Skip to main content
Free demo available - Try PLANKA today!

PLANKA Pro Changelog

What changed in each release of PLANKA Pro, newest first.

Last updated Sep 7, 2026

[2.5.0] - 2026-09-06

Our biggest release so far: phones and tablets, a new look with five themes, a personal dashboard, cards on more than one board, boards you can open to everyone, four ways to read a whole project, PDF and HTML exports, live presence, templates, and a lot of polish. Two large areas ship as previews and are marked as such.

Added

Phones and tablets — a layout built for touch, chosen by how you point rather than by window size, so tablets get it in landscape too.

  • Board bar: a floating pill with previous/next list, a + that adds and opens a card in view, and a ... for the header actions a phone has no room for.
  • Swipe between lists, between cards, and pull a card aside, down (archive/delete) or up (its actions).
  • Drag and drop reworked for touch, with feedback and no accidental text selection.
  • Finger-sized menus, safe-area-aware layouts, bigger type, a header and toolbar that fold down to a 390px phone, a full-screen notepad.

Look and feel

  • Five themes (Beta): Default, Dark, Elegant, Frosty, Dark Ice — from the user menu, or automatic to follow your OS; the top bar can carry its own. Rough edges remain in some dialogs.
  • Instance-wide accent colour, set once in administration.
  • Card density: Condensed, Medium, Spacious or Loose.
  • Colour-blind mode for labels and list colours (protanopia, deuteranopia, tritanopia).
  • Project backgrounds: a colour plus an optional tileable pattern, mirrored on the home-screen tiles.
  • A Visual tab in settings gathers everything that decides how the app looks.
  • Neighbouring lists with the same name and type read as one column; settings are per user and apply instantly across tabs.

Home screen and dashboard (Alpha) — an early preview; panels, layout and settings will still change, and some panels are placeholders.

  • Personal dashboard built from panels you pick: clock, my week, my focus, team pulse, arrivals, hotspots, activity, "important but forgotten", waiting on you, collaborators, and more. Each panel has its own settings.
  • Notepad: a personal scratchpad on the home screen.
  • Open a card without leaving the page, as an overlay from a panel, collection or search result, with comments, fields and attachments.
  • Global search redesigned: cards, boards and attachments in one layout that reflows to narrow screens.
  • PLANKA remembers where you left off (home scroll, last project, board position).

Boards and navigation

  • Board overview: mini previews of every board in a project; tabs collapse into a dropdown when space is tight.
  • Timeline view: dated cards as bars on a twelve-month axis — drag to move dates, group by member or label (editors only for the handles).
  • Read a whole project at once: calendar, map, timeline and media wall across all boards, each still deciding what you may see.
  • Media view: every attachment of a board, filterable.
  • Saved filters (personal, per board) and filter by date (from/between/until, start or due).
  • Flash recent cards: pulse what changed last, optionally on every board entry.
  • Board movement modes (off / relative / delayed).
  • Paste onto a board: text, links, images or files, with a preview; links become link cards.
  • A deep link survives login, and "auto open the last site" reopens where you were.

Adding cards

  • One card chooser everywhere: blank card, clipboard, and the templates the board offers — from every view, the inbox/archive/trash, the calendar, the map and the phone bar.
  • Start a card of a particular type from the chooser's second page.
  • A blank card is saved only once you write in it, and leaves nothing behind if closed untouched.
  • Paste a card (Ctrl+V) from text, a link, an image or a file, after a preview; a link to a card here reveals it instead of duplicating.
  • Turn a to-do into a card, taking its assignee with it.

Templates

  • Templates live in template projects: library boards hold the cards you reuse. Keep your own catalog; catalogs shared with you or published globally are offered too.
  • A board decides what it offers: pick templates from any catalog you can reach, order them, and choose the set each role sees.
  • Save a card as a template from the toolbar, choosing where it lands.
  • Board templates: publish a whole board as a global template, and decide which roles create freely and which only from a template.
  • Demo data on request: an admin can generate (and auto-revert) a demo project.

Linked cards

  • A card can appear on more than one board: paste its link with Ctrl+Y for a stand-in showing the original's content; what you write through it reaches the real card.
  • The board you are on decides what you may do — the rights that count are the ones you hold where the link sits, not on the source board.
  • Full or read-only: a read-only link refuses every change and wears a red corner; narrowed by any editor here, widened again only by an editor of both boards.
  • List, members and labels stay local, so the same card can carry different people and labels on each board.
  • A coloured frame marks it as a window; archiving, moving, unlinking and duplicating act on the stand-in.

Cards

  • New cards open instantly and save only when you are done.
  • Long descriptions load on demand, keeping big boards fast.
  • The next occurrence of a recurring card shows as a chip with a countdown.
  • Labels survive the archive and are restored even if deleted meanwhile.
  • Separate start/due chips, a bottom bar with page indicator and next-card navigation, confirmation on duplicate.

Labels

  • Project-wide labels: one shared vocabulary maintained in the project settings, marked with a globe in every board's picker; promote up or push down without losing it from cards.
  • Label groups by type, context, attribute, area or topic; a group can be single-select (one status/priority per card).
  • Weight and nudge level: heavy labels that go quiet resurface in the dashboard and nudge the responsible after 3, 7 or 14 days.
  • Automatic contrast keeps text readable in every theme; optional rounded-pill labels.

Custom fields

  • Fields now have a type: text, number, date, currency, yes/no, URL or dropdown, each with the right input and display.
  • Dropdowns with predefined values, optionally allowing free entry.
  • Repeatable field groups: many records on one card (contacts, line items, test runs), shown as a sortable table; up to 50 per card by default.

Attachments and images

  • Inline image previews: a display-optimised copy; the original stays available, and admins can decide whether originals are kept.
  • Attachments name themselves (IMG_20260714_183501.jpg becomes "Image").
  • Delete or rename a single attachment from its row; individual attachments can be hidden from guests.

Working together

  • Presence: online, idle or away on the avatar, on boards and in user lists; offline status can be hidden.
  • Editing a description together: see when someone else is writing, ask to take over if they go idle, drafts kept locally.
  • Share a card: a link to a single card for people outside the board, or ask a colleague to show you one of theirs.
  • Teams: give a whole team access to a board at once, kept in sync; project managers can maintain a project's own teams; a team can be assigned to a card like a person.
  • Accounts can be banned as well as deactivated.

Exports

  • PDF export for boards and single cards (description, labels, fields, attachments, notes section).
  • HTML export for boards: one self-contained file with images embedded.

Pinboards, public boards and guests

  • Pinboards: open a board to everyone signed in — read-only, under their own name, nobody added to the member list.
  • Public boards: open selected boards to visitors without an account, by link or in a directory; what they see is per board, and they cannot create or change anything.
  • Update interval for visitors is a project setting (real time, or 3/5/15/60 minutes); signed-in users keep live updates.

Personal preferences

  • Edit mode: always on, remembered, or off every time.
  • An inactivity cover: a curtain with time, date and quote after a while idle; the press that lifts it does nothing else.
  • A keyboard shortcuts panel in the user menu.
  • Every setting that could not explain itself by its label now carries a hint.

Administration

  • Two-factor authentication (TOTP) for non-SSO accounts: authenticator app, ten recovery codes, optional 30-day trusted browsers (listed, individually revocable); admins can reset 2FA. OIDC logins are unaffected.
  • Auto-logout on inactivity (2 minutes to a week, or never) with a 30-second warning; activity in any tab keeps you signed in.
  • Delete permission can be revoked: editors keep editing but lose permanent removal; on by default.
  • Login rate limiting: failed sign-ins counted per address and per account; wrong second-factor codes counted against the pending login and end it when spent.
  • One edit dialog per user (profile, credentials, API key, avatar); login welcome message (Markdown) and cover set in administration.
  • LOG_FILE=none keeps console output only; SERVER_INSTANCES sets the worker count; OIDC_END_SESSION_ON_LOGOUT=false leaves you signed in at your provider; BACKUP_PASSPHRASE encrypts the backup archive.

