diff --git a/changelog/8.19.19.asciidoc b/changelog/8.19.19.asciidoc new file mode 100644 index 0000000000..d121f36f41 --- /dev/null +++ b/changelog/8.19.19.asciidoc @@ -0,0 +1,31 @@ +// begin 8.19.19 relnotes + +[[release-notes-8.19.19]] +== 8.19.19 + +Review important information about the 8.19.19 release. + +[discrete] +[[security-updates-8.19.19]] +=== Security updates + + + + +* Enforce policy-based access control on artifact downloads. https://github.com/elastic/fleet-server/pull/7164[#7164] + + + + + + + + + + + + + + + +// end 8.19.19 relnotes diff --git a/changelog/8.19.19.yaml b/changelog/8.19.19.yaml new file mode 100644 index 0000000000..b832e12f3d --- /dev/null +++ b/changelog/8.19.19.yaml @@ -0,0 +1,15 @@ +version: 8.19.19 +entries: + - kind: security + summary: Enforce policy-based access control on artifact downloads + description: "" + component: fleet-server + pr: + - https://github.com/elastic/fleet-server/pull/7164 + issue: [] + impact: "" + action: "" + timestamp: 1778540235 + file: + name: 1778540235-fix-artifact-access-control.yaml + checksum: edad22f9232befcd82915193120bb892a3fc4c6c diff --git a/changelog/fragments/1778540235-fix-artifact-access-control.yaml b/changelog/fragments/1778540235-fix-artifact-access-control.yaml deleted file mode 100644 index f6ef4aeb60..0000000000 --- a/changelog/fragments/1778540235-fix-artifact-access-control.yaml +++ /dev/null @@ -1,32 +0,0 @@ -# Kind can be one of: -# - breaking-change: a change to previously-documented behavior -# - deprecation: functionality that is being removed in a later release -# - bug-fix: fixes a problem in a previous version -# - enhancement: extends functionality but does not break or fix existing behavior -# - feature: new functionality -# - known-issue: problems that we are aware of in a given version -# - security: impacts on the security of a product or a user’s deployment. -# - upgrade: important information for someone upgrading from a prior version -# - other: does not fit into any of the other categories -kind: security - -# Change summary; a 80ish characters long description of the change. -summary: Enforce policy-based access control on artifact downloads - -# Long description; in case the summary is not enough to describe the change -# this field accommodate a description without length limits. -# NOTE: This field will be rendered only for breaking-change and known-issue kinds at the moment. -#description: - -# Affected component; usually one of "elastic-agent", "fleet-server", "filebeat", "metricbeat", "auditbeat", "all", etc. -component: fleet-server - -# PR URL; optional; the PR number that added the changeset. -# If not present is automatically filled by the tooling finding the PR where this changelog fragment has been added. -# NOTE: the tooling supports backports, so it's able to fill the original PR number instead of the backport PR number. -# Please provide it if you are adding a fragment for a different PR. -#pr: https://github.com/owner/repo/1234 - -# Issue URL; optional; the GitHub issue related to this changeset (either closes or is part of). -# If not present is automatically filled by the tooling with the issue linked to the PR number. -#issue: https://github.com/owner/repo/1234