Skip to content

opengist

v1.14.0 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 5d File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

docker gist git go opengist pastebin
+3 more
pastebin-service self-hosted typescript

Affected surfaces

auth deps

Summary

AI summary

Adds Gist expiration, scheduled actions, archive support and OpenSSH integration.

Full changelog

See here how to update Opengist.

Added

  • Gist expiration + scheduled actions (#726)
  • Archive gists (#739)
  • Avatar upload (#730)
  • Push to gists with access tokens (#752)
  • Seed user/admin account via CLI (#750)
  • Open Graph and Twitter Card meta tags on gist pages (#756)
  • OpenSSH support (#735)
  • PKCE for OAuth providers (#720)
  • GitHub alerts in Markdown (#721)
  • Mermaid (.mmd) file rendering support (#741)
  • Syntax highlighting for Salesforce Apex language (#725)
  • Codemirror highlighting and comment shortcut (#742)
  • Confirmation prompt before deleting a file in the editor (#740)
  • Default sort gists user preference (#744)
  • Embedding light, dark and auto themes (#718)
  • Allow copying embedded gists (#719)
  • Option to disable file upload (#737)
  • HEAD endpoint for raw and download file (#748)
  • Log path config (#745)
  • PostgreSQL & MySQL socket connections (#733)
  • IPv6 literals support (#749)
  • Allow underscores in usernames (#703)
  • rel="canonical" link tag (#732)
  • Rootless Docker image (#716)
  • Korean (ko-KR) translation (#767)

Fixed

  • Improve Git handler security (#769)
  • Improve git /init with correlation token (#751)
  • Fix fatal startup error on unparseable git version (#731)
  • Fix actions db (#761)
  • Move users avatar directory (#760)
  • Better handler for committed HTTP responses (#734)
  • Sanitize DOM for ipynb rendering (#736)
  • Add no-store header for embedded js (#724)
  • Make ssh import failure a warning (#705)

Other

  • Package prebuilt frontend assets as webdist tarball (#768)
  • Update deps (#762)
  • Update community page with Pi share extension + gistviewer links (#755)

Security Fixes

  • Improve Git handler security (#769)
  • Sanitize DOM for ipynb rendering (#736)
  • Add `no-store` header for embedded JavaScript to mitigate caching issues (#724)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track opengist

Get notified when new releases ship.

Sign up free

About opengist

Self-hosted pastebin powered by Git, open-source alternative to Github Gist.

All releases →

Related context

Beta — feedback welcome: [email protected]