What's new with TinaCloud
Version 2026.09.0
Released on 9/3/2026
✨ Features
- @brookjeynes-ssw-
fix: disable zstd compression on content-api
Version 2026.08.8
Released on 9/3/2026
✨ Features
- @Aibono1225-
fix(dashboard): surface project deletion failures to the user
- @kulesy-
🐛 fix: preserve starter project state after Vercel deployment redirect
- @Aibono1225-
Improve AssetTransformer diagnostic logging
- @Aibono1225-
Improve GitHub authoring settings UX
- @kulesy-
Always deploy cf-security-headers before the main sst deploy on releases
- @vitest-
chore: bump vitest and @vitest/coverage-v8 to 3.2.6 across all workspaces
- @kulesy-
docs(adr): correct the WorkOS migration plan to a forced TinaCMS 3.12 upgrade with an October cutoff
- @brookjeynes-ssw-
fix: plaintext token retrieval
- @brookjeynes-ssw-
fix: conditionally check repo push access when guessing installation id
- @wicksipedia-
Prove the user can write to a repo before binding a project to it
- @kulesy-
fix: redact credential-bearing headers and tokens before writing them to logs
👒 Dependencies
- @dependabot-
chore(deps): bump golang.org/x/crypto from 0.35.0 to 0.52.0 in /identity[bot]
- @dependabot-
chore(deps): bump fast-uri from 3.1.5 to 3.1.7[bot]
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 57 updates[bot]
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 17 updates[bot]
Version 2026.08.7
Released on 8/31/2026
✨ Features
- @designbyalex-
🎨 Enlarge header menus: type scale, row height, menu height (#4063)
- @Aibono1225-
Fix TinaCloud no-access login handling
New Contributors
- @designbyalex-
their first contribution
Version 2026.08.6
Released on 8/27/2026
✨ Features
- @Aibono1225-
Add branch-aware media rename support to TinaCloud
- @kulesy-
chore: force patched fast-jwt and fast-xml-parser in sst's deploy tree
- @aws-sdk-
chore: float @aws-sdk/client-cognito-identity-provider and client-ssm off stale locks
- @kulesy-
fix(identity): gateway-level CORS so authorizer 401/403s carry CORS headers
- @kulesy-
🟥 fix: patch fast-xml-parser 4.5.7 entity-expansion cap that kills sst deploys
- @kulesy-
fix(ci): let the tinacms auto-bump workflow commit on the runner
- @kulesy-
fix: honest error when password reset hits a confirmed user with unverified email
- @kulesy-
fix: return 401 instead of 500 for expired GitHub refresh tokens
- @Aibono1225-
fix: guard tiny search index uploads
- @Aibono1225-
Fix projects wedged when Tina config is missing on the default branch
- @kulesy-
Add security.txt and public_key.asc to app.tina.io /.well-known/
- @kulesy-
chore: clear form-data and jsonpath-plus transitive alerts
- @kulesy-
📝 docs: onboarding checklist covers Internal Project in CRM
- @kulesy-
Allow /.well-known/ through the SPA rewrite in cf-security-headers
- @kulesy-
fix(identity): require an org admin caller to change org roles and app assignments
Version 2026.08.5
Released on 8/24/2026
✨ Features
- @Aibono1225-
Allow users to cancel pending account deletion
- @Aibono1225-
Fix disabled GitHub OAuth sign-in feedback
Version 2026.08.4
Released on 8/24/2026
✨ Features
- @kulesy-
🐛 Render the real CreateAppUser error when accepting a project invite
- @joshbermanssw-
🐛 Give every lambda only the stage params it reads
- @KahaMason-
Complete invite acceptance under AuthKit
Version 2026.08.1
Released on 8/18/2026
✨ Features
- @KahaMason-
Extract a shared FullScreenLoader component
- @KahaMason-
Thread the neutral getToken through the GitHub code exchange
- @kulesy-
fix(ci): normalise follow-redirects entry in yarn.lock
- @brookjeynes-ssw-
feat: tinacms workos support
- @KahaMason-
Render public routes for logged-out AuthKit visitors
- @kulesy-
chore(identity): retire the Bind integration
- @KahaMason-
Mint a new token in refreshAuth so newly granted access applies
- @kulesy-
docs: add dev onboarding issue template
- @KahaMason-
Un-fence repo-connect for WorkOS users
- @wicksipedia-
Add the staff admin panel, with WorkOS sign-in and its deployment stack
- @kulesy-
fix: allow customer origins CORS on GET /v2/auth/config
👒 Dependencies
- @dependabot-
chore(deps): bump fast-uri from 3.0.6 to 3.1.5[bot]
- @dependabot-
chore(deps): bump body-parser from 1.20.3 to 1.20.6[bot]
- @dependabot-
chore(deps): bump nanoid from 3.3.9 to 3.3.18[bot]
- @dependabot-
chore(deps): bump js-yaml from 3.14.2 to 3.15.1[bot]
- @dependabot-
chore(deps): bump brace-expansion from 1.1.13 to 1.1.18[bot]
- @dependabot-
chore(deps): bump tar from 7.5.11 to 7.5.22[bot]
- @dependabot-
chore(deps): bump linkify-it from 5.0.0 to 5.0.2[bot]
- @babel-
chore(deps): bump @babel/core from 7.26.10 to 7.29.7[bot]
- @tootallnate-
chore(deps): bump @tootallnate/once from 2.0.0 to 2.0.1[bot]
- @dependabot-
chore(deps): bump ws from 7.5.10 to 7.5.11[bot]
- @dependabot-
chore(deps): bump fast-xml-builder from 1.1.4 to 1.2.0[bot]
- @dependabot-
chore(deps): bump follow-redirects from 1.15.9 to 1.16.0[bot]
- @dependabot-
chore(deps-dev): bump esbuild from 0.25.12 to 0.28.1[bot]
- @dependabot-
chore(deps-dev): bump postcss from 8.5.3 to 8.5.23[bot]
- @dependabot-
chore(deps-dev): bump aws-cdk-lib from 2.224.0 to 2.260.0[bot]
- @dependabot-
chore(deps): bump axios from 1.12.0 to 1.18.0[bot]
- @dependabot-
chore(deps): bump the patch-and-minor group across 1 directory with 2 updates[bot]
- @dependabot-
chore(deps): bump form-data from 4.0.4 to 4.0.6[bot]
- @dependabot-
chore(deps): bump markdown-it from 14.1.1 to 14.2.0[bot]
- @dependabot-
chore(deps): bump actions/github-script from 8.0.0 to 9.0.0[bot]
- @dependabot-
chore(deps): bump actions/checkout from 5.0.1 to 7.0.0[bot]
- @dependabot-
chore(deps): bump actions/setup-node from 5.0.0 to 6.4.0[bot]
- @dependabot-
chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.1[bot]
Version 2026.07.4
Released on 7/31/2026
✨ Features
- @wicksipedia-
feat: personal activity calendar
Version 2026.07.3
Released on 7/31/2026
✨ Features
- @Aibono1225-
Stop logging raw tokens in plaintext
- @wicksipedia-
✨ Activity reporting: content-change leaderboard and latest landing
Version 2026.07.2
Released on 7/29/2026
✨ Features
- @kulesy-
fix(identity): harden org list against membership rows missing OrgName
- @kulesy-
feat(refresh-webhooks): refresh content-repo hooks in direct mode
- @KahaMason-
feat(auth): dual-issuer (Cognito + WorkOS) JWT verification for content-api & assets-api
- @joshbermanssw-
✨ Return matching folders as media-search results (v2 list)