Changelog#
All notable changes to Piler Enterprise Edition, starting from 2.1.0.
The Scanner add-on (ML phishing detection, semantic search, PII detection, categorization) is versioned and released independently of the main application below.
Scanner 1.3.0 - 2026-09-27#
Changed#
- The ML phishing detector no longer depends on a native runtime library or CGO - it's now a fully static, dependency-free Go binary. This makes the scanner image smaller, faster to build, and easier to deploy across architectures.
- Retrained the phishing-detection model on a substantially larger and more diverse set of examples. Internal testing shows a meaningful reduction in false positives (legitimate email incorrectly flagged) versus the previous model, with no loss in detection rate.
- Simplified the scanner's Docker image build to a prebuilt-binary copy, matching the main application image's build process.
2.2.2 - 2026-09-22#
Security#
- Upgraded
grpcandgo.opentelemetry.io/otelto address CVE-2026-84304 and related CVEs
Added#
- Per-message delete action in the preview pane
- Stable HTML customization hooks (
data-*attributes) for MSP frontend integration - Multi-node support for user email purge
Changed#
piler-uiDocker image build simplified to a prebuilt-binary copy (matches the pattern later applied to the scanner image)- Manticore search engine upgraded to 29.9.0
- Message selection: Ctrl/Cmd+click for single-message selection, Shift+click for range selection
Fixed#
- Table content clipping in dashboard cards
- Bogus sort order in multinode search results
- Regular users seeing 0 search results in multinode mode
- Timezone validation failing on Alpine runtime images (IANA tzdata now embedded rather than relying on the host OS)
- Unmounted Vue templates briefly flashing placeholder content (
v-cloak) - Trailing boundary CRLF in attachment MIME parts incorrectly flagged as invalid
- False-positive attachment size mismatch logging for base64-encoded attachments
- S3 promotion window returning an empty
200instead of503
2.2.1 - 2026-09-06#
Security#
- Upgraded
nanoidto 3.3.18 to fix CVE-2026-67213 (high severity)
Added#
S3_SKIP_EXISTING_OBJECTSto skip re-uploading objects already present across nodesS3_PART_SIZE_MBandS3_DISABLE_MULTIPARTknobs fors3uploaderpurge --restore-idfor restoring a specific prior purge run;PACKAGES.mddocumenting package build/signing
Changed#
- Dockerfiles upgraded to
alpine:3.24; audit log table gained stable CSS identifiers for MSP customization RPM_RELEASEoverride for RPM packaging; fixeddpkg-sigremoval on package updates
Fixed#
- Fixed a tenant-configuration bug that could cause scheduled purges to be skipped
- Nested-multipart attachments misindexed in
pilerimport; mismatched download objects now caught explicitly - Five distinct archiving bugs: duplicate detection, purge tombstone
handling,
Fromheader overflow,enable_purgeflag handling, and an attachment-processing race condition - Purge command: tombstone restore, recipient preservation, dry-run loop behavior, missing-env-var warning
2.2.0 - 2026-08-16#
Changed#
- Semantic search embeddings: replaced in-process ONNX embedding
generation with calls to an external, OpenAI-compatible HTTP endpoint
(
SEMANTIC_SEARCH_ENDPOINT_URL);piler-uiimage switched to an Alpine base as a result (no longer needs ONNX Runtime/CGO)
Added#
- OX (Open-Xchange) webmail integration: theme, language, timezone, and iframe CSS synchronization
Fixed#
- Session cookie expiry handled incorrectly in some flows;
dompurifyupgraded alongside the fix - Multi-tenant provisioning; tenant GUI URL not hot-reloading after change
- OAuth2 configs being rebuilt per-request instead of cached in multi-tenant mode
- Health page's "received messages" chart rendering incorrectly
2.1.5 - 2026-07-26#
Security#
grpcbumped to v1.82.1 to fix security vulnerabilitiesgofiberandgolang.org/x/netupgraded (security-motivated)dompurify3.4.11 → 3.4.12
Added#
- Pending conversations: badge in search results plus a dedicated drawer for messages awaiting a reply
- Attachment indexing gated on
TIKA_URLbeing configured, rather than always-on - Explicit Dependabot workflow for automated dependency PRs
- Standby-node support for import jobs; multi-node import handling
