v3.1.0
fosrl/pangolinv3.1.0Apr 16, 2026by mikecao
AI Summary
Pangolin v3.1.0 brings a major UI overhaul with custom Boards, Session Replay, and Web Vitals tracking, alongside improved filters, segments, and a redesigned share page.
Key Highlights
- Boards for custom dashboards with flexible layouts and component binding
- Session Replay for real user monitoring with configurable privacy masking
- Web Vitals performance tracking (LCP, INP, CLS, etc.)
- Redesigned share page with mobile support and per-share display options
New Features
- Boards with row/column layout editor and live preview
- Session Replay with per-visit recording and event-level filtering
- Web Vitals performance tracking with rating badges
- Redesigned share page with collapsible sidenav
- Filters and segments with OR logic and Regex operators
- Funnels with per-step event property filters
- Custom slug support for Links
- Pixel and Link detail pages with sharing
- MetricsBar on Events page
- Time unit selector (hour/day/month)
- Distinct ID as a filter and metric dimension
- Cache-control headers on GET responses
- SKIP_BUILD_GEO env variable
- Configurable salt rotation period
- Team validation and redirect for invalid teams
Full Release Notes
Umami `v3.1.0` is here with a ton of new features, including the much-anticipated **Boards** and **Session Replay**. This release also brings Web Vitals performance tracking, a redesigned share page, and hundreds of fixes and improvements. ## New features ### Boards <img width="2048" height="1088" alt="image" src="https://github.com/user-attachments/assets/92f55a0b-96ca-4084-af5c-7dfb5f7805b1" /> Boards are here! Create your own custom dashboards by composing components on a flexible row/column canvas. Pick from charts, tables, and metric components, bind them to any website, and share the finished board with your team. - Row/column layout editor with resize, reorder, and remove controls - Per-component website binding and live preview - Free-form `TextBlock` components for notes and section headers - Board sharing, duplication, and table-level edit/delete actions - Dashboard-wide date range and filter controls ### Session Replay <img alt="image" src="https://github.com/user-attachments/assets/0b66c0d4-b0f6-4529-8e5e-95bad76fcc03" /> Watch real user sessions replayed in the browser. Session Replay is built on [rrweb](https://www.rrweb.io/) and works alongside your existing tracker. - Configurable masking levels for privacy (defaults to *moderate*) - Per-visit recording so replays stay short and focused - Filterable replays table with event-level filtering - Replay modal with mobile-friendly playback ### Web Vitals performance tracking <img alt="image" src="https://github.com/user-attachments/assets/afe6f5a2-8b3c-42cf-926a-3c3b42a8eb63" /> Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from your visitors' browsers. The redesigned Performance page shows industry-standard calculations with rating badges for each metric. ### Redesigned share page <img width="400" alt="image" src="https://github.com/user-attachments/assets/589983c5-5e63-447f-add2-3dfadf831d7f" /> Share pages have a fresh look with full mobile support, a collapsible sidenav, and per-share display options. You can now: - Name each share link - Choose which sections visitors can see (overview, events, etc.) - Apply filtered navigation so visitors only see what you want ### Filters, segments, and cohorts - **OR logic** across filters, segments, and cohorts - **Regex operators** for more powerful matching - **Multiselect** on equals/not-equals operators - UTM filters and fields exposed throughout the app - **Exclude bounces** toggle with filter-form integration ### Funnels - Per-step event property filters in both funnel creation and overview - Wildcard support in the goals report ### Other improvements - Custom slug support for Links - Pixel and Link detail pages with sharing - `MetricsBar` added to the Events page - Event type filter on Journeys - Time unit selector (hour/day/month) - Distinct ID available as a filter and metric dimension - Cache-control headers on `GET` responses - `SKIP_BUILD_GEO` env variable to skip geo DB build - Configurable salt rotation period via env vars - EdgeOne geolocation headers - Version endpoint and settings display - Download for breakdown reports - Pagination limit on event charts, metrics tables, and UTM reports ### Admin & internationalization - Migrated from `react-intl` to `next-intl` with all 51 locale files translated - Adopted the [`react-zen`](https://zen.umami.is) design system across the app - Consolidated top navigation with embedded selectors for websites, boards, links, and pixels - Team validation and redirect for invalid teams - Team-gated feature resolution via Redis ## Security - Fixed IDOR vulnerabilities in reports and segments - Blocked share tokens from all editing permissions and API modifications - Restricted `x-umami-client-*` headers to cloud mode - Various dependency vulnerability fixes (tar, ajv, jws, brace-expansion, next) ## Migrations This release includes schema migrations for Boards, Shares, Session Replay, and board duplicate-key handling. Migrations run automatically during the build process. ## Fixes - PostgreSQL 12/13 syntax error in Journeys #3970 - Implicit alias syntax error in Postgres session and event queries #4147 - `name` alias compatibility for Postgres 12 relational queries #3970 - Table alias missing in `filterQuery` #3869 - Timezone not applied to relational queries #3975 - Revenue chart timezone mismatch #4107 - Ambiguous `session_id` errors in SQL queries - Breakdown alias column not found - `www.` prefix not stripped during hostname comparison #3256 - Minute label formatting #3088 - Website select page size limited to 10 #3913 - Deleted website visibility #3865 - `BASE_PATH` support #4064 - Pixel event tracking #4028 - Pagination issues #4029 - Login email case-sensitivity #3981 - Tracker double-initialization when script injected more than once - Tracker fetch priority now set to low #3642 - `robots.txt` fixes #3996 - Goals wildcard support #4086 - MetricsBar on Events page #3830 - Distinct ID in filters / expanded metrics #3861 - Team admin workflow for team members #2767 - Event type filter for Journeys #2803 - Salt rotation configurable via env #3427 - Share token allowing access to pages with undefined share params - Fix #4058 (pixel tracking null referrer) - Autofill background color in forms - Denied storage access in tracker - Prisma session race condition - Docker Prisma migrate and stray query log - Monthly truncation timezone issue - Share page retention and logo margins - Filters persisting across website change - "All time" filter on websites with no data - Japanese translation for "breakdown" label - UAE emirate names in `iso-3166-2.json` - IPv6 handling for client IP detection - Numerous mobile UI fixes across admin, nav, share, and team screens ## Updates - Next.js `16.2.4` - Prisma `7.6.0` - Minimum Node.js version bumped to `22` (Prisma 7 requirement) ## Thanks @Yashh56 @boutterudy @AymanAlSuleihi @juanisidoro @cryst-hq @RaenonX @PaiJi @Gouttfi @AlejandroGispert @lawrence3699 @kkhys @journry789 @sputnik-mac @sbozh @Mintimate @Mravuri96 @maphubs @maennenajere @XahidEx @IndraGunawan @GochoMugo @FEgor04 @Nayrode @diogotcorreia @dyanakiev @fauzora @BrentRobert @hilja