Skip to content

Latest commit

 

History

History
482 lines (395 loc) · 45.2 KB

CHANGELOG.md

File metadata and controls

482 lines (395 loc) · 45.2 KB

Change Log

Nothing.

Added

Nothing.

Changed

Nothing.

Fixed

  • decidim-comments, decidim-core, decidim-meetings: Backport "Fix timeout in comment view and during meetings" to v0.26 #9091
  • decidim-core: Backport "Dont add external link container inside editor" to v0.26 #9108
  • decidim-core: Backport "Add base URI to meta image URLs" to v0.26 #9153
  • decidim-initiatives: Backport "Remove 'edit link' in topbar for initiative's authors" to v0.26 #9239
  • decidim-elections: Backport 'Clarify message to user when checking census' to v0.26 #9240
  • decidim-participatory processes: Backport 'Fix processes count in processes group title cell' to v0.26 #9242
  • decidim-elections: Backport 'Improve wording when casting your vote' to v0.26 #9243
  • decidim-proposals: Backport 'Add 'not answered' as a possible answer in proposals' to v0.26 #9246
  • decidim-meetings: Backport 'Fix meetings minutes migration' to v0.26 #9247
  • decidim-assemblies, decidim-proposals: Backport "Fix absolute urls on 'assembly member' and 'collaborative drafts' events" to v0.26 #9248
  • decidim-accountability, decidim-consultations: Backport 'Fix components navbar in consultations mobile ' to v0.26 #9249
  • decidim-meetings: Backport 'Move modal to body and fix condition' to v0.26 #9250
  • decidim-meetings: Backport 'Do not send upcoming meeting notification for hidden or withdrawn meetings' to v0.26 #9251
  • decidim-core: Backport 'Show only current organization in verification conflicts with multitenants' to v0.26 #9252
  • decidim-elections: Backport 'Send email to newly added trustees' to v0.26 #9253
  • decidim-meetings: Backport 'Fix registration type field highlighted in admin meeting creation form' to v0.26 #9254
  • decidim-surveys: Backport 'Fix contradictory form errors on survey form' to v0.26 #9257
  • decidim-initiatives: Backport 'Add edit and delete actions in InitiativeType admin table' to v0.26 #9260
  • decidim-surveys: Backport 'Clarify unregistered answers on surveys behavior' to v0.26 #9261
  • decidim-elections: Backport 'Fix voting with single election' to v0.26 #9262
  • decidim-initiatives: Backport 'Fix initiative print link, margin, and organization logo' to v0.26 #9263
  • decidim-elections: Backport 'Remove show more button on elections' to v0.26 #9264
  • decidim-surveys: Backport 'Fix survey activity log entries' to v0.26 #9265
  • decidim-budgets: Backport 'Remove beforeunload confirmation panel from the budgets voting' to v0.26 #9266
  • decidim-admin, decidim-elections: Backport 'Fix newsletters and Decidim Votings' to v0.26 #9258
  • decidim-core: Backport 'Fix notifications where resources are missing' to v0.26 #9256
  • decidim-core: Backport 'Enforce password validation rules on 'Forgot your password?' form' to v0.26 #9245
  • decidim-core: Backport 'Fix displaying blocked users in account follow pages' to v0.26 #9255
  • decidim-core: Backport 'Fix Leaflet trying to load "infinite amount of tiles"' to v0.26 #9269
  • decidim-system: Backport 'Enforce password validation rules on system admins' to v0.26 #9259
  • decidim-meetings: Backport 'Remove presenters in the meetings admin backoffice' to v0.26 #9323
  • decidim-elections: Backport 'Correctly show trustees and votings menu' to v0.26 #9324
  • decidim-core: Backport 'Fix hashtag parsing on URLs with fragments' to v0.26 #9326
  • decidim-comments, decidim-core: Backport 'Add missing events locales' to v0.26 #9327
  • decidim-conferences: Backport 'Make conference's partners logos always mandatory' to v0.26 #9328
  • decidim-admin: Backport 'Fix margin around warning message in colour settings' to v0.26 #9329
  • decidim-elections: Backport 'Hide more information link when there's no description on an election' to v0.26 #9331
  • decidim-admin, decidim-assemblies, decidim-budgets, decidim-core, decidim-elections, decidim-meetings, decidim-pages, decidim-proposals: Backport 'Apply crowdin feedback' to v0.26 #9333
  • decidim-comments, decidim-core: Backport 'Don't show deleted resources in last activities ' to v0.26 #9330
  • decidim-elections: Backport 'Fix election label translations' to v0.26 #9343
  • decidim-verifications: Backport 'Allow to renew expired verifications (if renewable)' to v0.26 #9344
  • decidim-elections: Backport 'Add error message when adding question and election has started' to v0.26 #9404
  • decidim-core: Backport 'Fix user interests' to v0.26 #9406
  • decidim-elections: Backport 'Fix regular expression on census check' to v0.26 #9408
  • decidim-elections: Backport 'Enforce YYYYmmdd format in birthdate when uploading census' to v0.26 #9410
  • decidim-consultations: Backport 'Return 404 when there isn't a question' to v0.26 #9414
  • decidim-consultations: Backport 'Return 404 when there isn't a consultation' to v0.26 #9413
  • decidim-elections: Backport 'Return 404 when there isn't a voting in elections_log' to v0.26 #9415
  • decidim-proposals: Backport 'Fix proposals creation with Participatory Texts ' to v0.26 #9416
  • decidim-elections: Backport 'Fix ActionLog when a ballot style is deleted' to v0.26 #9411
  • decidim-elections: Backport 'Only show that the code can be requested via SMS if its true' to v0.26 #9409
  • decidim-budgets, decidim-proposals: Backport 'Add missing translation keys proposals import and proposals picker' to v0.26 #9412
  • decidim-elections: Backport 'Fix HTML safe content in election voting' to v0.26 #9405
  • decidim-core: Backport 'Fix for internal links not displaying on page title' to v0.26 #9407

Removed

Nothing.

Internal

  • Backport 'Fix generators specs target branch' to v0.26 #9290

Developer improvements

Nothing.

Added

Nothing.

Changed

Nothing.

Fixed

  • decidim-meetings: Backport "Fix the meetings export to also include unpublished meetings" to v0.26 #8939
  • decidim-system, decidim-verifications: Backport "Fix verification report with multitenants" to v0.26 #8940
  • decidim-core: Backport "Fix officialized user event missing translations" to v0.26 #8942
  • decidim-verifications: Backport "Fix email for verification conflict with managed users" to v0.26 #8945
  • decidim-core: Backport "Fix profile notifications" to v0.26 #8949
  • decidim-assemblies, decidim-budgets, decidim-comments, decidim-consultations, decidim-core, decidim-elections, decidim-forms, decidim-initiatives, decidim-participatory processes, decidim-proposals: Backport several accessibility fixes to v0.26 #8950
  • decidim-core: Backport "Add missing 'Locale' string in i18n in account page" to v0.26 #8980
  • decidim-meetings: Backport "Truncate the meetings card description" to v0.26 #8979
  • decidim-proposals: Backport "Fix proposals' cards with big images" to v0.26 #8978
  • decidim-initiatives: Backport "Fix link to docs in initiatives admin" to v0.26 #8975
  • decidim-comments: Backport "Fix budget hard dependency and caching flag issues in comments" to v0.26 #8973
  • decidim-participatory processes: Backport "Fix processes creation form with stats, metrics and announcements" to v0.26 #8977
  • decidim-initiatives: Backport "Show signatures in answered initiatives" to v0.26 #8991
  • decidim-core: Backport "Add missing reveal__title classes" to v0.26 #8999
  • decidim-core: Backport "Remove the label from the dropdown menu opener" to v0.26 #9002
  • decidim-core: Backport "Fix mobile nav keyboard focus" to v0.26 #9001
  • decidim-core: Backport "Fix main navigation aria-current attribute" to v0.26 #9000
  • decidim-core: Backport "Show character counter when replying to message" to v0.26 #9003
  • decidim-core: Backport "Fix character counter with emoji picker close to maximum characters" to v0.26 #9012
  • decidim-api, decidim-assemblies, decidim-conferences, decidim-consultations, decidim-initiatives, decidim-meetings, decidim-participatory processes, decidim-proposals: Backport "Fix API when meetings have proposal linking disabled" to v0.26 #8992
  • decidim-core: Backport "Fix Devise flash messages translation" to v0.26 #9043
  • decidim-core: Backport "Disable new conversation next button when no users selected" to v0.26 #9054
  • decidim-initiatives: Backport "Fix initiatives signatures issues" to v0.26 #8974
  • decidim-blogs, decidim-core, decidim-debates, decidim-proposals: Backport "Fix for endorsed_by with other user group's member" to v0.26 #9062
  • decidim-proposals: Backport "Fix footer actions caching on proposals' card" to v0.26 #9063
  • decidim-admin: Backport "Add missing 'Locale' string in i18n in selective newsletter" to v0.26 #9064
  • decidim-core: Backport "Fix social share button sharing" to v0.26 #9065
  • decidim-meetings: Backport "Use published meetings scope on processes landing and proposal's form" to v0.26 #9066
  • decidim-core: Backport "Require omniauth/rails_csrf_protection explicitly" to v0.26 #9067
  • decidim-core, decidim-proposals: Backport "Fix amendable events title" to v0.26 #9079
  • decidim-proposals: Backport "Create admin log records when proposals are imported from a file" to v0.26 #9077
  • decidim-comments, decidim-core, decidim-proposals: Backport "Add noreferrer and ugc to links" to v0.26 #9078
  • decidim-meetings: Backport "Fix submit in meetings admin form" to v0.26 #9076
  • decidim-core: Backport "Fix session cookie SameSite policy" to v0.26 #9059
  • decidim-budgets, decidim-core, decidim-debates, decidim-meetings, decidim-proposals: Backport "Fix cache URLs on cards" to v0.26 #9074
  • decidim-assemblies, decidim-conferences, decidim-consultations, decidim-core, decidim-initiatives, decidim-participatory processes: Backport "Fix Twitter hashtag search when it starts with a number" to v0.26 #9075

Removed

Nothing.

Internal

  • Backport "Fix ActionMailer preview loading" to v0.26 #8963
  • Backport "Fix flaky spec in meetings multi-date selectors" to v0.26 #8976
  • Backport "Local HTML validator for the CI" to v0.26 #9004
  • Backport "Fix API when meetings have proposal linking disabled" to v0.26 #8992

Developer improvements

  • Backport "Fix Devise configs that depend on Decidim configs" to v0.26 #9022
  • Backport "Fix Faker address country code in seeds" to v0.26 #9046

Added

Nothing.

Changed

  • decidim-comments: Backport "Show hidden comments replies" to v0.26 #8868

Fixed

  • decidim-proposals: Backport "Fix geocoding NaN values" to v0.26 #8778
  • decidim-core: Backport "Add 'nofollow noopener' rel to the profile personal URL" to v0.26 #8780
  • decidim-generators: Backport "Add .keep file to empty directory to include on git committing" to v0.26 #8788
  • decidim-core: Backport "Fix avatar upload validation errors are displayed twice" to v0.26 #8798
  • decidim-meetings: Backport "Fix displaying hidden meetings in homepage's 'upcoming meetings' content block" to v0.26 #8819
  • decidim-participatory processes: Backport "Fix characters not encoded in highlighted participatory processes groups title" to v0.26 #8824
  • decidim-comments: Backport "Fix displaying hidden related resources" to v0.26 #8835
  • decidim-generators: Backport "Add natively a .keep file to empty directory to include on git committing" to v0.26 #8836
  • decidim-consultations, decidim-core, decidim-elections: Backport "Fix report moderation for all the spaces" to v0.26 #8841
  • decidim-meetings, decidim-participatory processes: Backport "Fix displaying hidden meetings in show process page" to v0.26 #8843
  • decidim-meetings: Backport "Fix displaying hidden resources in global search" to v0.26 #8850
  • decidim-core: Backport "Fix activity cell disappearing author images" to v0.26 #8848
  • decidim-initiatives: Backport "Fix scope validation on initiative's creation" to v0.26 #8857
  • decidim-accountability: Backport "Fix accountability categories' colors" to v0.26 #8858
  • decidim-debates: Backport "Remove actions from debates' cards" to v0.26 #8861
  • decidim-assemblies: Backport "Fix assemblies title when there are unpublished children" to v0.26 #8860
  • decidim-core: Backport "Fix cache_hash generation in AuthorCell" to v0.26 #8862
  • decidim-meetings, decidim-participatory processes: Backport "Fix displaying hidden meetings in processes group's 'upcoming meetings' content block" to v0.26 #8864
  • decidim-assemblies, decidim-conferences, decidim-consultations, decidim-proposals: Backport "Fix notifications when there is a note proposal in other spaces than processes" to v0.26 #8865
  • decidim-proposals: Backport "Fix answered proposals display" to v0.26 #8863
  • decidim-comments: Backport "Show hidden comments replies" to v0.26 #8868
  • decidim-meetings: Backport "Fix meetings iframe embed code" to v0.26 #8884

Removed

Nothing.

Internal

  • Backport "Fix flaky test in UpdateAssemblyMember" to v0.26 #8803

Developer improvements

Nothing.

Added

Nothing.

Moderated content can now be removed from search index

PR #8811 is addressing an issue when the moderated resources are not removed from the general search index.

This will automatically work for new moderated resources. For already existing ones, we have introduced a new task that will remove the moderated content from being displayed in search:

bin/rails decidim:upgrade:moderation:remove_from_search

Default Decidim app fully configurable via ENV vars

Changed

Nothing.

Fixed

  • decidim-meetings: Backport "Fix for preview unpublished meetings by admin user" to v0.26 #8724
  • decidim-comments: Backport "Adds emojis when user edits a comment" to v0.26 #8743
  • decidim-core: Backport "Properly mark sender and recipient in Conversation" to v0.26 #8746
  • decidim-participatory processes: Backport "Fix order by weight in processes groups' processes content block" to v0.26 #8771
  • decidim-core: Backport "Don't display blocked users in mentions" to v0.26 #8770

Removed

Nothing.

Internal

  • Backport "Revert the i18n-tasks initialization syntax" to v0.26 #8696
  • Backport "Lock graphql version to 1.12 minor" to v0.26 #8695
  • Disable codeclimate's stylelint #8711

Developer improvements

  • Backport "Fix webpacker generator for modules" to v0.26 #8750

Migration notes

Register assets paths

To prevent Zeitwerk from trying to autoload classes from the app/packs folder, it's necesary to register these paths for each module and for the application using the method Decidim.register_assets_path on initializers. This is explained in the webpacker migration guides for applications and modules), and was implemented in #8449.

Unconfirmed access disabled by default

As per #8233, by default all participants must confirm their email account to sign in. Implementors can change this setting as a initializer configuration:

Decidim.configure do |config|
  config.unconfirmed_access_for = 2.days
end

User workflows change to prevent user enumeration attacks

Until now it was possible to see if an email account was registered in Decidim, by using features like "Forgot your password", as the response changed if the email existed ("You will receive an email with instructions on how to reset your password in a few minutes") that's different to a non-existing user account ("could not be found. Did you sign up previously?"). This allows User Enumration attacks, where a malicious actor can check if anyone has an acount in the platform. As per #8537, anyone has the same answer always "If your email address exists in our database, you will receive a password recovery link at your email address in a few minutes".

Blocked user in global search

PR #8658 Blocked users are present in global search, to update the search and make them disappear, Run in a rails console or create a migration with:

  Decidim::User.find_each(&:try_update_index_for_search_resource)

Please be aware that it could take a while if your database has a lot of Users.

