semantic-release-bot
|
1c2c6f9669
|
chore(release): 9.8.0-alpha.4 [skip ci]
# [9.8.0-alpha.4](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.3...9.8.0-alpha.4) (2026-04-03)
### Features
* Add server option `fileDownload` to restrict file download ([#10394](https://github.com/parse-community/parse-server/issues/10394)) ([fc117ef](https://github.com/parse-community/parse-server/commit/fc117efa4dc233ad6dfee6f46d80991b10927ba8))
9.8.0-alpha.4
|
2026-04-03 18:42:34 +00:00 |
|
Manuel
|
fc117efa4d
|
feat: Add server option fileDownload to restrict file download (#10394)
|
2026-04-03 19:41:42 +01:00 |
|
semantic-release-bot
|
89dec6d789
|
chore(release): 9.8.0-alpha.3 [skip ci]
# [9.8.0-alpha.3](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.2...9.8.0-alpha.3) (2026-04-03)
### Bug Fixes
* Bump lodash from 4.17.23 to 4.18.1 ([#10393](https://github.com/parse-community/parse-server/issues/10393)) ([19716ad](https://github.com/parse-community/parse-server/commit/19716ad9afe9400ad2440c0ed3c5fbfe376a8585))
9.8.0-alpha.3
|
2026-04-03 18:01:53 +00:00 |
|
Manuel
|
19716ad9af
|
fix: Bump lodash from 4.17.23 to 4.18.1 (#10393)
|
2026-04-03 19:01:02 +01:00 |
|
dependabot[bot]
|
050887429a
|
refactor: Bump lodash-es from 4.17.23 to 4.18.1 (#10387)
|
2026-04-03 18:16:31 +01:00 |
|
Manuel
|
a4bf3fe145
|
refactor: Bump semver from 7.7.2 to 7.7.4 (#10392)
|
2026-04-03 18:14:19 +01:00 |
|
semantic-release-bot
|
259d48b790
|
chore(release): 9.8.0-alpha.2 [skip ci]
# [9.8.0-alpha.2](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.1...9.8.0-alpha.2) (2026-04-03)
### Bug Fixes
* Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting ([#10391](https://github.com/parse-community/parse-server/issues/10391)) ([7d8b367](https://github.com/parse-community/parse-server/commit/7d8b367e0b3ef9e9dd6735408068895ead873a0c))
9.8.0-alpha.2
|
2026-04-03 16:38:05 +00:00 |
|
Manuel
|
7d8b367e0b
|
fix: Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting (#10391)
|
2026-04-03 17:36:27 +01:00 |
|
semantic-release-bot
|
5323b08eea
|
chore(release): 9.8.0-alpha.1 [skip ci]
# [9.8.0-alpha.1](https://github.com/parse-community/parse-server/compare/9.7.1-alpha.4...9.8.0-alpha.1) (2026-04-03)
### Features
* Add route block with new server option `routeAllowList` ([#10389](https://github.com/parse-community/parse-server/issues/10389)) ([f2d06e7](https://github.com/parse-community/parse-server/commit/f2d06e7b95242268607bfa5205b4e86ba7c7698e))
9.8.0-alpha.1
|
2026-04-03 15:09:06 +00:00 |
|
Manuel
|
f2d06e7b95
|
feat: Add route block with new server option routeAllowList (#10389)
|
2026-04-03 16:08:18 +01:00 |
|
semantic-release-bot
|
73dde7680f
|
chore(release): 9.7.1-alpha.4 [skip ci]
## [9.7.1-alpha.4](https://github.com/parse-community/parse-server/compare/9.7.1-alpha.3...9.7.1-alpha.4) (2026-04-02)
### Bug Fixes
* File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) ([#10383](https://github.com/parse-community/parse-server/issues/10383)) ([dd7cc41](https://github.com/parse-community/parse-server/commit/dd7cc41a952b9ec6fa655a5655f106cca27d65c7))
9.7.1-alpha.4
|
2026-04-02 01:20:14 +00:00 |
|
Manuel
|
dd7cc41a95
|
fix: File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) (#10383)
|
2026-04-02 02:19:26 +01:00 |
|
semantic-release-bot
|
