# Email/Webhook Notification for Critical Security Updates

**URL:** https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951
**Category:** Support
**Created:** [February 10, 2024, 4:09pm UTC](https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951 "2024-02-10T16:09:12Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![markersocial](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/markersocial/32/170136_2.png) [@markersocial](https://meta.discourse.org/u/markersocial)
#### Post date: [February 10, 2024, 4:09pm UTC](https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951/1 "2024-02-10T16:09:12Z")

</div>

I think it would be nice if admins could receive an email when there is a new critical update available for a Discourse instance (according to the branch being used). Even better would be if a webhook could be triggered.

Essentially for the same conditions in which the ’ A critical update is available. Please upgrade!’ message is shown on the admin dashboard.

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [February 10, 2024, 4:51pm UTC](https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951/2 "2024-02-10T16:51:29Z")

</div>

Is this not provided by the `version checks` and `new version emails` settings?

I think a critical update would get a version bump, which should trigger both of those?

---

<div class="post-metadata">

### Author: ![markersocial](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/markersocial/32/170136_2.png) [@markersocial](https://meta.discourse.org/u/markersocial)
#### Post date: [February 10, 2024, 5:55pm UTC](https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951/3 "2024-02-10T17:55:27Z")

</div>

Thanks @JammyDodger!

I somehow missed that when searching.

Though it appears that the email used for this setting must be listed publicly on the /about page.

I had left ‘contact\_email’ empty (opting for using contact\_url), which explains why I have not been receiving these emails.

I do think that the email used for administrative critical alerts shouldn’t be the same as the email listed publicly for support/general contact emails though.

One email would make more sense to go to a support ticketing system, while the other should go to the server admin.

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [February 10, 2024, 6:12pm UTC](https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951/4 "2024-02-10T18:12:09Z")

</div>

Now you mention it, that does sound familiar. I think there’s an open #Contribute > UX topic here suggesting making those emails more configurable:

> [@Change sending New Version email to developer email (or configurable group)](https://meta.discourse.org/t/change-sending-new-version-email-to-developer-email-or-configurable-group/286170):
>
> Yes, That’s a pain point. It should rather default to the developer\_emails as defined in app.yml because the dev/sysadmin is far more interested in pushing the update than website support (which could be a non-tech team altogether)

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [March 11, 2024, 6:13pm UTC](https://meta.discourse.org/t/email-webhook-notification-for-critical-security-updates/294951/5 "2024-03-11T18:13:00Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
