This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
Summary
AI summarySecurity fixes including GHSA-fp8p-hf8g-fw65, GHSA-jh6v-w5f3-8p4x, and GHSA-2qgq-hv52-jhqq.
Full changelog
⚠️ Please update to v4.6.4 as soon as possible as it contains many security fixes. It is highly recommended to update Zipline, patch releases do not contain breaking changes and only usually contain bug fixes. If you do happen to encounter any bugs after updating, please create a detailed issue explaining it. ⚠️
What's Changed
- 🚨 GHSA-fp8p-hf8g-fw65, GHSA-jh6v-w5f3-8p4x, GHSA-2qgq-hv52-jhqq
- fixed OAuth flow to use nonce validation
- fixed folder ownership checks
- fixed rate limits on logins being too aggressive
- fixed dynamic imports
- added content security policy for raw file routes
- removed fluent-ffmpeg in favor of built-in stuff
- updated packages
Full Changelog: https://github.com/diced/zipline/compare/v4.6.3...v4.6.4
Security Fixes
- GHSA-fp8p-hf8g-fw65
- GHSA-jh6v-w5f3-8p4x
- GHSA-2qgq-hv52-jhqq
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About zipline
A ShareX/file upload server that is easy to use, packed with features, and with an easy setup!
Related context
Related tools
Beta — feedback welcome: [email protected]