<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Pi-hole?</title>
    <link>https://bumplog.org/apps/pi-hole/</link>
    <description>Update-safety verdicts for Pi-hole (pi-hole/pi-hole), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/pi-hole/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Pi-hole v6.4.2 — Update with care</title>
      <link>https://bumplog.org/apps/pi-hole/</link>
      <guid isPermaLink="false">bumplog:app:pi-hole:v6.4.2:caution</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>Update with care. The presence of a patched security advisory (GHSA-6w8x-p785-6pm4) makes updating advisable, but users should be aware of the permission and gravity-behaviour changes that could affect custom setups. No explicit breaking changes or required manual migration steps are called out in the notes, but the security nature of the release and the permission/ownership fixes warrant reading the advisory before updating. What changed: v6.4.2 delivers a security fix alongside a set of infrastructure and reliability improvements. A published security advisory has been patched in both the core installer and the FTL component. The release also tightens file ownership and permission handling, including a fix for .etag files after gravity runs and loosened requirements for local-file gravity sources. Installer behaviour is refined: the apt cache update is skipped when pihole-meta is already current, logrotate is now a declared dependency for DEB and RPM packages, and gravity error messages now include the curl exit code for easier debugging. Source release: https://github.com/pi-hole/pi-hole/releases/tag/v6.4.2</description>
    </item>
  </channel>
</rss>
