Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ permissions:
contents: write

env:
UPGRADE_BASE_TAG: v2.1.2
UPGRADE_BASE_TAG: v2.1.3

jobs:
verify-release:
Expand Down Expand Up @@ -185,7 +185,7 @@ jobs:
"from_version": "${UPGRADE_BASE_TAG}",
"to_version": "${RELEASE_TAG}",
"requires_backup": true,
"requires_migrations": true,
"requires_migrations": $(git diff --quiet "${UPGRADE_BASE_TAG}" "${RELEASE_TAG}" -- database/migrations && echo false || echo true),
"composer_install_required": $(git diff --quiet "${UPGRADE_BASE_TAG}" "${RELEASE_TAG}" -- composer.json composer.lock && echo false || echo true),
"frontend_assets_included": true,
"deleted_files_manifest": "deleted-files.txt"
Expand Down
17 changes: 17 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,23 @@ The format is intentionally lightweight and release-friendly so entries can be r

## Unreleased

## [v2.1.4] - 2026-07-06

### Changed

- The release workflow now builds the incremental upgrade package from `v2.1.3` to `v2.1.4`.
- Upgrade manifests now derive their migration requirement from the actual release diff.

### Security

- Update announcement links now accept and render only browser-safe HTTP and HTTPS URLs, including for legacy records.
- Updated Laravel, Guzzle, PhpSpreadsheet, and Symfony dependencies to patched releases with no known Composer security advisories.

### Upgrade Notes

- No database migrations are required for this release.
- Run `php artisan optimize:clear` after deploying the updated application files.

## [v2.1.3] - 2026-05-27

### Changed
Expand Down
4 changes: 2 additions & 2 deletions app/Http/Controllers/UpdateController.php
Original file line number Diff line number Diff line change
Expand Up @@ -44,8 +44,8 @@ public function store(Request $request): RedirectResponse
$this->authorize('manage-updates');

$request->validate([
'description' => 'required|string',
'link' => 'nullable|url',
'description' => ['required', 'string', 'max:5000'],
'link' => ['nullable', 'url:http,https', 'max:255'],
]);

Update::create($request->only('description', 'link'));
Expand Down
13 changes: 13 additions & 0 deletions app/Models/Update.php
Original file line number Diff line number Diff line change
Expand Up @@ -23,4 +23,17 @@ class Update extends Model
'description',
'link',
];

/**
* Return only browser-safe external links, including for legacy records.
*/
public function safeExternalLink(): ?string
{
$link = trim((string) $this->link);
$scheme = strtolower((string) parse_url($link, PHP_URL_SCHEME));

return $link !== '' && in_array($scheme, ['http', 'https'], true)
? $link
: null;
}
}
Loading