v2.20.12

mealie-recipes/mealiev2.20.12Mar 20, 2026by github-actions[bot]

AI Summary

A security-focused update that addresses a vulnerability and fixes workflow saving, file handling logic, and API specification issues.

Key Highlights

  • Addresses a security issue (GHSA-96jx-fj7m-qh6x) recommended for all users.
  • Fixes workflow saves to prevent clobbering filename/archive_filename.
  • Fixes file movement logic to avoid attempting to move files already moved.
  • Removes pagination from document notes API spec.
  • Restricts basic auth to appropriate requests for better security.

Full Release Notes

## paperless-ngx 2.20.12

> [!NOTE]
> This release addresses a security issue (GHSA-96jx-fj7m-qh6x) and is recommended for all users. Our sincere thank you to the community members who reported this.

### Bug Fixes

- Fix:  Scope the workflow saves to prevent clobbering filename/archive\_filename @stumpylog ([#12390](https://github.com/paperless-ngx/paperless-ngx/pull/12390))
- Fix: don't try to usermod/groupmod when non-root + update docs (#<!---->12365) @stumpylog ([#12391](https://github.com/paperless-ngx/paperless-ngx/pull/12391))
- Fix: avoid moving files if already moved @shamoon ([#12389](https://github.com/paperless-ngx/paperless-ngx/pull/12389))
- Fix: remove pagination from document notes api spec @shamoon ([#12388](https://github.com/paperless-ngx/paperless-ngx/pull/12388))
- Fix: fix file button hover color in dark mode @shamoon ([#12367](https://github.com/paperless-ngx/paperless-ngx/pull/12367))
- Fixhancement: only offer basic auth for appropriate requests @shamoon ([#12362](https://github.com/paperless-ngx/paperless-ngx/pull/12362))

### All App Changes

<details>
<summary>5 changes</summary>

- Fix:  Scope the workflow saves to prevent clobbering filename/archive\_filename @stumpylog ([#12390](https://github.com/paperless-ngx/paperless-ngx/pull/12390))
- Fix: avoid moving files if already moved @shamoon ([#12389](https://github.com/paperless-ngx/paperless-ngx/pull/12389))
- Fix: remove pagination from document notes api spec @shamoon ([#12388](https://github.com/paperless-ngx/paperless-ngx/pull/12388))
- Fix: fix file button hover color in dark mode @shamoon ([#12367](https://github.com/paperless-ngx/paperless-ngx/pull/12367))
- Fixhancement: only offer basic auth for appropriate requests @shamoon ([#12362](https://github.com/paperless-ngx/paperless-ngx/pull/12362))
</details>