What changed in Strapi from 4 to 5

13 releases numbered after v4.26.2 up to and including v5.52.3, stable releases only. v4.26.2 and v5.52.3 are the newest stable releases of 4 and 5 we track; this page follows them as new ones ship.

218 changes across 13 releases · 7 landed on more than one version

Added 25

v5.52.2

  • New opt-in beta Media Library UI available behind feature flag `future.betaMediaLibrary: true`

v5.52.0

  • Record MCP actions in audit logs
  • Add locale codes for Corsican in i18n
  • Enhance Koa app configuration with proxy settings

v5.51.2

  • Add optional component screenshots to DZ picker in content-manager

v5.51.0

  • Add exclude/only content type CLI filters to data-transfer
  • Add locale codes for Abkhazian and Circassian (Adyghe and Kabardian) to i18n

v5.50.2

  • Make admin auth cookie name configurable via admin.auth.cookie.name config
  • Complete Korean (ko) translation for i18n

v5.50.1

  • Complete Japanese (ja) translations
  • Update Polish translation

v5.50.0

  • Add active devices session management in admin
  • Add security defaults to create-strapi-app templates
  • Export lifecycle event type from database
  • Add region option for EU data residency in SendGrid email provider
  • Accept a credential provider function in AWS S3 upload provider
  • Add comprehensive Japanese translation update for admin and 9 plugins
  • Augment all context error response methods with TypeScript support

v5.49.0

  • Export defineTool/defineResource/definePrompt builders for MCP
  • Add optional replace method to upload providers

v5.48.1

  • Add optional OpenAPI spec routealso inv5.48.0
  • Gate OpenAPI endpoint access with configalso inv5.48.0
  • Add paginated GET /api/upload/files/page endpoint
  • Link to the Billing Portal
  • Point Upsell Banner to Strapi Billing
Changed 15

v5.52.0

  • Replace umzug with internal migration runner in database
  • Memoize private attributes in sanitizeOutput
  • Stop using a thrown Error to test for boolean-like populate keys
  • Memoize scope decisions and keep the relation visitor sync

v5.51.2

  • Use radio roles for accessibility and improve aria attributes
  • Support required on relation attributes in content-type-builder
  • Look models up on the registries in getModel in core
  • Reduce per-column work when mapping rows to entities in database

v5.51.1

  • Empty multiple media and morphMany relations now return [] instead of null

v5.50.1

  • Emit namespace keyword instead of deprecated module

v5.48.1

  • Update billing portal address

v5.48.0

  • Use ReadonlyArray for layout prop in content-manager
  • Use discriminated unions instead of unsafe type casting in GraphQL
  • Unhide and document upgrade to command
  • Apply rounded thin borders for startup banner
Fixed 172

v5.52.3

  • Preserve special characters in filter and search values in admin
  • Fix relation picker losing locale in nested entries in content-manager
  • Fix relation fields displaying document ids when main fields are empty
  • Remove unused runtime import of @strapi/types in content-type-builder
  • Guard release-action service call when cms-content-releases is disabled in review-workflows
  • Sniff file bytes in admin when browser MIME is generic in upload
  • Show each asset as soon as its upload completes in upload
  • Apply various fixes and adjustments to new media library in upload
  • Repair typecheck on develop after merge collision in upload
  • Disable the folder tree chevron when a folder has no children in upload
  • Keep the asset name when replacing its file in upload
  • Use path.posix.normalize for route matching and path sanitization in users-permissions and core

v5.52.2

  • Make drag and drop more fluent in configuration view
  • Fix out of sort memory when listing audit logs on MySQL
  • Send credentials on fetch client requests in admin
  • Keep API token permissions on localized content types at boot
  • Honour redirectTo when the auth page redirects an authenticated user
  • Fix slow startup with many roles due to redundant permission checks
  • Fix draft status filter with i18n sibling locale published
  • Reject MCP relation writes combining set with connect or disconnect
  • Fix out of sort memory when listing history versions on MySQL
  • Fix access token rotation failure with asymmetric JWT algorithms
  • Serialize JSON columns before INSERT in discard-drafts migration
  • Fix local plugins duplicating the admin module graph and exhausting build memory
  • Fix relation reorder saving the wrong position
  • Correct broken placeholders in pt-BR translations
  • Surface clear error for unsupported RBAC condition operators
  • Fix admin build failing to resolve @strapi/admin under isolated node_modules
  • Translate server error codes in the new media library
  • Enforce sizeLimit when replacing a file

v5.52.1

  • Unrelated permission conditions no longer block page access in admin
  • Deduplicate MCP tool names when an API has multiple content types in content-manager
  • Refrain from counting error draft relations in content-manager
  • Show tooltip on truncated names in the media library upload
  • Fix inability to clear refresh token cookie on logout due to mismatched options in users-permissions

v5.52.0

  • Fix typescript pipeline issue
  • Dedupe react-dnd in the admin bundle
  • Address filter entries by position so duplicate filter chips behave correctly
  • Merge query populate paths to preserve nested populate
  • Prevent editing relations from removing inverse field conditions
  • Clear stale validation errors when the form data is replaced
  • Skip orphaned links and isolate FK failures on restore in data-transfer
  • Skip unregistered RBAC conditions during ability generation in permissions
  • Allowlist Vite optimizeDeps.exclude for plugin UI kits
  • Refresh folder header count on upload and delete in upload
  • Guard cache-buster on signed URLs in new-ML AssetCropEditor
  • Target current asset in drawer actions in upload
  • Keep infinite scroll loading when the sentinel stays visible in upload

v5.51.2

  • Handle i18n conflict and local rights
  • Interpolate min/max values in validation error messages in admin
  • Pin react-colorful to prevent optimizeDeps include/exclude conflict in admin
  • Prevent relation creation from discarding parent changes in content-manager
  • Prevent relation order changes after saving dynamic-zone components in content-manager
  • Keep document status accurate on mixed-locale batches in content-manager
  • Use configured default pageSize when only page is provided in core
  • Escape LIKE wildcards in filters and use equality for $eqi/$nei in database
  • Use fractional __temp_key__ when filling from locale in i18n
  • Stream URL imports to disk instead of buffering in memory in upload
  • Keep cursor position while editing asset details fields in upload
  • Apply asset permissions to media library actions in upload
  • Keep crop drag tracking on touch devices in upload
  • Keep asset drawer header visible on mobile in upload
  • Apply media library MVP fixes in upload

v5.51.1

  • Respect field length constraints in AI localizations and isolate
  • Fix wording and merging sort options
  • Preserve sorting on view change
  • Scope audit logs user filter to log authors in admin
  • Fix homepage recent-documents dates serialize as empty objects in content-manager
  • Enforce required media and relations via api.documents.strictRelations in core
  • Return [] for empty morphMany on read in database
  • Prevent duplicate public assets in Vite builds

v5.51.0

  • Preserve order when reordering a relation to the start of a list
  • Use singleton modules for consistent runtime instances
  • Make admin session token respect configured admin-cookie-path
  • Make plugin/setting Select all work in admin token permissions
  • Revalidate SPA shell to avoid stale chunk imports
  • Expire admin reset-password tokens
  • Improve SSO session metadata and logout revocation
  • Fix blank admin in develop from prism language prebundle
  • Fix SSO remote logout infinite redirect caused by cookie path
  • Pre-bundle prism language plugins for all apps in content-manager
  • Respect disconnected draft relations in publish warning
  • Validate items passed to plugin action APIs
  • Skip blocks editor remount on equal value echoes
  • Keep preview button mounted during document churn
  • Normalise release id so rescheduling cancels the stale job in content-releases
  • Enforce default maxLength 255 for string fields
  • Preserve draft relation order in discard-drafts migration
  • Propagate server updatedAt in addFirstPublishedAtToDraft to avoid false modified flag

v5.50.2

  • Prevent deprecated CJS Vite Node API warning on startup
  • Fix pre-commit failing when staging files ignored by ESLint
  • Show plan label instead of edition in dashboard
  • Restore runtime default for context helper
  • Clear stale Blocks editor selection on external value change
  • Reject 'status' attribute when draftAndPublish is enabled for backward compatibility
  • Validate license registry responses with zod
  • Preserve duplicate form relation edits when cloning
  • Include status sort expression in SELECT when using DISTINCT
  • Only warn about sendmail provider in development
  • Add bearerAuth and bracket pagination query params to OpenAPI
  • Auto-exclude pre-built plugin UI libs from Vite optimizeDeps
  • Fix develop blank admin from optimizeDeps auto-exclude
  • Prompt to pin ranged @strapi/* dependencies before upgrading
  • Load remote asset thumbnails with crossOrigin to prevent CORS preview failures

v5.50.1

  • Give the ability to open a list item in a new tab
  • Translate enumeration option labels in the content manager
  • Seat limit billing links
  • Hide deploy menu in production using currentEnvironment
  • Allow reading hidden content types for relation targets
  • Preserve i18n locale on navigation and guard component schema race condition
  • Preserve self-referential relation order on child publish
  • Preserve published self-referential relation state
  • Prevent crash when reordering and removing a relation in the same save
  • Allow array populate parameter
  • Enable strict TypeScript in dev sandboxes
  • Detect plugin language from output path
  • Add server eslint config and declare server deps
  • Resolve admin Vite aliases from @strapi/admin closure
  • Accept single-file arrays on replacement
  • Align polymorphic populate validation with conversion
  • Return 400 instead of 500 for invalid sort order/params

v5.50.0

  • Fix refresh token cookies missing Max-Age when sessions.cookie.maxAge is set
  • Add test database healthchecks
  • Generate APIs in named directories
  • Retry lazy chunk loads and improve loading and error UX in admin
  • Open upgrade admin panel link in new tab
  • Hide boolean clear action when field is disabled in admin
  • Restore default locale in permissions when adding i18n to content type
  • Stop storing IP addresses in session metadata in admin
  • Validate populate for polymorphic structures in content API
  • Warn before publishing with draft relations in content manager
  • Serve live preview script from server endpoint in content manager
  • Prevent dynamic zone crash when value is null in content manager
  • Preserve M2M relation order on published version after reorganization

v5.49.0

  • Add support for initiallySelectedAssets
  • Fix homepage dashboard duplicates entries for users with multiple roles
  • Avoid buffering large uploads for MIME detection
  • Throw ValidationError when populate exceeds qs arrayLimit
  • Push anchor into view to prevent off-screen tooltips
  • Support array of links in StrapiApp.addSettingsLink
  • Fix admin users logged out mid-session by access-token expiry timer
  • Use top-level Core type import in MCP types
  • Save draft with Cmd/Ctrl+Enter, publish with Cmd/Ctrl+Shift+Enter
  • Reduce MCP relation output to identity-only shape
  • Deduplicate MCP tool names when plugin has multiple content types
  • Fix MCP misleading lifecycle docs
  • Allow pnpm to build better-sqlite3 for SQLite scaffolds
  • Transfer admin menu and auth logos with configuration
  • Stop full-schema component_type IN on dynamic zone populate
  • Preserve published relations from non-dp sources
  • Default allowedHosts and pin Vite HMR to main server in dev
  • Add explicit return types to recursive functions

v5.48.1

  • Upload returns unsigned URL on update media infoalso inv5.48.0
  • Widgets show error when role has no access to mainfield of content type
  • Correct IME Enter key handling in BlocksInput
  • Return empty object for empty json body in fetch clientalso inv5.48.0
  • Exclude disabled plugins from admin build
  • Rate limit and serialize first admin registration
  • Validate current user email updates
  • Guard stale admin configuration
  • Build does not run install; add install-deps argalso inv5.48.0
  • Raise z-index of code block language selectoralso inv5.48.0
  • Dedupe bulk delete document ids
  • Replace sanitize-html with dompurify in Wysiwyg preview
  • Validate numeric inputs before DB unique checksalso inv5.48.0
  • Combine multi-role field-level permissions

v5.48.0

  • Widgets show error when role has no access to main field of content type
  • Restore join-table relation sort order in components
  • Avoid double finalising completed transactions
  • Folder navigation bugs in Media Library
  • Preserve animation frames in GIF and WebP images
  • Ignore empty sort when building orderBy
Removed 1

v5.52.3

  • Remove unused nodemon dependencies
Security 5

v5.52.2

  • Deny SVG uploads by default in generated project defaults

v5.52.0

  • Bump @modelcontextprotocol/sdk to 1.30.0
  • Bump sharp to 0.35.3 for libvips CVEs in upload

v5.50.2

  • Bump ws to 8.21.0 to fix CVE-2026-48779

v5.48.0

  • Patch uuid and qs DoS advisories

Original release notes, newest first

The list above is our reading of these notes; the originals from Strapi are here, one fold per release.

v5.52.3
5.52.3 (2026-09-02)
🔥 Bug fix
  • admin: preserve special characters in filter and search values (#27440)
  • content-manager: relation picker loses locale in nested entries (#27487)
  • content-manager: relation fields display document ids when main fields are empty (#27488)
  • content-type-builder: remove unused runtime import of @strapi/types (#27452)
  • review-workflows: guard release-action service call when cms-content-releases is disabled (#27312)
  • upload: sniff file bytes in admin when browser MIME is generic (#27363)
  • upload: show each asset as soon as its upload completes (#27456)
  • upload: various fixes and adjustments of new media library (#27477)
  • upload: repair the typecheck on develop after two merges collided (#27497)
  • upload: disable the folder tree chevron when a folder has no children (#27495)
  • upload: keep the asset name when replacing its file (#27501)
  • users-permissions,core: use path.posix.normalize for route matching and path sanitization (#27158)
⚙️ Chore
  • strapi: remove unused nodemon dependencies (#27479)
❤️ Thank You
  • Adrien L @Adzouz
  • Andrei L @unrevised6419
  • Bassel Kanso
  • Ben Irvin
  • Kushal Rathod @KushalXCoder
  • Lovepreet Singh @singhlovepreet9
  • Nico André
  • Valentin @valfur03

View originalPermalink

v5.52.2
5.52.2 (2026-08-26)
✨ New Media Library (opt-in beta)

A complete revamped Media Library UI is available behind a feature flag. Set future.betaMediaLibrary: true in config/features and restart your app; it replaces the legacy Media Library when enabled (disabled by default). More info in docs and the Notion Page

Feedback while it's behind the flag is very welcome. Enjoy!

