Skip to content

Commit 739dcfd

Browse files
authored
chore: release notes for 1.4.1 (replace custom/manual content with JIRA-driven RN content too) (#848)
* chore: release notes for 1.4.1 (removing content from 1.3.0 too) Signed-off-by: Nick Boldt <[email protected]> fix queries Signed-off-by: Nick Boldt <[email protected]> put content in JIRA instead of overriding content after generation Signed-off-by: Nick Boldt <[email protected]> put back deleted content (why do people keep forgetting to put RN content in JIRA?) Signed-off-by: Nick Boldt <[email protected]> regen from jira Signed-off-by: Nick Boldt <[email protected]> regen more Signed-off-by: Nick Boldt <[email protected]> Remove empty lines Signed-off-by: Nick Boldt <[email protected]> * CVE-2024-56334 now fixed in 1.4.1 Signed-off-by: Nick Boldt <[email protected]> add CVE-2024-56334 to snip-fixed-security-issues-in-product-1.4.1.adoc Signed-off-by: Nick Boldt <[email protected]> add spaces back into the generated RN Signed-off-by: Nick Boldt <[email protected]> more fixes from JIRA updates Signed-off-by: Nick Boldt <[email protected]> * add 3 or 4 bug fixes that were previously not included in the RN because Release Note Status was not set to Done Signed-off-by: Nick Boldt <[email protected]> remove dupe RN issue (https://issues.redhat.com/browse/RHIDP-5319 is a subset of https://issues.redhat.com/browse/RHIDP-5308; some reformatting and language cleanup Signed-off-by: Nick Boldt <[email protected]> * apply Gerry's latest changes from 2 JIRAs Signed-off-by: Nick Boldt <[email protected]> --------- Signed-off-by: Nick Boldt <[email protected]>
1 parent 61ef95d commit 739dcfd

16 files changed

+304
-190
lines changed

artifacts/attributes.adoc

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,9 @@
1111
:product-short: Developer Hub
1212
:product-very-short: RHDH
1313
:product-version: 1.4
14-
:product-bundle-version: 1.4.0
15-
:product-chart-version: 1.4.0
14+
:product-version-next: 1.5.0
15+
:product-bundle-version: 1.4.1
16+
:product-chart-version: 1.4.1
1617
:product-backstage-version: 1.32.6
1718
:product-custom-resource-type: Backstage
1819
:rhdeveloper-name: Red Hat Developer

assemblies/assembly-release-notes-fixed-security-issues.adoc

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,13 @@ This section lists security issues fixed in {product} {product-version}.
66

77
== {product} {product-bundle-version}
88

9-
include::modules/release-notes/snip-fixed-security-issues-in-product-1.3.0.adoc[leveloffset=+2]
9+
include::./modules/release-notes/snip-fixed-security-issues-in-product-1.4.1.adoc[leveloffset=+2]
1010

11-
include::modules/release-notes/snip-fixed-security-issues-in-rpm-1.3.0.adoc[leveloffset=+2]
11+
// nothing yet so don't include this
12+
// include::./modules/release-notes/snip-fixed-security-issues-in-rpm-1.4.1.adoc[leveloffset=+2]
1213

14+
== {product} 1.4.0
15+
16+
include::./modules/release-notes/snip-fixed-security-issues-in-product-1.3.0.adoc[leveloffset=+2]
17+
18+
include::./modules/release-notes/snip-fixed-security-issues-in-rpm-1.3.0.adoc[leveloffset=+2]
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
CVE-2024-45338, rhdh/rhdh-rhel9-operator: Non-linear parsing of case-insensitive content in golang.org/x/net/html
2+
CVE-2024-56201, rhdh/rhdh-hub-rhel9: Jinja has a sandbox breakout through malicious filenames
3+
CVE-2024-56326, rhdh/rhdh-hub-rhel9: Jinja has a sandbox breakout through indirect reference to format method
4+
CVE-2024-55565, rhdh-hub-container: nanoid mishandles non-integer values
5+
CVE-2024-52798, rhdh-hub-container: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
6+
CVE-2024-56334, rhdh/rhdh-hub-rhel9: Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation

modules/release-notes/list-fixed-security-issues-in-rpm-1.4.1.txt

Whitespace-only changes.

