Skip to content

v2.11.17

Compare
Choose a tag to compare
@waiting-for-dev waiting-for-dev released this 15 Jul 11:58
86b70ac

Breaking changes

NOTE: This release contains a breaking change due to the backport of the fixes for CVE-2022-32224 in #4455, specifically due to the switch to YAML.safe_load in Spree::LogEntry here.

To ensure compatibility with this change, you may need to update your app configuration for Spree::AppConfiguration#log_entry_permitted_classes and ensure it includes any constants that may be serialized in YAML in addition to the already allowed ones by core or any extensions you may use.

What's Changed

Full Changelog: v2.11.16...v2.11.17