Skip to content

Release/4.1.2 #725

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Jun 12, 2025
Merged

Release/4.1.2 #725

merged 3 commits into from
Jun 12, 2025

Conversation

tillprochaska
Copy link
Contributor

No description provided.

@tillprochaska tillprochaska marked this pull request as ready for review June 12, 2025 16:33
@tillprochaska tillprochaska requested a review from en-occrp June 12, 2025 16:34
@tillprochaska tillprochaska added this pull request to the merge queue Jun 12, 2025
Merged via the queue into main with commit cbdbf83 Jun 12, 2025
2 checks passed
@riotbib
Copy link

riotbib commented Jun 13, 2025

Hi @tillprochaska, as I understand the discourse announcement, there is a serious security patch in 321ef6f.

I sunset my Aleph deployment a few weeks ago. I would have been quite disappointed to not hear about this security issue in advance.

IMHO best practice would be to announce the patch weeks in advance, so admins can be ready, when the patch released. Just dropping a patch like this, endangers the users, admins and data contained in an instance.

Would be happy to hear your thought about this. Thanks.

@zaniiezxx3
Copy link

Hi @riotbib. Thank you for your comment and we completely understand your concern.

We were notified of the issue just last week and moved quickly to release a patch for the Aleph community within 36 hours. Ideally, we would have provided advance notice to all administrators but in this case, acting swiftly was necessary. We absolutely agree that advance communication is best practice and we're committed to that whenever timelines allow.

For ongoing updates and community discussions, feel free to join us on our Discourse forum. We always welcome input and feedback there.

Thanks again for raising this.

@riotbib
Copy link

riotbib commented Jun 17, 2025

Hi @zaniiezxx3, thanks for your reply.

With all respect, I do not get the reasoning for this decision. Why was it necessary to expose the fix, allowing easy exploits for unpatched systems? The Discourse post has 17 views until today, 5 days after. I guess OCCRP and others patched their deployments, good for you. But what about the rest?

I did sign up for the Discourse forum, but my account was not enabled. Wanted to most my concerns there previously.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants