Joomla! 5.4.5
Security
- Delete .github/ISSUE_TEMPLATE/Security.md
- Security updates for composer and npm dependencies for the upcoming 5.3.4 release (#45984)
* composer update enshrined/svg-sanitize to 0.22.0
* npm fix audit issues
- NPM audit fix security vulnerabilities in development dependencies 2026-01-10 (#46662)
- NPM update indirect development dependencies to fix 19 security vulnerabilities (#46825)
5.4.5
- Fix regex pattern in ShowOnRule for custom fields
- Update version in allowEdit method documentation (#47520)
- Use the full path for $this in association template file (#47523)
- Fix double timezone conversion in Media Manager file dates (#47433)
- Use logical top corner radius for RTL/LTR consistency (#47448)
- The image rotation Angle field keeps the entered value (#47462)
- Handle onContentPrepare event in mod_articles (#47467)
- TinyMCE: Load non minified custom CSS (#47478)
* [5.4] TinyMCE: Load non minified custom CSS when no minified version exists
- Fix required modal category field highlighting on validation error (#47505)
- Composer update phpseclib/phpseclib to 3.0.50 (#47529)
- NPM audit fix indirect dependencies 2026-04-01 (#47530)
- Warn when duplicate subform fields are removed on save (#47511)
- Correct possessive apostrophe 'user's' to 'users''
- Prevent recursions in loadposition/loadmodule plugin (#47208)
- NPM update indirect development dependency lodash to 4.18.1 (#47534)
5.4.4
- Fix unset DEPLOY_VERSION (#46866)
- Reduce exclusions in phpstan-baseline.neon (#46857)
- Fix highlighting issue in frontend calendar (#46811)
- Update browserlist:update (#46905)
- Fix TinyMCE init to work in Firefox Developer edition (#46889)
- Content data-transitions attribute is inherited from the first allowed item (#46719)
- Update PR template to link issue automatically (#46835)
- RTL Calendar fixes (#46910)
1. Removes the need for a seperate rtl css stylesheet
2. Stops reversing the hours/minutes cell
- Enhance PR template with AI policy (#46917)
- Update browserlist 2026-02-17 (#46906)
- Add publishing checks to banner item retrieval (#46881)
---------
Co-authored-by: Harald Leithner
Co-authored-by: Stefan Wendhausen
- Expose filename on autoupdate prepare step (#46929)
- README.md – Remove duplicate empty line (#47235)
- Choices selected checkmark background (#47226)
Signed-off-by: BrianTeeman
- Add bug report issue template
This template allows users to submit detailed bug reports, including contact details, expected outcomes, software version, browser information, relevant logs, and agreement to the Code of Conduct.
- Revise bug report template for better user guidance
Updated the bug report template to improve clarity and streamline the information requested.
- Update default version in bug.yml template
Changed the default version from 5.4 to 0 in the bug report template.
- Correct expected result field description
Fix typo in expected result description.
- Remove title field from bug issue template
- Delete .github/ISSUE_TEMPLATE/Bug_report.md
- Delete .github/ISSUE_TEMPLATE/Custom.md
- Delete .github/ISSUE_TEMPLATE/Security.md
- Delete .github/ISSUE_TEMPLATE/rfc.md
- Revise feature request template for GitHub issues
- Rename Feature_request.md to Feature_request.yml
- Convert accessibility issue template to YAML format
Updated the accessibility issue template to YAML format with structured fields for better reporting.
