fix(deps): update payloadcms monorepo to v3 - #68
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
4 times, most recently
from
February 21, 2025 14:09
e933300 to
c55944d
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
July 29, 2025 23:34
e84830b to
4badad4
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
August 10, 2025 14:49
b866623 to
f298878
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
August 19, 2025 13:42
ac8ee56 to
c3b07df
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
August 28, 2025 16:48
ba24489 to
2c50efc
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
from
August 31, 2025 09:26
2c50efc to
4ab29a5
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
September 10, 2025 22:42
8898b7c to
3f55a2b
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
from
September 17, 2025 17:26
3f55a2b to
3d9f2f9
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
September 30, 2025 18:58
cc96513 to
fcc687d
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
October 8, 2025 04:08
429bdd1 to
eafe103
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
October 23, 2025 16:51
9e9f3d5 to
e3351b8
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
October 31, 2025 04:11
b63e383 to
ef3e00c
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
from
November 3, 2025 19:04
ef3e00c to
d175a20
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
December 19, 2025 21:55
256ee26 to
fbc4ff8
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
January 5, 2026 20:56
fae6910 to
0e4f35f
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
January 19, 2026 15:08
81c17a9 to
2f39d02
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
January 30, 2026 17:40
60570ce to
7b96de4
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
4 times, most recently
from
February 12, 2026 11:45
48eb6f7 to
275f712
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
from
February 19, 2026 08:17
275f712 to
0cc9332
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
March 5, 2026 14:13
9d182e9 to
f727ae7
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
March 16, 2026 17:33
a19a358 to
1cb49c5
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
March 27, 2026 01:04
704a7cd to
8e81e95
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
2 times, most recently
from
April 1, 2026 01:34
de446e3 to
9b73fc1
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
3 times, most recently
from
April 9, 2026 19:08
a38bef4 to
1afb78e
Compare
renovate
Bot
force-pushed
the
renovate/major-payloadcms-monorepo
branch
from
April 16, 2026 11:36
1afb78e to
5f15c29
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.0.0→^3.0.0^0.11.0→^3.0.0^1.0.0→^3.0.0Release Notes
payloadcms/payload (@payloadcms/db-mongodb)
v3.90.0Compare Source
These notes only cover the behavior, configuration, and API-surface changes that projects may need to react to when upgrading. Exploit details, attack surface descriptions, and severity are intentionally omitted.
CVE and GHSA identifiers for the underlying issues are published separately.
How to read this document
Every entry has: Affected if you (concrete conditions - if none apply, no action is required), and Action required.
After upgrading:
pnpm payload generate:typesPassword changes now revoke other sessions
Password reset now clears lockouts; forgot-password is throttled
Adds new
resetPasswordRequestedAtfield to user collectionsAction required:
pnpm payload generate:typesScheduled publishing preserves the scheduling user's auth collection
Affected if you:
schedulePublishjobs directly or depend on its generated task types.Action required:
user: { relationTo, value }(value is user ID).Stricter validation for SVG and XML uploads
Affected if you:
Action required:
allowRestrictedFileTypes: truein the collectionsuploadproperty if the previous behavior is explicitly required.Client uploads hardened across all adapters
Affected if you:
clientUploads: true(S3, GCS, Azure, or custom).Action required:
x-goog-if-generation-matchheader to GCS CORS allowed headers.Azure containers default to private
Affected if you:
@payloadcms/storage-azureadapter withallowContainerCreate: trueAction required:
containerAccess: 'blob'in your Azure storage config.disablePayloadAccessControlno longer disables safe outbound fetchAffected if you:
disableAccessControl: truein your Payload config.Action required:
upload.skipSafeFetchallowlist for trusted destinationsskipSafeFetch: trueonly when every URL accepted by the collection is trusted.External file fetches require a trusted origin
Affected if you:
upload.disableLocalStorage: trueand rely on Payload fetching relative URLs whose endpoint requires a Payload session cookie.externalFileHeaderFilter, particularly if it assumes it runs only once.Action required:
serverURLor add the exact application origin to your CORS or CSRF configuration.externalFileHeaderFilterand use the optional context when headers need to vary by destination.upload: { externalFileHeaderFilter: (headers, context) => { + if (!context?.isSameOrigin) { + delete headers.cookie + delete headers.authorization + } + return headers }, }Uploaded filename hardening
Affected if you:
Action required:
Multipart uploads are now capped at 50MB by default
Affected if you:
Action required:
requestSizeLimitin your Payload config:upload { + requestSizeLimit: 75 * 1024 * 1024, // Example 75 MiB for the complete multipart request }Form Builder defaults form submission read access to the admin collection
Affected if you:
Action required:
Stricter
wherevalidation for polymorphic joinsPolymorphic joins now apply complete
whereconstraints and throw aQueryErrorwhen a filter is unsupported.Unsupported filters include:
owner.email.near,within,intersects, andalloperators.Affected if you:
collectionreferences multiple collections, andwhereconstraint.baseFilterorbaseListFilterused by folder browsing.Action required:
whereconstraints and read access rules for every collection referenced by a polymorphic join.API keys are no longer readable after initial generation through UI or within Payload operations
If you wish to retain old behavior, set the following in your config:
auth: { - useAPIKey: true, + useAPIKey: { + reveal: true, + }, }Lexical version bump
Full Details
No application changes or data migration are needed when using Payload's built-in rich text features.