Changed

  • Boards scroll freely on desktop instead of snapping list by list (see board movement modes).
  • Image downloads default to the display-optimised copy; the original is still one click away in the viewer.
  • Redesigned user settings and About dialog, with clearer messages when a username, e-mail or password is rejected.
  • A team is managed by whoever owns it — instance-wide teams by admins, a project's teams by its managers; no one is offered another project's teams any more.
  • The file log is capped at 10 MB across three rotating files.
  • The Helm chart mounts /app/.tmp as an emptyDir in every configuration (tempStorage.sizeLimit caps it).
  • PLANKA warns on start when SECRET_KEY is the example key, missing, or shorter than 32 characters.

Fixed

  • Emoji and special characters in avatar initials
  • S3 request checksum calculation
  • Excessive memory use from unlimited proxy file descriptors
  • Readability in dark mode across dialogs, the editor and administration
  • Card dragging: grab offset, stacking order, redundant scrolling
  • A due date picked in the afternoon is due at end of day, not the minute you picked it
  • A drag interrupted by switching windows no longer swallows your next click
  • Reopening a board while it is being worked on no longer takes the tab down
  • Cards opened away from their board support comments, restoring, moving and deleting
  • A failed upload no longer leaves its temporary file behind
  • A single-string OIDC role claim is understood, and a mapping that matches nothing now says so in the log
  • Missing translations across the dashboard, search, presence, teams and card navigation

Security

  • The second factor is asked for even when the terms have changed. Accepting the terms handed out a full session before the second factor was reached, so someone with only the password could sign in without it. Only instances that changed their terms text were exposed; the stock terms never trigger it.
  • A file route stays inside the directory it serves. Shared files, avatars, background images and favicons resolved their path against a shared upload root, so a request could walk into the directories behind a session check. Each route is now confined to its own directory, on disk and on S3.
  • A link preview cannot be steered onto the internal network. Redirects and page-declared icons were followed without re-checking the address; every hop, and the icon's own address, is now checked, and private, loopback and link-local addresses (including 169.254.169.254) are refused.
  • A ban survives a single sign-on. A ban was read on password login only, so a banned user could sign back in through their identity provider and be reactivated on the way. Every login path now reads it.
  • A guest can no longer copy out what a board hides from it by saving a card as a template.
  • Leaving a group takes its board access with it — removal used to leave the granted board memberships behind.
  • A board offers only the templates whoever set it up can reach; foreign template ids are dropped rather than pulled across in full.
  • Group rosters stay with the people who administer them: a guest no longer receives every bound team's members and their profiles.
  • A card's record list asks about the card, not merely the board, and a card can no longer be moved onto a collection board.
  • The user search answers within your own boards and projects and turns the public visitor away, instead of handing out the whole directory.

[2.4.4] - 2026-08-21

This release brings PLANKA Pro level with PLANKA Community 2.2: everything Community gained since Pro 2.4.1 is here, so no feature is missing when moving across. It is built on the 2.4.1 line, not on the current development branch, so it carries these changes and nothing else.

