chore(deps): update dependency plausible/analytics to v3 #64
Open
renovate-bot
wants to merge 1 commit from
renovate/plausible-analytics-3.x into main
pull from: renovate/plausible-analytics-3.x
merge into: ops:main
ops:main
ops:renovate/ghcr.io-paperless-ngx-paperless-ngx-3.x
ops:renovate/ghcr.io-remsky-kokoro-fastapi-gpu-0.x
ops:renovate/ghcr.io-perfectra1n-kubesearch-mcp-1.x
ops:renovate/ghcr.io-atuinsh-atuin-18.x
ops:renovate/docker.io-binwiederhier-ntfy-2.x
ops:renovate/forgejo-1.x-lockfile
ops:renovate/registry.erwanleboucher.dev-eleboucher-charts-memini-0.x
ops:renovate/ghcr.io-siderolabs-installer-1.13.x
ops:renovate/ghcr.io-scanopy-scanopy-server-0.x
ops:renovate/crowci-0.x-lockfile
ops:renovate/quay.io-jetstack-charts-cert-manager-1.x
ops:renovate/loki-7.x
ops:renovate/gitlab-10.x
ops:renovate/ghcr.io-rommapp-romm-5.x
ops:renovate/quay.io-thanos-thanos-0.x
ops:renovate/plugin-barman-cloud-0.x
ops:renovate/cilium-1.x
ops:renovate/uv_build-0.x
ops:renovate/open-webui-15.x
ops:renovate/ghcr.io-siderolabs-charts-talos-cloud-controller-manager-0.x
ops:renovate/code.forgejo.org-forgejo-helm-forgejo-17.x
ops:renovate/ghcr.io-stacklok-toolhive-toolhive-operator-crds-0.x
ops:renovate/ghcr.io-stacklok-toolhive-toolhive-operator-0.x
ops:renovate/nvidia-gpu-exporter-2.x
ops:renovate/ghcr.io-diced-zipline-4.x
ops:renovate/sentry-33.x
ops:renovate/kube-prometheus-stack-87.x
ops:renovate/ghcr.io-mogenius-helm-charts-renovate-operator-5.x
ops:renovate/ghcr.io-controlplaneio-fluxcd-charts-flux-operator-0.x
ops:renovate/ghcr.io-home-operations-kromgo-0.x
ops:renovate/ghcr.io-home-operations-charts-echo-0.x
ops:renovate/ghcr.io-usememos-memos-0.x
ops:renovate/ghcr.io-helmforgedev-helm-kubernetes-mcp-server-1.x
ops:renovate/codefloe.com-crowci-crow-2.x
ops:renovate/altinity-clickhouse-operator-0.x
ops:renovate/ghcr.io-siderolabs-kubelet-1.x
ops:renovate/ghcr.io-siderolabs-kubelet-1.34.x
ops:renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x
ops:renovate/mail-5.x
ops:renovate/kubernetes.core-6.x
ops:renovate/ghcr.io-goauthentik-server-2026.x
ops:renovate/reloader-2.x
ops:renovate/metrics-server-3.x
ops:renovate/cert-manager-webhook-pdns-3.x
ops:renovate/bluesky-pds-0.x
ops:renovate/ghcr.io-sysadminsmedia-homebox-0.x
ops:renovate/promtail-6.x
ops:renovate/loki-6.x
ops:renovate/cloudnative-pg-0.x
ops:renovate/github.com-imusmanmalik-cert-manager-mixin-1.x
ops:renovate/gitlab-agent-2.x
ops:renovate/ghcr.io-spegel-org-helm-charts-spegel-0.x
ops:renovate/lock-file-maintenance
ops:renovate/bitwarden-secrets-1.x
ops:renovate/gitlab-19.x
ops:renovate/authentik-2026.x
ops:renovate/ruby-4.x
ops:renovate/docker.io-healthchecks-healthchecks-4.x
ops:renovate/sops-1.x
ops:renovate/random-3.x
ops:renovate/registry.gitlab.com-fmd-foss-fmd-server-0.x
ops:renovate/plausible-analytics-2.x
ops:renovate/quay.io-oauth2-proxy-oauth2-proxy-7.x
ops:renovate/python-3.x
ops:renovate/johly-airtrail-3.x
ops:renovate/ghcr.io-gethomepage-homepage-1.x
ops:renovate/ingress-nginx-4.x
ops:renovate/gitlab-9.x
ops:renovate/ghcr.io-rommapp-romm-4.x
ops:renovate/ghcr.io-gotson-komga-1.x
ops:renovate/gabehf-koito-0.x
ops:renovate/willshersystems.sshd-0.x
ops:renovate/containers.podman-1.x
ops:renovate/ghcr.io-prometheus-community-charts-prometheus-operator-crds-30.x
No reviewers
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
ops/homelab!64
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/plausible-analytics-3.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
2.0.0→3.2.1Release Notes
plausible/analytics (plausible/analytics)
v3.2.1Compare Source
Security related update
This patch release fixes a security vulnerability
CVE-2026-8467/GHSA-55hg-8qxv-qj4paffecting the following versions of Plausible Community Edition (image: ghcr.io/plausible/community-edition):Tags:
The affected versions expose a
HTTP "/storybook"endpoint which, under certain conditions, allows remote code execution with privileges of system user running the application.This release v3.2.1 of Plausible Community Edition completely removes that endpoint.
Who is affected?
All deployments of Plausible Community Edition running the following versions:
where
HTTP "/storybook"endpoint is exposed to a public or other untrusted network.Mitigation
All affected versions of Plausible Community Edition should be updated to v3.2.1 as soon as possible.
As an immediate mitigation, it is recommended to block access to HTTP "/storybook" endpoint in your reverse proxy configuration or via other applicable means.
Changes in this release
HTTP "/storybook"endpoint along with the associated logicNo other changes are included in this release.
v3.2.0Compare Source
Added
Removed
Changed
.../pages), the viewer will be redirected to that subpage after providing the passwordFixed
êin the legacy filter?page=%C3%AA)v3.1.0Compare Source
Added
include.trim_relative_date_range- this option allows trimming empty values after current time forday,monthandyeardate_range valuestransformRequestfunction to change event payloads before they're sentcustomPropertiesfunction hook to derive custom props for events on the flyplausible.init({ ...your overrides... })- this can be unique page-by-page@plausible-analytics/trackerESM module is available on NPM - it has near-identical configuration API and identical tracking logic as the script and it receives bugfixes and updates concurrently with the new tracker scriptRemoved
Changed
event.props.pathto be explicitly defined when tracking: it is set to be the same asevent.pathnamein event ingestion; if it is explicitly defined, it is not overridden for backwards compatibilityday,monthandyearperiodsbounce_ratemetric in Entry Pages breakdownFixed
visitorsandvisitsper hour, count visits in each hour they were active inv3.0.1Compare Source
This release contains a patch for the migration procedure (fixes #5319).
Functionally it is equivalent of https://github.com/plausible/analytics/releases/v3.0.0
Upgrade
Update the image used for
plausiblecompose.yml
and restart the containers
v3.0.0Compare Source
Added
exit_ratemetric in the dashboard Exit Pages > Details report28dand91davailable on both dashboard and in public APIcase_sensitive: falsemodifiers in Stats API V2 filters for case-insensitive searches.is notfor goals in dashboard #4983["is", "segment", [<segment ID>]]filter in Stats APIengagementevent. These are reported assdandeinteger parameters to /api/event endpoint respectively. If you're using a custom proxy for plausible script, please ensure that these parameters are being passed forward.vparameter sent with each request.has_doneandhas_not_doneon the Stats API to allow filtering sessions by other events that have been completed.time_on_pagemetric is now graphable, sortable on the dashboard, and available in the Stats API and CSV and GA4 exports/importsRemoved
Changed
todayrather thanlast 28 days. On the next day, the default changes tolast 28 days.Tstill works for last 30 days.7dand30dperiods do not include today anymorefetchwith keepalive flag as default overXMLHttpRequest. This will ensure more reliable tracking. Reminder to usecompatscript variant if tracking Internet Explorer is required./api/healthhealtcheck is soft-deprecated in favour of separate/api/system/health/liveand/api/system/health/readychecks-instead of0for visit duration, scroll depth when hovering a data point with no visit dataengagementevents sent by plausible tracker script. We still use the old calculation methods for periods before the self-hosted instance was upgraded. Warnings are shown in the dashboard and API when legacy calculation methods are used.date_rangeshorthand options like30d,3mo.Fixed