🔥 Bug fix
  • make drag and drop more fluently in configuation view fix#23161 (#26320, #23161)
  • admin: out of sort memory when listing audit logs on mysql (#27410)
  • admin: send credentials on fetch client requests (#27413)
  • admin: keep api token permissions on localized content types at boot (#27420)
  • admin: honour redirectTo when the auth page redirects an authenticated user (#27213)
  • admin: slow startup with many roles due to redundant permission … (#27438)
  • content-manager: draft status filter with i18n sibling locale published (#26835)
  • content-manager: reject MCP relation writes combining set with connect or disconnect (#27423)
  • content-manager: out of sort memory when listing history versions on mysql (#27394)
  • core: Access token rotation fails with asymmetric JWT algorithms (#27201)
  • core: serialize JSON columns before INSERT in discard-drafts migration (#25927)
  • core/strapi: local plugins duplicate the admin module graph and exhaust build memory (#27311)
  • database: relation reorder saves the wrong position (#27444)
  • i18n: correct broken placeholders in pt-BR translations (#27257, #27383)
  • permissions: surface clear error for unsupported RBAC condition operators (#27355)
  • plugins: admin build fails to resolve @strapi/admin under isolated node_modules (#27337)
  • upload: translate server error codes in the new media library (#27345)
  • upload: sizeLimit is not enforced when replacing a file (#27414)
  • upload: move replace media to the drawer footer, add tooltips (#27425)
  • upload: list queued files in the upload progress dialog (#27416)
  • upload: merge a second drop into the running upload batch (#27415)
⚙️ Chore
  • replace lodash forEach with native Object.entries/values (#27409)
  • add worktree bootstrap command (#27426)
  • deps: upgrade memfs to 4.68.1 in @strapi/upgrade (#27406)
  • deps: migrate first-party zod to 4.4.3 (#27428)
💅 Enhancement
  • data-transfer: clarify partial transfer stage scope (#27322)
  • database: log internal migrations at info level (#27324)
  • database: add migration progress heartbeats (#27325)
🚨 Security
  • graphql: warn about unbounded operation limits (#27390)
  • upload: deny svg in generated project defaults (#27360)
⚠️ Changes to be aware of
New projects block SVG uploads by default

Apps created with create-strapi-app now reject SVG files in the Media Library by default, because SVG can include active browser content. Existing projects are unchanged; if you need SVG in a new project, allow image/svg+xml in the generated upload security config. (#27360)

❤️ Thank You
  • Adrien L @Adzouz
  • Andrei L @unrevised6419
  • Ayoub Hidri @ayhid
  • Bassel Kanso
  • Ben Irvin
  • DMehaffy
  • Eliau Elkouby @eliau2005
  • Giulio Montagner @giu1io
  • jasleenkaur-qed42 @jasleenkaur-qed42
  • keke @kekekuli
  • Lazizbek Ergashev @lazerg
  • Merlijn van den Berg
  • Nico André
  • Omar MEBARKI
  • Rohit Singh @HitOP2509
  • Samran Asif @webdevsamran
  • Ziyi @butcherZ

View originalPermalink

v5.52.1
5.52.1 (2026-08-19)
🔥 Bug fix
  • admin: unrelated permission conditions no longer block page access (3ded36a7b0)
  • content-manager: deduplicate MCP tool names when an api has multiple content types (#27357)
  • content-manager: refraining from counting error draft relations … (#26900)
  • upload: show tooltip on truncated names in the media library (#27340)
  • users-permissions: unable to clear refresh token cookie on logout due to mismatched options (#25106)
⚙️ Chore
  • update develop with release 5.52.0 (#27343)
  • deps: bump fast-uri from 3.1.4 to 3.1.5 (#27242)
❤️ Thank You
  • akash-dabhi-qed @akash-dabhi-qed
  • Giulio Montagner @giu1io
  • kgndnc @kgndnc
  • Lazizbek Ergashev @lazerg
  • Nico André
  • Valentin Furmanek

View originalPermalink

v5.52.0
5.52.0 (2026-08-12)
🚀 New feature
  • record MCP actions in audit logs (#27151)
  • i18n: add locale codes for Corsican (#27099)
  • server: enhance Koa app configuration with proxy settings (#26409)
🔥 Bug fix
  • typescript pipeline issue (99a723d024)
  • admin: dedupe react-dnd in the admin bundle (#27217)
  • admin: address filter entries by position so duplicate filter chips behave (#27188)
  • content-manager: merge query populate paths to preserve nested populate (#27236)
  • content-type-builder: editing relations removes inverse field conditions (#27226)
  • content-type-builder: clear stale validation errors when the form data is replaced (#27222)
  • data-transfer: skip orphaned links and isolate FK failures on restore (#26852)
  • permissions: skip unregistered RBAC conditions during ability generation (#27282)
  • strapi: allowlist Vite optimizeDeps.exclude for plugin UI kits (#27264)
  • upload: refresh folder header count on upload & delete (CMS-1563) (#27231)
  • upload: guard cache-buster on signed URLs in new-ML AssetCropEditor (#27228)
  • upload: target current asset in drawer actions (#27259)
  • upload: keep infinite scroll loading when the sentinel stays visible (CMS-1562) (#27230)
⚙️ Chore
  • release v5.51.2 update develop (101643bcfb)
  • bump design system version (#27292)
  • cloud-cli: migrate unit tests from jest to vitest (#27218)
  • database: replace umzug with internal migration runner (#26824)
  • deps: bump ip-address from 10.2.0 to 10.4.0 (#27238)
  • deps: bump ws from 8.21.1 to 8.21.2 (#27239)
  • deps: bump hono from 4.12.27 to 4.13.0 (#27243)
  • deps: bump prettier from 3.3.3 to 3.6.2 (#27244)
  • deps: bump direct deps and yarn dedupe (#27291)
  • deps: bump nanoid from 3.3.16 to 3.3.18 (#27329)
  • permissions: migrate unit tests from jest to vitest (#27219)
  • sentry: migrate unit tests from jest to vitest (#27252)
  • tooling: add admin translation verification (#26960)
  • upload-aws-s3: migrate unit tests from jest to vitest (#27216)
💅 Enhancement
  • utils: memoize private attributes in sanitizeOutput (#27140)
  • utils: stop using a thrown Error to test for boolean-like populate keys (#27234)
  • utils: memoize scope decisions and keep the relation visitor sync (#27145)
🚨 Security
  • deps: bump @modelcontextprotocol/sdk to 1.30.0 (#27301)
  • upload: bump sharp to 0.35.3 for libvips CVEs (#27255)
❤️ Thank You
  • Adrien L @Adzouz
  • Adrien Lepoutre @Adzouz
  • Ayoub Hidri @ayhid
  • Bassel Kanso
  • Ben Irvin
  • DMehaffy
  • Giulio Montagner @giu1io
  • Gonzalo Andres Garcia @gonbaum
  • Lazizbek Ergashev @lazerg
  • Markus @MarkusAbtion
  • PetruMagdeleine
  • Sjouke de Vries @sjoukedv
  • Ziyi @butcherZ

