Security Patch Release
- Fixes critical auth vulnerability affecting self-hosted non-SSO deployments with publicly accessible
/auth/*endpoints - Switches to Docker Hardened base images to reduce exposure to 3rd party vulnerabilities
- Bump dependency versions to address various security vulnerabilities
- New Databricks OAuth M2M option for increased security
- New org setting to completely disable all Personal Access Tokens
- Various performance and bug fixes throughout the app
We recommend all self-hosted users update as soon as possible.
This is also a great time to read through our production hardening docs and ensure you are following all best practices for security.