Shipped · Databases

What payloadcms/payload shipped

The public repository of Payloadcms · github.com/payloadcms/payload

Written by FoxPlug from public releases; not affiliated with Payloadcms. An automatic summary of the public release, pull request and commit data of github.com/payloadcms/payload. Payloadcms did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.

Get a weekly update like this for your product, free

Or Use it as a GitHub Action

Follow payload's weekly shipped digest

Week of September 21, 2026

What shipped

Why it matters

This week brings breaking changes that enforce better defaults: access control is now required by default, and publish behavior respects locale boundaries without configuration. A new codemod command eases v3-to-v4 migrations. Several fixes improve draft handling, form state preservation, and compatibility across database adapters.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

v4 now enforces access control by default in the Local API and publishes active locale by default. Consolidating request creation APIs and adding a v3→v4 migration codemod.

Post for LinkedIn

This week in Payload: the v4 Local API now defaults overrideAccess to false, enforcing access control instead of bypassing it by default. The Publish button respects locale boundaries without config. We consolidated request creation around a single canonical function and added an upgrade codemod to help move projects from v3 to v4, including Next.js version bumps. Plus fixes for draft access checks, form state preservation, and MongoDB adapter warnings.

Week of September 14, 2026

What shipped

Why it matters

Critical security patches in v3.90.0 and v3.90.1 require immediate attention from users running v3. Access control fixes for nested relationships and dependency vulnerability resolutions improve stability and safety across all installations.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

v3.90.0 and v3.90.1 released with critical security fixes. Upgrade immediately. Also: nested relationship access control fix, dependency vulnerabilities resolved, Vitest 5.0.0, Playwright 1.63.0.

Post for LinkedIn

Payload v3.90.0 and v3.90.1 are now available with critical security fixes that require immediate upgrade. This release addresses high-severity vulnerabilities in consumer-facing dependencies, fixes access control behavior for nested relationship queries, and updates testing infrastructure with Vitest 5.0.0 and Playwright 1.63.0. All users are encouraged to upgrade promptly.

Weeks with too little public activity are left out rather than filled in. Last updated 2026-09-28.

Is this your repo? Ask us to remove this page.