Skip to content

3.5.12

Latest
Compare
Choose a tag to compare
@dzikoysk dzikoysk released this 03 May 19:59
· 17 commits to main since this release

Security

In a collaboration with GitHub Security Lab (big thanks to @artsploit 🤍) we've managed to resolve 3 vulnerabilities noticed in Reposilite:

  • GHSL-2024-072
  • GHSL-2024-073
  • GHSL-2024-074

It is highly recommended to update your instances as soon as possible to mitigate the risks. For the time being, we're not revealing details on each one of them, but every instance running on versions between 3.3.0 to 3.5.11 should be considered as vulnerable.

We also recommend regenerating your access tokens, because those could be leaked via malicious Javadocs archives. As long as it's unlikely that you were affected, it's a general good practice in such cases.

Other changes

  • Fixed invalid SHA checksums generated for files uploaded via the dashboard (thanks @laszlof)
  • Bumped dependencies

Sponsors
Thanks to everyone who supported me this month 💜

Active GitHub Sponsors milkyway0308, andrm, rdehuyss, joshuasing, insertt, GotoFinal, mcebular, Koressi, tipsy, Kamilkime, that-apex, SirEndii, crejk, Rollczi, Jan Bojarczuk

Minimal requirements

  • Java 11+
  • RAM 32MB

Downloads