Renovate: Update all non-major dependencies #151

Open
renovate wants to merge 1 commit from renovate/all-minor-patch into main
Collaborator

This PR contains the following updates:

Package Type Update Change
awesometechnologies/synapse-admin minor 0.10.3 → 0.11.4
docker.io/matrixdotorg/synapse minor v1.111.0 → v1.162.0
markdownlint/markdownlint repository minor v0.13.0 → v0.18.1

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

Awesome-Technologies/synapse-admin (awesometechnologies/synapse-admin)

v0.11.4

Compare Source

v0.11.3

Compare Source

v0.11.2

Compare Source

v0.11.1

Compare Source

v0.11.0

Compare Source

v0.10.4

Compare Source

element-hq/synapse (docker.io/matrixdotorg/synapse)

v1.162.0

Compare Source

Changelog: https://github.com/element-hq/synapse/blob/release-v1.162/CHANGES.md

v1.161.0

Compare Source

Changelog: https://github.com/element-hq/synapse/blob/release-v1.161/CHANGES.md

v1.160.0

Compare Source

Changelog: https://github.com/element-hq/synapse/blob/release-v1.160/CHANGES.md

v1.159.0

Compare Source

Changelog: https://github.com/element-hq/synapse/blob/release-v1.159/CHANGES.md

v1.158.0

Compare Source

Changelog: https://github.com/element-hq/synapse/blob/release-v1.158/CHANGES.md

v1.157.2

Compare Source

Synapse 1.157.2 (2026-07-28)

This security release addresses several vulnerabilities.

Please upgrade when you can, particularly if your homeserver participates in open federation
and/or has untrusted local users.

Security Fixes

High severity:

Moderate severity:

Low severity:

v1.157.1

Compare Source

Synapse 1.157.1 (2026-07-22)
Bugfixes
  • Fix config regression around falsy experimental_features no longer being accepted. (#​19987)

v1.157.0

Compare Source

Synapse 1.157.0 (2026-07-21)

No significant changes since 1.157.0rc1.

Synapse 1.157.0rc1 (2026-07-14)
Features
Bugfixes
  • MSC4140: Cancellable delayed events: Update error responses to match their format in the current draft of the MSC. (#​19539)
  • Lock Sliding Sync connections when inserting lazy members, to prevent repeated deadlocks. (#​19826)
  • Fix the flag_existing_quarantined_media background update skipping some quarantined remote media. Introduced in v1.152.0. (#​19901)
  • Fix a bug introduced in Synapse v1.150.0 where reactivating a deactivated and erased user did not restore their profile, breaking login, name changes, and invitations.
    Contributed by @​m4us1ne. (#​19902)
  • Fix a regression where application services that opted into ephemeral events using the legacy de.sorunome.msc2409.push_ephemeral registration flag stopped receiving ephemeral events (including to-device messages used for encryption). Introduced in v1.156.0. (#​19928)
  • Fix a bug causing device list pruning to skip some rows when the transaction gets retried. (#​19947)
  • Fix presence states being shown to clients forever after presence is disabled, by marking any previously only users as offline. (#​19948)
  • Fix SYNAPSE_ASYNC_IO_REACTOR=1 on Python 3.14. (#​19949)
Deprecations and Removals
  • Remove support for experimental MSC3861 auth delegation, in favour of the stable Matrix Authentication Service integration support. See the upgrade notes. (#​19895)
Internal Changes
  • Port the synchronous core of client event serialization to Rust. (#​19837, #​19922)
  • Update HomeserverTestCase.get_success(...) and friends to drive async Rust (Tokio runtime/thread pool). (#​19871, #​19879)
  • Allow Rust code to have database access via Python database connection pool. (#​19878)
  • Add golangci-lint to CI. (#​19888)
  • Remove wall-clock dependency of test_redact_messages_all_rooms test, as this caused flakiness. (#​19890)
  • Change the MSC3814 dehydrated device /events endpoint from POST to GET. (#​19896)
  • Change the MSC3814 dehydrated device /events endpoint paging to match spec conventions. (#​19897)
  • Fix storage type mismatches where values were bound with a type that didn't match their database column. (#​19911)
  • Speed up deletion of old sliding sync connections by adding an index. (#​19912)
  • Add note to 3PID email token request unit tests that the endpoint being tested can have an expected, artificial delay of up to 1s. (#​19916)
  • Add an index to sliding_sync_connection_lazy_members to speed up deleting old sliding sync connection positions. (#​19923)
  • Fix test_lock_contention being flaky when running against PostgreSQL by budgeting CPU time rather than wall-clock time. (#​19929)
  • Fix Complement test flake when restarting Synapse workers (cross-test pollution caused by nginx upstreams being temporarily unavailable). (#​19936)
  • Add clean deploy FIXME note for TestOIDCProviderUnavailable (problem tracked by #​19937). (#​19938)
  • Minor presence performance improvements for large servers. (#​19939)
  • Reduce replication traffic caused by presence. (#​19941)
  • Add last_active_granularity, sync_online_timeout and idle_timeout options to the presence config section to allow tuning the presence state machine timers. (#​19942)

v1.156.0

Compare Source

Synapse 1.156.0 (2026-07-07)

No significant changes since 1.156.0rc1.

Synapse 1.156.0rc1 (2026-06-30)
Features
Bugfixes
  • Provide remote servers a way to find out about an event created during the remote join handshake. Contributed by @​FrenchGithubUser and @​jason-famedly @​ Famedly. (#​19390, #​19855, #​19856)
  • Advertise org.matrix.msc4143 in unstable_features when msc4143_enabled is set. (#​19646)
  • Fix a long-standing bug where the badge notification count for a room could become permanently inflated if a read receipt was sent before the room's notification counts were first summarised. (#​19785)
  • Fix startup listener logging to report the actual bound TCP port, so listeners configured with port 0 no longer log Synapse now listening on TCP port 0. (#​19810)
  • Fix notification counts being inflated after a /purge_history when notifications had already been rotated into the summary table. (#​19834)
  • Fix /sync caching transient errors for the sync_response_cache_duration. (#​19845)
  • Fix local events being deleted by the Purge History admin API despite delete_local_events being set to false, in room versions other than 1 and 2. (#​19850)
  • Fix a bug where a user's dehydrated device (MSC3814) was deleted when their device list was synced from Matrix Authentication Service (e.g. upon logging out their last device), breaking offline key delivery. (#​19892)
Improved Documentation
  • Update auto_join_rooms config documentation to cover requirements for auto-joining invite-only rooms. (#​19660)
  • Add stable endpoint for MSC3266: Room summary API into worker docs. Contributed by @​olmari. (#​19788)
  • Tweak wording of Rust crate dependency update policy. (#​19829)
  • Fixed the Admin API user endpoint documentation examples to use JSON booleans (true/false) instead of numeric (0/1) values. (#​19847)
Internal Changes
  • Make simple_select_one_onecol_txn() more helpful by naming the table of the select - as all other query wrapper functions already did. (#​19869)
  • Refactor get_user_which_could_invite logic to reuse get_users_which_can_issue_invite. Contributed by Noah Markert. (#​19732)
  • Fix a flaky test (twisted.protocols.amp.TooLong error under trial -jN) caused by an oversized debug log line. (#​19832)
  • Upload Complement test logs as CI artifacts instead of printing the raw output to the build log. (#​19840)
  • Fix release script considering any workflow completion as successful. (#​19843)
  • Force keyword-args for clear default_config(server_name="test") usage in test utilities. (#​19849)
  • Add .ruff_cache/ directory to .gitignore. (#​19854)
  • Bump poetry in CI from 2.2.1 to 2.4.1. (#​19866, #​19877)
  • Split out deferred and tokio_runtime to their own Rust modules. (#​19868)
  • Prevent the cargo-test and cargo-bench CI jobs from being skipped, even on PRs that have Rust changes. (#​19883)

v1.155.0

Compare Source

Synapse 1.155.0 (2026-06-16)
End of Life of Debian 12 Bookworm

The next version of Synapse will not include Debian packages for Debian 12 Bookworm
as it reached end of life on the 10th of June 2026.

Internal Changes
  • When building releases, don't cancel Debian package builds when one of them fails. (#​19842)
Synapse 1.155.0rc1 (2026-06-09)
Bugfixes
  • Limit the to-device EDU size to a reasonable value to mitigate long queues of to-device messages preventing outgoing federation because of the size of the transaction. (#​19617)
  • Work around bug that sometimes breaks joining restricted rooms that require a remote join. Contributed by @​tulir @​ Beeper. (#​19730)
  • Update Sliding Sync to return a new response immediately if a room subscription has changed and produced a new response. (#​19734, #​19792)
  • Fix the /capabilities endpoint returning a 500 error on non-media workers when MSC4452: Preview URL capabilities API is enabled. (#​19839)
Improved Documentation
  • Document how to see Rust build failure output when using poetry install. (#​19818)
  • Document that the SQLite version included in Ubuntu LTS, aside from ESM-only versions, is included in our support policy. (#​19823)
Internal Changes
  • Port the Python Event classes to Rust. (#​19701, #​19816, #​19817, #​19819)
  • Added tests to ensure that email notification links are sanitized. Contributed by Noah Markert. (#​19741)
  • Add GcpJsonFormatter logging formatter for use with Google Cloud Logging and GKE deployments. (#​19775)
  • Add more logging to the to-device message replication stream. (#​19801, #​19821)
  • Port Requester class to Rust. (#​19828)

v1.154.0

Compare Source

Synapse 1.154.0 (2026-06-04)

No significant changes since 1.154.0rc1.

Synapse 1.154.0rc1 (2026-05-27)
Features
  • Add support for MSC4452: Preview URL capabilities API which exposes a io.element.msc4452.preview_url capability.
    If experimental_features.msc4452_enabled is true, the /_matrix/(client/v1/media|media/v3)/preview_url endpoint
    now responds with a 403 status code when the capability is disabled. (#​19715)
Bugfixes
  • Fix a bug in MSC4186: Simplified Sliding Sync that could prevent user avatars from showing if the room had an empty name. (#​19468, #​19791)
  • Fix access token cache not being invalidated for sessions using refresh tokens. Contributed by @​FrenchGithubUser @​ Famedly. (#​19483)
  • Fix bug where Synapse would return 400 (M_BAD_JSON) when sending a message with a mentions field and Synapse module check_event_allowed callback registered (frozen event). Contributed by @​gaetan-sbt. (#​19634)
  • Fix long-standing but niche bug with /sync where it could attempt to fetch data with flawed invalid future tokens. (#​19644)
  • Fix /sync failing when MSC4354 Sticky Events are enabled and the sync request filters out Ephemeral Data Units (EDUs). (#​19787)
  • Fix packaging for Fedora and EPEL caused by unnecessary bumping attrs minimum version requirement in pyproject.toml file. Contributed by Oleg Girko. (#​19789)
  • Fix merging signatures when a policy server is running under the same server name as Synapse. The bug was re-introduced in v1.153.0rc1 after being fixed earlier in v1.151.0rc1. Contributed by @​tulir @​ Beeper. (#​19797)
Improved Documentation
  • Added details about how Synapse syncs the picture claim when update_profile_information setting is true. (#​19508)
Internal Changes
  • Port Event.content field to Rust. (#​19725)
  • Prefer close backfill points (absolute distance). (#​19748)
  • Replace unique quarantined_media waiting patterns with standard wait_for_stream_token(...). (#​19764)
  • Improve Synapse logging around when someone encounters We can't get valid state history. so you can correlate everything by event_id. (#​19765)
  • Tidy up Rust RoomVersion structs. (#​19766)
  • Update WorkerLock tests to better stress the WORKER_LOCK_MAX_RETRY_INTERVAL. (#​19772)
  • Refactor MSC4242: State DAG checks behind a single TypeIs helper to avoid scattered isinstance casts. (#​19774)
  • Use StrCollection for prev_state_events. (#​19777)
  • Fix up the construction of events in tests, ahead of the Rust event port. (#​19781)

v1.153.0

Compare Source

Synapse 1.153.0 (2026-05-19)

No significant changes since 1.153.0rc3.

Synapse 1.153.0rc3 (2026-05-15)
Bugfixes
Synapse 1.153.0rc2 (2026-05-13)
Bugfixes
  • Correctly handle arbitrary precision integers in unsigned field of events. The bug was introduced in 1.153.0rc1. (#​19769)
Synapse 1.153.0rc1 (2026-05-08)
Features
Bugfixes
  • Allow self-requested user erasure (upon account deactivation) to succeed even if Synapse has disabled profile changes. Contributed by Famedly. (#​19398)
  • Fix Synapse not backfilling new history when attempting to use a pagination token near a backward extremity. (#​19611)
  • Have MSC4186: Simplified Sliding Sync return a new response immediately if a room subscription has changed and produced a new response. (#​19714)
  • Fix a bug where when upgrading a room to room version 12, the power level event in the old room got temporarily mutated to remove the user upgrading the room's power. (#​19727)
  • Fix packaging for Fedora and EPEL caused by unnecessary bumping authlib minimum version requirement in pyproject.toml file. Contributed by Oleg Girko. (#​19742)
Improved Documentation
  • Add warning about known problems when configuring use_frozen_dicts. (#​19711)
Internal Changes
  • Port Event.signatures field to Rust. (#​19706)
  • Port Event.unsigned field to Rust. (#​19708)
  • Add a Rust canonical JSON serializer. (#​19739, #​19763)
  • Configure Dependabot to only update Python dependencies in the lockfile, unless widening upper bounds. (#​19743)
  • Reduce WORKER_LOCK_MAX_RETRY_INTERVAL to 5 seconds to reduce idle time after lock is released. (#​19755)
  • Force keyword-only arguments for Duration so time units have to be specified. (#​19756)

v1.152.1

Compare Source

Synapse 1.152.1 (2026-05-07)
Security Fixes
  • Prevent CPU starvation (Denial of Service) under worker lock contention, additionally capping the WorkerLock time out interval to a maximum of 60 seconds. Contributed by Famedly. (#​19394, ELEMENTSEC-2026-1706, GHSA-8q93-326v-3m7g, CVE-2026-45078)
  • Prevent pagination ending when a page is full of rejected events. (ELEMENTSEC-2025-1636, GHSA-6qf2-7x63-mm6v, CVE-2026-45076)

v1.152.0

Compare Source

Synapse 1.152.0 (2026-04-28)

No significant changes since 1.152.0rc1.

Configuration changes needed for deployments using workers

For deployments using workers, please note that this version introduces a new quarantined_media_changes stream writer, which may require configuration changes.
Please see the the relevant section in the upgrade notes for details.

Without configuring this new stream writer, only the main process will be able to handle the /media/quarantine admin API endpoints for quarantining media.

Synapse 1.152.0rc1 (2026-04-22)
Features
Bugfixes
  • Reject device_keys: null in the request to POST /_matrix/client/v3/keys/upload, as per the spec. This was temporarily allowed as a workaround for misbehaving clients. (#​19637)
  • Fix database migrations failing on platforms where SQLite is configured with SQLITE_DBCONFIG_DEFENSIVE by default, such as macOS. (#​19690)
  • Fix a bug introduced in v1.145 where a non-admin could bypass admin checks for downloading remote quarantined media. This relied on the media already being previously present on the homeserver. (#​19639)
Improved Documentation
  • Include a workaround for running the unit tests with SQLite under recent versions of MacOS. (#​19615)
  • Fix Docker image link typo in worker docs. (#​19645)
  • Update the developer stream docs for creating a new stream to point out _setup_sequence(...) in portdb. (#​19675)
  • Update the developer stream docs for creating a new stream to highlight places that require documentation updates. (#​19696)
Internal Changes
  • Update CI to use re-usable Complement GitHub CI workflow. (#​19533)
  • Fix docstring for limit argument in _maybe_backfill_inner(...). (#​19630)
  • Document context for why increase timeout for policy server requests. (#​19633)
  • Run lint script to format Complement tests introduced in #​19509. (#​19636)
  • Small simplifications to the events class. (#​19680, #​19712)
  • Introduce spam_checker_spammy internal event metadata. (#​19453)
  • Add a FilteredEvent class that saves us copying events. (#​19640)
  • Convert EventInternalMetadata to use Arc<RwLock<_>>. (#​19669)

v1.151.0

Compare Source

Synapse 1.151.0 (2026-04-07)
Bugfixes
  • Fix KNOWN_ROOM_VERSIONS.__contains__ raising TypeError for non-string keys, which could cause /sync to fail for rooms with a NULL room version in the database. Bug introduced in #​19589 as part of v1.151.0rc1. (#​19649)
Synapse 1.151.0rc1 (2026-03-31)
Features
Bugfixes
  • Fix MSC4284 Policy Servers implementation to skip signing org.matrix.msc4284.policy and m.room.policy state events. (#​19503)
  • Correctly apply MSC4284 Policy Server signatures to events when the sender and policy server have the same server name. (#​19503)
  • Allow Synapse to start up even when discovery fails for an OpenID Connect provider. (#​19509)
  • Fix quarantine media admin APIs sometimes returning inaccurate counts for remote media. (#​19559)
  • Fix Build and push complement image CI job not having poetry available for the Complement runner script. (#​19578)
  • Increase timeout for policy server requests to avoid repeated requests for checking media. (#​19629)
Deprecations and Removals
Internal Changes
  • Fix small comment typo in config output from the demo/start.sh script. (#​19538)
  • Add MSC3820 comment context to RoomVersion attributes. (#​19577)
  • Remove redacted_because from internal unsigned. (#​19581)
  • Prevent sending registration emails if registration is disabled. (#​19585)
  • Port RoomVersion to Rust. (#​19589)
  • Only show failing Complement tests in the formatted output in CI. (#​19590)
  • Ensure old Complement test files are removed when downloading a Complement checkout via ./scripts-dev/complement.sh. (#​19592)
  • Update HomeserverTestCase.pump() docstring to demystify behavior (Twisted reactor/clock). (#​19602)
  • Deprecate HomeserverTestCase.pump() in favor of more direct HomeserverTestCase.reactor.advance(...) usage. (#​19602)
  • Lower the Postgres database statement_timeout to 10m (previously 1h). (#​19604)

v1.150.0

Compare Source

Synapse 1.150.0 (2026-03-24)

No significant changes since 1.150.0rc1.

Upgrade notes

Please read the upgrade notes as this release includes a few changes that may affect your deployment.

Synapse 1.150.0rc1 (2026-03-17)
Features
Bugfixes
  • Fix Build and push complement image CI job pointing to non-existent image. (#​19523)
  • Fix a bug introduced in v1.26.0 that caused deactivated, erased users to not be removed from the user directory. (#​19542)
Improved Documentation
  • In the Admin API documentation, always express path parameters as /<param> instead of as /$param. (#​19307)
  • Update docs to clarify outbound_federation_restricted_to can also be used with the Secure Border Gateway (SBG). (#​19517)
  • Unify Complement developer docs. (#​19518)
Internal Changes
  • Put membership updates in a background resumable task when changing the avatar or the display name. (#​19311)
  • Add in-repo Complement test to sanity check Synapse version matches git checkout (testing what we think we are). (#​19476)
  • Migrate dev dependencies to PEP 735 dependency groups. (#​19490)
  • Remove the optional systemd-python dependency and the systemd extra on the synapse package. (#​19491)
  • Avoid re-computing the event ID when cloning events. (#​19527)
  • Allow caching of the /versions and /auth_metadata public endpoints. (#​19530)
  • Add a few labels to the number groupings in the Processed request logs. (#​19548)

v1.149.1

Compare Source

Synapse 1.149.1 (2026-03-11)
Internal Changes
  • Bump matrix-synapse-ldap3 to 0.4.0 to support setuptools>=82.0.0. Fixes #​19541. (#​19543)

v1.149.0

Compare Source

Synapse 1.149.0 (2026-03-10)

No significant changes since 1.149.0rc1.

Synapse 1.149.0rc1 (2026-03-03)
Features
Bugfixes
  • Fix the 'Login as a user' Admin API not checking if the user exists before issuing an access token. (#​18518)
  • Fix /sync missing membership event in state_after (experimental MSC4222 implementation) in some scenarios. (#​19460)
Internal Changes
  • Add log to explain when and why we freeze objects in the garbage collector. (#​19440)
  • Better instrument JoinRoomAliasServlet with tracing. (#​19461)
  • Fix Complement CI not running against the code from our PRs. (#​19475)
  • Log docker system info in CI so we have a plain record of how GitHub runners evolve over time. (#​19480)
  • Rename the test_disconnect test helper so that pytest doesn't see it as a test. (#​19486)
  • Add a log line when we delete devices. Contributed by @​bradtgmurray @​ Beeper. (#​19496)
  • Pre-allocate the buffer based on the expected Content-Length with the Rust HTTP client. (#​19498)
  • Cancel long-running sync requests if the client has gone away. (#​19499)
  • Try and reduce reactor tick times when under heavy load. (#​19507)
  • Simplify Rust HTTP client response streaming and limiting. (#​19510)
  • Replace deprecated collection import locations with current locations. (#​19515)
  • Bump most locked Python dependencies to their latest versions. (#​19519)

v1.148.0

Compare Source

Synapse 1.148.0 (2026-02-24)

No significant changes since 1.148.0rc1.

Synapse 1.148.0rc1 (2026-02-17)
Features
Improved Documentation
  • Fix reference to the experimental_features section of the configuration manual documentation. (#​19435)
Deprecations and Removals
Internal Changes
  • Add in-repo Complement tests so we can test Synapse specific behavior at an end-to-end level. (#​19406)
  • Push Synapse docker images to Element OCI Registry. (#​19420)
  • Allow configuring the Rust HTTP client to use HTTP/2 only. (#​19457)
  • Correctly refuse to start if the Rust workspace config has changed and the Rust library has not been rebuilt. (#​19470)

v1.147.1

Compare Source

Synapse 1.147.1 (2026-02-12)

v1.147.0

Compare Source

Synapse 1.147.0 (2026-02-10)

No significant changes since 1.147.0rc1.

Synapse 1.147.0rc1 (2026-02-03)
Bugfixes
  • Fix memory leak caused by not cleaning up stopped looping calls. Introduced in v1.140.0. (#​19416)
  • Fix a typo that incorrectly made setuptools_rust a runtime dependency. (#​19417)
Internal Changes
  • Prune stale entries from sliding_sync_connection_required_state table. (#​19306)
  • Update "Event Send Time Quantiles" graph to only use dots for the event persistence rate (Grafana dashboard). (#​19399)
  • Update and align Grafana dashboard to use regex matching for job selectors (job=~"$job") so the "all" value works correctly across all panels. (#​19400)
  • Don't retry joining partial state rooms all at once on startup. (#​19402)
  • Disallow requests to the health endpoint from containing trailing path characters. (#​19405)
  • Add notes that new experimental features should have associated tracking issues. (#​19410)
  • Bump pyo3 from 0.26.0 to 0.27.2 and pythonize from 0.26.0 to 0.27.0. Contributed by @​razvp @​ ERCOM. (#​19412)

v1.146.0

Compare Source

Synapse 1.146.0 (2026-01-27)

No significant changes since 1.146.0rc1.

Deprecations and Removals
  • MSC2697 (Dehydrated devices) has been removed, as the MSC is closed. Developers should migrate to MSC3814. (#​19346)
  • Support for Ubuntu 25.04 (Plucky Puffin) has been dropped. Synapse no longer builds debian packages for Ubuntu 25.04.
Synapse 1.146.0rc1 (2026-01-20)
Features
  • Add a new config option enable_local_media_storage which controls whether media is additionally stored locally when using configured media_storage_providers. Setting this to false allows off-site media storage without a local cache. Contributed by Patrice Brend'amour @​dr.allgood. (#​19204)
  • Stabilise support for MSC4312's m.oauth User-Interactive Auth stage for resetting cross-signing identity with the OAuth 2.0 API. The old, unstable name (org.matrix.cross_signing_reset) is now deprecated and will be removed in a future release. (#​19273)
  • Refactor Grafana dashboard to use server_name label (instead of instance). (#​19337)
Bugfixes
  • Fix joining a restricted v12 room locally when no local room creator is present but local users with sufficient power levels are. Contributed by @​nexy7574. (#​19321)
  • Fixed parallel calls to /_matrix/media/v1/create being ratelimited for appservices even if rate_limited: false was set in the registration. Contributed by @​tulir @​ Beeper. (#​19335)
  • Fix a bug introduced in 1.61.0 where a user's membership in a room was accidentally ignored when considering access to historical state events in rooms with the "shared" history visibility. Contributed by Lukas Tautz. (#​19353)
  • MSC4140: Store the JSON content of scheduled delayed events as text instead of a byte array. This fixes the inability to schedule a delayed event with non-ASCII characters in its content. (#​19360)
  • Always rollback database transactions when retrying (avoid orphaned connections). (#​19372)
  • Fix InFlightGauge typing to allow upgrading to prometheus_client 0.24. (#​19379)
Updates to the Docker image
Improved Documentation
  • Remove docs on legacy metric names (no longer in the codebase since 2022-12-06). (#​19341)
  • Clarify how the estimated value of room complexity is calculated internally. (#​19384)
Internal Changes
  • Add an internal cancel_task API to the task scheduler. (#​19310)
  • Tweak docstrings and signatures of auth_types_for_event and get_catchup_room_event_ids. (#​19320)
  • Replace usage of deprecated assertEquals with assertEqual in unit test code. (#​19345)
  • Drop support for Ubuntu 25.04 'Plucky Puffin', add support for Ubuntu 25.10 'Questing Quokka'. (#​19348)
  • Revert "Add an Admin API endpoint for listing quarantined media (#​19268)". (#​19351)
  • Bump mdbook from 0.4.17 to 0.5.2 and remove our custom table-of-contents plugin in favour of the new default functionality. (#​19356)
  • Replace deprecated usage of PyGitHub's GitRelease.title with .name in release script. (#​19358)
  • Update the Element logo in Synapse's README to be an absolute URL, allowing it to render on other sites (such as PyPI). (#​19368)
  • Apply minor tweaks to v1.145.0 changelog. (#​19376)
  • Update Grafana dashboard syntax to use the latest from importing/exporting with Grafana 12.3.1. (#​19381)
  • Warn about skipping reactor metrics when using unknown reactor type. (#​19383)
  • Add support for reactor metrics with the ProxiedReactor used in worker Complement tests. (#​19385)

v1.145.0

Compare Source

Synapse 1.145.0 (2026-01-13)

No significant changes since 1.145.0rc4.

End of Life of Ubuntu 25.04 Plucky Puffin

Ubuntu 25.04 (Plucky Puffin) will be end of life on Jan 17, 2026. Synapse will stop building packages for Ubuntu 25.04 shortly thereafter.

Updates to Locked Dependencies No Longer Included in Changelog

The "Updates to locked dependencies" section has been removed from the changelog due to lack of use and the maintenance burden. (#​19254)

Synapse 1.145.0rc4 (2026-01-08)

No significant changes since 1.145.0rc3.

This RC contains a fix specifically for openSUSE packaging and no other changes.

Synapse 1.145.0rc3 (2026-01-07)

No significant changes since 1.145.0rc2.

This RC strips out unnecessary files from the wheels that were added when fixing the source distribution packaging in the previous RC.

Synapse 1.145.0rc2 (2026-01-07)

No significant changes since 1.145.0rc1.

This RC fixes the source distribution packaging for uploading to PyPI.

Synapse 1.145.0rc1 (2026-01-06)
Features
  • Add memberships endpoint to the admin API. This is useful for forensics and T&S purposes. (#​19260)
  • Server admins can bypass the quarantine media check when downloading media by setting the admin_unsafely_bypass_quarantine query parameter to true on Client-Server API media download requests. (#​19275)
  • Implemented pagination for the MSC2666 mutual rooms endpoint. Contributed by @​tulir @​ Beeper. (#​19279)
  • Admin API: add worker support to GET /_synapse/admin/v2/users/<user_id>. (#​19281)
  • Improve proxy support for the federation_client.py dev script. Contributed by Denis Kasak (@​dkasak). (#​19300)
Bugfixes
  • Fix sliding sync performance slow down for long lived connections. (#​19206)
  • Fix a bug where Mastodon posts (and possibly other embeds) have the wrong description for URL previews. (#​19231)
  • Fix bug where Duration was logged incorrectly. (#​19267)
  • Fix bug introduced in 1.143.0 that broke support for versions of zope-interface older than 6.2. (#​19274)
  • Transform events with client metadata before serialising in /event response. (#​19340)
Updates to the Docker image
  • Add a way to expose metrics from the Docker image (SYNAPSE_ENABLE_METRICS). (#​19324)
Improved Documentation
  • Document the importance of public_baseurl when configuring OpenID Connect authentication. (#​19270)
Deprecations and Removals
  • Ubuntu 25.04 (Plucky Puffin) will be end of life on Jan 17, 2026. Synapse will stop building packages for Ubuntu 25.04 shortly thereafter.
  • Remove the "Updates to locked dependencies" section from the changelog due to lack of use and the maintenance burden. (#​19254)
Internal Changes
  • Group together dependabot update PRs to reduce the review load. (#​18402)
  • Fix HomeServer.shutdown() failing if the homeserver hasn't been setup yet. (#​19187)
  • Respond with useful error codes with Content-Length header/s are invalid. (#​19212)
  • Fix HomeServer.shutdown() failing if the homeserver failed to start. (#​19232)
  • Switch the build backend from poetry-core to maturin. (#​19234)
  • Raise the limit for concurrently-open non-security @​dependabot PRs from 5 to 10. (#​19253)
  • Require 14 days to pass before pulling in general dependency updates to help mitigate upstream supply chain attacks. (#​19258)
  • Drop the broken netlify documentation workflow until a new one is implemented. (#​19262)
  • Don't include debug logs in Clock unless explicitly enabled. (#​19278)
  • Use uv to test olddeps to ensure all transitive dependencies use minimum versions. (#​19289)
  • Add a config to be able to rate limit search in the user directory. (#​19291)
  • Log the original bind exception when encountering Failed to listen on 0.0.0.0, continuing because listening on [::]. (#​19297)
  • Unpin the version of Rust we use to build Synapse wheels (was 1.82.0) now that MacOS support has been dropped. (#​19302)
  • Make it more clear how shared_extra_conf is combined in our Docker configuration scripts. (#​19323)
  • Update CI to stream Complement progress and format logs in a separate step after all tests are done. (#​19326)
  • Format .github/workflows/tests.yml. (#​19327)

v1.144.0

Compare Source

Synapse 1.144.0 (2025-12-09)
Deprecation of MacOS Python wheels

The team has decided to deprecate and stop publishing python wheels for MacOS as of this release. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler).

Unstable mutual rooms endpoint is now behind an experimental feature flag

Admins using the unstable MSC2666 endpoint (/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms), please check the relevant section in the upgrade notes as this release contains changes that disable that endpoint by default.

No significant changes since 1.144.0rc1.

Synapse 1.144.0rc1 (2025-12-02)

Admins using the unstable MSC2666 endpoint (/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms), please check the relevant section in the upgrade notes as this release contains changes that disable that endpoint by default.

Features
  • Add experimental implementation of MSC4380 (invite blocking). (#​19203)
  • Allow restarting delayed event timeouts on workers. (#​19207)
Bugfixes
  • Fix a bug in the database function for fetching state deltas that could result in unnecessarily long query times. (#​18960)
  • Fix v12 rooms when running with use_frozen_dicts: True. (#​19235)
  • Fix bug where invalid canonical_alias content would return 500 instead of 400. (#​19240)
  • Fix bug where Duration was logged incorrectly. (#​19267)
Improved Documentation
  • Document in the --config-path help how multiple files are merged - by merging them shallowly. (#​19243)
Deprecations and Removals
  • Stop building release wheels for MacOS. (#​19225)
Internal Changes
  • Improve event filtering for Simplified Sliding Sync. (#​17782)
  • Export SYNAPSE_SUPPORTED_COMPLEMENT_TEST_PACKAGES environment variable from scripts-dev/complement.sh. (#​19208)
  • Refactor scripts-dev/complement.sh logic to avoid exit to facilitate being able to source it from other scripts (composable). (#​19209)
  • Expire sliding sync connections that are too old or have too much pending data. (#​19211)
  • Require an experimental feature flag to be enabled in order for the unstable MSC2666 endpoint (/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms) to be available. (#​19219)
  • Prevent changelog check CI running on @​dependabot's PRs even when a human has modified the branch. (#​19220)
  • Auto-fix trailing spaces in multi-line strings and comments when running the lint script. (#​19221)
  • Move towards using a dedicated Duration type. (#​19223, #​19229)
  • Improve robustness of the SQL schema linting in CI. (#​19224)
  • Add log to determine whether clients are using /messages as expected. (#​19226)
  • Simplify README and add ESS Getting started section. (#​19228, #​19259)
  • Add a unit test for ensuring associated refresh tokens are erased when a device is deleted. (#​19230)
  • Prompt user to consider adding future deprecations to the changelog in release script. (#​19239)
  • Fix check of the Rust compiled code being outdated when using source checkout and .egg-info. (#​19251)
  • Stop building MacOS wheels in CI pipeline. (#​19263)
Updates to locked dependencies
  • Bump Swatinem/rust-cache from 2.8.1 to 2.8.2. (#​19244)
  • Bump actions/checkout from 5.0.0 to 6.0.0. (#​19213)
  • Bump actions/setup-go from 6.0.0 to 6.1.0. (#​19214)
  • Bump actions/setup-python from 6.0.0 to 6.1.0. (#​19245)
  • Bump attrs from 25.3.0 to 25.4.0. (#​19215)
  • Bump docker/metadata-action from 5.9.0 to 5.10.0. (#​19246)
  • Bump http from 1.3.1 to 1.4.0. (#​19249)
  • Bump pydantic from 2.12.4 to 2.12.5. (#​19250)
  • Bump pyopenssl from 25.1.0 to 25.3.0. (#​19248)
  • Bump rpds-py from 0.28.0 to 0.29.0. (#​19216)
  • Bump rpds-py from 0.29.0 to 0.30.0. (#​19247)
  • Bump sentry-sdk from 2.44.0 to 2.46.0. (#​19218)
  • Bump types-bleach from 6.2.0.20250809 to 6.3.0.20251115. (#​19217)
  • Bump types-jsonschema from 4.25.1.20250822 to 4.25.1.20251009. (#​19252)

v1.143.0

Compare Source

Synapse 1.143.0 (2025-11-25)
Dropping support for PostgreSQL 13

In line with our deprecation policy, we've dropped support for PostgreSQL 13, as it is no longer supported upstream. This release of Synapse requires PostgreSQL 14+.

No significant changes since 1.143.0rc2.

synapse 1.143.0rc2 (2025-11-18)
Internal Changes
  • Fixes docker image creation in the release workflow.
Synapse 1.143.0rc1 (2025-11-18)
Features
  • Support multiple config files in register_new_matrix_user. (#​18784)
  • Remove authentication from POST /_matrix/client/v1/delayed_events, and allow calling this endpoint with the update action to take (send/cancel/restart) in the request path instead of the body. (#​19152)
Bugfixes
  • Fixed a longstanding bug where background updates were only run on the main database. (#​19181)
  • Fixed a bug introduced in v1.142.0 preventing subpaths in MAS endpoints from working. (#​19186)
  • Fix the SQLite-to-PostgreSQL migration script to correctly migrate a boolean column in the delayed_events table. (#​19155)
Improved Documentation
  • Improve documentation around streams, particularly ID generators and adding new streams. (#​18943)
Deprecations and Removals
  • Remove support for PostgreSQL 13. (#​19170)
Internal Changes
  • Provide additional servers with federation room directory results. (#​18970)
  • Add a shortcut return when there are no events to purge. (#​19093)
  • Write union types as X | Y where possible, as per PEP 604, added in Python 3.10. (#​19111)
  • Reduce cardinality of synapse_storage_events_persisted_events_sep_total metric by removing origin_entity label. This also separates out events sent by local application services by changing the origin_type for such events to application_service. The type field also only tracks common event types, and anything else is bucketed under *other*. (#​19133, #​19168)
  • Run trial tests on Python 3.14 for PRs. (#​19135)
  • Update pyproject.toml project metadata to be compatible with standard Python packaging tooling. (#​19137)
  • Minor speed up of processing of inbound replication. (#​19138, #​19145, #​19146)
  • Ignore recent Python language refactors from git blame (.git-blame-ignore-revs). (#​19150)
  • Bump lower bounds of dependencies parameterized to 0.9.0 and idna to 3.3 as those are the first to advertise support for Python 3.10. (#​19167)
  • Point out which event caused the exception when checking MSC4293 redactions. (#​19169)
  • Restore printing sentinel for the log record request when no logcontext is active. (#​19172)
  • Add debug logs to track Clock utilities. (#​19173)
  • Remove explicit python version skips in cibuildwheel config as it's no longer required after #​19137. (#​19177)
  • Fix potential lost logcontext when PerDestinationQueue.shutdown(...) is called. (#​19178)
  • Fix bad deferred logcontext handling across the codebase. (#​19180)
Updates to locked dependencies
  • Bump bytes from 1.10.1 to 1.11.0. (#​19193)
  • Bump click from 8.1.8 to 8.3.1. (#​19195)
  • Bump cryptography from 43.0.3 to 45.0.7. (#​19159)
  • Bump docker/metadata-action from 5.8.0 to 5.9.0. (#​19161)
  • Bump pydantic from 2.12.3 to 2.12.4. (#​19158)
  • Bump pyo3-log from 0.13.1 to 0.13.2. (#​19156)
  • Bump ruff from 0.14.3 to 0.14.5. (#​19196)
  • Bump sentry-sdk from 2.34.1 to 2.43.0. (#​19157)
  • Bump sentry-sdk from 2.43.0 to 2.44.0. (#​19197)
  • Bump tomli from 2.2.1 to 2.3.0. (#​19194)
  • Bump types-netaddr from 1.3.0.20240530 to 1.3.0.20251108. (#​19160)

v1.142.1

Compare Source

Synapse 1.142.1 (2025-11-18)
Bugfixes
  • Fixed a bug introduced in v1.142.0 preventing subpaths in MAS endpoints from working. (#​19186)

v1.142.0

Compare Source

Synapse 1.142.0 (2025-11-11)
Dropped support for Python 3.9

This release drops support for Python 3.9, in line with our dependency deprecation policy, as it is now end of life.

SQLite 3.40.0+ is now required

The minimum supported SQLite version has been increased from 3.27.0 to 3.40.0.

If you use current versions of the matrixorg/synapse Docker images, no action is required.

Deprecation of MacOS Python wheels

The team has decided to deprecate and eventually stop publishing python wheels for MacOS. This is a burden on the team, and we're not aware of any parties that use them. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler).

At present, publishing MacOS Python wheels will continue for the next release (1.143.0), but will not be available after that (1.144.0+). If you do make use of these wheels downstream, please reach out to us in #synapse-dev:matrix.org. We'd love to hear from you!

Internal Changes
  • Properly stop building wheels for Python 3.9 and free-threaded CPython. (#​19154)
Synapse 1.142.0rc4 (2025-11-07)
Bugfixes
  • Fix a bug introduced in 1.142.0rc1 where any attempt to configure matrix_authentication_service.secret_path would prevent the homeserver from starting up. (#​19144)
Synapse 1.142.0rc3 (2025-11-04)
Internal Changes
  • Update release scripts to prevent building wheels for free-threaded Python, as Synapse does not currently support it. (#​19140)
Synapse 1.142.0rc2 (2025-11-04)
Internal Changes
  • Manually skip building Python 3.9 wheels, to prevent errors in the release workflow. (#​19119)
Synapse 1.142.0rc1 (2025-11-04)
Features
Bugfixes
  • Fix a bug introduced in 1.111.0 where failed attempts to download authenticated remote media would not be handled correctly. (#​19062)
  • Update the oidc_session_no_samesite cookie to have the Secure attribute, so the only difference between it and the paired oidc_session cookie, is the configuration of the SameSite attribute as described in the comments / cookie names. Contributed by @​kieranlane. (#​19079)
  • Fix a bug introduced in 1.140.0 where lost logcontext warnings would be emitted from timeouts in sync and requests made by Synapse itself. (#​19090)
  • Fix a bug introdued in 1.140.0 where lost logcontext warning were emitted when using HomeServer.shutdown(). (#​19108)
Improved Documentation
  • Update the link to the Debian oldstable package for SQLite. (#​19047)
  • Point out additional Redis configuration options available in the worker docs. Contributed by @​servisbryce. (#​19073)
  • Update the list of Debian releases that the downstream Debian package is maintained for. (#​19100)
  • Add a page to the documentation describing the steps the Synapse team takes to review the release notes before publishing them. (#​19109)
Deprecations and Removals
  • Drop support for Python 3.9. (#​19099)
  • Remove support for SQLite < 3.37.2. (#​19047)
Internal Changes
  • Fix CI linter for schema delta files to correctly handle all types of CREATE TABLE syntax. (#​19020)
  • Use type hinting generics in standard collections, as per PEP 585, added in Python 3.9. (#​19046)
  • Always treat RETURNING as supported by SQL engines, now that the minimum-supported versions of both SQLite and PostgreSQL support it. (#​19047)
  • Move oidc.load_metadata() startup into _base.start(). (#​19056)
  • Remove logcontext problems caused by awaiting raw deferLater(...). (#​19058)
  • Prevent duplicate logging setup when running multiple Synapse instances. (#​19067)
  • Be mindful of other logging context filters in 3rd-party code and avoid overwriting log record fields unless we know the log record is relevant to Synapse. (#​19068)
  • Update pydantic to v2. (#​19071)
  • Update deprecated code in the release script to prevent a warning message from being printed. (#​19080)
  • Update the deprecated poetry development dependencies group name in pyproject.toml. (#​19081)
  • Remove pp38* skip selector from cibuildwheel to silence warning. (#​19085)
  • Don't immediately exit the release script if the checkout is dirty. Instead, allow the user to clear the dirty changes and retry. (#​19088)
  • Update the release script's generated announcement text to include a title and extra text for RC's. (#​19089)
  • Fix lints on main branch. (#​19092)
  • Use cheaper random string function in logcontext utilities. (#​19094)
  • Avoid clobbering other SIGHUP handlers in 3rd-party code. (#​19095)
  • Prevent duplicate GitHub draft releases being created during the Synapse release process. (#​19096)
  • Use Pillow's Image.getexif method instead of the experimental Image._getexif. (#​19098)
  • Prevent uv /usr/local/.lock file from appearing in built Synapse docker images. (#​19107)
  • Allow Synapse's runtime dependency checking code to take packaging markers (i.e. python <= 3.14) into account when checking dependencies. (#​19110)
  • Move exception handling up the stack (avoid exit(1) in our composable functions). (#​19116)
  • Fix a lint error related to lifetimes in Rust 1.90. (#​19118)
  • Refactor and align app entrypoints (avoid exit(1) in our composable functions). (#​19121, #​19131)
  • Speed up pruning of ratelimiters. (#​19129)
Updates to locked dependencies
  • Bump actions/download-artifact from 5.0.0 to 6.0.0. (#​19102)
  • Bump actions/upload-artifact from 4 to 5. (#​19106)
  • Bump hiredis from 3.2.1 to 3.3.0. (#​19103)
  • Bump icu_segmenter from 2.0.0 to 2.0.1. (#​19126)
  • Bump idna from 3.10 to 3.11. (#​19053)
  • Bump ijson from 3.4.0 to 3.4.0.post0. (#​19051)
  • Bump markdown-it-py from 3.0.0 to 4.0.0. (#​19123)
  • Bump msgpack from 1.1.1 to 1.1.2. (#​19050)
  • Bump psycopg2 from 2.9.10 to 2.9.11. (#​19125)
  • Bump pyyaml from 6.0.2 to 6.0.3. (#​19105)
  • Bump regex from 1.11.3 to 1.12.2. (#​19074)
  • Bump reqwest from 0.12.23 to 0.12.24. (#​19077)
  • Bump ruff from 0.12.10 to 0.14.3. (#​19124)
  • Bump sigstore/cosign-installer from 3.10.0 to 4.0.0. (#​19075)
  • Bump stefanzweifel/git-auto-commit-action from 6.0.1 to 7.0.0. (#​19052)
  • Bump tokio from 1.47.1 to 1.48.0. (#​19076)
  • Bump types-psycopg2 from 2.9.21.20250915 to 2.9.21.20251012. (#​19054)

v1.141.0

Compare Source

Synapse 1.141.0 (2025-10-29)
Deprecation of MacOS Python wheels

The team has decided to deprecate and eventually stop publishing python wheels
for MacOS. This is a burden on the team, and we're not aware of any parties
that use them. Synapse docker images will continue to work on MacOS, as will
building Synapse from source (though note this requires a Rust compiler).

Publishing MacOS Python wheels will continue for the next few releases. If you
do make use of these wheels downstream, please reach out to us in
#synapse-dev:matrix.org. We'd love to hear from you!

Docker images now based on Debian trixie with Python 3.13

The Docker images are now based on Debian trixie and use Python 3.13. If you
are using the Docker images as a base image you may need to e.g. adjust the
paths you mount any additional Python packages at.

No significant changes since 1.141.0rc2.

Synapse 1.141.0rc2 (2025-10-28)
Bugfixes
  • Fix users being unable to log in if their password, or the server's configured pepper, was too long. (#​19101)
Synapse 1.141.0rc1 (2025-10-21)
Features
Bugfixes
  • Fix a bug introduced in 1.136.0 that would prevent Synapse from being able to be reload-ed more than once when running under systemd. (#​19060)
  • Fix a bug introduced in 1.140.0 where an internal server error could be raised when hashing user passwords that are too long. (#​19078)
Updates to the Docker image
  • Update docker image to use Debian trixie as the base and thus Python 3.13. (#​19064)
Internal Changes
  • Move unique snowflake homeserver background tasks to start_background_tasks (the standard pattern for this kind of thing). (#​19037)
  • Drop a deprecated field of the PyGitHub dependency in the release script and raise the dependency's minimum version to 1.59.0. (#​19039)
  • Update TODO list of conflicting areas where we encounter metrics being clobbered (ApplicationService). (#​19040)

v1.140.0

Compare Source

Synapse 1.140.0 (2025-10-14)
Compatibility notice for users of synapse-s3-storage-provider

Deployments that make use of the synapse-s3-storage-provider module must upgrade to v1.6.0.

Using older versions of the module with this release of Synapse will prevent users from being able to upload or download media.

No significant changes since 1.140.0rc1.

Synapse 1.140.0rc1 (2025-10-10)
Features
Bugfixes
  • Fix room upgrade room_config argument and documentation for user_may_create_room spam-checker callback. (#​18721)
  • Compute a user's last seen timestamp from their devices' last seen timestamps instead of IPs, because the latter are automatically cleared according to user_ips_max_age. (#​18948)
  • Fix bug where ephemeral events were not filtered by room ID. Contributed by @​frastefanini. (#​19002)
  • Update Synapse main process version string to include git info. (#​19011)
Improved Documentation
  • Explain how Deferred callbacks interact with logcontexts. (#​18914)
  • Fix documentation for rc_room_creation and rc_reports to clarify that a per_user rate limit is not supported. (#​18998)
Deprecations and Removals
  • Remove deprecated LoggingContext.set_current_context/LoggingContext.current_context methods which already have equivalent bare methods in synapse.logging.context. (#​18989)
  • Drop support for unstable field names from the long-accepted MSC2732 (Olm fallback keys) proposal. (#​18996)
Internal Changes
  • Cleanly shutdown SynapseHomeServer object, allowing artifacts of embedded small hosts to be properly garbage collected. (#​18828)
  • Update OEmbed providers to use 'X' instead of 'Twitter' in URL previews, following a rebrand. Contributed by @​HammyHavoc. (#​18767)
  • Fix server_name in logging context for multiple Synapse instances in one process. (#​18868)
  • Wrap the Rust HTTP client with make_deferred_yieldable so it follows Synapse logcontext rules. (#​18903)
  • Fix the GitHub Actions workflow that moves issues labeled "X-Needs-Info" to the "Needs info" column on the team's internal triage board. (#​18913)
  • Disconnect background process work from request trace. (#​18932)
  • Reduce overall number of calls to _get_e2e_cross_signing_signatures_for_devices by increasing the batch size of devices the query is called with, reducing DB load. (#​18939)
  • Update error code used when an appservice tries to masquerade as an unknown device using MSC4326. Contributed by @​tulir @​ Beeper. (#​18947)
  • Fix no active span when trying to log tracing error on startup (when OpenTracing is enabled). (#​18959)
  • Fix run_coroutine_in_background(...) incorrectly handling logcontext. (#​18964)
  • Add debug logs wherever we change current logcontext. (#​18966)
  • Update dockerfile metadata to fix broken link; point to documentation website. (#​18971)
  • Note that the code is additionally licensed under the Element Commercial license in SPDX expression field configs. (#​18973)
  • Fix logcontext handling in timeout_deferred tests. (#​18974)
  • Remove internal ReplicationUploadKeysForUserRestServlet as a follow-up to the work in #​18581 that moved device changes off the main process. (#​18988)
  • Switch task scheduler from raw logcontext manipulation to using the dedicated logcontext utils. (#​18990)
  • Remove MockClock() in tests. (#​18992)
  • Switch back to our own custom LogContextScopeManager instead of OpenTracing's ContextVarsScopeManager which was causing problems when using the experimental SYNAPSE_ASYNC_IO_REACTOR option with tracing enabled. (#​19007)
  • Remove version_string argument from HomeServer since it's always the same. (#​19012)
  • Remove duplicate call to hs.start_background_tasks() introduced from a bad merge. (#​19013)
  • Split homeserver creation (create_homeserver) and setup (setup). (#​19015)
  • Swap near-end-of-life macos-13 GitHub Actions runner for the macos-15-intel variant. (#​19025)
  • Introduce RootConfig.validate_config() which can be subclassed in HomeServerConfig to do cross-config class validation. (#​19027)
  • Allow any command of the release.py script to accept a --gh-token argument. (#​19035)
Updates to locked dependencies
  • Bump Swatinem/rust-cache from 2.8.0 to 2.8.1. (#​18949)
  • Bump actions/cache from 4.2.4 to 4.3.0. (#​18983)
  • Bump anyhow from 1.0.99 to 1.0.100. (#​18950)
  • Bump authlib from 1.6.3 to 1.6.4. (#​18957)
  • Bump authlib from 1.6.4 to 1.6.5. (#​19019)
  • Bump bcrypt from 4.3.0 to 5.0.0. (#​18984)
  • Bump docker/login-action from 3.5.0 to 3.6.0. (#​18978)
  • Bump lxml from 6.0.0 to 6.0.2. (#​18979)
  • Bump phonenumbers from 9.0.13 to 9.0.14. (#​18954)
  • Bump phonenumbers from 9.0.14 to 9.0.15. (#​18991)
  • Bump prometheus-client from 0.22.1 to 0.23.1. (#​19016)
  • Bump pydantic from 2.11.9 to 2.11.10. (#​19017)
  • Bump pygithub from 2.7.0 to 2.8.1. (#​18952)
  • Bump regex from 1.11.2 to 1.11.3. (#​18981)
  • Bump serde from 1.0.224 to 1.0.226. (#​18953)
  • Bump serde from 1.0.226 to 1.0.228. (#​18982)
  • Bump setuptools-rust from 1.11.1 to 1.12.0. (#​18980)
  • Bump twine from 6.1.0 to 6.2.0. (#​18985)
  • Bump types-pyyaml from 6.0.12.20250809 to 6.0.12.20250915. (#​19018)
  • Bump types-requests from 2.32.4.20250809 to 2.32.4.20250913. (#​18951)
  • Bump typing-extensions from 4.14.1 to 4.15.0. (#​18956)

v1.139.2

Compare Source

Synapse 1.139.2 (2025-10-07)
Bugfixes

v1.139.1

Compare Source

Synapse 1.139.1 (2025-10-07)
Security Fixes
  • Fix CVE-2025-61672 / GHSA-fh66-fcv5-jjfr. Lack of validation for device keys in Synapse before 1.139.1 allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. (#​17097)
Deprecations and Removals
  • Drop support for unstable field names from the long-accepted MSC2732 (Olm fallback keys) proposal. This change allows unit tests to pass following the security patch above. (#​18996)

v1.139.0

Compare Source

Synapse 1.139.0 (2025-09-30)
/register requests from old application service implementations may break when using MAS

If you are using Matrix Authentication Service (MAS), as of this release any Application Services that do not set inhibit_login=true when calling POST /_matrix/client/v3/register will receive the error IO.ELEMENT.MSC4190.M_APPSERVICE_LOGIN_UNSUPPORTED in response.

Please see the upgrade notes for more information.

No significant changes since 1.139.0rc3.

Synapse 1.139.0rc3 (2025-09-25)
Bugfixes
  • Fix a bug introduced in 1.139.0rc1 where run_coroutine_in_background(...) incorrectly handled logcontexts, resulting in partially broken logging. (#​18964)
Synapse 1.139.0rc2 (2025-09-23)
Internal Changes
  • Drop support for Ubuntu 24.10 Oracular Oriole, and add support for Ubuntu 25.04 Plucky Puffin. (#​18962)
Synapse 1.139.0rc1 (2025-09-23)
Features
Bugfixes
  • Ensure all PDUs sent via /send pass canonical JSON checks. (#​18641)
  • Fix bug where we did not send invite revocations over federation. (#​18823)
  • Fix prefixed support for MSC4133. (#​18875)
  • Fix open redirect in legacy SSO flow with the idp query parameter. (#​18909)
  • Fix a performance regression related to the experimental Delayed Events (MSC4140) feature. (#​18926)
Updates to the Docker image
  • Suppress "Applying schema" log noise bulk when SYNAPSE_LOG_TESTING is set. (#​18878)
Improved Documentation
  • Clarify Python dependency constraints in our deprecation policy. (#​18856)
  • Clarify necessary jwt_config parameter in OIDC documentation for authentik. Contributed by @​maxkratz. (#​18931)
Deprecations and Removals
  • Remove obsolete and experimental /sync/e2ee endpoint. (#​18583)
Internal Changes
  • Fix LaterGauge metrics to collect from all servers. (#​18791)
  • Configure Synapse to run MSC4306: Thread Subscriptions Complement tests. (#​18819)
  • Remove sentinel logcontext usage where we log in setup, start and exit. (#​18870)
  • Use the Enum's value for the dictionary key when responding to an admin request for experimental features. (#​18874)
  • Start background tasks after we fork the process (daemonize). (#​18886)
  • Better explain how we manage the logcontext in run_in_background(...) and run_as_background_process(...). (#​18900, #​18906)
  • Remove sentinel logcontext usage in Clock utilities like looping_call and call_later. (#​18907)
  • Replace usages of the deprecated pkg_resources interface in preparation of setuptools dropping it soon. (#​18910)
  • Split loading config from homeserver setup. (#​18933)
  • Fix run_in_background not being awaited properly in some tests causing LoggingContext problems. (#​18937)
  • Fix run_as_background_process not being awaited properly causing LoggingContext problems in experimental MSC4140: Delayed events implementation. (#​18938)
  • Introduce Clock.call_when_running(...) to wrap startup code in a logcontext, ensuring we can identify which server generated the logs. (#​18944)
  • Introduce Clock.add_system_event_trigger(...) to wrap system event callback code in a logcontext, ensuring we can identify which server generated the logs. (#​18945)
Updates to locked dependencies
  • Bump actions/setup-go from 5.5.0 to 6.0.0. (#​18891)
  • Bump actions/setup-python from 5.6.0 to 6.0.0. (#​18890)
  • Bump authlib from 1.6.1 to 1.6.3. (#​18921)
  • Bump jsonschema from 4.25.0 to 4.25.1. (#​18897)
  • Bump log from 0.4.27 to 0.4.28. (#​18892)
  • Bump phonenumbers from 9.0.12 to 9.0.13. (#​18893)
  • Bump pydantic from 2.11.7 to 2.11.9. (#​18922)
  • Bump serde from 1.0.219 to 1.0.223. (#​18920)
  • Bump serde_json from 1.0.143 to 1.0.145. (#​18919)
  • Bump sigstore/cosign-installer from 3.9.2 to 3.10.0. (#​18917)
  • Bump towncrier from 24.8.0 to 25.8.0. (#​18894)
  • Bump types-psycopg2 from 2.9.21.20250809 to 2.9.21.20250915. (#​18918)
  • Bump types-requests from 2.32.4.20250611 to 2.32.4.20250809. (#​18895)
  • Bump types-setuptools from 80.9.0.20250809 to 80.9.0.20250822. (#​18924)

v1.138.4

Compare Source

Synapse 1.138.4 (2025-10-07)
Bugfixes

v1.138.3

Compare Source

Synapse 1.138.3 (2025-10-07)
Security Fixes
  • Fix CVE-2025-61672 / GHSA-fh66-fcv5-jjfr. Lack of validation for device keys in Synapse before 1.139.1 allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. (#​17097)
Deprecations and Removals
  • Drop support for unstable field names from the long-accepted MSC2732 (Olm fallback keys) proposal. This change allows unit tests to pass following the security patch above. (#​18996)

v1.138.2

Compare Source

Synapse 1.138.2 (2025-09-24)
Internal Changes
  • Drop support for Ubuntu 24.10 Oracular Oriole, and add support for Ubuntu 25.04 Plucky Puffin. (#​18962)
Synapse 1.138.1 (2025-09-24)
Bugfixes
  • Fix a performance regression related to the experimental Delayed Events (MSC4140) feature. (#​18926)

v1.138.1

Compare Source

v1.138.0

Compare Source

Synapse 1.138.0 (2025-09-09)

No significant changes since 1.138.0rc1.

Synapse 1.138.0rc1 (2025-09-02)
Features
Bugfixes
  • Improve database performance of MSC4293 - Redact on Kick/Ban. (#​18851)
  • Do not throw an error when fetching a rejected delayed state event on startup. (#​18858)
Improved Documentation
  • Fix worker documentation incorrectly indicating all room Admin API requests were capable of being handled by workers. (#​18853)
Internal Changes
  • Instrument _ByteProducer with tracing to measure potential dead time while writing bytes to the request. (#​18804)
  • Switch to OpenTracing's ContextVarsScopeManager instead of our own custom LogContextScopeManager. (#​18849)
  • Trace how much work is being done while "recursively fetching redactions". (#​18854)
  • Link upstream Twisted bug tracking the problem that explains why we have to use a Producer to write bytes to the request. (#​18855)
  • Introduce EventPersistencePair type. (#​18857)
Updates to locked dependencies
  • Bump actions/add-to-project from c0c5949 to 4515659. (#​18863)
  • Bump actions/checkout from 4.3.0 to 5.0.0. (#​18834)
  • Bump anyhow from 1.0.98 to 1.0.99. (#​18841)
  • Bump docker/login-action from 3.4.0 to 3.5.0. (#​18835)
  • Bump dtolnay/rust-toolchain from b3b07ba to e97e2d8. (#​18862)
  • Bump phonenumbers from 9.0.11 to 9.0.12. (#​18837)
  • Bump regex from 1.11.1 to 1.11.2. (#​18864)
  • Bump reqwest from 0.12.22 to 0.12.23. (#​18842)
  • Bump ruff from 0.12.7 to 0.12.10. (#​18865)
  • Bump serde_json from 1.0.142 to 1.0.143. (#​18866)
  • Bump types-bleach from 6.2.0.20250514 to 6.2.0.20250809. (#​18838)
  • Bump types-jsonschema from 4.25.0.20250720 to 4.25.1.20250822. (#​18867)
  • Bump types-psycopg2 from 2.9.21.20250718 to 2.9.21.20250809. (#​18836)

v1.137.0

Compare Source

Synapse 1.137.0 (2025-08-26)

No significant changes since 1.137.0rc1.

Synapse 1.137.0rc1 (2025-08-19)
Bugfixes
  • Fix a bug which could corrupt auth chains making it impossible to perform state resolution. (#​18746)
  • Fix error message in register_new_matrix_user utility script for empty registration_shared_secret. (#​18780)
  • Allow enabling MSC4108 when the stable Matrix Authentication Service integration is enabled. (#​18832)
Improved Documentation
Internal Changes
  • Update tests to ensure all database tables are emptied when purging a room. (#​18794)
  • Instrument the encode_response part of Sliding Sync requests for more complete traces in Jaeger. (#​18815)
  • Tag Sliding Sync traces when we wait_for_events. (#​18816)
  • Fix portdb CI by hardcoding the new pg_dump restrict key that was added due to CVE-2025-8714. (#​18824)
Updates to locked dependencies
  • Bump actions/add-to-project from 5b1a254 to 0c37450. (#​18557)
  • Bump actions/cache from 4.2.3 to 4.2.4. (#​18799)
  • Bump actions/checkout from 4.2.2 to 4.3.0. (#​18800)
  • Bump actions/download-artifact from 4.3.0 to 5.0.0. (#​18801)
  • Bump docker/metadata-action from 5.7.0 to 5.8.0. (#​18773)
  • Bump mypy from 1.16.1 to 1.17.1. (#​18775)
  • Bump phonenumbers from 9.0.10 to 9.0.11. (#​18797)
  • Bump pygithub from 2.6.1 to 2.7.0. (#​18779)
  • Bump serde_json from 1.0.141 to 1.0.142. (#​18776)
  • Bump slab from 0.4.10 to 0.4.11. (#​18809)
  • Bump tokio from 1.47.0 to 1.47.1. (#​18774)
  • Bump types-pyyaml from 6.0.12.20250516 to 6.0.12.20250809. (#​18798)
  • Bump types-setuptools from 80.9.0.20250529 to 80.9.0.20250809. (#​18796)

v1.136.0

Compare Source

Synapse 1.136.0 (2025-08-12)

Note: This release includes the security fixes from 1.135.2 and 1.136.0rc2, detailed below.

Please also check the relevant section in the upgrade notes for the changes to MAS support, metrics labels and the module API which may require your attention when upgrading.

Bugfixes
  • Fix bug introduced in 1.135.2 and 1.136.0rc2 where the Make Room Admin API would not treat a room v12's creator power level as the highest in room. (#​18805)
Synapse 1.136.0rc2 (2025-08-11)

This is the Synapse portion of the Matrix coordinated security release. This release includes support for room version 12 which fixes a number of security vulnerabilities, including CVE-2025-49090.

The default room version is not changed. Not all clients will support room version 12 immediately, and not all users will be using the latest version of their clients. Large, public rooms are advised to wait a few weeks before upgrading to room version 12 to allow users throughout the Matrix ecosystem to update their clients.

Note: release 1.135.1 was skipped due to issues discovered during the release process.

Two patched Synapse releases are now available:

  • 1.135.2: stable release comprised of 1.135.0 + security patches
    • Upgrade to this release if you are currently running 1.135.0 or below.
  • 1.136.0rc2: unstable release candidate comprised of 1.136.0rc1 + security patches.
    • Upgrade to this release only if you are on 1.136.0rc1.
Bugfixes
  • Update MSC4293 redaction logic for room v12. (#​80)
Internal Changes
  • Add a parameter to upgrade_rooms(..) to allow auto join local users. (#​83)
Synapse 1.136.0rc1 (2025-08-05)
Features
  • Add configurable rate limiting for the creation of rooms. (#​18514)
  • Add support for MSC4293 - Redact on Kick/Ban. (#​18540)
  • When admins enable themselves to see soft-failed events, they will also see if the cause is due to the policy server flagging them as spam via unsigned. (#​18585)
  • Add ability to configure forward/outbound proxy via homeserver config instead of environment variables. See http_proxy, https_proxy, no_proxy_hosts. (#​18686)
  • Advertise experimental support for MSC4306 (Thread Subscriptions) through /_matrix/clients/versions if enabled. (#​18722)
  • Stabilise support for delegating authentication to Matrix Authentication Service. (#​18759)
  • Implement the push rules for experimental MSC4306: Thread Subscriptions. (#​18762)
Bugfixes
  • Allow return code 403 (allowed by C2S Spec since v1.2) when fetching profiles via federation. (#​18696)
  • Register the MSC4306 (Thread Subscriptions) endpoints in the CS API when the experimental feature is enabled. (#​18726)
  • Fix a long-standing bug where suspended users could not have server notices sent to them (a 403 was returned to the admin). (#​18750)
  • Fix an issue that could cause logcontexts to be lost on rate-limited requests. Found by @​realtyem. (#​18763)
  • Fix invalidation of storage cache that was broken in 1.135.0. (#​18786)
Improved Documentation
  • Minor improvements to README. (#​18700)
  • Document that there can be multiple workers handling the receipts stream. (#​18760)
  • Improve worker documentation for some device paths. (#​18761)
Deprecations and Removals
Internal Changes
  • Add debug logging for HMAC digest verification failures when using the admin API to register users. (#​18474)
  • Speed up upgrading a room with large numbers of banned users. (#​18574)
  • Fix config documentation generation script on Windows by enforcing UTF-8. (#​18580)
  • Refactor cache, background process, Counter, LaterGauge, GaugeBucketCollector, Histogram, and Gauge metrics to be homeserver-scoped. (#​18656, #​18714, #​18715, #​18724, #​18753, #​18725, #​18670, #​18748, #​18751)
  • Reduce database usage in Sliding Sync by not querying for background update completion after the update is known to be complete. (#​18718)
  • Improve order of validation and ratelimiting in room creation. (#​18723)
  • Bump minimum version bound on Twisted to 21.2.0. (#​18727, #​18729)
  • Use twisted.internet.testing module in tests instead of deprecated twisted.test.proto_helpers. (#​18728)
  • Remove obsolete /send_event replication endpoint. (#​18730)
  • Update metrics linting to be able to handle custom metrics. (#​18733)
  • Work around twisted.protocols.amp.TooLong error by reducing logging in some tests. (#​18736)
  • Prevent "Move labelled issues to correct projects" GitHub Actions workflow from failing when an issue is already on the project board. (#​18755)
  • Bump minimum supported Rust version (MSRV) to 1.82.0. Missed in #​18553 (released in Synapse 1.134.0). (#​18757)
  • Make Clock.sleep(...) return a coroutine, so that mypy can catch places where we don't await on it. (#​18772)
  • Update implementation of MSC4306: Thread Subscriptions to include automatic subscription conflict prevention as introduced in later drafts. (#​18756)
Updates to locked dependencies
  • Bump gitpython from 3.1.44 to 3.1.45. (#​18743)
  • Bump mypy-zope from 1.0.12 to 1.0.13. (#​18744)
  • Bump phonenumbers from 9.0.9 to 9.0.10. (#​18741)
  • Bump ruff from 0.12.4 to 0.12.5. (#​18742)
  • Bump sentry-sdk from 2.32.0 to 2.33.2. (#​18745)
  • Bump tokio from 1.46.1 to 1.47.0. (#​18740)
  • Bump types-jsonschema from 4.24.0.20250708 to 4.25.0.20250720. (#​18703)
  • Bump types-psycopg2 from 2.9.21.20250516 to 2.9.21.20250718. (#​18706)

v1.135.2

Compare Source

Synapse 1.135.2 (2025-08-11)

This is the Synapse portion of the Matrix coordinated security release. This release includes support for room version 12 which fixes a number of security vulnerabilities, including CVE-2025-49090.

The default room version is not changed. Not all clients will support room version 12 immediately, and not all users will be using the latest version of their clients. Large, public rooms are advised to wait a few weeks before upgrading to room version 12 to allow users throughout the Matrix ecosystem to update their clients.

Note: release 1.135.1 was skipped due to issues discovered during the release process.

Two patched Synapse releases are now available:

  • 1.135.2: stable release comprised of 1.135.0 + security patches
    • Upgrade to this release if you are currently running 1.135.0 or below.
  • 1.136.0rc2: unstable release candidate comprised of 1.136.0rc1 + security patches.
    • Upgrade to this release only if you are on 1.136.0rc1.
Bugfixes
  • Fix invalidation of storage cache that was broken in 1.135.0. (#​18786)
Internal Changes
  • Add a parameter to upgrade_rooms(..) to allow auto join local users. (#​82)
  • Speed up upgrading a room with large numbers of banned users. (#​18574)

v1.135.1

Compare Source

v1.135.0

Compare Source

Synapse 1.135.0 (2025-08-01)

No significant changes since 1.135.0rc2.

Synapse 1.135.0rc2 (2025-07-30)
Bugfixes
  • Fix user failing to deactivate with MAS when /_synapse/mas is handled by a worker. (#​18716)
Internal Changes
  • Fix performance regression introduced in #​18238 by adding a cache to is_server_admin. (#​18747)
Synapse 1.135.0rc1 (2025-07-22)
Features
Bugfixes
  • Fix CPU and database spinning when retrying sending events to servers whilst at the same time purging those events. (#​18499)
  • Don't allow creation of tags with names longer than 255 bytes, as per the spec. (#​18660)
  • Fix sliding_sync_connections-related errors when porting from SQLite to Postgres. (#​18677)
  • Fix the MAS integration not working when Synapse is started with --daemonize or using synctl. (#​18691)
Improved Documentation
  • Document that some config options for the user directory are in violation of the Matrix spec. (#​18548)
  • Update rc_delayed_event_mgmt docs to the actual nesting level. Contributed by @​HarHarLinks. (#​18692)
Internal Changes
  • Add a dedicated internal API for Matrix Authentication Service to Synapse communication. (#​18520)
  • Allow user registrations to be done on workers. (#​18552)
  • Remove unnecessary HTTP replication calls. (#​18564)
  • Refactor Measure block metrics to be homeserver-scoped. (#​18601)
  • Refactor cache metrics to be homeserver-scoped. (#​18604)
  • Unbreak "Latest dependencies" workflow by using the --without dev poetry option instead of removed --no-dev. (#​18617)
  • Update URL Preview code to work with lxml 6.0.0+. (#​18622)
  • Use markdown-it-py instead of commonmark in the release script. (#​18637)
  • Fix typing errors with upgraded mypy version. (#​18653)
  • Add doc comment explaining that config files are shallowly merged. (#​18664)
  • Minor speed up of insertion into stream_positions table. (#​18672)
  • Remove unused allow_no_prev_events option when creating an event. (#​18676)
  • Clean up MetricsResource and Prometheus hacks. (#​18687)
  • Fix dirty Cargo.lock changes appearing after install (base64). (#​18689)
  • Prevent dirty Cargo.lock changes from install. (#​18693)
  • Correct spelling of 'Admin token used' log line. (#​18697)
  • Reduce log spam when client stops downloading media while it is being streamed to them. (#​18699)
Updates to locked dependencies
  • Bump authlib from 1.6.0 to 1.6.1. (#​18704)
  • Bump base64 from 0.21.7 to 0.22.1. (#​18666)
  • Bump jsonschema from 4.24.0 to 4.25.0. (#​18707)
  • Bump lxml from 5.4.0 to 6.0.0. (#​18631)
  • Bump mypy from 1.13.0 to 1.16.1. (#​18653)
  • Bump once_cell from 1.19.0 to 1.21.3. (#​18710)
  • Bump phonenumbers from 9.0.8 to 9.0.9. (#​18681)
  • Bump ruff from 0.12.2 to 0.12.5. (#​18683, #​18705)
  • Bump serde_json from 1.0.140 to 1.0.141. (#​18709)
  • Bump sigstore/cosign-installer from 3.9.1 to 3.9.2. (#​18708)
  • Bump types-jsonschema from 4.24.0.20250528 to 4.24.0.20250708. (#​18682)

v1.134.0

Compare Source

Synapse 1.134.0 (2025-07-15)

No significant changes since 1.134.0rc1.

Synapse 1.134.0rc1 (2025-07-09)
Features
  • Support for MSC4235: via query param for hierarchy endpoint. Contributed by Krishan (@​kfiven). (#​18070)
  • Add forget_forced_upon_leave capability as per MSC4267. (#​18196)
  • Add federated_user_may_invite spam checker callback which receives the entire invite event. Contributed by @​tulir @​ Beeper. (#​18241)
Bugfixes
  • Fix KeyError on background updates when using split main/state databases. (#​18509)
  • Improve performance of device deletion by adding missing index. (#​18582)
  • Fix avatar_url and displayname being sent on federation profile queries when they are not set. (#​18593)
  • Respond with 401 & M_USER_LOCKED when a locked user calls POST /login, as per the spec. (#​18594)
  • Ensure policy servers are not asked to scan policy server change events, allowing rooms to disable the use of a policy server while the policy server is down. (#​18605)
Improved Documentation
  • Fix documentation of the Delete Room Admin API's status field. (#​18519)
Deprecations and Removals
  • Stop adding the "origin" field to newly-created events (PDUs). (#​18418)
Internal Changes
  • Replace PyICU crate with equivalent icu_segmenter Rust crate. (#​18553, #​18646)
  • Improve docstring on simple_upsert_many. (#​18573)
  • Raise poetry-core version cap to 2.1.3. (#​18575)
  • Raise setuptools_rust version cap to 1.11.1. (#​18576)
  • Better handling of ratelimited requests. (#​18595, #​18600)
  • Update to Rust 1.87.0 in CI, and bump the pinned commit of the dtolnay/rust-toolchain GitHub Action to b3b07ba8b418998c39fb20f53e8b695cdcc8de1b. (#​18596)
  • Speed up bulk device deletion. (#​18602)
  • Speed up the building of arm-based wheels in CI. (#​18618)
  • Speed up the building of Docker images in CI. (#​18620)
  • Add .zed/ directory to .gitignore. (#​18623)
  • Log the room ID we're purging state for. (#​18625)
Updates to locked dependencies
  • Bump Swatinem/rust-cache from 2.7.8 to 2.8.0. (#​18612)
  • Bump attrs from 24.2.0 to 25.3.0. (#​18649)
  • Bump authlib from 1.5.2 to 1.6.0. (#​18642)
  • Bump base64 from 0.21.7 to 0.22.1. (#​18589)
  • Bump base64 from 0.21.7 to 0.22.1. (#​18629)
  • Bump docker/build-push-action from 6.17.0 to 6.18.0. (#​18497)
  • Bump docker/setup-buildx-action from 3.10.0 to 3.11.1. (#​18587)
  • Bump hiredis from 3.1.0 to 3.2.1. (#​18638)
  • Bump ijson from 3.3.0 to 3.4.0. (#​18650)
  • Bump jsonschema from 4.23.0 to 4.24.0. (#​18630)
  • Bump msgpack from 1.1.0 to 1.1.1. (#​18651)
  • Bump mypy-zope from 1.0.11 to 1.0.12. (#​18640)
  • Bump phonenumbers from 9.0.2 to 9.0.8. (#​18652)
  • Bump pillow from 11.2.1 to 11.3.0. (#​18624)
  • Bump prometheus-client from 0.21.0 to 0.22.1. (#​18609)
  • Bump pyasn1-modules from 0.4.1 to 0.4.2. (#​18495)
  • Bump pydantic from 2.11.4 to 2.11.7. (#​18639)
  • Bump reqwest from 0.12.15 to 0.12.20. (#​18590)
  • Bump reqwest from 0.12.20 to 0.12.22. (#​18627)
  • Bump ruff from 0.11.11 to 0.12.1. (#​18645)
  • Bump ruff from 0.12.1 to 0.12.2. (#​18657)
  • Bump sentry-sdk from 2.22.0 to 2.32.0. (#​18633)
  • Bump setuptools-rust from 1.10.2 to 1.11.1. (#​18655)
  • Bump sigstore/cosign-installer from 3.8.2 to 3.9.0. (#​18588)
  • Bump sigstore/cosign-installer from 3.9.0 to 3.9.1. (#​18608)
  • Bump stefanzweifel/git-auto-commit-action from 5.2.0 to 6.0.1. (#​18607)
  • Bump tokio from 1.45.1 to 1.46.0. (#​18628)
  • Bump tokio from 1.46.0 to 1.46.1. (#​18667)
  • Bump treq from 24.9.1 to 25.5.0. (#​18610)
  • Bump types-bleach from 6.2.0.20241123 to 6.2.0.20250514. (#​18634)
  • Bump types-jsonschema from 4.23.0.20250516 to 4.24.0.20250528. (#​18611)
  • Bump types-opentracing from 2.4.10.6 to 2.4.10.20250622. (#​18586)
  • Bump types-psycopg2 from 2.9.21.20250318 to 2.9.21.20250516. (#​18658)
  • Bump types-pyyaml from 6.0.12.20241230 to 6.0.12.20250516. (#​18643)
  • Bump types-setuptools from 75.2.0.20241019 to 80.9.0.20250529. (#​18644)
  • Bump typing-extensions from 4.12.2 to 4.14.0. (#​18654)
  • Bump typing-extensions from 4.14.0 to 4.14.1. (#​18668)
  • Bump urllib3 from 2.2.2 to 2.5.0. (#​18572)

v1.133.0

Compare Source

Synapse 1.133.0 (2025-07-01)

Pre-built wheels are now built using the manylinux_2_28 base, which is expected to be compatible with distros using glibc 2.28 or later, including:

  • Debian 10+
  • Ubuntu 18.10+
  • Fedora 29+
  • CentOS/RHEL 8+

Previously, wheels were built using the manylinux2014 base, which was expected to be compatible with distros using glibc 2.17 or later.

Bugfixes
  • Bump cibuildwheel to 3.0.0 to fix the manylinux wheel builds. (#​18615)
Synapse 1.133.0rc1 (2025-06-24)
Features
Bugfixes
  • Fix an issue where, during state resolution for v11 rooms, Synapse would incorrectly calculate the power level of the creator when there was no power levels event in the room. (#​18534, #​18547)
  • Fix long-standing bug where sliding sync did not honour the room_id_to_include config option. (#​18535)
  • Fix an issue where "Lock timeout is getting excessive" warnings would be logged even when the lock timeout was <10 minutes. (#​18543)
  • Fix an issue where Synapse could calculate the wrong power level for the creator of the room if there was no power levels event. (#​18545)
Improved Documentation
  • Generate config documentation from JSON Schema file. (#​18528)
  • Fix typo in user type documentation. (#​18568)
Internal Changes
Updates to locked dependencies
  • Bump actions/setup-python from 5.5.0 to 5.6.0. (#​18555)
  • Bump base64 from 0.21.7 to 0.22.1. (#​18559)
  • Bump dawidd6/action-download-artifact from 9 to 11. (#​18556)
  • Bump headers from 0.4.0 to 0.4.1. (#​18529)
  • Bump requests from 2.32.2 to 2.32.4. (#​18533)
  • Bump types-requests from 2.32.0.20250328 to 2.32.4.20250611. (#​18558)

v1.132.0

Compare Source

Synapse 1.132.0 (2025-06-17)
Improved Documentation
  • Improvements to generate config documentation from JSON Schema file. (#​18522)
Synapse 1.132.0rc1 (2025-06-10)
Features
  • Add support for MSC4155 Invite Filtering. (#​18288)
  • Add experimental user_may_send_state_event module API callback. (#​18455)
  • Add experimental get_media_config_for_user and is_user_allowed_to_upload_media_of_size module API callbacks that allow overriding of media repository maximum upload size. (#​18457)
  • Add experimental get_ratelimit_override_for_user module API callback that allows overriding of per-user ratelimits. (#​18458)
  • Pass room_config argument to user_may_create_room spam checker module callback. (#​18486)
  • Support configuration of default and extra user types. (#​18456)
  • Successful requests to /_matrix/app/v1/ping will now force Synapse to reattempt delivering transactions to appservices. (#​18521)
  • Support the import of the RatelimitOverride type from synapse.module_api in modules and rename messages_per_second to per_second. (#​18513)
Bugfixes
  • Remove destinations from sending if not whitelisted. (#​18484)
  • Fixed room summary API incorrectly returning that a room is private in the room summary response when the join rule is omitted by the remote server. Contributed by @​nexy7574. (#​18493)
  • Prevent users from adding themselves to their own user ignore list. (#​18508)
Improved Documentation
  • Generate config documentation from JSON Schema file. (#​17892)
  • Mention CAP_NET_BIND_SERVICE as an alternative to running Synapse as root in order to bind to a privileged port. (#​18408)
  • Surface hidden Admin API documentation regarding fetching of scheduled tasks. (#​18516)
  • Mark the new module APIs in this release as experimental. (#​18536)
Internal Changes
  • Mark dehydrated devices in the List All User Devices Admin API. (#​18252)
  • Reduce disk wastage by cleaning up received_transactions older than 1 day, rather than 30 days. (#​18310)
  • Distinguish all vs local events being persisted in the "Event Send Time Quantiles" graph (Grafana). (#​18510)

v1.131.0

Compare Source

Synapse 1.131.0 (2025-06-03)

No significant changes since 1.131.0rc1.

Synapse 1.131.0rc1 (2025-05-28)
Features
Bugfixes
  • Prevent race-condition in _maybe_retry_device_resync entrance. (#​18391)
  • Fix the tests.handlers.test_worker_lock.WorkerLockTestCase.test_lock_contention test which could spuriously time out on RISC-V architectures due to performance differences. (#​18430)
  • Fix admin redaction endpoint not redacting encrypted messages. (#​18434)
Improved Documentation
  • Update room_list_publication_rules docs to consider defaults that changed in v1.126.0. Contributed by @​HarHarLinks. (#​18286)
  • Add advice for upgrading between major PostgreSQL versions to the database documentation. (#​18445)
Internal Changes
  • Fix a memory leak in _NotifierUserStream. (#​18380)
  • Fix a couple type annotations in the RootConfig/Config. (#​18409)
  • Explicitly enable PyPy builds in cibuildwheels config to avoid it being disabled on a future upgrade to cibuildwheel v3. (#​18417)
  • Update the PR review template to remove an erroneous line break from the final bullet point. (#​18419)
  • Explain why we flush_buffer() for Python print(...) output. (#​18420)
  • Add lint to ensure we don't add a CREATE/DROP INDEX in a schema delta. (#​18440)
  • Allow checking only for the existence of a field in an SSO provider's response, rather than requiring the value(s) to check. (#​18454)
  • Add unit tests for homeserver usage statistics. (#​18463)
  • Don't move invited users to new room when shutting down room. (#​18471)
Updates to locked dependencies
  • Bump actions/setup-python from 5.5.0 to 5.6.0. (#​18398)
  • Bump authlib from 1.5.1 to 1.5.2. (#​18452)
  • Bump docker/build-push-action from 6.15.0 to 6.17.0. (#​18397, #​18449)
  • Bump lxml from 5.3.0 to 5.4.0. (#​18480)
  • Bump mypy-zope from 1.0.9 to 1.0.11. (#​18428)
  • Bump pyo3 from 0.23.5 to 0.24.2. (#​18460)
  • Bump pyo3-log from 0.12.3 to 0.12.4. (#​18453)
  • Bump pyopenssl from 25.0.0 to 25.1.0. (#​18450)
  • Bump ruff from 0.7.3 to 0.11.11. (#​18451, #​18482)
  • Bump tornado from 6.4.2 to 6.5.0. (#​18459)
  • Bump setuptools from 72.1.0 to 78.1.1. (#​18461)
  • Bump types-jsonschema from 4.23.0.20241208 to 4.23.0.20250516. (#​18481)
  • Bump types-requests from 2.32.0.20241016 to 2.32.0.20250328. (#​18427)

v1.130.0

Compare Source

Synapse 1.130.0 (2025-05-20)
Bugfixes
  • Fix startup being blocked on creating a new index that was introduced in v1.130.0rc1. (#​18439)
  • Fix the ordering of local messages in rooms that were affected by GHSA-v56r-hwv5-mxg6. (#​18447)
Synapse 1.130.0rc1 (2025-05-13)
Features
  • Add an Admin API endpoint GET /_synapse/admin/v1/scheduled_tasks to fetch scheduled tasks. (#​18214)
  • Add config option user_directory.exclude_remote_users which, when enabled, excludes remote users from user directory search results. (#​18300)
  • Add support for handling GET /devices/ on workers. (#​18355)
Bugfixes
  • Fix a longstanding bug where Synapse would immediately retry a failing push endpoint when a new event is received, ignoring any backoff timers. (#​18363)
  • Pass leave from remote invite rejection down Sliding Sync. (#​18375)
Updates to the Docker image
  • In configure_workers_and_start.py, use the same absolute path of Python in the interpreter shebang, and invoke child Python processes with sys.executable. (#​18291)
  • Optimize the build of the workers image. (#​18292)
  • In start_for_complement.sh, replace some external program calls with shell builtins. (#​18293)
  • When generating container scripts from templates, don't add a leading newline so that their shebangs may be handled correctly. (#​18295)
Improved Documentation
  • Improve formatting of the README file. (#​18218)
  • Add documentation for configuring Pocket ID as an OIDC provider. (#​18237)
  • Fix typo in docs about the push config option. Contributed by @​HarHarLinks. (#​18320)
  • Add /_matrix/federation/v1/version to list of federation endpoints that can be handled by workers. (#​18377)
  • Add an Admin API endpoint GET /_synapse/admin/v1/scheduled_tasks to fetch scheduled tasks. (#​18384)
Internal Changes
  • Return specific error code when adding an email address / phone number to account is not supported (MSC4178). (#​17578)
  • Stop auto-provisionning missing users & devices when delegating auth to Matrix Authentication Service. Requires MAS 0.13.0 or later. (#​18181)
  • Apply file hashing and existing quarantines to media downloaded for URL previews. (#​18297)
  • Allow a few admin APIs used by matrix-authentication-service to run on workers. (#​18313)
  • Apply should_drop_federated_event to federation invites. (#​18330)
  • Allow /rooms/ admin API to be run on workers. (#​18360)
  • Minor performance improvements to the notifier. (#​18367)
  • Slight performance increase when using the ratelimiter. (#​18369)
  • Don't validate the at_hash (access token hash) field in OIDC ID Tokens if we don't end up actually using the OIDC Access Token. (#​18374, #​18385)
  • Fixed test failures when using authlib 1.5.2. (#​18390)
  • Refactor MSC4186 Simplified Sliding Sync room list tests to cover both new and fallback logic paths. (#​18399)
Updates to locked dependencies
  • Bump actions/add-to-project from 280af8a to 5b1a254. (#​18365)
  • Bump actions/download-artifact from 4.2.1 to 4.3.0. (#​18364)
  • Bump actions/setup-go from 5.4.0 to 5.5.0. (#​18426)
  • Bump anyhow from 1.0.97 to 1.0.98. (#​18336)
  • Bump packaging from 24.2 to 25.0. (#​18393)
  • Bump pillow from 11.1.0 to 11.2.1. (#​18429)
  • Bump pydantic from 2.10.3 to 2.11.4. (#​18394)
  • Bump pyo3-log from 0.12.2 to 0.12.3. (#​18317)
  • Bump pyopenssl from 24.3.0 to 25.0.0. (#​18315)
  • Bump sha2 from 0.10.8 to 0.10.9. (#​18395)
  • Bump sigstore/cosign-installer from 3.8.1 to 3.8.2. (#​18366)
  • Bump softprops/action-gh-release from 1 to 2. (#​18264)
  • Bump stefanzweifel/git-auto-commit-action from 5.1.0 to 5.2.0. (#​18354)
  • Bump txredisapi from 1.4.10 to 1.4.11. (#​18392)
  • Bump types-jsonschema from 4.23.0.20240813 to 4.23.0.20241208. (#​18305)
  • Bump types-psycopg2 from 2.9.21.20250121 to 2.9.21.20250318. (#​18316)

v1.129.0

Compare Source

Synapse 1.129.0 (2025-05-06)

No significant changes since 1.129.0rc2.

Synapse 1.129.0rc2 (2025-04-30)

Synapse 1.129.0rc1 was never formally released due to regressions discovered during the release process. 1.129.0rc2 fixes those regressions by reverting the affected PRs.

Internal Changes
  • Revert the slow background update introduced by #​18068 in v1.128.0. (#​18372)
  • Revert "Add total_event_count, total_message_count, and total_e2ee_event_count fields to the homeserver usage statistics.", added in v1.129.0rc1. (#​18373)
Synapse 1.129.0rc1 (2025-04-15)
Features
  • Add passthrough_authorization_parameters in OIDC configuration to allow passing parameters to the authorization grant URL. (#​18232)
  • Add total_event_count, total_message_count, and total_e2ee_event_count fields to the homeserver usage statistics. (#​18260) This was reverted in 1.129.0rc2.
Bugfixes
  • Fix force_tracing_for_users config when using delegated auth. (#​18334)
  • Fix the token introspection cache logging access tokens when MAS integration is in use. (#​18335)
  • Stop caching introspection failures when delegating auth to MAS. (#​18339)
  • Fix ExternalIDReuse exception after migrating to MAS on workers with a high traffic. (#​18342)
  • Fix minor performance regression caused by tracking of room participation. Regressed in v1.128.0. (#​18345)
Updates to the Docker image
  • Optimize the build of the complement-synapse image. (#​18294)
Internal Changes
  • Disable statement timeout during room purge. (#​18133)
  • Add cache to storage functions used to auth requests when using delegated auth. (#​18337)

v1.128.0

Compare Source

Synapse 1.128.0 (2025-04-08)

No significant changes since 1.128.0rc1.

Synapse 1.128.0rc1 (2025-04-01)
Features
  • Add an access token introspection cache to make Matrix Authentication Service integration (MSC3861) more efficient. (#​18231)
  • Add background job to clear unreferenced state groups. (#​18254)
  • Hashes of media files are now tracked by Synapse. Media quarantines will now apply to all files with the same hash. (#​18277, #​18302, #​18296)
Bugfixes
  • Add index to sliding sync (MSC4186) membership snapshot table, to fix a performance issue. (#​18074)
Updates to the Docker image
  • Specify the architecture of installed packages via an APT config option, which is more reliable than appending package names with :{arch}. (#​18271)
  • Always specify base image debian versions with a build argument. (#​18272)
  • Allow passing arguments to start_for_complement.sh (to be sent to configure_workers_and_start.py). (#​18273)
  • Make some improvements to the prefix-log script in the workers image. (#​18274)
  • Use uv pip to install supervisor in the worker image. (#​18275)
  • Avoid needing to download & use rsync in a build layer. (#​18287)
Improved Documentation
  • Fix how to obtain access token and change naming from riot to element (#​18225)
  • Correct a small typo in the SSO mapping providers documentation. (#​18276)
  • Add docs for how to clear out the Poetry wheel cache. (#​18283)
Internal Changes
  • Add a column participant to room_memberships table. (#​18068)
  • Update Poetry to 2.1.1, including updating the lock file version. (#​18251)
  • Pin GitHub Actions dependencies by commit hash. (#​18255)
  • Add DB delta to remove the old state group deletion job. (#​18284)
Updates to locked dependencies
  • Bump actions/add-to-project from f5473ac to 280af8a. (#​18303)
  • Bump actions/cache from 4.2.2 to 4.2.3. (#​18266)
  • Bump actions/download-artifact from 4.2.0 to 4.2.1. (#​18268)
  • Bump actions/setup-python from 5.4.0 to 5.5.0. (#​18298)
  • Bump actions/upload-artifact from 4.6.1 to 4.6.2. (#​18304)
  • Bump authlib from 1.4.1 to 1.5.1. (#​18306)
  • Bump dawidd6/action-download-artifact from 8 to 9. (#​18204)
  • Bump jinja2 from 3.1.5 to 3.1.6. (#​18223)
  • Bump log from 0.4.26 to 0.4.27. (#​18267)
  • Bump phonenumbers from 8.13.50 to 9.0.2. (#​18299)
  • Bump pygithub from 2.5.0 to 2.6.1. (#​18243)
  • Bump pyo3-log from 0.12.1 to 0.12.2. (#​18269)

v1.127.1

Compare Source

Synapse 1.127.1 (2025-03-26)
Security

v1.127.0

Compare Source

Synapse 1.127.0 (2025-03-25)

No significant changes since 1.127.0rc1.

Synapse 1.127.0rc1 (2025-03-18)
Features
  • Update MSC4140 implementation to no longer cancel a user's own delayed state events with an event type & state key that match a more recent state event sent by that user. (#​17810)
Improved Documentation
Internal Changes
  • Remove undocumented SYNAPSE_USE_FROZEN_DICTS environment variable. (#​18123)
  • Fix detection of workflow failures in the release script. (#​18211)
  • Add caching support to media endpoints. (#​18235)
Updates to locked dependencies
  • Bump anyhow from 1.0.96 to 1.0.97. (#​18201)
  • Bump bcrypt from 4.2.1 to 4.3.0. (#​18207)
  • Bump bytes from 1.10.0 to 1.10.1. (#​18227)
  • Bump http from 1.2.0 to 1.3.1. (#​18245)
  • Bump sentry-sdk from 2.19.2 to 2.22.0. (#​18205)
  • Bump serde from 1.0.218 to 1.0.219. (#​18228)
  • Bump serde_json from 1.0.139 to 1.0.140. (#​18202)
  • Bump ulid from 1.2.0 to 1.2.1. (#​18246)

v1.126.0

Compare Source

Synapse 1.126.0 (2025-03-11)

No significant changes since 1.126.0rc3.

Synapse 1.126.0rc3 (2025-03-07)
Bugfixes
  • Revert the background job to clear unreferenced state groups (that was introduced in v1.126.0rc1), due to a suspected issue that causes increased disk usage. (#​18222)
Synapse 1.126.0rc2 (2025-03-05)

Administrators using the Debian/Ubuntu packages from packages.matrix.org, please check the relevant section in the upgrade notes as we have recently updated the expiry date on the repository's GPG signing key. The old version of the key will expire on 2025-03-15.

Internal Changes
Synapse 1.126.0rc1 (2025-03-04)

Synapse 1.126.0rc1 was not fully released due to an error in CI.

Features
  • Define ratelimit configuration for delayed event management. (#​18019)
  • Add form_secret_path config option. (#​18090)
  • Add the --no-secrets-in-config command line option. (#​18092)
  • Add background job to clear unreferenced state groups. (#​18154)
  • Add support for specifying/overriding id_token_signing_alg_values_supported for an OpenID identity provider. (#​18177)
  • Add worker_replication_secret_path config option. (#​18191)
  • Add support for specifying/overriding redirect_uri in the authorization and token requests against an OpenID identity provider. (#​18197)
Bugfixes
  • Make sure we advertise registration as disabled when MSC3861 is enabled. (#​17661)
  • Prevent suspended users from sending encrypted messages. (#​18157)
  • Cleanup deleted state group references. (#​18165)
  • Fix MSC4108 QR-code login not working with some reverse-proxy setups. (#​18178)
  • Support device IDs that can't be represented in a scope when delegating auth to Matrix Authentication Service 0.15.0+. (#​18174)
Updates to the Docker image
  • Speed up the building of the Docker image. (#​18038)
Improved Documentation
  • Move incorrectly placed version indicator in User Event Redaction Admin API docs. (#​18152)
  • Document suspension Admin API. (#​18162)
Deprecations and Removals
  • Disable room list publication by default. (#​18175)
Updates to locked dependencies
  • Bump anyhow from 1.0.95 to 1.0.96. (#​18187)
  • Bump authlib from 1.4.0 to 1.4.1. (#​18190)
  • Bump click from 8.1.7 to 8.1.8. (#​18189)
  • Bump log from 0.4.25 to 0.4.26. (#​18184)
  • Bump pyo3-log from 0.12.0 to 0.12.1. (#​18046)
  • Bump serde from 1.0.217 to 1.0.218. (#​18183)
  • Bump serde_json from 1.0.138 to 1.0.139. (#​18186)
  • Bump sigstore/cosign-installer from 3.8.0 to 3.8.1. (#​18185)
  • Bump types-psycopg2 from 2.9.21.20241019 to 2.9.21.20250121. (#​18188)

v1.125.0

Compare Source

Synapse 1.125.0 (2025-02-25)

No significant changes since 1.125.0rc1.

Synapse 1.125.0rc1 (2025-02-18)
Features
  • Add functionality to be able to use multiple values in SSO feature attribute_requirements. (#​17949)
  • Add experimental config options admin_token_path and client_secret_path for MSC3861. (#​18004)
  • Add get_current_time_msec() method to the module API for sound time comparisons with Synapse. (#​18144)
Bugfixes
  • Update the response when a client attempts to add an invalid email address to the user's account from a 500, to a 400 with error text. (#​18125)
  • Fix user directory search when using a legacy module with a check_username_for_spam callback. Broke in v1.122.0. (#​18135)
Updates to the Docker image
  • Add SYNAPSE_HTTP_PROXY/SYNAPSE_HTTPS_PROXY/SYNAPSE_NO_PROXY environment variables to pass through specifically to the Synapse process (instead of needing to apply http_proxy/https_proxy/no_proxy globally). (#​18158)
Improved Documentation
  • Add Oracle Linux 8 and 9 installation instructions. (#​17436)
  • Document missing server config options (daemonize, print_pidfile, user_agent_suffix, use_frozen_dicts, manhole). (#​18122)
  • Document consequences of replacing secrets. (#​18138)
  • Make burst_count field an integer in rc_presence config documentation example. (#​18159)
Internal Changes
  • Overload DatabasePool.simple_select_one_txn to return non-None when the allow_none parameter is False. (#​17616)
  • Python 3.8 EOL: compile native extensions with the 3.9 ABI and use typing hints from the standard library. (#​17967)
  • Add log message when worker lock timeouts get large. (#​18124)
  • Make it explicit that you can buy an AGPL-alternative commercial license from Element. (#​18134)
  • Fix the 'Fix linting' GitHub Actions workflow. (#​18136)
  • Do not log at the exception-level when clients provide empty since token to /sync API. (#​18139)
  • Reduce database load of user search when using large search terms. (#​18172)
Updates to locked dependencies
  • Bump bcrypt from 4.2.0 to 4.2.1. (#​18127)
  • Bump bytes from 1.9.0 to 1.10.0. (#​18149)
  • Bump gitpython from 3.1.43 to 3.1.44. (#​18128)
  • Bump hiredis from 3.0.0 to 3.1.0. (#​18169)
  • Bump serde_json from 1.0.137 to 1.0.138. (#​18129)
  • Bump service-identity from 24.1.0 to 24.2.0. (#​18171)
  • Bump sigstore/cosign-installer from 3.7.0 to 3.8.0. (#​18147)
  • Bump twine from 6.0.1 to 6.1.0. (#​18170)
  • Bump types-pyyaml from 6.0.12.20240917 to 6.0.12.20241230. (#​18097)
  • Bump ulid from 1.1.4 to 1.2.0. (#​18148)

v1.124.0

Compare Source

Synapse 1.124.0 (2025-02-11)

No significant changes since 1.124.0rc3.

Synapse 1.124.0rc3 (2025-02-07)
Bugfixes
  • Fix regression in performance of sending events due to superfluous reads and locks. Introduced in v1.124.0rc1. (#​18141)
Synapse 1.124.0rc2 (2025-02-05)
Bugfixes
  • Fix regression where persisting events in some rooms could fail after a previous unclean shutdown. Introduced in v1.124.0rc1. (#​18137)
Synapse 1.124.0rc1 (2025-02-04)
Bugfixes
  • Add rate limit rc_presence.per_user. This prevents load from excessive presence updates sent by clients via sync api. Also rate limit /_matrix/client/v3/presence as per the spec. Contributed by @​rda0. (#​18000)
  • Deactivated users will no longer automatically accept an invite when auto_accept_invites is enabled. (#​18073)
  • Fix join being denied after being invited over federation. Also fixes other out-of-band membership transitions. (#​18075)
  • Updates contributed docker-compose.yml file to PostgreSQL v15, as v12 is no longer supported by Synapse.
    Contributed by @​maxkratz. (#​18089)
  • Fix rare edge case where state groups could be deleted while we are persisting new events that reference them. (#​18107, #​18130, #​18131)
  • Raise an error if someone is using an incorrect suffix in a config duration string. (#​18112)
  • Fix a bug where the Delete Room Admin API would fail if the block parameter was set to true and a worker other than the main process was configured to handle background tasks. (#​18119)
Internal Changes
  • Increase the length of the generated nonce parameter when perfoming OIDC logins to comply with the TI-Messenger spec. (#​18109)
Updates to locked dependencies
  • Bump dawidd6/action-download-artifact from 7 to 8. (#​18108)
  • Bump log from 0.4.22 to 0.4.25. (#​18098)
  • Bump python-multipart from 0.0.18 to 0.0.20. (#​18096)
  • Bump serde_json from 1.0.135 to 1.0.137. (#​18099)
  • Bump types-bleach from 6.1.0.20240331 to 6.2.0.20241123. (#​18082)

v1.123.0

Compare Source

Synapse 1.123.0 (2025-01-28)

No significant changes since 1.123.0rc1.

Synapse 1.123.0rc1 (2025-01-21)
Features
Bugfixes
  • Fix membership caches not updating in state reset scenarios. (#​17732)
  • Fix rare race where on upgrade to v1.122.0 a long running database upgrade could lock out new events from being received or sent. (#​18091)
Improved Documentation
  • Document tls option for a worker instance in instance_map. (#​18064)
Deprecations and Removals
Internal Changes
  • Increase invite rate limits (rc_invites.per_issuer) for Complement. (#​18072)
Updates to locked dependencies
  • Bump jinja2 from 3.1.4 to 3.1.5. (#​18067)
  • Bump mypy from 1.12.1 to 1.13.0. (#​18083)
  • Bump pillow from 11.0.0 to 11.1.0. (#​18084)
  • Bump pyo3 from 0.23.3 to 0.23.4. (#​18079)
  • Bump pyopenssl from 24.2.1 to 24.3.0. (#​18062)
  • Bump serde_json from 1.0.134 to 1.0.135. (#​18081)
  • Bump ulid from 1.1.3 to 1.1.4. (#​18080)

v1.122.0

Compare Source

Synapse 1.122.0 (2025-01-14)

Please note that this version of Synapse drops support for PostgreSQL 11 and 12. The minimum version of PostgreSQL supported is now version 13.

No significant changes since 1.122.0rc1.

Synapse 1.122.0rc1 (2025-01-07)
Deprecations and Removals
Features
  • Added the email.tlsname config option. This allows specifying the domain name used to validate the SMTP server's TLS certificate separately from the email.smtp_host to connect to. (#​17849)
  • Module developers will have access to the user ID of the requester when adding check_username_for_spam callbacks to spam_checker_module_callbacks. Contributed by Wilson@Pangea.chat. (#​17916)
  • Add endpoints to the Admin API to fetch the number of invites the provided user has sent after a given timestamp,
    fetch the number of rooms the provided user has joined after a given timestamp, and get report IDs of event
    reports against a provided user (i.e. where the user was the sender of the reported event). (#​17948)
  • Support stable account suspension from MSC3823. (#​17964)
  • Add macaroon_secret_key_path config option. (#​17983)
Bugfixes
  • Fix bug when rejecting withdrew invite with a third_party_rules module, where the invite would be stuck for the client. (#​17930)
  • Properly purge state groups tables when purging a room with the Admin API. (#​18024)
  • Fix a bug preventing the admin redaction endpoint from working on messages from remote users. (#​18029, #​18043)
Improved Documentation
  • Update synapse.app.generic_worker documentation to only recommend GET requests for stream writer routes by default, unless the worker is also configured as a stream writer. Contributed by @​evoL. (#​17954)
  • Add documentation for the previously-undocumented last_seen_ts query parameter to the query user Admin API. (#​17976)
  • Improve documentation for the TaskScheduler class. (#​17992)
  • Fix example in reverse proxy docs to include server port. (#​17994)
  • Update Alpine Linux Synapse Package Maintainer within the installation instructions. (#​17846)
Internal Changes
  • Add RoomID & EventID rust types. (#​17996)
  • Fix various type errors across the codebase. (#​17998)
  • Disable DB statement timeout when doing a room purge since it can be quite long. (#​18017)
  • Remove some remaining uses of twisted.internet.defer.returnValue. Contributed by Colin Watson. (#​18020)
  • Refactor get_profile to no longer include fields with a value of None. (#​18063)
Updates to locked dependencies
  • Bump mypy from 1.11.2 to 1.12.1. (#​17999)
  • Bump mypy-zope from 1.0.8 to 1.0.9. (#​18047)
  • Bump pillow from 10.4.0 to 11.0.0. (#​18015)
  • Bump pydantic from 2.9.2 to 2.10.3. (#​18014)
  • Bump pyicu from 2.13.1 to 2.14. (#​18060)
  • Bump pyo3 from 0.23.2 to 0.23.3. (#​18001)
  • Bump python-multipart from 0.0.16 to 0.0.18. (#​17985)
  • Bump sentry-sdk from 2.17.0 to 2.19.2. (#​18061)
  • Bump serde from 1.0.215 to 1.0.217. (#​18031, #​18059)
  • Bump serde_json from 1.0.133 to 1.0.134. (#​18044)
  • Bump twine from 5.1.1 to 6.0.1. (#​18049)

Changelogs for older versions can be found here.

v1.121.1

Compare Source

Synapse 1.121.1 (2024-12-11)

This release contains a fix for our docker build CI. It is functionally identical to 1.121.0, whose changelog is below.

Internal Changes
  • Downgrade the Ubuntu GHA runner when building docker images. (#​18026)
Synapse 1.121.0 (2024-12-11)
Internal Changes
  • Fix release process to not create duplicate releases. (#​18025)
Synapse 1.121.0rc1 (2024-12-04)
Features
  • Support for MSC4190: device management for Application Services. (#​17705)
  • Update MSC4186 Sliding Sync to include invite, ban, kick, targets when $LAZY-loading room members. (#​17947)
  • Use stable M_USER_LOCKED error code for locked accounts, as per Matrix 1.12. (#​17965)
  • MSC4076: Add disable_badge_count to pusher configuration. (#​17975)
Bugfixes
  • Fix long-standing bug where read receipts could get overly delayed being sent over federation. (#​17933)
Improved Documentation
  • Add OIDC example configuration for Forgejo (fork of Gitea). (#​17872)
  • Link to element-docker-demo from contrib/docker*. (#​17953)
Internal Changes
  • MSC4108: Add a Content-Type header on the PUT response to work around a faulty behavior in some caching reverse proxies. (#​17253)
  • Fix incorrect comment in new schema delta. (#​17936)
  • Raise setuptools_rust version cap to 1.10.2. (#​17944)
  • Enable encrypted appservice related experimental features in the complement docker image. (#​17945)
  • Return whether the user is suspended when querying the user account in the Admin API. (#​17952)
  • Fix new scheduled tasks jumping the queue. (#​17962)
  • Bump pyo3 and dependencies to v0.23.2. (#​17966)
  • Update setuptools-rust and fix building abi3 wheels in latest version. (#​17969)
  • Consolidate SSO redirects through /_matrix/client/v3/login/sso/redirect(/{idpId}). (#​17972)
  • Fix Docker and Complement config to be able to use public_baseurl. (#​17986)
  • Fix building wheels for MacOS which was temporarily disabled in Synapse 1.120.2. (#​17993)
  • Fix release process to not create duplicate releases. (#​17970, #​17995)
Updates to locked dependencies
  • Bump bytes from 1.8.0 to 1.9.0. (#​17982)
  • Bump pysaml2 from 7.3.1 to 7.5.0. (#​17978)
  • Bump serde_json from 1.0.132 to 1.0.133. (#​17939)
  • Bump tomli from 2.0.2 to 2.1.0. (#​17959)
  • Bump tomli from 2.1.0 to 2.2.1. (#​17979)
  • Bump tornado from 6.4.1 to 6.4.2. (#​17955)

v1.120.2

Compare Source

Synapse 1.120.2 (2024-12-03)

This version has building of wheels for macOS disabled.
It is functionally identical to 1.120.1, which contains multiple security fixes.
If you are already using 1.120.1, there is no need to upgrade to this version.

Synapse 1.120.1 (2024-12-03)

This patch release fixes multiple security vulnerabilities, some affecting all prior versions of Synapse. Server administrators are encouraged to update Synapse as soon as possible. We are not aware of these vulnerabilities being exploited in the wild.

Administrators who are unable to update Synapse may use the workarounds described in the linked GitHub Security Advisory below.

Security advisory

The following issues are fixed in 1.120.1.

Additionally, we disclose the following vulnerabilities, both have been fixed in Synapse 1.106.0:

See the advisories for more details. If you have any questions, email security at element.io.

Bug fixes
  • Fix release process to not create duplicate releases. (#​17970)

v1.120.1

Compare Source

v1.120.0

Compare Source

Synapse 1.120.0 (2024-11-26)

This release enables the enforcement of authenticated media by default, with exemptions for media that is already present in the
homeserver's media store.

Most homeservers operating in the public federation will not be impacted by this change, given that
the large homeserver matrix.org enabled this in September 2024 and therefore most clients and servers
will already have updated as a result.

Some server administrators may still wish to disable this enforcement for the time being, in the interest of compatibility with older clients
and older federated homeservers.
See the upgrade notes for more information.

Bugfixes
  • Fix a bug introduced in Synapse v1.120rc1 which would cause the newly-introduced delete_old_otks job to fail in worker-mode deployments. (#​17960)
Synapse 1.120.0rc1 (2024-11-20)
Features
  • Enforce authenticated media by default. Administrators can revert this by configuring enable_authenticated_media to false. In a future release of Synapse, this option will be removed and become always-on. (#​17889)
  • Add a one-off task to delete old One-Time Keys, to guard against us having old OTKs in the database that the client has long forgotten about. (#​17934)
Improved Documentation
  • Clarify the semantics of the enable_authenticated_media configuration option. (#​17913)
  • Add documentation about backing up Synapse. (#​17931)
Deprecations and Removals
Internal Changes
  • Addressed some typos in docs and returned error message for unknown MXC ID. (#​17865)
  • Unpin the upload release GHA action. (#​17923)
  • Bump macOS version used to build wheels during release, as current version used is end-of-life. (#​17924)
  • Move server event filtering logic to Rust. (#​17928)
  • Support new package name of PyPI package python-multipart 0.0.13 so that distro packagers do not need to work around name conflict with PyPI package multipart. (#​17932)
  • Speed up slow initial sliding syncs on large servers. (#​17946)
Updates to locked dependencies
  • Bump anyhow from 1.0.92 to 1.0.93. (#​17920)
  • Bump bleach from 6.1.0 to 6.2.0. (#​17918)
  • Bump immutabledict from 4.2.0 to 4.2.1. (#​17941)
  • Bump packaging from 24.1 to 24.2. (#​17940)
  • Bump phonenumbers from 8.13.49 to 8.13.50. (#​17942)
  • Bump pygithub from 2.4.0 to 2.5.0. (#​17917)
  • Bump ruff from 0.7.2 to 0.7.3. (#​17919)
  • Bump serde from 1.0.214 to 1.0.215. (#​17938)

v1.119.0

Compare Source

Synapse 1.119.0 (2024-11-13)

No significant changes since 1.119.0rc2.

Python 3.8 support dropped

Python 3.8 is end-of-life and is no longer supported by Synapse. The minimum supported Python version is now 3.9.

If you are running Synapse with Python 3.8, please upgrade to Python 3.9 (or greater) before upgrading Synapse.

Synapse 1.119.0rc2 (2024-11-11)

Note that due to packaging issues there was no v1.119.0rc1.

Features
Bugfixes
  • Fix bug with sliding sync where $LAZY-loading room members would not return required_state membership in incremental syncs. (#​17809)
  • Check if user has membership in a room before tagging it. Contributed by Lama Alosaimi. (#​17839)
  • Fix a bug in the admin redact endpoint where the background task would not run if a worker was specified in
    the config option run_background_tasks_on. (#​17847)
  • Fix bug where some presence and typing timeouts can expire early. (#​17850)
  • Fix detection when the built Rust library was outdated when using source installations. (#​17861)
  • Fix a long-standing bug in Synapse which could cause one-time keys to be issued in the incorrect order, causing message decryption failures. (#​17903)
  • Fix experimental support for MSC4222 (Adding state_after to sync v2) where we would return the full state on incremental syncs when using lazy loaded members and there were no new events in the timeline. (#​17915)
Internal Changes
  • Remove support for python 3.8. (#​17908)
  • Add a test for downloading and thumbnailing a CMYK JPEG. (#​17786)
  • Refactor database calls to remove Generator usage. (#​17813, #​17814, #​17815, #​17816, #​17817, #​17818, #​17890)
  • Include the destination in the error of 'Destination mismatch' on federation requests. (#​17830)
  • The nix flake inside the repository no longer tracks nixpkgs/master to not catch the latest bugs from a PR merged 5 minutes ago. (#​17852)
  • Minor speed-up of sliding sync by computing extensions results in parallel. (#​17884)
  • Bump the default Python version in the Synapse Dockerfile from 3.11 -> 3.12. (#​17887)
  • Remove usage of internal header encoding API. (#​17894)
  • Use unique name for each os.arch variant when uploading Wheel artifacts. (#​17905)
  • Fix tests to run with latest Twisted. (#​17906, #​17907, #​17911)
  • Update version constraint to allow the latest poetry-core 1.9.1. (#​17902)
  • Update the portdb CI to use Python 3.13 and Postgres 17 as latest dependencies. (#​17909)
  • Add an index to current_state_delta_stream table. (#​17912)
  • Fix building and attaching release artifacts during the release process. (#​17921)
Updates to locked dependencies

v1.118.0

Compare Source

Synapse 1.118.0 (2024-10-29)

No significant changes since 1.118.0rc1.

Python 3.8 support will be dropped in the next release

Python 3.8 is now end-of-life. As per our Deprecation Policy for Platform Dependencies, Synapse will be dropping support for Python 3.8 in the next release; Synapse 1.119.0.

Synapse 1.118.x will be the final release to support Python 3.8. If you are running Synapse with Python 3.8, please upgrade before the 1.119.0 release, due in less than one month.

Python 3.13 and PostgreSQL 17 support

On the other end of the spectrum, Synapse 1.118.0 is the first release to support Python 3.13! PostgreSQL 17 is also supported as of this release.

Synapse 1.118.0rc1 (2024-10-22)
Features
  • Added the display_name_claim option to the JWT configuration. This option allows specifying the claim key that contains the user's display name in the JWT payload. (#​17708)
  • Implement MSC4210: Remove legacy mentions. Contributed by @​tulir @​ Beeper. (#​17783)
Bugfixes
  • Fix saving of PNG thumbnails, when the original image is in the CMYK color space. (#​17736)
  • Fix bug with sliding sync where the server would not return state that was added to the required_state config. (#​17785, #​17805)
  • Fix a bug in MSC4186 Sliding Sync that would cause rooms to stay forgotten and hidden even after rejoining. (#​17835)
Improved Documentation
  • Clarify when the user_may_invite and user_may_send_3pid_invite module callbacks are called. (#​17627)
  • Correct documentation to refer to the --config-path argument instead of --config-file. (#​17802)
  • Fix typo in target_cache_memory_usage docs. (#​17825)
Internal Changes
  • Slight optimization when fetching state/events for Sliding Sync. (#​17718)
  • Add Python 3.13 and Postgres 17 to the test matrix. (#​17752)
  • Test github token before running release script steps. (#​17803)
  • Build debian packages for new Ubuntu versions, and stop building for no longer supported versions. (#​17824)
  • Enable the .org.matrix.msc4028.encrypted_event push rule by default in accordance with MSC4028. Note that the corresponding experimental feature must still be switched on for this push rule to have any effect. (#​17826)
  • Fix some typing issues uncovered by upgrading mypy to 1.11.x. (#​17842)
Updates to locked dependencies
  • Bump mypy from 1.10.1 to 1.11.2. (#​17842)
  • Bump mypy-zope from 1.0.5 to 1.0.7. (#​17827)
  • Bump phonenumbers from 8.13.46 to 8.13.47. (#​17797)
  • Bump psycopg2 from 2.9.9 to 2.9.10. (#​17843)
  • Bump ruff from 0.6.8 to 0.6.9. (#​17794)
  • Bump sentry-sdk from 2.14.0 to 2.15.0. (#​17795)
  • Bump sentry-sdk from 2.15.0 to 2.16.0. (#​17829)
  • Bump sentry-sdk from 2.16.0 to 2.17.0. (#​17844)
  • Bump sigstore/cosign-installer from 3.6.0 to 3.7.0. (#​17798)
  • Bump tomli from 2.0.1 to 2.0.2. (#​17796)
  • Bump types-requests from 2.32.0.20240914 to 2.32.0.20241016. (#​17841)
  • Bump types-setuptools from 75.1.0.20240917 to 75.1.0.20241014. (#​17828)

v1.117.0

Compare Source

Synapse 1.117.0 (2024-10-15)

No significant changes since 1.117.0rc1.

Synapse 1.117.0rc1 (2024-10-08)
Features
  • Add config option redis.password_path. (#​17717)
Bugfixes
  • Fix a rare bug introduced in v1.29.0 where invalidating a user's access token from a worker could raise an error. (#​17779)
  • In the response to GET /_matrix/client/versions, set the unstable_features flag for MSC4140 to false when server configuration disables support for delayed events. (#​17780)
  • Improve input validation and room membership checks in admin redaction API. (#​17792)
Improved Documentation
  • Clarify the docstring of test_forget_when_not_left. (#​17628)
  • Add documentation note about PYTHONMALLOC for accurate jemalloc memory tracking. Contributed by @​hensg. (#​17709)
  • Remove spurious "TODO UPDATE ALL THIS" note in the Debian installation docs. (#​17749)
  • Explain how load balancing works for federation_sender_instances. (#​17776)
Internal Changes
  • Minor performance increase for large accounts using sliding sync. (#​17751)
  • Increase performance of the notifier when there are many syncing users. (#​17765, #​17766)
  • Fix performance of streams that don't change often. (#​17767)
  • Improve performance of sliding sync connections that do not ask for any rooms. (#​17768)
  • Reduce overhead of sliding sync E2EE loops. (#​17771)
  • Sliding sync minor performance speed up using new table. (#​17787)
  • Sliding sync minor performance improvement by omitting unchanged data from incremental responses. (#​17788)
  • Speed up sliding sync when there are many active subscriptions. (#​17789)
  • Add missing license headers on new source files. (#​17799)
Updates to locked dependencies
  • Bump phonenumbers from 8.13.45 to 8.13.46. (#​17773)
  • Bump python-multipart from 0.0.10 to 0.0.12. (#​17772)
  • Bump regex from 1.10.6 to 1.11.0. (#​17770)
  • Bump ruff from 0.6.7 to 0.6.8. (#​17774)

v1.116.0

Compare Source

Synapse 1.116.0 (2024-10-01)

No significant changes since 1.116.0rc2.

Synapse 1.116.0rc2 (2024-09-26)
Features
  • Add implementation of restricting who can overwrite a state event as proposed by MSC3757. (#​17513)
Synapse 1.116.0rc1 (2024-09-25)
Features
Bugfixes
  • Make sure we get up-to-date state information when using the new MSC4186 Sliding Sync tables to derive room membership. (#​17692)
  • Fix bug where room account data would not correctly be sent down MSC4186 Sliding Sync for old rooms. (#​17695)
  • Fix a bug in MSC4186 Sliding Sync which could prevent /sync from working for certain user accounts. (#​17727, #​17733)
  • Ignore invites from ignored users in Sliding Sync. (#​17729)
  • Fix bug in MSC4186 Sliding Sync where the server would incorrectly return a negative bump stamp, which caused Element X apps to stop syncing. (#​17748)
Internal Changes
  • Import pydantic objects from the _pydantic_compat module.
    This allows check_pydantic_models.py to mock those pydantic objects
    only in the synapse module, and not interfere with pydantic objects in
    external dependencies. (#​17667)
  • Use MSC4186 Sliding Sync tables as a bulk shortcut for getting the max event_stream_ordering of rooms. (#​17693)
  • Speed up MSC4186 sliding sync requests a bit where there are many room changes. (#​17696)
  • Refactor MSC4186 sliding sync filter unit tests so the sliding sync API has better test coverage. (#​17703)
  • Fetch bump_stamps more efficiently in MSC4186 Sliding Sync. (#​17723)
  • Shortcut for checking if certain background updates have completed (utilized in MSC4186 Sliding Sync). (#​17724)
  • More efficiently fetch rooms for MSC4186 Sliding Sync. (#​17725)
  • Fix _bulk_get_max_event_pos being inefficient. (#​17728)
  • Add cache to get_tags_for_room(...). (#​17730)
  • Small performance improvement in speeding up MSC4186 Sliding Sync. (#​17731)
  • Minor speed up of initial MSC4186 sliding sync requests. (#​17734)
  • Remove usage of the deprecated cgi module, deprecated in Python 3.11 and removed in Python 3.13. (#​17741)
  • Fix typing of a variable that is not Unknown anymore after updating treq. (#​17744)
Updates to locked dependencies
  • Bump anyhow from 1.0.86 to 1.0.89. (#​17685, #​17716)
  • Bump bytes from 1.7.1 to 1.7.2. (#​17743)
  • Bump cryptography from 43.0.0 to 43.0.1. (#​17689)
  • Bump idna from 3.8 to 3.10. (#​17758)
  • Bump msgpack from 1.0.8 to 1.1.0. (#​17759)
  • Bump phonenumbers from 8.13.44 to 8.13.45. (#​17762)
  • Bump prometheus-client from 0.20.0 to 0.21.0. (#​17746)
  • Bump pyasn1 from 0.6.0 to 0.6.1. (#​17714)
  • Bump pyasn1-modules from 0.4.0 to 0.4.1. (#​17747)
  • Bump pydantic from 2.8.2 to 2.9.2. (#​17756)
  • Bump python-multipart from 0.0.9 to 0.0.10. (#​17745)
  • Bump ruff from 0.6.4 to 0.6.7. (#​17715, #​17760)
  • Bump sentry-sdk from 2.13.0 to 2.14.0. (#​17712)
  • Bump serde from 1.0.209 to 1.0.210. (#​17686)
  • Bump serde_json from 1.0.127 to 1.0.128. (#​17687)
  • Bump treq from 23.11.0 to 24.9.1. (#​17744)
  • Bump types-pyyaml from 6.0.12.20240808 to 6.0.12.20240917. (#​17755)
  • Bump types-requests from 2.32.0.20240712 to 2.32.0.20240914. (#​17713)
  • Bump types-setuptools from 74.1.0.20240907 to 75.1.0.20240917. (#​17757)

v1.115.0

Compare Source

Synapse 1.115.0 (2024-09-17)

No significant changes since 1.115.0rc2.

Synapse 1.115.0rc2 (2024-09-12)
Internal Changes
  • Pre-populate room data used in experimental MSC3575 Sliding Sync /sync endpoint for quick filtering/sorting. (#​17652)
  • Speed up sliding sync by reducing amount of data pulled out of the database for large rooms. (#​17683)
Synapse 1.115.0rc1 (2024-09-10)
Features
  • Improve cross-signing upload when using MSC3861 to use a custom UIA flow stage, with web fallback support. (#​17509)
Bugfixes
  • Return 400 M_BAD_JSON upon attempting to complete various room actions with a non-local user ID and unknown room ID, rather than an internal server error. (#​17607)
  • Fix authenticated media responses using a wrong limit when following redirects over federation. (#​17626)
  • Fix bug where we returned the wrong bump_stamp for invites in sliding sync response, causing incorrect ordering of invites in the room list. (#​17674)
Improved Documentation
  • Clarify that the admin api resource is only loaded on the main process and not workers. (#​17590)
  • Fixed typo in saml2_config config example. (#​17594)
Deprecations and Removals
  • Stabilise MSC4156 by removing the msc4156_enabled config setting and defaulting it to true. (#​17650)
Internal Changes
Updates to locked dependencies
  • Bump authlib from 1.3.1 to 1.3.2. (#​17679)
  • Bump idna from 3.7 to 3.8. (#​17682)
  • Bump ruff from 0.6.2 to 0.6.4. (#​17680)
  • Bump towncrier from 24.7.1 to 24.8.0. (#​17645)
  • Bump twisted from 24.7.0rc1 to 24.7.0. (#​17647)
  • Bump types-pillow from 10.2.0.20240520 to 10.2.0.20240822. (#​17644)
  • Bump types-psycopg2 from 2.9.21.20240417 to 2.9.21.20240819. (#​17646)
  • Bump types-setuptools from 71.1.0.20240818 to 74.1.0.20240907. (#​17681)

v1.114.0

Compare Source

Synapse 1.114.0 (2024-09-02)

This release enables support for MSC4186 — Simplified Sliding Sync. This allows using the upcoming releases of the Element X mobile apps without having to run a Sliding Sync Proxy.

Features
Synapse 1.114.0rc3 (2024-08-30)
Bugfixes
  • Fix regression in v1.114.0rc2 that caused workers to fail to start. (#​17626)
Synapse 1.114.0rc2 (2024-08-30)
Features
  • Improve cross-signing upload when using MSC3861 to use a custom UIA flow stage, with web fallback support. (#​17509)
  • Make hash_password script accept password input from stdin. (#​17608)
Bugfixes
  • Fix hierarchy returning 403 when room is accessible through federation. Contributed by Krishan (@​kfiven). (#​17194)
  • Fix content-length on federation /thumbnail responses. (#​17532)
  • Fix authenticated media responses using a wrong limit when following redirects over federation. (#​17543)
Internal Changes
  • MSC3861: load the issuer and account management URLs from OIDC discovery. (#​17407)
  • Refactor sliding sync class into multiple files. (#​17595)
  • Store sliding sync per-connection state in the database. (#​17599)
  • Make the sliding sync PerConnectionState class immutable. (#​17600)
  • Add support to @tag_args for standalone functions. (#​17604)
  • Speed up incremental syncs in sliding sync by adding some more caching. (#​17606)
  • Always return the user's own read receipts in sliding sync. (#​17617)
  • Replace isort and black with ruff. (#​17620)
  • Refactor sliding sync code to move room list logic out into a separate class. (#​17622)
Updates to locked dependencies
  • Bump attrs from 23.2.0 to 24.2.0. (#​17609)
  • Bump cryptography from 42.0.8 to 43.0.0. (#​17584)
  • Bump phonenumbers from 8.13.43 to 8.13.44. (#​17610)
  • Bump pygithub from 2.3.0 to 2.4.0. (#​17612)
  • Bump pyyaml from 6.0.1 to 6.0.2. (#​17611)
  • Bump sentry-sdk from 2.12.0 to 2.13.0. (#​17585)
  • Bump serde from 1.0.206 to 1.0.208. (#​17581)
  • Bump serde from 1.0.208 to 1.0.209. (#​17613)
  • Bump serde_json from 1.0.124 to 1.0.125. (#​17582)
  • Bump serde_json from 1.0.125 to 1.0.127. (#​17614)
  • Bump types-jsonschema from 4.23.0.20240712 to 4.23.0.20240813. (#​17583)
  • Bump types-setuptools from 71.1.0.20240726 to 71.1.0.20240818. (#​17586)
Synapse 1.114.0rc1 (2024-08-20)
Features
  • Add a flag to /versions, org.matrix.simplified_msc3575, to indicate whether experimental sliding sync support has been enabled. (#​17571)
  • Handle changes in timeline_limit in experimental sliding sync. (#​17579)
  • Correctly track read receipts that should be sent down in experimental sliding sync. (#​17575, #​17589, #​17592)
Bugfixes
  • Start handlers for new media endpoints when media resource configured. (#​17483)
  • Fix timeline ordering (using stream_ordering instead of topological ordering) in experimental MSC3575 Sliding Sync /sync endpoint. (#​17510)
  • Fix experimental sliding sync implementation to remember any updates in rooms that were not sent down immediately. (#​17535)
  • Better exclude partially stated rooms if we must await full state in experimental MSC3575 Sliding Sync /sync endpoint. (#​17538)
  • Handle lower-case http headers in _Mulitpart_Parser_Protocol. (#​17545)
  • Fix fetching federation signing keys from servers that omit old_verify_keys. Contributed by @​tulir @​ Beeper. (#​17568)
  • Fix bug where we would respond with an error when a remote server asked for media that had a length of 0, using the new multipart federation media endpoint. (#​17570)
Improved Documentation
Internal Changes
  • Add more tracing to experimental MSC3575 Sliding Sync /sync endpoint. (#​17514)
  • Fixup comment in sliding sync implementation. (#​17531)
  • Replace override of deprecated method HTTPAdapter.get_connection with get_connection_with_tls_context. (#​17536)
  • Fix performance of device lists in /key/changes and sliding sync. (#​17537, #​17548)
  • Bump setuptools from 67.6.0 to 72.1.0. (#​17542)
  • Add a utility function for generating random event IDs. (#​17557)
  • Speed up responding to media requests. (#​17558, #​17561, #​17564, #​17566, #​17567, #​17569)
  • Test github token before running release script steps. (#​17562)
  • Reduce log spam of multipart files. (#​17563)
  • Refactor per-connection state in experimental sliding sync handler. (#​17574)
  • Add histogram metrics for sliding sync processing time. (#​17593)
Updates to locked dependencies
  • Bump bytes from 1.6.1 to 1.7.1. (#​17526)
  • Bump lxml from 5.2.2 to 5.3.0. (#​17550)
  • Bump phonenumbers from 8.13.42 to 8.13.43. (#​17551)
  • Bump regex from 1.10.5 to 1.10.6. (#​17527)
  • Bump sentry-sdk from 2.10.0 to 2.12.0. (#​17553)
  • Bump serde from 1.0.204 to 1.0.206. (#​17556)
  • Bump serde_json from 1.0.122 to 1.0.124. (#​17555)
  • Bump sigstore/cosign-installer from 3.5.0 to 3.6.0. (#​17549)
  • Bump types-pyyaml from 6.0.12.20240311 to 6.0.12.20240808. (#​17552)
  • Bump types-requests from 2.31.0.20240406 to 2.32.0.20240712. (#​17524)

v1.113.0

Compare Source

Synapse 1.113.0 (2024-08-13)

No significant changes since 1.113.0rc1.

Synapse 1.113.0rc1 (2024-08-06)
Features
  • Track which rooms have been sent to clients in the experimental MSC3575 Sliding Sync /sync endpoint. (#​17447)
  • Add Account Data extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17477)
  • Add receipts extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17489)
  • Add typing notification extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17505)
Bugfixes
  • Update experimental MSC3575 Sliding Sync /sync endpoint to handle invite/knock rooms when filtering. (#​17450)
  • Fix a bug introduced in v1.110.0 which caused /keys/query to return incomplete results, leading to high network activity and CPU usage on Matrix clients. (#​17499)
Improved Documentation
Internal Changes
  • Change sliding sync to use their own token format in preparation for storing per-connection state. (#​17452)
  • Ensure we don't send down negative bump_stamp in experimental sliding sync endpoint. (#​17478)
  • Do not send down empty room entries down experimental sliding sync endpoint. (#​17479)
  • Refactor Sliding Sync tests to better utilize the SlidingSyncBase. (#​17481, #​17482)
  • Add some opentracing tags and logging to the experimental sliding sync implementation. (#​17501)
  • Split and move Sliding Sync tests so we have some more sane test file sizes. (#​17504)
  • Update the limited field description in the Sliding Sync response to accurately describe what it actually represents. (#​17507)
  • Easier to understand timeline assertions in Sliding Sync tests. (#​17511)
  • Reset the sliding sync connection if we don't recognize the per-connection state position. (#​17529)
Updates to locked dependencies
  • Bump bcrypt from 4.1.3 to 4.2.0. (#​17495)
  • Bump black from 24.4.2 to 24.8.0. (#​17522)
  • Bump phonenumbers from 8.13.39 to 8.13.42. (#​17521)
  • Bump ruff from 0.5.4 to 0.5.5. (#​17494)
  • Bump serde_json from 1.0.120 to 1.0.121. (#​17493)
  • Bump serde_json from 1.0.121 to 1.0.122. (#​17525)
  • Bump towncrier from 23.11.0 to 24.7.1. (#​17523)
  • Bump types-pyopenssl from 24.1.0.20240425 to 24.1.0.20240722. (#​17496)
  • Bump types-setuptools from 70.1.0.20240627 to 71.1.0.20240726. (#​17497)

v1.112.0

Compare Source

Synapse 1.112.0 (2024-07-30)

This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.

Note that this security fix is also available as Synapse 1.111.1, which does not include the rest of the changes in Synapse 1.112.0.

This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.

With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.

Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.

pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using pip install Twisted==24.7.0rc1. Note also that even the --upgrade-strategy=eager flag to pip install -U matrix-synapse will not upgrade Twisted to a patched version because it is only a release candidate at this time.

Internal Changes
  • Upgrade locked dependency on Twisted to 24.7.0rc1. (#​17502)
Synapse 1.112.0rc1 (2024-07-23)

Please note that this release candidate does not include the security dependency update
included in version 1.111.1 as this version was released before 1.111.1.
The same security fix can be found in the full release of 1.112.0.

Features
  • Add to-device extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17416)
  • Populate name/avatar fields in experimental MSC3575 Sliding Sync /sync endpoint. (#​17418)
  • Populate heroes and room summary fields (joined_count, invited_count) in experimental MSC3575 Sliding Sync /sync endpoint. (#​17419)
  • Populate is_dm room field in experimental MSC3575 Sliding Sync /sync endpoint. (#​17429)
  • Add room subscriptions to experimental MSC3575 Sliding Sync /sync endpoint. (#​17432)
  • Prepare for authenticated media freeze. (#​17433)
  • Add E2EE extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17454)
Bugfixes
  • Add configurable option to always include offline users in presence sync results. Contributed by @​Michael-Hollister. (#​17231)
  • Fix bug in experimental MSC3575 Sliding Sync /sync endpoint when using room type filters and the user has one or more remote invites. (#​17434)
  • Order heroes by stream_ordering as the Matrix specification states (applies to /sync). (#​17435)
  • Fix rare bug where /sync would break for a user when using workers with multiple stream writers. (#​17438)
Improved Documentation
Internal Changes
  • Make sure we always use the right logic for enabling the media repo. (#​17424)
  • Fix argument documentation for method RateLimiter.record_action. (#​17426)
  • Reduce volume of 'Waiting for current token' logs, which were introduced in v1.109.0. (#​17428)
  • Limit concurrent remote downloads to 6 per IP address, and decrement remote downloads without a content-length from the ratelimiter after the download is complete. (#​17439)
  • Remove unnecessary call to resume producing in fake channel. (#​17449)
  • Update experimental MSC3575 Sliding Sync /sync endpoint to bump room when it is created. (#​17453)
  • Speed up generating sliding sync responses. (#​17458)
  • Add cache to get_rooms_for_local_user_where_membership_is to speed up sliding sync. (#​17460)
  • Speed up fetching room keys from backup. (#​17461)
  • Speed up sorting of the room list in sliding sync. (#​17468)
  • Implement handling of $ME as a state key in sliding sync. (#​17469)
Updates to locked dependencies
  • Bump bytes from 1.6.0 to 1.6.1. (#​17441)
  • Bump hiredis from 2.3.2 to 3.0.0. (#​17464)
  • Bump jsonschema from 4.22.0 to 4.23.0. (#​17444)
  • Bump matrix-org/done-action from 2 to 3. (#​17440)
  • Bump mypy from 1.9.0 to 1.10.1. (#​17445)
  • Bump pyopenssl from 24.1.0 to 24.2.1. (#​17465)
  • Bump ruff from 0.5.0 to 0.5.4. (#​17466)
  • Bump sentry-sdk from 2.6.0 to 2.8.0. (#​17456)
  • Bump sentry-sdk from 2.8.0 to 2.10.0. (#​17467)
  • Bump setuptools from 67.6.0 to 70.0.0. (#​17448)
  • Bump twine from 5.1.0 to 5.1.1. (#​17443)
  • Bump types-jsonschema from 4.22.0.20240610 to 4.23.0.20240712. (#​17446)
  • Bump ulid from 1.1.2 to 1.1.3. (#​17442)
  • Bump zipp from 3.15.0 to 3.19.1. (#​17427)

v1.111.1

Compare Source

Synapse 1.111.1 (2024-07-30)

This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.

This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.

With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.

Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.

pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using pip install Twisted==24.7.0rc1. Note also that even the --upgrade-strategy=eager flag to pip install -U matrix-synapse will not upgrade Twisted to a patched version because it is only a release candidate at this time.

Internal Changes
  • Upgrade locked dependency on Twisted to 24.7.0rc1. (#​17502)
markdownlint/markdownlint (markdownlint/markdownlint)

v0.18.1

Compare Source

Fixed
  • Fixed crash on startup when using old versions of the uri gem.
    #​606

v0.18.0

Compare Source

Added
  • MD034 - Add allow_quoted option.
    #​594
  • Add config options for kramdown parser opts: parse_block_html,
    parse_span_html, html_to_native
    #​568
  • Support options on codeblock openers
    #​590
  • Add front_matter_title parameter for all header-related rules
    #​570
Fixed
  • MD024 - Fix crash when allow_different_nesting was set
    #​593
  • Handle UTF-8 filenames better with -g
    #​591
Changed
  • MD013 - When treat_links_as_single_words is set, also allow
    link references to be on a single line regardless of length
    #​597

v0.17.0

Compare Source

Added
  • Added treat_links_as_single_word option to MD013
    #​580
Fixed
  • MD013 - Do not trigger on a single long word in backticks
    #​580
  • MD013 - Do not trigger on a single long word alone on a line continuation
    #​580
  • MD013 - Do not trigger on a list item with a single long word
    #​580
  • Docker - Use latest alphine so mdl version is correct

v0.16.0

Compare Source

Added
Changed
  • Added extra documentation around excluding rules
    #​516
  • Update Kramdown
    #​539
  • Start from all rules when style only contains exclusions
    #​551
  • Give error when explicitly specified config file is not found
    #​554
  • Skip docs footer for rules without a docs URL
    #​556
  • Fix "bulletd" typo in test file names
    #​557
  • Accept string values for symbol params in style files
    #​561
  • Bump bundler version
    #​569
Fixed
  • MD005 - Fixed inconsistent UL/OL ordering
    #​539
  • MD013 - Fixed line length detection
    #​539
  • Fix fenced code blocks not detected without preceding blank line
    #​541
  • Fix front matter offset when blank line follows closing ---
    #​542
  • MD029 - Fix false positive for ordered lists inside blockquotes
    #​543
  • MD026 - Fix false positive on emoji shortcodes in headers
    #​543
  • MD011 - Fix false positive on footnote references
    #​545
  • Fix crash on files with invalid UTF-8 byte sequences
    #​546
  • MD034 - FIx not detecting bare URLs inside tables
    #​547
  • Fix front matter regex matching --- inside code blocks
    #​548
  • MD037 - Fix false positive on escaped emphasis markers
    #​549
  • MD014 - Fix false positive on code blocks with only blank lines
    #​550
  • MD040 - Fix false positive on tab-indented code blocks
    #​552
  • MD034 - Fix false positive for URLs inside HTML elements
    #​553
  • Fix double slashes in file paths when directory has trailing slash
    #​555
  • MD031 - Fix false positive on inline backtick code spans
    #​558
  • MD013 - Detect table-like lines even when kramdown parses them as paragraphs
    #​560
  • MD007 - Fix false positive on unrelated lists at different indent levels
    #​562
  • MD034 - Fix false positive when link text contains pipe character
    #​564
  • MD032 - Fix false positive on HTML comments adjacent to lists
    #​565
  • MD027 - Fix false positive on blockquotes with soft line breaks
    #​566
  • MD013 - Add :headings parameter to exclude headings from line length
    #​563
  • MD013 - Don't flag lines that are single-words
    #​572

v0.15.0

Compare Source

Changed
  • Bumped minum ruby version to 3.2
    #​531, and associated
    changes

