← Back to all sparks
Redmine logo

Redmine

PM
Velocity2.5

Open source project management web application

Twenty years in, Redmine is on a disciplined security-patch cadence behind its first major release since 6.0.

issue trackingself-hostedsecurity patchingwebhooksrailsopen source
Current state
Redmine shipped 7.0.0 at the end of June with webhook triggers, a Rails 8 migration, and a header redesign, then followed it eight weeks later with 7.0.1 alongside backports to the 6.1 and 6.0 branches. That August release fixes five security defects, including a session-affecting API flaw and a stored XSS in the Textile formatter, and lands them on all three supported series at once. Alongside the real releases the feed also carries version-index wiki pages captured as entries, which are crawl artifacts rather than releases.
Where it's heading
The maintenance pattern is consistent and easy to read: coordinated multi-branch security releases roughly every two to three months, with the newest series also collecting performance and API work. Redmine 7.0.1 adds project information to the wiki page list API and fixes an OAuth2-related user deletion bug, so the 7.0 branch is absorbing polish rather than new capability. The three-branch support window is holding steady as 5.1 drops off the list.
Prediction
Expect the next coordinated release to cover 7.0, 6.1, and 6.0 on the same schedule, with continued API and OAuth2 refinement on the 7.0 branch rather than new features before 7.1.

Recent moves

  1. 21d ago

    Redmine 7.0.1, 6.1.4 and 6.0.11 released

    The first maintenance release on the 7.0 branch, backported to 6.1 and 6.0, carrying five security fixes plus a text-formatting performance regression fix and an addition to the wiki page list API. It is the follow-through that makes 7.0 safe to adopt rather than anything new.

    View source ↗
  2. 2mo ago

    Redmine 7.0.0 is now available

    ⚡ SPARK

    The anchor of the current arc: the first major version since 6.0, adding an outbound integration surface and resetting the framework baseline. Everything shipped since has been maintenance on the branch it opened.

    View source ↗
  3. 3mo ago

    Redmine 6.1.3, 6.0.10 and 5.1.13 released

    A coordinated security release across 6.1, 6.0, and 5.1 two weeks before 7.0.0 shipped, closing six defects including a permission bypass on bulk attachment downloads and a private-project name leak. Standard pre-major hygiene on the outgoing branches.

    View source ↗
  4. 6mo ago

    Redmine 6.1.2, 6.0.9 and 5.1.12 released

    The March coordinated release, seven security defects across three series plus thirty maintenance fixes on 6.1, including the RTL work that 7.0.0 would later complete. It marks where the current release rhythm was already established.

    View source ↗
  5. 6mo ago

    1.1.x series

    View source ↗
  6. 6mo ago

    1.4.x series

    View source ↗