HedgeDoc
Open-source collaborative Markdown note editor for real-time team writing.
A collaborative markdown editor on a security-driven maintenance cadence.
◆Recent moves
- 21d ago
HedgeDoc 1.12.0
1.12.0 raises the floor to Node 20.17 now that Node 18's security support has lapsed, and prunes some highlight.js languages. The substantive change continues the realtime thread — several connection-handling bugs could cost users on flaky links their edits — and login now skips the modal when exactly one external provider is configured.
View source ↗ - 1mo ago
HedgeDoc 1.11.1
A permission-validation advisory is fixed, and the external-link warning added one release earlier gains both a whitelist and an off switch. Webp uploads arrive, and the old Temp database object and its endpoints are deleted — the same trim-the-surface habit visible across the line.
View source ↗ - 2mo ago
HedgeDoc 1.11.0
Four advisories land at once — HTML injection, a YAML frontmatter denial of service, CSRF in the Gist export, and a rate-limit bypass via CF-Connecting-IP — with a config flag operators behind Cloudflare must set for rate limiting to work correctly. The heaviest security release in the run.
View source ↗ - 4mo ago
HedgeDoc 1.10.8
Fixes data loss when five or more users edit concurrently, caused by the operational-transform client discarding operations during revision gap recovery. For a tool whose premise is simultaneous editing, this is the most consequential bug in the run.
View source ↗ - 6mo ago
HedgeDoc 1.10.7
Small correctness fixes: cursor colours pinned to hex to avoid conversion errors, realtime connections closed properly when they drop mid-handshake, and the manage_users CLI no longer swallowing errors.
View source ↗ - 7mo ago
HedgeDoc 1.10.6
Two medium-severity fixes covering security headers on uploaded files and limited script execution in uploaded SVGs. Uploads recur as a weak point across this line, and both advisories came from outside reporters.
View source ↗