This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
ReleasePort's take
Light signalVersion 1.20.0 introduces a resource launcher page with savable views and a global command palette for navigation, plus new geoblocking options.
Why it matters: These UI enhancements improve discoverability and workflow efficiency across the dashboard; operators should review updated navigation paths before deployment.
Summary
AI summaryAdd a resource launcher page, global command palette, and country‑not geoblocking rule.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds resource launcher page with configurable, savable views for all users Adds resource launcher page with configurable, savable views for all users Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds global command palette to navigate dashboard and search sites/resources Adds global command palette to navigate dashboard and search sites/resources Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds "Country Is Not" matching type to resource geoblocking rules Adds "Country Is Not" matching type to resource geoblocking rules Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds username field to VNC auth form, enabling macOS compatibility Adds username field to VNC auth form, enabling macOS compatibility Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Improves private resource edit and create UI consistency by migrating from dialog to dedicated pages Improves private resource edit and create UI consistency by migrating from dialog to dedicated pages Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Releases EE feature gate on labels, making the labels feature generally available Releases EE feature gate on labels, making the labels feature generally available Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | Low |
Updates dependencies for security patches Updates dependencies for security patches Source: llm_adapter@2026-07-16 Confidence: low |
— |
| Bugfix | Medium |
Fixes redirect back to resource after completing session expired checkpoint Fixes redirect back to resource after completing session expired checkpoint Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
Read the 1.20 Announcement
Read the full announcement with discussion of new features: Pangolin 1.20: Resource Launcher & Global Command Palette
What's Changed
- Add resource launcher page with configurable and savable views; available to non-admins and admins
- Add global command palette to navigate the dashboard and search for sites and resources
- Add
Country Is Notmatching type to resource geoblocking rules - Add username field to VNC auth form; now works with macOS
- Improve private resource edit and create UI consistency to match dashboard UX patterns (migrate from dialog to dedicated pages)
- Release EE feature gate on labels feature
- Fix redirect back to resource after completing session expired checkpoint
- Dependency security updates
- General UI improvements
- Various other bug fixes
New Contributors
- @jaisinha77777 made their first contribution in https://github.com/fosrl/pangolin/pull/3369
Full Changelog: https://github.com/fosrl/pangolin/compare/1.19.4...1.20.0
How to Update
[!IMPORTANT]
Always back up your config app-data before updating. This will allow you to easily roll back if the update breaks your configuration. You will not be able to easily downgrade otherwise.
Security Fixes
- Dependency security updates applied
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]