Added

  • Two-factor authentication (TOTP) for non-SSO users: enable in user settings → security with a QR-code-based authenticator app, get 10 one-time recovery codes, and optionally trust a browser for 30 days. Trusted browsers are listed with OS / browser / device info and can be revoked individually; admins can reset 2FA on any user (with step-up password confirmation). OIDC logins are unaffected.
  • Auto-logout on inactivity: pick a timeout (2/5/10/30 min, 12 h, or never) in user settings → preferences; a 30 s warning dialog appears before the session ends, and activity in any open tab keeps you signed in across all of them
  • Open a unified user edit modal in administration → users/guests by clicking a user's name (combines profile, credentials and API key in one place); the administration modal itself now uses the same lighter pointing-tab style
  • Customize the login screen welcome message (Markdown) and cover image directly from administration → general; the separate Login Page tab has been merged in
  • Redesign the user settings modal to match the new look: two-column layout, lockable username/email fields, inline password change with confirmation, and a single save action
  • Show inline error messages when changing username, email, or password (e.g. "already in use", "invalid current password")
  • Allow admins to edit user avatars

Fixed

  • Fix Unicode and emoji characters in user avatar initials
  • Fix S3 request checksum calculation
  • Limit proxy file descriptors to prevent excessive memory allocation

Security

  • Fix a path traversal in the local file manager (CWE-22). Attacker-controlled path segments were joined into the uploads storage path without checking that the result stayed under the uploads root, which allowed arbitrary file reads through the static file routes — on the unauthenticated /shared/* route without any login. Paths are now resolved and confined to the uploads root centrally, and symlinks are resolved and re-checked so one inside the root cannot be used to escape it.

Upgrading from PLANKA Community

npm run server:db:promote now accepts two Community schemas:

  • Community 2.1.0 / 2.1.1 — the last releases with single sign-on. Identity provider links come across intact, and the two-factor columns start at their defaults.
  • Community 2.2.0 / 2.2.1 — trusted devices and TOTP settings come across, and accounts keep their two-factor setup.

If you use OIDC, promote from 2.1.1, the newer of the two. Community 2.2 removed single sign-on: it drops the identity provider links and deactivates the accounts that used them, and that data cannot be recovered afterwards. Any other Community version has to be updated to one of the two above first.

Helm chart

The chart moved to its own OCI repository, so charts and container images are no longer mixed in one place:

  • Container image — docker.planka-services.de/planka/planka-pro
  • Helm chart — docker.planka-services.de/planka/planka-pro-chart

Resource names and labels are unchanged, so helm upgrade on an existing release works as before — only the chart reference has to be updated.

[2.4.1] - 2026-03-26

Fixed

  • Add support to Upgrade from latest Community Version

[2.4.0] - 2026-03-19

Added

  • Add maintenance mode
  • Support running under subpath
  • Add ability to display card ages
  • Allow exposing Swagger specification
  • Configurable HTTP timeout for OIDC

[2.3.4] - 2026-03-01

Fixed

  • Prevent dropzone from overflowing content
  • Update Gravatar hash algorithm
  • Improve backup and restore scripts
  • Improve installation on Windows and containerized environments
  • Improve security by ensuring the outgoing proxy is not accessible from outside

[2.3.3] - 2026-02-17

Fixed

  • Improve connection reliability after the app is idle
  • Allow loading custom End User Terms of Service

[2.3.2] - 2026-01-31

Fixed

  • Ensure correct permission checks when copying or moving cards
  • Fix link card animations and label displays
  • Optimize database indexes to improve performance
  • Improve stability of card drag-and-drop in calendar view

[2.3.1] - 2026-01-17

Fixed

  • Correct calendar row styling and drag-to all-day behavior
  • Properly handle timezones for recurring cards
  • Include location name in board and global search
  • Prevent language conflicts in notifications

[2.3.0] - 2025-12-23

Added

  • New calendar view for planning and scheduling
  • Support for recurring cards with flexible rules
  • Ability to copy, cut, and paste cards (with hotkeys)
  • New link card type with improved visuals and previews
  • Ability to select department and location for users
  • Lazy loading to support an unlimited number of users
  • Customizable logo and login cover
  • Due date offset for recurring cards
  • Interactive map opening when clicking a location
  • Separate tracking and management of guest-only users

Changed

  • Enhanced users modal to display full information
  • More consistent card actions menu layout with separators
  • Made location search more accurate and easier to use