Gateway and relay fixes lead a busy release week
Weekly threads
Gateway payment-path hardening across Fedimint branches
Fedimint 0.11.3 and 0.12.1 both shipped the same gateway security fix targeting LNv1 payment handling and adding hardening to LNv2, LND, and LDK backends. Operators running gateways on either branch should update promptly; the bug affects payment paths regardless of version. The coordinated release suggests the issue was identified in shared gateway code.
Self-hosting backup tooling enters new stability tiers
Duplicati 2.4.0 moved to canary, Syncthing-Fork Android 2.1.5 shipped recent-changes UI refactors, and Jellyfin 12.0 arrived with database schema changes that prevent rollback without backup. Operators who already snapshot before major upgrades will find Jellyfin’s new stance familiar; those who skip backups should start with this release. Duplicati’s canary tag signals intent to stabilize after an extended development cycle.
Citrine NIP-42 bypass and ngit-cli 3.0 workflow refinement
Citrine 3.1.1 closed an AUTH bypass where kind-22242 events were added to connections without signature checks, and scoped REQ subscription IDs per socket to prevent clobbering. ngit-cli 3.0.0 followed two months after its last RC, marking the project’s biggest release yet with workflow changes detailed in the notes. Operators running Citrine relays should patch immediately; the bypass allowed unauthenticated connection state.
Release board
Privacy
- Thunderbird for Android 23.0. Signature field only accepted single-line text in Composition defaults
- Thunderbird for Android K-9 Mail 23.0. Signature field only accepted single-line text in Composition defaults
- Element Web 2.0.0. Tweak Banner module styling
- Tor Browser 15.0.22. Tor Browser 15.0.22 is now available from the Tor Browser download page and also from our distribution directory.
- uBlock Origin 1.74. - Fix parsing of invalid regex-like domain in static extended filters - Improve remove-node-text / replace-node-text scriptlets - Improve prevent-clipboard-write scriptlet - Address multiple static filter parser issues - Treat resources…
- Mullvad VPN 2026.5-beta2. This release is for desktop only.
- XSAs released on 2026-09-08. Qubes OS references new Xen Security Advisories released 2026-09-08.
- Signal Desktop 8.27.0. - This update introduces more granular settings to give you significantly more control over your Signal notifications.
- Signal Android 8.27.1. The media editor has been completely redesigned to better support tablets and foldable devices, and now it looks great on screens of all sizes.
- Signal Android 8.26.3. The media editor has been completely redesigned to better support tablets and foldable devices, and now it looks great on screens of all sizes.
- Vanadium 153.0.8010. Vanadium 153.0.8010 updates to Chromium 153.0.8010.36.
- Nostr VPN 4.1.10. Reliability across every platform Cashu paid exits now connect, recover, and bill reliably with either manual or automatic selection on platforms that support paid exits.
Also shipped: Joplin 3.7.18, gopass 1.17.2, Yubico Authenticator 7.4.2.
Self-hosting
- Jellyfin 12.0. :rocket: Release notes for 12.0 Notes on Updating Before upgrading from an earlier version, a full backup of the data directory is strongly recommended, as this release includes database changes that prevent rolling back without a full r…
- FreshRSS 1.30.0. Milestone This is a security-oriented major release with several important security patches, so users are encouraged to update without delay.
- Coolify 4.3.19. Breaking Changes (well not breaking, but kinda, not sure haha) - Made Sentinel mandatory on regular servers.
- StartOS StartWRT 1.1.1. StartWRT 1.1.1 fixes flashing to internal storage from a microSD card whose partition table was altered after the image was written.
- n8n beta. 2.38.4 (2026-09-07) Bug Fixes core: Cap task runner task timeouts to the graceful shutdown window (6e12447) core: Keep a serving external secrets provider active when its replacement fails (1abbd4b) core: Prevent Anthropic agent threads…
- N8n 2.38.4. 2.38.4 (2026-09-07) Bug Fixes core: Cap task runner task timeouts to the graceful shutdown window (6e12447) core: Keep a serving external secrets provider active when its replacement fails (1abbd4b) core: Prevent Anthropic agent threads…
- N8n 2.39.0. 2.39.0 (2026-09-08) Bug Fixes ai-builder: UI tweak to prevent overflowing text on err callout when on Agent Preview (c2e8d02) AMQP Trigger Node: Reattach the receiver link when the broker detaches it (ddf6534) Anthropic Chat Model Node…
- Duplicati 2.4.0. This release is a canary release intended to be used for testing.
- authentik 2026.5.7. See fixed-in-202657 ci: add working dir prefix to file paths (cherry-pick 24319 to version-2026.5) endpoints/connectors/agent…
AI
- Qwen Code 0.23.1. Highlights See the complete change list below.
- opencode 1.18.30. Core Improvements - Added the Astra system prompt for GPT-6 models.
