What arangodb/arangodb shipped
Written by FoxPlug from public releases; not affiliated with Arangodb. An automatic summary of the public release, pull request and commit data of github.com/arangodb/arangodb. Arangodb did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Released version 3.12.12. Release
- Released version 3.12.11.1. Release
- Client tools arangodump, arangorestore, arangoexport, arangobench, and arangobackup now request and renew JWT tokens from the server when started with username and password. Pull request #23341
- arangodump, arangorestore, and arangosh now renew JWT tokens during execution to prevent timeouts on long-running operations. Pull request #23308
- Vector index is now enabled by default in all setups. Pull request #23333
- Added maximum WAL point TTL to prevent clients from indefinitely pinning RocksDB WAL. Pull request #23339
- ArangoSearch stats API now returns information about all indexes across all ArangoSearch stores instead of just the first store. Pull request #23303
- Fixed graph traversal bug where integer underflow caused the server to skip edges when refilling cache. Pull request #23316
- Fixed AQL UPDATE with keepNull: false on non-disjoint SmartGraphs leaving attributes in the shadow collection. Pull request #23318
- Metric names are now escaped for Prometheus output compatibility. Pull request #23340
Why it matters
Two patch releases ship this week with critical fixes for JWT token handling in long-running operations and graph traversal. The default enablement of vector indexing and improved ArangoSearch stats reporting expand functionality for users working with advanced index types and analytics.
Changelog entry
- Released v3.12.12 Release
- Released v3.12.11.1 Release
- Client tools (arangodump, arangorestore, arangoexport, arangobench, arangobackup) request and renew JWT tokens via /_open/auth when started with username and password Pull request #23341
- arangodump, arangorestore, and arangosh renew JWT tokens if they expire during long-running operations Pull request #23308
- Fixed JWT vs.
jwt_secrethandling in additional places Pull request #23346 - Vector index enabled by default in all setups Pull request #23333
- Added maximum WAL point TTL to prevent indefinite WAL pinning by clients Pull request #23339
- ArangoSearch stats API (/_admin/arangosearch/stats) now returns statistics for all indexes across all stores Pull request #23303
- Fixed graph traversal missing edges due to integer underflow when refilling cache Pull request #23316
- Fixed AQL UPDATE with keepNull: false leaving attributes in non-disjoint SmartGraph shadow collections Pull request #23318
- Metric names are now properly escaped for Prometheus output format Pull request #23340
- Separated fixed-length and variable-length relationship handling in MATCH queries Pull request #23332
- Added comprehensive unit tests for MATCH components including PatternTypes, VariableScope, and PathConstruction Pull request #23344
- Refactored MATCH path construction into dedicated logic Pull request #23310
- Fixed flaky NetworkFeature assertion in restart tests Pull request #23312
- Fixed forwarding of API version in /_arango/experimental/_admin/activities requests Pull request #23325
- Fixed StringBuffer pre-allocation in lz4Decompress with size validation Pull request #23332
- Fixed improper AstNode comparison for non-const objects that generated invalid vpack Pull request #23311
- Made OBJECT comparison order-independent when keys are safe to reorder Pull request #23313
- Fixed TSAN race conditions in faiss IVF_HNSW parallel searches Pull request #23327
3.12.12 and 3.12.11.1 released. JWT tokens now auto-renew in client tools for long operations. Vector index enabled by default. Graph traversal and SmartGraph UPDATE bugs fixed.
Versions 3.12.12 and 3.12.11.1 are now available. Key improvements include automatic JWT token renewal in arangodump, arangorestore, and other client tools to prevent timeout failures, vector index enabled by default, expanded ArangoSearch stats to cover all indexes, and fixes for graph traversal edge skipping and SmartGraph UPDATE operations.
Week of September 14, 2026
What shipped
- Fixed returnNew/returnOld incorrectly being stored as document attributes in shadow collections on non-disjoint SmartGraphs, causing inconsistency between edge halves. Pull request #23279
- Fixed shutdown crash caused by a race condition in the heartbeat thread that did not wait for scheduled work items to complete. Pull request #23299
- Fixed UI login for users without _system database access. Pull request #23301
- Fixed SUBSTITUTE function to return empty string instead of null when operating on empty input strings. Pull request #23297
- Security fix applied to address COR-984. Pull request #23295
- Made swagger.json publicly available again at /_admin/aardvark/api/ for REST API documentation without authentication. Pull request #23291
- Restored public access to / root path for Aardvark UI when authentication-system-only is disabled. Pull request #23281
- Improved arangodump error messages to include actual server errors when connection attempts fail. Pull request #23274
- Hardened JavaScript sandbox settings and removed broken routes in /_admin/foxx/* endpoints. Pull request #23298
- Added typed AST node wrappers for MATCH and PATTERN_MATCH_EXPRESSION with updated builder and normalizer entry points. Pull request #23305
Why it matters
This week includes fixes for critical issues affecting SmartGraphs, server stability, and UI accessibility. Security improvements and hardened JavaScript sandbox settings strengthen the platform. Refactoring of MATCH query planning code improves code organization and maintainability.
Changelog entry
- Fixed returnNew/returnOld being incorrectly stored as document attributes in shadow collections on non-disjoint SmartGraphs Pull request #23279
- Fixed shutdown crash caused by race condition in heartbeat thread Pull request #23299
- Fixed UI login for users without _system database access Pull request #23301
- Fixed SUBSTITUTE function returning null instead of empty string on empty input Pull request #23297
- Security fix for COR-984 Pull request #23295
- Restored public access to swagger.json at /_admin/aardvark/api/ Pull request #23291
- Restored public access to root path / for Aardvark UI Pull request #23281
- Improved arangodump error messages to display actual server errors Pull request #23274
- Hardened JavaScript sandbox settings and removed broken routes in Foxx endpoints Pull request #23298
- Added typed AST node wrappers for MATCH query planning Pull request #23305
Week 25 shipped: SmartGraph attribute fix, shutdown race condition fix, UI login for non-_system users, SUBSTITUTE on empty strings, API documentation access restored, and security improvements.
This week's release includes important fixes for SmartGraph consistency issues, a critical shutdown race condition, and improved UI accessibility for users without _system access. We've also restored public access to API documentation and strengthened security with hardened sandbox settings. These changes address stability, usability, and security concerns identified by the community.