Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
483 commits
Select commit Hold shift + click to select a range
1f04e1c
[6.x] Don't show unsaved changes warning when switching tabs (#14678)
jasonvarga May 15, 2026
75e9277
[6.x] Better collapsible sections (#14679)
jaygeorge May 15, 2026
8fec33d
[6.x] Update Italian translations (#14683)
sbellesis May 18, 2026
e8dbd0c
[6.x] Bump shivammathur/setup-php from 2.37.0 to 2.37.1 in the github…
dependabot[bot] May 18, 2026
4a30688
[6.x] French translations (#14680)
ebeauchamps May 18, 2026
2681908
[6.x] When enabling Pro, prompts for license key (#14686)
jackmcdade May 18, 2026
431c8ad
[6.x] Swap image dimensions when EXIF orientation indicates a 90° rot…
jasonvarga May 18, 2026
66762e1
[6.x] Harden GitHub Actions workflows with zizmor (#14687)
jasonvarga May 18, 2026
4a14142
[6.x] Hook up "Add Row" config for List fields (#14689)
jackmcdade May 19, 2026
68d2eab
[5.x] Harden `DataCollection` sort value resolution (#14693)
duncanmcclean May 20, 2026
0e9f860
[6.x] Include `is_pdf` in augmented asset data (#14699)
jacksleight May 21, 2026
eecc9ed
[5.x] Fix token path traversal (#14700)
duncanmcclean May 21, 2026
a2b0a0f
Merge branch '5.x' into 6.x
jasonvarga May 21, 2026
6bf773f
[5.x] Authorize relationship fieldtype data (#14718)
jasonvarga May 22, 2026
e288f8f
Merge branch '5.x' into 6.x
jasonvarga May 22, 2026
41b2ad5
[6.x] Relationship UI adjustments (#14719)
jasonvarga May 22, 2026
7616945
[5.x] Fix asset fieldtype icon (#14720)
jasonvarga May 22, 2026
2c5d833
changelog
jasonvarga May 22, 2026
3363f7c
changelog
jasonvarga May 23, 2026
b85333a
[6.x] Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 in the github…
dependabot[bot] May 25, 2026
5d1ac8d
[6.x] Avoid crop aspect ratios select being truncated (#14712)
duncanmcclean May 25, 2026
b2a2212
[6.x] Stop (excessive) logging of `ElevatedSessionAuthorizationExcept…
joshuablum May 26, 2026
a318f81
[6.x] Remove `pt-4` as the default padding for a Group fieldtype (#14…
martyf May 26, 2026
bcfa63d
[6.x] Fix `Cached Pages` count for multi-site setups (#14726)
joshuablum May 26, 2026
481f830
[6.x] Bump js-cookie from 3.0.5 to 3.0.7 (#14705)
dependabot[bot] May 26, 2026
e33f0ab
[6.x] Bump qs from 6.15.0 to 6.15.2 (#14721)
dependabot[bot] May 26, 2026
49e4fab
[6.x] Hash URL in static caching lock key (#14716)
duncanmcclean May 26, 2026
6494014
[6.x] Fix entry revision localizations to filter unauthorized sites (…
duncanmcclean May 26, 2026
26620f6
[6.x] Date scrollbar fix (#14730)
jaygeorge May 26, 2026
15c6aab
[6.x] Remove custom scrollbar from date fields (#14731)
jaygeorge May 26, 2026
57667ab
[6.x] Fix form box-shadows being clipped by expanding/collapsing sect…
jaygeorge May 27, 2026
32005d0
[6.x] French translations (#14738)
ebeauchamps May 28, 2026
3e78b6f
[6.x] Improve modal text formatting and dark mode background (#14740)
jaygeorge May 28, 2026
00ec795
[6.x] Reusable GitHub workflows (#14743)
jasonvarga May 28, 2026
db41e06
[6.x] Add codeowners and tripwire (#14744)
jasonvarga May 28, 2026
a879a70
[6.x] Handle replicator handle overflow (#14746)
jaygeorge May 29, 2026
018fbf3
[6.x] Fix tests (#14748)
jasonvarga May 29, 2026
bc3afd0
[6.x] More elegantly mask horizontal overflow for sets (#14753)
jaygeorge Jun 1, 2026
ba86589
[5.x] Harden workflows (#14756)
jasonvarga Jun 1, 2026
00608c0
[6.x] Improve collapsible section trigger (#14758)
jaygeorge Jun 2, 2026
f17c098
[5.x] Escape formula characters in form submission CSV exports (#14760)
jasonvarga Jun 2, 2026
d8f4575
[5.x] Harden remote URL validation (#14761)
jasonvarga Jun 2, 2026
1566276
Merge branch '5.x' into 6.x
jasonvarga Jun 2, 2026
ee9c0c1
[6.x] Scope shared static cache errors to sites (#14763)
joshuablum Jun 2, 2026
9c3d8da
[6.x] Bump league/csv (#14768)
jasonvarga Jun 2, 2026
b38aa2d
[6.x] Fix share_errors breaking nocache regions on successful respons…
joshuablum Jun 2, 2026
a9ca149
[6.x] Truncate full measure static cache files before writing (#14755)
joshuablum Jun 2, 2026
9f0e61e
[6.x] Fix `current` augmentation handling in users fieldtype (#14724)
joshuablum Jun 2, 2026
75e8ffd
[6.x] Fix clipboard pasting of validation rules (#14754)
joshuablum Jun 2, 2026
a041f2a
[5.x] Fix Bard/Link Blink cache type collision (#14739)
simonerd Jun 2, 2026
07a7925
changelog
jasonvarga Jun 2, 2026
6971bd7
Merge branch '5.x' into 6.x
jasonvarga Jun 2, 2026
ae63c74
changelog
jasonvarga Jun 2, 2026
cb75f5a
[6.x] Fix GraphiQL (#14770)
joshuablum Jun 3, 2026
eb05041
[6.x] Fix TypeError when elevated_session_duration is a string (#14771)
duncanmcclean Jun 3, 2026
62f5621
[6.x] Fix asset selection in Markdown fieldtype (#14715)
duncanmcclean Jun 3, 2026
3c2735d
[6.x] Fix configure navs permission not working properly (#14775)
joshuablum Jun 3, 2026
3920bd5
[6.x] Resolve Entry::descendants() N+1 query (#14773)
SteveEdson Jun 3, 2026
f909e18
[6.x] Fix asset editor prev/next buttons and "Edit Image" button in B…
joshuablum Jun 3, 2026
8b02ee0
[6.x] Apply regenerate handle pattern for replicator sections (#14745)
jaygeorge Jun 3, 2026
cc286d5
[6.x] Fix static cache invalidation stripping trailing slashes (#14713)
duncanmcclean Jun 3, 2026
0ce3195
[6.x] Add impersonation permission description (#14776)
jasonvarga Jun 3, 2026
638b54d
[6.x] Fix field filters returning all results when filtering by 0 (#1…
joshuablum Jun 4, 2026
2669921
[6.x] Render PDF viewer pages lazily (#14764)
daun Jun 4, 2026
68b4d77
[6.x] Fix share_errors breaking nocache regions on error responses (#…
joshuablum Jun 4, 2026
8432caa
[6.x] Add support for Collection in last modifier (#14778)
JonKaric Jun 4, 2026
32cfa03
[6.x] Fix date picker inconsistencies (#14732)
jaygeorge Jun 4, 2026
68b7552
[6.x] Avoid version inertia prop (#14783)
jasonvarga Jun 5, 2026
83b33ca
changelog
jasonvarga Jun 5, 2026
126dc0f
[6.x] Trigger the grid table mode at lower viewports because it's mor…
jaygeorge Jun 8, 2026
3ac8c2f
[5.x] Drop support for Laravel 10/11 (#14793)
jasonvarga Jun 8, 2026
87b9998
[5.x] Fix permission for Live Preview (#14791)
jasonvarga Jun 8, 2026
d567af4
Merge branch '5.x' into merge-5x
jasonvarga Jun 8, 2026
6abd361
[6.x] Merge 5.x (#14794)
jasonvarga Jun 8, 2026
dec5607
Merge branch '5.x' into 6.x
jasonvarga Jun 8, 2026
57764c7
[6.x] 6.20.3 changelog (#14795)
jasonvarga Jun 8, 2026
f8546c1
[6.x] French translations (#14789)
ebeauchamps Jun 8, 2026
1221030
[6.x] Add default sorting support for taxonomies (#14772)
finnjsmith Jun 9, 2026
7b93712
[6.x] Fix Modify::__toString() throwing TypeError for non-string scal…
VerburgtJimmy Jun 9, 2026
a216c27
[6.x] Add default initial option configuration option for Link fieldt…
martyf Jun 9, 2026
8773b2b
[6.x] Speed up Stache warming for large structured collections (#14781)
o1y Jun 9, 2026
a8d25cb
[6.x] Implement permissions cache on eloquent users (#14661)
ryanmitchell Jun 9, 2026
1d003b3
[6.x] Add `exclude` param to stache commands (#14788)
edalzell Jun 9, 2026
2fafd10
[6.x] Adjust listing skeleton to match configured features (#14796)
daun Jun 10, 2026
5c7e3c4
[6.x] Fix docs for `Listing` component (#14798)
duncanmcclean Jun 10, 2026
88196da
[6.x] Don't reserve space when a field's display label is hidden (#14…
jasonvarga Jun 10, 2026
6830e26
[6.x] Bump web-auth/webauthn-lib to ^5.3.0 (#14727)
sstraakenbroek Jun 10, 2026
2649964
[6.x] Prevent overlapping git commit jobs (#14672)
aerni Jun 10, 2026
f9f67d0
[6.x] 6.21.0 (#14805)
jasonvarga Jun 10, 2026
3f106fc
[6.x] Give precognitive form requests a separate rate limit bucket (#…
jasonvarga Jun 11, 2026
2b76510
[6.x] Fix nested Bard data loss when editing a set (#14808)
joshuablum Jun 11, 2026
4e01ea6
[6.x] Always render Control Panel exceptions as JSON for XHR requests…
jasonvarga Jun 11, 2026
5007262
[6.x] Chips 🍟 (#14766)
jaygeorge Jun 12, 2026
a370d59
[6.x] German translations (#14818)
helloDanuk Jun 15, 2026
155ee9b
[6.x] Make the whole radio/checkbox item clickable (#14821)
duncanmcclean Jun 15, 2026
3700298
[6.x] Bump the github-actions group with 2 updates (#14817)
dependabot[bot] Jun 15, 2026
9ed4636
[6.x] Fix mobile nav button failing (#14673)
jaygeorge Jun 15, 2026
aabed0a
[6.x] Render asset editor video player with dimensions (#14813)
daun Jun 15, 2026
5b588dd
[6.x] Bump vite from 8.0.7 to 8.0.16 (#14824)
dependabot[bot] Jun 16, 2026
1836298
[6.x] Handle external links in empty-state component (#14814)
daun Jun 16, 2026
9a7e05b
[6.x] Bump form-data from 4.0.5 to 4.0.6 (#14825)
dependabot[bot] Jun 16, 2026
d1ba522
[6.x] Bump markdown-it from 14.1.1 to 14.2.0 (#14827)
dependabot[bot] Jun 16, 2026
ecd8c66
[6.x] Bump dompurify from 3.4.0 to 3.4.9 (#14826)
dependabot[bot] Jun 16, 2026
78eb41f
[6.x] Bump esbuild and storybook (#14828)
dependabot[bot] Jun 16, 2026
b800166
[6.x] Fix inconsistent dark mode text colours (#14830)
jaygeorge Jun 16, 2026
bba2526
[6.x] Autopopulate email on password reset form (#14834)
jackmcdade Jun 17, 2026
d879105
[6.x] Crop images server-side (#14841)
jasonvarga Jun 18, 2026
b1826cc
[6.x] Avoid loading the revisions store when finding a working copy (…
jasonvarga Jun 19, 2026
5569208
[6.x] Retain current tab hash in URL when switching localization (#14…
duncanmcclean Jun 19, 2026
120f1b9
[6.x] Bump dompurify from 3.4.9 to 3.4.11 in the npm_and_yarn group a…
dependabot[bot] Jun 19, 2026
5500d1c
[6.x] Translate untranslated CP page titles (#14848)
jasonvarga Jun 19, 2026
03d536a
[6.x] Don't show selection checkboxes when bulk actions are disabled …
jasonvarga Jun 19, 2026
8b1967b
[6.x] Avoid widget table overflow (#14851)
daun Jun 19, 2026
8e2b7b0
[6.x] 6.22.0 (#14852)
jasonvarga Jun 19, 2026
56d99c1
[6.x] Prevent rare case of the container scrolling when focusing on t…
jaygeorge Jun 19, 2026
4510e68
[6.x] French translations (#14856)
ebeauchamps Jun 22, 2026
4b7086e
[6.x] Handle linked field comboboxes when the text is long (#14863)
jaygeorge Jun 23, 2026
1d509f3
[6.x] Prevent the link field group from exceeding 50% of the containe…
jaygeorge Jun 23, 2026
ba6404d
[6.x] Update Release Workflow (#14804)
jasonvarga Jun 23, 2026
fae029d
[6.x] Apply as-config prop to top-level container only (#14855)
daun Jun 23, 2026
167987f
[6.x] Hide "Live Preview" button while live preview is active (#14866)
duncanmcclean Jun 23, 2026
70fb0c3
[6.x] Add explicit `package` param to `installed` tag (#14858)
daun Jun 23, 2026
a338587
[6.x] 6.23.0 (#14868)
jasonvarga Jun 23, 2026
c56c1c3
[5.x] Update Release Workflow (#14861)
jasonvarga Jun 23, 2026
e34a8a4
[6.x] Remove `v6.` subdomain from documentation links (#14870)
duncanmcclean Jun 24, 2026
9f08e49
[6.x] Define emits in `PublishActions` component (#14872)
duncanmcclean Jun 24, 2026
3bd0eb5
[6.x] Style the list of blueprints as badges instead, improving legib…
jaygeorge Jun 25, 2026
626888f
[6.x] Prevent browser re-sort of dictionary options with integer keys…
helloiamlukas Jun 25, 2026
1c20231
[6.x] Change how the slot with the "customize columns" works. Instead…
jaygeorge Jun 26, 2026
e59dd34
[5.x] Fix OAuth (#14887)
jasonvarga Jun 26, 2026
d7678b9
[6.x] Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions…
dependabot[bot] Jun 29, 2026
a9b09b0
[6.x] Fix kebab-cased props not binding on Blade components in Antler…
marcorieser Jun 29, 2026
c73d628
[6.x] Tolerate a folded X-Statamic-Pagination header when warming (#1…
mynetx Jun 29, 2026
f1442b0
[6.x] Fix icon fieldtype error when stored icon is missing (#14881)
mynetx Jun 29, 2026
fb49016
[5.x] Fix failing Guzzle tests (#14897)
jasonvarga Jun 29, 2026
b2cb18e
Merge branch '5.x' into merge-5x
jasonvarga Jun 29, 2026
ab1a9d5
apply guzzle fix to additional tests that didnt exist in 5.x
jasonvarga Jun 29, 2026
010e0f9
[6.x] Merge 5.x (#14898)
jasonvarga Jun 29, 2026
5c3c78b
[6.x] Add JSON language modes to code editor (#14904)
daun Jun 30, 2026
aea6805
[5.x] Fix user wizard authorization check (#14905)
jasonvarga Jun 30, 2026
32e4bde
[6.x] Pass active query scope handles to relationship index scopes (#…
mynetx Jun 30, 2026
6557f1d
[5.x] Fix nav authorization checks (#14906)
jasonvarga Jun 30, 2026
a28f5b3
[6.x] Fix stale Stache entry order when reordering structured collect…
joshuablum Jul 1, 2026
466d7e3
[6.x] OAuth Improvements (#14899)
jasonvarga Jul 1, 2026
d4158d9
[5.x] Tighten up dynamic method resolution (#14911)
jasonvarga Jul 1, 2026
52ef6a3
Merge branch '5.x' into merge-5x
jasonvarga Jul 1, 2026
8472ded
[6.x] Merge 5.x (#14912)
jasonvarga Jul 1, 2026
03ab5b7
[5.x] 5.74.1 (#14913)
jasonvarga Jul 1, 2026
b3b1171
[6.x] 6.24.0 (#14914)
jasonvarga Jul 1, 2026
19b305b
[6.x] Fix CodeQL parse error for import.meta.glob (#14915)
jasonvarga Jul 2, 2026
83c7fb6
[6.x] Mention JSON language modes in prop description (#14916)
duncanmcclean Jul 2, 2026
cd7392d
[6.x] Do not show a disabled cursor for start/end of pagination (#14921)
jaygeorge Jul 2, 2026
f208e67
[6.x] Update changelog (#14923)
jasonvarga Jul 2, 2026
26a2d80
[6.x] Upgrade PHPUnit and add laravel/pao (#14922)
jasonvarga Jul 2, 2026
a5baa35
[6.x] Fix Bard link entry selector not showing pre-selected entry (#1…
duncanmcclean Jul 2, 2026
43dcac1
[6.x] Fix required validation on empty code fields (#14918)
duncanmcclean Jul 2, 2026
aae06c7
[6.x] Fix fieldtype picker showing wrong list after switching bluepri…
duncanmcclean Jul 2, 2026
0e11cf9
[5.x] Fix roles/groups select being empty for non-super users (#14889)
mynetx Jul 2, 2026
d94d7cc
[6.x] Fix Glide route double slash for path-prefixed sites (#14908)
lwekuiper Jul 2, 2026
bb7507e
[6.x] French translations (#14926)
ebeauchamps Jul 3, 2026
5f26347
[6.x] Fix amber and default badge button hover background shade (#14924)
lazerg Jul 3, 2026
26bca1f
[6.x] PHPStan (#14925)
jasonvarga Jul 3, 2026
453d79a
[6.x] Rename phpunit.xml.dist to phpunit.dist.xml (#14930)
jasonvarga Jul 3, 2026
840d093
[6.x] Default the create user wizard super toggle to false (#14927)
stoffelio Jul 3, 2026
102ef28
[6.x] Fix progress bar triggering excessive recursion (#14931)
jasonvarga Jul 3, 2026
bc8744c
[5.x] 5.74.2 (#14932)
jasonvarga Jul 3, 2026
983e585
Merge branch '5.x' into release
jasonvarga Jul 3, 2026
982d45a
changelog
jasonvarga Jul 3, 2026
5171897
[6.x] 6.24.1 (#14933)
jasonvarga Jul 3, 2026
fe9ffe9
[6.x] Convert date bindings to app timezone in raw SQL dump (#14937)
marcorieser Jul 6, 2026
2ae9a13
[6.x] Fix errors when a structure tree contains a null item (#14941)
mynetx Jul 6, 2026
b5d59a4
[6.x] Fix timezone handling in `whereDate` and `whereTime` (#14940)
marcorieser Jul 6, 2026
3eca0f1
[6.x] Fix dictionary single-select showing the raw id instead of the …
mynetx Jul 6, 2026
1304b85
[6.x] Do not set the Inertia root view globally (#14942)
lazerg Jul 6, 2026
2ba4f02
[6.x] Fix asset filters not applying the first time (#14943)
duncanmcclean Jul 6, 2026
ec3fd0b
[6.x] Prevent the focus box on filters from being clipped (#14953)
jaygeorge Jul 7, 2026
cd4ad2f
[6.x] Fix incorrect update badges in the Control Panel updater (#14890)
aaronbushnell Jul 7, 2026
5b5995f
[6.x] Fix global variable references not resolving through the data r…
lazerg Jul 7, 2026
8be7b6c
[5.x] Tighten front-end form upload validation (#14958)
jasonvarga Jul 8, 2026
4ad1335
[5.x] Escape submitted values in automagic email (#14959)
jasonvarga Jul 8, 2026
58ddfff
[5.x] 5.74.3 (#14960)
jasonvarga Jul 8, 2026
09f9c17
Merge branch '5.x' into merge-5x
jasonvarga Jul 8, 2026
39500ff
[6.x] Merge 5.x (#14961)
jasonvarga Jul 8, 2026
1f2e607
[6.x] Fix broken asset reference when discarding a duplicate upload (…
lazerg Jul 8, 2026
aa49838
[6.x] Fix relationship-based fields showing raw ids after saving (#14…
mynetx Jul 8, 2026
6fa971b
[6.x] Fix Bard set disappearing after save (#14956)
eminos Jul 8, 2026
55e353c
[6.x] 6.24.2 (#14962)
jasonvarga Jul 8, 2026
0d93232
[6.x] Hide permissions covered by a broader permission (#14970)
jasonvarga Jul 9, 2026
307dfc7
[6.x] Prevent vertical focus clipping on listing pages (#14978)
jaygeorge Jul 10, 2026
bc46d78
[6.x] Fix Control Panel not scrolling to top on navigation (#14965)
duncanmcclean Jul 10, 2026
50f1bf6
[6.x] Fix video thumbnail generation logging an error on success (#14…
lazerg Jul 10, 2026
d9f2945
[6.x] Preserve unregistered permissions when saving a role (#14975)
jasonvarga Jul 10, 2026
cc69a96
[6.x] Use form handle in key (#14974)
edalzell Jul 10, 2026
20ff8da
[6.x] Improve recursive behavior when using route data in computed va…
JohnathonKoster Jul 10, 2026
b443c78
[6.x] Fix global variables being lost when migrated alongside addon u…
duncanmcclean Jul 10, 2026
9fe5908
[6.x] Fix filter badge showing the term title in the wrong site (#14973)
lazerg Jul 10, 2026
198329f
[6.x] Pass the configured index name to the search insert job (#14949)
ajnsn Jul 10, 2026
aea31c3
[6.x] Update pull request template (#14993)
joshuablum Jul 13, 2026
c12a8fa
[6.x] Hide unauthorized sections in nav (#14990)
lazerg Jul 13, 2026
df7dbbe
[6.x] Fix English CP locale showing fallback locale translations (#15…
jasonvarga Jul 13, 2026
954dd18
[6.x] Allow taxonomy create button customization (#14997)
efc Jul 13, 2026
4be20a7
[6.x] Fix performance issue when duplicating entries in large collect…
duncanmcclean Jul 13, 2026
44ef569
[6.x] Update site:clear config stubs to match current defaults (#14991)
lazerg Jul 13, 2026
706e70b
[6.x] Fix error on out-of-range pagination page number (#14981)
mynetx Jul 13, 2026
307412d
[6.x] Fix malformed URLs with duplicate leading slashes resolving to …
