Repository navigation
fix(deps): update payloadcms monorepo to v3.90.2 - #957
Open
github-actions[bot] wants to merge 1 commit into
Open
github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
March 9, 2026 08:45
d67e489 to
f159c95
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
March 23, 2026 08:58
f159c95 to
318d11b
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
April 6, 2026 09:10
318d11b to
1d3bb89
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
April 13, 2026 09:57
1d3bb89 to
75dba2d
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
April 20, 2026 10:00
75dba2d to
0792264
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
April 27, 2026 10:17
0792264 to
2c5dd0b
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
June 1, 2026 13:38
2c5dd0b to
87caf58
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
June 15, 2026 13:56
87caf58 to
520af65
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
July 6, 2026 12:07
520af65 to
76ed73a
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
July 13, 2026 11:12
76ed73a to
21359ca
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
August 3, 2026 11:23
21359ca to
c8b3171
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
August 10, 2026 09:21
c8b3171 to
579161c
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
August 17, 2026 08:44
579161c to
97988ae
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
September 14, 2026 14:48
97988ae to
2a7b408
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
September 21, 2026 14:54
2a7b408 to
6424523
Compare
github-actions
Bot
force-pushed
the
renovate/payloadcms-monorepo
branch
from
September 28, 2026 16:30
6424523 to
52799ad
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.76.1->3.90.23.76.1->3.90.23.76.1->3.90.23.76.1->3.90.2Release Notes
payloadcms/payload (@payloadcms/db-mongodb)
v3.90.2Compare Source
🐛 Bug Fixes
⚙️ CI
🤝 Contributors
v3.90.1Compare Source
🐛 Bug Fixes
🏡 Chores
🤝 Contributors
v3.90.0Compare Source
These notes only cover the behavior, configuration, and API-surface changes that projects may need to react to when upgrading. Exploit details, attack surface descriptions, and severity are intentionally omitted.
CVE and GHSA identifiers for the underlying issues are published separately.
How to read this document
Every entry has: Affected if you (concrete conditions - if none apply, no action is required), and Action required.
After upgrading:
pnpm payload generate:typesPassword changes now revoke other sessions
Password reset now clears lockouts; forgot-password is throttled
Adds new
resetPasswordRequestedAtfield to user collectionsAction required:
pnpm payload generate:typesScheduled publishing preserves the scheduling user's auth collection
Affected if you:
schedulePublishjobs directly or depend on its generated task types.Action required:
user: { relationTo, value }(value is user ID).Stricter validation for SVG and XML uploads
Affected if you:
Action required:
allowRestrictedFileTypes: truein the collectionsuploadproperty if the previous behavior is explicitly required.Client uploads hardened across all adapters
Affected if you:
clientUploads: true(S3, GCS, Azure, or custom).Action required:
x-goog-if-generation-matchheader to GCS CORS allowed headers.Azure containers default to private
Affected if you:
@payloadcms/storage-azureadapter withallowContainerCreate: trueAction required:
containerAccess: 'blob'in your Azure storage config.Client uploads are stored in a per-upload folder
Affected if you:
clientUploadswith a storage adapter and access stored files outside Payload (for example, by building paths fromprefixandfilename)prefixvalues outside the adapter's collectionprefixWhat changed:
<prefix>/<_objectKey>/<filename>, including generated image sizes._objectKeyis a new field on upload collections. Existing files are not moved.user-123with collection prefixmediais stored undermedia/user-123/.Action required:
_objectKey(when set) between the prefix and filename when building storage paths outside Payload._objectKeycolumn.disablePayloadAccessControlno longer disables safe outbound fetchAffected if you:
disableAccessControl: truein your Payload config.Action required:
upload.skipSafeFetchallowlist for trusted destinationsskipSafeFetch: trueonly when every URL accepted by the collection is trusted.External file fetches require a trusted origin
Affected if you:
upload.disableLocalStorage: trueand rely on Payload fetching relative URLs whose endpoint requires a Payload session cookie.externalFileHeaderFilter, particularly if it assumes it runs only once.Action required:
serverURLor add the exact application origin to your CORS or CSRF configuration.externalFileHeaderFilterand use the optional context when headers need to vary by destination.upload: { externalFileHeaderFilter: (headers, context) => { + if (!context?.isSameOrigin) { + delete headers.cookie + delete headers.authorization + } + return headers }, }Uploaded filename hardening
Affected if you:
Action required:
Multipart uploads are now capped at 50MB by default
Affected if you:
Action required:
requestSizeLimitin your Payload config:upload { + requestSizeLimit: 75 * 1024 * 1024, // Example 75 MiB for the complete multipart request }Form Builder defaults form submission read access to the admin collection
Affected if you:
Action required:
Stricter
wherevalidation for polymorphic joinsPolymorphic joins now apply complete
whereconstraints and throw aQueryErrorwhen a filter is unsupported.Unsupported filters include:
owner.email.near,within,intersects, andalloperators.Affected if you:
collectionreferences multiple collections, andwhereconstraint.baseFilterorbaseListFilterused by folder browsing.Action required:
whereconstraints and read access rules for every collection referenced by a polymorphic join.API keys are no longer readable after initial generation through UI or within Payload operations
If you wish to retain old behavior, set the following in your config:
auth: { - useAPIKey: true, + useAPIKey: { + reveal: true, + }, }Lexical version bump
Full Details
No application changes or data migration are needed when using Payload's built-in rich text features.
If you maintain custom rich text features, check that they still compile and that custom content loads, copies, and pastes correctly. Lexical removed some older APIs, tightened TypeScript types, and changed how custom nodes are loaded and copied. Tests that inspect the editor's HTML may also need updated selectors or snapshots because Lexical adds some internal markup.
Do not install lexical or @lexical/* yourself for use with Payload. Remove any direct dependencies you added for the editor and use Payload's re-exports from
@payloadcms/richtext-lexical/lexicaland@payloadcms/richtext-lexical/lexical/*. Payload supplies the matching versions; mixing versions can break the editor. This is the existing custom feature requirement.v3.89.0Compare Source
🚀 Features
🐛 Bug Fixes
🛠 Refactors
📚 Documentation
improve access defaults for jobs (#17867) (4379bf0)
This backports the v4 jobs access changes to Payload v3.
🤝 Contributors
v3.88.0Compare Source
🐛 Bug Fixes
🛠 Refactors
📝 Templates
🤝 Contributors
v3.87.1Compare Source
🐛 Bug Fixes
📚 Documentation
⚙️ CI
🤝 Contributors
v3.87.0Compare Source
🚀 Features
🐛 Bug Fixes
📚 Documentation
🧪 Tests
⚙️ CI
🏡 Chores
🤝 Contributors
v3.86.0Compare Source
🚀 Features
🐛 Bug Fixes
⚙️ CI
🤝 Contributors
v3.85.2Compare Source
🐛 Bug Fixes
⚙️ CI
🤝 Contributors
v3.85.1Compare Source
🐛 Bug Fixes
⚡ Performance
📚 Documentation
⚙️ CI
🤝 Contributors
v3.85.0Compare Source
🚀 Features
🐛 Bug Fixes
📚 Documentation
📝 Templates
⚙️ CI
🏡 Chores
🤝 Contributors
v3.84.1Compare Source
Retargeting create-payload-app to pull from 3.x branch.
⚙️ CI
🤝 Contributors
v3.84.0Compare Source
🚀 Features
🐛 Bug Fixes
📚 Documentation
🧪 Tests
📝 Templates
⚙️ CI
🏡 Chores
🤝 Contributors
v3.83.0Compare Source
🚀 Features
Expanded Plugin API — New
definePluginhelper introduces opt-in execution ordering, cross-plugin discovery via a slug-keyedpluginsmap, and module augmentation for type-safe plugin options. The existing(config) => configcontract remains unchanged. #16247Profiling Utilities — Lightweight
timeSyncandtimeAsyncwrappers for measuring function execution time during development. Wrap any function to capture its duration, then callprintProfileResultsfor a formatted timing table. Not intended for production use. #16198Internal Plugin Priority & Slug API — Plugins can now attach
priority,slug, andoptionsproperties for execution ordering and cross-plugin discovery. Lower priority runs first; other plugins can find each other by slug viaconfig.pluginswithout imports. Marked@internalfor now. #16244Hidden Slug Field Buttons on Read-Only — The Generate and Lock/Unlock buttons on slug fields are now automatically hidden when the field is read-only, removing controls that serve no purpose in that state. #14824
Agent Flag for CPA (cpa) —
create-payload-appnow supports a--agent/-aflag (claude,codex,cursor) that downloads the Payload coding skill from GitHub and installs it in the correct directory for your agent. A root-levelCLAUDE.mdorAGENTS.mdis written for discoverability. Use--no-agentto skip. #16278UUIDv7 Support (drizzle) — New
idType: 'uuidv7'option for Postgres and SQLite adapters generates time-ordered UUIDs that are friendlier for B-tree indexes than random v4 UUIDs, while using the same storage column type. IDs are generated in application code so older Postgres versions are supported. #16113Custom Email Headers (email-resend) — The Resend adapter now passes custom headers from
sendEmailoptions to the Resend API, enabling features likeList-Unsubscribeheaders that were previously silently dropped. #15645Custom Collection Views (next) — Register custom views at the collection level
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Renovate Bot.