diff --git a/release-notes-published/11.0.8.md b/release-notes-published/11.0.8.md new file mode 100644 index 0000000000..035b0e4e14 --- /dev/null +++ b/release-notes-published/11.0.8.md @@ -0,0 +1,21 @@ + + + + +## Release notes + +- Security bug fixes + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): fix(api): fix dependency repo perms in Create/RemoveIssueDependency + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): fix(api): draft releases could be read before being published + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): misconfigured security checks on tag delete web form + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): incorrect logic in "Update PR" did not enforce head branch protection rules correctly + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): issue owner can delete another user's comment's edit history on same issue + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10039): tag protection rules can be bypassed during tag delete operation +- Included for completeness but not user-facing (chores, etc.) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10186): fix: frontend-checks failure + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10176): Update dependency @playwright/test to v1.56.1 (v11.0/forgejo) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10177): chore: pin node version + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10174): Update module golang.org/x/crypto to v0.45.0 (v11.0/forgejo) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10134): Update module golang.org/x/crypto to v0.44.0 (v11.0/forgejo) + - [PR](https://codeberg.org/forgejo/forgejo/pulls/10043): feat: Replace mholt/archiver/v3 with mholt/archives (#7025) +