lazerg Jul 13, 2026
6a81472
[6.x] Throw parser error when mixing pipe and shorthand modifier synt…
marcorieser Jul 13, 2026
af0f318
[6.x] Fix link fieldtype ignoring sometimes validator (#14985)
lazerg Jul 13, 2026
d522f2f
[6.x] Fix range date fields ignoring the configured timezone on save …
lazerg Jul 13, 2026
49a3630
[6.x] Fix stache:refresh flattening structured collection trees (#15003)
mynetx Jul 14, 2026
aa60563
[6.x] Fix save crash after deleting a Bard set containing a hidden fi…
werner-freytag Jul 14, 2026
a3ac1ea
[6.x] Bump ws from 8.20.0 to 8.21.1 (#15011)
dependabot[bot] Jul 14, 2026
1fac14f
[6.x] Update link to permission docs (#15012)
duncanmcclean Jul 15, 2026
95fbd3c
[6.x] Fix nested Bard data loss when reordering sets (#15013)
mynetx Jul 15, 2026
e5fff43
[6.x] Fix toasts breaking when sessions are serialized as JSON (#15015)
mynetx Jul 15, 2026
507259c
[6.x] Fix runtime assignment in a partial blanking a later partial's …
mynetx Jul 15, 2026
5a2b40a
[6.x] Fix Replicator field labels hidden when nested in Grid (#14987)
lazerg Jul 15, 2026
c07fed4
[6.x] Make Files fieldtype temporary upload storage configurable (#14…
duncanmcclean Jul 15, 2026
7105939
[6.x] Fix blueprint assignment of entries using custom entry class (#…
daun Jul 16, 2026
903f963
[6.x] Support Glide 4 and Intervention Image 4 (#15019)
joshuablum Jul 16, 2026
057945c
[6.x] Fix session-expiry modals being dismissible and silently re-ext…
jasonvarga Jul 16, 2026
73ceb30
[6.x] Fix validation rules being lost when saving without pressing en…
mynetx Jul 16, 2026
5d7ccd7
[6.x] Fix search:update ignoring the index argument when index names …
edalzell Jul 17, 2026
ff15c6c
[6.x] Fix errors rendering blueprints & publish components when logge…
duncanmcclean Jul 17, 2026
1904c28
[6.x] Fix control panel text direction on RTL sites (#15023)
jasonvarga Jul 17, 2026
15bd863
[6.x] 6.25.0 (#15030)
jasonvarga Jul 17, 2026
b64c1c1
[6.x] Harmonize label customization config text (#15034)
duncanmcclean Jul 20, 2026
5401ea4
[6.x] Fix Custom Invalidator background recache (#15031)
marcorieser Jul 20, 2026
0831d49
[6.x] Bump the github-actions group with 2 updates (#15032)
dependabot[bot] Jul 20, 2026
f433035
[6.x] Fix grid min_rows breaking CP navigation (#15033)
duncanmcclean Jul 20, 2026
ce80780
[6.x] German translations (#15036)
helloDanuk Jul 20, 2026
6530a62
[6.x] Add support for custom link types (#15004)
duncanmcclean Jul 20, 2026
369547b
[6.x] Public dictionaries (#15029)
duncanmcclean Jul 20, 2026
d137426
[6.x] Do not hide the primary save button for mobile (#15041)
jaygeorge Jul 21, 2026
887a7e5
[6.x] Bump axios from 1.16.0 to 1.18.1 (#15038)
dependabot[bot] Jul 21, 2026
f323ac4
[6.x] Show an entry selector when filtering by an entries field (#15043)
duncanmcclean Jul 21, 2026
0e7e555
[6.x] Fix customized listing columns being overridden by default pref…
mynetx Jul 21, 2026
d684df0
[6.x] Fix origin() on null when fetching nav tree with origin_id fiel…
duncanmcclean Jul 21, 2026
ef47138
[6.x] Pass field prefix to custom conditions (#15044)
duncanmcclean Jul 21, 2026
b581e83
[6.x] Ensure application cache honours static_cache store (#15045)
ryanmitchell Jul 21, 2026
a152b4c
[6.x] 6.26.0 (#15047)
jasonvarga Jul 21, 2026
3cb09f0
[6.x] Prevent errors when Stache indexes contain keys without files (…
joshuablum Jul 22, 2026
0f68656
[6.x] Handle download responses in Inertia requests (#15050)
duncanmcclean Jul 22, 2026
4e215a4
[6.x] Prevent bogus content when dragging inside a node-selected Bard…
duncanmcclean Jul 22, 2026
724a387
[6.x] Use correct types in Tags class (#15059)
daun Jul 23, 2026
c2e5197
[6.x] Use correct parameter name in Scope class (#15060)
daun Jul 23, 2026
0908e1b
Add failing test for pipe + shorthand modifier regression
marcorieser Jul 24, 2026
848f3e9
Revert "[6.x] Throw parser error when mixing pipe and shorthand modif…
marcorieser Jul 24, 2026
1043f1d
Drop comment
marcorieser Jul 24, 2026
2a6b90a
[6.x] Throw parser error when mixing pipe and shorthand modifier synt…
marcorieser Jul 13, 2026
886b1ec
Remove regression test
marcorieser Jul 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
29 changes: 26 additions & 3 deletions .claude/skills/changelog/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,23 +8,46 @@ Generate a changelog entry for the CHANGELOG.md file by following these steps:

## 1. Get commits since last tag

Run `git --no-pager log $(git describe --tags --abbrev=0)..HEAD --oneline --no-decorate --first-parent --no-merges`) to get the list of commits.
First, fetch tags from origin — they sit off-branch (see note below) so they don't come down with a normal `git pull`/`git fetch` on the branch:

```
git fetch origin --tags
```

Then run the following to get the list of commits:

```
git --no-pager log $(git merge-base $(git tag --list 'v*' --sort=-v:refname | head -n1) HEAD)..HEAD --oneline --no-decorate --no-merges
```

Note: The release workflow tags a separate "Build assets" commit that is *not* an ancestor of the branch, so the tag itself never lands on `6.x`. That means `git describe --tags` walks back to a stale tag. Instead, take the newest tag and use its `git merge-base` with `HEAD`, which resolves to the release commit that *is* on the branch.

5.x commits are merged into 6.x as-is (not squashed), so this plain `--no-merges` log already walks both the 6.x mainline and every commit brought in via a 5.x merge, in true chronological order — it only excludes the merge commits themselves (multi-parent, no real change of their own).

## 2. Process each commit

For each commit:
- Extract the PR number from the commit message (e.g., `(#13331)`)
- Remove the commit SHA and `[6.x]` prefix from the message
- Remove the commit SHA and `[6.x]`/`[5.x]` prefix from the message
- Fetch the PR author from GitHub using a sequential loop — do NOT use parallel background jobs (`&`) as they interleave stdout unpredictably. Use: `for pr in <numbers>; do echo -n "PR $pr: "; gh pr view $pr --json author --jq '.author.login'; done`

## 3. Skip certain commits

Skip commits that are:
- Test fixture updates (e.g., "Update composer test fixtures")
- CI/workflow changes (e.g., "Only run lint workflow...")
- Test-only fixes with no user-facing effect (e.g., "Fix failing Guzzle tests" — check the PR body; if it says the bug only affected tests, skip it)
- Internal release/workflow-only PRs (e.g., "Update Release Workflow")
- Commits with no PR number, or whose message is itself a merge bookkeeping commit (e.g., "Merge 5.x (#NUM)", "Merge branch '5.x' into...")

Do not skip dependency bumps from dependabot.

For `[5.x]`-prefixed commits, also skip/dedupe:
- Changes already superseded by a bigger PR in this release. Read the PR bodies — if a larger 6.x PR's description explicitly covers what the smaller 5.x fix addressed (e.g., a big OAuth rework that says it removes email-based matching supersedes a smaller "Fix OAuth" email-trust patch), skip the smaller one and note it in the summary (step 10).
- Changes that no longer apply to 6.x because 6.x already handled it independently (e.g., a 5.x "Drop support for Laravel 10/11" PR when 6.x already dropped those versions).

When in doubt about whether a `[5.x]`-prefixed commit is user-facing, lean toward including it — security/authorization hardening fixes (auth checks, method-resolution guarding, validation hardening) belong in the changelog even without a lot of detail in the title, matching how they're written up in the 5.x changelog (e.g. "Harden remote URL validation", "Fix token path traversal").

