Skip to content

v1.5.2

Choose a tag to compare

@github-actions github-actions released this 25 Sep 22:55
· 39 commits to main since this release

What's new in 1.5.2

Security: a saved password never reaches the app's page. Until now, picking a saved connection handed its password - and its SSH password - to the page, which sent it with every request. The page now only names the saved connection, and the password is filled in behind it: only for the host, port and user it was saved for, and with that connection's own SSL settings. A script that got into the page could otherwise have read every saved password, or sent one to another server under the saved connection's name.

What this changes for you:

  • The password box stays empty for a saved connection; the key icon still shows that one is saved.
  • In Save, Edit and Clone connection, leave the password box empty to keep the saved password.
  • A saved connection pointed at another host, port or user has its password typed again - a saved password is never carried over to a different address.

This completes the security review of 1.5.1.

Verify your download

This script is not code-signed. Compare what you downloaded against the SHA-256 below:

3183e1398a5301cb07101ce6230da5fc56f8713f43dba5f651641ff5876bb327  NOBSSQL.ps1

PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256

See CODE_SIGNING.md for what this does and does not prove.

Full Changelog: v1.5.1...v1.5.2