Skip to content

feat: semaphore v1.4.0 release candidate 2 #470

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 11 commits into
base: release/v1.4.x
Choose a base branch
from

Conversation

skipi and others added 5 commits August 8, 2025 10:52
## 📝 Description
This PR introduces a new configuration option to control whether draft
PRs trigger builds. This setting is available in project settings when
PR building is enabled.

## ✅ Checklist
- [x] I have tested this change
- [x] This change requires documentation update
renderedtext/project-tasks#2650

- [x] I have tested this change
- [ ] This change requires documentation update
Service is using rabbitmq but is missing init container that waits for
rabbitmq pod bootup

## 📝 Description
<!-- Describe your changes in detail -->

## ✅ Checklist
- [x] I have tested this change
- [ ] ~This change requires documentation update~
During bootup, service is often killed by OOMKiller

## 📝 Description
<!-- Describe your changes in detail -->

## ✅ Checklist
- [x] I have tested this change
- [ ] ~This change requires documentation update~
…#441)

- Remove entr file watching in favor of LiveReload
- Enable distributed node for clustering in local development
- Move hardcoded internal APIs from dev config to docker compose
- Remove CORS headers blocking LiveReload websockets
- Enable websocket upgrades for LiveReload in ingress

## 📝 Description
<!-- Describe your changes in detail -->

## ✅ Checklist
- [x] I have tested this change
- [x] ~This change requires documentation update~
skipi and others added 4 commits August 8, 2025 11:07
## 📝 Description
Address GHSA-353f-x4gh-cqq8 in
github_hooks service.

## ✅ Checklist
- [x] I have tested this change
- [ ] This change requires documentation update
## 📝 Description
- Fixes CVE-2025-22868
- Bumps golang to 1.23

## ✅ Checklist
- [x] I have tested this change
- [ ] This change requires documentation update
## 📝 Description

- Implemented a modern CSS build pipeline using PostCSS for better CSS
processing and optimization
- Consolidated CSS output to a single file for improved performance
- Aligned with Phoenix 1.6+ asset management best practices
- Updated the security toolbox to properly display JS dependency scan
results

## ✅ Checklist
- [x] I have tested this change
- [ ] This change requires documentation update
## 📝 Description
- Update billboard.js from 3.9.3 to 3.16.0 to fix CVE-2025-49223
(critical prototype pollution vulnerability)
- Update d3-color from 1.4.1 to 3.1.0 to fix GHSA-36jr-mh4h-2g58 (high
severity ReDoS vulnerability)

## ✅ Checklist
- [x] I have tested this change
- [x] ~This change requires documentation update~
lucaspin
lucaspin previously approved these changes Aug 8, 2025
@skipi skipi requested a review from lucaspin August 8, 2025 11:03
@skipi skipi enabled auto-merge (squash) August 8, 2025 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants