App Suite Releases
  • 8.47
  • 8.35
  • 7.10.6
Imprint
  • 8.47
  • 8.35
  • 7.10.6
Imprint
  • Release 8.53Upcoming
    • Noteworthy Changes
      • Important Changes
      • App Suite Middleware
    • Changelogs
      • App Suite UI
      • App Suite Middleware
      • Additional Components
        • AI Service
        • Booking Service
        • OX Guard UI
        • Switchboard
        • UI Service
    • Helm Charts
      • AI-Service documentation
      • App Suite Stack Chart
      • Booking
      • Helm Chart core-cacheservice
      • Helm Chart core-documentconverter
      • Helm Chart core-imageconverter
      • core-mw
      • UI Service
      • Switchboard
  • Release 8.52
  • Release 8.51
  • Release 8.50
  • Release 8.49
  • Release 8.48
Maintained. Older releases are best effort.
Upcoming
Not released yet
LTS
Long-term support branch

App Suite Middleware

8.53.267 - 2026-09-03

Fixed

  • Refresh a session's OAuth tokens before mail access uses them outside of HTTP requests, e.g. for IMAP-IDLE (core-gitlab-com#36)

8.53.265 - 2026-09-02

Changed

  • ASB-56: Cap autocomplete results and honor right_hand_limit for all sort orders
    • SCR-1877: New configuration option for contact auto-complete result limiting

8.53.264 - 2026-09-02

Fixed

  • ASB-25: Report the server's refusal when moving a mail folder into a shared mailbox is denied

8.53.261 - 2026-09-02

Fixed

  • ASB-21: Register late-looked-up mailboxes with their actual subscription state instead of LIST-only

8.53.260 - 2026-09-02

Added

  • ASB-65: Import parameter applyDefaultAlarms to apply the user's own reminders to imported appointments
    • SCR-1875: New optional parameter applyDefaultAlarms for the iCal import request

Fixed

  • ASB-21: Register late-looked-up mailboxes with their actual subscription state instead of LIST-only

8.53.259 - 2026-09-02

Added

  • ASB-65: Import parameter applyDefaultAlarms to apply the user's own reminders to imported appointments
    • SCR-1875: New optional parameter applyDefaultAlarms for the iCal import request

Fixed

  • ASB-190: Keep a user's SMS tokens in one cluster map entry instead of scanning the whole Redis key space to count them

8.53.258 - 2026-09-02

Fixed

  • ASB-192: Reload lean reloadables when a configuration file they declared interest in changes

8.53.257 - 2026-09-01

Fixed

  • ASB-22: Let the folder's create-objects permission suffice for importing iCal data

8.53.256 - 2026-09-01

Fixed

  • ASB-22: Let the folder's create-objects permission suffice for importing iCal data
  • ASB-148: Parse a multipart body that lost its start boundary instead of failing the whole mail

8.53.255 - 2026-09-01

Fixed

  • ASB-189: Keep the bearer token alive across the WebDAV auth cache round trip

8.53.254 - 2026-09-01

Fixed

  • ASB-185: Let an attendee reply from the mail module to an appointment in an inaccessible public folder

8.53.252 - 2026-08-31

Fixed

  • ASB-119: Leave \Draft flags untouched when a draft is copied or moved into a foreign folder

8.53.251 - 2026-08-31

Fixed

  • ASB-180: Apply the configured batch sizes when moving a context and keep its idle connections alive
  • ASB-181: Drop the cached database assignment when a failed context move is reverted

8.53.250 - 2026-08-31

Fixed

  • ASB-180: Apply the configured batch sizes when moving a context and keep its idle connections alive
  • ASB-181: Drop the cached database assignment when a failed context move is reverted

8.53.249 - 2026-08-31

Fixed

  • ASB-179: Bind OXTaskManagement again so the jobcontrol CLI works

8.53.248 - 2026-08-31

Fixed

  • ASB-146: Isolate a failing mail account from account status and folder listing

8.53.247 - 2026-08-30

Fixed

  • ASB-175: ASB-175: Optionally use the configured no-reply address as From for internal calendar notifications
    • SCR-1854: New property com.openexchange.calendar.useNoReplyAddressForNotifications

8.53.246 - 2026-08-28

Fixed

  • ASB-171: Gate deputy modules on the sharing permission and keep permissions removable

8.53.245 - 2026-08-28

Fixed

  • Resolve image URLs independent of the configured dispatcher prefix

8.53.243 - 2026-08-28

Fixed

  • SCR-1853: Keep the deputy mail ACL baseline in its own table and fix the surrounding METADATA handling

8.53.242 - 2026-08-28

Fixed

  • SCR-1853: Keep the deputy mail ACL baseline in its own table and fix the surrounding METADATA handling

8.53.239 - 2026-08-27

Added

  • ASB-132: Light-weight deputy action=reverseIds listing grantors without resolving grant details
    • SCR-1844: New deputy module action reverseIds that lists the granting users without resolving grant details
  • SCR-1845: New Configuration Option for Expanding Nested LDAP Distribution Lists

Changed

  • ASB-132: Report send-on-behalf-of and the granter's addresses in deputy action=reverseIds
    • SCR-1844: New deputy module action reverseIds that lists the granting users without resolving grant details
  • Align the active-task watcher with the request watcher (core-gitlab-com#26)
    • SCR-1849: New configuration options for the thread pool's active-task watcher
    • SCR-1850: Changed reporting of long-running tasks by the thread pool's active-task watcher
  • Make the thread pool's saturation semantics effective and observable (core-gitlab-com#27)
    • SCR-1847: Changed behavior of the thread pool saturation settings
    • SCR-1848: New thread pool saturation metrics
  • Give AJAX job-queue jobs their own virtual-thread budget instead of the shared one (core-gitlab-com#28)
    • SCR-1841: New configuration option for the AJAX job queue

Fixed

  • ASB-162: Parse mail filter rule metadata for non-IPv4 update sources and heal polluted rule names

8.53.217 - 2026-08-27

Added

  • ASB-120: com.openexchange.mail.import.enforceFromValidation to optionally validate From on forced import
    • SCR-1824: New property com.openexchange.mail.import.enforceFromValidation
  • ASB-132: Honor an explicitly configured read responses timeout for primary and secondary IMAP accounts
    • SCR-1843: New configuration options for capping how long IMAP responses are read from the primary and secondary account
    • SCR-1844: New deputy module action reverseIds that lists the granting users without resolving grant details
  • SCR-1818: Token that hands out a whole message as .eml file without a session
    • SCR-1819: New properties for eml token lifetime, message size limit and concurrent token downloads
  • SCR-1822: Command-line tool threaddump for dumps covering virtual threads
  • SCR-1825: New configuration option for Redis Sentinel authentication
  • SCR-1826: New metrics for the Redis circuit breakers and bulkhead
  • SCR-1827: New configuration option for the Redis connector start-up behavior
  • SCR-1845: New Configuration Option for Expanding Nested LDAP Distribution Lists
  • Accept administrative credentials from the authorization header on the gRPC endpoint
  • Complete the gRPC coverage of context, user and deputy provisioning
  • Copy the ical4j resources as part of gradlew eclipse
  • Documentation for the mail account property infixes
  • Documentation for the virtual-thread executor metrics
  • Drive linux client identifier
  • Enable the Gradle configuration cache for the non-release image build and the unit tests
  • End-to-end regression test for a decorating javax filter on the Jetty engine
  • Expose reseller administration and restriction management via gRPC
  • Expose session maintenance via gRPC
  • Expose shared account provisioning and permission management via gRPC
  • Expose the server, database, filestore and maintenance reason registry via gRPC
  • Generate the sieve parser sources as part of gradlew eclipse
  • Honor the ".secondary" property infix alongside ".primary" for mail accounts
  • Make the provisioning gRPC server configurable, TLS-capable and stop it cleanly on shutdown
  • Micrometer meters and JMX MBean for the virtual-thread executor
  • Persist the configuration cache state across builds via per-job archives on the shared PVC
  • Publish each main build's dependency set to the shared read-only Gradle dependency cache
  • Serve HTTP/2 on the cleartext listener behind a property, with a per-connection stream-churn bound (core-gitlab-com#1)
  • Redirect reads to the master while a read replica reports broken or excessive replication lag (core-gitlab-com#4)
  • Let the reseller extension take part in the usercopy provisioning call (core-gitlab-com#15)
    • SCR-1814: Reseller ownership and restrictions are now enforced when copying a user
  • Optionally share replication monitor transaction counters across nodes via the distributed cache (core-gitlab-com#20)
  • Report spill-over volume, expose the timer executor via JMX and cover the untested paths (core-gitlab-com#31)
    • SCR-1840: New JMX bean for the timer executor and spill-over volume in its warning
  • Routing test asserting every OXUserInterface delegate forwards to the resolved service (support#1632)

