Skip to content

Releases: InseeFrLab/onyxia-api

v4.2.0

19 Dec 10:12
bc9627a
Compare
Choose a tag to compare

This release contains multiple fixes for security issues related to helm command injection.
Those fixes have been backported to previous Onyxia-API major versions
Read more here : https://docs.onyxia.sh/vulnerability-disclosure

Security ⚠️

  • Sanitize helm names and namespace (#542) @olevitt
  • Fix arbitrary Helm list parameter injection in GET /my-lab/app (#540) @nicolst
  • Fix command injection vulnerability in HelmInstallService (#539) @nicolst

Changes

🐎 Performance

📦 Dependencies

  • Fabric8 k8s client : revert to OkHTTPClient (#535) @olevitt
  • fix(deps): update fabric8-kubernetes-client monorepo to v7.0.1 (#538) @renovate
  • chore(deps): update fabric8-kubernetes-client monorepo to v7 (major) (#531) @renovate

v3.1.1

19 Dec 10:08
Compare
Choose a tag to compare

This release contains multiple fixes for security issues related to helm command injection.
This is a backport of those fixes.
Read more here : https://docs.onyxia.sh/vulnerability-disclosure

Users are strongly encouraged to use this version instead of v3.1.0 (this can be done by overriding api.image.tag in your helm values) or upgrade to more recent Onyxia releases.

v2.8.2

19 Dec 10:04
Compare
Choose a tag to compare

This release contains multiple fixes for security issues related to helm command injection.
This is a backport of those fixes.
Read more here : https://docs.onyxia.sh/vulnerability-disclosure

Users are strongly encouraged to use this version instead of v2.8.1 (this can be done by overriding api.image.tag in your helm values) or upgrade to more recent Onyxia releases.

v4.1.0

26 Nov 13:26
7c6675a
Compare
Choose a tag to compare

Changes

🪲 Fixes

  • Refactor catalog refresh to make it more resilient (#516) @olevitt

📚 Documentation

📦 Dependencies

  • Upgrade spring-boot to 3.4 (#523) @olevitt
  • Bump helm version to v3.16.3 (#530) @olevitt
  • fix(deps): update dependency org.springdoc:springdoc-openapi-starter-webmvc-ui to v2.7.0 (#529) @renovate
  • chore(deps): update crazy-max/ghaction-docker-meta action to v5.6.1 (#528) @renovate
  • chore(deps): update eclipse-temurin docker tag to v21.0.5_11-jre (#527) @renovate

v4.0.0

06 Nov 09:40
6fe0f88
Compare
Choose a tag to compare

🚀 Features

Changes

v3.1.0

14 Oct 14:32
086217e
Compare
Choose a tag to compare

🚀 Features

🪲 Fixes

Changes

📦 Dependencies

  • Bump helm to v3.16.1 (#506) @olevitt
  • chore(deps): update fabric8-kubernetes-client monorepo to v6.13.4 (#503) @renovate
  • fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v3.3.4 (#499) @renovate

v3.0.0

12 Sep 11:07
9565aa7
Compare
Choose a tag to compare

⚠️ Breaking changes with this release, see migration guide : https://docs.onyxia.sh/v/v9/admin-doc/migration-guides/v8-greater-than-v9 ⚠️

🚀 Features

Changes

📚 Documentation

📦 Dependencies

  • fix(deps): update dependency com.github.erosb:everit-json-schema to v1.14.4 (#482) @renovate
  • chore(deps): update fabric8-kubernetes-client monorepo to v6.13.3 (#474) @renovate
  • fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v3.3.3 - autoclosed (#475) @renovate
  • fix(deps): update dependency org.apache.commons:commons-compress to v1.27.1 (#473) @renovate
  • fix(deps): update dependency org.apache.commons:commons-lang3 to v3.17.0 (#472) @renovate

v2.8.1

05 Aug 10:34
Compare
Choose a tag to compare

🪲 Fixes

  • Fix suspend and resume fails on restricted catalogs (#471) @fcomte

Changes

📦 Dependencies

  • Cleanup unused metrics (#469) @olevitt
  • fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v3.3.2 (#463) @renovate
  • chore(deps): update eclipse-temurin docker tag to v21.0.4_7-jre (#467) @renovate

v2.8.0

22 Jul 10:23
e0155f3
Compare
Choose a tag to compare

🚀 Features

  • openshift scc support (#459) @fcomte
  • Return the list of controllers to better determine service's health (#428) @fcomte
  • Quotas : add ignore annotation (#465) @olevitt
  • Add values.yaml to help discover default values. (#458) @fcomte

Changes

🪲 Fixes

📚 Documentation

📦 Dependencies

  • fix(deps): update dependency org.apache.commons:commons-compress to v1.26.2 (#462) @renovate
  • fix(deps): update dependency org.apache.commons:commons-compress to v1.26.0 [security] (#394) @renovate
  • Bump helm to v3.15.3 (#461) @olevitt
  • Bump helm to v3.15.2 (#449) @olevitt
  • fix(deps): update dependency org.apache.commons:commons-lang3 to v3.15.0 (#460) @renovate
  • chore(deps): update fabric8-kubernetes-client monorepo to v6.13.1 (#439) @renovate
  • fix(deps): update dependency org.springdoc:springdoc-openapi-starter-webmvc-ui to v2.6.0 (#450) @renovate

v2.7.1

24 Jun 11:47
2fea9d3
Compare
Choose a tag to compare

🪲 Fixes

📦 Dependencies

  • fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v3.3.1 (#442) @renovate