What's new with TinaCloud
Version 2026.09.4
Released on 9/24/2026
✨ Features
- @kulesy-
fix(dashboard): keep Update Payment Method reachable when no card resolves
- @wicksipedia-
feat(admin): find customer projects from the staff admin panel
- @wicksipedia-
feat(admin): add project and organisation pages to the staff panel
- @wicksipedia-
feat(admin): let staff grant a project extra contributor seats
- @wicksipedia-
feat(admin): show staff change history in the panel
- @kulesy-
feat(content-api): alarm when editorial workflow saves keep failing for one project
- @kulesy-
chore(deps): take the September patch-and-minor group except react-icons
- @KahaMason-
feat: freeze new account deletion requests before WorkOS migration
- @harley-j-
feat: Heal unprovisioned WorkOS user on retry
- @Aibono1225-
test: add deployed TinaCMS client compatibility coverage
- @designbyalex-
feat(dashboard): orange primary buttons, llama welcome hero, responsive Create Project chooser
- @joshbermanssw-
📝 Remove "may" from the deploy popup warning
- @brookjeynes-ssw-
feat: add bulk-send email logic
- @kulesy-
fix(billing): resolve a project's live subscription when it holds more than one row
- @kulesy-
feat(ses-email-templates): tell announcement recipients what happens to their sign-in
- @kulesy-
feat: show announcements on the TinaCloud login screen
- @kulesy-
fix(deps): bump the stale axios copies onto patched releases
- @kulesy-
chore(identity): log authorizer and gateway errors in the Identity API access log
- @tinacms-
feat: alarm when the latest @tinacms/graphql has no alias in the deployed content API
👒 Dependencies
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 3 updates[bot]
- @dependabot-
chore(deps): bump aws-actions/configure-aws-credentials from 6.2.4 to 6.3.0 in the patch-and-minor group across 1 directory[bot]
- @dependabot-
chore(deps-dev): bump vite from 5.4.21 to 6.4.3 in /e2e/tinacms-compat[bot]
- @dependabot-
chore(deps): bump sonner from 1.7.4 to 2.0.8[bot]
- @dependabot-
chore(deps-dev): bump vite from 6.4.3 to 8.3.0 in /e2e/tinacms-compat[bot]
Version 2026.09.3
Released on 9/17/2026
✨ Features
👒 Dependencies
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 2 updates[bot]
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 6 updates[bot]
- @dependabot-
chore(deps): bump js-yaml from 3.15.1 to 3.15.2[bot]
- @types-
chore(deps): bump fs-extra and @types/fs-extra[bot]
- @dependabot-
chore(deps-dev): bump jsdom from 21.1.2 to 30.0.1[bot]
Version 2026.09.2
Released on 9/14/2026
✨ Features
- @wicksipedia-
Stop reporting a blocked GitHub call as missing push access
- @wicksipedia-
feat(identity): backfill owners on projects and orgs that have none
- @wicksipedia-
Administer the CMS announcement bar from a staff admin panel
- @KahaMason-
feat: add MFA enrolment for AuthKit accounts
- @koa-
chore: upgrade koa to 3 with @koa/cors 5, koa-router 12 and @koa/bodyparser 6
- @release-bot-allow-prs-and-push-
chore: update TinaCMS dependencies[bot]
Version 2026.09.1
Released on 9/14/2026
✨ Features
- @harley-j-
Development/2057 improve consistency of domain name overrides
- @kulesy-
fix(identity): require an org admin caller and refuse owner deletion when removing an org user
- @Aibono1225-
fix(content-api): validate GraphQL schema before indexing succeeds
- @joshbermanssw-
💄 Shorten the co-authoring name and email fields
- @Aibono1225-
fix(content-api): recover failed index migrations
- @release-bot-allow-prs-and-push-
chore: update TinaCMS dependencies[bot]
- @kulesy-
fix: teach the Lambda wrapper that compressed bodies are binary
- @KahaMason-
Hide account deletion for WorkOS users until it cascades
- @kulesy-
chore(assets-api): align aws-sdk-client-mock with the rest of the workspace
- @joshbermanssw-
fix(dashboard): mark required fields and hold errors until blur
- @kulesy-
chore(dashboard): upgrade vite 4 to 6
- @isaaclombardssw-
feat(dashboard): capture churn feedback on cancel
- @kulesy-
test: add deployed-environment e2e coverage for the content editing flow
- @joshbermanssw-
💄 Replace the chevron wizard steps with a rail on a card
- @kulesy-
fix(content-api): stop applying the generator pathToTina to content repo clones
👒 Dependencies
- @dependabot-
chore(deps): bump qs from 6.15.3 to 6.16.0[bot]
- @dependabot-
chore(deps): bump browserslist from 4.24.4 to 4.28.8[bot]
- @dependabot-
chore(deps): bump github.com/go-chi/chi/v5 from 5.0.8 to 5.2.4 in /identity[bot]
- @dependabot-
chore(deps): bump postcss-selector-parser from 6.1.2 to 6.1.4[bot]
- @dependabot-
chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /identity[bot]
New Contributors
- @isaaclombardssw-
their first contribution
Version 2026.09.0
Released on 9/3/2026
✨ Features
- @brookjeynes-ssw-
fix: disable zstd compression on content-api
Version 2026.08.8
Released on 9/3/2026
✨ Features
- @Aibono1225-
fix(dashboard): surface project deletion failures to the user
- @kulesy-
🐛 fix: preserve starter project state after Vercel deployment redirect
- @Aibono1225-
Improve AssetTransformer diagnostic logging
- @Aibono1225-
Improve GitHub authoring settings UX
- @kulesy-
Always deploy cf-security-headers before the main sst deploy on releases
- @vitest-
chore: bump vitest and @vitest/coverage-v8 to 3.2.6 across all workspaces
- @kulesy-
docs(adr): correct the WorkOS migration plan to a forced TinaCMS 3.12 upgrade with an October cutoff
- @brookjeynes-ssw-
fix: plaintext token retrieval
- @brookjeynes-ssw-
fix: conditionally check repo push access when guessing installation id
- @wicksipedia-
Prove the user can write to a repo before binding a project to it
- @kulesy-
fix: redact credential-bearing headers and tokens before writing them to logs
👒 Dependencies
- @dependabot-
chore(deps): bump golang.org/x/crypto from 0.35.0 to 0.52.0 in /identity[bot]
- @dependabot-
chore(deps): bump fast-uri from 3.1.5 to 3.1.7[bot]
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 57 updates[bot]
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 17 updates[bot]
Version 2026.08.7
Released on 8/31/2026
✨ Features
- @designbyalex-
🎨 Enlarge header menus: type scale, row height, menu height (#4063)
- @Aibono1225-
Fix TinaCloud no-access login handling
New Contributors
- @designbyalex-
their first contribution
Version 2026.08.6
Released on 8/27/2026
✨ Features
- @Aibono1225-
Add branch-aware media rename support to TinaCloud
- @kulesy-
chore: force patched fast-jwt and fast-xml-parser in sst's deploy tree
- @aws-sdk-
chore: float @aws-sdk/client-cognito-identity-provider and client-ssm off stale locks
- @kulesy-
fix(identity): gateway-level CORS so authorizer 401/403s carry CORS headers
- @kulesy-
🟥 fix: patch fast-xml-parser 4.5.7 entity-expansion cap that kills sst deploys
- @kulesy-
fix(ci): let the tinacms auto-bump workflow commit on the runner
- @kulesy-
fix: honest error when password reset hits a confirmed user with unverified email
- @kulesy-
fix: return 401 instead of 500 for expired GitHub refresh tokens
- @Aibono1225-
fix: guard tiny search index uploads
- @Aibono1225-
Fix projects wedged when TinaCMS config is missing on the default branch
- @kulesy-
Add security.txt and public_key.asc to app.tina.io /.well-known/
- @kulesy-
chore: clear form-data and jsonpath-plus transitive alerts
- @kulesy-
📝 docs: onboarding checklist covers Internal Project in CRM
- @kulesy-
Allow /.well-known/ through the SPA rewrite in cf-security-headers
- @kulesy-
fix(identity): require an org admin caller to change org roles and app assignments
Version 2026.08.5
Released on 8/24/2026
✨ Features
- @Aibono1225-
Allow users to cancel pending account deletion
- @Aibono1225-
Fix disabled GitHub OAuth sign-in feedback
Version 2026.08.4
Released on 8/24/2026
✨ Features
- @kulesy-
🐛 Render the real CreateAppUser error when accepting a project invite
- @joshbermanssw-
🐛 Give every lambda only the stage params it reads
- @KahaMason-
Complete invite acceptance under AuthKit