You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Chore(deps): Bump the utilities-patch group across 1 directory with 2 updates @dependabot[bot] (#14338)
Chore(deps): Bump the pre-commit-dependencies group across 1 directory with 3 updates @dependabot[bot] (#14351)
Chore(deps-dev): Bump types-channels from 4.3.0.20260408 to 4.3.0.20260518 @dependabot[bot] (#14335)
docker(deps): Bump astral-sh/uv from 0.12.20-python3.14-trixie-slim to 0.12.23-python3.14-trixie-slim @dependabot[bot] (#14327)
Chore(deps): Bump the actions group across 1 directory with 4 updates @dependabot[bot] (#14332)
Chore(deps): Bump the uv group across 1 directory with 2 updates @dependabot[bot] (#14325)
Chore(deps): Bump the frontend-angular-dependencies group across 1 directory with 13 updates @dependabot[bot] (#14329)
Chore(deps-dev): Bump prettier from 3.9.8 to 3.9.9 in /src-ui @dependabot[bot] (#14331)
Chore(deps-dev): Bump the frontend-eslint-dependencies group across 1 directory with 3 updates @dependabot[bot] (#14330)
Chore(deps-dev): Bump zensical from 0.0.64 to 0.0.65 in the development group @dependabot[bot] (#14326)
Chore(deps): Bump the uv group across 1 directory with 2 updates @dependabot[bot] (#14314)
Chore(deps): Bump the utilities-minor group across 1 directory with 7 updates @dependabot[bot] (#14305)
docker-compose(deps): bump greenmail/standalone from 2.1.13 to 2.1.14 in /docker/compose @dependabot[bot] (#14281)
docker(deps): Bump astral-sh/uv from 0.12.16-python3.14-trixie-slim to 0.12.20-python3.14-trixie-slim @dependabot[bot] (#14282)
Chore(deps): Bump the pre-commit-dependencies group across 1 directory with 3 updates @dependabot[bot] (#14283)
Chore(deps): Bump the utilities-patch group across 1 directory with 6 updates @dependabot[bot] (#14297)
Chore(deps): Bump the actions group across 1 directory with 10 updates @dependabot[bot] (#14301)
Chore(deps-dev): Bump the frontend-jest-dependencies group across 1 directory with 2 updates @dependabot[bot] (#14286)
Chore(deps-dev): Bump eslint from 10.10.0 to 10.11.0 in /src-ui in the frontend-eslint-dependencies group across 1 directory @dependabot[bot] (#14287)
Chore(deps-dev): Bump @types/node from 26.5.0 to 26.6.2 in /src-ui @dependabot[bot] (#14288)
Chore(deps-dev): Bump prettier from 3.9.6 to 3.9.8 in /src-ui @dependabot[bot] (#14289)
Chore(deps): Bump the frontend-angular-dependencies group across 1 directory with 10 updates @dependabot[bot] (#14285)
Chorehancement: set manifest CORS for credentials @shamoon (#14307)
Chore(deps): Bump the utilities-minor group across 1 directory with 7 updates @dependabot[bot] (#14305)
Chore(deps): Bump the utilities-patch group across 1 directory with 6 updates @dependabot[bot] (#14297)
Chore(deps-dev): Bump the frontend-jest-dependencies group across 1 directory with 2 updates @dependabot[bot] (#14286)
Chore(deps-dev): Bump eslint from 10.10.0 to 10.11.0 in /src-ui in the frontend-eslint-dependencies group across 1 directory @dependabot[bot] (#14287)
Chore(deps-dev): Bump @types/node from 26.5.0 to 26.6.2 in /src-ui @dependabot[bot] (#14288)
Chore(deps-dev): Bump prettier from 3.9.6 to 3.9.8 in /src-ui @dependabot[bot] (#14289)
Chore(deps): Bump the frontend-angular-dependencies group across 1 directory with 10 updates @dependabot[bot] (#14285)
Fix: use version page_count for versioned document @shamoon (#14280)
v3.0.0 — Security: enforce current permissions in autocomplete; bound email linkification; validate/sanitize uploaded logos; opt-in blocking internal mail hosts; permission check fixes
v3.0.2 — Bug fix only (broken migration repair)
Recommendations
MERGE PRIORITY: LOW — No security vulnerabilities found in either version. All 15 previously disclosed GHSA advisories are patched in both the old (2.20.15) and new (3.0.2) versions. Merge at own discretion.
⚠️This is a major version bump (2.x → 3.x) with breaking changes. Review the v3.0.0 release notes for breaking changes including dropped Python 3.10 support, API version changes, removed features (document encryption, pybzar barcode reader), and pre/post consume script changes.
⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.
=== NEW: 3.0.1 ===
=== OSV.dev query for ghcr.io-paperless-ngx-paperless-ngx@3.0.1 (ecosystem: container) ===
No vulnerabilities found on OSV.dev for ghcr.io-paperless-ngx-paperless-ngx@3.0.1
=== NVD query for 'ghcr.io-paperless-ngx-paperless-ngx' (version filter: 3.0.1) ===
No CVEs found on NVD for keyword: ghcr.io-paperless-ngx-paperless-ngx
=== GHSA query for ghcr.io-paperless-ngx-paperless-ngx (ecosystem: container) ===
{"message":"Invalid request.\n\nInvalid input: `container` is not a possible value. Must be one of the following: rubygems, npm, pip, maven, nuget, composer, go, rust, erlang, actions, pub, other, swift.","documentation_url":"https://docs.github.com/rest/security-advisories/global-advisories#list-global-security-advisories","status":"422"}No GHSA advisories found
Recommendations
Review the findings above before merging.
Verify version-range applicability of each CVE before treating as actionable.
⚠️ This comment was posted by an automated security scanner (Ciel, fast mode).
To re-scan, trigger the renovate-security-scanner skill.
tinfoildBot
changed the title
feat(oci/paperless-ngx)!: Update 2.20.15 ➼ 3.2.1
feat(oci/paperless-ngx)!: Update 2.20.15 ➼ 3.3.0
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.20.15→3.3.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
paperless-ngx/paperless-ngx (ghcr.io/paperless-ngx/paperless-ngx)
v3.3.0: Paperless-ngx v3.3.0Compare Source
paperless-ngx 3.3.0
Features / Enhancements
Bug Fixes
Documentation
Maintenance
Dependencies
27 changes
All App Changes
41 changes
v3.2.1: Paperless-ngx v3.2.1Compare Source
paperless-ngx 3.2.1
Bug Fixes
Dependencies
All App Changes
4 changes
v3.2.0: Paperless-ngx v3.2.0Compare Source
paperless-ngx 3.2.0
Features / Enhancements
Bug Fixes
Dependencies
29 changes
All App Changes
80 changes
set_permissions@stumpylog (#13806)modify_custom_fields@stumpylog (#13807)Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.