Liquibase Community 5.0.4 Release

This one’s a security release, and it’s a meaty one. Credentials are now redacted from error messages and logs, passwords get cleared from memory once we’re done with them, and there are new opt-in lockdown flags if you’re running ChangeLogs from less-trusted sources. We also closed off an XML entity trick and fixed a reflected XSS vulnerability in the status servlet.

:raising_hands: Thank You, Contributors

29 people contributed to this release, 23 of them for the first time. Thank you for filing issues, submitting PRs, testing, and reviewing! Couldn’t do any of this without that.

Full details, including 30+ fixes across Oracle, PostgreSQL, MySQL/MariaDB, and diff-changelog, are in the release notes.

Release notes

Get the latest version