diff --git a/CHANGELOG.md b/CHANGELOG.md index 2c9da7e3b..f4b97ea4a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,15 @@ Fixing other platforms In Progress. [Upgrade WeKan](https://wekan.fi/upgrade/) +# v7.99 2025-10-11 WeKan ® release + +This release fixed the following bugs: + +- [Improve automatic Snap upgrades](https://github.com/wekan/wekan/commit/aab671398c7ee3d7ea4934c6c9c977ad630fa74f). + Thanks to xet7. + +Thanks to above GitHub users for their contributions and translators for their translations. + # v7.98 2025-10-11 WeKan ® release This release adds the following CRITICAL SECURITY FIXES: @@ -29,14 +38,14 @@ This release adds the following CRITICAL SECURITY FIXES: Thanks to Anynymous Security Researcher and xet7. - [Security Fix FG-VD-22-078: Prevent SVG Billion Laughs Attack](https://github.com/wekan/wekan/commit/30c1597b658b0ef50fd2efc56786e8b0f08ac72c). Thanks to Nguyen Thanh Nguyen of Fortinet's FortiGuard Labs and xet7. +- [Security Fix usd-2022-0041: CWE-284 Improper Access Control](https://github.com/wekan/wekan/commit/f6591d7820e01075cba93612a5fdbf692fbe49dc). + Thanks to Christian Pöschl of usd AG and xet7. - [Security Fix JVN#14269684: Broken access control](https://github.com/wekan/wekan/commit/9720e703fd9432bf0e1bfea2358f8c7ea078f1b1). Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7. - [Security Fix JVN#74210258: Stored XSS](https://github.com/wekan/wekan/commit/e1fa607f87d821accb846f2deef1f388003848d1). Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7. - [Security Fix JVN#86586539: Stored XSS](https://github.com/wekan/wekan/commit/ee79cab7b27f73fab62a00ec49add73fd6f7bcaa). Thanks to Ryoya Koyama of Mitsui Bussan Secure Directions, Inc and xet7. -- [Security Fix usd-2022-0041: CWE-284 Improper Access Control](https://github.com/wekan/wekan/commit/f6591d7820e01075cba93612a5fdbf692fbe49dc). - Thanks to Christian Pöschl of usd AG and xet7. - [Security Fix JVN#15385465: CWE-79 XSS, that affected WeKan 7.94](https://github.com/wekan/wekan/commit/81c3dc1d956cd7040655940f6569653d7b98fa9a). Thanks to Sho Sugiyama and xet7. - Security Fix JVN#80785288: CWE-79 XSS, that affected WeKan 3.94 and v3.95. This was already previously fixed. diff --git a/Dockerfile b/Dockerfile index df2b3a565..46b2b2861 100644 --- a/Dockerfile +++ b/Dockerfile @@ -249,9 +249,9 @@ cd /home/wekan/app # Remove legacy webbroser bundle, so that Wekan works also at Android Firefox, iOS Safari, etc. #rm -rf /home/wekan/app_build/bundle/programs/web.browser.legacy #mv /home/wekan/app_build/bundle /build -wget "https://github.com/wekan/wekan/releases/download/v7.98/wekan-7.98-amd64.zip" -unzip wekan-7.98-amd64.zip -rm wekan-7.98-amd64.zip +wget "https://github.com/wekan/wekan/releases/download/v7.99/wekan-7.99-amd64.zip" +unzip wekan-7.99-amd64.zip +rm wekan-7.99-amd64.zip mv /home/wekan/app/bundle /build # Put back the original tar diff --git a/Stackerfile.yml b/Stackerfile.yml index 329259b0a..52684e9b2 100644 --- a/Stackerfile.yml +++ b/Stackerfile.yml @@ -1,5 +1,5 @@ appId: wekan-public/apps/77b94f60-dec9-0136-304e-16ff53095928 -appVersion: "v7.98.0" +appVersion: "v7.99.0" files: userUploads: - README.md diff --git a/docs/Platforms/Propietary/Windows/Offline.md b/docs/Platforms/Propietary/Windows/Offline.md index ef4619bab..73fee082d 100644 --- a/docs/Platforms/Propietary/Windows/Offline.md +++ b/docs/Platforms/Propietary/Windows/Offline.md @@ -10,7 +10,7 @@ This is without container (without Docker or Snap). Right click and download files 1-4: -1. [wekan-7.98-amd64-windows.zip](https://github.com/wekan/wekan/releases/download/v7.98/wekan-7.98-amd64-windows.zip) +1. [wekan-7.99-amd64-windows.zip](https://github.com/wekan/wekan/releases/download/v7.99/wekan-7.99-amd64-windows.zip) 2. [node.exe](https://nodejs.org/dist/latest-v14.x/win-x64/node.exe) @@ -22,7 +22,7 @@ Right click and download files 1-4: 6. Double click `mongodb-windows-x86_64-7.0.25-signed.msi` . In installer, uncheck downloading MongoDB compass. -7. Unzip `wekan-7.98-amd64-windows.zip` , inside it is directory `bundle`, to it copy other files: +7. Unzip `wekan-7.99-amd64-windows.zip` , inside it is directory `bundle`, to it copy other files: ``` bundle (directory) diff --git a/package-lock.json b/package-lock.json index 742d67a48..becdd38bd 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,6 +1,6 @@ { "name": "wekan", - "version": "v7.98.0", + "version": "v7.99.0", "lockfileVersion": 1, "requires": true, "dependencies": { diff --git a/package.json b/package.json index 5d137a65a..9633969a5 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "wekan", - "version": "v7.98.0", + "version": "v7.99.0", "description": "Open-Source kanban", "private": true, "repository": { diff --git a/public/api/wekan.html b/public/api/wekan.html index b4e015e6b..93fe696bf 100644 --- a/public/api/wekan.html +++ b/public/api/wekan.html @@ -1524,7 +1524,7 @@ var n=this.pipeline.run(e.tokenizer(t)),r=new e.Vector,i=[],o=this._fields.reduc