Skip to content

Commit d517ccd

Browse files
committed
chore: release notes for 1.4.1 (removing content from 1.3.0 too)
Signed-off-by: Nick Boldt <[email protected]> fix queries Signed-off-by: Nick Boldt <[email protected]> put content in JIRA instead of overriding content after generation Signed-off-by: Nick Boldt <[email protected]> put back deleted content (why do people keep forgetting to put RN content in JIRA?) Signed-off-by: Nick Boldt <[email protected]> regen from jira Signed-off-by: Nick Boldt <[email protected]> regen more Signed-off-by: Nick Boldt <[email protected]> Remove empty lines Signed-off-by: Nick Boldt <[email protected]>
1 parent 175fe06 commit d517ccd

16 files changed

+247
-265
lines changed

artifacts/attributes.adoc

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,9 @@
1111
:product-short: Developer Hub
1212
:product-very-short: RHDH
1313
:product-version: 1.4
14-
:product-bundle-version: 1.4.0
15-
:product-chart-version: 1.4.0
14+
:product-version-next: 1.5.0
15+
:product-bundle-version: 1.4.1
16+
:product-chart-version: 1.4.1
1617
:product-backstage-version: 1.32.6
1718
:product-custom-resource-type: Backstage
1819
:rhdeveloper-name: Red Hat Developer

assemblies/assembly-release-notes-fixed-security-issues.adoc

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,13 @@ This section lists security issues fixed in {product} {product-version}.
66

77
== {product} {product-bundle-version}
88

9-
include::modules/release-notes/snip-fixed-security-issues-in-product-1.3.0.adoc[leveloffset=+2]
9+
include::./modules/release-notes/snip-fixed-security-issues-in-product-1.4.1.adoc[leveloffset=+2]
1010

11-
include::modules/release-notes/snip-fixed-security-issues-in-rpm-1.3.0.adoc[leveloffset=+2]
11+
// nothing yet so don't include this
12+
// include::./modules/release-notes/snip-fixed-security-issues-in-rpm-1.4.1.adoc[leveloffset=+2]
1213

14+
== {product} 1.4.0
15+
16+
include::./modules/release-notes/snip-fixed-security-issues-in-product-1.3.0.adoc[leveloffset=+2]
17+
18+
include::./modules/release-notes/snip-fixed-security-issues-in-rpm-1.3.0.adoc[leveloffset=+2]
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
CVE-2024-45338, rhdh/rhdh-rhel9-operator: Non-linear parsing of case-insensitive content in golang.org/x/net/html
2+
CVE-2024-56201, rhdh/rhdh-hub-rhel9: Jinja has a sandbox breakout through malicious filenames
3+
CVE-2024-56326, rhdh/rhdh-hub-rhel9: Jinja has a sandbox breakout through indirect reference to format method
4+
CVE-2024-55565, rhdh-hub-container: nanoid mishandles non-integer values
5+
CVE-2024-52798, rhdh-hub-container: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
6+
7+
# not yet fixed for 1.4.z
8+
# CVE-2024-56334, rhdh/rhdh-hub-rhel9: Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation

modules/release-notes/list-fixed-security-issues-in-rpm-1.4.1.txt

Whitespace-only changes.

modules/release-notes/ref-release-notes-breaking-changes.adoc

Lines changed: 78 additions & 78 deletions
Original file line numberDiff line numberDiff line change
@@ -8,84 +8,84 @@ This section lists breaking changes in {product} {product-version}.
88
== Updated monitoring and logging metrics
99

1010
Prom-client metrics have been removed and replaced with OpenTelemetry metrics. As a result, the metrics port has changed from `7007` to `9464`. Deprecated metrics have also been removed. If you had dependencies on these, ensure your prometheus queries are updated. For further information, see link:https://docs.redhat.com/en/documentation/red_hat_developer_hub/1.3/html-single/monitoring_and_logging/index#assembly-rhdh-observability[Monitoring and logging]
11-
12-
1311
.Additional resources
1412
* link:https://issues.redhat.com/browse/RHIDP-4572[RHIDP-4572]
15-
16-
[id="feature-rhidp-4853"]
17-
== Plugins with updated scope
18-
19-
To upgrade from {product-very-short} 1.3 to 1.4, you must update your configuration to use the latest versions of the following plugins from the new scope.
20-
21-
With this update, the following plugins, previously under the `@janus-idp` scope, have now been moved to the `@backstage-community` scope:
22-
23-
[cols=2,%header]
24-
|===
25-
| *RHDH 1.3 Plugin Name*
26-
| *RHDH 1.4 Plugin Name*
27-
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
28-
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
29-
|`@janus-idp/backstage-plugin-analytics-provider-segment`|`@backstage-community/plugin-analytics-provider-segment`
30-
|`@janus-idp/backstage-plugin-jfrog-artifactory`|`@backstage-community/plugin-jfrog-artifactory`
31-
|`@janus-idp/backstage-plugin-keycloak-backend`|`@backstage-community/plugin-catalog-backend-module-keycloak`
32-
|`@janus-idp/backstage-plugin-nexus-repository-manager`|`@backstage-community/plugin-nexus-repository-manager`
33-
|`@janus-idp/backstage-plugin-ocm`|`@backstage-community/plugin-ocm`
34-
|`@janus-idp/backstage-plugin-ocm-backend`|`@backstage-community/plugin-ocm-backend`
35-
|`@janus-idp/backstage-plugin-quay`|`@backstage-community/plugin-quay`
36-
|`@janus-idp/backstage-plugin-rbac`|`@backstage-community/plugin-rbac`
37-
|`@janus-idp/backstage-plugin-tekton`|`@backstage-community/plugin-tekton`
38-
|`@janus-idp/backstage-plugin-topology`|`@backstage-community/plugin-topology`
39-
|`@janus-idp/backstage-scaffolder-backend-module-quay`|`@backstage-community/plugin-scaffolder-backend-module-quay`
40-
|`@janus-idp/backstage-scaffolder-backend-module-regex`|`@backstage-community/plugin-scaffolder-backend-module-regex`
41-
|`@janus-idp/backstage-scaffolder-backend-module-servicenow`|`@backstage-community/plugin-scaffolder-backend-module-servicenow`
42-
|`@janus-idp/backstage-scaffolder-backend-module-sonarqube`|`@backstage-community/plugin-scaffolder-backend-module-sonarqube`
43-
|===
44-
45-
The following plugins, previously under the `@backstage` scope, have now been moved to the `@backstage-community` scope:
46-
[cols=2,%header]
47-
|===
48-
| *RHDH 1.3 Plugin Name*
49-
| *RHDH 1.4 Plugin Name*
50-
|`@backstage/plugin-azure-devops`|`@backstage-community/plugin-azure-devops`
51-
|`@backstage/plugin-azure-devops-backend`|`@backstage-community/plugin-azure-devops-backend`
52-
|`@backstage/plugin-dynatrace`|`@backstage-community/plugin-dynatrace`
53-
|`@backstage/plugin-github-actions`|`@backstage-community/plugin-github-actions`
54-
|`@backstage/plugin-github-issues`|`@backstage-community/plugin-github-issues`
55-
|`@backstage/plugin-jenkins`|`@backstage-community/plugin-jenkins`
56-
|`@backstage/plugin-jenkins-backend`|`@backstage-community/plugin-jenkins-backend`
57-
|`@backstage/plugin-lighthouse`|`@backstage-community/plugin-lighthouse`
58-
|`@backstage/plugin-sonarqube`|`@backstage-community/plugin-sonarqube`
59-
|`@backstage/plugin-sonarqube-backend`|`@backstage-community/plugin-sonarqube-backend`
60-
|`@backstage/plugin-tech-radar`|`@backstage-community/plugin-tech-radar`
61-
|===
62-
63-
Two plugins previously under the `@janus-idp` scope have moved to `@red-hat-developer-hub` scope:
64-
65-
[cols=2,%header]
66-
|===
67-
| *RHDH 1.3 Plugin Name*
68-
| *RHDH 1.4 Plugin Name*
69-
70-
| `@janus-idp/backstage-plugin-bulk-import`
71-
| `@red-hat-developer-hub/backstage-plugin-bulk-import`
72-
73-
| `@janus-idp/backstage-plugin-bulk-import-backend`
74-
| `@red-hat-developer-hub/backstage-plugin-bulk-import-backend`
75-
|===
76-
77-
With the update to the plugin scope, the dynamic plugin configuration has also been modified.
78-
79-
[cols=2,%header]
80-
|===
81-
|*RHDH 1.3 Configuration*|*RHDH 1.4 Configuration*
82-
|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.3/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.4/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]
83-
|===
84-
85-
.Procedure
86-
* To upgrade from {product-very-short} 1.3 to {product-very-short} 1.4, you must update your configuration to use the latest versions of the plugins listed previously from the new scope.
87-
88-
[NOTE]
89-
====
90-
In addition to the previously provided tables, you can compare the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.4/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.4 CSV file] with the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.3/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.3 CSV file] to identify the changes in dynamic plugins.
