Is it safe to update Navidrome?

Tracking navidrome/navidrome

Update with care.

No hard breaking changes or mandatory migration steps are declared, but two config options are deprecated and renamed (EnableTranscodingCancellation → Transcoding.EnableCancellation; SimilarSongsMatchThreshold → Matcher.FuzzyThreshold), and the playback-reporting behavior is materially changed. Users with custom config or scrobble-dependent workflows should review the Configuration Changes table before upgrading. The security fixes are significant enough to make upgrading strongly advisable, but a quick config audit is warranted first.

Latest version
v0.62.0
Last checked

What changed

Navidrome v0.62.0 delivers a significant security hardening pass, fixing six reported vulnerabilities covering cross-account data disclosure, player takeover, Last.fm session hijack, JWT bypass on share streams, and unauthorized access to transcoding config and radio management endpoints. The playback reporting flow is overhauled: the UI now uses the OpenSubsonic playbackReport extension with a redesigned Now Playing panel and a configurable reporting interval, replacing the old scrobble mechanism. Two configuration options are deprecated and renamed — EnforceNonRootUser and per-user/server transcode limits are new additions, while EnableTranscodingCancellation and SimilarSongsMatchThreshold move under new namespaced sections. Smart playlists gain ReplayGain fields and new track-presence operators, and five new UI themes are included.

Source

Every verdict on Bumplog traces back to a GitHub release. No invented details.