## 4. Categorize commits

- **What's new**: Commits that add new features (title contains "Add" or introduces new functionality). An "improvement" is not to be considered new.
Expand All @@ -37,7 +60,7 @@ Format: `- Description [#NUMBER](https://github.com/statamic/cms/issues/NUMBER)
## 6. Order entries

- Reverse the list so earliest commits come first (git log shows newest first)
- Within each category, maintain chronological order
- Within each category, maintain chronological order — this already interleaves 5.x-origin commits correctly since step 1's log is in true merge order
- Translation PRs get moved to the bottom of the list
- Dependabot PRs get moved to the bottom, after translations

Expand Down
12 changes: 11 additions & 1 deletion .gitattributes
Original file line number Diff line number Diff line change
@@ -1,14 +1,24 @@
* text=auto
*.php eol=lf

/resources/dist/**/* linguist-generated=true
/resources/dist-dev/**/* linguist-generated=true
/resources/dist-frontend/**/* linguist-generated=true
/resources/dist-package/**/* linguist-generated=true

/.github export-ignore
/resources/js export-ignore
/resources/css export-ignore
/packages export-ignore
/tests export-ignore
.babelrc export-ignore
.gitattributes export-ignore
.gitignore export-ignore
.travis.yml export-ignore
CONTRIBUTING.md export-ignore
jest.config.js export-ignore
phpstan.dist.neon export-ignore
phpunit.bat export-ignore
phpunit.xml.dist export-ignore
phpunit.dist.xml export-ignore
SECURITY.md export-ignore
translator export-ignore
8 changes: 8 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
/composer.json @statamic/security
/src/helpers.php @statamic/security
/src/namespaced_helpers.php @statamic/security
/src/View/Blade/helpers.php @statamic/security

/.github/CODEOWNERS @statamic/security
/.github/workflows/tripwire.yml @statamic/security
/scripts/check-autoload-files.sh @statamic/security
12 changes: 7 additions & 5 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,14 @@ Please take 30 seconds to read the following so we can be as efficient as possib

1️⃣ Is this your first PR? If so, please read our [contribution guide](https://statamic.dev/contribution-guide) first.

2️⃣ Please make sure to create a new branch for your PR.
2️⃣ Did you use AI tools to create this PR? If so, please review changes carefully to make sure they meet our code standards. We all know how AI can behave sometimes. This helps to make the review easier for us. Reviewing PRs can be a lot of work.

3️⃣ Typically you should target the branch of the most current release, e.g. `6.x`, unless your PR includes a breaking change, in which case you should target the `master` branch for the next major release.
3️⃣ Please make sure to create a new branch for your PR.

4️⃣ We _really_ appreciate it if your PR includes tests. This makes it much easier for us to review, merge, and release. A PR with tests is usually reviewed and merged 5x-10x faster.
4️⃣ Typically you should target the branch of the most current release, e.g. `6.x`, unless your PR includes a breaking change, in which case you should target the `master` branch for the next major release.

5️⃣ If your PR introduce a new feature, adds to an existing one, or changes current behavior, please **open an issue for it in the [statamic/docs](https://github.com/statamic/docs/issues) repo referencing your PR**. A simple "Goes along with statamic/cms#9000" is enough. Otherwise it's really easy to forget and no will ever become aware of your ✨ sparkling ✨ invention if it's not documented.
5️⃣ We _really_ appreciate it if your PR includes tests. This makes it much easier for us to review, merge, and release. A PR with tests is usually reviewed and merged 5x-10x faster.

6️⃣ Remove this placeholder text and replace it with a description of what this PR is doing.
6️⃣ If your PR introduce a new feature, adds to an existing one, or changes current behavior, please **open an issue for it in the [statamic/docs](https://github.com/statamic/docs/issues) repo referencing your PR**. A simple "Goes along with statamic/cms#9000" is enough. Otherwise it's really easy to forget and no will ever become aware of your ✨ sparkling ✨ invention if it's not documented.

7️⃣ Remove this placeholder text and replace it with a description of what this PR is doing.
12 changes: 12 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
groups:
github-actions:
patterns:
- "*"
cooldown:
default-days: 7
21 changes: 17 additions & 4 deletions .github/workflows/code-style-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,25 +3,38 @@ name: Lint code style issues
on:
pull_request:

permissions: {}

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
lint-code-styling:
lint-code-styling: # zizmor: ignore[anonymous-definition]
runs-on: ubuntu-latest
permissions:
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Get changed files
id: changed-files
uses: tj-actions/changed-files@v46
uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6
with:
files: |
**.php

- name: Check PHP code style issues
if: steps.changed-files.outputs.any_modified == 'true'
uses: aglipanci/laravel-pint-action@v2
uses: aglipanci/laravel-pint-action@36de00d5f5a8a4e12d443e01671daa12a18f4c79 # 2.6
with:
testMode: true
verboseMode: true
pintVersion: 1.16.0

- name: Check Statamic\trans imports
run: bash scripts/check-trans-import.sh
53 changes: 53 additions & 0 deletions .github/workflows/phpstan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
name: PHPStan

on:
pull_request:

permissions: {}

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
phpstan:
name: Analyze
runs-on: ubuntu-latest
permissions:
contents: read

steps:
- name: Checkout code
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Get changed files
id: changed-files
uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6
with:
files: |
src/**
composer.json
phpstan.dist.neon
.phpstan/**
.github/workflows/phpstan.yml

