Repository navigation
Releases: unopim/unopim
Release list
v3.1.3
What's Changed
Improvements
- "Select all matching" now covers every matching record. The old cap was 10,000. Works with Elasticsearch on or off.
- Product status update and delete on large selections now run on the queue in chunks of 100. The admin who started the action gets a notification when it finishes.
- "Select all matching" now also works for mass actions on attributes, association types, category fields, currencies, locales, completeness settings, measurement families, product passports and webhooks.
- New ProductType and VariantLevel enums. The old string constants still work.
- The AI chat import confirmation now links to the job tracker.
Bug fixes
- Datagrid no longer gets stuck on a loading shimmer or shows an empty error after a mass action.
- Agentic PIM product updates that include a translation no longer fail with "Unknown column 'name'".
- Magic AI translation no longer wraps plain-text fields in HTML tags. Only WYSIWYG fields keep HTML.
- AI chat reloads the edit page only when a reply actually changed data.
- AI chat images are now kept per admin and per conversation. They expire after 10 minutes, so old uploads no longer get attached to new messages.
- If the model can't read images, the chat now says so instead of blocking every message after it.
- Uploading an oversized image in the chat now shows the server's upload limit.
Full Changelog: v3.1.2...v3.1.3
v3.1.2
What's Changed
A patch release for the 3.1 line, focused on Magic AI, with security hardening and admin fixes. Upgrading is recommended for all 3.1.x installations.
Security
- Pinned OpenAI, Anthropic and Gemini model discovery to the validated address with redirects barred, closing an SSRF path (#719).
- Stopped database failures leaking the host, schema and SQL into the AI chat window (#719).
- Validated the channel, locale and resource on the AI generation endpoints (#719).
Improvements
- Manage Magic AI platforms from the server with
unopim:magic-ai:platform:list|add|edit|delete|default, including managed platforms that are locked in the admin panel (#723). - New "Maximum Output Tokens" setting; the default ceiling rises from 1024 to 4096, and truncated output is reported instead of returned half-finished (#719).
- Model discovery uses the platform's own base URL and pre-selects the newest PIM-capable models (#719, #724).
- Added Concentrate AI; Azure platforms use the configured deployment name (#719).
- Reworked the product translation dialog (#719).
- Export profile pages expose view events for extra filters (#717, #718).
Bug fixes
- Content generation no longer fails on Claude Opus/Sonnet 4.7+ and Claude 5, which reject
temperature(#728). - Attribute codes starting with a digit or containing a hyphen or space no longer break MySQL JSON queries (#719).
- AI translation saves each value to the scope its attribute uses (#719).
- Clearing a channel name works on PostgreSQL (#725).
- The queue worker no longer kills an in-process
unopim:queue:workafter the queue drains (#713, #722). - Admin fixes: AI translate toggle saving, gallery unsaved badge, import filter values, price input layout, confirmation dialog layering (#713, #719, #720, #726, #727, #733).
Upgrade notes
Includes three migrations; run php artisan migrate --force as part of the standard upgrade in UPGRADE.md.
See CHANGELOG.md for full details.
Full Changelog: v3.1.1...v3.1.2
v3.1.1
What's Changed
A patch release for the 3.1 line, focused on security hardening, export correctness, and admin interface fixes. Upgrading is recommended for all 3.1.x installations.
Highlights
- Security - closed a privilege-escalation path in role management and two SSRF paths in Magic AI provider configuration, and extended the upload active-content scan from PDF to Office and RTF documents.
- Exports - a product export now writes only the attributes the profile selected, and category filters match codes exactly regardless of letter case.
- Media - replacing a media value on a product or category no longer discards the newly uploaded file, and rejected uploads are reported the moment a file is picked.
- Admin - fixes to the unsaved-changes bar, datagrid toolbar and media upload layouts, gallery previews, and the tags field.
- Platform - AI Agent now runs on Gemini models, the Elasticsearch mapped field limit is configurable, and concurrent boots no longer race on the HTMLPurifier cache directory.
Security
- Fixed a role holding
settings.roles.editbeing able to grant itself permissions its own role does not carry - a vertical privilege escalation. Role create and update now reject any permission the acting administrator does not already hold (#689). - Fixed Magic AI model discovery validating the provider URL and then fetching it with a client that follows redirects and re-resolves DNS, so a validated public URL could pivot to an internal host. The fetch is now pinned to the validated address and does not follow redirects (#690).
- Fixed the Magic AI connection test merging the unvalidated
extraspayload over the provider overrides, soextras.urlreplaced the validated endpoint and reached internal hosts with the response returned verbatim. Extras can no longer override keys the platform record owns, which also neutralises rows saved before the guard existed (#691). - Extended the upload active-content scan from PDF to Office documents:
.docx/.pptxpackages shipping a VBA project, legacy.doc/.pptfiles carrying a VBA stream, and RTF documents with auto-updating embedded objects are now rejected at save time, with the reason reported in the validation message (#694).
Bug fixes
- Added a pick-time scan to the media widgets (files, gallery, image) so a rejected upload is reported as soon as it is chosen, before the form is submitted (#694).
- Fixed the SKU field rejecting valid values containing characters other than letters, numbers, hyphens and underscores (such as
%). A SKU is now only rejected for being blank, over 255 characters, padded with leading or trailing spaces, or containing a comma or semicolon, which break CSV import/export (#708). - Fixed the product-edit category tree and the datagrid category filter requiring every subcategory to be ticked individually. Clicking a category's folder icon now selects or deselects it together with every descendant in one action, resolved through a single nested-set query regardless of branch depth (#707).
- Fixed a product export writing a column for every attribute in the installation instead of only the ones the profile selected (#697).
- Fixed a product export filtered on a category code containing an uppercase letter matching nothing and completing with an empty file and a "0 records" summary (#698).
- Fixed replacing a media value on a product or category discarding the newly uploaded file (#709).
- Fixed the AI Agent being unable to run on Gemini models, which have their own chat completions endpoint (#699).
- Fixed channel deletion failing to complete (#688).
- Fixed concurrent boots on a cold
storage/aborting when two processes created the HTMLPurifier cache directory at once - CI static analysis workers, Octane workers and parallel test runs all raced the same check, and the loser's warning was promoted to an exception that killed the process before the application finished booting (#675). - Fixed the unsaved-changes bar closing when an edit landed before the form re-baselined, which happened with rich-text fields because their edits reach the tracker from inside an...
v3.1.0
What's Changed
This release improves scalability, database support, API capabilities, and overall export/import reliability.
Highlights
- Added first-class MariaDB support, including installation, upgrades, migrations, audit logs, and REST API compatibility.
- Added REST APIs for association types, variant structures, and variant groups.
- Improved catalog performance for large product volumes with parallel Elasticsearch indexing, stable keyset reindexing, and faster dashboard statistics.
- Added secure authenticated media downloads from the admin panel.
- Improved Docker reliability by fixing queue/scheduler permissions and preserving OAuth signing keys during upgrades.
- Fixed product variants, bulk edit, webhooks, imports/exports, media handling, REST API responses, and permission-related issues.
- Improved export reliability by reporting skipped records with clear reasons instead of failing the entire batch.
New Contributors
Full Changelog: v3.0.0...v3.1.0
v3.0.0
UnoPim 3.0.0 — Major Release
UnoPim 3.0.0 is here — our biggest release yet.
Highlights:
- SPA-style AJAX navigation
- Digital Product Passports
- Advanced two-level product variants
- Measurement module
- Configurable product associations
- Multi-webhook support
- Microsoft SSO
- Major performance and security improvements
- Laravel 13 and PHP 8.4+
- Improved PostgreSQL and Docker support
A major step forward for modern, scalable, open-source Product Information Management.
Release date: July 31, 2026
What's Changed
Pasted_text_cleaned.txt
- fix(installer): preserve user locales/currencies during demo seed
- fix(installer): public/ now redirects to install.php on fresh checkout
- fix(magic-ai): drop
-- ... --wrapper from dropdown placeholders - fix(admin): hide product edit More button when no actions are available
- fix(datagrid): exclude hidden filterable attributes from Manage Columns selected panel
- fix(webhook): validate URL on save + rename menu to "Webhook"
- Add Gravatar fallback for admin avatars
- fix: strip HTML from datagrid cell title tooltip
- Add Playwright REST API test suite and CI improvements
- Update code for chat-latest model temperature not supported
- Fix/installer csrf on db retry
- fix(webhook): logs grid search placeholder reflects SKU/user
- Fix/docker multi arch publish master
- Fix/installer trim whitespace db inputs
- fix: demo extras seed completes on PostgreSQL
- fix(api): configurable POST creates the variants it receives
- fix: handle MethodNotAllowedHttpException with styled 405 page
- fix: reject special characters in DB_DATABASE to prevent reinstall fa…
- Add Microsoft SSO for admin login (email match only)
- chore(deps-e2e)(deps-dev): Bump @playwright/test from 1.52.0 to 1.60.0 in /tests/e2e-pw in the playwright group by @dependabot[bot] in #428
- chore(deps)(deps): Bump shetabit/visitor from 4.5.3 to 4.5.6 by @dependabot[bot] in #437
- chore(deps)(deps): Bump astrotomic/laravel-translatable from 11.16.1 to 11.17.0 by @dependabot[bot] in #438
- chore(deps)(deps): Bump diglactic/laravel-breadcrumbs from 10.0.0 to 10.1.0 by @dependabot[bot] in #442
- chore(deps)(deps): Bump maatwebsite/excel from 3.1.68 to 3.1.69 by @dependabot[bot] in #443
- Feat/currency export import
- chore(ci)(deps): Bump docker/build-push-action from 6 to 7 by @dependabot[bot] in #429
- chore(ci)(deps): Bump actions/upload-artifact from 5 to 7 by @dependabot[bot] in #431
- chore(ci)(deps): Bump peter-evans/dockerhub-description from 4 to 5 by @dependabot[bot] in #432
- chore(ci)(deps): Bump docker/setup-buildx-action from 3 to 4 by @dependabot[bot] in #433
- chore(ci)(deps): Bump docker/setup-qemu-action from 3 to 4 by @dependabot[bot] in #434
- chore(deps)(deps-dev): Bump the dev-dependencies group with 3 updates by @dependabot[bot] in #436
- chore(deps-e2e)(deps-dev): Bump @types/node from 22.19.19 to 25.9.1 in /tests/e2e-pw by @dependabot[bot] in #430
- chore(deps)(deps): Bump pusher/pusher-php-server from 7.2.7 to 7.2.8 by @dependabot[bot] in #441
- chore(deps)(deps): Bump prettus/l5-repository from 2.10.1 to 3.0.1 by @dependabot[bot] in #439
- chore(deps)(deps): Bump predis/predis from 2.4.1 to 3.4.2 by @dependabot[bot] in #440
- chore(deps)(deps): Bump intervention/image from 3.11.7 to 4.1.2 by @dependabot[bot] in #444
- Add admin dark mode with manual toggle and browser auto mode
- chore(deps)(deps): Bump the laravel group across 1 directory with 7 updates by @dependabot[bot] in #435
- Roles & User Import-Export Functionality.
- Channel export import functionality
- fix(webhook): coerce status filter to array and drop unused error placeholder
- chore(webhook): harden webhook URL validation and dispatch [Master]
- feat(app-url-guard): add APP_URL mismatch developer guard package
- fix(installer): drop hardcoded admin default credentials; preserve operator rotations on re-seed
- Harden installer state guards and seal install endpoints once installed
- Enforce ACL permission checks on state-changing admin routes
- Fix: Import validation error font color visibility in dark mode
- Show a 429 page instead of 500 on login lockout master
- Port 2.1 validation & permission-enforcement improvements to master
- feat(installer): add type-to-search locale & currency prompts to CLI installer
- fixed: Confirm and guard demo-data seeding to prevent data loss
- Fixed Accept uppercase image extensions (.JPG/.JPEG)
- Fixed : Index audits, skip empty translation audits, and fix history preview
- Port missing 2.1 features + security dep bumps to master (#474, #480)
- feat(installer): add Canadian locales (en_CA, fr_CA) and CAD currency support (fixes #520)
- Preselect application locale and currency from .env during reinstallation
- Feat(export): add dynamic export jobs for scalable large product exports
- added the payload view on the webhook log
- Add Appearance settings page for admin logo and favicon
- chore: apply 2.1 dead-file cleanup to master (#493 parity)
- Converge: merge all 2.1 changes into master (keep master's features/fixes)
- fix(installer): restore composerProbePaths() — fixes 2 CI Pest failures on master
- Chore: updated the import on the installer file