v0.14.0

Compare Source

Fixed
  • Fix Markdown lint version in SARIF output test
    #​469
  • Fix example for rulesets flag in configuration docs
    #​473
  • Require ruby-3.3.0 for standalone pre-commit hook
    #​528
Rules Removed
  • Removed MD055, MD056, MD057 - These rules for tables caused regressions and
    were removed (see
    #​472 for details)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [awesometechnologies/synapse-admin](https://github.com/Awesome-Technologies/synapse-admin) | | minor | `0.10.3` → `0.11.4` | | [docker.io/matrixdotorg/synapse](https://github.com/element-hq/synapse) | | minor | `v1.111.0` → `v1.162.0` | | [markdownlint/markdownlint](https://github.com/markdownlint/markdownlint) | repository | minor | `v0.13.0` → `v0.18.1` | Note: The `pre-commit` manager in Renovate is not supported by the `pre-commit` maintainers or community. Please do not report any problems there, instead [create a Discussion in the Renovate repository](https://github.com/renovatebot/renovate/discussions/new) if you have any questions. --- ### Release Notes <details> <summary>Awesome-Technologies/synapse-admin (awesometechnologies/synapse-admin)</summary> ### [`v0.11.4`](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.3...0.11.4) [Compare Source](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.3...0.11.4) ### [`v0.11.3`](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.2...0.11.3) [Compare Source](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.2...0.11.3) ### [`v0.11.2`](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.1...0.11.2) [Compare Source](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.1...0.11.2) ### [`v0.11.1`](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.0...0.11.1) [Compare Source](https://github.com/Awesome-Technologies/synapse-admin/compare/0.11.0...0.11.1) ### [`v0.11.0`](https://github.com/Awesome-Technologies/synapse-admin/compare/0.10.4...0.11.0) [Compare Source](https://github.com/Awesome-Technologies/synapse-admin/compare/0.10.4...0.11.0) ### [`v0.10.4`](https://github.com/Awesome-Technologies/synapse-admin/compare/0.10.3...0.10.4) [Compare Source](https://github.com/Awesome-Technologies/synapse-admin/compare/0.10.3...0.10.4) </details> <details> <summary>element-hq/synapse (docker.io/matrixdotorg/synapse)</summary> ### [`v1.162.0`](https://github.com/element-hq/synapse/releases/tag/v1.162.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.161.0...v1.162.0) Changelog: <https://github.com/element-hq/synapse/blob/release-v1.162/CHANGES.md> ### [`v1.161.0`](https://github.com/element-hq/synapse/releases/tag/v1.161.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.160.0...v1.161.0) Changelog: <https://github.com/element-hq/synapse/blob/release-v1.161/CHANGES.md> ### [`v1.160.0`](https://github.com/element-hq/synapse/releases/tag/v1.160.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.159.0...v1.160.0) Changelog: <https://github.com/element-hq/synapse/blob/release-v1.160/CHANGES.md> ### [`v1.159.0`](https://github.com/element-hq/synapse/releases/tag/v1.159.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.158.0...v1.159.0) Changelog: <https://github.com/element-hq/synapse/blob/release-v1.159/CHANGES.md> ### [`v1.158.0`](https://github.com/element-hq/synapse/releases/tag/v1.158.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.157.2...v1.158.0) Changelog: <https://github.com/element-hq/synapse/blob/release-v1.158/CHANGES.md> ### [`v1.157.2`](https://github.com/element-hq/synapse/releases/tag/v1.157.2) [Compare Source](https://github.com/element-hq/synapse/compare/v1.157.1...v1.157.2) ##### Synapse 1.157.2 (2026-07-28) This security release addresses several vulnerabilities. Please upgrade when you can, particularly if your homeserver participates in open federation and/or has untrusted local users. ##### Security Fixes High severity: - Fix [ELEMENTSEC-2026-1071](https://github.com/element-hq/synapse/security/advisories/GHSA-fp53-rw9v-hcf9) - Fix [ELEMENTSEC-2024-1520](https://github.com/element-hq/synapse/security/advisories/GHSA-rgv2-84w7-5j9p) - Fix [ELEMENTSEC-2026-1717](https://github.com/element-hq/synapse/security/advisories/GHSA-27p5-4f45-gx76) - Fix [ELEMENTSEC-2026-1721](https://github.com/element-hq/synapse/security/advisories/GHSA-95fh-hv8c-chvq) - Fix [ELEMENTSEC-2026-1729](https://github.com/element-hq/synapse/security/advisories/GHSA-cjh7-rcpx-xpf8) - Fix [ELEMENTSEC-2026-1740](https://github.com/element-hq/synapse/security/advisories/GHSA-6wjm-9p2x-gvpm) Moderate severity: - Fix [ELEMENTSEC-2026-1714](https://github.com/element-hq/synapse/security/advisories/GHSA-qcjr-46gf-7f4r) - Fix [ELEMENTSEC-2026-1718](https://github.com/element-hq/synapse/security/advisories/GHSA-r66v-qhwx-8rg4) - Fix [ELEMENTSEC-2026-1751](https://github.com/element-hq/synapse/security/advisories/GHSA-jhcg-5392-5mjw) Low severity: - Fix [ELEMENTSEC-2026-1703](https://github.com/element-hq/synapse/security/advisories/GHSA-vh4c-pqh4-w3wq) - Fix [ELEMENTSEC-2026-1760](https://github.com/element-hq/synapse/security/advisories/GHSA-hgcg-p9gx-fq5f) ### [`v1.157.1`](https://github.com/element-hq/synapse/releases/tag/v1.157.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.157.0...v1.157.1) ##### Synapse 1.157.1 (2026-07-22) ##### Bugfixes - Fix config regression around falsy `experimental_features` no longer being accepted. ([#&#8203;19987](https://github.com/element-hq/synapse/issues/19987)) ### [`v1.157.0`](https://github.com/element-hq/synapse/releases/tag/v1.157.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.156.0...v1.157.0) ##### Synapse 1.157.0 (2026-07-21) No significant changes since 1.157.0rc1. ##### Synapse 1.157.0rc1 (2026-07-14) ##### Features - [MSC4140: Cancellable delayed events](https://github.com/matrix-org/matrix-spec-proposals/pull/4140): Limit how many delayed events a user may have scheduled at once. ([#&#8203;19539](https://github.com/element-hq/synapse/issues/19539)) - Support [MSC4446](https://github.com/matrix-org/matrix-spec-proposals/pull/4446) for moving fully read markers backwards. Contributed by [@&#8203;SpiritCroc](https://github.com/SpiritCroc) @&#8203; Beeper. ([#&#8203;19663](https://github.com/element-hq/synapse/issues/19663)) - Add before and after time filters to the ['Redact events of a user'](https://element-hq.github.io/synapse/v1.157/admin_api/user_admin_api.html#redact-events-of-a-user) Admin API. ([#&#8203;19802](https://github.com/element-hq/synapse/issues/19802)) - Updated experimental support for [MSC4388: Secure out-of-band channel for sign in with QR](https://github.com/matrix-org/matrix-spec-proposals/pull/4388). ([#&#8203;19808](https://github.com/element-hq/synapse/issues/19808)) - Add an `exclude_rooms_from_presence` configuration option to stop presence being routed between users solely because they share one of the listed rooms. ([#&#8203;19935](https://github.com/element-hq/synapse/issues/19935)) ##### Bugfixes - [MSC4140: Cancellable delayed events](https://github.com/matrix-org/matrix-spec-proposals/pull/4140): Update error responses to match their format in the current draft of the MSC. ([#&#8203;19539](https://github.com/element-hq/synapse/issues/19539)) - Lock Sliding Sync connections when inserting lazy members, to prevent repeated deadlocks. ([#&#8203;19826](https://github.com/element-hq/synapse/issues/19826)) - Fix the `flag_existing_quarantined_media` background update skipping some quarantined remote media. Introduced in v1.152.0. ([#&#8203;19901](https://github.com/element-hq/synapse/issues/19901)) - Fix a bug introduced in Synapse v1.150.0 where reactivating a deactivated and erased user did not restore their profile, breaking login, name changes, and invitations. Contributed by [@&#8203;m4us1ne](https://github.com/m4us1ne). ([#&#8203;19902](https://github.com/element-hq/synapse/issues/19902)) - Fix a regression where application services that opted into ephemeral events using the legacy `de.sorunome.msc2409.push_ephemeral` registration flag stopped receiving ephemeral events (including to-device messages used for encryption). Introduced in v1.156.0. ([#&#8203;19928](https://github.com/element-hq/synapse/issues/19928)) - Fix a bug causing device list pruning to skip some rows when the transaction gets retried. ([#&#8203;19947](https://github.com/element-hq/synapse/issues/19947)) - Fix presence states being shown to clients forever after presence is disabled, by marking any previously only users as offline. ([#&#8203;19948](https://github.com/element-hq/synapse/issues/19948)) - Fix `SYNAPSE_ASYNC_IO_REACTOR=1` on Python 3.14. ([#&#8203;19949](https://github.com/element-hq/synapse/issues/19949)) ##### Deprecations and Removals - Remove support for experimental [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861) auth delegation, in favour of the stable Matrix Authentication Service integration support. See [the upgrade notes](https://element-hq.github.io/synapse/v1.157/upgrade.html#upgrading-to-v11570). ([#&#8203;19895](https://github.com/element-hq/synapse/issues/19895)) ##### Internal Changes - Port the synchronous core of client event serialization to Rust. ([#&#8203;19837](https://github.com/element-hq/synapse/issues/19837), [#&#8203;19922](https://github.com/element-hq/synapse/issues/19922)) - Update `HomeserverTestCase.get_success(...)` and friends to drive async Rust (Tokio runtime/thread pool). ([#&#8203;19871](https://github.com/element-hq/synapse/issues/19871), [#&#8203;19879](https://github.com/element-hq/synapse/issues/19879)) - Allow Rust code to have database access via Python database connection pool. ([#&#8203;19878](https://github.com/element-hq/synapse/issues/19878)) - Add `golangci-lint` to CI. ([#&#8203;19888](https://github.com/element-hq/synapse/issues/19888)) - Remove wall-clock dependency of `test_redact_messages_all_rooms` test, as this caused flakiness. ([#&#8203;19890](https://github.com/element-hq/synapse/issues/19890)) - Change the [MSC3814](https://github.com/matrix-org/matrix-spec-proposals/pull/3814) dehydrated device `/events` endpoint from `POST` to `GET`. ([#&#8203;19896](https://github.com/element-hq/synapse/issues/19896)) - Change the [MSC3814](https://github.com/matrix-org/matrix-spec-proposals/pull/3814) dehydrated device `/events` endpoint paging to match spec conventions. ([#&#8203;19897](https://github.com/element-hq/synapse/issues/19897)) - Fix storage type mismatches where values were bound with a type that didn't match their database column. ([#&#8203;19911](https://github.com/element-hq/synapse/issues/19911)) - Speed up deletion of old sliding sync connections by adding an index. ([#&#8203;19912](https://github.com/element-hq/synapse/issues/19912)) - Add note to 3PID email token request unit tests that the endpoint being tested can have an expected, artificial delay of up to 1s. ([#&#8203;19916](https://github.com/element-hq/synapse/issues/19916)) - Add an index to `sliding_sync_connection_lazy_members` to speed up deleting old sliding sync connection positions. ([#&#8203;19923](https://github.com/element-hq/synapse/issues/19923)) - Fix `test_lock_contention` being flaky when running against PostgreSQL by budgeting CPU time rather than wall-clock time. ([#&#8203;19929](https://github.com/element-hq/synapse/issues/19929)) - Fix Complement test flake when restarting Synapse workers (cross-test pollution caused by nginx upstreams being temporarily unavailable). ([#&#8203;19936](https://github.com/element-hq/synapse/issues/19936)) - Add clean deploy `FIXME` note for `TestOIDCProviderUnavailable` (problem tracked by [#&#8203;19937](https://github.com/element-hq/synapse/issues/19937)). ([#&#8203;19938](https://github.com/element-hq/synapse/issues/19938)) - Minor presence performance improvements for large servers. ([#&#8203;19939](https://github.com/element-hq/synapse/issues/19939)) - Reduce replication traffic caused by presence. ([#&#8203;19941](https://github.com/element-hq/synapse/issues/19941)) - Add `last_active_granularity`, `sync_online_timeout` and `idle_timeout` options to the `presence` config section to allow tuning the presence state machine timers. ([#&#8203;19942](https://github.com/element-hq/synapse/issues/19942)) ### [`v1.156.0`](https://github.com/element-hq/synapse/releases/tag/v1.156.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.155.0...v1.156.0) ##### Synapse 1.156.0 (2026-07-07) No significant changes since 1.156.0rc1. ##### Synapse 1.156.0rc1 (2026-06-30) ##### Features - Expose [MSC4354 Sticky Events](https://github.com/matrix-org/matrix-spec-proposals/pull/4354) over [MSC4186 (Simplified) Sliding Sync](https://github.com/matrix-org/matrix-spec-proposals/pull/4186). ([#&#8203;19591](https://github.com/element-hq/synapse/issues/19591)) - Stabilize support for sending ephemeral events to application services, as per [MSC2409](https://github.com/matrix-org/matrix-spec-proposals/pull/2409). Contributed by [@&#8203;jason-famedly](https://github.com/jason-famedly) @&#8203; Famedly. ([#&#8203;19758](https://github.com/element-hq/synapse/issues/19758)) - Include `allowed_room_ids` in the `/summary` client-server API response for rooms with restricted join rules, as required by Matrix 1.15. Contributed by [@&#8203;FrenchGithubUser](https://github.com/FrenchGithubUser) [@&#8203;Famedly](https://github.com/Famedly). ([#&#8203;19762](https://github.com/element-hq/synapse/issues/19762)) - [MSC4140: Cancellable delayed events](https://github.com/matrix-org/matrix-spec-proposals/pull/4140): Allow authentication on delayed event management endpoints (such as `/restart`) to bypass ratelimits for unauthenticated requests based on the client IP address. ([#&#8203;19794](https://github.com/element-hq/synapse/issues/19794)) - Add new metric `synapse_non_deactivated_user_count` which tracks the number of non-deactivated users in the database, split by `app_service`. ([#&#8203;19848](https://github.com/element-hq/synapse/issues/19848)) - The `GET /_matrix/client/unstable/org.matrix.msc1763/retention/configuration` endpoint is now provided when retention is enabled and `experimental_features.msc1763_enabled` is enabled, based on [MSC1763](https://github.com/matrix-org/matrix-spec-proposals/pull/1763). ([#&#8203;19853](https://github.com/element-hq/synapse/issues/19853)) - Add experimental support for [MSC4491: Invite reasons in room creation](https://github.com/matrix-org/matrix-spec-proposals/pull/4491). ([#&#8203;19874](https://github.com/element-hq/synapse/issues/19874)) ##### Bugfixes - Provide remote servers a way to find out about an event created during the remote join handshake. Contributed by [@&#8203;FrenchGithubUser](https://github.com/FrenchGithubUser) and [@&#8203;jason-famedly](https://github.com/jason-famedly) @&#8203; Famedly. ([#&#8203;19390](https://github.com/element-hq/synapse/issues/19390), [#&#8203;19855](https://github.com/element-hq/synapse/issues/19855), [#&#8203;19856](https://github.com/element-hq/synapse/issues/19856)) - Advertise `org.matrix.msc4143` in `unstable_features` when `msc4143_enabled` is set. ([#&#8203;19646](https://github.com/element-hq/synapse/issues/19646)) - Fix a long-standing bug where the badge notification count for a room could become permanently inflated if a read receipt was sent before the room's notification counts were first summarised. ([#&#8203;19785](https://github.com/element-hq/synapse/issues/19785)) - Fix startup listener logging to report the actual bound TCP port, so listeners configured with port `0` no longer log `Synapse now listening on TCP port 0`. ([#&#8203;19810](https://github.com/element-hq/synapse/issues/19810)) - Fix notification counts being inflated after a `/purge_history` when notifications had already been rotated into the summary table. ([#&#8203;19834](https://github.com/element-hq/synapse/issues/19834)) - Fix `/sync` caching transient errors for the `sync_response_cache_duration`. ([#&#8203;19845](https://github.com/element-hq/synapse/issues/19845)) - Fix local events being deleted by the [Purge History admin API](https://element-hq.github.io/synapse/v1.155/admin_api/purge_history_api.html) despite `delete_local_events` being set to false, in room versions other than 1 and 2. ([#&#8203;19850](https://github.com/element-hq/synapse/issues/19850)) - Fix a bug where a user's dehydrated device ([MSC3814](https://github.com/matrix-org/matrix-spec-proposals/pull/3814)) was deleted when their device list was synced from Matrix Authentication Service (e.g. upon logging out their last device), breaking offline key delivery. ([#&#8203;19892](https://github.com/element-hq/synapse/issues/19892)) ##### Improved Documentation - Update `auto_join_rooms` config documentation to cover requirements for auto-joining invite-only rooms. ([#&#8203;19660](https://github.com/element-hq/synapse/issues/19660)) - Add stable endpoint for [MSC3266: Room summary API](https://github.com/matrix-org/matrix-spec-proposals/pull/3266) into worker docs. Contributed by [@&#8203;olmari](https://github.com/olmari). ([#&#8203;19788](https://github.com/element-hq/synapse/issues/19788)) - Tweak wording of Rust crate dependency update policy. ([#&#8203;19829](https://github.com/element-hq/synapse/issues/19829)) - Fixed the Admin API user endpoint documentation examples to use JSON booleans (true/false) instead of numeric (0/1) values. ([#&#8203;19847](https://github.com/element-hq/synapse/issues/19847)) ##### Internal Changes - Make `simple_select_one_onecol_txn()` more helpful by naming the table of the select - as all other query wrapper functions already did. ([#&#8203;19869](https://github.com/element-hq/synapse/issues/19869)) - Refactor `get_user_which_could_invite` logic to reuse `get_users_which_can_issue_invite`. Contributed by Noah Markert. ([#&#8203;19732](https://github.com/element-hq/synapse/issues/19732)) - Fix a flaky test (`twisted.protocols.amp.TooLong` error under `trial -jN`) caused by an oversized debug log line. ([#&#8203;19832](https://github.com/element-hq/synapse/issues/19832)) - Upload Complement test logs as CI artifacts instead of printing the raw output to the build log. ([#&#8203;19840](https://github.com/element-hq/synapse/issues/19840)) - Fix release script considering any workflow completion as successful. ([#&#8203;19843](https://github.com/element-hq/synapse/issues/19843)) - Force keyword-args for clear `default_config(server_name="test")` usage in test utilities. ([#&#8203;19849](https://github.com/element-hq/synapse/issues/19849)) - Add `.ruff_cache/` directory to `.gitignore`. ([#&#8203;19854](https://github.com/element-hq/synapse/issues/19854)) - Bump `poetry` in CI from `2.2.1` to `2.4.1`. ([#&#8203;19866](https://github.com/element-hq/synapse/issues/19866), [#&#8203;19877](https://github.com/element-hq/synapse/issues/19877)) - Split out `deferred` and `tokio_runtime` to their own Rust modules. ([#&#8203;19868](https://github.com/element-hq/synapse/issues/19868)) - Prevent the `cargo-test` and `cargo-bench` CI jobs from being skipped, even on PRs that have Rust changes. ([#&#8203;19883](https://github.com/element-hq/synapse/issues/19883)) ### [`v1.155.0`](https://github.com/element-hq/synapse/releases/tag/v1.155.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.154.0...v1.155.0) ##### Synapse 1.155.0 (2026-06-16) ##### End of Life of Debian 12 Bookworm The next version of Synapse will not include Debian packages for Debian 12 Bookworm as it reached end of life on the 10th of June 2026. ##### Internal Changes - When building releases, don't cancel Debian package builds when one of them fails. ([#&#8203;19842](https://github.com/element-hq/synapse/issues/19842)) ##### Synapse 1.155.0rc1 (2026-06-09) ##### Bugfixes - Limit the to-device EDU size to a reasonable value to mitigate long queues of to-device messages preventing outgoing federation because of the size of the transaction. ([#&#8203;19617](https://github.com/element-hq/synapse/issues/19617)) - Work around bug that sometimes breaks joining restricted rooms that require a remote join. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19730](https://github.com/element-hq/synapse/issues/19730)) - Update Sliding Sync to return a new response immediately if a room subscription has changed and produced a new response. ([#&#8203;19734](https://github.com/element-hq/synapse/issues/19734), [#&#8203;19792](https://github.com/element-hq/synapse/issues/19792)) - Fix the `/capabilities` endpoint returning a 500 error on non-media workers when [MSC4452: Preview URL capabilities API](https://github.com/matrix-org/matrix-spec-proposals/pull/4452) is enabled. ([#&#8203;19839](https://github.com/element-hq/synapse/issues/19839)) ##### Improved Documentation - Document how to see Rust build failure output when using `poetry install`. ([#&#8203;19818](https://github.com/element-hq/synapse/issues/19818)) - Document that the SQLite version included in Ubuntu LTS, aside from ESM-only versions, is included in our support policy. ([#&#8203;19823](https://github.com/element-hq/synapse/issues/19823)) ##### Internal Changes - Port the Python Event classes to Rust. ([#&#8203;19701](https://github.com/element-hq/synapse/issues/19701), [#&#8203;19816](https://github.com/element-hq/synapse/issues/19816), [#&#8203;19817](https://github.com/element-hq/synapse/issues/19817), [#&#8203;19819](https://github.com/element-hq/synapse/issues/19819)) - Added tests to ensure that email notification links are sanitized. Contributed by Noah Markert. ([#&#8203;19741](https://github.com/element-hq/synapse/issues/19741)) - Add `GcpJsonFormatter` logging formatter for use with Google Cloud Logging and GKE deployments. ([#&#8203;19775](https://github.com/element-hq/synapse/issues/19775)) - Add more logging to the to-device message replication stream. ([#&#8203;19801](https://github.com/element-hq/synapse/issues/19801), [#&#8203;19821](https://github.com/element-hq/synapse/issues/19821)) - Port `Requester` class to Rust. ([#&#8203;19828](https://github.com/element-hq/synapse/issues/19828)) ### [`v1.154.0`](https://github.com/element-hq/synapse/releases/tag/v1.154.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.153.0...v1.154.0) ##### Synapse 1.154.0 (2026-06-04) No significant changes since 1.154.0rc1. ##### Synapse 1.154.0rc1 (2026-05-27) ##### Features - Add support for [MSC4452: Preview URL capabilities API](https://github.com/matrix-org/matrix-spec-proposals/pull/4452) which exposes a `io.element.msc4452.preview_url` capability. If `experimental_features.msc4452_enabled` is `true`, the `/_matrix/(client/v1/media|media/v3)/preview_url` endpoint now responds with a 403 status code when the capability is disabled. ([#&#8203;19715](https://github.com/element-hq/synapse/issues/19715)) ##### Bugfixes - Fix a bug in [MSC4186: Simplified Sliding Sync](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) that could prevent user avatars from showing if the room had an empty name. ([#&#8203;19468](https://github.com/element-hq/synapse/issues/19468), [#&#8203;19791](https://github.com/element-hq/synapse/issues/19791)) - Fix access token cache not being invalidated for sessions using refresh tokens. Contributed by [@&#8203;FrenchGithubUser](https://github.com/FrenchGithubUser) @&#8203; Famedly. ([#&#8203;19483](https://github.com/element-hq/synapse/issues/19483)) - Fix bug where Synapse would return 400 (`M_BAD_JSON`) when sending a message with a `mentions` field and Synapse module `check_event_allowed` callback registered (frozen event). Contributed by [@&#8203;gaetan-sbt](https://github.com/gaetan-sbt). ([#&#8203;19634](https://github.com/element-hq/synapse/issues/19634)) - Fix long-standing but niche bug with `/sync` where it could attempt to fetch data with flawed invalid future tokens. ([#&#8203;19644](https://github.com/element-hq/synapse/issues/19644)) - Fix `/sync` failing when [MSC4354 Sticky Events](https://github.com/matrix-org/matrix-spec-proposals/pull/4354) are enabled and the sync request filters out Ephemeral Data Units (EDUs). ([#&#8203;19787](https://github.com/element-hq/synapse/issues/19787)) - Fix packaging for Fedora and EPEL caused by unnecessary bumping `attrs` minimum version requirement in `pyproject.toml` file. Contributed by Oleg Girko. ([#&#8203;19789](https://github.com/element-hq/synapse/issues/19789)) - Fix merging signatures when a policy server is running under the same server name as Synapse. The bug was re-introduced in v1.153.0rc1 after being fixed earlier in v1.151.0rc1. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19797](https://github.com/element-hq/synapse/issues/19797)) ##### Improved Documentation - Added details about how Synapse syncs the picture claim when `update_profile_information` setting is true. ([#&#8203;19508](https://github.com/element-hq/synapse/issues/19508)) ##### Internal Changes - Port `Event.content` field to Rust. ([#&#8203;19725](https://github.com/element-hq/synapse/issues/19725)) - Prefer close backfill points (absolute distance). ([#&#8203;19748](https://github.com/element-hq/synapse/issues/19748)) - Replace unique `quarantined_media` waiting patterns with standard `wait_for_stream_token(...)`. ([#&#8203;19764](https://github.com/element-hq/synapse/issues/19764)) - Improve Synapse logging around when someone encounters `We can't get valid state history.` so you can correlate everything by `event_id`. ([#&#8203;19765](https://github.com/element-hq/synapse/issues/19765)) - Tidy up Rust `RoomVersion` structs. ([#&#8203;19766](https://github.com/element-hq/synapse/issues/19766)) - Update `WorkerLock` tests to better stress the `WORKER_LOCK_MAX_RETRY_INTERVAL`. ([#&#8203;19772](https://github.com/element-hq/synapse/issues/19772)) - Refactor [MSC4242: State DAG](https://github.com/matrix-org/matrix-spec-proposals/pull/4242) checks behind a single `TypeIs` helper to avoid scattered `isinstance` casts. ([#&#8203;19774](https://github.com/element-hq/synapse/issues/19774)) - Use `StrCollection` for `prev_state_events`. ([#&#8203;19777](https://github.com/element-hq/synapse/issues/19777)) - Fix up the construction of events in tests, ahead of the Rust event port. ([#&#8203;19781](https://github.com/element-hq/synapse/issues/19781)) ### [`v1.153.0`](https://github.com/element-hq/synapse/releases/tag/v1.153.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.152.1...v1.153.0) ##### Synapse 1.153.0 (2026-05-19) No significant changes since 1.153.0rc3. ##### Synapse 1.153.0rc3 (2026-05-15) ##### Bugfixes - Revert 'Have [MSC4186: Simplified Sliding Sync](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) return a new response immediately if a room subscription has changed and produced a new response. ([#&#8203;19714](https://github.com/element-hq/synapse/issues/19714))' (introduced in 1.153.0rc1) due to performance problems. ([#&#8203;19784](https://github.com/element-hq/synapse/issues/19784)) ##### Synapse 1.153.0rc2 (2026-05-13) ##### Bugfixes - Correctly handle arbitrary precision integers in `unsigned` field of events. The bug was introduced in 1.153.0rc1. ([#&#8203;19769](https://github.com/element-hq/synapse/issues/19769)) ##### Synapse 1.153.0rc1 (2026-05-08) ##### Features - Make ACLs apply to EDUs per [MSC4163](https://github.com/matrix-org/matrix-spec-proposals/pull/4163). ([#&#8203;18475](https://github.com/element-hq/synapse/issues/18475)) - Stabilize [MSC3266: Room summary API](https://github.com/matrix-org/matrix-spec-proposals/pull/3266), removing the experimental config flag `msc3266_enabled`. Contributed by [@&#8203;dasha-uwu](https://github.com/dasha-uwu). ([#&#8203;19720](https://github.com/element-hq/synapse/issues/19720)) - Partial [MSC4311](https://github.com/matrix-org/matrix-spec-proposals/pull/4311) implementation: `m.room.create` is now a required part of stripped `invite_state`/`knock_state` . Contributed by [@&#8203;FrenchGithubUser](https://github.com/FrenchGithubUser) [@&#8203;Famedly](https://github.com/Famedly). ([#&#8203;19722](https://github.com/element-hq/synapse/issues/19722)) - Expose `tombstoned` and `replacement_room` in room details on admin API endpoint `GET /_synapse/admin/v1/rooms/<room_id>`. Contributed by Noah Markert. ([#&#8203;19737](https://github.com/element-hq/synapse/issues/19737)) ##### Bugfixes - Allow self-requested user erasure (upon account deactivation) to succeed even if Synapse has disabled profile changes. Contributed by Famedly. ([#&#8203;19398](https://github.com/element-hq/synapse/issues/19398)) - Fix Synapse not backfilling new history when attempting to use a pagination token near a backward extremity. ([#&#8203;19611](https://github.com/element-hq/synapse/issues/19611)) - Have [MSC4186: Simplified Sliding Sync](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) return a new response immediately if a room subscription has changed and produced a new response. ([#&#8203;19714](https://github.com/element-hq/synapse/issues/19714)) - Fix a bug where when upgrading a room to room version 12, the power level event in the old room got temporarily mutated to remove the user upgrading the room's power. ([#&#8203;19727](https://github.com/element-hq/synapse/issues/19727)) - Fix packaging for Fedora and EPEL caused by unnecessary bumping `authlib` minimum version requirement in `pyproject.toml` file. Contributed by Oleg Girko. ([#&#8203;19742](https://github.com/element-hq/synapse/issues/19742)) ##### Improved Documentation - Add warning about known problems when configuring `use_frozen_dicts`. ([#&#8203;19711](https://github.com/element-hq/synapse/issues/19711)) ##### Internal Changes - Port `Event.signatures` field to Rust. ([#&#8203;19706](https://github.com/element-hq/synapse/issues/19706)) - Port `Event.unsigned` field to Rust. ([#&#8203;19708](https://github.com/element-hq/synapse/issues/19708)) - Add a Rust canonical JSON serializer. ([#&#8203;19739](https://github.com/element-hq/synapse/issues/19739), [#&#8203;19763](https://github.com/element-hq/synapse/issues/19763)) - Configure Dependabot to only update Python dependencies in the lockfile, unless widening upper bounds. ([#&#8203;19743](https://github.com/element-hq/synapse/issues/19743)) - Reduce `WORKER_LOCK_MAX_RETRY_INTERVAL` to 5 seconds to reduce idle time after lock is released. ([#&#8203;19755](https://github.com/element-hq/synapse/issues/19755)) - Force keyword-only arguments for `Duration` so time units have to be specified. ([#&#8203;19756](https://github.com/element-hq/synapse/issues/19756)) ### [`v1.152.1`](https://github.com/element-hq/synapse/releases/tag/v1.152.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.152.0...v1.152.1) ##### Synapse 1.152.1 (2026-05-07) ##### Security Fixes - Prevent CPU starvation (Denial of Service) under worker lock contention, additionally capping the `WorkerLock` time out interval to a maximum of 60 seconds. Contributed by Famedly. ([#&#8203;19394](https://github.com/element-hq/synapse/issues/19394), ELEMENTSEC-2026-1706, [GHSA-8q93-326v-3m7g](https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g), CVE-2026-45078) - Prevent pagination ending when a page is full of rejected events. (ELEMENTSEC-2025-1636, [GHSA-6qf2-7x63-mm6v](https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v), CVE-2026-45076) ### [`v1.152.0`](https://github.com/element-hq/synapse/releases/tag/v1.152.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.151.0...v1.152.0) ##### Synapse 1.152.0 (2026-04-28) No significant changes since 1.152.0rc1. ##### Configuration changes needed for deployments using workers For deployments using workers, please note that this version introduces a new `quarantined_media_changes` stream writer, which may require configuration changes. Please see the [the relevant section in the upgrade notes](https://github.com/element-hq/synapse/blob/develop/docs/upgrade.md#upgrading-to-v11520) for details. Without configuring this new stream writer, only the main process will be able to handle the `/media/quarantine` admin API endpoints for quarantining media. ##### Synapse 1.152.0rc1 (2026-04-22) ##### Features - Add a ["Listing quarantined media changes" Admin API](https://element-hq.github.io/synapse/latest/admin_api/media_admin_api.html#listing-quarantined-media-changes) for retrieving a paginated record of when media became (un)quarantined. ([#&#8203;19558](https://github.com/element-hq/synapse/issues/19558), [#&#8203;19677](https://github.com/element-hq/synapse/issues/19677), [#&#8203;19694](https://github.com/element-hq/synapse/issues/19694)) - Advertise [MSC4445](https://github.com/matrix-org/matrix-spec-proposals/pull/4445) sync timeline order in `unstable_features`. ([#&#8203;19642](https://github.com/element-hq/synapse/issues/19642)) - Report the Rust compiler version used in the Prometheus metrics. Contributed by Noah Markert. ([#&#8203;19643](https://github.com/element-hq/synapse/issues/19643)) - Passthrough 'article' and 'profile' OpenGraph metadata on URL preview requests. ([#&#8203;19659](https://github.com/element-hq/synapse/issues/19659)) - Add a way to re-sign local events with a new signing key. ([#&#8203;19668](https://github.com/element-hq/synapse/issues/19668)) - Support [MSC4450: Identity Provider selection for User-Interactive Authentication with Legacy Single Sign-On](https://github.com/matrix-org/matrix-spec-proposals/pull/4450). ([#&#8203;19693](https://github.com/element-hq/synapse/issues/19693)) - Add experimental support for [MSC4242](https://github.com/matrix-org/matrix-spec-proposals/pull/4242): State DAGs. Excludes federation support. ([#&#8203;19424](https://github.com/element-hq/synapse/issues/19424)) - Adds [Admin API](https://element-hq.github.io/synapse/latest/usage/administration/admin_api/index.html) endpoints to list, fetch and delete user reports. ([#&#8203;19657](https://github.com/element-hq/synapse/issues/19657)) - Reduce database disk space usage by pruning old rows from `device_lists_changes_in_room`. ([#&#8203;19473](https://github.com/element-hq/synapse/issues/19473), [#&#8203;19709](https://github.com/element-hq/synapse/issues/19709)) ##### Bugfixes - Reject `device_keys: null` in the request to [`POST /_matrix/client/v3/keys/upload`](https://spec.matrix.org/v1.16/client-server-api/#post_matrixclientv3keysupload), as per the spec. This was temporarily allowed as a workaround for misbehaving clients. ([#&#8203;19637](https://github.com/element-hq/synapse/issues/19637)) - Fix database migrations failing on platforms where SQLite is configured with `SQLITE_DBCONFIG_DEFENSIVE` by default, such as macOS. ([#&#8203;19690](https://github.com/element-hq/synapse/issues/19690)) - Fix a bug introduced in v1.145 where a non-admin could bypass admin checks for downloading remote quarantined media. This relied on the media already being previously present on the homeserver. ([#&#8203;19639](https://github.com/element-hq/synapse/issues/19639)) ##### Improved Documentation - Include a workaround for running the unit tests with SQLite under recent versions of MacOS. ([#&#8203;19615](https://github.com/element-hq/synapse/issues/19615)) - Fix Docker image link typo in worker docs. ([#&#8203;19645](https://github.com/element-hq/synapse/issues/19645)) - Update the developer stream docs for creating a new stream to point out `_setup_sequence(...)` in `portdb`. ([#&#8203;19675](https://github.com/element-hq/synapse/issues/19675)) - Update the developer stream docs for creating a new stream to highlight places that require documentation updates. ([#&#8203;19696](https://github.com/element-hq/synapse/issues/19696)) ##### Internal Changes - Update CI to use re-usable Complement GitHub CI workflow. ([#&#8203;19533](https://github.com/element-hq/synapse/issues/19533)) - Fix docstring for `limit` argument in `_maybe_backfill_inner(...)`. ([#&#8203;19630](https://github.com/element-hq/synapse/issues/19630)) - Document context for why increase timeout for policy server requests. ([#&#8203;19633](https://github.com/element-hq/synapse/issues/19633)) - Run lint script to format Complement tests introduced in [#&#8203;19509](https://github.com/element-hq/synapse/pull/19509). ([#&#8203;19636](https://github.com/element-hq/synapse/issues/19636)) - Small simplifications to the events class. ([#&#8203;19680](https://github.com/element-hq/synapse/issues/19680), [#&#8203;19712](https://github.com/element-hq/synapse/issues/19712)) - Introduce `spam_checker_spammy` internal event metadata. ([#&#8203;19453](https://github.com/element-hq/synapse/issues/19453)) - Add a `FilteredEvent` class that saves us copying events. ([#&#8203;19640](https://github.com/element-hq/synapse/issues/19640)) - Convert `EventInternalMetadata` to use `Arc<RwLock<_>>`. ([#&#8203;19669](https://github.com/element-hq/synapse/issues/19669)) ### [`v1.151.0`](https://github.com/element-hq/synapse/releases/tag/v1.151.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.150.0...v1.151.0) ##### Synapse 1.151.0 (2026-04-07) ##### Bugfixes - Fix `KNOWN_ROOM_VERSIONS.__contains__` raising `TypeError` for non-string keys, which could cause `/sync` to fail for rooms with a `NULL` room version in the database. Bug introduced in [#&#8203;19589](https://github.com/element-hq/synapse/pull/19589) as part of v1.151.0rc1. ([#&#8203;19649](https://github.com/element-hq/synapse/issues/19649)) ##### Synapse 1.151.0rc1 (2026-03-31) ##### Features - Add stable support for [MSC4284](https://github.com/matrix-org/matrix-spec-proposals/pull/4284) Policy Servers. ([#&#8203;19503](https://github.com/element-hq/synapse/issues/19503)) - Update and stabilize support for [MSC2666](https://github.com/matrix-org/matrix-spec-proposals/pull/2666): Get rooms in common with another user. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19511](https://github.com/element-hq/synapse/issues/19511)) - Updated experimental support for [MSC4388: Secure out-of-band channel for sign in with QR](https://github.com/matrix-org/matrix-spec-proposals/pull/4388). ([#&#8203;19573](https://github.com/element-hq/synapse/issues/19573)) - Stabilize `room_version` and `encryption` fields in the space/room `/hierarchy` API (part of [MSC3266](https://github.com/matrix-org/matrix-spec-proposals/pull/3266)). ([#&#8203;19576](https://github.com/element-hq/synapse/issues/19576)) - Introduce a [configuration option](https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#matrix_authentication_service) to allow using HTTP/2 over plaintext when Synapse connects to Matrix Authentication Service. ([#&#8203;19586](https://github.com/element-hq/synapse/issues/19586)) ##### Bugfixes - Fix [MSC4284](https://github.com/matrix-org/matrix-spec-proposals/pull/4284) Policy Servers implementation to skip signing `org.matrix.msc4284.policy` and `m.room.policy` state events. ([#&#8203;19503](https://github.com/element-hq/synapse/issues/19503)) - Correctly apply [MSC4284](https://github.com/matrix-org/matrix-spec-proposals/pull/4284) Policy Server signatures to events when the sender and policy server have the same server name. ([#&#8203;19503](https://github.com/element-hq/synapse/issues/19503)) - Allow Synapse to start up even when discovery fails for an OpenID Connect provider. ([#&#8203;19509](https://github.com/element-hq/synapse/issues/19509)) - Fix quarantine media admin APIs sometimes returning inaccurate counts for remote media. ([#&#8203;19559](https://github.com/element-hq/synapse/issues/19559)) - Fix `Build and push complement image` CI job not having `poetry` available for the Complement runner script. ([#&#8203;19578](https://github.com/element-hq/synapse/issues/19578)) - Increase timeout for policy server requests to avoid repeated requests for checking media. ([#&#8203;19629](https://github.com/element-hq/synapse/issues/19629)) ##### Deprecations and Removals - Remove support for [MSC3852: Expose user agent information on Device](https://github.com/matrix-org/matrix-spec-proposals/pull/3852) as the MSC was closed. ([#&#8203;19430](https://github.com/element-hq/synapse/issues/19430)) ##### Internal Changes - Fix small comment typo in config output from the `demo/start.sh` script. ([#&#8203;19538](https://github.com/element-hq/synapse/issues/19538)) - Add MSC3820 comment context to `RoomVersion` attributes. ([#&#8203;19577](https://github.com/element-hq/synapse/issues/19577)) - Remove `redacted_because` from internal unsigned. ([#&#8203;19581](https://github.com/element-hq/synapse/issues/19581)) - Prevent sending registration emails if registration is disabled. ([#&#8203;19585](https://github.com/element-hq/synapse/issues/19585)) - Port `RoomVersion` to Rust. ([#&#8203;19589](https://github.com/element-hq/synapse/issues/19589)) - Only show failing Complement tests in the formatted output in CI. ([#&#8203;19590](https://github.com/element-hq/synapse/issues/19590)) - Ensure old Complement test files are removed when downloading a Complement checkout via `./scripts-dev/complement.sh`. ([#&#8203;19592](https://github.com/element-hq/synapse/issues/19592)) - Update `HomeserverTestCase.pump()` docstring to demystify behavior (Twisted reactor/clock). ([#&#8203;19602](https://github.com/element-hq/synapse/issues/19602)) - Deprecate `HomeserverTestCase.pump()` in favor of more direct `HomeserverTestCase.reactor.advance(...)` usage. ([#&#8203;19602](https://github.com/element-hq/synapse/issues/19602)) - Lower the Postgres database `statement_timeout` to 10m (previously 1h). ([#&#8203;19604](https://github.com/element-hq/synapse/issues/19604)) ### [`v1.150.0`](https://github.com/element-hq/synapse/releases/tag/v1.150.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.149.1...v1.150.0) ##### Synapse 1.150.0 (2026-03-24) No significant changes since 1.150.0rc1. ##### Upgrade notes **Please read the [upgrade notes](https://element-hq.github.io/synapse/latest/upgrade.html#upgrading-to-v11500)** as this release includes a few changes that may affect your deployment. ##### Synapse 1.150.0rc1 (2026-03-17) ##### Features - Add experimental support for the [MSC4370](https://github.com/matrix-org/matrix-spec-proposals/pull/4370) Federation API `GET /extremities` endpoint. ([#&#8203;19314](https://github.com/element-hq/synapse/issues/19314)) - [MSC4140: Cancellable delayed events](https://github.com/matrix-org/matrix-spec-proposals/pull/4140): When persisting a delayed event to the timeline, include its `delay_id` in the event's `unsigned` section in `/sync` responses to the event sender. ([#&#8203;19479](https://github.com/element-hq/synapse/issues/19479)) - Expose [MSC4354 Sticky Events](https://github.com/matrix-org/matrix-spec-proposals/pull/4354) over the legacy (v3) /sync API. ([#&#8203;19487](https://github.com/element-hq/synapse/issues/19487)) - When Matrix Authentication Service (MAS) integration is enabled, allow MAS to set the user locked status in Synapse. ([#&#8203;19554](https://github.com/element-hq/synapse/issues/19554)) ##### Bugfixes - Fix `Build and push complement image` CI job pointing to non-existent image. ([#&#8203;19523](https://github.com/element-hq/synapse/issues/19523)) - Fix a bug introduced in v1.26.0 that caused deactivated, erased users to not be removed from the user directory. ([#&#8203;19542](https://github.com/element-hq/synapse/issues/19542)) ##### Improved Documentation - In the Admin API documentation, always express path parameters as `/<param>` instead of as `/$param`. ([#&#8203;19307](https://github.com/element-hq/synapse/issues/19307)) - Update docs to clarify `outbound_federation_restricted_to` can also be used with the [Secure Border Gateway (SBG)](https://element.io/en/server-suite/secure-border-gateways). ([#&#8203;19517](https://github.com/element-hq/synapse/issues/19517)) - Unify Complement developer docs. ([#&#8203;19518](https://github.com/element-hq/synapse/issues/19518)) ##### Internal Changes - Put membership updates in a background resumable task when changing the avatar or the display name. ([#&#8203;19311](https://github.com/element-hq/synapse/issues/19311)) - Add in-repo Complement test to sanity check Synapse version matches git checkout (testing what we think we are). ([#&#8203;19476](https://github.com/element-hq/synapse/issues/19476)) - Migrate `dev` dependencies to [PEP 735](https://peps.python.org/pep-0735/) dependency groups. ([#&#8203;19490](https://github.com/element-hq/synapse/issues/19490)) - Remove the optional `systemd-python` dependency and the `systemd` extra on the `synapse` package. ([#&#8203;19491](https://github.com/element-hq/synapse/issues/19491)) - Avoid re-computing the event ID when cloning events. ([#&#8203;19527](https://github.com/element-hq/synapse/issues/19527)) - Allow caching of the `/versions` and `/auth_metadata` public endpoints. ([#&#8203;19530](https://github.com/element-hq/synapse/issues/19530)) - Add a few labels to the number groupings in the `Processed request` logs. ([#&#8203;19548](https://github.com/element-hq/synapse/issues/19548)) ### [`v1.149.1`](https://github.com/element-hq/synapse/releases/tag/v1.149.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.149.0...v1.149.1) ##### Synapse 1.149.1 (2026-03-11) ##### Internal Changes - Bump `matrix-synapse-ldap3` to `0.4.0` to support `setuptools>=82.0.0`. Fixes [#&#8203;19541](https://github.com/element-hq/synapse/issues/19541). ([#&#8203;19543](https://github.com/element-hq/synapse/issues/19543)) ### [`v1.149.0`](https://github.com/element-hq/synapse/releases/tag/v1.149.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.148.0...v1.149.0) ##### Synapse 1.149.0 (2026-03-10) No significant changes since 1.149.0rc1. ##### Synapse 1.149.0rc1 (2026-03-03) ##### Features - Add experimental support for [MSC4388: Secure out-of-band channel for sign in with QR](https://github.com/matrix-org/matrix-spec-proposals/pull/4388). ([#&#8203;19127](https://github.com/element-hq/synapse/issues/19127)) - Add stable support for [MSC4380](https://github.com/matrix-org/matrix-spec-proposals/pull/4380) invite blocking. ([#&#8203;19431](https://github.com/element-hq/synapse/issues/19431)) ##### Bugfixes - Fix the 'Login as a user' Admin API not checking if the user exists before issuing an access token. ([#&#8203;18518](https://github.com/element-hq/synapse/issues/18518)) - Fix `/sync` missing membership event in `state_after` (experimental [MSC4222](https://github.com/matrix-org/matrix-spec-proposals/pull/4222) implementation) in some scenarios. ([#&#8203;19460](https://github.com/element-hq/synapse/issues/19460)) ##### Internal Changes - Add log to explain when and why we freeze objects in the garbage collector. ([#&#8203;19440](https://github.com/element-hq/synapse/issues/19440)) - Better instrument `JoinRoomAliasServlet` with tracing. ([#&#8203;19461](https://github.com/element-hq/synapse/issues/19461)) - Fix Complement CI not running against the code from our PRs. ([#&#8203;19475](https://github.com/element-hq/synapse/issues/19475)) - Log `docker system info` in CI so we have a plain record of how GitHub runners evolve over time. ([#&#8203;19480](https://github.com/element-hq/synapse/issues/19480)) - Rename the `test_disconnect` test helper so that pytest doesn't see it as a test. ([#&#8203;19486](https://github.com/element-hq/synapse/issues/19486)) - Add a log line when we delete devices. Contributed by [@&#8203;bradtgmurray](https://github.com/bradtgmurray) @&#8203; Beeper. ([#&#8203;19496](https://github.com/element-hq/synapse/issues/19496)) - Pre-allocate the buffer based on the expected `Content-Length` with the Rust HTTP client. ([#&#8203;19498](https://github.com/element-hq/synapse/issues/19498)) - Cancel long-running sync requests if the client has gone away. ([#&#8203;19499](https://github.com/element-hq/synapse/issues/19499)) - Try and reduce reactor tick times when under heavy load. ([#&#8203;19507](https://github.com/element-hq/synapse/issues/19507)) - Simplify Rust HTTP client response streaming and limiting. ([#&#8203;19510](https://github.com/element-hq/synapse/issues/19510)) - Replace deprecated collection import locations with current locations. ([#&#8203;19515](https://github.com/element-hq/synapse/issues/19515)) - Bump most locked Python dependencies to their latest versions. ([#&#8203;19519](https://github.com/element-hq/synapse/issues/19519)) ### [`v1.148.0`](https://github.com/element-hq/synapse/releases/tag/v1.148.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.147.1...v1.148.0) ##### Synapse 1.148.0 (2026-02-24) No significant changes since 1.148.0rc1. ##### Synapse 1.148.0rc1 (2026-02-17) ##### Features - Support sending and receiving [MSC4354 Sticky Event](https://github.com/matrix-org/matrix-spec-proposals/pull/4354) metadata. ([#&#8203;19365](https://github.com/element-hq/synapse/issues/19365)) ##### Improved Documentation - Fix reference to the `experimental_features` section of the configuration manual documentation. ([#&#8203;19435](https://github.com/element-hq/synapse/issues/19435)) ##### Deprecations and Removals - Remove support for [MSC3244: Room version capabilities](https://github.com/matrix-org/matrix-spec-proposals/pull/3244) as the MSC was rejected. ([#&#8203;19429](https://github.com/element-hq/synapse/issues/19429)) ##### Internal Changes - Add in-repo Complement tests so we can test Synapse specific behavior at an end-to-end level. ([#&#8203;19406](https://github.com/element-hq/synapse/issues/19406)) - Push Synapse docker images to Element OCI Registry. ([#&#8203;19420](https://github.com/element-hq/synapse/issues/19420)) - Allow configuring the Rust HTTP client to use HTTP/2 only. ([#&#8203;19457](https://github.com/element-hq/synapse/issues/19457)) - Correctly refuse to start if the Rust workspace config has changed and the Rust library has not been rebuilt. ([#&#8203;19470](https://github.com/element-hq/synapse/issues/19470)) ### [`v1.147.1`](https://github.com/element-hq/synapse/releases/tag/v1.147.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.147.0...v1.147.1) ##### Synapse 1.147.1 (2026-02-12) - Block federation requests and events authenticated using a known insecure signing key. See [CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) / [ELEMENTSEC-2025-1670](https://github.com/element-hq/ess-helm/security/advisories/GHSA-qwcj-h6m8-vp6q). ([#&#8203;19459](https://github.com/element-hq/synapse/issues/19459)) ### [`v1.147.0`](https://github.com/element-hq/synapse/releases/tag/v1.147.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.146.0...v1.147.0) ##### Synapse 1.147.0 (2026-02-10) No significant changes since 1.147.0rc1. ##### Synapse 1.147.0rc1 (2026-02-03) ##### Bugfixes - Fix memory leak caused by not cleaning up stopped looping calls. Introduced in v1.140.0. ([#&#8203;19416](https://github.com/element-hq/synapse/issues/19416)) - Fix a typo that incorrectly made `setuptools_rust` a runtime dependency. ([#&#8203;19417](https://github.com/element-hq/synapse/issues/19417)) ##### Internal Changes - Prune stale entries from `sliding_sync_connection_required_state` table. ([#&#8203;19306](https://github.com/element-hq/synapse/issues/19306)) - Update "Event Send Time Quantiles" graph to only use dots for the event persistence rate (Grafana dashboard). ([#&#8203;19399](https://github.com/element-hq/synapse/issues/19399)) - Update and align Grafana dashboard to use regex matching for `job` selectors (`job=~"$job"`) so the "all" value works correctly across all panels. ([#&#8203;19400](https://github.com/element-hq/synapse/issues/19400)) - Don't retry joining partial state rooms all at once on startup. ([#&#8203;19402](https://github.com/element-hq/synapse/issues/19402)) - Disallow requests to the health endpoint from containing trailing path characters. ([#&#8203;19405](https://github.com/element-hq/synapse/issues/19405)) - Add notes that new experimental features should have associated tracking issues. ([#&#8203;19410](https://github.com/element-hq/synapse/issues/19410)) - Bump `pyo3` from 0.26.0 to 0.27.2 and `pythonize` from 0.26.0 to 0.27.0. Contributed by [@&#8203;razvp](https://github.com/razvp) @&#8203; ERCOM. ([#&#8203;19412](https://github.com/element-hq/synapse/issues/19412)) ### [`v1.146.0`](https://github.com/element-hq/synapse/releases/tag/v1.146.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.145.0...v1.146.0) ##### Synapse 1.146.0 (2026-01-27) No significant changes since 1.146.0rc1. ##### Deprecations and Removals - [MSC2697](https://github.com/matrix-org/matrix-spec-proposals/pull/2697) (Dehydrated devices) has been removed, as the MSC is closed. Developers should migrate to [MSC3814](https://github.com/matrix-org/matrix-spec-proposals/pull/3814). ([#&#8203;19346](https://github.com/element-hq/synapse/issues/19346)) - Support for Ubuntu 25.04 (Plucky Puffin) has been dropped. Synapse no longer builds debian packages for Ubuntu 25.04. ##### Synapse 1.146.0rc1 (2026-01-20) ##### Features - Add a new config option [`enable_local_media_storage`](https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#enable_local_media_storage) which controls whether media is additionally stored locally when using configured `media_storage_providers`. Setting this to `false` allows off-site media storage without a local cache. Contributed by Patrice Brend'amour [@&#8203;dr](https://github.com/dr).allgood. ([#&#8203;19204](https://github.com/element-hq/synapse/issues/19204)) - Stabilise support for [MSC4312](https://github.com/matrix-org/matrix-spec-proposals/pull/4312)'s `m.oauth` User-Interactive Auth stage for resetting cross-signing identity with the OAuth 2.0 API. The old, unstable name (`org.matrix.cross_signing_reset`) is now deprecated and will be removed in a future release. ([#&#8203;19273](https://github.com/element-hq/synapse/issues/19273)) - Refactor Grafana dashboard to use `server_name` label (instead of `instance`). ([#&#8203;19337](https://github.com/element-hq/synapse/issues/19337)) ##### Bugfixes - Fix joining a restricted v12 room locally when no local room creator is present but local users with sufficient power levels are. Contributed by [@&#8203;nexy7574](https://github.com/nexy7574). ([#&#8203;19321](https://github.com/element-hq/synapse/issues/19321)) - Fixed parallel calls to `/_matrix/media/v1/create` being ratelimited for appservices even if `rate_limited: false` was set in the registration. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19335](https://github.com/element-hq/synapse/issues/19335)) - Fix a bug introduced in 1.61.0 where a user's membership in a room was accidentally ignored when considering access to historical state events in rooms with the "shared" history visibility. Contributed by Lukas Tautz. ([#&#8203;19353](https://github.com/element-hq/synapse/issues/19353)) - [MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140): Store the JSON content of scheduled delayed events as text instead of a byte array. This fixes the inability to schedule a delayed event with non-ASCII characters in its content. ([#&#8203;19360](https://github.com/element-hq/synapse/issues/19360)) - Always rollback database transactions when retrying (avoid orphaned connections). ([#&#8203;19372](https://github.com/element-hq/synapse/issues/19372)) - Fix `InFlightGauge` typing to allow upgrading to `prometheus_client` 0.24. ([#&#8203;19379](https://github.com/element-hq/synapse/issues/19379)) ##### Updates to the Docker image - Add [Prometheus HTTP service discovery](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#http_sd_config) endpoint for easy discovery of all workers when using the `docker/Dockerfile-workers` image (see the [*Metrics* section of our Docker testing docs](docker/README-testing.md#metrics)). ([#&#8203;19336](https://github.com/element-hq/synapse/issues/19336)) ##### Improved Documentation - Remove docs on legacy metric names (no longer in the codebase since 2022-12-06). ([#&#8203;19341](https://github.com/element-hq/synapse/issues/19341)) - Clarify how the estimated value of room complexity is calculated internally. ([#&#8203;19384](https://github.com/element-hq/synapse/issues/19384)) ##### Internal Changes - Add an internal `cancel_task` API to the task scheduler. ([#&#8203;19310](https://github.com/element-hq/synapse/issues/19310)) - Tweak docstrings and signatures of `auth_types_for_event` and `get_catchup_room_event_ids`. ([#&#8203;19320](https://github.com/element-hq/synapse/issues/19320)) - Replace usage of deprecated `assertEquals` with `assertEqual` in unit test code. ([#&#8203;19345](https://github.com/element-hq/synapse/issues/19345)) - Drop support for Ubuntu 25.04 'Plucky Puffin', add support for Ubuntu 25.10 'Questing Quokka'. ([#&#8203;19348](https://github.com/element-hq/synapse/issues/19348)) - Revert "Add an Admin API endpoint for listing quarantined media ([#&#8203;19268](https://github.com/element-hq/synapse/issues/19268))". ([#&#8203;19351](https://github.com/element-hq/synapse/issues/19351)) - Bump `mdbook` from 0.4.17 to 0.5.2 and remove our custom table-of-contents plugin in favour of the new default functionality. ([#&#8203;19356](https://github.com/element-hq/synapse/issues/19356)) - Replace deprecated usage of PyGitHub's `GitRelease.title` with `.name` in release script. ([#&#8203;19358](https://github.com/element-hq/synapse/issues/19358)) - Update the Element logo in Synapse's README to be an absolute URL, allowing it to render on other sites (such as PyPI). ([#&#8203;19368](https://github.com/element-hq/synapse/issues/19368)) - Apply minor tweaks to v1.145.0 changelog. ([#&#8203;19376](https://github.com/element-hq/synapse/issues/19376)) - Update Grafana dashboard syntax to use the latest from importing/exporting with Grafana 12.3.1. ([#&#8203;19381](https://github.com/element-hq/synapse/issues/19381)) - Warn about skipping reactor metrics when using unknown reactor type. ([#&#8203;19383](https://github.com/element-hq/synapse/issues/19383)) - Add support for reactor metrics with the `ProxiedReactor` used in worker Complement tests. ([#&#8203;19385](https://github.com/element-hq/synapse/issues/19385)) ### [`v1.145.0`](https://github.com/element-hq/synapse/releases/tag/v1.145.