Critical & security fixes:
- #18652 fix(organization): improvement of organization segregation
- #18813 chore(deps): security updates
- #18637 fix(ingestion): confine feed execution identity to its creator rights
- #18096 fix(backend): escaping in templates
- #18159 fix(ci): replace deprecated circleci/node:current image with cimg/node
- #18528 fix(publicdashboard): enforce capability checks for publicdashboards
- #17742 fix(user): improve org admin
- #18144 fix(user): improve userEdit
- #18446 fix(user): improve user service account edition
- #18423 chore(deps): LTS security update
- #18423 chore(deps): LTS security updates
- #18238 chore(dev): replace the MinIO image by pgsty/silo in the development + fix mkdoc build
- #17705 fix(email): Improve email verification
- #17754 fix(search): Update of search query processing
- #17756 fix(access): minor refactor of access utils
- #17678 fix(backend): improve emails
- #18075 fix(user): normalize email to avoid duplicate
- #17750 chore(lts03): update dependencies
- #17818 fix(notifiers): improve notifier connection query
- #17761 chore(lts03): update CI/CD and skills
- #17772 fix(theme): refactor themes
- #17618 fix(case-template): improvement of capability for case template relation mutations
Direct security updates:
- compression updated from 1.8.1 to 1.8.2
- nodemailer updated from 9.0.5 to 10.0.10
- sanitize-html updated from — to 2.17.6
- @types/sanitize-html updated from — to 2.16.1
- seroval updated from — to 1.6.3
- pycti updated from 7.260309.0.7 to 7.260309.0.8
- starlette updated from — to 1.3.1
- @graphql-tools/merge updated from — to 9.2.3
- @graphql-tools/schema updated from — to 10.1.0
- @graphql-tools/utils updated from — to 11.2.2
- content-type updated from 2.0.0 to 2.1.0
- zod updated from — to 4.5.4
Indirect (transient) security updates:
- @babel/generator updated from 7.29.7 to 7.29.8
- @babel/parser updated from — to 7.29.8
- @babel/traverse updated from 7.29.7 to 7.29.8
- @babel/types updated from — to 7.29.8
- @envelop/core updated from — to 5.6.0
- @graphql-tools/executor-legacy-ws updated from 1.1.28 to 1.1.33
- @graphql-tools/graphql-file-loader updated from 8.1.14 to 8.1.19
- @graphql-tools/import updated from 7.1.14 to 7.1.19
- @graphql-tools/json-file-loader updated from 8.0.28 to 8.0.33
- @graphql-tools/load updated from 8.1.10 to 8.1.16
- @graphql-tools/url-loader updated from 9.1.2 to 9.1.7
- @repeaterjs/repeater updated from 3.0.6 to 3.1.0
- @xmldom/xmldom updated from 0.8.13 to 0.8.15
- dayjs updated from — to 1.11.21
- deepmerge updated from — to 4.3.1
- destroy updated from — to 1.2.0
- dom-serializer updated from — to 2.0.0
- dom-serializer updated from — to 3.1.1
- domelementtype updated from — to 2.3.0
- domelementtype updated from — to 3.0.0
- domhandler updated from — to 5.0.3
- domhandler updated from — to 6.0.1
- domutils updated from — to 3.2.2
- domutils updated from — to 4.0.2
- entities updated from — to 4.5.0
- entities updated from — to 7.0.1
- entities updated from — to 8.0.0
- fast-uri updated from 3.1.5 to 3.1.8
- htmlparser2 updated from — to 10.1.0
- htmlparser2 updated from — to 12.0.0
- iconv-lite updated from — to 0.7.3
- ip-address updated from — to 10.7.0
- is-plain-object updated from — to 5.0.0
- js-yaml updated from 4.1.1 to 4.3.2
- launder updated from — to 1.7.1
- nanoid updated from — to 3.3.18
- parse-srcset updated from — to 1.0.2
- picomatch updated from 4.0.4 to 4.0.7
- postcss updated from — to 8.5.26
- proxy-addr updated from 2.0.7 to 2.0.8
- qs updated from — to 6.16.0
- side-channel updated from 1.1.0 to 1.1.1
- side-channel-list updated from 1.0.0 to 1.0.1
- undici updated from 6.27.0 to 6.29.0
- @grpc/grpc-js updated from 1.14.3 to 1.14.5
- undici updated from 7.22.0 to 7.30.0
Pull Requests:
- fix(case-template): improvement of capability for case template relation mutations (#17618) by Céline Sèbe (@CelineSebe) in #17692
- fix(theme): refactor themes (#17772) by Jeremy Cloarec (@JeremyCloarec) in #17780
- chore(lts03): update CI/CD and skills (#17761) by A. Jard (@aHenryJard) in #17762
- fix(notifiers): improve notifier connection query (#17818) by Sarah Bocognano (@SarahBocognano) in #17821
- chore(lts03): update dependencies (#17750) by A. Jard (@aHenryJard) in #17751
- fix(user): normalize email to avoid duplicate (#18075) by Marie Flores (@marieflorescontact) in #18106
- fix(backend): improve emails (#17678) by Landry Trebon (@lndrtrbn) in #18145
- fix(access): minor refactor of access utils (#17756) by Florian DeLemarre (@delemaf) in #18165
- fix(search): Update of search query processing (#17754) by Florian DeLemarre (@delemaf) in #18167
- fix(email): Improve email verification (#17705) by Sarah Bocognano (@SarahBocognano) in #17777
- chore(dev): replace the MinIO image by pgsty/silo in the development + fix mkdoc build (#18238) by A. Jard (@aHenryJard) in #18310
- chore(deps): LTS security updates (#18423) by Laurent Bonnet (@labo-flg) in #18424
- chore(deps): LTS security update (#18423) by Laurent Bonnet (@labo-flg) in #18425
- fix(user): improve user service account edition (#18446) by Jeremy Cloarec (@JeremyCloarec) in #18401
- fix(user): improve userEdit (#18144) by Marie Flores (@marieflorescontact) in #18519
- fix(user): improve org admin (#17742) by Jeremy Cloarec (@JeremyCloarec) in #18466
- fix(publicdashboard): enforce capability checks for publicdashboards (#18528) by Marie Flores (@marieflorescontact) in #18539
- fix(ci): replace deprecated circleci/node:current image with cimg/node (#18159) by A. Jard (@aHenryJard) in #18530
- fix(backend): escaping in templates (#18096) by A. Jard (@aHenryJard) in #18535
- fix(ingestion): confine feed execution identity to its creator rights (#18637) by Marie Flores (@marieflorescontact) in #18815
- chore(deps): security updates (#18813) by Laurent Bonnet (@labo-flg) in #18812
- fix(organization): improvement of organization segregation (#18652) by Céline Sèbe (@CelineSebe) in #18811
Full Changelog: 7.260309.0-lts.7...7.260309.0-lts.8