This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
ReleasePort's take
Light signalThe July 2026 release of NocoDB adds multiple new features including Calendar Sync for Google, Outlook, and CalDAV; Image Annotations on attachments; Workflow Comment Triggers; comment‑action webhooks; checksum formula functions (MD5, SHA256, SHA512); localized date formatting via DATETIME_FORMAT(); sortable/limited Lookup fields in PostgreSQL; Persian calendar support; and iCalendar (.ics) export for Calendar views.
Why it matters: These feature additions expand integrations, improve data handling, and enhance reporting capabilities across developers, SREs, and security engineers managing NocoDB deployments.
Summary
AI summaryBroad release touches Improvements & Fixes, Self-Hosting, https://nocodb.com/docs/product-docs/records/expand-record, and https://nocodb.com/docs/product-docs/views/view-types/calendar.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Tightens network access controls for external resource connections. Tightens network access controls for external resource connections. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Security | Medium |
Reinforces data access controls to keep information visible only to authorized users. Reinforces data access controls to keep information visible only to authorized users. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Security | Medium |
Improves input validation throughout the platform for more robust handling. Improves input validation throughout the platform for more robust handling. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Adds Calendar Sync feature for Google, Outlook, CalDAV calendars. Adds Calendar Sync feature for Google, Outlook, CalDAV calendars. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds Image Annotations to comment on exact spots of images. Adds Image Annotations to comment on exact spots of images. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds Workflow Comment Trigger for comment‑related workflow events. Adds Workflow Comment Trigger for comment‑related workflow events. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Allows attaching files and images to comments. Allows attaching files and images to comments. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Enables webhooks triggered by comment actions (add, edit, delete, resolve, reopen). Enables webhooks triggered by comment actions (add, edit, delete, resolve, reopen). Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Introduces MD5(), SHA256(), and SHA512() checksum formula functions. Introduces MD5(), SHA256(), and SHA512() checksum formula functions. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds DATETIME_FORMAT() for localized date formatting in formulas. Adds DATETIME_FORMAT() for localized date formatting in formulas. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Allows sorting and limiting values of Lookup fields (PostgreSQL). Allows sorting and limiting values of Lookup fields (PostgreSQL). Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Supports Persian (Jalali) calendar display in Date and DateTime fields. Supports Persian (Jalali) calendar display in Date and DateTime fields. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Enables exporting Calendar views as .ics iCalendar files. Enables exporting Calendar views as .ics iCalendar files. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds custom timescale mode to calendars (any number of days or weeks). Adds custom timescale mode to calendars (any number of days or weeks). Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Provides event themes (Bordered, Dot, Solid, Minimal, Pill) for calendar views. Provides event themes (Bordered, Dot, Solid, Minimal, Pill) for calendar views. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Renders calendar views on mobile devices with compact toolbar and sidebar. Renders calendar views on mobile devices with compact toolbar and sidebar. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Allows skipping unwanted sheets during Excel import. Allows skipping unwanted sheets during Excel import. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Enables creation of new fields while importing data into an existing table. Enables creation of new fields while importing data into an existing table. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Increases comment length limit from 3,000 to 10,000 characters. Increases comment length limit from 3,000 to 10,000 characters. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Allows Lookup fields to drive form field visibility conditions. Allows Lookup fields to drive form field visibility conditions. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Shows field descriptions in expanded record and shared views via info icon. Shows field descriptions in expanded record and shared views via info icon. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Accepts unpadded dates (e.g., 5/5/2026) in MM/DD/YYYY fields without dropping them. Accepts unpadded dates (e.g., 5/5/2026) in MM/DD/YYYY fields without dropping them. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Keeps Multi-Select values alphabetically ordered when "Alphabetize" is enabled. Keeps Multi-Select values alphabetically ordered when "Alphabetize" is enabled. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Derives self‑hosted plan tier directly from signed license, fixing mis‑detected Enterprise features. Derives self‑hosted plan tier directly from signed license, fixing mis‑detected Enterprise features. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Falls back to Community behavior when an Enterprise trial expires instead of blocking UI. Falls back to Community behavior when an Enterprise trial expires instead of blocking UI. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Allows invited users to set a password during sign‑up when email & password login is enabled alongside SSO. Allows invited users to set a password during sign‑up when email & password login is enabled alongside SSO. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Introduces NC_ALLOW_LOCAL_DATA_IMPORT and NC_AI_* environment variables for configuration tuning. Introduces NC_ALLOW_LOCAL_DATA_IMPORT and NC_AI_* environment variables for configuration tuning. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Performance | Low |
Reads image dimensions from headers instead of decoding full images, speeding up uploads. Reads image dimensions from headers instead of decoding full images, speeding up uploads. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Bugfix | Medium |
Handles permanent deletion of records with formula or link fields whose config was already cleaned up. Handles permanent deletion of records with formula or link fields whose config was already cleaned up. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Bugfix | Low |
Prevents log flooding when an external data source becomes unreachable during formula re‑validation. Prevents log flooding when an external data source becomes unreachable during formula re‑validation. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
Full changelog
Availability
| Feature | CE / Free | Paid / Enterprise |
|---|:---:|:---:|
| Calendar Sync | – | ✅ |
| Image Annotations | – | ✅ |
| Workflow Comment Trigger | – | ✅ |
Calendar Sync
Calendar Sync brings events from Google Calendar, Outlook Calendar, or any CalDAV server (Apple iCloud, Fastmail, Nextcloud, and others) into NocoDB as a read-only Event table that stays up to date on its own. Pick a calendar and a date window from the new Calendar category in the App Sync wizard; NocoDB syncs the event details and sets up a colour-coded Calendar view on the first sync. Available on NocoDB Cloud (Plus plan and above) and licensed self-hosted deployments (Business plan and above).
Learn more about Calendar Sync →
Image Annotations
Image annotations let a comment point at an exact spot on an image instead of describing it in words. Open an image in the attachment viewer, drop a pin or drag a rectangle, and leave your comment; annotations are labelled, and replies thread underneath. Available on all NocoDB Cloud plans and licensed self-hosted deployments.
Workflow Comment Trigger
When comment changes is a new workflow trigger that runs a workflow when a comment is added, edited, deleted, resolved, or reopened on a record. Narrow it to specific comment events or to comments that mention particular people, and use the comment, its author, and mentions in later steps. Available on all NocoDB Cloud plans and licensed self-hosted deployments (Business plan and above).
Learn more about the comment trigger →
Improvements & Fixes
- Attach files to comments. Comments now take images and files, added from the file picker, pasted straight in, or dropped onto the composer. Available on NocoDB Cloud (Plus plan and above) and licensed self-hosted deployments (Business plan and above). Learn more →
- Trigger webhooks from comments. Webhooks can now fire when a comment is added, edited, deleted, resolved, or reopened, and can be narrowed to comments that mention a particular person or exclude comments posted by your own integrations. Learn more →
- Checksum formulas. New
MD5(),SHA256(), andSHA512()functions compute a hash of any value, useful for checksums and spotting changed records. Available on PostgreSQL and MySQL. Learn more → - Localized date formatting in formulas. A new
DATETIME_FORMAT()function formats a date or datetime into text, including the localizedLL,LLL, andLLLLpresets. Learn more → - Sort and limit Lookup values. A Lookup field can now sort the values it pulls in and show only the first or last few, instead of every linked value. Available on PostgreSQL, on NocoDB Cloud (Plus plan and above) and licensed self-hosted deployments (Business plan and above). Learn more →
- Persian (Jalali) calendar. Date and DateTime fields can display and accept dates in the Jalali calendar by picking one of the new Jalali date formats; values are still stored as standard dates underneath. Learn more →
- Export a calendar as .ics. Calendar views can be downloaded as an iCalendar (.ics) file and opened in any calendar app. Learn more →
- Custom calendar timescale. Alongside day, week, and month, calendars now offer a Custom mode that shows any number of days or weeks from one to six. Learn more →
- Event themes for calendars. Choose how event chips look with five themes, Bordered, Dot, Solid, Minimal, and Pill, set per view from the calendar toolbar. Available on NocoDB Cloud paid plans and licensed self-hosted deployments. Learn more →
- Calendar views on mobile. Calendar views now render and navigate properly on phones, with a compact toolbar and a record sidebar for busy days.
- Skip sheets when importing Excel. Multi-sheet workbooks now let you untick the sheets you don't want before importing, rather than importing everything and cleaning up after.
- Create new fields while importing. When importing into an existing table, unmatched columns can be mapped to a brand new field instead of only to existing fields or dropped.
- Longer comments. The comment length limit was raised from 3,000 to 10,000 characters.
- Lookup fields as form conditions. A form field's "Show on conditions" rule can now be driven by a Lookup field, so a question can appear based on data from the linked record the respondent picks. Learn more →
- Field descriptions in the expanded record. Fields with a description now show an info icon in the expanded record and in shared views; hover it to read the description.
- Unpadded dates are no longer dropped. Typing or pasting a date like
5/5/2026into aMM/DD/YYYYfield is now accepted and normalised, where before it was silently discarded and could clear an existing value. - Alphabetized multi-select values. With "Alphabetize" enabled, the values stored in a Multi Select cell are now kept in alphabetical order, not just the option list. Existing records are re-sorted the next time they are saved.
Security
- Network access. Tighter controls over how NocoDB connects to external resources.
- Data access controls. Reinforced protections that keep information visible only to those authorised to see it.
- Input handling. More robust validation throughout the platform.
Self-Hosting
- On-prem plans resolve from the license itself. The plan for a self-hosted deployment is now derived from the signed license type rather than optional metadata, so each install gets exactly the tier it is licensed for. Deployments activated through a marketplace, an admin-issued key, or a legacy key without that metadata could previously fall back to Enterprise features they were not licensed for and will now resolve to their actual plan. Expired legacy Enterprise trial licenses no longer grant Enterprise features. This release ships a database migration to record the license type on existing plans.
- Expired trials no longer lock you out. When an Enterprise trial expires, the instance now falls back to Community behaviour with paid features gated, instead of covering the interface with a full-screen blocking overlay.
- Email and password sign-up alongside SSO. With "Allow email & password sign-in alongside SSO" enabled, invited users can now set a password from the sign-up page, not just the sign-in page.
- Lighter image processing. Attachment dimensions are now read straight from image headers instead of decoding the full image, so uploads are quicker and gentler on the server.
- New configuration options.
NC_ALLOW_LOCAL_DATA_IMPORTopts in to importing from local or private hosts, and a set ofNC_AI_*options tune the AI chat's record and token budgets. Learn more → - Reliability improvements. Permanently deleting records now handles formula and link fields whose configuration was already cleaned up, and an unreachable external data source no longer floods the logs while re-validating formulas.
Deprecation Notice
As announced in 2026.06.1, this release no longer publishes pre-built executables. If you currently run NocoDB from an executable, switch to Docker or another supported installation method to keep receiving updates.
Breaking Changes
- Pre‑built executables are no longer published; self‑hosted installations must switch to Docker or another supported method.
Security Fixes
- Tighter network access controls, reinforced data access protections, and more robust input validation across the platform.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]