A maintenance release changes server defaults and behavior, fixes correctness issues, and addresses disclosed security issues in watch permissions and google.. It also includes fixes for unbounded peer lease HTTP request reads and nested transaction request handling.
Action needed (3)
securityhighThe
google.dependency updategolang. org/grpc The release updates
google.to versiongolang. org/grpc 1.to address GHSA-hrxh-6v49-42gf.82. 1 breakingThe
snapshotLimitBytedefaultThe release sets a reasonable default value for
snapshotLimitByte.breakingThe client HTTP server
ReadHeaderTimeoutThe client HTTP server now sets
ReadHeaderTimeout.
Check if affected (1)
securityhighWatch responses restricted to authorized keys
Applicability is not stated in the release notes.
The watch permission issue covered by GHSA-xg4h-6gfc-h4m8 is fixed. A user granted read permission on one key no longer receives watch responses for every key starting from that key.