{
 "schema": "bumplog.app.v1",
 "generatedAt": "2026-07-26T13:02:49.521Z",
 "slug": "navidrome",
 "name": "Navidrome",
 "repo": "navidrome/navidrome",
 "latestVersion": "v0.62.0",
 "safeToUpdate": "caution",
 "rationale": "No hard breaking changes or mandatory migration steps are declared, but two config options are deprecated and renamed (EnableTranscodingCancellation → Transcoding.EnableCancellation; SimilarSongsMatchThreshold → Matcher.FuzzyThreshold), and the playback-reporting behavior is materially changed. Users with custom config or scrobble-dependent workflows should review the Configuration Changes table before upgrading. The security fixes are significant enough to make upgrading strongly advisable, but a quick config audit is warranted first.",
 "changelogSummary": "Navidrome v0.62.0 delivers a significant security hardening pass, fixing six reported vulnerabilities covering cross-account data disclosure, player takeover, Last.fm session hijack, JWT bypass on share streams, and unauthorized access to transcoding config and radio management endpoints. The playback reporting flow is overhauled: the UI now uses the OpenSubsonic playbackReport extension with a redesigned Now Playing panel and a configurable reporting interval, replacing the old scrobble mechanism. Two configuration options are deprecated and renamed — EnforceNonRootUser and per-user/server transcode limits are new additions, while EnableTranscodingCancellation and SimilarSongsMatchThreshold move under new namespaced sections. Smart playlists gain ReplayGain fields and new track-presence operators, and five new UI themes are included.",
 "sourceUrl": "https://github.com/navidrome/navidrome/releases/tag/v0.62.0",
 "lastChecked": "2026-07-04",
 "successor": null,
 "url": "https://bumplog.org/apps/navidrome/",
 "badge": "https://bumplog.org/badge/navidrome.svg",
 "lifecycle": null
}