-
Notifications
You must be signed in to change notification settings - Fork 468
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
8.0.0 roadmap #710
Comments
Hi, I have a question: do you some plans to take a look into vulnerabilites detected in the image?
Anyways, thx for your project :) |
Dependencies will be updated so I guess it will take care of 芦聽vulnerabilities聽禄. |
Regarding deprecated flags/options, is there an API to check the version of Gotenberg a client is communicating with? I maintain a little library for talking to Gotenberg, so the version might be basically anything somewhat recent, depending on the user. |
Best option is to release a major version of your client. For instance, |
Can you please consider adding a CORS option env into docker image to make the server callable from a web browser. Now it can only be called by developers making their own backend API that calls Gotenberg. That means a lot of extra work to do and in addition, 2 containers must be running for one purpose. |
Gotenberg should not be exposed to the external world, you'll make your internal network vulnerable. See https://infosecwriteups.com/0-day-bug-breaks-multi-million-dollar-system-38c9e31b27e9. |
Hi, |
Hello @maj2c 馃憢 I don鈥檛 want to create additional release with another Debian version, because the Go code and the Dockerfile dependencies are quite interdependent. |
Hello folks 馃憢 ,
I'm planning to release Gotenberg
8.0.0
before the end of the year. It will be a "light" release, i.e., if you're using the latest7.x
version, all you'll have to do is remove the deprecated flags, form fields and so on. Checking your Gotenberg instance(s) logging entries should be enough to know if you're using any deprecated features 馃憤7.10.0
main
branch now triggers the build ofgotenberg/gotenberg:edge
andgotenberg/gotenberg:edge-cloudrun
. Good to know: the live demo is based on this new version.armhf
build (Chromium not working on armhf after version 116.0.5845.180-1~deb12u1聽#709).convert
method from PDF engines to be more generic (no more PDF format, but PDF Archive, PDF UA, etc.).unoconv
with a newunoconverter
Python project.8.0.0
skipNetworkIdleEvent
(done in feat: skip networkIdle event聽#749).Do you want to help? Consider testing
gotenberg/gotenberg:edge
, thanks!The text was updated successfully, but these errors were encountered: