy menu in production using currentEnvironment
  • Allow reading hidden content types for relation targets
  • Preserve i18n locale on navigation and guard component schema race condition
5.50.1 (2026-07-08)
🚀 New feature
  • i18n: complete Japanese (ja) translations (#26855)
  • i18n: update Polish translation (#26592)
🔥 Bug fix
  • give the ability to open a list item in a new tab (#26853)
  • admin: translate enumeration option labels in the content manager (#26837)
  • admin: seat limit billing links (#26728)
  • cloud: hide deploy menu in production using currentEnvironment (#26733)
  • content-manager: allow reading hidden content types for relation targets (#26844)
  • content-manager: preserve i18n locale on navigation and guard component schema race condition (#26167)
  • core: preserve self-referential relation order on child publish (#26838)
  • core: preserve published self-referential relation state (#26932)
  • database: prevent crash when reordering and removing a relation in the same save (#26210)
  • documentation: allow array populate parameter (#26358)
  • examples: enable strict TypeScript in dev sandboxes (#26780)
  • generators: detect plugin language from output path (#26750)
  • review-workflows: add server eslint config and declare server deps (#26800)
  • strapi: resolve admin Vite aliases from @strapi/admin closure (#26756)
  • typescript-utils: emit namespace keyword instead of deprecated module (#26195)
  • upload: accept single-file arrays on replacement (#26405)
  • utils: align polymorphic populate validation with conversion (#26848)
  • utils: return 400 instead of 500 for invalid sort order/params (#26907)
📚 Documentation Changes
  • Highlight destructive operation in transfer engine (#25081)
⚙️ Chore
  • fix lint warnings (#26818)
  • deps: bump nodemailer from 8.0.9 to 9.0.1 (#26721)
  • deps: bump qs from 6.15.2 to 6.15.3 (#26846)
  • deps: bump tar from 7.5.16 to 7.5.17 (#26847)
  • deps: bump js-yaml from 3.14.2 to 3.15.0 (#26888)
  • deps: bump tar from 7.5.17 to 7.5.18 (#26887)
  • deps-dev: bump eslint-plugin-prettier in the eslint group (#26828)
  • deps-dev: bump @rollup/plugin-swc in the rollup group (#26906)
  • deps-dev: align @babel/* family to 7.29.7 (#26911)
💅 Enhancement
  • ci: block community PRs targeting main (#26854)
  • content-manager: keep sidebar primary actions and search bar fixed… (#26867)
❤️ Thank You
  • Adrien L @Adzouz
  • Alexandre Noblet @AlexNbl27
  • Andrei L @unrevised6419
  • Aryan Katiyar @Kelpy2004
  • Bassel Kanso
  • Ben Irvin
  • jasleenkaur-qed42
  • Maksim Zhukau @MaksZhukov
  • Mateusz Lesiak
  • mathildeleg @mathildeleg
  • mehmet turac @mturac
  • Nico André
  • santichausis @santichausis
  • Shivam S @BIGSUS24
  • Steven @compair-steven
  • Zyggzz @Zyggzzz
View originalPermalink
How v5.50.1 went

