This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
ReleasePort's take
Moderate signalTailwind CSS is upgraded from v3 to v4 in this release; several bug‑fixes and dependency bumps are also included.
Why it matters: Upgrading Tailwind CSS to version 4 introduces new features and cascade fixes that affect UI styling pipelines. Developers must review component configurations after migration.
Summary
AI summaryUpdates fix, deps, and feat across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Migrate Tailwind CSS from v3 to v4 (second attempt with cascade fix) Migrate Tailwind CSS from v3 to v4 (second attempt with cascade fix) Source: llm_adapter@2026-05-23 Confidence: high |
— |
| Dependency | Medium |
Bump ws from 8.18.2 to 8.20.1 Bump ws from 8.18.2 to 8.20.1 Source: llm_adapter@2026-05-23 Confidence: low |
— |
| Dependency | Medium |
Bump js-cookie from 3.0.5 to 3.0.7 Bump js-cookie from 3.0.5 to 3.0.7 Source: llm_adapter@2026-05-23 Confidence: low |
— |
| Bugfix | Medium |
Cap QR-login auto-refresh and add pause overlay Cap QR-login auto-refresh and add pause overlay Source: llm_adapter@2026-05-23 Confidence: high |
— |
| Bugfix | Medium |
Canonicalize media_path and enforce boundary check in media browser Canonicalize media_path and enforce boundary check in media browser Source: llm_adapter@2026-05-23 Confidence: high |
— |
Full changelog
What's Changed
- docs: clarify scheduler is auto-installed by koel:init by @phanan in https://github.com/koel/koel/pull/2487
- feat: migrate Tailwind CSS from v3 to v4 (second attempt with cascade fix) by @phanan in https://github.com/koel/koel/pull/2488
- refactor: replace overflowFade directive with CSS scroll-mask utility by @phanan in https://github.com/koel/koel/pull/2490
- fix: cap QR-login auto-refresh and add pause overlay by @phanan in https://github.com/koel/koel/pull/2491
- chore(deps): bump ws from 8.18.2 to 8.20.1 by @dependabot[bot] in https://github.com/koel/koel/pull/2489
- chore(deps): bump js-cookie from 3.0.5 to 3.0.7 by @dependabot[bot] in https://github.com/koel/koel/pull/2493
- fix: canonicalize media_path and enforce boundary check in media browser by @phanan in https://github.com/koel/koel/pull/2492
Full Changelog: https://github.com/koel/koel/compare/v9.3.5...v9.3.6
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]