- Create convert-issue-to-discussion
- Create convert-issue-to-discussion.yml
- Delete .github/workflows/convert-issue-to-discussion
- Add workflow to mark conflicting PRs (#47253)
- disable blank issue template
- Fix comment typo in merge-conflicts.yml (#47286)
- Add deleted files from PR #46910 (#47258)
- CONTRIBUTING.md – Add new Joomla versions (#47293)
- Fix sidebar admin flashing icons (#47268)
- mod_tags_popular: Fix duplicate article count (#47218)
- mod_articles conditional readmore (#47263)
- Choices select padding (#47244)
Increases the inline-end padding so that the checkmark if present doesnt appear on top of the text
- NPM audit fix 2026-03-07 (#47321)
- Fix scheduled tasks stopping when one task gets stuck (#47217)
- Check if schema path exists in manifest (#47336)
- Reset selector filters when clearing SearchTools filters (#47352)
- Fix undefined array key warnings in workflow permissionns (#46933)
- fix missing joomla version in nightly notification (#47274)
* [5.4] fix missing joomla version in nightly notification
* Update HMAC value in .drone.yml
---------
Co-authored-by: Harald Leithner
- Try to fix nightly build
- Use "DRONE_BRANCH" instead of "MINORVERSION" variable for nightly build commands (#47390)
- Another attempt to fix the nightly build notifications - use double backslash to escape double quotes (#47397)
* Use double backslash to escape double quotes
* Sign .drone.yml
- Another attempt to fix the nightly build notifications - back to single quotes and use string concatenation (#47399)
* Back to single quotes and use string concatenation
* Sign .drone.yml
- Fix MailHelper::isEmailAddress() throwing exception for invalid domain characters (#47376)
- Hide Versions button when com_contenthistory is disabled (#47388)
- NPM fix audit for non-dev dependency "flatted" (#47406)
- Fix relative asset paths on Cassiopeia error page (#47251)
- Maintenance Task: Change feature request issue template (#47411)
---------
Co-authored-by: Benjamin Trenkle
Co-authored-by: Brian Teeman
- update GitHub actions (drops node.js 20) (#47422)
* update actions/checkout
* update actions/cache
* update actions/upload-artifact
* update actions/setup-node
- Fix disable media edit(icon) when no media action plugins are enabled (#47427)
5.4.3
- Fix copy / paste error (#45979)
- Security updates for composer and npm dependencies for the upcoming 5.3.4 release (#45984)
* composer update enshrined/svg-sanitize to 0.22.0
* npm fix audit issues
- Update TinyMCE from 6.8.5 to 6.8.6 to fix TinyMCE issue with cursor placement (#45987)
* npm update tinymce from 6.8.5 to 6.8.6
* Update version in tinymce.xml
- Revert b/c breaking change in AbstractView::get (#45940)
* Revert "[5.4] Replace deprecation AbstractView::get() in layouts (#45702)"
* This reverts commit f1906ba6e8efb356198c0281126bc84a5e1cf457.
- Update joomla/filesystem to fix extension uploads when post_max_size is 0 (#45986)
- Composer update joomla/filesystem to 3.2.0 (#45999)
- Autoupdate email groups (#45721)
---------
Co-authored-by: Brian Teeman
Co-authored-by: Heiko Lübbe
Co-authored-by: Richard Fath
- Remove duplicate string (#46008)
- Custom Logging Description (#46004)
- Add check if fields exist in versioning (#46009)
- Move associations alert (#46011)
- Start/End Featured (#46003)
- Fix caching for Predefinedlist getOptions method (#45885)
- Show field "Show Article Images" also if introtext is truncated (#45969)
- Add h6 option for Display Options > Header Level (#46037)
- Remove unused CSS from mod_articles (#45974)
- Fix fields menu items in preset (#46062)
- Fix backend com_fields field list menu item (#46052)
* fix the request parameter of the backend field list menu item
* fix context names
- Use correct language for autoupdate notification mails (#46050)
* Use correct default admin language for update notification mails
---------
Co-authored-by: Richard Fath
Co-authored-by: Tuan Pham Ngoc
- Change the table event name from onBeforeDelete to on TableBeforeDelete (#46020)
---------
Co-authored-by: Richard Fath
- Fix field groups menu item type (#46070)
- Update Icon of Misc Information in Contact (#46067)
Until version 5.2 the icon for the Miscellaneous information is a black circle with the letter "i" in the middle (ie. icon-info-circle).
In version 5.3, the icon has changed to Home icon (ie. icon-home) which is same as that of the Website.
So, this change would differentiate the field identifications.
Pull Request for Issue # 46057.
- Update notification code improvements (#46071)
* Improve sends update notification code
- Add settings icon for debug plugin (#46076)
* Update debug.css
---------
Co-authored-by: Richard Fath
- Add Support for Github Codespaces (#45950)
Backport [6.0] Add Support for Github Codespaces #45719 to 5.4
- Resolve deploy version typo (#46085)
- PHPDoc cleanup (#46122)
- clean newsfeed & newsfeed category after first test suite run (#46115)
* afterEach
clean feed after test
* afterEach
clean for re-run
---------
Co-authored-by: Allon Moritz
- Fix missing sentence period (#46105)
- Joomla Dialog add support for aria-label (#46090)
- Fix author not being updated in Tagged Item upon saving article (#44571)
Co-authored-by: Richard Fath
- Documentation for Joomla! Programmers (#46126)
Adds link to manual.joomla.org to the help pages
Signed-off-by: BrianTeeman
- Improve ordering of settings in System Info (#46124)
* [5.4] System Info
This is a cosmetic change to the order that settings are displayed in the System Information page.
