Nautobot
Network source of truth and network automation platform
Nautobot patched the same permissions hole on both branches, then spent the release making the UI usable without sight.
◆Recent moves
- 1d ago
Accessibility pass lands beside a legacy-endpoint permissions fix
The advisory fix closes object-level permission enforcement on the legacy console-connection and power-connection endpoints, extending the authorization sweep that has driven this whole release line into the compatibility corners of the API. The accessibility batch alongside it is new to the arc: keyboard bypass links, live regions so HTMX-injected messages are announced, alt content for rack elevation SVGs, and contrast-measured badge colors.
View source ↗ - 1d ago
Same permissions advisory backported to the 2.4 branch
The 2.4 branch takes the same advisory within a minute of its 3.2 twin, covering one endpoint more — interface-connections. The accompanying documentation updates spell out which permissions should stay with highly trusted users and how Secrets access becomes privilege escalation, continuing the pattern of patching expectations alongside code.
View source ↗ - 15d ago
Cable termination filter and GraphQL OpenTelemetry corrections
A broad fix release covering the fallout of the 3.2 cable data model change, GraphQL telemetry that recorded API-token requests as anonymous, and a scheduler that silently produced no JobResult when no worker was running. Repair work on the surfaces 3.2.0 rearranged.
View source ↗ - 15d ago
Many-to-many change logging and GitRepository sync permissions
The 2.4 counterpart of the same day, carrying the many-to-many change-logging fix and closing a GitRepository sync endpoint that skipped object-level restrictions. Both branches were treated as first-class recipients of the same corrections.
View source ↗ - 21d ago
Public API constants and a widened cryptography range
Two constants promoted into the public apps API and a widened cryptography range to unblock apps that had not moved to v49. Housekeeping in service of the ecosystem rather than the core.
View source ↗ - 23d ago
REST API permission enforcement on related objects; job_kwargs required
The release that set this cycle's terms: CVE fixes that break REST and GraphQL clients, required job_kwargs on job execution APIs, and device component foreign keys that now resolve through module bays. Nautobot chose correct authorization over compatibility and told operators to expect TypeErrors.
View source ↗