- Fixed - Security: SQLi in datagrid, image-ZIP import RCE, installer takeover + hardening (master)
- locales export import
- Attribute Export/Import
- Upgrade/laravel 13
- ci: run on PHP 8.4 for Laravel 13, refresh deps, add static analysis
- Feature/system settings hub
- Refactor Dynamic Export Filters into Reusable Components
- feat: variant structure, per-user catalog scope, admin hardening + Resource CRUD kit
- Refactor/admin views review
- Refactor/admin views review
- Feature/digital product passport
- support subdirectory deployments in admin AJAX navigation
- feat: Add Measurement Module with Precision Config and Validation Hardening
- feat(passport): Digital Product Passport + admin refactor + E2E suite
- Fix PostgreSQL install failure and measurement seeding
- Fix/category field input validation
- feat(product): configurable association types with per-link fields
- fix: allow empty name values after removing the required name constraint
- Fix/critical high prio issues
- fix(upgrade-13): resolve 14 high-priority ACL, mail, catalog and admin UI issues
- feat(passport): Digital Product Passport publishing, admin UI and API hardening
- fix(upgrade-13) measurement API contract, ACL gaps and admin UI consistency
- Fix/system issue unopim
- Fix/remaining issues
- Feature/configurable associations
- Post-merge CI repair: passport template drift, translations, e2e harness
- Fix parallel Pest CI: stale repository cache, pre-switch fixture DDL, prefix-unsafe datagrid subquery
- Playwright E2E repair: quick-create modal drift, select-handler DOM id, harness fixes
- Dev/product association issue fix
- fix(upgrade-13) catalog locale resolution, migration rollback, image import and admin form defects
- Fix/final fixes
- Catalog, passport, data-transfer and docker fixes with request-path performance work
- Fix/master product category issue
- Fix/remaining
- Accept real-world punctuation in measurement labels, and stop losing failed notification mails
- Fix: fixed the category unsave popup on the product edit page
- Correct the install requirements, Docker admin credentials and PHP support table in the docs
- fixed gravatar issue when running upgrade
New Contributors
- @wattnpapa made their first contribution in #357
- @dieuctunpimp made their first contribution in #521
Full Changelog: v2.1.0...v3.0.0
v2.1.6
v2.1.6
What's Changed
- Fixed Accept uppercase image extensions (.JPG/.JPEG) [2.1]
- Fixed Index audits, skip empty translation audits, and fix history preview[2.1]
- Fixed Confirm before demo-data seeding overwrites existing data[2.1]
- Chore(deps): Bump laravel/framework from 12.55.1 to 12.61.1
- Chore(deps): Bump phpseclib/phpseclib from 3.0.52 to 3.0.55
- Preselect application locale and currency from .env during reinstallation by
- Fixed - Security: SQLi in datagrid, image-ZIP import RCE, installer takeover + hardening (2.1)
Full Changelog: v2.1.5...v2.1.6
v2.0.4
v2.0.4 - Security Update
This release patches multiple security vulnerabilities and a critical import bug. Upgrading is strongly recommended.
- Fixed #502 - Accept uppercase image extensions (.JPG/.JPEG) in #513
- Fixed - Security: SQLi in datagrid, image-ZIP import RCE, installer takeover + hardening in #533
- Fixed - Import job fails with SQL 1064 on JSON_EXTRACT reserved-word column (values) in #536
Full Changelog: v2.0.3...v2.0.4
v2.0.3
Security Release
UnoPim v2.0.3 introduces important security enhancements, performance optimizations, and bug fixes to improve platform stability, administration security, and overall user experience.
Highlights
- Strengthened file upload validation and security controls.
- Improved access control (ACL) enforcement across administrative actions.
- Enhanced API request protection and installer security.
- Fixed performance bottlenecks affecting attribute creation on large datasets.
- Improved application configuration diagnostics with AppUrlGuard.
- Resolved multiple stability and security-related issues.
Full Changelog: v2.1.4...v2.0.3
v2.1.5
UnoPim 2.1.5
UnoPim 2.1.5 is a maintenance and security release focused on platform hardening, upgrade reliability, and project maintenance.
What's Included
- Security hardening for file uploads, API permission checks, Magic AI platform actions, and product-grid sorting.
- Multiple fixes to the
upgrade.shutility, including safer backups, improved.envparsing, hidden-file handling, and PostgreSQL compatibility. - Fixes and updates for project documentation, issue templates, and contributor workflows.
- Repository cleanup and DevOps improvements, including the migration of AI agent skills to a dedicated repository.
Recommended Update
We recommend upgrading to v2.1.5 for all UnoPim 2.1.x installations.
Full Changelog: v2.1.4...v2.1.5