Fix statistics in Comments

As per #8012, for fixing statistic in comments. There's a rake task that you need to run:

rake decidim_comments:update_participatory_process_in_comments

Base64 images migration

As per #8250, we've replaced the default base64 editor images attachment with the use of ActiveStorage attachments. This PR also adds a task to parse all editor contents and replace existing base64 images with attachments. The task parses all the attributes which can be edited from admin using the WYSIWYG editor. The task requires an argument with the email of an admin used to create EditorImage instances. To run this task execute:

rails decidim:active_storage_migrations:migrate_inline_images_to_active_storage[admin_email]

Added

  • decidim-budgets: Port decidim-budgets improvements from AjuntamentdeBarcelona/decidim #8249
  • decidim-elections: Improve evote admin logs #8263
  • decidim-blogs, decidim-meetings: Add card images to meetings and blog posts #8276
  • decidim-admin: Align UI groups filtering with the rest of decidim #8105
  • decidim-admin, decidim-proposals: Improve error messages in admin panel #8193
  • decidim-elections: Allow to mark trustees as missing #8314
  • decidim-admin: Add sorting to private participants in a participatory space #8242
  • decidim-comments: Improve control of comments in meetings and debates #8027
  • decidim-proposals: Offer a way to see all proposals in withdrawn proposal list #8251
  • decidim-admin, decidim-proposals: Configurable default order for proposals #8295
  • decidim-assemblies: Filter assemblies by assembly type in admin #7153
  • decidim-assemblies: Non participant assembly members avatar #8277
  • decidim-core: Add image file upload in QuillJS editor #8250
  • decidim-meetings: Make meeting report editable by the author in front-end #8209
  • decidim-core: Improve dialog accessibility #8294
  • decidim-meetings: Ability for users to withdraw their meetings #8248
  • decidim-admin: Add colors accessibility warning in admin Appearance #8354
  • decidim-proposals: Import proposal answers #8271
  • decidim-core: Add more actions in QuillJS toolbar #8120
  • decidim-meetings: Add more filter options to directory meetings page #8333
  • decidim-assemblies, decidim-conferences, decidim-participatory processes: Add filters for Participatory process admins section #8106
  • decidim-budgets: Show modal when user is trying to leave with pending vote #8387
  • decidim-meetings: Meetings iframe visibility #8307
  • decidim-budgets: Add search, filters and sorting to admin panel budget projects #8592
  • decidim-core: Describe the notifications' time with words #8564
  • decidim-comments, decidim-core: Add link to comments in Notifications #8607
  • decidim-comments, decidim-core: Add full content of comments in notifications #8581
  • decidim-core: Change colors on mobile navigation bar #8628
  • decidim-core, decidim-proposals: Add author to proposals in notifications #8603
  • decidim-comments, decidim-core, decidim-meetings, decidim-proposals: Allow participants to receive translated content by email #8174
  • decidim-admin: Add search, filters, pagination and sorting to moderated users #8620
  • decidim-surveys: Add "title and description" in surveys #8588

Changed

  • decidim-elections: Validate census CSV headers #8264
  • decidim-meetings: Improve Attendees count error handling on frontend #8238
  • decidim-core: Disable unconfirmed access by default #8233
  • decidim-meetings: Rename 'upcoming events' content block to 'upcoming meetings' #8412
  • decidim-core: Change user workflows to prevent user enumeration attacks #8537

