From e870b9cb74a1292839a630c321d49ea300b5e04c Mon Sep 17 00:00:00 2001 From: Mathieu Fenniak Date: Sat, 28 Feb 2026 15:12:04 -0700 Subject: [PATCH] docs: add release notes for PR #11457 --- release-notes/11457.md | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 release-notes/11457.md diff --git a/release-notes/11457.md b/release-notes/11457.md new file mode 100644 index 0000000000..edd0199b0d --- /dev/null +++ b/release-notes/11457.md @@ -0,0 +1,6 @@ +Accessing the `/repositories/{id}` API with a public-only access token did not restrict read access to only public repositories, which is now prevented. +Accessing the `/repos/{owner}/{repo}/issues/{index}/dependencies` and `/repos/{owner}/{repo}/issues/{index}/blocks` APIs with a public-only access token had access to modification operations against private repositories in the *form* component of the API (not the URL component), which is now prevented. +Accessing the `/repos/{owner}/{repo}/issues/{index}/dependencies` and `/repos/{owner}/{repo}/issues/{index}/blocks` APIs with a public-only access token could view dependencies or blocking issues from private repositories, which is now prevented. +Accessing the `/repos/{owner}/{repo}/issues/{index}/timeline` API with a public-only access token could view comment cross-references from private repositories, which is now prevented. +Accessing the `/teams/{id}/repos/{org}/{repo}` API with a public-only access token could view private repositories assigned to a team, which is now prevented. +Access the watched repos and starred repos of a your own user through /user/subscriptions and /user/starred APIs with a public-only access token could view private repositories, which is now prevented. \ No newline at end of file