View originalPermalink

v5.51.2
5.51.2 (2026-08-05)
🚀 New feature
  • content-manager: add optional component screenshots to DZ picker (#26863)
🔥 Bug fix
  • use radio roles for accessibility and improve aria attributes (#27139)
  • handle i18n conflict and local rights (6519f4d5db)
  • admin: interpolate min/max values in validation error messages (#27172)
  • admin: pin react-colorful to prevent optimizeDeps include/exclude conflict (#27203)
  • content-manager: relation creation discards parent changes (#27081)
  • content-manager: relation order changes after saving dynamic-zone components (#27135)
  • content-manager: keep document status accurate on mixed-locale batches (#27035)
  • core: use configured default pageSize when only page is provided (#27132)
  • database: escape LIKE wildcards in filters and use equality for $eqi/$nei (#26476)
  • i18n: use fractional temp_key when filling from locale (#26296)
  • upload: stream URL imports to disk instead of buffering in memory (#27176)
  • upload: keep cursor position while editing asset details fields (CMS-1536) (2c6edbfacb)
  • upload: apply asset permissions to media library actions (CMS-434) (e8099188e2)
  • upload: keep crop drag tracking on touch devices (CMS-1538) (7807ea83dc)
  • upload: keep asset drawer header visible on mobile (CMS-1539) (4edad7ca75)
  • upload: media library MVP fixes (7a4012c65a)
📚 Documentation Changes
  • add contributor documentation for the MCP server (#27160)
⚙️ Chore
  • deps: bump @hono/node-server from 1.19.14 to 1.19.17 (#27166)
  • deps: bump postcss from 8.5.14 to 8.5.25 (#27195)
  • deps: bump brace-expansion from 1.1.16 to 1.1.18 (#27196)
  • deps: bump js-yaml from 3.15.0 to 3.15.1 (#27197)
  • deps: bump motion from 12.23.24 to 12.40.0 (#27133)
  • deps: bump tar from 7.5.21 to 7.5.22 (#27165)
  • deps: bump react-router-dom from 6.30.3 to 6.30.4 (#27134)
  • deps: bump undici from 6.27.0 to 6.28.0 (#27164)
  • deps: bump axios from 1.18.1 to 1.19.0 (#27198)
  • deps: align app-template react-router-dom with admin 6.30.4 (#27210)
  • jest: run unit/front tests via nx, drop root jest config and dep (#26701)
  • lint: add non-blocking oxlint setup (#26923)
  • users-permissions: move server code into server/src (#26105)
💅 Enhancement
  • content-type-builder: support required on relation attributes (#27080)
  • core: look models up on the registries in getModel (#27143)
  • database: reduce per-column work when mapping rows to entities (#27144)
⚠️ Changes to be aware of
Filter operators: literal wildcards and true case-insensitive equality

$eqi / $nei now do real case-insensitive equality (= LOWER(?)), not LIKE, so values with %, _, or a trailing \ no longer act as wildcards or crash some databases. Substring operators ($contains, $startsWith, $endsWith, and case-insensitive variants) now treat %, _, and \ in the filter value as literal characters. If you relied on % / _ inside those filters as SQL wildcards, update filters to match the new literal semantics. (#26476)

❤️ Thank You
  • Adrien L @Adzouz
  • Adrien Lepoutre @Adzouz
  • Andrei L @unrevised6419
  • Arthur Moreau
  • Ayoub Hidri @ayhid
  • Bassel Kanso
  • Ben Irvin
  • DMehaffy
  • Dominik Juriga @dominik-juriga
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • magics @hugomagics
  • Mason McElvain @masonmcelvain
  • Nico André
  • Syed Osama Ali Shah @Osamaali313
  • Vansh Parmar @vansh1011
  • Vishal Kumar Singh @singhvishalkr

View originalPermalink

v5.51.1
5.51.1 (2026-07-29)
🔥 Bug fix
  • respect field length constraints in AI localizations and isolate… (#26880)
  • wording and merging sort options (844c8d625d)
  • preserve sorting on view change (6ed616ab9a)
  • admin: scope audit logs user filter to log authors (#27047)
  • content-manager: homepage recent-documents dates serialize as empty objects (#27066)
  • core: enforce required media and relations via api.documents.strictRelations (#27028)
  • database: return [] for empty morphMany on read (#27090)
  • strapi: prevent duplicate public assets in Vite builds (#27089)
⚙️ Chore
  • admin: allow RFC 6265 control-char regex under develop eslint rules (e8338bb6ba)
  • ci: remove admin bundle-size workflow (#27070)
  • deps: bump brace-expansion from 1.1.14 to 1.1.16 (#27071)
  • deps: bump shell-quote from 1.8.4 to 1.10.0 (#27072)
  • deps: bump body-parser from 1.20.4 to 1.20.6 (#27094)
  • deps: bump dompurify from 3.4.11 to 3.4.12 (#27095)
  • deps: bump fast-uri from 3.1.2 to 3.1.4 (#27098)
  • deps: bump use-context-selector from 1.4.1 to 1.4.4 (#27061)
  • deps: bump cropperjs from 1.6.1 to 1.6.2 (#27060)
  • deps: upgrade handlebars, axios, tar, and related transitive deps (#27091)
  • deps: bump @radix-ui/react-toolbar from 1.0.4 to 1.1.11 (#27059)
  • email-nodemailer: migrate unit tests from jest to vitest (#27074)
  • email-sendmail: migrate unit tests from jest to vitest (#27075)
  • upload-local: migrate unit tests from jest to vitest (#27073)
⚠️ Changes to be aware of
Required media and relations: opt-in strictRelations

New config api.documents.strictRelations enforces required media and relations on publish (drafts can still be empty). On by default for new projects; existing apps are unchanged until you set it. To opt in, set documents.strictRelations: true in config/api. (#27028)

Empty multiple media / morphMany now returns []

Populated empty morphMany relations (including type: 'media', multiple: true) serialize as [] instead of null, matching other to-many relations. This is unconditional and not gated by strictRelations. If clients, webhooks, or integrations check field === null for empty galleries / morphMany, treat [] as empty instead (e.g. !field?.length). (#27090)

❤️ Thank You
  • Adrien L @Adzouz
  • Adrien Lepoutre @Adzouz
  • akash-dabhi-qed @akash-dabhi-qed
  • Ben Irvin
  • Giulio Montagner @giu1io
  • Gonzalo Andres Garcia @gonbaum
  • Mehdi Rezaei @mehdiraized
  • Nico André

