<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — Home automation stack updates</title>
    <link>https://bumplog.org/stacks/home-automation/</link>
    <description>Update-safety verdicts for the Home automation self-hosted stack: Run your smart home and network-wide ad blocking locally, no cloud required.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/stacks/home-automation/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AdGuard Home v0.107.77 — Update with care</title>
      <link>https://bumplog.org/apps/adguard-home/</link>
      <guid isPermaLink="false">bumplog:app:adguard-home:v0.107.77:caution</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>Update with care. This release patches a path traversal vulnerability (CVE-2026-41448) in GLiNET mode authorization, making it a security-motivated update worth applying. However, it also deprecates the `response_status` query parameter in `GET /control/querylog` in favor of a new `reason` parameter — users or integrations relying on that API endpoint should review the change before updating. No breaking migrations or manual upgrade steps are noted. What changed: v0.107.77 patches a path traversal vulnerability in authorization for GLiNET mode (CVE-2026-41448), reported by a community member. The query log API gains a new `reason` query parameter on `GET /control/querylog` that replaces the now-deprecated `response_status` parameter. No other user-facing changes are included in this release. Source release: https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.77</description>
    </item>
    <item>
      <title>Home Assistant 2026.6.4 — Safe to update</title>
      <link>https://bumplog.org/apps/home-assistant/</link>
      <guid isPermaLink="false">bumplog:app:home-assistant:2026.6.4:safe</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <description>Safe to update. All changes in 2026.6.4 are bug fixes, dependency bumps, and translation additions — none of the release notes mention breaking changes, required migrations, or manual upgrade steps. Notable fixes include a Growatt sensor value correction (1000× off), an Immich API key log leak, an InfluxDB URL double-slash bug, and an MQTT discovery data fix, all of which are improvements rather than behavior changes that would require user action. The notes are slightly truncated but the visible content is uniformly patch-level. What changed: Home Assistant 2026.6.4 delivers a security fix that prevents the Immich API key from appearing in error logs, and corrects a Growatt power reporting bug where total output power was reported 1,000 times too low when using the V1 API. Sonos now dynamically includes saved favorites in the media player source list, Subaru gains fourth-generation API support, and Amber Electric&apos;s configuration flow filters out closed sites to avoid setup confusion. WebDAV integration now retries setup on connection errors rather than failing outright, and the La Marzocco pre-brew time limits have been updated. A broad sweep of translation fixes across more than two dozen integrations improves the setup flow experience for non-English users. Source release: https://github.com/home-assistant/core/releases/tag/2026.6.4</description>
    </item>
  </channel>
</rss>
