From c24eb2e1c3fed8559db4b66fc2761b0491da03fe Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Fri, 31 Jul 2026 15:52:45 +0000 Subject: [PATCH 01/11] chore: generate changelog for 6.6.0 --- docs/release-notes/6.6.0/changelog.ai.txt | 8 +++ docs/release-notes/6.6.0/changelog.mdx | 61 ++++++++++++++++++++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 61 ++++++++++++++++++++++ 3 files changed, 130 insertions(+) create mode 100644 docs/release-notes/6.6.0/changelog.ai.txt create mode 100644 docs/release-notes/6.6.0/changelog.mdx create mode 100644 docs/release-notes/6.6.0/upgrade-guide.mdx diff --git a/docs/release-notes/6.6.0/changelog.ai.txt b/docs/release-notes/6.6.0/changelog.ai.txt new file mode 100644 index 000000000..0b064480f --- /dev/null +++ b/docs/release-notes/6.6.0/changelog.ai.txt @@ -0,0 +1,8 @@ +AI Context: 6.6.0 Changelog (changelog.mdx) + +This file tracks manual edits made after the generation script ran. +The script reads the "Skipped PRs" section to avoid re-adding removed entries. + +## Skipped PRs + +## Manual Rewrites diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx new file mode 100644 index 000000000..c914ce028 --- /dev/null +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -0,0 +1,61 @@ +--- +id: olwgge93 +title: Webiny 6.6.0 Changelog +description: See what's new in Webiny version 6.6.0 +--- + +import { GithubRelease } from "@/components/GithubRelease"; +import { Alert } from "@/components/Alert"; + + + +## Development + +### Self-Hosted Webiny with Built-In Authentication ([#5368](https://github.com/webiny/webiny-js/pull/5368), [#5367](https://github.com/webiny/webiny-js/pull/5367), [#5374](https://github.com/webiny/webiny-js/pull/5374), [#5393](https://github.com/webiny/webiny-js/pull/5393)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Webiny can now run entirely on your own infrastructure without AWS, Pulumi, or an external authentication service. The new self-hosted flavour uses a plain Node HTTP server backed by SQL/SQLite, with a dedicated `webiny-server` CLI separate from the AWS-focused `webiny` CLI. + +Key capabilities: + +- **Built-in username/password authentication** — a first-party identity provider with a login screen matching the Cognito UI, JWT-based sessions, and scrypt password hashing. Configure it entirely from `webiny.config.tsx` via ``. +- **`webiny-server serve`** — runs built apps as long-running servers: `serve api` boots the API, `serve admin` statically serves the admin SPA with proper client-side routing, and `serve` runs both. +- **`webiny-server watch api`** — boots the API automatically alongside build watchers, with cleaner output and automatic reload on changes. +- **WebSocket support** — real-time features now work on self-hosted deployments just as they do on AWS. +- **Config-driven admin API URL** — `` tells the admin where the API lives, falling back to same-origin for deployed self-hosted setups. + +The AWS flavour's behaviour is unchanged. + +### TypeScript 7 Compatibility ([#5380](https://github.com/webiny/webiny-js/pull/5380)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +The build tooling has been updated for TypeScript 7, which removed the programmatic compiler API. The new approach shells out to the native `tsc` binary with proper cross-platform support (Windows long paths, ARM64 macOS). Several deprecated compiler options were also removed from the root config. + +### Testable API Handler Composition ([#5361](https://github.com/webiny/webiny-js/pull/5361)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +The code that assembles Webiny's API Lambda used to live in a project template that could only be verified by a full deploy. This wiring now lives in real packages (`@webiny/api-infra-aws`, `@webiny/api-infra-aws-ddb`, `@webiny/api-infra-aws-ddb-os`) with an automated integration test that boots the entire handler against an in-process DynamoDB. This catches composition and registration-order bugs before deploy. + +## Headless CMS + +### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +The CMS storage layer was restructured for better maintainability. Each of the 22 entry storage operations (create, update, publish, list, etc.) is now an independent abstraction registered via dependency injection, replacing a monolithic interface that bundled all operations together. This is an internal architecture improvement with no change to API behaviour. + +### Platform-Agnostic Search Index Tasks ([#5487](https://github.com/webiny/webiny-js/pull/5487), [#5450](https://github.com/webiny/webiny-js/pull/5450), [#5431](https://github.com/webiny/webiny-js/pull/5431)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +Search index task handling has been restructured to support multiple database backends. The code previously tied to DynamoDB + OpenSearch has been split into base abstractions (`api-search-index`) with dedicated implementations for OpenSearch (`api-search-index-os`) and DynamoDB + OpenSearch (`api-search-index-ddb-os`). This enables the upcoming Postgres + OpenSearch support. + +## Infrastructure + +### Replaced Vulnerable `decompress` Library ([#5521](https://github.com/webiny/webiny-js/pull/5521)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +The unmaintained `decompress` package (last published 2018) has been replaced with `adm-zip`, which is actively maintained, has zero dependencies, and includes built-in zip-slip protection against path traversal attacks. + +### Unified Event Handler Architecture ([#5359](https://github.com/webiny/webiny-js/pull/5359), [#5360](https://github.com/webiny/webiny-js/pull/5360)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +The AWS Lambda and self-hosted server request handlers previously maintained nearly identical copies of the same request loop. These are now unified into a single shared implementation with transport-specific pieces isolated behind a `Transport` abstraction. This is an internal cleanup with no change to application behaviour. diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx new file mode 100644 index 000000000..2c87d0435 --- /dev/null +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -0,0 +1,61 @@ +--- +id: kfoim6pl +title: Upgrade from 6.4.x to 6.6.0 +description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. +--- + +import { Alert } from "@/components/Alert"; +import { AdditionalNotes } from "@/components/upgrade/AdditionalNotes"; + + + +- how to upgrade Webiny from 6.4.x to 6.6.0 + + + + + +Make sure to check out the [6.6.0 changelog](./changelog) to get familiar with the changes introduced in this release. + + + +## Step-by-Step Guide + +### 1. Upgrade Webiny Packages + +Upgrade all Webiny packages by running the following command: + +```bash +yarn webiny upgrade 6.6.0 --debug +``` + +Note that the command above will run upgrades for all available versions of Webiny up to 6.6.0. If there are upgrades for 6.4.1, 6.4.5, they will be ran. + +You can omit the version to upgrade to the latest available: + +```bash +yarn webiny upgrade --debug +``` + +Once the upgrade has finished, running the `yarn webiny --version` command in your terminal should return **6.6.0**. + + + +If the above command fails or is not available in your setup, you can run the upgrade script directly via `npx`: + +```bash +npx https://github.com/webiny/webiny-upgrades-v6 6.6.0 --debug +``` + + + +### 2. Deploy Your Project + +Proceed by redeploying your Webiny project: + +```bash +# Execute in your project root. +yarn webiny deploy --env {environment} +``` + + From 6d92f6fbf1a851c66e67bad82d8104b3c8573b88 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Tue, 15 Sep 2026 14:19:53 +0000 Subject: [PATCH 02/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 2c87d0435..160914786 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: kfoim6pl +id: 7uc753po title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From e40f4cc118235d93688901580ddc105fc9139fad Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Tue, 15 Sep 2026 21:26:31 +0000 Subject: [PATCH 03/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 81 ++++++++++++++++++++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 82 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index c914ce028..68788389c 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -36,6 +36,29 @@ The build tooling has been updated for TypeScript 7, which removed the programma The code that assembles Webiny's API Lambda used to live in a project template that could only be verified by a full deploy. This wiring now lives in real packages (`@webiny/api-infra-aws`, `@webiny/api-infra-aws-ddb`, `@webiny/api-infra-aws-ddb-os`) with an automated integration test that boots the entire handler against an in-process DynamoDB. This catches composition and registration-order bugs before deploy. +### Remote Components Feature Flag ([#5559](https://github.com/webiny/webiny-js/pull/5559)) +{/* REVIEW-PENDING @Pavel910 — confirm this entry, then delete this line */} + +Remote Components is a new enterprise feature that allows you to create, edit, and bundle React components directly from the Admin UI, then load and render them in a Next.js frontend at runtime. The feature includes a Monaco editor with live sandbox preview, AI-powered component generation, and a Next.js runtime loader. + +The `remoteComponents` feature flag gates the entire extension. When disabled, no GraphQL schema is registered and no admin UI is mounted. + +### Dependency-Aware Build Cache Now Default ([#5430](https://github.com/webiny/webiny-js/pull/5430)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +The experimental dependency-aware build cache is now the default behavior. A plain `yarn build` now automatically rebuilds any changed package plus all packages that depend on it, whether workspace packages or resolved third-party dependencies. The `--rebuild-dependents` flag and `WEBINY_EXPERIMENTAL_DEP_AWARE_CACHE` environment variable have been removed. + + + +The first build after upgrading will be slower as cached hashes are recalculated. Subsequent builds return to normal speed. + + + +### Apollo Client Removed ([#5519](https://github.com/webiny/webiny-js/pull/5519)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +Apollo Client and all related code have been completely removed from the repository. The Admin UI now uses a different GraphQL client internally. + ## Headless CMS ### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) @@ -48,6 +71,27 @@ The CMS storage layer was restructured for better maintainability. Each of the 2 Search index task handling has been restructured to support multiple database backends. The code previously tied to DynamoDB + OpenSearch has been split into base abstractions (`api-search-index`) with dedicated implementations for OpenSearch (`api-search-index-os`) and DynamoDB + OpenSearch (`api-search-index-ddb-os`). This enables the upcoming Postgres + OpenSearch support. +### CMS Entry Collaboration with Threaded Comments ([#5473](https://github.com/webiny/webiny-js/pull/5473)) +{/* REVIEW-PENDING @SvenAlHamad — confirm this entry, then delete this line */} + +You can now add threaded comments to Headless CMS entries, anchored to the entire entry or a specific field. Comments support replies, resolve/reopen states, editing, @mentions, and soft-delete. A new Comments toggle in the entry editor header opens an animated side panel with per-field comment markers. + +Key capabilities: +- Click a field's comment marker to filter the panel to that field's threads +- Copy shareable deep-links to specific threads via "Copy link to thread" +- URL query parameters (`commentThread` / `commentField`) open the panel and scroll to the referenced thread + +### Notifications Inbox for Comments and Workflows ([#5473](https://github.com/webiny/webiny-js/pull/5473)) +{/* REVIEW-PENDING @SvenAlHamad — confirm this entry, then delete this line */} + +A per-user notifications inbox is now available in the Admin UI. A bell icon in the top bar shows an unread badge and opens a slide-in panel with Inbox/Archive tabs, an unread-only filter, and time-grouped notification items. + +Notifications are triggered by: +- **Comments** — when you're @mentioned in a comment or someone replies to your thread +- **Advanced Publishing Workflow** — when your entry is approved or rejected + +Each notification deep-links to the relevant CMS entry and comment thread. + ## Infrastructure ### Replaced Vulnerable `decompress` Library ([#5521](https://github.com/webiny/webiny-js/pull/5521)) @@ -59,3 +103,40 @@ The unmaintained `decompress` package (last published 2018) has been replaced wi {/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} The AWS Lambda and self-hosted server request handlers previously maintained nearly identical copies of the same request loop. These are now unified into a single shared implementation with transport-specific pieces isolated behind a `Transport` abstraction. This is an internal cleanup with no change to application behaviour. + +### Fixed Destroy Failures with GuardDuty Malware Protection ([#5475](https://github.com/webiny/webiny-js/pull/5475)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Destroying a Webiny project failed when a GuardDuty Malware Protection Plan existed (File Manager Threat Detection), because the deploy role lacked EventBridge permissions for GuardDuty-managed rules. The deploy policy now includes the necessary permissions scoped via the `events:ManagedBy` condition key. + +### Fixed SQLite Self-Hosted Builds Failing at Boot ([#5525](https://github.com/webiny/webiny-js/pull/5525)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +SQLite self-hosted deploy artifacts crashed at boot with `Cannot find module 'pg-connection-string'`. The build process incorrectly pruned this package, but it's required by Knex regardless of which database driver you use. + +## Breaking Changes + +### Feature Flags Replace WCP as Primary Feature Availability System ([#5559](https://github.com/webiny/webiny-js/pull/5559)) +{/* REVIEW-PENDING @Pavel910 — confirm this entry, then delete this line */} + +Feature flags are now the primary authority for feature availability, replacing the previous WCP-based system. The license acts as the gate, while configuration in `webiny.config.tsx` acts as the switch within that gate. In the Admin UI, `useFeatureFlags()` replaces `useWcp()`, and `FeatureFlag.CanUse*` components replace `Wcp.CanUse*` components. + +The decision flow is: +1. No license → feature disabled +2. License blocks the flag → feature disabled (config ignored) +3. License allows + config explicitly false → feature disabled +4. License allows + config unset → feature enabled (license is authority) +5. Not license-governed + license exists → config decides + +Use the new `isEnabled("name")` API with dot-path support for checking feature availability: + +```typescript +import { useFeatureFlags } from "webiny/admin"; + +const { isEnabled } = useFeatureFlags(); + +// Check if a feature is enabled +if (isEnabled("aiPowerups.cms.entryGeneration")) { + // Feature is available +} +``` diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 160914786..66fef323e 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: 7uc753po +id: 65ndckua title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From 276873b0d75accaf21d6a6ce62c7134c070fc183 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Wed, 16 Sep 2026 12:05:17 +0000 Subject: [PATCH 04/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 45 ++++++++++++++++++++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 46 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 68788389c..60ba6cdc2 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -59,6 +59,16 @@ The first build after upgrading will be slower as cached hashes are recalculated Apollo Client and all related code have been completely removed from the repository. The Admin UI now uses a different GraphQL client internally. +### Improved Content Drift Detection in Generated Webiny Package ([#5476](https://github.com/webiny/webiny-js/pull/5476)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +The `validate-webiny-package` command now detects when exports are hand-edited directly into the generated `webiny` package instead of following the source `src/exports` folder convention. Previously, edits to already-expected generated files would pass validation but get silently wiped on the next `generate-webiny-package` run. The validation now compares file contents (whitespace-normalized) and fails loudly when drift is detected. + +### Fixed Cypress Tests After TypeScript Upgrade ([#5410](https://github.com/webiny/webiny-js/pull/5410)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +Resolved Cypress test failures introduced by the TypeScript 7 upgrade. + ## Headless CMS ### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) @@ -92,6 +102,16 @@ Notifications are triggered by: Each notification deep-links to the relevant CMS entry and comment thread. +### Extract OpenSearch Sync to a Dedicated Package ([#5413](https://github.com/webiny/webiny-js/pull/5413)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +The OpenSearch synchronization logic has been extracted from the DynamoDB-specific package into its own standalone module. This architectural change enables reuse of the sync mechanism across different storage backends. + +### CMS Bulk Actions Now Support Multiple Deployment Targets ([#5529](https://github.com/webiny/webiny-js/pull/5529)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +CMS bulk actions have been restructured to support both serverless (AWS) and traditional server deployments, following the same pattern used by other Webiny packages. + ## Infrastructure ### Replaced Vulnerable `decompress` Library ([#5521](https://github.com/webiny/webiny-js/pull/5521)) @@ -114,6 +134,31 @@ Destroying a Webiny project failed when a GuardDuty Malware Protection Plan exis SQLite self-hosted deploy artifacts crashed at boot with `Cannot find module 'pg-connection-string'`. The build process incorrectly pruned this package, but it's required by Knex regardless of which database driver you use. +### Background Tasks Split for Multi-Environment Support ([#5370](https://github.com/webiny/webiny-js/pull/5370)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +The background tasks package has been split into `core`, `aws`, and `server` variants, enabling background task functionality across different deployment environments (AWS Lambda and traditional servers). + +### Improved Background Tasks Internal Architecture ([#5382](https://github.com/webiny/webiny-js/pull/5382)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Modernized how background tasks and several related features are wired internally, replacing a legacy plugin mechanism with dependency injection. The GraphQL schema for tasks is now built per-request from the tenant's task models. This is an internal structure improvement with no change to application behavior. + +### Consistent License Refresh Across All Deployment Types ([#5378](https://github.com/webiny/webiny-js/pull/5378)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Reworked where the per-request WCP license refresh runs internally so it applies uniformly across both AWS and self-hosted deployments. + +### Removed the Internal `@webiny/handler-db` Package ([#5399](https://github.com/webiny/webiny-js/pull/5399)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +An obsolete internal package was removed and its remaining pieces folded into `@webiny/db-dynamodb`. The `DynamoDBCoreFeature` is now the standard way to register DynamoDB core functionality. No functional change for end users. + +### Consolidated Internal Test Utilities ([#5379](https://github.com/webiny/webiny-js/pull/5379)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Removed approximately 1400 lines of duplicated test setup code across ~14 internal packages by consolidating shared test mocks, auth decorators, and helpers into a single `@webiny/api-testing` package. + ## Breaking Changes ### Feature Flags Replace WCP as Primary Feature Availability System ([#5559](https://github.com/webiny/webiny-js/pull/5559)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 66fef323e..cbcac4702 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: 65ndckua +id: q61nrow4 title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From d38b33471e95478122d457a4ced442b12c73076f Mon Sep 17 00:00:00 2001 From: Adrian Smijulj Date: Mon, 21 Sep 2026 13:44:57 +0200 Subject: [PATCH 05/11] docs: document Project.BugReporter (#830) Co-authored-by: Claude Opus 5 (1M context) --- .../6.x/reference/extensions/project.ai.txt | 31 ++++++++++++++++ .../6.x/reference/extensions/project.mdx | 36 +++++++++++++++++++ 2 files changed, 67 insertions(+) diff --git a/docs/developer-docs/6.x/reference/extensions/project.ai.txt b/docs/developer-docs/6.x/reference/extensions/project.ai.txt index 84895c0b1..b1de075d5 100644 --- a/docs/developer-docs/6.x/reference/extensions/project.ai.txt +++ b/docs/developer-docs/6.x/reference/extensions/project.ai.txt @@ -22,3 +22,34 @@ Related Documents: Tone Guidelines: - Reference: minimal prose, tables are the content + +--- Project.BugReporter (added when the bug reporter shipped in 6.6.0) --- + +Source of Information: +1. ~/dev/wby-next3/packages/project/src/extensions/BugReporter.tsx — the defineExtension and its params schema +2. ~/dev/wby-next3/packages/bug-reporter/src/api/config/BugReportConfig.ts — defaults, label parsing, canFileDirectly +3. ~/dev/wby-next3/packages/bug-reporter/src/admin/recording/ActionRecorder.ts — what is recorded, MAX_EVENTS +4. webiny/webiny-js#5736 (feature), #5746 (moved here from a BugReporter export on webiny/extensions) + +Key Documentation Decisions: +1. Documented here rather than on its own page. It shipped as `` from a separate + `webiny/extensions` export and briefly had a page of its own; moving it into the Project + namespace made a sibling section the obvious home, and one prop table is better than two that + drift. +2. The conceptual material was compressed rather than dropped. Compose vs filed is two sentences, + and the recorder is one paragraph instead of a seven-row table, which keeps this section in + proportion to Project.FeatureFlags above it. +3. Two bolded gotchas, because both are invisible from the types and both fail quietly or + confusingly: + - filing needs token AND repository, since the props are independently optional + - `process.env.X` must be guarded with `|| ""`; an unset key renders as an object, not undefined, + and fails the params schema mid-build. This bit the feature's own PR. +4. The default repository keeps a warning block. With no configuration a customer's compose URLs + point at webiny/webiny-js carrying their page titles and click timeline. + +Understanding: +- The extension does not enable the reporter. DefaultExtensions already does, in compose mode. +- canFileDirectly requires both token and repository; the repository default applies to compose only. +- A malformed repository throws rather than falling back, hence "fails the report". +- Screenshots need contents write because issues have no attachment API. +- `labels` REPLACES the "bug" default; `reported-in-app` is always appended and not configurable. diff --git a/docs/developer-docs/6.x/reference/extensions/project.mdx b/docs/developer-docs/6.x/reference/extensions/project.mdx index 91440079f..6c2f357d0 100644 --- a/docs/developer-docs/6.x/reference/extensions/project.mdx +++ b/docs/developer-docs/6.x/reference/extensions/project.mdx @@ -84,3 +84,39 @@ Enables or disables Webiny Cloud Platform (WCP) licensed features. lexicalGeneration?: boolean; } ``` + +### Project.BugReporter + +Points the bug reporter at a GitHub repository, so the API files issues itself. + +The bug reporter is enabled in every project already, so this extension is not what turns it on. Without it the reporter runs in **compose mode**: `cmd+shift+b` in the Admin app, describe what broke, and the API returns a prefilled `issues/new` URL that the reporter submits under their own account. No credentials are involved. This switches it to **filed mode**, where the API creates the issue and commits screenshots to a `bug-report-assets` branch. + +| Prop | Type | Required | Description | +| ------------ | -------- | -------- | --------------------------------------------------------------------------------------------- | +| `token` | `string` | No | Personal access token with write access to issues and contents. Omit to stay in compose mode. | +| `repository` | `string` | No | Target repository as `owner/name`. Defaults to `webiny/webiny-js`. | +| `labels` | `string` | No | Comma separated labels applied to every issue. Defaults to `bug`. | + +```tsx webiny.config.tsx + +``` + +**Filing requires both `token` and `repository`.** A token on its own is not enough, and leaves the reporter in compose mode. Filing is the irreversible direction, so the target has to be named explicitly rather than inherited from a default. A value that is not exactly `owner/name` fails the report rather than falling back. + +**Guard every environment variable with `|| ""`.** Reading an unset key off `process.env` while the config renders returns an object rather than `undefined`, which fails the string check and stops the build. + + + +Set `repository` even if you do not want filing. In compose mode it is the repository the prefilled URL points at, and it defaults to `webiny/webiny-js`. A project that configures nothing sends its users to Webiny's issue composer, prefilled with their page titles, URLs and click timeline. + + + +A classic personal access token with the `repo` scope covers filed mode. Write access to **contents** is needed as well as issues, because GitHub's issue API has no attachment endpoint, so screenshots are committed to a branch and linked. Pass the token through a build-time environment variable, never as a literal: the value is serialized into the build artifact. + +Labels are applied on top of `reported-in-app`, which every issue gets and which cannot be turned off. Setting `labels` replaces the `bug` default rather than adding to it, so `labels={"admin"}` produces `admin` and `reported-in-app`. + +Alongside the description, each report carries the environment and a timeline of the last 150 recorded actions: route changes, clicks, field edits, GraphQL operations, anything that returned 4xx or 5xx, `console.error` and `console.warn`, and uncaught exceptions. Field values are never recorded, only the label of the field, and a label is only read from an interactive element, so clicking a table cell records where the click landed rather than what the cell contained. Both rules exist because reports get filed from tenants holding real customer data. From e37557d6fea41ac498c0fe6239c113334f4a9306 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Thu, 