modules/release-notes/ref-release-notes-breaking-changes.adoc

Lines changed: 78 additions & 71 deletions
Original file line numberDiff line numberDiff line change
@@ -13,79 +13,86 @@ Prom-client metrics have been removed and replaced with OpenTelemetry metrics. A
1313
.Additional resources
1414
* link:https://issues.redhat.com/browse/RHIDP-4572[RHIDP-4572]
1515

16-
[id="feature-rhidp-4853"]
17-
== Plugins with updated scope
18-
19-
To upgrade from {product-very-short} 1.3 to 1.4, you must update your configuration to use the latest versions of the following plugins from the new scope.
20-
21-
With this update, the following plugins, previously under the `@janus-idp` scope, have now been moved to the `@backstage-community` scope:
22-
23-
[cols=2,%header]
24-
|===
25-
| *RHDH 1.3 Plugin Name*
26-
| *RHDH 1.4 Plugin Name*
27-
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
28-
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
29-
|`@janus-idp/backstage-plugin-analytics-provider-segment`|`@backstage-community/plugin-analytics-provider-segment`
30-
|`@janus-idp/backstage-plugin-jfrog-artifactory`|`@backstage-community/plugin-jfrog-artifactory`
31-
|`@janus-idp/backstage-plugin-keycloak-backend`|`@backstage-community/plugin-catalog-backend-module-keycloak`
32-
|`@janus-idp/backstage-plugin-nexus-repository-manager`|`@backstage-community/plugin-nexus-repository-manager`
33-
|`@janus-idp/backstage-plugin-ocm`|`@backstage-community/plugin-ocm`
34-
|`@janus-idp/backstage-plugin-ocm-backend`|`@backstage-community/plugin-ocm-backend`
35-
|`@janus-idp/backstage-plugin-quay`|`@backstage-community/plugin-quay`
36-
|`@janus-idp/backstage-plugin-rbac`|`@backstage-community/plugin-rbac`
37-
|`@janus-idp/backstage-plugin-tekton`|`@backstage-community/plugin-tekton`
38-
|`@janus-idp/backstage-plugin-topology`|`@backstage-community/plugin-topology`
39-
|`@janus-idp/backstage-scaffolder-backend-module-quay`|`@backstage-community/plugin-scaffolder-backend-module-quay`
40-
|`@janus-idp/backstage-scaffolder-backend-module-regex`|`@backstage-community/plugin-scaffolder-backend-module-regex`
41-
|`@janus-idp/backstage-scaffolder-backend-module-servicenow`|`@backstage-community/plugin-scaffolder-backend-module-servicenow`
42-
|`@janus-idp/backstage-scaffolder-backend-module-sonarqube`|`@backstage-community/plugin-scaffolder-backend-module-sonarqube`
43-
|===
44-
45-
The following plugins, previously under the `@backstage` scope, have now been moved to the `@backstage-community` scope:
46-
[cols=2,%header]
47-
|===
48-
| *RHDH 1.3 Plugin Name*
49-
| *RHDH 1.4 Plugin Name*
50-
|`@backstage/plugin-azure-devops`|`@backstage-community/plugin-azure-devops`
51-
|`@backstage/plugin-azure-devops-backend`|`@backstage-community/plugin-azure-devops-backend`
52-
|`@backstage/plugin-dynatrace`|`@backstage-community/plugin-dynatrace`
53-
|`@backstage/plugin-github-actions`|`@backstage-community/plugin-github-actions`
54-
|`@backstage/plugin-github-issues`|`@backstage-community/plugin-github-issues`
55-
|`@backstage/plugin-jenkins`|`@backstage-community/plugin-jenkins`
56-
|`@backstage/plugin-jenkins-backend`|`@backstage-community/plugin-jenkins-backend`
57-
|`@backstage/plugin-lighthouse`|`@backstage-community/plugin-lighthouse`
58-
|`@backstage/plugin-sonarqube`|`@backstage-community/plugin-sonarqube`
59-
|`@backstage/plugin-sonarqube-backend`|`@backstage-community/plugin-sonarqube-backend`
60-
|`@backstage/plugin-tech-radar`|`@backstage-community/plugin-tech-radar`
61-
|===
62-
63-
Two plugins previously under the `@janus-idp` scope have moved to `@red-hat-developer-hub` scope:
64-
65-
[cols=2,%header]
66-
|===
67-
| *RHDH 1.3 Plugin Name*
68-
| *RHDH 1.4 Plugin Name*
69-
70-
| `@janus-idp/backstage-plugin-bulk-import`
71-
| `@red-hat-developer-hub/backstage-plugin-bulk-import`
16+
[id="removed-functionality-rhidp-4853"]
17+
== Plugins with updated scope
18+
19+
To upgrade from {product-very-short} 1.3 to 1.4, you must update your configuration to use the latest versions of the following plugins from the new scope.
20+
21+
With this update, the following plugins, previously under the `@janus-idp` scope, have now been moved to the `@backstage-community` scope:
22+
23+
[cols=2,%header]
24+
|===
25+
| *RHDH 1.3 Plugin Name*
26+
| *RHDH 1.4 Plugin Name*
27+
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
28+
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
29+
|`@janus-idp/backstage-plugin-analytics-provider-segment`|`@backstage-community/plugin-analytics-provider-segment`
30+
|`@janus-idp/backstage-plugin-jfrog-artifactory`|`@backstage-community/plugin-jfrog-artifactory`
31+
|`@janus-idp/backstage-plugin-keycloak-backend`|`@backstage-community/plugin-catalog-backend-module-keycloak`
32+
|`@janus-idp/backstage-plugin-nexus-repository-manager`|`@backstage-community/plugin-nexus-repository-manager`
33+
|`@janus-idp/backstage-plugin-ocm`|`@backstage-community/plugin-ocm`
34+
|`@janus-idp/backstage-plugin-ocm-backend`|`@backstage-community/plugin-ocm-backend`
35+
|`@janus-idp/backstage-plugin-quay`|`@backstage-community/plugin-quay`
36+
|`@janus-idp/backstage-plugin-rbac`|`@backstage-community/plugin-rbac`
37+
|`@janus-idp/backstage-plugin-tekton`|`@backstage-community/plugin-tekton`
38+
|`@janus-idp/backstage-plugin-topology`|`@backstage-community/plugin-topology`
39+
|`@janus-idp/backstage-scaffolder-backend-module-quay`|`@backstage-community/plugin-scaffolder-backend-module-quay`
40+
|`@janus-idp/backstage-scaffolder-backend-module-regex`|`@backstage-community/plugin-scaffolder-backend-module-regex`
41+
|`@janus-idp/backstage-scaffolder-backend-module-servicenow`|`@backstage-community/plugin-scaffolder-backend-module-servicenow`
42+
|`@janus-idp/backstage-scaffolder-backend-module-sonarqube`|`@backstage-community/plugin-scaffolder-backend-module-sonarqube`
43+
|===
44+
45+
The following plugins, previously under the `@backstage` scope, have now been moved to the `@backstage-community` scope:
46+
[cols=2,%header]
47+
|===
48+
| *RHDH 1.3 Plugin Name*
49+
| *RHDH 1.4 Plugin Name*
50+
|`@backstage/plugin-azure-devops`|`@backstage-community/plugin-azure-devops`
51+
|`@backstage/plugin-azure-devops-backend`|`@backstage-community/plugin-azure-devops-backend`
52+
|`@backstage/plugin-dynatrace`|`@backstage-community/plugin-dynatrace`
53+
|`@backstage/plugin-github-actions`|`@backstage-community/plugin-github-actions`
54+
|`@backstage/plugin-github-issues`|`@backstage-community/plugin-github-issues`
55+
|`@backstage/plugin-jenkins`|`@backstage-community/plugin-jenkins`
56+
|`@backstage/plugin-jenkins-backend`|`@backstage-community/plugin-jenkins-backend`
57+
|`@backstage/plugin-lighthouse`|`@backstage-community/plugin-lighthouse`
58+
|`@backstage/plugin-sonarqube`|`@backstage-community/plugin-sonarqube`
59+
|`@backstage/plugin-sonarqube-backend`|`@backstage-community/plugin-sonarqube-backend`
60+
|`@backstage/plugin-tech-radar`|`@backstage-community/plugin-tech-radar`
61+
|===
62+
63+
Two plugins previously under the `@janus-idp` scope have moved to `@red-hat-developer-hub` scope:
64+
65+
[cols=2,%header]
66+
|===
67+
| *RHDH 1.3 Plugin Name*
68+
| *RHDH 1.4 Plugin Name*
69+
70+
| `@janus-idp/backstage-plugin-bulk-import`
71+
| `@red-hat-developer-hub/backstage-plugin-bulk-import`
72+
73+
| `@janus-idp/backstage-plugin-bulk-import-backend`
74+
| `@red-hat-developer-hub/backstage-plugin-bulk-import-backend`
75+
|===
76+
77+
With the update to the plugin scope, the dynamic plugin configuration has also been modified.
78+
79+
[cols=2,%header]
80+
|===
81+
|*RHDH 1.3 Configuration*|*RHDH 1.4 Configuration*
82+
|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.3/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.4/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]
83+
|===
84+
85+
.Procedure
86+
* To upgrade from {product-very-short} 1.3 to {product-very-short} 1.4, you must update your configuration to use the latest versions of the plugins listed previously from the new scope.
87+
88+
[NOTE]
89+
====
90+
In addition to the previously provided tables, you can compare the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.4/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.4 CSV file] with the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.3/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.3 CSV file] to identify the changes in dynamic plugins.
91+
====
7292

