Commit Graph
5436 Commits
Author SHA1 Message Date
semantic-release-bot e573cfa43d chore(release): 9.7.0-alpha.16 [skip ci]
# [9.7.0-alpha.16](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.15...9.7.0-alpha.16) (2026-03-29)

### Bug Fixes

* LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) ([#10350](https://github.com/parse-community/parse-server/issues/10350)) ([f63fd1a](https://github.com/parse-community/parse-server/commit/f63fd1a3fe0a7c1c5fe809f01b0e04759e8c9b98))
9.7.0-alpha.16
2026-03-29 18:37:39 +00:00
Manuel f63fd1a3fe fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10350) 2026-03-29 19:36:52 +01:00
semantic-release-bot f897d83e2e chore(release): 9.7.0-alpha.15 [skip ci]
# [9.7.0-alpha.15](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.14...9.7.0-alpha.15) (2026-03-29)

### Bug Fixes

* Batch login sub-request rate limit uses IP-based keying ([#10349](https://github.com/parse-community/parse-server/issues/10349)) ([63c37c4](https://github.com/parse-community/parse-server/commit/63c37c49c7a72dc617635da8859004503021b8fd))
9.7.0-alpha.15
2026-03-29 15:09:33 +00:00
Manuel 63c37c49c7 fix: Batch login sub-request rate limit uses IP-based keying (#10349) 2026-03-29 16:08:36 +01:00
semantic-release-bot 12d6fae848 chore(release): 9.7.0-alpha.14 [skip ci]
# [9.7.0-alpha.14](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.13...9.7.0-alpha.14) (2026-03-29)

### Bug Fixes

* Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) ([#10347](https://github.com/parse-community/parse-server/issues/10347)) ([9080296](https://github.com/parse-community/parse-server/commit/90802969fc713b7bc9733d7255c7519a6ed75d21))
9.7.0-alpha.14
2026-03-29 03:56:56 +00:00
Manuel 90802969fc fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10347) 2026-03-29 04:55:39 +01:00
semantic-release-bot 1d5dd64419 chore(release): 9.7.0-alpha.13 [skip ci]
# [9.7.0-alpha.13](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.12...9.7.0-alpha.13) (2026-03-29)

### Features

* Add support for `partialFilterExpression` in MongoDB storage adapter ([#10346](https://github.com/parse-community/parse-server/issues/10346)) ([8dd7bf2](https://github.com/parse-community/parse-server/commit/8dd7bf2f61c07b0467d6dbc7aad5142db6694339))
9.7.0-alpha.13
2026-03-29 02:38:08 +00:00
Manuel 8dd7bf2f61 feat: Add support for partialFilterExpression in MongoDB storage adapter (#10346) 2026-03-29 03:37:19 +01:00
semantic-release-bot e71e0301df chore(release): 9.7.0-alpha.12 [skip ci]
# [9.7.0-alpha.12](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.11...9.7.0-alpha.12) (2026-03-29)

### Bug Fixes

* GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) ([#10344](https://github.com/parse-community/parse-server/issues/10344)) ([f759bda](https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b))
9.7.0-alpha.12
2026-03-29 01:33:26 +00:00
Manuel f759bda075 fix: GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) (#10344) 2026-03-29 02:32:35 +01:00
semantic-release-bot 458b718cb8 chore(release): 9.7.0-alpha.11 [skip ci]
# [9.7.0-alpha.11](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.10...9.7.0-alpha.11) (2026-03-28)

