--- snapshot-1791033818+++ snapshot-1791055417@@ -18,7 +18,7 @@ v0.26.0 -
Caution
We recommend skipping direct to v0.26.1, this release has an issue with attachments for docker containers.
Note
As always, we highly recommend making a backup of your databases and files before upgrading! But especially this one for it's major architecture changes.
Warning
This release requires an additional environment variable or CLI parameter to be set. HBOX_AUTH_API_KEY_PEPPER or --auth-api-key-pepper must be set to at least 32 characters random secret.
This is by far the biggest, most comprehensive release of Homebox since we took over. Below are the biggest, most important changes. Please read through the warnings and notes carefully, as they contain important upgrade information.
This release officially implements the entity merge, one of the most comprehensive and complex changes to the Homebox backend ever. Items and locations now share a single underlying "entity" structure, allowing them to share custom fields, attachments, entity types, and templates — and preparing Homebox to take on the features and capabilities people have been asking for.
Warning
The entity merge introduces significant database re-work. You should always make a backup before updating, but a backup is especially important in this case.
Important
If you are an integration/software developer, the /v1/items* and /v1/locations* endpoints have been entirely replaced by /v1/entities*. Please review our entity merge documentation for the API changes.
Homebox can now generate static API Keys for developers/integrations. Each key takes on the access level of the user who created it. All Homebox keys are prefixed with hb_ to help prevent secrets from being accidentally committed to source code repositories.

Homebox now supports password resets. If the instance admin configures the SMTP environment variables, users can reset their password from the front-end quickly and easily. For those not wanting to set up SMTP, you can run homebox reset-password --email=, which outputs a random new password for that user (which they can then change from the UI).

Thanks to the entity merge, you can now export an entire collection's inventory (including attachments, tags, entities, etc.) into a single ZIP file. That ZIP can then be imported into a different Homebox instance (the receiving collection must be "empty"). A recurring background export task is included as well.
Added more as a fun experiment, but we think some people will find it genuinely useful. Switch to "AR" mode and point your camera at a Homebox QR code — a hovering box appears with basic information about the entity, and if it has children, a list of those child entities.
The following security advisories have been fixed:
Full Changelog: v0.25.0...v0.26.0
tankerkiller125 tag:github.com,2008:Repository/816422401/v0.26.0-rc.1 2026-05-25T16:06:37Z +Caution
We recommend skipping direct to v0.26.1, this release has an issue with attachments for docker containers.
Note
As always, we highly recommend making a backup of your databases and files before upgrading! But especially this one for it's major architecture changes.
Warning
This release requires an additional environment variable or CLI parameter to be set. HBOX_AUTH_API_KEY_PEPPER or --auth-api-key-pepper must be set to at least 32 characters random secret.
This is by far the biggest, most comprehensive release of Homebox since we took over. Below are the biggest, most important changes. Please read through the warnings and notes carefully, as they contain important upgrade information.
This release officially implements the entity merge, one of the most comprehensive and complex changes to the Homebox backend ever. Items and locations now share a single underlying "entity" structure, allowing them to share custom fields, attachments, entity types, and templates — and preparing Homebox to take on the features and capabilities people have been asking for.
Warning
The entity merge introduces significant database re-work. You should always make a backup before updating, but a backup is especially important in this case.
Important
If you are an integration/software developer, the /v1/items* and /v1/locations* endpoints have been entirely replaced by /v1/entities*. Please review our entity merge documentation for the API changes.
Homebox can now generate static API Keys for developers/integrations. Each key takes on the access level of the user who created it. All Homebox keys are prefixed with hb_ to help prevent secrets from being accidentally committed to source code repositories.

Homebox now supports password resets. If the instance admin configures the SMTP environment variables, users can reset their password from the front-end quickly and easily. For those not wanting to set up SMTP, you can run homebox reset-password --email=, which outputs a random new password for that user (which they can then change from the UI).

Thanks to the entity merge, you can now export an entire collection's inventory (including attachments, tags, entities, etc.) into a single ZIP file. That ZIP can then be imported into a different Homebox instance (the receiving collection must be "empty"). A recurring background export task is included as well.
Added more as a fun experiment, but we think some people will find it genuinely useful. Switch to "AR" mode and point your camera at a Homebox QR code — a hovering box appears with basic information about the entity, and if it has children, a list of those child entities.
The following security advisories have been fixed:
Full Changelog: v0.25.0...v0.26.0
tankerkiller125 tag:github.com,2008:Repository/816422401/v0.26.0-rc.1 2026-05-25T16:06:37Z v0.26.0-rc.1