visitors.csv(in dashboard CSV export) vs dashboard main graph reporting different results forvisitorsandvisitswith atime:minuteinterval./api/v2/queryno longer returns a 500 when querying percentage metric withoutvisitorsv2.1.5Compare Source
Added
Removed
v2.1.4Compare Source
Added
Changed
invite_onlyfor registration #4616Fixed
v2.1.3Compare Source
Fixed
v2.1.2Compare Source
Added
contains_notfilter support to dashboard/assets/assetsRemoved
ECTO_IPV6andECTO_CH_IPV6env vars in CE #4245DATABASE_SOCKET_DIR#4202Changed
DATABASE_URL#42021000000(practically removing the limit) #4200isandis notfilters in dashboard no longer support wildcards. Use contains/does not contain filter instead.bounce_ratemetric now returns 0 instead of null for event:page breakdown when page has never been entry page.TOTP_VAULT_KEYoptional #4317DATABASE_CACERTFILEnow forces TLS for PostgreSQL connections, so you don't need to add?ssl=trueinDATABASE_URLFixed
plausible_dbandplausible_events_dbdatabases #4466v2.1.1Compare Source
Added
Fixed
v2.1.0Compare Source
Added
conversion_rateto Stats API Timeseries and on the main graphtotal_conversionsandconversion_ratetovisitors.csvin a goal-filtered CSV exportconversion_rateto Stats API Timeseries and on the main graphtime_on_pagemetric into the Stats APIviews_per_visitmetric based on imported data as well if possibleoperating_system_versionsbyoperating_systemin Stats API breakdownoperating_system_versions.csvinto the CSV exportTotal visitors,Conversions, andCRin the "Details" views of Countries, Regions and Cities (when filtering by a goal)conversion_rateto Regions and Cities reports (when filtering by a goal)conversion_ratemetric to Stats API Breakdown and Aggregate endpointscontains/matchesoperator for Sources, Browsers and Operating Systems.event:goalpropertycontains/matchesoperator for custom propertiesreferrers.csvto CSV exportcustom_props.csvto CSV export (almost the same as the oldprop_breakdown.csv, but has different column headers, and includes props for pageviews too, not only custom events)referrers.csvto CSV exportCLICKHOUSE_MAX_BUFFER_SIZE_BYTESenv var which defaults to100000(100KB)EXTRA_CONFIG_PATHenv var to specify extra Elixir config #3906robots.txtfor self-hosted #3905DATA_DIRenv var for exports/imports #4100Removed
prop_namesreturned in the Stats APIevent:goalbreakdown responseprop-breakdown.csvfile from CSV exportCLICKHOUSE_MAX_BUFFER_SIZE/app/init-admin.shthat was deprecated in v2.0.0 #3903DISABLE_AUTHdeprecation warning #3904Changed
entry_pageandexit_pageis only set and updated for pageviews, not custom eventsCLICKHOUSE_MAX_BUFFER_SIZEwithCLICKHOUSE_MAX_BUFFER_SIZE_BYTESMAILER_EMAILnow defaults to an address built off ofBASE_URL#4538MAILER_ADAPTERhas been changed toBamboo.Mua#4538Fixed
entry_pageandexit_pagebreakdownsVersionedCollapsingMergeTreeto store visit data to avoid rare race conditions that led to wrong visit data being shownconversion_ratemetric in abrowser_versionsbreakdownconversion_ratepercentage change in the same way likebounce_rate(subtraction instead of division)bounce_ratepercentage change in the Stats API in the same way as it's done in the dashboard(none)values in custom property breakdown for the first page (pagination) of resultswidth=manualin embedded dashboards #3910Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
Update dependency plausible/analytics to v3to chore(deps): update dependency plausible/analytics to v3chore(deps): update dependency plausible/analytics to v3to Update dependency plausible/analytics to v3Update dependency plausible/analytics to v3to chore(deps): update dependency plausible/analytics to v3View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.