v0.16.14
achtungsoftware/alarikv0.16.14Jul 20, 2026by github-actions[bot]
AI Summary
This release introduces VAPID support for JMAP Web Push and addresses numerous bugs across IMAP, JMAP, CalDAV, MTA, and HTTP modules, including quota enforcement and push subscription handling.
Key Highlights
- Added VAPID support for JMAP Web Push (RFC 9749)
- Fixed IMAP mailbox object-quota enforcement in JMAP
- Fixed JMAP push subscription verification and payload encoding issues
- Fixed CalDAV calendar-query REPORT returning empty data for JMAP events
- Fixed MTA DMARC handling when SPF is unavailable
New Features
- VAPID support for JMAP Web Push
Full Release Notes
## [0.16.14] - 2026-07-20 If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions. ## Added - Use of Voluntary Application Server Identification (VAPID) in JMAP Web Push ([RFC 9749](https://datatracker.ietf.org/doc/html/rfc9749)). ## Changed ## Fixed - IMAP: - Mailbox object-quota only enforced in JMAP. - Pipelined `STORE` and `EXPUNGE` can execute out of order. - JMAP: - Read-only sharee cannot set `isSubscribed` on a shared mailbox. - Web Push payloads with `Content-Encoding: aes128gcm` should not be base64-encoded but sent as raw bytes. - Stale push subscription can block verification of a new one. - `PushSubscription/set` rejects the unpadded base64url keys the W3C Push API produces. - `Email/import` does not send push notifications for imported messages. - `CalendarEvent/set` silently ignores `ifInState`. - CalDAV: `calendar-query` REPORT returns empty calendar-data for JMAP-created events. - MTA: - DMARC is skipped when MAIL FROM SPF is unavailable. - `queue_name` variable not available in rate limiter expressions. - Calendar: - No expanded occurrences are returned for a daily recurrences crossing DST. - Uppercase `MAILTO` calendar addresses become invalid SMTP recipients. - Scheduling invitations on a shared, non-owned calendar fail with `MAIL FROM unauthorized`. - HTTP: Disable `allowedEndpoints` expression in recovery mode. - Telemetry: Tasks are serialized to the wrong store when using separate stores for telemetry and data. <hr /> ### Check binary attestation [here](https://github.com/stalwartlabs/stalwart/attestations/36162381)