HisarBlok · changelog
Changelog
What changed in every release, from the user's side. We also say plainly what the security reviews found. The detailed, technical changelog ships with the code.
Current version 0.13.1 · In development
0.13 — accounts limited to some sites, an accessible admin
0.13.1 (September 28, 2026)
- The admin was reviewed end to end against WCAG 2.2 AA: a "Stay signed in" dialog before a session is dropped, a command palette and confirmation dialogs that work fully from the keyboard, heading levels and names for screen readers, and a statistics chart that can also be read as a table.
- A refused page save no longer loses what was typed, and marks the wrong field.
- Badge, warning and state colours reach enough contrast in light and dark; the reduced-motion setting stops every animation.
0.13.0 (September 28, 2026)
- An account can be limited to some of an installation's sites, with a role per site. A limited account sees only its sites; people, modules, updates, backups and email stay with the administrators of the whole installation.
- The audit log records each entry's site; giving an administrator role asks for the password again, and a change that would remove the last administrator is refused.
- Two medium issues found by the authorization review before release were fixed: comment and forum notices could reach accounts of another site, and two sites' language settings could share one key.
0.12 — the command line, the Journal theme, footnotes
0.12.0 – 0.12.1 (September 27, 2026)
- One door to every server tool: the
hisarblokcommand.doctorreports the installation's health;make:moduleandmake:themewrite working skeletons. - A third theme, Journal, for writing meant to be read: a serif reading column, pull quotes, footnotes, reading time, an author box and related posts.
- Footnotes in Markdown, and a Latest posts block for pages.
- Modules can ship translations of their own strings; a module can never change a word of core's.
- Security review: a footnote mark inside an image description can no longer break out of the HTML attribute, and translations of switched-off modules no longer reach core's strings.
0.11 — six new visitor languages, two more forum sources
0.11.0 – 0.11.1 (September 27, 2026)
- Everything a visitor reads is now also in German, Spanish, French, Portuguese, Russian and Arabic, with numbers following each language's plural rules.
- Imports from two more forum packages; imported old password hashes that are never used are deleted after a year.
- Switching a module off rebuilds the site without that module's links.
- Security review: switching a module off could delete the uploaded images if its address was set wrongly; uploads, theme files and other modules' areas are now never removed.
0.10 — a build queue, right-to-left languages, addresses in any script
0.10.0 – 0.10.1 (September 27, 2026)
- Build queue: the saved page is written at once, while lists, feeds and full rebuilds follow in the background. Measured, saving a post went from 1.6 seconds to 0.11, and the "Rebuild site" button from 7.5 seconds to 0.04.
- Arabic, Persian, Hebrew and Urdu pages are drawn right to left.
- Titles in non-Latin scripts keep their letters in the address; Latin addresses did not change.
- An Atom feed for every blog tag and forum category; AVIF image copies where the server supports them.
- Queue review: a page that crashes its process no longer blocks the queue; it is skipped and reported.
0.9 — accessibility and an independent security review
0.9.0 – 0.9.3 (September 27, 2026)
- A WCAG 2.2 AA audit of the live sites: a sticky header no longer covers the focus, page titles name the site, links that open a new tab say so.
- A refused visitor form is drawn again with each error beside its field and everything typed kept.
- Optional MySQL/MariaDB support; a tool to move in either direction, the same backup format for both.
- An independent security review found two high issues, both fixed: server directives could be smuggled into the exported redirect rules, and accepted visitor submissions had no rate limit. There is now a submission budget per address and per site, and notifications are queued.
- Admin sign-in is limited per address and per account name; the installation and upgrade guides were followed end to end on a clean machine.
0.8 — signed, atomic updates, lighter pages
0.8.0 – 0.8.1 (September 27, 2026)
- The update tool unpacks a new version only if its Ed25519 signature checks out; it backs up first, switches the code in one move and brings back both code and database if a step fails. It refuses to run as root, and the admin never writes code.
- WebP copies for images outside the library too, a content fingerprint on images, and prefetching between pages. On a sample home page, images went from 349 KB to 48 KB.
0.7 — forum migration
0.7.0 (September 27, 2026)
- Imports from four more forum packages; members sign in with their old passwords, upgraded to a strong hash on first sign-in. Old addresses are kept alive with permanent redirects, but never over a page that lives on the site.
- All-languages categories can carry their own title in each language; members choose their mail language on their account page.
0.6 — a multilingual forum and members
0.6.0 (September 27, 2026)
- Forum and member pages are built in every language of the site. One account for all languages; mail goes out in the member's language. None of the existing Turkish addresses changed.
0.5 — cookieless statistics, Atom, a full export
0.5.0 (September 27, 2026)
- Built-in statistics: views, daily visitors, the most read pages, referring sites. No cookie, no IP address, no third party.
- An Atom feed beside RSS in every language, a forum feed, a time zone per site, dates in the page's language.
- An export that puts the whole site into one file in an open, documented format; the same file reads into another installation. Imports from feeds and from several publishing platforms' exports.
- Security review: an import file from elsewhere can no longer write a redirect over a live page.
0.4 — a broken link report, a faster first paint
0.4.0 – 0.4.4 (September 26, 2026)
- A broken link report that checks every internal link against the files on disk; the language switcher now links only to translations that exist.
- 480/960/1440 px copies of images, with
srcset. - The CSS a page uses is inside the page: on a slow mobile connection, first paint went from about 1.3 seconds to 0.65.
- 15 correctness bugs found by an independent code review, each fixed after a test that caught it. End-to-end tests that use the admin in a real browser the way a person does.
0.3 — site settings in the admin
0.3.0 (September 26, 2026)
- The site's name, description, logo, footer, call-to-action button and sharing image can be changed from the admin, per language. An uploaded logo is re-encoded on the server.
0.2 — a setup wizard, backups, new themes
0.2.0 – 0.2.2 (September 26, 2026)
- A web setup wizard locked by a one-time code, and a command-line installer.
- Backup and restore in the core; System → Backups in the admin.
- A dashboard with real numbers, and paging that puts no load on long lists.
- A redesigned default theme, and Studio for software product sites.
- Structured data, OpenGraph cards and one
h1on every page; a first WCAG 2.2 AA pass over the themes and forms.
0.1 — the first release
0.1.0 (September 23, 2026)
- The first version running a public site: pages, a blog, media, menus, redirects, search, announcements, members with two-factor sign-in, comments, forms, a forum with importers and downloads with counted links.