0f322141e0
|
chore(release): 9.7.1-alpha.3 [skip ci]
## [9.7.1-alpha.3](https://github.com/parse-community/parse-server/compare/9.7.1-alpha.2...9.7.1-alpha.3) (2026-04-01)
### Bug Fixes
* Session field guard bypass via falsy values for ACL and user fields ([#10382](https://github.com/parse-community/parse-server/issues/10382)) ([ead12bd](https://github.com/parse-community/parse-server/commit/ead12bd1df7f11013d9266e41014dcb143351341))
9.7.1-alpha.3
|
2026-04-01 20:26:19 +00:00 |
|
Manuel
|
ead12bd1df
|
fix: Session field guard bypass via falsy values for ACL and user fields (#10382)
|
2026-04-01 21:25:30 +01:00 |
|
Manuel
|
b587767aa3
|
test: Plaintext password accessible in beforeSave trigger on _User class (#10380)
|
2026-04-01 20:40:18 +01:00 |
|
Manuel
|
df5cd46c83
|
refactor: Bump @parse/push-adapter from 8.3.1 to 8.4.0 (#10381)
|
2026-04-01 20:32:33 +01:00 |
|
Manuel
|
c7814b4429
|
refactor: Bump jsdoc from 4.0.4 to 4.0.5 (#10379)
|
2026-04-01 19:35:38 +01:00 |
|
Manuel
|
03be0c07e9
|
docs: Add multi-tenancy section to README (#10378)
|
2026-04-01 18:05:08 +01:00 |
|
Manuel
|
b4888948b5
|
refactor: Bump @graphql-tools/utils from 10.8.6 to 11.0.0 (#10377)
|
2026-04-01 17:55:25 +01:00 |
|
Manuel
|
225a4bb2ad
|
test: CLI execution tests fail on Node 22 due to late stderr callback (#10376)
|
2026-04-01 16:46:24 +01:00 |
|
semantic-release-bot
|
537c2affc5
|
chore(release): 9.7.1-alpha.2 [skip ci]
## [9.7.1-alpha.2](https://github.com/parse-community/parse-server/compare/9.7.1-alpha.1...9.7.1-alpha.2) (2026-04-01)
### Bug Fixes
* Nested batch sub-requests cause unclear error ([#10371](https://github.com/parse-community/parse-server/issues/10371)) ([6635096](https://github.com/parse-community/parse-server/commit/66350964c8a200eb9e4540f6fcdc0fe0099c5ff6))
9.7.1-alpha.2
|
2026-04-01 13:36:21 +00:00 |
|
Manuel
|
66350964c8
|
fix: Nested batch sub-requests cause unclear error (#10371)
|
2026-04-01 14:35:25 +01:00 |
|
Manuel
|
82edbd747c
|
refactor: Bump uuid from 11.1.0 to 13.0.0 (#10370)
|
2026-03-31 17:57:06 +01:00 |
|
Manuel
|
1cea69a6fa
|
refactor: Bump yaml from 2.8.2 to 2.8.3 (#10369)
|
2026-03-31 15:55:48 +01:00 |
|
Manuel
|
eae967cd53
|
refactor: Bump lint-staged from 16.2.7 to 16.4.0 (#10368)
|
2026-03-31 13:53:50 +01:00 |
|
Manuel
|
8a581e940f
|
refactor: Upgrade ws to 7.5.10 (GHSA-3h5v-q93c-6h6q) (#10363)
|
2026-03-31 02:41:17 +01:00 |
|
semantic-release-bot
|
4d7f5942b6
|
chore(release): 9.7.1-alpha.1 [skip ci]
## [9.7.1-alpha.1](https://github.com/parse-community/parse-server/compare/9.7.0...9.7.1-alpha.1) (2026-03-30)
### Bug Fixes
* Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) ([#10361](https://github.com/parse-community/parse-server/issues/10361)) ([a0b0c69](https://github.com/parse-community/parse-server/commit/a0b0c69fc44f87f80d793d257344e7dcbf676e22))
9.7.1-alpha.1
|
2026-03-30 23:18:43 +00:00 |
|
Manuel
|
a0b0c69fc4
|
fix: Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) (#10361)
|
2026-03-31 00:17:57 +01:00 |
|
Manuel
|
54c835e0fa
|
refactor: Bump mime from 4.0.7 to 4.1.0 (#10360)
|
2026-03-30 20:38:12 +01:00 |
|
Manuel
|
2f7dd2e4bb
|
refactor: Bump express-rate-limit from 8.3.0 to 8.3.1 (#10359)
|
2026-03-30 19:32:34 +01:00 |
|
Manuel
|
2f2c548605
|
refactor: Bump @babel/preset-env from 7.27.2 to 7.29.2 (#10358)
|
2026-03-30 18:13:15 +01:00 |
|
semantic-release-bot
|
84ca53352f
|
chore(release): 9.7.0 [skip ci]
# [9.7.0](https://github.com/parse-community/parse-server/compare/9.6.1...9.7.0) (2026-03-30)
### Bug Fixes
* Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) ([#10323](https://github.com/parse-community/parse-server/issues/10323)) ([770be86](https://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed))
* Batch login sub-request rate limit uses IP-based keying ([#10349](https://github.com/parse-community/parse-server/issues/10349)) ([63c37c4](https://github.com/parse-community/parse-server/commit/63c37c49c7a72dc617635da8859004503021b8fd))
* Cloud Code trigger context vulnerable to prototype pollution ([#10352](https://github.com/parse-community/parse-server/issues/10352)) ([d5f5128](https://github.com/parse-community/parse-server/commit/d5f5128ade49749856d8ad5f9750ffd26d44836a))
* Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) ([#10342](https://github.com/parse-community/parse-server/issues/10342)) ([dc59e27](https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674))
* Duplicate session destruction can cause unhandled promise rejection ([#10319](https://github.com/parse-community/parse-server/issues/10319)) ([92791c1](https://github.com/parse-community/parse-server/commit/92791c1d1d4b042a0e615ba45dcef491b904eccf))
* GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) ([#10334](https://github.com/parse-community/parse-server/issues/10334)) ([4dd0d3d](https://github.com/parse-community/parse-server/commit/4dd0d3d8be1c39664c74ad10bb0abaa76bc41203))
* GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) ([#10344](https://github.com/parse-community/parse-server/issues/10344)) ([f759bda](https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b))
* LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) ([#10330](https://github.com/parse-community/parse-server/issues/10330)) ([776c71c](https://github.com/parse-community/parse-server/commit/776c71c3078e77d38c94937f463741793609d055))
* LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) ([#10350](https://github.com/parse-community/parse-server/issues/10350)) ([f63fd1a](https://github.com/parse-community/parse-server/commit/f63fd1a3fe0a7c1c5fe809f01b0e04759e8c9b98))
* Maintenance key blocked from querying protected fields ([#10290](https://github.com/parse-community/parse-server/issues/10290)) ([7c8b213](https://github.com/parse-community/parse-server/commit/7c8b213d96f1fd79f27d3a2bc01bef8bcaf588cd))
* MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) ([#10326](https://github.com/parse-community/parse-server/issues/10326)) ([e7efbeb](https://github.com/parse-community/parse-server/commit/e7efbebba398ce6abe5b6b6fb9829c6ebe310fbf))
* Missing error messages in Parse errors ([#10304](https://github.com/parse-community/parse-server/issues/10304)) ([f128048](https://github.com/parse-community/parse-server/commit/f12804800bc9232de02b4314e886bab6b169f041))
* Postgres query on non-existent column throws internal server error ([#10308](https://github.com/parse-community/parse-server/issues/10308)) ([c5c4325](https://github.com/parse-community/parse-server/commit/c5c43259d1f98af5bbbbc44d9daf7c0f1f8168d3))
* Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) ([#10347](https://github.com/parse-community/parse-server/issues/10347)) ([9080296](https://github.com/parse-community/parse-server/commit/90802969fc713b7bc9733d7255c7519a6ed75d21))
### Features
* Add `protectedFieldsSaveResponseExempt` option to strip protected fields from save responses ([#10289](https://github.com/parse-community/parse-server/issues/10289)) ([4f7cb53](https://github.com/parse-community/parse-server/commit/4f7cb53bd114554cf9e6d7855b5e8911cb87544b))
* Add `protectedFieldsTriggerExempt` option to exempt Cloud Code triggers from `protectedFields` ([#10288](https://github.com/parse-community/parse-server/issues/10288)) ([1610f98](https://github.com/parse-community/parse-server/commit/1610f98316f7cb1120a7e20be7a1570b0e116df7))
* Add support for `partialFilterExpression` in MongoDB storage adapter ([#10346](https://github.com/parse-community/parse-server/issues/10346)) ([8dd7bf2](https://github.com/parse-community/parse-server/commit/8dd7bf2f61c07b0467d6dbc7aad5142db6694339))
* Extend storage adapter interface to optionally return `matchedCount` and `modifiedCount` from `DatabaseController.update` with `many: true` ([#10353](https://github.com/parse-community/parse-server/issues/10353)) ([aea7596](https://github.com/parse-community/parse-server/commit/aea7596cd2336c1c179ae130efd550f1596f5f3a))
9.7.0
|
2026-03-30 00:31:17 +00:00 |
|
Manuel
|
6d0bd1eb40
|
build: Release (#10354)
|
2026-03-30 01:30:17 +01:00 |
|
GitHub Actions
|
d01675bc55
|
empty commit to trigger CI
|
2026-03-30 00:11:26 +00:00 |
|
semantic-release-bot
|
99fc339395
|
chore(release): 9.7.0-alpha.18 [skip ci]
# [9.7.0-alpha.18](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.17...9.7.0-alpha.18) (2026-03-30)
### Features
* Extend storage adapter interface to optionally return `matchedCount` and `modifiedCount` from `DatabaseController.update` with `many: true` ([#10353](https://github.com/parse-community/parse-server/issues/10353)) ([aea7596](https://github.com/parse-community/parse-server/commit/aea7596cd2336c1c179ae130efd550f1596f5f3a))
9.7.0-alpha.18
|
2026-03-30 00:09:55 +00:00 |
|
Manuel
|
aea7596cd2
|
feat: Extend storage adapter interface to optionally return matchedCount and modifiedCount from DatabaseController.update with many: true (#10353)
|
2026-03-30 01:09:10 +01:00 |
|
semantic-release-bot
|
6183d4bfc6
|
chore(release): 9.7.0-alpha.17 [skip ci]
# [9.7.0-alpha.17](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.16...9.7.0-alpha.17) (2026-03-29)
### Bug Fixes
* Cloud Code trigger context vulnerable to prototype pollution ([#10352](https://github.com/parse-community/parse-server/issues/10352)) ([d5f5128](https://github.com/parse-community/parse-server/commit/d5f5128ade49749856d8ad5f9750ffd26d44836a))
9.7.0-alpha.17
|
2026-03-29 23:22:13 +00:00 |
|
Manuel
|
d5f5128ade
|
fix: Cloud Code trigger context vulnerable to prototype pollution (#10352)
|
2026-03-30 00:21:18 +01:00 |
|
semantic-release-bot
|
e573cfa43d
|
chore(release): 9.7.0-alpha.16 [skip ci]
# [9.7.0-alpha.16](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.15...9.7.0-alpha.16) (2026-03-29)
### Bug Fixes
* LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) ([#10350](https://github.com/parse-community/parse-server/issues/10350)) ([f63fd1a](https://github.com/parse-community/parse-server/commit/f63fd1a3fe0a7c1c5fe809f01b0e04759e8c9b98))
