harness v3.0.0-beta.2 版本更新介绍
发布日期: 2023-10-09
版本号: v3.0.0-beta.2
本次更新主要包含以下改进和修复:新增对流水线和Webhook中pr_closed事件的支持,允许在导入URL中使用.git后缀,实现过期会话令牌及旧Webhook执行记录的自动清理,添加从克隆URL到仓库主页的浏览器重定向功能。安全方面修复了gitness Docker镜像中alpine/git、docker/distribution、containerd/containerd的漏洞以及路径遍历漏洞。代码贡献者@enverbisevac和@DharunKumar04分别通过移除npmrc配置文件和修复路径遍历漏洞完成了首次贡献。该RAM包版本从v3.0.0-beta.1升级至v3.0.0-beta.2。
更新内容 (中文)
更新内容
- 新增对流水线及Webhook中
pr_closed
事件的支持 - 新增支持导入URL中包含
.git
的仓库 - 新增自动清理过期会话令牌及旧Webhook执行记录
- 新增克隆URL自动重定向至仓库首页功能
- 修复gitness Docker镜像中的安全漏洞 [alpine/git, docker/distribution, containerd/containerd]
- 修复路径遍历漏洞
变更详情
- [修复] 移除npmrc并通过@enverbisevac在https://github.com/harness/gitness/pull/3405提供npm缓存锁文件
- 修复路径遍历漏洞 by @DharunKumar04 在 https://github.com/harness/gitness/pull/3399
新贡献者
- @enverbisevac 在https://github.com/harness/gitness/pull/3405完成首次贡献
- @DharunKumar04 在https://github.com/harness/gitness/pull/3399完成首次贡献
完整变更日志: https://github.com/harness/gitness/compare/v3.0.0-beta.1...v3.0.0-beta.2
更新内容 (原始)
Updates
- Added support for pr_closed event in pipeline and webhook
- Added support for .git in import url
- Added automated cleanup of expired session tokens & old webhook executions
- Added browser redirect from clone URL to repo home page
- Fixed vulnerabilities in gitness docker image [ alpine/git, docker/distribution, containerd/containerd ]
- Fixed path-traversal vulnerability
What’s Changed
- [fix] removed npmrc and provide lock file for npm cache by @enverbisevac in https://github.com/harness/gitness/pull/3405
- fix-path-traversal-vulnerability by @DharunKumar04 in https://github.com/harness/gitness/pull/3399
New Contributors
- @enverbisevac made their first contribution in https://github.com/harness/gitness/pull/3405
- @DharunKumar04 made their first contribution in https://github.com/harness/gitness/pull/3399
Full Changelog: https://github.com/harness/gitness/compare/v3.0.0-beta.1...v3.0.0-beta.2