- Elevenlabs Python 3.0.0-alpha.1. Add file ids to send multimodal message SDK v3: regeneration + hand-written migration (agents rename, orchestrator config, generated websocket clients)
- openclaw 2026.9.4. OpenClaw v2026.9.4 20 direct commits 1,558 pull requests 294
- Client Python 2.10.0. It may change practical decisions for Bitcoin users, operators, builders, or privacy-focused readers.
- Hermes Agent 0.21.2. Hermes Agent v0.21.2 (v2026.9.11) - The state.db Patch Release Release Date: September 11, 2026 Patch release.
- HelixML 2.12.13. Separate Org Bots from people and Apps use tenant desktop quotas for agents Speed up and paginate the admin…
- langchain-openai== 1.6.2. Changes since langchain-openai==1.6.1 release(openai): 1.6.2 add GPT-6 Astra reasoning efforts chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai
- Open Interpreter 0.0.42. Open Interpreter 0.0.42 Open Interpreter 0.0.42 improves provider and transport discoverability, keeps the command-line experience consistently branded, and adds a reusable diagnostic harness for Ollama-backed Qwen tool-use checks.
Nostr
- ngit-cli 3.0.0. Release overview ngit v3 is its biggest release yet.
- Amber 6.6.3. Changelog Amber 6.6.3 - Fix the “start service on boot” setting not being respected after an app update - Fix a crash on the offline flavor caused SecurityException from WorkManager network tracking left over from an upgrade - Fix the Ru…
- Amethyst 1.15. Nostr changes affect identity, relays, zaps, messaging, and wallet-connect workflows.
- Grain 0.8.0-rc2. GRAIN v0.8.0-rc2 Stabilizing the client release - and teaching the relay to stay healthy Release candidate 9.7.2026
Bitcoin
- Fedimint 0.12.1. Gateway security release This release fixes a bug in the Lightning gateway’s LNv1 payment handling and adds further hardening to the gateway’s payment paths, including the LNv2 module and the LND and LDK backends.
- Fedimint 0.11.3. Same gateway payment-path fix as 0.12.1, backported to the 0.11 branch.
- Fedimint Web Canary Release. Flatten RPC payload and use persistent callback in ReactNativeTr…
- RoboSats 0.8.7-alpha. RoboSats v0.8.7-alpha is now out!
- Ashigaru Desktop 1.4.5. Released 2026-09-07 Everything since 1.1.2.
- BTCPay Server 2.4.4. Breaking changes Checkout: NFC payments are now disabled.
- Liquid GDK 0.78.0. Release 0.78.0 - 26-09-10 NOTE: This release is an ABI breaking change Added Changed - Signing: Check for pre-segwit inputs that previous transaction hash to the given txid and have correct amounts.
- Bitcoin Seed Tool 2.4.0. V2.4.0: Scanning, Seed XOR split, backup sheets and seed safety fixes This release is about the seed tools themselves.
- JoinMarket-NG 0.39.2. JoinMarket-NG 0.39.2 is a pre-release awaiting signature quorum.
- Ride The Lightning 0.15.12-beta. 0.15.12 is primarily a login-hardening release: it closes the remaining gaps in RTL’s login lockout and the application-settings API, and fixes a set of long-standing Eclair and LND behaviours around invoices, payments and channel opens.
- NodeGuard 0.30.1. Enhance AutoRebalanceJobTests with budget handling scenarios Enforce single template PSBT per request via unique index
- Flint 1.1.0. Verify before you install Every artifact here is signed with GitHub build provenance - a Sigstore attestation binding the file’s digest to this repository, this workflow, and the commit that built it.
Also shipped: BDK FFI 3.1.0, LNbits 1.6.1.
What to watch
- Jellyfin 12.0 database-schema rollback window closes. Jellyfin 12.0 shipped with database changes that prevent rollback without restore. Operators who upgrade and encounter issues cannot revert to 11.x without a full backup. Monitor for rollback-related support requests in the coming week.
- Dify 1.17.1 Weaviate staged-upgrade completion. Dify 1.17.1 requires a manual, staged upgrade for bundled Weaviate deployments. Self-hosted operators must complete the procedure or risk data loss. Watch for reports of incomplete upgrades as operators work through the multi-step process.
- ngit-cli 3.0.0 workflow-change adoption. ngit-cli 3.0.0 is its biggest release yet, with automatic PR branch downloads now opt-in and issue edit history exposed. Operators using ngit in automated Git-over-Nostr pipelines should test before promoting. Watch for workflow-breakage reports as the release rolls out.
By the numbers
- Stories tracked: 126
- Featured: 51
- Releases: 113
- Active sources: 152
- Security patches: 0
- Days covered: 7
Top beats this week
- AI: 49
- Privacy: 28
- Bitcoin: 22
- Self-hosting: 15
- Nostr: 9
- Unspecified: 3
Read on Freedom.Tech: https://freedom.tech/posts/2026-09-13-weekly-recap/
Get the weekly recap in your inbox: https://freedom.tech/subscribe/
Freedom.Tech is powered by Foundation.
Catch the weekly discussion on Freedom Tech Friday via Ungovernable Misfits.
Write a comment