JupyterLab v4.6.2

v4.6.2
Fixed 7
  • Fix resolving platform-specific shortcuts in keyboard shortcuts
  • Clear stale Table of Contents error markers
  • Fix stale document load after rename during initialization
  • Fix notebook initialization stealing focus
  • Fix spurious 3s kernel restart delay
  • Fix bottom activity bar restoring as collapsed
  • Handle invalid file browser drag target
Security 5
  • Fix image viewer XSS vulnerability when opening malicious image in new browser tab
  • Fix PyPI extension blocklist package-name canonicalization bypass
  • Fix PluginManager lock-rule enforcement bypass
  • Fix cross-site scripting (XSS) vulnerability via crafted settings file (overrides.json)
  • Fix allowlist/blocklist check in PyPIExtensionManager.install() not enforced for direct callers
4.6.2

(Full Changelog)

Security patches
  • GHSA-gx64-gj6p-pc4c: Image viewer allows XSS when opening malicious image in new browser tab
  • GHSA-89vp-jrxv-24w8: PyPI extension blocklist package-name canonicalization bypass
  • GHSA-h5v5-8746-g7mm: PluginManager lock-rule enforcement bypass
  • GHSA-pppj-hq3g-57pj: Cross-site scripting (XSS) via crafted settings file (overrides.json)
  • GHSA-whvh-wf3x-g77j: Allowlist/blocklist check in PyPIExtensionManager.install() not enforced for direct callers (missing await)
Bugs fixed
Maintenance and upkeep improvements
Documentation improvements
Other merged PRs
Contributors to this release

The following people contributed discussions, new ideas, code and documentation contributions, and review. See our definition of contributors.

(GitHub contributors page for this release)

@afshin (activity) | @GagandeepSingh20 (activity) | @jtpio (activity) | @krassowski (activity) | @MUFFANUJ (activity)

View original

Upgraded? How did it go?

Discussion