24 Sep 2026 20:33:47 +0000 Subject: [PATCH 06/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 18 ++++++++++++++++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 60ba6cdc2..726114c38 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -112,6 +112,24 @@ The OpenSearch synchronization logic has been extracted from the DynamoDB-specif CMS bulk actions have been restructured to support both serverless (AWS) and traditional server deployments, following the same pattern used by other Webiny packages. +### Postgres Storage Operations Research and Design ([#5402](https://github.com/webiny/webiny-js/pull/5402)) +{/* REVIEW-PENDING @brunozoric — confirm this entry, then delete this line */} + +This release includes internal research and design documentation for adding Postgres + OpenSearch storage operations to the Headless CMS. No code changes are included — this is foundational work exploring a hybrid architecture where Postgres serves as the source of truth for writes and point lookups, while OpenSearch handles all search, filter, and sort operations. + +Key architectural decisions documented: + +- Table-per-model structure with shared tables using a tenant column +- System fields stored as real columns, user field values in a single `values` JSONB column +- WAL logical replication for Postgres → OpenSearch synchronisation +- Upsert pattern for CRUD operations + + + +This is research-only — no production code or migration paths are included in this release. + + + ## Infrastructure ### Replaced Vulnerable `decompress` Library ([#5521](https://github.com/webiny/webiny-js/pull/5521)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index cbcac4702..8403d69d1 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: q61nrow4 +id: 3qbdgq2y title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From 7947ce639bdc2cdb0425a8ad969c1f9ca8edf0a1 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Fri, 25 Sep 2026 11:00:01 +0000 Subject: [PATCH 07/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 5 +++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 726114c38..332c644b7 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -130,6 +130,11 @@ This is research-only — no production code or migration paths are included in +### Internal Cleanup of Legacy Setup Code ([#5381](https://github.com/webiny/webiny-js/pull/5381)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Removed leftover internal setup code from File Manager, Record Locking, and folder-level permissions that was no longer in use. This is internal cleanup with no effect on how these features work. + ## Infrastructure ### Replaced Vulnerable `decompress` Library ([#5521](https://github.com/webiny/webiny-js/pull/5521)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 8403d69d1..774502495 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: 3qbdgq2y +id: wjz5d5hg title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From 3a2f14768e55fde1b4a72415a236b129f69eda43 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Mon, 28 Sep 2026 12:13:49 +0000 Subject: [PATCH 08/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 5 +++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 332c644b7..0c981d6e2 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -69,6 +69,11 @@ The `validate-webiny-package` command now detects when exports are hand-edited d Resolved Cypress test failures introduced by the TypeScript 7 upgrade. +### Project Application Server Now Included in All Templates ([#5364](https://github.com/webiny/webiny-js/pull/5364)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Every Webiny project template now ships with a built-in application server located in `/apps/projectServer`. This local server hosts your Admin and Website applications during development. Previously, the server was only available in certain templates — it's now standard across all project types, providing a consistent development experience. + ## Headless CMS ### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 774502495..1cd046d64 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: wjz5d5hg +id: cep237pb title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From ec480b07b4734681f7263c03f20c00acc5a482b4 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Wed, 30 Sep 2026 04:29:31 +0000 Subject: [PATCH 09/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 5 +++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 0c981d6e2..9a462f3a7 