Renovate: Update all non-major dependencies #151
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
NB-Public/rocketchat2matrix!151
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/all-minor-patch"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
0.10.3→0.11.4v1.111.0→v1.162.0v0.13.0→v0.18.1Note: The
pre-commitmanager in Renovate is not supported by thepre-commitmaintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
Awesome-Technologies/synapse-admin (awesometechnologies/synapse-admin)
v0.11.4Compare Source
v0.11.3Compare Source
v0.11.2Compare Source
v0.11.1Compare Source
v0.11.0Compare Source
v0.10.4Compare Source
element-hq/synapse (docker.io/matrixdotorg/synapse)
v1.162.0Compare Source
Changelog: https://github.com/element-hq/synapse/blob/release-v1.162/CHANGES.md
v1.161.0Compare Source
Changelog: https://github.com/element-hq/synapse/blob/release-v1.161/CHANGES.md
v1.160.0Compare Source
Changelog: https://github.com/element-hq/synapse/blob/release-v1.160/CHANGES.md
v1.159.0Compare Source
Changelog: https://github.com/element-hq/synapse/blob/release-v1.159/CHANGES.md
v1.158.0Compare Source
Changelog: https://github.com/element-hq/synapse/blob/release-v1.158/CHANGES.md
v1.157.2Compare Source
Synapse 1.157.2 (2026-07-28)
This security release addresses several vulnerabilities.
Please upgrade when you can, particularly if your homeserver participates in open federation
and/or has untrusted local users.
Security Fixes
High severity:
Moderate severity:
Low severity:
v1.157.1Compare Source
Synapse 1.157.1 (2026-07-22)
Bugfixes
experimental_featuresno longer being accepted. (#19987)v1.157.0Compare Source
Synapse 1.157.0 (2026-07-21)
No significant changes since 1.157.0rc1.
Synapse 1.157.0rc1 (2026-07-14)
Features
exclude_rooms_from_presenceconfiguration option to stop presence being routed between users solely because they share one of the listed rooms. (#19935)Bugfixes
flag_existing_quarantined_mediabackground update skipping some quarantined remote media. Introduced in v1.152.0. (#19901)Contributed by @m4us1ne. (#19902)
de.sorunome.msc2409.push_ephemeralregistration flag stopped receiving ephemeral events (including to-device messages used for encryption). Introduced in v1.156.0. (#19928)SYNAPSE_ASYNC_IO_REACTOR=1on Python 3.14. (#19949)Deprecations and Removals
Internal Changes
HomeserverTestCase.get_success(...)and friends to drive async Rust (Tokio runtime/thread pool). (#19871, #19879)golangci-lintto CI. (#19888)test_redact_messages_all_roomstest, as this caused flakiness. (#19890)/eventsendpoint fromPOSTtoGET. (#19896)/eventsendpoint paging to match spec conventions. (#19897)sliding_sync_connection_lazy_membersto speed up deleting old sliding sync connection positions. (#19923)test_lock_contentionbeing flaky when running against PostgreSQL by budgeting CPU time rather than wall-clock time. (#19929)FIXMEnote forTestOIDCProviderUnavailable(problem tracked by #19937). (#19938)last_active_granularity,sync_online_timeoutandidle_timeoutoptions to thepresenceconfig section to allow tuning the presence state machine timers. (#19942)v1.156.0Compare Source
Synapse 1.156.0 (2026-07-07)
No significant changes since 1.156.0rc1.
Synapse 1.156.0rc1 (2026-06-30)
Features
allowed_room_idsin the/summaryclient-server API response for rooms with restricted join rules, as required by Matrix 1.15.Contributed by @FrenchGithubUser @Famedly. (#19762)
/restart) to bypass ratelimits for unauthenticated requests based on the client IP address. (#19794)synapse_non_deactivated_user_countwhich tracks the number of non-deactivated users in the database, split byapp_service. (#19848)GET /_matrix/client/unstable/org.matrix.msc1763/retention/configurationendpoint is now provided when retentionis enabled and
experimental_features.msc1763_enabledis enabled, based onMSC1763. (#19853)
Bugfixes
org.matrix.msc4143inunstable_featureswhenmsc4143_enabledis set. (#19646)0no longer logSynapse now listening on TCP port 0. (#19810)/purge_historywhen notifications had already been rotated into the summary table. (#19834)/synccaching transient errors for thesync_response_cache_duration. (#19845)delete_local_eventsbeing set to false, in room versions other than 1 and 2. (#19850)Improved Documentation
auto_join_roomsconfig documentation to cover requirements for auto-joining invite-only rooms. (#19660)Internal Changes
simple_select_one_onecol_txn()more helpful by naming the table of the select - as all other query wrapper functions already did. (#19869)get_user_which_could_invitelogic to reuseget_users_which_can_issue_invite. Contributed by Noah Markert. (#19732)twisted.protocols.amp.TooLongerror undertrial -jN) caused by an oversized debug log line. (#19832)default_config(server_name="test")usage in test utilities. (#19849).ruff_cache/directory to.gitignore. (#19854)poetryin CI from2.2.1to2.4.1. (#19866, #19877)deferredandtokio_runtimeto their own Rust modules. (#19868)cargo-testandcargo-benchCI jobs from being skipped, even on PRs that have Rust changes. (#19883)v1.155.0Compare Source
Synapse 1.155.0 (2026-06-16)
End of Life of Debian 12 Bookworm
The next version of Synapse will not include Debian packages for Debian 12 Bookworm
as it reached end of life on the 10th of June 2026.
Internal Changes
Synapse 1.155.0rc1 (2026-06-09)
Bugfixes
/capabilitiesendpoint returning a 500 error on non-media workers when MSC4452: Preview URL capabilities API is enabled. (#19839)Improved Documentation
poetry install. (#19818)Internal Changes
GcpJsonFormatterlogging formatter for use with Google Cloud Logging and GKE deployments. (#19775)Requesterclass to Rust. (#19828)v1.154.0Compare Source
Synapse 1.154.0 (2026-06-04)
No significant changes since 1.154.0rc1.
Synapse 1.154.0rc1 (2026-05-27)
Features
io.element.msc4452.preview_urlcapability.If
experimental_features.msc4452_enabledistrue, the/_matrix/(client/v1/media|media/v3)/preview_urlendpointnow responds with a 403 status code when the capability is disabled. (#19715)
Bugfixes
M_BAD_JSON) when sending a message with amentionsfield and Synapse modulecheck_event_allowedcallback registered (frozen event). Contributed by @gaetan-sbt. (#19634)/syncwhere it could attempt to fetch data with flawed invalid future tokens. (#19644)/syncfailing when MSC4354 Sticky Events are enabled and the sync request filters out Ephemeral Data Units (EDUs). (#19787)attrsminimum version requirement inpyproject.tomlfile. Contributed by Oleg Girko. (#19789)Improved Documentation
update_profile_informationsetting is true. (#19508)Internal Changes
Event.contentfield to Rust. (#19725)quarantined_mediawaiting patterns with standardwait_for_stream_token(...). (#19764)We can't get valid state history.so you can correlate everything byevent_id. (#19765)RoomVersionstructs. (#19766)WorkerLocktests to better stress theWORKER_LOCK_MAX_RETRY_INTERVAL. (#19772)TypeIshelper to avoid scatteredisinstancecasts. (#19774)StrCollectionforprev_state_events. (#19777)v1.153.0Compare Source
Synapse 1.153.0 (2026-05-19)
No significant changes since 1.153.0rc3.
Synapse 1.153.0rc3 (2026-05-15)
Bugfixes
Synapse 1.153.0rc2 (2026-05-13)
Bugfixes
unsignedfield of events. The bug was introduced in 1.153.0rc1. (#19769)Synapse 1.153.0rc1 (2026-05-08)
Features
msc3266_enabled. Contributed by @dasha-uwu. (#19720)m.room.createis now a required part of strippedinvite_state/knock_state. Contributed by @FrenchGithubUser @Famedly. (#19722)tombstonedandreplacement_roomin room details on admin API endpointGET /_synapse/admin/v1/rooms/<room_id>. Contributed by Noah Markert. (#19737)Bugfixes
authlibminimum version requirement inpyproject.tomlfile. Contributed by Oleg Girko. (#19742)Improved Documentation
use_frozen_dicts. (#19711)Internal Changes
Event.signaturesfield to Rust. (#19706)Event.unsignedfield to Rust. (#19708)WORKER_LOCK_MAX_RETRY_INTERVALto 5 seconds to reduce idle time after lock is released. (#19755)Durationso time units have to be specified. (#19756)v1.152.1Compare Source
Synapse 1.152.1 (2026-05-07)
Security Fixes
WorkerLocktime out interval to a maximum of 60 seconds. Contributed by Famedly. (#19394, ELEMENTSEC-2026-1706, GHSA-8q93-326v-3m7g, CVE-2026-45078)v1.152.0Compare Source
Synapse 1.152.0 (2026-04-28)
No significant changes since 1.152.0rc1.
Configuration changes needed for deployments using workers
For deployments using workers, please note that this version introduces a new
quarantined_media_changesstream writer, which may require configuration changes.Please see the the relevant section in the upgrade notes for details.
Without configuring this new stream writer, only the main process will be able to handle the
/media/quarantineadmin API endpoints for quarantining media.Synapse 1.152.0rc1 (2026-04-22)
Features
unstable_features. (#19642)list, fetch and delete user reports. (#19657)
device_lists_changes_in_room. (#19473, #19709)Bugfixes
device_keys: nullin the request toPOST /_matrix/client/v3/keys/upload, as per the spec. This was temporarily allowed as a workaround for misbehaving clients. (#19637)SQLITE_DBCONFIG_DEFENSIVEby default, such as macOS. (#19690)Improved Documentation
_setup_sequence(...)inportdb. (#19675)Internal Changes
limitargument in_maybe_backfill_inner(...). (#19630)spam_checker_spammyinternal event metadata. (#19453)FilteredEventclass that saves us copying events. (#19640)EventInternalMetadatato useArc<RwLock<_>>. (#19669)v1.151.0Compare Source
Synapse 1.151.0 (2026-04-07)
Bugfixes
KNOWN_ROOM_VERSIONS.__contains__raisingTypeErrorfor non-string keys, which could cause/syncto fail for rooms with aNULLroom version in the database. Bug introduced in #19589 as part of v1.151.0rc1. (#19649)Synapse 1.151.0rc1 (2026-03-31)
Features
room_versionandencryptionfields in the space/room/hierarchyAPI (part of MSC3266). (#19576)Bugfixes
org.matrix.msc4284.policyandm.room.policystate events. (#19503)Build and push complement imageCI job not havingpoetryavailable for the Complement runner script. (#19578)Deprecations and Removals
Internal Changes
demo/start.shscript. (#19538)RoomVersionattributes. (#19577)redacted_becausefrom internal unsigned. (#19581)RoomVersionto Rust. (#19589)./scripts-dev/complement.sh. (#19592)HomeserverTestCase.pump()docstring to demystify behavior (Twisted reactor/clock). (#19602)HomeserverTestCase.pump()in favor of more directHomeserverTestCase.reactor.advance(...)usage. (#19602)statement_timeoutto 10m (previously 1h). (#19604)v1.150.0Compare Source
Synapse 1.150.0 (2026-03-24)
No significant changes since 1.150.0rc1.
Upgrade notes
Please read the upgrade notes as this release includes a few changes that may affect your deployment.
Synapse 1.150.0rc1 (2026-03-17)
Features
GET /extremitiesendpoint. (#19314)delay_idin the event'sunsignedsection in/syncresponses to the event sender. (#19479)Bugfixes
Build and push complement imageCI job pointing to non-existent image. (#19523)Improved Documentation
/<param>instead of as/$param. (#19307)outbound_federation_restricted_tocan also be used with the Secure Border Gateway (SBG). (#19517)Internal Changes
devdependencies to PEP 735 dependency groups. (#19490)systemd-pythondependency and thesystemdextra on thesynapsepackage. (#19491)/versionsand/auth_metadatapublic endpoints. (#19530)Processed requestlogs. (#19548)v1.149.1Compare Source
Synapse 1.149.1 (2026-03-11)
Internal Changes
matrix-synapse-ldap3to0.4.0to supportsetuptools>=82.0.0. Fixes #19541. (#19543)v1.149.0Compare Source
Synapse 1.149.0 (2026-03-10)
No significant changes since 1.149.0rc1.
Synapse 1.149.0rc1 (2026-03-03)
Features
Bugfixes
/syncmissing membership event instate_after(experimental MSC4222 implementation) in some scenarios. (#19460)Internal Changes
JoinRoomAliasServletwith tracing. (#19461)docker system infoin CI so we have a plain record of how GitHub runners evolve over time. (#19480)test_disconnecttest helper so that pytest doesn't see it as a test. (#19486)Content-Lengthwith the Rust HTTP client. (#19498)v1.148.0Compare Source
Synapse 1.148.0 (2026-02-24)
No significant changes since 1.148.0rc1.
Synapse 1.148.0rc1 (2026-02-17)
Features
Improved Documentation
experimental_featuressection of the configuration manual documentation. (#19435)Deprecations and Removals
Internal Changes
v1.147.1Compare Source
Synapse 1.147.1 (2026-02-12)
v1.147.0Compare Source
Synapse 1.147.0 (2026-02-10)
No significant changes since 1.147.0rc1.
Synapse 1.147.0rc1 (2026-02-03)
Bugfixes
setuptools_rusta runtime dependency. (#19417)Internal Changes
sliding_sync_connection_required_statetable. (#19306)jobselectors (job=~"$job") so the "all" value works correctly across all panels. (#19400)pyo3from 0.26.0 to 0.27.2 andpythonizefrom 0.26.0 to 0.27.0. Contributed by @razvp @ ERCOM. (#19412)v1.146.0Compare Source
Synapse 1.146.0 (2026-01-27)
No significant changes since 1.146.0rc1.
Deprecations and Removals
Synapse 1.146.0rc1 (2026-01-20)
Features
enable_local_media_storagewhich controls whether media is additionally stored locally when using configuredmedia_storage_providers. Setting this tofalseallows off-site media storage without a local cache. Contributed by Patrice Brend'amour @dr.allgood. (#19204)m.oauthUser-Interactive Auth stage for resetting cross-signing identity with the OAuth 2.0 API. The old, unstable name (org.matrix.cross_signing_reset) is now deprecated and will be removed in a future release. (#19273)server_namelabel (instead ofinstance). (#19337)Bugfixes
/_matrix/media/v1/createbeing ratelimited for appservices even ifrate_limited: falsewas set in the registration. Contributed by @tulir @ Beeper. (#19335)InFlightGaugetyping to allow upgrading toprometheus_client0.24. (#19379)Updates to the Docker image
docker/Dockerfile-workersimage (see the Metrics section of our Docker testing docs). (#19336)Improved Documentation
Internal Changes
cancel_taskAPI to the task scheduler. (#19310)auth_types_for_eventandget_catchup_room_event_ids. (#19320)assertEqualswithassertEqualin unit test code. (#19345)mdbookfrom 0.4.17 to 0.5.2 and remove our custom table-of-contents plugin in favour of the new default functionality. (#19356)GitRelease.titlewith.namein release script. (#19358)ProxiedReactorused in worker Complement tests. (#19385)v1.145.0Compare Source
Synapse 1.145.0 (2026-01-13)
No significant changes since 1.145.0rc4.
End of Life of Ubuntu 25.04 Plucky Puffin
Ubuntu 25.04 (Plucky Puffin) will be end of life on Jan 17, 2026. Synapse will stop building packages for Ubuntu 25.04 shortly thereafter.
Updates to Locked Dependencies No Longer Included in Changelog
The "Updates to locked dependencies" section has been removed from the changelog due to lack of use and the maintenance burden. (#19254)
Synapse 1.145.0rc4 (2026-01-08)
No significant changes since 1.145.0rc3.
This RC contains a fix specifically for openSUSE packaging and no other changes.
Synapse 1.145.0rc3 (2026-01-07)
No significant changes since 1.145.0rc2.
This RC strips out unnecessary files from the wheels that were added when fixing the source distribution packaging in the previous RC.
Synapse 1.145.0rc2 (2026-01-07)
No significant changes since 1.145.0rc1.
This RC fixes the source distribution packaging for uploading to PyPI.
Synapse 1.145.0rc1 (2026-01-06)
Features
membershipsendpoint to the admin API. This is useful for forensics and T&S purposes. (#19260)admin_unsafely_bypass_quarantinequery parameter totrueon Client-Server API media download requests. (#19275)GET /_synapse/admin/v2/users/<user_id>. (#19281)federation_client.pydev script. Contributed by Denis Kasak (@dkasak). (#19300)Bugfixes
Durationwas logged incorrectly. (#19267)zope-interfaceolder than 6.2. (#19274)Updates to the Docker image
SYNAPSE_ENABLE_METRICS). (#19324)Improved Documentation
public_baseurlwhen configuring OpenID Connect authentication. (#19270)Deprecations and Removals
Internal Changes
HomeServer.shutdown()failing if the homeserver hasn't been setup yet. (#19187)Content-Lengthheader/s are invalid. (#19212)HomeServer.shutdown()failing if the homeserver failed tostart. (#19232)poetry-coretomaturin. (#19234)Clockunless explicitly enabled. (#19278)uvto test olddeps to ensure all transitive dependencies use minimum versions. (#19289)Failed to listen on 0.0.0.0, continuing because listening on [::]. (#19297)shared_extra_confis combined in our Docker configuration scripts. (#19323).github/workflows/tests.yml. (#19327)v1.144.0Compare Source
Synapse 1.144.0 (2025-12-09)
Deprecation of MacOS Python wheels
The team has decided to deprecate and stop publishing python wheels for MacOS as of this release. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler).
Unstable mutual rooms endpoint is now behind an experimental feature flag
Admins using the unstable MSC2666 endpoint (
/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms), please check the relevant section in the upgrade notes as this release contains changes that disable that endpoint by default.No significant changes since 1.144.0rc1.
Synapse 1.144.0rc1 (2025-12-02)
Admins using the unstable MSC2666 endpoint (
/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms), please check the relevant section in the upgrade notes as this release contains changes that disable that endpoint by default.Features
Bugfixes
use_frozen_dicts: True. (#19235)canonical_aliascontent would return 500 instead of 400. (#19240)Durationwas logged incorrectly. (#19267)Improved Documentation
--config-pathhelp how multiple files are merged - by merging them shallowly. (#19243)Deprecations and Removals
Internal Changes
SYNAPSE_SUPPORTED_COMPLEMENT_TEST_PACKAGESenvironment variable fromscripts-dev/complement.sh. (#19208)scripts-dev/complement.shlogic to avoidexitto facilitate being able to source it from other scripts (composable). (#19209)/_matrix/client/unstable/uk.half-shot.msc2666/user/mutual_rooms) to be available. (#19219)Durationtype. (#19223, #19229)/messagesas expected. (#19226).egg-info. (#19251)Updates to locked dependencies
v1.143.0Compare Source
Synapse 1.143.0 (2025-11-25)
Dropping support for PostgreSQL 13
In line with our deprecation policy, we've dropped support for PostgreSQL 13, as it is no longer supported upstream. This release of Synapse requires PostgreSQL 14+.
No significant changes since 1.143.0rc2.
synapse 1.143.0rc2 (2025-11-18)
Internal Changes
Synapse 1.143.0rc1 (2025-11-18)
Features
register_new_matrix_user. (#18784)POST /_matrix/client/v1/delayed_events, and allow calling this endpoint with the update action to take (send/cancel/restart) in the request path instead of the body. (#19152)Bugfixes
maindatabase. (#19181)delayed_eventstable. (#19155)Improved Documentation
Deprecations and Removals
Internal Changes
X | Ywhere possible, as per PEP 604, added in Python 3.10. (#19111)synapse_storage_events_persisted_events_sep_totalmetric by removingorigin_entitylabel. This also separates out events sent by local application services by changing theorigin_typefor such events toapplication_service. Thetypefield also only tracks common event types, and anything else is bucketed under*other*. (#19133, #19168)pyproject.tomlproject metadata to be compatible with standard Python packaging tooling. (#19137).git-blame-ignore-revs). (#19150)parameterizedto0.9.0andidnato3.3as those are the first to advertise support for Python 3.10. (#19167)sentinelfor the log recordrequestwhen no logcontext is active. (#19172)Clockutilities. (#19173)cibuildwheelconfig as it's no longer required after #19137. (#19177)PerDestinationQueue.shutdown(...)is called. (#19178)Updates to locked dependencies
v1.142.1Compare Source
Synapse 1.142.1 (2025-11-18)
Bugfixes
v1.142.0Compare Source
Synapse 1.142.0 (2025-11-11)
Dropped support for Python 3.9
This release drops support for Python 3.9, in line with our dependency deprecation policy, as it is now end of life.
SQLite 3.40.0+ is now required
The minimum supported SQLite version has been increased from 3.27.0 to 3.40.0.
If you use current versions of the matrixorg/synapse Docker images, no action is required.
Deprecation of MacOS Python wheels
The team has decided to deprecate and eventually stop publishing python wheels for MacOS. This is a burden on the team, and we're not aware of any parties that use them. Synapse docker images will continue to work on MacOS, as will building Synapse from source (though note this requires a Rust compiler).
At present, publishing MacOS Python wheels will continue for the next release (1.143.0), but will not be available after that (1.144.0+). If you do make use of these wheels downstream, please reach out to us in #synapse-dev:matrix.org. We'd love to hear from you!
Internal Changes
Synapse 1.142.0rc4 (2025-11-07)
Bugfixes
matrix_authentication_service.secret_pathwould prevent the homeserver from starting up. (#19144)Synapse 1.142.0rc3 (2025-11-04)
Internal Changes
Synapse 1.142.0rc2 (2025-11-04)
Internal Changes
Synapse 1.142.0rc1 (2025-11-04)
Features
to allow an admin to fetch the space/room hierarchy for a given space. (#19021)
Bugfixes
oidc_session_no_samesitecookie to have theSecureattribute, so the only difference between it and the pairedoidc_sessioncookie, is the configuration of theSameSiteattribute as described in the comments / cookie names. Contributed by @kieranlane. (#19079)HomeServer.shutdown(). (#19108)Improved Documentation
Deprecations and Removals
Internal Changes
CREATE TABLEsyntax. (#19020)RETURNINGas supported by SQL engines, now that the minimum-supported versions of both SQLite and PostgreSQL support it. (#19047)oidc.load_metadata()startup into_base.start(). (#19056)deferLater(...). (#19058)pyproject.toml. (#19081)pp38*skip selector from cibuildwheel to silence warning. (#19085)SIGHUPhandlers in 3rd-party code. (#19095)Image.getexifmethod instead of the experimentalImage._getexif. (#19098)/usr/local/.lockfile from appearing in built Synapse docker images. (#19107)python <= 3.14) into account when checking dependencies. (#19110)exit(1)in our composable functions). (#19116)exit(1)in our composable functions). (#19121, #19131)Updates to locked dependencies
v1.141.0Compare Source
Synapse 1.141.0 (2025-10-29)
Deprecation of MacOS Python wheels
The team has decided to deprecate and eventually stop publishing python wheels
for MacOS. This is a burden on the team, and we're not aware of any parties
that use them. Synapse docker images will continue to work on MacOS, as will
building Synapse from source (though note this requires a Rust compiler).
Publishing MacOS Python wheels will continue for the next few releases. If you
do make use of these wheels downstream, please reach out to us in
#synapse-dev:matrix.org. We'd love to hear from you!
Docker images now based on Debian
trixiewith Python 3.13The Docker images are now based on Debian
trixieand use Python 3.13. If youare using the Docker images as a base image you may need to e.g. adjust the
paths you mount any additional Python packages at.
No significant changes since 1.141.0rc2.
Synapse 1.141.0rc2 (2025-10-28)
Bugfixes
Synapse 1.141.0rc1 (2025-10-21)
Features
Bugfixes
reload-ed more than once when running under systemd. (#19060)Updates to the Docker image
Internal Changes
start_background_tasks(the standard pattern for this kind of thing). (#19037)PyGitHubdependency in the release script and raise the dependency's minimum version to1.59.0. (#19039)ApplicationService). (#19040)v1.140.0Compare Source
Synapse 1.140.0 (2025-10-14)
Compatibility notice for users of
synapse-s3-storage-providerDeployments that make use of the synapse-s3-storage-provider module must upgrade to v1.6.0.