### Bug Fixes

* Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) ([#10342](https://github.com/parse-community/parse-server/issues/10342)) ([dc59e27](https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674))
9.7.0-alpha.11
2026-03-28 18:48:17 +00:00
Manuel dc59e27266 fix: Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) (#10342) 2026-03-28 18:46:42 +00:00
Manuel 9c83e1a504 refactor: Bump path-to-regexp from 8.3.0 to 8.4.0 (#10340) 2026-03-28 16:39:54 +00:00
Manuel 705855cfa4 refactor: Bump jasmine from 5.7.1 to 6.1.0 (#10338) 2026-03-28 16:10:57 +00:00
dependabot[bot] faec9235eb refactor: Bump picomatch from 2.3.1 to 2.3.2 (#10318) 2026-03-27 20:59:21 +00:00
Manuel 97921cbc5c refactor: Bump @semantic-release/github from 12.0.0 to 12.0.6 (#10337) 2026-03-27 20:03:29 +00:00
dependabot[bot] d1f343cc9c refactor: Bump handlebars from 4.7.8 to 4.7.9 (#10328) 2026-03-27 19:22:59 +00:00
Manuel c717cc8667 refactor: Bump @apollo/server from 5.4.0 to 5.5.0 (#10336) 2026-03-27 18:03:06 +00:00
semantic-release-bot e34caf8123 chore(release): 9.7.0-alpha.10 [skip ci]
# [9.7.0-alpha.10](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.9...9.7.0-alpha.10) (2026-03-27)

### Bug Fixes

* GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) ([#10334](https://github.com/parse-community/parse-server/issues/10334)) ([4dd0d3d](https://github.com/parse-community/parse-server/commit/4dd0d3d8be1c39664c74ad10bb0abaa76bc41203))
9.7.0-alpha.10
2026-03-27 15:04:22 +00:00
Manuel 4dd0d3d8be fix: GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) (#10334) 2026-03-27 15:03:33 +00:00
semantic-release-bot 5bb8edeb83 chore(release): 9.7.0-alpha.9 [skip ci]
# [9.7.0-alpha.9](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.8...9.7.0-alpha.9) (2026-03-27)

### Bug Fixes

* LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) ([#10330](https://github.com/parse-community/parse-server/issues/10330)) ([776c71c](https://github.com/parse-community/parse-server/commit/776c71c3078e77d38c94937f463741793609d055))
9.7.0-alpha.9
2026-03-27 13:44:49 +00:00
Manuel 776c71c307 fix: LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) (#10330) 2026-03-27 13:44:00 +00:00
semantic-release-bot aee2146e7e chore(release): 9.7.0-alpha.8 [skip ci]
# [9.7.0-alpha.8](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.7...9.7.0-alpha.8) (2026-03-26)

### Bug Fixes

* MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) ([#10326](https://github.com/parse-community/parse-server/issues/10326)) ([e7efbeb](https://github.com/parse-community/parse-server/commit/e7efbebba398ce6abe5b6b6fb9829c6ebe310fbf))
9.7.0-alpha.8
2026-03-26 23:38:16 +00:00
Manuel e7efbebba3 fix: MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) (#10326) 2026-03-26 23:37:10 +00:00
Manuel 2be73d9d7b ci: Increase npm network timeout for Docker arm64 builds (#10325) 2026-03-26 21:04:27 +00:00
semantic-release-bot 7fec0d0733 chore(release): 9.7.0-alpha.7 [skip ci]
# [9.7.0-alpha.7](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.6...9.7.0-alpha.7) (2026-03-26)

### Bug Fixes

* Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) ([#10323](https://github.com/parse-community/parse-server/issues/10323)) ([770be86](https://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed))
9.7.0-alpha.7
2026-03-26 20:37:08 +00:00
Manuel 770be86474 fix: Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) (#10323) 2026-03-26 20:35:44 +00:00
Manuel f537e677f0 test: Fix flaky tests (#10320) 2026-03-26 02:20:57 +00:00
semantic-release-bot 7a1b11b0fc chore(release): 9.7.0-alpha.6 [skip ci]
# [9.7.0-alpha.6](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.5...9.7.0-alpha.6) (2026-03-26)

