What metabase/metabase shipped
Written by FoxPlug from public releases; not affiliated with Metabase. An automatic summary of the public release, pull request and commit data of github.com/metabase/metabase. Metabase did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
SendMeteringEventsjob no longer does full table scans ofquery_execution, reducing load on the app database on busy instances. Pull request #83034- Related tables lookup in the MCP
browse_datatool now caps permission queries instead of making uncapped requests to the app DB. Pull request #82962 - The Metabot illustrations toggle in Admin > AI > Customization now stays visible after being toggled on. Pull request #82946
- pgvector credentials are no longer exposed in error messages when using alternate
user:pass@hostURL forms. Pull request #83010 - pgvector database URL and credentials are excluded from c3p0 and pgjdbc log output. Pull request #82930
- Remote Sync now properly types columns when importing a GUI model before the target database schema sync completes. Pull request #82945
- Remote Sync now cleans up nested content when a parent collection is archived, preventing orphaned files from accumulating in git. Pull request #82876
- Pivot table subtotals with month-bucketed dates now maintain correct localization when formatted multiple times. Pull request #82947
- Storybook builds for Loki screenshot runs now skip unnecessary steps like React docgen, MDX docs, and source maps. Pull request #83003
- Permission errors on cards and dashboards no longer replace the entire page. Pull request #82943
Why it matters
This week addressed several performance bottlenecks affecting database load and API efficiency, fixed credential exposure in logs and error messages, and resolved UI issues where toggles and error messages were behaving unexpectedly. These improvements reduce operational strain on busy instances and enhance security for sensitive database configurations.
Changelog entry
- Performance: SendMeteringEvents job no longer performs full table scans of
query_executionPull request #83034 - Performance: MCP
browse_datatool caps permission queries for related tables lookup Pull request #82962 - Fixed: Metabot illustrations toggle now remains visible in Admin > AI > Customization Pull request #82946
- Security: pgvector credentials removed from error messages using alternate URL forms Pull request #83010
- Security: pgvector database URL and credentials excluded from logs Pull request #82930
- Fixed: Remote Sync now properly types columns when importing models before schema sync completes Pull request #82945
- Fixed: Remote Sync cleans up nested content when parent collections are archived Pull request #82876
- Fixed: Pivot table subtotals with bucketed dates maintain correct localization Pull request #82947
- Fixed: Permission errors no longer replace the entire page Pull request #82943
- Build: Storybook optimized for Loki screenshot runs with reduced build steps Pull request #83003
This week we fixed performance issues in metering jobs and related table lookups, prevented credential leaks in pgvector logs, made Remote Sync handle archiving properly, and ensured UI toggles and error messages work as expected.
This week's updates focus on performance, security, and reliability. We eliminated full table scans in the metering job that were slowing busy instances, prevented pgvector credentials from leaking in logs and errors, fixed Remote Sync to properly clean up archived content, and addressed UI issues with toggles and error displays. These improvements reduce database strain, enhance security, and improve user experience.
Week of September 14, 2026
What shipped
- Unauthenticated request body sizes are now limited to help protect server memory, while authenticated users remain unaffected. Pull request #82572
- Indexed-entity handling in xrays was improved to avoid using indexed-entry values directly. Pull request #82699
- Development Docker ports, socket REPL, and rspack dev server now bind to loopback only instead of 0.0.0.0 for improved security. Pull request #82707
- Remote sync was made robust against restarts to fix issues where pull operations could get stuck for extended periods. Pull request #82553
- C3p0 pool stats are now read directly from pool objects instead of through JMX to avoid locking issues. Pull request #82760
- Channel write permissions are now required when sending to a channel by ID. Pull request #82608
- Filter widgets set to Input box type now return empty lists from values endpoints since the UI never requests values for that widget type. Pull request #82535
- Slack messages without text fields now contribute their attachments to thread history instead of being dropped. Pull request #82631
- Memory allocation during remote sync statistics collection was improved to reduce OOMKill incidents. Pull request #82625
- Error messages now format blocked table IDs as plain numbers without thousands separators. Pull request #82772
Why it matters
This week focused on stability and security improvements across multiple systems. Server memory protection, permission checking, and robustness against restarts address production reliability concerns that users experience with long-running operations and sync processes.
Changelog entry
- Unauthenticated request body sizes are now limited Pull request #82572
- Improved indexed-entity handling in xrays Pull request #82699
- Development servers now bind to loopback only for security Pull request #82707
- Remote sync is now robust against restarts Pull request #82553
- C3p0 pool stats now read directly from pool objects Pull request #82760
- Channel write permissions required for sending by channel ID Pull request #82608
- Input box filter widgets no longer return values from endpoints Pull request #82535
- Slack attachments preserved in thread history when text is missing Pull request #82631
- Remote sync memory allocation improved Pull request #82625
- Error messages format table IDs as plain numbers Pull request #82772
This week: request body limits for unauthenticated users, improved remote sync robustness, better permission checks, and fixes for xrays and pool stats reading.
Metabase shipped several important improvements this week focused on stability and security. We added request body size limits for unauthenticated requests to protect server memory, made remote sync operations more robust against restarts to fix extended wait times, and improved permission checking for channel operations. We also fixed issues with indexed-entity handling in xrays and optimized how database pool statistics are read to prevent locking problems.