If you maintain custom rich text features, check that they still compile and that custom content loads, copies, and pastes correctly. Lexical removed some older APIs, tightened TypeScript types, and changed how custom nodes are loaded and copied. Tests that inspect the editor's HTML may also need updated selectors or snapshots because Lexical adds some internal markup.
Do not install lexical or @lexical/* yourself for use with Payload. Remove any direct dependencies you added for the editor and use Payload's re-exports from
@payloadcms/richtext-lexical/lexicaland@payloadcms/richtext-lexical/lexical/*. Payload supplies the matching versions; mixing versions can break the editor. This is the existing custom feature requirement.v3.89.0Compare Source
🚀 Features
🐛 Bug Fixes
🛠 Refactors
📚 Documentation
improve access defaults for jobs (#17867) (4379bf0)
This backports the v4 jobs access changes to Payload v3.
🤝 Contributors
v3.88.0Compare Source
🐛 Bug Fixes
🛠 Refactors
📝 Templates
🤝 Contributors
v3.87.1Compare Source
🐛 Bug Fixes
📚 Documentation
⚙️ CI
🤝 Contributors
v3.87.0Compare Source
🚀 Features
🐛 Bug Fixes
📚 Documentation
🧪 Tests
⚙️ CI
🏡 Chores
🤝 Contributors
v3.86.0Compare Source
🚀 Features
🐛 Bug Fixes
⚙️ CI
🤝 Contributors
v3.85.2Compare Source
🐛 Bug Fixes
⚙️ CI
🤝 Contributors
v3.85.1Compare Source
🐛 Bug Fixes
⚡ Performance
📚 Documentation
⚙️ CI
🤝 Contributors
v3.85.0Compare Source
🚀 Features
🐛 Bug Fixes
📚 Documentation
📝 Templates
⚙️ CI
🏡 Chores
🤝 Contributors
v3.84.1Compare Source
Retargeting create-payload-app to pull from 3.x branch.
⚙️ CI
🤝 Contributors
v3.84.0Compare Source
🚀 Features
🐛 Bug Fixes
📚 Documentation
🧪 Tests
📝 Templates
⚙️ CI
🏡 Chores
🤝 Contributors
v3.83.0Compare Source
🚀 Features
Expanded Plugin API — New
definePluginhelper introduces opt-in execution ordering, cross-plugin discovery via a slug-keyedpluginsmap, and module augmentation for type-safe plugin options. The existing(config) => configcontract remains unchanged. #16247Profiling Utilities — Lightweight
timeSyncandtimeAsyncwrappers for measuring function execution time during development. Wrap any function to capture its duration, then callprintProfileResultsfor a formatted timing table. Not intended for production use. #16198Internal Plugin Priority & Slug API — Plugins can now attach
priority,slug, andoptionsproperties for execution ordering and cross-plugin discovery. Lower priority runs first; other plugins can find each other by slug viaconfig.pluginswithout imports. Marked@internalfor now. #16244Hidden Slug Field Buttons on Read-Only — The Generate and Lock/Unlock buttons on slug fields are now automatically hidden when the field is read-only, removing controls that serve no purpose in that state. #14824
Agent Flag for CPA (cpa) —
create-payload-appnow supports a--agent/-aflag (claude,codex,cursor) that downloads the Payload coding skill from GitHub and installs it in the correct directory for your agent. A root-levelCLAUDE.mdorAGENTS.mdis written for discoverability. Use--no-agentto skip. #16278UUIDv7 Support (drizzle) — New
idType: 'uuidv7'option for Postgres and SQLite adapters generates time-ordered UUIDs that are friendlier for B-tree indexes than random v4 UUIDs, while using the same storage column type. IDs are generated in application code so older Postgres versions are supported. #16113Custom Email Headers (email-resend) — The Resend adapter now passes custom headers from
sendEmailoptions to the Resend API, enabling features likeList-Unsubscribeheaders that were previously silently dropped. #15645Custom Collection Views (next) — Register custom views at the collection level via
admin.components.views[key]with aComponentandpath. Folders take routing precedence over custom views on upload collections. #16243Checkbox Label Clarity (plugin-form-builder) — The form builder checkbox field label was changed from "Default Value" to "Checked by default" to eliminate confusion about whether the checkbox toggles a default value or sets the initial checked state. #15229
Extensible MCP Plugin (plugin-mcp) — External plugins can now extend plugin-mcp by finding it via slug in
config.pluginsand injecting custom MCP tools into its options. Also exports theMCPPluginConfigtype for type-safe tool injection. #16245View Override System for Custom Node Rendering (richtext-lexical) —⚠️ Experimental. Override how any Lexical node type is rendered in the editor via view maps. Supports custom DOM, React components, or HTML strings. Works in both the admin editor and frontend JSX serialization for WYSIWYG consistency. #14244