Update ghcr.io/ancsemi/haven Docker tag in stack haven from 4.12.0 to v4.13.0 #531
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/ghcr.io-ancsemi-haven-4.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
4.12.0→4.13.0Release Notes
ancsemi/Haven (ghcr.io/ancsemi/haven)
v4.13.0Compare Source
A second security release, following up the review in 4.12.0. DMs no longer
go out unencrypted without asking, a contact's changed encryption key is
flagged, and the backup of your DM key can be locked with a passphrase the
server never sees (Settings > Encryption). Private channel codes change when
someone is removed, and forged proxy addresses are ignored. If your server
sits behind Cloudflare's proxy (not the tunnel), set TRUST_PROXY=1 or every
visitor looks like the same person to the login limits. Also: a too-long
thread reply is no longer lost. Run npm install (Start Haven.bat and start.sh
do it for you): the Flash games player is a new dependency.
Security
by the server, without asking, whenever encryption was locked on the
device or the other person had never set it up, and pictures and files
went up the same way. Now nothing is sent until you choose: send it
unencrypted, unlock encryption, or cancel, which puts the message back in
the box. The lock in a DM's header shows when messages there are not
encrypted, and a message that fails to encrypt is no longer sent anyway.
contact's key on your device. If it changes, because they reset their
keys or because someone in between swapped it, the DM says so, the lock
turns into a warning, and nothing is encrypted to the new key until you
trust it. Show verification code opens the code to compare with them.
encrypted-DM key is locked with your login password, which the server
receives every time you sign in. You can lock it with a separate
passphrase instead, one the server never sees. Sign-in then asks for it
once on each new device, and changing your password no longer touches the
backup. Nobody can reset the passphrase for you, including the server
admin.
on the same machine or the local network (nginx, Caddy, Docker, the
built-in tunnel), so a server exposed straight to the internet ignores a
forged X-Forwarded-For and nobody can pick their own address to get past
login limits or IP bans. If your proxy runs on another machine, such as
Cloudflare's proxy, set TRUST_PROXY=1, or every visitor will look like
the proxy.
code, and its private sub-channels' codes, so the code they already know
no longer lets them back in.
permission on it, since the move lets that parent's sub-channel managers
delete it.
from unpkg, whichever version was newest that day, fetched from a third
party by every player, and the games pages allowed scripts from all of
unpkg. It is a pinned dependency now, and no page allows unpkg.
Fixed
covered the main message box and DMs. A thread reply comes back into the
thread box now too, and the thread and pop-out DM boxes stop at the length
limit like the main box does.
time it runs.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.