13.0.7
Download page What's new highlights
- CVE-2026-17183
- Reporting: batch dashboard lookups when listing reports (Enterprise)
13.1.4
Download page What's new highlights
- CVE-2026-17183
- Reporting: batch dashboard lookups when listing reports (Enterprise)
12.4.9
Download page What's new highlights
- CVE-2026-17183
- Dashboard Import: Labels in v2 schema #130428, @harisrozajac
- Azure Monitor: fix migration for dimension filters #130521, @olivierlemasle
13.2.0
Download page What's new highlights
- CVE-2026-17183
- Alerting: Add Import tab in alerting settings page #129051, @rodrigopk
- Alerting: Add notification template import to the import-to-GMA wizard #128329, @rodrigopk
- Alerting: Add promote and auto sync to ImportToGMAWizard #126907, @rodrigopk
- Alerting: Add staged configuration summary in import settings page #129204, @rodrigopk
- Alerting: Compute staged config origin server-side #130727, @rodrigopk
- Alerting: Migrate notifications API to v1beta1 #124702, @rodrigopk
- Alerting: Recognize "default" and "user-defined" as the default routing tree (1/4) #127880, @rodrigopk
- Alerting: Recognize "default" and "user-defined" as the default routing tree (2/4) #127881, @rodrigopk
- Alerting: Recognize "default" and "user-defined" as the default routing tree (3/4) #127883, @rodrigopk
- Alerting: Recognize "default" and "user-defined" as the default routing tree (4/4) #127884, @rodrigopk
- Alerting: Return 403 instead of 500 on contact point provenance mismatch #127699, @rwwiv
- Alerting: Revert a staged import configuration #129243, @rodrigopk
- Alerting: Show unusable time intervals as disabled in the mute timings selector #130323, @rodrigopk
- Alerting: Track import method analytics in import to gma #128142, @rodrigopk
- Alerting: remove AlertingCentralHistory FT #130164, @konstantinmv
- Analytics: Add public dashboard UID to loki usage insights events (Enterprise)
- Auditing: Record the user name on user deletion audit logs (Enterprise)
- Azure Monitor: Cache subscription lookups and collapse double Unmarshal in buildQuery #123556, @adamyeats
- Azure monitor: Azure Metrics Batch API Implementation backend #123696, @bossinc
- CloudWatch Logs: Add frontend support for querying by data source #123742, @kevinwcyu
- ColorScale: Remove live hoverValue, remove from HeatMap tooltip #128812, @leeoniya
- DashList: Show dashboard description tooltip when it's available #130006, @DeeGeeGit
- Dashboard: redirect from dashboard settings tabs to sidebar counterparts #125966, @bfmatei
- Dashboards: Allow threshold interpolation #128451, @mdvictor
- Dashboards: Deprecate scripted dashboards and disable them by default #130207, @kristinademeshchik
- Dashboards: Enable new view panel controls by default #129187, @torkelo
- Dashboards: Increase nesting depth to 4 and allow nested tabs #129174, @bfmatei
- Dashboards: Show panel query errors and notices in one UI #127436, @mdvictor
- Developer Guide: Add note about requiring signed commits #127162, @gelicia
- Docs: document the tracing file exporter #129339, @leandro-deveikis
- Explore Logs: log line highlight color lighten in dark, update deprecated pinned color #130516, @L2D2Grafana
- Folder API: Replace legacy access control logic with app platform API call #125642, @aocenas
- Go: Update version to 1.26.5 #128011, @macabu
- GrafanaUI: Add real magnification effect to GrotNotFound lens #130118, @xndcn
- Home: Enable unified homepage for all users (remove flag) #129054, @MattIPv4
- Live: Support redis:// and rediss:// (TLS) connection URLs in ha_engine_address #129938, @DeeGeeGit
- Logs: Add more suggested fields and integrate with the new Logs Table #128002, @matyax
- Logs: use gray (dimgray) for debug level color #129896, @L2D2Grafana
- Plugins: Force TLS 1.3 feature toggle #130390, @aangelisc
- Provisioning (enterprise): (4/8) Add OAuth app connections for GitLab and Bitbucket (Enterprise)
- Provisioning: Add Dashboard Previews to GitHub Enterprise #127614, @floriecai
- Provisioning: Add Github Enterprise frontend #127209, @floriecai
- Provisioning: Add filter for out-of-sync resources in Resources tab #128456, @MissingRoberto
- Provisioning: Add option to author commits as the signer #127970, @amalavet
- Provisioning: Add resource kind icons to job summary table #127237, @MissingRoberto
- Provisioning: Add webhook support for GithubEnterprise (Enterprise)
- Provisioning: Allow overriding the Git Sync commit author #130547, @amalavet
- Provisioning: Attribute jobs to their author and origin #128819, @amalavet
- Provisioning: Attribute webhook-created jobs to the sending user (Enterprise)
- Provisioning: Bitbucket webhook UI #128649, @amalavet
- Provisioning: Bitbucket webhooks (Enterprise)
- Provisioning: Change commit message template to multi-line textarea #128529, @cursoragent
- Provisioning: Diff Git Sync PR previews against the merge base #128149, @amalavet
- Provisioning: Diff GitLab Git Sync PR previews against the merge base (Enterprise)
- Provisioning: Enable Dashboard Previews for Github Enterprise in UI #127906, @floriecai
- Provisioning: Enable Git Sync conventions by default in public preview #130670, @MissingRoberto
- Provisioning: Enable Git Sync user attribution by default #130671, @MissingRoberto
- Provisioning: Enable Github Enterprise provider by default #128376, @floriecai
- Provisioning: Enable Github Enterprise provider by default for enterp… (Enterprise)
- Provisioning: Exclude SLO-apps from UI in migrate gitops workflow #128961, @floriecai
- Provisioning: Exclude SLO-managed dashboards from being exported #128815, @floriecai
- Provisioning: GitLab webhooks (backend) #127204, @amalavet
- Provisioning: Improve Git Sync pull-request comment #128100, @MissingRoberto
- Provisioning: Improve form errors for github connections #128133, @floriecai
- Provisioning: Link folder metadata and deleted files in PR comments #128895, @MissingRoberto
- Provisioning: Make Migrate to GitOps resource-agnostic for playlists #127028, @MissingRoberto
- Provisioning: Make Resources tab tree foldable #128453, @MissingRoberto
- Provisioning: Paginate the Migrate to GitOps resources table #128042, @MissingRoberto
- Provisioning: Pretty-print generated _folder.json #127947, @MissingRoberto
- Provisioning: Show folder path in Migrate resources list #128454, @MissingRoberto
- Provisioning: Show job author and origin in recent jobs #128820, @amalavet
- Provisioning: Show job errors in Migrate to GitOps drawer #127936, @MissingRoberto
- Provisioning: Show sync status for playlists in Resources tab #127021, @MissingRoberto
- Provisioning: Show who triggered repository jobs #127984, @amalavet
- Provisioning: Surface github error details #128059, @floriecai
- Provisioning: UI to set branch when migrating grafana -> gitops #128562, @floriecai
- Provisioning: adapt GitLab to the provider-agnostic webhook lifecycle (Enterprise)
- Provisioning: add "View repository" link next to provisioned badges #127409, @ywzheng1
- Provisioning: add ability to force full pull instead of incremental sync #128330, @floriecai
- Provisioning: add option to disable webhook in repository and connection #126790, @Shubham19032004
- Provisioning: add provider logo to repository page title #127223, @amalavet
- Provisioning: allow Git Sync option for root-level saves and new folders in folderless mode #127399, @Shubham19032004
- Provisioning: implement GitLab webhooks (Enterprise)
- Provisioning: link Git Sync PR footer to repo admin page #128353, @MissingRoberto
- Provisioning: make sync per-resource write timeout configurable #127862, @MissingRoberto
- Provisioning: regenerate token when its secret is missing #127878, @MissingRoberto
- Provisioning: show webhook UI for GitLab repositories #127806, @amalavet
- Provisioning: support migrating to a selected branch #128356, @MissingRoberto
- QueryVariable: Redesign the query variable editor #127048, @grafakus
- Reports: support template variables without a type allowlist (Enterprise)
- SQLite: Revert the journal mode when wal is disabled #130695, @pstibrany
- Table: Make cell tooltips dynamic height so content is not cut off #127107, @fastfrwrd
- Trace View: Check for the existence of logs when showing the trace-to-logs button #128702, @matyax
- Tracing: add file exporter to write traces as OTLP/JSON #128679, @leandro-deveikis
- Transformations: Keep Merge series/tables available with a single data series #129569, @nicwestvold
- Unified Storage: set garbage collection dry run default to false #130533, @filewalkwithme
- ViewPanel: Url sync for fanout option #128270, @torkelo
- alerting: allow import to gma wizard navigation for non admin users when sync is not active #127818, @rodrigopk
- provisioning: allow authoring commits as the signer #127969, @amalavet
- ** Gauge:** Fix gradient stops out of order for negative thresholds #128532, @fastfrwrd
- Accessibility: Ensure
InlineToastcontents are announced by screenreaders #128488, @ashharrison90 - Accessibility: Properly announce section headings on variable edit pages #130706, @ashharrison90
- Alerting: Check managed routes when deleting a time interval #129247, @JacobsonMT
- Alerting: Fix alert rule detail showing "Inhibited" when nothing is inhibited #130264, @petergreen86
- Alerting: Fix reset default route wiping provenance for all managed routes #130553, @JacobsonMT
- Auth: Deduplicate concurrent login pings #129927, @cipher416
- Auth: Skip session token rotation when request is not session authenticated #129920, @thejamesgore
- Azure Monitor: fix migration for dimension filters #128786, @olivierlemasle
- Dashboard scene: Activate edit pane for programmatic panel mutations #128433, @ivanortegaalba
- DashboardDS: Fix chained dashboard datasource panels showing stale data #126378, @oscarkilhed
- Dashboards: Fix loading indicator not clipping to panel border radius #128040, @hckhanh
- Dashboards: Fixes panel header spacing issues #128910, @torkelo
- DataSourcePicker: Fix selected datasource not being highlighted #126948, @mikkancso
- Fix: Parse epoch ms strings correctly to prevent NaN in Postgres queries #122693, @Tarasusrus
- Logs Table: Fix data export by passing the raw table frame #130245, @matyax
- Logs Table: Fix missing results when logs stream #128870, @matyax
- Logs Table: Fix mixed usage of field name and display name #128677, @matyax
- Logs Table: Fix sticky filter after closing details #128398, @matyax
- Navigation: Inject orgId into all navigations #120978, @QuentinBisson
- PostgreSQL: Fix data source init failure when maxOpenConns=0 #122556, @Tarasusrus
- Provisioning: Disable next button until a branch is selected in the Git Sync wizard #127973, @amalavet
- Provisioning: Export v0 dashboards as v1 so synced files load #128357, @MissingRoberto
- Provisioning: Fix NPE when testing GHE repo on creation #127207, @floriecai
- Provisioning: Fix blank Action for deleted resources in PR comment #128522, @MissingRoberto
- Provisioning: Fix customServerURL resolution for GHE #127113, @floriecai
- Provisioning: Fix enforced branch name template dropping ref on save #130163, @ferruvich
- Provisioning: Fix job user attribution in multi-tenant deployments #129598, @amalavet
- Provisioning: Fix multi-org usage stats #127465, @ferruvich
- Provisioning: Fix selective export quota counting whole namespace #127927, @MissingRoberto
- Provisioning: Keep migrate reachable when connected repo can't push #127921, @MissingRoberto
- Provisioning: Only regenerate folder UIDs for folder/folderless migrations #127925, @MissingRoberto
- Provisioning: Preserve the original creator on job history records #128712, @amalavet
- Provisioning: Set FileToLarge error as warning instead of error #128822, @floriecai
- Provisioning: Strip deprecatedInternalId label for dashboards #128530, @floriecai
- Provisioning: Use neutral fallback in the jobs Triggered by column #128238, @amalavet
- Provisioning: abort in-flight worker when job lease is lost #127792, @MissingRoberto
- Provisioning: don't stamp a folder on org-scoped resources when writing #127142, @MissingRoberto
- Provisioning: drop stale and duplicate watch events in the frontend list cache #128766, @MissingRoberto
- Provisioning: fix zero-margin job lease renewal, raise claim expiry to 60s #127786, @MissingRoberto
- Provisioning: make GitHub webhook creation idempotent (fix repos stuck unhealthy with HTTP 422) #128068, @floriecai
- Provisioning: normalize folder titles into safe export paths #127946, @MissingRoberto
- Provisioning: only push variable changes to git if save variables is … #128818, @floriecai
- Provisioning: retry connection status patch conflicts #127754, @MissingRoberto
- Provisioning: tolerate NotFound in expired job cleanup for multi-pod #127753, @MissingRoberto
- Provisioning: treat skip-delete of resource owned by another file as a warning #129029, @ferruvich
- Provisioning: verify claim ownership so two pods don't run the same job #127783, @MissingRoberto
- Reporting: batch dashboard lookups when listing reports (Enterprise)
- Secrets: Fix RBAC gate on AWS keeper creation route (Enterprise)
- SqlExpressions: Fix parsing for Table Names with spaces #117615, @NWRichmond
- Table: Fix apply to entire row when multiple columns enable it #128527, @fastfrwrd
- Transformations: Fix Filter by value regex matching null values #129572, @nicwestvold
- Transformations: Fix field lookup failing for the Countries and USA States gazetteers #129568, @nicwestvold
- Transformations: Fix field name deduplication in Extract fields #129889, @nicwestvold
- Transformations: Fix inner join returning rows when a frame is dropped #129576, @nicwestvold
- fix: fix panic for unimplemented gitlab webhook repo (Enterprise)
- Alerting: Remove alertingSaveStateCompressed feature flag #129135, @yuri-tceretian
- Combobox: Fix duplicate async requests and stale errors overwriting fresh options #129788, @joshhunt
- PageLoader: Expose in @grafana/ui and apply custom branding automatically #124597, @ashharrison90
- Pagination: Set
aria-currenton active page #128494, @ashharrison90 - Tag: Fix crash when picking an out of bounds
colorIndex#129579, @ashharrison90
2.29.2 (2026-08-18)
This release contains bug fixes since the 2.29.1 release. We recommend that you upgrade at the next available opportunity.
Bugfixes
- #10189 Fix user-defined functions named
time_bucketcausing SQLSTATEXX000 - #10363 Fix
time_bucket_gapfill()with window aggregates over constants - #10416 Repair mismatched dimensional
CHECKconstraints - #10423 Fix compressed
SkipScandropping uncompressed rows when sort keys do not match distinct keys - #10430 Do not attach
SkipScanto mismatchedIndexScanpaths underMergeAppend - #9921 Fix wrong results for
IS NULLpredicates with min/max sparse-index pushdown
Thanks
- @borisborelly for reporting incorrect results with
COUNT(DISTINCT)due toSkipScandropping uncompressed rows.
8.10.1
Update urgency: SECURITY: There are security fixes in the release.
- (CVE-2026-62356) Miscalculated buffer size in
CMSketchRDB loading may lead to heap OOB write - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
- Use-after-free in the TLS pending-data list when a command closes another pending connection
- A malicious RDB payload with an out-of-range
SLOT_INFOslot id causes memory corruption during RDB loading, which may lead to Remote Code Execution - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
- Vector Sets: use-after-free when
VREMmutates the HNSW graph while backgroundVSIMthreads are still running - Vector Sets: a negative
hnsw_search()return was treated as a huge unsigned count, reading past the end of the result arrays - TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
- #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key
8.8.2
Update urgency: SECURITY: There are security fixes in the release.
- (CVE-2026-62356) Miscalculated buffer size in
CMSketchRDB loading may lead to heap OOB write - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
- Use-after-free in the TLS pending-data list when a command closes another pending connection
- #15478 ACL key permission bypass in
SORT,GEORADIUS/GEORADIUSBYMEMBERandXREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses - A malicious RDB payload with an out-of-range
SLOT_INFOslot id causes memory corruption during RDB loading, which may lead to Remote Code Execution - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
- Vector Sets: use-after-free when
VREMmutates the HNSW graph while backgroundVSIMthreads are still running - Vector Sets: a negative
hnsw_search()return was treated as a huge unsigned count, reading past the end of the result arrays - TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
- #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key
8.6.6
Update urgency: SECURITY: There are security fixes in the release.
- (CVE-2026-62356) Miscalculated buffer size in
CMSketchRDB loading may lead to heap OOB write - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
- Use-after-free in the TLS pending-data list when a command closes another pending connection
- #15478 ACL key permission bypass in
SORT,GEORADIUS/GEORADIUSBYMEMBERandXREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses - A malicious RDB payload with an out-of-range
SLOT_INFOslot id causes memory corruption during RDB loading, which may lead to Remote Code Execution - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
- Vector Sets: use-after-free when
VREMmutates the HNSW graph while backgroundVSIMthreads are still running - Vector Sets: a negative
hnsw_search()return was treated as a huge unsigned count, reading past the end of the result arrays - TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
- #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key