Skip to main content

Pantheon release notes

Your destination for staying informed about our latest innovations and product updates.
Subscribe to RSS feed

September 25, 2026

PHP versions 8.2.34, 8.3.35, 8.4.26, and 8.5.11 are now available on the platform. These updates include important security fixes, along with bug fixes and enhancements that improve performance and stability.

The security fixes include a high-severity issue in the SOAP extension (CVE-2026-91765), plus fixes in OpenSSL certificate verification, the HTTP stream wrapper, and PHP-FPM.

Updates will be applied automatically over the next few days, so no manual action is required. See PHP versions on Pantheon to check or change your site's PHP version.

September 22, 2026

The latest security release for WordPress, 7.1.2, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.2 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of this vulnerability (CVE-2026-87902), and is actively monitoring those rules. However, customers need to update their sites as soon as possible.

Highlights

This release resolves one critical severity vulnerability (CVE-2026-87902) that does not require authentication to exploit. Under certain server and theme conditions, an unauthenticated attacker can cause page template resolution to include a chosen readable local PHP file outside the active theme directories, which could potentially lead to remote code execution.

For full details, see the WordPress 7.1.2 release notes and WordPress documentation.

September 18, 2026

The latest security release for WordPress, 7.1.1, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.1 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of some of these vulnerabilities, and are actively monitoring those rules. This includes an unauthenticated stored cross-site scripting vulnerability (CVE-2026-93485), reported through Patchstack's Vulnerability Disclosure Program, which was already covered by these mitigations ahead of the release. However, customers need to update their sites as soon as possible.

Highlights

This release resolves 11 security vulnerabilities, most requiring an authenticated role (Contributor or above) to exploit. WordPress has not assigned CVE identifiers to these issues.

For full details, see the WordPress 7.1.1 release notes and WordPress documentation.

September 18, 2026

Version 1.4.0 of the Pantheon Content Publisher WordPress plugin is now available.

What's new?

New Feature: Smart Components ** You can now embed videos and interactive smart components directly into your posts and pages using the updated Google Docs add-on. #206

Update to 1.4.0 from the WordPress dashboard under Plugins > Installed Plugins, or download it from the WordPress Plugin Repository.

For more details, see the plugin changelog.

September 10, 2026

Starting September 10, 2026, new sites created on Pantheon are provisioned on the next-generation Global CDN, powered by Cloudflare, instead of the legacy Global CDN.

This change applies to newly created sites only. Existing sites are not affected and remain eligible for migration through the normal migration path.

No action is required: the next-generation GCDN is provisioned automatically at site creation.

Advanced Global CDN (AGCDN) customers are not affected by this change. If you have any questions, contact Pantheon Support.

September 10, 2026

Sites on the Next Generation GCDN can now exempt their own trusted automation from bot protection, without contacting support.

Bot protection on the Next Generation GCDN automatically challenges traffic that looks automated. That is the right default for scrapers and attack tools, but it can also challenge automation you rely on: uptime monitors, CI/CD pipelines, feed importers, and custom API clients that are not on the verified bot list.

You can now generate a bot bypass token for your site using Terminus and configure your automation to send it in the x-pantheon-bot-bypass request header. Requests carrying a valid token skip the standard challenge applied to automated traffic; targeted protections, rate limiting, and the managed WAF still apply to every request.

Key details:

  • Tokens are scoped to a single site (all environments) and valid for 6 months. The command returns a current token and a next token that becomes valid 3 months later; both are accepted during the overlap. Send the current token now, switch to the next token on or after its start date, and re-run the command each quarter to pick up the following pair.
  • Treat the token like a credential. Send it only from trusted servers and services, and never expose it in client-side code. If a token is leaked, contact Pantheon support to revoke it; a replacement token becomes available at the start of the following month.
  • Requests without the header are evaluated by bot protection as usual. Requests with an incorrect token are rejected with a 403, so check the header value first if your automation starts failing.

See Bot Bypass Tokens in the Next Generation GCDN guide for setup instructions.

