Self-Hostedv4.0.02026-09-17
Self-Hosted 4.0: Public API, watchers, and cross-project dependencies
The Base Edition opens its 4.0 line, bringing the Public API, watchers, reusable checklists, dependencies that cross projects, and the rebuilt left navigation together under one major version.
- Public APIREST access authenticated by API key, with per-key role validation, IP allow lists, and scopes checked against a fixed catalog rather than trusted from the request. Includes a milestone endpoint reporting document approval progress per task. Gated by PUBLIC_API_ENABLED.
- WatchersWatch any work item and be notified as it changes, or take it as a daily or weekly digest instead. Watch settings sit on the task detail view, and digests are delivered by their own scheduled commands.
- Checklist frameworkReusable checklists with an administration area and a checklist rail on the task detail view, with inline editing of items and groups, suggested items, and activity tracking.
- Dependencies across projectsTasks can be linked and made dependent across project boundaries. A link stored once is shown from both sides with the correct label, and feeds a program Flow view and the Gantt chart.
- Rebuilt left navigationA grouped, dynamic menu with shortcuts each person pins and custom links they add themselves, validated and capped per user. Where it is switched off the previous menu is served instead, so a staged rollout strands nobody.
- Upgrading from the 3.8 series4.0 is the 3.8.26 build under the new version line, so an install already on 3.8.26 is current. Coming from earlier, follow the migration and seeder steps in the 3.8.25 and 3.8.26 notes and clear the cache afterwards.
Self-Hostedv3.8.262026-09-15
Disabled accounts shut out, and the Public API moves into Settings
Account status is now enforced on every way into the product, including the new Public API, and the API itself moves out of the left navigation into Settings.
- Disabled accounts are refused everywhereAccount status is checked across the app, the REST endpoints, single sign-on, and the Public API key middleware, so a disabled user can no longer reach any of them.
- Public API moves into SettingsIt now sits under Settings and Integrations rather than in the left navigation.
- License owner resolved properlyThe license owner comes from the real owner record instead of assuming the first user account, with a fallback for older installs.
- Epic and Feature edit dialogsTeam assignment is filled from the record and the assignee list is resolved for each dialog, so the current assignee is no longer lost when you switch teams.
- Add task reads only the dialog you can seeEpic, feature, and story ids are taken from the visible dialog, so a hidden one can no longer leak stale ids into the task you save.
- After upgradingRun the Public API seeder and the two commands named in the release notes, then clear the cache. The per-user sidebar is cached, so a stale menu will keep being served until you do.
Self-Hostedv3.8.252026-09-01
Watchers, checklists, a public API, and a new sidebar
Three cloud capabilities are ported into self-hosted, dependencies can cross projects, and the left navigation is rebuilt. Every new plugin sits behind its own flag and adds nothing until you turn it on.
- Public APIKey authenticated REST access with role checks and IP allow lists, plus a milestone document approval report. The scopes attached to a key are validated against a fixed catalog rather than trusted from the request.
- WatchersWatch any work item and be told when it changes, with a daily or weekly digest email.
- Checklist frameworkAn admin area and a checklist rail on the task detail view, with inline editing of items and groups, AI suggested items, and activity tracking.
- Dependencies across projectsTasks can be linked and made dependent across projects, with a company scoped picker, a program Flow view, and Gantt integration. A link stored once appears on both items, labeled correctly from each side.
- A new left navigationA grouped, dynamic menu with shortcuts you can pin and links you add yourself. Where it is not supported the navigation falls back to the previous menu instead of breaking.
- Run migrations after deployingThis release adds tables for the new plugins.
Self-Hostedv3.8.242026-08-19
Archived documents and cleaner version history
Archived documents get a status of their own, the change request work from 3.8.23 reaches the dashboard, and the editor stops creating versions nobody asked for.
- Closing the editor no longer creates a versionA version is created only when you choose one in the Save version dialog. Leaving the editor no longer bumps the number on its own.
- Simpler Save version dialogThe optional change summary is gone. Choose the patch, minor, or major bump and save.
- Changes Requested on the dashboardThe dashboard status breakdown counts change requests on their own line, and the draft count no longer includes them.
- Archived is a first class statusArchived documents get their own badge, their own label, and a filter option on the All Documents list.
Self-Hostedv3.8.232026-08-14
Request changes, made visible
A documents only release that repairs the request changes half of document approval. A change request used to erase every trace of itself from the document lists, and in several cases the document could not be recovered.
- Change requests appear in the listsA document with changes requested carries its own amber badge and filter option, and the status tooltip names who asked and at which level.
- The workflow can always be resumedAnyone permitted to upload a new version can resume the review, not only the person who submitted it. Documents used to be stranded in draft.
- Earlier approvals are carried forwardA new version resumes at the level that asked for changes rather than discarding approvals already given. Restart approval workflow stays as the opt in for a full re-review.
- Choose the level to resume fromThe New Version dialog exposes a resume level, capped at the level that asked for the changes and floored at the first level that has not approved.
- Rework assignment is surfacedWhen a document is rejected and assigned to someone for rework, the sidebar and the rejected step now name them.
Self-Hostedv3.8.222026-08-12
Leave workflows, custom fields, and exports
Editing a leave approval workflow silently wiped its approval levels. That is fixed here, alongside custom field ordering, date handling, and the Task Detail export.
- Leave workflow edits keep their levelsEditing a leave approval workflow, or simply setting it as the default, no longer deactivates its approval levels.
- A command to restore wiped levelsA maintenance command reports workflows whose levels were already lost, and reactivates them when you ask it to apply the change.
- Task Detail export produces a file againThe export was failing outright. It now builds and returns the file.
- Custom field order follows SettingsThe order you set by dragging in Settings now reaches the task list and the exports, instead of being ignored.
- Custom field dates behaveDates parse from an explicit list of formats, store consistently, and preselect when you edit inline. A start and due date on the same day is accepted.
- Search ignores capitalizationProject, task group, user, and timesheet approver searches all match regardless of case.
Self-Hostedv3.8.212026-08-04
Task nesting capped at three levels
Task nesting is capped at three levels. Convert To Subtask previously accepted any parent, so a deep chain could be built by accident and then rendered awkwardly in the task list.
- Three levels, enforced on the serverTask, subtask, and sub-subtask. A conversion is checked against the moved task's own depth and the target parent's, and a task cannot be nested under itself or its own descendant.
- The action hides where it cannot workConvert To Subtask no longer appears on tasks that already have grandchildren.
- The parent task dropdown lists the right tasksThe combined parent and subtask list keeps real task ids instead of replacing them with positions, so the dropdown no longer offers the wrong tasks.
- Wiki lookups are permission checkedThe two read only wiki lookups are gated on project membership and scoped to your company, and a denial returns a proper error rather than a page the browser silently follows.
Self-Hostedv3.8.202026-07-30
Hide deletions from the document audit log
Deletions can be kept out of the document audit log entirely. Some organizations do not want them surfaced in the audit trail at all, because the Deleted filter itself invites questions about what was removed.
- A delete filter constantA new setting, shipped switched off, hides the Deleted option in the document audit log and excludes deletion records from the listing, the audit API, and the CSV export. It is enforced on the server.
- Company branding in the editorThe editor top strip resolves your company logo and shows the company name alongside it.
- Editors on a prefixed document serverA document server URL that carries a path prefix no longer breaks the editor logo or the Back to document link.
Self-Hostedv3.8.192026-07-30
A per field task audit log
Until now a task edit produced a single generic Modified the Task row. You could see that something had changed, but not what.
