Content and publishing · Edition No. 46 · 10 Oct 2026

decaporg/decap-cms

An editing screen for a website whose pages live as files in a repository, where every save becomes an ordinary commit.

← Content and publishingRead the whole edition →

19,423 stars · MIT read from raw main/LICENSE after the blob URL returned a server error. HOLDER FILLED IN BUT STALE AND INTERESTING: 'Copyright (c) 2016 Netlify <decap@p-m.si>' — the original owner's name with the new maintainer's contact address. Ownership moved in February 2023; the copyright line did not. No added conditions. · decap-cms@3.16.3 (2026-09-22), settled against the mirror's releases/latest record (publishedAt 2026-09-22T12:51:56Z) and corroborated by packages/decap-cms-core/CHANGELOG.md on main and by the npm registry's own latest for decap-cms-core (3.19.1, same date). THE RELEASES LIST PAGE WAS STALE, showing 3.16.1. · Track this in Scout

An editing screen for a website whose pages live as files in a repository, where every save becomes an ordinary commit.

▶Repo detailsthe review · specs · pros & cons · install

What it does

Decap CMS is a single-page application written in React that you mount at an /admin address on a site you already publish. Someone visits that address, signs in, and gets a clean screen for editing the content; every change becomes a commit in the repository, so the files themselves are the content store and there is no separate database. What the screen offers is declared in one config.yml file: collections, fields and widgets, with widgets shipped for boolean, date, file, image, list, markdown, number, object, relation, select, string and text, plus components that embed inside the text. It works against several repository hosts — Bitbucket, a hosted gateway, GitHub, GitLab and a test backend — and recent work adds another. It does not implement passwords at all: its own security document states the project "does not store passwords, delegating authentication to providers". An optional editorial workflow adds draft, review and ready states, backed by branches and pull requests. It supports several languages, media folders and pluggable media libraries. It does not have a content interface of its own, no database and no server-side part in the default install — it is a browser program talking to a repository host. It does not host or build the website. The editorial workflow does not work against a local repository through the development proxy, which its own documentation states. And centralised user management, advanced roles, a database proxy and paid support are all routed to a commercial offering, so they are outside the open-source part.

Why it matters

Who it suits. Anyone running a site built from files — a documentation site, a company blog, a marketing site — who needs a non-technical colleague to change the text without learning git or opening an editor. It suits that job better than a database-backed system because there is nothing extra to run, back up or patch, and the content history is the repository history. Skip it if you want live collaborative editing, several people typing in one document at once, which it does not do. Skip it too if you want a content interface other programs can read from, because there isn't one.

What people say. The most authoritative outside account is three and a half years old and is about ownership rather than quality. Netlify's own engineering blog, in a post by Min Kim on 23 February 2023, announced that it was handing the project — then called Netlify CMS — to an agency partner, which renamed it Decap CMS and took over the packages, the accounts, the repositories and the website; Netlify is the party giving the project away and it sells the hosting and identity services the default configuration leans on, so that is a first-party announcement with a commercial interest, not analysis. Joost van der Schee at the web agency Usecue corroborated the handover independently in a post dated 24 February 2023; a practitioner's note, and his firm builds the kind of sites this software serves. Beyond 2023 there is no credible dated review of it that we could find — the searches returned only auto-generated directory pages, and we used none of them. One more thing belongs here because it is a competitor's claim and must carry its own label: the README of sveltia/sveltia-cms describes itself as a "complete modern rewrite", says Decap "has been neglected for years", and claims to have solved 365 reported issues from Decap's tracker. That is a rival project stating its case, none of it independently verified, and the checkable part cuts against the strong version: Decap released version 3.16.3 on 22 September 2026 and merged work in early October 2026.

Verdict. Still the sensible default for this job, with one caveat about resourcing and one about development safety. It is not abandoned — code landed on 8 October 2026, five pull requests were opened on 2 October, and the newest release is three weeks old — but 565 open issues on a project whose own security document says it is "a community-maintained open-source project without dedicated security staff" is a real signal about how much attention it can give. The thing to be careful about is the local development proxy, npx decap-server: it listens on port 8081, has no authentication of any kind, writes to your repository on behalf of whoever reaches it, and does not bind to the local machine only unless you tell it to. Before version 3.8.0 it accepted requests from anywhere. If you want a drop-in replacement whose compatibility is the whole pitch, look at sveltia/sveltia-cms; if you want visual editing on the page itself, tinacms/tinacms does that and was Edition 35's late substitution.

Stars19,423
LicenceMIT read from raw main/LICENSE after the blob URL returned a server error. HOLDER FILLED IN BUT STALE AND INTERESTING: 'Copyright (c) 2016 Netlify <decap@p-m.si>' — the original owner's name with the new maintainer's contact address. Ownership moved in February 2023; the copyright line did not. No added conditions.
Latestdecap-cms@3.16.3 (2026-09-22), settled against the mirror's releases/latest record (publishedAt 2026-09-22T12:51:56Z) and corroborated by packages/decap-cms-core/CHANGELOG.md on main and by the npm registry's own latest for decap-cms-core (3.19.1, same date). THE RELEASES LIST PAGE WAS STALE, showing 3.16.1.
Good
  • Plain MIT read from the file with no added conditions, and no database, no server process and nothing extra to patch in the default install. The content is the repository.
  • Genuinely alive: release 3.16.3 on 22 September 2026, code on 8 October 2026, and pull requests opened eight days before this edition.
  • It stores no passwords at all and says so in writing, delegating sign-in to a provider — which means there is no credential store of yours for anyone to steal.
Watch for
  • 565 open issues, and the project's own security document says it has no dedicated security staff and that some dependency problems "may not be patchable without breaking backward compatibility" because the legacy dependencies are hard to update.
  • The local development proxy listens with no authentication, writes to your repository, and does not bind to the local machine by default — only a cross-origin check stands in the way, and that check only arrived in decap-server 3.8.0.
  • The no-build-tooling install route loads the application from a third-party content network at a floating version range, so what the editing screen runs is whatever that network serves at page load. And centralised user management, roles and support are a paid offering, not part of this.
Similar repositories
Install
npm install decap-cms-app --save
Screenshots
decaporg/decap-cms: Screenshot 1

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.