# Any release notes (not just commit log) available?

**URL:** https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431
**Category:** Support
**Created:** [January 9, 2017, 7:35pm UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431 "2017-01-09T19:35:10Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Jeremy\_Howard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jeremy_howard/32/168120_2.png) [@Jeremy\_Howard](https://meta.discourse.org/u/Jeremy_Howard)
#### Post date: [January 9, 2017, 7:35pm UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/1 "2017-01-09T19:35:10Z")

</div>

I’m always a little nervous of upgrading something when it’s working well, so was looking to see if there are release notes for 1.8 that mention if there are any critical security fixes or major feature additions that might make the upgrade a priority. All I found were the git commit messages, which are a little long, are not prioritized, and frequently don’t provide enough info for regular folks to know what they’re about.

Could anyone summarize what the major changes in 1.8 were, and whether there are any important security fixes? Is this something that may be able to be included in future releases, since I assume that a lot of people would be interested… 🙂

---

<div class="post-metadata">

### Author: ![vinothkannans](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/vinothkannans/32/86465_2.png) [@vinothkannans](https://meta.discourse.org/u/vinothkannans)
#### Post date: [January 9, 2017, 8:00pm UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/2 "2017-01-09T20:00:41Z")

</div>

You may get some ideas if you look at the topics in #releases category

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [January 9, 2017, 8:19pm UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/3 "2017-01-09T20:19:43Z")

</div>

The best summary would be the blog post:

> **[Discourse 1.7 released!](https://blog.discourse.org/2017/01/discourse-1-7-released/)**
>
> Today, after four months of work, we’re proud to release Discourse 1.7.

Yes, there were security fixes. They’re listed in the releases topic that Vinoth mentioned. Here they are:

- Do cookie auth rate limiting earlier
- Escape image title in lightbox
- Escape HTML in filename
- Upgrade Rails
- Don’t allow re-using the current password during password reset
- Add filename validation for backup uploads
- Escape advanced search term
- Don’t grant same privileges to user\_api and api access
- Fix reflected XSS with safe\_mode param
- Protect upload params, only allow very strict filenames
- Prevent reuse of password reset
- Users can only bookmark posts which they can see

---

<div class="post-metadata">

### Author: ![Jeremy\_Howard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jeremy_howard/32/168120_2.png) [@Jeremy\_Howard](https://meta.discourse.org/u/Jeremy_Howard)
#### Post date: [January 19, 2017, 2:16am UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/4 "2017-01-19T02:16:37Z")

</div>

Many thanks to you both.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [April 23, 2019, 7:04am UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/5 "2019-04-23T07:04:46Z")

</div>



---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 23, 2019, 7:12am UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/6 "2019-04-23T07:12:36Z")

</div>

We now have proper release notes for every beta release per #release-notes !!! 🎊 🤩

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 23, 2019, 7:12am UTC](https://meta.discourse.org/t/any-release-notes-not-just-commit-log-available/55431/7 "2019-04-23T07:12:40Z")

</div>


