github WeblateOrg/weblate weblate-2026.9
Weblate 2026.9

3 hours ago

Released on September 3rd 2026.

New features

  • Repository maintenance actions now run as background tasks, avoiding request and proxy timeouts. Project-wide maintenance remains available for authorized repositories and lists components skipped because of linked-component permissions. The repository API supports the same behavior using background: true.

  • Component discovery can optionally create components from a monolingual base or new base file when no translation files exist yet.

  • Added Version control parameters to configure repository behavior per component, including force pushing, opting out of pull requests, and GitHub pull request automerge.

  • Added Migrating existing components for migrating existing Git and GitHub components to the Weblate GitHub App integration.

  • Added a Visible columns in lists preference to choose which statistics columns are shown in project, component, and language lists. See Preferences.

Improvements

  • AWS SES can now be used as the outbound e-mail transport in Docker deployments by setting WEBLATE_EMAIL_BACKEND to django_ses.SESBackend. Region, endpoint, and SES v2 API opt-in are configurable via WEBLATE_AWS_SES_REGION_NAME, WEBLATE_AWS_SES_REGION_ENDPOINT, and WEBLATE_USE_SES_V2.

  • Removing the final Weblate workspace connection for a GitHub account, or removing the workspace holding it, now also uninstalls the Weblate GitHub App from GitHub.

  • Update POT file (xgettext) now accepts multiple custom keywords (newline-separated) passed to xgettext via --keyword, enabling extraction from different function names.

  • Screenshot images are now cached in browsers to reduce repeated downloads.

  • Administrators can now find removed accounts by their former e-mail address in the audit log until AUDITLOG_EXPIRY. See Privacy regulations compliance.

  • Deployment diagnostics now detect slow filesystem metadata access in data and cache directories, and validate VCS command versions during configuration health checks instead of every process startup. See Performance report and VCS_BACKENDS.

  • Clarified the instance-wide impact of roles containing site-wide permissions, including site-wide user management.

  • Improved translation file loading performance for metadata-only string changes.

  • Reduced Celery worker startup memory usage by avoiding duplicate Django system checks and loading font rendering only when needed.

  • Billing audit logs now identify users who change plans, initiate payments, or merge billings.

  • Assigning languages to a team now uses an All languages toggle which disables the language choice when turned on, and a manually chosen set of languages is kept when toggling it. See Managing per-project access control.

  • Management notices now distinguish support package activation, status refresh, unlinking, and Discover Weblate registration.

  • Clarified generic notification hook matching and privacy behavior.

  • Clarified that Weblate does not populate Git submodules. See Git submodules.

  • The initial Search and replace action is now labeled Review changes to distinguish it from confirmation.

  • The translation flags editor now supports reopening flags for editing, arrow-key navigation, and copying with Ctrl+C. It also keeps commas inside quoted values intact, allowing flags such as regex:"^.{1,32}$" to be typed and pasted.

  • Repository failure alerts now provide guidance matching repository URL validation errors. See Troubleshooting repository URLs.

Security fixes

  • Component discovery now limits repository paths and file-mask comparisons to prevent excessive resource consumption from specially crafted repositories.

  • Rejected two-factor authentication attempts now apply AUTH_LOCK_ATTEMPTS, invalidate pending password sign-ins on lock or password change, and accept six-digit TOTP codes with leading zeroes.

  • Project backup restores now preserve all project, category, and component settings. They also allowlist repository metadata for Git, git-svn, and Mercurial to prevent archives from supplying executable configuration or repository indirection.

  • Project administrators can no longer remove API tokens belonging to other projects.

  • User listings and site-wide searches no longer expose project-scoped API tokens to users without global user viewing or editing permission.

  • Project and workspace translation memory now respects restricted component access, and restricted components no longer contribute to shared translation memory.

  • Webhook target matching no longer falls back to host/path suffix matching. Component repository URLs must match a repository URL from the webhook payload. See Matching webhook targets.

Bug fixes

  • LLM-based machine translation services now report invalid provider responses more clearly, custom OpenAI and Mistral models no longer require a model-listing endpoint, and OpenAI automatic selection supports API keys restricted to older GPT models.

  • Daily metric collection now uses independent tasks and more efficient database queries to reduce peak memory usage and avoid losing all scopes when one collection fails.

  • Database dump failures are now shown in the backups management interface.

  • GitLab merge request forks now disable Git LFS to avoid missing-object push failures. See Git LFS.

  • Notification e-mails now wrap long strings instead of overflowing, keeping the View button reachable without horizontal scrolling.

  • Creating additional components for a repository imported through the GitHub App no longer fails without showing any error, and component creation errors which previously could go unreported are now always displayed.

Compatibility

  • The json_sort_keys File format parameters is now a choice between none, case_sensitive, and case_insensitive instead of a boolean, including when reading or writing it through the component REST API; existing components are migrated automatically. See GET /api/components/(string:project)/(string:component)/.

  • The Git with force push version control system has been replaced by the git_force_push version control parameter; existing components are migrated automatically.

  • Component and category removal now preserves automatically generated translation memory by default. See Translation Memory for the optional cleanup behavior.

  • Mercurial and Subversion repository hosts can now be trusted using VCS_PRIVATE_ALLOWLIST without restricting Git to the same hosts through VCS_ALLOW_HOSTS.

  • The project deletion REST API endpoint now returns 202 Accepted instead of 204 No Content and contains a task URL in the response to track asynchronous deletion progress.

Upgrading

Please follow Generic upgrade instructions in order to perform update.

  • Docker deployments need to configure trusted proxy addresses. Set WEBLATE_TRUSTED_PROXY_ADDRESSES to preserve client IP addresses in nginx logs and Weblate when WEBLATE_IP_PROXY_HEADER=HTTP_X_FORWARDED_FOR is used; otherwise, the immediate TCP peer is used.

Contributors

Code contributions
Michal Čihař, Karen Konou, Gersona, Spyder, mmustafasenoglu, Kartik Ohri, Shweta Singh, Fabian Berg

Translations contributions
Yuri Chornoivan, Matthaiks, Steve, hoanghuy309, VfBFan, António Oliveira, Andrei Stepanov, Adam Havránek, Dick Groskamp, Aindriú Mac Giolla Eoin, Andi Chandler, Lee Vincent, Michal Čihař, Milo Ivir, Ldm Public, Peter Vančo, Alos (bop2039), Tarás Lavrentiev, Lito Parra, goeran, Любомир Василев, Vik, Bone NI, Pierfrancesco Passerini, CYAXXX, Yaron Shahrabani, Pavel Borecki, حسين نور الإسلام, amano, reducedradius, Fjuro, Frostre_, Sup! 0_0, Ulrik, xiezhihai, Yoshi, Alexander Gabilondo, Eduard Ereza Martínez, Watchman89, Kyotaro Iijima, AlexYang, justcontributor, Background update, Arif Budiman, Harsha Kanaparthi, notlin4, KuroisKitsune, Zahid Rizky Fakhri, Michal Várady, Massimo Pissarello, HThuren, SeyhaLite, David Wagener, Yauhen, Anucha Hlownonkor, michael0820, Artyom Rybakov, Nhật Nhật, 子悦解说, Mahdi B. Jahani, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝)

Documentation contributions
Michal Čihař, Gersona, Karen Konou, Spyder, mmustafasenoglu, Kartik Ohri, Shweta Singh

All changes in detail.

Don't miss a new weblate release

NewReleases is sending notifications on new releases.