v5.50.0

Added 7
  • Add active devices session management in admin
  • Add security defaults to create-strapi-app templates
  • Export lifecycle event type from database
  • Add region option for EU data residency in SendGrid email provider
  • Accept a credential provider function in AWS S3 upload provider
  • Add comprehensive Japanese translation update for admin and 9 plugins
  • Augment all context error response methods with TypeScript support
Fixed 13
  • Fix refresh token cookies missing Max-Age when sessions.cookie.maxAge is set
  • Add test database healthchecks
  • Generate APIs in named directories
  • Retry lazy chunk loads and improve loading and error UX in admin
  • Open upgrade admin panel link in new tab
  • Hide boolean clear action when field is disabled in admin
5.50.0 (2026-07-02)
🚀 New feature
  • admin: add active devices session management (#26628)
  • cli: add security defaults to create-strapi-app templates (#26737)
  • database: export lifecycle event type (#25637)
  • provider-email-sendgrid: add region option for EU data residency (#25907)
  • provider-upload-aws-s3: accept a credential provider function (#26796)
  • translations: comprehensive Japanese (ja) translation update for admin and 9 plugins (#26687)
  • ts: augment all context error response methods (#25424)
🔥 Bug fix
  • refresh token cookies missing Max-Age when sessions.cookie.maxAg… (#26747)
  • add test database healthchecks (#26511)
  • generate apis in named directories (#26354)
  • admin: retry lazy chunk loads and improve loading and error UX (#25954)
  • admin: open "Upgrade your admin panel" link in new tab (#26510)
  • admin: remove @ts-expect-error in useQueryParams hook (#25006)
  • admin: hide boolean clear action when field is disabled (#26294)
  • admin: restore default locale in permissions when adding i18n to ct (#26548)
  • admin: keep static fallback paths url-safe (#26518)
  • admin: stop storing IP addresses in session metadata (#26873)
  • ci: use allowlisted thollander action ref in experimental publish workflow (#26768)
  • content-api: validate populate for polymorphic structures (#25854)
  • content-manager: warn before publishing with draft relations (#26736)
  • content-manager: use ListViewTable relation-loaded translation key (#26798)
  • content-manager: serve live preview script from server endpoint (#26732)
  • content-manager: capitalize component category names in dynamic zone (#24426, #26337)
  • content-manager: add Japanese EditView shortcut hint translations (#26814)
  • content-manager: prevent dynamic zone crash when value is null (#26816)
  • content-manager: skip publish warning for M2M links to published entries (#26858)
  • content-type-builder: improve component category validation error message (#25455)
  • core: preserve M2M relation order on published version after reo… (#26791)
  • core: maxFileSize error not detected in body middleware (#25011)
  • core: resolve relations on non-localized entries with stale locale column (#26805)
  • create-strapi-app: scaffold pnpm 11 allowBuilds for Strapi Cloud (#26757)
  • create-strapi-app: enable strict TypeScript in app scaffolds (#26779)
  • create-strapi-app: limit odd Node major warning to versions before 26 (#26810)
  • data-transfer: restore localizations links that use document_id refs (#26870)
  • graphql: preserve M2M relation order with pagination (#26577, #26785)
  • test: tighten jest ignore patterns to match path segments (#26753)
  • translations: correct ja "characters" mistranslation in WYSIWYG controls (#26845)
  • types: tighten Core.Config typings with backward-compatible deprecations (#26787)
  • upload: disable asset editing and deletion on published entries (#26127)
  • users-permissions: accept documentId for the role relation on user create/update (#26715)
  • users-permissions: correct "occured" → "occurred" typo in error notifications (#26508)
  • utils: prevent crash on null dynamic zone entry during traversal (#24303, #26842)
📚 Documentation Changes
  • fix typos and grammar slips in content-manager docs (#26600)
⚙️ Chore
  • add ai-tooling sync script for skill symlinks (#26594)
  • rename ai-tooling yarn scripts to ai:* (#26767)
  • reduce Vercel noise on PRs (contributor-docs ignore step) (#26772)
  • cloud plugin updates (#26801)
  • update cli deploy copies (f0fa460525)
  • deps: hoist @types/node to root and align with 20, min supported engine (#26291)
  • deps: upgrade TypeScript to 5.9.3 (#26782)
  • deps: bump hono from 4.12.23 to 4.12.27 (#26761)
  • deps: bump design-system to v2.2.1 (#26788)
  • deps: bump axios from 1.18.0 to 1.18.1 (#26762)
  • deps: upgrade lint-staged to 16 and scope linting to staged files (#26765)
  • deps: remove unused @strapi/ts-zen dev dependency (#26759)
  • typescript: enable erasableSyntaxOnly and noUncheckedSideEffectImports (#26790)
  • workflows: make documentation flag name more obvious (#26649)
💅 Enhancement
  • admin: add uz-Cyrl native name to languageNativeNames (#24920)
  • strapi: lazy-load TypeScript chain for non-build CLI commands (#26265)
  • utils: add env.required for strict scaffold secrets (#26830)
🚨 Security
  • users-permissions: default legacy JWT verify to HS256 (#26752)
❤️ Thank You
  • Akash Santra @Akash504-ai
  • Andrei L @unrevised6419
  • Arthur
  • Aurélien GEORGET
  • Ayoub Hidri @ayhid
  • Ben Irvin
  • Daiske @daiske
  • Florent Baldino @Baldinof
  • greymoth
  • ivseb @ivseb
  • jasleenkaur-qed42
  • Jian Zhang @Jian-Zhang08
  • Joseph Ajayi @ajayi-joseph
  • kdt523
  • kibwashere
  • Maksim Zhukau @MaksZhukov
  • mariekirsch @mariekirsch
  • mathildeleg @mathildeleg
  • mehmet turac @mturac
  • mhsnsfh
  • Minh Lê @DucMinhNe
  • Nico André
  • Niels Kaspers @nielskaspers
  • Nuraliev Alirahmon
  • Pierre Wizla
  • Rowan-Paul
  • Tewson Seeoun @tewson
  • Vibhu Gupta @VibhuGupta-dev
  • Vishal Kumar Singh @singhvishalkr
View originalPermalink
How v5.50.0 went