View originalPermalink

v5.51.0
5.51.0 (2026-07-23)
🚀 New feature
  • data-transfer: add exclude/only content type CLI filters (#26915)
  • i18n: add locale codes for Abkhazian and Circassian (Adyghe and Kabardian) (#26255)
🔥 Bug fix
  • preserve order when reordering a relation to the start of a list (#26112)
  • singleton modules for consistent runtime instances (#27064)
  • admin: admin session token respects configured admin-cookie-path (#25478, #26300)
  • admin: make plugin/setting "Select all" work in admin token permissions (#27027)
  • admin: revalidate SPA shell to avoid stale chunk imports (#27039)
  • admin: expire admin reset-password tokens (#27020)
  • admin: improve SSO session metadata and logout revocation (#26872)
  • admin: blank admin in develop from prism language prebundle (#27086)
  • admin: SSO remote logout infinite redirect (cookie path) (#27100)
  • content-manager: pre-bundle prism language plugins for all apps (#26978)
  • content-manager: respect disconnected draft relations in publish warning (#26871)
  • content-manager: validate items passed to plugin action APIs (#27008)
  • content-manager: skip blocks editor remount on equal value echoes (#27042)
  • content-manager: keep preview button mounted during document churn (#27043)
  • content-releases: normalise release id so rescheduling cancels the stale job (#27063
  • core: enforce default maxLength 255 for string fields (#26128)
  • core: preserve draft relation order in discard-drafts migration (#26851)
  • core: propagate server updatedAt in addFirstPublishedAtToDraft to avoid false modified flag (#26525)
  • create-strapi-app: npm ci fails on fresh npm scaffold (#27038)
  • create-strapi-app: missing @strapi/database dependency breaks pnpm builds (#27083)
  • database: apply MySQL dialect configure to resolved connection functions (#26646)
  • graphql: include private fields in mutation inputs (#26489)
  • types: update LoadedPlugin type to understand factories (#25298)
  • upload: report real upload progress in the media library (#27045)
  • users-permissions: use correct i18n ids for role notifications (#27044)
  • users-permissions: fix role notification translations (#26933)
⚙️ Chore
  • merge main into develop after 5.50.2 release (9d93244f7e)
  • deps: bump ws from 8.21.0 to 8.21.1 (#27030)
  • deps: bump tar from 7.5.18 to 7.5.20 (#27029)
  • deps: bump linkify-it from 5.0.0 to 5.0.2 (#26886)
  • email-mailgun: migrate unit tests from jest to vitest (#27069)
  • types: per-client database connection types (#26949)
  • users-permissions: replace grant/purest/jwk-to-pem with fetch and crypto (#26820)
  • utils: upgrade preferred-pm to v5 with dynamic import (#26822)
❤️ Thank You
  • Akash Santra @Akash504-ai
  • akash-dabhi-qed @akash-dabhi-qed
  • Akash! @Akash5908
  • Andrei L @unrevised6419
  • Andrew Bone
  • Ben Irvin
  • deferral-opium
  • Dijedon @dijedontahiri
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • jasleenkaur-qed42 @jasleenkaur-qed42
  • KaiNative
  • Maher @abaza738
  • Mohammad Arshid @Mohammadarshid
  • Rowan-Paul
  • Sami Waseem @AbdulSamiWaseem
  • santichausis @santichausis

View originalPermalink

v5.50.2
5.50.2 (2026-07-15)
🚀 New feature
  • admin: make admin auth cookie name configurable (#26931)
  • i18n: complete Korean (ko) translation (#26941)
🔥 Bug fix
  • admin: prevent deprecated CJS Vite Node API warning on startup (#26947)
  • admin: pre-commit fails when staging files ignored by ESLint (#26958)
  • admin: show plan label instead of edition in dashboard (#26891)
  • admin: restore runtime default for context helper (#26809)
  • ci: reduce false positives in issue template checker (#26955)
  • ci: use npm install in issue template checker workflow (#26974)
  • content-manager: clear stale Blocks editor selection on external value change (#26959)
  • core: backward compat - reject 'status' attribute when draftAndPublish is enabled (#26890)
  • core: validate license registry responses with zod (#26935)
  • core: preserve duplicate form relation edits when cloning (#26961)
  • data-transfer: bump ws to 8.21.0 to fix CVE-2026-48779 (#26898)
  • database: include status sort expression in SELECT when using DISTINCT (#26751)
  • database: lint script does not run type check (#26819)
  • email: only warn about sendmail provider in development (#26893)
  • openapi: add bearerAuth and bracket pagination query params (#26948)
  • strapi: auto-exclude pre-built plugin UI libs from Vite optimizeDeps (#26944)
  • strapi: fix develop blank admin from optimizeDeps auto-exclude (#27014)
  • upgrade: prompt to pin ranged @strapi/* dependencies before upgrading (#26929)
  • upload: load remote asset thumbnails with crossOrigin to prevent CORS preview failures (#26581, #26901)
  • utils: align remaining convert-query-params errors with ValidationError (#26908)
⚙️ Chore
  • ai-tooling: sync skills when cursor sets up a new worktree (#26954)
  • data-transfer: clarify --exclude files CLI messaging (#26914)
  • deps: patch/minor dependency bumps (#26823)
  • deps: bump @xhmikosr/decompress from 10.2.0 to 10.2.1 (#26928)
  • deps: bump sharp from 0.33.5 to 0.34.5 (#26993)
  • deps: bump @internationalized/date from 3.5.4 to 3.12.1 (#26994)
  • deps: bump design-system and icons to v2.2.3 (#27002)
  • eslint: enforce zero warnings in package lint scripts (#26922)
  • husky: run git hooks through yarn exec (#27006)
  • tooling: remove unused find-up after lint-staged 16 (#26792)
  • types: drop CommonJS tsconfig overrides, build JS via rollup (#26934)
  • typescript: scope tsconfig types per workspace (#26699)
  • typescript-utils: migrate to typescript (#26811)
  • typescript-utils: bump internal deps to 5.50.1 (#26946)
⚠️ Changes to be aware of
Admin auth cookie name

You can set admin.auth.cookie.name in admin config to rename the access-token cookie (default remains jwtToken). Useful when another app on a shared parent domain sets a jwtToken cookie and breaks admin login.

(#26931)

status attribute with Draft & Publish

In v5, status is reserved for draft/published filtering. If a content type has Draft & Publish enabled and a custom status field, Strapi now logs a startup warning instead of failing boot. The Content-Type Builder still blocks adding status or enabling D&P when status already exists.

(#26890)

Upgrade tool and ranged @strapi/* versions

@strapi/upgrade now warns and offers to pin ranged @strapi/* dependencies (e.g. ^5.50.0) before upgrading, so upgrades don't silently report "already up-to-date" when node_modules resolved ahead of package.json.

(#26929)

❤️ Thank You
  • Abdallah M. @abdallahmz
  • akash-dabhi-qed @akash-dabhi-qed
  • Ali Ataf @aliataf
  • Andrei L @unrevised6419
  • arun @aun009
  • Bassel Kanso
  • Ben Irvin
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • jasleenkaur-qed42
  • moduvoice
  • Monu Meena @Monu01123
  • Nico André

View originalPermalink

v5.50.1
5.50.1 (2026-07-08)
🚀 New feature
  • i18n: complete Japanese (ja) translations (#26855)
  • i18n: update Polish translation (#26592)
🔥 Bug fix
  • give the ability to open a list item in a new tab (#26853)
  • admin: translate enumeration option labels in the content manager (#26837)
  • admin: seat limit billing links (#26728)
  • cloud: hide deploy menu in production using currentEnvironment (#26733)
  • content-manager: allow reading hidden content types for relation targets (#26844)
  • content-manager: preserve i18n locale on navigation and guard component schema race condition (#26167)
  • core: preserve self-referential relation order on child publish (#26838)
  • core: preserve published self-referential relation state (#26932)
  • database: prevent crash when reordering and removing a relation in the same save (#26210)
  • documentation: allow array populate parameter (#26358)
  • examples: enable strict TypeScript in dev sandboxes (#26780)
  • generators: detect plugin language from output path (#26750)
  • review-workflows: add server eslint config and declare server deps (#26800)
  • strapi: resolve admin Vite aliases from @strapi/admin closure (#26756)
  • typescript-utils: emit namespace keyword instead of deprecated module (#26195)
  • upload: accept single-file arrays on replacement (#26405)
  • utils: align polymorphic populate validation with conversion (#26848)
  • utils: return 400 instead of 500 for invalid sort order/params (#26907)
📚 Documentation Changes
  • Highlight destructive operation in transfer engine (#25081)
⚙️ Chore
  • fix lint warnings (#26818)
  • deps: bump nodemailer from 8.0.9 to 9.0.1 (#26721)
  • deps: bump qs from 6.15.2 to 6.15.3 (#26846)
  • deps: bump tar from 7.5.16 to 7.5.17 (#26847)
  • deps: bump js-yaml from 3.14.2 to 3.15.0 (#26888)
  • deps: bump tar from 7.5.17 to 7.5.18 (#26887)
  • deps-dev: bump eslint-plugin-prettier in the eslint group (#26828)
  • deps-dev: bump @rollup/plugin-swc in the rollup group (#26906)
  • deps-dev: align @babel/* family to 7.29.7 (#26911)
💅 Enhancement
  • ci: block community PRs targeting main (#26854)
  • content-manager: keep sidebar primary actions and search bar fixed… (#26867)
❤️ Thank You
  • Adrien L @Adzouz
  • Alexandre Noblet @AlexNbl27
  • Andrei L @unrevised6419
  • Aryan Katiyar @Kelpy2004
  • Bassel Kanso
  • Ben Irvin
  • jasleenkaur-qed42
  • Maksim Zhukau @MaksZhukov
  • Mateusz Lesiak
  • mathildeleg @mathildeleg
  • mehmet turac @mturac
  • Nico André
  • santichausis @santichausis
  • Shivam S @BIGSUS24
  • Steven @compair-steven
  • Zyggzz @Zyggzzz

View originalPermalink

v5.50.0
5.50.0 (2026-07-02)
🚀 New feature
  • admin: add active devices session management (#26628)
  • cli: add security defaults to create-strapi-app templates (#26737)
  • database: export lifecycle event type (#25637)
  • provider-email-sendgrid: add region option for EU data residency (#25907)
  • provider-upload-aws-s3: accept a credential provider function (#26796)
  • translations: comprehensive Japanese (ja) translation update for admin and 9 plugins (#26687)
  • ts: augment all context error response methods (#25424)
🔥 Bug fix
  • refresh token cookies missing Max-Age when sessions.cookie.maxAg… (#26747)
  • add test database healthchecks (#26511)
  • generate apis in named directories (#26354)
  • admin: retry lazy chunk loads and improve loading and error UX (#25954)
  • admin: open "Upgrade your admin panel" link in new tab (#26510)
  • admin: remove @ts-expect-error in useQueryParams hook (#25006)
  • admin: hide boolean clear action when field is disabled (#26294)
  • admin: restore default locale in permissions when adding i18n to ct (#26548)
  • admin: keep static fallback paths url-safe (#26518)
  • admin: stop storing IP addresses in session metadata (#26873)
  • ci: use allowlisted thollander action ref in experimental publish workflow (#26768)
  • content-api: validate populate for polymorphic structures (#25854)
  • content-manager: warn before publishing with draft relations (#26736)
  • content-manager: use ListViewTable relation-loaded translation key (#26798)
  • content-manager: serve live preview script from server endpoint (#26732)
  • content-manager: capitalize component category names in dynamic zone (#24426, #26337)
  • content-manager: add Japanese EditView shortcut hint translations (#26814)
  • content-manager: prevent dynamic zone crash when value is null (#26816)
  • content-manager: skip publish warning for M2M links to published entries (#26858)
  • content-type-builder: improve component category validation error message (#25455)
  • core: preserve M2M relation order on published version after reo… (#26791)
  • core: maxFileSize error not detected in body middleware (#25011)
  • core: resolve relations on non-localized entries with stale locale column (#26805)
  • create-strapi-app: scaffold pnpm 11 allowBuilds for Strapi Cloud (#26757)
  • create-strapi-app: enable strict TypeScript in app scaffolds (#26779)
  • create-strapi-app: limit odd Node major warning to versions before 26 (#26810)
  • data-transfer: restore localizations links that use document_id refs (#26870)
  • graphql: preserve M2M relation order with pagination (#26577, #26785)
  • test: tighten jest ignore patterns to match path segments (#26753)
  • translations: correct ja "characters" mistranslation in WYSIWYG controls (#26845)
  • types: tighten Core.Config typings with backward-compatible deprecations (#26787)
  • upload: disable asset editing and deletion on published entries (#26127)
  • users-permissions: accept documentId for the role relation on user create/update (#26715)
  • users-permissions: correct "occured" → "occurred" typo in error notifications (#26508)
  • utils: prevent crash on null dynamic zone entry during traversal (#24303, #26842)
📚 Documentation Changes
  • fix typos and grammar slips in content-manager docs (#26600)
⚙️ Chore
  • add ai-tooling sync script for skill symlinks (#26594)
  • rename ai-tooling yarn scripts to ai:* (#26767)
  • reduce Vercel noise on PRs (contributor-docs ignore step) (#26772)
  • cloud plugin updates (#26801)
  • update cli deploy copies (f0fa460525)
  • deps: hoist @types/node to root and align with 20, min supported engine (#26291)
  • deps: upgrade TypeScript to 5.9.3 (#26782)
  • deps: bump hono from 4.12.23 to 4.12.27 (#26761)
  • deps: bump design-system to v2.2.1 (#26788)
  • deps: bump axios from 1.18.0 to 1.18.1 (#26762)
  • deps: upgrade lint-staged to 16 and scope linting to staged files (#26765)
  • deps: remove unused @strapi/ts-zen dev dependency (#26759)
  • typescript: enable erasableSyntaxOnly and noUncheckedSideEffectImports (#26790)
  • workflows: make documentation flag name more obvious (#26649)
💅 Enhancement
  • admin: add uz-Cyrl native name to languageNativeNames (#24920)
  • strapi: lazy-load TypeScript chain for non-build CLI commands (#26265)
  • utils: add env.required for strict scaffold secrets (#26830)
🚨 Security
  • users-permissions: default legacy JWT verify to HS256 (#26752)
❤️ Thank You
  • Akash Santra @Akash504-ai
  • Andrei L @unrevised6419
  • Arthur
  • Aurélien GEORGET
  • Ayoub Hidri @ayhid
  • Ben Irvin
  • Daiske @daiske
  • Florent Baldino @Baldinof
  • greymoth
  • ivseb @ivseb
  • jasleenkaur-qed42
  • Jian Zhang @Jian-Zhang08
  • Joseph Ajayi @ajayi-joseph
  • kdt523
  • kibwashere
  • Maksim Zhukau @MaksZhukov
  • mariekirsch @mariekirsch
  • mathildeleg @mathildeleg
  • mehmet turac @mturac
  • mhsnsfh
  • Minh Lê @DucMinhNe
  • Nico André
  • Niels Kaspers @nielskaspers
  • Nuraliev Alirahmon
  • Pierre Wizla
  • Rowan-Paul
  • Tewson Seeoun @tewson
  • Vibhu Gupta @VibhuGupta-dev
  • Vishal Kumar Singh @singhvishalkr

View originalPermalink

v5.49.0
5.49.0 (2026-06-24)
🚀 New feature
  • mcp: export defineTool/defineResource/definePrompt builders (#26603)
🔥 Bug fix
  • add support for initiallySelectedAssets (#26679)
  • homepage dashboard duplicates entries for users with multiple roles (#25860)
  • avoid buffering large uploads for MIME detection (#26678)
  • throw ValidationError when populate exceeds qs arrayLimit (#25632, #25916)
  • push anchor into view to prevent off-screen tooltips (#26303)
  • admin: support array of links in StrapiApp.addSettingsLink (#26433)
  • admin: admin users logged out mid-session by access-token expiry timer (#26680)
  • content-manager: use top-level Core type import in MCP types (#26681)
  • content-manager: save draft with Cmd/Ctrl+Enter, publish with Cmd/Ctrl+Shift+Enter (#26621)
  • content-manager: reduce MCP relation output to identity-only shape (#26560)
  • content-manager: deduplicate MCP tool names when plugin has multiple content types (#26710)
  • core/core: mcp misleading lifecycle docs (#26698)
  • create-strapi-app: allow pnpm to build better-sqlite3 for SQLite scaffolds (#26675)
  • data-transfer: transfer admin menu and auth logos with configuration (#26425)
  • database: stop full-schema component_type IN on dynamic zone populate (#26734)
  • document-service: preserve published relations from non-dp sources (#26654)
  • strapi: default allowedHosts and pin Vite HMR to main server in dev (#26244)
  • types: add explicit return types to recursive functions (#26704)
📚 Documentation Changes
  • fix spelling typos in content-manager relations guide (#26724)
⚙️ Chore
  • removing coderabbit status (#26703)
  • core: upgrade package-json to 10.0.1 + rollup interop 'auto' (#26673)
  • deps: bump markdown-it from 14.1.1 to 14.2.0 in the richtext-editor-security group across 1 directory (#26688)
  • deps: bump dompurify from 3.4.5 to 3.4.9 (#26684)
  • deps: bump nodemailer from 8.0.5 to 8.0.9 (#26689)
  • deps: bump tar from 7.5.11 to 7.5.16 (#26691)
  • deps: bump form-data from 4.0.4 to 4.0.6 (#26692)
  • deps: bump anthropics/claude-code-action from 1.0.123 to 1.0.132 (#26727)
  • deps: bump piscina from 4.9.2 to 4.9.3 (#26716)
  • deps: bump undici from 6.25.0 to 6.27.0 (#26714)
  • deps: bump dompurify from 3.4.9 to 3.4.11 (#26719)
  • deps-dev: bump @babel/core (#26667)
💅 Enhancement
  • upload: add optional replace method to upload providers (#26582)
❤️ Thank You
  • akash-dabhi-qed @akash-dabhi-qed
  • Andrei L @unrevised6419
  • Andrew Bone
  • Bassel Kanso @Bassel17
  • Ben Irvin
  • Giulio Montagner @giu1io
  • guoyangzhen
  • jasleenkaur-qed42
  • Nico André
  • Shivam S @BIGSUS24
  • Simon Norris @cache-your-dreams
  • Travis Swientek @travelton
  • Vallabh Mahajan @Vallabh-1504
  • Vishal Kumar Singh @singhvishalkr
⚠️ Changes to be aware of
Content Manager keyboard shortcuts

Save a draft with Cmd/Ctrl+Enter (or Cmd/Ctrl+S). Publish with Cmd/Ctrl+Shift+Enter. Since v5.31.3, plain Cmd/Ctrl+Enter published immediately — that shortcut now saves instead. (#26621)