- Field by field task historyTask edits are recorded per field and rendered on the task Activity tab as the field, its old value, and its new one. Around twenty fields are tracked, with ids resolved to names and long values shortened.
- Version compare uses the editor's own panesIn page and split page comparisons hand the revised file to OnlyOffice with track changes on for the formats that support it. The built in colored diff remains the fallback.
- Choose your editorWith the engine setting on ask, Edit becomes a dropdown of the editors available for that document.
- One rule for editing during approvalThe same check drives the button label and what the editor enforces. Pending means current level approvers only, changes requested means the owner only, and everyone else is read only.
Self-Hostedv3.8.182026-07-27
OnlyOffice for documents
OnlyOffice Document Server joins the existing editor, so Office formats and PDFs can be edited at their native fidelity, with version comparison and a permission that separates editing from reading.
- OnlyOffice as an editor engineEdit Word, Excel, PowerPoint, and PDF files in place. The document server pulls each version's bytes from the app, and a verified save callback creates a new version through the same line that uploads use.
- Save version dialogChoose a patch, minor, or major bump, with a preview of the next label and an optional summary of what changed.
- Compare two versionsA colored line and cell diff across Office, CSV, and text formats, in page or split page, with changes that are formatting only detected as such.
- An Edit Document permissionA dedicated permission decides who can edit rather than only read, enforced through the signed editor configuration. Owners and admins have it, and other roles need it alongside Upload New Version.
- Approvals KPI cardsOverdue, Approved Today, and Delegated to me counts on the Approvals page, with overdue taken from the same threshold the reminder emails use.
- Callbacks are hardenedA save is refused when no document server secret is configured, and the save and changes URLs must belong to the configured server before any bytes are fetched.
Self-Hostedv3.8.172026-07-22
The Outlook add-in is turned on
The Outlook integration ships enabled, and its email to task pane gets a proper sign-in.
- Bearer token sign-inThe task pane signs in with a token held in Office Roaming Settings, issued with an expiry and checked on every API request. Sign-in works through the Office Dialog API or a system browser fallback.
- Labels reach the pluginsProject and Task labels that were still hardcoded now honor each company's Label Customizer overlay, both on server rendered screens and in the single page screens.
Self-Hostedv3.8.162026-07-21
Scrum backlog and board
The cloud edition's Scrum backlog and board is ported to self-hosted. It ships prebuilt and owns no migrations.
- Backlog and Kanban boardScrum projects get sprint and backlog columns, epic grouping, a Backlog and Board toggle on each page, and view state that is remembered.
- Filter by a date range you chooseA custom date range on the Filters, Dates tab.
- Reassign from a backlog rowChange the assignee inline, without opening the item.
- Defects in sprint planningDefects can be associated with sprints and milestones.
Self-Hostedv3.8.152026-07-17
More than one approver per level
Approval workflows can assign several approvers to a single level, and user created folders can be deleted.
- Multiple approvers per levelEach level of an approval workflow takes a list of approvers, chosen with a multi-select user search, instead of exactly one person.
- Delete a folderUser created folders can be removed, with a confirmation and an optional move of their contents. Only empty, directly selected, user created folders qualify, so auto-generated folders cannot be removed.
- More email tokensThe six task templates expose the actor's full name and email address alongside their first name, with the sender name corrected.
- No more duplicated commentTask comment notification emails render the comment once, not twice.
Self-Hostedv3.8.142026-07-15
Folder paths in the document reports
Document reporting picks up full folder paths, and the audit log becomes readable.
- Folder column on the Document Ageing ReportThe report shows each document's folder as a full breadcrumb path, with the approver for each stage shown in the grid.
- Readable audit detailsActivity details render as clean rows with internal ids removed, folder events show the full breadcrumb, and timestamps use 12 hour AM and PM.
- One folder path builderA single shared service renders folder paths identically in the audit log and the Document Ageing Report.
- Accurate invitation countsThe invited tab badge and the manage KPI card count members with an active invitation, matching the invited list and its export.
Self-Hostedv3.8.132026-07-15
User KPIs and a PostgreSQL porting toolkit
A KPI header on User Management, and a toolkit for teams moving a live MySQL database onto PostgreSQL 16.
- KPI header on User ManagementKey user counts, including an online users metric based on recent logins, with a tooltip explaining how online is measured.
- MySQL to PostgreSQL toolkitTwo commands. One reconciles a schema against a reference, creating missing tables and columns and correcting type mismatches. The other completes the move and can be re-run safely.
- Unlimited and free plansThe user subscriptions page no longer fails on plans with unlimited seats, which also affected fresh installs.
Self-Hostedv3.8.112026-07-13
Label Customizer on by default
Per company relabeling ships switched on, and now reaches the screens that still hardcoded Project and Task. No migrations ship with this release.
- On by defaultRename core nouns for your company, for example Project to Case. The overlay is applied by middleware that can still be switched off with a constant.
- Coverage across the pluginsServer rendered screens and the single page screens for Documents, Attendance and Leave, and Risk Management all pick up the overlay.
Self-Hostedv3.8.102026-07-13
Document audit log gets a project filter
A patch that tightens the document reporting added in the previous two releases.
- Audit log project filterThe document audit log and document settings gain a project filter. People only see the projects they belong to.
- Ageing report fixesBetter grid rendering and text handling in the Document Ageing Report, with corrected sorting and timezones in the CSV and XLSX export.
- Audit log eventsThe Deletion option is removed from the audit log event filter, and deletion events no longer appear there.
Self-Hostedv3.8.92026-07-10
Document Ageing Report
A new report that shows how long each document sits at every approval stage.
- Document Ageing ReportMeasures per stage and total approval age across multi level workflows, for approved and in progress documents. Filter, sort, paginate, and export to CSV or XLSX. It is read only and never touches the approval flow.
- Working day ageingApproval age can count working days only, skipping weekends and holidays taken from the Attendance and Leave calendar.
- Configurable audit KPIsAdmins choose which activity metrics appear on the document audit log.
Self-Hostedv3.8.82026-07-09
Approval reminders and overdue escalation
Automatic chasing for approvals that have been waiting too long, for both documents and leave.
- Document approval remindersA scheduled job emails a reminder once an approval passes the threshold you set, then a final escalation notice to the document owner. Each level is chased once.
- Leave approval remindersPending leave requests now chase both the applicant and the approver, with a final overdue notice. Approval email times show in the reader's own timezone.
- Approval turn around timeNotified and actioned times are recorded, so the approval progress view shows how long each step took.
- Repository and audit logFolders and documents sort in natural order, and the audit log gains server side filtering with headline figures.
Self-Hostedv3.8.72026-07-07
Cleaner file list on tasks and in the repository
A focused fix for how task attachments appear in the document repository.
- No duplicate attachmentsFiles uploaded straight to a task no longer appear a second time as separate document links. Documents you added with Link from DMS still show as before.
- Correct file pathsTask file attachments resolve their file path correctly, and only active tasks are counted.
Self-Hostedv3.8.62026-07-06
Gantt export runs in the background
Large Gantt exports no longer tie up your browser.
- Async Gantt exportPDF and PNG export runs as a queued job with progress tracking, and resumes if you reload the page. You can pick a sprint, a date range, and a scale.
- Gantt task typesThe timeline shows task type icons and a clearer task name layout.
- Comment email controlThe comment box gains a toggle for which recipients get the notification email.
- Document search and repositorySearch query fixes, loading indicators, an approval date column, and MSG added to the allowed file types.
Self-Hostedv3.8.52026-07-02
Bulk approve documents from a review window
Approval and repository navigation improvements in document management.
- Bulk approve with a commentApprovers can clear several pending documents at once through a review window that captures a comment and an optional supporting file.
- Folder navigationThe repository expands the tree to the folder you are in and keeps the address in step, so going back keeps your place.
- Mention searchMentions now match on first name, last name, or full name, whatever the capitalisation.
Self-Hostedv3.8.42026-07-01
Working hours figure and a Gantt epic filter
A round of fixes and small additions across attendance, Gantt, and documents.
- Total working hoursThe team attendance grid shows a working hours figure next to the clock in and clock out counts.
- Gantt epic filterScope the Gantt timeline to a single epic.
- Bulk approve for role approversApprovers who hold their place through a role or a role group can now bulk approve documents.
- Email subjectsSubject lines no longer show encoded characters.
- Leave day countsHolidays are no longer counted in the total days of a leave request.
Self-Hostedv3.8.32026-06-29
Per tab permissions for test management
Finer control over who sees what in test management, plus two optional document approval switches.
- Test management tab permissionsEach of the eleven test management tabs is granted separately from the Roles screen. Owner and Admin always see all of them.
- Document type approval switchA new setting, off by default, controls whether approval templates are applied automatically by document type. Document type classification itself is unaffected.
- Role group approval switchA new setting, on by default, lets any holder of an approval role act when no specific person is named on that level.
- Attendance export by locationThe team attendance report export now tracks presence per work location.
Self-Hostedv3.8.22026-06-26
Sidebar repair commands
Two admin commands that restore a missing sidebar link after an upgrade.
- Menu repair commandsRun bin/cake dms_ensure_menu or bin/cake risk_ensure_menu to restore the Documents or Risk Management sidebar link on an upgraded install. Both are safe to run again and offer a dry run.
Self-Hostedv3.8.12026-06-25
Approval workflows chosen by document type
The right approval chain is picked automatically from the document's type.
- Approval by document typeAn approval template can be tied to one or more document types, so uploading a contract picks the contract approval chain on its own. A template you choose by hand is no longer overwritten.
- Role scoped approversApprover pickers are scoped by role, show full names, and support role groups.
- Accurate attendance countsThe team grid roster counts active users only, correcting the working hours and clock in or clock out figures. Business units can be filtered as a hierarchy.
Self-Hostedv3.8.02026-06-24
Public API with REST, GraphQL and webhooks
A key authenticated public API so external systems can read and write your Orangescrum data. Ships turned off, so nothing changes until an admin enables it.
- REST and GraphQLKey authenticated REST endpoints plus a single GraphQL endpoint, covering projects, the work item hierarchy, time logs, and test management.
- API key managementGenerate, scope, and revoke API keys from an admin screen, with fine grained per key scopes and a rate limiter.
- Outbound webhooksSubscribe to events, with delivery logging, test and redeliver actions, and a background delivery job.
- Developer portalA bundled API explorer documents the whole surface. It serves documentation only, never live data.
- Role based accessA permission matrix controls who can manage keys, settings, permissions, and webhooks.
Self-Hostedv3.7.22026-06-24
Delete permissions for documents
Deleting a document is now governed by a role permission, with notice to anyone in the approval chain.
- Delete Documents and FoldersDeleting a document is gated by a role permission, and the old separate folder delete permission folds into a single key.
- Delete notificationsDeleting a document that has an approval workflow can email everyone in its chain. You opt out per document from the upload screen.
- Approval progress panelA progress panel shows where a document stands across the document views, and empty system folders can be hidden in the repository tree.
- Reminder recipientsClock in reminders sent direct to staff now respect the same role allow list as the manager digest.
Self-Hostedv3.7.12026-06-23
Essential SAFe
Scaled agile for organizations running several agile teams together.
- Essential SAFeAgile Release Trains, a WSJF prioritized Epic, Feature and Story backlog with Kanban, PI planning with a program board and ROAM risks, and Inspect and Adapt with five flow metric dashboards. Behind a feature flag, so it stays off until you turn it on.
- Back dated leaveStaff can apply for leave on past dates, within a window the admin sets.
- Attendance dashboard figuresTotal working hours plus clock in and clock out user counts, filtered by role group, department, or team.
- Location data in reportsThe team attendance report export carries clock in and clock out coordinates and the work location name and address.
- Document folder countsFolder badges count distinct documents per subtree, and the Delete folder button is removed to prevent accidents.
Self-Hostedv3.7.02026-06-19
Release management, Outlook, and label customization
Three new modules in one release.
- Version and Release ManagementFull version lifecycle, release roll ups, approvals, automatic release notes, a release calendar, dependencies, blackout windows, and a complete audit trail.
- Outlook integrationAn Outlook on the Web add in backed by Microsoft Graph, with calendar mapping, email rules, and email to task conversion.
- Label CustomizerRename interface labels per company, with reusable templates and per language substitution.
- Inline custom fieldsCustom fields can be edited directly in the task details panel, and team assignment is surfaced in the task popup.
- Advanced BI offlineEmbedded dashboards now load in air gapped deployments, with no external dependency.
Self-Hostedv3.6.122026-06-17
Assign only to people on the project
A small release that tidies task assignment and last week's clock in reminders.
- Team filtered assignmentThe team dropdown on the task, epic, and feature popups lists only teams with a member on the project. Picking a team narrows the assignee list to people in both the team and the project.
- Reminder fixesCorrect links in the reminder emails, support for several fallback recipients, a row cap on the manager digest, and corrected scheduling.
Self-Hostedv3.6.112026-06-16
Clock in reminders
Opt in nudges for staff who have not clocked in, and a digest for their manager.
- Clock in remindersA scheduled job spots staff with no clock in for the working day, emails them, and sends a summary of the misses to their manager. Non working days, leave, and people who have already punched are excluded. Recipients and schedule come from the attendance settings.
- Default view by task typeEach person chooses which task types appear on the project Task page. Tasks are always shown.
- Reviewer comments in emailsApproval emails now include the reviewer's comment where there is one, so the decision has context.
Self-Hostedv3.6.102026-06-11
Present by default attendance
A rework of how each day's attendance status is decided, plus paginated test management lists.
- Present by defaultAnyone who punches counts as Present, with a qualifier of Late, Half Day, Partial, or Overtime. Absent now means a true no show. Day credit toward the attendance percentage is proportional or tiered.
- Day finaliserA scheduled job stamps the final verdict for each person at their own local day close, with a seven day self healing window. Manual entries re-finalise that day at once.
- Leave workflow emailsApplication confirmation, approval pending to the approver, and per step progress emails, all customisable from the email templates screen.
- Test management listsEnvironments, plans, runs, scenarios, steps, strategies, and suites gain sortable, searchable, paginated lists, and linked epic to feature to story dropdowns.
- Project name encodingEditing a project name no longer double encodes characters such as an ampersand.
Self-Hostedv3.6.92026-06-10
Git auto sync and document discussions
Git integration works without webhooks, and documents gain files and comments.
- Git auto syncA scheduled two way sync for installs that providers cannot reach by webhook, plus immediate outbound comment sync to GitHub and GitLab. The old GitHub only plugin is removed, and Git Sync is now the single integration.
- Document files and commentsThe document page gains a Files tab for supporting attachments and a Comments tab with mentions.
- Attendance status rulesSet full day hours, the half day threshold, a late grace period, and office start time, with a plain English preview. Overtime and Absent statuses are added.
- Test management linksTest cases can be tied to a story, and defects can be linked to existing tasks.
- Gantt deletion permissionDeleting a task from the Gantt chart is now permission gated.
