OpenProject 17.5









Released version OpenProject 17.5.0 — an open project management system for projects, tasks, roadmaps, agile planning, meetings, documentation, and team collaboration. The project's code is distributed under the license GPLv3, development is ongoing openly on GitHub. The release took place on June 10, 2026.

The main change in OpenProject 17.5 is the introduction of project-based identifiers for work packages, currently in Beta status. Previously, tasks in OpenProject received a unique numeric ID across the entire installation, for example #2385. Now, the administrator can choose a mode where the identifier includes the project context, such as PROJ-01. This simplifies work in organizations with many projects and assists in migration from Jira, where teams often have become accustomed to task project keys.

List of major changes:

  • Project-based identifiers for work packages.
    In OpenProject 17.5, administrators can choose between the previous shared numeric sequence and the new project-based identifiers mode. The setting applies to the entire installation. Old numeric references, bookmarks, and mentions continue to work, and the setting can be rolled back.

  • Improved migration from Jira.
    The Jira Migrator now retains task project identifiers when transferring to OpenProject. Additionally, migration of deadlines, estimated effort, and remaining effort has been added. This reduces context loss when moving from Jira and allows for the preservation of familiar task designations.

  • Exclusion of task types from Backlogs.
    In the project settings, specific types of work packages can now be excluded from backlog views. For example, a team may choose to remove high-level Epics or Milestones from the backlog, leaving only items that the team actively works on in sprint planning.

  • Enhanced processing of Definition of Done in Backlogs.
    The configuration of statuses considered complete is now more consistently accounted for in Backlogs. This is beneficial for teams where different types of work are considered complete at different stages of the process.

  • Redesigned sprint views and task cards.
    In the Backlogs module, sprint headers, backlog containers, and work package cards have been updated. The interface has become clearer: parent tasks, story points, priorities, assignees, and sprint status are now more visible.

  • Built-in links to tasks in Documents.
    In the Documents module, links to work packages can now be inserted directly within text paragraphs, rather than just as separate blocks. This enhances the readability of project documentation and allows for natural referencing of tasks in the text.

  • Extended task mentions in CKEditor.
    In text fields based on CKEditor, including task descriptions, meeting agenda items, and wiki pages, mentions via ## and ### now expand directly in the editor. More context is displayed instead of just one identifier: type, status, and topic of the task.

  • Monthly recurring meetings.
    Meeting series have gained more flexible scheduling: recurring meetings can be set up using templates like 'first Monday of the month' or 'last Friday of the month'. This is convenient for regular reviews, committees, syncs, and retrospectives.

  • Fewer unnecessary emails.
    OpenProject now consolidates multiple quick changes in meetings into fewer emails. Notifications are sent only after a pause in editing, reducing the number of unnecessary emails when preparing agendas.

  • Bulk role selection in workflow settings.
    Administrators can select multiple roles at once when configuring workflows. This speeds up the configuration of complex permission and status schemes, especially in installations with a large number of roles.

  • Change in sprint sharing licensing.
    Sprint sharing between projects has been moved to the Corporate plan. Existing configurations will be preserved after the update, but creating, modifying, or reactivating such settings now requires a Corporate plan.

  • Change in session-authenticated API request protection.
    For non-GET requests to APIv3 with session authentication, Sec-Fetch-Site: same-origin is now used instead of checking X-Requested-With: XMLHttpRequest. This change is related to CSRF protection and should not affect normal API integrations using OAuth or API tokens.

  • SSRF protection for SAML integration.
    Protection against Server-Side Request Forgery has been extended to SAML. In most installations, no additional actions are required, but when using internal IP addresses for SAML, allowlist configuration may be necessary through OPENPROJECT_SSRF_PROTECTION_IP_ALLOWLIST.

  • Fix for vulnerability CVE-2026-52779.
    The release includes a fix for the authentication issue in the Calendar and Team Planner modules. The problem allowed a user with management rights in one project to delete public calendar or team planner requests from another project where they did not have the appropriate permissions.

In addition, OpenProject 17.5 includes numerous fixes in Backlogs, Jira Migrator, Meetings, Documents, BlockNote, CKEditor, the administration interface, filter functionality, themes, mobile layout, and PDF export. The update is recommended for all users of the 17.x branch.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster