What payloadcms/payload shipped
Generated by FoxPlug from public activity — not affiliated with Payloadcms.
Week of September 14, 2026
What shipped
- v3.90.0 released with critical security fixes that warrant immediate upgrade regardless of specific affected features. Release
- v3.90.1 released fixing a bug where parent collection's where queries were incorrectly applied to nested relationship fields. Release
- High-severity audit vulnerabilities affecting consumers resolved through direct dependency version bumps in published packages. Pull request #18158
- High-severity audit advisories addressed with direct bumps and peer-range adjustments across the monorepo. Pull request #18159
- Vitest updated to 5.0.0 and Playwright to 1.63.0 with E2E helpers migrated to newer Playwright APIs. Pull request #18096
- Turbo server fast refresh re-enabled for Next.js dev server following fixes in Next.js 16.3 release. Pull request #18187
- Templates regenerated with correct sharp versions and migrations for v3.90.0 to ensure 1-click deploys get current dependencies. Pull request #18209
- CI runner memory limits standardized for memory-heavy steps and job token permissions scoped to least-privilege defaults. Pull request #18211
- V3 telemetry backported from V4 with relevant metrics excluded to match V3 feature set. Pull request #18133
Why it matters
Critical security patches in v3.90.0 and v3.90.1 require immediate attention from users running v3. Access control fixes for nested relationships and dependency vulnerability resolutions improve stability and safety across all installations.
Changelog entry
- 🔒 v3.90.0: Critical security fixes included in this release Release
- 🐛 v3.90.1: Fixed parent where queries incorrectly carrying into nested relationship fields Release
- 🔒 Resolved consumer-facing high-severity audit vulnerabilities through direct dependency bumps Pull request #18158
- 🔒 Resolved high-severity audit advisories with direct version bumps and peer-range adjustments Pull request #18159
- 🧪 Updated Vitest to 5.0.0 and Playwright to 1.63.0 with migrated E2E helper APIs Pull request #18096
- ⚡ Re-enabled turborepoServerFastRefresh for Next.js dev server following Next.js 16.3 improvements Pull request #18187
- 📦 Regenerated templates with correct sharp versions and migrations for accurate deployments Pull request #18209
- 🔧 Standardized Node heap limits and scoped job token permissions in CI configuration Pull request #18211
- 📊 Backported V4 telemetry to V3 with excluded metrics irrelevant to V3 feature set Pull request #18133
v3.90.0 and v3.90.1 released with critical security fixes. Upgrade immediately. Also: nested relationship access control fix, dependency vulnerabilities resolved, Vitest 5.0.0, Playwright 1.63.0.
Payload v3.90.0 and v3.90.1 are now available with critical security fixes that require immediate upgrade. This release addresses high-severity vulnerabilities in consumer-facing dependencies, fixes access control behavior for nested relationship queries, and updates testing infrastructure with Vitest 5.0.0 and Playwright 1.63.0. All users are encouraged to upgrade promptly.