Repository navigation
4.0.0 (2026-09-26)
Major release: standalone budgets, a new recurrence engine, exact decimal arithmetic, API tokens with two-factor authentication, and Laravel 13.
Before upgrading, read the 3.x to 4.x upgrade guide. Update to the latest 3.x release first, run php artisan app:check:budget-migration, and back up your database. The data migrations cannot be undone with migrate:rollback.
⚠ BREAKING CHANGES
- budgets: the
transactions.budgetflag is removed and replaced by a standaloneBudgetentity. Budget-only transactions are converted toBudgetrows (one per category) and deleted fromtransactions. The "Budget" checkbox on the transaction form is removed; budgets are managed from Reports → Schedules and Budgets (#525, #528) - schedules: schedule and budget recurrence is stored in a single RFC 5545
rrulecolumn, and thefrequency/interval/count/end_datecolumns are dropped. The recurrence fields in the UI and API are unchanged (#548) - api: money and quantity fields in
/api/v1/*responses are decimal strings instead of JSON numbers. Report endpoints are unaffected (#522) - api:
GET /api/v1/transactions/scheduled-itemsno longer acceptstype=budget|budget_only|both|any. The budget-vs-actual chart response addsbudgetBreakdownandscheduleBreakdownarrays (#525) - auth: reCAPTCHA is removed from login, registration and password reset.
RECAPTCHA_*variables are no longer read (8530275) - platform: requires Laravel 13 and the
ext-bcmathPHP extension. Laravel 13 changes the defaultCACHE_PREFIX,REDIS_PREFIXandSESSION_COOKIEvalues, so pin them in.envto keep existing cache and sessions (8530275, #522) - docker: the Caddy reverse proxy is now the
httpsCompose profile instead of a commented-out block. Re-apply any manual Caddy edits and start it withdocker compose --profile https up -d(#531) - ai documents: deleting an AI document no longer deletes the transaction created from it (#547)
✨ Features
- budgets: standalone budgets with a combined Schedules and Budgets report, budget-vs-actual chart drill-down, inflation-adjusted forecasting and dashboard widgets (#525, #528)
- schedules: ordinal weekday patterns such as "first Wednesday of every month" or "last Friday of November" (#518)
- schedules: "N days before month end" and "last business day of month" patterns for schedules and budgets (#548)
- schedules: "skip to nearest future occurrence" when entering a scheduled transaction, step buttons and pattern validation for the next occurrence date, and a new dashboard calendar (#518)
- security: personal API access tokens with
read/write/settingsscopes, and optional TOTP two-factor authentication with recovery codes, both managed from user settings (#512) - precision: exact decimal arithmetic for money and quantities, which removes rounding drift in split totals, investment values and monthly summaries (#522)
- reports: Find Transactions adds transaction type and investment filters, a category waterfall chart and item-level breakdown filtering. The dashboard waterfall widget now links into the report (#520)
- ai documents: opt-in, per-user retention policy that deletes old finalized documents, and sends reminder emails for old documents that are not finalized (#547)
- accounts: account history uses virtual scrolling for large histories, and tables across the app use a single contextual action menu per row (#543)
- docker: the container generates and keeps its
APP_KEYon first boot, sodocker compose up -dworks without editing.env(#527) - docker: HTTPS through Caddy as a Compose profile, with a configurable
APP_PORT(#531)
🐛 Bug Fixes
- render notification and toast text as plain text to prevent XSS (#552)
- "first Wednesday" style schedules no longer fall back to a fixed day of the month (#525)
- over-precise money input is rejected instead of silently rounded, and amounts display with their stored precision (#542, 4753265)
- forms in modals ask for confirmation before discarding unsaved input, and deleting currencies, tags, categories and groups works without a page reload (#535)
- investment price web scraping no longer depends on the unmaintained roach-php package (#537)
- AI documents created from pasted text stored an invalid file path. A migration repairs existing ones (#547)
- many smaller fixes to schedules, budgets, forms, tables and migrations found during 4.0 testing and review
🚀 Performance Improvements
- redundant indexes removed, and primary/unique keys added to pivot tables. Duplicate pivot rows are cleaned up during migration (#526)
- number and date formatters are cached, which speeds up large tables (#543)