What go-vikunja/vikunja shipped
Written by FoxPlug from public releases; not affiliated with Vikunja. An automatic summary of the public release, pull request and commit data of github.com/go-vikunja/vikunja. Vikunja did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Timer and task-comment events now reconcile through QueryClient, completing cross-tab timer synchronization. Pull request #3963
- Quick add with repeat now sets first due date to today at the user's default due time instead of leaving it unset. Pull request #4011
- Pasting rich text from webpages or other Vikunja descriptions now preserves formatting instead of converting to markdown. Pull request #4021
- Dragging tasks in Gantt view no longer crashes from recursive cache updates when related tasks are involved. Pull request #3968
- Dragging projects in the sidebar no longer breaks the sidebar layout with null reference errors. Pull request #3970
- Outgoing requests now respect HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables and support private proxies. Pull request #4015
- OIDC users are now linked by verified email when username matching fails, preventing duplicate accounts. Pull request #4012
- API v2 list endpoints now respect the service.maxitemsperpage configuration instead of hardcoding limits. Pull request #3977
- Broken images in user content no longer spam error reports to Sentry. Pull request #3969
- Loading buttons remain focusable for keyboard navigation instead of being disabled. Pull request #3972
Why it matters
This week completed a major refactor of data synchronization across tabs and fixed critical regressions in drag operations, pasting, and quick-add workflows. The stack also adds proper proxy support for corporate environments and improves error reporting.
Changelog entry
- fix(editor): keep formatting when pasting rich text Pull request #4021
- fix: support HTTP_PROXY and private proxies for outgoing requests Pull request #4015
- fix(auth): link OIDC users by email when username fallback misses Pull request #4012
- feat(quick-add): set first due date for repeating tasks without a date Pull request #4011
- refactor(websocket): reconcile task and timer query caches Pull request #3963
- refactor(time-tracking): move timers and entries into QueryClient Pull request #3962
- refactor(subscriptions): finish generated subscription migration Pull request #3961
- refactor(comments): migrate comments and paging to v2 queries Pull request #3960
- refactor(reactions): migrate task and comment reactions to v2 Pull request #3958
- refactor(attachments): migrate uploads and previews to v2 Pull request #3957
- fix(api): respect service.maxitemsperpage in v2 list endpoints Pull request #3977
- fix(frontend): hold sidebar project list updates until a drag ends Pull request #3970
- fix(tasks): stop related task cache updates from recursing forever Pull request #3968
- fix(frontend): don't report broken images inside user content Pull request #3969
- fix(frontend): stop dropping DOMExceptions before they reach sentry Pull request #3971
This week: rich text paste works, quick-add sets due dates, timers sync across tabs, Gantt drag crashes fixed, and HTTP proxies work.
Week highlights: pasting rich text now preserves formatting, repeating tasks get a first due date, timers synchronize across browser tabs, and drag operations in Gantt and sidebar no longer crash. We also added proxy support for corporate networks and fixed OIDC email linking.
Week of September 14, 2026
What shipped
- Expose Vikunja's v2 REST API actions to MCP clients through
/api/v2/mcp, deriving 24 typed tools from the OpenAPI document including projects, tasks, labels, comments, assignees, and user search. Pull request #3860 - Users can now discover the MCP endpoint in Settings → MCP, create a token with suitable permissions, and follow connection instructions for their client. Pull request #3864
- Replace the useTaskActions facade with direct mutations, breaking up the deleted Pinia task store into a quick-add composable and direct mutation calls. Pull request #3950
- Activate query-owned tasks and boards with navigation query scopes, date/form boundaries, and quick-add orchestration. Pull request #3941
- Gantt bars narrower than their title now show a tooltip with the full task name on hover. Pull request #3917
- About dialog now shows 'Pro active' when the server advertises enabled pro features via
/info. Pull request #3925 - Fix atom feed returning 500 on task assigned notifications by setting Target to feed owner instead of dereferencing nil. Pull request #3916
- Store queued import uploads in the file storage backend (local or S3) instead of temp directory, allowing any instance to run the import job. Pull request #3889
- Parse Z-suffixed timestamps as UTC in caldav instead of server timezone. Pull request #3883
- Add
/.well-known/change-passwordredirect to password change page for password manager support. Pull request #3897
Why it matters
MCP support opens Vikunja to external tools and clients, while the v2 API refactor continues consolidating the frontend onto a modern data layer. Multiple bug fixes resolve issues with feeds, migrations, caldav, and UI stacking.
Changelog entry
- feat(mcp): expose v2 API tools over streamable HTTP Pull request #3860
- feat(settings): add MCP connection setup Pull request #3864
- refactor(tasks): replace the useTaskActions facade with direct mutations Pull request #3950
- refactor(tasks): activate query-owned tasks and boards Pull request #3941
- feat(gantt): show full title tooltip on bars too narrow for their label Pull request #3917
- feat(frontend): show pro license status in about dialog Pull request #3925
- fix(feeds): don't panic on task assigned notifications in atom feed Pull request #3916
- feat(migration): store queued import uploads in the file storage Pull request #3889
- fix(caldav): parse Z-suffixed timestamps as UTC Pull request #3883
- feat: add /.well-known/change-password redirect Pull request #3897
- fix(admin): show project owner with user component Pull request #3955
- fix(frontend): bucket dropdown stacking and close-on-select in task detail Pull request #3947
- fix(user)!: give colliding TOTP and account-locked error codes unique values Pull request #3901
- fix(migration): stop file imports from timing out and locking the migration slot Pull request #3827
- fix(restore): convert numeric bools when restoring into postgres Pull request #3898
- fix(restore): restore empty json column values as NULL Pull request #3896
MCP tools now available via /api/v2/mcp. Set up in Settings → MCP with a token. Vikunja tasks, projects, labels, and more are now discoverable and callable from MCP clients.
Vikunja now supports Model Context Protocol (MCP), allowing external tools and clients to interact with tasks, projects, labels, comments, and more through typed REST actions. Users can set up MCP connections in Settings and generate tokens with suitable permissions. The v2 API continues its frontend migration with query-owned tasks and direct mutations, while fixes address feeds, caldav timestamps, and import reliability.