XNAT 1.10.2 is a maintenance release focused on DICOM handling. It includes security fixes, and we recommend it for all 1.10.x sites. It requires no change to your Java, Apache Tomcat, or PostgreSQL versions from 1.10.1, makes no database schema changes, and bundles DicomEdit 6.10.0. Sites that don't use the official XNAT container image should check the Before You Upgrade section of the release notes first.
-
Snapshots for more kinds of scans. Snapshots and thumbnails now render for JPEG-compressed scans, segmentations, series that mix single- and multi-frame instances such as whole-slide imaging, and scans whose objects all went to the secondary DICOM catalog.
-
A new pixel redaction engine.
alterPixelsis more efficient, keeps the transfer syntax of uncompressed and lossless objects where it can, and uses the fill value the script asks for. Redacted output differs from 1.10.1, so we recommend verifying existing scripts that usealterPixels. -
Very large DICOM objects. Anonymization streams pixel data from disk instead of holding it in memory, so objects with Pixel Data over 2 GiB can be anonymized and redacted, and sites need less heap for large objects and many concurrent imports.
-
DICOM elements after Pixel Data. Routing rules, DICOM mappings and the DICOM dump can now use elements that come after Pixel Data, including private tags in groups 0x8000 and above.
-
Direct archive and the prearchive. Deleting a direct-archive session now removes its files along with its record, and non-admin users with All Data Access get read-only access to the whole prearchive.
-
Stability. A fix for a deadlock that could stop a node, plus other stability improvements and security hardening.
Before you upgrade: sites that deploy the XNAT WAR into their own Tomcat, or build their own container image instead of using the XNAT image, need to install the OpenCV native library, which XNAT now uses to decode JPEG-family pixel data. Some changes also affect existing behavior, scripts and plugins, so review the Before You Upgrade section of the release notes.
Released alongside it, Container Service 3.9.0 adds optional scheduled cleanup of the build directories that finished containers leave behind, with on-demand runs through the REST API. It also reduces the database load of Docker Swarm status polling, and on Kubernetes, containers that already finished are no longer finalized again, and reported as failed, when XNAT restarts. Container Service 3.9.0 is built for XNAT 1.10.1 and later and Java 21, and no longer runs on XNAT 1.9.
Also recently released:
-
OpenID Authentication Plugin 1.6.0 adds optional audience and role checks on tokens, opt-in bearer-token authentication for REST requests, opt-in linking to an XNAT account that another provider already maps, and opt-in auto-login with unified logout. Account creation now refuses a sign-in whose username already belongs to an XNAT account it isn't linked to, which changes behavior for some existing deployments, so read its release notes before upgrading.
-
XNAT Desktop Client 3.2.6 adds a native build for Apple Silicon Macs, signed installers (notarized on macOS), and the option to turn off image anonymization for specific scan modalities. It also fixes pixel anonymization writing empty DICOM files. Clear your upload and download queue before upgrading from 3.2.5.
Full details are in the XNAT 1.10.2 Release Notes, the Container Service 3.9.0 Release Notes, the OpenID Authentication Plugin 1.6.0 release and the XNAT Desktop Client 3.2.6 release. Download XNAT and its plugins from the XNAT downloads page.