# 2.8.12: Security Release

**URL:** https://meta.discourse.org/t/2-8-12-security-release/246873
**Category:** Announcements
**Tags:** release-notes
**Created:** [November 28, 2022, 1:16am UTC](https://meta.discourse.org/t/2-8-12-security-release/246873 "2022-11-28T01:16:56Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [November 28, 2022, 1:16am UTC](https://meta.discourse.org/t/2-8-12-security-release/246873/1 "2022-11-28T01:16:56Z")

</div>

## Discourse 2.8.12 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

### Changes

#### Security:

- Hide notifications for inaccessible topics [CVE-2022-41944](https://github.com/discourse/discourse/security/advisories/GHSA-354r-jpj5-53c2)

#### Bug fix:

- Update GitImporter to match main

#### Performance:

- Correct should\_skip? logic in`s3:upload`
- Update`s3:expire_missing_assets` to delete in batches

#### Plugin Security Updates

The Calendar plugin has also received a security fix. Be sure to update plugins in addition to Discourse.

- Calendar: Do not expose private group members [CVE-2022-41913](https://github.com/discourse/discourse-calendar/security/advisories/GHSA-jh96-w279-g7r9)
