fix(deps): update dependency @strapi/strapi to v5 [security] #119
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.25.13->^5.0.0GitHub Vulnerability Alerts
CVE-2025-3930
Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). The existence of /admin/renew-token endpoint allows anyone to renew near-expiration tokens indefinitely, further increasing the impact of this attack. This issue has been fixed in version 5.24.1.
Release Notes
strapi/strapi (@strapi/strapi)
v5.24.2Compare Source
Strapi was made aware of a vulnerably that were patched in this release, for now we are going to delay the detailed disclosure of the exact details on how to exploit it and how it was patched to give time for users to upgrade before we do public disclosure.
5.24.2 (2025-09-29)
🚀 New feature
🔥 Bug fix
❤️ Thank You
This release fundamentally changes how Admin Panel login and register JWTs work from 5.23.6.
If your project or plugins rely on undocumented functionality or internal behavior related to the Admin JWT, those implementations are very likely to break after upgrading and affect your ability to log in to the Strapi Admin Panel.
For more information on the new feature configuration settings, please see the configuration docs for Users and Permissions and Admin Panel
v5.24.1Compare Source
5.24.1 (2025-09-25)
includes release notes from deprecated 5.24.0
🚀 New feature
🔥 Bug fix
❤️ Thank You
This release does not introduce breaking changes in any documented Strapi APIs or functions.
However, it fundamentally changes how Admin Panel login and register JWTs work.
If your project or plugins rely on undocumented functionality or internal behavior related to the Admin JWT, those implementations are very likely to break after upgrading and affect your ability to log in to the Strapi Admin Panel.
For more information on the new feature configuration settings, please see the configuration docs for Users and Permissions and Admin Panel
v5.24.0: [Deprecated] v5.24.0Compare Source
5.24.0 (2025-09-24)
🚀 New feature
🔥 Bug fix
❤️ Thank You
This release does not introduce breaking changes in any documented Strapi APIs or functions.
However, it fundamentally changes how Admin Panel login and register JWTs work.
If your project or plugins rely on undocumented functionality or internal behavior related to the Admin JWT, those implementations are very likely to break after upgrading and affect your ability to log in to the Strapi Admin Panel.
For more information on the new feature configuration settings, please see the configuration docs for Users and Permissions and Admin Panel
v5.23.6Compare Source
5.23.6 (2025-09-19)
🔥 Bug fix
❤️ Thank You
v5.23.5Compare Source
5.23.5 (2025-09-17)
🔥 Bug fix
💅 Enhancement
🚨 Security
❤️ Thank You
v5.23.4Compare Source
5.23.4 (2025-09-10)
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.23.3Compare Source
5.23.3 (2025-09-04)
🔥 Bug fix
❤️ Thank You
v5.23.2Compare Source
5.23.2 (2025-09-03)
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.23.1Compare Source
5.23.1 (2025-08-27)
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.23.0Compare Source
5.23.0 (2025-08-20)
🚀 New feature
🔥 Bug fix
💅 Enhancement
❤️ Thank You
v5.22.0Compare Source
5.22.0 (2025-08-13)
🚀 New feature
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.21.0Compare Source
5.21.0 (2025-08-06)
🚀 New feature
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.20.0Compare Source
Strapi was made aware of a vulnerably that were patched in this release, for now we are going to delay the detailed disclosure of the exact details on how to exploit it and how it was patched to give time for users to upgrade before we do public disclosure.
5.20.0 (2025-07-30)
🚀 New feature
🔥 Bug fix
⚙️ Chore
💅 Enhancement
❤️ Thank You
v5.19.0Compare Source
5.19.0 (2025-07-23)
🚀 New feature
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.18.1Compare Source
5.18.1 (2025-07-16)
🚀 New feature
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.18.0Compare Source
5.18.0 (2025-07-09)
🚀 New feature
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.17.0Compare Source
5.17.0 (2025-07-02)
🚀 New feature
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.16.1Compare Source
5.16.1 (2025-06-25)
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.16.0Compare Source
5.16.0 (2025-06-17)
🚀 New feature
🔥 Bug fix
⚙️ Chore
💅 Enhancement
🚨 Security
❤️ Thank You
v5.15.1Compare Source
5.15.1 (2025-06-11)
🔥 Bug fix
⚙️ Chore
💅 Enhancement
❤️ Thank You
v5.15.0Compare Source
5.15.0 (2025-06-04)
🚀 New feature
🔥 Bug fix
⚙️ Chore
🚨 Security
❤️ Thank You
v5.14.0Compare Source
Changelog for releases/5.14.0
🚀 Feature
Revamp the Content-Type Builder (CTB) with undo/redo, drag & drop attributes, collapsible sections, concurrent editing, new shortcuts, and numerous UX/UI enhancements (#23288) by @alexandrebodin
✨ Enhancements
🐛 Bug Fixes
⚙️ Chores
image-sizepackage dependency within the documentation (#23564) by @Marc-Roig❤️ Thank You
v5.13.1Compare Source
5.13.1 (2025-05-21)
🔥 Bug fix
📚 Documentation Changes
❤️ Thank You
v5.13.0Compare Source
5.13.0 (2025-05-07)
🚀 New feature
🔥 Bug fix
data-transferCLI (#23422)📚 Documentation Changes
⚙️ Chore
💅 Enhancement
❤️ Thank You
v5.12.7Compare Source
5.12.7 (2025-04-30)
🔥 Bug fix
data-transferCLI (#23422)⚙️ Chore
❤️ Thank You
v5.12.6Compare Source
5.12.6 (2025-04-23)
🔥 Bug fix
⚙️ Chore
❤️ Thank You
v5.12.5Compare Source
5.12.5 (2025-04-16)
🔥 Bug fix
⚙️ Chore
💅 Enhancement
❤️ Thank You
v5.12.4Compare Source
5.12.4 (2025-04-09)
🔥 Bug fix
⚙️ Chore
💅 Enhancement
❤️ Thank You
v5.12.3Compare Source
5.12.3 (2025-04-02)
🔥 Bug fix
❤️ Thank You
v5.12.2Compare Source
5.12.2 (2025-04-02)
🔥 Bug fix
⚙️ Chore
💅 Enhancement
❤️ Thank You
v5.12.1Compare Source
5.12.1 (2025-03-28)
🔥 Hotfix
❤️ Thank You
v5.12.0Compare Source
5.12.0 (2025-03-26)
🚀 New feature
🔥 Bug fix
📚 Documentation Changes
⚙️ Chore
💅 Enhancement
🚨 Security
❤️ Thank You
[
v5.11.3]Configuration
📅 Schedule: Branch creation - "" in timezone America/Vancouver, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
Thanks for the PR!
Deployments, as required, will be available below:
Please create PRs in draft mode. Mark as ready to enable:
After merge, new images are deployed in: