{
 "schema": "bumplog.app.v1",
 "generatedAt": "2026-07-26T13:02:49.519Z",
 "slug": "uptime-kuma",
 "name": "Uptime Kuma",
 "repo": "louislam/uptime-kuma",
 "latestVersion": "2.4.0",
 "safeToUpdate": "safe",
 "rationale": "The 2.4.0 release notes list only additive new features (new notification providers, RSS incidents), optional improvements (bearer token support, gamedig token field), and bug fixes — none of which require migration or manual upgrade steps. Notably, the release patches a Remote Code Execution vulnerability in the LiquidJS dependency (GHSA-gf2q-c269-pqgc), making the update actively advisable for security. No breaking changes, deprecations, or required configuration changes are called out.",
 "changelogSummary": "Uptime Kuma 2.4.0 adds two new notification providers — EgoSMS (for Uganda-based SMS) and VKTeams bot — and now includes incidents in RSS feeds. Monitor configuration gains bearer token support across HTTP and WebSocket upgrade monitors, plus an optional token field for GameDig monitors. A critical security fix patches a Remote Code Execution vulnerability in the LiquidJS dependency used by notification templates. The release also resolves a long-standing bug where NTLM monitors over plain HTTP would fail with a 400 Bad Request error.",
 "sourceUrl": "https://github.com/louislam/uptime-kuma/releases/tag/2.4.0",
 "lastChecked": "2026-06-29",
 "successor": null,
 "url": "https://bumplog.org/apps/uptime-kuma/",
 "badge": "https://bumplog.org/badge/uptime-kuma.svg",
 "lifecycle": null
}