Conversation
Signed-off-by: Gaurav Mishra <mishra.gaurav@siemens.com>
|
Hey @GMishx @KoukiHama, did a quick pass through the codebase looking for regressions before this ships. The one blocker I found; Two things worth noting though: anyone who ran release merges on rc-2 with packages attached probably has dirty data in CouchDB and should reconcile before upgrading. And the Good work everyone, nice to see the security patches land 🙌 |
|
Nice observation Aman. However, no one has updated their SW360 since the last 18 release, so can be safe in assuming no harm. |
|
Hey @GMishx! I don’t have full clarity on the intended design here, so please treat the below as a guess. If I’m off base, I’d appreciate a correction. I’m mainly trying to get this straight. One thing stood out: GET Why it might matters: anyone who can hit that URL (for example an internet-facing deployment, mis-routed traffic, a compromised client on the VPN, or another issue that exposes the link) might be able to pull files the JVM can read, such as configs or secrets. Please check if this is of any real concern. Thanks! |
Changelog in preparation for Release 20.0.0 of backend.
This PR is in preparation for the release 20.0.0
This PR also serves as an intimation of merge freeze and a request for testing for finding new bugs.
If until 27/03/2026, there are no comments on this PR, will proceed with the release.
Thank you everyone involved for their hard work and make this release possible!