v5.49.0

Added 2
  • Export defineTool/defineResource/definePrompt builders for MCP
  • Add optional replace method to upload providers
Fixed 18
  • Add support for initiallySelectedAssets
  • Fix homepage dashboard duplicates entries for users with multiple roles
  • Avoid buffering large uploads for MIME detection
  • Throw ValidationError when populate exceeds qs arrayLimit
  • Push anchor into view to prevent off-screen tooltips
  • Support array of links in StrapiApp.addSettingsLink
5.49.0 (2026-06-24)
🚀 New feature
  • mcp: export defineTool/defineResource/definePrompt builders (#26603)
🔥 Bug fix
  • add support for initiallySelectedAssets (#26679)
  • homepage dashboard duplicates entries for users with multiple roles (#25860)
  • avoid buffering large uploads for MIME detection (#26678)
  • throw ValidationError when populate exceeds qs arrayLimit (#25632, #25916)
  • push anchor into view to prevent off-screen tooltips (#26303)
  • admin: support array of links in StrapiApp.addSettingsLink (#26433)
  • admin: admin users logged out mid-session by access-token expiry timer (#26680)
  • content-manager: use top-level Core type import in MCP types (#26681)
  • content-manager: save draft with Cmd/Ctrl+Enter, publish with Cmd/Ctrl+Shift+Enter (#26621)
  • content-manager: reduce MCP relation output to identity-only shape (#26560)
  • content-manager: deduplicate MCP tool names when plugin has multiple content types (#26710)
  • core/core: mcp misleading lifecycle docs (#26698)
  • create-strapi-app: allow pnpm to build better-sqlite3 for SQLite scaffolds (#26675)
  • data-transfer: transfer admin menu and auth logos with configuration (#26425)
  • database: stop full-schema component_type IN on dynamic zone populate (#26734)
  • document-service: preserve published relations from non-dp sources (#26654)
  • strapi: default allowedHosts and pin Vite HMR to main server in dev (#26244)
  • types: add explicit return types to recursive functions (#26704)
📚 Documentation Changes
  • fix spelling typos in content-manager relations guide (#26724)
⚙️ Chore
  • removing coderabbit status (#26703)
  • core: upgrade package-json to 10.0.1 + rollup interop 'auto' (#26673)
  • deps: bump markdown-it from 14.1.1 to 14.2.0 in the richtext-editor-security group across 1 directory (#26688)
  • deps: bump dompurify from 3.4.5 to 3.4.9 (#26684)
  • deps: bump nodemailer from 8.0.5 to 8.0.9 (#26689)
  • deps: bump tar from 7.5.11 to 7.5.16 (#26691)
  • deps: bump form-data from 4.0.4 to 4.0.6 (#26692)
  • deps: bump anthropics/claude-code-action from 1.0.123 to 1.0.132 (#26727)
  • deps: bump piscina from 4.9.2 to 4.9.3 (#26716)
  • deps: bump undici from 6.25.0 to 6.27.0 (#26714)
  • deps: bump dompurify from 3.4.9 to 3.4.11 (#26719)
  • deps-dev: bump @babel/core (#26667)
💅 Enhancement
  • upload: add optional replace method to upload providers (#26582)
❤️ Thank You
  • akash-dabhi-qed @akash-dabhi-qed
  • Andrei L @unrevised6419
  • Andrew Bone
  • Bassel Kanso @Bassel17
  • Ben Irvin
  • Giulio Montagner @giu1io
  • guoyangzhen
  • jasleenkaur-qed42
  • Nico André
  • Shivam S @BIGSUS24
  • Simon Norris @cache-your-dreams
  • Travis Swientek @travelton
  • Vallabh Mahajan @Vallabh-1504
  • Vishal Kumar Singh @singhvishalkr
⚠️ Changes to be aware of
Content Manager keyboard shortcuts