Using older versions of the module with this release of Synapse will prevent users from being able to upload or download media.
No significant changes since 1.140.0rc1.
Synapse 1.140.0rc1 (2025-10-10)
Features
the
origin/media_ididentifier found in a Matrix Content URI. (#18911)GET /_matrix/client/v1/rtc/transportsendpoint for the latest draft of MSC4143: MatrixRTC. (#18967)defer_to_threadpoolfunction in the Synapse Module API that allows modules to run a function on a separate thread in a custom threadpool. (#19032)Bugfixes
room_configargument and documentation foruser_may_create_roomspam-checker callback. (#18721)user_ips_max_age. (#18948)Improved Documentation
Deferredcallbacks interact with logcontexts. (#18914)rc_room_creationandrc_reportsto clarify that aper_userrate limit is not supported. (#18998)Deprecations and Removals
LoggingContext.set_current_context/LoggingContext.current_contextmethods which already have equivalent bare methods insynapse.logging.context. (#18989)Internal Changes
SynapseHomeServerobject, allowing artifacts of embedded small hosts to be properly garbage collected. (#18828)server_namein logging context for multiple Synapse instances in one process. (#18868)make_deferred_yieldableso it follows Synapse logcontext rules. (#18903)_get_e2e_cross_signing_signatures_for_devicesby increasing the batch size of devices the query is called with, reducing DB load. (#18939)no active span when trying to logtracing error on startup (when OpenTracing is enabled). (#18959)run_coroutine_in_background(...)incorrectly handling logcontext. (#18964)timeout_deferredtests. (#18974)ReplicationUploadKeysForUserRestServletas a follow-up to the work in #18581 that moved device changes off the main process. (#18988)MockClock()in tests. (#18992)LogContextScopeManagerinstead of OpenTracing'sContextVarsScopeManagerwhich was causing problems when using the experimentalSYNAPSE_ASYNC_IO_REACTORoption with tracing enabled. (#19007)version_stringargument fromHomeServersince it's always the same. (#19012)hs.start_background_tasks()introduced from a bad merge. (#19013)create_homeserver) and setup (setup). (#19015)macos-13GitHub Actions runner for themacos-15-intelvariant. (#19025)RootConfig.validate_config()which can be subclassed inHomeServerConfigto do cross-config class validation. (#19027)release.pyscript to accept a--gh-tokenargument. (#19035)Updates to locked dependencies
v1.139.2Compare Source
Synapse 1.139.2 (2025-10-07)
Bugfixes
device_keys: nullin the request toPOST /_matrix/client/v3/keys/upload. (#19023)v1.139.1Compare Source
Synapse 1.139.1 (2025-10-07)
Security Fixes
Deprecations and Removals
v1.139.0Compare Source
Synapse 1.139.0 (2025-09-30)
/registerrequests from old application service implementations may break when using MASIf you are using Matrix Authentication Service (MAS), as of this release any Application Services that do not set
inhibit_login=truewhen callingPOST /_matrix/client/v3/registerwill receive the errorIO.ELEMENT.MSC4190.M_APPSERVICE_LOGIN_UNSUPPORTEDin response.Please see the upgrade notes for more information.
No significant changes since 1.139.0rc3.
Synapse 1.139.0rc3 (2025-09-25)
Bugfixes
run_coroutine_in_background(...)incorrectly handled logcontexts, resulting in partially broken logging. (#18964)Synapse 1.139.0rc2 (2025-09-23)
Internal Changes
Synapse 1.139.0rc1 (2025-09-23)
Features
get_media_upload_limits_for_userandon_media_upload_limit_exceededmodule API callbacks to the media repository. (#18848)/sendendpoint. Contributed by @SpiritCroc @ Beeper. (#18898)_get_e2e_cross_signing_signatures_for_devicesto reduce DB load. (#18899)Bugfixes
/sendpass canonical JSON checks. (#18641)idpquery parameter. (#18909)Updates to the Docker image
SYNAPSE_LOG_TESTINGis set. (#18878)Improved Documentation
jwt_configparameter in OIDC documentation for authentik. Contributed by @maxkratz. (#18931)Deprecations and Removals
/sync/e2eeendpoint. (#18583)Internal Changes
LaterGaugemetrics to collect from all servers. (#18791)sentinellogcontext usage where we log insetup,startandexit. (#18870)Enum's value for the dictionary key when responding to an admin request for experimental features. (#18874)run_in_background(...)andrun_as_background_process(...). (#18900, #18906)sentinellogcontext usage inClockutilities likelooping_callandcall_later. (#18907)pkg_resourcesinterface in preparation of setuptools dropping it soon. (#18910)setup. (#18933)run_in_backgroundnot being awaited properly in some tests causingLoggingContextproblems. (#18937)run_as_background_processnot being awaited properly causingLoggingContextproblems in experimental MSC4140: Delayed events implementation. (#18938)Clock.call_when_running(...)to wrap startup code in a logcontext, ensuring we can identify which server generated the logs. (#18944)Clock.add_system_event_trigger(...)to wrap system event callback code in a logcontext, ensuring we can identify which server generated the logs. (#18945)Updates to locked dependencies
v1.138.4Compare Source
Synapse 1.138.4 (2025-10-07)
Bugfixes
device_keys: nullin the request toPOST /_matrix/client/v3/keys/upload. (#19023)v1.138.3Compare Source
Synapse 1.138.3 (2025-10-07)
Security Fixes
Deprecations and Removals
v1.138.2Compare Source
Synapse 1.138.2 (2025-09-24)
Internal Changes
Synapse 1.138.1 (2025-09-24)
Bugfixes
v1.138.1Compare Source
v1.138.0Compare Source
Synapse 1.138.0 (2025-09-09)
No significant changes since 1.138.0rc1.
Synapse 1.138.0rc1 (2025-09-02)
Features
Bugfixes
Improved Documentation
Internal Changes
_ByteProducerwith tracing to measure potential dead time while writing bytes to the request. (#18804)ContextVarsScopeManagerinstead of our own customLogContextScopeManager. (#18849)Producerto write bytes to the request. (#18855)EventPersistencePairtype. (#18857)Updates to locked dependencies
c0c5949to4515659. (#18863)b3b07batoe97e2d8. (#18862)v1.137.0Compare Source
Synapse 1.137.0 (2025-08-26)
No significant changes since 1.137.0rc1.
Synapse 1.137.0rc1 (2025-08-19)
Bugfixes
register_new_matrix_userutility script for emptyregistration_shared_secret. (#18780)Improved Documentation
denied-peer-ipsof coturn setup. Contributed by @litetex. (#18781)Internal Changes
encode_responsepart of Sliding Sync requests for more complete traces in Jaeger. (#18815)wait_for_events. (#18816)portdbCI by hardcoding the newpg_dumprestrict key that was added due to CVE-2025-8714. (#18824)Updates to locked dependencies
5b1a254to0c37450. (#18557)v1.136.0Compare Source
Synapse 1.136.0 (2025-08-12)
Note: This release includes the security fixes from
1.135.2and1.136.0rc2, detailed below.Please also check the relevant section in the upgrade notes for the changes to MAS support, metrics labels and the module API which may require your attention when upgrading.
Bugfixes
Synapse 1.136.0rc2 (2025-08-11)
This is the Synapse portion of the Matrix coordinated security release. This release includes support for room version 12 which fixes a number of security vulnerabilities, including CVE-2025-49090.
The default room version is not changed. Not all clients will support room version 12 immediately, and not all users will be using the latest version of their clients. Large, public rooms are advised to wait a few weeks before upgrading to room version 12 to allow users throughout the Matrix ecosystem to update their clients.
Note: release 1.135.1 was skipped due to issues discovered during the release process.
Two patched Synapse releases are now available:
1.135.2: stable release comprised of1.135.0+ security patches1.136.0rc2: unstable release candidate comprised of1.136.0rc1+ security patches.Bugfixes
Internal Changes
upgrade_rooms(..)to allow auto join local users. (#83)Synapse 1.136.0rc1 (2025-08-05)
Features
unsigned. (#18585)http_proxy,https_proxy,no_proxy_hosts. (#18686)/_matrix/clients/versionsif enabled. (#18722)Bugfixes
Improved Documentation
receiptsstream. (#18760)Deprecations and Removals
run_as_background_processexported as part of the module API interface in favor ofModuleApi.run_as_background_process. See the relevant section in the upgrade notes for more information. (#18737)Internal Changes
Counter,LaterGauge,GaugeBucketCollector,Histogram, andGaugemetrics to be homeserver-scoped. (#18656, #18714, #18715, #18724, #18753, #18725, #18670, #18748, #18751)twisted.internet.testingmodule in tests instead of deprecatedtwisted.test.proto_helpers. (#18728)/send_eventreplication endpoint. (#18730)twisted.protocols.amp.TooLongerror by reducing logging in some tests. (#18736)Clock.sleep(...)return a coroutine, so that mypy can catch places where we don't await on it. (#18772)Updates to locked dependencies
v1.135.2Compare Source
Synapse 1.135.2 (2025-08-11)
This is the Synapse portion of the Matrix coordinated security release. This release includes support for room version 12 which fixes a number of security vulnerabilities, including CVE-2025-49090.
The default room version is not changed. Not all clients will support room version 12 immediately, and not all users will be using the latest version of their clients. Large, public rooms are advised to wait a few weeks before upgrading to room version 12 to allow users throughout the Matrix ecosystem to update their clients.
Note: release 1.135.1 was skipped due to issues discovered during the release process.
Two patched Synapse releases are now available:
1.135.2: stable release comprised of1.135.0+ security patches1.136.0rc2: unstable release candidate comprised of1.136.0rc1+ security patches.Bugfixes
Internal Changes
upgrade_rooms(..)to allow auto join local users. (#82)v1.135.1Compare Source
v1.135.0Compare Source
Synapse 1.135.0 (2025-08-01)
No significant changes since 1.135.0rc2.
Synapse 1.135.0rc2 (2025-07-30)
Bugfixes
/_synapse/masis handled by a worker. (#18716)Internal Changes
is_server_admin. (#18747)Synapse 1.135.0rc1 (2025-07-22)
Features
recaptcha_private_key_pathandrecaptcha_public_key_pathconfig option. (#17984, #18684)event_idwhen getting state with?format=event. Contributed by @tulir @ Beeper. (#18675)Bugfixes
sliding_sync_connections-related errors when porting from SQLite to Postgres. (#18677)--daemonizeor usingsynctl. (#18691)Improved Documentation
rc_delayed_event_mgmtdocs to the actual nesting level. Contributed by @HarHarLinks. (#18692)Internal Changes
Measureblock metrics to be homeserver-scoped. (#18601)--without devpoetry option instead of removed--no-dev. (#18617)lxml6.0.0+. (#18622)markdown-it-pyinstead ofcommonmarkin the release script. (#18637)stream_positionstable. (#18672)allow_no_prev_eventsoption when creating an event. (#18676)MetricsResourceand Prometheus hacks. (#18687)Cargo.lockchanges appearing after install (base64). (#18689)Cargo.lockchanges from install. (#18693)Updates to locked dependencies
v1.134.0Compare Source
Synapse 1.134.0 (2025-07-15)
No significant changes since 1.134.0rc1.
Synapse 1.134.0rc1 (2025-07-09)
Features
viaquery param for hierarchy endpoint. Contributed by Krishan (@kfiven). (#18070)forget_forced_upon_leavecapability as per MSC4267. (#18196)federated_user_may_invitespam checker callback which receives the entire invite event. Contributed by @tulir @ Beeper. (#18241)Bugfixes
KeyErroron background updates when using split main/state databases. (#18509)avatar_urlanddisplaynamebeing sent on federation profile queries when they are not set. (#18593)M_USER_LOCKEDwhen a locked user callsPOST /login, as per the spec. (#18594)Improved Documentation
Deprecations and Removals
Internal Changes
PyICUcrate with equivalenticu_segmenterRust crate. (#18553, #18646)simple_upsert_many. (#18573)dtolnay/rust-toolchainGitHub Action tob3b07ba8b418998c39fb20f53e8b695cdcc8de1b. (#18596).zed/directory to.gitignore. (#18623)Updates to locked dependencies
v1.133.0Compare Source
Synapse 1.133.0 (2025-07-01)
Pre-built wheels are now built using the manylinux_2_28 base, which is expected to be compatible with distros using glibc 2.28 or later, including:
Previously, wheels were built using the manylinux2014 base, which was expected to be compatible with distros using glibc 2.17 or later.
Bugfixes
cibuildwheelto 3.0.0 to fix themanylinuxwheel builds. (#18615)Synapse 1.133.0rc1 (2025-06-24)
Features
Bugfixes
room_id_to_includeconfig option. (#18535)Improved Documentation
Internal Changes
flake8-loggingandflake8-logging-formatrules in Ruff and fix related issues throughout the codebase. (#18542)device_federation_inboxtable. (#18546)25.5.0+ releases. (#18577)Updates to locked dependencies
v1.132.0Compare Source
Synapse 1.132.0 (2025-06-17)
Improved Documentation
Synapse 1.132.0rc1 (2025-06-10)
Features
user_may_send_state_eventmodule API callback. (#18455)get_media_config_for_userandis_user_allowed_to_upload_media_of_sizemodule API callbacks that allow overriding of media repository maximum upload size. (#18457)get_ratelimit_override_for_usermodule API callback that allows overriding of per-user ratelimits. (#18458)room_configargument touser_may_create_roomspam checker module callback. (#18486)/_matrix/app/v1/pingwill now force Synapse to reattempt delivering transactions to appservices. (#18521)RatelimitOverridetype fromsynapse.module_apiin modules and renamemessages_per_secondtoper_second. (#18513)Bugfixes
Improved Documentation
CAP_NET_BIND_SERVICEas an alternative to running Synapse as root in order to bind to a privileged port. (#18408)Internal Changes
received_transactionsolder than 1 day, rather than 30 days. (#18310)v1.131.0Compare Source
Synapse 1.131.0 (2025-06-03)
No significant changes since 1.131.0rc1.
Synapse 1.131.0rc1 (2025-05-28)
Features
msc4263_limit_key_queries_to_users_who_share_roomsconfig option as per MSC4263. (#18180)_. Contributed by_(@hex5f). (#18262)Bugfixes
_maybe_retry_device_resyncentrance. (#18391)tests.handlers.test_worker_lock.WorkerLockTestCase.test_lock_contentiontest which could spuriously time out on RISC-V architectures due to performance differences. (#18430)Improved Documentation
room_list_publication_rulesdocs to consider defaults that changed in v1.126.0. Contributed by @HarHarLinks. (#18286)Internal Changes
_NotifierUserStream. (#18380)RootConfig/Config. (#18409)cibuildwheels config to avoid it being disabled on a future upgrade tocibuildwheelv3. (#18417)flush_buffer()for Pythonprint(...)output. (#18420)CREATE/DROP INDEXin a schema delta. (#18440)Updates to locked dependencies
v1.130.0Compare Source
Synapse 1.130.0 (2025-05-20)
Bugfixes
Synapse 1.130.0rc1 (2025-05-13)
Features
GET /_synapse/admin/v1/scheduled_tasksto fetch scheduled tasks. (#18214)user_directory.exclude_remote_userswhich, when enabled, excludes remote users from user directory search results. (#18300)GET /devices/on workers. (#18355)Bugfixes
Updates to the Docker image
configure_workers_and_start.py, use the same absolute path of Python in the interpreter shebang, and invoke child Python processes withsys.executable. (#18291)start_for_complement.sh, replace some external program calls with shell builtins. (#18293)Improved Documentation
pushconfig option. Contributed by @HarHarLinks. (#18320)/_matrix/federation/v1/versionto list of federation endpoints that can be handled by workers. (#18377)GET /_synapse/admin/v1/scheduled_tasksto fetch scheduled tasks. (#18384)Internal Changes
should_drop_federated_eventto federation invites. (#18330)/rooms/admin API to be run on workers. (#18360)at_hash(access token hash) field in OIDC ID Tokens if we don't end up actually using the OIDC Access Token. (#18374, #18385)Updates to locked dependencies
280af8ato5b1a254. (#18365)v1.129.0Compare Source
Synapse 1.129.0 (2025-05-06)
No significant changes since 1.129.0rc2.
Synapse 1.129.0rc2 (2025-04-30)
Synapse 1.129.0rc1 was never formally released due to regressions discovered during the release process. 1.129.0rc2 fixes those regressions by reverting the affected PRs.
Internal Changes
total_event_count,total_message_count, andtotal_e2ee_event_countfields to the homeserver usage statistics.", added in v1.129.0rc1. (#18373)Synapse 1.129.0rc1 (2025-04-15)
Features
passthrough_authorization_parametersin OIDC configuration to allow passing parameters to the authorization grant URL. (#18232)AddThis was reverted in 1.129.0rc2.total_event_count,total_message_count, andtotal_e2ee_event_countfields to the homeserver usage statistics. (#18260)Bugfixes
force_tracing_for_usersconfig when using delegated auth. (#18334)ExternalIDReuseexception after migrating to MAS on workers with a high traffic. (#18342)Updates to the Docker image
Internal Changes
v1.128.0Compare Source
Synapse 1.128.0 (2025-04-08)
No significant changes since 1.128.0rc1.
Synapse 1.128.0rc1 (2025-04-01)
Features
Bugfixes
Updates to the Docker image
:{arch}. (#18271)start_for_complement.sh(to be sent toconfigure_workers_and_start.py). (#18273)prefix-logscript in the workers image. (#18274)uv pipto installsupervisorin the worker image. (#18275)rsyncin a build layer. (#18287)Improved Documentation
Internal Changes
participanttoroom_membershipstable. (#18068)Updates to locked dependencies
f5473acto280af8a. (#18303)v1.127.1Compare Source
Synapse 1.127.1 (2025-03-26)
Security
v1.127.0Compare Source
Synapse 1.127.0 (2025-03-25)
No significant changes since 1.127.0rc1.
Synapse 1.127.0rc1 (2025-03-18)
Features
Improved Documentation
Internal Changes
SYNAPSE_USE_FROZEN_DICTSenvironment variable. (#18123)Updates to locked dependencies
v1.126.0Compare Source
Synapse 1.126.0 (2025-03-11)
No significant changes since 1.126.0rc3.
Synapse 1.126.0rc3 (2025-03-07)
Bugfixes
Synapse 1.126.0rc2 (2025-03-05)
Administrators using the Debian/Ubuntu packages from
packages.matrix.org, please check the relevant section in the upgrade notes as we have recently updated the expiry date on the repository's GPG signing key. The old version of the key will expire on2025-03-15.Internal Changes
Synapse 1.126.0rc1 (2025-03-04)
Synapse 1.126.0rc1 was not fully released due to an error in CI.
Features
form_secret_pathconfig option. (#18090)--no-secrets-in-configcommand line option. (#18092)id_token_signing_alg_values_supportedfor an OpenID identity provider. (#18177)worker_replication_secret_pathconfig option. (#18191)redirect_uriin the authorization and token requests against an OpenID identity provider. (#18197)Bugfixes
Updates to the Docker image
Improved Documentation
Deprecations and Removals
Updates to locked dependencies
v1.125.0Compare Source
Synapse 1.125.0 (2025-02-25)
No significant changes since 1.125.0rc1.
Synapse 1.125.0rc1 (2025-02-18)
Features
attribute_requirements. (#17949)admin_token_pathandclient_secret_pathfor MSC3861. (#18004)get_current_time_msec()method to the module API for sound time comparisons with Synapse. (#18144)Bugfixes
check_username_for_spamcallback. Broke in v1.122.0. (#18135)Updates to the Docker image
SYNAPSE_HTTP_PROXY/SYNAPSE_HTTPS_PROXY/SYNAPSE_NO_PROXYenvironment variables to pass through specifically to the Synapse process (instead of needing to applyhttp_proxy/https_proxy/no_proxyglobally). (#18158)Improved Documentation
daemonize,print_pidfile,user_agent_suffix,use_frozen_dicts,manhole). (#18122)burst_countfield an integer inrc_presenceconfig documentation example. (#18159)Internal Changes
DatabasePool.simple_select_one_txnto return non-Nonewhen theallow_noneparameter isFalse. (#17616)sincetoken to/syncAPI. (#18139)Updates to locked dependencies
v1.124.0Compare Source
Synapse 1.124.0 (2025-02-11)
No significant changes since 1.124.0rc3.
Synapse 1.124.0rc3 (2025-02-07)
Bugfixes
Synapse 1.124.0rc2 (2025-02-05)
Bugfixes
Synapse 1.124.0rc1 (2025-02-04)
Bugfixes
rc_presence.per_user. This prevents load from excessive presence updates sent by clients via sync api. Also rate limit/_matrix/client/v3/presenceas per the spec. Contributed by @rda0. (#18000)auto_accept_invitesis enabled. (#18073)docker-compose.ymlfile to PostgreSQL v15, as v12 is no longer supported by Synapse.Contributed by @maxkratz. (#18089)
blockparameter was set totrueand a worker other than the main process was configured to handle background tasks. (#18119)Internal Changes
nonceparameter when perfoming OIDC logins to comply with the TI-Messenger spec. (#18109)Updates to locked dependencies
v1.123.0Compare Source
Synapse 1.123.0 (2025-01-28)
No significant changes since 1.123.0rc1.
Synapse 1.123.0rc1 (2025-01-21)
Features
typeto the Room State Admin API that filters the state event. (#18035)/auth_metadataendpoint defined in MSC2965. (#18093)Bugfixes
Improved Documentation
tlsoption for a worker instance ininstance_map. (#18064)Deprecations and Removals
Internal Changes
rc_invites.per_issuer) for Complement. (#18072)Updates to locked dependencies
v1.122.0Compare Source
Synapse 1.122.0 (2025-01-14)
Please note that this version of Synapse drops support for PostgreSQL 11 and 12. The minimum version of PostgreSQL supported is now version 13.
No significant changes since 1.122.0rc1.
Synapse 1.122.0rc1 (2025-01-07)
Deprecations and Removals
Features
email.tlsnameconfig option. This allows specifying the domain name used to validate the SMTP server's TLS certificate separately from theemail.smtp_hostto connect to. (#17849)check_username_for_spamcallbacks tospam_checker_module_callbacks. Contributed by Wilson@Pangea.chat. (#17916)fetch the number of rooms the provided user has joined after a given timestamp, and get report IDs of event
reports against a provided user (i.e. where the user was the sender of the reported event). (#17948)
macaroon_secret_key_pathconfig option. (#17983)Bugfixes
third_party_rulesmodule, where the invite would be stuck for the client. (#17930)Improved Documentation
synapse.app.generic_workerdocumentation to only recommendGETrequests for stream writer routes by default, unless the worker is also configured as a stream writer. Contributed by @evoL. (#17954)last_seen_tsquery parameter to the query user Admin API. (#17976)TaskSchedulerclass. (#17992)Internal Changes
RoomID&EventIDrust types. (#17996)twisted.internet.defer.returnValue. Contributed by Colin Watson. (#18020)get_profileto no longer include fields with a value ofNone. (#18063)Updates to locked dependencies
Changelogs for older versions can be found here.
v1.121.1Compare Source
Synapse 1.121.1 (2024-12-11)
This release contains a fix for our docker build CI. It is functionally identical to 1.121.0, whose changelog is below.
Internal Changes
Synapse 1.121.0 (2024-12-11)
Internal Changes
Synapse 1.121.0rc1 (2024-12-04)
Features
$LAZY-loading room members. (#17947)M_USER_LOCKEDerror code for locked accounts, as per Matrix 1.12. (#17965)disable_badge_countto pusher configuration. (#17975)Bugfixes
Improved Documentation
Internal Changes
Content-Typeheader on thePUTresponse to work around a faulty behavior in some caching reverse proxies. (#17253)/_matrix/client/v3/login/sso/redirect(/{idpId}). (#17972)public_baseurl. (#17986)Updates to locked dependencies
v1.120.2Compare Source
Synapse 1.120.2 (2024-12-03)
This version has building of wheels for macOS disabled.
It is functionally identical to 1.120.1, which contains multiple security fixes.
If you are already using 1.120.1, there is no need to upgrade to this version.
