Weblate 2026.10.1

まだリリースされていません。

新機能

改良点

  • Made unused components and glossary languages warning diagnostics and enabled dismissal for them and suspected monolingual or bilingual file-format misconfiguration.

Security fixes

  • Added restrictive cache controls to authenticated HTML responses to prevent previously viewed content from being restored after logout.

  • Hardened version control metadata filtering against trailing-dot and trailing-space path aliases.

  • Prevented sitemaps from disclosing restricted component and translation URLs.

  • Restricted stale Git lock cleanup to the repository running the failed command and prevented empty file lists from committing unrelated changes.

  • Prevented project backup imports from granting site-wide permissions through restored project teams.

バグ修正

互換性

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

貢献者

All changes in detail.

Weblate 2026.10

Released on October 1st 2026.

新機能

改良点

  • Component configuration errors are reported before fetching the repository when repository files are not needed for validation.

  • Clarified that site-wide team management can grant access to private projects independently of the team manager's own project access.

  • Improved checks, automatic fixes, glossary matching, and machine translation for independent alternatives in multivalue formats.

  • Added a thumbnail picker to associate existing screenshots with a string from the translation editor.

  • Repository maintenance now checks permissions on the repository-owning component and explains where missing permissions are required.

  • Automatic translation using other components now prefers translations with matching source text and context.

  • Aligned string search filters with the status overview's order and colors, and added an All strings option to clear the query.

  • Added monthly instance activity to the data sent with support integration for activity monitoring and discovery ranking.

  • Improved repository maintenance with disabled push controls when push configuration is missing and direct links to component VCS settings.

  • The automatic translation add-on can create approved strings, falling back to translated strings when reviews are disabled for the target language.

  • Added independent term alternatives and scoped metadata to TBX glossaries, including metadata-preserving TBX exports.

  • Whitespace characters are now rendered consistently in the source string display and the translation editor, and different kinds of whitespace are now distinguishable from each other.

  • Added a font-monospace flag to display a string in the translation editor using a monospace font, useful for aligning command-line or terminal output.

  • History View details and Revert actions are larger, more widely spaced, and show a hover and focus background.

  • The units API now links to a unit's associated screenshots and supports listing, assigning, and removing them via GET /api/units/(int:id)/screenshots/.

  • Added a keyboard shortcut to approve a translation and save and continue.

  • Clarified translation quality filter explanations and effective per-language review settings, with links to workflow configuration.

  • Reworked the Automatic suggestions tab to use the same layout as suggestions, and it now shows the translation memory context of each match.

  • The xgettext and Meson extraction add-ons now bundle common XML translation rules and support project-local ITS directories for extracting mixed source formats into a shared POT.

  • Repository maintenance now links to the latest pull or merge request opened by Weblate.

  • The project Files menu now lists translation download formats from WEBLATE_EXPORTERS instead of a fixed subset.

  • LLM automatic suggestions now show the model and, for custom API endpoints, the host that produced them.

  • Automation actions can select strings from the triggering change or a previous action's affected units. See Automation reference and cookbook.

  • Unified browsing and searching strings, aligned search filters with the status overview, and added direct editor access to language-specific lists and an All strings filter.

  • Improved translation history with faster browsing, date navigation, and clearer actions.

  • Improved screenshot assignment in the editor with a thumbnail picker, predictable ordering, and removal without reloading.

  • The editor now distinguishes whitespace in source and translation strings, supports the font-monospace flag, and accepts decimal font-spacing values.

  • Added a Markdown preview to comments, explanations, announcements, and project instructions.

  • Added a keyboard shortcut to approve a translation and continue.

  • Clarified translation quality filters and effective per-language review settings.

  • Improved translation memory lookup performance and added match context to automatic suggestions.

  • Reduced aggregation overhead for the inconsistent translations check on large projects.

  • Moved related quality check updates to background tasks to avoid slow saves when many strings share a source or translation.

  • Markdown のリンク quality check now detects untranslated link titles.

  • Automatic translation across components now prefers matching source text and context. The automatic translation add-on can create approved strings, or translated strings when reviews are disabled.

  • Improved checks, fixes, glossary matching, and machine translation for multivalue alternatives.

  • TBX glossaries now support independent term alternatives and scoped metadata, preserved on export.

  • The xgettext and Meson add-ons now support bundled XML rules and project-local ITS directories.

  • Added uploaded file language checking with an override in the upload form and API.

  • Translation file uploads through the API accept form field content without a filename.

  • Repository maintenance now checks permissions on the repository-owning component, links to VCS settings, and disables unavailable push controls.

  • SSH repository connections now try IPv4 and IPv6 addresses in a staggered sequence and report failed addresses and ports.

  • Add-on error diagnostics now link to the responsible add-on configuration.

  • Added monthly instance activity to support integration data.

  • Suggestions can be shown in the Zen モード and accepted, rejected, or voted on in place.

  • Added a separate repository browser URL for translation files.

  • Docker startup now reports invalid nginx-related environment values before attempting to start nginx.

  • Git コミットのスカッシュ now supports squashing together per author and language.

  • The automatic translation API can run as a background task. See POST /api/translations/(string:project)/(string:component)/(string:language)/autotranslate/.

Security fixes

  • Project administrators can no longer see blocked users' account e-mail addresses without site-wide user management permission.

  • Removed repositories created from rejected component ZIP and document uploads.

  • Prevented App Store metadata files from following symbolic links outside the component repository.

  • Protected translation reverts against cross-site request forgery.

  • Prevented client-supplied forwarded IP headers from bypassing anonymous API rate limits.

  • Prevented whitespace-only username searches from listing users through GET /api/users/.

  • Prevented project access managers from assigning users to site-wide teams associated with the project.

  • Invalidated outstanding password reset links after password changes regardless of e-mail address casing.

  • Prevented concurrent requests from exceeding configured web action rate limits.

  • Prevented repository URLs from injecting executable Mercurial configuration.

  • Limited XLIFF language declarations in uploads and the number and size of translation alternatives to prevent resource exhaustion.

  • Enforced language-scoped screenshot permissions and restricted component access in translation consistency and direct automatic translation workflows.

  • Prevented project API tokens from inheriting permissions through automatic team assignments.

  • Protected Git and Mercurial metadata consistently in repository paths and downloads, and excluded known foreign VCS metadata when importing component ZIP files.

  • Prevented notification subscriptions from exposing inaccessible project and component settings through the REST API and profile settings.

  • Rate-limited password-reset requests for unknown e-mail addresses.

バグ修正

  • Project backups now tolerate missing or damaged repositories and preserve available files and translation data during restore.

  • Project MO archive downloads now skip incompatible file formats without failing the download.

  • Made eligible automatic-translation sources consistent across web, API, and Automation add-on configuration.

  • Fixed move_language and automatic language alias updates to preserve language-specific settings and permission limits, and detect conflicting translations or settings before moving content.

  • Suppressed OpenSSH post-quantum key exchange warnings that obscured errors from SSH repositories.

