Fixed
- Prometheus errors other than 400/422 (for example 500s or proxy errors) now include the response body, so failures explain what went wrong instead of only showing the status code (#1270)
- Docker images now report the correct release version instead of a build-info fallback (#1269)
Security
- Outbound Grafana clients now refuse redirects to a different scheme, host, or port, so Grafana credentials are never forwarded to a redirect target. Use
--allow-cross-origin-redirects(orGRAFANA_ALLOW_CROSS_ORIGIN_REDIRECTS=true) to restore the previous behaviour (#1268)