- Theme and accent-color support carried over from EAM authentication
Changed#
- Build tooling switched from the previous bundler to Vite (and bumped
several times through the 6.4→8.1 series as issues were found); iframe
session cookie set to
SameSite=Nonefor embedding scenarios; listens for apostMessagetheme-change event from a parent iframe - Import job handling simplified
Fixed#
- Email direction now computed per-message from the local domain table, rather than a possibly-stale cached value
c.IP()captured before entering a goroutine inZipAndStreamDownloadRemote(was reading a request-scoped value after the request had already returned)- Multi-node export; mobile screen layout issues; vendor CSS handling under the Vite build; header parser edge case; several import/migration fixes; purge logging
Dependencies#
- Routine bumps:
vue3.5.38→3.5.39,postcss8.5.16→8.5.23,axios1.18.0→1.18.1,@vitejs/plugin-vue5.2.4→6.0.7, plus a batch of GitHub Actions version bumps (actions/checkout,actions/setup-go,actions/setup-python,actions/upload-artifact,actions/download-artifact,docker/setup-buildx-action,docker/setup-qemu-action,docker/login-action,docker/metadata-action,softprops/action-gh-release)
2.1.4 - 2026-06-09#
Added#
- Standalone importer web app (
cmd/importUI) ANALYTICS_ENABLEDenvironment variable- Rate limiting on authentication endpoints (security hardening)
Changed#
- All config keys now registered with
viperregardless of whether a default is empty, so they can still be overridden via environment variables
Fixed#
- Microsoft 365 journal processing
- LDAP authentication edge case
- Header/footer branding logo display
serverIdevaluation lacking a safety check- Import job responses missing the
idfield on creation - Purge endpoint failing on already-deleted emails
- Background job SQL queries
- Extremely long
Message-ID/attachment filenames not handled correctly chowncommand incorrect in package install scripts
Dependencies#
gofiber/fiber2.52.12 → 2.52.13 (main app andcontrib/external-jwt-shared-secret)Azure/go-ntlmsspbumped
2.1.3 - 2026-04-09#
Added#
SHOW_IMPORT_MENUconfiguration option- NIS2 compliance documentation
Changed#
- Manticore upgraded to 25.0.0 in tests and the installer
Fixed#
- Swagger/OpenAPI docs generation
Dependencies#
go.opentelemetry.io/otel/sdk1.40.0 → 1.43.0russellhaering/goxmldsig1.4.0 → 1.6.0google.golang.org/grpc1.72.1 → 1.79.3
2.1.2 - 2026-03-15#
The largest release in this window - unified archiving for chat platforms,
GDPR right-to-erasure, passkey authentication, multi-master-node HA, and a
round of gosec-driven security hardening.
Security#
- Passkey (WebAuthn) authentication support added
gosecstatic-analysis fixes applied acrossreindex,imapimport,pilerimport, ands3uploader- TLS support added for the MySQL connection
- Added additional iframe-embedding security headers
- Sensitive SIEM connection details no longer appear in logs
Added#
- Slack and Microsoft Teams collectors: initial unified-archiving support for chat platforms, including a parallelized Slack collector and dedicated UI/API components
- GDPR Right to Erasure: multi-node-aware implementation
- Find similar messages: KNN vector search over message embeddings
- Multi-master-node support (previously single-master architecture)
- IMAP import checkpoint/resume support: connection details and progress are persisted so long-running imports can resume after an interruption
- Swagger/OpenAPI documentation for the admin API
- Attachment search, with flat mode made the default
SEMANTIC_SEARCH_ONNX_THREADSconfiguration option- SIEM Sumo Logic support
Changed#
- Metadata/attachment inserts now use a database transaction
- ediscovery exports now emit an audit log entry
- Purge performance improvements
Fixed#
- Deb packaging issue; API auth edge case; cron entry handling; various migration/import fixes
Dependencies#
gofiber/fiberbumped incontrib/external-jwt-shared-secret;go.opentelemetry.io/otel/sdk1.36.0 → 1.40.0;gofiber/fiber2.52.11 → 2.52.12;filippo.io/edwards255191.1.0 → 1.1.1
2.1.1 - 2025-12-13#
Added#
- SIEM support
install.shbare-metal installer script
Changed#
- Microsoft Teams collector updates
Dependencies#
gofiber/utilsbumped to 1.2.0