Joomla version is moved to the top as the highest priority
Followed by php, database and web server
Signed-off-by: BrianTeeman
* update text download to new ordering
Signed-off-by: BrianTeeman
---------
Signed-off-by: BrianTeeman
- Enhance header handling in transport classes to support array values - (#46078)
Co-authored-by: Martina Scholz <64533137+LadySolveig@users.noreply.github.com>
- Fix date format to use ISO 8601 in SchemaorgPrepareDateTrait (#45581)
- Composer update joomla/oauth2 to 3.0.2 (#46132)
- Update Composer and NPM dependencies for 5.4.0-rc1 (#46099)
* Composer updates
* NPM updates
- update translation pull request action (#46150)
* [5.4] update translation pull request action
schedule works only at default branch
* prepare translation pull request J6
* Update .github/workflows/create-translation-pull-request-v5.yml
* Update .github/workflows/create-translation-pull-request-v6.yml
---------
Co-authored-by: Harald Leithner
- [5.4] update translation pull request action (#46153)
* fix time comment
* fix syntax error
- Fix yaml float to integer autoconversion for translation bot
- Fix language string order (#46164)
- Fix missing copyright in media assets (#46146)
- Update GitHub Actions versions to v5 (#46160)
- Fix wrong variable in build script (#46170)
- Fix alphabetic order installation joomla.ini (#46172)
- Final update of Composer and NPM dependencies for 5.4.0-rc1 (#46167)
* Composer update 2025-09-25
* NPM update 2025-09-25
- PHP8.5 deprecated code (#46134)
* PHP8.5 deprecated
* Update HtmlDocument.php
---------
Co-authored-by: Tuan Pham Ngoc
- PHP8.5 Deprecations (#46136)
* PHP8.5 Deprecations
* Update administrator/components/com_menus/src/Model/MenuModel.php
---------
Co-authored-by: Tuan Pham Ngoc
- PHP8.5 deprecated code (#46137)
* PHP8.5 Deprecations
* Update Select.php
- Add Mailpit Email Testing Support to Codespaces (#46154)
* Add Mailpit
- Fix missing options in pagination (#46219)
* Fix missing 200 and 500 options in pagination
- Remove wrong unique constraint from "#__ucm_content" table on PostgreSQL (#46243)
- xml_parser_free() function has been deprecated (#46199)
- curl_close() function has been deprecated (#46198)
https://wiki.php.net/rfc/deprecations_php_8_5#deprecate_curl_close
- Fix InstallerScript using 'id' instead of 'extension_id' for #__extension (#46195)
* Fix InstallerScript using 'id' instead of 'extension_id' for #__extensions table
- Using null as an array offset is now deprecated (#46201)
- setAccessible() methods of various Reflection objects have been deprecated (#46202)
https://wiki.php.net/rfc/deprecations_php_8_5#deprecate_reflectionsetaccessible
- Using null as an array offset is now deprecated (unit tests) (#46203)
https://wiki.php.net/rfc/deprecations_php_8_5#deprecate_using_values_null_as_an_array_offset_and_when_calling_array_key_exists
- Composer update joomla/http to 3.1.3 (#46301)
* Fixing PHP 8.5 `curl_close() is deprecated`
- Composer update joomla/test to 3.0.4 (#46309)
* Fix phpunit's `ReflectionMethod::setAccessible() is deprecated` with PHP 8.5
- imagedestroy() function has been deprecated (#46200)
---------
Co-authored-by: Quy Ton <190299371+QuyTon@users.noreply.github.com>
Co-authored-by: Harald Leithner <1497730+HLeithner@users.noreply.github.com>
- Privacy Request message when mail is disabled (#46256)
- cli error/help message (#46259)
- Colour Scheme (#46264)
Corrects the americanisation of colour
- Log entry format (#46273)
* [5.4] Log entry format
Changes a space to a tab
---------
Signed-off-by: BrianTeeman
- Underline links [a11y] (#46298)
Underline links inside alerts
- Remove 4.4 GHA and cleanup contributing.md (#46317)
* remove 4.4 and cleanup contributing.md
* Update .github/CONTRIBUTING.md
Co-authored-by: Richard Fath
---------
Co-authored-by: Richard Fath
- Add libraries/vendor/joomla/filter/PATCHES.txt for deletion (#46321)
- fix update notification scheduled task (#46315)
- Fix Automated Update installation error on Windows (#46286)
---------
Co-authored-by: Richard Fath
- check if state is initialized in content CategoryModel (#46316)
Fix regression from #45704
- Fix return type for App getDocument, getLanguage methods as nullability (#46238)
- Fancy select: mark already selected elements with checkmark (#46328)
- Improve Pre-Update Check for Joomla 6.0.0: fix confusing message + additional notices (#46324)
* Improve UX: confusing message about the compatibility plugin
* Update icons and classes for preupdatecheck.php
* Update error messages and notices in language file
* Enhance language strings in com_joomlaupdate.ini
* Updated various text strings in the Joomla update component language file to include additional information and improve clarity.
---------
Co-authored-by: Brian Teeman
- Add mysql to test matrix and proper min max db versions (#46186)
* Add mysql to test system matrix and proper min max db versions
* Extend integration tests
* Load constants from env
- Handle 401 Unauthorized error instead of throwing CRITICAL uncaught 500 server (#46305)
- php temporary folder message (#46337)
Slight language tweak to the two error strings related to the php temporary folder either not being set or not being writeable. Makes the message more specific by explictly writing "upload_tmp_dir"
- Articles module ordering (#46372)
Move the hits filter in the ordering towards the end of the list to more closely match the order of the fields in the article manager. Makes it easier to find this way.
- Upgrade NPM dev dependency mysql2 from ^2.3.3 to ^3.15.3 (#46383)
- Fix mod_articles cache not being cleared automatically (#45475)
- replace 404 and 406 CRITICAL errors with NOTICE and useful information (#46296)
- Always allow the captive page and captive.validate task even with PW reset requested (#46247)
- Update NULLs in Smart Search links (#46395)
Bug fix: Articles that originally expired cannot be found on smart search even the finish publishing date is deleted
- Generate unique alias on “Save as Copy” for Smart Search filters (#46081)
- Fix xml sha verification (#44336)
- Fix for untranslated JLIB_APPLICATION_ERROR string (#45028)
- Fix headers are not sent correctly in com_media api controller (#45150)
- Task SessionGC delete metadata from db (#46128)
- Error page fix: prevent modules rendering in the incomplete Application (#46272)
- Fix issues in language installer (#46403)
* Hide autoupdate box when installing languages
* Fix loader when installing the language
* Fix auto update disabled
- fix version (#46425)
Due to a typo the version was not set correctly in #45762 and #45801
Signed-off-by: BrianTeeman
- Do not get the profile info for the linked user when no user is linked (#46398)
- Update repeatable-table.php (#46287)
* Update repeatable-table.php
The
width was hardcoded to 45%, regardless of the number of columns.
This change makes it dynamic, distributing the width according to the number of fields, while reserving 8% for the action column.
- codestyle comment block (#46427)
Just for consistency - code review only
Signed-off-by: BrianTeeman
Co-authored-by: Richard Fath
- NPM audit fix indirect dev dependencies (#46429)
- Preventing notices for broken images (#46435)
- Revert PR 46081 (#46453)
- Docs: Add a PR targeting section to the README (#46471)
- Fix static getTemplate call in mail template (#46448)
- Avoid fputcsv deprecation notice (#46423)
- php 8.5 version dates check (#46480)
- Remove last uses of JText (#46473)
- Fix webservice API config component: Component with numbers in name get code 404 (#46462)
- Improve e-mail deliverability by aligning from and envelope-from (#46431)
Set the setSender auto flag to true so the DKIM and SPF domains will align the domain form the envelope-from and Return Path with the "from" e-mail address.
- Fix condition to check request format in MenusHelper (#46341)
Thanks @MacJoom for this PR, and thanks @exlemor , @dautrich and @ceford for testing.
@MacJoom Could you create a new issue for the remaining router issue? Thanks in advance.
- success / message type not mapped to SymfonyStyle in ConsoleApplication (#43739)
- autum dark-mode - remove border from sidebar wrapper and add box-shadow (#43202)
- NPM audit fix indirect dev dependencies 2025-11-26 (#46502)
- Smart Search: Fix taxonomy filter overwriting when titles are identical - fix issue #43528 (#44437)
- Do not load articles in blog layout if configured (#46542)
- Add php 8.5 to unit and integration tests (#46223)
- Update DocumentRenderer.php (#45592)
Fixes the regex to prevent double-slashes in RSS/Atom feed URLs for intro images.
- Load extension language for Latest Actions module (#46540)
- fix plg_quickicon_eos snooze function (#46573)
- Fix MySql 8 error "Illegal argument to a regular expression." in banners model (#46547)
---------
Co-authored-by: Richard Fath
- NPM audit fix indirect dev dependencies 2025-12-13 (#46571)
- fix task notification for updated Joomla versions (prior 5.3) (#45497)
---------
Co-authored-by: Brian Teeman
- Expose finalization errors in autoupdate API response (#46493)
- Remove unnecessary $this->setError('') (#46527)
- NPM audit fix dev dependencies 2025-12-19 (#46590)
- Remove the link to skin creator in TinyMCE (#46583)
- Fix subform field dropdown showing current field (Fixes #46214) (#46529)
- Comment Typo (#46613)
Spotted this typo while testing a PR. It should be fixed so that people can search the codebase for this term
- Fix warning and deprecation in tags link without itemid (#46588)
- Skip anchor references in css versioning build script (#46609)
- Update BreadcrumbsHelper.php (#46581)
- Hide help on alternate preset admin menu (#46620)
- Update framework http package to 3.1.4 (#46638)
- Accept custom image class settings in Articles module (#46619)
- Fix CLI installation exit code to 1 when PHP version requirement not met (#46625)
- Add legacy label to mod_articles_archived (#46626)
---------
Co-authored-by: Brian Teeman
- Fix 500 error in Smart Search with specific search query (#46586)
- Tightened site menu item edit button regex (#46569)
- Update type=UserGroupList in xml to align all lowercase type for usergrouplist (#46650)
- Fix: Parent menu items missing when creating menu item via Save to Menu (#46621)
- Composer update paragonie/sodium_compat to v1.24.0 (#46659)
- NPM audit fix security vulnerabilities in development dependencies 2026-01-10 (#46662)
- Comment typo editor fixed (#46673)
- Remove 'layouts' folder and add presets (#46677)
- Fix: Parent menu items missing when creating menu item via 'save to menu' v2 (#46681)
* Remove wrong id from menu edit data
* Revert "[5.4] Fix: Parent menu items missing when creating menu item via Save to Menu (#46621)"
* This reverts commit 7cbd3b9d502478352c276c05c9acd6f3758c371b.
- Fix OptionsRule validation to support groupedlist fields (#46608)
- fix case mod_articles manifest (#46674)
- Revert Mailer improvements from PR #46431 to fix issue #46643 (#46693)
- Fix metis-menu-error when clicking outside the menu (#46669)
- Composer update algo26-matthias/idna-convert to v3.2.1 (#46724)
- Fixed Archive not found error message (#46726)
Fixes obvious copy paste error using the wrong language string for an error message
- Prepend root url to schema images (#46306)
- Extension variable in AssociationExtensionHelper is string (#46741)
- Clean GitHub actions cache for merged PR (#46684)
- API 404 for non-existing users/levels/id (#46742)
Add null check before converting rules to array
- Using null as the key parameter for array_key_exists() is deprecated (#46736)
- Outline selected rows in debug Profile timeline (#46623)
- mod_articles image (#46598)
Make sure the image is displayed AND ensure there are no empty list elements
---------
Signed-off-by: BrianTeeman
- Fix btn in alert messages (#46752)
When using btn-classes in an alert message, the styling is not everywhere readable. This PR fixes it.
- Proper com_templates error when PHP zip extension is missing (#46716)
- NPM updates diff and lodash (#46758)
NPM modules patch level updates:
- diff from 5.2.0 to 5.2.2
- lodash from 4.17.21 to 4.17.23
- Allow PATCH /api/users/id without the need to specify 'groups' in the payload (#46750)
- Add integration test for checking extensions updates (#46754)
Co-authored-by: Allon Moritz
- Fix fonts URL (#46757)
- Fix undefined array key "language" in sef plugin (#45959)
- Fix WebAssetRegistry to work with redefined administrator folder (#44980)
- Mysql installation Error Message (#46794)
Signed-off-by: BrianTeeman
- Load language for com_installer in CheckUpdatesCommand (#46753)
- Update PR template with guide.joomla.org (#46803)
- Make Email Notifications field non-required (#46768)
- Fix missing names quotes and wrong casing of column alias in libraries/src/Table/Nested.php (#45848)
- XML files code style (#46809)
- Exclude Symfony HTTP client Test folders from release packages (#46765)
- Fix composer audit warnings 2026-02-01 (#46821)
- NPM update indirect development dependencies to fix 19 security vulnerabilities (#46825)
- Add unit tests for form rules (#46723)
---------
Co-authored-by: Brian Teeman
- Partial fix for removing the installation folder on Windows (#46584)
- Create a user access level via POST (#46080)
- Add deleted files and folders from PR #46765 (#46830)
- Checkin with default value in task (#46694)
- Fix duplicate getLayoutData execution in mod_tags_popular (#46827)
- Fix null user check in ActionLogPlugin to prevent PHP warnings (#46599)
- Check if page title element exists in table column script (#46776)
- Name calendar field name with the invalid date format (#46833)
* [5.4] Fix crash in Calendar field with invalid date format
- Revert [webservices] Create a user access level via POST (#46080)" (#46846)
This reverts commit 26439d6d2979cade07ffdb81e9ef606b2de5b7c0.
|