Skip to content

OpenRefine 3.8.7

Choose a tag to compare

@tfmorris tfmorris released this 21 Nov 20:58
· 1094 commits to master since this release

This release fixes an issue (#6977) which prevents exporting Wikidata QuickStatements in OpenRefine 3.8.5 and 3.8.4, as well as an issue (#6941) which prevents login to Wikidata with OpenRefine 3.8.4. This release includes the same collection of important vulnerability fixes as 3.8.4. We encourage users to upgrade swiftly. It also fixes an issue (#7001) in 3.8.6 where the update banner was always displayed. It is otherwise identical to 3.8.6.

To continue using the Google Drive and Google Sheets integration, users need to obtain their own application credentials from the Google API Console.

Note: the vulnerability fixes were originally released as 3.8.3 but that version is dysfunctional due to human errors in the release process. The description of the vulnerabilities is included again here for visibility.

Vulnerabilities in OpenRefine

Vulnerabilities in bundled extensions

Vulnerabilities in Butterfly (web framework used in OpenRefine)

Special thanks to @wandernauta for the hard work that went into analyzing and reporting those vulnerabilities responsibly and to @tfmorris for reviewing mitigations.

Full Changelog: 3.8.5...3.8.6