13+
[id="removed-functionality-rhidp-4853"]
14+
== Plugins with updated scope
15+
16+
To upgrade from {product-very-short} 1.3 to 1.4, you must update your configuration to use the latest versions of the following plugins from the new scope.
17+
18+
With this update, the following plugins, previously under the `@janus-idp` scope, have now been moved to the `@backstage-community` scope:
19+
20+
[cols=2,%header]
21+
|===
22+
| *RHDH 1.3 Plugin Name*
23+
| *RHDH 1.4 Plugin Name*
24+
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
25+
|`@janus-idp/backstage-plugin-acr`|`@backstage-community/plugin-acr`
26+
|`@janus-idp/backstage-plugin-analytics-provider-segment`|`@backstage-community/plugin-analytics-provider-segment`
27+
|`@janus-idp/backstage-plugin-jfrog-artifactory`|`@backstage-community/plugin-jfrog-artifactory`
28+
|`@janus-idp/backstage-plugin-keycloak-backend`|`@backstage-community/plugin-catalog-backend-module-keycloak`
29+
|`@janus-idp/backstage-plugin-nexus-repository-manager`|`@backstage-community/plugin-nexus-repository-manager`
30+
|`@janus-idp/backstage-plugin-ocm`|`@backstage-community/plugin-ocm`
31+
|`@janus-idp/backstage-plugin-ocm-backend`|`@backstage-community/plugin-ocm-backend`
32+
|`@janus-idp/backstage-plugin-quay`|`@backstage-community/plugin-quay`
33+
|`@janus-idp/backstage-plugin-rbac`|`@backstage-community/plugin-rbac`
34+
|`@janus-idp/backstage-plugin-tekton`|`@backstage-community/plugin-tekton`
35+
|`@janus-idp/backstage-plugin-topology`|`@backstage-community/plugin-topology`
36+
|`@janus-idp/backstage-scaffolder-backend-module-quay`|`@backstage-community/plugin-scaffolder-backend-module-quay`
37+
|`@janus-idp/backstage-scaffolder-backend-module-regex`|`@backstage-community/plugin-scaffolder-backend-module-regex`
38+
|`@janus-idp/backstage-scaffolder-backend-module-servicenow`|`@backstage-community/plugin-scaffolder-backend-module-servicenow`
39+
|`@janus-idp/backstage-scaffolder-backend-module-sonarqube`|`@backstage-community/plugin-scaffolder-backend-module-sonarqube`
40+
|===
41+
42+
The following plugins, previously under the `@backstage` scope, have now been moved to the `@backstage-community` scope:
43+
[cols=2,%header]
44+
|===
45+
| *RHDH 1.3 Plugin Name*
46+
| *RHDH 1.4 Plugin Name*
47+
|`@backstage/plugin-azure-devops`|`@backstage-community/plugin-azure-devops`
48+
|`@backstage/plugin-azure-devops-backend`|`@backstage-community/plugin-azure-devops-backend`
49+
|`@backstage/plugin-dynatrace`|`@backstage-community/plugin-dynatrace`
50+
|`@backstage/plugin-github-actions`|`@backstage-community/plugin-github-actions`
51+
|`@backstage/plugin-github-issues`|`@backstage-community/plugin-github-issues`
52+
|`@backstage/plugin-jenkins`|`@backstage-community/plugin-jenkins`
53+
|`@backstage/plugin-jenkins-backend`|`@backstage-community/plugin-jenkins-backend`
54+
|`@backstage/plugin-lighthouse`|`@backstage-community/plugin-lighthouse`
55+
|`@backstage/plugin-sonarqube`|`@backstage-community/plugin-sonarqube`
56+
|`@backstage/plugin-sonarqube-backend`|`@backstage-community/plugin-sonarqube-backend`
57+
|`@backstage/plugin-tech-radar`|`@backstage-community/plugin-tech-radar`
58+
|===
59+
60+
Two plugins previously under the `@janus-idp` scope have moved to `@red-hat-developer-hub` scope:
61+
62+
[cols=2,%header]
63+
|===
64+
| *RHDH 1.3 Plugin Name*
65+
| *RHDH 1.4 Plugin Name*
66+
67+
| `@janus-idp/backstage-plugin-bulk-import`
68+
| `@red-hat-developer-hub/backstage-plugin-bulk-import`
69+
70+
| `@janus-idp/backstage-plugin-bulk-import-backend`
71+
| `@red-hat-developer-hub/backstage-plugin-bulk-import-backend`
72+
|===
73+
74+
With the update to the plugin scope, the dynamic plugin configuration has also been modified.
75+
76+
[cols=2,%header]
77+
|===
78+
|*RHDH 1.3 Configuration*|*RHDH 1.4 Configuration*
79+
|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.3/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]|link:https://github.com/janus-idp/backstage-showcase/blob/release-1.4/dynamic-plugins.default.yaml[dynamic-plugins.default.yaml]
80+
|===
81+
82+
.Procedure
83+
* To upgrade from {product-very-short} 1.3 to {product-very-short} 1.4, you must update your configuration to use the latest versions of the plugins listed previously from the new scope.
84+
85+
[NOTE]
86+
====
87+
In addition to the previously provided tables, you can compare the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.4/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.4 CSV file] with the link:https://github.com/redhat-developer/red-hat-developers-documentation-rhdh/blob/release-1.3/modules/dynamic-plugins/rhdh-supported-plugins.csv[RHDH 1.3 CSV file] to identify the changes in dynamic plugins.
9188
====
89+
.Additional resources
90+
* link:https://issues.redhat.com/browse/RHIDP-4853[RHIDP-4853]
91+

