This release includes 1 security fix for security teams reviewing exposed deployments.
Published 3d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
laravel
self-hosted
time-tracker
time-tracking
timetracker
timetracking
+2 more
timetrackingapp
vue
Affected surfaces
auth
rbac
Summary
AI summaryFixes a security vulnerability allowing original owners to edit or delete reassigned time entries.
Full changelog
[!NOTE]
This release includes security fixes, please make sure to upgrade as soon as possible.
What's Changed
- Solidtime time-entry reassignment leaves stale user_id, letting the original owner bulk edit and delete a reassigned member's entry - thanks @ashrexon for the report
- Fix awkward wording for time tracker alert email by @candideu in https://github.com/solidtime-io/solidtime/pull/1156
- Reduce amount of failed jobs by @korridor in https://github.com/solidtime-io/solidtime/pull/1157
- Bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/solidtime-io/solidtime/pull/1126
- Bump actions/setup-node from 6 to 7 by @dependabot[bot] in https://github.com/solidtime-io/solidtime/pull/1161
- Extension manifest and dockerignore by @korridor in https://github.com/solidtime-io/solidtime/pull/1134
New Contributors
- @candideu made their first contribution in https://github.com/solidtime-io/solidtime/pull/1156
Full Changelog: https://github.com/solidtime-io/solidtime/compare/v0.16.0...v0.17.0
Security Fixes
- GHSA-jj53-w7j5-jhp7 — Solidtime time‑entry reassignment leaves stale user_id, allowing original owner to bulk edit/delete reassigned entries
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]