diff --git a/docs/release-notes/release-notes-5.3.0.rst b/docs/release-notes/release-notes-5.3.0.rst new file mode 100644 --- /dev/null +++ b/docs/release-notes/release-notes-5.3.0.rst @@ -0,0 +1,45 @@ +|RCE| 5.3.0 |RNS| +----------------- + +Release Date +^^^^^^^^^^^^ + +- 2024-09-17 + + +New Features +^^^^^^^^^^^^ + +- System-info: expose rhodecode config for better visibility of set settings for RhodeCode system. + + +General +^^^^^^^ + + + +Security +^^^^^^^^ + +- Permissions: fixed security problem with apply-to-children from a repo group functionality breaking + permissions for private repositories exposing them despite repo being private. +- Git-lfs: fixed security problem with allowing off-chain attacks to replace OID data without validating hash for already present oids. + This allowed to replace an LFS OID content with malicious request tailored to open RhodeCode server. + + +Performance +^^^^^^^^^^^ + + + + +Fixes +^^^^^ + +- Fixed problems with incorrect user agent errors + + +Upgrade notes +^^^^^^^^^^^^^ + +- RhodeCode 5.3.0 is unscheduled security release to address some build issues with 5.X images diff --git a/docs/release-notes/release-notes.rst b/docs/release-notes/release-notes.rst --- a/docs/release-notes/release-notes.rst +++ b/docs/release-notes/release-notes.rst @@ -10,6 +10,7 @@ Release Notes .. toctree:: :maxdepth: 1 + release-notes-5.3.0.rst release-notes-5.2.1.rst release-notes-5.2.0.rst release-notes-5.1.2.rst