Skip to content

Release 2.10.2

Latest

Choose a tag to compare

@anvit anvit released this 24 Aug 20:58
· 87 commits to qa/2.x since this release

Release 2.10.2 is a security focused release that includes a few critical security related updates, as well as dependency updates. This release also addresses the security issue that we'd released a security patch for on July 14th 2026.

Community Contributors

A massive thanks to folks who reported issues and vulnerabilities for this release!

Big thanks to these contributors for contributing fixes for this release:

List of changes

Security updates:

  • Added a check to autocomplete actions (#2407)
  • Aligned finding aid action permissions (#2415)
  • Improved generated salt entropy (#2398)
  • Removed unused digital object module action (#2395)
  • Restricted physical object API creation (#2390)
  • Added culture_header filter to plugin folders (#2388)
  • Refactored HTTP_X_ATOM_CULTURE handling (#2384)
  • Refactored finding aid generation commands (#2382)
  • Refactored CSV Import command (#2381)
  • Refactored ffmpeg video thumbnail generation (#2379)
  • Updated pdftotext to escape shell args (#2377)
  • Fixed broken user log in redirect page with BS5 when SSO is enabled (#2364)
  • Fixed BS5 styling for user list with SSO (#2316)
  • Pinned trivy version in SBOM generation workflow (#2324)

Bug fixes and other changes:

  • Fixed Google Analytics key not being loaded (#2317)
  • Expanded Getting Started information (#2311)
  • Set consistent message for logged out users attempting to access draft pages (#2257)
  • Fixed php error message in csv import (#2369)
  • Fixed failing cypress tests (#2404)

Dependency updates:

  • Bumped fast-uri from 3.1.2 to 3.1.5 (#2410)
  • Bumped nanoid from 3.3.12 to 3.3.18 (#2409)
  • Bumped immutable from 5.0.3 to 5.1.5 (#2310)
  • Bumped serialize-javascript and terser-webpack-plugin (#2309)
  • Bumped MySQL version for docker (#2308)
  • Bumped qs from 6.14.1 to 6.14.2 (#2295)
  • Bumped webpack from 5.97.1 to 5.105.0 (#2291)
  • Bumped composer dependencies (#2287)
  • Bumped symfony/process from 7.3.0 to 7.4.5 (#2281)
  • Bumped lodash from 4.17.21 to 4.17.23 (#2277)
  • Bumped postcss from 8.5.13 to 8.5.26 (#2406)
  • Bumped immutable from 5.1.5 to 5.1.9 (#2399)
  • Bumped systeminformation from 5.31.6 to 5.33.1 (#2391)
  • Bumped form-data from 4.0.5 to 4.0.6 (#2373)
  • Bumped phpseclib/phpseclib from 3.0.52 to 3.0.55 (#2372)
  • Bumped qs and @cypress/request (#2362)
  • Bumped tmp from 0.2.4 to 0.2.7 (#2358)
  • Bumped uuid and cypress (#2357)
  • Bumped fast-uri from 3.0.6 to 3.1.2 (#2350)
  • Bumped phpseclib/phpseclib from 3.0.51 to 3.0.52 (#2347)
  • Bumped postcss from 8.5.1 to 8.5.13 (#2346)
  • Bumped phpseclib/phpseclib from 3.0.50 to 3.0.51 (#2339)
  • Bumped lodash from 4.17.23 to 4.18.1 (#2338)
  • Bumped picomatch from 2.3.1 to 2.3.2 (#2325)
  • Bumped phpseclib/phpseclib from 3.0.49 to 3.0.50 (#2320)
  • Bumped qs and @cypress/request (#2264)

Full Changelog: v2.10.1...v2.10.2