Self-Hostedv3.6.82026-06-07
Default work locations and Outlook proof emails
Attendance gets a default work location, and email buttons render properly in Outlook Classic.
- Default work locationsA command creates a default work location per company, with coordinates and geo fence enforcement. Branch and Remote replace Work From Home in the location types.
- Outlook proof buttonsEvery call to action button across the email templates is rebuilt so it renders correctly in Outlook Classic.
- Demo dataNew commands seed a populated risk register and a Scrum sprint with tasks into a chosen project. Both are safe to run on a live system.
Self-Hostedv3.6.72026-06-05
Stories and tasks on the epic detail
Epic and feature lists gain their own column choices, and attendance locks work location detection.
- Epic detail tabsThe epic detail popup gains Stories and Tasks tabs, so an epic's children are browsable in place.
- Columns on epics and featuresThe show and hide column picker now works on the Epics and Features lists, each keeping its own independent choice. Approver, Approval Status, and Approval Date can be shown.
- Add a custom field from a taskJump straight to custom field management from the task detail popup.
- Attendance work locationClock entries gain a work location auto detect lock, a redesigned dashboard with quick actions, and a day level On Site chip.
Self-Hostedv3.6.62026-06-03
Work location on attendance reports
Attendance reports show where each punch happened, and task files link into documents.
- Location and flags in exportsAttendance report exports gain Location and Flags columns, resolved the same way on screen and in the file.
- Team grid location filterFilter the team grid by work location alongside the existing employee type and search filters.
- Task files link to documentsLinked document titles on a task Files tab open the document detail page, with clear headings for uploaded files and linked documents.
Self-Hostedv3.6.52026-06-02
App launcher permissions
Control who sees each app in the launcher, and link documents from a task.
- App launcher permissionsEach tile in the nine dot launcher, meaning Orangescrum, Wiki, and Reports, is granted separately. A role denied all three loses the launcher button entirely. Everything is granted by default, so nothing changes until you opt out.
- Link from documents on a taskA Link from DMS button on the task Files tab opens the repository picker, scoped to that project. Edit Task preloads what is already linked and unlinks anything you untick.
- Epic approval emailsApprover and approval status emails now address each person by name and carry a details table, instead of opening with a blank greeting.
- Leave notificationsApproval and rejection emails are sent for leave requests, and deleted requests are excluded.
- Fresh install fixIdentity sequences are correct after a fresh install, so the first custom role, status, field, or template you create no longer collides.
Self-Hostedv3.6.42026-05-28
Two acceptance fixes
Follow up fixes from testing the previous release.
- Report page filtersThe attendance Reports page no longer resets your search and accordion when more clock entries load as you scroll.
- Broken approval linksSaving an email template with a full web address wrapped in braces is now rejected with a clear message, instead of producing an approval link that fails when clicked.
Self-Hostedv3.6.32026-05-28
Email templates get an admin screen and SMTP settings
The email templating work from 3.6.0 becomes a full admin experience, and queued emails finally send.
- Per company template editorEvery template is editable per company, with a preview tile, a scrollable token list, and import or export of your overrides.
- SMTP settings in the appConfigure SMTP from the settings screen, with a test email, a history view, a revert path, and password re-confirmation on save.
- Background email queueA queue worker runs every minute, so queued attendance, test management, and two factor emails are actually delivered.
- Outlook safe layoutsThe notification and task activity shells are rebuilt so they render correctly in Outlook.
- Delivery fixesProject note emails send again, task assignment emails route to the right template, and defect emails no longer arrive with a blank subject.
Self-Hostedv3.6.22026-05-27
User management gets grid and list views
A rebuilt Manage Users page and a per role switch for test management.
- Grid and list viewsThe user list can be shown as a grid or as a sortable list, with chip based filters for role, business unit, project, and team.
- Test management visibilityA new View Test Case Management permission lets admins decide which roles can reach the module.
- Permission fixesRead only attendance screens no longer refuse custom roles, and marking a project complete is checked on the server as well as in the interface.
Self-Hostedv3.6.12026-05-26
Correct submitter on document approvals
A fix for approval records that named the wrong person.
- Right submitter recordedApproval records and the activity log now name the person who submitted the document, rather than the last approver in the chain.
- Draft documentsA document reset to draft after a new version upload no longer shows stale approval details from the previous round.
Self-Hostedv3.6.02026-05-26
Branded email templates
Make notification emails look like they came from your organization.
- Email templatingCustomize 33 notification templates from a settings screen, using structured fields, token substitution, and a live preview. No HTML editing required.
- Common settingsSet the brand color, sender name, sign off, and logo once and every notification picks them up. A per template override still wins where you set one.
- Redesigned emailsAll 24 notification emails are redesigned, and task activity emails change heading and accent color by activity type.
- SafetyOnly owners and admins can change email templates, the preview is sandboxed and inert, and the HTML sanitiser was rewritten to close bypasses.
Self-Hostedv3.5.62026-05-26
Custom employee types
Define your own employee types, and tighten who can see the employee list.
- Employee typesEmployee, contractor, client, intern, and consultant ship as defaults, and you can add your own inline from the employee form or the settings tab. A type still in use cannot be deleted.
- View only employee accessA new View Employees permission gives read access to the Employees tab without the right to change anything.
- Team grid legend as a filterClick a status chip to dim non matching days, and export just the highlighted cells.
- All Leaves tabA new tab showing every leave request, for roles allowed to see it. The tab you land on now depends on your permissions.
- Timezone fixPeople with no timezone set no longer see yesterday's data on the attendance screens.
Self-Hostedv3.5.52026-05-25
Leave approval and document access tidy up
A patch that corrects leave approvals for people who sit in several workflows.
- Leave approval lookupThe leave approval screen shows the right flow for a person who is part of more than one active workflow.
- Interface refreshRefreshed styling and responsiveness on the Leaves, Approval, and Team Grid screens.
Self-Hostedv3.5.42026-05-25
Clock in and clock out report
A dedicated attendance report, and a fairer attendance percentage.
- Clock reportA new clock in and clock out report, filterable by person, team, and date range, with weekly totals. Times show in 12 hour format in the CSV and Excel export.
- Working day percentagePresent days no longer count weekends and holidays, so the attendance percentage reflects working days only.
Self-Hostedv3.5.32026-05-22
Permissions for programs, epics and features
Four new permission modules, plus pagination and task hierarchy handling.
- New permission modulesPrograms, Epics, Features, and Project Templates each get their own permissions, including separate delete actions. Existing custom roles are seeded explicitly, so nothing is silently granted.
- Sidebar and route gatingDenied modules disappear from the sidebar and their routes redirect, rather than half loading.
- Document paginationRepository listings paginate at 20 rows per page and hide orphaned documents.
- Group by on task groupsGroup by none, updated date, assignee, status, or priority, with sortable column headers.
- Deleting a parent taskWhen a task has children, choose whether to move them to another parent or delete them along with the parent.
Self-Hostedv3.5.22026-05-21
One dashboard, and saved team grid views
Dashboard addresses consolidate onto one screen, and the team grid gains saved views.
- Saved views and groupsSave your own named filter views on the team attendance grid, and let admins define shared user groups for scoping.
- One dashboardThe older dashboard addresses now all render the same modern dashboard for Owner, Admin, and User. Existing links keep working.
- Role changes take effect at onceGranting or removing admin or client rights applies on the next request, with no need to sign out and back in.
- Task save fixesSaving a task after clearing its subtasks no longer freezes, and removing a label no longer leaves a phantom entry or duplicates the task.
Self-Hostedv3.5.12026-05-20
Security hardening patch
Fixes from a code review, mostly around escaping and permissions.
- Escaping fixesTask filter output, dashboard values, and search filters are escaped correctly, closing a cross site scripting hole.
- Storage widget permissionsStorage usage widgets now respect the permission that is meant to gate them.
Self-Hostedv3.5.02026-05-20
Export and timezone fixes
A small patch. This release also set the package version number back to 3.5.0 after the 4.0.0 tag cut the day before.
- Export column orderStart date and due date values in the Excel and CSV export now line up with their headers.
- Import validationAdvanced import rejects rows where the start date is later than the due date, and shows the error in the preview.
- Clock timezoneClock entries resolve the company timezone setting correctly.
Self-Hostedv4.0.02026-05-19
Single sign on across Orangescrum, Wiki and Reports
Orangescrum becomes the identity provider for the suite, so people sign in once. This release was tagged v4.0.0 from the v3.4.8 line, and the package version number was set back to 3.5.0 the following day. The capabilities below stayed in the product and carried into the 3.5 and later releases.
- Unified single sign onA built in OIDC and OAuth2 authorization server makes Orangescrum the login for OS Wiki and OS Reports, so one sign in reaches all three. Uses authorization code with PKCE, signed ID tokens, refresh token rotation with replay detection, and an audit log.
- Nine dot app launcherA launcher tile in the header for moving between Orangescrum, Wiki, and Reports.
- Single logoutSigning out of Orangescrum also clears your session in Wiki and Reports.
- Admin set passwordsWhen adding a user, an admin can set the password directly instead of sending an invite, with a strong password generator. Useful where there is no mail server.
- Reset a password for someoneA Reset Password action on each row of Manage Users, so an admin can issue a new password without email.
- Email capitalisation no longer mattersAddresses are stored in lower case and sign in accepts any capitalisation. Existing records are corrected on upgrade.
Self-Hostedv3.4.82026-05-16
Several approvers on one level
Document approval levels can name several people, any of whom can approve.
- Multiple approvers per levelAn approval level can list several named people, and any one of them can approve to move the document on.
- Approver chipsRole and multi person levels show as chips with a count. Hovering lists the actual names behind them.
- Focus card for rejected workThe sidebar focus card now covers changes requested and rejected states, not just pending, with the reviewer comment shown inline.
- All Documents filterFilter by all, uploaded by me, acted on, or pending my review.
Self-Hostedv3.4.72026-05-16
Role based document approvers
A large update to document approval, including approval by role and protection against self approval.
- Approve by roleAn approval level can name a role such as QA Lead instead of one person, and every active holder of that role is notified.
- Resume or restartWhen resubmitting a document, choose whether to resume the existing approval chain or cancel it and start fresh.
- Saving during approval is safeSaving a document while it is in approval no longer cancels or restarts the workflow. A major version bump logs a warning and an audit row, and the chain continues.
- No self approvalPeople cannot approve or reject their own submissions. The review window explains why the buttons are disabled.
- Open comments block approvalApproval is blocked while comments are unresolved, unless the reviewer explicitly acknowledges them.
- Template archiving and exportDeleting a workflow template that is still in use archives it instead, and the dashboard gains a summary CSV export.
Self-Hostedv3.4.62026-05-15
Edit a document while it is in approval
Approvers can make changes without leaving the approval flow.
- Edit in approvalPeople in the approval chain can edit a document while it is under review. Saving cancels or restarts the workflow depending on how large the change is, and banners explain what will happen before you save.
- Approver edit accessExternal approvers get edit access without needing the general document view permission.
- Employee searchThe reporting manager dropdown can be searched by name and shows each person's email alongside.
Self-Hostedv3.4.52026-05-14
Sixteen fixes brought over from cloud
Mostly a fix release, bringing cloud fixes into the self hosted build.
- Cloud fixesSixteen fixes ported from the cloud codebase, covering the Firefox project filter, theme colors on pagination and tabs, timesheet labels, burndown tooltips, and quick tasks for custom roles.
- Tenant isolation fixBillable hours queries are scoped to the company, closing a route by which data could cross between tenants.
- Document diff and printVersion differences show side by side, and the document detail view can be printed.
Self-Hostedv3.4.42026-05-11
Automatic clock out
Attendance closes forgotten clock entries, and the document editor gains PDF handling.
- Automatic clock outA scheduled job closes clock entries left running past the configured daily hours, and signing out closes an open entry.
- PDF from the editorDownload the current document as a PDF from the editor toolbar. Filenames now carry the document title and version.
- Annotation positioningAnnotations land in the right place on flattened PDFs, and exported documents keep their table borders and embedded images.
Self-Hostedv3.4.32026-05-06
Redesigned document editor
A visual overhaul of the collaborative editor, plus Word import.
- Editor redesignA rebuilt toolbar and layout with cleaner typography and spacing.
- Word importImport .docx files into a document with formatting preserved.
- Inline commentsHighlight text in a document and attach a threaded comment to it.
- Page breaksInsert page breaks so documents lay out correctly for print.
Self-Hostedv3.4.22026-05-04
User export fix
A hotfix for the user list export added in 3.3.3.
- Export downloads correctlyThe user CSV export downloads in place instead of showing a blank page, and it no longer opens a new tab.
- Faster on large listsProject lookups are batched, so exporting a long user list is much quicker.
Self-Hostedv3.4.12026-05-04
PDF annotation
Mark up PDFs in the browser, with no extra server component to run.
- PDF annotatorSticky notes, highlights, freehand drawing, text boxes, signatures, and an eraser, over a three column view of thumbnails, page, and an annotations rail. Annotations can be flattened into a new PDF version.
- No sidecar needed for PDFsA pure PHP transport means PDF annotation works without running the separate collaboration service.
- Version bumps on saveThe save dialog offers major, minor, or patch version options with a clearer version label.
Self-Hostedv3.4.02026-05-01
Collaborative document editing
Edit documents together in the browser, straight from the repository.
- CollabDocsReal time co editing of .doc, .docx, and .txt documents from the document repository, with version snapshots, compare and restore, and collaborator grants. OnlyOffice and Collabora can be used instead where you need full Office fidelity.
- Restart approval after rejectionTicking restart approval when uploading a new version of a rejected document now actually restarts the workflow and notifies the first approver.
- Pending approval countThe pending approval figure on the dashboard matches the list it sits above.
- Approver dropdown respects the templateWhen a workflow template pins a level to a role, the picker only offers project members holding that role.
Self-Hostedv3.3.32026-05-01
Eight fixes and a user export
A fix led release, with one small new feature.
- User CSV exportExport the company user list to CSV from the Users screen.
- Leave queue orderApprovers see the newest leave request at the top, matching every other queue.
- Attendance for several people at onceManual attendance entry accepts several employees in one action, so a manager can backfill in one go.
- Document status on tasksEach linked document on a task Files tab shows a draft, pending, approved, or rejected chip.
- Risk dashboard stabilityThe risk dashboard degrades gracefully instead of failing outright when one section has a problem.
Self-Hostedv3.3.22026-04-29
Clock in restrictions and monthly attendance approval
Control where staff can clock in from, and route monthly attendance through an approval chain.
- IP restrictionStop clock in and clock out from outside approved networks such as the office network or VPN. Choose whether to block or just flag.
- Geo fenceStop clock in and clock out from outside a set radius of the office. Choose whether to block or just flag.
- Monthly attendance approvalMonthly attendance runs through a proper approval chain of up to five levels, and can route through each person's own reporting manager.
- Audit log viewerReview who changed clock restriction policy and who imported attendance, with before and after values.
- Document fixesBulk approve works, task files show who uploaded them, and documents can be attached straight from the comment box.
Self-Hostedv3.3.12026-04-23
Bulk risk import and task to document links
Import risks from a spreadsheet, and link documents to tasks.
- Bulk risk importUpload an XLSX, CSV, or TXT file to create many risks at once, with field mapping, a dry run preview, and per row validation.
- Documents on tasksTask detail pages can link documents from the repository through an inline picker, and approval chains show the document owner.
Self-Hostedv3.3.02026-04-21
Attendance and Leave
A new module for clocking in and out, and for managing leave.
- Attendance and LeaveClock in and out, leave management, approval workflows, a team grid, and reports, installed as a module and scoped per organization.
- Leave approval chainsUp to five approval levels, each routed to a role, a named person, or the requester's reporting manager, with auto approve timers and escalation hours.
- Risk management fixesFour fixes from stakeholder review, covering risk filters, bulk actions, owner only views, and assignment notifications.
Self-HostedvV4.1.12025-11-26
Orangescrum On-Premises V4.1.1
A major upgrade built for modern teams, with faster performance, smarter automation, and improved collaboration. Existing on-premises customers can upgrade completely free, including migration and onboarding.
- Free upgrade for existing customersExisting on-premises customers upgrade at no cost, with migration and onboarding included.
Cloudv3.4.0Updated continuously
Current cloud release
The cloud edition runs continuously, so features arrive as they are ready rather than in numbered packages.
- AI ChatAsk questions about your projects in plain English, and let AI create tasks or log time with confirmation before anything changes.
- MCP ServerConnect Claude, Cursor, GitHub Copilot, and other AI clients straight to your workspace using the open Model Context Protocol.
- Scaled AgileEssential SAFe with Agile Release Trains, PI planning, WSJF, ROAM risks, and flow metrics.
- Test Case ManagerTest plans, suites, cases, runs, and defect tracking with traceability back to tasks and sprints.
- Azure DevOpsConnect your organization, link projects and repositories, create branches, and track pull requests.
- Task watchersFollow any work item and control exactly which notifications you receive.
- Cloud storage linksAttach files from Google Drive, Dropbox, and OneDrive without re uploading them.
A rollup of what is live in the cloud today. The dated entries below trace the same history month by month.
Cloudv2026.09September 2026
Links across projects, a rebuilt left navigation, and a new MCP sign-in
Work items can depend on each other across project boundaries, the left navigation is rebuilt and versioned so the new rail can roll out gradually, and connecting an AI client gets a redesigned sign-in and consent screen.
- Link work across projectsA cross project linking plugin lets a task depend on work in another project, with the dependency logic pulled into a shared service.
- A redesigned MCP sign-in and consentThe pages an AI client sends you to when it connects are rebuilt, with Google sign-in alongside the existing route, the connecting client's own logo so you can see what is asking, and consent scopes grouped into collapsible sections so the page no longer grows with the number of them.
- A client cannot ask for more than the workspace allowsA client requesting wider access than the workspace permits is clamped down to that ceiling and connected, instead of being refused with nothing to act on.
- A redesigned left railThe navigation is versioned, so the rebuilt rail can reach people gradually. Settings gets a full height rail and the sidebar gains a toggle.
- Export the Scrum backlogExport a backlog with a column picker, with dates and priority in the same shape the previous export produced.
- FixesThe resource availability check no longer fails, email subjects encode correctly, the left menu footer stops covering the last group, and the toast dismiss button follows the theme.
Cloudv2026.08August 2026
MCP tools reach more of a task, and release notifications arrive
The MCP server gains per-tool permissions and reaches far more of a task's fields, product release announcements arrive inside the app, and task import learns to build real subtasks.
- Every MCP tool enforces its own permissionUntil now any valid token could call any tool, because the gate admitted anything carrying mcp:use and no tool checked further. All 73 tools now refuse a call whose token lacks that tool's scope, before the arguments are even validated.
- More of a task reachable over MCPCreating and updating a task now carries its type, epic, feature, story points, estimated hours and start date. Reading one returns the epic, feature, sprint and start date it used to omit, and a new list_task_types tool makes numeric type ids discoverable rather than guesswork.
- Sprints and time logs over MCPSprints can be listed filtered by status, a time log can be addressed by its unique id string, and task status resolves consistently however the caller cases or spaces it.
- Scopes follow the workspaceA connected client is granted the scopes the workspace has enabled rather than a bare access gate, widening an entitlement is no longer blocked by stale stored scopes, and enabling one entitlement stops resetting the others.
- Product release notificationsA release portal in the app, with each announcement delivered to the people who should see it.
- Import builds real subtasksThe Parent column in a task import creates genuine subtasks, with parent lookups scoped to the project rather than the whole company.
- Every MCP scope in the entitlements pickerSuper admins can grant any tool backed Model Context Protocol scope, so an AI client connected to the workspace can be given exactly the access intended.
- Custom sidebar linksAdd your own links to the sidebar and reach the places you use most without leaving the workspace.
- Timezone handled end to endA user record carries a timezone and the screens that read one honor it, with the Log Time date picker format corrected and an invitee's timezone resolved reliably.
- Notification fixesA failure on the notifications screen is fixed, and task links in the bell popup now resolve to the canonical task page.
- Onboarding and bookmarksFixes to the onboarding card and to bookmarks on the dashboard.
Cloudv2026.07July 2026
Scaled agile, the new workspace, and dark mode
A large month. Scaled agile reached the cloud edition, the rebuilt workspace screens went live behind opt in toggles, and existing Orangescrum accounts started moving across to the new platform.
- Scaled agile on cloudEssential SAFe arrives, with Agile Release Trains, PI planning, a WSJF prioritized backlog, ROAM risks, and flow metrics. A plan level feature gate decides who sees it.
- One workspaceA rebuilt Team Members page and invite flow, inside a single workspace shell shared by boards, lists, and settings.
- New views are opt inNew Planning, New Board, New Projects and Programs, and New Time Log all ship switched off. Each person turns them on from Settings when they are ready.
- Live updatesBoard and list screens refresh as other people make changes, so you no longer reload the page to see them.
- Watchers follow assignmentAnyone assigned to a work item becomes a watcher automatically, and email can be switched off per watcher.
- Dark modeA dark theme for the whole interface, plus a personal accent color.
Cloudv2026.06June 2026
Scrum boards, the AI copilot, checklists and watchers
The busiest month of the year. A new Scrum module, a much deeper AI assistant, and two new ways to keep track of work.
- New Scrum moduleBacklog, sprint board, and sprint reports rebuilt as a single page experience. Defects can sit in agile planning and the backlog alongside stories and tasks, and a defect can be linked to the task it came from.
- Board and filter redesignA redesigned active sprint board with swimlanes, a new filter panel, epic and feature boards, a command palette, and saved views.
- AI copilot acts on real dataThe assistant proposes a change, you commit it, and you can undo it. Adds generated replies, project memory, and document upload so answers draw on your own files.
- Configurable checklistsReusable checklist groups and templates that attach to epics, features, stories, tasks, defects, test scenarios, test cases, projects, and programs.
- WatchersFollow any work item, choose what you are told about, and receive a daily or weekly digest.
- Feedback from inside the appA feedback tab on the edge of every screen for feature requests, bug reports, and a star rating.
Cloudv2026.05May 2026
Orangescrum AI arrives
The AI assistant went live, and plans began to control which modules a company sees. The platform version moved from 3.1.11 to 3.4.0 on 7 May.
- Orangescrum AI chatAsk questions about your projects in plain English. An admin sets up the provider with your own API key, calibrates the model, and the assistant can create a task from the conversation.
- AI clients over MCPA company can connect its workspace to the Orangescrum MCP server, so approved AI clients reach your data through that connection. The entitlement is granted per company.
- Epic detail with stories and tasksThe epic detail view gains Stories and Tasks tabs and a progress summary, so an epic's children are browsable in place.
- Sprint reportA rebuilt sprint report with metric tiles, charts, a resource breakdown, and a PDF export that matches what is on screen.
- Storage limits by planEach plan carries a storage quota, enforced as files are uploaded, with usage widgets on the dashboard and a warning before you run out.
- Transfer ownershipA company owner can hand ownership of the account to someone else.
Cloudv2026.04April 2026
Guided onboarding and Azure DevOps
New accounts got a guided setup, and the Azure DevOps integration shipped.
- Onboarding wizardNew owners are walked through four steps before they reach the app: name a project, choose a work style, invite the team, and log a first task. Invited members go straight in.
- Take a TourThe product tour was rebuilt so it keeps its place as you move between pages, and it no longer restarts itself every time you create a task.
- Azure DevOpsLink an Azure DevOps organization to Orangescrum projects, with two way task sync behind a toggle, branch and pull request activity on the task view, and Azure Active Directory user sync.
- Task email notificationsEmail notifications for task activity, with control over who receives them.
- New pricing plansPlans without a seat ceiling, and a subscription page where an admin can see and change what the company is on.
- Two large fix wavesNinety fixes across time log, sprint, Git integration, project templates, and custom fields, then a second wave covering CSV custom fields and Git comment sync.
Cloudv2026.03March 2026
One tap sign in, theme editor, and test management access
Signing in got quicker, the interface became themeable, and test management gained per role access.
- Google One TapReturning users can sign in with their Google account in one tap, without typing a password.
- Theme editorChoose the interface colors for your company. The sidebar also remembers whether you left it open or closed.
- Test management accessReaching the test case module is granted per role, and test cases can be imported from a file.
- Git comments sync at onceA comment added in Orangescrum reaches the linked GitHub item straight away, rather than waiting for the next scheduled sync.
- Resource utilization exportExport the resource utilization view, and timesheet approval no longer locks rows it should leave alone.
- Helpdesk agentsA user can be created as a helpdesk agent or a client, with the matching record raised in the connected HRMS at the same time.
Cloudv2026.02February 2026
Two factor authentication and company API keys
A security led month, plus the first API keys a company can issue for itself.
- Two factor authenticationA one time code by email at sign in, with security questions as a fallback. Turn it on for the whole company and exempt named roles.
- Password policyRequire a password change every so many months, and stop people reusing their recent passwords.
- Developer API keysOwners and admins can create API keys for the company, switch a key off, and review a log of the calls made with it.
- Plan feature managementWhat a plan includes is held as data, so a feature can be turned on per plan and overridden for a single company.
- Advance analyticsEmbedded analytics dashboards under their own reports menu, with row level security so people only see their own organization's data.
- Utilization filtersThe resource utilization view can be filtered by label and by whether the time is billable.
Cloudv2026.01January 2026
The rebuilt cloud platform
The cloud edition moved onto the version 4 codebase. VERSION.txt read 3.1.11 at the first commit on 9 January 2026.
- New platformOrangescrum cloud runs on the version 4 codebase, multi tenant on PostgreSQL, with company scoping applied throughout.
- Sign in rebuiltRedesigned sign up, sign in, and forgot password pages, with sign in by Google account and a clearer change password screen.
- Work runs in the backgroundEmail and other long running jobs move to a background queue, so pages no longer wait on them.
- Billing on StripeCard billing through Stripe, with trial periods, plan changes, and webhook handling for payment events.
- Tenant isolation fixesQueries that could reach across organizations were scoped correctly, covering time logs, teams, programs, and project templates.
- A broad fix sweepFixes across seventeen modules, plus corrected date handling and row limits in import and export.
Cloudv2025.12December 2025
Version 26.1.1, and the Epic hierarchy
The unified 26.1.1 platform release, and the work that made the Epic to Feature to Story to Task hierarchy real end to end.
- Orangescrum releases version 26.1.1Orangescrum introduced Version 26.1.1, a unified Cloud and On-Premises platform built on a modern, AI ready foundation for faster innovation, simpler upgrades, and a consistent experience for every team. Released 18 December 2025.
- Epic Tree ViewGet complete visibility into your Agile work hierarchy with the Epic Tree View. View epics, features, stories, tasks, and sub tasks in a single expandable structure to quickly understand scope, progress, and dependencies. Released 17 December 2025.
- Task predecessor and successor dependenciesDefine precise task sequencing using full predecessor and successor relationships. Model real world execution logic with Finish to Start, Start to Start, Finish to Finish, and Start to Finish dependencies. Released 17 December 2025.
- Critical path and circular dependency controlsQuickly identify delivery critical tasks in the Gantt chart and prevent workflow blockages with automatic circular dependency detection. Ensure smarter scheduling, fewer delays, and consistent on time project delivery. Released 11 December 2025.
- Feature list and the Orangescrum Feature BoardGain clearer agile visibility with a new Epic to Feature to Story to Task hierarchy and track progress instantly using the Orangescrum Feature Board for faster, more structured delivery. Released 10 December 2025.
Cloudv2025.11November 2025
Epic governance, and the multi tenant foundation
Approval and board views for Epics. The platform groundwork listed at the end comes from migration timestamps in the cloud repo rather than from the old page, so treat those dates as approximate.
- Epic approval workflowA structured Epic approval process to standardize governance across projects. Assign approvers, track decisions, and ensure every Epic is validated before execution begins. Released 21 November 2025.
- Epic Board for high level visibilityThe Epic Board gives you a visual overview of every Epic across its lifecycle. Track progress, identify bottlenecks, and maintain complete project transparency in one unified view. Released 21 November 2025.
- Multi tenant baseCompany scoped data, company identifiers moved to UUIDs, and sessions held in the database.
- Cloud storage linksAttach files from Google Drive, Dropbox, and OneDrive to a task without uploading them again.
- Subscription plansPlans, gateway subscriptions, and the first per plan feature flags.
- InvitationsUser invitations carry a token, so an invite link can be traced and used once.
- Git syncTables for syncing tasks and comments with GitHub, GitLab, and Bitbucket repositories.
Cloudv2025.10October 2025
Epic management, timezones, and the Help Center
The Help Center opened as a single home for guides and best practices, admins gained control of user timezones and permissions, and Epic management arrived for planning large initiatives.
- Orangescrum Help CenterThe Orangescrum Help Center launched as a single destination for guides and best practices. Find answers, learn new features, and make the most of your Orangescrum experience. Released 25 October 2025.
- Control user timezone and permissionsOrangescrum Cloud now allows admins to set user timezones and manage permissions effectively, ensuring accurate scheduling and streamlined team collaboration. Released 16 October 2025.
- End to end Epic managementOrangescrum Enterprise now supports comprehensive Epic management, helping teams plan, track, and deliver large initiatives. Released 15 October 2025.
Cloudv2025.09September 2025
Advanced import, and accurate utilization exports
Advanced Import cuts the manual work of setting a project up, and resource utilization exports report in the same hours and minutes the app shows.
- Advanced importUpload project data with the new Advanced Import feature, reducing manual effort and accelerating project setup. Released 26 September 2025.
