🚀 Vikunja 2.6.0 is out! 380 commits, 18 of which are security fixes. 🔒
Also new: import from Planka 📥, image/audio/video previews for attachments 🖼️, and an email change flow that no longer locks you out on a typo. ✉️
The open source to-do app to simplify your life. Built by @kolaente@mastodon.social
🚀 Vikunja 2.6.0 is out! 380 commits, 18 of which are security fixes. 🔒
Also new: import from Planka 📥, image/audio/video previews for attachments 🖼️, and an email change flow that no longer locks you out on a typo. ✉️
🚀 Vikunja 2.5.0 is out! Small release, 203 commits of cleanup.
🔒 One security fix: a share link could act as another user. Please update.
⚡ Pasting a list into quick add magic now creates every task in one request, in the order you wrote them.
Plus a bunch of CalDAV, notification and import fixes 🦙
Cal.com announced they're going closed source. The stated reason: AI has made it too easy for attackers to find bugs in public code.
I've been thinking about this for a bit. It's security-through-obscurity with a 2026 paint job, and I don't buy it.
Kerckhoffs's principle is over a century old: a system should remain secure even when everything about it except the key is public.
LLMs don't change the direction, only the speed. AI scans closed code just fine (fuzzing, binaries, APIs). Hiding the source doesn't remove bugs. It just means whoever finds them has no obligation to tell you first.
From Vikunja's own release notes: CVE-2026-28268, fixed in 2.1.0. Password reset tokens weren't being invalidated after use. The bug had been sitting in the codebase since v0.18.0 in September 2021.
A researcher found it (probably with the help of AI), reported it responsibly, and it got fixed. If the source had been closed, nobody external would have been in a position to catch it.
Every founder who eventually closed their source once said "I promise we won't." I believe they meant it at the time. Circumstances change.
So the better question is: what would have to happen for Vikunja to close? Four structural facts: AGPL-3 license, no CLA, no investors, and anyone can fork today's code.
Transparency trades "bugs found later by the wrong people" for "bugs found earlier by the right ones."
That's the actual tradeoff. Closing the source flips the sign on every term.
🦙 Vikunja 2.4.0 is out! Ten security fixes (please update soon), the first Vikunja Pro features, and a brand-new v2 API. Full rundown: https://vikunja.io/changelog/vikunja-2.4.0-pro-and-a-new-api
In 2020 the EU's open-source strategy was an internal memo about the Commission's own code. Today's wants Europe to build open alternatives to US proprietary software, and treat them as industrial policy.
Good, and long overdue. But it's non-binding, and ~€2B over 7 years is a rounding error next to the ~€264B Europe spends on proprietary software every year.
The lever it keeps ignoring is its own procurement budget.
https://vikunja.io/changelog/eu-open-source-budget-is-the-policy/
🦙 Vikunja 2.3.0 is out! 11 security fixes, a new plugin system, quick-entry window for the desktop app, Vikunja as an OAuth 2.0 provider, WeKan + CSV imports, and more across 277 commits. Updating soon is highly reccomended!
cal.com closed their source this week, citing AI bug-hunters as the reason.
Every time a project does this, someone asks if Vikunja could too.
Not easily. AGPL-3, no CLA, no investors, and anyone can fork today's code.
More on why: https://vikunja.io/changelog/vikunja-stays-open/
🔒 Vikunja 2.2.2 is out: nine security fixes including a critical chain that could expose instance-wide data. Also adds centralized SSRF protection and a few nice bug fixes. Please update soon!
(2.2.1 has been released as well but did not fix the issues fully, therefore I went and pushed 2.2.2 right after)
📣 Vikunja now (finally) has help docs for end users! Check it out at the website and tell me what you think: https://vikunja.io/help
PSA: there will be a release tomorrow (April 8th) or the day after that with a bunch of security fixes
🔒 Vikunja 2.2.0 is out! 10 security fixes (update now!), plus task duplication, an improved Gantt chart with subtask hierarchy & dependency arrows, and user-level webhooks. 237 commits of goodness 🚀
PSA: Because of the great recent success, there will be ANOTHER release later today or tomorrow fixing 9 more security vulnerabilities.