Angaben zum Datum
Datum aus dem Text des Eintrags.
Erstmals gesehen am .
DataHub Version 1.6.0.3: Sicherheitshärtung, Python 3.11 erforderlich
DataHub v1.6.0.3 ist ein Patch-Release für die v1.6.0-LTS-Linie mit Sicherheits- und Autorisierungshärtung (u. a. Snowflake-Connector ab 4.7.3, aiohttp 3.14.3, pip 26.2+), verlangt nun Python 3.11, setzt den SecretService-Caller-Guard standardmäßig auf ENFORCE und bietet optionale Security-Header im Frontend.
Released on 2026-09-25 by @david-leifker.
DataHub v1.6.0.3
Patch release for the v1.6.0 LTS line. Focus is security and authorization hardening, plus a few ingestion and platform fixes.
Full diff: https://github.com/datahub-project/datahub/compare/v1.6.0.2...v1.6.0.3
Operator notes
- Python 3.11 is required on this hotfix line (ingestion CLI/images and related packages). Python 3.10 is no longer supported for v1.6.0.x (#19703).
- SecretService caller guard defaults to
ENFORCE. Secret encrypt/decrypt now requires anOperationContext; misconfigured callers fail closed instead of silently succeeding (#17995). - Opt-in frontend security headers. Set
DATAHUB_SECURITY_HEADERS_FRAME_OPTIONS,DATAHUB_SECURITY_HEADERS_CONTENT_TYPE_OPTIONS, and/orDATAHUB_SECURITY_HEADERS_REFERRER_POLICYto emitX-Frame-Options,X-Content-Type-Options, andReferrer-Policy. Unset vars omit those headers (#19848).
Security
Dependency floors and library bumps, including:
| Area | Fix |
|---|---|
| Snowflake connector | Floor raised to 4.7.3 (CVE-2026-15925, plus 4.7.1/4.7.2 TLS SAN regression for account locators with _) |
| aiohttp | 3.14.3 (CVE-2026-69244 / 59881 / 69243) |
| pip | 26.2+ (CVE-2026-13346) |