Skip to content

Release history

papra releases

The minimalistic document archiving platform.

All releases

13 shown

Upgrade now
@papra/[email protected] Breaking risk
Auth RBAC Dependencies

Tag scope + webhook redirects + upload limit

No immediate action
@papra/[email protected] Maintenance

Routine maintenance and dependency updates.

Upgrade now
@papra/[email protected] Maintenance
Dependencies

Routine maintenance and dependency updates.

@papra/[email protected] Breaking risk
Breaking changes
  • Webhooks pointing to private or reserved IP addresses are now blocked unless explicitly listed in WEBHOOK_URL_ALLOWED_HOSTNAMES config
Security fixes
  • GHSA-cjw7-qg95-58mq: SSRF protection for webhook URLs
  • GHSA-866c-mc22-wvv5: Removed unsafe expiresAt placeholder fields in API key creation endpoint
  • GHSA-6f8x-2rc9-vgh4: Sanitized user names in email content to prevent XSS/HTML injection
Notable features
  • SSRF protection for webhook URLs with configurable allowlist via WEBHOOK_URL_ALLOWED_HOSTNAMES
  • Improved error handling returning 409 status code for duplicate tags instead of 400 or 500 errors
@papra/[email protected] New feature
Breaking changes
  • Distribution package renamed from @papra/docker to @papra/app
Notable features
  • Auto-admin role assignment
  • Tag date-based ordering
  • Multi-language support
@papra/[email protected] Breaking risk
Breaking changes
  • Document search endpoint response structure changed - searchResults nesting removed, results now at top level with totalCount
Notable features
  • Two-factor authentication
  • Advanced search syntax
  • Search index improvements

Beta — feedback welcome: [email protected]