From 60d368f7ed5fad094c72aede8fca647bebc79183 Mon Sep 17 00:00:00 2001 From: Hayden <8418760+Hayden-IO@users.noreply.github.com> Date: Wed, 21 Jan 2026 15:24:59 -0800 Subject: [PATCH 1/2] Changelog for v1.5.0 Signed-off-by: Hayden <8418760+Hayden-IO@users.noreply.github.com> --- CHANGELOG.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8306adc45..fb9b9b29f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,17 @@ +# v1.5.0 + +This release fixes GHSA-273p-m2cw-6833 and GHSA-4c4x-jm2x-pf9j. Note that this +drops support for fetching public keys via URL when querying the search API. + +## Vulnerability Fixes + +* Handle malformed COSE and DSSE entries (#2729) +* Drop support for fetching public keys by URL in the search index (#2730) + +## Features + +* Add support for a custom TLS config for clients (#2709) + # v1.4.3 This release reduces dependencies for a number of exported packages. From 204d5fd1320a1ba2d0d19902e3bcf4f67c42ca95 Mon Sep 17 00:00:00 2001 From: Hayden <8418760+Hayden-IO@users.noreply.github.com> Date: Wed, 21 Jan 2026 15:31:35 -0800 Subject: [PATCH 2/2] Update CHANGELOG.md Signed-off-by: Hayden <8418760+Hayden-IO@users.noreply.github.com> --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index fb9b9b29f..0c169c681 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ drops support for fetching public keys via URL when querying the search API. ## Vulnerability Fixes * Handle malformed COSE and DSSE entries (#2729) -* Drop support for fetching public keys by URL in the search index (#2730) +* Drop support for fetching public keys by URL in the search index (#2731) ## Features