  • Fixed the BBCode markup check for parameterized, nested, and multiline tags.

  • Improved plain-text notification e-mails with readable links and tables instead of Markdown.

  • Project language archive downloads in the REST API now honor language-scoped download permissions consistently with the web interface.

  • Fixed authentication initialization with Sample configuration to start Granian with ASGI when Sentry instrumentation is enabled.

  • Fixed status widgets for categories, category-language pages, and workspaces, and corrected statistics for nested categories and deleted 文字列ラベル.

  • Fixed MIME nesting and reduced the size of inline branding images in notification e-mails.

  • Anthropic now preserves path prefixes in custom base URLs.

  • Fixed false positives in the consecutive duplicated words check for South Asian languages and prevented the punctuation spacing check from inserting spaces in URLs.

  • Fixed the maximum size check preview shifting text when font-spacing is set.

  • Fixed Docker startup warning checks when the warning directory is missing or inaccessible.

  • Fixed an upgrade failure when migrating dismissed component alerts from releases before 2026.8.

  • Fixed the search results refresh icon color in themes and on hover.

  • Fixed truncated grouped summaries in notification e-mails; the 100 entries limit now applies only to listings of individual changes.

  • Fixed bilingual glossary terms appearing as untranslatable when translating in their source language.

  • Fixed component discovery with inherited licenses and other inherited settings.

  • Backups containing legacy component formats (e.g plainxliff, csv-utf-8) are now correctly restored.

  • Fixed switching between singular and plural forms when adding new strings.

互換性

  • An explicit source-wide read-only flag now takes precedence over translation flags. Remove it from the source to allow editing.

  • Existing project API tokens lose permissions inherited from non-project teams. Assign required permissions through project-specific teams.

  • API throttles now use API_RATELIMIT_ANON and API_RATELIMIT_USER instead of REST_FRAMEWORK["DEFAULT_THROTTLE_RATES"].

  • API authentication now rejects unsupported authentication schemes, such as Basic, with HTTP 401, including when a valid browser session is present.

  • Notification subscription API responses now expose project and component as nullable URL strings instead of nested objects.

  • The former plainxliff and xliff2-placeables file formats are migrated to XLIFF 1.1 および 1.2 / XLIFF 2.0 with the xliff_placeables ファイル形式パラメータ.

  • Norwegian Bokmål now uses nb as its built-in language code while preserving nb_NO support, see 言語の定義.

アップグレード

  • Add weblate.automation to custom INSTALLED_APPS before migrating. If WEBLATE_ADDONS explicitly lists the automation add-on, change its import path to weblate.automation.addon.AutomationAddon. The official Docker image includes the new app.

  • Existing contributor comments add-ons migrate to component file format parameters. Remove the obsolete add-on from custom WEBLATE_ADDONS and DEFAULT_ADDONS settings; new components no longer inherit it.

  • Add weblate.api and weblate.kotlin_sdk to INSTALLED_APPS before migrating. The official Docker image includes both. Installing the Kotlin app does not enable CDN publication on any component.

  • In non-Docker settings, move the anon_throttle and user_throttle arguments from get_drf_settings and any custom REST_FRAMEWORK["DEFAULT_THROTTLE_RATES"] values to API_RATELIMIT_ANON and API_RATELIMIT_USER. Existing Docker rate-limit variables still work.

更新するには、一般的なアップグレード方法 に従ってください。

貢献者

コードに貢献

Michal Čihař, Karen Konou, michael-smt, Mark Davies, Diptajoy Mistry, krisna, Metin Kılagöz, MIHAIL N., Claude Sonnet 5, mmustafasenoglu, i4i, Mustafa Senoglu, anishkun, Anish kunda, Gersona, Magnus Karlsson, JUSHUANGHUI LI, Chimwemwe Siyingwa, krisnaparahita, Dr Alex Mitre, Aditi Tarate, Kartik Ohri, Suleyman Arif Uzun

翻訳に貢献

hoanghuy309, Watchman89, Adam Havránek, Fjuro, justcontributor, Szafranek13, Tony Ng, Chloe Wang, VfBFan, Valentin Ljuba, Daniel Nylander, Andrei Stepanov, Michal Čihař, Matthaiks, Arif Budiman, Любомир Василев, Aindriú Mac Giolla Eoin, Yaron Shahrabani, Adolfo Jayme Barrientos, Sup! 0_0, Lee Vincent, Milo Ivir, Dick Groskamp, Eduard Ereza Martínez, Ricky Tigg, Mickaël Binos, reducedradius, Artyom Rybakov, Kyotaro Iijima, Jim Kats, Supaplex, Peter Vančo, Stysusss, Ulrik, Ldm Public, Júlia Rosell Saldaña, Deleted User, eulalio, Zahid Rizky Fakhri, Takeru Mikenu, 이정희, António Oliveira, xXx, தமிழ்நேரம், Kaya Zeren, Bone NI, QuietCedar47, Andi Chandler, Ettore Atalan, Massimo Pissarello, Besnik Bleta, Chimwemwe Siyingwa, Nicat, Sketch6580, Areera

ドキュメントに貢献

Michal Čihař, Karen Konou, michael-smt, Diptajoy Mistry, Maciej Olko, MIHAIL N., Claude Sonnet 5, mmustafasenoglu, i4i, Mustafa Senoglu, anishkun, Anish kunda, Gersona, Magnus Karlsson, JUSHUANGHUI LI, Chimwemwe Siyingwa, krisnaparahita, krisna, Claude Opus 5.5, spatterlight, Dr Alex Mitre, Aditi Tarate, Kartik Ohri, Suleyman Arif Uzun

All changes in detail.

Weblate 2026.9.1

Released on September 8th 2026.

新機能

  • Added per-user notification diagnostics for users and administrators, with compact explanations of matching subscriptions for object paths.

改良点

  • Added explicit search result refresh in the translation editors and improved recovery when saved search results expire.

  • Docker development tests now automatically prepare an isolated test environment without requiring application startup or the Dev Container CLI.

  • Added a development container for tests and lint, with an optional application QA profile, isolated storage per Git worktree, dynamically allocated localhost application and mailbox ports, and Chromium diagnostics and mandatory browser test commands.

  • Improved translation statistics calculation performance and avoided redundant parent updates when loading check and label details.

  • Added posting and displaying scoped announcements on category-language pages.

  • Added a dismissible diagnostic for glossaries with disabled string management when they use a local repository or contain terminology.

  • Clarified incident reporting, reporting deadlines, and security notifications for hosted and self-hosted users.

  • The Manage reports permission now consistently grants access to complete translation reports for the selected scope, including private projects and restricted components below it.

  • Docker deployments now use a combined Celery worker by default, reducing memory usage while increasing task throughput. Use CELERY_WORKER_MODE to select the combined, split, or single worker setup.

  • Improved Billing detail page loading performance by batching related project, invoice, and audit log queries.

