semantic-release-bot
|
2b9d93d224
|
chore(release): 9.9.1-alpha.4 [skip ci]
## [9.9.1-alpha.4](https://github.com/parse-community/parse-server/compare/9.9.1-alpha.3...9.9.1-alpha.4) (2026-06-01)
### Bug Fixes
* Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) ([#10489](https://github.com/parse-community/parse-server/issues/10489)) ([66484ce](https://github.com/parse-community/parse-server/commit/66484ce8fdd87a5d4c23bf9e40f7ea379b4dce79))
9.9.1-alpha.4
|
2026-06-01 21:37:18 +00:00 |
|
Manuel
|
66484ce8fd
|
fix: Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) (#10489)
|
2026-06-01 23:36:26 +02:00 |
|
semantic-release-bot
|
1e0d6cee9b
|
chore(release): 9.9.1-alpha.3 [skip ci]
## [9.9.1-alpha.3](https://github.com/parse-community/parse-server/compare/9.9.1-alpha.2...9.9.1-alpha.3) (2026-05-27)
### Bug Fixes
* Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) ([#10482](https://github.com/parse-community/parse-server/issues/10482)) ([552c6dd](https://github.com/parse-community/parse-server/commit/552c6dd754638c9f546fbceecd2ba0f7225a95d1))
9.9.1-alpha.3
|
2026-05-27 20:42:36 +00:00 |
|
Manuel
|
552c6dd754
|
fix: Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) (#10482)
|
2026-05-27 22:41:48 +02:00 |
|
Manuel
|
0ae0ed382b
|
test: GraphQL endpoint is exempt from routeAllowList by design (#10480)
|
2026-05-27 00:36:20 +02:00 |
|
semantic-release-bot
|
828d0e0e45
|
chore(release): 9.9.1-alpha.2 [skip ci]
## [9.9.1-alpha.2](https://github.com/parse-community/parse-server/compare/9.9.1-alpha.1...9.9.1-alpha.2) (2026-05-18)
### Bug Fixes
* GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) ([#10467](https://github.com/parse-community/parse-server/issues/10467)) ([155123a](https://github.com/parse-community/parse-server/commit/155123ade9bc88cdf4807cf267ea1196f9274773))
9.9.1-alpha.2
|
2026-05-18 15:05:52 +00:00 |
|
Manuel
|
155123ade9
|
fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10467)
|
2026-05-18 17:04:56 +02:00 |
|
semantic-release-bot
|
216cf8335b
|
chore(release): 9.9.1-alpha.1 [skip ci]
## [9.9.1-alpha.1](https://github.com/parse-community/parse-server/compare/9.9.0...9.9.1-alpha.1) (2026-05-17)
### Bug Fixes
* Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) ([#10463](https://github.com/parse-community/parse-server/issues/10463)) ([56c159e](https://github.com/parse-community/parse-server/commit/56c159ec962d729df09ccaa5cc2537751511e375))
9.9.1-alpha.1
|
2026-05-17 14:12:01 +00:00 |
|
Manuel
|
56c159ec96
|
fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10463)
|
2026-05-17 15:11:10 +01:00 |
|
semantic-release-bot
|
4f90c5e107
|
chore(release): 9.9.0 [skip ci]
# [9.9.0](https://github.com/parse-community/parse-server/compare/9.8.0...9.9.0) (2026-05-01)
### Bug Fixes
* Context mutations leak across requests in `ParseServerRESTController` ([#10291](https://github.com/parse-community/parse-server/issues/10291)) ([60a58ec](https://github.com/parse-community/parse-server/commit/60a58ec11a8bb67aaf217b1e7362b89d742b66da))
* MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) ([#10448](https://github.com/parse-community/parse-server/issues/10448)) ([725be0d](https://github.com/parse-community/parse-server/commit/725be0d602baa619492606e7b3f6829082d93a4c))
### Features
* Add `rawValues` and `rawFieldNames` options for aggregation queries ([#10438](https://github.com/parse-community/parse-server/issues/10438)) ([f26700e](https://github.com/parse-community/parse-server/commit/f26700e39d1980940467bee0d26ca3deb88e3924))
* Add installation deviceToken deduplication options ([#10451](https://github.com/parse-community/parse-server/issues/10451)) ([9fee1a0](https://github.com/parse-community/parse-server/commit/9fee1a07080ab8bda2a3d4798881bcc288e5b37a))
9.9.0
|
2026-05-01 12:15:41 +00:00 |
|
Manuel
|
eb6441362a
|
build: Release (#10452)
|
2026-05-01 13:14:53 +01:00 |
|
GitHub Actions
|
6667900f94
|
empty commit to trigger CI
|
2026-05-01 00:37:57 +00:00 |
|
semantic-release-bot
|
50c37a4ea3
|
chore(release): 9.9.0-alpha.3 [skip ci]
# [9.9.0-alpha.3](https://github.com/parse-community/parse-server/compare/9.9.0-alpha.2...9.9.0-alpha.3) (2026-04-30)
### Features
* Add installation deviceToken deduplication options ([#10451](https://github.com/parse-community/parse-server/issues/10451)) ([9fee1a0](https://github.com/parse-community/parse-server/commit/9fee1a07080ab8bda2a3d4798881bcc288e5b37a))
9.9.0-alpha.3
|
2026-04-30 22:12:36 +00:00 |
|
Manuel
|
9fee1a0708
|
feat: Add installation deviceToken deduplication options (#10451)
|
2026-04-30 23:11:39 +01:00 |
|
semantic-release-bot
|
35207c2796
|
chore(release): 9.9.0-alpha.2 [skip ci]
# [9.9.0-alpha.2](https://github.com/parse-community/parse-server/compare/9.9.0-alpha.1...9.9.0-alpha.2) (2026-04-26)
### Bug Fixes
* MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) ([#10448](https://github.com/parse-community/parse-server/issues/10448)) ([725be0d](https://github.com/parse-community/parse-server/commit/725be0d602baa619492606e7b3f6829082d93a4c))
9.9.0-alpha.2
|
2026-04-26 02:11:20 +00:00 |
|
Manuel
|
725be0d602
|
fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10448)
|
2026-04-26 03:10:27 +01:00 |
|
semantic-release-bot
|
0980ab1a40
|
chore(release): 9.9.0-alpha.1 [skip ci]
# [9.9.0-alpha.1](https://github.com/parse-community/parse-server/compare/9.8.1-alpha.1...9.9.0-alpha.1) (2026-04-17)
### Features
* Add `rawValues` and `rawFieldNames` options for aggregation queries ([#10438](https://github.com/parse-community/parse-server/issues/10438)) ([f26700e](https://github.com/parse-community/parse-server/commit/f26700e39d1980940467bee0d26ca3deb88e3924))
9.9.0-alpha.1
|
2026-04-17 08:13:09 +00:00 |
|
Manuel
|
f26700e39d
|
feat: Add rawValues and rawFieldNames options for aggregation queries (#10438)
|
2026-04-17 09:12:18 +01:00 |
|
Manuel
|
fc53270dbe
|
test: Fix socket hang up in node-fetch 3.3.2 fails tests (#10443)
|
2026-04-17 01:39:53 +01:00 |
|
Manuel
|
f303f752c6
|
refactor: Bump node-fetch from 3.2.10 to 3.3.2 (#10441)
|
2026-04-17 01:52:11 +02:00 |
|
Manuel
|
163d7be605
|
refactor: Bump jsonwebtoken from 9.0.2 to 9.0.3 (#10440)
|
2026-04-17 01:19:05 +02:00 |
|
Manuel
|
cbd1da7be3
|
refactor: Bump path-to-regexp from 8.4.0 to 8.4.2 (#10439)
|
2026-04-16 13:39:55 +02:00 |
|
semantic-release-bot
|
31f70a3269
|
chore(release): 9.8.1-alpha.1 [skip ci]
## [9.8.1-alpha.1](https://github.com/parse-community/parse-server/compare/9.8.0...9.8.1-alpha.1) (2026-04-12)
### Bug Fixes
* Context mutations leak across requests in `ParseServerRESTController` ([#10291](https://github.com/parse-community/parse-server/issues/10291)) ([60a58ec](https://github.com/parse-community/parse-server/commit/60a58ec11a8bb67aaf217b1e7362b89d742b66da))
9.8.1-alpha.1
|
2026-04-12 14:21:46 +00:00 |
|
Yogendra Singh
|
60a58ec11a
|
fix: Context mutations leak across requests in ParseServerRESTController (#10291)
|
2026-04-12 15:20:58 +01:00 |
|
semantic-release-bot
|
7c3b43d263
|
chore(release): 9.8.0 [skip ci]
# [9.8.0](https://github.com/parse-community/parse-server/compare/9.7.0...9.8.0) (2026-04-12)
### Bug Fixes
* Bump lodash from 4.17.23 to 4.18.1 ([#10393](https://github.com/parse-community/parse-server/issues/10393)) ([19716ad](https://github.com/parse-community/parse-server/commit/19716ad9afe9400ad2440c0ed3c5fbfe376a8585))
* Endpoint `/sessions/me` bypasses `_Session` `protectedFields` ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) ([#10406](https://github.com/parse-community/parse-server/issues/10406)) ([d507575](https://github.com/parse-community/parse-server/commit/d5075758f6c3ae9d806671de196fd8b419bc517e))
* Endpoint `/upgradeToRevocableSession` ignores `_Session` `protectedFields` ([#10408](https://github.com/parse-community/parse-server/issues/10408)) ([c136e2b](https://github.com/parse-community/parse-server/commit/c136e2b7ab74609a5127fb68fc5ba40fef440f48))
* Endpoints `/login` and `/verifyPassword` ignore `_User` `protectedFields` ([#10409](https://github.com/parse-community/parse-server/issues/10409)) ([8a3db3b](https://github.com/parse-community/parse-server/commit/8a3db3b9666ea998a8843c629e1af55b105e22e0))
* Facebook Standard Login missing app ID validation ([#10429](https://github.com/parse-community/parse-server/issues/10429)) ([fd31159](https://github.com/parse-community/parse-server/commit/fd31159859ed90f57eb3713f82c9f5b04b20a28c))
* File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) ([#10383](https://github.com/parse-community/parse-server/issues/10383)) ([dd7cc41](https://github.com/parse-community/parse-server/commit/dd7cc41a952b9ec6fa655a5655f106cca27d65c7))
* Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) ([#10398](https://github.com/parse-community/parse-server/issues/10398)) ([531b9ab](https://github.com/parse-community/parse-server/commit/531b9ab6dda4268ede365367fcdc6d98e737ccc3))
* Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting ([#10391](https://github.com/parse-community/parse-server/issues/10391)) ([7d8b367](https://github.com/parse-community/parse-server/commit/7d8b367e0b3ef9e9dd6735408068895ead873a0c))
* Master key does not bypass `protectedFields` on various endpoints ([#10412](https://github.com/parse-community/parse-server/issues/10412)) ([c0889c8](https://github.com/parse-community/parse-server/commit/c0889c8575ee6c6ee01c79cd1ae457124e2a08b3))
* Nested batch sub-requests cause unclear error ([#10371](https://github.com/parse-community/parse-server/issues/10371)) ([6635096](https://github.com/parse-community/parse-server/commit/66350964c8a200eb9e4540f6fcdc0fe0099c5ff6))
* Session field guard bypass via falsy values for ACL and user fields ([#10382](https://github.com/parse-community/parse-server/issues/10382)) ([ead12bd](https://github.com/parse-community/parse-server/commit/ead12bd1df7f11013d9266e41014dcb143351341))
* Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) ([#10361](https://github.com/parse-community/parse-server/issues/10361)) ([a0b0c69](https://github.com/parse-community/parse-server/commit/a0b0c69fc44f87f80d793d257344e7dcbf676e22))
### Features
* Add `requestComplexity.allowRegex` option to disable `$regex` query operator ([#10418](https://github.com/parse-community/parse-server/issues/10418)) ([18482e3](https://github.com/parse-community/parse-server/commit/18482e386c1e723da2df3137f61fa5e2bc8983a6))
* Add `requestComplexity.subqueryLimit` option to limit subquery results ([#10420](https://github.com/parse-community/parse-server/issues/10420)) ([bf40004](https://github.com/parse-community/parse-server/commit/bf40004d258f114c06a3085052ca094384b52b43))
* Add route block with new server option `routeAllowList` ([#10389](https://github.com/parse-community/parse-server/issues/10389)) ([f2d06e7](https://github.com/parse-community/parse-server/commit/f2d06e7b95242268607bfa5205b4e86ba7c7698e))
* Add server option `fileDownload` to restrict file download ([#10394](https://github.com/parse-community/parse-server/issues/10394)) ([fc117ef](https://github.com/parse-community/parse-server/commit/fc117efa4dc233ad6dfee6f46d80991b10927ba8))
* Add support for invoking Cloud Function with `multipart/form-data` protocol ([#10395](https://github.com/parse-community/parse-server/issues/10395)) ([a3f36a2](https://github.com/parse-community/parse-server/commit/a3f36a2ddb981d9868ddf26b128e24b2d58214bd))
9.8.0
|
2026-04-12 10:26:31 +00:00 |
|
Manuel
|
b3dedd0482
|
build: Release (#10430)
|
2026-04-12 11:25:40 +01:00 |
|
GitHub Actions
|
1464b8c582
|
empty commit to trigger CI
|
2026-04-12 00:21:42 +00:00 |
|
semantic-release-bot
|
2998532966
|
chore(release): 9.8.0-alpha.13 [skip ci]
# [9.8.0-alpha.13](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.12...9.8.0-alpha.13) (2026-04-12)
### Bug Fixes
* Facebook Standard Login missing app ID validation ([#10429](https://github.com/parse-community/parse-server/issues/10429)) ([fd31159](https://github.com/parse-community/parse-server/commit/fd31159859ed90f57eb3713f82c9f5b04b20a28c))
9.8.0-alpha.13
|
2026-04-12 00:17:00 +00:00 |
|
Manuel
|
fd31159859
|
fix: Facebook Standard Login missing app ID validation (#10429)
|
2026-04-12 01:16:11 +01:00 |
|
Manuel
|
39af946200
|
refactor: Bump @babel/cli from 7.27.0 to 7.28.6 (#10424)
|
2026-04-10 21:45:42 +01:00 |
|
Manuel
|
8b80e55afd
|
refactor: Bump otpauth from 9.4.0 to 9.5.0 (#10423)
|
2026-04-10 21:22:07 +01:00 |
|
Manuel
|
b55880d702
|
refactor: Bump typescript-eslint from 8.53.1 to 8.58.0 (#10422)
|
2026-04-10 20:51:40 +01:00 |
|
semantic-release-bot
|
406a92743b
|
chore(release): 9.8.0-alpha.12 [skip ci]
# [9.8.0-alpha.12](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.11...9.8.0-alpha.12) (2026-04-10)
### Features
* Add `requestComplexity.subqueryLimit` option to limit subquery results ([#10420](https://github.com/parse-community/parse-server/issues/10420)) ([bf40004](https://github.com/parse-community/parse-server/commit/bf40004d258f114c06a3085052ca094384b52b43))
9.8.0-alpha.12
|
2026-04-10 15:50:28 +00:00 |
|
Manuel
|
bf40004d25
|
feat: Add requestComplexity.subqueryLimit option to limit subquery results (#10420)
|
2026-04-10 16:49:34 +01:00 |
|
semantic-release-bot
|
df5e97fd40
|
chore(release): 9.8.0-alpha.11 [skip ci]
# [9.8.0-alpha.11](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.10...9.8.0-alpha.11) (2026-04-09)
### Features
* Add `requestComplexity.allowRegex` option to disable `$regex` query operator ([#10418](https://github.com/parse-community/parse-server/issues/10418)) ([18482e3](https://github.com/parse-community/parse-server/commit/18482e386c1e723da2df3137f61fa5e2bc8983a6))
9.8.0-alpha.11
|
2026-04-09 17:13:01 +00:00 |
|
Manuel
|
18482e386c
|
feat: Add requestComplexity.allowRegex option to disable $regex query operator (#10418)
|
2026-04-09 18:12:12 +01:00 |
|
Antoine Cormouls
|
f208037b3b
|
refactor: Replace uuid dependency with native UUID (#10416)
|
2026-04-08 14:17:24 +01:00 |
|
Manuel
|
d7d5ae56f7
|
test: Fix flaky LiveQuery tests caused by session token leak (#10415)
|
2026-04-08 00:36:45 +01:00 |
|
Manuel
|
7d4a4607fa
|
test: LiveQuery disconnect does not clear subscription info (#10414)
|
2026-04-08 00:11:55 +01:00 |
|
semantic-release-bot
|
f184f76bce
|
chore(release): 9.8.0-alpha.10 [skip ci]
# [9.8.0-alpha.10](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.9...9.8.0-alpha.10) (2026-04-07)
### Bug Fixes
* Master key does not bypass `protectedFields` on various endpoints ([#10412](https://github.com/parse-community/parse-server/issues/10412)) ([c0889c8](https://github.com/parse-community/parse-server/commit/c0889c8575ee6c6ee01c79cd1ae457124e2a08b3))
9.8.0-alpha.10
|
2026-04-07 12:49:34 +00:00 |
|
Manuel
|
c0889c8575
|
fix: Master key does not bypass protectedFields on various endpoints (#10412)
|
2026-04-07 13:48:39 +01:00 |
|
semantic-release-bot
|
32680e3046
|
chore(release): 9.8.0-alpha.9 [skip ci]
# [9.8.0-alpha.9](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.8...9.8.0-alpha.9) (2026-04-07)
### Bug Fixes
* Endpoints `/login` and `/verifyPassword` ignore `_User` `protectedFields` ([#10409](https://github.com/parse-community/parse-server/issues/10409)) ([8a3db3b](https://github.com/parse-community/parse-server/commit/8a3db3b9666ea998a8843c629e1af55b105e22e0))
9.8.0-alpha.9
|
2026-04-07 12:02:01 +00:00 |
|
Manuel
|
8a3db3b966
|
fix: Endpoints /login and /verifyPassword ignore _User protectedFields (#10409)
|
2026-04-07 13:01:11 +01:00 |
|
semantic-release-bot
|
57a4fba827
|
chore(release): 9.8.0-alpha.8 [skip ci]
# [9.8.0-alpha.8](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.7...9.8.0-alpha.8) (2026-04-07)
### Bug Fixes
* Endpoint `/upgradeToRevocableSession` ignores `_Session` `protectedFields` ([#10408](https://github.com/parse-community/parse-server/issues/10408)) ([c136e2b](https://github.com/parse-community/parse-server/commit/c136e2b7ab74609a5127fb68fc5ba40fef440f48))
9.8.0-alpha.8
|
2026-04-07 09:10:02 +00:00 |
|
Manuel
|
c136e2b7ab
|
fix: Endpoint /upgradeToRevocableSession ignores _Session protectedFields (#10408)
|
2026-04-07 10:09:09 +01:00 |
|
semantic-release-bot
|
8b19852ff2
|
chore(release): 9.8.0-alpha.7 [skip ci]
# [9.8.0-alpha.7](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.6...9.8.0-alpha.7) (2026-04-06)
### Bug Fixes
* Endpoint `/sessions/me` bypasses `_Session` `protectedFields` ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) ([#10406](https://github.com/parse-community/parse-server/issues/10406)) ([d507575](https://github.com/parse-community/parse-server/commit/d5075758f6c3ae9d806671de196fd8b419bc517e))
9.8.0-alpha.7
|
2026-04-06 16:47:25 +00:00 |
|
Manuel
|
d5075758f6
|
fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10406)
|
2026-04-06 17:46:32 +01:00 |
|
Manuel
|
9168e69cb7
|
test: Webhook overwrites Cloud Code function warning (#10400)
|
2026-04-05 22:08:12 +01:00 |
|
semantic-release-bot
|
6322aab48d
|
chore(release): 9.8.0-alpha.6 [skip ci]
# [9.8.0-alpha.6](https://github.com/parse-community/parse-server/compare/9.8.0-alpha.5...9.8.0-alpha.6) (2026-04-05)
### Bug Fixes
* Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) ([#10398](https://github.com/parse-community/parse-server/issues/10398)) ([531b9ab](https://github.com/parse-community/parse-server/commit/531b9ab6dda4268ede365367fcdc6d98e737ccc3))
9.8.0-alpha.6
|
2026-04-05 16:49:42 +00:00 |
|
Manuel
|
531b9ab6dd
|
fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10398)
|
2026-04-05 17:48:57 +01:00 |
|