3.4.7: Security and maintenance release

Discourse 3.4.7 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on lack of change than lack of bugs - all releases, including those on tests-passed and beta are production ready.

Security Updates

This release includes fixes for these security issues reported by our community and HackerOne.

2 Likes

Even more!

But wait, there’s more! We do our best to highlight new features and changes for you, but there’s always too many changes to detail. For a full list of new features, bug fixes, UX improvements, and more, be sure to review the Additional Features and Fixes listed below.

All Features and Fixes

Bug Fixes

  • UppyUploader issues when authorized_extensions setting is blank but authorized_extensions_for_staff is not (33424)

Security Changes

  • Clear webauthn challenge from session after authenticating
3 Likes