  • Further reduced Celery worker memory usage by sharing preloaded URL configuration between worker processes and loading bitmap widget rendering dependencies only when needed.

  • Docker startup configuration warnings are now available as deployment checks, including in horizontally scaled deployments.

  • Reduced peak memory use and task duration for notification digests by processing recipients in bounded batches and limiting each summary to 100 entries.

Security fixes

  • Prevented repeated authenticator app registration from creating duplicate devices and allowing reuse of one-time codes. Existing equivalent duplicate devices are merged while preserving consumed codes.

  • Borg backup passphrases are now recursively scrubbed from Sentry error reports, including when a custom event scrubber is configured.

  • Font overrides are now restricted to fonts uploaded to the same project.

  • Engage pages and status widgets no longer disclose Private or Custom projects unless Public sharing is enabled.

  • Prevented excessive CPU consumption while checking malformed Markdown and MDX syntax.

バグ修正

  • Fixed the approved-only commit policy blocking commits for languages with reviews disabled by workflow settings.

  • Fixed the uWSGI configuration example to use the virtual environment's Python when launching helpers for SSH repository operations.

  • Fixed language context and links in change history for scoped announcements and other language-specific events.

  • Restored DeepL API v1 translation support while retaining modern API language discovery and glossary improvements.

  • REST API unit updates now enforce the same translation text length limit as the web editor.

  • HTML void elements in MDX ファイル translations are now kept self-closing after sanitization, preventing invalid MDX output.

  • The autotranslate API endpoint now correctly describes its accepted request body fields (q, mode, auto_source, component, engines, threshold) in the OpenAPI schema instead of incorrectly reflecting the Translation resource.

  • Links outside tab navigation now correctly activate their target tabs, fixing upload links for missing translations and new components.

  • Error reporting integrations now distinguish informational messages from exceptions and reliably report the explicitly handled exception.

  • The default Celery per-child memory limit now accommodates the application's baseline memory usage, avoiding unnecessary worker recycling.

  • Backup services now start only after settings and database backup files are fully updated, while backups to different Borg repositories can run in parallel.

互換性

  • Anonymous access to engage pages and status widgets is now disabled by default for Private and Custom projects. Enable Public sharing to preserve existing shared links after upgrading. Public and Protected projects are unchanged.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

  • Authenticator app registrations started before this upgrade must be restarted. Sessions referencing a removed duplicate device may require two-factor verification again.

  • Docker deployments now default to the combined Celery worker mode. If your deployment relies on separate workers for each queue or configures them using CELERY_MAIN_OPTIONS, CELERY_NOTIFY_OPTIONS, CELERY_MEMORY_OPTIONS, CELERY_TRANSLATE_OPTIONS, or CELERY_BACKUP_OPTIONS, set CELERY_WORKER_MODE=split to preserve the previous behavior.

  • The Docker CELERY_SINGLE_PROCESS environment variable is deprecated. Use CELERY_WORKER_MODE=single instead; the compatibility alias logs a startup warning.

貢献者

コードに貢献

Michal Čihař, Karen Konou, Shweta Singh, michael-smt

翻訳に貢献

ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝), Ldm Public, hoanghuy309, Vaclovas Intas (Vac31.), Matthaiks, Adam Havránek, VfBFan, reducedradius, Bone NI, Yaron Shahrabani, Любомир Василев, Fjuro, Andrei Stepanov, Arif Budiman, Watchman89

ドキュメントに貢献

Michal Čihař, Shweta Singh, michael-smt

All changes in detail.

Weblate 2026.9

Released on September 3rd 2026.

新機能

  • Repository maintenance actions now run as background tasks, avoiding request and proxy timeouts. Project-wide maintenance remains available for authorized repositories and lists components skipped because of linked-component permissions. The repository API supports the same behavior using background: true.

  • コンポーネントの検出 can optionally create components from a monolingual base or new base file when no translation files exist yet.

  • Added Version control parameters to configure repository behavior per component, including force pushing, opting out of pull requests, and GitHub pull request automerge.

  • Added Migrating existing components for migrating existing Git and GitHub components to the Weblate GitHub App integration.

  • Added a Visible columns in lists preference to choose which statistics columns are shown in project, component, and language lists. See 環境設定.

改良点

  • AWS SES can now be used as the outbound e-mail transport in Docker deployments by setting WEBLATE_EMAIL_BACKEND to django_ses.SESBackend. Region, endpoint, and SES v2 API opt-in are configurable via WEBLATE_AWS_SES_REGION_NAME, WEBLATE_AWS_SES_REGION_ENDPOINT, and WEBLATE_USE_SES_V2.

  • Removing the final Weblate workspace connection for a GitHub account, or removing the workspace holding it, now also uninstalls the Weblate GitHub App from GitHub.

  • POT ファイルの更新(xgettext) now accepts multiple custom keywords (newline-separated) passed to xgettext via --keyword, enabling extraction from different function names.

  • Screenshot images are now cached in browsers to reduce repeated downloads.

  • Administrators can now find removed accounts by their former e-mail address in the audit log until AUDITLOG_EXPIRY. See 個人情報保護規制への対応.

  • Deployment diagnostics now detect slow filesystem metadata access in data and cache directories, and validate VCS command versions during configuration health checks instead of every process startup. See 性能レポート and VCS_BACKENDS.

  • Clarified the instance-wide impact of roles containing site-wide permissions, including site-wide user management.

  • Improved translation file loading performance for metadata-only string changes.

  • Reduced Celery worker startup memory usage by avoiding duplicate Django system checks and loading font rendering only when needed.

  • Billing audit logs now identify users who change plans, initiate payments, or merge billings.

  • Assigning languages to a team now uses an All languages toggle which disables the language choice when turned on, and a manually chosen set of languages is kept when toggling it. See プロジェクトごとのアクセス制御の管理.

  • Management notices now distinguish support package activation, status refresh, unlinking, and Discover Weblate registration.

  • Clarified generic notification hook matching and privacy behavior.

  • Clarified that Weblate does not populate Git submodules. See Git submodules.

  • The initial 検索と置換 action is now labeled Review changes to distinguish it from confirmation.

  • The translation flags editor now supports reopening flags for editing, arrow-key navigation, and copying with Ctrl+C. It also keeps commas inside quoted values intact, allowing flags such as regex:"^.{1,32}$" to be typed and pasted.

  • Repository failure alerts now provide guidance matching repository URL validation errors. See Troubleshooting repository URLs.

Security fixes

  • Component discovery now limits repository paths and file-mask comparisons to prevent excessive resource consumption from specially crafted repositories.

  • Rejected two-factor authentication attempts now apply AUTH_LOCK_ATTEMPTS, invalidate pending password sign-ins on lock or password change, and accept six-digit TOTP codes with leading zeroes.

  • Project backup restores now preserve all project, category, and component settings. They also allowlist repository metadata for Git, git-svn, and Mercurial to prevent archives from supplying executable configuration or repository indirection.