modules/release-notes/ref-release-notes-deprecated-functionalities.adoc

Lines changed: 3 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -8,25 +8,18 @@ This section lists deprecated functionalities in {product} {product-version}.
88
== `./dynamic-plugins/dist/janus-idp-backstage-plugin-aap-backend-dynamic` plugin is deprecated
99

1010
The `./dynamic-plugins/dist/janus-idp-backstage-plugin-aap-backend-dynamic` plugin has been deprecated and will be removed in the next release. You can link:https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html-single/using_ansible_plug-ins_for_red_hat_developer_hub/index[use Ansible plug-ins for {product-very-short}] instead.
11-
12-
1311
.Additional resources
1412
* link:https://issues.redhat.com/browse/RHIDP-3545[RHIDP-3545]
15-
1613
[id="deprecated-functionality-rhidp-4913"]
1714
== Audit log rotation is deprecated
1815

19-
With this update, you can evaluate your platform's log forwarding solutions to align with your security and compliance needs. Most of these solutions offer configurable options to minimize the loss of logs in the event of an outage.
20-
21-
16+
With this update, you can evaluate your platform&#39;s log forwarding solutions to align with your security and compliance needs. Most of these solutions offer configurable options to minimize the loss of logs in the event of an outage.
2217
.Additional resources
2318
* link:https://issues.redhat.com/browse/RHIDP-4913[RHIDP-4913]
24-
2519
[id="deprecated-functionality-rhidp-5218"]
2620
== {rhsso-brand-name} `7.6` is deprecated as an authentication provider
2721

2822
{rhsso-brand-name} ({rhsso}) `7.6` is deprecated as an authentication provider. You can continue to use {rhsso} until the end of maintenance support. For details, see link:https://access.redhat.com/support/policy/updates/jboss_notes/#p_sso[RHSSO lifecycle dates]. As an alternative, migrate to {rhbk-brand-name} `v24`.
29-
30-
3123
.Additional resources
32-
* link:https://issues.redhat.com/browse/RHIDP-5218[RHIDP-5218]
24+
* link:https://issues.redhat.com/browse/RHIDP-5218[RHIDP-5218]
25+

0 commit comments

Comments
 (0)