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
if: steps.changed-files.outputs.any_modified == 'true'
with:
php-version: 8.5
coverage: none

- name: Install dependencies
uses: nick-invision/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
if: steps.changed-files.outputs.any_modified == 'true'
with:
timeout_minutes: 5
max_attempts: 5
command: composer update --prefer-stable --prefer-dist --no-interaction

- name: Run PHPStan
if: steps.changed-files.outputs.any_modified == 'true'
run: vendor/bin/phpstan analyse --memory-limit=2G
63 changes: 8 additions & 55 deletions .github/workflows/pr-title.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,60 +4,13 @@ on:
pull_request:
types: [opened, edited, synchronize, reopened]

jobs:
pr-title:
runs-on: ubuntu-latest
steps:
- name: Validate PR title matches target branch
env:
PR_TITLE: ${{ github.event.pull_request.title }}
BASE_BRANCH: ${{ github.event.pull_request.base.ref }}
DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
run: |
# Validates PR title against target branch
# Returns error message if invalid, empty string if valid
validate_pr_title() {
local target_branch="$1"
local pr_title="$2"
local default_branch="$3"

# Check if target branch is a version branch (e.g., 5.x, 4.x)
if [[ $target_branch =~ ^([0-9]+)\.x$ ]]; then
local version="${BASH_REMATCH[1]}"
if [[ ! $pr_title =~ ^\[$version\.x\][[:space:]] ]]; then
echo "PR targeting '$target_branch' must have title starting with '[$version.x] '"
return
fi

# Check if target branch is master (next major version)
elif [[ $target_branch == "master" ]]; then
local current_version="${default_branch//\.x/}"
local next_version=$((current_version + 1))
if [[ ! $pr_title =~ ^\[$next_version\.x\][[:space:]] ]]; then
echo "PR targeting 'master' must have title starting with '[$next_version.x] '"
return
fi

# For other branches, just enforce that there's a version prefix
else
if [[ ! $pr_title =~ ^\[[0-9]+\.x\][[:space:]] ]]; then
echo "PR title must start with a version prefix like '[5.x] '"
return
fi
fi
permissions: {}

echo ""
}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

echo "PR Title: $PR_TITLE"
echo "Base Branch: $BASE_BRANCH"
echo "Default Branch: $DEFAULT_BRANCH"

ERROR=$(validate_pr_title "$BASE_BRANCH" "$PR_TITLE" "$DEFAULT_BRANCH")

if [[ -n $ERROR ]]; then
echo $ERROR
exit 1
fi

echo "PR title validation passed"
jobs:
pr-title:
uses: statamic/.github/.github/workflows/pr-title.yml@bebe92309b4276e45ebc0d0c65854fb2ecf786ba
permissions: {}
75 changes: 9 additions & 66 deletions .github/workflows/pull-requests.yml
Original file line number Diff line number Diff line change
@@ -1,75 +1,18 @@
name: Pull Requests

# Credit: https://github.com/github/docs/blob/main/.github/workflows/notify-when-maintainers-cannot-edit.yaml
# https://github.com/laravel/.github/blob/main/.github/workflows/pull-requests.yml

on:
pull_request_target:
pull_request_target: # zizmor: ignore[dangerous-triggers]
types:
- opened

permissions:
pull-requests: write
permissions: {}

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
uneditable:
runs-on: ubuntu-latest
steps:
- uses: actions/github-script@v7
with:
script: |
const repo = context.repo.repo;

const query = `
query($number: Int!) {
repository(owner: "statamic", name: "${repo}") {
pullRequest(number: $number) {
headRepositoryOwner {
login
}
maintainerCanModify
state
}
}
}
`;

const pullNumber = context.issue.number;
const variables = { number: pullNumber };

try {
console.log(`Check for maintainer edit access ...`);
const result = await github.graphql(query, variables);
console.log(JSON.stringify(result, null, 2));
const pullRequest = result.repository.pullRequest;

if (pullRequest.headRepositoryOwner.login === 'statamic') {
console.log('PR owned by statamic');
return;
}

if (pullRequest.state !== 'OPEN') {
console.log('PR has already been closed or merged');
return;
}

if (!pullRequest.maintainerCanModify) {
console.log('PR not owned by statamic and does not have maintainer edits enabled');

await github.rest.issues.createComment({
issue_number: pullNumber,
owner: 'statamic',
repo,
body: "Thanks for submitting a PR!\n\nIn order to review and merge PRs most efficiently, we require that all PRs grant maintainer edit access before we review them. For information on how to do this, [see the relevant GitHub documentation](https://docs.github.com/en/github/collaborating-with-pull-requests/working-with-forks/allowing-changes-to-a-pull-request-branch-created-from-a-fork). Additionally, GitHub doesn't allow maintainer permissions from organization accounts. Please resubmit this PR from a personal GitHub account with maintainer permissions enabled."
});

await github.rest.pulls.update({
pull_number: pullNumber,
owner: 'statamic',
repo,
state: 'closed'
});
}
} catch(e) {
console.log(e);
}
uses: statamic/.github/.github/workflows/pull-requests.yml@bebe92309b4276e45ebc0d0c65854fb2ecf786ba
permissions:
pull-requests: write # post comment and close PRs that don't allow maintainer edits
Loading
Loading