  • Project administrators can no longer remove API tokens belonging to other projects.

  • User listings and site-wide searches no longer expose project-scoped API tokens to users without global user viewing or editing permission.

  • Project and workspace translation memory now respects restricted component access, and restricted components no longer contribute to shared translation memory.

  • Webhook target matching no longer falls back to host/path suffix matching. Component repository URLs must match a repository URL from the webhook payload. See Matching webhook targets.

バグ修正

  • LLM-based machine translation services now report invalid provider responses more clearly, custom OpenAI and Mistral models no longer require a model-listing endpoint, and OpenAI automatic selection supports API keys restricted to older GPT models.

  • Daily metric collection now uses independent tasks and more efficient database queries to reduce peak memory usage and avoid losing all scopes when one collection fails.

  • Database dump failures are now shown in the backups management interface.

  • GitLab merge request forks now disable Git LFS to avoid missing-object push failures. See Git LFS.

  • Notification e-mails now wrap long strings instead of overflowing, keeping the View button reachable without horizontal scrolling.

  • Creating additional components for a repository imported through the GitHub App no longer fails without showing any error, and component creation errors which previously could go unreported are now always displayed.

互換性

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

  • Docker deployments need to configure trusted proxy addresses. Set WEBLATE_TRUSTED_PROXY_ADDRESSES to preserve client IP addresses in nginx logs and Weblate when WEBLATE_IP_PROXY_HEADER=HTTP_X_FORWARDED_FOR is used; otherwise, the immediate TCP peer is used.

貢献者

コードに貢献

Michal Čihař, Karen Konou, Gersona, Spyder, mmustafasenoglu, Kartik Ohri, Shweta Singh, Fabian Berg

翻訳に貢献

Yuri Chornoivan, Matthaiks, Steve, hoanghuy309, VfBFan, António Oliveira, Andrei Stepanov, Adam Havránek, Dick Groskamp, Aindriú Mac Giolla Eoin, Andi Chandler, Lee Vincent, Michal Čihař, Milo Ivir, Ldm Public, Peter Vančo, Alos (bop2039), Tarás Lavrentiev, Lito Parra, goeran, Любомир Василев, Vik, Bone NI, Pierfrancesco Passerini, CYAXXX, Yaron Shahrabani, Pavel Borecki, حسين نور الإسلام, amano, reducedradius, Fjuro, Frostre_, Sup! 0_0, Ulrik, xiezhihai, Yoshi, Alexander Gabilondo, Eduard Ereza Martínez, Watchman89, Kyotaro Iijima, AlexYang, justcontributor, Background update, Arif Budiman, Harsha Kanaparthi, notlin4, KuroisKitsune, Zahid Rizky Fakhri, Michal Várady, Massimo Pissarello, HThuren, SeyhaLite, David Wagener, Yauhen, Anucha Hlownonkor, michael0820, Artyom Rybakov, Nhật Nhật, 子悦解说, Mahdi B. Jahani, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝)

ドキュメントに貢献

Michal Čihař, Gersona, Karen Konou, Spyder, mmustafasenoglu, Kartik Ohri, Shweta Singh

All changes in detail.

Weblate 2026.8.1

Released on August 7th 2026.

新機能

  • Project and component APIs now expose all user-configurable settings, including access control and translation-memory settings. See Weblate の REST API.

  • Added the metrics command for retrieving server metrics locally in JSON, CSV, or OpenMetrics format.

バグ修正

  • Task progress now requires authentication and works for aggregate automatic translation operations.

  • Docker Celery worker logging no longer emits duplicate records through both Celery and Weblate log handlers.

  • Component creation through the REST API now returns the background task URL in the response when creation work is queued.

  • Large language model machine translation services no longer fail when the optional persona and style settings are absent from the stored configuration, as happens when the service is installed through the REST API.

  • import_json now preserves the component source language for newly imported components from JSON exports.

  • Repository actions now require permission on every component sharing the affected repository, including linked components in other projects.

  • Legal document confirmation now explicitly covers the linked privacy policy. See 法務モジュール.

  • Add-on change history now retains only explicitly public configuration values and marks changed credential fields as redacted.

  • Translator work reports with metrics can now be displayed and downloaded as HTML.

  • Repository credentials are now consistently hidden from web and API output.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

貢献者

コードに貢献

Michal Čihař, i4i, Alafi, Kartik Ohri

翻訳に貢献

Yuri Chornoivan, hoanghuy309, goeran, peterxy, Ldm Public, António Oliveira, CYAXXX, Aindriú Mac Giolla Eoin, Valeria Sofia Azañero, DocNoc, Libre, MrLeaves, Matt P, Yaron Shahrabani, VfBFan, Lee Vincent, Michal Čihař, Andrei Stepanov, cat, Любомир Василев, Artyom Rybakov, Matthaiks, reducedradius, Peter Vančo, Steve, Anmoll Gupta, justcontributor, Besnik Bleta

ドキュメントに貢献

Michal Čihař, i4i, Kartik Ohri

All changes in detail.

Weblate 2026.8

Released on August 3rd 2026.

新機能

  • Added a Show all columns in lists using horizontal scrolling preference to keep all listing columns visible on narrow screens instead of hiding them.

  • Workspaces now provide aggregate translation statistics and historical metrics, a permission-filtered My workspaces list, archive downloads, search and replace, upload guidance, workspace translation memory management, and removal of empty workspaces not associated with billing.

  • Added project-level translation metrics in JSON, CSV, and OpenMetrics formats.

  • Added opt-in Sample configuration to start Granian with ASGI deployment support, including WEBLATE_ASGI for Docker containers and asynchronous machine translation editor, GitHub App connection, and repository refresh requests.

  • Added grouped project and workspace Diagnostics views with state, severity, category, and actionable-by-user filters. Component diagnostics now track dismissal ownership, reopen after relevant changes, and notify only project maintainers who can act on warnings and errors.

  • Added API endpoints for listing, adding, accepting, rejecting, and voting on translation suggestions.

  • Translation reports are now generated in the background, stored for later download, available at workspace scope, and include translator work analysis.

  • Added Use keywords exclusively option to POT ファイルの更新(xgettext), allowing projects to disable xgettext default keywords and rely only on a custom keyword.

  • Added API support for reading and updating ユーザー情報 preferences. See ユーザー endpoint.

  • Added 最大の行数 and AsciiDoc マークアップ quality checks for limiting the number of translation lines and validating AsciiDoc strings.

  • Added Limiting translation languages, including per-language control for restricting direct translation editing to privileged users.

  • Added support for legacy Qt Linguist TS version 1 files. See Qt Linguist .ts.

  • Weblate is now available in Lao language.

改良点

  • Authenticated web-action rate-limit lockouts are now recorded in the 監査ログ with the affected scope and request path.

  • OpenMetrics API responses now include metric metadata and a versioned content type.

  • Add-on management now uses separate configuration, logs, and components tabs, while activity logs distinguish pending, successful, failed, and skipped executions and explain skipped executions.

  • Expanded 選択した変更イベント documentation with detailed event semantics and improved OpenAPI schema accuracy.

  • Improved loading performance for multi-language matrix views, dashboard component lists, category histories, and shared component listings.

  • Translation memory management now loads origin summaries more efficiently, shows active and pending entry counts, and reports the number of entries processed during import.

  • Static assets now use content-hashed filenames, and CAPTCHA JavaScript is loaded only when needed.

  • Amazon Translate machine translation now supports configuring formality, brevity, and profanity masking.

  • Improved Screenshots and visual context OCR reliability and error reporting when downloading recognition data.

  • Repository failure alerts now link directly to component version control settings for users who can edit them, keep technical errors in English, and localize actionable diagnoses for each viewer, including GitHub pull request restrictions.

  • Celery workers now prefetch fewer tasks by default to reduce memory usage and improve task distribution.

  • Improved the recommended Granianを起動するための設定例 configuration and Docker container worker resilience for Weblate's WSGI workload.

  • Deployment checks now detect corrupted PostgreSQL relation statistics.

  • Community diagnostics now show source-string screenshot coverage, recommend key translation-instruction topics, and distinguish inbound from outbound repository automation.

  • User-provided links, such as those in comments, announcements, and profiles, are now underlined and use a higher contrast color.

バグ修正

  • Disabling password authentication from site-wide user management now regenerates the user's personal API key by default.

  • Category, project, and comment statistics now stay consistent after component topology and comment changes, and category metrics are collected correctly.

  • Mercurial repository filenames beginning with a dash are now handled safely.

  • URLs containing backslashes are now rejected as invalid.

  • Protected outbound HTTP and Git connections now bind to validated public addresses; protected Git operations fail closed when clients cannot enforce that binding (GHSA-45m9-pf98-8jmq).

  • Permanent same-host Git HTTP redirects are now validated and stored as canonical component repository URLs.

  • Self-service REST API e-mail changes are now restricted to verified addresses (GHSA-x84p-6892-473c).

  • REST API authorization now consistently protects internal accounts, restricted components, add-on configuration, component sharing, repository links, and review states.

  • Project backup imports now validate restored data before creating project state, skip repository-linked components the importer cannot access, and no longer load archive-supplied Mercurial configuration or shared-repository indirection (GHSA-f66g-8pcg-jm8r, GHSA-327h-qqgm-qv55).

  • Rebuilding project translation memory no longer removes entries imported from files.

  • Suggestion submission and rejection now reject excessively long suggestion text and rejection reasons.

  • Restricted components are now available on Hosted Weblate when the billing plan permits private projects.

  • Machine translation and translation memory AJAX lookups no longer disclose whether inaccessible unit IDs exist.

  • RSS feeds no longer disclose change history from inaccessible projects or restricted components (GHSA-vvc6-wvqm-w5gc).

  • Authenticated legacy GitHub App webhooks can again trigger repository updates through the generic GitHub webhook endpoint.

互換性

  • django-compressor is no longer used, and the COMPRESS_* settings have been removed.

  • Legal document styling is now provided through an overridable template instead of Weblate's global stylesheet. See Customizing legal documents and styles.

  • When VCS_RESTRICT_PRIVATE is enabled, Mercurial and Subversion repository hosts must be explicitly included in VCS_ALLOW_HOSTS; Git over HTTPS and SSH enforces connection address pinning without an allowlist entry.

  • Outbound HTTP proxy configuration is limited to the per-protocol environment variables documented in HTTP プロキシ.

  • Git SSH validates configured HostName and Port destinations before connecting; administrator SSH configuration remains trusted, and SSH_EXTRA_ARGS can override connection routing and address pinning.

  • Git LFS object transfers are unsupported and disabled for Weblate-managed repositories; LFS-tracked files remain pointer files.

  • The project and component credits REST API endpoints and their credits_url response fields have been replaced by scoped reports endpoints and reports_url. Credits report generation is now asynchronous; clients need to submit a credits report, follow the returned task URL, and fetch the completed report. See POST /api/reports/.

  • The top-level languages field on user REST API responses has been removed; use profile.languages instead. See ユーザー情報.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

  • There are changes in settings_example.py, most notably the new STORAGES configuration and removal of the COMPRESS_* settings; please adjust your settings accordingly.

  • Running weblate compress is no longer necessary; weblate collectstatic --noinput now prepares versioned static assets without clearing the static storage.

  • NumPy is now a required dependency; review the updated hardware requirements before upgrading.

貢献者

コードに貢献

Michal Čihař, Karen Konou, Nikunj Tyagi, Weblate CI, Shweta Singh, Gersona, Giacomo La Serra, Kartik Ohri, mmustafasenoglu, Mustafa Senoğlu, "Emmanuelle Bonnemay", Nicolas Lepage, "Guillaume Lagorce", "Jérémie Jadé", "Matthias le Coach", Любомир Василев, Spyder

翻訳に貢献

António Oliveira, hoanghuy309, reducedradius, Michal Čihař, Andrei Stepanov, 為什麼不加空格, BoneNI, Любомир Василев, Adam Havránek, Libre, Horus68, Peter Vančo, Aindriú Mac Giolla Eoin, Matthaiks, VfBFan, Ldm Public, Mickaël Binos, Lee Vincent, Dick Groskamp, Rafael Fontenelle, Justin Parrot, Valeria Sofia Azañero, Priit Jõerüüt, Frank Paul Silye, goeran, Abduqadir Abliz, Arif Budiman, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝), Aniwene Madolomani, Pierfrancesco Passerini, Andi Chandler, Thunderstrike116, Giacomo La Serra, Ulrik, Cyborus, PPNplus, justcontributor, AlexYang, Kyotaro Iijima, Rajkumar Ramadoss, Yuri Chornoivan, DocNoc, Anucha Hlownonkor, Milo Ivir, Alexander Gabilondo, mbutsk, Oğuz Ersen, nautilusx, Yago Raña Gayoso, Blueberry, Yoshihoko, suyeon kim, Azharul Haque, win7guru, Matt P, Miguel A. Bouzada

ドキュメントに貢献

Michal Čihař, Nikunj Tyagi, Shweta Singh, Gersona, Giacomo La Serra, Weblate CI, Kartik Ohri, Karen Konou, mmustafasenoglu, Mustafa Senoğlu, Robert Wolff

All changes in detail.

Weblate 2026.7.1

Released on July 10th 2026.

新機能

改良点

  • Restricted components now show a status icon in component listings.

  • Permission checks now reuse materialized team membership data from lightweight relation lookups.

  • Documented that intermediate language files are hidden from language listings and can make target strings read-only.

  • Component diagnostics now warn when regular GNU gettext PO(ポータブル オブジェクト) PO files are configured as monolingual PO files.

  • Translation memory fuzzy lookups are now faster on large translation memories.

  • Permission denied messages when saving translations, editing glossaries, or voting on suggestions now show more specific reasons.

  • Comment notifications for strings you translated now also include strings you previously commented on or suggested translations for.

  • Comments and suggestions now auto-watch the project when Automatically watch projects on contribution is enabled.

  • Clarified Hosted Weblate repository access guidance in コードホスティング統合.

  • 文字列の検索 now includes filters for comments by the current user and separate source string comment lookups.

  • Code-hosting account pages now consistently use Code-hosting connections and provider-neutral connected account wording.

  • Weblate プロジェクトの探索 registration can now be started from the management interface without manually copying the activation token.

  • Weblate プロジェクトの探索 can now be managed from a dedicated management panel, registration starts with discovery enabled, and protected projects are included in the listing.

  • Updated the OpenAI, Mistral, and Anthropic model lists for currently supported models.

バグ修正

  • Filtered translation and zen navigation now reuse a stable session result list, keeping positions and counts stable after translated strings leave the filter.

  • Component priority icons are no longer shown on translation listings.

  • 句読点のスペース no longer flags Markdown image markers as French punctuation and now shows which punctuation marks triggered the check.

  • Fedora メッセージング received several reliability fixes.

  • The Things to check panel no longer uses error highlighting for suggestions and other non-error translation states.

  • Translation workflow customization now makes it clearer when per-language workflow settings are disabled until customization is enabled.

  • Anonymous user permission caches are now isolated between requests.

  • GitHub App setup now explains that a workspace is required instead of showing a permission error when no workspace exists.

  • LLM automatic suggestion settings no longer show null for empty language-specific instructions.

  • File format feature tables now better match actual format support, including descriptions, context, plural metadata, obsolete string removal, specialized file extensions, and merged variants.

  • Accepting a project invitation now automatically adds the project to the user's watched projects.

  • Dismissing a failing check no longer shows a JSON parsing error in the translation editor.

  • Screenshot searches without an explicit field now match screenshot names only, and the search box links to the full screenshot search documentation.

  • Anonymous and internal bot accounts can no longer be edited through generic user management.

  • LLM machine translation suggestions now recover from more malformed structured JSON replies.

  • Azure AI Translator settings now reject malformed region names before validating service connectivity.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

  • Weblate now requires the PostgreSQL btree_gist extension for translation memory lookups. The migration installs it automatically when the database user has sufficient privileges. Installations using a non-superuser database user should pre-create it before upgrading; see PostgreSQL でデータベースの作成.

貢献者

コードに貢献

Michal Čihař, Karen Konou, Weblate CI, Benjamin Alan Jamie, Kartik Ohri

翻訳に貢献

Michal Čihař, António Oliveira, 大学没毕业, 為什麼不加空格, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝), hoanghuy309, Libre, VfBFan, Peter Vančo, Jim Kats, ButterflyOfFire, Kiên Trần Trung, skittles poopy, Ulrik, Horus68, Mickaël Binos, Adam Havránek

ドキュメントに貢献

Michal Čihař, mayank-dev-15, Benjamin Alan Jamie

All changes in detail.

Weblate 2026.7

Released on July 1st 2026.

新機能

改良点

  • RTL editing and translation display now handle bidirectional text better, including Unicode isolate controls in the ビジュアル キーボード.

  • Management interface access control is now more fine-grained with dedicated site-wide permissions.

  • Default commit and merge request message templates now use Conventional Commits, settings forms can restore installation defaults, and pull request messages use a compact language progress matrix.

  • Documented 法務モジュール customizations and added options to hide legal pages or disable document numbering.

  • Expanded security documentation for data residency, EU cloud sovereignty, release artifacts, supported versions, release verification, SBOMs, dependency handling, vulnerability reporting, hosted-service incident response, and self-hosted operator responsibilities.

  • LINGUAS ファイルの更新 better detects LINGUAS file presence.

  • POT ファイルの更新(xgettext) can now leave the xgettext language blank to let xgettext guess it from source file extensions.

  • POT ファイルの更新(xgettext), POT ファイルの更新(Meson), gettext テンプレートの更新(Django), and POT ファイルの更新(Sphinx) can now keep source locations in generated POT files even when translated PO files omit locations.

  • Add-ons installed at higher scopes are now shown on lower-scope add-on pages, and broad-scope add-ons can list affected components with compatibility details.

  • WEBLATE_ALLOWED_ASSET_SIZE is now available in Docker container.

  • LLM automatic suggestions now use translated examples, language-specific instructions, richer glossary context, and structured placeholder context for more reliable output.

  • Meta descriptions now better match single-project and self-hosted installations.

  • Zen mode, filtered searches, nearby strings, translation form submissions, and add-on management pages now load more efficiently on large sites.

  • Added Packaging Weblate for distributions guidance for distribution maintainers.

  • Large component imports now avoid duplicate translation-memory processing.

  • GNU gettext PO(ポータブル オブジェクト) files can now be configured to remove obsolete strings on save, including during repository maintenance.

  • Bulk accepting suggestions now confirms the number of affected suggestions, can approve them for reviewers, and processes the acceptance in the background.

  • Committing large numbers of pending translations now queues browser requests in the background and avoids duplicate repository commit tasks.

  • Change-event notification add-ons can now use presets for translation content events, all events, or selected individual events.

  • Fedora メッセージング now validates secure broker connections and exposes delivery timing and topic prefix settings.

  • Component diagnostics now sort entries by severity, color-code severity badges, and show the error count on the Diagnostics tab.

  • 性能レポート now shows PostgreSQL database disk usage next to server disk usage and warns when the database usage cannot be collected.

  • 性能レポート now shows PostgreSQL database disk usage next to server disk usage and warns when the database usage cannot be collected or there is not enough free space in the backup destination to store a database dump.

  • The 検索と置換 preview now keeps the search parameters editable so the query can be refined before applying replacements.

バグ修正

  • 正規表現 and プレースホルダー now enforce regular expression timeouts when evaluating source-string flags (CVE 2026-62326, GHSA-r52j-4vjp-q949).

  • Restricted component changes are no longer exposed through nested project, component, or translation API change endpoints (CVE 2026-62249, GHSA-92m8-wv36-prmx).

  • ZIP downloads, including アプリ ストアのメタデータ ファイル translation bundles, no longer follow child symbolic links outside the downloaded tree (CVE 2026-61792, GHSA-xwj4-fp82-r2rj).

  • Teams enforcing two-factor authentication now also withhold site-wide permissions from human members without 2FA configured (CVE 2026-61790, GHSA-x86c-ff69-cr2m).

  • Globally scoped HTML and AJAX object lookups no longer disclose object existence in private projects (CVE 2026-55227, GHSA-2p9g-x3cv-5hh4).

  • Team API access checks now prevent project managers from reading private-project team data or expanding scoped team assignments outside their allowed projects (CVE 2026-55228, GHSA-2q2q-jr9g-v9rf).

  • Malformed replacements flags no longer abort source length checks.

  • Empty component lists are no longer exposed to users without component list management permission.

  • Glossary handling no longer duplicates TBX terms or shows source-language terms in both translation columns.

  • Duplicate string alerts now offer a cleanup action to remove repeated strings from translation files.

  • Gerrit review requests review pushes can again include Gerrit push options in the target branch.

  • Webhook target fallback matching is now stricter and reported in component diagnostics.

  • Creating components linked with weblate:// no longer waits on the shared repository lock during the request.

  • Project and workspace translation license defaults now follow component and project licenses more closely.

  • Component and category API PATCH requests no longer remove the category when the field is omitted.

  • Document and translation-memory uploads now enforce TRANSLATION_UPLOAD_MAX_SIZE, and API document uploads validate file extensions.

  • reStructuredText 構文エラー now detects inline roles wrapped in stray backticks.

  • 安全でない HTML now efficiently detects changed placeholder-only HTML attribute values in translations.

  • 翻訳の文字の最大サイズ no longer wraps text configured to fit on one line, checks source strings, and refreshes rendered previews after source edits.

  • Bitmap widgets and 翻訳の文字の最大サイズ previews now use Matplotlib and no longer require Pango, Cairo, librsvg, or GObject Introspection.

  • Repository reset and update history now keeps attribution, records remote update failures, and includes follow-up translation-file reconciliation.

  • Updating repository URLs now validates compatible Git history without requiring an immediate successful merge.

  • 自動翻訳 no longer validates hidden component fields when using machine translation.

  • Strings marked for edit links now include all strings needing editing, checking, or rewriting.

  • Anonymous permission checks no longer fail when loading teams scoped to projects or workspaces.

  • API project creation can again use the user's only eligible workspace when no explicit workspace is supplied.

  • Git auto-maintenance is now disabled for Weblate-managed repositories to avoid concurrent detached maintenance jobs.

  • Interrupted Git repository operations are now either recovered and recorded or surfaced as a repository alert.

  • Watched translations on the dashboard now include category path segments.

  • Unsupported upload levels now show an upload placeholder pointing to individual translations.

  • Component API responses no longer expose repository export, push branch, or repository browser links to users without repository access.

互換性

  • DeepL now handles DeepL API versions internally, uses v3 for glossary management and language discovery, and no longer supports DeepL API v1.

  • Fedora メッセージング topics now include category path segments, and broker settings are stored as an AMQP URL with existing host and SSL settings migrated automatically.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

  • There are changes in settings_example.py, most notably in SOCIAL_AUTH_PIPELINE and SOCIAL_AUTH_DISCONNECT_PIPELINE; please adjust your settings accordingly.

  • Existing translation-memory entries are moved to scoped storage by a periodic Celery background task. Keep Celery running after the upgrade; translation-memory suggestions can be incomplete until the backfill finishes.

貢献者

コードに貢献

Michal Čihař, Karen Konou, Weblate CI, michael-smt, Samuel Gomes, Dinis Sales, Gersona, Harsha C, Kartik Ohri, Besnik Bleta, fahadhewad

翻訳に貢献

Dick Groskamp, Michal Čihař, 為什麼不加空格, VfBFan, Любомир Василев, 이정희, Aindriú Mac Giolla Eoin, Yaron Shahrabani, jiahaisheng, Horus68, Andrei Stepanov, Martin Srebotnjak, Peter Vančo, Hotripak, 大王叫我来巡山, Milo Ivir, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝), Mickaël Binos, Besnik Bleta, Frank Paul Silye, Matthaiks, abd sak, Hoseok Seo, Fulup Jakez, Gaël TISSERAND (Gtisseran), Azamat Аituganov, Mahirə Həsənova, Pierfrancesco Passerini, Libre, Mohamed Aymane Farhi, Júlia Rosell Saldaña, پرویز قادر, Jim Kats, Miguel A. Bouzada, Manuela Silva, reducedradius, Hanssium, Uh idk, Arif Budiman, Feike Donia, Zahid Rizky Fakhri, Emin Tufan Çetin, ojppe, தமிழ்நேரம், António Oliveira, Rumuz AGO, justcontributor, Flynn, Ștefan Zaharia, Nozomu Matsui, H-Media, Ecron, Weblate CI, Balázs Meskó, Fjuro, goeran, Adam Havránek, Priit Jõerüüt, Astrid Høie Silden, Alan S. Muhammed (Alan Kurdish), hoanghuy309, Yamin Siahmargooei, MeahNunh, Kartik Ohri, Valeria Sofia Azañero, Tuomas Hietala, Rafael Fontenelle, Yuri Chornoivan, AWwue-work, Kristoffer Grundström, ssantos, Andi Chandler, Ldm Public, Alc4Traz45, Szafranek13, hms5232, Victor K, 大学没毕业

ドキュメントに貢献

Michal Čihař, michael-smt, Karen Konou, Gersona, Weblate CI, Kartik Ohri, Besnik Bleta, fahadhewad, Harsha C

All changes in detail.

Weblate 2026.6.1

Released on June 1st 2026.

バグ修正

  • Language-wide お知らせ no longer break language overview pages.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

貢献者

コードに貢献

Michal Čihař

ドキュメントに貢献

Michal Čihař

All changes in detail.

Weblate 2026.6

Released on June 1st 2026.

新機能

  • お知らせ can now also be managed via the Weblate の REST API for specific project languages.

  • Team memberships can now be limited to selected languages for per-user translation permissions.

  • Added cost estimates to translation reports.

  • Added optional OpenTelemetry tracing for backend requests and tasks, and Google Cloud Error Reporting for handled server errors.

  • Added Workspaces to group related projects, with workspace project listings, workspace-scoped teams and project creation permissions, inherited workspace, project, and category defaults for selected component settings, and billing details when available.

改良点

バグ修正

  • Outbound URL validation now rejects additional non-public targets (CVE 2026-50127, GHSA-vmfc-9982-2m45).

  • Project-language お知らせ no longer appear across the whole project.

  • Hardened POST /api/screenshots/ access checks against private project enumeration.

  • Registration-attempt account activity e-mails now link to password reset to help users finish account setup.

  • 新しいユーザーの招待 links now work for signed-in users whose account owns the invited e-mail address.

  • Searching for strings with content changes without a recorded author now supports changed_by:"", and combined change filters now apply to the same change event.

  • Gitea and Forgejo pull requests no longer reconfigure existing fork remotes to point to the source repository.

  • Project and category language translation sessions now keep strings grouped by component priority and show component switch warnings reliably.

  • Engage page task links now stay centered and show the target translation language.

  • Gettext POT update add-ons now rescan translations after committing updated POT and PO files.

  • Git repositories now update branches correctly when the remote also has a tag with the same name.

  • Conflicting repository setup alerts now allow same-branch direct pushes.

  • Obsolete cleanup schedules are now removed from Celery beat during upgrade.

  • Translation pages for workspace projects no longer crash when workspace fields are deferred.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

  • There is a change in INSTALLED_APPS; weblate.workspaces should be added.

  • The database migrations might take longer on larger instances.

貢献者

コードに貢献

Michal Čihař, Karen Konou, Weblate CI, Basheer Radman, michael-smt, Kristián Kunc, felixfon

翻訳に貢献

Michal Čihař, VfBFan, 大王叫我来巡山, Emin Tufan Çetin, Basheer Radman, 為什麼不加空格, Peter Vančo, Christian Wia, Любомир Василев, Matthaiks, Andrei Stepanov, Libre, Besnik Bleta, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝), Balázs Meskó, Aindriú Mac Giolla Eoin, Adam Havránek, Dick Groskamp, Arif Budiman, Mickaël Binos, Ryo Nakano, hoanghuy309, Pierfrancesco Passerini, Alefsander Ribeiro Nascimento, Massimo Pissarello, justcontributor, 이정희, Cabdi Waaxid Siciid, Yaron Shahrabani, User2068, Kyotaro Iijima, pan93412, jernejp21, libermax, Phileas Fogg, Fjuro, Jim Kats, Fulup Jakez, Priit Jõerüüt, Ldm Public, Andi Chandler, Burak SDN, ojppe

ドキュメントに貢献

Michal Čihař, VfBFan, Basheer Radman, Weblate CI, michael-smt, felixfon

All changes in detail.

Weblate 2026.5

Released on May 15th 2026.

新機能

  • Added MDX ファイル support for translating Markdown text while preserving JSX syntax, with ファイル形式パラメータ shared with Markdown ファイル for line wrapping, code blocks, front matter, and placeholder handling.

  • Added extended LLM translation context for automatic suggestions, covering string context, explanations, secondary-language translations, plurals, failing checks, and placeholders.

  • Added a digest-only translation activity summary notification, see 通知.

  • CSV and XLSX downloads in 翻訳のダウンロード now export plural strings as separate plural-form rows that can be imported back.

  • Added Gettext PO and POT ファイル形式パラメータ to control whether Weblate updates the Language-Team, Last-Translator, X-Generator, and Report-Msgid-Bugs-To headers.

  • Added a backup to run configured backup services synchronously.

  • The translation memory lookup API can now skip fuzzy matching with the exact query parameter.

  • Added 翻訳ファイルの CDN to publish translation files to the configured CDN.

改良点

  • Using DOS line endings can now be configured using the dos_eol ファイル形式パラメータ.

  • OpenAI and Alibaba no longer require their vendor Python SDKs.

  • Audited project and component setting changes are now recorded in history.

  • Gerrit review pushes now use プッシュ先のブランチ as the target branch.

  • Weblate now checks whether CACHE_DIR allows executing generated helper files.

  • The ソフトウェア部品表 is now generated during release and published as a versioned release asset instead of being stored in the source repository.

  • The translating page now separates screenshots from string information, collapses rarely used string details, and groups glossary and screenshot actions more consistently.

  • Project access management now paginates users and better explains site-wide automatic team assignments.

  • Added provider-oriented code-hosting documentation and Gettext-style 複数形判別式 guidance.

  • The Python wheel no longer ships source translation catalogs, test files, or deployment example files, reducing the installed package size.

  • The engage page now highlights actionable translation task buckets for newcomers.

  • RSS feeds can now use the same filters as the changes browsing page.

  • gettext テンプレートの更新(Django) now supports gettext PO files used as templates when they are excluded by the language filter.

  • Reworked Weblate の脅威モデル into a contract-style document.

バグ修正

  • Hardened search previews and 自動提案 suggestion origins against XSS, and stopped exposing database error details in upload failures (CVE 2026-45106 / GHSA-6wxc-8mgq-w26m).

  • Screenshot URL uploads, remote HTML extraction in JavaScript 現地語化 CDN, and URL health-check redirects now reject internal or non-public targets by default.

  • Gerrit review pushes now reject target branches containing push options, track the target branch before invoking git-review, and suggest short branch names when full refs are supplied.

  • Category お知らせ no longer appear across the whole project, and translation announcement deletion now honors language-scoped permissions.

  • Merge request pushes now refresh stale fork remotes after changing repository hosting.

  • Plural counts parsed from translation file headers are now bounded, and plural formulas are rejected when they can evaluate outside the configured plural form range.

  • プロジェクトごとのアクセストークン expiring today now remain valid until the end of the day.

  • Malformed ALTCHA CAPTCHA submissions and repository URLs in webhook payloads no longer cause server errors.

  • プレースホルダー now merges overlapping non-nested spans from multiple flags.

  • Weblate のバックアップと移動 logs no longer include OpenSSH post-quantum key exchange warnings from remote Borg connections.

  • Category repository paths are now handled more safely during cleanup and moves.

  • Locked component pages now show an unsubscribe action after subscribing to unlock notifications.

  • プロジェクト レベルのバックアップ imports now restore in the background to avoid web worker memory limits.

互換性

  • The dos-eol flag is no longer supported. Use the dos_eol ファイル形式パラメータ instead.

  • The registration CAPTCHA now uses the ALTCHA widget v3 protocol with Argon2id proof-of-work.

  • The set_language_team project attribute has been replaced with the po_set_language_team file format parameter at the component level; see ファイル形式パラメータ.

  • Weblate now uses calendar versioning for releases, see リリースの周期.

  • Weblate now uses stricter dependency version constraints to better control runtime environment.

アップグレード

更新するには、一般的なアップグレード方法 に従ってください。

貢献者

コードに貢献

Michal Čihař, Karen Konou, AliceVisek, Gersona, Weblate CI

翻訳に貢献

이정희, Andrei Stepanov, Milo Ivir, ssantos, 大王叫我来巡山, Kaya Zeren, reducedradius, Peter Vančo, amano, Michal Čihař, Anucha Hlownonkor, Yaron Shahrabani, UDP, Максим Горпиніч, Agnieszka C, VfBFan, Blueberry, ojppe, Francisco Serrador, Aindriú Mac Giolla Eoin, Fjuro, Любомир Василев, Frank Paul Silye, Temuri Doghonadze, Yuri Chornoivan, Sergio Granadoz, Sketch6580, Hyeonjeong Lee, 為什麼不加空格, ℂ𝕠𝕠𝕠𝕝 (𝕘𝕚𝕥𝕙𝕦𝕓.𝕔𝕠𝕞/ℂ𝕠𝕠𝕠𝕝), justcontributor, Kristijan "Fremen" Velkovski, Pierfrancesco Passerini, Besnik Bleta, Arif Budiman, Andi Chandler, jernejp21, Manuela Silva, Sjur N Moshagen, Abduqadir Abliz, Laitei, Кирилл Ванин, Matthaiks, Nozomu Matsui, Dick Groskamp, MrZwave, hoanghuy309, Jim Spentzos, Adam Havránek, Ricky Tigg, Christian Wia, ButterflyOfFire

ドキュメントに貢献

Michal Čihař, Gersona, Karen Konou, AliceVisek

All changes in detail.