News

Redmine 4.0.4 and 3.4.11 released (incl. security fix) (5 comments)

Added by Jean-Philippe Lang 3 months ago

These 2 maintenance releases are available for download, you can review the changes in the Changelog.

Security: these 2 release include a fix for a persistent XSS vulnerability found in the Redmine Textile formatter. This issue was discovered and reported to the security team by Глеб Будило and fixed by Holger Just on behalf on Planio. People who uses Textile formatting should upgrade as soon as possible. Those who use Markdown or no text formatting are not vulnerable.

Redmine 4.0.3 and 3.4.10 released (5 comments)

Added by Jean-Philippe Lang 6 months ago

These 2 maintenance releases are available for download, you can review the changes in the Changelog.

Security: several vulnerabilities have been discovered in Ruby on Rails 4 and 5 (see announcement). These 2 releases include an update to the latest Ruby on Rails versions 5.2.2.1 (for Redmine 4.0.3) and Rails 4.2.11.1 (for Redmine 3.4.10) which fix these security issues. Upgrading is highly recommended.

Redmine 4.0.2 and 3.4.9 released (4 comments)

Added by Jean-Philippe Lang 7 months ago

These 2 maintenance releases are available for download, you can review the changes in the Changelog.
Thanks to the contributors for their submissions!

Redmine 4.0.1 and 3.4.8 released (6 comments)

Added by Jean-Philippe Lang 8 months ago

These maintenance releases are available for download.
You can review the changes in the Changelog.

Happy New Year 2019!

Redmine 4.0.0, 3.4.7 and 3.3.9 released (18 comments)

Added by Jean-Philippe Lang 10 months ago

Thanks to the many people who contributed to Redmine since last year, I'm glad to announce that Redmine 4.0.0 is now available for download. It brings more than 200 changes including:
  • a major change to email notifications: each user now receives its own notification email whereas previous versions were sending a single email to all the notified users
  • many improvements to text formatting
  • the replacement of Coderay by Rouge to support more languages for code highlighting

Email delivery now relies on Rails ActiveJob. Emails are sent asynchronously by default. But you should consider configuring a persistent backend for ActiveJob since the default uses an in-memory queue that is not well suited for production environnements:
https://guides.rubyonrails.org/v5.2/active_job_basics.html#job-execution

Redmine 4.0.0 uses Rails 5.2.2, the latest Rails version released a few days ago.

Redmine 3.4.7 and 3.3.9 are maintenance releases for 3.4.x and 3.3.x users. You can review the details in the Changelog. They both include an upgrade to Rails 4.2.11 that fixed 2 Rails vulnerabilities. Although these vulnerabilities does not affect Redmine 3.x, you should upgrade if possible.

Redmine 3.4.6 and 3.3.8 released (1 comment)

Added by Jean-Philippe Lang over 1 year ago

These maintenance releases are available for download.
They include several fixes that you can review the changes in the Changelog.

Redmine 3.4.5 and 3.3.7 released (2 comments)

Added by Jean-Philippe Lang over 1 year ago

These maintenance releases are available for download.
You can review the changes in the Changelog.

Thanks to all the contributors who worked on these releases!

Redmine 3.4.4, 3.3.6 and 3.2.9 released (5 comments)

Added by Jean-Philippe Lang over 1 year ago

The first maintenance releases for 2018 are available for download, happy new year!
You can review the changes in the Changelog.

Security: All of these releases include a fix for a remote command execution vulnerability in the Mercurial adapter. Thanks to Yuya Nishihara who reported this issue to the Redmine team. If you are using Mercurial repositories with Redmine, you should update to one of these releases as soon as possible.

Redmine 3.4.3, 3.3.5 and 3.2.8 released (2 comments)

Added by Jean-Philippe Lang almost 2 years ago

These 3 new maintenance release are available for download.
You can review the changes in the Changelog.

Security: All of these releases include a fix for multiple XSS vulnerabilities. Thanks to Andi Fink and Holger Just who reported them to the Redmine team.

Redmine 3.4.2 released

Added by Jean-Philippe Lang about 2 years ago

This maintenance release addresses a few more issues that were found in the latest Redmine 3.4.x releases.
Thanks to the contributors who reported these defects to the Redmine dev team.

1 2 3 ... 13 (1-10/123)

Also available in: Atom