What OneUptime/oneuptime shipped
Written by FoxPlug from public releases; not affiliated with Oneuptime. An automatic summary of the public release, pull request and commit data of github.com/OneUptime/oneuptime. Oneuptime did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Incidents can now be scoped to status pages with targeted, structured subscriber notifications. Pull request #4095
- Email verification screen redesigned with resend option after signup. Pull request #4090
- Topology map now computes server-side so search and connection counts cover the whole inventory. Pull request #4072
- RUM now shows INP per-view in session replay and by route with P75 aggregation. Pull request #4070
- Device Topology search now works across every level of the site hierarchy. Pull request #4069
- Fixed security issue where internal DNS names could leak to SaaS tenants on refused egress. Pull request #4092
- SMTP servers and OAuth token URLs now pinned to validated addresses to close DNS-rebinding window. Pull request #4094
- Kubernetes dashboard now shows peak CPU of busiest node instead of summing gauges. Pull request #4065
Why it matters
This week shipped topology computation on the server side so searches cover everything, redesigned email verification with resend, and scoped incidents to status pages. Security fixes closed DNS-rebinding and egress-information leaks for SaaS tenants. Several monitor alert templates now fire and recover correctly on Kubernetes and Ceph.
Changelog entry
- feat(incidents): scope incidents to status pages with targeted, structured subscriber notifications Pull request #4095
- feat(accounts): resend verification email with redesigned verify-your-email screen Pull request #4090
- feat(topology): compute topology server-side for complete inventory search and connection counts Pull request #4072
- feat(rum): per-view INP in session replay, INP by route on RUM, P75 aggregation Pull request #4070
- feat(network): search every level of site hierarchy from Device Topology Pull request #4069
- fix(security): stop egress refusals mapping internal DNS for SaaS tenants Pull request #4092
- fix(security): pin SMTP servers and OAuth token URLs to validated addresses Pull request #4094
- fix(dashboards): show busiest node's peak CPU instead of summing gauge on Kubernetes template Pull request #4065
- fix(probe): report when probe cannot send IPv6 instead of blaming monitored host Pull request #4091
- fix(egress): pass DATA_SOURCE_BLOCK_PRIVATE_ADDRESSES through Docker Compose and Helm Pull request #4093
14.0.7 ships server-side topology, email verification resend, status-page scoped incidents, and security fixes for DNS-rebinding and egress leaks.
14.0.7 moves topology computation to the server so Device Topology search works across the whole hierarchy, redesigns email verification with resend, scopes incidents to status pages with targeted notifications, and closes security gaps in DNS-rebinding and egress filtering for SaaS tenants.
Week of September 14, 2026
What shipped
- Enterprise Edition code moved to
ee/directory under its own license, kept out of community Docker images. Pull request #3912 - On-call schedules now display in a shared week/month timeline view across project and team. Pull request #3901
- Security Events page adds a stacked severity volume chart over time above the events list. Pull request #3894
- IPv6 monitor destinations now work end-to-end after fixing address truncation on save. Pull request #3928
- CI pipeline gained an end-to-end job for self-hosted Enterprise stack in two phases. Pull request #3927
- OTLP exporters now receive success only after telemetry queue admission, triggering proper retries on failure. Pull request #3921
- Removing permission blocks now enforces authority over the complete saved block to prevent access exposure. Pull request #3891
- Multi-tenant team-member reads now enforce remaining authorization checks to prevent password hash exposure. Pull request #3890
- CLI
--versionflag now reports the correct package version instead of a hardcoded value. Pull request #3925 - Expired sessions now refresh automatically instead of showing a bogus authorization error. Pull request #3900
Why it matters
This week shipped major architectural changes with Enterprise Edition separation and improved security across permission enforcement. Several bugs were fixed that prevented IPv6 monitors from working and exposed sensitive data through authorization bypasses, while on-call scheduling gained a unified timeline view that customers requested.
Changelog entry
- Enterprise Edition split into ee/ directory under OneUptime Enterprise License Pull request #3912
- On-call: Schedule Timeline view across all schedules in project and team views Pull request #3901
- Security Events: severity volume chart stacked over time with time-range picker Pull request #3894
- Monitor: IPv6 destinations now work end-to-end Pull request #3928
- CI: end-to-end job for self-hosted Enterprise stack Pull request #3927
- Telemetry: OTLP exporters receive success only after queue admission Pull request #3921
- Permissions: delegation limits enforced when removing permission blocks Pull request #3891
- Security: multi-tenant team-member reads now enforce complete authorization Pull request #3890
- CLI: --version flag reports correct package version Pull request #3925
- Auth: expired sessions refresh automatically instead of showing authorization error Pull request #3900
- Security Events: Detection Rules and Threat Intel pages added explanatory 'How it works' cards Pull request #3888
- SLO detail navigation reorganized by task grouping Pull request #3883
- SLO overview redesigned with larger status headline and labeled detail cards Pull request #3884
- Billing: payment-method requirement restricted to Free plans only Pull request #3881
- On-call: shared calendar feed status permissions fixed for authorized readers Pull request #3880
13.0.7 shipped: Enterprise Edition under its own license, IPv6 monitors fixed, on-call timeline view across schedules, Security Events volume chart, and multi-tenant permission enforcement improvements.
This week's releases include major structural changes: Enterprise Edition moved to its own ee/ directory under separate licensing, keeping community images focused on open source. Operationally, on-call schedules now support unified week/month timeline views, Security Events gained severity volume charting, and we fixed IPv6 monitor destinations. On security, we hardened multi-tenant authorization checks and permission block enforcement to prevent sensitive data exposure.