- Details
Security release!
This release includes fixes for issues found in a security audit by Cure53 funded by Alpha-Omega.
- Security: Fixed command injection via malicious git branch name (GHSA-47f6-5gq3-vx9c / CVE-2024-35241)
- Security: Fixed multiple command injections via malicious git/hg branch names (GHSA-v9qv-c7wm-wgmf / CVE-2024-35242)
- Security: Fixed secure-http checks that could be bypassed by using malformed URL formats (fa3b958)
- Security: Fixed Filesystem::isLocalPath including windows-specific checks on linux (3c37a67)
- Security: Fixed perforce argument escaping (3773f77)
- Security: Fixed handling of zip bombs when extracting archives (de5f7e3)
- Security: Fixed Windows command parameter escaping to prevent abuse of unicode characters with best fit encoding conversion, reported by Splitline Huang (3130a74, 04a63b3)
- Fixed PSR violations for classes not matching the namespace of a rule being hidden, this may lead to new violations being shown (#11957)
- Fixed UX when a plugin is still in vendor dir but is not required nor allowed anymore after changing branches (#12000)
- Fixed new platform requirements from composer.json not being checked if the lock file is outdated (#12001)
- Fixed ability for
configcommand to remove autoload keys (#11967) - Fixed empty
typesupport ininitcommand (#11999) - Fixed git clone errors when
safe.bareRepositoryis set tostrictin the git config (#11969) - Fixed regression showing network errors on PHP <8.1 (#11974)
- Fixed some color bleed from a few warnings (#11972)
- Details
Bugfix release including hotfix for imagick
PHP 8.1.28 - https://www.php.net/ChangeLog-8.php#PHP_8_1
PHP 8.2.19 - https://www.php.net/ChangeLog-8.php#PHP_8_2
PHP 8.3.7 - https://www.php.net/ChangeLog-8.php#PHP_8_3
- Details
Bugfix releases for MySQL 8.3.0 and 8.4
- Details
Enhancement release
[Enhancement] added german language file
[Enhancement] add password manager feature
- Details
Fixes issue where certain modules were missing by default in full release of Bearsampp and iconography fixes
Fixes issue where certain modules were missing by default in full release of Bearsampp
Updates Iconography back to production version of Bearsampp