Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. HedgeDoc
  3. HedgeDoc - Package Updates

HedgeDoc - Package Updates

Scheduled Pinned Locked Moved HedgeDoc
38 Posts 3 Posters 10.8k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Package UpdatesP Offline
    Package UpdatesP Offline
    Package Updates
    wrote on last edited by
    #29

    [1.20.0]

    • Update HedgeDoc to 1.10.0
    • Full changelog
    • GHSA-pjf2-269h-cx7p: MySQL & free URL mode allows to hide existing notes
    • Add disableNoteCreation config option for read-only instances
    • Add a pointer to Mermaid 9.1.7 documentation, which is what HedgeDoc 1 supports.
    • Compatibility with Node.js 22 is now checked in CI
    • Fix a crash when having numeric-only values in opengraph frontmatter
    • Fix unnecessary session creation on healthcheck endpoint
    • Fix invalid metadata being sent for minio uploads
    • Fix screen readers announcing headings twice
    • Fix a crash when receiving unexpected OAuth profile data
    • Fix some cases of HedgeDoc not redirecting to the previous page after login
    • Fix heading anchor links referencing an invalid URL
    • Our meta-marked package is now published to NPM, fixing some installation issues
    1 Reply Last reply
    0
    • Package UpdatesP Offline
      Package UpdatesP Offline
      Package Updates
      wrote on last edited by
      #30

      Latest release was reverted https://community.hedgedoc.org/t/new-hedgedoc-1-x-release/1908

      1 Reply Last reply
      0
      • Package UpdatesP Offline
        Package UpdatesP Offline
        Package Updates
        wrote on last edited by
        #31

        Turns out it was a false alarm , so the release is back

        1 Reply Last reply
        0
        • Package UpdatesP Offline
          Package UpdatesP Offline
          Package Updates
          wrote on last edited by
          #32

          [1.20.1]

          • CLOUDRON_OIDC_PROVIDER_NAME implemented
          1 Reply Last reply
          0
          • Package UpdatesP Offline
            Package UpdatesP Offline
            Package Updates
            wrote on last edited by
            #33

            [1.20.2]

            • Update hedgedoc to 1.10.1
            • Full Changelog
            • Add fixed rate-limiting to the login and register endpoints
            • Add configurable rate-limiting to the new notes endpoint
            • Fix a crash when cannot read user profile in OAuth (#​5850 by @​lautaroalvarez)
            • Fix CSP Header for mermaid embedded images (#​5887 by @​domrim)
            • Change default of HSTS preload to false for compliance with the HSTS preload list requirements (#​5913 by @​SvizelPritula)
            • Dominik Rimpf
            • Lautaro Alvarez
            1 Reply Last reply
            0
            • Package UpdatesP Offline
              Package UpdatesP Offline
              Package Updates
              wrote on last edited by
              #34

              [1.20.3]

              • Update hedgedoc to 1.10.2
              • Full Changelog
              • Check if a valid user id is present when using OAuth2
              • Abort SAML login if NameID is undefined instead of logging in with a user named "undefined" (Thanks @​Haanifee)
              • Set default values for username and email attribute mapping in SAML configuration
              1 Reply Last reply
              0
              • Package UpdatesP Offline
                Package UpdatesP Offline
                Package Updates
                wrote on last edited by
                #35

                [1.21.0]

                • Update base image to 5.0.0
                1 Reply Last reply
                0
                • Package UpdatesP Offline
                  Package UpdatesP Offline
                  Package Updates
                  wrote on last edited by
                  #36

                  [1.21.1]

                  • Update hedgedoc to 1.10.3
                  • Full Changelog
                  • This release fixes a security issue of a possible XSS exploit which can be planted via a malicous SVG file upload.
                  • See GHSA-3983-rrqh-mvx5 for more details
                  • Add config options CMD_SAML_WANT_ASSERTIONS_SIGNED and CMD_SAML_WANT_AUTHN_RESPONSE_SIGNED for SAML auth, since
                  • some instances didn't comply with the new defaults of @node-saml/passport-saml
                  1 Reply Last reply
                  0
                  • Package UpdatesP Offline
                    Package UpdatesP Offline
                    Package Updates
                    wrote on last edited by
                    #37

                    [1.21.2]

                    • Update hedgedoc to 1.10.5
                    • Full Changelog
                    • Fix the bundled healthcheck in the docker container
                    • GHSA-gmgw-rcmh-7x47 reports potential cross-site side-effects due to not applying sandboxing to iframes.
                    • GHSA-6wm6-3vpq-6qvv reports a possible CSRF vulnerability when using certain social login providers because the state parameter is not used and checked.
                    • Add enableUploads (CMD_ENABLE_UPLOADS) config option to restrict uploads to registered users, all users or
                    • Allow links to protocols such as xmpp, webcal or geo
                    • Switch from deprecated shortid to nanoid module, with 10 character long aliases in "public" links
                    • Ensure compatibility with Node 24
                    • Protect user history from accidental or malicious deletion by adding a CSRF-like token
                    • Many enhancements in the documentation at docs.hedgedoc.org
                    • Ignore the healthcheck endpoint in the "too busy" limiter
                    • Send the referrer origin for YouTube embeddings due to their requirement
                    1 Reply Last reply
                    0
                    • Package UpdatesP Offline
                      Package UpdatesP Offline
                      Package Updates
                      wrote last edited by
                      #38

                      [1.21.3]

                      • Update hedgedoc to 1.10.6
                      • Full Changelog
                      • GHSA-x74j-jmf9-534w reports a bug where security headers for upload files were not set correctly.
                      • GHSA-672m-p72w-gw28 reports potential security issues with limited script execution in uploaded SVG files.
                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search