Bump version to v4.2.6
This commit is contained in:
		
							parent
							
								
									f1700523f1
								
							
						
					
					
						commit
						7c8ca0c6d6
					
				
							
								
								
									
										19
									
								
								CHANGELOG.md
									
									
									
									
									
								
							
							
						
						
									
										19
									
								
								CHANGELOG.md
									
									
									
									
									
								
							| @ -2,6 +2,25 @@ | |||||||
| 
 | 
 | ||||||
| All notable changes to this project will be documented in this file. | All notable changes to this project will be documented in this file. | ||||||
| 
 | 
 | ||||||
|  | ## [4.2.6] - 2024-02-14 | ||||||
|  | 
 | ||||||
|  | ### Security | ||||||
|  | 
 | ||||||
|  | - Update the `sidekiq-unique-jobs` dependency (see [GHSA-cmh9-rx85-xj38](https://github.com/mhenrixon/sidekiq-unique-jobs/security/advisories/GHSA-cmh9-rx85-xj38)) | ||||||
|  |   In addition, we have disabled the web interface for `sidekiq-unique-jobs` out of caution. | ||||||
|  |   If you need it, you can re-enable it by setting `ENABLE_SIDEKIQ_UNIQUE_JOBS_UI=true`. | ||||||
|  |   If you only need to clear all locks, you can now use `bundle exec rake sidekiq_unique_jobs:delete_all_locks`. | ||||||
|  | - Update the `nokogiri` dependency (see [GHSA-xc9x-jj77-9p9j](https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-xc9x-jj77-9p9j)) | ||||||
|  | - Disable administrative Doorkeeper routes ([ThisIsMissEm](https://github.com/mastodon/mastodon/pull/29187)) | ||||||
|  | - Fix ongoing streaming sessions not being invalidated when applications get deleted in some cases ([GHSA-7w3c-p9j8-mq3x](https://github.com/mastodon/mastodon/security/advisories/GHSA-7w3c-p9j8-mq3x)) | ||||||
|  |   In some rare cases, the streaming server was not notified of access tokens revocation on application deletion. | ||||||
|  | - Change external authentication behavior to never reattach a new identity to an existing user by default ([GHSA-vm39-j3vx-pch3](https://github.com/mastodon/mastodon/security/advisories/GHSA-vm39-j3vx-pch3)) | ||||||
|  |   Up until now, Mastodon has allowed new identities from external authentication providers to attach to an existing local user based on their verified e-mail address. | ||||||
|  |   This allowed upgrading users from a database-stored password to an external authentication provider, or move from one authentication provider to another. | ||||||
|  |   However, this behavior may be unexpected, and means that when multiple authentication providers are configured, the overall security would be that of the least secure authentication provider. | ||||||
|  |   For these reasons, this behavior is now locked under the `ALLOW_UNSAFE_AUTH_PROVIDER_REATTACH` environment variable. | ||||||
|  |   In addition, regardless of this environment variable, Mastodon will refuse to attach two identities from the same authentication provider to the same account. | ||||||
|  | 
 | ||||||
| ## [4.2.5] - 2024-02-01 | ## [4.2.5] - 2024-02-01 | ||||||
| 
 | 
 | ||||||
| ### Security | ### Security | ||||||
|  | |||||||
| @ -56,7 +56,7 @@ services: | |||||||
| 
 | 
 | ||||||
|   web: |   web: | ||||||
|     build: . |     build: . | ||||||
|     image: ghcr.io/mastodon/mastodon:v4.2.5 |     image: ghcr.io/mastodon/mastodon:v4.2.6 | ||||||
|     restart: always |     restart: always | ||||||
|     env_file: .env.production |     env_file: .env.production | ||||||
|     command: bash -c "rm -f /mastodon/tmp/pids/server.pid; bundle exec rails s -p 3000" |     command: bash -c "rm -f /mastodon/tmp/pids/server.pid; bundle exec rails s -p 3000" | ||||||
| @ -77,7 +77,7 @@ services: | |||||||
| 
 | 
 | ||||||
|   streaming: |   streaming: | ||||||
|     build: . |     build: . | ||||||
|     image: ghcr.io/mastodon/mastodon:v4.2.5 |     image: ghcr.io/mastodon/mastodon:v4.2.6 | ||||||
|     restart: always |     restart: always | ||||||
|     env_file: .env.production |     env_file: .env.production | ||||||
|     command: node ./streaming |     command: node ./streaming | ||||||
| @ -95,7 +95,7 @@ services: | |||||||
| 
 | 
 | ||||||
|   sidekiq: |   sidekiq: | ||||||
|     build: . |     build: . | ||||||
|     image: ghcr.io/mastodon/mastodon:v4.2.5 |     image: ghcr.io/mastodon/mastodon:v4.2.6 | ||||||
|     restart: always |     restart: always | ||||||
|     env_file: .env.production |     env_file: .env.production | ||||||
|     command: bundle exec sidekiq |     command: bundle exec sidekiq | ||||||
|  | |||||||
| @ -13,7 +13,7 @@ module Mastodon | |||||||
|     end |     end | ||||||
| 
 | 
 | ||||||
|     def patch |     def patch | ||||||
|       5 |       6 | ||||||
|     end |     end | ||||||
| 
 | 
 | ||||||
|     def default_prerelease |     def default_prerelease | ||||||
|  | |||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user