73-
| `@janus-idp/backstage-plugin-bulk-import-backend`
74-
| `@red-hat-developer-hub/backstage-plugin-bulk-import-backend`
75-
|===
7693

77-
With the update to the plugin scope, the dynamic plugin configuration has also been modified.
94+
.Additional resources
95+
* link:https://issues.redhat.com/browse/RHIDP-4853[RHIDP-4853]
7896

79-
[cols=2,%header]
80-
|===
81-
|*RHDH 1.3 Configuration*|*RHDH 1.4 Configuration*
82-
|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.3/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.4/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]
83-
|===
8497

85-
.Procedure
86-
* To upgrade from {product-very-short} 1.3 to {product-very-short} 1.4, you must update your configuration to use the latest versions of the plugins listed previously from the new scope.
8798

88-
[NOTE]
89-
====
90-
In addition to the previously provided tables, you can compare the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.4/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.4 CSV file] with the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.3/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.3 CSV file] to identify the changes in dynamic plugins.
91-
====

modules/release-notes/ref-release-notes-deprecated-functionalities.adoc

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ The `./dynamic-plugins/dist/janus-idp-backstage-plugin-aap-backend-dynamic` plug
1616
[id="deprecated-functionality-rhidp-4913"]
1717
== Audit log rotation is deprecated
1818

19-
With this update, you can evaluate your platform's log forwarding solutions to align with your security and compliance needs. Most of these solutions offer configurable options to minimize the loss of logs in the event of an outage.
19+
With this update, you can evaluate your platform&#39;s log forwarding solutions to align with your security and compliance needs. Most of these solutions offer configurable options to minimize the loss of logs in the event of an outage.
2020

2121

2222
.Additional resources
@@ -29,4 +29,7 @@ With this update, you can evaluate your platform's log forwarding solutions to a
2929

3030

3131
.Additional resources
32-
* link:https://issues.redhat.com/browse/RHIDP-5218[RHIDP-5218]
32+
* link:https://issues.redhat.com/browse/RHIDP-5218[RHIDP-5218]
33+
34+
35+

0 commit comments

Comments
 (0)