Skip to main content

Grafana 13.1.3

Release Date: August 7, 2026

Remember when Grafana was just a single-purpose dashboard for Prometheus metrics? That era feels ancient now. Grafana Labs shipped 13.1.3 on August 7, 2026 — a quiet patch release that says less about new features and more about how far the platform's security posture has come.

The Trajectory

What began in 2014 as an open-source charting tool has grown into an observability platform spanning metrics, logs, traces, and alerting. The 13.x line, released earlier this year, consolidated that sprawl under a unified query experience. 13.1.3 doesn't move that needle — it hardens it. With nine commits against the 13.1 branch, this is a maintenance release in the truest sense.

Security Hardening

  • fast-uri upgraded to >= 3.1.5
  • socket.io-parser upgraded to >= 4.2.7
  • ip-address upgraded to >= 10.3.1
  • postcss upgraded to >= 8.5.23
  • brace-expansion upgraded across multiple major lines

Each of these dependency bumps closes a known vulnerability class in the transitive dependency tree — the kind of work that never shows up in a demo but shows up in a security audit.

Bug Fixes Worth Noting

Two behavior fixes rode along with the security work. The BarChart component no longer breaks its tooltip when fed a circular dataframe field value, fixing a crash that appeared in dashboards with self-referencing data. And the snapshots delete key behavior was backported into 13.1.x, restoring a workflow that power users had reported as broken.

Looking Back, Looking Ahead

Seen in the long arc, releases like 13.1.3 are the quiet chapters between the exciting ones. They're what let Grafana claim, year after year, that the platform is dependable enough to run on-call rotations. If you're on the 13.1 train, the upgrade is a low-risk pull. If you're still on 12.x, this is a reminder that the security gap only widens with time.

What is New?

By continuing to use the site, you agree to the use of cookies.