diff --git a/CHANGELOG.md b/CHANGELOG.md index 283bcdfd46..6853624a3b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,75 +2,78 @@ **Topics** -- v9\.5\.12 +- v9\.5\.13 - Release Summary + - Security Fixes +- v9\.5\.12 + - Release Summary - Bugfixes - v9\.5\.11 - - Release Summary + - Release Summary - Bugfixes - v9\.5\.10 - - Release Summary + - Release Summary - Bugfixes - v9\.5\.9 - - Release Summary + - Release Summary - Bugfixes - v9\.5\.8 - - Release Summary + - Release Summary - Bugfixes - v9\.5\.7 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - Known Issues - v9\.5\.6 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - v9\.5\.5 - - Release Summary + - Release Summary - Bugfixes - v9\.5\.4 - - Security Fixes + - Security Fixes - Bugfixes - v9\.5\.3 - - Release Summary + - Release Summary - Minor Changes - - Security Fixes + - Security Fixes - Bugfixes - v9\.5\.2 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - v9\.5\.1 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - v9\.5\.0 - - Release Summary + - Release Summary - Minor Changes - Deprecated Features - Bugfixes - New Modules - v9\.4\.0 - - Release Summary + - Release Summary - Minor Changes - Deprecated Features - Bugfixes - New Modules - v9\.3\.0 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - New Modules - v9\.2\.0 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - New Plugins - Filter - Test - v9\.1\.0 - - Release Summary + - Release Summary - Minor Changes - Deprecated Features - Bugfixes @@ -79,16 +82,16 @@ - Filter - New Modules - v9\.0\.1 - - Release Summary + - Release Summary - Minor Changes - Bugfixes - v9\.0\.0 - - Release Summary + - Release Summary - Minor Changes - Breaking Changes / Porting Guide - Deprecated Features - Removed Features \(previously deprecated\) - - Security Fixes + - Security Fixes - Bugfixes - New Plugins - Become @@ -100,10 +103,27 @@ - New Modules This changelog describes changes after version 8\.0\.0\. + +## v9\.5\.13 + + +### Release Summary + +Final maintenance release\. + +This is the last community\.general 9\.x\.y release\. +Please upgrade to community\.general 10\.x\.y\, 11\.x\.y\, or 12\.x\.y\. +Thanks a lot to everyone who contributed to a 9\.x\.y release\! + + +### Security Fixes + +* keycloak\_user \- the parameter credentials\[\]\.value is now marked as no\_log\=true\. Before it was logged by Ansible\, unless the task was marked as no\_log\: true\. Since this parameter can be used for passwords\, this resulted in credential leaking \([https\://github\.com/ansible\-collections/community\.general/issues/11000](https\://github\.com/ansible\-collections/community\.general/issues/11000)\, [https\://github\.com/ansible\-collections/community\.general/pull/11005](https\://github\.com/ansible\-collections/community\.general/pull/11005)\)\. + ## v9\.5\.12 - + ### Release Summary Bugfix release\. @@ -117,7 +137,7 @@ Bugfix release\. ## v9\.5\.11 - + ### Release Summary Bugfix release\. @@ -140,7 +160,7 @@ Bugfix release\. ## v9\.5\.10 - + ### Release Summary Bugfix release with improved ansible\-core 2\.19 compatibility\. @@ -156,7 +176,7 @@ Bugfix release with improved ansible\-core 2\.19 compatibility\. ## v9\.5\.9 - + ### Release Summary Bugfix release\. @@ -170,7 +190,7 @@ Bugfix release\. ## v9\.5\.8 - + ### Release Summary Regular bugfix release\. @@ -188,7 +208,7 @@ Regular bugfix release\. ## v9\.5\.7 - + ### Release Summary Regular bugfix release\. @@ -221,7 +241,7 @@ Regular bugfix release\. ## v9\.5\.6 - + ### Release Summary Regular bugfix release\. @@ -245,7 +265,7 @@ Regular bugfix release\. ## v9\.5\.5 - + ### Release Summary Regular bugfix release\. @@ -271,7 +291,7 @@ Regular bugfix release\. ## v9\.5\.4 - + ### Security Fixes * keycloak\_client \- Sanitize saml\.encryption\.private\.key so it does not show in the logs \([https\://github\.com/ansible\-collections/community\.general/pull/9621](https\://github\.com/ansible\-collections/community\.general/pull/9621)\)\. @@ -288,7 +308,7 @@ Regular bugfix release\. ## v9\.5\.3 - + ### Release Summary Regular bugfix release\. @@ -298,7 +318,7 @@ Regular bugfix release\. * proxmox module utils \- add method api\_task\_complete that can wait for task completion and return error message \([https\://github\.com/ansible\-collections/community\.general/pull/9256](https\://github\.com/ansible\-collections/community\.general/pull/9256)\)\. - + ### Security Fixes * keycloak\_authentication \- API calls did not properly set the priority during update resulting in incorrectly sorted authentication flows\. This apparently only affects Keycloak 25 or newer \([https\://github\.com/ansible\-collections/community\.general/pull/9263](https\://github\.com/ansible\-collections/community\.general/pull/9263)\)\. @@ -316,7 +336,7 @@ Regular bugfix release\. ## v9\.5\.2 - + ### Release Summary Regular bugfix release\. @@ -343,7 +363,7 @@ Regular bugfix release\. ## v9\.5\.1 - + ### Release Summary Regular bugfix release\. @@ -371,7 +391,7 @@ Regular bugfix release\. ## v9\.5\.0 - + ### Release Summary Regular bugfix and feature release\. @@ -470,7 +490,7 @@ From now on\, new features will only go into community\.general 10\.x\.y\. ## v9\.4\.0 - + ### Release Summary Bugfix and feature release\. @@ -584,7 +604,7 @@ Bugfix and feature release\. ## v9\.3\.0 - + ### Release Summary Regular bugfix and feature release\. @@ -633,7 +653,7 @@ Regular bugfix and feature release\. ## v9\.2\.0 - + ### Release Summary Regular bugfix and feature release\. @@ -675,7 +695,7 @@ Regular bugfix and feature release\. ## v9\.1\.0 - + ### Release Summary Regular feature and bugfix release\. @@ -742,7 +762,7 @@ Regular feature and bugfix release\. ## v9\.0\.1 - + ### Release Summary Bugfix release for inclusion in Ansible 10\.0\.0rc1\. @@ -771,7 +791,7 @@ Bugfix release for inclusion in Ansible 10\.0\.0rc1\. ## v9\.0\.0 - + ### Release Summary This is release 9\.0\.0 of community\.general\, released on 2024\-05\-20\. @@ -940,7 +960,7 @@ This is release 9\.0\.0 of community\.general\, released on 2024\-0 * stackdriver \- this module relied on HTTPS APIs that do not exist anymore and was thus removed \([https\://github\.com/ansible\-collections/community\.general/pull/8198](https\://github\.com/ansible\-collections/community\.general/pull/8198)\)\. * webfaction\_\* modules \- these modules relied on HTTPS APIs that do not exist anymore and were thus removed \([https\://github\.com/ansible\-collections/community\.general/pull/8198](https\://github\.com/ansible\-collections/community\.general/pull/8198)\)\. - + ### Security Fixes * cobbler\, gitlab\_runners\, icinga2\, linode\, lxd\, nmap\, online\, opennebula\, proxmox\, scaleway\, stackpath\_compute\, virtualbox\, and xen\_orchestra inventory plugin \- make sure all data received from the remote servers is marked as unsafe\, so remote code execution by obtaining texts that can be evaluated as templates is not possible \([https\://www\.die\-welt\.net/2024/03/remote\-code\-execution\-in\-ansible\-dynamic\-inventory\-plugins/](https\://www\.die\-welt\.net/2024/03/remote\-code\-execution\-in\-ansible\-dynamic\-inventory\-plugins/)\, [https\://github\.com/ansible\-collections/community\.general/pull/8098](https\://github\.com/ansible\-collections/community\.general/pull/8098)\)\. diff --git a/CHANGELOG.rst b/CHANGELOG.rst index b8e9acad5b..5e50d46f4e 100644 --- a/CHANGELOG.rst +++ b/CHANGELOG.rst @@ -6,6 +6,23 @@ Community General Release Notes This changelog describes changes after version 8.0.0. +v9.5.13 +======= + +Release Summary +--------------- + +Final maintenance release. + +This is the last community.general 9.x.y release. +Please upgrade to community.general 10.x.y, 11.x.y, or 12.x.y. +Thanks a lot to everyone who contributed to a 9.x.y release! + +Security Fixes +-------------- + +- keycloak_user - the parameter ``credentials[].value`` is now marked as ``no_log=true``. Before it was logged by Ansible, unless the task was marked as ``no_log: true``. Since this parameter can be used for passwords, this resulted in credential leaking (https://github.com/ansible-collections/community.general/issues/11000, https://github.com/ansible-collections/community.general/pull/11005). + v9.5.12 ======= diff --git a/changelogs/changelog.yaml b/changelogs/changelog.yaml index 3eca1fa5eb..64790062b0 100644 --- a/changelogs/changelog.yaml +++ b/changelogs/changelog.yaml @@ -1806,3 +1806,23 @@ releases: - 10857-github_deploy_key-err.yml - 9.5.12.yml release_date: '2025-10-06' + 9.5.13: + changes: + release_summary: 'Final maintenance release. + + + This is the last community.general 9.x.y release. + + Please upgrade to community.general 10.x.y, 11.x.y, or 12.x.y. + + Thanks a lot to everyone who contributed to a 9.x.y release!' + security_fixes: + - 'keycloak_user - the parameter ``credentials[].value`` is now marked as + ``no_log=true``. Before it was logged by Ansible, unless the task was marked + as ``no_log: true``. Since this parameter can be used for passwords, this + resulted in credential leaking (https://github.com/ansible-collections/community.general/issues/11000, + https://github.com/ansible-collections/community.general/pull/11005).' + fragments: + - 11005-keycloak_user.yml + - 9.5.13.yml + release_date: '2025-11-02' diff --git a/changelogs/fragments/11005-keycloak_user.yml b/changelogs/fragments/11005-keycloak_user.yml deleted file mode 100644 index d715ca8c94..0000000000 --- a/changelogs/fragments/11005-keycloak_user.yml +++ /dev/null @@ -1,4 +0,0 @@ -security_fixes: - - "keycloak_user - the parameter ``credentials[].value`` is now marked as ``no_log=true``. Before it was logged by Ansible, unless the task was marked as ``no_log: true``. - Since this parameter can be used for passwords, this resulted in credential leaking - (https://github.com/ansible-collections/community.general/issues/11000, https://github.com/ansible-collections/community.general/pull/11005)." diff --git a/changelogs/fragments/9.5.13.yml b/changelogs/fragments/9.5.13.yml deleted file mode 100644 index 779f4ab688..0000000000 --- a/changelogs/fragments/9.5.13.yml +++ /dev/null @@ -1,6 +0,0 @@ -release_summary: |- - Final maintenance release. - - This is the last community.general 9.x.y release. - Please upgrade to community.general 10.x.y, 11.x.y, or 12.x.y. - Thanks a lot to everyone who contributed to a 9.x.y release!