Save a draft with Cmd/Ctrl+Enter (or Cmd/Ctrl+S). Publish with Cmd/Ctrl+Shift+Enter. Since v5.31.3, plain Cmd/Ctrl+Enter published immediately — that shortcut now saves instead. (#26621)

View originalPermalink
How v5.49.0 went

v5.48.1

Added 5
  • Add optional OpenAPI spec route
  • Gate OpenAPI endpoint access with config
  • Add paginated GET /api/upload/files/page endpoint
  • Link to the Billing Portal
  • Point Upsell Banner to Strapi Billing
Changed 1
  • Update billing portal address
Fixed 14
  • Upload returns unsigned URL on update media info
  • Widgets show error when role has no access to mainfield of content type
  • Correct IME Enter key handling in BlocksInput
  • Return empty object for empty json body in fetch client
  • Exclude disabled plugins from admin build
  • Rate limit and serialize first admin registration
5.48.1 (2026-06-17)
🚀 New feature
  • linking to the Billing Portal (3df113f545)
  • pointing Upsell Banner to Strapi Billing (06b0c31f47)
  • add optional openapi spec route (#26239)
  • updating billing portal address (2d3fea21ff)
  • openapi: gate endpoint access with config (#26574)
  • upload: add paginated GET /api/upload/files/page endpoint (#26597)
🔥 Bug fix
  • upload returns unsigned URL on update media info (#25195)
  • widgets show error when role has no access to mainfield of ct (#26537)
  • correct IME Enter key handling in BlocksInput (#24997)
  • admin: return empty object for empty json body in fetch client (#26277)
  • admin: exclude disabled plugins from admin build (#26448)
  • admin: rate limit and serialize first admin registration (#26576)
  • admin: validate current user email updates (#26591)
  • admin: guard stale admin configuration (#26625)
  • build: build does not run install; add install-deps arg (#26483)
  • ci: run build:size as full command for compressed-size-action v3 (#26556)
  • ci: restore allowed paths-filter pin (#26575)
  • ci: avoid syncing CPR labels to CMS tickets (#26648)
  • content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
  • content-manager: raise z-index of code block language selector (#25010, #26324)
  • content-manager: dedupe bulk delete document ids (#26613)
  • content-manager: replace sanitize-html with dompurify in Wysiwyg preview (#26150)
  • core: validate numeric inputs before DB unique checks (#26101)
  • core/admin | content-manager: combine multi-role field-level permissions (#26055)
  • data-transfer: skip links referencing data that was never transferred (#26531)
  • data-transfer: buffer push assets before invoking uploadStream (#26086)
  • database: restore join-table relation sort order in components (#26553)
  • database: avoid double finalising completed transactions (#26122)
  • database: move document_id secondary indexes to schema sync (#26241)
  • strapi: stabilize admin redux deps during upgrade (#26249)
  • tsconfig: remove lodash from server compilerOptions.types (#26627)
  • upload: folder navigation bugs in Media Library (#26515)
  • upload: preserve animation frames in GIF and WebP images (#26126)
  • users-permissions: support documentId user relations (#26607)
  • utils: ignore empty sort when building orderBy (#26427)
📚 Documentation Changes
  • add CLAUDE.md alias and link PR template from AGENTS.md (#26251)
  • fix typos across contributor docs (#26590)
  • fix broken relative cross-doc links (#26601)
  • deprecate Node 20 in documentation (#26623)
  • openapi: add contributor documentation (#26410)
