<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — Productivity stack updates</title>
    <link>https://bumplog.org/stacks/productivity/</link>
    <description>Update-safety verdicts for the Productivity self-hosted stack: Self-hosted documents, files, and password management for everyday work.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/stacks/productivity/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Nextcloud v34.0.1 — Not assessed yet</title>
      <link>https://bumplog.org/apps/nextcloud/</link>
      <guid isPermaLink="false">bumplog:app:nextcloud:v34.0.1:unknown</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <description>Not assessed yet. The release notes provided contain only a changelog comparison URL and no substantive text describing changes, migrations, deprecations, or breaking changes. Without actual note content there is no basis to classify the update. The source must be fetched and read before a classification can be made. What changed: ... Source release: https://github.com/nextcloud/server/releases/tag/v34.0.1</description>
    </item>
    <item>
      <title>Vaultwarden 1.36.0 — Update with care</title>
      <link>https://bumplog.org/apps/vaultwarden/</link>
      <guid isPermaLink="false">bumplog:app:vaultwarden:1.36.0:caution</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <description>Update with care. This release patches six security advisories (SSO CSRF, user/org enumeration, SSO existing-user binding, and SSRF via Icon Endpoint) and the maintainers explicitly urge updating &apos;as soon as possible,&apos; making the upgrade strongly recommended. No breaking changes or required manual migration steps are called out in the notes. However, the multiple SSO-related fixes (CSRF, identifier handling, user binding) and the Web Vault bump to v2026.4.1 warrant reading the individual advisories—especially if SSO is enabled—before updating in production. What changed: Vaultwarden 1.36.0 is a security-critical release that patches multiple vulnerabilities including SSO login CSRF, user/organization enumeration, SSO existing-user binding issues, and server-side request forgery (SSRF) via the icon endpoint — an immediate upgrade is strongly advised. On the features side, vault item archiving is now supported, letting users tidy their vault without permanently deleting entries. The bundled Web Vault has been updated to v2026.4.1, and DuckDuckGo has been added as a recognized browser device type. Several SSO improvements and a fix for favicon fetching (which now checks all icon links rather than only the first) round out the release. Source release: https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0</description>
    </item>
    <item>
      <title>Paperless-ngx v2.20.15 — Safe to update</title>
      <link>https://bumplog.org/apps/paperless-ngx/</link>
      <guid isPermaLink="false">bumplog:app:paperless-ngx:v2.20.15:safe</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <description>Safe to update. This release contains only bug fixes, including a recommended security patch (GHSA-8c6x-pfjq-9gr7) addressing mail account enumeration and login/logout endpoint issues. There are no breaking changes, required migrations, or manual upgrade steps noted. What changed: v2.20.15 is a security-focused patch release that all users are encouraged to apply. It closes a disclosed vulnerability (GHSA-8c6x-pfjq-9gr7) by tightening authentication flows to use only the allauth login and logout endpoints, and by correctly scoping mail account enumeration to prevent unauthorized access. Two additional bug fixes ship alongside: one eliminates a spurious change event that could fire when switching operator types on a custom field query, and another rejects malformed requests to the API notes endpoint. Source release: https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.20.15</description>
    </item>
  </channel>
</rss>