### Bug Fixes

* Duplicate session destruction can cause unhandled promise rejection ([#10319](https://github.com/parse-community/parse-server/issues/10319)) ([92791c1](https://github.com/parse-community/parse-server/commit/92791c1d1d4b042a0e615ba45dcef491b904eccf))
9.7.0-alpha.6
2026-03-26 01:42:30 +00:00
Manuel 92791c1d1d fix: Duplicate session destruction can cause unhandled promise rejection (#10319) 2026-03-26 01:41:45 +00:00
Manuel eea27af3b1 ci: Remove feature to retry flaky tests (#10314) 2026-03-26 00:30:55 +00:00
Manuel 3ff818034a refactor: Bump redis from 5.10.0 to 5.11.0 (#10317) 2026-03-25 23:56:19 +00:00
Manuel af23b92a34 refactor: Bump graphql from 16.11.0 to 16.13.2 (#10315) 2026-03-25 22:18:51 +00:00
Manuel cfbe7a04cc test: Fix flaky tests (#10313) 2026-03-25 19:20:55 +00:00
semantic-release-bot f77a51e38d chore(release): 9.7.0-alpha.5 [skip ci]
# [9.7.0-alpha.5](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.4...9.7.0-alpha.5) (2026-03-25)

### Bug Fixes

* Postgres query on non-existent column throws internal server error ([#10308](https://github.com/parse-community/parse-server/issues/10308)) ([c5c4325](https://github.com/parse-community/parse-server/commit/c5c43259d1f98af5bbbbc44d9daf7c0f1f8168d3))
9.7.0-alpha.5
2026-03-25 00:07:59 +00:00
Manuel c5c43259d1 fix: Postgres query on non-existent column throws internal server error (#10308) 2026-03-25 00:07:06 +00:00
Manuel 3f888b1aac refactor: Bump follow-redirects from 1.15.9 to 1.15.11 (#10307) 2026-03-24 20:10:01 +00:00
Manuel 1bacddb1e4 refactor: Bump ws from 8.18.2 to 8.20.0 (#10306) 2026-03-24 19:48:06 +00:00
Manuel 0f3717d4ee refactor: Bump lru-cache from 11.2.6 to 11.2.7 (#10305) 2026-03-24 18:58:53 +00:00
semantic-release-bot 52fb3cc66d chore(release): 9.7.0-alpha.4 [skip ci]
# [9.7.0-alpha.4](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.3...9.7.0-alpha.4) (2026-03-24)

### Bug Fixes

* Missing error messages in Parse errors ([#10304](https://github.com/parse-community/parse-server/issues/10304)) ([f128048](https://github.com/parse-community/parse-server/commit/f12804800bc9232de02b4314e886bab6b169f041))
9.7.0-alpha.4
2026-03-24 18:57:23 +00:00
Manuel f12804800b fix: Missing error messages in Parse errors (#10304) 2026-03-24 18:56:25 +00:00
Manuel fe9fba61dd test: Fix flaky test (#10303) 2026-03-24 15:52:45 +00:00
Manuel 6fcbb173d2 refactor: Bump lru-cache from 10.4.0 to 11.2.6 (#10302) 2026-03-24 15:41:17 +00:00
Manuel 9ec6f283a5 refactor: Bump semantic-release from 24.2.5 to 25.0.3 (#10297) 2026-03-24 03:01:04 +00:00
Manuel 1622f6af1c refactor: Bump lint-staged from 16.1.0 to 16.2.7 (#10296) 2026-03-24 02:04:23 +00:00
dependabot[bot] cb78133590 refactor: Bump bn.js from 4.12.0 to 4.12.3 (#10074) 2026-03-24 01:37:43 +00:00
Manuel b344927b89 ci: Fix flaky GC tests (#10294) 2026-03-24 00:15:30 +00:00
Manuel c77330d5a7 refactor: Unnecessary deprecation warning on enableProductPurchaseLegacyApi: false (#10293) 2026-03-23 23:07:17 +00:00
Manuel 6449397e86 refactor: Bump express-rate-limit from 8.2.1 to 8.3.0 (#10292) 2026-03-23 22:56:25 +00:00
dependabot[bot] 87c4717b49 refactor: Bump undici (#10198) 2026-03-23 22:26:25 +00:00