Changed

  • ASB-132: Report send-on-behalf-of and the granter's addresses in deputy action=reverseIds
    • SCR-1844: New deputy module action reverseIds that lists the granting users without resolving grant details
  • SCR-1817: Replace the Guava caches with Caffeine
  • SCR-1827: Await the Redis end-point on start-up by default again
  • SCR-1828: Run IMAP-IDLE cycles on virtual threads and expose listener metrics
  • SCR-1838: Enable the in-memory cache layer by default with a 5 s time-to-live
    • SCR-1839: New configuration option for remote invalidation of the in-memory cache layer
  • Allow external developers to skip the VPN-only Artifactory repository
  • Answer only GET and HEAD on the Jetty liveness listener
  • Build the release image with the configuration cache now that the image content is proven version-independent
  • Bump OSGi Gradle plugin to 5.0.1 to close leaked JAR file handles during dependency resolution
  • Collect a virtual-thread-aware dump in oxsysreport
  • Correct the Jetty access log documentation and the bundle stop rationale
  • Cover virtual threads in the out-of-memory thread dump
  • Demote the uncaught-exception thread dump to debug level and rate-limit it
  • Document the measured configuration cache archive size and transfer times
  • Drop the NFS-read GRADLE_RO_DEP_CACHE consumption in favor of the local warm-up copy
  • Drop the thread dump from the uncaught-exception handlers
  • Dump virtual threads too when the graceful shutdown does not get through
  • Gate release promotion on the image version and correct the store-skip rationale
  • Indicate the folder admin flag on administrable calendar folders of shared accounts and reject permission changes
  • Keep five configuration cache entries per key so parallel merge requests no longer evict each other's entry from the shared archive
  • Move the build plugin pins into the version catalog gradle/libs.versions.toml
  • Name the exceeded limit and the client in the rate limit rejection log
  • Parallelize configuration cache misses so cold configuration phases finish faster
  • Pin the Core Image workspace path so configuration cache entries are reusable across jobs
  • Reject granting further entities access to the mail folders of a shared account
  • Remove the configuration cache wiring, its entries cannot be reused on ephemeral agents
  • Resolve the documented configdb configuration properties
  • Restore the configuration cache wiring for the non-release image build and the unit tests
  • Run six instead of four parallel integration tests per fork so a long suite no longer starves its fork's class queue
  • Run the bundle class path check in the artifact-producing build path
  • Skip the configuration cache store on release runs to keep the shared archive on the MR-family state
  • Sort mail folders by precomputed collation keys instead of re-collating on every comparison
  • Split the configuration cache archive into a shared user-home tier and a slim per-job entry tier
  • Stage the java-commons drop-in jars from Gradle instead of the Ant script
  • State in showruntimestats that virtual threads are not listed
  • Stop publishing to the shared dependency cache, core-test owns that snapshot
  • Stop shipping renamed configuration properties under their new names
  • Store configuration cache entries on release runs into a trusted-family archive so consecutive trusted-branch builds reuse the image invocation's entry
  • Update the documentation-properties plugin to 6.0.3 so the plugin classpath survives jackson 2.22.1 from plugin-bom 2.2.0
  • Update the image-builder plugin to 10.0.5 with the hardened project set discovery
  • Update the install plugin to 8.0.10
  • Update the install plugin to 8.0.8 and the image-builder plugin to 10.0.4
  • Update the install plugin to 9.0.0 and the osgi plugin to 5.0.2 to complete the plugin-bom alignment
  • Update the projectset plugin to 4.0.14 so project set file edits invalidate the configuration cache
  • Update the projectset plugin to 4.0.15 so directory listings no longer invalidate the configuration cache
  • Update to gradle-git 8.0.0 and packaging 12.0.0 with the result-carrying release version provider
  • Updated integrated timezone definitions to tzdata2026c
  • Use the shared read-only dependency cache in the core build again
  • Allow globaldb.yml to reference the cross-context database by name
  • Stop advertising the Jetty package as an HTTP service alternative (core#532)
  • Key IMAP trace files by context, user and server through a logback SiftingAppender (core-gitlab-com#5)
  • Resolve image tags, labels and the container version at execution time so configuration-cache entries stay reusable (core-gitlab-com#14)
  • Register RedisConnectorService only once the Redis end-point answered (core-gitlab-com#23)
  • Align the active-task watcher with the request watcher (core-gitlab-com#26)
    • SCR-1849: New configuration options for the thread pool's active-task watcher
    • SCR-1850: Changed reporting of long-running tasks by the thread pool's active-task watcher
  • Make the thread pool's saturation semantics effective and observable (core-gitlab-com#27)
    • SCR-1847: Changed behavior of the thread pool saturation settings
    • SCR-1848: New thread pool saturation metrics
  • Give AJAX job-queue jobs their own virtual-thread budget instead of the shared one (core-gitlab-com#28)
    • SCR-1841: New configuration option for the AJAX job queue
  • Run timer tasks on a bounded virtual-thread executor instead of the platform pool (core-gitlab-com#29)
    • SCR-1837: Changed timer tasks to run on virtual threads instead of the platform thread pool
    • SCR-1836: New configuration option for the timer executor's concurrency
  • Do not report a failed calendar folder lookup as a missing folder, and skip the affected events instead of deleting or failing (support#1599)

Fixed

  • ASB-130: Do not fail a stored mail account because its trailing cache invalidation could not reach Redis
  • ASB-132: Serve the reverse deputy look-up from one cached server-wide sweep instead of one sweep and connection per grant
  • ASB-142: Restore config fallbacks hidden by substituted built-in defaults
  • ASB-147: Keep inline image references resolvable across composition spaces
  • ASB-154: Drop a topic-less push subscription instead of failing every access to it
  • ASB-162: Parse mail filter rule metadata for non-IPv4 update sources and heal polluted rule names
  • PBSR-1478: Added missing "sentMailAccountId" parameter to HTTP-API documentation
  • SCR-1802: De-flake the integration suite and fix the races it was hiding
  • SCR-1806: Keep validating OAuth access tokens when the JWKS end-point is briefly unavailable
  • Abort start-up when the Redis end-point reports a condition that will not resolve
  • Accept only http and https from the forwarded protocol header and cap the patient stop timeout
  • Advertise cross-context mail grantees as type user in extended permissions
  • Answer what javax cannot express from the original request when re-bridging
  • Attach each Redis pub/sub listener once, even when a subscribe succeeds between retries
  • Avoid the gap-lock deadlock when backing up a folder before deleting it
  • Await every alias and asynchronous cycle before a Jetty servlet or filter is destroyed
  • Await the caller before failing the load in the Caffeine single-flight test
  • Build the command facades with the timeout of the running operation
  • Classify failed IMAP standard-folder creation by the parsed response code
  • Close the phantom success of a lost calendar account compare-and-set and make its timestamps strictly monotonic
  • Close the static service registry mock that leaked into other POP3 tests
  • Correct the Jetty connector's forwarded header trust, shut-down grace period and header compliance
  • Correct the misspelled mail capability cache idle time property, keeping the old name as a fallback
  • Correctness, robustness and performance issues in HTML/CSS sanitizing
  • Deflake the session OAuth lock tests by holding the lock until observed instead of for a fixed duration
  • Deflake the thread pool hook test by waiting for afterExecute instead of assuming it ran when the future completed
  • Deny when a security-relevant rate limit fails with an unchecked exception
  • Discriminate contact picture URL and ETag by context
  • Do not drop session data from the deferred structure version check
  • Error FLD-1001 on creating new subscribed calendar folder for shared accounts
  • Evaluate repeated forwarded-for field lines and sanitize the tracking identifier
  • Expire a failed or degraded mail server capability probe instead of caching it forever
  • Give configuration cache invocations enough build JVM heap to survive entry serialization
  • Harden the Dovecot Push listener lifecycle against stale retries, missing performer and needless delete-time stops
  • Honor the configured lenient remote addresses in the rate limit checks
  • IMAP command injection through user flags plus a set of correctness and operations findings
  • Keep awaiting a Redis end-point that answers but is not usable yet
  • Keep foreign servlet wrappers in the path when crossing the servlet bridge
  • Keep the jakarta wrapper identity when re-bridging a foreign servlet request wrapper
  • Let security-relevant rate limits deny instead of passing when they cannot be enforced
  • Only require administrative rights for mail folder updates that actually change permissions
  • Preserve CRLF line endings when adding VTIMEZONE resources
  • Promote guest recipients only on enabled cross-context surfaces
  • Release permanent mail push registrations when pns subscriptions expire
  • Release the in-flight gate even when the asynchronous hand-off fails
  • Report an unusable lock-out store instead of reading it as "not locked out"
  • Require the folder creation permission for renaming or moving mail folders
  • Resolve allowFetchSingleHeaders per mail account in the conversation view
  • Restore the back-off jitter and make the resilience signals attributable
  • Restore the cache buster on contact picture URLs in Drive autocomplete
  • Retry a Redis pub/sub listener whose attach attempt failed
  • Retry transiently failing IMAP folder creation in cross-context mail tests
  • Run the configuration cache archive steps in the gradle container which owns the entry files
  • Sanitize the user agent and Unicode line separators before they reach the log context
  • Serialize each CardDAV test's vCard with its own writer
  • Strip control characters from client-supplied log properties in every case
  • Take the command facade timeout from the configuration instead of the shared connection
  • Treat a successfully persisted calendar update lock as acquired instead of trusting a possibly stale re-load
  • Treat empty and whitespace-padded mail account property values correctly
  • Unregister the aliases of a shared whiteboard servlet collectively
  • Wait out Redis conditions by default instead of aborting start-up on unlisted ones
  • Write the session structure version when there is no stale data to keep
  • Replace 'which' command by 'command -v' to make it wolfi compatible
  • Pin the Jetty response charset, rebuild the forwarded request URL and re-pair split surrogates (core#532)
  • Restore payload and keep-alive state that Grizzly skips for upgrade-advertising requests (core-gitlab-com#1)
  • Derive table name also for "CREATE TABLE IF NOT EXISTS" statements (core-gitlab-com#2)
  • Release the IMAP debug logger when the connect fails or is retried (core-gitlab-com#5)
  • Release the per-session JMAP trace appender when the access is retired (core-gitlab-com#11)
  • Match contexts to their owners by identifier when checking ownership of multiple contexts (core-gitlab-com#15)
  • Bound the attempts to establish an OAuth session and remember backend failures per access token (core-gitlab-com#17)
  • Do not fail sessiond start-up because the timer task lock probe cannot reach Redis (core-gitlab-com#22)
  • Establish the session structure version along with session data (core-gitlab-com#24)
  • Invalidated grantee caches on shared-account/deputy revocation so revoked shared accounts and mailboxes no longer linger (support#1126)
  • Take a snippet's identity from the database instead of stale file-storage headers (support#1329)
  • Assert the bulk pre-cache waiter causally instead of by wall-clock timing (support#1522)
  • Honor the timezone parameter when converting a single mail outside the get action (support#1598)
  • Restore replica staleness check by tracking the replication monitor counter process-locally (support#1599)
  • Do not announce base64 for composite MIME parts (support#1600)
  • Keep an inline image's position between plain-text parts (support#1605)
  • Do not tear down the Dovecot mail push registration when a pns re-subscribe replaces its subscription (support#1606)
  • Validate vacation notice sender address against the account the rule belongs to (support#1611)
  • Restrict the vacation notice to the addresses it has been enabled for (support#1614)
  • Keep writing a datamining report when a database schema is unreachable (support#1618)
  • Encode address headers as RFC 2047 when the transport re-writes them (support#1619)
  • Accept requests that carry no cookies when building a login request (support#1624)
  • Check attachment quota and max mail size against the spooled attachment size (support#1627)
  • Group search could pin a CPU core indefinitely on a crafted wild-card pattern (support#1628)
  • Route getContextAdmin to the site owning the context instead of recursing into itself (support#1632)
  • Accept wildcard-only search patterns in calendar search instead of rejecting them as too short (support#1635)
  • Do not report a failed IMAP quota look-up as exceeded quota (support#1636)
  • Require the folder owner's consent to send on behalf of them from a shared folder (support#1645)
    • SCR-1821: Sending with a shared folder owner's address now requires an explicit permission
  • Announce converted text/enriched, text/richtext and text/rtf bodies as text/html so clients render them (support#1647)
Prev
App Suite UI
Next
Additional Components