<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Uptime Kuma?</title>
    <link>https://bumplog.org/apps/uptime-kuma/</link>
    <description>Update-safety verdicts for Uptime Kuma (louislam/uptime-kuma), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/uptime-kuma/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Uptime Kuma 2.4.0 — Safe to update</title>
      <link>https://bumplog.org/apps/uptime-kuma/</link>
      <guid isPermaLink="false">bumplog:app:uptime-kuma:2.4.0:safe</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>Safe to update. The 2.4.0 release notes list only additive new features (new notification providers, RSS incidents), optional improvements (bearer token support, gamedig token field), and bug fixes — none of which require migration or manual upgrade steps. Notably, the release patches a Remote Code Execution vulnerability in the LiquidJS dependency (GHSA-gf2q-c269-pqgc), making the update actively advisable for security. No breaking changes, deprecations, or required configuration changes are called out. What changed: Uptime Kuma 2.4.0 adds two new notification providers — EgoSMS (for Uganda-based SMS) and VKTeams bot — and now includes incidents in RSS feeds. Monitor configuration gains bearer token support across HTTP and WebSocket upgrade monitors, plus an optional token field for GameDig monitors. A critical security fix patches a Remote Code Execution vulnerability in the LiquidJS dependency used by notification templates. The release also resolves a long-standing bug where NTLM monitors over plain HTTP would fail with a 400 Bad Request error. Source release: https://github.com/louislam/uptime-kuma/releases/tag/2.4.0</description>
    </item>
  </channel>
</rss>
