Zum Inhalt springen

DataHub Release Notes

7 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus dem Text des Eintrags.

Erstmals gesehen am .

DataHub

DataHub Version 1.6.0.3: Sicherheitshärtung, Python 3.11 erforderlich

DataHub v1.6.0.3 ist ein Patch-Release für die v1.6.0-LTS-Linie mit Sicherheits- und Autorisierungshärtung (u. a. Snowflake-Connector ab 4.7.3, aiohttp 3.14.3, pip 26.2+), verlangt nun Python 3.11, setzt den SecretService-Caller-Guard standardmäßig auf ENFORCE und bietet optionale Security-Header im Frontend.

Released on 2026-09-25 by @david-leifker.

DataHub v1.6.0.3

Patch release for the v1.6.0 LTS line. Focus is security and authorization hardening, plus a few ingestion and platform fixes.

Full diff: https://github.com/datahub-project/datahub/compare/v1.6.0.2...v1.6.0.3


Operator notes

  • Python 3.11 is required on this hotfix line (ingestion CLI/images and related packages). Python 3.10 is no longer supported for v1.6.0.x (#19703).
  • SecretService caller guard defaults to ENFORCE. Secret encrypt/decrypt now requires an OperationContext; misconfigured callers fail closed instead of silently succeeding (#17995).
  • Opt-in frontend security headers. Set DATAHUB_SECURITY_HEADERS_FRAME_OPTIONS, DATAHUB_SECURITY_HEADERS_CONTENT_TYPE_OPTIONS, and/or DATAHUB_SECURITY_HEADERS_REFERRER_POLICY to emit X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. Unset vars omit those headers (#19848).

Security

Dependency floors and library bumps, including:

Area Fix
Snowflake connector Floor raised to 4.7.3 (CVE-2026-15925, plus 4.7.1/4.7.2 TLS SAN regression for account locators with _)
aiohttp 3.14.3 (CVE-2026-69244 / 59881 / 69243)
pip 26.2+ (CVE-2026-13346)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus dem Text des Eintrags.

Erstmals gesehen am .

DataHub

DataHub Version 1.7.0.1: Strengere Autorisierung und Custom-Assertion-Stack

DataHub v1.7.0.1 ist ein Patch-Release für die v1.7.0-Linie mit strengerer Autorisierung, CVE-Dependency-Updates, Korrekturen am Entity-Graph-Cache und an der Lineage, optionalem Optimistic Locking für Aspect-Schreibvorgänge und dem Rest des Custom-Assertion-Stacks inklusive neuem Aspekt assertionNote.

Released on 2026-09-03 by @david-leifker.

DataHub v1.7.0.1 🖖

Patch release for the v1.7.0 line: authorization tightening, CVE dependency bumps, entity-graph-cache and lineage correctness fixes, optional optimistic locking for aspect writes, and the remainder of the custom-assertion stack.

Requirements

  • CLI / Python SDK: 1.7.0.9
  • Helm Chart: 1.1.0

Full upgrade guidance, including every breaking change and migration step: Updating DataHub — v1.7.0.1.

Upgrade path

  • From v1.7.0: drop-in image bump. No ZDU or Helm chart change is required. System-update runs a resumable backfill that copies embedded assertion notes to the new assertionNote aspect (tunable with SYSTEM_UPDATE_ASSERTION_NOTE_MIGRATION_ENABLED, _BATCH_SIZE, _DELAY_MS, _LIMIT).
  • From pre-1.7.0: the v1.7.0 path still applies — you must upgrade to v1.6.0 first (Helm chart 1.0.3, let system-update complete), then upgrade to v1.7.0.1 with Helm chart 1.1.0. Do not skip 1.6.0.

Model changes: additive only. The assertionNote aspect is now registered on the assertion entity so ingestion can fully upsert assertionInfo without clobbering user-authored notes. Assertion URNs and run history are unchanged.


Action required before upgrading

| Area | What changed | Who is affected | | --- | --- | --- | …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus dem Text des Eintrags.

Erstmals gesehen am .

DataHub

DataHub Version 1.6.0.2: Rückportierte Sicherheitsfixes und Validator-Kontrollen

DataHub v1.6.0.2 bringt rückportierte Sicherheitsfixes und CVE-Dependency-Updates, Validator-Kontrollen für das Bearbeiten von User- und Group-Aspekten sowie ein abgesichertes GMS-/auth-Helper-Gate und Timeseries-View-Privilegien.

Released on 2026-09-01 by @david-leifker.

What's Changed

Full Changelog: https://github.com/datahub-project/datahub/compare/v1.6.0.1...v1.6.0.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus dem Text des Eintrags.

Erstmals gesehen am .

DataHub

DataHub Version 1.6.0.1: Sicherheitsfixes und Plattform-Bugfixes

DataHub v1.6.0.1 enthält rückportierte Sicherheitsfixes und Plattform-Bugfixes, darunter Updates von lz4-java, Jackson, wire-runtime und Apache Parquet 1.18.0, Verbesserungen bei Transaction-Retry und PostgreSQL-Lock-Reihenfolge sowie Spring 7.0.8.

Released on 2026-08-13 by @david-leifker.

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus dem Text des Eintrags.

Erstmals gesehen am .

DataHub

DataHub Version 1.7.0: Upgrade nur über v1.6.0 mit Helm Chart 1.0.3

DataHub v1.7.0 erscheint mit CLI/Python SDK 1.7.0 und Helm Chart 1.1.0, wobei vor dem Upgrade zwingend zuerst v1.6.0 mit Helm Chart 1.0.3 installiert werden muss.

Released on 2026-08-04 by @david-leifker.

DataHub v1.7.0

Requirements

  • CLI / Python SDK: 1.7.0
  • Helm Chart: 1.1.0

Full upgrade guidance, including every breaking change and migration step: Updating DataHub — v1.7.0.

Upgrade path / ZDU: You must upgrade to v1.6.0 before upgrading to v1.7.0 — do not skip 1.6.0. Deploy v1.6.0 with Helm chart 1.0.3, let system-update complete, then upgrade to v1.7.0 with Helm chart 1.1.0. Enable Elasticsearch/OpenSearch ZDU (global.datahub.systemUpdate.zdu) with the 1.1.0 chart on a subsequent OpenSearch/Elasticsearch version bump — not during the v1.6.0 install.


Feature highlights

UI and experience …

Originalquelle(öffnet in neuem Tab)Problem melden