Skip to content

Maintainerr

v3.17.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 22d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

docker jellyfin maintainerr maintenance movies plex
+6 more
plex-media-server radarr seerr sonarr tv-series tv-shows

Affected surfaces

deps

Summary

AI summary

Updates Highlights, Internal, and Performance across a mixed release.

Full changelog

3.17.0 (2026-07-05)

Highlights

  • Added new rule properties for Sonarr and Radarr, enabling advanced scoping and rolling window functionality (#3095, #3222, #3223).
  • Fixed issues with library reconciliation and improved error handling for transient errors and unavailable dependencies (#3226).
  • Addressed compatibility issues with older CPUs by ensuring the server continues to boot when certain libraries fail to load (#3184).

Features

  • Added seasonFileRank rule property for Sonarr, enabling season-level rolling windows (#3223).
  • Added movieTitle and movieId rule properties for Radarr, allowing movie-specific scoping (#3222).
  • Added episodeFileRank rule property for Sonarr with seriesTitle and seriesId scoping (#3095).

Fixes

  • Resolved validation error when adding seasons or episodes with hex-GUIDs to collections in Jellyfin (#3225).
  • Improved clarity of rule-builder labels for rank properties (#3224).
  • Fixed misleading messaging for automatic collections when a library is missing (#3203, #3211).
  • Hardened library reconciliation against transient errors and clarified messaging for unavailable dependencies (#3226).
  • Ensured server boots even when sharp library fails to load on pre-x86-64-v2 CPUs (#3184).

Performance

  • Patched vulnerable transitive dependencies, including multer, dompurify, and linkify-it, via resolutions (#3201).

Database migrations

  • Backfilled the operator field in stored rules to ensure explicit values for section and within-section operators, preserving existing behavior.

Internal

  • Addressed a potential code scanning alert related to untrusted checkout in GitHub Actions (#3209).

Dependencies

  • Updated 28 dependencies, including sharp, typescript-eslint, prettier, and eslint.

New Contributors

  • @jackemcpherson made their first contribution in https://github.com/Maintainerr/Maintainerr/pull/3095

Security Fixes

  • Patched vulnerable transitive dependencies: multer, dompurify, linkify-it

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Maintainerr

Get notified when new releases ship.

Sign up free

About Maintainerr

Looks and smells like Seerr, does the opposite. A library maintenance tool for Plex and Jellyfin.

All releases →

Related context

Earlier breaking changes

  • v3.13.0 Section without an operator is now treated as OR instead of AND; migration not reversible.
  • v3.13.0 Per-group exclusions now apply only to their own group, not globally.
  • v3.13.0 Exclusions are now either global or per-group; removing a global exclusion requires re-adding per-group ones.
  • v3.12.1 Renames `WATCH_HISTORY_CONCURRENCY` to `RULE_EVALUATION_CONCURRENCY` for clarity.
  • v3.11.0 Overlay reset operations are now gated against concurrent processing runs.

Beta — feedback welcome: [email protected]