Skip to content

v1.5.2

Choose a tag to compare

@github-actions github-actions released this 25 Sep 22:55
· 53 commits to main since this release

What's new in 1.5.2

Security: a saved password never reaches the app's page. Until now, picking a saved connection handed its password - and its SSH password - to the page, which sent it with every request. The page now only names the saved connection, and the password is filled in behind it: only for the host, port and user it was saved for, and with that connection's own SSL settings. A script that got into the page could otherwise have read every saved password, or sent one to another server under the saved connection's name.

What this changes for you:

  • The password box stays empty for a saved connection; the key icon still shows that one is saved.
  • In Save, Edit and Clone connection, leave the password box empty to keep the saved password.
  • A saved connection pointed at another host, port or user has its password typed again - a saved password is never carried over to a different address.

This completes the security review of 1.5.1.

Verify your download

These installers are not code-signed. Compare what you downloaded against the SHA-256 below:

d531508afa094e98cff11796071262dc4a49d3a9523d48ca7521ca120164a7b8  NOBS.SQL.Editor_1.5.2_x64-setup.exe
b4c889c876f238194142d2ecc9f83a925245da5888ca7dc5e6df80d98c0191f4  NOBS.SQL.Editor_1.5.2_x64_en-US.msi

PowerShell: Get-FileHash .\<file> -Algorithm SHA256

See CODE_SIGNING.md for what this does and does not prove.

Full Changelog: v1.5.1...v1.5.2