Released on October 9th 2026.
New features
-
Added opt-in team synchronization from identity providers, including GitLab group mapping and group-based login restrictions.
-
Added
DEFAULT_NOTIFICATIONSto configure Notifications settings for new users. -
Added Push on update to push only after committing translations, not after upstream updates.
Improvements
-
Improved diagnostics for failed GitHub pull request creation.
-
Added a Kotlin SDK quickstart and an overview of official and third-party libraries and SDKs.
-
Clarified the labels and consequences of reset actions in Repository maintenance.
-
Authentication method names and icons now come from python-social-auth, including current service branding, while existing authentication settings overrides remain supported.
-
Improved full name initialization from provider names during social authentication.
-
Made unused components and glossary languages warning diagnostics and enabled dismissal for them and suspected monolingual or bilingual file-format misconfiguration.
-
Clarified that contributing to shared translation memory publishes strings and their origin outside project access control.
Security fixes
-
Prevented project backup imports from granting site-wide permissions through restored project teams (GHSA-pgmx-p3h7-7q8x).
-
Prevented Automation workflow configuration from disclosing references to restricted components in change history.
-
Marked access-controlled status widget responses as private to shared caches.
-
Disallowed filesystem paths and the
filescheme for version control repository URLs. -
Added restrictive cache controls to authenticated HTML responses to prevent previously viewed content from being restored after logout.
-
Hardened version control metadata filtering against trailing-dot and trailing-space path aliases.
-
Prevented sitemaps from disclosing restricted component and translation URLs.
-
Restricted stale Git lock cleanup to the repository running the failed command and prevented empty file lists from committing unrelated changes.
-
Enforced e-mail confirmation code expiry through Python Social Auth using
AUTH_TOKEN_VALID, independently of scheduled cleanup.
Bug fixes
-
Fixed Key filter for JSON and other formats supporting both monolingual and bilingual use.
-
Fixed acting-user attribution and display for administrative account changes in audit logs.
-
Removed expired OpenID associations and OIDC login nonces during hourly authentication storage cleanup.
-
Fixed Project level backups restoration of translation file language aliases and duplicate team names, and improved validation error formatting.
-
Prevented concurrent creation of duplicate project team names and preserved custom teams when enabling features that require conflicting built-in team names.
-
Prevented duplicate initiation of provider authentication and improved recovery guidance for authentication failures and token errors.
-
Components using the GitHub App now follow renamed or transferred repositories; existing Apps need to subscribe to the
Repositoryevent, see App webhook URL.
Compatibility
- The
filescheme is disabled for security reasons and can no longer be included inVCS_ALLOW_SCHEMES. Weblate now fails to start until it is removed from the setting and existing components are migrated to supported repository URLs.
Upgrading
Authentication names and provider logos now come from python-social-auth. Add social_django.finders.SocialAuthIconFinder after the standard finders in STATICFILES_FINDERS in settings.py, then run weblate collectstatic --noinput. The example configuration and Docker image already include the finder. Existing authentication name and image settings remain supported. See Authentication for details.
If you maintain a custom SOCIAL_AUTH_PIPELINE in settings.py, add social_core.pipeline.social_auth.social_names immediately after social_core.pipeline.social_auth.social_details. Name conversion now runs in this shared step, and Weblate no longer joins provider first and last names itself. Existing full names are preserved. The example configuration and Docker image already include the new step. See Authentication for details.
Please follow Generic upgrade instructions in order to perform update.
Contributors
Code contributions
Michal Čihař, Kartik Ohri, Karen Konou, Philipp R, michael-smt
Translations contributions
Michal Čihař, VfBFan, Eduardo Addad de Oliveira, Basheer Radman, Любомир Василев, Watchman89, Matthaiks, Peter Vančo, Negonkey, Andrei Stepanov, Fjuro, justcontributor, reducedradius, Lee Vincent, Arif Budiman, Florent, Alexis Launay, Alagirisamy Rengaraj, Sup! 0_0, Milo Ivir, Adolfo Jayme Barrientos, Yaron Shahrabani, Kristoffer Grundström, Dick Groskamp, Ldm Public, hoanghuy309, Nicat, Nitin Jangra, Temuri Doghonadze, Horus68, Szafranek13, LaKato, Daniel Nylander, Massimo Pissarello, Aindriú Mac Giolla Eoin, Dan, Eduard Ereza Martínez
Documentation contributions
Michal Čihař, Kartik Ohri, Philipp R, michael-smt