Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

fix(core): Upgrade tournament to address some XSS vulnerabilities #10277

Merged
merged 1 commit into from
Aug 1, 2024

Conversation

netroy
Copy link
Member

@netroy netroy commented Aug 1, 2024

Summary

Related PRs:

Related Linear tickets, Github issues, and Community forum posts

https://linear.app/n8n/issue/SEC-58
https://linear.app/n8n/issue/SEC-60

Review / Merge checklist

  • PR title and summary are descriptive

@n8n-assistant n8n-assistant bot added core Enhancement outside /nodes-base and /editor-ui n8n team Authored by the n8n team labels Aug 1, 2024
@netroy netroy added security release/backport Changes that need to be backported to older releases. labels Aug 1, 2024
Copy link

cypress bot commented Aug 1, 2024



Test summary

390 0 0 0Flakiness 0


Run details

Project n8n
Status Passed
Commit 00ff299
Started Aug 1, 2024 3:14 PM
Ended Aug 1, 2024 3:19 PM
Duration 04:48 💡
OS Linux Debian -
Browser Electron 118

View run in Cypress Cloud ➡️


This comment has been generated by cypress-bot as a result of this project's GitHub integration settings. You can manage this integration in this project's settings in the Cypress Cloud

Copy link
Contributor

github-actions bot commented Aug 1, 2024

✅ All Cypress E2E specs passed

@netroy netroy merged commit 43ae159 into master Aug 1, 2024
27 checks passed
@netroy netroy deleted the upgrade-tournament branch August 1, 2024 15:19
@github-actions github-actions bot mentioned this pull request Aug 2, 2024
@janober
Copy link
Member

janober commented Aug 2, 2024

Got released with n8n@1.53.1

MiloradFilipovic added a commit that referenced this pull request Aug 2, 2024
* master:
  refactor(core): Clean up event relays (no-changelog) (#10284)
  fix(editor): Fix execution retry button (#10275)
  feat(core): Show sub-node error on the logs pane. Open logs pane on sub-node error (#10248)
  refactor(core): Move instanceRole to InstanceSettings (no-changelog) (#10242)
  feat(core): Allow filtering executions and users by project in Public API  (#10250)
  fix(core): Make execution and its data creation atomic (#10276)
  refactor(core): Mark schema env vars used by cloud hooks (no-changelog) (#10283)
  ci: Fix DB tests (no-changelog) (#10282)
  feat(core): Support create, delete, edit role for users in Public API (#10279)
  refactor(core): Decouple post workflow execute event from internal hooks (no-changelog) (#10280)
  feat(core): Allow transferring credentials in Public API (#10259)
  feat(core): Support create, read, update, delete projects in Public API (#10269)
  ci: Introduce lint rule `no-type-unsafe-event-emitter` (no-changelog) (#10254)
  fix(core): Surface enterprise trial error message (#10267)
  fix(editor): Enable moving resources only if team projects are available by the license (#10271)
  fix(core): Upgrade tournament to address some XSS vulnerabilities (#10277)

# Conflicts:
#	packages/cli/src/Server.ts
@github-actions github-actions bot mentioned this pull request Aug 7, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
core Enhancement outside /nodes-base and /editor-ui n8n team Authored by the n8n team release/backport Changes that need to be backported to older releases. Released security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants