Skip to content

ghostfolio

v3.30.0 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

angular etf finance fintech ghostfolio investing
+11 more
nestjs personal-finance portfolio prisma software stock tracker trading typescript wealth-management web

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 7d

Version 3.30.0 removes the deprecated GET /auth endpoint that accepted security tokens for login.

Why it matters: All clients using the deprecated authentication flow must migrate before the removal takes effect; failure will cause login failures.

Summary

AI summary

Removed the deprecated auth endpoint for security token login.

Changes in this release

Security High

Restricts symbol data endpoint to authenticated users

Restricts symbol data endpoint to authenticated users

Source: llm_adapter@2026-07-19

Confidence: high

Feature Low

Adds support for converting an asset profile to the MANUAL data source in admin control panel dialog

Adds support for converting an asset profile to the MANUAL data source in admin control panel dialog

Source: llm_adapter@2026-07-19

Confidence: high

Feature Low

Extends extractNumberFromString() to support negative values

Extends extractNumberFromString() to support negative values

Source: llm_adapter@2026-07-19

Confidence: high

Dependency Low

Upgraded bull-board from version 8.0.1 to 8.1.2

Upgraded bull-board from version 8.0.1 to 8.1.2

Source: llm_adapter@2026-07-19

Confidence: high

Deprecation High

Removes deprecated auth endpoint for login with Security Token

Removes deprecated auth endpoint for login with Security Token

Source: llm_adapter@2026-07-19

Confidence: high

Refactor Low

Simplifies getHistorical() function response in data provider interface

Simplifies getHistorical() function response in data provider interface

Source: llm_adapter@2026-07-19

Confidence: high

Full changelog

Added

  • Added support for converting an asset profile to the MANUAL data source in the asset profile details dialog of the admin control panel

Changed

  • Extended the extractNumberFromString() function to support negative values
  • Restricted the symbol data endpoint (GET /api/v1/symbol/:dataSource/:symbol) to authenticated users
  • Removed the deprecated auth endpoint of the login with Security Token (GET)
  • Simplified the getHistorical() function response in the data provider interface
  • Upgraded bull-board from version 8.0.1 to 8.1.2

Special Thanks

  • @arhxam
  • @dtslvr
  • @KenTandrian

Breaking Changes

  • Removed the deprecated `auth` endpoint of the login with _Security Token_ (`GET`).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ghostfolio

Get notified when new releases ship.

Sign up free

About ghostfolio

Open Source Wealth Management Software. Angular + NestJS + Prisma + Nx + TypeScript

All releases →

Related context

Earlier breaking changes

  • v3.25.0 Changed default DATA_SOURCE_FEAR_AND_GREED_INDEX_STOCKS from RAPID_API to MANUAL

Beta — feedback welcome: [email protected]