2.2.1
d2lang/d22.2.1Mar 10, 2026by louislam
AI Summary
A patch release for uptime-kuma featuring new notification providers, UI fixes, and a critical security patch for Server-side Template Injection (SSTI).
Key Highlights
- New Fluxer notification provider
- Critical security fix for Server-side Template Injection (SSTI)
- Fixed UI styling for Fluxer input
- Removed unused Prometheus metrics (uptime ratio and avg response time)
New Features
- Fluxer notification provider
- SSTI security patch
- UI and metric improvements
Full Release Notes
### 🆕 New Features - #7109 feat: fluxer notification provider (Thanks @letruxux) - #7096 feat: set process.title to uptime-kuma (Thanks @Hill-98) ### 🐞 Bug Fixes - #7121 fix: isParentActive return type to boolean (Thanks @terisikk) - #7110 fix(ui): fix fluxer input styling; make discord input hidden (Thanks @letruxux) - #6915 fix: removal of uptime ratio and avg. response time from prometheus metrics (Thanks @tr4nt0r) - #7101 fix: revert: remove @aws-sdk, @azure packages ### ⬆️ Security Fixes GHSA-v832-4r73-wx5j - Another Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read (fixed in upstream dependency LiquidJS, also see: https://github.com/harttle/liquidjs/security/advisories/GHSA-wmfp-5q7x-987x) ### 🦎 Translation Contributions - #7119 #7099 chore: Translations Update from Weblate (Thanks @aindriu80 @Aluisio @cyril59310 @dodog @fabianovich @krmu @letruxux @maxisimonazzi @MrEddX) ### Others - #7120 #7100 chore: Update dependencies