This release includes 1 security fix for security teams reviewing exposed deployments.
Published 22d
Media Servers
✓ No known CVEs patched
This release patches 1 known CVE
Topics
docker
jellyfin
maintainerr
maintenance
movies
plex
+6 more
plex-media-server
radarr
seerr
sonarr
tv-series
tv-shows
Affected surfaces
deps
Summary
AI summaryUpdates Highlights, Internal, and Performance across a mixed release.
Full changelog
3.17.0 (2026-07-05)
Highlights
- Added new rule properties for Sonarr and Radarr, enabling advanced scoping and rolling window functionality (#3095, #3222, #3223).
- Fixed issues with library reconciliation and improved error handling for transient errors and unavailable dependencies (#3226).
- Addressed compatibility issues with older CPUs by ensuring the server continues to boot when certain libraries fail to load (#3184).
Features
- Added
seasonFileRankrule property for Sonarr, enabling season-level rolling windows (#3223). - Added
movieTitleandmovieIdrule properties for Radarr, allowing movie-specific scoping (#3222). - Added
episodeFileRankrule property for Sonarr withseriesTitleandseriesIdscoping (#3095).
Fixes
- Resolved validation error when adding seasons or episodes with hex-GUIDs to collections in Jellyfin (#3225).
- Improved clarity of rule-builder labels for rank properties (#3224).
- Fixed misleading messaging for automatic collections when a library is missing (#3203, #3211).
- Hardened library reconciliation against transient errors and clarified messaging for unavailable dependencies (#3226).
- Ensured server boots even when
sharplibrary fails to load on pre-x86-64-v2 CPUs (#3184).
Performance
- Patched vulnerable transitive dependencies, including
multer,dompurify, andlinkify-it, via resolutions (#3201).
Database migrations
- Backfilled the
operatorfield in stored rules to ensure explicit values for section and within-section operators, preserving existing behavior.
Internal
- Addressed a potential code scanning alert related to untrusted checkout in GitHub Actions (#3209).
Dependencies
- Updated 28 dependencies, including
sharp,typescript-eslint,prettier, andeslint.
New Contributors
- @jackemcpherson made their first contribution in https://github.com/Maintainerr/Maintainerr/pull/3095
Security Fixes
- Patched vulnerable transitive dependencies: multer, dompurify, linkify-it
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Maintainerr
Looks and smells like Seerr, does the opposite. A library maintenance tool for Plex and Jellyfin.
Related context
Related tools
Earlier breaking changes
- v3.13.0 Section without an operator is now treated as OR instead of AND; migration not reversible.
- v3.13.0 Per-group exclusions now apply only to their own group, not globally.
- v3.13.0 Exclusions are now either global or per-group; removing a global exclusion requires re-adding per-group ones.
- v3.12.1 Renames `WATCH_HISTORY_CONCURRENCY` to `RULE_EVALUATION_CONCURRENCY` for clarity.
- v3.11.0 Overlay reset operations are now gated against concurrent processing runs.
Beta — feedback welcome: [email protected]