Fixed

  • decidim-accountability: Fix accountability notifications proposal title #8240
  • decidim-elections: Remove white spaces in Census #8262
  • decidim-debates, decidim-meetings, decidim-proposals: Fix characters not encoded in title #8253
  • decidim-proposals: Fix flaky test on proposals splitting #8302
  • decidim-core: Fix invalid i18n values for diff changeset #8299
  • decidim-meetings: Fix live? missing method delegation in online_meeting cell #8241
  • decidim-comments: Fix statistics in Comments #8012
  • decidim-budgets: Fix some explore budgets specs #8303
  • decidim-core: Fix missing icons after CORS #8290
  • decidim-core: Remove unnecessary spacer from external link indicator #8291
  • decidim-core: [CVE-2021-22942] Possible Open Redirect in Host Authorization Middleware #8265
  • decidim-debates: Fix "last comment by" when commenter is a user group #8279
  • decidim-proposals: Similar proposal functionality breaks when the machine translation is enabled. #8098
  • decidim-core: Fix regex that parses users and groups references inside content. #8297
  • decidim-assemblies: Fix birthday attribute type in Assembly Members #8311
  • decidim-comments: Fix issues with dynamic comments polling #8317
  • decidim-assemblies: Fix "Edit" and "View public page" in Assembly Members #8312
  • decidim-comments: Fix "View all comments" link in single comment page #8308
  • decidim-budgets: Fix dont allow budget exceeding in project view #8261
  • decidim-debates: Fix title meta tag for debates #8323
  • decidim-proposals: Fix UserAnswersSerializer for CSV exports #8329
  • decidim-admin: Do not block registered users with InviteUserAgain #8268
  • decidim-conferences: Fix error when accessing the meetings of a conference with speakers related #8369
  • decidim-conferences: Fix details on conference speakers: affiliation order, personal URL link, seeds and more info link #8378
  • decidim-meetings: Define localized fields in Decidim::Meetings:DiffRenderer #8381
  • decidim-core: Include only public entities in the following page #8361
  • decidim-proposals: Any user can access proposal's pages representing the "create a proposal" steps #8390
  • decidim-core: Fix localized faker with single locale #8394
  • decidim-core: Fix user activity page error message with missing username #8403
  • decidim-core: Fix conversation with deleted account #8409
  • decidim-core: Fix javascript exception when geocoding proposals is disabled #8413
  • decidim-blogs: Add missing translations #8426
  • decidim-comments: Refresh comments component after updating #8362
  • decidim-core: Fix webpacker issue when using zeitwerk #8444
  • decidim-core: Improve Zeitwerk assets paths to ignore #8449
  • decidim-surveys: Fix notification after creating survey #8463
  • decidim-budgets, decidim-comments: Fix comment's get link in project view #8450
  • decidim-elections: Fix report missing trustee admin log entry #8468
  • decidim-system: Add pptx in allowed_file_extensions (of admin) #8502
  • decidim-core: Fix 404 link in 'how to participate' home content block #8513
  • decidim-meetings: Fix meetings with multiple dates #8497
  • decidim-core: Fix pt-BR issue #8523
  • decidim-generators: Freezing webpacker to RC.5 until RC.7 is fixed #8531
  • decidim-conferences: Fix conference speakers when there isn't any avatar #8520
  • decidim-assemblies, decidim-participatory processes: Fix the copy of components weights in participatory processes and assemblies #8498
  • decidim-meetings: Fix meetings input when rich text editor is disabled #8534
  • decidim-meetings: Fix showing created meetings in 'my public profile' #8519
  • decidim-meetings, decidim-proposals: Fix various proposal picker issues when there are thousands of proposals #8558
  • decidim-core: Remove border on all the fieldsets #8561
  • decidim-initiatives: Remove wrong in initiatives header #8563
  • decidim-core: Fix CSS layout wrapper top padding #8562
  • decidim-forms, decidim-surveys: Fix duplicated answers in surveys #8560
  • decidim-meetings: Fix the meeting copy functionality #8430
  • decidim-core: Move social login buttons to the top of the login modal #8574
  • decidim-comments, decidim-meetings: Fix HTML injection in comments and meeting's description #8511
  • decidim-core: Fix avatar thumbnail in participants' profile #8577
  • decidim-core: Rename index to avoid conflicts with decidim_awesome module migrations #8613
  • decidim-core: Fix group mentions in notifications #8598
  • decidim-forms, decidim-surveys: Fix surveys exports with free text in multiple option #8582
  • decidim-core: Fix reply to a conversation with deleted participants #8635
  • decidim-admin, decidim-debates, decidim-proposals: Fix consistency in creation actions phrasing: "Participants can create XXX" #8650
  • decidim-core: Fix wrong display of deleted accounts in conversations #8641
  • decidim-core: Fix cache key on ActivityCell #8654
  • decidim-participatory processes: Fix participatory groups leaks on other organizations/tenants #8651
  • decidim-core: Fix blocked users appear in search #8658
  • decidim-meetings: Don't start poll meetings component when DOM elements are not present #8676
  • decidim-initiatives, decidim-proposals: Fix initiative attachments #7452
  • decidim-assemblies: Fix performance issues on assemblies page when having many private users #8509
  • decidim-proposals: Add location data to proposals export and import #8679
  • decidim-meetings: Fix meetings form embed type visibility #8602
  • decidim-meetings: Do not send upcoming meeting events notification for past events #8665

Removed

  • decidim-proposals: Remove "Allow card image" setting from Proposals #8281
  • decidim-assemblies: Remove designation_mode field from Assembly Members #8310
  • decidim-participatory processes: Remove admin show page in Participatory Process Groups #8313

Developer improvements

  • Fix Luxembourgish locale #8270
  • Fix ARIA roles for dialogs and tooltips #8293
  • Add selectors on edit_form_fields #8353
  • Fix HTTPOnly and secure flag on the cookie acceptance cookie #8358
  • Add Brakeman to GitHub Actions for improving security #6832
  • Disallow redirection to the host when performing redirect_back #8296
  • Improve performance on the serializers by using includes, query counter #8278
  • Enforce redirects to include the organization host #8385
  • Fix issues with the session/environment security configs #8360
  • Improve extendability on some controllers #8398
  • Add avatar eager logging to UserEntityFinder #8416 #8417
  • Increase text contrast in current phase of a participatory process #8422
  • Fix CVE-2021-41136 (HTTP Request Smuggling in puma) #8431
  • Remove anchored dependency #8453
  • Fix pt-BR issue #8523
  • Add rendered view instrumentation information #8530
  • Optimize open data exporter for large amount of data #8503
  • Add cache key separator to cache_hash #8559
  • Improve generation of the opendata export #8593
  • Add several cache keys to cells #8566
  • Update password strength check #8455
  • Remove etherpad-lite dependency #8541
  • Fix Rack::Attack initializer custom parameter configuration #8643

Internal

  • Fix dependencies locks after 0.26.0.dev bump #8247
  • Add modules recommendations in documentation #8218
  • Fix webpacker dependency lock #8272
  • Improve README with examples #8244
  • Update foundation-sites to 6.7.0 for better Dart Sass compatibility #8273
  • Fix NPM packages versioning during release process #8280
  • Add 'Lint PR title' workflow to CI #8285
  • Don't trigger PR linting on pushes, only on PRs #8304
  • Prevent root package.json to be treated as a package #8315
  • Fix CSS validation tests caused by a bug on the validation service #8322
  • decidim-core: Remove npm decidim packages with dependencies from other decidim packages #8330
  • decidim-core: Fix problems introduced by #8330 #8341
  • Update Node and NPM version #8343
  • Remove hack for CSS validation #8326
  • Update docs in migrating to webpacker #8349
  • decidim-comments: Ignore errors during comments migration task #8351
  • decidim-meetings: Fix published and title in seeded meetings #8359
  • decidim-core: Fix SQL to make version display faster #8393
  • Remove GraphQL deprecated API call #8432
  • decidim-generators: Fixing generator webpacker issues #8427
  • decidim-generators: Fix railties requirements on created applications #8415
  • decidim-core: Update omniauth gem and dependencies #8388
  • Document how to enable machine translations on organization #8458
  • decidim-dev: Improves manual installation documentation #8508
  • Update the i18n-tasks initialization syntax #8544
  • Documentation: improve develop section #8553
  • Change default window size in Capybara configuration #8576
  • Fix security instructions #8587
  • Temporarily ignore CSS validation issue in CI #8597
  • Update nokogiri to 1.12.5 #8609
  • Update paper_trail to 12.1 #8608
  • Update ruby to 2.7.5 #8629
  • Remove truncato dependency #8507
  • Change figaro to rbenv-vars in "manual installation" documentation #8575
  • Add instructions PostgreSQL configuration in development app #8618
  • Fix etherpad doc reference in initializer #8632
  • Clarifies git branches conventions in doc #8644
  • Fix changelog link #8671
  • Enable simplecov only for rspec step #8674
  • decidim-dev: Improve machine translation documentation and comments #8668
  • Split the workflows files for CI #8675
  • DRY GitHub workflows with composite actions #8677
  • Change Gitter to Matrix.org in documentation #8466

Previous versions

Please check release/0.25-stable for previous changes.