Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing breaking change in 5.0.0 changelog: URL tokens #4978

Merged
merged 1 commit into from
Jan 9, 2025

Conversation

manics
Copy link
Member

@manics manics commented Jan 8, 2025

This breaking change was missing from the 5.0.0 changelog, because it doesn't seem to be associated with a PR:
b319b58

@minrk
Copy link
Member

minrk commented Jan 9, 2025

Right, it was in the forward-port of the security PR for GHSA-7r3h-4ph8-w38g, which touched a lot of things. The PR merge commit is here. The 4.x PR introduced the option, leaving it opt-out to avoid breaking things, while 5.0 opted in to better security by default. Looking back, I probably should have made the toggle in its own PR instead of its own commit for better visibility.

@minrk minrk merged commit 8391d1d into jupyterhub:main Jan 9, 2025
4 checks passed
@manics manics deleted the url-tokens-5.0.0-changelog branch January 9, 2025 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants