Security
- The Quarto conversions now run in a private temporary directory, so that the output file that
quarto convertnames after its input can no longer be pre-created as a symlink by another user of the machine. Thanks to Naveed for the PR (#1615). - Paired paths from notebook
formatsmetadata are now prevented from escaping the working tree, including when an absolute notebook path is used. Thanks to Naveed for addressing the issue (#1588). - The CLI now ignores
trustedcell metadata when the notebook signature is invalid, so atrusted=trueoption in a
paired text file cannot make untrusted notebook outputs trusted during--sync. Thanks to Naveed for the fix (#1617). - Custom
cell_markersandendofcellvalues in the light format are now matched literally, preventing regular-expression
injection, parsing errors, and excessive processing time on crafted notebooks. This also fixes writing OCaml notebooks
with custom cell markers. Thanks to Naveed again for the PR (#1618). - We have merged Dependabot security updates for the JupyterLab extension and the documentation website (#1614, #1620, #1622, #1624, #1634, #1639, #1642, #1643, #1647, #1653, #1654).
Fixed
- Menu entries such as "Rename Notebook…" name the file type again, instead of saying "default". Thanks to Michał Krassowski for this PR (#1632).
- Mermaid
%%comments inside a markdown cell are no longer mistaken forpy:percentcell markers (#1533). Thanks to Sanjay Santhanam for his PR (#1609) - A whitespace-only final line in a percent-format cell is now preserved when reading and round-tripping the notebook (#1599). Thanks to lowbyteguy for the PR (#1610).
- The JupyterLab extension's development install script now uses the correct
jupyter-builderimport (#1632). Thanks again to Michał Krassowski for this fix. - Fixed JupyterLab extension build issues related to Yarn package checksums. Thanks to Mahendra Paipuri for his contributions to #1614, #1620, and #1621.
- Fixed pairing on Windows when a prefix root contains subdirectories, such as
notebooks/tutorials///ipynb.
Changed
- Updated the JupyterLab extension's production dependencies (#1621, #1641, #1652).
- Updated the documentation website's Astro, Starlight, and Sharp dependencies (#1612, #1621, #1625, #1641, #1646, #1650, #1652).
- Updated the GitHub Actions used for CI and publishing (#1613, #1619, #1633, #1640, #1649, #1651).
- Updated Jupyter Server in the Pixi environments. Thanks again to Mahendra Paipuri for this update (#1646).
Added
- We have added a development container that can be opened with VS Code’s Dev Containers extension (#1655).
- Added support for the Jenner language. Thanks to Lawrence Sinclair for this contribution (#1493).