3.4.7: Security and maintenance release

Discourse 3.4.7 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on lack of change than lack of bugs - all releases, including those on tests-passed and beta are production ready.

Security Updates

This release includes fixes for these security issues reported by our community and HackerOne.

Even more!

But wait, there’s more! We do our best to highlight new features and changes for you, but there’s always too many changes to detail. For a full list of new features, bug fixes, UX improvements, and more, be sure to review the Additional Features and Fixes listed below.

All Features and Fixes

Bug Fixes

  • UppyUploader issues when authorized_extensions setting is blank but authorized_extensions_for_staff is not (33424)

Security Changes

  • Clear webauthn challenge from session after authenticating
2 Likes