What payloadcms/payload shipped
Written by FoxPlug from public releases; not affiliated with Payloadcms. An automatic summary of the public release, pull request and commit data of github.com/payloadcms/payload. Payloadcms did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- The Local API now defaults
overrideAccesstofalse, enforcing access control by default instead of bypassing it. Pull request #17869 - The Admin UI Publish button now publishes only the active locale by default when localized fields exist, removing the
defaultLocalePublishOptionconfig flag. Pull request #17874 - Request creation APIs consolidated around a canonical
createPayloadRequestfunction, removing overlappingcreateLocalReqand other paths. Pull request #18287 - Removed deprecated
savedDocumentDataandupdateSavedDocumentDataaliases fromuseDocumentInfo, requiring updates to custom components. Pull request #18319 - Added an
upgradecommand to@payloadcms/codemodto move Payload projects from v3 to v4, including Next.js version upgrades. Pull request #17825 - Fixed
findByID({ draft: true })to query the latest draft version row and apply read access correctly. Pull request #17999 - Image thumbnails now render in folder list view when a preview URL is available. Pull request #17980
- Block row metadata and
blockTypeare now preserved when conditional blocks fields become visible. Pull request #17797 - Updated MongoDB adapter to use
returnDocument: 'after'instead of the deprecatednewoption. Pull request #18277 - Added
devServerExternalPackagesoption to TanStack Start'swithPayloadfor controlling which packages stay external during dev. Pull request #17631
Why it matters
This week brings breaking changes that enforce better defaults: access control is now required by default, and publish behavior respects locale boundaries without configuration. A new codemod command eases v3-to-v4 migrations. Several fixes improve draft handling, form state preservation, and compatibility across database adapters.
Changelog entry
- BREAKING: Local API
overrideAccessnow defaults tofalse, enforcing access control. Explicitly setoverrideAccess: truewhere needed. Pull request #17869 - BREAKING: Removed
localization.defaultLocalePublishOptionconfig. Admin UI Publish button now always publishes active locale for localized documents. Pull request #17874 - BREAKING: Consolidated request creation APIs. Use canonical
createPayloadRequestinstead ofcreateLocalReqor framework-specific variants. Pull request #18287 - BREAKING: Removed deprecated
savedDocumentDataandupdateSavedDocumentDatafromuseDocumentInfo. Update custom components to usesetData. Pull request #18319 - Added
upgradecommand to@payloadcms/codemodfor automated v3 to v4 migrations. Pull request #17825 - Fixed
findByID({ draft: true })to apply read access against the latest draft version. Pull request #17999 - Image thumbnails now display in folder list view. Pull request #17980
- Fixed block type preservation when conditional blocks fields become visible. Pull request #17797
- Updated MongoDB adapter to eliminate deprecation warnings for
findOneAndUpdateandfindOneAndReplace. Pull request #18277 - TanStack Start: added
devServerExternalPackagesoption towithPayload. Pull request #17631
v4 now enforces access control by default in the Local API and publishes active locale by default. Consolidating request creation APIs and adding a v3→v4 migration codemod.
This week in Payload: the v4 Local API now defaults overrideAccess to false, enforcing access control instead of bypassing it by default. The Publish button respects locale boundaries without config. We consolidated request creation around a single canonical function and added an upgrade codemod to help move projects from v3 to v4, including Next.js version bumps. Plus fixes for draft access checks, form state preservation, and MongoDB adapter warnings.
Week of September 14, 2026
What shipped
- v3.90.0 released with critical security fixes that warrant immediate upgrade regardless of specific affected features. Release
- v3.90.1 released fixing a bug where parent collection's where queries were incorrectly applied to nested relationship fields. Release
- High-severity audit vulnerabilities affecting consumers resolved through direct dependency version bumps in published packages. Pull request #18158
- High-severity audit advisories addressed with direct bumps and peer-range adjustments across the monorepo. Pull request #18159
- Vitest updated to 5.0.0 and Playwright to 1.63.0 with E2E helpers migrated to newer Playwright APIs. Pull request #18096
- Turbo server fast refresh re-enabled for Next.js dev server following fixes in Next.js 16.3 release. Pull request #18187
- Templates regenerated with correct sharp versions and migrations for v3.90.0 to ensure 1-click deploys get current dependencies. Pull request #18209
- CI runner memory limits standardized for memory-heavy steps and job token permissions scoped to least-privilege defaults. Pull request #18211
- V3 telemetry backported from V4 with relevant metrics excluded to match V3 feature set. Pull request #18133
Why it matters
Critical security patches in v3.90.0 and v3.90.1 require immediate attention from users running v3. Access control fixes for nested relationships and dependency vulnerability resolutions improve stability and safety across all installations.
Changelog entry
- 🔒 v3.90.0: Critical security fixes included in this release Release
- 🐛 v3.90.1: Fixed parent where queries incorrectly carrying into nested relationship fields Release
- 🔒 Resolved consumer-facing high-severity audit vulnerabilities through direct dependency bumps Pull request #18158
- 🔒 Resolved high-severity audit advisories with direct version bumps and peer-range adjustments Pull request #18159
- 🧪 Updated Vitest to 5.0.0 and Playwright to 1.63.0 with migrated E2E helper APIs Pull request #18096
- ⚡ Re-enabled turborepoServerFastRefresh for Next.js dev server following Next.js 16.3 improvements Pull request #18187
- 📦 Regenerated templates with correct sharp versions and migrations for accurate deployments Pull request #18209
- 🔧 Standardized Node heap limits and scoped job token permissions in CI configuration Pull request #18211
- 📊 Backported V4 telemetry to V3 with excluded metrics irrelevant to V3 feature set Pull request #18133
v3.90.0 and v3.90.1 released with critical security fixes. Upgrade immediately. Also: nested relationship access control fix, dependency vulnerabilities resolved, Vitest 5.0.0, Playwright 1.63.0.
Payload v3.90.0 and v3.90.1 are now available with critical security fixes that require immediate upgrade. This release addresses high-severity vulnerabilities in consumer-facing dependencies, fixes access control behavior for nested relationship queries, and updates testing infrastructure with Vitest 5.0.0 and Playwright 1.63.0. All users are encouraged to upgrade promptly.