Rocket.Chat 8.9.0-rc.1
Release candidate update with Node.js 22.22.3+ or 24.15.0+ support, MongoDB 8.0 compatibility, and Apps-Engine 1.67.0-rc.0. Includes dependency bumps for meteor, core-typings, and rest-typings.
Rocket.Chat — Collaboration product updates and releases, tracked on megachangelog.
Release candidate update with Node.js 22.22.3+ or 24.15.0+ support, MongoDB 8.0 compatibility, and Apps-Engine 1.67.0-rc.0. Includes dependency bumps for meteor, core-typings, and rest-typings.
Release candidate featuring a new realtime message composer, hybrid AI search with semantic and keyword retrieval, custom sidebar categories for enterprise users, enhanced video conference window with dedicated UI, and new API endpoints for messages, autotranslation metadata, cloud registration, and room history.
Fixed Omnichannel rooms failing to register agent responses and show send errors on messages and file uploads when rooms contained corrupted visitor activity data from older app integrations.
Rocket.Chat 8.8.0 introduces classification banners for ABAC-managed rooms, SAML auth support in mobile/desktop apps, forced end-to-end encryption for private rooms, new REST audit and TOTP endpoints replacing deprecated DDP methods, status visibility controls, and an AI Model Context Protocol endpoint. The default apps-engine runtime backend changes from Deno to Node, and LDAP/SAML authentication is deprecated for non-Premium workspaces.
Release candidate with updated engine versions including Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.66.0-rc.0. Dependencies updated including core-typings and rest-typings.
Voice Call Screen Sharing is now stable with the beta alert removed and in-room call interface enabled for all calls. Fixed silent background loading of entire room history and attachments, and resolved a reload loop when opening links to older messages.
Release candidate 8.8.0 introduces classification banners for ABAC-managed rooms, new REST endpoints for audit trails and 2FA workflows, SAML support in mobile/desktop apps, forced end-to-end encryption for private rooms, status visibility controls, and deprecates LDAP/SAML on non-Premium workspaces. Engine updates include Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.66.0-rc.0.
This patch release includes security fixes, per-client rate limiting for the password recovery endpoint, and a bug fix for special character escaping in Omnichannel queue display. Multiple dependencies have been updated to maintain compatibility and stability.
Security hotfix and improvements including per-client rate limiting for password reset requests, fixed special character escaping in Omnichannel visitor names, and dependency updates across core packages.
Patch release with security fixes including per-client rate limiting for forgot password endpoint, SSRF protection in file downloads, and fixes for special character escaping in Omnichannel visitor names.
Patch release with security improvements including rate limiting on password reset, SSRF protection in file downloads, and special character escaping in Omnichannel queue display.
Patch release with security improvements including rate limiting on the unauthenticated sendForgotPasswordEmail method, SSRF protection in file downloads, and fixes for special character escaping in Omnichannel. Also updates Node, Deno, MongoDB, and Apps-Engine engine versions.
Patch release with security fixes including SSRF protection in file downloads, rate limiting for password reset emails, and fixes for special character handling in Omnichannel. Updates Node, Deno, MongoDB, and Apps-Engine engine versions.
Patch release with security improvements including per-client rate limiting for password reset requests, SSRF protection in file downloads, and fixes for UI checkbox state and special character handling in Omnichannel messages.
Patch release with security improvements including rate limiting on unauthenticated password reset, SSRF protection in file download, a critical security hotfix, and fixes for special character handling in Omnichannel.
Release 8.7.0 introduces phishing-resistant OAuth authentication, AI-powered semantic search with optional OpenAI integration, FIPS mode support for compliance, offline licensing for air-gapped deployments, persistent audio playback across rooms, and modernizes the REST API by replacing deprecated DDP methods. Additionally includes improved emoji support using native Unicode characters and enhanced admin settings with JSON validation.
Release candidate 8.7.0-rc.6 updates engine versions including Node 22.22.3, Deno 2.3.1, and MongoDB 8.0. Includes dependency updates and bumps to Rocket.Chat Meteor and core typings.
Release candidate update with updated dependencies and bumped Meteor version. Includes updated engine versions: Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.65.1-rc.0.
Release candidate 8.7.0-rc.4 updates engine versions and fixes audio attachments to be seekable using the progress slider, along with dependency updates.
Release candidate 8.7.0-rc.3 with updated engine versions including Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.65.1-rc.0. Includes dependency updates for core-typings and rest-typings packages.
Release candidate 8.7.0-rc.2 includes updated Engine versions (Node 22.22.3, Deno 2.3.1, MongoDB 8.0, Apps-Engine 1.65.1-rc.0) and dependency updates for core-typings and rest-typings packages.
Release candidate update with upgraded engine versions including Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.65.1-rc.0. Dependencies updated for core typings and REST typings.
Rocket.Chat 8.7.0-rc.0 introduces phishing-resistant OAuth authentication, AI search with semantic results, FIPS mode support, persistent audio playback, and multiple REST API endpoints replacing deprecated DDP methods for better security and reliability.
Patch release with security hotfixes and permission checking improvements. Includes fixes for the users.CreateToken endpoint permission validation and consistent room permission checks when converting channels to teams or creating teams from existing rooms.
Patch release with security hotfixes, permission validation improvements for token generation and room conversion endpoints, and updated engine versions including Node 22.16.0, MongoDB 8.0, and Apps-Engine 1.60.1.
Patch release with security hotfixes and permission enforcement improvements. Fixes user token generation permission checks and ensures consistent room permission validation when converting channels to teams.
Patch release with security hotfixes and improved room permission consistency when converting channels to teams. Dependencies updated across multiple packages.
Patch release with security hotfixes, permission validation improvements for token generation and room operations, and dependency updates. Includes updates to Node 22.16.0, Deno 1.43.5, MongoDB 8.2, and multiple Rocket.Chat packages.
Patch release including security hotfixes, permission checking improvements for token generation and room operations, and a TypeScript type correction for FederationLookup in apps. Updates core dependencies and engine versions.
Patch release with security hotfixes and permission checks. Updates include enhanced authorization for token generation and consistent room permission validation for team operations, plus dependency updates for core typings and models.
Patch release with security hotfixes, permission checks for token generation and room operations, and updated dependencies. Engine versions updated to Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.63.0.
Rocket.Chat 8.6.0 delivers security hardening including Virtru ABAC support and token validation improvements, enhanced messaging with voice call popout windows and LibreTranslate, platform extensibility through unified presence sync and new API endpoints, and infrastructure optimizations for faster room loading and search performance.
Version 8.5.0 delivers significant security hardening with stricter access controls and token handling across multiple systems including OAuth, SAML, and file uploads. New features include a Drafts sidebar group, message list virtualization for performance, custom sound REST APIs, improved ABAC administration, and updated runtime to Node.js 22.22.3 and Meteor 3.4.1.
Updated core dependencies including Meteor, core-typings, and rest-typings. Updated engine versions including Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.63.0-rc.0.
Release candidate 8.5.0-rc.5 includes updated dependencies and bumped Meteor version. Engine versions updated to Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.63.0-rc.0.
Release candidate update with bumped Meteor version and updated core typings and REST typings packages. Includes Node 22.22.3, MongoDB 8.0, and Apps-Engine 1.63.0-rc.0.
Release candidate with engine version updates (Node 22.22.3, Deno 2.3.1, MongoDB 8.0) and a fix to the Chat Limits locking mechanism allowing bot agents to skip the lock since they aren't subject to chat limits.
Fixed the Chat Limits locking mechanism to allow bot agents to bypass the lock, since they are not subject to rate limits. Updated engine dependencies including Node 22.16.0 and MongoDB 8.0.
Bumped Meteor version and fixed the Chat Limits locking mechanism to allow bot agents to skip the lock since they are not subject to rate limits. Updated core and REST typings dependencies.
Patch release with dependency updates and a fix to the Chat Limits locking mechanism that now allows bot agents to skip the lock since they aren't subject to rate limits.
Release candidate 8.5.0-rc.2 includes updated Node 22.22.3, Deno 2.3.1, MongoDB 8.0, and Apps-Engine 1.63.0-rc.0 with bumped dependencies for core-typings and rest-typings.
Security and stability patch addressing OAuth token cleanup after user deactivation, login token cleanup for idle users, access validation for message translation endpoints, and visitor token exposure. Multiple internal dependencies updated.
39 more changes from Rocket.Chat. Sign up to read the whole changelog.
Sign up freeGitHub or email — no card needed.