Skip to content

mealie

v3.22.0 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

Published 11h Productivity & Wikis
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

meal-plans recipe-manager self-hosted

Affected surfaces

auth

Summary

AI summary

Broad release touches 🧰 Maintenance, ⬆️ Dependency updates, l10n, and deps.

Full changelog

🍴🍴🍴🍴🍴🍴

The previous version of Mealie (v3.21.0) introduced a ⚠️BREAKING CHANGE⚠️ for instances using OIDC: Mealie now requires your OIDC provider to confirm the user's email address before allowing the login. This prevents an unverified, self-asserted email address from being used to match (and sign in) to an existing Mealie account.

If an identity provider does not emit the email_verified claim, logins now fail. If you cannot configure your identity provider to include the email_verified claim, you can set OIDC_REQUIRES_EMAIL_VERIFICATION to false (this is not recommended per the above security concerns). See the docs for more details.

πŸŽ‰ Highlights

New to this release, many improvements have been made to make importing recipes more reliable. Mealie does a better job of looking like a real browser, rotates between several browser signatures, and retries more intelligently when a site pushes back. This works out of the box, with no configuration.

For sites sitting behind extra bot protection (such as Cloudflare) server admins have two additional controls:

  • Proxy support, which routes recipe and image requests through a proxy. This helps with sites that block your server's IP address.
  • FlareSolverr support, which hands the page to a real headless browser as a last resort. This helps with challenges that Mealie can't get past on its own.

Both require additional configuration to work. Mealie does not ship or manage either one. You supply the proxy, and host FlareSolverr yourself (it runs nicely as a sidecar container). See the configuration docs for the settings, setup details, and an example compose file.

✨ New features

  • feat: Improve scraper resiliency and add both proxy and FlareSolverr support @michael-genson (#7953)
  • feat: Add feedback for bad JSON in HTML-JSON page @michael-genson (#7956)
  • feat: Announce OIDC email change and announce new scraper capabilities @michael-genson (#7963)

πŸ› Bug fixes

  • fix: Clear InputLabelType item-id as null instead of empty string @lehnerpat (#7950)

🧰 Maintenance

5 changes
  • chore(l10n): New Crowdin updates @hay-kot (#7943)
  • chore(l10n): New Crowdin updates @hay-kot (#7945)
  • chore(l10n): Crowdin locale sync @mealie-actions[bot] (#7948)
  • chore(l10n): New Crowdin updates @hay-kot (#7952)
  • chore(l10n): New Crowdin updates @hay-kot (#7960)

πŸ”¨ Internal development

  • dev: Update front end unit test dependencies @miah120 (#7949)

⬆️ Dependency updates

5 changes
  • chore(deps): update dependency js-yaml to v5.2.2 [security] @renovate[bot] (#7951)
  • chore(deps): update dependency pre-commit to v4.6.1 @renovate[bot] (#7955)
  • chore(deps): lock file maintenance @renovate[bot] (#7958)
  • fix(deps): update dependency pillow-heif to v1.5.0 @renovate[bot] (#7959)
  • fix(deps): update dependency openai to v2.47.0 @renovate[bot] (#7962)

🍴🍴🍴🍴🍴🍴

Breaking Changes

  • OIDC now requires the `email_verified` claim; logins fail without it unless `OIDC_REQUIRES_EMAIL_VERIFICATION` is set to false.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track mealie

Get notified when new releases ship.

Sign up free

About mealie

Mealie is a self hosted recipe manager and meal planner with a RestAPI backend and a reactive frontend application built in Vue for a pleasant user experience for the whole family. Easily add recipes into your database by providing the url and mealie will automatically import the relevant data or add a family recipe with the UI editor

All releases β†’

Related context

Related tools

Beta — feedback welcome: [email protected]