View originalPermalink

v5.48.1
5.48.1 (2026-06-17)
🚀 New feature
  • linking to the Billing Portal (3df113f545)
  • pointing Upsell Banner to Strapi Billing (06b0c31f47)
  • add optional openapi spec route (#26239)
  • updating billing portal address (2d3fea21ff)
  • openapi: gate endpoint access with config (#26574)
  • upload: add paginated GET /api/upload/files/page endpoint (#26597)
🔥 Bug fix
  • upload returns unsigned URL on update media info (#25195)
  • widgets show error when role has no access to mainfield of ct (#26537)
  • correct IME Enter key handling in BlocksInput (#24997)
  • admin: return empty object for empty json body in fetch client (#26277)
  • admin: exclude disabled plugins from admin build (#26448)
  • admin: rate limit and serialize first admin registration (#26576)
  • admin: validate current user email updates (#26591)
  • admin: guard stale admin configuration (#26625)
  • build: build does not run install; add install-deps arg (#26483)
  • ci: run build:size as full command for compressed-size-action v3 (#26556)
  • ci: restore allowed paths-filter pin (#26575)
  • ci: avoid syncing CPR labels to CMS tickets (#26648)
  • content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
  • content-manager: raise z-index of code block language selector (#25010, #26324)
  • content-manager: dedupe bulk delete document ids (#26613)
  • content-manager: replace sanitize-html with dompurify in Wysiwyg preview (#26150)
  • core: validate numeric inputs before DB unique checks (#26101)
  • core/admin | content-manager: combine multi-role field-level permissions (#26055)
  • data-transfer: skip links referencing data that was never transferred (#26531)
  • data-transfer: buffer push assets before invoking uploadStream (#26086)
  • database: restore join-table relation sort order in components (#26553)
  • database: avoid double finalising completed transactions (#26122)
  • database: move document_id secondary indexes to schema sync (#26241)
  • strapi: stabilize admin redux deps during upgrade (#26249)
  • tsconfig: remove lodash from server compilerOptions.types (#26627)
  • upload: folder navigation bugs in Media Library (#26515)
  • upload: preserve animation frames in GIF and WebP images (#26126)
  • users-permissions: support documentId user relations (#26607)
  • utils: ignore empty sort when building orderBy (#26427)
📚 Documentation Changes
  • add CLAUDE.md alias and link PR template from AGENTS.md (#26251)
  • fix typos across contributor docs (#26590)
  • fix broken relative cross-doc links (#26601)
  • deprecate Node 20 in documentation (#26623)
  • openapi: add contributor documentation (#26410)
⚙️ Chore
  • remove experimental-dev example app (#26552)
  • update .gitignore for AI tooling directories (#26526)
  • release v5.48.0 update develop (#26599)
  • adding check for valid template on issue creation (#26546)
  • adding translations for manage subscription (aa0b3da3eb)
  • getting tests to pass (d2c06c6ca2)
  • *: support Node 26 (#26232)
  • ai/skills: add writing-a-skill skill (#26428)
  • ai/skills: add commit conventions (#26431)
  • ci: drop Node 20 from test workflow matrices (6f1a21c528)
  • ci: drop Node 20 from test workflow matrices (#26609)
  • core/strapi: dynamically import browserslist-to-esbuild (#25507)
  • data-transfer: move types into src so they are type-checked (#26352)
  • deps: bump axios from 1.16.1 to 1.17.0 (#26539)
  • deps: bump the testing-library group across 1 directory with 2 updates (#26506)
  • deps: bump actions/setup-node from 4 to 6 (#26496)
  • deps: bump actions/stale from 10 to 10.2.0 (#26497)
  • deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
  • deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
  • deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
  • deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
  • deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
  • deps: bump follow-redirects from 1.15.6 to 1.16.0 (#26580)
  • deps: bump shell-quote from 1.8.1 to 1.8.4 (#26585)
  • deps: bump @vitejs/plugin-react-swc (#26567)
  • deps: bump the rollup group across 1 directory with 3 updates (#26505)
  • deps: bump nrwl/nx-set-shas from 4 to 5 (#26565)
  • deps: bump anthropics/claude-code-action from 1 to 1.0.123 (#26640)
  • deps: bump trunk-io/analytics-uploader from 1.15.0 to 2.0.9 (#26638)
  • deps: bump rollup from 4.60.1 to 4.60.4 in the rollup group across 1 directory (#26641)
  • deps: bump open from 8.4.0 to 8.4.2 (#26643)
  • deps: bump stream-json and @types/stream-json (#26645)
  • deps: bump koa-helmet from 7.0.2 to 7.1.0 (#26642)
  • deps: bump axios from 1.17.0 to 1.18.0 (#26647)
  • deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
  • deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
  • deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
  • deps-dev: bump @types/webpack-hot-middleware from 2.25.9 to 2.25.12 (#26568)
  • deps-dev: bump @types/invariant from 2.2.36 to 2.2.37 (#26644)
  • repo: skip change freeze ownership check when freeze disabled (#26474)
💅 Enhancement
  • admin: hide deploy-now widget in production (#26660)
  • core/core: rounded thin borders for startup banner (#26273)
  • graphql: use discriminated unions instead of unsafe type casting (#25913)
  • upgrade: unhide and document upgrade to command (#26446)
🚨 Security
  • deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
  • deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
❤️ Thank You
  • Adrien L @Adzouz
  • Andrei L @unrevised6419
  • Andrei Varapayeu @thisavoropaev
  • Arav Menon @Arav-Menon
  • Aurélien GEORGET
  • Ayoub Hidri @ayhid
  • Bassel Kanso @Bassel17
  • Ben Irvin
  • Dante Calderon @dantehemerson
  • DMehaffy
  • Giulio Montagner @giu1io
  • Jamie Howard @jhoward1994
  • Jasleen Kaur @Jasleen-Kaur96
  • Maksim Zhukau @MaksZhukov
  • Masamune Utsunomiya @masamunet
  • mathildeleg @mathildeleg
  • nclsndr
  • Nico André
  • Pierre Levavasseur @plevavas
  • Simon Norris @cache-your-dreams
  • Yazan Amer Abu Obaideh @yazan-abu-obaideh
  • Ziyi @butcherZ

View originalPermalink

v5.48.0
5.48.0 (2026-06-10)
🚀 New feature
  • add optional openapi spec route (#26239)
  • openapi: gate endpoint access with config (#26574)
🔥 Bug fix
  • upload returns unsigned URL on update media info (#25195)
  • widgets show error when role has no access to mainfield of ct (#26537)
  • admin: return empty object for empty json body in fetch client (#26277)
  • build: build does not run install; add install-deps arg (#26483)
  • ci: run build:size as full command for compressed-size-action v3 (#26556)
  • ci: restore allowed paths-filter pin (#26575)
  • content-manager: use ReadonlyArray for layout prop and fix Repeatable test fixture (#26522)
  • content-manager: raise z-index of code block language selector (#25010, #26324)
  • core: validate numeric inputs before DB unique checks (#26101)
  • database: restore join-table relation sort order in components (#26553)
  • database: avoid double finalising completed transactions (#26122)
  • upload: folder navigation bugs in Media Library (#26515)
  • upload: preserve animation frames in GIF and WebP images (#26126)
  • utils: ignore empty sort when building orderBy (#26427)
📚 Documentation Changes
  • openapi: add contributor documentation (#26410)
⚙️ Chore
  • remove experimental-dev example app (#26552)
  • update .gitignore for AI tooling directories (#26526)
  • deps: bump axios from 1.16.1 to 1.17.0 (#26539)
  • deps: bump the testing-library group across 1 directory with 2 updates (#26506)
  • deps: bump actions/setup-node from 4 to 6 (#26496)
  • deps: bump actions/stale from 10 to 10.2.0 (#26497)
  • deps: bump preactjs/compressed-size-action from 2 to 3 (#26498)
  • deps: resolve vulnerable transitive deps via lockfile dedupe and resolutions (#26540)
  • deps: bump cheerio from 1.0.0 to 1.2.0 (#26569)
  • deps: bump dorny/paths-filter from 3.0.3 to 4.0.1 (#26566)
  • deps: bump actions/download-artifact from 4.3.0 to 8.0.1 (#26564)
  • deps-dev: bump the eslint group across 1 directory with 10 updates (#26500)
  • deps-dev: bump @types/delegates from 1.0.0 to 1.0.3 (#26570)
  • deps-dev: bump the nx group across 1 directory with 2 updates (#26502)
  • repo: skip change freeze ownership check when freeze disabled (#26474)
💅 Enhancement
  • core/core: rounded thin borders for startup banner (#26273)
  • graphql: use discriminated unions instead of unsafe type casting (#25913)
  • upgrade: unhide and document upgrade to command (#26446)
🚨 Security
  • deps: patch uuid (GHSA-w5hq-g745-h8pq) and qs DoS advisories (9aef801f35)
  • deps: scope uuid/qs resolutions to affected descriptors (38b6831652)
❤️ Thank You
  • Andrei L @unrevised6419
  • Andrei Varapayeu @thisavoropaev
  • Arav Menon @Arav-Menon
  • Aurélien GEORGET
  • Ben Irvin
  • Dante Calderon @dantehemerson
  • Jamie Howard @jhoward1994
  • Maksim Zhukau @MaksZhukov
  • mathildeleg @mathildeleg
  • Nico André

View originalPermalink