Update ghcr.io/mealie-recipes/mealie Docker tag to v1.4.0 #224
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "renovate/ghcr.io-mealie-recipes-mealie-1.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v1.3.2
->v1.4.0
Release Notes
mealie-recipes/mealie (ghcr.io/mealie-recipes/mealie)
v1.4.0
Compare Source
Highlights
Security Updates
The team at Github Security Lab provided us with a disclosure containing some recommendations for enhancing the security of Mealie, which have been implemented as part of this release. The vulnerabilities all required an authenticated user to exploit, so were likely only an issue if you allowed open registration to your system.
The key functional change you'll notice is that it's now not possible to scrape recipes/images from URLs that resolve to internal IP addresses. This is to prevent a user being able to map out the network the Mealie instance is part of.
Note that we now default the
ALLOW_SIGNUP
environment variable to false, previously it was true.There is a new security page available in the documentation should you want to read up on some extra security steps you can take for your Mealie instance.
The pull request was https://github.com/mealie-recipes/mealie/pull/3368
What's Changed
New Contributors
Full Changelog: https://github.com/mealie-recipes/mealie/compare/v1.3.2...v1.4.0
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
Renovate Ignore Notification
Because you closed this PR without merging, Renovate will ignore this update (
v1.4.0
). You will get a PR once a newer version is released. To ignore this dependency forever, add it to theignoreDeps
array of your Renovate config.If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.