Update quay.io/hedgedoc/hedgedoc Docker tag to v1.10.1

No problems upgrading the Docker container with a Docker compse yaml file within Portainer and by means of Watchtower DevOps with dependency update facilitated by Mend's Renovate Bot.

This MR contains the following updates:

Package Update Change
quay.io/hedgedoc/hedgedoc (source) patch 1.10.0 -> 1.10.1

Release Notes

hedgedoc/hedgedoc (quay.io/hedgedoc/hedgedoc)

v1.10.1: HedgeDoc 1.10.1

Compare Source

This release fixes a security issue where brute-forcing local email/passwords is possible because of missing rate-limits.
We recommend upgrading as soon as possible, if you use local logins.

See also https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-6w39-x2c6-6mpf

This release changes the default configuration of the HSTS preload attribute to false for compliance with the
HSTS preload list requirements. This shouldn't impact any instance. However, if you intend to use HSTS preloading
you should enable the config setting hsts.preload to true or set environment variable CMD_HSTS_PRELOAD=true.

This release deprecates support for Node 18.
As the LTS support for 18 runs out in April 2025, the next release will only work with Node 20 and upwards.
Consider this your early warning to upgrade any running instances to at least Node 20.

Enhancements
  • Add fixed rate-limiting to the login and register endpoints
  • Add configurable rate-limiting to the new notes endpoint
Bugfixes
Contributors