## Release notes - Security bug fixes - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): fix(api): fix dependency repo perms in Create/RemoveIssueDependency - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): fix(api): draft releases could be read before being published - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): misconfigured security checks on tag delete web form - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): incorrect logic in "Update PR" did not enforce head branch protection rules correctly - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): issue owner can delete another user's comment's edit history on same issue - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): tag protection rules can be bypassed during tag delete operation - Included for completeness but not user-facing (chores, etc.) - [PR](https://codeberg.org/forgejo/forgejo/pulls/10186): fix: frontend-checks failure - [PR](https://codeberg.org/forgejo/forgejo/pulls/10176): Update dependency @playwright/test to v1.56.1 (v11.0/forgejo) - [PR](https://codeberg.org/forgejo/forgejo/pulls/10177): chore: pin node version - [PR](https://codeberg.org/forgejo/forgejo/pulls/10174): Update module golang.org/x/crypto to v0.45.0 (v11.0/forgejo) - [PR](https://codeberg.org/forgejo/forgejo/pulls/10134): Update module golang.org/x/crypto to v0.44.0 (v11.0/forgejo) - [PR](https://codeberg.org/forgejo/forgejo/pulls/10043): feat: Replace mholt/archiver/v3 with mholt/archives (#7025)