Synapse 1.120.1 (2024-12-03)
This patch release fixes multiple security vulnerabilities, some affecting all prior versions of Synapse. Server administrators are encouraged to update Synapse as soon as possible. We are not aware of these vulnerabilities being exploited in the wild.
Administrators who are unable to update Synapse may use the workarounds described in the linked GitHub Security Advisory below.
Security advisory
The following issues are fixed in 1.120.1.
GHSA-rfq8-j7rh-8hf2 / CVE-2024-52805 (high): Unsupported content types can lead to memory exhaustion
Synapse instances which have a high
max_upload_sizeand which don't have a reverse proxy in front of them that would otherwise limit upload size are affected.Fixed by 4b7154c58501b4bf5e1c2d6c11ebef96529f2fdf.
GHSA-f3r3-h2mq-hx2h / CVE-2024-52815 (high): Malicious invites via federation can break a user's sync
Fixed by d82e1ed357b7ee21dff83d06cba7a67840cfd464.
GHSA-vp6v-whfm-rv3g / CVE-2024-53863 (high): Synapse can be forced to thumbnail unexpected file formats, invoking potentially untrustworthy decoders
Synapse instances can disable dynamic thumbnailing by setting
dynamic_thumbnailstofalsein the configuration file.Fixed by b64a4e5fbbbf119b6c65aedf0d999b4237d55503.
GHSA-56w4-5538-8v8h / CVE-2024-53867 (moderate): The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room
Non-state events, like messages, are unaffected.
Synapse instances can disable the Sliding Sync feature by setting
experimental_features.msc3575_enabledtofalsein the configuration file.Fixed by 4daa533e82f345ce87b9495d31781af570ba3ead.
Additionally, we disclose the following vulnerabilities, both have been fixed in Synapse 1.106.0:
GHSA-4mhg-xv73-xq2x / CVE-2024-37302 (high): Denial of service through media disk space consumption
GHSA-gjgr-7834-rhxr / CVE-2024-37303 (moderate): Unauthenticated writes to the media repository allow planting of problematic content
See the advisories for more details. If you have any questions, email security at element.io.
Bug fixes
v1.120.1Compare Source
v1.120.0Compare Source
Synapse 1.120.0 (2024-11-26)
This release enables the enforcement of authenticated media by default, with exemptions for media that is already present in the
homeserver's media store.
Most homeservers operating in the public federation will not be impacted by this change, given that
the large homeserver
matrix.orgenabled this in September 2024 and therefore most clients and serverswill already have updated as a result.
Some server administrators may still wish to disable this enforcement for the time being, in the interest of compatibility with older clients
and older federated homeservers.
See the upgrade notes for more information.
Bugfixes
delete_old_otksjob to fail in worker-mode deployments. (#17960)Synapse 1.120.0rc1 (2024-11-20)
Features
enable_authenticated_mediatofalse. In a future release of Synapse, this option will be removed and become always-on. (#17889)Improved Documentation
enable_authenticated_mediaconfiguration option. (#17913)Deprecations and Removals
Internal Changes
python-multipart0.0.13 so that distro packagers do not need to work around name conflict with PyPI packagemultipart. (#17932)Updates to locked dependencies
v1.119.0Compare Source
Synapse 1.119.0 (2024-11-13)
No significant changes since 1.119.0rc2.
Python 3.8 support dropped
Python 3.8 is end-of-life and is no longer supported by Synapse. The minimum supported Python version is now 3.9.
If you are running Synapse with Python 3.8, please upgrade to Python 3.9 (or greater) before upgrading Synapse.
Synapse 1.119.0rc2 (2024-11-11)
Note that due to packaging issues there was no v1.119.0rc1.
Features
state_afterto sync v2). (#17888)Bugfixes
$LAZY-loading room members would not returnrequired_statemembership in incremental syncs. (#17809)the config option
run_background_tasks_on. (#17847)state_afterto sync v2) where we would return the full state on incremental syncs when using lazy loaded members and there were no new events in the timeline. (#17915)Internal Changes
Generatorusage. (#17813, #17814, #17815, #17816, #17817, #17818, #17890)current_state_delta_streamtable. (#17912)Updates to locked dependencies
v1.118.0Compare Source
Synapse 1.118.0 (2024-10-29)
No significant changes since 1.118.0rc1.
Python 3.8 support will be dropped in the next release
Python 3.8 is now end-of-life. As per our Deprecation Policy for Platform Dependencies, Synapse will be dropping support for Python 3.8 in the next release; Synapse 1.119.0.
Synapse 1.118.x will be the final release to support Python 3.8. If you are running Synapse with Python 3.8, please upgrade before the 1.119.0 release, due in less than one month.
Python 3.13 and PostgreSQL 17 support
On the other end of the spectrum, Synapse 1.118.0 is the first release to support Python 3.13! PostgreSQL 17 is also supported as of this release.
Synapse 1.118.0rc1 (2024-10-22)
Features
display_name_claimoption to the JWT configuration. This option allows specifying the claim key that contains the user's display name in the JWT payload. (#17708)Bugfixes
required_stateconfig. (#17785, #17805)Improved Documentation
user_may_inviteanduser_may_send_3pid_invitemodule callbacks are called. (#17627)--config-pathargument instead of--config-file. (#17802)target_cache_memory_usagedocs. (#17825)Internal Changes
.org.matrix.msc4028.encrypted_eventpush rule by default in accordance with MSC4028. Note that the corresponding experimental feature must still be switched on for this push rule to have any effect. (#17826)Updates to locked dependencies
v1.117.0Compare Source
Synapse 1.117.0 (2024-10-15)
No significant changes since 1.117.0rc1.
Synapse 1.117.0rc1 (2024-10-08)
Features
redis.password_path. (#17717)Bugfixes
GET /_matrix/client/versions, set theunstable_featuresflag for MSC4140 tofalsewhen server configuration disables support for delayed events. (#17780)Improved Documentation
test_forget_when_not_left. (#17628)federation_sender_instances. (#17776)Internal Changes
Updates to locked dependencies
v1.116.0Compare Source
Synapse 1.116.0 (2024-10-01)
No significant changes since 1.116.0rc2.
Synapse 1.116.0rc2 (2024-09-26)
Features
Synapse 1.116.0rc1 (2024-09-25)
Features
and an endpoint to check on the status of that redaction task. (#17506)
tagsandnot_tagsfilters for MSC4186 Sliding Sync. (#17662)turn_shared_secret_path. (#17690)Bugfixes
Internal Changes
_pydantic_compatmodule.This allows
check_pydantic_models.pyto mock those pydantic objectsonly in the synapse module, and not interfere with pydantic objects in
external dependencies. (#17667)
event_stream_orderingof rooms. (#17693)bump_stamps more efficiently in MSC4186 Sliding Sync. (#17723)_bulk_get_max_event_posbeing inefficient. (#17728)get_tags_for_room(...). (#17730)cgimodule, deprecated in Python 3.11 and removed in Python 3.13. (#17741)Unknownanymore after updatingtreq. (#17744)Updates to locked dependencies
v1.115.0Compare Source
Synapse 1.115.0 (2024-09-17)
No significant changes since 1.115.0rc2.
Synapse 1.115.0rc2 (2024-09-12)
Internal Changes
/syncendpoint for quick filtering/sorting. (#17652)Synapse 1.115.0rc1 (2024-09-10)
Features
Bugfixes
400 M_BAD_JSONupon attempting to complete various room actions with a non-local user ID and unknown room ID, rather than an internal server error. (#17607)bump_stampfor invites in sliding sync response, causing incorrect ordering of invites in the room list. (#17674)Improved Documentation
saml2_configconfig example. (#17594)Deprecations and Removals
msc4156_enabledconfig setting and defaulting it totrue. (#17650)Internal Changes
/syncendpoint for quick filtering/sorting. (#17512, #17632, #17633, #17634, #17635, #17636, #17641, #17654, #17673)PerConnectionStateclass immutable. (#17600)isortandblackwithruff. (#17620, #17643)get_room_membership_for_user_at_to_token. (#17629)bump_stampfrom new sliding sync tables which should be faster. (#17658)Updates to locked dependencies
v1.114.0Compare Source
Synapse 1.114.0 (2024-09-02)
This release enables support for MSC4186 — Simplified Sliding Sync. This allows using the upcoming releases of the Element X mobile apps without having to run a Sliding Sync Proxy.
Features
Synapse 1.114.0rc3 (2024-08-30)
Bugfixes
Synapse 1.114.0rc2 (2024-08-30)
Features
hash_passwordscript accept password input from stdin. (#17608)Bugfixes
/thumbnailresponses. (#17532)Internal Changes
PerConnectionStateclass immutable. (#17600)@tag_argsfor standalone functions. (#17604)isortandblackwithruff. (#17620)Updates to locked dependencies
Synapse 1.114.0rc1 (2024-08-20)
Features
/versions,org.matrix.simplified_msc3575, to indicate whether experimental sliding sync support has been enabled. (#17571)timeline_limitin experimental sliding sync. (#17579)Bugfixes
stream_orderinginstead of topological ordering) in experimental MSC3575 Sliding Sync/syncendpoint. (#17510)/syncendpoint. (#17538)_Mulitpart_Parser_Protocol. (#17545)old_verify_keys. Contributed by @tulir @ Beeper. (#17568)Improved Documentation
auto_accept_invites.worker_to_run_onoption. (#17515)
Internal Changes
/syncendpoint. (#17514)HTTPAdapter.get_connectionwithget_connection_with_tls_context. (#17536)/key/changesand sliding sync. (#17537, #17548)Updates to locked dependencies
v1.113.0Compare Source
Synapse 1.113.0 (2024-08-13)
No significant changes since 1.113.0rc1.
Synapse 1.113.0rc1 (2024-08-06)
Features
/syncendpoint. (#17447)/syncendpoint. (#17477)/syncendpoint. (#17489)/syncendpoint. (#17505)Bugfixes
/syncendpoint to handle invite/knock rooms when filtering. (#17450)/keys/queryto return incomplete results, leading to high network activity and CPU usage on Matrix clients. (#17499)Improved Documentation
allowed_local_3pidsconfig option's msisdn address to a working example. (#17476)Internal Changes
bump_stampin experimental sliding sync endpoint. (#17478)SlidingSyncBase. (#17481, #17482)limitedfield description in the Sliding Sync response to accurately describe what it actually represents. (#17507)timelineassertions in Sliding Sync tests. (#17511)Updates to locked dependencies
v1.112.0Compare Source
Synapse 1.112.0 (2024-07-30)
This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.
Note that this security fix is also available as Synapse 1.111.1, which does not include the rest of the changes in Synapse 1.112.0.
This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.
With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.
Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.
pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using
pip install Twisted==24.7.0rc1. Note also that even the--upgrade-strategy=eagerflag topip install -U matrix-synapsewill not upgrade Twisted to a patched version because it is only a release candidate at this time.Internal Changes
Synapse 1.112.0rc1 (2024-07-23)
Please note that this release candidate does not include the security dependency update
included in version 1.111.1 as this version was released before 1.111.1.
The same security fix can be found in the full release of 1.112.0.
Features
/syncendpoint. (#17416)name/avatarfields in experimental MSC3575 Sliding Sync/syncendpoint. (#17418)heroesand room summary fields (joined_count,invited_count) in experimental MSC3575 Sliding Sync/syncendpoint. (#17419)is_dmroom field in experimental MSC3575 Sliding Sync/syncendpoint. (#17429)/syncendpoint. (#17432)/syncendpoint. (#17454)Bugfixes
/syncendpoint when using room type filters and the user has one or more remote invites. (#17434)heroesbystream_orderingas the Matrix specification states (applies to/sync). (#17435)/syncwould break for a user when using workers with multiple stream writers. (#17438)Improved Documentation
default_power_level_content_overrideconfig option. (#17451)Internal Changes
RateLimiter.record_action. (#17426)/syncendpoint to bump room when it is created. (#17453)get_rooms_for_local_user_where_membership_isto speed up sliding sync. (#17460)$MEas a state key in sliding sync. (#17469)Updates to locked dependencies
v1.111.1Compare Source
Synapse 1.111.1 (2024-07-30)
This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.
This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.
With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.
Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.
pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using
pip install Twisted==24.7.0rc1. Note also that even the--upgrade-strategy=eagerflag topip install -U matrix-synapsewill not upgrade Twisted to a patched version because it is only a release candidate at this time.Internal Changes
markdownlint/markdownlint (markdownlint/markdownlint)
v0.18.1Compare Source
Fixed
#606
v0.18.0Compare Source
Added
allow_quotedoption.#594
parse_block_html,parse_span_html,html_to_native#568
#590
front_matter_titleparameter for all header-related rules#570
Fixed
allow_different_nestingwas set#593
-g#591
Changed
treat_links_as_single_wordsis set, also allowlink references to be on a single line regardless of length
#597
v0.17.0Compare Source
Added
treat_links_as_single_wordoption to MD013#580
Fixed
#580
#580
#580
v0.16.0Compare Source
Added
#519
Changed
#516
#539
#551
#554
#556
#557
#561
#569
Fixed
#539
#539
#541
#542
#543
#543
#545
#546
#547
#548
#549
#550
#552
#553
#555
#558
#560
#562
#564
#565
#566
#563
#572
v0.15.0Compare Source
Changed
#531, and associated
changes
v0.14.0Compare Source
Fixed
#469
#473
#528
Rules Removed
were removed (see
#472 for details)
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.
bc3771729e0f08efbbcdRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.112.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.113.00f08efbbcd5a102dddc7Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.113.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.114.05a102dddc77509412bacRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.114.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.115.07509412bac457cc9adeeRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.115.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.116.0457cc9adee04d06dad3cRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.116.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.117.004d06dad3c55bb3982c7Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.117.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.118.055bb3982c7to6c793a548eRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.118.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.119.06c793a548etoc037ae5ab0Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.119.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.0c037ae5ab0to2169092f56Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.22169092f56toa33993660dRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.120.2to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.121.1a33993660dto651bac3071Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.121.1to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.122.0651bac3071to7f70fa5268Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.122.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.123.07f70fa5268to65fc0c0daaRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.123.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.124.065fc0c0daatofa1d7c5a33Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.124.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.125.0fa1d7c5a33todfaa0714f6Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.125.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.126.0dfaa0714f6to2837bae2a0Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.126.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.02837bae2a0to3d4b283665Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.13d4b283665toa7e227461bRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.127.1to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.128.0a7e227461bto76d6dcdc19Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.128.0to Renovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.129.076d6dcdc19to79431dc14aRenovate: Update docker.io/matrixdotorg/synapse Docker tag to v1.129.0to Renovate: Update all non-major dependencies79431dc14ato2de302022e2de302022etoeb2d26b28beb2d26b28btod21a9f51d0d21a9f51d0to810670dc25810670dc25toff10a4c858ff10a4c858to7102db27c77102db27c7to7ec4fc57967ec4fc5796to6ec7d8ec046ec7d8ec04tob34af1c76eb34af1c76etoc7a2597eeac7a2597eeatof56bac66e8f56bac66e8to084bb00cb6084bb00cb6to84b603631184b6036311to9b5c61a0a59b5c61a0a5to2469cd1de82469cd1de8to42f41a102142f41a1021toab45b858deab45b858detofb2af66298fb2af66298to39f5358ae739f5358ae7tofe7b832865fe7b832865toeaf5b59fe7eaf5b59fe7to4f3528fe334f3528fe33to01338193400133819340to2ca56bf4d02ca56bf4d0to38d240cb1138d240cb11to63c72e6a7a63c72e6a7ato2be5336b1c2be5336b1cto7f0135ef577f0135ef57tocc1f48e151cc1f48e151tod2b961eec1d2b961eec1to5c1958f0b55c1958f0b5to8c53f874288c53f87428to9c8248965a9c8248965atoe796c50ba0e796c50ba0to9bc2ea64409bc2ea6440tocba293cf6acba293cf6ato981013a947981013a947toa886729a30a886729a30to0a57ad5f160a57ad5f16to1270468d041270468d04to6c312324b16c312324b1tof4102f454cf4102f454ctof60123707bf60123707bto81da02d04381da02d043tob2fb683c88b2fb683c88to1121a8aea11121a8aea1to19adfa8cfb19adfa8cfbtoe58152bce8e58152bce8to021974f05c021974f05ctodef9f406c0def9f406c0to5cb0619d3d5cb0619d3dto89760d836dView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.