github WeblateOrg/weblate weblate-2026.10
Weblate 2026.10

4 hours ago

Released on October 1st 2026.

New features

Improvements

  • Component configuration errors are reported before fetching the repository when repository files are not needed for validation.

  • Clarified that site-wide team management can grant access to private projects independently of the team manager’s own project access.

  • Improved checks, automatic fixes, glossary matching, and machine translation for independent alternatives in multivalue formats.

  • Added a thumbnail picker to associate existing screenshots with a string from the translation editor.

  • Repository maintenance now checks permissions on the repository-owning component and explains where missing permissions are required.

  • Automatic translation using other components now prefers translations with matching source text and context.

  • Aligned string search filters with the status overview’s order and colors, and added an All strings option to clear the query.

  • Added monthly instance activity to the data sent with support integration for activity monitoring and discovery ranking.

  • Improved repository maintenance with disabled push controls when push configuration is missing and direct links to component VCS settings.

  • The automatic translation add-on can create approved strings, falling back to translated strings when reviews are disabled for the target language.

  • Added independent term alternatives and scoped metadata to TBX glossaries, including metadata-preserving TBX exports.

  • Whitespace characters are now rendered consistently in the source string display and the translation editor, and different kinds of whitespace are now distinguishable from each other.

  • Added a font-monospace flag to display a string in the translation editor using a monospace font, useful for aligning command-line or terminal output.

  • History View details and Revert actions are larger, more widely spaced, and show a hover and focus background.

  • The units API now links to a unit’s associated screenshots and supports listing, assigning, and removing them via GET /api/units/(int:id)/screenshots/.

  • Added a keyboard shortcut to approve a translation and save and continue.

  • Clarified translation quality filter explanations and effective per-language review settings, with links to workflow configuration.

  • Reworked the Automatic suggestions tab to use the same layout as suggestions, and it now shows the translation memory context of each match.

  • The xgettext and Meson extraction add-ons now bundle common XML translation rules and support project-local ITS directories for extracting mixed source formats into a shared POT.

  • Repository maintenance now links to the latest pull or merge request opened by Weblate.

  • The project Files menu now lists translation download formats from WEBLATE_EXPORTERS instead of a fixed subset.

  • LLM automatic suggestions now show the model and, for custom API endpoints, the host that produced them.

  • Automation actions can select strings from the triggering change or a previous action’s affected units. See Automation reference and cookbook.

  • Unified browsing and searching strings, aligned search filters with the status overview, and added direct editor access to language-specific lists and an All strings filter.

  • Improved translation history with faster browsing, date navigation, and clearer actions.

  • Improved screenshot assignment in the editor with a thumbnail picker, predictable ordering, and removal without reloading.

  • The editor now distinguishes whitespace in source and translation strings, supports the font-monospace flag, and accepts decimal font-spacing values.

  • Added a Markdown preview to comments, explanations, announcements, and project instructions.

  • Added a keyboard shortcut to approve a translation and continue.

  • Clarified translation quality filters and effective per-language review settings.

  • Improved translation memory lookup performance and added match context to automatic suggestions.

  • Reduced aggregation overhead for the inconsistent translations check on large projects.

  • Moved related quality check updates to background tasks to avoid slow saves when many strings share a source or translation.

  • Markdown links quality check now detects untranslated link titles.

  • Automatic translation across components now prefers matching source text and context. The automatic translation add-on can create approved strings, or translated strings when reviews are disabled.

  • Improved checks, fixes, glossary matching, and machine translation for multivalue alternatives.

  • TBX glossaries now support independent term alternatives and scoped metadata, preserved on export.

  • The xgettext and Meson add-ons now support bundled XML rules and project-local ITS directories.

  • Added uploaded file language checking with an override in the upload form and API.

  • Translation file uploads through the API accept form field content without a filename.

  • Repository maintenance now checks permissions on the repository-owning component, links to VCS settings, and disables unavailable push controls.

  • SSH repository connections now try IPv4 and IPv6 addresses in a staggered sequence and report failed addresses and ports.

  • Add-on error diagnostics now link to the responsible add-on configuration.

  • Added monthly instance activity to support integration data.

  • Suggestions can be shown in the Zen Mode and accepted, rejected, or voted on in place.

  • Added a separate repository browser URL for translation files.

  • Docker startup now reports invalid nginx-related environment values before attempting to start nginx.

  • Squash Git commits now supports squashing together per author and language.

  • The automatic translation API can run as a background task. See POST /api/translations/(string:project)/(string:component)/(string:language)/autotranslate/.

Security fixes

  • Project administrators can no longer see blocked users’ account e-mail addresses without site-wide user management permission.

  • Removed repositories created from rejected component ZIP and document uploads.

  • Prevented App Store metadata files from following symbolic links outside the component repository.

  • Protected translation reverts against cross-site request forgery.

  • Prevented client-supplied forwarded IP headers from bypassing anonymous API rate limits.

  • Prevented whitespace-only username searches from listing users through GET /api/users/.

  • Prevented project access managers from assigning users to site-wide teams associated with the project.

  • Invalidated outstanding password reset links after password changes regardless of e-mail address casing.

  • Prevented concurrent requests from exceeding configured web action rate limits.

  • Prevented repository URLs from injecting executable Mercurial configuration.

  • Limited XLIFF language declarations in uploads and the number and size of translation alternatives to prevent resource exhaustion.

  • Enforced language-scoped screenshot permissions and restricted component access in translation consistency and direct automatic translation workflows.

  • Prevented project API tokens from inheriting permissions through automatic team assignments.

  • Protected Git and Mercurial metadata consistently in repository paths and downloads, and excluded known foreign VCS metadata when importing component ZIP files.

  • Prevented notification subscriptions from exposing inaccessible project and component settings through the REST API and profile settings.

  • Rate-limited password-reset requests for unknown e-mail addresses.

Bug fixes

  • Project backups now tolerate missing or damaged repositories and preserve available files and translation data during restore.

  • Project MO archive downloads now skip incompatible file formats without failing the download.

  • Made eligible automatic-translation sources consistent across web, API, and Automation add-on configuration.

  • Fixed move_language and automatic language alias updates to preserve language-specific settings and permission limits, and detect conflicting translations or settings before moving content.

  • Suppressed OpenSSH post-quantum key exchange warnings that obscured errors from SSH repositories.

  • Fixed the BBCode markup check for parameterized, nested, and multiline tags.

  • Improved plain-text notification e-mails with readable links and tables instead of Markdown.

  • Project language archive downloads in the REST API now honor language-scoped download permissions consistently with the web interface.

  • Fixed authentication initialization with Sample configuration to start Granian with ASGI when Sentry instrumentation is enabled.

  • Fixed status widgets for categories, category-language pages, and workspaces, and corrected statistics for nested categories and deleted String labels.

  • Fixed MIME nesting and reduced the size of inline branding images in notification e-mails.

  • Anthropic now preserves path prefixes in custom base URLs.

  • Fixed false positives in the consecutive duplicated words check for South Asian languages and prevented the punctuation spacing check from inserting spaces in URLs.

  • Fixed the maximum size check preview shifting text when font-spacing is set.

  • Fixed Docker startup warning checks when the warning directory is missing or inaccessible.

  • Fixed an upgrade failure when migrating dismissed component alerts from releases before 2026.8.

  • Fixed the search results refresh icon color in themes and on hover.

  • Fixed truncated grouped summaries in notification e-mails; the 100 entries limit now applies only to listings of individual changes.

  • Fixed bilingual glossary terms appearing as untranslatable when translating in their source language.

  • Fixed component discovery with inherited licenses and other inherited settings.

  • Backups containing legacy component formats (e.g plainxliff, csv-utf-8) are now correctly restored.

  • Fixed switching between singular and plural forms when adding new strings.

Compatibility

  • An explicit source-wide read-only flag now takes precedence over translation flags. Remove it from the source to allow editing.

  • Existing project API tokens lose permissions inherited from non-project teams. Assign required permissions through project-specific teams.

  • API throttles now use API_RATELIMIT_ANON and API_RATELIMIT_USER instead of REST_FRAMEWORK["DEFAULT_THROTTLE_RATES"].

  • API authentication now rejects unsupported authentication schemes, such as Basic, with HTTP 401, including when a valid browser session is present.

  • Notification subscription API responses now expose project and component as nullable URL strings instead of nested objects.

  • The former plainxliff and xliff2-placeables file formats are migrated to XLIFF 1.1 and 1.2 / XLIFF 2.0 with the xliff_placeables File format parameters.

  • Norwegian Bokmål now uses nb as its built-in language code while preserving nb_NO support, see Language definitions.

Upgrading

  • Add weblate.automation to custom INSTALLED_APPS before migrating. If WEBLATE_ADDONS explicitly lists the automation add-on, change its import path to weblate.automation.addon.AutomationAddon. The official Docker image includes the new app.

  • Existing contributor comments add-ons migrate to component file format parameters. Remove the obsolete add-on from custom WEBLATE_ADDONS and DEFAULT_ADDONS settings; new components no longer inherit it.

  • Add weblate.api and weblate.kotlin_sdk to INSTALLED_APPS before migrating. The official Docker image includes both. Installing the Kotlin app does not enable CDN publication on any component.

  • In non-Docker settings, move the anon_throttle and user_throttle arguments from get_drf_settings and any custom REST_FRAMEWORK["DEFAULT_THROTTLE_RATES"] values to API_RATELIMIT_ANON and API_RATELIMIT_USER. Existing Docker rate-limit variables still work.

Please follow Generic upgrade instructions in order to perform update.

Contributors

Code contributions
Michal Čihař, Karen Konou, michael-smt, Mark Davies, Diptajoy Mistry, krisna, Metin Kılagöz, MIHAIL N., Claude Sonnet 5, mmustafasenoglu, i4i, Mustafa Senoglu, anishkun, Anish kunda, Gersona, Magnus Karlsson, JUSHUANGHUI LI, Chimwemwe Siyingwa, krisnaparahita, Dr Alex Mitre, Aditi Tarate, Kartik Ohri, Suleyman Arif Uzun

Translations contributions
hoanghuy309, Watchman89, Adam Havránek, Fjuro, justcontributor, Szafranek13, Tony Ng, Chloe Wang, VfBFan, Valentin Ljuba, Daniel Nylander, Andrei Stepanov, Michal Čihař, Matthaiks, Arif Budiman, Любомир Василев, Aindriú Mac Giolla Eoin, Yaron Shahrabani, Adolfo Jayme Barrientos, Sup! 0_0, Lee Vincent, Milo Ivir, Dick Groskamp, Eduard Ereza Martínez, Ricky Tigg, Mickaël Binos, reducedradius, Artyom Rybakov, Kyotaro Iijima, Jim Kats, Supaplex, Peter Vančo, Stysusss, Ulrik, Ldm Public, Júlia Rosell Saldaña, Deleted User, eulalio, Zahid Rizky Fakhri, Takeru Mikenu, 이정희, António Oliveira, xXx, தமிழ்நேரம், Kaya Zeren, Bone NI, QuietCedar47, Andi Chandler, Ettore Atalan, Massimo Pissarello, Besnik Bleta, Chimwemwe Siyingwa, Nicat, Sketch6580, Areera

Documentation contributions
Michal Čihař, Karen Konou, michael-smt, Diptajoy Mistry, Maciej Olko, MIHAIL N., Claude Sonnet 5, mmustafasenoglu, i4i, Mustafa Senoglu, anishkun, Anish kunda, Gersona, Magnus Karlsson, JUSHUANGHUI LI, Chimwemwe Siyingwa, krisnaparahita, krisna, Claude Opus 5.5, spatterlight, Dr Alex Mitre, Aditi Tarate, Kartik Ohri, Suleyman Arif Uzun

All changes in detail.

Don't miss a new weblate release

NewReleases is sending notifications on new releases.