<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Vikunja?</title>
    <link>https://bumplog.org/apps/vikunja/</link>
    <description>Update-safety verdicts for Vikunja (go-vikunja/vikunja), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/vikunja/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vikunja v2.3.0 — Update with care</title>
      <link>https://bumplog.org/apps/vikunja/</link>
      <guid isPermaLink="false">bumplog:app:vikunja:v2.3.0:caution</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
      <description>Update with care. No explicit breaking changes or required migration steps are called out in the notes, but the introduction of a plugin system and OAuth 2.0 provider mode are significant architectural additions that may affect existing integrations or configuration. The 11 security fixes make upgrading urgent, so reviewing the full changelog at the linked URL before deploying is prudent. What changed: v2.3.0 ships 11 security fixes, making prompt upgrading strongly advisable. It introduces a new plugin system, adds Vikunja itself as an OAuth 2.0 provider, and brings WeKan and CSV import options. Desktop users gain a quick-entry window for faster task capture. The release spans 277 commits, reflecting a substantial cycle of improvements alongside the security work. Source release: https://github.com/go-vikunja/vikunja/releases/tag/v2.3.0</description>
    </item>
  </channel>
</rss>
