- This is a security release: fix 2 high vulnerabilities
- Disable forgot password functionality via email if ALLOWED_HOSTS is unset (GHSA-9x2r-5pff-8w6c)
- Details for a second vulnerability have been temporarily withheld and will be disclosed at a later date
- Enable/disable plugins in settings web UI
- Enable some plugins by default
- Allow SSO identity API for API token auth
- Restore archive: different message filename per key
- AI agent: Confirm delete when reverting changes
Click here to go to the update instructions: https://docs.sysreptor.com/setup/updates/