This is a security-oriented release with several security patches and bug fixes in the continuation of 1.30.0.
Note that our rolling-release channel (edge) is recommended for faster security patches.
Bug fixes highlights 🐛:
- Some security attack scenarios patched
- Fix domain-wide
Retry-After - Fix muting of feeds gone with HTTP 410
Feature highlights✨:
- CLI: Add optional feed argument to
actualize-user.php
This release has been made by @Alkarex, @andris155, @fzlzjerry, @Inverle, @jamalkamaladdin, @jtracey, @Otolock and newcomers @akine, @colons, @ethanstoner, @gigioneggiando, @Juice-de-Orange, @pavel-miniutka, @qwist1233-cpu, @Sharawey74, @shcheglovnd, @TapuGithub, @yuchenshi, @ZainnQureshii
Full changelog:
- Deployment
- Reword recommendations and explanations for edge (rolling release) vs. latest (versioned release) channels #9270
- Security
- Config + increase default values for search max length and depth #9280
- Accept a trusted proxy address given without a subnet #9301
- Warn during session regenerate fail #9311, #9376
- CI/CD add zizmor workflow for action security checks #9228, #9331
- Use PHP
#[\SensitiveParameter]#9322 - Reject token access (RSS/OPML export, feed refresh) for disabled accounts #9336
- Require POST+CSRF for self-update mutations #9335
- Make the login challenge nonce one-time #9334
- Bound ZIP import against decompression bombs #9332
- Rotate session ID on all authenticated transitions #9333
- Minz: Remove vulnerable and unused code path for displaying errors #9395
- Fix NAT64 feed fetching on IPv6-only hosts #9372
- Bug fixes
- Fix domain-wide
Retry-After#9390 - Fix muting of feeds gone with HTTP 410 #9391
- Fix infinite redirect loop due to
SCRIPT_NAMEinPATH_INFO#9282, #9287 - Restore the automatic reading view after marking articles as read, while preserving explicit filters #9288
- Fix adaptive reading state after marking articles read #9290
- Fix regression sharing links #9303
- Don’t disable anonymous refresh when anonymous feed access is disabled #9354
- Fix regression with HTTPS proxies due to wrong TLS SNI resolution #9341
- Better enforce limits for feeds and categories #9357
- Fix JavaScript error when opening a label menu in sidebar #9377
- Fix custom favicon with GReader API #9409
- Fix domain-wide
- CLI
- Add optional feed argument to
actualize-user.php#9319
- Add optional feed argument to
- UI
- Extensions
- Call
check_url_before_addhook when previewing a feed #9343
- Call
- I18n
- Misc.
- Check SVG optimization in the tests CI workflow with SVGO #9361
- Move PHPUnit flags to a config file and use strictest failure mode #9374
- Avoid writing to log files during unit tests #9373
- Bump Ruby gems automatically with Dependabot for docs #9401
- Update dev dependencies #9323, #9324,
#9325, #9326, #9327,
#9328, #9368, #9378,
#9379, #9380, #9381,
#9402, #9403, #9404,
#9405, #9406, #9407