- Export resource utilization in hours and minutesResource utilization can now be exported in precise hours and minutes, providing accurate reporting for project planning and management. Released 25 September 2025.
- Decimal time conversion in exportsResource utilization exports now match the in app hours and minutes format, eliminating manual conversions and ensuring accurate, easy to read reports. Fixed 25 September 2025.
Cloudv2025.05May 2025
A smarter UI
The left navigation and application settings in Orangescrum Agile were redesigned for a faster and more intuitive experience.
- Revamped settings and navigation in Orangescrum AgileThe left navigation menu and application settings were redesigned for a faster, smoother, and more intuitive Orangescrum experience. Released 20 May 2025.
Cloudv2025.02February 2025
Report accuracy
Team utilization now reflects company defined working hours in the All Projects view, and profitability estimates, margins, and exports report accurately.
- Team utilization report enhancementCompany defined working hours now display correctly in the All Projects view, giving accurate team utilization insights and a clear, consolidated view of workloads. Released 12 February 2025.
- Profitability report accuracy enhancementProject estimation hours, profit margin percentage, and spent hours calculations are now accurate, and report exports include all data and metrics for reliable profitability insights. Released 12 February 2025.
Open Sourcev0.1.142026-09-09
The user menu closes when you pick an action
Choosing Reset Password left the user menu sitting open on top of the dialog it had just opened, covering the password fields.
- Menus close on selectionEvery item left the menu open, not just that one, because clicks inside it never reached the place the menu was closed from. The menu now closes when one of its own actions is chosen.
- Filters are unaffectedThe change is scoped to the two user action menus. Dropdowns that hold checkboxes and filters still stay open while you use them.
Open Sourcev0.1.132026-09-09
Accepting an invitation works
An invited user who opened their link and set a password was shown an Internal Server Error and could not get into the product at all. Upgrade if you invite people by email.
- Invitations completeThe step that activates the account wrote a column this edition does not have, which failed the request before it reached the database. The field is dropped, and an invited user now lands signed in.
- Token only linksAn invitation URL carrying a token and nothing else no longer fails outright.
Open Sourcev0.1.122026-08-29
The subtask popover is readable again
Hovering the Subtask icon opened a popover whose first line was drawn underneath the sticky column header.
- Popovers sit above the headerThe row is lifted above the header while one of its popovers is open, and passes back under it when closed so scrolling still looks right. The Dependents popover beside it is covered by the same rule.
- Force reload after upgradingThe asset release moves forward, so clear your browser cache or force reload once you have upgraded.
Open Sourcev0.1.112026-08-26
Forgot Password reports what happened
The Forgot Password page came back with no message at all, for two separate reasons.
- Messages reach the screenMessages were written to session keys the sign-in templates never render, so every one of them was silently dropped. They now go through the same mechanism the rest of the site uses.
- A failed send says soWith no reachable mail server the page used to say to check your mail while nothing had been sent. A failure is now reported plainly, and no reset token is issued.
- Unknown addresses stay privateThe reply is deliberately identical whether or not the address is registered, so the page cannot be used to discover accounts.
Open Sourcev0.1.102026-08-26
Security: disabled accounts could still sign in
Disabling a user account did not stop that account signing in. Upgrade if you rely on disabling accounts.
- Disabled accounts are refusedDisabling a user marked their company membership inactive but left the global flag alone, and the sign-in check never dropped the row, so the account still authenticated. Sign-in now requires an active membership.
- Auto-login and live sessionsThe auto-login link resolves through the same check, and a session is revoked on the next request if the account is disabled while it is in use.
- A clear messageSomeone with the correct password whose account is disabled is told so, rather than being told to check their password.
Open Sourcev0.1.92026-08-25
A 500 for regular users with no active admin
In a company with no active owner or admin, a regular user got a 500 on every page that draws the New Project popup.
- Pages render againIn a company with no active owner or admin, a regular user got a 500 on every page that draws the New Project popup, including the dashboard, Tasks, About, and their own profile.
Open Sourcev0.1.82026-08-25
The uploads fix reaches existing installs
Completes the uploads fix from 0.1.7, which could not reach installs that already existed.
- Existing installs are repairedThe uploads directory is a Docker named volume, and Docker only fills one from the image while it is empty, so no upgrade could replace the broken file already sitting in an existing install. The image now keeps a clean copy outside the mount and restores it whenever it differs.
Open Sourcev0.1.72026-08-25
Uploaded files are served again
Every request for an uploaded file returned a 500, so no avatar, project logo, or task attachment would load on any install running an earlier build.
- Files return instead of failingEvery request for an uploaded file returned a 500, so no avatar, project logo, or task attachment could load. A directive Apache does not accept in that context made it fail the whole directory tree rather than skip the line.
- The profile image spinnerThat is also what left the profile image spinning forever, because the cropper waited on a preview that could never load. The crop step is hardened so a missing selection or a failed request cannot strand it.
- Changing your email addressA new address is saved, instead of being parked behind a confirmation link this edition has no way to send while the screen still reported success.
Open Sourcev0.1.62026-08-25
Task import, search, and the My Works filters
Task import handles a file whose columns differ from the template, the task search field draws one border, and the My Works filter row is realigned behind a single Filter popup.
- Task import handles any column setA file whose columns differ from the template no longer fails on Confirm and Import. This supersedes the narrower fix in 0.1.5, covering four failure points rather than three, and was verified against nine files.
- One border on task searchThe search field draws a single border, not two.
- My Works filters realignedThe filter row shares one vertical center again, and the eleven chips are gathered behind a single Filter popup where each chosen value can remove itself.
Open Sourcev0.1.52026-08-25
Task import with a different column set
A file whose columns differed from the shipped template showed its preview and then failed on Confirm and Import.
- Missing columns no longer stop the importThree places read a column without checking it was present, and a file with no Created By column was enough to halt the import. Verified against seven files, including a title only file and a semicolon separated one.
Open Sourcev0.1.42026-08-25
Time Log, task import, and a security fix
Time Log opens again and holds up on large sets, task import is hardened, and a filter chip that allowed attribute injection is fixed. This is the build running on the public demo.
- Time Log opens againIt pages at fifty rows, totals the whole filtered set rather than the visible page, loads project names in one query instead of one per row, and sorts on a fixed list of columns. The CSV export no longer fails.
- Task importContinue waits for the file checks instead of running ahead of them, long rows are no longer cut in half, Cancel deletes the staged file, and someone without admin rights is sent to the dashboard rather than an error.
- Security fixA filter chip placed a name supplied by a user into a tooltip attribute without escaping the double quote, which allowed attribute injection.
- User filter panelA long project or role name is clipped with an ellipsis and shown in full in the tooltip, instead of spilling out of the panel.
Open Sourcev0.1.02026-08-11
Community Edition is released
Orangescrum Community Edition is now free, open source software under the GNU AGPL v3 license. The first public release is on GitHub. Self host it on your own servers with no seat limits.
View the source on GitHub →
- Free and open sourceReleased under GNU AGPL v3. Read the source, change it, and run it for as many people as you like.
- First public releaseTagged v0.1.0 and published on 11 August 2026. Clone it, download the release, or run it with Docker.
- Core project managementProjects, tasks and subtasks, Kanban boards, task discussions, time log, documents, and role based access.
- Runs anywhereTwo documented install paths: Docker, which is recommended, or a manual install with PHP and PostgreSQL. Both run on Linux, Windows and macOS.
- Modern stackBuilt on CakePHP 4 with PHP 8.2 or later and PostgreSQL 16.