github mealie-recipes/mealie v3.26.0

4 hours ago

🍴🍴🍴🍴🍴🍴

Welcome to the latest release of Mealie! We have tons of new features packed into this one, as well as a large collection of bug fixes. Check them out below 👇

🚨 BREAKING CHANGE

Mealie now checks where its own outgoing requests are going. Anything the server fetches on your behalf, such as importing a recipe from a URL, downloading a recipe image, sending a webhook, or running a recipe action, is only allowed to reach addresses on the public internet.

Webhooks and recipe actions were not checked before, and the checks on recipe imports were narrower than they are now. If any of these pointed at something on your own network, they will stop working after this update.

If you need a target on your own network to keep working, allow it explicitly with HTTP_ALLOW_LIST, which accepts hostnames or CIDRs. To keep a Tailscale host reachable, for example:

HTTP_ALLOW_LIST=100.64.0.0/10

For more information, check out the docs and the in-app announcement.

🎉 Highlights

You can now add substitutions to your ingredients. We support two kinds of substitutions:

Recipe-specific substitutions:

image image

Common substitutions (not tied to specific recipe, edited on the data management page):

image image

Substitutions are (optionally) considered in the recipe finder, too!
image


You can now link recipe notes to individual steps:
image
image

🚨 Breaking changes

  • fix: harden server-initiated HTTP against SSRF and DNS rebinding @hay-kot (#7914)

✨ New features

🐛 Bug fixes

🧰 Maintenance

14 changes

📚 Documentation

🔨 Internal development

⬆️ Dependency updates

14 changes

🙏 New Contributors

🍴🍴🍴🍴🍴🍴

Don't miss a new mealie release

NewReleases is sending notifications on new releases.