Skip to content

docs: add server release notes for 10.16.4 - #199

Merged
phil-davis merged 1 commit into
masterfrom
docs/10.16.4-release-notes
Jul 29, 2026
Merged

docs: add server release notes for 10.16.4#199
phil-davis merged 1 commit into
masterfrom
docs/10.16.4-release-notes

Conversation

@DeepDiver1975

Copy link
Copy Markdown
Member

Summary

Add release notes for ownCloud Classic 10.16.4, published 2026-07-29. The page previously stopped at 10.16.3, so admins had no rendered page telling them what changed or that they should upgrade.

10.16.4 is a security release. It carries a critical fix for the legacy chunked WebDAV upload path, which assembled the final file without honouring the pre-write hook veto — so the filename blacklist enforced on ordinary uploads was bypassable via chunking.

Changes

modules/ROOT/pages/server_release_notes.adoc — new == Changes in 10.16.4 section inserted above 10.16.3 (newest first), covering owncloud/core#41763 and owncloud/core#41574.

Notes on style

  • Uses a flat === Security Fixes list rather than the nested * Security: / * Bugfix: grouping of the 10.16.3 block. That nesting exists because 10.16.3 had six entries across categories; with two entries the flat form (same shape as the 10.16.1 and 10.15.2 blocks in this file) reads better.
  • The GHSA advisory IDs are deliberately not linked — both are still triage/draft, so their URLs 404 for the public. PR links are what this file uses throughout.

Verification

Rendered locally with asciidoctor — no warnings or errors. Confirmed in the output HTML:

  • <h2 id="_changes_in_10_16_4"> appears before _changes_in_10_16_3
  • the IMPORTANT admonition renders as admonitionblock important
  • === Security Fixes renders as a [discrete] <h3> (excluded from the TOC, as intended)
  • all three links resolve, and {oc-changelog-url} is substituted correctly
  • the + line continuations keep each description attached to its bullet

Related

🤖 Generated with Claude Code

10.16.4 was published 2026-07-29 as a security release. It carries a critical
fix for the legacy chunked WebDAV upload path, which did not enforce the
filename blacklist, plus the subadmin email-change fix.

Uses a flat "Security Fixes" list rather than the nested Security:/Bugfix:
grouping of the 10.16.3 block, matching the 10.16.1 and 10.15.2 shape - with
only two entries the nesting adds no clarity.

The GHSA advisories are not linked because both are still in triage/draft and
their URLs are not publicly reachable.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
@DeepDiver1975
DeepDiver1975 requested a review from a team as a code owner July 29, 2026 21:29
@phil-davis
phil-davis merged commit 94b9556 into master Jul 29, 2026
2 checks passed
@phil-davis
phil-davis deleted the docs/10.16.4-release-notes branch July 29, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants