Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      rel #41834 16.9
    Details
    Manuel Vacelet (vaceletm)
    16.9
    Schedule
    2025-05-22
    19 (2025-06-18 00:00)


    Delivered
    Contents
    Referencing rel #41834

    Artifact

    request #42976 Clear sensitive information of deleted users
    request #42977 Harden CSRF protection by blocking all cross-site state modifying queries to the Web UI
    request #42980 Library jquery 1.9.1 is vulnerable
    request #42982 Fixable Sass deprecations
    request #42984 Be able to save the new/edited query without searching for the result before in XTS widget
    request #42988 Program increments are not synchronized when adding a team
    request #42997 stylelint-config-recommended: 14.0.0 -> 16.0.0, stylelint-config-standard-scss: 13.0.0 -> 15.0.1
    request #43305 Password should not be requested when creating an account linked to an OIDC provider
    request #43311 Migrate document test from jest to vitest
    request #43313 Wasmtime: 31.0.0 -> 33.0.0
    request #43314 Document app themes should be in same package
    request #43317 Migrate js document files to ts
    request #43319 Migrate PriorityDao to EasyDB
    request #43321 Impossible to open documents with an extension in uppercase in OnlyOffice
    request #43323 Replace "artéfact" by "artifact"
    request #43324 patches.md documentation is not up to date
    request #43325 Introduce a CLI command to unlink user from providers
    request #43327 Scan for secrets in Tuleap source code
    request #43328 Broken artifact tooltip when linking sprint
    request #43329 Split XTS select query in multiple queries
    request #43332 Add Clément Gayot to contributors list
    request #43335 stylelint-config-recommended-vue: 1.5.0 -> 1.6.0
    request #43340 Tooltips are not shown anymore in Gantt
    request #43343 Angular: ignore CVE-2025-2336
    request #43344 Artifact link field check update permission even if no changes
    request #43345 Error when SQL query is built in Cross Tracker Search
    request #43346 browserslist: 4.23.1, 4.24.4 -> 4.25.0, autoprefixer: 10.4.18 -> 10.4.21
    request #43347 Do not crash when trying to access raw file content with invalid parameters
    request #43348 Do not crash when creating or updating widgets with incorrect parameters
    request #43349 Do not crash when accessing the password reset form with invalid parameter
    request #43351 User cannot create a Kanban if Backlog has not been installed first
    request #43352 Inform Admins we only work with One SQL mode
    request #43353 github.com/cloudflare/circl: 1.5.0 -> 1.6.1
    request #43354 brace-expansion: 1.1.11 -> 1.1.12, 2.0.1 -> 2.0.2
    request #43355 Drop redundant JS polyfills [2025 W24]
    request #43357 Missing CSRF protection on tracker reports manipulation
    request #43359 Go: ignore CVE-2025-22874, CVE-2025-0913, CVE-2025-4673
    request #43360 Duplicating artifact not in planning add the new artifact in backlog
    request #43362 Missing assets in semantic done config page

    Follow-ups