⚙️ Chore
  • remove experimental-dev example app (#26552)
  • update .gitignore for AI tooling directories (#26526)
  • release v5.48.0 update develop (#26599)
  • adding check for valid template on issue creation (#26546)
  • adding translations for manage subscription (aa0b3da3eb)
  • getting tests to pass (d2c06c6ca2)
  • *: support Node 26 (#26232)
  • ai/skills: add writing-a-skill skill (#26428)
  • ai/skills: add commit conventions (#26431)
  • ci: drop Node 20 from test workflow matrices (6f1a21c528)
  • ci: drop Node 20 from test workflow matrices (#26609)
  • core/strapi: dynamically import browserslist-to-esbuild (#25507)
  • data-transfer: move types into src so they are type-checked (#26352)
  • deps: bump axios from 1.16.1 to 1.17.0 (#26539)
  • deps: bump the testing-library group across 1 directory with 2 updates (#26506)
  • deps: bump actions/setup-node from 4 to 6 (#26496)
  • deps: bump actions/stale from 10 to 10.2.0 (#26497)
  • deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
  • deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
  • deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
  • deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
  • deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
  • deps: bump follow-redirects from 1.15.6 to 1.16.0 (#26580)
  • deps: bump shell-quote from 1.8.1 to 1.8.4 (#26585)
  • deps: bump @vitejs/plugin-react-swc (#26567)
  • deps: bump the rollup group across 1 directory with 3 updates (#26505)
  • deps: bump nrwl/nx-set-shas from 4 to 5 (#26565)
  • deps: bump anthropics/claude-code-action from 1 to 1.0.123 (#26640)
  • deps: bump trunk-io/analytics-uploader from 1.15.0 to 2.0.9 (#26638)
  • deps: bump rollup from 4.60.1 to 4.60.4 in the rollup group across 1 directory (#26641)
  • deps: bump open from 8.4.0 to 8.4.2 (#26643)
  • deps: bump stream-json and @types/stream-json (#26645)
  • deps: bump koa-helmet from 7.0.2 to 7.1.0 (#26642)
  • deps: bump axios from 1.17.0 to 1.18.0 (#26647)
  • deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
  • deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
  • deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
  • deps-dev: bump @types/webpack-hot-middleware from 2.25.9 to 2.25.12 (#26568)
  • deps-dev: bump @types/invariant from 2.2.36 to 2.2.37 (#26644)
  • repo: skip change freeze ownership check when freeze disabled (#26474)
💅 Enhancement
  • admin: hide deploy-now widget in production (#26660)
  • core/core: rounded thin borders for startup banner (#26273)
  • graphql: use discriminated unions instead of unsafe type casting (#25913)
  • upgrade: unhide and document upgrade to command (#26446)
🚨 Security
  • deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
  • deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
❤️ Thank You
  • Adrien L @Adzouz
  • Andrei L @unrevised6419
  • Andrei Varapayeu @thisavoropaev
  • Arav Menon @Arav-Menon
  • Aurélien GEORGET
  • Ayoub Hidri @ayhid
  • Bassel Kanso @Bassel17
  • Ben Irvin
  • Dante Calderon @dantehemerson
  • DMehaffy
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • Jasleen Kaur @Jasleen-Kaur96
  • Maksim Zhukau @MaksZhukov
  • Masamune Utsunomiya @masamunet
  • mathildeleg @mathildeleg
  • nclsndr
  • Nico André
  • Pierre Levavasseur @plevavas
  • Simon Norris @cache-your-dreams
  • Yazan Amer Abu Obaideh @yazan-abu-obaideh
  • Ziyi @butcherZ
View originalPermalink
How v5.48.1 went

