A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the . URL, and includes broad correctness and dependency updates.
Action needed (4)
securityhighThe
globandrollupdependencies, upgradedThe
globdependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.rollupwas upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.securityThe
globdependency, upgraded to v13The
globdependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.securityThe
rollupdependency, upgraded to v4.59+rollupwas upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.securityThe
.URLwell-known/oauth-protected-resource The
.resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.well-known/oauth-protected-resource
Check if affected (22)
breakingThe
auth.settingomitIdentityTokenOwnershipClaim Applies if you do not configure
auth..omitIdentityTokenOwnershipClaim breakingThe
SignInResolverFactoryOptionstype parametersApplies if you use
SignInResolverFactoryOptions.breakingThe catalog permission exports, removed
Applies if you use
CatalogPermissionRuleInput,CatalogPermissionExtensionPoint, orcatalogPermissionExtensionPoint.- + 19 more on the release page
Plan ahead (6)
deprecatedThe
showandshowModalcompatibility implementation, deprecatedApplies if you use
showorshowModal.deprecatedThe
auth.setting, deprecatedremoval date not announcedomitIdentityTokenOwnershipClaim Applies if you configure
auth..omitIdentityTokenOwnershipClaim deprecatedThe
config.callback format, deprecatedschema Applies if you use
config..schema - + 3 more on the release page