Update docker.io/matomo Docker tag to v5.14.0
No problems automatically updating the Docker image, migrating the application manually and run the container by Watchtower with dependency update facilitated by Mend's Renovate Bot.
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| docker.io/matomo (source) | minor | 5.13.0 → 5.14.0 |
Release Notes
matomo-org/matomo (docker.io/matomo)
v5.14.0
Breaking Changes
- The interface
Piwik\Settings\Interfaces\PolicyComparisonInterfacegained four methods used by the granular compliance dashboard:getPolicySettingId(),isExternallyManagedByPolicyPage(),getWhatItDoes()andgetImpact(). Plugins that implement the interface directly must implement them. Plugins usingPiwik\Settings\Interfaces\Traits\PolicyComparisonTrait(as all known implementers do) inherit default implementations and are not affected. - Exporting a report for a single goal (a goals table or a bar/pie/evolution chart showing one goal's
conversions or revenue) now returns only the columns shown in the UI, by addingshowColumnsto the
export request. Previously the export returned the aggregated all-goals columns and every other
goal's columns as well. Integrations that reuse an export URL copied from the UI will receive a
narrower set of columns than before. - The
Referrers_distinctWebsitesUrlsmetric is now listed among the metrics of theReferrers.getreport, carries the labelDistinct website URLs, and is declared as a numeric metric. It was already archived and already part ofReferrers.get's own output, so that call returns the same columns as before; what changes is the surfaces driven by the report's metric list.API.getProcessedReportforReferrers.getnow returns the metric instead of stripping it, and scheduled and emailed reports include it -- a new row in the HTML rendering, a new column in the CSV and TSV ones -- so consumers parsing those exports by column position will see a changed header and column count. Wherever a rendering resolves metric labels,Distinct website URLsnow appears in place of the raw column name. Being declared numeric also brings it under CNIL data rounding, so on installations with that setting enabled the count is rounded to the same scale as other counts. - The
UserCountry_distinctCountriesmetric, returned byUserCountry.getNumberOfDistinctCountriesand plotted by the distinct-countries sparkline widget on the Locations page, is now declared as a numeric metric and is therefore subject to CNIL data rounding. On installations with CNIL rounding enabled the returned count is rounded to the same scale as other counts instead of being passed through unrounded, so a value of18now reads as20. Installations without CNIL rounding are unaffected. - The
Marketplace.searchPluginscontroller action now returns only the fields the plugin cards render, and thepluginstemplate variable theMarketplace.GetNewPluginsandMarketplace.GetPremiumFeatureswidgets pass to their templates has been reduced the same way. The version history, shop details, screenshots, support links, authors, changelog and activity they used to carry are served per plugin by the newMarketplace.getPluginDetailsaction instead, which the plugin details modal requests when it opens. A template overriding either widget has to fetch anything beyond the card fields itself. - Tooltip content - the
titleof the hovered element, or thedata-tooltipa report cell carries - may only use simple inline formatting (b,br,em,i,small,span,strong,u, without attributes). Content carrying anything else is displayed as text in full rather than rendered, so nothing is lost from it, but adiv, animgor aclassno longer has any effect. A report cell tooltip built from<column>_tooltiprow metadata used to be inserted without a sanitizer and now shows markup as text. What a plugin returns fromPiwik\Plugins\Live\VisitorDetailsAbstract::renderActionTooltip()for theLive.renderActionTooltipevent is escaped where the entries are combined, so the visitor log's action tooltip shows that content as text even when it uses those tags; separate entries with a line break as before. Markup Matomo puts in a tooltip itself lost the classes it carried -tooltip-action-*in the visits log tooltip andcomparison-card-tooltipin the comparison cards - since attributes are not kept; nothing in Matomo styled them, but a third-party theme might. Tooltips track the cursor and close as soon as it leaves their target, so their content was never interactive.
New APIs
Piwik\Plugins\AIProvidersnow implements provider-side web search, also called grounding, so an AI
feature can ask the provider to search the web before answering and then read the sources it used.
Piwik\Plugins\AIProviders\AIRequest::withWebSearchEnabled()is no longer advisory: Anthropic,
Google and OpenAI honour it, while AWS Bedrock and the custom provider reject a grounded request with
anAIProviderClientExceptionrather than silently answering ungrounded.AIProviderResponsegained
wasWebSearchUsed(),getWebSearchCitations(),getWebSearchRequestCount()and
getWebSearchQueries(), backed by the newPiwik\Plugins\AIProviders\WebSearchUsage, which
normalises the three providers' incompatible grounding shapes;AIProviderService::canUseWebSearch()
and the newsupportsWebSearchkey ofgetProviderStatusesForCaller()let a feature check first.
Citation titles and queries are untrusted model output, length-capped but otherwise verbatim, so
escape them where they are rendered. Grounding is not a marginal cost: every provider charges per
search and bills the retrieved page content as input tokens on top. Seeplugins/AIProviders/README.md
for the per-provider caveats and the cost and timeout implications.AIRequest::withTimeoutSeconds()overrides the provider HTTP timeout, which now defaults to 120s for
a grounded completion and stays at 30s otherwise. That outlasts the default read timeout of common
web servers and proxies, so grounded completions are intended for CLI commands and scheduled tasks.AIProviderResponse::getStopReason()now reports a value for Google completions, which previously
always returnednull. Google'sfinishReasonis mapped onto the same vocabulary the conversation
API already uses (STOPbecomesend_turn,MAX_TOKENSbecomesmax_tokens,SAFETYand
RECITATIONbecomeguardrail_intervened), so it matches AWS Bedrock and Anthropic. OpenAI keeps
reportingstop/lengthon both its grounded and ungrounded paths. A caller that treats an
unrecognised stop reason as a failure will start seeing Google values.- The new
Piwik\Http\SecurityHeaders::sendForDataResponse()sends the header set for a response that is data rather than application UI:X-Content-Type-Options: nosniff,Referrer-Policy: no-referrer,X-Frame-Options: denyunless[General] enable_framed_pagesallows embedding, and aContent-Security-Policythat allows no scripts, forms or base URI, only inline styles and images from Matomo itself (built by the newPiwik\View\SecurityPolicy::restrictToDataResponse()). Core sends it for the API endpoint itself, report exports, inline report previews, and the API module'slistAllMethodsandlistSegmentsactions, which return HTML without a view;action=listAllAPI, which renders one, keeps the headers of a regular page. Call it in a plugin that streams an export or a report, before writing any output. - Two new events let plugins customise the "No data has been recorded yet" page, on both the standalone page and its embedding in the reporting UI:
Template.siteWithoutData.afterTrackingMethodscollects additional HTML rendered below the tracking methods list and the section for temporarily hiding the page.SitesManager.siteWithoutData.showInviteTeamMemberLinklets a plugin hide the "Invite Team Member" link by setting the posted flag tofalse.
- The new
CoreHome.tooltipContentrenders thetitleof the hovered element as the content of a jQuery UI tooltip, andwindow.vueSanitizeTooltip()does the same for a value at hand in plain JavaScript. Both keep only the simple inline formatting a tooltip may show and fall back to displaying the whole value as text, so a title that was not written for a tooltip loses nothing while nothing in it is rendered.
Deprecations
Piwik\Plugins\AIProviders\AIProviderResponse::isWebSearchEnabled()is deprecated in favour of
wasWebSearchUsed(), and thewebSearchEnabledkey ofAIProviderResponse::toArray()in favour of
the newwebSearchUsedkey. The name reads as request state, but both report what the provider
actually did, whileAIRequest::isWebSearchEnabled()keeps the request meaning. Both will be removed
in Matomo 6.- The
$webSearchEnabledparameter of theAIProviderResponseconstructor is deprecated. Pass a
Piwik\Plugins\AIProviders\WebSearchUsageas the new trailing$webSearchparameter instead, which
reports the searches, queries and citations a completion actually produced rather than a bare flag.
The parameter keeps its position and its meaning, so positional callers written against Matomo 5.13.0
keep working and atruestill makeswasWebSearchUsed()report a search. It will be removed in
Matomo 6. Piwik\Plugins\AIProviders\Provider\AIProvider::isWebSearchUsed()is deprecated. It was a
placeholder whose base implementation always returnedfalse, and no bundled provider overrode it,
but a third-party provider that did override it controlledAIProviderResponse::isWebSearchEnabled().
Such a provider should now overridesupportsWebSearch()to declare the capability and pass a
WebSearchUsagetobuildResponse(). An existing override is still honoured by
wasWebSearchUsed()for the transition, and will stop being consulted in Matomo 6.
HTTP API
- A new
keep_flattened_dimension_columnsparameter keeps the columns a flattened report adds for its
dimensions when the request also restricts columns withshowColumns. Flattening with
flat=1&show_dimensions=1adds one column per dimension, but their names only exist after
flattening, so a caller cannot include them in ashowColumnsallowlist andColumnDeletewould
drop them. Settingkeep_flattened_dimension_columns=1re-adds them after flattening. It defaults
to0, soshowColumnson its own behaves exactly as before.