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.144.0...v1.145.0) ##### Synapse 1.145.0 (2026-01-13) No significant changes since 1.145.0rc4. ##### End of Life of Ubuntu 25.04 Plucky Puffin Ubuntu 25.04 (Plucky Puffin) will be end of life on Jan 17, 2026. Synapse will stop building packages for Ubuntu 25.04 shortly thereafter. ##### Updates to Locked Dependencies No Longer Included in Changelog The "Updates to locked dependencies" section has been removed from the changelog due to lack of use and the maintenance burden. ([#&#8203;19254](https://github.com/element-hq/synapse/issues/19254)) ##### Synapse 1.145.0rc4 (2026-01-08) No significant changes since 1.145.0rc3. This RC contains a fix specifically for openSUSE packaging and no other changes. ##### Synapse 1.145.0rc3 (2026-01-07) No significant changes since 1.145.0rc2. This RC strips out unnecessary files from the wheels that were added when fixing the source distribution packaging in the previous RC. ##### Synapse 1.145.0rc2 (2026-01-07) No significant changes since 1.145.0rc1. This RC fixes the source distribution packaging for uploading to PyPI. ##### Synapse 1.145.0rc1 (2026-01-06) ##### Features - Add `memberships` endpoint to the admin API. This is useful for forensics and T\&S purposes. ([#&#8203;19260](https://github.com/element-hq/synapse/issues/19260)) - Server admins can bypass the quarantine media check when downloading media by setting the `admin_unsafely_bypass_quarantine` query parameter to `true` on Client-Server API media download requests. ([#&#8203;19275](https://github.com/element-hq/synapse/issues/19275)) - Implemented pagination for the [MSC2666](https://github.com/matrix-org/matrix-spec-proposals/pull/2666) mutual rooms endpoint. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19279](https://github.com/element-hq/synapse/issues/19279)) - Admin API: add worker support to `GET /_synapse/admin/v2/users/<user_id>`. ([#&#8203;19281](https://github.com/element-hq/synapse/issues/19281)) - Improve proxy support for the `federation_client.py` dev script. Contributed by Denis Kasak ([@&#8203;dkasak](https://github.com/dkasak)). ([#&#8203;19300](https://github.com/element-hq/synapse/issues/19300)) ##### Bugfixes - Fix sliding sync performance slow down for long lived connections. ([#&#8203;19206](https://github.com/element-hq/synapse/issues/19206)) - Fix a bug where Mastodon posts (and possibly other embeds) have the wrong description for URL previews. ([#&#8203;19231](https://github.com/element-hq/synapse/issues/19231)) - Fix bug where `Duration` was logged incorrectly. ([#&#8203;19267](https://github.com/element-hq/synapse/issues/19267)) - Fix bug introduced in 1.143.0 that broke support for versions of `zope-interface` older than 6.2. ([#&#8203;19274](https://github.com/element-hq/synapse/issues/19274)) - Transform events with client metadata before serialising in /event response. ([#&#8203;19340](https://github.com/element-hq/synapse/issues/19340)) ##### Updates to the Docker image - Add a way to expose metrics from the Docker image (`SYNAPSE_ENABLE_METRICS`). ([#&#8203;19324](https://github.com/element-hq/synapse/issues/19324)) ##### Improved Documentation - Document the importance of `public_baseurl` when configuring OpenID Connect authentication. ([#&#8203;19270](https://github.com/element-hq/synapse/issues/19270)) ##### Deprecations and Removals - Ubuntu 25.04 (Plucky Puffin) will be end of life on Jan 17, 2026. Synapse will stop building packages for Ubuntu 25.04 shortly thereafter. - Remove the "Updates to locked dependencies" section from the changelog due to lack of use and the maintenance burden. ([#&#8203;19254](https://github.com/element-hq/synapse/issues/19254)) ##### Internal Changes - Group together dependabot update PRs to reduce the review load. ([#&#8203;18402](https://github.com/element-hq/synapse/issues/18402)) - Fix `HomeServer.shutdown()` failing if the homeserver hasn't been setup yet. ([#&#8203;19187](https://github.com/element-hq/synapse/issues/19187)) - Respond with useful error codes with `Content-Length` header/s are invalid. ([#&#8203;19212](https://github.com/element-hq/synapse/issues/19212)) - Fix `HomeServer.shutdown()` failing if the homeserver failed to `start`. ([#&#8203;19232](https://github.com/element-hq/synapse/issues/19232)) - Switch the build backend from `poetry-core` to `maturin`. ([#&#8203;19234](https://github.com/element-hq/synapse/issues/19234)) - Raise the limit for concurrently-open non-security [@&#8203;dependabot](https://github.com/dependabot) PRs from 5 to 10. ([#&#8203;19253](https://github.com/element-hq/synapse/issues/19253)) - Require 14 days to pass before pulling in general dependency updates to help mitigate upstream supply chain attacks. ([#&#8203;19258](https://github.com/element-hq/synapse/issues/19258)) - Drop the broken netlify documentation workflow until a new one is implemented. ([#&#8203;19262](https://github.com/element-hq/synapse/issues/19262)) - Don't include debug logs in `Clock` unless explicitly enabled. ([#&#8203;19278](https://github.com/element-hq/synapse/issues/19278)) - Use `uv` to test olddeps to ensure all transitive dependencies use minimum versions. ([#&#8203;19289](https://github.com/element-hq/synapse/issues/19289)) - Add a config to be able to rate limit search in the user directory. ([#&#8203;19291](https://github.com/element-hq/synapse/issues/19291)) - Log the original bind exception when encountering `Failed to listen on 0.0.0.0, continuing because listening on [::]`. ([#&#8203;19297](https://github.com/element-hq/synapse/issues/19297)) - Unpin the version of Rust we use to build Synapse wheels (was 1.82.0) now that MacOS support has been dropped. ([#&#8203;19302](https://github.com/element-hq/synapse/issues/19302)) - Make it more clear how `shared_extra_conf` is combined in our Docker configuration scripts. ([#&#8203;19323](https://github.com/element-hq/synapse/issues/19323)) - Update CI to stream Complement progress and format logs in a separate step after all tests are done. ([#&#8203;19326](https://github.com/element-hq/synapse/issues/19326)) - Format `.github/workflows/tests.yml`. ([#&#8203;19327](https://github.com/element-hq/synapse/issues/19327)) ### [`v1.144.0`](https://github.com/element-hq/synapse/releases/tag/v1.144.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.143.0...v1.144.0) ##### Synapse 1.144.0 (2025-12-09) ##### Deprecation of MacOS Python wheels The team has decided to deprecate and stop publishing python wheels for MacOS as of this release. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler). ##### Unstable mutual rooms endpoint is now behind an experimental feature flag Admins using the unstable [MSC2666](https://github.com/matrix-org/matrix-spec-proposals/pull/2666) endpoint (`/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms`), please check [the relevant section in the upgrade notes](https://github.com/element-hq/synapse/blob/develop/docs/upgrade.md#upgrading-to-v11440) as this release contains changes that disable that endpoint by default. No significant changes since 1.144.0rc1. ##### Synapse 1.144.0rc1 (2025-12-02) Admins using the unstable [MSC2666](https://github.com/matrix-org/matrix-spec-proposals/pull/2666) endpoint (`/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms`), please check [the relevant section in the upgrade notes](https://github.com/element-hq/synapse/blob/develop/docs/upgrade.md#upgrading-to-v11440) as this release contains changes that disable that endpoint by default. ##### Features - Add experimental implementation of [MSC4380](https://github.com/matrix-org/matrix-spec-proposals/pull/4380) (invite blocking). ([#&#8203;19203](https://github.com/element-hq/synapse/issues/19203)) - Allow restarting delayed event timeouts on workers. ([#&#8203;19207](https://github.com/element-hq/synapse/issues/19207)) ##### Bugfixes - Fix a bug in the database function for fetching state deltas that could result in unnecessarily long query times. ([#&#8203;18960](https://github.com/element-hq/synapse/issues/18960)) - Fix v12 rooms when running with `use_frozen_dicts: True`. ([#&#8203;19235](https://github.com/element-hq/synapse/issues/19235)) - Fix bug where invalid `canonical_alias` content would return 500 instead of 400. ([#&#8203;19240](https://github.com/element-hq/synapse/issues/19240)) - Fix bug where `Duration` was logged incorrectly. ([#&#8203;19267](https://github.com/element-hq/synapse/issues/19267)) ##### Improved Documentation - Document in the `--config-path` help how multiple files are merged - by merging them shallowly. ([#&#8203;19243](https://github.com/element-hq/synapse/issues/19243)) ##### Deprecations and Removals - Stop building release wheels for MacOS. ([#&#8203;19225](https://github.com/element-hq/synapse/issues/19225)) ##### Internal Changes - Improve event filtering for Simplified Sliding Sync. ([#&#8203;17782](https://github.com/element-hq/synapse/issues/17782)) - Export `SYNAPSE_SUPPORTED_COMPLEMENT_TEST_PACKAGES` environment variable from `scripts-dev/complement.sh`. ([#&#8203;19208](https://github.com/element-hq/synapse/issues/19208)) - Refactor `scripts-dev/complement.sh` logic to avoid `exit` to facilitate being able to source it from other scripts (composable). ([#&#8203;19209](https://github.com/element-hq/synapse/issues/19209)) - Expire sliding sync connections that are too old or have too much pending data. ([#&#8203;19211](https://github.com/element-hq/synapse/issues/19211)) - Require an experimental feature flag to be enabled in order for the unstable [MSC2666](https://github.com/matrix-org/matrix-spec-proposals/pull/2666) endpoint (`/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms`) to be available. ([#&#8203;19219](https://github.com/element-hq/synapse/issues/19219)) - Prevent changelog check CI running on [@&#8203;dependabot](https://github.com/dependabot)'s PRs even when a human has modified the branch. ([#&#8203;19220](https://github.com/element-hq/synapse/issues/19220)) - Auto-fix trailing spaces in multi-line strings and comments when running the lint script. ([#&#8203;19221](https://github.com/element-hq/synapse/issues/19221)) - Move towards using a dedicated `Duration` type. ([#&#8203;19223](https://github.com/element-hq/synapse/issues/19223), [#&#8203;19229](https://github.com/element-hq/synapse/issues/19229)) - Improve robustness of the SQL schema linting in CI. ([#&#8203;19224](https://github.com/element-hq/synapse/issues/19224)) - Add log to determine whether clients are using `/messages` as expected. ([#&#8203;19226](https://github.com/element-hq/synapse/issues/19226)) - Simplify README and add ESS Getting started section. ([#&#8203;19228](https://github.com/element-hq/synapse/issues/19228), [#&#8203;19259](https://github.com/element-hq/synapse/issues/19259)) - Add a unit test for ensuring associated refresh tokens are erased when a device is deleted. ([#&#8203;19230](https://github.com/element-hq/synapse/issues/19230)) - Prompt user to consider adding future deprecations to the changelog in release script. ([#&#8203;19239](https://github.com/element-hq/synapse/issues/19239)) - Fix check of the Rust compiled code being outdated when using source checkout and `.egg-info`. ([#&#8203;19251](https://github.com/element-hq/synapse/issues/19251)) - Stop building MacOS wheels in CI pipeline. ([#&#8203;19263](https://github.com/element-hq/synapse/issues/19263)) ##### Updates to locked dependencies - Bump Swatinem/rust-cache from 2.8.1 to 2.8.2. ([#&#8203;19244](https://github.com/element-hq/synapse/issues/19244)) - Bump actions/checkout from 5.0.0 to 6.0.0. ([#&#8203;19213](https://github.com/element-hq/synapse/issues/19213)) - Bump actions/setup-go from 6.0.0 to 6.1.0. ([#&#8203;19214](https://github.com/element-hq/synapse/issues/19214)) - Bump actions/setup-python from 6.0.0 to 6.1.0. ([#&#8203;19245](https://github.com/element-hq/synapse/issues/19245)) - Bump attrs from 25.3.0 to 25.4.0. ([#&#8203;19215](https://github.com/element-hq/synapse/issues/19215)) - Bump docker/metadata-action from 5.9.0 to 5.10.0. ([#&#8203;19246](https://github.com/element-hq/synapse/issues/19246)) - Bump http from 1.3.1 to 1.4.0. ([#&#8203;19249](https://github.com/element-hq/synapse/issues/19249)) - Bump pydantic from 2.12.4 to 2.12.5. ([#&#8203;19250](https://github.com/element-hq/synapse/issues/19250)) - Bump pyopenssl from 25.1.0 to 25.3.0. ([#&#8203;19248](https://github.com/element-hq/synapse/issues/19248)) - Bump rpds-py from 0.28.0 to 0.29.0. ([#&#8203;19216](https://github.com/element-hq/synapse/issues/19216)) - Bump rpds-py from 0.29.0 to 0.30.0. ([#&#8203;19247](https://github.com/element-hq/synapse/issues/19247)) - Bump sentry-sdk from 2.44.0 to 2.46.0. ([#&#8203;19218](https://github.com/element-hq/synapse/issues/19218)) - Bump types-bleach from 6.2.0.20250809 to 6.3.0.20251115. ([#&#8203;19217](https://github.com/element-hq/synapse/issues/19217)) - Bump types-jsonschema from 4.25.1.20250822 to 4.25.1.20251009. ([#&#8203;19252](https://github.com/element-hq/synapse/issues/19252)) ### [`v1.143.0`](https://github.com/element-hq/synapse/releases/tag/v1.143.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.142.1...v1.143.0) ##### Synapse 1.143.0 (2025-11-25) ##### Dropping support for PostgreSQL 13 In line with our [deprecation policy](https://github.com/element-hq/synapse/blob/develop/docs/deprecation_policy.md), we've dropped support for PostgreSQL 13, as it is no longer supported upstream. This release of Synapse requires PostgreSQL 14+. No significant changes since 1.143.0rc2. ##### synapse 1.143.0rc2 (2025-11-18) ##### Internal Changes - Fixes docker image creation in the release workflow. ##### Synapse 1.143.0rc1 (2025-11-18) ##### Features - Support multiple config files in `register_new_matrix_user`. ([#&#8203;18784](https://github.com/element-hq/synapse/issues/18784)) - Remove authentication from `POST /_matrix/client/v1/delayed_events`, and allow calling this endpoint with the update action to take (`send`/`cancel`/`restart`) in the request path instead of the body. ([#&#8203;19152](https://github.com/element-hq/synapse/issues/19152)) ##### Bugfixes - Fixed a longstanding bug where background updates were only run on the `main` database. ([#&#8203;19181](https://github.com/element-hq/synapse/issues/19181)) - Fixed a bug introduced in v1.142.0 preventing subpaths in MAS endpoints from working. ([#&#8203;19186](https://github.com/element-hq/synapse/issues/19186)) - Fix the SQLite-to-PostgreSQL migration script to correctly migrate a boolean column in the `delayed_events` table. ([#&#8203;19155](https://github.com/element-hq/synapse/issues/19155)) ##### Improved Documentation - Improve documentation around streams, particularly ID generators and adding new streams. ([#&#8203;18943](https://github.com/element-hq/synapse/issues/18943)) ##### Deprecations and Removals - Remove support for PostgreSQL 13. ([#&#8203;19170](https://github.com/element-hq/synapse/issues/19170)) ##### Internal Changes - Provide additional servers with federation room directory results. ([#&#8203;18970](https://github.com/element-hq/synapse/issues/18970)) - Add a shortcut return when there are no events to purge. ([#&#8203;19093](https://github.com/element-hq/synapse/issues/19093)) - Write union types as `X | Y` where possible, as per PEP 604, added in Python 3.10. ([#&#8203;19111](https://github.com/element-hq/synapse/issues/19111)) - Reduce cardinality of `synapse_storage_events_persisted_events_sep_total` metric by removing `origin_entity` label. This also separates out events sent by local application services by changing the `origin_type` for such events to `application_service`. The `type` field also only tracks common event types, and anything else is bucketed under `*other*`. ([#&#8203;19133](https://github.com/element-hq/synapse/issues/19133), [#&#8203;19168](https://github.com/element-hq/synapse/issues/19168)) - Run trial tests on Python 3.14 for PRs. ([#&#8203;19135](https://github.com/element-hq/synapse/issues/19135)) - Update `pyproject.toml` project metadata to be compatible with standard Python packaging tooling. ([#&#8203;19137](https://github.com/element-hq/synapse/issues/19137)) - Minor speed up of processing of inbound replication. ([#&#8203;19138](https://github.com/element-hq/synapse/issues/19138), [#&#8203;19145](https://github.com/element-hq/synapse/issues/19145), [#&#8203;19146](https://github.com/element-hq/synapse/issues/19146)) - Ignore recent Python language refactors from git blame (`.git-blame-ignore-revs`). ([#&#8203;19150](https://github.com/element-hq/synapse/issues/19150)) - Bump lower bounds of dependencies `parameterized` to `0.9.0` and `idna` to `3.3` as those are the first to advertise support for Python 3.10. ([#&#8203;19167](https://github.com/element-hq/synapse/issues/19167)) - Point out which event caused the exception when checking [MSC4293](https://github.com/matrix-org/matrix-spec-proposals/pull/4293) redactions. ([#&#8203;19169](https://github.com/element-hq/synapse/issues/19169)) - Restore printing `sentinel` for the log record `request` when no logcontext is active. ([#&#8203;19172](https://github.com/element-hq/synapse/issues/19172)) - Add debug logs to track `Clock` utilities. ([#&#8203;19173](https://github.com/element-hq/synapse/issues/19173)) - Remove explicit python version skips in `cibuildwheel` config as it's no longer required after [#&#8203;19137](https://github.com/element-hq/synapse/pull/19137). ([#&#8203;19177](https://github.com/element-hq/synapse/issues/19177)) - Fix potential lost logcontext when `PerDestinationQueue.shutdown(...)` is called. ([#&#8203;19178](https://github.com/element-hq/synapse/issues/19178)) - Fix bad deferred logcontext handling across the codebase. ([#&#8203;19180](https://github.com/element-hq/synapse/issues/19180)) ##### Updates to locked dependencies - Bump bytes from 1.10.1 to 1.11.0. ([#&#8203;19193](https://github.com/element-hq/synapse/issues/19193)) - Bump click from 8.1.8 to 8.3.1. ([#&#8203;19195](https://github.com/element-hq/synapse/issues/19195)) - Bump cryptography from 43.0.3 to 45.0.7. ([#&#8203;19159](https://github.com/element-hq/synapse/issues/19159)) - Bump docker/metadata-action from 5.8.0 to 5.9.0. ([#&#8203;19161](https://github.com/element-hq/synapse/issues/19161)) - Bump pydantic from 2.12.3 to 2.12.4. ([#&#8203;19158](https://github.com/element-hq/synapse/issues/19158)) - Bump pyo3-log from 0.13.1 to 0.13.2. ([#&#8203;19156](https://github.com/element-hq/synapse/issues/19156)) - Bump ruff from 0.14.3 to 0.14.5. ([#&#8203;19196](https://github.com/element-hq/synapse/issues/19196)) - Bump sentry-sdk from 2.34.1 to 2.43.0. ([#&#8203;19157](https://github.com/element-hq/synapse/issues/19157)) - Bump sentry-sdk from 2.43.0 to 2.44.0. ([#&#8203;19197](https://github.com/element-hq/synapse/issues/19197)) - Bump tomli from 2.2.1 to 2.3.0. ([#&#8203;19194](https://github.com/element-hq/synapse/issues/19194)) - Bump types-netaddr from 1.3.0.20240530 to 1.3.0.20251108. ([#&#8203;19160](https://github.com/element-hq/synapse/issues/19160)) ### [`v1.142.1`](https://github.com/element-hq/synapse/releases/tag/v1.142.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.142.0...v1.142.1) ##### Synapse 1.142.1 (2025-11-18) ##### Bugfixes - Fixed a bug introduced in v1.142.0 preventing subpaths in MAS endpoints from working. ([#&#8203;19186](https://github.com/element-hq/synapse/issues/19186)) ### [`v1.142.0`](https://github.com/element-hq/synapse/releases/tag/v1.142.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.141.0...v1.142.0) ##### Synapse 1.142.0 (2025-11-11) ##### Dropped support for Python 3.9 This release drops support for Python 3.9, in line with our [dependency deprecation policy](https://element-hq.github.io/synapse/latest/deprecation_policy.html#platform-dependencies), as it is now [end of life](https://endoflife.date/python). ##### SQLite 3.40.0+ is now required The minimum supported SQLite version has been increased from 3.27.0 to 3.40.0. If you use current versions of the [matrixorg/synapse](setup/installation.html#docker-images-and-ansible-playbooks) Docker images, no action is required. ##### Deprecation of MacOS Python wheels The team has decided to deprecate and eventually stop publishing python wheels for MacOS. This is a burden on the team, and we're not aware of any parties that use them. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler). At present, publishing MacOS Python wheels will continue for the next release (1.143.0), but will not be available after that (1.144.0+). If you do make use of these wheels downstream, please reach out to us in [#synapse-dev:matrix.org](https://matrix.to/#/#synapse-dev:matrix.org). We'd love to hear from you! ##### Internal Changes - Properly stop building wheels for Python 3.9 and free-threaded CPython. ([#&#8203;19154](https://github.com/element-hq/synapse/issues/19154)) ##### Synapse 1.142.0rc4 (2025-11-07) ##### Bugfixes - Fix a bug introduced in 1.142.0rc1 where any attempt to configure `matrix_authentication_service.secret_path` would prevent the homeserver from starting up. ([#&#8203;19144](https://github.com/element-hq/synapse/issues/19144)) ##### Synapse 1.142.0rc3 (2025-11-04) ##### Internal Changes - Update release scripts to prevent building wheels for free-threaded Python, as Synapse does not currently support it. ([#&#8203;19140](https://github.com/element-hq/synapse/issues/19140)) ##### Synapse 1.142.0rc2 (2025-11-04) ##### Internal Changes - Manually skip building Python 3.9 wheels, to prevent errors in the release workflow. ([#&#8203;19119](https://github.com/element-hq/synapse/issues/19119)) ##### Synapse 1.142.0rc1 (2025-11-04) ##### Features - Add support for Python 3.14. ([#&#8203;19055](https://github.com/element-hq/synapse/issues/19055), [#&#8203;19134](https://github.com/element-hq/synapse/issues/19134)) - Add an [Admin API](https://element-hq.github.io/synapse/latest/usage/administration/admin_api/index.html) to allow an admin to fetch the space/room hierarchy for a given space. ([#&#8203;19021](https://github.com/element-hq/synapse/issues/19021)) ##### Bugfixes - Fix a bug introduced in 1.111.0 where failed attempts to download authenticated remote media would not be handled correctly. ([#&#8203;19062](https://github.com/element-hq/synapse/issues/19062)) - Update the `oidc_session_no_samesite` cookie to have the `Secure` attribute, so the only difference between it and the paired `oidc_session` cookie, is the configuration of the `SameSite` attribute as described in the comments / cookie names. Contributed by [@&#8203;kieranlane](https://github.com/kieranlane). ([#&#8203;19079](https://github.com/element-hq/synapse/issues/19079)) - Fix a bug introduced in 1.140.0 where lost logcontext warnings would be emitted from timeouts in sync and requests made by Synapse itself. ([#&#8203;19090](https://github.com/element-hq/synapse/issues/19090)) - Fix a bug introdued in 1.140.0 where lost logcontext warning were emitted when using `HomeServer.shutdown()`. ([#&#8203;19108](https://github.com/element-hq/synapse/issues/19108)) ##### Improved Documentation - Update the link to the Debian oldstable package for SQLite. ([#&#8203;19047](https://github.com/element-hq/synapse/issues/19047)) - Point out additional Redis configuration options available in the worker docs. Contributed by [@&#8203;servisbryce](https://github.com/servisbryce). ([#&#8203;19073](https://github.com/element-hq/synapse/issues/19073)) - Update the list of Debian releases that the downstream Debian package is maintained for. ([#&#8203;19100](https://github.com/element-hq/synapse/issues/19100)) - Add [a page](https://element-hq.github.io/synapse/latest/development/internal_documentation/release_notes_review_checklist.html) to the documentation describing the steps the Synapse team takes to review the release notes before publishing them. ([#&#8203;19109](https://github.com/element-hq/synapse/issues/19109)) ##### Deprecations and Removals - Drop support for Python 3.9. ([#&#8203;19099](https://github.com/element-hq/synapse/issues/19099)) - Remove support for SQLite < 3.37.2. ([#&#8203;19047](https://github.com/element-hq/synapse/issues/19047)) ##### Internal Changes - Fix CI linter for schema delta files to correctly handle all types of `CREATE TABLE` syntax. ([#&#8203;19020](https://github.com/element-hq/synapse/issues/19020)) - Use type hinting generics in standard collections, as per [PEP 585](https://peps.python.org/pep-0585/), added in Python 3.9. ([#&#8203;19046](https://github.com/element-hq/synapse/issues/19046)) - Always treat `RETURNING` as supported by SQL engines, now that the minimum-supported versions of both SQLite and PostgreSQL support it. ([#&#8203;19047](https://github.com/element-hq/synapse/issues/19047)) - Move `oidc.load_metadata()` startup into `_base.start()`. ([#&#8203;19056](https://github.com/element-hq/synapse/issues/19056)) - Remove logcontext problems caused by awaiting raw `deferLater(...)`. ([#&#8203;19058](https://github.com/element-hq/synapse/issues/19058)) - Prevent duplicate logging setup when running multiple Synapse instances. ([#&#8203;19067](https://github.com/element-hq/synapse/issues/19067)) - Be mindful of other logging context filters in 3rd-party code and avoid overwriting log record fields unless we know the log record is relevant to Synapse. ([#&#8203;19068](https://github.com/element-hq/synapse/issues/19068)) - Update pydantic to v2. ([#&#8203;19071](https://github.com/element-hq/synapse/issues/19071)) - Update deprecated code in the release script to prevent a warning message from being printed. ([#&#8203;19080](https://github.com/element-hq/synapse/issues/19080)) - Update the deprecated poetry development dependencies group name in `pyproject.toml`. ([#&#8203;19081](https://github.com/element-hq/synapse/issues/19081)) - Remove `pp38*` skip selector from cibuildwheel to silence warning. ([#&#8203;19085](https://github.com/element-hq/synapse/issues/19085)) - Don't immediately exit the release script if the checkout is dirty. Instead, allow the user to clear the dirty changes and retry. ([#&#8203;19088](https://github.com/element-hq/synapse/issues/19088)) - Update the release script's generated announcement text to include a title and extra text for RC's. ([#&#8203;19089](https://github.com/element-hq/synapse/issues/19089)) - Fix lints on main branch. ([#&#8203;19092](https://github.com/element-hq/synapse/issues/19092)) - Use cheaper random string function in logcontext utilities. ([#&#8203;19094](https://github.com/element-hq/synapse/issues/19094)) - Avoid clobbering other `SIGHUP` handlers in 3rd-party code. ([#&#8203;19095](https://github.com/element-hq/synapse/issues/19095)) - Prevent duplicate GitHub draft releases being created during the Synapse release process. ([#&#8203;19096](https://github.com/element-hq/synapse/issues/19096)) - Use Pillow's `Image.getexif` method instead of the experimental `Image._getexif`. ([#&#8203;19098](https://github.com/element-hq/synapse/issues/19098)) - Prevent uv `/usr/local/.lock` file from appearing in built Synapse docker images. ([#&#8203;19107](https://github.com/element-hq/synapse/issues/19107)) - Allow Synapse's runtime dependency checking code to take packaging markers (i.e. `python <= 3.14`) into account when checking dependencies. ([#&#8203;19110](https://github.com/element-hq/synapse/issues/19110)) - Move exception handling up the stack (avoid `exit(1)` in our composable functions). ([#&#8203;19116](https://github.com/element-hq/synapse/issues/19116)) - Fix a lint error related to lifetimes in Rust 1.90. ([#&#8203;19118](https://github.com/element-hq/synapse/issues/19118)) - Refactor and align app entrypoints (avoid `exit(1)` in our composable functions). ([#&#8203;19121](https://github.com/element-hq/synapse/issues/19121), [#&#8203;19131](https://github.com/element-hq/synapse/issues/19131)) - Speed up pruning of ratelimiters. ([#&#8203;19129](https://github.com/element-hq/synapse/issues/19129)) ##### Updates to locked dependencies - Bump actions/download-artifact from 5.0.0 to 6.0.0. ([#&#8203;19102](https://github.com/element-hq/synapse/issues/19102)) - Bump actions/upload-artifact from 4 to 5. ([#&#8203;19106](https://github.com/element-hq/synapse/issues/19106)) - Bump hiredis from 3.2.1 to 3.3.0. ([#&#8203;19103](https://github.com/element-hq/synapse/issues/19103)) - Bump icu\_segmenter from 2.0.0 to 2.0.1. ([#&#8203;19126](https://github.com/element-hq/synapse/issues/19126)) - Bump idna from 3.10 to 3.11. ([#&#8203;19053](https://github.com/element-hq/synapse/issues/19053)) - Bump ijson from 3.4.0 to 3.4.0.post0. ([#&#8203;19051](https://github.com/element-hq/synapse/issues/19051)) - Bump markdown-it-py from 3.0.0 to 4.0.0. ([#&#8203;19123](https://github.com/element-hq/synapse/issues/19123)) - Bump msgpack from 1.1.1 to 1.1.2. ([#&#8203;19050](https://github.com/element-hq/synapse/issues/19050)) - Bump psycopg2 from 2.9.10 to 2.9.11. ([#&#8203;19125](https://github.com/element-hq/synapse/issues/19125)) - Bump pyyaml from 6.0.2 to 6.0.3. ([#&#8203;19105](https://github.com/element-hq/synapse/issues/19105)) - Bump regex from 1.11.3 to 1.12.2. ([#&#8203;19074](https://github.com/element-hq/synapse/issues/19074)) - Bump reqwest from 0.12.23 to 0.12.24. ([#&#8203;19077](https://github.com/element-hq/synapse/issues/19077)) - Bump ruff from 0.12.10 to 0.14.3. ([#&#8203;19124](https://github.com/element-hq/synapse/issues/19124)) - Bump sigstore/cosign-installer from 3.10.0 to 4.0.0. ([#&#8203;19075](https://github.com/element-hq/synapse/issues/19075)) - Bump stefanzweifel/git-auto-commit-action from 6.0.1 to 7.0.0. ([#&#8203;19052](https://github.com/element-hq/synapse/issues/19052)) - Bump tokio from 1.47.1 to 1.48.0. ([#&#8203;19076](https://github.com/element-hq/synapse/issues/19076)) - Bump types-psycopg2 from 2.9.21.20250915 to 2.9.21.20251012. ([#&#8203;19054](https://github.com/element-hq/synapse/issues/19054)) ### [`v1.141.0`](https://github.com/element-hq/synapse/releases/tag/v1.141.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.140.0...v1.141.0) ##### Synapse 1.141.0 (2025-10-29) ##### Deprecation of MacOS Python wheels The team has decided to deprecate and eventually stop publishing python wheels for MacOS. This is a burden on the team, and we're not aware of any parties that use them. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler). Publishing MacOS Python wheels will continue for the next few releases. If you do make use of these wheels downstream, please reach out to us in [#synapse-dev:matrix.org](https://matrix.to/#/#synapse-dev:matrix.org). We'd love to hear from you! ##### Docker images now based on Debian `trixie` with Python 3.13 The Docker images are now based on Debian `trixie` and use Python 3.13. If you are using the Docker images as a base image you may need to e.g. adjust the paths you mount any additional Python packages at. No significant changes since 1.141.0rc2. ##### Synapse 1.141.0rc2 (2025-10-28) ##### Bugfixes - Fix users being unable to log in if their password, or the server's configured pepper, was too long. ([#&#8203;19101](https://github.com/element-hq/synapse/issues/19101)) ##### Synapse 1.141.0rc1 (2025-10-21) ##### Features - Allow using [MSC4190](https://github.com/matrix-org/matrix-spec-proposals/pull/4190) behavior without the opt-in registration flag. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19031](https://github.com/element-hq/synapse/issues/19031)) - Stabilized support for [MSC4326](https://github.com/matrix-org/matrix-spec-proposals/pull/4326): Device masquerading for appservices. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;19033](https://github.com/element-hq/synapse/issues/19033)) ##### Bugfixes - Fix a bug introduced in 1.136.0 that would prevent Synapse from being able to be `reload`-ed more than once when running under systemd. ([#&#8203;19060](https://github.com/element-hq/synapse/issues/19060)) - Fix a bug introduced in 1.140.0 where an internal server error could be raised when hashing user passwords that are too long. ([#&#8203;19078](https://github.com/element-hq/synapse/issues/19078)) ##### Updates to the Docker image - Update docker image to use Debian trixie as the base and thus Python 3.13. ([#&#8203;19064](https://github.com/element-hq/synapse/issues/19064)) ##### Internal Changes - Move unique snowflake homeserver background tasks to `start_background_tasks` (the standard pattern for this kind of thing). ([#&#8203;19037](https://github.com/element-hq/synapse/issues/19037)) - Drop a deprecated field of the `PyGitHub` dependency in the release script and raise the dependency's minimum version to `1.59.0`. ([#&#8203;19039](https://github.com/element-hq/synapse/issues/19039)) - Update TODO list of conflicting areas where we encounter metrics being clobbered (`ApplicationService`). ([#&#8203;19040](https://github.com/element-hq/synapse/issues/19040)) ### [`v1.140.0`](https://github.com/element-hq/synapse/releases/tag/v1.140.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.139.2...v1.140.0) ##### Synapse 1.140.0 (2025-10-14) ##### Compatibility notice for users of `synapse-s3-storage-provider` Deployments that make use of the [synapse-s3-storage-provider](https://github.com/matrix-org/synapse-s3-storage-provider) module must upgrade to [v1.6.0](https://github.com/matrix-org/synapse-s3-storage-provider/releases/tag/v1.6.0). Using older versions of the module with this release of Synapse will prevent users from being able to upload or download media. No significant changes since 1.140.0rc1. ##### Synapse 1.140.0rc1 (2025-10-10) ##### Features - Add [a new Media Query by ID Admin API](https://element-hq.github.io/synapse/v1.140/admin_api/media_admin_api.html#query-a-piece-of-media-by-id) that allows server admins to query and investigate the metadata of local or cached remote media via the `origin/media_id` identifier found in a [Matrix Content URI](https://spec.matrix.org/v1.14/client-server-api/#matrix-content-mxc-uris). ([#&#8203;18911](https://github.com/element-hq/synapse/issues/18911)) - Add [a new Fetch Event Admin API](https://element-hq.github.io/synapse/v1.140/admin_api/fetch_event.html) to fetch an event by ID. ([#&#8203;18963](https://github.com/element-hq/synapse/issues/18963)) - Update [MSC4284: Policy Servers](https://github.com/matrix-org/matrix-spec-proposals/pull/4284) implementation to support signatures when available. ([#&#8203;18934](https://github.com/element-hq/synapse/issues/18934)) - Add experimental implementation of the `GET /_matrix/client/v1/rtc/transports` endpoint for the latest draft of [MSC4143: MatrixRTC](https://github.com/matrix-org/matrix-spec-proposals/pull/4143). ([#&#8203;18967](https://github.com/element-hq/synapse/issues/18967)) - Expose a `defer_to_threadpool` function in the Synapse Module API that allows modules to run a function on a separate thread in a custom threadpool. ([#&#8203;19032](https://github.com/element-hq/synapse/issues/19032)) ##### Bugfixes - Fix room upgrade `room_config` argument and documentation for `user_may_create_room` spam-checker callback. ([#&#8203;18721](https://github.com/element-hq/synapse/issues/18721)) - Compute a user's last seen timestamp from their devices' last seen timestamps instead of IPs, because the latter are automatically cleared according to `user_ips_max_age`. ([#&#8203;18948](https://github.com/element-hq/synapse/issues/18948)) - Fix bug where ephemeral events were not filtered by room ID. Contributed by [@&#8203;frastefanini](https://github.com/frastefanini). ([#&#8203;19002](https://github.com/element-hq/synapse/issues/19002)) - Update Synapse main process version string to include git info. ([#&#8203;19011](https://github.com/element-hq/synapse/issues/19011)) ##### Improved Documentation - Explain how `Deferred` callbacks interact with logcontexts. ([#&#8203;18914](https://github.com/element-hq/synapse/issues/18914)) - Fix documentation for `rc_room_creation` and `rc_reports` to clarify that a `per_user` rate limit is not supported. ([#&#8203;18998](https://github.com/element-hq/synapse/issues/18998)) ##### Deprecations and Removals - Remove deprecated `LoggingContext.set_current_context`/`LoggingContext.current_context` methods which already have equivalent bare methods in `synapse.logging.context`. ([#&#8203;18989](https://github.com/element-hq/synapse/issues/18989)) - Drop support for unstable field names from the long-accepted [MSC2732](https://github.com/matrix-org/matrix-spec-proposals/pull/2732) (Olm fallback keys) proposal. ([#&#8203;18996](https://github.com/element-hq/synapse/issues/18996)) ##### Internal Changes - Cleanly shutdown `SynapseHomeServer` object, allowing artifacts of embedded small hosts to be properly garbage collected. ([#&#8203;18828](https://github.com/element-hq/synapse/issues/18828)) - Update OEmbed providers to use 'X' instead of 'Twitter' in URL previews, following a rebrand. Contributed by [@&#8203;HammyHavoc](https://github.com/HammyHavoc). ([#&#8203;18767](https://github.com/element-hq/synapse/issues/18767)) - Fix `server_name` in logging context for multiple Synapse instances in one process. ([#&#8203;18868](https://github.com/element-hq/synapse/issues/18868)) - Wrap the Rust HTTP client with `make_deferred_yieldable` so it follows Synapse logcontext rules. ([#&#8203;18903](https://github.com/element-hq/synapse/issues/18903)) - Fix the GitHub Actions workflow that moves issues labeled "X-Needs-Info" to the "Needs info" column on the team's internal triage board. ([#&#8203;18913](https://github.com/element-hq/synapse/issues/18913)) - Disconnect background process work from request trace. ([#&#8203;18932](https://github.com/element-hq/synapse/issues/18932)) - Reduce overall number of calls to `_get_e2e_cross_signing_signatures_for_devices` by increasing the batch size of devices the query is called with, reducing DB load. ([#&#8203;18939](https://github.com/element-hq/synapse/issues/18939)) - Update error code used when an appservice tries to masquerade as an unknown device using [MSC4326](https://github.com/matrix-org/matrix-spec-proposals/pull/4326). Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;18947](https://github.com/element-hq/synapse/issues/18947)) - Fix `no active span when trying to log` tracing error on startup (when OpenTracing is enabled). ([#&#8203;18959](https://github.com/element-hq/synapse/issues/18959)) - Fix `run_coroutine_in_background(...)` incorrectly handling logcontext. ([#&#8203;18964](https://github.com/element-hq/synapse/issues/18964)) - Add debug logs wherever we change current logcontext. ([#&#8203;18966](https://github.com/element-hq/synapse/issues/18966)) - Update dockerfile metadata to fix broken link; point to documentation website. ([#&#8203;18971](https://github.com/element-hq/synapse/issues/18971)) - Note that the code is additionally licensed under the [Element Commercial license](https://github.com/element-hq/synapse/blob/develop/LICENSE-COMMERCIAL) in SPDX expression field configs. ([#&#8203;18973](https://github.com/element-hq/synapse/issues/18973)) - Fix logcontext handling in `timeout_deferred` tests. ([#&#8203;18974](https://github.com/element-hq/synapse/issues/18974)) - Remove internal `ReplicationUploadKeysForUserRestServlet` as a follow-up to the work in [#&#8203;18581](https://github.com/element-hq/synapse/pull/18581) that moved device changes off the main process. ([#&#8203;18988](https://github.com/element-hq/synapse/issues/18988)) - Switch task scheduler from raw logcontext manipulation to using the dedicated logcontext utils. ([#&#8203;18990](https://github.com/element-hq/synapse/issues/18990)) - Remove `MockClock()` in tests. ([#&#8203;18992](https://github.com/element-hq/synapse/issues/18992)) - Switch back to our own custom `LogContextScopeManager` instead of OpenTracing's `ContextVarsScopeManager` which was causing problems when using the experimental `SYNAPSE_ASYNC_IO_REACTOR` option with tracing enabled. ([#&#8203;19007](https://github.com/element-hq/synapse/issues/19007)) - Remove `version_string` argument from `HomeServer` since it's always the same. ([#&#8203;19012](https://github.com/element-hq/synapse/issues/19012)) - Remove duplicate call to `hs.start_background_tasks()` introduced from a bad merge. ([#&#8203;19013](https://github.com/element-hq/synapse/issues/19013)) - Split homeserver creation (`create_homeserver`) and setup (`setup`). ([#&#8203;19015](https://github.com/element-hq/synapse/issues/19015)) - Swap near-end-of-life `macos-13` GitHub Actions runner for the `macos-15-intel` variant. ([#&#8203;19025](https://github.com/element-hq/synapse/issues/19025)) - Introduce `RootConfig.validate_config()` which can be subclassed in `HomeServerConfig` to do cross-config class validation. ([#&#8203;19027](https://github.com/element-hq/synapse/issues/19027)) - Allow any command of the `release.py` script to accept a `--gh-token` argument. ([#&#8203;19035](https://github.com/element-hq/synapse/issues/19035)) ##### Updates to locked dependencies - Bump Swatinem/rust-cache from 2.8.0 to 2.8.1. ([#&#8203;18949](https://github.com/element-hq/synapse/issues/18949)) - Bump actions/cache from 4.2.4 to 4.3.0. ([#&#8203;18983](https://github.com/element-hq/synapse/issues/18983)) - Bump anyhow from 1.0.99 to 1.0.100. ([#&#8203;18950](https://github.com/element-hq/synapse/issues/18950)) - Bump authlib from 1.6.3 to 1.6.4. ([#&#8203;18957](https://github.com/element-hq/synapse/issues/18957)) - Bump authlib from 1.6.4 to 1.6.5. ([#&#8203;19019](https://github.com/element-hq/synapse/issues/19019)) - Bump bcrypt from 4.3.0 to 5.0.0. ([#&#8203;18984](https://github.com/element-hq/synapse/issues/18984)) - Bump docker/login-action from 3.5.0 to 3.6.0. ([#&#8203;18978](https://github.com/element-hq/synapse/issues/18978)) - Bump lxml from 6.0.0 to 6.0.2. ([#&#8203;18979](https://github.com/element-hq/synapse/issues/18979)) - Bump phonenumbers from 9.0.13 to 9.0.14. ([#&#8203;18954](https://github.com/element-hq/synapse/issues/18954)) - Bump phonenumbers from 9.0.14 to 9.0.15. ([#&#8203;18991](https://github.com/element-hq/synapse/issues/18991)) - Bump prometheus-client from 0.22.1 to 0.23.1. ([#&#8203;19016](https://github.com/element-hq/synapse/issues/19016)) - Bump pydantic from 2.11.9 to 2.11.10. ([#&#8203;19017](https://github.com/element-hq/synapse/issues/19017)) - Bump pygithub from 2.7.0 to 2.8.1. ([#&#8203;18952](https://github.com/element-hq/synapse/issues/18952)) - Bump regex from 1.11.2 to 1.11.3. ([#&#8203;18981](https://github.com/element-hq/synapse/issues/18981)) - Bump serde from 1.0.224 to 1.0.226. ([#&#8203;18953](https://github.com/element-hq/synapse/issues/18953)) - Bump serde from 1.0.226 to 1.0.228. ([#&#8203;18982](https://github.com/element-hq/synapse/issues/18982)) - Bump setuptools-rust from 1.11.1 to 1.12.0. ([#&#8203;18980](https://github.com/element-hq/synapse/issues/18980)) - Bump twine from 6.1.0 to 6.2.0. ([#&#8203;18985](https://github.com/element-hq/synapse/issues/18985)) - Bump types-pyyaml from 6.0.12.20250809 to 6.0.12.20250915. ([#&#8203;19018](https://github.com/element-hq/synapse/issues/19018)) - Bump types-requests from 2.32.4.20250809 to 2.32.4.20250913. ([#&#8203;18951](https://github.com/element-hq/synapse/issues/18951)) - Bump typing-extensions from 4.14.1 to 4.15.0. ([#&#8203;18956](https://github.com/element-hq/synapse/issues/18956)) ### [`v1.139.2`](https://github.com/element-hq/synapse/releases/tag/v1.139.2) [Compare Source](https://github.com/element-hq/synapse/compare/v1.139.1...v1.139.2) ##### Synapse 1.139.2 (2025-10-07) ##### Bugfixes - Fix a bug introduced in 1.139.1 where a client could receive an Internal Server Error if they set `device_keys: null` in the request to [`POST /_matrix/client/v3/keys/upload`](https://spec.matrix.org/v1.16/client-server-api/#post_matrixclientv3keysupload). ([#&#8203;19023](https://github.com/element-hq/synapse/issues/19023)) ### [`v1.139.1`](https://github.com/element-hq/synapse/releases/tag/v1.139.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.139.0...v1.139.1) ##### Synapse 1.139.1 (2025-10-07) ##### Security Fixes - Fix [CVE-2025-61672](https://www.cve.org/CVERecord?id=CVE-2025-61672) / [GHSA-fh66-fcv5-jjfr](https://github.com/element-hq/synapse/security/advisories/GHSA-fh66-fcv5-jjfr). Lack of validation for device keys in Synapse before 1.139.1 allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. ([#&#8203;17097](https://github.com/element-hq/synapse/issues/17097)) ##### Deprecations and Removals - Drop support for unstable field names from the long-accepted [MSC2732](https://github.com/matrix-org/matrix-spec-proposals/pull/2732) (Olm fallback keys) proposal. This change allows unit tests to pass following the security patch above. ([#&#8203;18996](https://github.com/element-hq/synapse/issues/18996)) ### [`v1.139.0`](https://github.com/element-hq/synapse/releases/tag/v1.139.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.138.4...v1.139.0) ##### Synapse 1.139.0 (2025-09-30) ##### `/register` requests from old application service implementations may break when using MAS If you are using Matrix Authentication Service (MAS), as of this release any Application Services that do not set `inhibit_login=true` when calling `POST /_matrix/client/v3/register` will receive the error `IO.ELEMENT.MSC4190.M_APPSERVICE_LOGIN_UNSUPPORTED` in response. Please see [the upgrade notes](https://element-hq.github.io/synapse/develop/upgrade.html#register-requests-from-old-application-service-implementations-may-break-when-using-mas) for more information. No significant changes since 1.139.0rc3. ##### Synapse 1.139.0rc3 (2025-09-25) ##### Bugfixes - Fix a bug introduced in 1.139.0rc1 where `run_coroutine_in_background(...)` incorrectly handled logcontexts, resulting in partially broken logging. ([#&#8203;18964](https://github.com/element-hq/synapse/issues/18964)) ##### Synapse 1.139.0rc2 (2025-09-23) ##### Internal Changes - Drop support for Ubuntu 24.10 Oracular Oriole, and add support for Ubuntu 25.04 Plucky Puffin. ([#&#8203;18962](https://github.com/element-hq/synapse/issues/18962)) ##### Synapse 1.139.0rc1 (2025-09-23) ##### Features - Add experimental support for [MSC4308: Thread Subscriptions extension to Sliding Sync](https://github.com/matrix-org/matrix-spec-proposals/pull/4308) when [MSC4306: Thread Subscriptions](https://github.com/matrix-org/matrix-spec-proposals/pull/4306) and [MSC4186: Simplified Sliding Sync](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) are enabled. ([#&#8203;18695](https://github.com/element-hq/synapse/issues/18695)) - Update push rules for experimental [MSC4306: Thread Subscriptions](https://github.com/matrix-org/matrix-doc/issues/4306) to follow a newer draft. ([#&#8203;18846](https://github.com/element-hq/synapse/issues/18846)) - Add `get_media_upload_limits_for_user` and `on_media_upload_limit_exceeded` module API callbacks to the media repository. ([#&#8203;18848](https://github.com/element-hq/synapse/issues/18848)) - Support [MSC4169](https://github.com/matrix-org/matrix-spec-proposals/pull/4169) for backwards-compatible redaction sending using the `/send` endpoint. Contributed by [@&#8203;SpiritCroc](https://github.com/SpiritCroc) @&#8203; Beeper. ([#&#8203;18898](https://github.com/element-hq/synapse/issues/18898)) - Add an in-memory cache to `_get_e2e_cross_signing_signatures_for_devices` to reduce DB load. ([#&#8203;18899](https://github.com/element-hq/synapse/issues/18899)) - Update [MSC4190](https://github.com/matrix-org/matrix-spec-proposals/pull/4190) support to return correct errors and allow appservices to reset cross-signing keys without user-interactive authentication. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;18946](https://github.com/element-hq/synapse/issues/18946)) ##### Bugfixes - Ensure all PDUs sent via `/send` pass canonical JSON checks. ([#&#8203;18641](https://github.com/element-hq/synapse/issues/18641)) - Fix bug where we did not send invite revocations over federation. ([#&#8203;18823](https://github.com/element-hq/synapse/issues/18823)) - Fix prefixed support for [MSC4133](https://github.com/matrix-org/matrix-spec-proposals/pull/4133). ([#&#8203;18875](https://github.com/element-hq/synapse/issues/18875)) - Fix open redirect in legacy SSO flow with the `idp` query parameter. ([#&#8203;18909](https://github.com/element-hq/synapse/issues/18909)) - Fix a performance regression related to the experimental Delayed Events ([MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140)) feature. ([#&#8203;18926](https://github.com/element-hq/synapse/issues/18926)) ##### Updates to the Docker image - Suppress "Applying schema" log noise bulk when `SYNAPSE_LOG_TESTING` is set. ([#&#8203;18878](https://github.com/element-hq/synapse/issues/18878)) ##### Improved Documentation - Clarify Python dependency constraints in our deprecation policy. ([#&#8203;18856](https://github.com/element-hq/synapse/issues/18856)) - Clarify necessary `jwt_config` parameter in OIDC documentation for authentik. Contributed by [@&#8203;maxkratz](https://github.com/maxkratz). ([#&#8203;18931](https://github.com/element-hq/synapse/issues/18931)) ##### Deprecations and Removals - Remove obsolete and experimental `/sync/e2ee` endpoint. ([#&#8203;18583](https://github.com/element-hq/synapse/issues/18583)) ##### Internal Changes - Fix `LaterGauge` metrics to collect from all servers. ([#&#8203;18791](https://github.com/element-hq/synapse/issues/18791)) - Configure Synapse to run [MSC4306: Thread Subscriptions](https://github.com/matrix-org/matrix-spec-proposals/pull/4306) Complement tests. ([#&#8203;18819](https://github.com/element-hq/synapse/issues/18819)) - Remove `sentinel` logcontext usage where we log in `setup`, `start` and `exit`. ([#&#8203;18870](https://github.com/element-hq/synapse/issues/18870)) - Use the `Enum`'s value for the dictionary key when responding to an admin request for experimental features. ([#&#8203;18874](https://github.com/element-hq/synapse/issues/18874)) - Start background tasks after we fork the process (daemonize). ([#&#8203;18886](https://github.com/element-hq/synapse/issues/18886)) - Better explain how we manage the logcontext in `run_in_background(...)` and `run_as_background_process(...)`. ([#&#8203;18900](https://github.com/element-hq/synapse/issues/18900), [#&#8203;18906](https://github.com/element-hq/synapse/issues/18906)) - Remove `sentinel` logcontext usage in `Clock` utilities like `looping_call` and `call_later`. ([#&#8203;18907](https://github.com/element-hq/synapse/issues/18907)) - Replace usages of the deprecated `pkg_resources` interface in preparation of setuptools dropping it soon. ([#&#8203;18910](https://github.com/element-hq/synapse/issues/18910)) - Split loading config from homeserver `setup`. ([#&#8203;18933](https://github.com/element-hq/synapse/issues/18933)) - Fix `run_in_background` not being awaited properly in some tests causing `LoggingContext` problems. ([#&#8203;18937](https://github.com/element-hq/synapse/issues/18937)) - Fix `run_as_background_process` not being awaited properly causing `LoggingContext` problems in experimental [MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140): Delayed events implementation. ([#&#8203;18938](https://github.com/element-hq/synapse/issues/18938)) - Introduce `Clock.call_when_running(...)` to wrap startup code in a logcontext, ensuring we can identify which server generated the logs. ([#&#8203;18944](https://github.com/element-hq/synapse/issues/18944)) - Introduce `Clock.add_system_event_trigger(...)` to wrap system event callback code in a logcontext, ensuring we can identify which server generated the logs. ([#&#8203;18945](https://github.com/element-hq/synapse/issues/18945)) ##### Updates to locked dependencies - Bump actions/setup-go from 5.5.0 to 6.0.0. ([#&#8203;18891](https://github.com/element-hq/synapse/issues/18891)) - Bump actions/setup-python from 5.6.0 to 6.0.0. ([#&#8203;18890](https://github.com/element-hq/synapse/issues/18890)) - Bump authlib from 1.6.1 to 1.6.3. ([#&#8203;18921](https://github.com/element-hq/synapse/issues/18921)) - Bump jsonschema from 4.25.0 to 4.25.1. ([#&#8203;18897](https://github.com/element-hq/synapse/issues/18897)) - Bump log from 0.4.27 to 0.4.28. ([#&#8203;18892](https://github.com/element-hq/synapse/issues/18892)) - Bump phonenumbers from 9.0.12 to 9.0.13. ([#&#8203;18893](https://github.com/element-hq/synapse/issues/18893)) - Bump pydantic from 2.11.7 to 2.11.9. ([#&#8203;18922](https://github.com/element-hq/synapse/issues/18922)) - Bump serde from 1.0.219 to 1.0.223. ([#&#8203;18920](https://github.com/element-hq/synapse/issues/18920)) - Bump serde\_json from 1.0.143 to 1.0.145. ([#&#8203;18919](https://github.com/element-hq/synapse/issues/18919)) - Bump sigstore/cosign-installer from 3.9.2 to 3.10.0. ([#&#8203;18917](https://github.com/element-hq/synapse/issues/18917)) - Bump towncrier from 24.8.0 to 25.8.0. ([#&#8203;18894](https://github.com/element-hq/synapse/issues/18894)) - Bump types-psycopg2 from 2.9.21.20250809 to 2.9.21.20250915. ([#&#8203;18918](https://github.com/element-hq/synapse/issues/18918)) - Bump types-requests from 2.32.4.20250611 to 2.32.4.20250809. ([#&#8203;18895](https://github.com/element-hq/synapse/issues/18895)) - Bump types-setuptools from 80.9.0.20250809 to 80.9.0.20250822. ([#&#8203;18924](https://github.com/element-hq/synapse/issues/18924)) ### [`v1.138.4`](https://github.com/element-hq/synapse/releases/tag/v1.138.4) [Compare Source](https://github.com/element-hq/synapse/compare/v1.138.3...v1.138.4) ##### Synapse 1.138.4 (2025-10-07) ##### Bugfixes - Fix a bug introduced in 1.138.3 where a client could receive an Internal Server Error if they set `device_keys: null` in the request to [`POST /_matrix/client/v3/keys/upload`](https://spec.matrix.org/v1.16/client-server-api/#post_matrixclientv3keysupload). ([#&#8203;19023](https://github.com/element-hq/synapse/issues/19023)) ### [`v1.138.3`](https://github.com/element-hq/synapse/releases/tag/v1.138.3) [Compare Source](https://github.com/element-hq/synapse/compare/v1.138.2...v1.138.3) ##### Synapse 1.138.3 (2025-10-07) ##### Security Fixes - Fix [CVE-2025-61672](https://www.cve.org/CVERecord?id=CVE-2025-61672) / [GHSA-fh66-fcv5-jjfr](https://github.com/element-hq/synapse/security/advisories/GHSA-fh66-fcv5-jjfr). Lack of validation for device keys in Synapse before 1.139.1 allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. ([#&#8203;17097](https://github.com/element-hq/synapse/issues/17097)) ##### Deprecations and Removals - Drop support for unstable field names from the long-accepted [MSC2732](https://github.com/matrix-org/matrix-spec-proposals/pull/2732) (Olm fallback keys) proposal. This change allows unit tests to pass following the security patch above. ([#&#8203;18996](https://github.com/element-hq/synapse/issues/18996)) ### [`v1.138.2`](https://github.com/element-hq/synapse/releases/tag/v1.138.2) [Compare Source](https://github.com/element-hq/synapse/compare/v1.138.1...v1.138.2) ##### Synapse 1.138.2 (2025-09-24) ##### Internal Changes - Drop support for Ubuntu 24.10 Oracular Oriole, and add support for Ubuntu 25.04 Plucky Puffin. ([#&#8203;18962](https://github.com/element-hq/synapse/issues/18962)) ##### Synapse 1.138.1 (2025-09-24) ##### Bugfixes - Fix a performance regression related to the experimental Delayed Events ([MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140)) feature. ([#&#8203;18926](https://github.com/element-hq/synapse/issues/18926)) ### [`v1.138.1`](https://github.com/element-hq/synapse/compare/v1.138.0...v1.138.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.138.0...v1.138.1) ### [`v1.138.0`](https://github.com/element-hq/synapse/releases/tag/v1.138.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.137.0...v1.138.0) ##### Synapse 1.138.0 (2025-09-09) No significant changes since 1.138.0rc1. ##### Synapse 1.138.0rc1 (2025-09-02) ##### Features - Support for the stable endpoint and scopes of [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861) & co. ([#&#8203;18549](https://github.com/element-hq/synapse/issues/18549)) ##### Bugfixes - Improve database performance of [MSC4293](https://github.com/matrix-org/matrix-spec-proposals/pull/4293) - Redact on Kick/Ban. ([#&#8203;18851](https://github.com/element-hq/synapse/issues/18851)) - Do not throw an error when fetching a rejected delayed state event on startup. ([#&#8203;18858](https://github.com/element-hq/synapse/issues/18858)) ##### Improved Documentation - Fix worker documentation incorrectly indicating all room Admin API requests were capable of being handled by workers. ([#&#8203;18853](https://github.com/element-hq/synapse/issues/18853)) ##### Internal Changes - Instrument `_ByteProducer` with tracing to measure potential dead time while writing bytes to the request. ([#&#8203;18804](https://github.com/element-hq/synapse/issues/18804)) - Switch to OpenTracing's `ContextVarsScopeManager` instead of our own custom `LogContextScopeManager`. ([#&#8203;18849](https://github.com/element-hq/synapse/issues/18849)) - Trace how much work is being done while "recursively fetching redactions". ([#&#8203;18854](https://github.com/element-hq/synapse/issues/18854)) - Link [upstream Twisted bug](https://github.com/twisted/twisted/issues/12498) tracking the problem that explains why we have to use a `Producer` to write bytes to the request. ([#&#8203;18855](https://github.com/element-hq/synapse/issues/18855)) - Introduce `EventPersistencePair` type. ([#&#8203;18857](https://github.com/element-hq/synapse/issues/18857)) ##### Updates to locked dependencies - Bump actions/add-to-project from [`c0c5949`](https://github.com/element-hq/synapse/commit/c0c5949b017d0d4a39f7ba888255881bdac2a823) to [`4515659`](https://github.com/element-hq/synapse/commit/4515659e2b458b27365e167605ac44f219494b66). ([#&#8203;18863](https://github.com/element-hq/synapse/issues/18863)) - Bump actions/checkout from 4.3.0 to 5.0.0. ([#&#8203;18834](https://github.com/element-hq/synapse/issues/18834)) - Bump anyhow from 1.0.98 to 1.0.99. ([#&#8203;18841](https://github.com/element-hq/synapse/issues/18841)) - Bump docker/login-action from 3.4.0 to 3.5.0. ([#&#8203;18835](https://github.com/element-hq/synapse/issues/18835)) - Bump dtolnay/rust-toolchain from [`b3b07ba`](https://github.com/element-hq/synapse/commit/b3b07ba8b418998c39fb20f53e8b695cdcc8de1b) to [`e97e2d8`](https://github.com/element-hq/synapse/commit/e97e2d8cc328f1b50210efc529dca0028893a2d9). ([#&#8203;18862](https://github.com/element-hq/synapse/issues/18862)) - Bump phonenumbers from 9.0.11 to 9.0.12. ([#&#8203;18837](https://github.com/element-hq/synapse/issues/18837)) - Bump regex from 1.11.1 to 1.11.2. ([#&#8203;18864](https://github.com/element-hq/synapse/issues/18864)) - Bump reqwest from 0.12.22 to 0.12.23. ([#&#8203;18842](https://github.com/element-hq/synapse/issues/18842)) - Bump ruff from 0.12.7 to 0.12.10. ([#&#8203;18865](https://github.com/element-hq/synapse/issues/18865)) - Bump serde\_json from 1.0.142 to 1.0.143. ([#&#8203;18866](https://github.com/element-hq/synapse/issues/18866)) - Bump types-bleach from 6.2.0.20250514 to 6.2.0.20250809. ([#&#8203;18838](https://github.com/element-hq/synapse/issues/18838)) - Bump types-jsonschema from 4.25.0.20250720 to 4.25.1.20250822. ([#&#8203;18867](https://github.com/element-hq/synapse/issues/18867)) - Bump types-psycopg2 from 2.9.21.20250718 to 2.9.21.20250809. ([#&#8203;18836](https://github.com/element-hq/synapse/issues/18836)) ### [`v1.137.0`](https://github.com/element-hq/synapse/releases/tag/v1.137.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.136.0...v1.137.0) ##### Synapse 1.137.0 (2025-08-26) No significant changes since 1.137.0rc1. ##### Synapse 1.137.0rc1 (2025-08-19) ##### Bugfixes - Fix a bug which could corrupt auth chains making it impossible to perform state resolution. ([#&#8203;18746](https://github.com/element-hq/synapse/issues/18746)) - Fix error message in `register_new_matrix_user` utility script for empty `registration_shared_secret`. ([#&#8203;18780](https://github.com/element-hq/synapse/issues/18780)) - Allow enabling [MSC4108](https://github.com/matrix-org/matrix-spec-proposals/pull/4108) when the stable Matrix Authentication Service integration is enabled. ([#&#8203;18832](https://github.com/element-hq/synapse/issues/18832)) ##### Improved Documentation - Include IPv6 networks in `denied-peer-ips` of coturn setup. Contributed by [@&#8203;litetex](https://github.com/litetex). ([#&#8203;18781](https://github.com/element-hq/synapse/issues/18781)) ##### Internal Changes - Update tests to ensure all database tables are emptied when purging a room. ([#&#8203;18794](https://github.com/element-hq/synapse/issues/18794)) - Instrument the `encode_response` part of Sliding Sync requests for more complete traces in Jaeger. ([#&#8203;18815](https://github.com/element-hq/synapse/issues/18815)) - Tag Sliding Sync traces when we `wait_for_events`. ([#&#8203;18816](https://github.com/element-hq/synapse/issues/18816)) - Fix `portdb` CI by hardcoding the new `pg_dump` restrict key that was added due to [CVE-2025-8714](https://nvd.nist.gov/vuln/detail/cve-2025-8714). ([#&#8203;18824](https://github.com/element-hq/synapse/issues/18824)) ##### Updates to locked dependencies - Bump actions/add-to-project from [`5b1a254`](https://github.com/element-hq/synapse/commit/5b1a254a3546aef88e0a7724a77a623fa2e47c36) to [`0c37450`](https://github.com/element-hq/synapse/commit/0c37450c4be3b6a7582b2fb013c9ebfd9c8e9300). ([#&#8203;18557](https://github.com/element-hq/synapse/issues/18557)) - Bump actions/cache from 4.2.3 to 4.2.4. ([#&#8203;18799](https://github.com/element-hq/synapse/issues/18799)) - Bump actions/checkout from 4.2.2 to 4.3.0. ([#&#8203;18800](https://github.com/element-hq/synapse/issues/18800)) - Bump actions/download-artifact from 4.3.0 to 5.0.0. ([#&#8203;18801](https://github.com/element-hq/synapse/issues/18801)) - Bump docker/metadata-action from 5.7.0 to 5.8.0. ([#&#8203;18773](https://github.com/element-hq/synapse/issues/18773)) - Bump mypy from 1.16.1 to 1.17.1. ([#&#8203;18775](https://github.com/element-hq/synapse/issues/18775)) - Bump phonenumbers from 9.0.10 to 9.0.11. ([#&#8203;18797](https://github.com/element-hq/synapse/issues/18797)) - Bump pygithub from 2.6.1 to 2.7.0. ([#&#8203;18779](https://github.com/element-hq/synapse/issues/18779)) - Bump serde\_json from 1.0.141 to 1.0.142. ([#&#8203;18776](https://github.com/element-hq/synapse/issues/18776)) - Bump slab from 0.4.10 to 0.4.11. ([#&#8203;18809](https://github.com/element-hq/synapse/issues/18809)) - Bump tokio from 1.47.0 to 1.47.1. ([#&#8203;18774](https://github.com/element-hq/synapse/issues/18774)) - Bump types-pyyaml from 6.0.12.20250516 to 6.0.12.20250809. ([#&#8203;18798](https://github.com/element-hq/synapse/issues/18798)) - Bump types-setuptools from 80.9.0.20250529 to 80.9.0.20250809. ([#&#8203;18796](https://github.com/element-hq/synapse/issues/18796)) ### [`v1.136.0`](https://github.com/element-hq/synapse/releases/tag/v1.136.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.135.2...v1.136.0) ##### Synapse 1.136.0 (2025-08-12) Note: This release includes the security fixes from `1.135.2` and `1.136.0rc2`, detailed below. Please also check [the relevant section in the upgrade notes](https://github.com/element-hq/synapse/blob/develop/docs/upgrade.md#upgrading-to-v11360) for the changes to MAS support, metrics labels and the module API which may require your attention when upgrading. ##### Bugfixes - Fix bug introduced in 1.135.2 and 1.136.0rc2 where the [Make Room Admin API](https://element-hq.github.io/synapse/latest/admin_api/rooms.html#make-room-admin-api) would not treat a room v12's creator power level as the highest in room. ([#&#8203;18805](https://github.com/element-hq/synapse/issues/18805)) ##### Synapse 1.136.0rc2 (2025-08-11) This is the Synapse portion of the [Matrix coordinated security release](https://matrix.org/blog/2025/07/security-predisclosure/). This release includes support for [room version](https://spec.matrix.org/v1.15/rooms/) 12 which fixes a number of security vulnerabilities, including [CVE-2025-49090](https://www.cve.org/CVERecord?id=CVE-2025-49090). The default room version is not changed. Not all clients will support room version 12 immediately, and not all users will be using the latest version of their clients. Large, public rooms are advised to wait a few weeks before upgrading to room version 12 to allow users throughout the Matrix ecosystem to update their clients. Note: release 1.135.1 was skipped due to issues discovered during the release process. Two patched Synapse releases are now available: - `1.135.2`: stable release comprised of `1.135.0` + security patches - Upgrade to this release **if you are currently running 1.135.0 or below**. - `1.136.0rc2`: unstable release candidate comprised of `1.136.0rc1` + security patches. - Upgrade to this release **only if you are on 1.136.0rc1**. ##### Bugfixes - Update MSC4293 redaction logic for room v12. ([#&#8203;80](https://github.com/element-hq/synapse/issues/80)) ##### Internal Changes - Add a parameter to `upgrade_rooms(..)` to allow auto join local users. ([#&#8203;83](https://github.com/element-hq/synapse/issues/83)) ##### Synapse 1.136.0rc1 (2025-08-05) ##### Features - Add configurable rate limiting for the creation of rooms. ([#&#8203;18514](https://github.com/element-hq/synapse/issues/18514)) - Add support for [MSC4293](https://github.com/matrix-org/matrix-spec-proposals/pull/4293) - Redact on Kick/Ban. ([#&#8203;18540](https://github.com/element-hq/synapse/issues/18540)) - When admins enable themselves to see soft-failed events, they will also see if the cause is due to the policy server flagging them as spam via `unsigned`. ([#&#8203;18585](https://github.com/element-hq/synapse/issues/18585)) - Add ability to configure forward/outbound proxy via homeserver config instead of environment variables. See `http_proxy`, `https_proxy`, `no_proxy_hosts`. ([#&#8203;18686](https://github.com/element-hq/synapse/issues/18686)) - Advertise experimental support for [MSC4306](https://github.com/matrix-org/matrix-spec-proposals/pull/4306) (Thread Subscriptions) through `/_matrix/clients/versions` if enabled. ([#&#8203;18722](https://github.com/element-hq/synapse/issues/18722)) - Stabilise support for delegating authentication to [Matrix Authentication Service](https://github.com/element-hq/matrix-authentication-service/). ([#&#8203;18759](https://github.com/element-hq/synapse/issues/18759)) - Implement the push rules for experimental [MSC4306: Thread Subscriptions](https://github.com/matrix-org/matrix-doc/issues/4306). ([#&#8203;18762](https://github.com/element-hq/synapse/issues/18762)) ##### Bugfixes - Allow return code 403 (allowed by C2S Spec since v1.2) when fetching profiles via federation. ([#&#8203;18696](https://github.com/element-hq/synapse/issues/18696)) - Register the MSC4306 (Thread Subscriptions) endpoints in the CS API when the experimental feature is enabled. ([#&#8203;18726](https://github.com/element-hq/synapse/issues/18726)) - Fix a long-standing bug where suspended users could not have server notices sent to them (a 403 was returned to the admin). ([#&#8203;18750](https://github.com/element-hq/synapse/issues/18750)) - Fix an issue that could cause logcontexts to be lost on rate-limited requests. Found by [@&#8203;realtyem](https://github.com/realtyem). ([#&#8203;18763](https://github.com/element-hq/synapse/issues/18763)) - Fix invalidation of storage cache that was broken in 1.135.0. ([#&#8203;18786](https://github.com/element-hq/synapse/issues/18786)) ##### Improved Documentation - Minor improvements to README. ([#&#8203;18700](https://github.com/element-hq/synapse/issues/18700)) - Document that there can be multiple workers handling the `receipts` stream. ([#&#8203;18760](https://github.com/element-hq/synapse/issues/18760)) - Improve worker documentation for some device paths. ([#&#8203;18761](https://github.com/element-hq/synapse/issues/18761)) ##### Deprecations and Removals - Deprecate `run_as_background_process` exported as part of the module API interface in favor of `ModuleApi.run_as_background_process`. See [the relevant section in the upgrade notes](https://github.com/element-hq/synapse/blob/develop/docs/upgrade.md#upgrading-to-v11360) for more information. ([#&#8203;18737](https://github.com/element-hq/synapse/issues/18737)) ##### Internal Changes - Add debug logging for HMAC digest verification failures when using the admin API to register users. ([#&#8203;18474](https://github.com/element-hq/synapse/issues/18474)) - Speed up upgrading a room with large numbers of banned users. ([#&#8203;18574](https://github.com/element-hq/synapse/issues/18574)) - Fix config documentation generation script on Windows by enforcing UTF-8. ([#&#8203;18580](https://github.com/element-hq/synapse/issues/18580)) - Refactor cache, background process, `Counter`, `LaterGauge`, `GaugeBucketCollector`, `Histogram`, and `Gauge` metrics to be homeserver-scoped. ([#&#8203;18656](https://github.com/element-hq/synapse/issues/18656), [#&#8203;18714](https://github.com/element-hq/synapse/issues/18714), [#&#8203;18715](https://github.com/element-hq/synapse/issues/18715), [#&#8203;18724](https://github.com/element-hq/synapse/issues/18724), [#&#8203;18753](https://github.com/element-hq/synapse/issues/18753), [#&#8203;18725](https://github.com/element-hq/synapse/issues/18725), [#&#8203;18670](https://github.com/element-hq/synapse/issues/18670), [#&#8203;18748](https://github.com/element-hq/synapse/issues/18748), [#&#8203;18751](https://github.com/element-hq/synapse/issues/18751)) - Reduce database usage in Sliding Sync by not querying for background update completion after the update is known to be complete. ([#&#8203;18718](https://github.com/element-hq/synapse/issues/18718)) - Improve order of validation and ratelimiting in room creation. ([#&#8203;18723](https://github.com/element-hq/synapse/issues/18723)) - Bump minimum version bound on Twisted to 21.2.0. ([#&#8203;18727](https://github.com/element-hq/synapse/issues/18727), [#&#8203;18729](https://github.com/element-hq/synapse/issues/18729)) - Use `twisted.internet.testing` module in tests instead of deprecated `twisted.test.proto_helpers`. ([#&#8203;18728](https://github.com/element-hq/synapse/issues/18728)) - Remove obsolete `/send_event` replication endpoint. ([#&#8203;18730](https://github.com/element-hq/synapse/issues/18730)) - Update metrics linting to be able to handle custom metrics. ([#&#8203;18733](https://github.com/element-hq/synapse/issues/18733)) - Work around `twisted.protocols.amp.TooLong` error by reducing logging in some tests. ([#&#8203;18736](https://github.com/element-hq/synapse/issues/18736)) - Prevent "Move labelled issues to correct projects" GitHub Actions workflow from failing when an issue is already on the project board. ([#&#8203;18755](https://github.com/element-hq/synapse/issues/18755)) - Bump minimum supported Rust version (MSRV) to 1.82.0. Missed in [#&#8203;18553](https://github.com/element-hq/synapse/pull/18553) (released in Synapse 1.134.0). ([#&#8203;18757](https://github.com/element-hq/synapse/issues/18757)) - Make `Clock.sleep(...)` return a coroutine, so that mypy can catch places where we don't await on it. ([#&#8203;18772](https://github.com/element-hq/synapse/issues/18772)) - Update implementation of [MSC4306: Thread Subscriptions](https://github.com/matrix-org/matrix-doc/issues/4306) to include automatic subscription conflict prevention as introduced in later drafts. ([#&#8203;18756](https://github.com/element-hq/synapse/issues/18756)) ##### Updates to locked dependencies - Bump gitpython from 3.1.44 to 3.1.45. ([#&#8203;18743](https://github.com/element-hq/synapse/issues/18743)) - Bump mypy-zope from 1.0.12 to 1.0.13. ([#&#8203;18744](https://github.com/element-hq/synapse/issues/18744)) - Bump phonenumbers from 9.0.9 to 9.0.10. ([#&#8203;18741](https://github.com/element-hq/synapse/issues/18741)) - Bump ruff from 0.12.4 to 0.12.5. ([#&#8203;18742](https://github.com/element-hq/synapse/issues/18742)) - Bump sentry-sdk from 2.32.0 to 2.33.2. ([#&#8203;18745](https://github.com/element-hq/synapse/issues/18745)) - Bump tokio from 1.46.1 to 1.47.0. ([#&#8203;18740](https://github.com/element-hq/synapse/issues/18740)) - Bump types-jsonschema from 4.24.0.20250708 to 4.25.0.20250720. ([#&#8203;18703](https://github.com/element-hq/synapse/issues/18703)) - Bump types-psycopg2 from 2.9.21.20250516 to 2.9.21.20250718. ([#&#8203;18706](https://github.com/element-hq/synapse/issues/18706)) ### [`v1.135.2`](https://github.com/element-hq/synapse/releases/tag/v1.135.2) [Compare Source](https://github.com/element-hq/synapse/compare/v1.135.1...v1.135.2) ##### Synapse 1.135.2 (2025-08-11) This is the Synapse portion of the [Matrix coordinated security release](https://matrix.org/blog/2025/07/security-predisclosure/). This release includes support for [room version](https://spec.matrix.org/v1.15/rooms/) 12 which fixes a number of security vulnerabilities, including [CVE-2025-49090](https://www.cve.org/CVERecord?id=CVE-2025-49090). The default room version is not changed. Not all clients will support room version 12 immediately, and not all users will be using the latest version of their clients. Large, public rooms are advised to wait a few weeks before upgrading to room version 12 to allow users throughout the Matrix ecosystem to update their clients. Note: release 1.135.1 was skipped due to issues discovered during the release process. Two patched Synapse releases are now available: - `1.135.2`: stable release comprised of `1.135.0` + security patches - Upgrade to this release **if you are currently running 1.135.0 or below**. - `1.136.0rc2`: unstable release candidate comprised of `1.136.0rc1` + security patches. - Upgrade to this release **only if you are on 1.136.0rc1**. ##### Bugfixes - Fix invalidation of storage cache that was broken in 1.135.0. ([#&#8203;18786](https://github.com/element-hq/synapse/issues/18786)) ##### Internal Changes - Add a parameter to `upgrade_rooms(..)` to allow auto join local users. ([#&#8203;82](https://github.com/element-hq/synapse/issues/82)) - Speed up upgrading a room with large numbers of banned users. ([#&#8203;18574](https://github.com/element-hq/synapse/issues/18574)) ### [`v1.135.1`](https://github.com/element-hq/synapse/compare/v1.135.0...v1.135.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.135.0...v1.135.1) ### [`v1.135.0`](https://github.com/element-hq/synapse/releases/tag/v1.135.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.134.0...v1.135.0) ##### Synapse 1.135.0 (2025-08-01) No significant changes since 1.135.0rc2. ##### Synapse 1.135.0rc2 (2025-07-30) ##### Bugfixes - Fix user failing to deactivate with MAS when `/_synapse/mas` is handled by a worker. ([#&#8203;18716](https://github.com/element-hq/synapse/issues/18716)) ##### Internal Changes - Fix performance regression introduced in [#&#8203;18238](https://github.com/element-hq/synapse/issues/18238) by adding a cache to `is_server_admin`. ([#&#8203;18747](https://github.com/element-hq/synapse/issues/18747)) ##### Synapse 1.135.0rc1 (2025-07-22) ##### Features - Add `recaptcha_private_key_path` and `recaptcha_public_key_path` config option. ([#&#8203;17984](https://github.com/element-hq/synapse/issues/17984), [#&#8203;18684](https://github.com/element-hq/synapse/issues/18684)) - Add plain-text handling for rich-text topics as per [MSC3765](https://github.com/matrix-org/matrix-spec-proposals/pull/3765). ([#&#8203;18195](https://github.com/element-hq/synapse/issues/18195)) - If enabled by the user, server admins will see [soft failed](https://spec.matrix.org/v1.13/server-server-api/#soft-failure) events over the Client-Server API. ([#&#8203;18238](https://github.com/element-hq/synapse/issues/18238)) - Add experimental support for [MSC4277: Harmonizing the reporting endpoints](https://github.com/matrix-org/matrix-spec-proposals/pull/4277). ([#&#8203;18263](https://github.com/element-hq/synapse/issues/18263)) - Add ability to limit amount of media uploaded by a user in a given time period. ([#&#8203;18527](https://github.com/element-hq/synapse/issues/18527)) - Enable workers to write directly to the device lists stream and handle device list updates, reducing load on the main process. ([#&#8203;18581](https://github.com/element-hq/synapse/issues/18581)) - Support arbitrary profile fields. Contributed by [@&#8203;clokep](https://github.com/clokep). ([#&#8203;18635](https://github.com/element-hq/synapse/issues/18635)) - Advertise support for Matrix v1.12. ([#&#8203;18647](https://github.com/element-hq/synapse/issues/18647)) - Add an option to issue redactions as an admin user via the [admin redaction endpoint](https://element-hq.github.io/synapse/latest/admin_api/user_admin_api.html#redact-all-the-events-of-a-user). ([#&#8203;18671](https://github.com/element-hq/synapse/issues/18671)) - Add experimental and incomplete support for [MSC4306: Thread Subscriptions](https://github.com/matrix-org/matrix-spec-proposals/blob/rei/msc_thread_subscriptions/proposals/4306-thread-subscriptions.md). ([#&#8203;18674](https://github.com/element-hq/synapse/issues/18674)) - Include `event_id` when getting state with `?format=event`. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;18675](https://github.com/element-hq/synapse/issues/18675)) ##### Bugfixes - Fix CPU and database spinning when retrying sending events to servers whilst at the same time purging those events. ([#&#8203;18499](https://github.com/element-hq/synapse/issues/18499)) - Don't allow creation of tags with names longer than 255 bytes, [as per the spec](https://spec.matrix.org/v1.15/client-server-api/#events-14). ([#&#8203;18660](https://github.com/element-hq/synapse/issues/18660)) - Fix `sliding_sync_connections`-related errors when porting from SQLite to Postgres. ([#&#8203;18677](https://github.com/element-hq/synapse/issues/18677)) - Fix the MAS integration not working when Synapse is started with `--daemonize` or using `synctl`. ([#&#8203;18691](https://github.com/element-hq/synapse/issues/18691)) ##### Improved Documentation - Document that some config options for the user directory are in violation of the Matrix spec. ([#&#8203;18548](https://github.com/element-hq/synapse/issues/18548)) - Update `rc_delayed_event_mgmt` docs to the actual nesting level. Contributed by [@&#8203;HarHarLinks](https://github.com/HarHarLinks). ([#&#8203;18692](https://github.com/element-hq/synapse/issues/18692)) ##### Internal Changes - Add a dedicated internal API for Matrix Authentication Service to Synapse communication. ([#&#8203;18520](https://github.com/element-hq/synapse/issues/18520)) - Allow user registrations to be done on workers. ([#&#8203;18552](https://github.com/element-hq/synapse/issues/18552)) - Remove unnecessary HTTP replication calls. ([#&#8203;18564](https://github.com/element-hq/synapse/issues/18564)) - Refactor `Measure` block metrics to be homeserver-scoped. ([#&#8203;18601](https://github.com/element-hq/synapse/issues/18601)) - Refactor cache metrics to be homeserver-scoped. ([#&#8203;18604](https://github.com/element-hq/synapse/issues/18604)) - Unbreak "Latest dependencies" workflow by using the `--without dev` poetry option instead of removed `--no-dev`. ([#&#8203;18617](https://github.com/element-hq/synapse/issues/18617)) - Update URL Preview code to work with `lxml` 6.0.0+. ([#&#8203;18622](https://github.com/element-hq/synapse/issues/18622)) - Use `markdown-it-py` instead of `commonmark` in the release script. ([#&#8203;18637](https://github.com/element-hq/synapse/issues/18637)) - Fix typing errors with upgraded mypy version. ([#&#8203;18653](https://github.com/element-hq/synapse/issues/18653)) - Add doc comment explaining that config files are shallowly merged. ([#&#8203;18664](https://github.com/element-hq/synapse/issues/18664)) - Minor speed up of insertion into `stream_positions` table. ([#&#8203;18672](https://github.com/element-hq/synapse/issues/18672)) - Remove unused `allow_no_prev_events` option when creating an event. ([#&#8203;18676](https://github.com/element-hq/synapse/issues/18676)) - Clean up `MetricsResource` and Prometheus hacks. ([#&#8203;18687](https://github.com/element-hq/synapse/issues/18687)) - Fix dirty `Cargo.lock` changes appearing after install (`base64`). ([#&#8203;18689](https://github.com/element-hq/synapse/issues/18689)) - Prevent dirty `Cargo.lock` changes from install. ([#&#8203;18693](https://github.com/element-hq/synapse/issues/18693)) - Correct spelling of 'Admin token used' log line. ([#&#8203;18697](https://github.com/element-hq/synapse/issues/18697)) - Reduce log spam when client stops downloading media while it is being streamed to them. ([#&#8203;18699](https://github.com/element-hq/synapse/issues/18699)) ##### Updates to locked dependencies - Bump authlib from 1.6.0 to 1.6.1. ([#&#8203;18704](https://github.com/element-hq/synapse/issues/18704)) - Bump base64 from 0.21.7 to 0.22.1. ([#&#8203;18666](https://github.com/element-hq/synapse/issues/18666)) - Bump jsonschema from 4.24.0 to 4.25.0. ([#&#8203;18707](https://github.com/element-hq/synapse/issues/18707)) - Bump lxml from 5.4.0 to 6.0.0. ([#&#8203;18631](https://github.com/element-hq/synapse/issues/18631)) - Bump mypy from 1.13.0 to 1.16.1. ([#&#8203;18653](https://github.com/element-hq/synapse/issues/18653)) - Bump once\_cell from 1.19.0 to 1.21.3. ([#&#8203;18710](https://github.com/element-hq/synapse/issues/18710)) - Bump phonenumbers from 9.0.8 to 9.0.9. ([#&#8203;18681](https://github.com/element-hq/synapse/issues/18681)) - Bump ruff from 0.12.2 to 0.12.5. ([#&#8203;18683](https://github.com/element-hq/synapse/issues/18683), [#&#8203;18705](https://github.com/element-hq/synapse/issues/18705)) - Bump serde\_json from 1.0.140 to 1.0.141. ([#&#8203;18709](https://github.com/element-hq/synapse/issues/18709)) - Bump sigstore/cosign-installer from 3.9.1 to 3.9.2. ([#&#8203;18708](https://github.com/element-hq/synapse/issues/18708)) - Bump types-jsonschema from 4.24.0.20250528 to 4.24.0.20250708. ([#&#8203;18682](https://github.com/element-hq/synapse/issues/18682)) ### [`v1.134.0`](https://github.com/element-hq/synapse/releases/tag/v1.134.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.133.0...v1.134.0) ##### Synapse 1.134.0 (2025-07-15) No significant changes since 1.134.0rc1. ##### Synapse 1.134.0rc1 (2025-07-09) ##### Features - Support for [MSC4235](https://github.com/matrix-org/matrix-spec-proposals/pull/4235): `via` query param for hierarchy endpoint. Contributed by Krishan ([@&#8203;kfiven](https://github.com/kfiven)). ([#&#8203;18070](https://github.com/element-hq/synapse/issues/18070)) - Add `forget_forced_upon_leave` capability as per [MSC4267](https://github.com/matrix-org/matrix-spec-proposals/pull/4267). ([#&#8203;18196](https://github.com/element-hq/synapse/issues/18196)) - Add `federated_user_may_invite` spam checker callback which receives the entire invite event. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;18241](https://github.com/element-hq/synapse/issues/18241)) ##### Bugfixes - Fix `KeyError` on background updates when using split main/state databases. ([#&#8203;18509](https://github.com/element-hq/synapse/issues/18509)) - Improve performance of device deletion by adding missing index. ([#&#8203;18582](https://github.com/element-hq/synapse/issues/18582)) - Fix `avatar_url` and `displayname` being sent on federation profile queries when they are not set. ([#&#8203;18593](https://github.com/element-hq/synapse/issues/18593)) - Respond with 401 & `M_USER_LOCKED` when a locked user calls `POST /login`, as per the spec. ([#&#8203;18594](https://github.com/element-hq/synapse/issues/18594)) - Ensure policy servers are not asked to scan policy server change events, allowing rooms to disable the use of a policy server while the policy server is down. ([#&#8203;18605](https://github.com/element-hq/synapse/issues/18605)) ##### Improved Documentation - Fix documentation of the Delete Room Admin API's status field. ([#&#8203;18519](https://github.com/element-hq/synapse/issues/18519)) ##### Deprecations and Removals - Stop adding the "origin" field to newly-created events (PDUs). ([#&#8203;18418](https://github.com/element-hq/synapse/issues/18418)) ##### Internal Changes - Replace `PyICU` crate with equivalent `icu_segmenter` Rust crate. ([#&#8203;18553](https://github.com/element-hq/synapse/issues/18553), [#&#8203;18646](https://github.com/element-hq/synapse/issues/18646)) - Improve docstring on `simple_upsert_many`. ([#&#8203;18573](https://github.com/element-hq/synapse/issues/18573)) - Raise poetry-core version cap to 2.1.3. ([#&#8203;18575](https://github.com/element-hq/synapse/issues/18575)) - Raise setuptools\_rust version cap to 1.11.1. ([#&#8203;18576](https://github.com/element-hq/synapse/issues/18576)) - Better handling of ratelimited requests. ([#&#8203;18595](https://github.com/element-hq/synapse/issues/18595), [#&#8203;18600](https://github.com/element-hq/synapse/issues/18600)) - Update to Rust 1.87.0 in CI, and bump the pinned commit of the `dtolnay/rust-toolchain` GitHub Action to `b3b07ba8b418998c39fb20f53e8b695cdcc8de1b`. ([#&#8203;18596](https://github.com/element-hq/synapse/issues/18596)) - Speed up bulk device deletion. ([#&#8203;18602](https://github.com/element-hq/synapse/issues/18602)) - Speed up the building of arm-based wheels in CI. ([#&#8203;18618](https://github.com/element-hq/synapse/issues/18618)) - Speed up the building of Docker images in CI. ([#&#8203;18620](https://github.com/element-hq/synapse/issues/18620)) - Add `.zed/` directory to `.gitignore`. ([#&#8203;18623](https://github.com/element-hq/synapse/issues/18623)) - Log the room ID we're purging state for. ([#&#8203;18625](https://github.com/element-hq/synapse/issues/18625)) ##### Updates to locked dependencies - Bump Swatinem/rust-cache from 2.7.8 to 2.8.0. ([#&#8203;18612](https://github.com/element-hq/synapse/issues/18612)) - Bump attrs from 24.2.0 to 25.3.0. ([#&#8203;18649](https://github.com/element-hq/synapse/issues/18649)) - Bump authlib from 1.5.2 to 1.6.0. ([#&#8203;18642](https://github.com/element-hq/synapse/issues/18642)) - Bump base64 from 0.21.7 to 0.22.1. ([#&#8203;18589](https://github.com/element-hq/synapse/issues/18589)) - Bump base64 from 0.21.7 to 0.22.1. ([#&#8203;18629](https://github.com/element-hq/synapse/issues/18629)) - Bump docker/build-push-action from 6.17.0 to 6.18.0. ([#&#8203;18497](https://github.com/element-hq/synapse/issues/18497)) - Bump docker/setup-buildx-action from 3.10.0 to 3.11.1. ([#&#8203;18587](https://github.com/element-hq/synapse/issues/18587)) - Bump hiredis from 3.1.0 to 3.2.1. ([#&#8203;18638](https://github.com/element-hq/synapse/issues/18638)) - Bump ijson from 3.3.0 to 3.4.0. ([#&#8203;18650](https://github.com/element-hq/synapse/issues/18650)) - Bump jsonschema from 4.23.0 to 4.24.0. ([#&#8203;18630](https://github.com/element-hq/synapse/issues/18630)) - Bump msgpack from 1.1.0 to 1.1.1. ([#&#8203;18651](https://github.com/element-hq/synapse/issues/18651)) - Bump mypy-zope from 1.0.11 to 1.0.12. ([#&#8203;18640](https://github.com/element-hq/synapse/issues/18640)) - Bump phonenumbers from 9.0.2 to 9.0.8. ([#&#8203;18652](https://github.com/element-hq/synapse/issues/18652)) - Bump pillow from 11.2.1 to 11.3.0. ([#&#8203;18624](https://github.com/element-hq/synapse/issues/18624)) - Bump prometheus-client from 0.21.0 to 0.22.1. ([#&#8203;18609](https://github.com/element-hq/synapse/issues/18609)) - Bump pyasn1-modules from 0.4.1 to 0.4.2. ([#&#8203;18495](https://github.com/element-hq/synapse/issues/18495)) - Bump pydantic from 2.11.4 to 2.11.7. ([#&#8203;18639](https://github.com/element-hq/synapse/issues/18639)) - Bump reqwest from 0.12.15 to 0.12.20. ([#&#8203;18590](https://github.com/element-hq/synapse/issues/18590)) - Bump reqwest from 0.12.20 to 0.12.22. ([#&#8203;18627](https://github.com/element-hq/synapse/issues/18627)) - Bump ruff from 0.11.11 to 0.12.1. ([#&#8203;18645](https://github.com/element-hq/synapse/issues/18645)) - Bump ruff from 0.12.1 to 0.12.2. ([#&#8203;18657](https://github.com/element-hq/synapse/issues/18657)) - Bump sentry-sdk from 2.22.0 to 2.32.0. ([#&#8203;18633](https://github.com/element-hq/synapse/issues/18633)) - Bump setuptools-rust from 1.10.2 to 1.11.1. ([#&#8203;18655](https://github.com/element-hq/synapse/issues/18655)) - Bump sigstore/cosign-installer from 3.8.2 to 3.9.0. ([#&#8203;18588](https://github.com/element-hq/synapse/issues/18588)) - Bump sigstore/cosign-installer from 3.9.0 to 3.9.1. ([#&#8203;18608](https://github.com/element-hq/synapse/issues/18608)) - Bump stefanzweifel/git-auto-commit-action from 5.2.0 to 6.0.1. ([#&#8203;18607](https://github.com/element-hq/synapse/issues/18607)) - Bump tokio from 1.45.1 to 1.46.0. ([#&#8203;18628](https://github.com/element-hq/synapse/issues/18628)) - Bump tokio from 1.46.0 to 1.46.1. ([#&#8203;18667](https://github.com/element-hq/synapse/issues/18667)) - Bump treq from 24.9.1 to 25.5.0. ([#&#8203;18610](https://github.com/element-hq/synapse/issues/18610)) - Bump types-bleach from 6.2.0.20241123 to 6.2.0.20250514. ([#&#8203;18634](https://github.com/element-hq/synapse/issues/18634)) - Bump types-jsonschema from 4.23.0.20250516 to 4.24.0.20250528. ([#&#8203;18611](https://github.com/element-hq/synapse/issues/18611)) - Bump types-opentracing from 2.4.10.6 to 2.4.10.20250622. ([#&#8203;18586](https://github.com/element-hq/synapse/issues/18586)) - Bump types-psycopg2 from 2.9.21.20250318 to 2.9.21.20250516. ([#&#8203;18658](https://github.com/element-hq/synapse/issues/18658)) - Bump types-pyyaml from 6.0.12.20241230 to 6.0.12.20250516. ([#&#8203;18643](https://github.com/element-hq/synapse/issues/18643)) - Bump types-setuptools from 75.2.0.20241019 to 80.9.0.20250529. ([#&#8203;18644](https://github.com/element-hq/synapse/issues/18644)) - Bump typing-extensions from 4.12.2 to 4.14.0. ([#&#8203;18654](https://github.com/element-hq/synapse/issues/18654)) - Bump typing-extensions from 4.14.0 to 4.14.1. ([#&#8203;18668](https://github.com/element-hq/synapse/issues/18668)) - Bump urllib3 from 2.2.2 to 2.5.0. ([#&#8203;18572](https://github.com/element-hq/synapse/issues/18572)) ### [`v1.133.0`](https://github.com/element-hq/synapse/releases/tag/v1.133.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.132.0...v1.133.0) ##### Synapse 1.133.0 (2025-07-01) Pre-built wheels are now built using the [manylinux\_2\_28](https://github.com/pypa/manylinux#manylinux_2_28-almalinux-8-based) base, which is expected to be compatible with distros using glibc 2.28 or later, including: - Debian 10+ - Ubuntu 18.10+ - Fedora 29+ - CentOS/RHEL 8+ Previously, wheels were built using the [manylinux2014](https://github.com/pypa/manylinux#manylinux2014-centos-7-based-glibc-217) base, which was expected to be compatible with distros using glibc 2.17 or later. ##### Bugfixes - Bump `cibuildwheel` to 3.0.0 to fix the `manylinux` wheel builds. ([#&#8203;18615](https://github.com/element-hq/synapse/issues/18615)) ##### Synapse 1.133.0rc1 (2025-06-24) ##### Features - Add support for the [MSC4260 user report API](https://github.com/matrix-org/matrix-spec-proposals/pull/4260). ([#&#8203;18120](https://github.com/element-hq/synapse/issues/18120)) ##### Bugfixes - Fix an issue where, during state resolution for v11 rooms, Synapse would incorrectly calculate the power level of the creator when there was no power levels event in the room. ([#&#8203;18534](https://github.com/element-hq/synapse/issues/18534), [#&#8203;18547](https://github.com/element-hq/synapse/issues/18547)) - Fix long-standing bug where sliding sync did not honour the `room_id_to_include` config option. ([#&#8203;18535](https://github.com/element-hq/synapse/issues/18535)) - Fix an issue where "Lock timeout is getting excessive" warnings would be logged even when the lock timeout was <10 minutes. ([#&#8203;18543](https://github.com/element-hq/synapse/issues/18543)) - Fix an issue where Synapse could calculate the wrong power level for the creator of the room if there was no power levels event. ([#&#8203;18545](https://github.com/element-hq/synapse/issues/18545)) ##### Improved Documentation - Generate config documentation from JSON Schema file. ([#&#8203;18528](https://github.com/element-hq/synapse/issues/18528)) - Fix typo in user type documentation. ([#&#8203;18568](https://github.com/element-hq/synapse/issues/18568)) ##### Internal Changes - Increase performance of introspecting access tokens when using delegated auth. ([#&#8203;18357](https://github.com/element-hq/synapse/issues/18357), [#&#8203;18561](https://github.com/element-hq/synapse/issues/18561)) - Log user deactivations. ([#&#8203;18541](https://github.com/element-hq/synapse/issues/18541)) - Enable [`flake8-logging`](https://docs.astral.sh/ruff/rules/#flake8-logging-log) and [`flake8-logging-format`](https://docs.astral.sh/ruff/rules/#flake8-logging-format-g) rules in Ruff and fix related issues throughout the codebase. ([#&#8203;18542](https://github.com/element-hq/synapse/issues/18542)) - Clean up old, unused rows from the `device_federation_inbox` table. ([#&#8203;18546](https://github.com/element-hq/synapse/issues/18546)) - Run config schema CI on develop and release branches. ([#&#8203;18551](https://github.com/element-hq/synapse/issues/18551)) - Add support for Twisted `25.5.0`+ releases. ([#&#8203;18577](https://github.com/element-hq/synapse/issues/18577)) - Update PyO3 to version 0.25. ([#&#8203;18578](https://github.com/element-hq/synapse/issues/18578)) ##### Updates to locked dependencies - Bump actions/setup-python from 5.5.0 to 5.6.0. ([#&#8203;18555](https://github.com/element-hq/synapse/issues/18555)) - Bump base64 from 0.21.7 to 0.22.1. ([#&#8203;18559](https://github.com/element-hq/synapse/issues/18559)) - Bump dawidd6/action-download-artifact from 9 to 11. ([#&#8203;18556](https://github.com/element-hq/synapse/issues/18556)) - Bump headers from 0.4.0 to 0.4.1. ([#&#8203;18529](https://github.com/element-hq/synapse/issues/18529)) - Bump requests from 2.32.2 to 2.32.4. ([#&#8203;18533](https://github.com/element-hq/synapse/issues/18533)) - Bump types-requests from 2.32.0.20250328 to 2.32.4.20250611. ([#&#8203;18558](https://github.com/element-hq/synapse/issues/18558)) ### [`v1.132.0`](https://github.com/element-hq/synapse/releases/tag/v1.132.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.131.0...v1.132.0) ##### Synapse 1.132.0 (2025-06-17) ##### Improved Documentation - Improvements to generate config documentation from JSON Schema file. ([#&#8203;18522](https://github.com/element-hq/synapse/issues/18522)) ##### Synapse 1.132.0rc1 (2025-06-10) ##### Features - Add support for [MSC4155](https://github.com/matrix-org/matrix-spec-proposals/pull/4155) Invite Filtering. ([#&#8203;18288](https://github.com/element-hq/synapse/issues/18288)) - Add experimental `user_may_send_state_event` module API callback. ([#&#8203;18455](https://github.com/element-hq/synapse/issues/18455)) - Add experimental `get_media_config_for_user` and `is_user_allowed_to_upload_media_of_size` module API callbacks that allow overriding of media repository maximum upload size. ([#&#8203;18457](https://github.com/element-hq/synapse/issues/18457)) - Add experimental `get_ratelimit_override_for_user` module API callback that allows overriding of per-user ratelimits. ([#&#8203;18458](https://github.com/element-hq/synapse/issues/18458)) - Pass `room_config` argument to `user_may_create_room` spam checker module callback. ([#&#8203;18486](https://github.com/element-hq/synapse/issues/18486)) - Support configuration of default and extra user types. ([#&#8203;18456](https://github.com/element-hq/synapse/issues/18456)) - Successful requests to `/_matrix/app/v1/ping` will now force Synapse to reattempt delivering transactions to appservices. ([#&#8203;18521](https://github.com/element-hq/synapse/issues/18521)) - Support the import of the `RatelimitOverride` type from `synapse.module_api` in modules and rename `messages_per_second` to `per_second`. ([#&#8203;18513](https://github.com/element-hq/synapse/issues/18513)) ##### Bugfixes - Remove destinations from sending if not whitelisted. ([#&#8203;18484](https://github.com/element-hq/synapse/issues/18484)) - Fixed room summary API incorrectly returning that a room is private in the room summary response when the join rule is omitted by the remote server. Contributed by [@&#8203;nexy7574](https://github.com/nexy7574). ([#&#8203;18493](https://github.com/element-hq/synapse/issues/18493)) - Prevent users from adding themselves to their own user ignore list. ([#&#8203;18508](https://github.com/element-hq/synapse/issues/18508)) ##### Improved Documentation - Generate config documentation from JSON Schema file. ([#&#8203;17892](https://github.com/element-hq/synapse/issues/17892)) - Mention `CAP_NET_BIND_SERVICE` as an alternative to running Synapse as root in order to bind to a privileged port. ([#&#8203;18408](https://github.com/element-hq/synapse/issues/18408)) - Surface hidden Admin API documentation regarding fetching of scheduled tasks. ([#&#8203;18516](https://github.com/element-hq/synapse/issues/18516)) - Mark the new module APIs in this release as experimental. ([#&#8203;18536](https://github.com/element-hq/synapse/issues/18536)) ##### Internal Changes - Mark dehydrated devices in the [List All User Devices Admin API](https://element-hq.github.io/synapse/latest/admin_api/user_admin_api.html#list-all-devices). ([#&#8203;18252](https://github.com/element-hq/synapse/issues/18252)) - Reduce disk wastage by cleaning up `received_transactions` older than 1 day, rather than 30 days. ([#&#8203;18310](https://github.com/element-hq/synapse/issues/18310)) - Distinguish all vs local events being persisted in the "Event Send Time Quantiles" graph (Grafana). ([#&#8203;18510](https://github.com/element-hq/synapse/issues/18510)) ### [`v1.131.0`](https://github.com/element-hq/synapse/releases/tag/v1.131.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.130.0...v1.131.0) ##### Synapse 1.131.0 (2025-06-03) No significant changes since 1.131.0rc1. ##### Synapse 1.131.0rc1 (2025-05-28) ##### Features - Add `msc4263_limit_key_queries_to_users_who_share_rooms` config option as per [MSC4263](https://github.com/matrix-org/matrix-spec-proposals/pull/4263). ([#&#8203;18180](https://github.com/element-hq/synapse/issues/18180)) - Add option to allow registrations that begin with `_`. Contributed by `_` ([@&#8203;hex5f](https://github.com/hex5f)). ([#&#8203;18262](https://github.com/element-hq/synapse/issues/18262)) - Include room ID in response to the [Room Deletion Status Admin API](https://element-hq.github.io/synapse/latest/admin_api/rooms.html#status-of-deleting-rooms). ([#&#8203;18318](https://github.com/element-hq/synapse/issues/18318)) - Add support for calling Policy Servers ([MSC4284](https://github.com/matrix-org/matrix-spec-proposals/pull/4284)) to mark events as spam. ([#&#8203;18387](https://github.com/element-hq/synapse/issues/18387)) ##### Bugfixes - Prevent race-condition in `_maybe_retry_device_resync` entrance. ([#&#8203;18391](https://github.com/element-hq/synapse/issues/18391)) - Fix the `tests.handlers.test_worker_lock.WorkerLockTestCase.test_lock_contention` test which could spuriously time out on RISC-V architectures due to performance differences. ([#&#8203;18430](https://github.com/element-hq/synapse/issues/18430)) - Fix admin redaction endpoint not redacting encrypted messages. ([#&#8203;18434](https://github.com/element-hq/synapse/issues/18434)) ##### Improved Documentation - Update `room_list_publication_rules` docs to consider defaults that changed in v1.126.0. Contributed by [@&#8203;HarHarLinks](https://github.com/HarHarLinks). ([#&#8203;18286](https://github.com/element-hq/synapse/issues/18286)) - Add advice for upgrading between major PostgreSQL versions to the database documentation. ([#&#8203;18445](https://github.com/element-hq/synapse/issues/18445)) ##### Internal Changes - Fix a memory leak in `_NotifierUserStream`. ([#&#8203;18380](https://github.com/element-hq/synapse/issues/18380)) - Fix a couple type annotations in the `RootConfig`/`Config`. ([#&#8203;18409](https://github.com/element-hq/synapse/issues/18409)) - Explicitly enable PyPy builds in `cibuildwheel`s config to avoid it being disabled on a future upgrade to `cibuildwheel` v3. ([#&#8203;18417](https://github.com/element-hq/synapse/issues/18417)) - Update the PR review template to remove an erroneous line break from the final bullet point. ([#&#8203;18419](https://github.com/element-hq/synapse/issues/18419)) - Explain why we `flush_buffer()` for Python `print(...)` output. ([#&#8203;18420](https://github.com/element-hq/synapse/issues/18420)) - Add lint to ensure we don't add a `CREATE/DROP INDEX` in a schema delta. ([#&#8203;18440](https://github.com/element-hq/synapse/issues/18440)) - Allow checking only for the existence of a field in an SSO provider's response, rather than requiring the value(s) to check. ([#&#8203;18454](https://github.com/element-hq/synapse/issues/18454)) - Add unit tests for homeserver usage statistics. ([#&#8203;18463](https://github.com/element-hq/synapse/issues/18463)) - Don't move invited users to new room when shutting down room. ([#&#8203;18471](https://github.com/element-hq/synapse/issues/18471)) ##### Updates to locked dependencies - Bump actions/setup-python from 5.5.0 to 5.6.0. ([#&#8203;18398](https://github.com/element-hq/synapse/issues/18398)) - Bump authlib from 1.5.1 to 1.5.2. ([#&#8203;18452](https://github.com/element-hq/synapse/issues/18452)) - Bump docker/build-push-action from 6.15.0 to 6.17.0. ([#&#8203;18397](https://github.com/element-hq/synapse/issues/18397), [#&#8203;18449](https://github.com/element-hq/synapse/issues/18449)) - Bump lxml from 5.3.0 to 5.4.0. ([#&#8203;18480](https://github.com/element-hq/synapse/issues/18480)) - Bump mypy-zope from 1.0.9 to 1.0.11. ([#&#8203;18428](https://github.com/element-hq/synapse/issues/18428)) - Bump pyo3 from 0.23.5 to 0.24.2. ([#&#8203;18460](https://github.com/element-hq/synapse/issues/18460)) - Bump pyo3-log from 0.12.3 to 0.12.4. ([#&#8203;18453](https://github.com/element-hq/synapse/issues/18453)) - Bump pyopenssl from 25.0.0 to 25.1.0. ([#&#8203;18450](https://github.com/element-hq/synapse/issues/18450)) - Bump ruff from 0.7.3 to 0.11.11. ([#&#8203;18451](https://github.com/element-hq/synapse/issues/18451), [#&#8203;18482](https://github.com/element-hq/synapse/issues/18482)) - Bump tornado from 6.4.2 to 6.5.0. ([#&#8203;18459](https://github.com/element-hq/synapse/issues/18459)) - Bump setuptools from 72.1.0 to 78.1.1. ([#&#8203;18461](https://github.com/element-hq/synapse/issues/18461)) - Bump types-jsonschema from 4.23.0.20241208 to 4.23.0.20250516. ([#&#8203;18481](https://github.com/element-hq/synapse/issues/18481)) - Bump types-requests from 2.32.0.20241016 to 2.32.0.20250328. ([#&#8203;18427](https://github.com/element-hq/synapse/issues/18427)) ### [`v1.130.0`](https://github.com/element-hq/synapse/releases/tag/v1.130.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.129.0...v1.130.0) ##### Synapse 1.130.0 (2025-05-20) ##### Bugfixes - Fix startup being blocked on creating a new index that was introduced in v1.130.0rc1. ([#&#8203;18439](https://github.com/element-hq/synapse/issues/18439)) - Fix the ordering of local messages in rooms that were affected by [GHSA-v56r-hwv5-mxg6](https://github.com/advisories/GHSA-v56r-hwv5-mxg6). ([#&#8203;18447](https://github.com/element-hq/synapse/issues/18447)) ##### Synapse 1.130.0rc1 (2025-05-13) ##### Features - Add an Admin API endpoint `GET /_synapse/admin/v1/scheduled_tasks` to fetch scheduled tasks. ([#&#8203;18214](https://github.com/element-hq/synapse/issues/18214)) - Add config option `user_directory.exclude_remote_users` which, when enabled, excludes remote users from user directory search results. ([#&#8203;18300](https://github.com/element-hq/synapse/issues/18300)) - Add support for handling `GET /devices/` on workers. ([#&#8203;18355](https://github.com/element-hq/synapse/issues/18355)) ##### Bugfixes - Fix a longstanding bug where Synapse would immediately retry a failing push endpoint when a new event is received, ignoring any backoff timers. ([#&#8203;18363](https://github.com/element-hq/synapse/issues/18363)) - Pass leave from remote invite rejection down Sliding Sync. ([#&#8203;18375](https://github.com/element-hq/synapse/issues/18375)) ##### Updates to the Docker image - In `configure_workers_and_start.py`, use the same absolute path of Python in the interpreter shebang, and invoke child Python processes with `sys.executable`. ([#&#8203;18291](https://github.com/element-hq/synapse/issues/18291)) - Optimize the build of the workers image. ([#&#8203;18292](https://github.com/element-hq/synapse/issues/18292)) - In `start_for_complement.sh`, replace some external program calls with shell builtins. ([#&#8203;18293](https://github.com/element-hq/synapse/issues/18293)) - When generating container scripts from templates, don't add a leading newline so that their shebangs may be handled correctly. ([#&#8203;18295](https://github.com/element-hq/synapse/issues/18295)) ##### Improved Documentation - Improve formatting of the README file. ([#&#8203;18218](https://github.com/element-hq/synapse/issues/18218)) - Add documentation for configuring [Pocket ID](https://github.com/pocket-id/pocket-id) as an OIDC provider. ([#&#8203;18237](https://github.com/element-hq/synapse/issues/18237)) - Fix typo in docs about the `push` config option. Contributed by [@&#8203;HarHarLinks](https://github.com/HarHarLinks). ([#&#8203;18320](https://github.com/element-hq/synapse/issues/18320)) - Add `/_matrix/federation/v1/version` to list of federation endpoints that can be handled by workers. ([#&#8203;18377](https://github.com/element-hq/synapse/issues/18377)) - Add an Admin API endpoint `GET /_synapse/admin/v1/scheduled_tasks` to fetch scheduled tasks. ([#&#8203;18384](https://github.com/element-hq/synapse/issues/18384)) ##### Internal Changes - Return specific error code when adding an email address / phone number to account is not supported ([MSC4178](https://github.com/matrix-org/matrix-spec-proposals/pull/4178)). ([#&#8203;17578](https://github.com/element-hq/synapse/issues/17578)) - Stop auto-provisionning missing users & devices when delegating auth to Matrix Authentication Service. Requires MAS 0.13.0 or later. ([#&#8203;18181](https://github.com/element-hq/synapse/issues/18181)) - Apply file hashing and existing quarantines to media downloaded for URL previews. ([#&#8203;18297](https://github.com/element-hq/synapse/issues/18297)) - Allow a few admin APIs used by matrix-authentication-service to run on workers. ([#&#8203;18313](https://github.com/element-hq/synapse/issues/18313)) - Apply `should_drop_federated_event` to federation invites. ([#&#8203;18330](https://github.com/element-hq/synapse/issues/18330)) - Allow `/rooms/` admin API to be run on workers. ([#&#8203;18360](https://github.com/element-hq/synapse/issues/18360)) - Minor performance improvements to the notifier. ([#&#8203;18367](https://github.com/element-hq/synapse/issues/18367)) - Slight performance increase when using the ratelimiter. ([#&#8203;18369](https://github.com/element-hq/synapse/issues/18369)) - Don't validate the `at_hash` (access token hash) field in OIDC ID Tokens if we don't end up actually using the OIDC Access Token. ([#&#8203;18374](https://github.com/element-hq/synapse/issues/18374), [#&#8203;18385](https://github.com/element-hq/synapse/issues/18385)) - Fixed test failures when using authlib 1.5.2. ([#&#8203;18390](https://github.com/element-hq/synapse/issues/18390)) - Refactor [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Simplified Sliding Sync room list tests to cover both new and fallback logic paths. ([#&#8203;18399](https://github.com/element-hq/synapse/issues/18399)) ##### Updates to locked dependencies - Bump actions/add-to-project from [`280af8a`](https://github.com/element-hq/synapse/commit/280af8ae1f83a494cfad2cb10f02f6d13529caa9) to [`5b1a254`](https://github.com/element-hq/synapse/commit/5b1a254a3546aef88e0a7724a77a623fa2e47c36). ([#&#8203;18365](https://github.com/element-hq/synapse/issues/18365)) - Bump actions/download-artifact from 4.2.1 to 4.3.0. ([#&#8203;18364](https://github.com/element-hq/synapse/issues/18364)) - Bump actions/setup-go from 5.4.0 to 5.5.0. ([#&#8203;18426](https://github.com/element-hq/synapse/issues/18426)) - Bump anyhow from 1.0.97 to 1.0.98. ([#&#8203;18336](https://github.com/element-hq/synapse/issues/18336)) - Bump packaging from 24.2 to 25.0. ([#&#8203;18393](https://github.com/element-hq/synapse/issues/18393)) - Bump pillow from 11.1.0 to 11.2.1. ([#&#8203;18429](https://github.com/element-hq/synapse/issues/18429)) - Bump pydantic from 2.10.3 to 2.11.4. ([#&#8203;18394](https://github.com/element-hq/synapse/issues/18394)) - Bump pyo3-log from 0.12.2 to 0.12.3. ([#&#8203;18317](https://github.com/element-hq/synapse/issues/18317)) - Bump pyopenssl from 24.3.0 to 25.0.0. ([#&#8203;18315](https://github.com/element-hq/synapse/issues/18315)) - Bump sha2 from 0.10.8 to 0.10.9. ([#&#8203;18395](https://github.com/element-hq/synapse/issues/18395)) - Bump sigstore/cosign-installer from 3.8.1 to 3.8.2. ([#&#8203;18366](https://github.com/element-hq/synapse/issues/18366)) - Bump softprops/action-gh-release from 1 to 2. ([#&#8203;18264](https://github.com/element-hq/synapse/issues/18264)) - Bump stefanzweifel/git-auto-commit-action from 5.1.0 to 5.2.0. ([#&#8203;18354](https://github.com/element-hq/synapse/issues/18354)) - Bump txredisapi from 1.4.10 to 1.4.11. ([#&#8203;18392](https://github.com/element-hq/synapse/issues/18392)) - Bump types-jsonschema from 4.23.0.20240813 to 4.23.0.20241208. ([#&#8203;18305](https://github.com/element-hq/synapse/issues/18305)) - Bump types-psycopg2 from 2.9.21.20250121 to 2.9.21.20250318. ([#&#8203;18316](https://github.com/element-hq/synapse/issues/18316)) ### [`v1.129.0`](https://github.com/element-hq/synapse/releases/tag/v1.129.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.128.0...v1.129.0) ##### Synapse 1.129.0 (2025-05-06) No significant changes since 1.129.0rc2. ##### Synapse 1.129.0rc2 (2025-04-30) Synapse 1.129.0rc1 was never formally released due to regressions discovered during the release process. 1.129.0rc2 fixes those regressions by reverting the affected PRs. ##### Internal Changes - Revert the slow background update introduced by [#&#8203;18068](https://github.com/element-hq/synapse/issues/18068) in v1.128.0. ([#&#8203;18372](https://github.com/element-hq/synapse/issues/18372)) - Revert "Add `total_event_count`, `total_message_count`, and `total_e2ee_event_count` fields to the homeserver usage statistics.", added in v1.129.0rc1. ([#&#8203;18373](https://github.com/element-hq/synapse/issues/18373)) ##### Synapse 1.129.0rc1 (2025-04-15) ##### Features - Add `passthrough_authorization_parameters` in OIDC configuration to allow passing parameters to the authorization grant URL. ([#&#8203;18232](https://github.com/element-hq/synapse/issues/18232)) - ~~Add `total_event_count`, `total_message_count`, and `total_e2ee_event_count` fields to the homeserver usage statistics. ([#&#8203;18260](https://github.com/element-hq/synapse/issues/18260))~~ This was reverted in 1.129.0rc2. ##### Bugfixes - Fix `force_tracing_for_users` config when using delegated auth. ([#&#8203;18334](https://github.com/element-hq/synapse/issues/18334)) - Fix the token introspection cache logging access tokens when MAS integration is in use. ([#&#8203;18335](https://github.com/element-hq/synapse/issues/18335)) - Stop caching introspection failures when delegating auth to MAS. ([#&#8203;18339](https://github.com/element-hq/synapse/issues/18339)) - Fix `ExternalIDReuse` exception after migrating to MAS on workers with a high traffic. ([#&#8203;18342](https://github.com/element-hq/synapse/issues/18342)) - Fix minor performance regression caused by tracking of room participation. Regressed in v1.128.0. ([#&#8203;18345](https://github.com/element-hq/synapse/issues/18345)) ##### Updates to the Docker image - Optimize the build of the complement-synapse image. ([#&#8203;18294](https://github.com/element-hq/synapse/issues/18294)) ##### Internal Changes - Disable statement timeout during room purge. ([#&#8203;18133](https://github.com/element-hq/synapse/issues/18133)) - Add cache to storage functions used to auth requests when using delegated auth. ([#&#8203;18337](https://github.com/element-hq/synapse/issues/18337)) ### [`v1.128.0`](https://github.com/element-hq/synapse/releases/tag/v1.128.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.127.1...v1.128.0) ##### Synapse 1.128.0 (2025-04-08) No significant changes since 1.128.0rc1. ##### Synapse 1.128.0rc1 (2025-04-01) ##### Features - Add an access token introspection cache to make Matrix Authentication Service integration ([MSC3861](https://github.com/matrix-org/matrix-doc/pull/3861)) more efficient. ([#&#8203;18231](https://github.com/element-hq/synapse/issues/18231)) - Add background job to clear unreferenced state groups. ([#&#8203;18254](https://github.com/element-hq/synapse/issues/18254)) - Hashes of media files are now tracked by Synapse. Media quarantines will now apply to all files with the same hash. ([#&#8203;18277](https://github.com/element-hq/synapse/issues/18277), [#&#8203;18302](https://github.com/element-hq/synapse/issues/18302), [#&#8203;18296](https://github.com/element-hq/synapse/issues/18296)) ##### Bugfixes - Add index to sliding sync ([MSC4186](https://github.com/matrix-org/matrix-doc/pull/4186)) membership snapshot table, to fix a performance issue. ([#&#8203;18074](https://github.com/element-hq/synapse/issues/18074)) ##### Updates to the Docker image - Specify the architecture of installed packages via an APT config option, which is more reliable than appending package names with `:{arch}`. ([#&#8203;18271](https://github.com/element-hq/synapse/issues/18271)) - Always specify base image debian versions with a build argument. ([#&#8203;18272](https://github.com/element-hq/synapse/issues/18272)) - Allow passing arguments to `start_for_complement.sh` (to be sent to `configure_workers_and_start.py`). ([#&#8203;18273](https://github.com/element-hq/synapse/issues/18273)) - Make some improvements to the `prefix-log` script in the workers image. ([#&#8203;18274](https://github.com/element-hq/synapse/issues/18274)) - Use `uv pip` to install `supervisor` in the worker image. ([#&#8203;18275](https://github.com/element-hq/synapse/issues/18275)) - Avoid needing to download & use `rsync` in a build layer. ([#&#8203;18287](https://github.com/element-hq/synapse/issues/18287)) ##### Improved Documentation - Fix how to obtain access token and change naming from riot to element ([#&#8203;18225](https://github.com/element-hq/synapse/issues/18225)) - Correct a small typo in the SSO mapping providers documentation. ([#&#8203;18276](https://github.com/element-hq/synapse/issues/18276)) - Add docs for how to clear out the Poetry wheel cache. ([#&#8203;18283](https://github.com/element-hq/synapse/issues/18283)) ##### Internal Changes - Add a column `participant` to `room_memberships` table. ([#&#8203;18068](https://github.com/element-hq/synapse/issues/18068)) - Update Poetry to 2.1.1, including updating the lock file version. ([#&#8203;18251](https://github.com/element-hq/synapse/issues/18251)) - Pin GitHub Actions dependencies by commit hash. ([#&#8203;18255](https://github.com/element-hq/synapse/issues/18255)) - Add DB delta to remove the old state group deletion job. ([#&#8203;18284](https://github.com/element-hq/synapse/issues/18284)) ##### Updates to locked dependencies - Bump actions/add-to-project from [`f5473ac`](https://github.com/element-hq/synapse/commit/f5473ace9aeee8b97717b281e26980aa5097023f) to [`280af8a`](https://github.com/element-hq/synapse/commit/280af8ae1f83a494cfad2cb10f02f6d13529caa9). ([#&#8203;18303](https://github.com/element-hq/synapse/issues/18303)) - Bump actions/cache from 4.2.2 to 4.2.3. ([#&#8203;18266](https://github.com/element-hq/synapse/issues/18266)) - Bump actions/download-artifact from 4.2.0 to 4.2.1. ([#&#8203;18268](https://github.com/element-hq/synapse/issues/18268)) - Bump actions/setup-python from 5.4.0 to 5.5.0. ([#&#8203;18298](https://github.com/element-hq/synapse/issues/18298)) - Bump actions/upload-artifact from 4.6.1 to 4.6.2. ([#&#8203;18304](https://github.com/element-hq/synapse/issues/18304)) - Bump authlib from 1.4.1 to 1.5.1. ([#&#8203;18306](https://github.com/element-hq/synapse/issues/18306)) - Bump dawidd6/action-download-artifact from 8 to 9. ([#&#8203;18204](https://github.com/element-hq/synapse/issues/18204)) - Bump jinja2 from 3.1.5 to 3.1.6. ([#&#8203;18223](https://github.com/element-hq/synapse/issues/18223)) - Bump log from 0.4.26 to 0.4.27. ([#&#8203;18267](https://github.com/element-hq/synapse/issues/18267)) - Bump phonenumbers from 8.13.50 to 9.0.2. ([#&#8203;18299](https://github.com/element-hq/synapse/issues/18299)) - Bump pygithub from 2.5.0 to 2.6.1. ([#&#8203;18243](https://github.com/element-hq/synapse/issues/18243)) - Bump pyo3-log from 0.12.1 to 0.12.2. ([#&#8203;18269](https://github.com/element-hq/synapse/issues/18269)) ### [`v1.127.1`](https://github.com/element-hq/synapse/releases/tag/v1.127.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.127.0...v1.127.1) ##### Synapse 1.127.1 (2025-03-26) ##### Security - Fix [CVE-2025-30355](https://www.cve.org/CVERecord?id=CVE-2025-30355) / [GHSA-v56r-hwv5-mxg6](https://github.com/element-hq/synapse/security/advisories/GHSA-v56r-hwv5-mxg6). **High severity vulnerability affecting federation. The vulnerability has been exploited in the wild.** ### [`v1.127.0`](https://github.com/element-hq/synapse/releases/tag/v1.127.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.126.0...v1.127.0) ##### Synapse 1.127.0 (2025-03-25) No significant changes since 1.127.0rc1. ##### Synapse 1.127.0rc1 (2025-03-18) ##### Features - Update [MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140) implementation to no longer cancel a user's own delayed state events with an event type & state key that match a more recent state event sent by that user. ([#&#8203;17810](https://github.com/element-hq/synapse/issues/17810)) ##### Improved Documentation - Fixed a minor typo in the Synapse documentation. Contributed by [@&#8203;karuto12](https://github.com/karuto12). ([#&#8203;18224](https://github.com/element-hq/synapse/issues/18224)) ##### Internal Changes - Remove undocumented `SYNAPSE_USE_FROZEN_DICTS` environment variable. ([#&#8203;18123](https://github.com/element-hq/synapse/issues/18123)) - Fix detection of workflow failures in the release script. ([#&#8203;18211](https://github.com/element-hq/synapse/issues/18211)) - Add caching support to media endpoints. ([#&#8203;18235](https://github.com/element-hq/synapse/issues/18235)) ##### Updates to locked dependencies - Bump anyhow from 1.0.96 to 1.0.97. ([#&#8203;18201](https://github.com/element-hq/synapse/issues/18201)) - Bump bcrypt from 4.2.1 to 4.3.0. ([#&#8203;18207](https://github.com/element-hq/synapse/issues/18207)) - Bump bytes from 1.10.0 to 1.10.1. ([#&#8203;18227](https://github.com/element-hq/synapse/issues/18227)) - Bump http from 1.2.0 to 1.3.1. ([#&#8203;18245](https://github.com/element-hq/synapse/issues/18245)) - Bump sentry-sdk from 2.19.2 to 2.22.0. ([#&#8203;18205](https://github.com/element-hq/synapse/issues/18205)) - Bump serde from 1.0.218 to 1.0.219. ([#&#8203;18228](https://github.com/element-hq/synapse/issues/18228)) - Bump serde\_json from 1.0.139 to 1.0.140. ([#&#8203;18202](https://github.com/element-hq/synapse/issues/18202)) - Bump ulid from 1.2.0 to 1.2.1. ([#&#8203;18246](https://github.com/element-hq/synapse/issues/18246)) ### [`v1.126.0`](https://github.com/element-hq/synapse/releases/tag/v1.126.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.125.0...v1.126.0) ##### Synapse 1.126.0 (2025-03-11) No significant changes since 1.126.0rc3. ##### Synapse 1.126.0rc3 (2025-03-07) ##### Bugfixes - Revert the background job to clear unreferenced state groups (that was introduced in v1.126.0rc1), due to [a suspected issue](https://github.com/element-hq/synapse/issues/18217) that causes increased disk usage. ([#&#8203;18222](https://github.com/element-hq/synapse/issues/18222)) ##### Synapse 1.126.0rc2 (2025-03-05) Administrators using the Debian/Ubuntu packages from `packages.matrix.org`, please check [the relevant section in the upgrade notes](https://github.com/element-hq/synapse/blob/release-v1.126/docs/upgrade.md#change-of-signing-key-expiry-date-for-the-debianubuntu-package-repository) as we have recently updated the expiry date on the repository's GPG signing key. The old version of the key will expire on `2025-03-15`. ##### Internal Changes - Fix wheel building configuration in CI by installing libatomic1. ([#&#8203;18212](https://github.com/element-hq/synapse/issues/18212), [#&#8203;18213](https://github.com/element-hq/synapse/issues/18213)) ##### Synapse 1.126.0rc1 (2025-03-04) Synapse 1.126.0rc1 was not fully released due to an error in CI. ##### Features - Define ratelimit configuration for delayed event management. ([#&#8203;18019](https://github.com/element-hq/synapse/issues/18019)) - Add `form_secret_path` config option. ([#&#8203;18090](https://github.com/element-hq/synapse/issues/18090)) - Add the `--no-secrets-in-config` command line option. ([#&#8203;18092](https://github.com/element-hq/synapse/issues/18092)) - Add background job to clear unreferenced state groups. ([#&#8203;18154](https://github.com/element-hq/synapse/issues/18154)) - Add support for specifying/overriding `id_token_signing_alg_values_supported` for an OpenID identity provider. ([#&#8203;18177](https://github.com/element-hq/synapse/issues/18177)) - Add `worker_replication_secret_path` config option. ([#&#8203;18191](https://github.com/element-hq/synapse/issues/18191)) - Add support for specifying/overriding `redirect_uri` in the authorization and token requests against an OpenID identity provider. ([#&#8203;18197](https://github.com/element-hq/synapse/issues/18197)) ##### Bugfixes - Make sure we advertise registration as disabled when [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861) is enabled. ([#&#8203;17661](https://github.com/element-hq/synapse/issues/17661)) - Prevent suspended users from sending encrypted messages. ([#&#8203;18157](https://github.com/element-hq/synapse/issues/18157)) - Cleanup deleted state group references. ([#&#8203;18165](https://github.com/element-hq/synapse/issues/18165)) - Fix [MSC4108 QR-code login](https://github.com/matrix-org/matrix-spec-proposals/pull/4108) not working with some reverse-proxy setups. ([#&#8203;18178](https://github.com/element-hq/synapse/issues/18178)) - Support device IDs that can't be represented in a scope when delegating auth to Matrix Authentication Service 0.15.0+. ([#&#8203;18174](https://github.com/element-hq/synapse/issues/18174)) ##### Updates to the Docker image - Speed up the building of the Docker image. ([#&#8203;18038](https://github.com/element-hq/synapse/issues/18038)) ##### Improved Documentation - Move incorrectly placed version indicator in User Event Redaction Admin API docs. ([#&#8203;18152](https://github.com/element-hq/synapse/issues/18152)) - Document suspension Admin API. ([#&#8203;18162](https://github.com/element-hq/synapse/issues/18162)) ##### Deprecations and Removals - Disable room list publication by default. ([#&#8203;18175](https://github.com/element-hq/synapse/issues/18175)) ##### Updates to locked dependencies - Bump anyhow from 1.0.95 to 1.0.96. ([#&#8203;18187](https://github.com/element-hq/synapse/issues/18187)) - Bump authlib from 1.4.0 to 1.4.1. ([#&#8203;18190](https://github.com/element-hq/synapse/issues/18190)) - Bump click from 8.1.7 to 8.1.8. ([#&#8203;18189](https://github.com/element-hq/synapse/issues/18189)) - Bump log from 0.4.25 to 0.4.26. ([#&#8203;18184](https://github.com/element-hq/synapse/issues/18184)) - Bump pyo3-log from 0.12.0 to 0.12.1. ([#&#8203;18046](https://github.com/element-hq/synapse/issues/18046)) - Bump serde from 1.0.217 to 1.0.218. ([#&#8203;18183](https://github.com/element-hq/synapse/issues/18183)) - Bump serde\_json from 1.0.138 to 1.0.139. ([#&#8203;18186](https://github.com/element-hq/synapse/issues/18186)) - Bump sigstore/cosign-installer from 3.8.0 to 3.8.1. ([#&#8203;18185](https://github.com/element-hq/synapse/issues/18185)) - Bump types-psycopg2 from 2.9.21.20241019 to 2.9.21.20250121. ([#&#8203;18188](https://github.com/element-hq/synapse/issues/18188)) ### [`v1.125.0`](https://github.com/element-hq/synapse/releases/tag/v1.125.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.124.0...v1.125.0) ##### Synapse 1.125.0 (2025-02-25) No significant changes since 1.125.0rc1. ##### Synapse 1.125.0rc1 (2025-02-18) ##### Features - Add functionality to be able to use multiple values in SSO feature `attribute_requirements`. ([#&#8203;17949](https://github.com/element-hq/synapse/issues/17949)) - Add experimental config options `admin_token_path` and `client_secret_path` for [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861). ([#&#8203;18004](https://github.com/element-hq/synapse/issues/18004)) - Add `get_current_time_msec()` method to the [module API](https://matrix-org.github.io/synapse/latest/modules/writing_a_module.html) for sound time comparisons with Synapse. ([#&#8203;18144](https://github.com/element-hq/synapse/issues/18144)) ##### Bugfixes - Update the response when a client attempts to add an invalid email address to the user's account from a 500, to a 400 with error text. ([#&#8203;18125](https://github.com/element-hq/synapse/issues/18125)) - Fix user directory search when using a legacy module with a `check_username_for_spam` callback. Broke in v1.122.0. ([#&#8203;18135](https://github.com/element-hq/synapse/issues/18135)) ##### Updates to the Docker image - Add `SYNAPSE_HTTP_PROXY`/`SYNAPSE_HTTPS_PROXY`/`SYNAPSE_NO_PROXY` environment variables to pass through specifically to the Synapse process (instead of needing to apply [`http_proxy`/`https_proxy`/`no_proxy`](https://element-hq.github.io/synapse/latest/setup/forward_proxy.html) globally). ([#&#8203;18158](https://github.com/element-hq/synapse/issues/18158)) ##### Improved Documentation - Add Oracle Linux 8 and 9 installation instructions. ([#&#8203;17436](https://github.com/element-hq/synapse/issues/17436)) - Document missing server config options (`daemonize`, `print_pidfile`, `user_agent_suffix`, `use_frozen_dicts`, `manhole`). ([#&#8203;18122](https://github.com/element-hq/synapse/issues/18122)) - Document consequences of replacing secrets. ([#&#8203;18138](https://github.com/element-hq/synapse/issues/18138)) - Make `burst_count` field an integer in `rc_presence` config documentation example. ([#&#8203;18159](https://github.com/element-hq/synapse/issues/18159)) ##### Internal Changes - Overload `DatabasePool.simple_select_one_txn` to return non-`None` when the `allow_none` parameter is `False`. ([#&#8203;17616](https://github.com/element-hq/synapse/issues/17616)) - Python 3.8 EOL: compile native extensions with the 3.9 ABI and use typing hints from the standard library. ([#&#8203;17967](https://github.com/element-hq/synapse/issues/17967)) - Add log message when worker lock timeouts get large. ([#&#8203;18124](https://github.com/element-hq/synapse/issues/18124)) - Make it explicit that you can buy an AGPL-alternative commercial license from Element. ([#&#8203;18134](https://github.com/element-hq/synapse/issues/18134)) - Fix the 'Fix linting' GitHub Actions workflow. ([#&#8203;18136](https://github.com/element-hq/synapse/issues/18136)) - Do not log at the exception-level when clients provide empty `since` token to `/sync` API. ([#&#8203;18139](https://github.com/element-hq/synapse/issues/18139)) - Reduce database load of user search when using large search terms. ([#&#8203;18172](https://github.com/element-hq/synapse/issues/18172)) ##### Updates to locked dependencies - Bump bcrypt from 4.2.0 to 4.2.1. ([#&#8203;18127](https://github.com/element-hq/synapse/issues/18127)) - Bump bytes from 1.9.0 to 1.10.0. ([#&#8203;18149](https://github.com/element-hq/synapse/issues/18149)) - Bump gitpython from 3.1.43 to 3.1.44. ([#&#8203;18128](https://github.com/element-hq/synapse/issues/18128)) - Bump hiredis from 3.0.0 to 3.1.0. ([#&#8203;18169](https://github.com/element-hq/synapse/issues/18169)) - Bump serde\_json from 1.0.137 to 1.0.138. ([#&#8203;18129](https://github.com/element-hq/synapse/issues/18129)) - Bump service-identity from 24.1.0 to 24.2.0. ([#&#8203;18171](https://github.com/element-hq/synapse/issues/18171)) - Bump sigstore/cosign-installer from 3.7.0 to 3.8.0. ([#&#8203;18147](https://github.com/element-hq/synapse/issues/18147)) - Bump twine from 6.0.1 to 6.1.0. ([#&#8203;18170](https://github.com/element-hq/synapse/issues/18170)) - Bump types-pyyaml from 6.0.12.20240917 to 6.0.12.20241230. ([#&#8203;18097](https://github.com/element-hq/synapse/issues/18097)) - Bump ulid from 1.1.4 to 1.2.0. ([#&#8203;18148](https://github.com/element-hq/synapse/issues/18148)) ### [`v1.124.0`](https://github.com/element-hq/synapse/releases/tag/v1.124.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.123.0...v1.124.0) ##### Synapse 1.124.0 (2025-02-11) No significant changes since 1.124.0rc3. ##### Synapse 1.124.0rc3 (2025-02-07) ##### Bugfixes - Fix regression in performance of sending events due to superfluous reads and locks. Introduced in v1.124.0rc1. ([#&#8203;18141](https://github.com/element-hq/synapse/issues/18141)) ##### Synapse 1.124.0rc2 (2025-02-05) ##### Bugfixes - Fix regression where persisting events in some rooms could fail after a previous unclean shutdown. Introduced in v1.124.0rc1. ([#&#8203;18137](https://github.com/element-hq/synapse/issues/18137)) ##### Synapse 1.124.0rc1 (2025-02-04) ##### Bugfixes - Add rate limit `rc_presence.per_user`. This prevents load from excessive presence updates sent by clients via sync api. Also rate limit `/_matrix/client/v3/presence` as per the spec. Contributed by [@&#8203;rda0](https://github.com/rda0). ([#&#8203;18000](https://github.com/element-hq/synapse/issues/18000)) - Deactivated users will no longer automatically accept an invite when `auto_accept_invites` is enabled. ([#&#8203;18073](https://github.com/element-hq/synapse/issues/18073)) - Fix join being denied after being invited over federation. Also fixes other out-of-band membership transitions. ([#&#8203;18075](https://github.com/element-hq/synapse/issues/18075)) - Updates contributed `docker-compose.yml` file to PostgreSQL v15, as v12 is no longer supported by Synapse. Contributed by [@&#8203;maxkratz](https://github.com/maxkratz). ([#&#8203;18089](https://github.com/element-hq/synapse/issues/18089)) - Fix rare edge case where state groups could be deleted while we are persisting new events that reference them. ([#&#8203;18107](https://github.com/element-hq/synapse/issues/18107), [#&#8203;18130](https://github.com/element-hq/synapse/issues/18130), [#&#8203;18131](https://github.com/element-hq/synapse/issues/18131)) - Raise an error if someone is using an incorrect suffix in a config duration string. ([#&#8203;18112](https://github.com/element-hq/synapse/issues/18112)) - Fix a bug where the [Delete Room Admin API](https://element-hq.github.io/synapse/latest/admin_api/rooms.html#version-2-new-version) would fail if the `block` parameter was set to `true` and a worker other than the main process was configured to handle background tasks. ([#&#8203;18119](https://github.com/element-hq/synapse/issues/18119)) ##### Internal Changes - Increase the length of the generated `nonce` parameter when perfoming OIDC logins to comply with the TI-Messenger spec. ([#&#8203;18109](https://github.com/element-hq/synapse/issues/18109)) ##### Updates to locked dependencies - Bump dawidd6/action-download-artifact from 7 to 8. ([#&#8203;18108](https://github.com/element-hq/synapse/issues/18108)) - Bump log from 0.4.22 to 0.4.25. ([#&#8203;18098](https://github.com/element-hq/synapse/issues/18098)) - Bump python-multipart from 0.0.18 to 0.0.20. ([#&#8203;18096](https://github.com/element-hq/synapse/issues/18096)) - Bump serde\_json from 1.0.135 to 1.0.137. ([#&#8203;18099](https://github.com/element-hq/synapse/issues/18099)) - Bump types-bleach from 6.1.0.20240331 to 6.2.0.20241123. ([#&#8203;18082](https://github.com/element-hq/synapse/issues/18082)) ### [`v1.123.0`](https://github.com/element-hq/synapse/releases/tag/v1.123.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.122.0...v1.123.0) ##### Synapse 1.123.0 (2025-01-28) No significant changes since 1.123.0rc1. ##### Synapse 1.123.0rc1 (2025-01-21) ##### Features - Implement [MSC4133](https://github.com/matrix-org/matrix-spec-proposals/pull/4133) for custom profile fields. Contributed by [@&#8203;clokep](https://github.com/clokep). ([#&#8203;17488](https://github.com/element-hq/synapse/issues/17488)) - Add a query parameter `type` to the [Room State Admin API](https://element-hq.github.io/synapse/develop/admin_api/rooms.html#room-state-api) that filters the state event. ([#&#8203;18035](https://github.com/element-hq/synapse/issues/18035)) - Support the new `/auth_metadata` endpoint defined in [MSC2965](https://github.com/matrix-org/matrix-spec-proposals/pull/2965). ([#&#8203;18093](https://github.com/element-hq/synapse/issues/18093)) ##### Bugfixes - Fix membership caches not updating in state reset scenarios. ([#&#8203;17732](https://github.com/element-hq/synapse/issues/17732)) - Fix rare race where on upgrade to v1.122.0 a long running database upgrade could lock out new events from being received or sent. ([#&#8203;18091](https://github.com/element-hq/synapse/issues/18091)) ##### Improved Documentation - Document `tls` option for a worker instance in `instance_map`. ([#&#8203;18064](https://github.com/element-hq/synapse/issues/18064)) ##### Deprecations and Removals - Remove the unstable [MSC4151](https://github.com/matrix-org/matrix-spec-proposals/pull/4151) implementation. The stable support remains, per [Matrix 1.13](https://spec.matrix.org/v1.13/client-server-api/#post_matrixclientv3roomsroomidreport). ([#&#8203;18052](https://github.com/element-hq/synapse/issues/18052)) ##### Internal Changes - Increase invite rate limits (`rc_invites.per_issuer`) for Complement. ([#&#8203;18072](https://github.com/element-hq/synapse/issues/18072)) ##### Updates to locked dependencies - Bump jinja2 from 3.1.4 to 3.1.5. ([#&#8203;18067](https://github.com/element-hq/synapse/issues/18067)) - Bump mypy from 1.12.1 to 1.13.0. ([#&#8203;18083](https://github.com/element-hq/synapse/issues/18083)) - Bump pillow from 11.0.0 to 11.1.0. ([#&#8203;18084](https://github.com/element-hq/synapse/issues/18084)) - Bump pyo3 from 0.23.3 to 0.23.4. ([#&#8203;18079](https://github.com/element-hq/synapse/issues/18079)) - Bump pyopenssl from 24.2.1 to 24.3.0. ([#&#8203;18062](https://github.com/element-hq/synapse/issues/18062)) - Bump serde\_json from 1.0.134 to 1.0.135. ([#&#8203;18081](https://github.com/element-hq/synapse/issues/18081)) - Bump ulid from 1.1.3 to 1.1.4. ([#&#8203;18080](https://github.com/element-hq/synapse/issues/18080)) ### [`v1.122.0`](https://github.com/element-hq/synapse/releases/tag/v1.122.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.121.1...v1.122.0) ##### Synapse 1.122.0 (2025-01-14) Please note that this version of Synapse drops support for PostgreSQL 11 and 12. The minimum version of PostgreSQL supported is now version 13. No significant changes since 1.122.0rc1. ##### Synapse 1.122.0rc1 (2025-01-07) ##### Deprecations and Removals - Remove support for PostgreSQL 11 and 12. Contributed by [@&#8203;clokep](https://github.com/clokep). ([#&#8203;18034](https://github.com/element-hq/synapse/issues/18034)) ##### Features - Added the `email.tlsname` config option. This allows specifying the domain name used to validate the SMTP server's TLS certificate separately from the `email.smtp_host` to connect to. ([#&#8203;17849](https://github.com/element-hq/synapse/issues/17849)) - Module developers will have access to the user ID of the requester when adding `check_username_for_spam` callbacks to `spam_checker_module_callbacks`. Contributed by <Wilson@Pangea.chat>. ([#&#8203;17916](https://github.com/element-hq/synapse/issues/17916)) - Add endpoints to the Admin API to fetch the number of invites the provided user has sent after a given timestamp, fetch the number of rooms the provided user has joined after a given timestamp, and get report IDs of event reports against a provided user (i.e. where the user was the sender of the reported event). ([#&#8203;17948](https://github.com/element-hq/synapse/issues/17948)) - Support stable account suspension from [MSC3823](https://github.com/matrix-org/matrix-spec-proposals/pull/3823). ([#&#8203;17964](https://github.com/element-hq/synapse/issues/17964)) - Add `macaroon_secret_key_path` config option. ([#&#8203;17983](https://github.com/element-hq/synapse/issues/17983)) ##### Bugfixes - Fix bug when rejecting withdrew invite with a `third_party_rules` module, where the invite would be stuck for the client. ([#&#8203;17930](https://github.com/element-hq/synapse/issues/17930)) - Properly purge state groups tables when purging a room with the Admin API. ([#&#8203;18024](https://github.com/element-hq/synapse/issues/18024)) - Fix a bug preventing the admin redaction endpoint from working on messages from remote users. ([#&#8203;18029](https://github.com/element-hq/synapse/issues/18029), [#&#8203;18043](https://github.com/element-hq/synapse/issues/18043)) ##### Improved Documentation - Update `synapse.app.generic_worker` documentation to only recommend `GET` requests for stream writer routes by default, unless the worker is also configured as a stream writer. Contributed by [@&#8203;evoL](https://github.com/evoL). ([#&#8203;17954](https://github.com/element-hq/synapse/issues/17954)) - Add documentation for the previously-undocumented `last_seen_ts` query parameter to the query user Admin API. ([#&#8203;17976](https://github.com/element-hq/synapse/issues/17976)) - Improve documentation for the `TaskScheduler` class. ([#&#8203;17992](https://github.com/element-hq/synapse/issues/17992)) - Fix example in reverse proxy docs to include server port. ([#&#8203;17994](https://github.com/element-hq/synapse/issues/17994)) - Update Alpine Linux Synapse Package Maintainer within the installation instructions. ([#&#8203;17846](https://github.com/element-hq/synapse/issues/17846)) ##### Internal Changes - Add `RoomID` & `EventID` rust types. ([#&#8203;17996](https://github.com/element-hq/synapse/issues/17996)) - Fix various type errors across the codebase. ([#&#8203;17998](https://github.com/element-hq/synapse/issues/17998)) - Disable DB statement timeout when doing a room purge since it can be quite long. ([#&#8203;18017](https://github.com/element-hq/synapse/issues/18017)) - Remove some remaining uses of `twisted.internet.defer.returnValue`. Contributed by Colin Watson. ([#&#8203;18020](https://github.com/element-hq/synapse/issues/18020)) - Refactor `get_profile` to no longer include fields with a value of `None`. ([#&#8203;18063](https://github.com/element-hq/synapse/issues/18063)) ##### Updates to locked dependencies - Bump anyhow from 1.0.93 to 1.0.95. ([#&#8203;18012](https://github.com/element-hq/synapse/issues/18012), [#&#8203;18045](https://github.com/element-hq/synapse/issues/18045)) - Bump authlib from 1.3.2 to 1.4.0. ([#&#8203;18048](https://github.com/element-hq/synapse/issues/18048)) - Bump dawidd6/action-download-artifact from 6 to 7. ([#&#8203;17981](https://github.com/element-hq/synapse/issues/17981)) - Bump http from 1.1.0 to 1.2.0. ([#&#8203;18013](https://github.com/element-hq/synapse/issues/18013)) * Bump mypy from 1.11.2 to 1.12.1. ([#&#8203;17999](https://github.com/element-hq/synapse/issues/17999)) - Bump mypy-zope from 1.0.8 to 1.0.9. ([#&#8203;18047](https://github.com/element-hq/synapse/issues/18047)) - Bump pillow from 10.4.0 to 11.0.0. ([#&#8203;18015](https://github.com/element-hq/synapse/issues/18015)) - Bump pydantic from 2.9.2 to 2.10.3. ([#&#8203;18014](https://github.com/element-hq/synapse/issues/18014)) - Bump pyicu from 2.13.1 to 2.14. ([#&#8203;18060](https://github.com/element-hq/synapse/issues/18060)) - Bump pyo3 from 0.23.2 to 0.23.3. ([#&#8203;18001](https://github.com/element-hq/synapse/issues/18001)) - Bump python-multipart from 0.0.16 to 0.0.18. ([#&#8203;17985](https://github.com/element-hq/synapse/issues/17985)) - Bump sentry-sdk from 2.17.0 to 2.19.2. ([#&#8203;18061](https://github.com/element-hq/synapse/issues/18061)) - Bump serde from 1.0.215 to 1.0.217. ([#&#8203;18031](https://github.com/element-hq/synapse/issues/18031), [#&#8203;18059](https://github.com/element-hq/synapse/issues/18059)) - Bump serde\_json from 1.0.133 to 1.0.134. ([#&#8203;18044](https://github.com/element-hq/synapse/issues/18044)) - Bump twine from 5.1.1 to 6.0.1. ([#&#8203;18049](https://github.com/element-hq/synapse/issues/18049)) **Changelogs for older versions can be found [here](docs/changelogs/).** ### [`v1.121.1`](https://github.com/element-hq/synapse/releases/tag/v1.121.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.120.2...v1.121.1) ##### Synapse 1.121.1 (2024-12-11) This release contains a fix for our docker build CI. It is functionally identical to 1.121.0, whose changelog is below. ##### Internal Changes - Downgrade the Ubuntu GHA runner when building docker images. ([#&#8203;18026](https://github.com/element-hq/synapse/issues/18026)) ##### Synapse 1.121.0 (2024-12-11) ##### Internal Changes - Fix release process to not create duplicate releases. ([#&#8203;18025](https://github.com/element-hq/synapse/issues/18025)) ##### Synapse 1.121.0rc1 (2024-12-04) ##### Features - Support for [MSC4190](https://github.com/matrix-org/matrix-spec-proposals/pull/4190): device management for Application Services. ([#&#8203;17705](https://github.com/element-hq/synapse/issues/17705)) - Update [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync to include invite, ban, kick, targets when `$LAZY`-loading room members. ([#&#8203;17947](https://github.com/element-hq/synapse/issues/17947)) - Use stable `M_USER_LOCKED` error code for locked accounts, as per [Matrix 1.12](https://spec.matrix.org/v1.12/client-server-api/#account-locking). ([#&#8203;17965](https://github.com/element-hq/synapse/issues/17965)) - [MSC4076](https://github.com/matrix-org/matrix-spec-proposals/pull/4076): Add `disable_badge_count` to pusher configuration. ([#&#8203;17975](https://github.com/element-hq/synapse/issues/17975)) ##### Bugfixes - Fix long-standing bug where read receipts could get overly delayed being sent over federation. ([#&#8203;17933](https://github.com/element-hq/synapse/issues/17933)) ##### Improved Documentation - Add OIDC example configuration for Forgejo (fork of Gitea). ([#&#8203;17872](https://github.com/element-hq/synapse/issues/17872)) - Link to element-docker-demo from contrib/docker\*. ([#&#8203;17953](https://github.com/element-hq/synapse/issues/17953)) ##### Internal Changes - [MSC4108](https://github.com/matrix-org/matrix-spec-proposals/pull/4108): Add a `Content-Type` header on the `PUT` response to work around a faulty behavior in some caching reverse proxies. ([#&#8203;17253](https://github.com/element-hq/synapse/issues/17253)) - Fix incorrect comment in new schema delta. ([#&#8203;17936](https://github.com/element-hq/synapse/issues/17936)) - Raise setuptools\_rust version cap to 1.10.2. ([#&#8203;17944](https://github.com/element-hq/synapse/issues/17944)) - Enable encrypted appservice related experimental features in the complement docker image. ([#&#8203;17945](https://github.com/element-hq/synapse/issues/17945)) - Return whether the user is suspended when querying the user account in the Admin API. ([#&#8203;17952](https://github.com/element-hq/synapse/issues/17952)) - Fix new scheduled tasks jumping the queue. ([#&#8203;17962](https://github.com/element-hq/synapse/issues/17962)) - Bump pyo3 and dependencies to v0.23.2. ([#&#8203;17966](https://github.com/element-hq/synapse/issues/17966)) - Update setuptools-rust and fix building abi3 wheels in latest version. ([#&#8203;17969](https://github.com/element-hq/synapse/issues/17969)) - Consolidate SSO redirects through `/_matrix/client/v3/login/sso/redirect(/{idpId})`. ([#&#8203;17972](https://github.com/element-hq/synapse/issues/17972)) - Fix Docker and Complement config to be able to use `public_baseurl`. ([#&#8203;17986](https://github.com/element-hq/synapse/issues/17986)) - Fix building wheels for MacOS which was temporarily disabled in Synapse 1.120.2. ([#&#8203;17993](https://github.com/element-hq/synapse/issues/17993)) - Fix release process to not create duplicate releases. ([#&#8203;17970](https://github.com/element-hq/synapse/issues/17970), [#&#8203;17995](https://github.com/element-hq/synapse/issues/17995)) ##### Updates to locked dependencies - Bump bytes from 1.8.0 to 1.9.0. ([#&#8203;17982](https://github.com/element-hq/synapse/issues/17982)) - Bump pysaml2 from 7.3.1 to 7.5.0. ([#&#8203;17978](https://github.com/element-hq/synapse/issues/17978)) - Bump serde\_json from 1.0.132 to 1.0.133. ([#&#8203;17939](https://github.com/element-hq/synapse/issues/17939)) - Bump tomli from 2.0.2 to 2.1.0. ([#&#8203;17959](https://github.com/element-hq/synapse/issues/17959)) - Bump tomli from 2.1.0 to 2.2.1. ([#&#8203;17979](https://github.com/element-hq/synapse/issues/17979)) - Bump tornado from 6.4.1 to 6.4.2. ([#&#8203;17955](https://github.com/element-hq/synapse/issues/17955)) ### [`v1.120.2`](https://github.com/element-hq/synapse/releases/tag/v1.120.2) [Compare Source](https://github.com/element-hq/synapse/compare/v1.120.1...v1.120.2) ##### Synapse 1.120.2 (2024-12-03) This version has building of wheels for macOS disabled. It is functionally identical to 1.120.1, which contains **multiple security fixes**. If you are already using 1.120.1, there is no need to upgrade to this version. ##### Synapse 1.120.1 (2024-12-03) This patch release fixes multiple security vulnerabilities, some affecting all prior versions of Synapse. Server administrators are encouraged to update Synapse as soon as possible. We are not aware of these vulnerabilities being exploited in the wild. Administrators who are unable to update Synapse may use the workarounds described in the linked GitHub Security Advisory below. ##### Security advisory The following issues are fixed in 1.120.1. - [GHSA-rfq8-j7rh-8hf2](https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2) / [CVE-2024-52805](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52805) (high): **Unsupported content types can lead to memory exhaustion** Synapse instances which have a high `max_upload_size` and which don't have a reverse proxy in front of them that would otherwise limit upload size are affected. Fixed by [4b7154c58501b4bf5e1c2d6c11ebef96529f2fdf](https://github.com/element-hq/synapse/commit/4b7154c58501b4bf5e1c2d6c11ebef96529f2fdf). - [GHSA-f3r3-h2mq-hx2h](https://github.com/element-hq/synapse/security/advisories/GHSA-f3r3-h2mq-hx2h) / [CVE-2024-52815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52815) (high): **Malicious invites via federation can break a user's sync** Fixed by [d82e1ed357b7ee21dff83d06cba7a67840cfd464](https://github.com/element-hq/synapse/commit/d82e1ed357b7ee21dff83d06cba7a67840cfd464). - [GHSA-vp6v-whfm-rv3g](https://github.com/element-hq/synapse/security/advisories/GHSA-vp6v-whfm-rv3g) / [CVE-2024-53863](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53863) (high): **Synapse can be forced to thumbnail unexpected file formats, invoking potentially untrustworthy decoders** Synapse instances can disable dynamic thumbnailing by setting `dynamic_thumbnails` to `false` in the configuration file. Fixed by [b64a4e5fbbbf119b6c65aedf0d999b4237d55503](https://github.com/element-hq/synapse/commit/b64a4e5fbbbf119b6c65aedf0d999b4237d55503). - [GHSA-56w4-5538-8v8h](https://github.com/element-hq/synapse/security/advisories/GHSA-56w4-5538-8v8h) / [CVE-2024-53867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53867) (moderate): **The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room** Non-state events, like messages, are unaffected. Synapse instances can disable the Sliding Sync feature by setting `experimental_features.msc3575_enabled` to `false` in the configuration file. Fixed by [4daa533e82f345ce87b9495d31781af570ba3ead](https://github.com/element-hq/synapse/commit/4daa533e82f345ce87b9495d31781af570ba3ead). Additionally, we disclose the following vulnerabilities, both have been fixed in Synapse 1.106.0: - [GHSA-4mhg-xv73-xq2x](https://github.com/element-hq/synapse/security/advisories/GHSA-4mhg-xv73-xq2x) / [CVE-2024-37302](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37302) (high): **Denial of service through media disk space consumption** - [GHSA-gjgr-7834-rhxr](https://github.com/element-hq/synapse/security/advisories/GHSA-gjgr-7834-rhxr) / [CVE-2024-37303](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37303) (moderate): **Unauthenticated writes to the media repository allow planting of problematic content** See the advisories for more details. If you have any questions, email [security at element.io](mailto:security@element.io). ##### Bug fixes - Fix release process to not create duplicate releases. ([#&#8203;17970](https://github.com/element-hq/synapse/issues/17970)) ### [`v1.120.1`](https://github.com/element-hq/synapse/compare/v1.120.0...v1.120.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.120.0...v1.120.1) ### [`v1.120.0`](https://github.com/element-hq/synapse/releases/tag/v1.120.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.119.0...v1.120.0) ##### Synapse 1.120.0 (2024-11-26) This release enables the enforcement of authenticated media by default, with exemptions for media that is already present in the homeserver's media store. Most homeservers operating in the public federation will not be impacted by this change, given that the large homeserver `matrix.org` enabled this in September 2024 and therefore most clients and servers will already have updated as a result. Some server administrators may still wish to disable this enforcement for the time being, in the interest of compatibility with older clients and older federated homeservers. See the [upgrade notes](https://element-hq.github.io/synapse/v1.120/upgrade.html#authenticated-media-is-now-enforced-by-default) for more information. ##### Bugfixes - Fix a bug introduced in Synapse v1.120rc1 which would cause the newly-introduced `delete_old_otks` job to fail in worker-mode deployments. ([#&#8203;17960](https://github.com/element-hq/synapse/issues/17960)) ##### Synapse 1.120.0rc1 (2024-11-20) ##### Features - Enforce authenticated media by default. Administrators can revert this by configuring `enable_authenticated_media` to `false`. In a future release of Synapse, this option will be removed and become always-on. ([#&#8203;17889](https://github.com/element-hq/synapse/issues/17889)) - Add a one-off task to delete old One-Time Keys, to guard against us having old OTKs in the database that the client has long forgotten about. ([#&#8203;17934](https://github.com/element-hq/synapse/issues/17934)) ##### Improved Documentation - Clarify the semantics of the `enable_authenticated_media` configuration option. ([#&#8203;17913](https://github.com/element-hq/synapse/issues/17913)) - Add documentation about backing up Synapse. ([#&#8203;17931](https://github.com/element-hq/synapse/issues/17931)) ##### Deprecations and Removals - Remove support for [MSC3886: Simple client rendezvous capability](https://github.com/matrix-org/matrix-spec-proposals/pull/3886), which has been superseded by [MSC4108](https://github.com/matrix-org/matrix-spec-proposals/pull/4108) and therefore closed. ([#&#8203;17638](https://github.com/element-hq/synapse/issues/17638)) ##### Internal Changes - Addressed some typos in docs and returned error message for unknown MXC ID. ([#&#8203;17865](https://github.com/element-hq/synapse/issues/17865)) - Unpin the upload release GHA action. ([#&#8203;17923](https://github.com/element-hq/synapse/issues/17923)) - Bump macOS version used to build wheels during release, as current version used is end-of-life. ([#&#8203;17924](https://github.com/element-hq/synapse/issues/17924)) - Move server event filtering logic to Rust. ([#&#8203;17928](https://github.com/element-hq/synapse/issues/17928)) - Support new package name of PyPI package `python-multipart` 0.0.13 so that distro packagers do not need to work around name conflict with PyPI package `multipart`. ([#&#8203;17932](https://github.com/element-hq/synapse/issues/17932)) - Speed up slow initial sliding syncs on large servers. ([#&#8203;17946](https://github.com/element-hq/synapse/issues/17946)) ##### Updates to locked dependencies - Bump anyhow from 1.0.92 to 1.0.93. ([#&#8203;17920](https://github.com/element-hq/synapse/issues/17920)) - Bump bleach from 6.1.0 to 6.2.0. ([#&#8203;17918](https://github.com/element-hq/synapse/issues/17918)) - Bump immutabledict from 4.2.0 to 4.2.1. ([#&#8203;17941](https://github.com/element-hq/synapse/issues/17941)) - Bump packaging from 24.1 to 24.2. ([#&#8203;17940](https://github.com/element-hq/synapse/issues/17940)) - Bump phonenumbers from 8.13.49 to 8.13.50. ([#&#8203;17942](https://github.com/element-hq/synapse/issues/17942)) - Bump pygithub from 2.4.0 to 2.5.0. ([#&#8203;17917](https://github.com/element-hq/synapse/issues/17917)) - Bump ruff from 0.7.2 to 0.7.3. ([#&#8203;17919](https://github.com/element-hq/synapse/issues/17919)) - Bump serde from 1.0.214 to 1.0.215. ([#&#8203;17938](https://github.com/element-hq/synapse/issues/17938)) ### [`v1.119.0`](https://github.com/element-hq/synapse/releases/tag/v1.119.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.118.0...v1.119.0) ##### Synapse 1.119.0 (2024-11-13) No significant changes since 1.119.0rc2. ##### Python 3.8 support dropped Python 3.8 is [end-of-life](https://devguide.python.org/versions/) and is no longer supported by Synapse. The minimum supported Python version is now 3.9. If you are running Synapse with Python 3.8, please upgrade to Python 3.9 (or greater) before upgrading Synapse. ##### Synapse 1.119.0rc2 (2024-11-11) Note that due to packaging issues there was no v1.119.0rc1. ##### Features - Support [MSC4151](https://github.com/matrix-org/matrix-spec-proposals/pull/4151)'s stable report room API. ([#&#8203;17374](https://github.com/element-hq/synapse/issues/17374)) - Add experimental support for [MSC4222](https://github.com/matrix-org/matrix-spec-proposals/pull/4222) (Adding `state_after` to sync v2). ([#&#8203;17888](https://github.com/element-hq/synapse/issues/17888)) ##### Bugfixes - Fix bug with sliding sync where `$LAZY`-loading room members would not return `required_state` membership in incremental syncs. ([#&#8203;17809](https://github.com/element-hq/synapse/issues/17809)) - Check if user has membership in a room before tagging it. Contributed by Lama Alosaimi. ([#&#8203;17839](https://github.com/element-hq/synapse/issues/17839)) - Fix a bug in the admin redact endpoint where the background task would not run if a worker was specified in the config option `run_background_tasks_on`. ([#&#8203;17847](https://github.com/element-hq/synapse/issues/17847)) - Fix bug where some presence and typing timeouts can expire early. ([#&#8203;17850](https://github.com/element-hq/synapse/issues/17850)) - Fix detection when the built Rust library was outdated when using source installations. ([#&#8203;17861](https://github.com/element-hq/synapse/issues/17861)) - Fix a long-standing bug in Synapse which could cause one-time keys to be issued in the incorrect order, causing message decryption failures. ([#&#8203;17903](https://github.com/element-hq/synapse/pull/17903)) - Fix experimental support for [MSC4222](https://github.com/matrix-org/matrix-spec-proposals/pull/4222) (Adding `state_after` to sync v2) where we would return the full state on incremental syncs when using lazy loaded members and there were no new events in the timeline. ([#&#8203;17915](https://github.com/element-hq/synapse/pull/17915)) ##### Internal Changes - Remove support for python 3.8. ([#&#8203;17908](https://github.com/element-hq/synapse/issues/17908)) - Add a test for downloading and thumbnailing a CMYK JPEG. ([#&#8203;17786](https://github.com/element-hq/synapse/issues/17786)) - Refactor database calls to remove `Generator` usage. ([#&#8203;17813](https://github.com/element-hq/synapse/issues/17813), [#&#8203;17814](https://github.com/element-hq/synapse/issues/17814), [#&#8203;17815](https://github.com/element-hq/synapse/issues/17815), [#&#8203;17816](https://github.com/element-hq/synapse/issues/17816), [#&#8203;17817](https://github.com/element-hq/synapse/issues/17817), [#&#8203;17818](https://github.com/element-hq/synapse/issues/17818), [#&#8203;17890](https://github.com/element-hq/synapse/issues/17890)) - Include the destination in the error of 'Destination mismatch' on federation requests. ([#&#8203;17830](https://github.com/element-hq/synapse/issues/17830)) - The nix flake inside the repository no longer tracks nixpkgs/master to not catch the latest bugs from a PR merged 5 minutes ago. ([#&#8203;17852](https://github.com/element-hq/synapse/issues/17852)) - Minor speed-up of sliding sync by computing extensions results in parallel. ([#&#8203;17884](https://github.com/element-hq/synapse/issues/17884)) - Bump the default Python version in the Synapse Dockerfile from 3.11 -> 3.12. ([#&#8203;17887](https://github.com/element-hq/synapse/issues/17887)) - Remove usage of internal header encoding API. ([#&#8203;17894](https://github.com/element-hq/synapse/issues/17894)) - Use unique name for each os.arch variant when uploading Wheel artifacts. ([#&#8203;17905](https://github.com/element-hq/synapse/issues/17905)) - Fix tests to run with latest Twisted. ([#&#8203;17906](https://github.com/element-hq/synapse/pull/17906), [#&#8203;17907](https://github.com/element-hq/synapse/pull/17907), [#&#8203;17911](https://github.com/element-hq/synapse/pull/17911)) - Update version constraint to allow the latest poetry-core 1.9.1. ([#&#8203;17902](https://github.com/element-hq/synapse/pull/17902)) - Update the portdb CI to use Python 3.13 and Postgres 17 as latest dependencies. ([#&#8203;17909](https://github.com/element-hq/synapse/pull/17909)) - Add an index to `current_state_delta_stream` table. ([#&#8203;17912](https://github.com/element-hq/synapse/issues/17912)) - Fix building and attaching release artifacts during the release process. ([#&#8203;17921](https://github.com/element-hq/synapse/issues/17921)) ##### Updates to locked dependencies - Bump actions/download-artifact & actions/upload-artifact from 3 to 4 in /.github/workflows. ([#&#8203;17657](https://github.com/element-hq/synapse/issues/17657)) - Bump anyhow from 1.0.89 to 1.0.92. ([#&#8203;17858](https://github.com/element-hq/synapse/issues/17858), [#&#8203;17876](https://github.com/element-hq/synapse/issues/17876), [#&#8203;17901](https://github.com/element-hq/synapse/issues/17901)) - Bump bytes from 1.7.2 to 1.8.0. ([#&#8203;17877](https://github.com/element-hq/synapse/issues/17877)) - Bump cryptography from 43.0.1 to 43.0.3. ([#&#8203;17853](https://github.com/element-hq/synapse/issues/17853)) - Bump mypy-zope from 1.0.7 to 1.0.8. ([#&#8203;17898](https://github.com/element-hq/synapse/issues/17898)) - Bump phonenumbers from 8.13.47 to 8.13.49. ([#&#8203;17880](https://github.com/element-hq/synapse/issues/17880), [#&#8203;17899](https://github.com/element-hq/synapse/issues/17899)) - Bump python-multipart from 0.0.12 to 0.0.16. ([#&#8203;17879](https://github.com/element-hq/synapse/issues/17879)) - Bump regex from 1.11.0 to 1.11.1. ([#&#8203;17874](https://github.com/element-hq/synapse/issues/17874)) - Bump ruff from 0.6.9 to 0.7.2. ([#&#8203;17868](https://github.com/element-hq/synapse/issues/17868), [#&#8203;17897](https://github.com/element-hq/synapse/issues/17897)) - Bump serde from 1.0.210 to 1.0.214. ([#&#8203;17875](https://github.com/element-hq/synapse/issues/17875), [#&#8203;17900](https://github.com/element-hq/synapse/issues/17900)) - Bump serde\_json from 1.0.128 to 1.0.132. ([#&#8203;17857](https://github.com/element-hq/synapse/issues/17857)) - Bump types-psycopg2 from 2.9.21.20240819 to 2.9.21.20241019. ([#&#8203;17855](https://github.com/element-hq/synapse/issues/17855)) - Bump types-setuptools from 75.1.0.20241014 to 75.2.0.20241019. ([#&#8203;17856](https://github.com/element-hq/synapse/issues/17856)) ### [`v1.118.0`](https://github.com/element-hq/synapse/releases/tag/v1.118.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.117.0...v1.118.0) ##### Synapse 1.118.0 (2024-10-29) No significant changes since 1.118.0rc1. ##### Python 3.8 support will be dropped in the next release Python 3.8 is now [end-of-life](https://devguide.python.org/versions/). As per our [Deprecation Policy for Platform Dependencies](https://element-hq.github.io/synapse/latest/deprecation_policy.html#policy), Synapse will be dropping support for Python 3.8 in the next release; Synapse 1.119.0. Synapse 1.118.x will be the final release to support Python 3.8. If you are running Synapse with Python 3.8, please upgrade before the 1.119.0 release, due in less than one month. ##### Python 3.13 and PostgreSQL 17 support On the other end of the spectrum, Synapse 1.118.0 is the first release to support [Python 3.13](https://www.python.org/downloads/release/python-3130/)! [PostgreSQL 17](https://www.postgresql.org/about/news/postgresql-17-released-2936/) is also supported as of this release. ##### Synapse 1.118.0rc1 (2024-10-22) ##### Features - Added the `display_name_claim` option to the JWT configuration. This option allows specifying the claim key that contains the user's display name in the JWT payload. ([#&#8203;17708](https://github.com/element-hq/synapse/issues/17708)) - Implement [MSC4210](https://github.com/matrix-org/matrix-spec-proposals/pull/4210): Remove legacy mentions. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;17783](https://github.com/element-hq/synapse/issues/17783)) ##### Bugfixes - Fix saving of PNG thumbnails, when the original image is in the CMYK color space. ([#&#8203;17736](https://github.com/element-hq/synapse/issues/17736)) - Fix bug with sliding sync where the server would not return state that was added to the `required_state` config. ([#&#8203;17785](https://github.com/element-hq/synapse/issues/17785), [#&#8203;17805](https://github.com/element-hq/synapse/issues/17805)) - Fix a bug in [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync that would cause rooms to stay forgotten and hidden even after rejoining. ([#&#8203;17835](https://github.com/element-hq/synapse/issues/17835)) ##### Improved Documentation - Clarify when the `user_may_invite` and `user_may_send_3pid_invite` module callbacks are called. ([#&#8203;17627](https://github.com/element-hq/synapse/issues/17627)) - Correct documentation to refer to the `--config-path` argument instead of `--config-file`. ([#&#8203;17802](https://github.com/element-hq/synapse/issues/17802)) - Fix typo in `target_cache_memory_usage` docs. ([#&#8203;17825](https://github.com/element-hq/synapse/issues/17825)) ##### Internal Changes - Slight optimization when fetching state/events for Sliding Sync. ([#&#8203;17718](https://github.com/element-hq/synapse/issues/17718)) - Add Python 3.13 and Postgres 17 to the test matrix. ([#&#8203;17752](https://github.com/element-hq/synapse/issues/17752)) - Test github token before running release script steps. ([#&#8203;17803](https://github.com/element-hq/synapse/issues/17803)) - Build debian packages for new Ubuntu versions, and stop building for no longer supported versions. ([#&#8203;17824](https://github.com/element-hq/synapse/issues/17824)) - Enable the `.org.matrix.msc4028.encrypted_event` push rule by default in accordance with [MSC4028](https://github.com/matrix-org/matrix-spec-proposals/pull/4028). Note that the corresponding experimental feature must still be switched on for this push rule to have any effect. ([#&#8203;17826](https://github.com/element-hq/synapse/issues/17826)) - Fix some typing issues uncovered by upgrading mypy to 1.11.x. ([#&#8203;17842](https://github.com/element-hq/synapse/issues/17842)) ##### Updates to locked dependencies - Bump mypy from 1.10.1 to 1.11.2. ([#&#8203;17842](https://github.com/element-hq/synapse/issues/17842)) - Bump mypy-zope from 1.0.5 to 1.0.7. ([#&#8203;17827](https://github.com/element-hq/synapse/issues/17827)) - Bump phonenumbers from 8.13.46 to 8.13.47. ([#&#8203;17797](https://github.com/element-hq/synapse/issues/17797)) - Bump psycopg2 from 2.9.9 to 2.9.10. ([#&#8203;17843](https://github.com/element-hq/synapse/issues/17843)) - Bump ruff from 0.6.8 to 0.6.9. ([#&#8203;17794](https://github.com/element-hq/synapse/issues/17794)) - Bump sentry-sdk from 2.14.0 to 2.15.0. ([#&#8203;17795](https://github.com/element-hq/synapse/issues/17795)) - Bump sentry-sdk from 2.15.0 to 2.16.0. ([#&#8203;17829](https://github.com/element-hq/synapse/issues/17829)) - Bump sentry-sdk from 2.16.0 to 2.17.0. ([#&#8203;17844](https://github.com/element-hq/synapse/issues/17844)) - Bump sigstore/cosign-installer from 3.6.0 to 3.7.0. ([#&#8203;17798](https://github.com/element-hq/synapse/issues/17798)) - Bump tomli from 2.0.1 to 2.0.2. ([#&#8203;17796](https://github.com/element-hq/synapse/issues/17796)) - Bump types-requests from 2.32.0.20240914 to 2.32.0.20241016. ([#&#8203;17841](https://github.com/element-hq/synapse/issues/17841)) - Bump types-setuptools from 75.1.0.20240917 to 75.1.0.20241014. ([#&#8203;17828](https://github.com/element-hq/synapse/issues/17828)) ### [`v1.117.0`](https://github.com/element-hq/synapse/releases/tag/v1.117.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.116.0...v1.117.0) ##### Synapse 1.117.0 (2024-10-15) No significant changes since 1.117.0rc1. ##### Synapse 1.117.0rc1 (2024-10-08) ##### Features - Add config option `redis.password_path`. ([#&#8203;17717](https://github.com/element-hq/synapse/issues/17717)) ##### Bugfixes - Fix a rare bug introduced in v1.29.0 where invalidating a user's access token from a worker could raise an error. ([#&#8203;17779](https://github.com/element-hq/synapse/issues/17779)) - In the response to `GET /_matrix/client/versions`, set the `unstable_features` flag for [MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140) to `false` when server configuration disables support for delayed events. ([#&#8203;17780](https://github.com/element-hq/synapse/issues/17780)) - Improve input validation and room membership checks in admin redaction API. ([#&#8203;17792](https://github.com/element-hq/synapse/issues/17792)) ##### Improved Documentation - Clarify the docstring of `test_forget_when_not_left`. ([#&#8203;17628](https://github.com/element-hq/synapse/issues/17628)) - Add documentation note about PYTHONMALLOC for accurate jemalloc memory tracking. Contributed by [@&#8203;hensg](https://github.com/hensg). ([#&#8203;17709](https://github.com/element-hq/synapse/issues/17709)) - Remove spurious "TODO UPDATE ALL THIS" note in the Debian installation docs. ([#&#8203;17749](https://github.com/element-hq/synapse/issues/17749)) - Explain how load balancing works for `federation_sender_instances`. ([#&#8203;17776](https://github.com/element-hq/synapse/issues/17776)) ##### Internal Changes - Minor performance increase for large accounts using sliding sync. ([#&#8203;17751](https://github.com/element-hq/synapse/issues/17751)) - Increase performance of the notifier when there are many syncing users. ([#&#8203;17765](https://github.com/element-hq/synapse/issues/17765), [#&#8203;17766](https://github.com/element-hq/synapse/issues/17766)) - Fix performance of streams that don't change often. ([#&#8203;17767](https://github.com/element-hq/synapse/issues/17767)) - Improve performance of sliding sync connections that do not ask for any rooms. ([#&#8203;17768](https://github.com/element-hq/synapse/issues/17768)) - Reduce overhead of sliding sync E2EE loops. ([#&#8203;17771](https://github.com/element-hq/synapse/issues/17771)) - Sliding sync minor performance speed up using new table. ([#&#8203;17787](https://github.com/element-hq/synapse/issues/17787)) - Sliding sync minor performance improvement by omitting unchanged data from incremental responses. ([#&#8203;17788](https://github.com/element-hq/synapse/issues/17788)) - Speed up sliding sync when there are many active subscriptions. ([#&#8203;17789](https://github.com/element-hq/synapse/issues/17789)) - Add missing license headers on new source files. ([#&#8203;17799](https://github.com/element-hq/synapse/issues/17799)) ##### Updates to locked dependencies - Bump phonenumbers from 8.13.45 to 8.13.46. ([#&#8203;17773](https://github.com/element-hq/synapse/issues/17773)) - Bump python-multipart from 0.0.10 to 0.0.12. ([#&#8203;17772](https://github.com/element-hq/synapse/issues/17772)) - Bump regex from 1.10.6 to 1.11.0. ([#&#8203;17770](https://github.com/element-hq/synapse/issues/17770)) - Bump ruff from 0.6.7 to 0.6.8. ([#&#8203;17774](https://github.com/element-hq/synapse/issues/17774)) ### [`v1.116.0`](https://github.com/element-hq/synapse/releases/tag/v1.116.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.115.0...v1.116.0) ##### Synapse 1.116.0 (2024-10-01) No significant changes since 1.116.0rc2. ##### Synapse 1.116.0rc2 (2024-09-26) ##### Features - Add implementation of restricting who can overwrite a state event as proposed by [MSC3757](https://github.com/matrix-org/matrix-spec-proposals/pull/3757). ([#&#8203;17513](https://github.com/element-hq/synapse/issues/17513)) ##### Synapse 1.116.0rc1 (2024-09-25) ##### Features - Add initial implementation of delayed events as proposed by [MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140). ([#&#8203;17326](https://github.com/element-hq/synapse/issues/17326)) - Add an asynchronous Admin API endpoint [to redact all a user's events](https://element-hq.github.io/synapse/v1.116/admin_api/user_admin_api.html#redact-all-the-events-of-a-user), and [an endpoint to check on the status of that redaction task](https://element-hq.github.io/synapse/v1.116/admin_api/user_admin_api.html#check-the-status-of-a-redaction-process). ([#&#8203;17506](https://github.com/element-hq/synapse/issues/17506)) - Add support for the `tags` and `not_tags` filters for [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync. ([#&#8203;17662](https://github.com/element-hq/synapse/issues/17662)) - Guests can use the new media endpoints to download media, as described by [MSC4189](https://github.com/matrix-org/matrix-spec-proposals/pull/4189). ([#&#8203;17675](https://github.com/element-hq/synapse/issues/17675)) - Add config option `turn_shared_secret_path`. ([#&#8203;17690](https://github.com/element-hq/synapse/issues/17690)) - Return room tags in [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync account data extension. ([#&#8203;17707](https://github.com/element-hq/synapse/issues/17707)) ##### Bugfixes - Make sure we get up-to-date state information when using the new [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync tables to derive room membership. ([#&#8203;17692](https://github.com/element-hq/synapse/issues/17692)) - Fix bug where room account data would not correctly be sent down [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync for old rooms. ([#&#8203;17695](https://github.com/element-hq/synapse/issues/17695)) - Fix a bug in [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync which could prevent /sync from working for certain user accounts. ([#&#8203;17727](https://github.com/element-hq/synapse/issues/17727), [#&#8203;17733](https://github.com/element-hq/synapse/issues/17733)) - Ignore invites from ignored users in Sliding Sync. ([#&#8203;17729](https://github.com/element-hq/synapse/issues/17729)) - Fix bug in [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync where the server would incorrectly return a negative bump stamp, which caused Element X apps to stop syncing. ([#&#8203;17748](https://github.com/element-hq/synapse/issues/17748)) ##### Internal Changes - Import pydantic objects from the `_pydantic_compat` module. This allows `check_pydantic_models.py` to mock those pydantic objects only in the synapse module, and not interfere with pydantic objects in external dependencies. ([#&#8203;17667](https://github.com/element-hq/synapse/issues/17667)) - Use [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync tables as a bulk shortcut for getting the max `event_stream_ordering` of rooms. ([#&#8203;17693](https://github.com/element-hq/synapse/issues/17693)) - Speed up [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) sliding sync requests a bit where there are many room changes. ([#&#8203;17696](https://github.com/element-hq/synapse/issues/17696)) - Refactor [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) sliding sync filter unit tests so the sliding sync API has better test coverage. ([#&#8203;17703](https://github.com/element-hq/synapse/issues/17703)) - Fetch `bump_stamp`s more efficiently in [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync. ([#&#8203;17723](https://github.com/element-hq/synapse/issues/17723)) - Shortcut for checking if certain background updates have completed (utilized in [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync). ([#&#8203;17724](https://github.com/element-hq/synapse/issues/17724)) - More efficiently fetch rooms for [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync. ([#&#8203;17725](https://github.com/element-hq/synapse/issues/17725)) - Fix `_bulk_get_max_event_pos` being inefficient. ([#&#8203;17728](https://github.com/element-hq/synapse/issues/17728)) - Add cache to `get_tags_for_room(...)`. ([#&#8203;17730](https://github.com/element-hq/synapse/issues/17730)) - Small performance improvement in speeding up [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) Sliding Sync. ([#&#8203;17731](https://github.com/element-hq/synapse/issues/17731)) - Minor speed up of initial [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) sliding sync requests. ([#&#8203;17734](https://github.com/element-hq/synapse/issues/17734)) - Remove usage of the deprecated `cgi` module, deprecated in Python 3.11 and removed in Python 3.13. ([#&#8203;17741](https://github.com/element-hq/synapse/issues/17741)) - Fix typing of a variable that is not `Unknown` anymore after updating `treq`. ([#&#8203;17744](https://github.com/element-hq/synapse/issues/17744)) ##### Updates to locked dependencies - Bump anyhow from 1.0.86 to 1.0.89. ([#&#8203;17685](https://github.com/element-hq/synapse/issues/17685), [#&#8203;17716](https://github.com/element-hq/synapse/issues/17716)) - Bump bytes from 1.7.1 to 1.7.2. ([#&#8203;17743](https://github.com/element-hq/synapse/issues/17743)) - Bump cryptography from 43.0.0 to 43.0.1. ([#&#8203;17689](https://github.com/element-hq/synapse/issues/17689)) - Bump idna from 3.8 to 3.10. ([#&#8203;17758](https://github.com/element-hq/synapse/issues/17758)) - Bump msgpack from 1.0.8 to 1.1.0. ([#&#8203;17759](https://github.com/element-hq/synapse/issues/17759)) - Bump phonenumbers from 8.13.44 to 8.13.45. ([#&#8203;17762](https://github.com/element-hq/synapse/issues/17762)) - Bump prometheus-client from 0.20.0 to 0.21.0. ([#&#8203;17746](https://github.com/element-hq/synapse/issues/17746)) - Bump pyasn1 from 0.6.0 to 0.6.1. ([#&#8203;17714](https://github.com/element-hq/synapse/issues/17714)) - Bump pyasn1-modules from 0.4.0 to 0.4.1. ([#&#8203;17747](https://github.com/element-hq/synapse/issues/17747)) - Bump pydantic from 2.8.2 to 2.9.2. ([#&#8203;17756](https://github.com/element-hq/synapse/issues/17756)) - Bump python-multipart from 0.0.9 to 0.0.10. ([#&#8203;17745](https://github.com/element-hq/synapse/issues/17745)) - Bump ruff from 0.6.4 to 0.6.7. ([#&#8203;17715](https://github.com/element-hq/synapse/issues/17715), [#&#8203;17760](https://github.com/element-hq/synapse/issues/17760)) - Bump sentry-sdk from 2.13.0 to 2.14.0. ([#&#8203;17712](https://github.com/element-hq/synapse/issues/17712)) - Bump serde from 1.0.209 to 1.0.210. ([#&#8203;17686](https://github.com/element-hq/synapse/issues/17686)) - Bump serde\_json from 1.0.127 to 1.0.128. ([#&#8203;17687](https://github.com/element-hq/synapse/issues/17687)) - Bump treq from 23.11.0 to 24.9.1. ([#&#8203;17744](https://github.com/element-hq/synapse/issues/17744)) - Bump types-pyyaml from 6.0.12.20240808 to 6.0.12.20240917. ([#&#8203;17755](https://github.com/element-hq/synapse/issues/17755)) - Bump types-requests from 2.32.0.20240712 to 2.32.0.20240914. ([#&#8203;17713](https://github.com/element-hq/synapse/issues/17713)) - Bump types-setuptools from 74.1.0.20240907 to 75.1.0.20240917. ([#&#8203;17757](https://github.com/element-hq/synapse/issues/17757)) ### [`v1.115.0`](https://github.com/element-hq/synapse/releases/tag/v1.115.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.114.0...v1.115.0) ##### Synapse 1.115.0 (2024-09-17) No significant changes since 1.115.0rc2. ##### Synapse 1.115.0rc2 (2024-09-12) ##### Internal Changes - Pre-populate room data used in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint for quick filtering/sorting. ([#&#8203;17652](https://github.com/element-hq/synapse/issues/17652)) - Speed up sliding sync by reducing amount of data pulled out of the database for large rooms. ([#&#8203;17683](https://github.com/element-hq/synapse/issues/17683)) ##### Synapse 1.115.0rc1 (2024-09-10) ##### Features - Improve cross-signing upload when using [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861) to use a custom UIA flow stage, with web fallback support. ([#&#8203;17509](https://github.com/element-hq/synapse/issues/17509)) ##### Bugfixes - Return `400 M_BAD_JSON` upon attempting to complete various room actions with a non-local user ID and unknown room ID, rather than an internal server error. ([#&#8203;17607](https://github.com/element-hq/synapse/issues/17607)) - Fix authenticated media responses using a wrong limit when following redirects over federation. ([#&#8203;17626](https://github.com/element-hq/synapse/issues/17626)) - Fix bug where we returned the wrong `bump_stamp` for invites in sliding sync response, causing incorrect ordering of invites in the room list. ([#&#8203;17674](https://github.com/element-hq/synapse/issues/17674)) ##### Improved Documentation - Clarify that the admin api resource is only loaded on the main process and not workers. ([#&#8203;17590](https://github.com/element-hq/synapse/issues/17590)) - Fixed typo in `saml2_config` config [example](https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#saml2_config). ([#&#8203;17594](https://github.com/element-hq/synapse/issues/17594)) ##### Deprecations and Removals - Stabilise [MSC4156](https://github.com/matrix-org/matrix-spec-proposals/pull/4156) by removing the `msc4156_enabled` config setting and defaulting it to `true`. ([#&#8203;17650](https://github.com/element-hq/synapse/issues/17650)) ##### Internal Changes - Update [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861) implementation: load the issuer and account management URLs from OIDC discovery. ([#&#8203;17407](https://github.com/element-hq/synapse/issues/17407)) - Pre-populate room data used in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint for quick filtering/sorting. ([#&#8203;17512](https://github.com/element-hq/synapse/issues/17512), [#&#8203;17632](https://github.com/element-hq/synapse/issues/17632), [#&#8203;17633](https://github.com/element-hq/synapse/issues/17633), [#&#8203;17634](https://github.com/element-hq/synapse/issues/17634), [#&#8203;17635](https://github.com/element-hq/synapse/issues/17635), [#&#8203;17636](https://github.com/element-hq/synapse/issues/17636), [#&#8203;17641](https://github.com/element-hq/synapse/issues/17641), [#&#8203;17654](https://github.com/element-hq/synapse/issues/17654), [#&#8203;17673](https://github.com/element-hq/synapse/issues/17673)) - Store sliding sync per-connection state in the database. ([#&#8203;17599](https://github.com/element-hq/synapse/issues/17599), [#&#8203;17631](https://github.com/element-hq/synapse/issues/17631)) - Make the sliding sync `PerConnectionState` class immutable. ([#&#8203;17600](https://github.com/element-hq/synapse/issues/17600)) - Replace `isort` and `black` with `ruff`. ([#&#8203;17620](https://github.com/element-hq/synapse/issues/17620), [#&#8203;17643](https://github.com/element-hq/synapse/issues/17643)) - Sliding Sync: Split up `get_room_membership_for_user_at_to_token`. ([#&#8203;17629](https://github.com/element-hq/synapse/issues/17629)) - Use new database tables for sliding sync. ([#&#8203;17630](https://github.com/element-hq/synapse/issues/17630), [#&#8203;17649](https://github.com/element-hq/synapse/issues/17649)) - Prevent duplicate tags being added to Sliding Sync traces. ([#&#8203;17655](https://github.com/element-hq/synapse/issues/17655)) - Get `bump_stamp` from [new sliding sync tables](https://github.com/element-hq/synapse/pull/17512) which should be faster. ([#&#8203;17658](https://github.com/element-hq/synapse/issues/17658)) - Speed up incremental Sliding Sync requests by avoiding extra work. ([#&#8203;17665](https://github.com/element-hq/synapse/issues/17665)) - Small performance improvement in speeding up sliding sync. ([#&#8203;17666](https://github.com/element-hq/synapse/issues/17666), [#&#8203;17670](https://github.com/element-hq/synapse/issues/17670), [#&#8203;17672](https://github.com/element-hq/synapse/issues/17672)) - Speed up sliding sync by reducing number of database calls. ([#&#8203;17684](https://github.com/element-hq/synapse/issues/17684)) - Speed up sync by pulling out fewer events from the database. ([#&#8203;17688](https://github.com/element-hq/synapse/issues/17688)) ##### Updates to locked dependencies - Bump authlib from 1.3.1 to 1.3.2. ([#&#8203;17679](https://github.com/element-hq/synapse/issues/17679)) - Bump idna from 3.7 to 3.8. ([#&#8203;17682](https://github.com/element-hq/synapse/issues/17682)) - Bump ruff from 0.6.2 to 0.6.4. ([#&#8203;17680](https://github.com/element-hq/synapse/issues/17680)) - Bump towncrier from 24.7.1 to 24.8.0. ([#&#8203;17645](https://github.com/element-hq/synapse/issues/17645)) - Bump twisted from 24.7.0rc1 to 24.7.0. ([#&#8203;17647](https://github.com/element-hq/synapse/issues/17647)) - Bump types-pillow from 10.2.0.20240520 to 10.2.0.20240822. ([#&#8203;17644](https://github.com/element-hq/synapse/issues/17644)) - Bump types-psycopg2 from 2.9.21.20240417 to 2.9.21.20240819. ([#&#8203;17646](https://github.com/element-hq/synapse/issues/17646)) - Bump types-setuptools from 71.1.0.20240818 to 74.1.0.20240907. ([#&#8203;17681](https://github.com/element-hq/synapse/issues/17681)) ### [`v1.114.0`](https://github.com/element-hq/synapse/releases/tag/v1.114.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.113.0...v1.114.0) ##### Synapse 1.114.0 (2024-09-02) This release enables support for [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186) — Simplified Sliding Sync. This allows using the upcoming releases of the Element X mobile apps without having to run a Sliding Sync Proxy. ##### Features - Enable native sliding sync support ([MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) and [MSC4186](https://github.com/matrix-org/matrix-spec-proposals/pull/4186)) by default. ([#&#8203;17648](https://github.com/element-hq/synapse/issues/17648)) ##### Synapse 1.114.0rc3 (2024-08-30) ##### Bugfixes - Fix regression in v1.114.0rc2 that caused workers to fail to start. ([#&#8203;17626](https://github.com/element-hq/synapse/issues/17626)) ##### Synapse 1.114.0rc2 (2024-08-30) ##### Features - Improve cross-signing upload when using [MSC3861](https://github.com/matrix-org/matrix-spec-proposals/pull/3861) to use a custom UIA flow stage, with web fallback support. ([#&#8203;17509](https://github.com/element-hq/synapse/issues/17509)) - Make `hash_password` script accept password input from stdin. ([#&#8203;17608](https://github.com/element-hq/synapse/issues/17608)) ##### Bugfixes - Fix hierarchy returning 403 when room is accessible through federation. Contributed by Krishan ([@&#8203;kfiven](https://github.com/kfiven)). ([#&#8203;17194](https://github.com/element-hq/synapse/issues/17194)) - Fix content-length on federation `/thumbnail` responses. ([#&#8203;17532](https://github.com/element-hq/synapse/issues/17532)) - Fix authenticated media responses using a wrong limit when following redirects over federation. ([#&#8203;17543](https://github.com/element-hq/synapse/issues/17543)) ##### Internal Changes - MSC3861: load the issuer and account management URLs from OIDC discovery. ([#&#8203;17407](https://github.com/element-hq/synapse/issues/17407)) - Refactor sliding sync class into multiple files. ([#&#8203;17595](https://github.com/element-hq/synapse/issues/17595)) - Store sliding sync per-connection state in the database. ([#&#8203;17599](https://github.com/element-hq/synapse/issues/17599)) - Make the sliding sync `PerConnectionState` class immutable. ([#&#8203;17600](https://github.com/element-hq/synapse/issues/17600)) - Add support to `@tag_args` for standalone functions. ([#&#8203;17604](https://github.com/element-hq/synapse/issues/17604)) - Speed up incremental syncs in sliding sync by adding some more caching. ([#&#8203;17606](https://github.com/element-hq/synapse/issues/17606)) - Always return the user's own read receipts in sliding sync. ([#&#8203;17617](https://github.com/element-hq/synapse/issues/17617)) - Replace `isort` and `black` with `ruff`. ([#&#8203;17620](https://github.com/element-hq/synapse/issues/17620)) - Refactor sliding sync code to move room list logic out into a separate class. ([#&#8203;17622](https://github.com/element-hq/synapse/issues/17622)) ##### Updates to locked dependencies - Bump attrs from 23.2.0 to 24.2.0. ([#&#8203;17609](https://github.com/element-hq/synapse/issues/17609)) - Bump cryptography from 42.0.8 to 43.0.0. ([#&#8203;17584](https://github.com/element-hq/synapse/issues/17584)) - Bump phonenumbers from 8.13.43 to 8.13.44. ([#&#8203;17610](https://github.com/element-hq/synapse/issues/17610)) - Bump pygithub from 2.3.0 to 2.4.0. ([#&#8203;17612](https://github.com/element-hq/synapse/issues/17612)) - Bump pyyaml from 6.0.1 to 6.0.2. ([#&#8203;17611](https://github.com/element-hq/synapse/issues/17611)) - Bump sentry-sdk from 2.12.0 to 2.13.0. ([#&#8203;17585](https://github.com/element-hq/synapse/issues/17585)) - Bump serde from 1.0.206 to 1.0.208. ([#&#8203;17581](https://github.com/element-hq/synapse/issues/17581)) - Bump serde from 1.0.208 to 1.0.209. ([#&#8203;17613](https://github.com/element-hq/synapse/issues/17613)) - Bump serde\_json from 1.0.124 to 1.0.125. ([#&#8203;17582](https://github.com/element-hq/synapse/issues/17582)) - Bump serde\_json from 1.0.125 to 1.0.127. ([#&#8203;17614](https://github.com/element-hq/synapse/issues/17614)) - Bump types-jsonschema from 4.23.0.20240712 to 4.23.0.20240813. ([#&#8203;17583](https://github.com/element-hq/synapse/issues/17583)) - Bump types-setuptools from 71.1.0.20240726 to 71.1.0.20240818. ([#&#8203;17586](https://github.com/element-hq/synapse/issues/17586)) ##### Synapse 1.114.0rc1 (2024-08-20) ##### Features - Add a flag to `/versions`, `org.matrix.simplified_msc3575`, to indicate whether experimental sliding sync support has been enabled. ([#&#8203;17571](https://github.com/element-hq/synapse/issues/17571)) - Handle changes in `timeline_limit` in experimental sliding sync. ([#&#8203;17579](https://github.com/element-hq/synapse/issues/17579)) - Correctly track read receipts that should be sent down in experimental sliding sync. ([#&#8203;17575](https://github.com/element-hq/synapse/issues/17575), [#&#8203;17589](https://github.com/element-hq/synapse/issues/17589), [#&#8203;17592](https://github.com/element-hq/synapse/issues/17592)) ##### Bugfixes - Start handlers for new media endpoints when media resource configured. ([#&#8203;17483](https://github.com/element-hq/synapse/issues/17483)) - Fix timeline ordering (using `stream_ordering` instead of topological ordering) in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17510](https://github.com/element-hq/synapse/issues/17510)) - Fix experimental sliding sync implementation to remember any updates in rooms that were not sent down immediately. ([#&#8203;17535](https://github.com/element-hq/synapse/issues/17535)) - Better exclude partially stated rooms if we must await full state in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17538](https://github.com/element-hq/synapse/issues/17538)) - Handle lower-case http headers in `_Mulitpart_Parser_Protocol`. ([#&#8203;17545](https://github.com/element-hq/synapse/issues/17545)) - Fix fetching federation signing keys from servers that omit `old_verify_keys`. Contributed by [@&#8203;tulir](https://github.com/tulir) @&#8203; Beeper. ([#&#8203;17568](https://github.com/element-hq/synapse/issues/17568)) - Fix bug where we would respond with an error when a remote server asked for media that had a length of 0, using the new multipart federation media endpoint. ([#&#8203;17570](https://github.com/element-hq/synapse/issues/17570)) ##### Improved Documentation - Clarify default behaviour of the [`auto_accept_invites.worker_to_run_on`](https://element-hq.github.io/synapse/develop/usage/configuration/config_documentation.html#auto-accept-invites) option. ([#&#8203;17515](https://github.com/element-hq/synapse/issues/17515)) - Improve docstrings for profile methods. ([#&#8203;17559](https://github.com/element-hq/synapse/issues/17559)) ##### Internal Changes - Add more tracing to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17514](https://github.com/element-hq/synapse/issues/17514)) - Fixup comment in sliding sync implementation. ([#&#8203;17531](https://github.com/element-hq/synapse/issues/17531)) - Replace override of deprecated method `HTTPAdapter.get_connection` with `get_connection_with_tls_context`. ([#&#8203;17536](https://github.com/element-hq/synapse/issues/17536)) - Fix performance of device lists in `/key/changes` and sliding sync. ([#&#8203;17537](https://github.com/element-hq/synapse/issues/17537), [#&#8203;17548](https://github.com/element-hq/synapse/issues/17548)) - Bump setuptools from 67.6.0 to 72.1.0. ([#&#8203;17542](https://github.com/element-hq/synapse/issues/17542)) - Add a utility function for generating random event IDs. ([#&#8203;17557](https://github.com/element-hq/synapse/issues/17557)) - Speed up responding to media requests. ([#&#8203;17558](https://github.com/element-hq/synapse/issues/17558), [#&#8203;17561](https://github.com/element-hq/synapse/issues/17561), [#&#8203;17564](https://github.com/element-hq/synapse/issues/17564), [#&#8203;17566](https://github.com/element-hq/synapse/issues/17566), [#&#8203;17567](https://github.com/element-hq/synapse/issues/17567), [#&#8203;17569](https://github.com/element-hq/synapse/issues/17569)) - Test github token before running release script steps. ([#&#8203;17562](https://github.com/element-hq/synapse/issues/17562)) - Reduce log spam of multipart files. ([#&#8203;17563](https://github.com/element-hq/synapse/issues/17563)) - Refactor per-connection state in experimental sliding sync handler. ([#&#8203;17574](https://github.com/element-hq/synapse/issues/17574)) - Add histogram metrics for sliding sync processing time. ([#&#8203;17593](https://github.com/element-hq/synapse/issues/17593)) ##### Updates to locked dependencies - Bump bytes from 1.6.1 to 1.7.1. ([#&#8203;17526](https://github.com/element-hq/synapse/issues/17526)) - Bump lxml from 5.2.2 to 5.3.0. ([#&#8203;17550](https://github.com/element-hq/synapse/issues/17550)) - Bump phonenumbers from 8.13.42 to 8.13.43. ([#&#8203;17551](https://github.com/element-hq/synapse/issues/17551)) - Bump regex from 1.10.5 to 1.10.6. ([#&#8203;17527](https://github.com/element-hq/synapse/issues/17527)) - Bump sentry-sdk from 2.10.0 to 2.12.0. ([#&#8203;17553](https://github.com/element-hq/synapse/issues/17553)) - Bump serde from 1.0.204 to 1.0.206. ([#&#8203;17556](https://github.com/element-hq/synapse/issues/17556)) - Bump serde\_json from 1.0.122 to 1.0.124. ([#&#8203;17555](https://github.com/element-hq/synapse/issues/17555)) - Bump sigstore/cosign-installer from 3.5.0 to 3.6.0. ([#&#8203;17549](https://github.com/element-hq/synapse/issues/17549)) - Bump types-pyyaml from 6.0.12.20240311 to 6.0.12.20240808. ([#&#8203;17552](https://github.com/element-hq/synapse/issues/17552)) - Bump types-requests from 2.31.0.20240406 to 2.32.0.20240712. ([#&#8203;17524](https://github.com/element-hq/synapse/issues/17524)) ### [`v1.113.0`](https://github.com/element-hq/synapse/releases/tag/v1.113.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.112.0...v1.113.0) ##### Synapse 1.113.0 (2024-08-13) No significant changes since 1.113.0rc1. ##### Synapse 1.113.0rc1 (2024-08-06) ##### Features - Track which rooms have been sent to clients in the experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17447](https://github.com/element-hq/synapse/issues/17447)) - Add Account Data extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17477](https://github.com/element-hq/synapse/issues/17477)) - Add receipts extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17489](https://github.com/element-hq/synapse/issues/17489)) - Add typing notification extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17505](https://github.com/element-hq/synapse/issues/17505)) ##### Bugfixes - Update experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint to handle invite/knock rooms when filtering. ([#&#8203;17450](https://github.com/element-hq/synapse/issues/17450)) - Fix a bug introduced in v1.110.0 which caused `/keys/query` to return incomplete results, leading to high network activity and CPU usage on Matrix clients. ([#&#8203;17499](https://github.com/element-hq/synapse/issues/17499)) ##### Improved Documentation - Update the [`allowed_local_3pids`](https://element-hq.github.io/synapse/v1.112/usage/configuration/config_documentation.html#allowed_local_3pids) config option's msisdn address to a working example. ([#&#8203;17476](https://github.com/element-hq/synapse/issues/17476)) ##### Internal Changes - Change sliding sync to use their own token format in preparation for storing per-connection state. ([#&#8203;17452](https://github.com/element-hq/synapse/issues/17452)) - Ensure we don't send down negative `bump_stamp` in experimental sliding sync endpoint. ([#&#8203;17478](https://github.com/element-hq/synapse/issues/17478)) - Do not send down empty room entries down experimental sliding sync endpoint. ([#&#8203;17479](https://github.com/element-hq/synapse/issues/17479)) - Refactor Sliding Sync tests to better utilize the `SlidingSyncBase`. ([#&#8203;17481](https://github.com/element-hq/synapse/issues/17481), [#&#8203;17482](https://github.com/element-hq/synapse/issues/17482)) - Add some opentracing tags and logging to the experimental sliding sync implementation. ([#&#8203;17501](https://github.com/element-hq/synapse/issues/17501)) - Split and move Sliding Sync tests so we have some more sane test file sizes. ([#&#8203;17504](https://github.com/element-hq/synapse/issues/17504)) - Update the `limited` field description in the Sliding Sync response to accurately describe what it actually represents. ([#&#8203;17507](https://github.com/element-hq/synapse/issues/17507)) - Easier to understand `timeline` assertions in Sliding Sync tests. ([#&#8203;17511](https://github.com/element-hq/synapse/issues/17511)) - Reset the sliding sync connection if we don't recognize the per-connection state position. ([#&#8203;17529](https://github.com/element-hq/synapse/issues/17529)) ##### Updates to locked dependencies - Bump bcrypt from 4.1.3 to 4.2.0. ([#&#8203;17495](https://github.com/element-hq/synapse/issues/17495)) - Bump black from 24.4.2 to 24.8.0. ([#&#8203;17522](https://github.com/element-hq/synapse/issues/17522)) - Bump phonenumbers from 8.13.39 to 8.13.42. ([#&#8203;17521](https://github.com/element-hq/synapse/issues/17521)) - Bump ruff from 0.5.4 to 0.5.5. ([#&#8203;17494](https://github.com/element-hq/synapse/issues/17494)) - Bump serde\_json from 1.0.120 to 1.0.121. ([#&#8203;17493](https://github.com/element-hq/synapse/issues/17493)) - Bump serde\_json from 1.0.121 to 1.0.122. ([#&#8203;17525](https://github.com/element-hq/synapse/issues/17525)) - Bump towncrier from 23.11.0 to 24.7.1. ([#&#8203;17523](https://github.com/element-hq/synapse/issues/17523)) - Bump types-pyopenssl from 24.1.0.20240425 to 24.1.0.20240722. ([#&#8203;17496](https://github.com/element-hq/synapse/issues/17496)) - Bump types-setuptools from 70.1.0.20240627 to 71.1.0.20240726. ([#&#8203;17497](https://github.com/element-hq/synapse/issues/17497)) ### [`v1.112.0`](https://github.com/element-hq/synapse/releases/tag/v1.112.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.111.1...v1.112.0) ##### Synapse 1.112.0 (2024-07-30) This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for [CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again](https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7). Note that this security fix is also available as **Synapse 1.111.1**, which does not include the rest of the changes in Synapse 1.112.0. This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request. If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality. With that said, despite being a high severity issue, **we consider it unlikely that Synapse installations will be affected**. The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration. Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today. **pip users:** Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. **Please manually install the new version of Twisted** using `pip install Twisted==24.7.0rc1`. Note also that even the `--upgrade-strategy=eager` flag to `pip install -U matrix-synapse` will not upgrade Twisted to a patched version because it is only a release candidate at this time. ##### Internal Changes - Upgrade locked dependency on Twisted to 24.7.0rc1. ([#&#8203;17502](https://github.com/element-hq/synapse/issues/17502)) ##### Synapse 1.112.0rc1 (2024-07-23) Please note that this release candidate does not include the security dependency update included in version 1.111.1 as this version was released before 1.111.1. The same security fix can be found in the full release of 1.112.0. ##### Features - Add to-device extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17416](https://github.com/element-hq/synapse/issues/17416)) - Populate `name`/`avatar` fields in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17418](https://github.com/element-hq/synapse/issues/17418)) - Populate `heroes` and room summary fields (`joined_count`, `invited_count`) in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17419](https://github.com/element-hq/synapse/issues/17419)) - Populate `is_dm` room field in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17429](https://github.com/element-hq/synapse/issues/17429)) - Add room subscriptions to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17432](https://github.com/element-hq/synapse/issues/17432)) - Prepare for authenticated media freeze. ([#&#8203;17433](https://github.com/element-hq/synapse/issues/17433)) - Add E2EE extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17454](https://github.com/element-hq/synapse/issues/17454)) ##### Bugfixes - Add configurable option to always include offline users in presence sync results. Contributed by [@&#8203;Michael-Hollister](https://github.com/Michael-Hollister). ([#&#8203;17231](https://github.com/element-hq/synapse/issues/17231)) - Fix bug in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint when using room type filters and the user has one or more remote invites. ([#&#8203;17434](https://github.com/element-hq/synapse/issues/17434)) - Order `heroes` by `stream_ordering` as the Matrix specification states (applies to `/sync`). ([#&#8203;17435](https://github.com/element-hq/synapse/issues/17435)) - Fix rare bug where `/sync` would break for a user when using workers with multiple stream writers. ([#&#8203;17438](https://github.com/element-hq/synapse/issues/17438)) ##### Improved Documentation - Update the readme image to have a white background, so that it is readable in dark mode. ([#&#8203;17387](https://github.com/element-hq/synapse/issues/17387)) - Add Red Hat Enterprise Linux and Rocky Linux 8 and 9 installation instructions. ([#&#8203;17423](https://github.com/element-hq/synapse/issues/17423)) - Improve documentation for the [`default_power_level_content_override`](https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#default_power_level_content_override) config option. ([#&#8203;17451](https://github.com/element-hq/synapse/issues/17451)) ##### Internal Changes - Make sure we always use the right logic for enabling the media repo. ([#&#8203;17424](https://github.com/element-hq/synapse/issues/17424)) - Fix argument documentation for method `RateLimiter.record_action`. ([#&#8203;17426](https://github.com/element-hq/synapse/issues/17426)) - Reduce volume of 'Waiting for current token' logs, which were introduced in v1.109.0. ([#&#8203;17428](https://github.com/element-hq/synapse/issues/17428)) - Limit concurrent remote downloads to 6 per IP address, and decrement remote downloads without a content-length from the ratelimiter after the download is complete. ([#&#8203;17439](https://github.com/element-hq/synapse/issues/17439)) - Remove unnecessary call to resume producing in fake channel. ([#&#8203;17449](https://github.com/element-hq/synapse/issues/17449)) - Update experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint to bump room when it is created. ([#&#8203;17453](https://github.com/element-hq/synapse/issues/17453)) - Speed up generating sliding sync responses. ([#&#8203;17458](https://github.com/element-hq/synapse/issues/17458)) - Add cache to `get_rooms_for_local_user_where_membership_is` to speed up sliding sync. ([#&#8203;17460](https://github.com/element-hq/synapse/issues/17460)) - Speed up fetching room keys from backup. ([#&#8203;17461](https://github.com/element-hq/synapse/issues/17461)) - Speed up sorting of the room list in sliding sync. ([#&#8203;17468](https://github.com/element-hq/synapse/issues/17468)) - Implement handling of `$ME` as a state key in sliding sync. ([#&#8203;17469](https://github.com/element-hq/synapse/issues/17469)) ##### Updates to locked dependencies - Bump bytes from 1.6.0 to 1.6.1. ([#&#8203;17441](https://github.com/element-hq/synapse/issues/17441)) - Bump hiredis from 2.3.2 to 3.0.0. ([#&#8203;17464](https://github.com/element-hq/synapse/issues/17464)) - Bump jsonschema from 4.22.0 to 4.23.0. ([#&#8203;17444](https://github.com/element-hq/synapse/issues/17444)) - Bump matrix-org/done-action from 2 to 3. ([#&#8203;17440](https://github.com/element-hq/synapse/issues/17440)) - Bump mypy from 1.9.0 to 1.10.1. ([#&#8203;17445](https://github.com/element-hq/synapse/issues/17445)) - Bump pyopenssl from 24.1.0 to 24.2.1. ([#&#8203;17465](https://github.com/element-hq/synapse/issues/17465)) - Bump ruff from 0.5.0 to 0.5.4. ([#&#8203;17466](https://github.com/element-hq/synapse/issues/17466)) - Bump sentry-sdk from 2.6.0 to 2.8.0. ([#&#8203;17456](https://github.com/element-hq/synapse/issues/17456)) - Bump sentry-sdk from 2.8.0 to 2.10.0. ([#&#8203;17467](https://github.com/element-hq/synapse/issues/17467)) - Bump setuptools from 67.6.0 to 70.0.0. ([#&#8203;17448](https://github.com/element-hq/synapse/issues/17448)) - Bump twine from 5.1.0 to 5.1.1. ([#&#8203;17443](https://github.com/element-hq/synapse/issues/17443)) - Bump types-jsonschema from 4.22.0.20240610 to 4.23.0.20240712. ([#&#8203;17446](https://github.com/element-hq/synapse/issues/17446)) - Bump ulid from 1.1.2 to 1.1.3. ([#&#8203;17442](https://github.com/element-hq/synapse/issues/17442)) - Bump zipp from 3.15.0 to 3.19.1. ([#&#8203;17427](https://github.com/element-hq/synapse/issues/17427)) ### [`v1.111.1`](https://github.com/element-hq/synapse/releases/tag/v1.111.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.111.0...v1.111.1) ##### Synapse 1.111.1 (2024-07-30) This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for [CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again](https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7). This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request. If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality. With that said, despite being a high severity issue, **we consider it unlikely that Synapse installations will be affected**. The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration. Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today. **pip users:** Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. **Please manually install the new version of Twisted** using `pip install Twisted==24.7.0rc1`. Note also that even the `--upgrade-strategy=eager` flag to `pip install -U matrix-synapse` will not upgrade Twisted to a patched version because it is only a release candidate at this time. ##### Internal Changes - Upgrade locked dependency on Twisted to 24.7.0rc1. ([#&#8203;17502](https://github.com/element-hq/synapse/issues/17502)) </details> <details> <summary>markdownlint/markdownlint (markdownlint/markdownlint)</summary> ### [`v0.18.1`](https://github.com/markdownlint/markdownlint/blob/HEAD/CHANGELOG.md#v0181-2026-08-09) [Compare Source](https://github.com/markdownlint/markdownlint/compare/v0.18.0...v0.18.1) ##### Fixed - Fixed crash on startup when using old versions of the uri gem. [#&#8203;606](https://github.com/markdownlint/markdownlint/pull/606/) ### [`v0.18.0`](https://github.com/markdownlint/markdownlint/blob/HEAD/CHANGELOG.md#v0180-2026-08-05) [Compare Source](https://github.com/markdownlint/markdownlint/compare/v0.17.0...v0.18.0) ##### Added - MD034 - Add `allow_quoted` option. [#&#8203;594](https://github.com/markdownlint/markdownlint/pull/594/) - Add config options for kramdown parser opts: `parse_block_html`, `parse_span_html`, `html_to_native` [#&#8203;568](https://github.com/markdownlint/markdownlint/pull/568/) - Support options on codeblock openers [#&#8203;590](https://github.com/markdownlint/markdownlint/pull/590/) - Add `front_matter_title` parameter for all header-related rules [#&#8203;570](https://github.com/markdownlint/markdownlint/pull/570/) ##### Fixed - MD024 - Fix crash when `allow_different_nesting` was set [#&#8203;593](https://github.com/markdownlint/markdownlint/pull/593/) - Handle UTF-8 filenames better with `-g` [#&#8203;591](https://github.com/markdownlint/markdownlint/pull/591/) ##### Changed - MD013 - When `treat_links_as_single_words` is set, also allow link references to be on a single line regardless of length [#&#8203;597](https://github.com/markdownlint/markdownlint/pull/597/) ### [`v0.17.0`](https://github.com/markdownlint/markdownlint/blob/HEAD/CHANGELOG.md#v0170-2026-06-03) [Compare Source](https://github.com/markdownlint/markdownlint/compare/v0.16.0...v0.17.0) ##### Added - Added `treat_links_as_single_word` option to MD013 [#&#8203;580](https://github.com/markdownlint/markdownlint/pull/580/) ##### Fixed - MD013 - Do not trigger on a single long word in backticks [#&#8203;580](https://github.com/markdownlint/markdownlint/pull/580/) - MD013 - Do not trigger on a single long word alone on a line continuation [#&#8203;580](https://github.com/markdownlint/markdownlint/pull/580/) - MD013 - Do not trigger on a list item with a single long word [#&#8203;580](https://github.com/markdownlint/markdownlint/pull/580/) - Docker - Use latest alphine so mdl version is correct ### [`v0.16.0`](https://github.com/markdownlint/markdownlint/blob/HEAD/CHANGELOG.md#v0160-2026-05-29) [Compare Source](https://github.com/markdownlint/markdownlint/compare/v0.15.0...v0.16.0) ##### Added - Add autocorrecting [#&#8203;519](https://github.com/markdownlint/markdownlint/pull/559/) ##### Changed - Added extra documentation around excluding rules [#&#8203;516](https://github.com/markdownlint/markdownlint/pull/516/) - Update Kramdown [#&#8203;539](https://github.com/markdownlint/markdownlint/pull/539/) - Start from all rules when style only contains exclusions [#&#8203;551](https://github.com/markdownlint/markdownlint/pull/551/) - Give error when explicitly specified config file is not found [#&#8203;554](https://github.com/markdownlint/markdownlint/pull/554/) - Skip docs footer for rules without a docs URL [#&#8203;556](https://github.com/markdownlint/markdownlint/pull/556/) - Fix "bulletd" typo in test file names [#&#8203;557](https://github.com/markdownlint/markdownlint/pull/557/) - Accept string values for symbol params in style files [#&#8203;561](https://github.com/markdownlint/markdownlint/pull/561/) - Bump bundler version [#&#8203;569](https://github.com/markdownlint/markdownlint/pull/569/) ##### Fixed - MD005 - Fixed inconsistent UL/OL ordering [#&#8203;539](https://github.com/markdownlint/markdownlint/pull/539/) - MD013 - Fixed line length detection [#&#8203;539](https://github.com/markdownlint/markdownlint/pull/539/) - Fix fenced code blocks not detected without preceding blank line [#&#8203;541](https://github.com/markdownlint/markdownlint/pull/541/) - Fix front matter offset when blank line follows closing --- [#&#8203;542](https://github.com/markdownlint/markdownlint/pull/542/) - MD029 - Fix false positive for ordered lists inside blockquotes [#&#8203;543](https://github.com/markdownlint/markdownlint/pull/543/) - MD026 - Fix false positive on emoji shortcodes in headers [#&#8203;543](https://github.com/markdownlint/markdownlint/pull/544/) - MD011 - Fix false positive on footnote references [#&#8203;545](https://github.com/markdownlint/markdownlint/pull/545/) - Fix crash on files with invalid UTF-8 byte sequences [#&#8203;546](https://github.com/markdownlint/markdownlint/pull/546/) - MD034 - FIx not detecting bare URLs inside tables [#&#8203;547](https://github.com/markdownlint/markdownlint/pull/547/) - Fix front matter regex matching --- inside code blocks [#&#8203;548](https://github.com/markdownlint/markdownlint/pull/548/) - MD037 - Fix false positive on escaped emphasis markers [#&#8203;549](https://github.com/markdownlint/markdownlint/pull/549/) - MD014 - Fix false positive on code blocks with only blank lines [#&#8203;550](https://github.com/markdownlint/markdownlint/pull/550/) - MD040 - Fix false positive on tab-indented code blocks [#&#8203;552](https://github.com/markdownlint/markdownlint/pull/552/) - MD034 - Fix false positive for URLs inside HTML elements [#&#8203;553](https://github.com/markdownlint/markdownlint/pull/553/) - Fix double slashes in file paths when directory has trailing slash [#&#8203;555](https://github.com/markdownlint/markdownlint/pull/555/) - MD031 - Fix false positive on inline backtick code spans [#&#8203;558](https://github.com/markdownlint/markdownlint/pull/558/) - MD013 - Detect table-like lines even when kramdown parses them as paragraphs [#&#8203;560](https://github.com/markdownlint/markdownlint/pull/560/) - MD007 - Fix false positive on unrelated lists at different indent levels [#&#8203;562](https://github.com/markdownlint/markdownlint/pull/562/) - MD034 - Fix false positive when link text contains pipe character [#&#8203;564](https://github.com/markdownlint/markdownlint/pull/564/) - MD032 - Fix false positive on HTML comments adjacent to lists [#&#8203;565](https://github.com/markdownlint/markdownlint/pull/565/) - MD027 - Fix false positive on blockquotes with soft line breaks [#&#8203;566](https://github.com/markdownlint/markdownlint/pull/566/) - MD013 - Add :headings parameter to exclude headings from line length [#&#8203;563](https://github.com/markdownlint/markdownlint/pull/563/) - MD013 - Don't flag lines that are single-words [#&#8203;572](https://github.com/markdownlint/markdownlint/pull/572/) ### [`v0.15.0`](https://github.com/markdownlint/markdownlint/blob/HEAD/CHANGELOG.md#v0150-2025-11-25) [Compare Source](https://github.com/markdownlint/markdownlint/compare/v0.14.0...v0.15.0) ##### Changed - Bumped minum ruby version to 3.2 [#&#8203;531](https://github.com/markdownlint/markdownlint/pull/531), and associated changes ### [`v0.14.0`](https://github.com/markdownlint/markdownlint/blob/HEAD/CHANGELOG.md#v0140-2025-11-25) [Compare Source](https://github.com/markdownlint/markdownlint/compare/v0.13.0...v0.14.0) ##### Fixed - Fix Markdown lint version in SARIF output test [#&#8203;469](https://github.com/markdownlint/markdownlint/pull/469) - Fix example for rulesets flag in configuration docs [#&#8203;473](https://github.com/markdownlint/markdownlint/pull/473) - Require ruby-3.3.0 for standalone pre-commit hook [#&#8203;528](https://github.com/markdownlint/markdownlint/pull/528) ##### Rules Removed - Removed MD055, MD056, MD057 - These rules for tables caused regressions and were removed (see [#&#8203;472](https://github.com/markdownlint/markdownlint/issues/472) for details) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMS4xIiwidXBkYXRlZEluVmVyIjoiNDIuOTkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.112.0
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
bc3771729e
renovate force-pushed renovate/all-minor-patch from bc3771729e
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
to 0f08efbbcd
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
2024-08-13 16:20:42 +02:00
Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.112.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.113.0 2024-08-13 16:20:48 +02:00
renovate force-pushed renovate/all-minor-patch from 0f08efbbcd
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
to 5a102dddc7
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
2024-09-03 09:10:46 +02:00
Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.113.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.114.0 2024-09-03 09:10:53 +02:00
renovate force-pushed renovate/all-minor-patch from 5a102dddc7
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
to 7509412bac
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
2024-09-17 16:06:21 +02:00
Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.114.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.115.0 2024-09-17 16:06:27 +02:00
renovate force-pushed renovate/all-minor-patch from 7509412bac
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
to 457cc9adee
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
2024-10-01 13:06:49 +02:00
Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.115.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.116.0 2024-10-01 13:06:59 +02:00
renovate force-pushed renovate/all-minor-patch from 457cc9adee
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
to 04d06dad3c
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
2024-10-15 15:06:37 +02:00
Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.116.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.117.0 2024-10-15 15:06:48 +02:00
renovate force-pushed renovate/all-minor-patch from 04d06dad3c
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
to 55bb3982c7 2024-10-30 08:16:08 +01:00
Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.117.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.118.0 2024-10-30 08:16:19 +01:00
renovate force-pushed renovate/all-minor-patch from 55bb3982c7 to 6c793a548e 2024-11-13 19:37:48 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.118.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.119.0 2024-11-13 19:38:00 +01:00
renovate force-pushed renovate/all-minor-patch from 6c793a548e to c037ae5ab0 2024-11-28 11:09:44 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.119.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.0 2024-11-28 11:09:59 +01:00
renovate force-pushed renovate/all-minor-patch from c037ae5ab0 to 2169092f56 2024-12-04 10:16:59 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.2 2024-12-04 10:17:13 +01:00
renovate force-pushed renovate/all-minor-patch from 2169092f56 to a33993660d 2024-12-12 10:16:13 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.2 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.121.1 2024-12-12 10:16:27 +01:00
renovate force-pushed renovate/all-minor-patch from a33993660d to 651bac3071 2025-01-15 10:15:25 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.121.1 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.122.0 2025-01-15 10:15:32 +01:00
renovate force-pushed renovate/all-minor-patch from 651bac3071 to 7f70fa5268 2025-01-28 18:57:07 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.122.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.123.0 2025-01-28 18:57:14 +01:00
renovate force-pushed renovate/all-minor-patch from 7f70fa5268 to 65fc0c0daa 2025-02-11 13:14:28 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.123.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.124.0 2025-02-11 13:14:36 +01:00
renovate force-pushed renovate/all-minor-patch from 65fc0c0daa to fa1d7c5a33 2025-02-26 10:13:23 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.124.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.125.0 2025-02-26 10:13:30 +01:00
renovate force-pushed renovate/all-minor-patch from fa1d7c5a33 to dfaa0714f6 2025-03-11 15:12:05 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.125.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.126.0 2025-03-11 15:12:13 +01:00
renovate force-pushed renovate/all-minor-patch from dfaa0714f6 to 2837bae2a0 2025-03-25 14:10:44 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.126.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.0 2025-03-25 14:10:55 +01:00
renovate force-pushed renovate/all-minor-patch from 2837bae2a0 to 3d4b283665 2025-03-27 10:14:22 +01:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.1 2025-03-27 10:14:32 +01:00
renovate force-pushed renovate/all-minor-patch from 3d4b283665 to a7e227461b 2025-04-08 16:10:38 +02:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.1 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.128.0 2025-04-08 16:10:50 +02:00
renovate force-pushed renovate/all-minor-patch from a7e227461b to 76d6dcdc19 2025-05-06 14:14:50 +02:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.128.0 to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.129.0 2025-05-06 14:15:00 +02:00
renovate force-pushed renovate/all-minor-patch from 76d6dcdc19 to 79431dc14a 2025-05-12 11:16:58 +02:00 Compare
renovate changed title from Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.129.0 to Renovate: Update all non-major dependencies 2025-05-12 11:17:09 +02:00
renovate force-pushed renovate/all-minor-patch from 79431dc14a to 2de302022e 2025-05-20 17:16:59 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 2de302022e to eb2d26b28b 2025-05-21 11:18:33 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from eb2d26b28b to d21a9f51d0 2025-06-02 15:10:31 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from d21a9f51d0 to 810670dc25 2025-06-03 16:10:38 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 810670dc25 to ff10a4c858 2025-06-17 16:10:00 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from ff10a4c858 to 7102db27c7 2025-07-01 17:14:33 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 7102db27c7 to 7ec4fc5796 2025-07-15 16:16:20 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 7ec4fc5796 to 6ec7d8ec04 2025-08-01 15:16:41 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 6ec7d8ec04 to b34af1c76e 2025-08-12 11:15:49 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from b34af1c76e to c7a2597eea 2025-08-12 16:14:49 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from c7a2597eea to f56bac66e8 2025-08-26 12:16:21 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from f56bac66e8 to 084bb00cb6 2025-09-09 13:18:13 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 084bb00cb6 to 84b6036311 2025-09-24 13:19:55 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 84b6036311 to 9b5c61a0a5 2025-09-24 14:20:25 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 9b5c61a0a5 to 2469cd1de8 2025-09-30 13:21:06 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 2469cd1de8 to 42f41a1021 2025-10-07 14:20:04 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 42f41a1021 to ab45b858de 2025-10-08 09:20:48 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from ab45b858de to fb2af66298 2025-10-14 17:20:56 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from fb2af66298 to 39f5358ae7 2025-10-29 12:21:19 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 39f5358ae7 to fe7b832865 2025-11-11 11:23:42 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from fe7b832865 to eaf5b59fe7 2025-11-19 08:24:47 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from eaf5b59fe7 to 4f3528fe33 2025-11-26 08:24:44 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 4f3528fe33 to 0133819340 2025-12-10 08:27:13 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 0133819340 to 2ca56bf4d0 2026-01-14 08:10:50 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 2ca56bf4d0 to 38d240cb11 2026-01-28 08:09:31 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 38d240cb11 to 63c72e6a7a 2026-02-10 15:10:59 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 63c72e6a7a to 2be5336b1c 2026-02-13 08:11:14 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 2be5336b1c to 7f0135ef57 2026-02-24 14:14:25 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 7f0135ef57 to cc1f48e151 2026-03-04 08:14:20 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from cc1f48e151 to d2b961eec1 2026-03-09 08:14:55 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from d2b961eec1 to 5c1958f0b5 2026-03-10 15:15:02 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 5c1958f0b5 to 8c53f87428 2026-03-11 11:14:07 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 8c53f87428 to 9c8248965a 2026-03-24 16:08:33 +01:00 Compare
renovate force-pushed renovate/all-minor-patch from 9c8248965a to e796c50ba0 2026-04-08 10:18:57 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from e796c50ba0 to 9bc2ea6440 2026-04-28 15:21:17 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 9bc2ea6440 to cba293cf6a 2026-05-07 16:21:48 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from cba293cf6a to 981013a947 2026-05-19 15:25:33 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 981013a947 to a886729a30 2026-06-01 09:25:35 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from a886729a30 to 0a57ad5f16 2026-06-04 09:26:39 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 0a57ad5f16 to 1270468d04 2026-06-04 15:25:50 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 1270468d04 to 6c312324b1 2026-06-16 16:27:02 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 6c312324b1 to f4102f454c 2026-07-07 15:29:22 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from f4102f454c to f60123707b 2026-07-21 17:31:45 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from f60123707b to 81da02d043 2026-07-22 17:31:49 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 81da02d043 to b2fb683c88 2026-07-28 15:32:37 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from b2fb683c88 to 1121a8aea1 2026-08-05 09:33:31 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 1121a8aea1 to 19adfa8cfb 2026-08-06 09:34:42 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 19adfa8cfb to e58152bce8 2026-08-10 09:34:55 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from e58152bce8 to 021974f05c 2026-08-19 09:35:14 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 021974f05c to def9f406c0 2026-09-03 09:37:36 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from def9f406c0 to 5cb0619d3d 2026-09-16 09:39:23 +02:00 Compare
renovate force-pushed renovate/all-minor-patch from 5cb0619d3d to 89760d836d 2026-09-29 20:41:24 +02:00 Compare
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/all-minor-patch:renovate/all-minor-patch
git switch renovate/all-minor-patch

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/all-minor-patch
git switch renovate/all-minor-patch
git rebase main
git switch main
git merge --ff-only renovate/all-minor-patch
git switch renovate/all-minor-patch
git rebase main
git switch main
git merge --no-ff renovate/all-minor-patch
git switch main
git merge --squash renovate/all-minor-patch
git switch main
git merge --ff-only renovate/all-minor-patch
git switch main
git merge renovate/all-minor-patch
git push origin main
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
NB-Public/rocketchat2matrix!151
No description provided.