1.2.6
Note: This includes a security update for a data exposure issue to authenticated users. Please upgrade promptly.
Security
- Resolve GHSA-c5vw-3gpx-gv22 data exposure to authenticated users (thank you Patchstack for responsibly disclosing this issue; props @kmgalanakis, @dkotter, @jeffpaul, @peterwilsoncc via GHSA-c5vw-3gpx-gv22).
Added
- Expand E2E tests to increase coverage (props @sudip-md, @jeffpaul, @iamdharmesh via #148).
Changed
- Bump WordPress "tested up to" version 6.8 (props @Sourabh208, @dkotter, @jeffpaul via #171).
- Bump tar-fs from 2.1.1 to 2.1.2 (props @dependabot, @peterwilsoncc via #170).
- Update CTA to Fueled (props @jeffpaul via #6ce451a2).
Developer
- Update all third-party actions our workflows rely on to use versions based on specific commit hashes (props @dkotter, @jeffpaul via #168).
- Update workflow permissions for various GitHub actions (props @dkotter, @jeffpaul via #176, #177).
New Contributors
- @sudip-md made their first contribution in #148
- @Sourabh208 made their first contribution in #171
Full Changelog: 1.2.5...1.2.6