<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Bazarr?</title>
    <link>https://bumplog.org/apps/bazarr/</link>
    <description>Update-safety verdicts for Bazarr (morpheus65535/bazarr), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/bazarr/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Bazarr v1.6.0 — Update with care</title>
      <link>https://bumplog.org/apps/bazarr/</link>
      <guid isPermaLink="false">bumplog:app:bazarr:v1.6.0:caution</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
      <description>Update with care. The permanent removal of the Podnapisi provider is a functional breaking point for anyone who had it configured — those users must reconfigure their subtitle sources before or after upgrading. All other changes are fixes, improvements, and additions with no stated migration steps, making this otherwise a routine update. What changed: v1.6.0 removes the Podnapisi provider entirely since the service is no longer online, so any users relying on it will need to switch to an alternative source. The release adds two new Bulgarian subtitle providers (Bayflix and Vladoon) and fixes a command-injection vulnerability (CWE-78) in subtitle post-processing by switching to safer subprocess invocation. Several provider improvements land as well: better rate-limit handling for SubDL, fixed RegieLive.ro downloads, improved audio and Chinese subtitle language detection, and a dramatic Sonarr/Radarr sync performance boost. A new option lets you disable SSL verification globally for providers, and the base config file path can now be set via an environment variable. Source release: https://github.com/morpheus65535/bazarr/releases/tag/v1.6.0</description>
    </item>
  </channel>
</rss>
