Skip to content

Changelog#

All notable changes to Piler Enterprise Edition, starting from 2.1.0.

The Scanner add-on (ML phishing detection, semantic search, PII detection, categorization) is versioned and released independently of the main application below.

Scanner 1.3.0 - 2026-09-27#

Changed#

  • The ML phishing detector no longer depends on a native runtime library or CGO - it's now a fully static, dependency-free Go binary. This makes the scanner image smaller, faster to build, and easier to deploy across architectures.
  • Retrained the phishing-detection model on a substantially larger and more diverse set of examples. Internal testing shows a meaningful reduction in false positives (legitimate email incorrectly flagged) versus the previous model, with no loss in detection rate.
  • Simplified the scanner's Docker image build to a prebuilt-binary copy, matching the main application image's build process.

2.2.2 - 2026-09-22#

Security#

  • Upgraded grpc and go.opentelemetry.io/otel to address CVE-2026-84304 and related CVEs

Added#

  • Per-message delete action in the preview pane
  • Stable HTML customization hooks (data-* attributes) for MSP frontend integration
  • Multi-node support for user email purge

Changed#

  • piler-ui Docker image build simplified to a prebuilt-binary copy (matches the pattern later applied to the scanner image)
  • Manticore search engine upgraded to 29.9.0
  • Message selection: Ctrl/Cmd+click for single-message selection, Shift+click for range selection

Fixed#

  • Table content clipping in dashboard cards
  • Bogus sort order in multinode search results
  • Regular users seeing 0 search results in multinode mode
  • Timezone validation failing on Alpine runtime images (IANA tzdata now embedded rather than relying on the host OS)
  • Unmounted Vue templates briefly flashing placeholder content (v-cloak)
  • Trailing boundary CRLF in attachment MIME parts incorrectly flagged as invalid
  • False-positive attachment size mismatch logging for base64-encoded attachments
  • S3 promotion window returning an empty 200 instead of 503

2.2.1 - 2026-09-06#

Security#

  • Upgraded nanoid to 3.3.18 to fix CVE-2026-67213 (high severity)

Added#

  • S3_SKIP_EXISTING_OBJECTS to skip re-uploading objects already present across nodes
  • S3_PART_SIZE_MB and S3_DISABLE_MULTIPART knobs for s3uploader
  • purge --restore-id for restoring a specific prior purge run; PACKAGES.md documenting package build/signing

Changed#

  • Dockerfiles upgraded to alpine:3.24; audit log table gained stable CSS identifiers for MSP customization
  • RPM_RELEASE override for RPM packaging; fixed dpkg-sig removal on package updates

Fixed#

  • Fixed a tenant-configuration bug that could cause scheduled purges to be skipped
  • Nested-multipart attachments misindexed in pilerimport; mismatched download objects now caught explicitly
  • Five distinct archiving bugs: duplicate detection, purge tombstone handling, From header overflow, enable_purge flag handling, and an attachment-processing race condition
  • Purge command: tombstone restore, recipient preservation, dry-run loop behavior, missing-env-var warning

2.2.0 - 2026-08-16#

Changed#

  • Semantic search embeddings: replaced in-process ONNX embedding generation with calls to an external, OpenAI-compatible HTTP endpoint (SEMANTIC_SEARCH_ENDPOINT_URL); piler-ui image switched to an Alpine base as a result (no longer needs ONNX Runtime/CGO)

Added#

  • OX (Open-Xchange) webmail integration: theme, language, timezone, and iframe CSS synchronization

Fixed#

  • Session cookie expiry handled incorrectly in some flows; dompurify upgraded alongside the fix
  • Multi-tenant provisioning; tenant GUI URL not hot-reloading after change
  • OAuth2 configs being rebuilt per-request instead of cached in multi-tenant mode
  • Health page's "received messages" chart rendering incorrectly

2.1.5 - 2026-07-26#

Security#

  • grpc bumped to v1.82.1 to fix security vulnerabilities
  • gofiber and golang.org/x/net upgraded (security-motivated)
  • dompurify 3.4.11 → 3.4.12

Added#

  • Pending conversations: badge in search results plus a dedicated drawer for messages awaiting a reply
  • Attachment indexing gated on TIKA_URL being configured, rather than always-on
  • Explicit Dependabot workflow for automated dependency PRs
  • Standby-node support for import jobs; multi-node import handling
  • Theme and accent-color support carried over from EAM authentication

Changed#

  • Build tooling switched from the previous bundler to Vite (and bumped several times through the 6.4→8.1 series as issues were found); iframe session cookie set to SameSite=None for embedding scenarios; listens for a postMessage theme-change event from a parent iframe
  • Import job handling simplified

Fixed#

  • Email direction now computed per-message from the local domain table, rather than a possibly-stale cached value
  • c.IP() captured before entering a goroutine in ZipAndStreamDownloadRemote (was reading a request-scoped value after the request had already returned)
  • Multi-node export; mobile screen layout issues; vendor CSS handling under the Vite build; header parser edge case; several import/migration fixes; purge logging

Dependencies#

  • Routine bumps: vue 3.5.38→3.5.39, postcss 8.5.16→8.5.23, axios 1.18.0→1.18.1, @vitejs/plugin-vue 5.2.4→6.0.7, plus a batch of GitHub Actions version bumps (actions/checkout, actions/setup-go, actions/setup-python, actions/upload-artifact, actions/download-artifact, docker/setup-buildx-action, docker/setup-qemu-action, docker/login-action, docker/metadata-action, softprops/action-gh-release)

2.1.4 - 2026-06-09#

Added#

  • Standalone importer web app (cmd/import UI)
  • ANALYTICS_ENABLED environment variable
  • Rate limiting on authentication endpoints (security hardening)

Changed#

  • All config keys now registered with viper regardless of whether a default is empty, so they can still be overridden via environment variables

Fixed#

  • Microsoft 365 journal processing
  • LDAP authentication edge case
  • Header/footer branding logo display
  • serverId evaluation lacking a safety check
  • Import job responses missing the id field on creation
  • Purge endpoint failing on already-deleted emails
  • Background job SQL queries
  • Extremely long Message-ID/attachment filenames not handled correctly
  • chown command incorrect in package install scripts

Dependencies#

  • gofiber/fiber 2.52.12 → 2.52.13 (main app and contrib/external-jwt-shared-secret)
  • Azure/go-ntlmssp bumped

2.1.3 - 2026-04-09#

Added#

  • SHOW_IMPORT_MENU configuration option
  • NIS2 compliance documentation

Changed#

  • Manticore upgraded to 25.0.0 in tests and the installer

Fixed#

  • Swagger/OpenAPI docs generation

Dependencies#

  • go.opentelemetry.io/otel/sdk 1.40.0 → 1.43.0
  • russellhaering/goxmldsig 1.4.0 → 1.6.0
  • google.golang.org/grpc 1.72.1 → 1.79.3

2.1.2 - 2026-03-15#

The largest release in this window - unified archiving for chat platforms, GDPR right-to-erasure, passkey authentication, multi-master-node HA, and a round of gosec-driven security hardening.

Security#

  • Passkey (WebAuthn) authentication support added
  • gosec static-analysis fixes applied across reindex, imapimport, pilerimport, and s3uploader
  • TLS support added for the MySQL connection
  • Added additional iframe-embedding security headers
  • Sensitive SIEM connection details no longer appear in logs

Added#

  • Slack and Microsoft Teams collectors: initial unified-archiving support for chat platforms, including a parallelized Slack collector and dedicated UI/API components
  • GDPR Right to Erasure: multi-node-aware implementation
  • Find similar messages: KNN vector search over message embeddings
  • Multi-master-node support (previously single-master architecture)
  • IMAP import checkpoint/resume support: connection details and progress are persisted so long-running imports can resume after an interruption
  • Swagger/OpenAPI documentation for the admin API
  • Attachment search, with flat mode made the default
  • SEMANTIC_SEARCH_ONNX_THREADS configuration option
  • SIEM Sumo Logic support

Changed#

  • Metadata/attachment inserts now use a database transaction
  • ediscovery exports now emit an audit log entry
  • Purge performance improvements

Fixed#

  • Deb packaging issue; API auth edge case; cron entry handling; various migration/import fixes

Dependencies#

  • gofiber/fiber bumped in contrib/external-jwt-shared-secret; go.opentelemetry.io/otel/sdk 1.36.0 → 1.40.0; gofiber/fiber 2.52.11 → 2.52.12; filippo.io/edwards25519 1.1.0 → 1.1.1

2.1.1 - 2025-12-13#

Added#

  • SIEM support
  • install.sh bare-metal installer script

Changed#

  • Microsoft Teams collector updates

Dependencies#

  • gofiber/utils bumped to 1.2.0