v5.48.0

Added 2
  • Add optional OpenAPI spec route
  • Gate OpenAPI endpoint access with config
Changed 4
  • Use ReadonlyArray for layout prop in content-manager
  • Use discriminated unions instead of unsafe type casting in GraphQL
  • Unhide and document upgrade to command
  • Apply rounded thin borders for startup banner
Fixed 11
  • Upload returns unsigned URL on update media info
  • Widgets show error when role has no access to main field of content type
  • Return empty object for empty JSON body in fetch client
  • Build does not run install; add install-deps arg
  • Raise z-index of code block language selector
  • Validate numeric inputs before DB unique checks
Security 1
  • Patch uuid and qs DoS advisories
5.48.0 (2026-06-10)
🚀 New feature
  • add optional openapi spec route (#26239)
  • openapi: gate endpoint access with config (#26574)
🔥 Bug fix
  • upload returns unsigned URL on update media info (#25195)
  • widgets show error when role has no access to mainfield of ct (#26537)
  • admin: return empty object for empty json body in fetch client (#26277)
  • build: build does not run install; add install-deps arg (#26483)
  • ci: run build:size as full command for compressed-size-action v3 (#26556)
  • ci: restore allowed paths-filter pin (#26575)
  • content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
  • content-manager: raise z-index of code block language selector (#25010, #26324)
  • core: validate numeric inputs before DB unique checks (#26101)
  • database: restore join-table relation sort order in components (#26553)
  • database: avoid double finalising completed transactions (#26122)
  • upload: folder navigation bugs in Media Library (#26515)
  • upload: preserve animation frames in GIF and WebP images (#26126)
  • utils: ignore empty sort when building orderBy (#26427)
📚 Documentation Changes
  • openapi: add contributor documentation (#26410)
⚙️ Chore
  • remove experimental-dev example app (#26552)
  • update .gitignore for AI tooling directories (#26526)
  • deps: bump axios from 1.16.1 to 1.17.0 (#26539)
  • deps: bump the testing-library group across 1 directory with 2 updates (#26506)
  • deps: bump actions/setup-node from 4 to 6 (#26496)
  • deps: bump actions/stale from 10 to 10.2.0 (#26497)
  • deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
  • deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
  • deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
  • deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
  • deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
  • deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
  • deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
  • deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
  • repo: skip change freeze ownership check when freeze disabled (#26474)
💅 Enhancement
  • core/core: rounded thin borders for startup banner (#26273)
  • graphql: use discriminated unions instead of unsafe type casting (#25913)
  • upgrade: unhide and document upgrade to command (#26446)
🚨 Security
  • deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
  • deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
❤️ Thank You
  • Andrei L @unrevised6419
  • Andrei Varapayeu @thisavoropaev
  • Arav Menon @Arav-Menon
  • Aurélien GEORGET
  • Ben Irvin
  • Dante Calderon @dantehemerson
  • Jamie Howard @jhoward1994
  • Maksim Zhukau @MaksZhukov
  • mathildeleg @mathildeleg
  • Nico André
View originalPermalink
How v5.48.0 went

v4.26.2

Added 1
  • Added Node.js 22 support for Strapi v4
Fixed 1
  • Enforced unique admin email validation when updating the authenticated user profile
Security 3
  • Fixed a critical vulnerability where relational filtering could expose sensitive data through insufficient query sanitization
  • Upgraded tar to v7 to address security warnings
  • Applied v4 dependency security and maintenance updates
:warning: Note: This is the final Strapi 4 release :warning:

No further updates to Strapi 4 will be published, this release serves as the final version of Strapi 4 which is considered EOL (End-Of-Life) as of April 30th, 2026. All Strapi users should migrate to Strapi 5: https://docs.strapi.io/cms/migration/v4-to-v5/introduction-and-faq

Also please note, this does include Strapi Customers as well. Strapi Cloud will still continue to function with Strapi 4 but that may be subject change in the near future without warning.

What's Changed
Security
  • Fixed a critical vulnerability where relational filtering could expose sensitive data through insufficient query sanitization. See GHSA-rjg2-95x7-8qmx / CVE-2026-27886.
  • Upgraded tar to v7 to address security warnings.
  • Applied v4 dependency security and maintenance updates.
Fixes
  • Enforced unique admin email validation when updating the authenticated user profile.
Compatibility
  • Added Node.js 22 support for Strapi v4.

Full Changelog: https://github.com/strapi/strapi/compare/v4.26.1...v4.26.2

View originalPermalink
How v4.26.2 went
View all

Discussion