Skip to content

Halo

Productivity & Wikis

An open‑source, easy‑to‑use website building tool for blogs, knowledge bases, corporate sites and online stores.

Java Latest v2.24.2 · 1mo ago Security brief →

Features

  • Supports personal blogs, knowledge libraries, enterprise websites and e‑commerce shops in one platform
  • Provides a free community edition with over 100 free themes and plugins under GPLv3
  • Offers professional and commercial editions adding mobile app management, AI site generation, private deployment, paid marketplace and full online store capabilities

Recent releases

View all 33 releases →
v2.24.2 Bug fix
Notable features
  • Improved UA parsing accuracy in login device management
Full changelog

功能优化

  • 提升登录设备管理中 UA 信息解析的准确性 by @JohnNiang in https://github.com/halo-dev/halo/pull/9921

问题修复

  • 解决“保持登录会话”功能在特定情况下可能失效的问题 by @JohnNiang in https://github.com/halo-dev/halo/pull/9928
  • 修复通过 URL 下载大文件(如插件安装包)时因响应体大小限制导致下载失败的问题 by @JohnNiang in https://github.com/halo-dev/halo/pull/9931
  • 修复通过 PostFinder#random 随机获取文章时可能返回少于请求的文章的问题 by @JohnNiang in https://github.com/halo-dev/halo/pull/9932

Full Changelog: https://github.com/halo-dev/halo/compare/v2.24.1...v2.24.2

v2.24.1 Security relevant
Security fixes
  • Improved target URL validation for personal center attachment uploads via URL, mitigating server request abuse risk (reported by JD-Security SHENYI Team).
Notable features
  • Added `random` method to `PostFinder` for retrieving random articles
Full changelog

安全性修复

  • 加强了个人中心通过 URL 上传附件时的目标地址校验,降低服务端请求被滥用的风险

问题修复

  • 修复登录时勾选记住我后撤销设备后不起作用的问题 by @JohnNiang in https://github.com/halo-dev/halo/pull/9899
  • 修复 2.24.0 自动为主题资源加版本参数功能在部分边缘场景下路径拼接错误的问题 by @ruibaby in https://github.com/halo-dev/halo/pull/9897

开发者相关

  • PostFinder 添加 random 方法以支持随机获取文章 by @JohnNiang in https://github.com/halo-dev/halo/pull/9918

致谢

感谢 JD-Security SHENYI Team 报告的安全漏洞。

Full Changelog: https://github.com/halo-dev/halo/compare/v2.24.0...v2.24.1

v2.24.0 Bug fix
Notable features
  • Plugin detail page management improvements
  • Reload plugin support in Console plugin management
  • Select current role when creating personal token
Full changelog

新特性

功能优化

问题修复

开发者相关

依赖更新

Full Changelog: https://github.com/halo-dev/halo/compare/v2.23.2...v2.24.0

v2.23.3 Bug fix

Fixed creation of articles to allow setting an author.

Full changelog

问题修复

  • 修复编辑器图片、视频、音频类型的对齐图标显示不正确的问题 by @ruibaby in https://github.com/halo-dev/halo/pull/9852
  • 修复创建文章时无法设置作者的问题 by @ruibaby in https://github.com/halo-dev/halo/pull/9862
  • 修复部分包含 Finder API 的插件可能在升级后无法正常启动的问题 by @ruibaby in https://github.com/halo-dev/halo/pull/9853
  • 修复附件插件未实现缩略图生成功能时出现大量警告日志的问题 by @JohnNiang in https://github.com/halo-dev/halo/pull/9878

Full Changelog: https://github.com/halo-dev/halo/compare/v2.23.2...v2.23.3

v2.23.2 Bug fix
⚠ Upgrade required
  • Upgraded Spring Boot to version 4.0.4
Full changelog

问题修复

  • 解决当富文本编辑器中嵌套其他编辑器时所导致的异常滚动问题 by @LIlGG in https://github.com/halo-dev/halo/pull/8436
  • 解决 FormKit Array 渲染图片时可能出现的报错问题 by @LIlGG in https://github.com/halo-dev/halo/pull/8495
  • 修复 FormKit Iconify 自定义图片时,表单可能出现自动关闭的问题 by @ruibaby in https://github.com/halo-dev/halo/pull/8497

依赖更新

  • 升级 Spring Boot 至 4.0.4 by @JohnNiang in https://github.com/halo-dev/halo/pull/8434

开发者相关

  • 修复标签归档页面缺少 _templateId 变量的问题 by @Copilot in https://github.com/halo-dev/halo/pull/8485

Full Changelog: https://github.com/halo-dev/halo/compare/v2.23.1...v2.23.2

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
38,790
Forks
10,271
Languages
Java TypeScript Vue
Downloads/week
743 ↑24%
NPM Maintainers
2
Contributors
169
TypeScript
Types included ✓

Install & Platforms

Install via
docker
Platforms
linux

Community & Support

Beta — feedback welcome: [email protected]