v0.16.14
diffusionstudio/corev0.16.14Jul 20, 2026by github-actions[bot]
AI Summary
This release introduces VAPID support for JMAP Web Push and resolves numerous bugs across IMAP, JMAP, CalDAV, MTA, and Calendar modules.
Key Highlights
- Introduced VAPID support for JMAP Web Push
- Fixed IMAP mailbox quota enforcement and pipelined command ordering
- Resolved JMAP push subscription verification and payload encoding issues
- Fixed CalDAV reporting and Calendar scheduling failures
New Features
- VAPID support for JMAP Web Push
Full Release Notes
## [0.16.14] - 2026-07-20 If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions. ## Added - Use of Voluntary Application Server Identification (VAPID) in JMAP Web Push ([RFC 9749](https://datatracker.ietf.org/doc/html/rfc9749)). ## Changed ## Fixed - IMAP: - Mailbox object-quota only enforced in JMAP. - Pipelined `STORE` and `EXPUNGE` can execute out of order. - JMAP: - Read-only sharee cannot set `isSubscribed` on a shared mailbox. - Web Push payloads with `Content-Encoding: aes128gcm` should not be base64-encoded but sent as raw bytes. - Stale push subscription can block verification of a new one. - `PushSubscription/set` rejects the unpadded base64url keys the W3C Push API produces. - `Email/import` does not send push notifications for imported messages. - `CalendarEvent/set` silently ignores `ifInState`. - CalDAV: `calendar-query` REPORT returns empty calendar-data for JMAP-created events. - MTA: - DMARC is skipped when MAIL FROM SPF is unavailable. - `queue_name` variable not available in rate limiter expressions. - Calendar: - No expanded occurrences are returned for a daily recurrences crossing DST. - Uppercase `MAILTO` calendar addresses become invalid SMTP recipients. - Scheduling invitations on a shared, non-owned calendar fail with `MAIL FROM unauthorized`. - HTTP: Disable `allowedEndpoints` expression in recovery mode. - Telemetry: Tasks are serialized to the wrong store when using separate stores for telemetry and data. <hr /> ### Check binary attestation [here](https://github.com/stalwartlabs/stalwart/attestations/36162381)