github Kha-kis/arr-dashboard v2.9.1
v2.9.1 — Security Patches, Incognito Mode, TRaSH Cloning, Docs Overhaul

latest releases: v2.24.1, v2.24.0, v2.23.0...
5 months ago

What's Changed

Security

  • Dependency overrides — Updated hono to 4.12.8 (CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, GHSA-v8w9), @hono/node-server to 1.19.11 (CVE-2026-29087), and flatted to 3.4.2 (prototype pollution)
  • Input sanitization — Added validation for TRaSH profile match fields in clone template API
  • Semgrep fix — Resolved unsafe format string finding in pattern tester

Incognito Mode (Hide Sensitive Data)

  • Complete coverage across all features — Extended incognito mode to 40+ components across every page, tab, modal, filter dropdown, chart, and toast message
  • Dashboard — Hides media titles, usernames, server names, device names, platform info in Plex widgets, health messages, and username greeting
  • Library — Hides titles, overviews, poster images, instance names, file paths, and Plex usernames
  • Calendar — Anonymizes event titles, instance names, and overviews
  • Statistics — Hides Plex usernames, media titles, device/player names across all charts
  • Requests (Seerr) — Anonymizes media titles, user display names, email addresses, avatar images
  • Hunting / Queue Cleaner / Library Cleanup — Hides instance names, item titles, indexer names
  • Notifications — Anonymizes channel names and event titles
  • Settings — Hides instance labels, service URLs, and username
  • Queue messages — Added Lidarr music release anonymization patterns
  • New utility functions: getLinuxUsername, getLinuxDevice, getLinuxSectionName, getLinuxServerName, getLinuxEmail

TRaSH Guides

  • Cloned template quality display — Templates created via "Clone from Instance" now properly show quality configuration in the editor
  • TRaSH profile linking — Cloned templates are linked to their matching TRaSH Guides profile for ongoing score updates. User score overrides are preserved

Documentation

  • README — Complete rewrite with all 8 supported services, 16 new screenshots, updated tech stack, 24 wiki links
  • Wiki — Complete rewrite: 25 pages covering every feature (up from 9 pages at v2.6.6)
  • DOCKERHUB — Updated for v2.9.1 with all new features

Full Changelog: v2.9.0...v2.9.1

Don't miss a new arr-dashboard release

NewReleases is sending notifications on new releases.