aboutsummaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2026-07-17Merge pull request #17334 from nyanmisaka/fix-cuda-hwuploadBond-009
Fix format negotiation in hybrid SW decode and CUDA tonemap pipeline
2026-07-17Merge pull request #17151 from theguymadmax/fix-indentify-imageBond-009
Fix Identify returning wrong images
2026-07-17Merge pull request #17326 from theguymadmax/update-series-nameBond-009
Update season and episode SeriesName when renaming a series
2026-07-17Merge pull request #17280 from Shadowghost/remove-image-override-hackBond-009
Remove episode image override hack
2026-07-17Merge pull request #17191 from IDisposable/fix/handler-path-traversalBond-009
Fix path transversal exposure in Plugins
2026-07-17Added verbose, rambling, log warning to help users with config issues ↵WizardOfYendor1
(hoping to reduce false issues reports). Also added a test to exercise it, which is perhaps silly but convenient.
2026-07-17Append base URL if the published server URL override omits it. Fleshed out ↵WizardOfYendor1
unit tests to cover that and https->http reverse proxy scenario(s).
2026-07-17fix: don't throw ArgumentNullException on partial UpdateItem payloads (#17366)zerafachris
BaseItemDto.Genres, .Tags, and .ProviderIds are plain auto-properties with no default initializer, so they deserialize to null when a client omits them from a partial POST /Items/{itemId} body. The OpenAPI spec documents every BaseItemDto field as optional, but ItemUpdateController.UpdateItem fed these three properties straight into Distinct()/Select()/ToList() without a null check, so a request that (for example) only sets Tags throws ArgumentNullException("source") once it reaches the unguarded Genres line, before Tags is even processed. Guard all three assignments with the same "if (request.X is not null)" pattern already used for the neighboring Studios/Taglines/ProductionLocations fields in this method, so omitted fields are left unchanged instead of crashing the request. Adds ItemUpdateControllerTests covering the reported repro (only Tags supplied) and a companion case asserting existing Genres/ProviderIds are preserved when omitted from the payload. Signed-off-by: zerafachris <christopher.zerafa@blocklabs.io>
2026-07-17Prevent unauthenticated re-run of the startup wizard on misconfigurationShadowghost
2026-07-17Harden remaining path-construction sinks against traversalShadowghost
2026-07-17Sanitize media attachment and lyric paths against traversalShadowghost
2026-07-17Sanitize ClientLog upload filename to prevent path traversalShadowghost
2026-07-17Skip corrupt KeyframeData rows during full system backupzerafachris
A single row with malformed KeyframeTicks JSON (e.g. a truncated array from an interrupted write) currently aborts the entire backup, because the try/catch in BackupService.CreateBackupAsync only wraps serialization of an already-materialized entity, not the enumeration itself. EF Core throws JsonReaderException from MoveNextAsync() while materializing the corrupt row, which propagates past that catch block. Switch to manual enumerator iteration so MoveNextAsync() failures can be caught per-row, logged as a warning identifying the affected table, and skipped, allowing the remaining rows and the rest of the backup to complete. Fixes #17216 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-17Merge pull request #17354 from jellyfin/renovate/actions-setup-dotnet-6.xBond-009
2026-07-17Merge pull request #17359 from jellyfin/renovate/ci-depsBond-009
2026-07-17Merge pull request #17348 from ↵Bond-009
theguymadmax/revert-includeItemTypes-in-collectionType
2026-07-17Merge pull request #17343 from mbastian77/docs/channels-xml-docsBond-009
2026-07-17Merge pull request #17344 from mbastian77/docs/session-model-xml-docsBond-009
2026-07-17Merge pull request #17340 from mbastian77/docs/dlna-model-xml-docsBond-009
2026-07-17Merge pull request #17339 from mbastian77/docs/providers-lookup-info-xml-docsBond-009
2026-07-17Merge pull request #17338 from mbastian77/docs/deviceid-xml-docsBond-009
2026-07-17Translated using Weblate (Spanish (Latin America))Fabián Sanhueza
Translation: Jellyfin/Jellyfin Translate-URL: https://translate.jellyfin.org/projects/jellyfin/jellyfin-core/es_419/
2026-07-17Merge pull request #17337 from Shadowghost/limit-similar-itemsBond-009
2026-07-16Revert setting default BaseItemKind for CollectionTypetheguymadmax
2026-07-16Reduce cognitive complexity of RemoveFromPlaylistEnea D'Angiò
2026-07-16Update github/codeql-action action to v4.37.1renovate[bot]
2026-07-16Fix user data batch query perfShadowghost
2026-07-16Fix tie-breaker performanceShadowghost
2026-07-16Update actions/setup-dotnet action to v6renovate[bot]
2026-07-15Move GetUserDataBatch to use ResolveUserDataRow when item.UserData isn't ↵Jordan Rushing
preloaded
2026-07-15Fix SchedulesDirect image limit recognitionShadowghost
2026-07-15Add XML docs to small entity interfaces and remove CS1591 suppressionsmbastian77
2026-07-15Add XML docs to small session model types and remove CS1591 suppressionsmbastian77
2026-07-15Add XML docs to small channel types and remove CS1591 suppressionsmbastian77
2026-07-15Fix race condition in concurrent subtitle conversionPiotr Niełacny
SubtitleEncoder.ConvertSubtitles parsed subtitles with libse's static Subtitle.Parse, which iterates a statically cached list of shared SubtitleFormat instances. Format parsers keep mutable per-parse state on the instance, so concurrent subtitle requests corrupted each other's output (cues mixed across streams and languages, truncated files) or failed with NullReferenceException when format detection broke down and Subtitle.Parse returned null. Parse through the injected ISubtitleParser instead. SubtitleEditParser instantiates a fresh format parser per call, so requests no longer share state. Its Parse method now returns the libse Subtitle directly (the SubtitleTrackInfo flattening was unused since the SubtitleEdit writer rework) so the writers keep full fidelity such as ASS styling.
2026-07-15Merge pull request #17331 from jellyfin/renovate/dotnet-monorepoBond-009
2026-07-15Merge pull request #17274 from theguymadmax/fix-max-login-attemptsBond-009
2026-07-15Merge pull request #17248 from theguymadmax/add-novelBond-009
2026-07-15Add XML docs to small DLNA model types and remove CS1591 suppressionsmbastian77
2026-07-15Add XML docs to lookup info types and remove CS1591 suppressionsmbastian77
2026-07-15Add XML docs to DeviceId and remove CS1591 suppressionmbastian77
2026-07-15Limit similar items to user accessible librariesShadowghost
2026-07-15Merge pull request #17330 from jellyfin/renovate/microsoftBond-009
2026-07-15Merge pull request #17250 from ↵Bond-009
TaterTechStudios/feature/books-series-name-metadata
2026-07-15Fix format negotiation in hybrid SW decode and CUDA tonemap pipelinenyanmisaka
The CUDA hwcontext in FFmpeg 8.1 has added support for 10bit fully-planar formats, but few CUDA filters support them. Signed-off-by: nyanmisaka <nst799610810@gmail.com>
2026-07-14Update Microsoftrenovate[bot]
2026-07-14Update dependency dotnet-ef to v10.0.10renovate[bot]
2026-07-14Merge pull request #17266 from Shadowghost/fix-non-admin-additional-partsBond-009
2026-07-14remove PlaybackPositionTicks from MediaSourceInfoShadowghost
2026-07-13Update season and episode SeriesName when renaming a seriestheguymadmax