This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryAdded per-item visibility options for tasks and calendar events with three sharing levels.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Enforces server-side visibility checks on every read path with no admin bypass. Enforces server-side visibility checks on every read path with no admin bypass. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Medium |
Adds per-item visibility options for tasks and calendar events: all family members, assignees only, or private. Adds per-item visibility options for tasks and calendar events: all family members, assignees only, or private. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds "Assigned to me" quick filter on Tasks and Calendar views, remembered per device. Adds "Assigned to me" quick filter on Tasks and Calendar views, remembered per device. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds default assignee setting per calendar sync target in Settings → Sync for new imported events. Adds default assignee setting per calendar sync target in Settings → Sync for new imported events. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Added
- Per-item visibility for tasks and calendar events: choose "all family members" (default), "assignees only", or "private" (only you). Enforced server-side on every read path — list, detail, dashboard, search, and MCP — with no admin bypass, so a private item stays hidden even from a parent/admin (useful for preparing a surprise). Restricted items carry a lock/people icon in the list, and the event export feed is deliberately not filtered by it. (Discussion #474)
- "Assigned to me" quick filter on the Tasks and Calendar views: one toggle limits the list to items assigned to you, remembered per device and shown only in multi-member households. (Discussion #472)
- Default assignee per calendar sync target: give each synced Google/CalDAV calendar or ICS subscription an optional default person in Settings → Sync, and newly imported events of that target are automatically assigned to them (new events only, never retroactively). (Discussion #459)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v0.71.3 Changes WebDAV backup default path from "/oikos/backups/" to "/yuvomi/backups/".
- v0.66.0 Repository URL changed to `https://github.com/ulsklyc/yuvomi`.
- v0.66.0 Docker image moved to `ghcr.io/ulsklyc/yuvomi`.
- v0.66.0 Project renamed from Oikos to Yuvomi.
- v0.62.0 Changes event dialog to unified sync target picker across Google and CalDAV calendars.
Beta — feedback welcome: [email protected]