Kiwi TCMS 16.3

critical security related updates, several improvements

Posted by Kiwi TCMS Team on Mon 24 August 2026 under releases

Dear testers, we're happy to announce Kiwi TCMS version 16.3!

IMPORTANT:

This is a minor version release which includes critical security related updates and several improvements.

You can explore everything at https://public.tenant.kiwitcms.org!

---

Public container image (x86_64):

pub.kiwitcms.eu/kiwitcms/kiwi   latest  33e301a080d4    862MB

IMPORTANT: version tagged and multi-arch container images are available only to subscribers!

Changes since Kiwi TCMS 16.2

Security

  • Update Django from 6.0.7 to 6.0.8
  • Update django-simple-captcha from 0.6.3 to 0.7.0
  • Update node_modules/brace-expansion from 1.1.12 to 1.1.18
  • Update node_modules/fast-uri from 3.1.4 to 3.1.5
  • Update node_modules/js-yaml from 4.2.0 to 4.3.1
  • Do not render BugSystem.api_password field value in Admin page to prevent exposing 3rd party credentials. Fixes GHSA-cq4x-2h36-285q

Improvements

  • Update Node.js runtime from 22 to 24
  • Update django-guardian from 3.3.2 to 3.3.3
  • Update django-simple-history from 3.12.0 to 3.13.0
  • Update markdown from 3.10.2 to 3.10.3
  • Update pygments from 2.20.0 to 2.21.0
  • Update python-gitlab from 8.4.0 to 8.5.0
  • Update node_modules/webpack from 5.108.4 to 5.109.2
  • Update node_modules/webpack-cli from 7.2.1 to 7.2.2
  • Improve internal caching for Markdown.render() API method to remove cache key warnings and avoid crashes with 3rd party cache backends
  • Update helm charts. Closes Issue #4232 and Issue #3323

Bug fixes

Refactoring and testing

  • Update actions/setup-python from 6 to 7
  • Update locust from 2.46.1 to 2.46.3
  • Update pylint from 4.0.6 to 4.0.7
  • Update fedora from 43 to 44 in /tests/bugzilla
  • Update redmine from 6 to 7 in /tests/redmine
  • Remove deprecated version field from docker-compose files
  • Remove license specifier from setup.py in favor of setup.cfg

Changes since Kiwi TCMS Enterprise v16.2-mt

  • Based on Kiwi TCMS v16.3
  • Update kiwitcms-trackers-integration from 1.4.0 to 1.5.0
  • Update sentry-sdk from 2.66.0 to 2.68.0

Private container images

hub.kiwitcms.eu/kiwitcms/version            16.3 (aarch64)          f60a9c080e41    24 Aug 2026     715MB
hub.kiwitcms.eu/kiwitcms/version            16.3 (x86_64)           37e2579041b9    24 Aug 2026     696MB
hub.kiwitcms.eu/kiwitcms/enterprise         16.3-mt (aarch64)       349b31927cdb    24 Aug 2026     913MB
hub.kiwitcms.eu/kiwitcms/enterprise         16.3-mt (x86_64)        d8b365f321a8    24 Aug 2026     892MB

IMPORTANT: version tagged, multi-arch and Enterprise container images are available only to subscribers!

How to upgrade

Follow the Upgrading instructions from our documentation.

Happy testing!

---

If you like what we're doing please help us grow: