<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Paperless-ngx?</title>
    <link>https://bumplog.org/apps/paperless-ngx/</link>
    <description>Update-safety verdicts for Paperless-ngx (paperless-ngx/paperless-ngx), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/paperless-ngx/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Paperless-ngx v2.20.15 — Safe to update</title>
      <link>https://bumplog.org/apps/paperless-ngx/</link>
      <guid isPermaLink="false">bumplog:app:paperless-ngx:v2.20.15:safe</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <description>Safe to update. This release contains only bug fixes, including a recommended security patch (GHSA-8c6x-pfjq-9gr7) addressing mail account enumeration and login/logout endpoint issues. There are no breaking changes, required migrations, or manual upgrade steps noted. What changed: v2.20.15 is a security-focused patch release that all users are encouraged to apply. It closes a disclosed vulnerability (GHSA-8c6x-pfjq-9gr7) by tightening authentication flows to use only the allauth login and logout endpoints, and by correctly scoping mail account enumeration to prevent unauthorized access. Two additional bug fixes ship alongside: one eliminates a spurious change event that could fire when switching operator types on a custom field query, and another rejects malformed requests to the API notes endpoint. Source release: https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.20.15</description>
    </item>
  </channel>
</rss>
