Repository navigation
v1.5.2
What's new in 1.5.2
Security: a saved password never reaches the app's page. Until now, picking a saved connection handed its password - and its SSH password - to the page, which sent it with every request. The page now only names the saved connection, and the password is filled in behind it: only for the host, port and user it was saved for, and with that connection's own SSL settings. A script that got into the page could otherwise have read every saved password, or sent one to another server under the saved connection's name.
What this changes for you:
- The password box stays empty for a saved connection; the key icon still shows that one is saved.
- In Save, Edit and Clone connection, leave the password box empty to keep the saved password.
- A saved connection pointed at another host, port or user has its password typed again - a saved password is never carried over to a different address.
This completes the security review of 1.5.1.
Verify your download
These installers are not code-signed. Compare what you downloaded against the SHA-256 below:
d531508afa094e98cff11796071262dc4a49d3a9523d48ca7521ca120164a7b8 NOBS.SQL.Editor_1.5.2_x64-setup.exe
b4c889c876f238194142d2ecc9f83a925245da5888ca7dc5e6df80d98c0191f4 NOBS.SQL.Editor_1.5.2_x64_en-US.msi
PowerShell: Get-FileHash .\<file> -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.5.1...v1.5.2