Solidus Quarterly Roundup: Q3 2026

portrait of Jared Norman

Jared Norman

8 Oct 2026 - 7 mins read

Cover image of Solidus Quarterly Roundup: Q3 2026 post

Hey Solidus community! It's been a while since we put out a quarterly roundup or proper status update, so I'm excited to share all the work that's gone into Solidus over the last three months. We haven't posted an update since our status update in May, but we'll be focusing on the work that went into Solidus from July through September 2026.

This has been our busiest quarter in a while, with more distinct PRs merged this quarter than any quarter since Q4 2023. Thank you to all 19 contributors who worked hard to keep the Solidus project moving forward. We also closed more issues than during any quarter since Q3 2022! We put some long-standing bugs to bed, shipped new features, improved the new admin, and shipped the first of two rounds of coordinated security releases across the Solidus ecosystem.

Solidus v4.8 is right around the corner, so I wanted to make sure to highlight some of the most important changes in Solidus over the last three months. Let's get into it.

New Core Team Members

This quarter Alistair Norman joined the core team. At the same time as we announced it, we fixed an error of omission: we never announced that Martin Meyerhoff had also joined the core team about a year prior. Find out more in our announcement post!

The New Admin

We're currently using the Solidus Open Collective to fund work on the new admin interface, dubbed Solidus Admin. This new interface aims to replace Solidus Backend with a more modern, maintainable, and (perhaps most importantly) extensible interface. While still a work in progress, you can add it to your store today and use it alongside Solidus Backend.

Benjamin Wil has been hard at work executing the vision for this interface. He's added a host of new interfaces for managing payment methods, tax rates, stores, option types and values, and product taxons. He hasn't been alone: Sascha Karnatz made it possible to give stores an address, Thomas von Deyen added time zone support and tidied up the typography, and Chris Todorov rebuilt the confirm modal without any third-party dependencies. We're also preparing support for ViewComponent v4.

It's been a long time since the last minor release of Solidus Admin (yesterday's v0.4.1 was a security fix and nothing more), so expect a new version in the near future and a more rapid release cycle now that Benjamin is moving the project along more quickly.

Coming in Solidus v4.8

Solidus v4.8 is coming very soon, by which I mean tomorrow. I'll cover it in-depth in the release announcement, but we've made some great improvements. Solidus Storefront and I18n are both part of the monorepo now. Martin and Ikraam have made a ton of performance improvements across admin, API, taxes, promotions, inventory, and payments. We've closed a number of long-standing bugs, some as old as 9 years. Stay tuned for the release!

Extension Changes

Folks have been hard at work in the extension ecosystem, too. Solidus Stripe is undergoing serious work to modernize it, improve CI, and better manage payment intents. Solidus Auth Devise now supports user time zones (in service of the admin feature) and has received some security patches. If you're using Solidus Frontend, it's also undergone CI modernization and received some fixup work and fresh releases.

Two Rounds of Security Releases

After a quiet stretch, our security program is running at full speed again. We've fixed a whole host of issues across two separate rounds of coordinated releases, one in September and another just yesterday. If you've not upgraded yet, please make it a priority.

The September round shipped as Solidus v4.7.1 and v4.6.3, with matching Solidus Frontend releases. Yesterday's round shipped as Solidus v4.7.2 and v4.6.4, Solidus Frontend v4.7.2 and v4.6.4, Solidus Auth Devise v2.6.1, and Solidus Admin v0.4.1.

If your store was generated from Solidus Starter Frontend (newly renamed Solidus Storefront), upgrading the gems is not enough. Two of the fixes require changes to the generated code in your application. The advisories linked from those posts walk you through them.

If you're curious about how we handle vulnerabilities, you can read our security policy.

What's Next

Our new Core Team member, Alistair, has been hard at work collaborating with us and our clients to build out the roadmap for upcoming versions of Solidus. While nothing is set in stone yet, here are some changes we're hoping to land in the near future:

If you have hopes and dreams for what you'd like to see in Solidus, please reach out. I'm always happy to hear about how Solidus is being used and how we can shape it to fit the needs of our different kinds of users.

Thanks to the Community

I'd like to thank all our contributors, new and old. It's been great to see some new faces this quarter: welcome to minhluuquang, owgreen-dev, SiddharthGautam040, and wakqasahmed. Additionally, huge thanks to the folks who reported security vulnerabilities, including samipmainali, alex-sc, and ChrishSec.

If you'd like to get involved with Solidus, please stop by our community Slack or hop on GitHub Discussions!