I Finally Read the Home Assistant 2026.9 Patch Notes Line by Line. Here Is What My Update Routine Looks Like Now.

Ethernet cables plugged into a network switch

Patch releases are the part of Home Assistant I used to skim. The headline features go into the monthly release, the .1, .2 and .3 follow, and I would click Update whenever the badge appeared. This month I stopped and read the release notes for 2026.9.2 and 2026.9.3 line by line instead. It took ten minutes, and it changed how I think about what a “boring” update actually contains.

Here is what I found, what applies to my bare-metal install, and the small routine I now follow before pressing the button.

What is actually in 2026.9.3

The 2026.9.3 release landed on 18 September and lists 23 changes. Almost all of them are integration-level bug fixes and dependency bumps. A few are worth a closer look because they are not cosmetic.

The Backup fix now encrypts and decrypts supervisor.tar correctly when a backup is rewritten. If you keep encrypted backups, which you should, that is exactly the type of bug you only discover on the day you need a restore. The Private BLE Device flow now requires the IRK, the identity resolving key, so you cannot end up with a half-configured tracker. Onboarding now validates the username before creating the user, and AirVisual no longer writes its API key into debug logs.

The rest is the long tail of a big ecosystem: a Matter cover that was not created when the tilt attribute was null, an Alexa doorbell that raised an error in state reports, a Nest thermostat turn_on that is now idempotent, an EnergyZero price regression, and Reolink, Lutron and Waterfurnace library bumps. None of those touch me directly, and that is precisely the point: a patch release is a bundle of other people’s fixes, and the chance that one of them is yours is higher than it feels.

And 2026.9.2, a week earlier

2026.9.2 (11 September) had the same shape: Hive login normalisation, a Vizio soundbar authentication fix, a ZHA library bump to 2.2.2, a frontend update, and credential redaction in go2rtc logging, which is the second “stop leaking secrets into logs” fix in two weeks. Two consecutive patch releases quietly closing log-leak paths is a nice reminder that the debug log is a place where secrets end up, so I never paste one into a forum thread unread.

The one thing that did draw complaints was not a bug at all. A community thread about the History page notes that the new layout reserves a panel for entity tags and leaves “barely half a screen” for the graph. Another user pointed out that the panel collapses via the Sources button at the top left. I would call that a discoverability problem rather than a defect, but it is a fair example of how even a patch release can change your daily workflow.

The routine I now use

Running Home Assistant OS on a used HP EliteDesk means I am the only person responsible for it. There is no vendor sitting between me and a bad update, so I keep the process short and dull.

First, I read the release notes for every patch, not only the monthly one. I am not looking for my integrations by name so much as for the words backup, auth, security, redact and migration. Those are the lines that change what I should do next. Second, I take a fresh full backup before updating, and I check that it is encrypted and that I can see it in the list. Third, I update on a quiet evening rather than in the morning while the household is trying to switch on lights. Finally, I glance at the log for new warnings for a day, and only then do I stop thinking about it.

None of this is heroic. It is the smart-home equivalent of looking both ways before crossing a quiet street. But local-first cuts both ways: no cloud means no one else can break my house, and also no one else will roll it back for me.

Should you update straight away?

My honest answer is yes for patch releases, with a backup, and I am more relaxed about it than I am about the .0 release. By the third patch a monthly release has usually been through a few thousand real installations, and the fixes are aimed at exactly the papercuts they found. If you use one of the integrations in the list above, the case gets stronger. If you keep encrypted backups, it gets much stronger.

The exception is the moment you rely on something fragile, like a custom integration that has not caught up with a core change. In that case read the notes twice, check the integration’s issue tracker and wait a week. Nobody ever lost a house to being seven days behind on a patch.

Next month I will be back with whatever the 2026.10 beta brings. Until then, go and read your release notes. They are shorter than you think, and this month they were more interesting than I expected.

Leave a Reply

Your email address will not be published. Required fields are marked *