github diced/zipline v3.7.11

one day ago

⚠️ Important ⚠️

  • Vulnerability within oauth
    • Versions affected: anything past v3.6.0
    • Providers affected: Google
    • The vulnerability is caused due to a backwards compatibility fallback method of trying to find a oauth user, this fallback method would not rely on the provider's ID but instead just the username + provider name. This meant that as long as the determined username was the same, two google accounts with the same username will point to the same user if linked.
    • This doesn't effect discord or github, since they have unique usernames.
  • If you don't use oauth, you are totally fine to continue using previous versions at your own risk.

What's Changed

New Contributors

Full Changelog: v3.7.10...v3.7.11

Don't miss a new zipline release

NewReleases is sending notifications on new releases.