September 3, 2026

Version 0.9.5 of the 'Push to Pantheon' GitHub Action is now available. This release changes how the action handles a push that has no Pantheon environment to deploy to, and corrects the documentation for the target_env and target_env_strategy inputs.

What's new

A Multidev comes from a pull request. A push to any other branch has nothing to derive an environment name from.

In 0.9.4 the action treated that as an error and failed the job, so adding the action to a workflow that runs on every push would fail on a feature branch with no PR. In 0.9.5 the action skips the remaining steps and the job succeeds, and the step log records why the deployment was skipped.

A misconfiguration still fails the job: a target_env value Pantheon will not accept, an unrecognized target_env_strategy, or the branch strategy with no branch to read.

If you want pushes to other branches to deploy, set target_env_strategy: branch to deploy to a Multidev named after the branch, or set target_env explicitly. (#188)

How to upgrade to 0.9.5

Update your workflow file to use 0.9.5:

For more information about this release, see the GitHub release page. To learn more about deploying to Pantheon from GitHub, see GitHub Actions.

If you have questions or concerns about the action, please use the Push to Pantheon issue queue.

September 3, 2026

Version 0.9.4 of the 'Push to Pantheon' GitHub Action is now available. This release fixes a command injection issue in the git_commit_message parameter, adds branch-based Multidev naming, and lets you name the GitHub deployment environment separately for each site.

Action required

Versions 0.9.0 through 0.9.3 interpolated the git_commit_message value into a shell string and evaluated it, so shell metacharacters in the message ran as commands rather than being passed as text. Arbitrary commands, passed through the git_commit_message could run on the GitHub Actions runner, which holds your PANTHEON_MACHINE_TOKEN and PANTHEON_SSH_KEY.

Only workflows that pass text into git_commit_message that someone else could control (e.g. via a PR title or branch name) are affected, and only on a site that has a Live environment and the workflow does not set skip_build_tools: true (e.g. uses the default behavior). The commit message the action generates on its own by default contains no such text, so default configurations are not affected. Versions earlier than 0.9.0 pass the message as a single quoted argument and are also unaffected.

Upgrade to 0.9.4 as soon as possible. If you cannot upgrade immediately, ensure you are not passing untrusted text into git_commit_message.

Reported by @ndewhurst. (#175)

Additional key improvements in this release

  • Branch-based Multidev naming: Set target_env_strategy: branch to name the Multidev after your branch instead of pr-[NUMBER]. Branch names are normalized to satisfy Pantheon's naming rules — lowercased, unusable characters folded to hyphens, and trimmed to 11 characters — and a digit is appended when another branch already holds that name. (#183)
  • Per-site GitHub deployment environments: Set deployment_environment to name the GitHub deployment environment separately from the Pantheon environment. Without it, a branch that deploys to several Pantheon sites reports every deployment under the same name, so only the most recent one stays visible in the pull request timeline. (#182)
  • Multiline commit messages: git_commit_message now accepts multiline values, so you can pass Git trailers such as Source-Commit: to record where a deployment came from. (#175)
  • More reliable Multidev cleanup: delete_old_environments: true now removes environments for closed pull requests that Terminus Build Tools misses. Build Tools stops paginating after roughly 200 pull requests, so environments for older closed pull requests remained until the site reached its Multidev limit. (#174)
  • Multidev limit reported for named environments: The Multidev limit check now runs when you set target_env explicitly. Previously it ran only for automatically derived names, so a deployment to a named environment failed inside Terminus instead of reporting the limit. (#176)

Changes to existing behavior

target_env is now validated against Pantheon's environment naming rules. A value Pantheon would reject (uppercase letters, underscores, more than 11 characters, or a reserved name such as master) now fails immediately with an explanation instead of failing later in Terminus.

How to upgrade to 0.9.4

Update your workflow file to use 0.9.4:

For more information about this release, visit the GitHub release page (https://github.com/pantheon-systems/push-to-pantheon/releases/tag/0.9.4). To learn more about deploying to Pantheon from GitHub, see GitHub Actions (/github-actions).

If you have questions or concerns about the action, please use the 'Push to Pantheon' issue queue (https://github.com/pantheon-systems/push-to-pantheon/issues).