diff --git a/release-notes-published/13.0.3.md b/release-notes-published/13.0.3.md new file mode 100644 index 0000000000..f6a76bba03 --- /dev/null +++ b/release-notes-published/13.0.3.md @@ -0,0 +1,33 @@ + + + + +## Release notes + +- Security bug fixes + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10038): fix(api): fix dependency repo perms in Create/RemoveIssueDependency + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10038): fix(api): draft releases could be read before being published + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10038): misconfigured security checks on tag delete web form + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10038): incorrect logic in "Update PR" did not enforce head branch protection rules correctly + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10038): issue owner can delete another user's comment's edit history on same issue + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10038): tag protection rules can be bypassed during tag delete operation +- Localization + - Updates from Codeberg Translate: [#10132](https://codeberg.org/forgejo/forgejo/pulls/10132) (backport of [#9804](https://codeberg.org/forgejo/forgejo/pulls/9804), [#9917](https://codeberg.org/forgejo/forgejo/pulls/9917)) +- Bug fixes + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10146) ([backported](https://codeberg.org/forgejo/forgejo/pulls/10170)): fix: support git clone when /tmp has noexec + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10140) ([backported](https://codeberg.org/forgejo/forgejo/pulls/10148)): fix: get new session from enginegroup instead of masterengine + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10002) ([backported](https://codeberg.org/forgejo/forgejo/pulls/10013)): fix: endless redirection loop between /user/settings/change_password and /user/settings/security + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9763) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9938)): fix(alt): handle package names with dots in ALT repository + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9914) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9920)): fix: pull request review comment position +- Included for completeness but not user-facing (chores, etc.) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10178): chore: pin node version + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10175): Update module golang.org/x/crypto to v0.45.0 (v13.0/forgejo) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10135): Update module golang.org/x/crypto to v0.44.0 (v13.0/forgejo) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10056) ([backported](https://codeberg.org/forgejo/forgejo/pulls/10064)): fix: less restrictive matrix room_id pattern + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9973) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9994)): fix: add required headers to Pagure migration + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9757) ([backported](https://codeberg.org/forgejo/forgejo/pulls/10027)): fix: prevent orgs from being added as members of orgs + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9997) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9998)): fix(api): set all hook event types + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9875) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9919)): fix: don't show ConEmu OSC escape sequences + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9913) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9918)): fix: set tag message on tag addition + - [PR](https://codeberg.org/forgejo/forgejo/pulls/9872) ([backported](https://codeberg.org/forgejo/forgejo/pulls/9901)): fix: construct project links in timeline better +