This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryGranular server‑enforced roles and permissions for family members.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds granular roles and permissions for server-enforced access control. Adds granular roles and permissions for server-enforced access control. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Supports per-family role and per-member access levels (No access, Read only, Full). Supports per-family role and per-member access levels (No access, Read only, Full). Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Allows per-dashboard widget settings: Available or Blocked. Allows per-dashboard widget settings: Available or Blocked. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Widget access inherits from its module's lock but can be overridden individually. Widget access inherits from its module's lock but can be overridden individually. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Stores only deviations from the default (full access) to preserve existing configurations. Stores only deviations from the default (full access) to preserve existing configurations. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Administrators retain full access and cannot be locked out. Administrators retain full access and cannot be locked out. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Blocked modules are hidden from navigation and the dashboard. Blocked modules are hidden from navigation and the dashboard. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Read‑only modules hide create buttons and show an explanatory banner. Read‑only modules hide create buttons and show an explanatory banner. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Settings page includes role/member switch, at‑a‑glance overview of deviations, and icon controls for per-module and per-widget access. Settings page includes role/member switch, at‑a‑glance overview of deviations, and icon controls for per-module and per-widget access. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
Full changelog
Added
- Roles and permissions: granular, server-enforced access control per family role and per member, configured under Settings → Administration → Roles and permissions. Each module can be set to No access, Read only, or Full, and each dashboard widget to Available or Blocked; widgets inherit their module's lock and can also be blocked on their own (for example, hiding the cycle widget for some members without disabling Health). Only deviations from the default (full access) are stored, so unset roles and members keep full access and existing installs are unchanged; administrators always keep full access and cannot be locked out. Blocked modules disappear from navigation and the dashboard, and a read-only module hides its create button and shows an explanatory banner. The settings page offers a role/member switch, an at-a-glance overview of a role's deviations, and per-module and per-widget access as icon controls with widgets nested under their module. (#467)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v0.71.3 Changes WebDAV backup default path from "/oikos/backups/" to "/yuvomi/backups/".
- v0.66.0 Repository URL changed to `https://github.com/ulsklyc/yuvomi`.
- v0.66.0 Docker image moved to `ghcr.io/ulsklyc/yuvomi`.
- v0.66.0 Project renamed from Oikos to Yuvomi.
- v0.62.0 Changes event dialog to unified sync target picker across Google and CalDAV calendars.
Beta — feedback welcome: [email protected]