← Back to all sparks
E

EGroupware

COLLAB
Velocity5.0

Online groupware suite with calendar, contacts, projects and file management

EGroupware's feed has become a security treadmill, with the 23.1 branch days from end of life.

securityself-hostinggroupwareend-of-lifewebauthnopenid
Current state
Almost every release in this window is a security release, and most ship as a pair — one build for 26.x, an identical-scope backport for 23.1. Feature work exists but arrives as single lines inside those security notes: WebAuthN two-factor moving out of the former EPL add-on, OpenID bumped to current upstream libraries, invoice XML gaining reverse-charge exemption codes. The recurring theme in the fixes themselves is authentication — OAuth bearer tokens, OpenID regressions, an inverted email_verified check, passkeys broken by a missing proxy config.
Where it's heading
The project is consolidating everyone onto 26.x and has put a date on it: security coverage for 23.1 ends August 15, 2026, repeated as a warning in every 23.1 build since July. After that the twin-release pattern should stop and the cadence should halve. The authentication stack is the least settled part of the codebase right now — the July and August releases keep re-fixing OpenID and WebAuthN regressions introduced by their own predecessors.
Prediction
Expect 23.1 builds to cease after August 15 and the feed to become single-track 26.x. On the evidence of the last six releases, expect at least one more OpenID or WebAuthN regression fix to follow the recent upstream library bump.

Recent moves

  1. 7d ago

    Security release fixes passkey regression and OAuth token errors

    Another high-severity security release, and again the substance is the authentication stack cleaning up after itself: passkeys had stopped working entirely due to a missing proxy configuration, and OpenID carries further regression fixes from the previous release's upstream bump. Calendar iCal import and timezone-correct notifications round it out.

    View source ↗
  2. 14d ago

    23.1 security release; branch support ends August 15

    The 23.1 backport of the same day's 26.8 security fixes, carrying almost no independent content beyond a repeated end-of-support notice. For anyone still on 23.1 the notice is the release: security coverage ends August 15, 2026.

    View source ↗
  3. 14d ago

    WebAuthN two-factor moves into core, plus security fixes

    The most substantive release in the window, though it takes reading past the security banner to find it. WebAuthN as a second factor — passkeys, Windows Hello, Yubikeys — arrives from the former EPL add-on, meaning a capability that used to sit behind the licensed tier is now in the base product. OpenID moves to current upstream libraries, which is what the following two releases spend their time repairing.

    View source ↗
  4. 25d ago

    Security release repairs merge-print and ImportExport regressions

    A security release that is mostly repair work on the previous security release — merge-print to PDF and ImportExport installation had both been broken by earlier hardening. The OpenIDConnect change tightening unverified email to an explicit opt-in is the one item with a real security posture behind it.

    View source ↗
  5. 25d ago

    23.1 security backport with end-of-support warning

    The 23.1 twin of the same-day 26.7 release, carrying the shared merge-print and unverified-email fixes and dropping the items that only apply to the newer branch. The end-of-support warning appears again, five weeks ahead of the date.

    View source ↗
  6. 1mo ago

    Two more security fixes for the 23.1 branch

    A same-day follow-up to the 23.1 release minutes earlier, covering two further vulnerabilities reported after it shipped. No detail is given beyond the advisory, and the note that this is probably the last 23.1 security release turned out to be premature — three more followed.

    View source ↗