9.7.0-alpha.16
|
2026-03-29 18:37:39 +00:00 |
|
Manuel
|
f63fd1a3fe
|
fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10350)
|
2026-03-29 19:36:52 +01:00 |
|
semantic-release-bot
|
f897d83e2e
|
chore(release): 9.7.0-alpha.15 [skip ci]
# [9.7.0-alpha.15](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.14...9.7.0-alpha.15) (2026-03-29)
### Bug Fixes
* Batch login sub-request rate limit uses IP-based keying ([#10349](https://github.com/parse-community/parse-server/issues/10349)) ([63c37c4](https://github.com/parse-community/parse-server/commit/63c37c49c7a72dc617635da8859004503021b8fd))
9.7.0-alpha.15
|
2026-03-29 15:09:33 +00:00 |
|
Manuel
|
63c37c49c7
|
fix: Batch login sub-request rate limit uses IP-based keying (#10349)
|
2026-03-29 16:08:36 +01:00 |
|
semantic-release-bot
|
12d6fae848
|
chore(release): 9.7.0-alpha.14 [skip ci]
# [9.7.0-alpha.14](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.13...9.7.0-alpha.14) (2026-03-29)
### Bug Fixes
* Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) ([#10347](https://github.com/parse-community/parse-server/issues/10347)) ([9080296](https://github.com/parse-community/parse-server/commit/90802969fc713b7bc9733d7255c7519a6ed75d21))
9.7.0-alpha.14
|
2026-03-29 03:56:56 +00:00 |
|
Manuel
|
90802969fc
|
fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10347)
|
2026-03-29 04:55:39 +01:00 |
|
semantic-release-bot
|
1d5dd64419
|
chore(release): 9.7.0-alpha.13 [skip ci]
# [9.7.0-alpha.13](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.12...9.7.0-alpha.13) (2026-03-29)
### Features
* Add support for `partialFilterExpression` in MongoDB storage adapter ([#10346](https://github.com/parse-community/parse-server/issues/10346)) ([8dd7bf2](https://github.com/parse-community/parse-server/commit/8dd7bf2f61c07b0467d6dbc7aad5142db6694339))
9.7.0-alpha.13
|
2026-03-29 02:38:08 +00:00 |
|
Manuel
|
8dd7bf2f61
|
feat: Add support for partialFilterExpression in MongoDB storage adapter (#10346)
|
2026-03-29 03:37:19 +01:00 |
|
semantic-release-bot
|
e71e0301df
|
chore(release): 9.7.0-alpha.12 [skip ci]
# [9.7.0-alpha.12](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.11...9.7.0-alpha.12) (2026-03-29)
### Bug Fixes
* GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) ([#10344](https://github.com/parse-community/parse-server/issues/10344)) ([f759bda](https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b))
9.7.0-alpha.12
|
2026-03-29 01:33:26 +00:00 |
|
Manuel
|
f759bda075
|
fix: GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) (#10344)
|
2026-03-29 02:32:35 +01:00 |
|
semantic-release-bot
|
458b718cb8
|
chore(release): 9.7.0-alpha.11 [skip ci]
# [9.7.0-alpha.11](https://github.com/parse-community/parse-server/compare/9.7.0-alpha.10...9.7.0-alpha.11) (2026-03-28)
### Bug Fixes
* Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) ([#10342](https://github.com/parse-community/parse-server/issues/10342)) ([dc59e27](https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674))
9.7.0-alpha.11
|
2026-03-28 18:48:17 +00:00 |
|
Manuel
|
dc59e27266
|
fix: Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) (#10342)
|
2026-03-28 18:46:42 +00:00 |
|