9 hours ago
grafana

13.0.7

Download page What's new highlights

Security

  • CVE-2026-17183

Bug fixes

  • Reporting: batch dashboard lookups when listing reports (Enterprise)
9 hours ago
grafana

13.1.4

Download page What's new highlights

Security

  • CVE-2026-17183

Bug fixes

  • Reporting: batch dashboard lookups when listing reports (Enterprise)
9 hours ago
grafana

12.4.9

Download page What's new highlights

Security

  • CVE-2026-17183

Features and enhancements

Bug fixes

9 hours ago
grafana
12 hours ago
grafana

13.2.0

Download page What's new highlights

Security

  • CVE-2026-17183

Features and enhancements

  • Alerting: Add Import tab in alerting settings page #129051, @rodrigopk
  • Alerting: Add notification template import to the import-to-GMA wizard #128329, @rodrigopk
  • Alerting: Add promote and auto sync to ImportToGMAWizard #126907, @rodrigopk
  • Alerting: Add staged configuration summary in import settings page #129204, @rodrigopk
  • Alerting: Compute staged config origin server-side #130727, @rodrigopk
  • Alerting: Migrate notifications API to v1beta1 #124702, @rodrigopk
  • Alerting: Recognize "default" and "user-defined" as the default routing tree (1/4) #127880, @rodrigopk
  • Alerting: Recognize "default" and "user-defined" as the default routing tree (2/4) #127881, @rodrigopk
  • Alerting: Recognize "default" and "user-defined" as the default routing tree (3/4) #127883, @rodrigopk
  • Alerting: Recognize "default" and "user-defined" as the default routing tree (4/4) #127884, @rodrigopk
  • Alerting: Return 403 instead of 500 on contact point provenance mismatch #127699, @rwwiv
  • Alerting: Revert a staged import configuration #129243, @rodrigopk
  • Alerting: Show unusable time intervals as disabled in the mute timings selector #130323, @rodrigopk
  • Alerting: Track import method analytics in import to gma #128142, @rodrigopk
  • Alerting: remove AlertingCentralHistory FT #130164, @konstantinmv
  • Analytics: Add public dashboard UID to loki usage insights events (Enterprise)
  • Auditing: Record the user name on user deletion audit logs (Enterprise)
  • Azure Monitor: Cache subscription lookups and collapse double Unmarshal in buildQuery #123556, @adamyeats
  • Azure monitor: Azure Metrics Batch API Implementation backend #123696, @bossinc
  • CloudWatch Logs: Add frontend support for querying by data source #123742, @kevinwcyu
  • ColorScale: Remove live hoverValue, remove from HeatMap tooltip #128812, @leeoniya
  • DashList: Show dashboard description tooltip when it's available #130006, @DeeGeeGit
  • Dashboard: redirect from dashboard settings tabs to sidebar counterparts #125966, @bfmatei
  • Dashboards: Allow threshold interpolation #128451, @mdvictor
  • Dashboards: Deprecate scripted dashboards and disable them by default #130207, @kristinademeshchik
  • Dashboards: Enable new view panel controls by default #129187, @torkelo
  • Dashboards: Increase nesting depth to 4 and allow nested tabs #129174, @bfmatei
  • Dashboards: Show panel query errors and notices in one UI #127436, @mdvictor
  • Developer Guide: Add note about requiring signed commits #127162, @gelicia
  • Docs: document the tracing file exporter #129339, @leandro-deveikis
  • Explore Logs: log line highlight color lighten in dark, update deprecated pinned color #130516, @L2D2Grafana
  • Folder API: Replace legacy access control logic with app platform API call #125642, @aocenas
  • Go: Update version to 1.26.5 #128011, @macabu
  • GrafanaUI: Add real magnification effect to GrotNotFound lens #130118, @xndcn
  • Home: Enable unified homepage for all users (remove flag) #129054, @MattIPv4
  • Live: Support redis:// and rediss:// (TLS) connection URLs in ha_engine_address #129938, @DeeGeeGit
  • Logs: Add more suggested fields and integrate with the new Logs Table #128002, @matyax
  • Logs: use gray (dimgray) for debug level color #129896, @L2D2Grafana
  • Plugins: Force TLS 1.3 feature toggle #130390, @aangelisc
  • Provisioning (enterprise): (4/8) Add OAuth app connections for GitLab and Bitbucket (Enterprise)
  • Provisioning: Add Dashboard Previews to GitHub Enterprise #127614, @floriecai
  • Provisioning: Add Github Enterprise frontend #127209, @floriecai
  • Provisioning: Add filter for out-of-sync resources in Resources tab #128456, @MissingRoberto
  • Provisioning: Add option to author commits as the signer #127970, @amalavet
  • Provisioning: Add resource kind icons to job summary table #127237, @MissingRoberto
  • Provisioning: Add webhook support for GithubEnterprise (Enterprise)
  • Provisioning: Allow overriding the Git Sync commit author #130547, @amalavet
  • Provisioning: Attribute jobs to their author and origin #128819, @amalavet
  • Provisioning: Attribute webhook-created jobs to the sending user (Enterprise)
  • Provisioning: Bitbucket webhook UI #128649, @amalavet
  • Provisioning: Bitbucket webhooks (Enterprise)
  • Provisioning: Change commit message template to multi-line textarea #128529, @cursoragent
  • Provisioning: Diff Git Sync PR previews against the merge base #128149, @amalavet
  • Provisioning: Diff GitLab Git Sync PR previews against the merge base (Enterprise)
  • Provisioning: Enable Dashboard Previews for Github Enterprise in UI #127906, @floriecai
  • Provisioning: Enable Git Sync conventions by default in public preview #130670, @MissingRoberto
  • Provisioning: Enable Git Sync user attribution by default #130671, @MissingRoberto
  • Provisioning: Enable Github Enterprise provider by default #128376, @floriecai
  • Provisioning: Enable Github Enterprise provider by default for enterp… (Enterprise)
  • Provisioning: Exclude SLO-apps from UI in migrate gitops workflow #128961, @floriecai
  • Provisioning: Exclude SLO-managed dashboards from being exported #128815, @floriecai
  • Provisioning: GitLab webhooks (backend) #127204, @amalavet
  • Provisioning: Improve Git Sync pull-request comment #128100, @MissingRoberto
  • Provisioning: Improve form errors for github connections #128133, @floriecai
  • Provisioning: Link folder metadata and deleted files in PR comments #128895, @MissingRoberto
  • Provisioning: Make Migrate to GitOps resource-agnostic for playlists #127028, @MissingRoberto
  • Provisioning: Make Resources tab tree foldable #128453, @MissingRoberto
  • Provisioning: Paginate the Migrate to GitOps resources table #128042, @MissingRoberto
  • Provisioning: Pretty-print generated _folder.json #127947, @MissingRoberto
  • Provisioning: Show folder path in Migrate resources list #128454, @MissingRoberto
  • Provisioning: Show job author and origin in recent jobs #128820, @amalavet
  • Provisioning: Show job errors in Migrate to GitOps drawer #127936, @MissingRoberto
  • Provisioning: Show sync status for playlists in Resources tab #127021, @MissingRoberto
  • Provisioning: Show who triggered repository jobs #127984, @amalavet
  • Provisioning: Surface github error details #128059, @floriecai
  • Provisioning: UI to set branch when migrating grafana -> gitops #128562, @floriecai
  • Provisioning: adapt GitLab to the provider-agnostic webhook lifecycle (Enterprise)
  • Provisioning: add "View repository" link next to provisioned badges #127409, @ywzheng1
  • Provisioning: add ability to force full pull instead of incremental sync #128330, @floriecai
  • Provisioning: add option to disable webhook in repository and connection #126790, @Shubham19032004
  • Provisioning: add provider logo to repository page title #127223, @amalavet
  • Provisioning: allow Git Sync option for root-level saves and new folders in folderless mode #127399, @Shubham19032004
  • Provisioning: implement GitLab webhooks (Enterprise)
  • Provisioning: link Git Sync PR footer to repo admin page #128353, @MissingRoberto
  • Provisioning: make sync per-resource write timeout configurable #127862, @MissingRoberto
  • Provisioning: regenerate token when its secret is missing #127878, @MissingRoberto
  • Provisioning: show webhook UI for GitLab repositories #127806, @amalavet
  • Provisioning: support migrating to a selected branch #128356, @MissingRoberto
  • QueryVariable: Redesign the query variable editor #127048, @grafakus
  • Reports: support template variables without a type allowlist (Enterprise)
  • SQLite: Revert the journal mode when wal is disabled #130695, @pstibrany
  • Table: Make cell tooltips dynamic height so content is not cut off #127107, @fastfrwrd
  • Trace View: Check for the existence of logs when showing the trace-to-logs button #128702, @matyax
  • Tracing: add file exporter to write traces as OTLP/JSON #128679, @leandro-deveikis
  • Transformations: Keep Merge series/tables available with a single data series #129569, @nicwestvold
  • Unified Storage: set garbage collection dry run default to false #130533, @filewalkwithme
  • ViewPanel: Url sync for fanout option #128270, @torkelo
  • alerting: allow import to gma wizard navigation for non admin users when sync is not active #127818, @rodrigopk
  • provisioning: allow authoring commits as the signer #127969, @amalavet

Bug fixes

Breaking changes

Plugin development fixes & changes

13 hours ago
timescaledb

2.29.2 (2026-08-18)

This release contains bug fixes since the 2.29.1 release. We recommend that you upgrade at the next available opportunity.

Bugfixes

  • #10189 Fix user-defined functions named time_bucket causing SQLSTATE XX000
  • #10363 Fix time_bucket_gapfill() with window aggregates over constants
  • #10416 Repair mismatched dimensional CHECK constraints
  • #10423 Fix compressed SkipScan dropping uncompressed rows when sort keys do not match distinct keys
  • #10430 Do not attach SkipScan to mismatched IndexScan paths under MergeAppend
  • #9921 Fix wrong results for IS NULL predicates with min/max sparse-index pushdown

Thanks

  • @borisborelly for reporting incorrect results with COUNT(DISTINCT) due to SkipScan dropping uncompressed rows.
1 days ago
redis

8.10.1

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key
1 days ago
redis

8.8.2

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key
1 days ago
redis

8.6.6

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • #15478 ACL key permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER and XREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key