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -74,6 +74,11 @@ Resolved Cypress test failures introduced by the TypeScript 7 upgrade. Every Webiny project template now ships with a built-in application server located in `/apps/projectServer`. This local server hosts your Admin and Website applications during development. Previously, the server was only available in certain templates — it's now standard across all project types, providing a consistent development experience. +### Updated Internal Dependencies ([#5377](https://github.com/webiny/webiny-js/pull/5377), [#5372](https://github.com/webiny/webiny-js/pull/5372), [#5363](https://github.com/webiny/webiny-js/pull/5363), [#5362](https://github.com/webiny/webiny-js/pull/5362), [#5355](https://github.com/webiny/webiny-js/pull/5355)) +{/* REVIEW-PENDING @brunozoric @adrians5j — confirm this entry, then delete this line */} + +Various internal dependencies have been updated across the monorepo, including an upgrade of `execa` from v5 to v9 and the `@webiny/di` package to its latest version. These changes are internal and require no action from users. + ## Headless CMS ### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 1cd046d64..59944ea5c 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: cep237pb +id: p9a9plaa title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From f931bfd7271f8c2ad098f10c6542180feb945975 Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Wed, 30 Sep 2026 05:18:52 +0000 Subject: [PATCH 10/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 5 +++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 9a462f3a7..526920d63 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -79,6 +79,11 @@ Every Webiny project template now ships with a built-in application server locat Various internal dependencies have been updated across the monorepo, including an upgrade of `execa` from v5 to v9 and the `@webiny/di` package to its latest version. These changes are internal and require no action from users. +### Fixed Beta Release npm Dist-Tag Strategy ([#5834](https://github.com/webiny/webiny-js/pull/5834)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +Beta releases for specific versions (e.g., 6.6.0) are now published under version-specific dist-tags like `beta-6.6.0` instead of a shared `beta` tag. This prevents version conflicts when multiple release branches have active betas. + ## Headless CMS ### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 59944ea5c..833b594a4 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: p9a9plaa +id: 98h6znfr title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. --- From f29d8dff73a547b22f211133499bf7403191428a Mon Sep 17 00:00:00 2001 From: webiny-bot Date: Wed, 30 Sep 2026 09:06:13 +0000 Subject: [PATCH 11/11] chore: regenerate release notes for 6.6.0 --- docs/release-notes/6.6.0/changelog.mdx | 5 +++++ docs/release-notes/6.6.0/upgrade-guide.mdx | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/release-notes/6.6.0/changelog.mdx b/docs/release-notes/6.6.0/changelog.mdx index 526920d63..d129b5e12 100644 --- a/docs/release-notes/6.6.0/changelog.mdx +++ b/docs/release-notes/6.6.0/changelog.mdx @@ -84,6 +84,11 @@ Various internal dependencies have been updated across the monorepo, including a Beta releases for specific versions (e.g., 6.6.0) are now published under version-specific dist-tags like `beta-6.6.0` instead of a shared `beta` tag. This prevents version conflicts when multiple release branches have active betas. +### Improved Release Process for Patch Versions ([#5841](https://github.com/webiny/webiny-js/pull/5841)) +{/* REVIEW-PENDING @adrians5j — confirm this entry, then delete this line */} + +When publishing patch releases for older version lines (e.g., 6.5.x while 6.6.x is current), the release process now correctly preserves the `latest` npm tag on the newest version. Older-line patches are published under `latest-.` tags instead, and GitHub releases are created without the "latest" marker to avoid confusion. + ## Headless CMS ### Modernised Storage Operations Architecture ([#5490](https://github.com/webiny/webiny-js/pull/5490)) diff --git a/docs/release-notes/6.6.0/upgrade-guide.mdx b/docs/release-notes/6.6.0/upgrade-guide.mdx index 833b594a4..9c315419d 100644 --- a/docs/release-notes/6.6.0/upgrade-guide.mdx +++ b/docs/release-notes/6.6.0/upgrade-guide.mdx @@ -1,5 +1,5 @@ --- -id: 98h6znfr +id: yymljgg6 title: Upgrade from 6.4.x to 6.6.0 description: Learn how to upgrade Webiny from 6.4.x to 6.6.0. ---