PostgreSQL 11
Read the English manualEnd of life · Recorded build 11.22 · 2023-11-09
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2018-10-18
- Support end
- 2023-11-09
- Indexed releases
- 23
- Original release-note entries
- 1141
Manuals & provenance
PostgreSQL 11 English manual · 1125 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 11.0 · Changes from the initial release through 11.22
Original migration guidance for 11.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.
Version 11 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 11.22 | 2023-11-09 | 31 | 10 | 0 | 3 |
| 11.21 | 2023-08-10 | 29 | 11 | 0 | 1 |
| 11.20 | 2023-05-11 | 44 | 22 | 0 | 2 |
| 11.19 | 2023-02-09 | 29 | 12 | 0 | 0 |
| 11.18 | 2022-11-10 | 32 | 15 | 0 | 0 |
| 11.17 | 2022-08-11 | 37 | 14 | 0 | 2 |
| 11.16 | 2022-05-12 | 32 | 16 | 0 | 1 |
| 11.15 | 2022-02-10 | 29 | 13 | 0 | 0 |
| 11.14 | 2021-11-11 | 58 | 27 | 0 | 2 |
| 11.13 | 2021-08-12 | 63 | 20 | 0 | 3 |
| 11.12 | 2021-05-13 | 33 | 17 | 0 | 3 |
| 11.11 | 2021-02-11 | 56 | 26 | 0 | 1 |
| 11.10 | 2020-11-12 | 46 | 17 | 0 | 3 |
| 11.9 | 2020-08-13 | 43 | 22 | 0 | 3 |
| 11.8 | 2020-05-14 | 55 | 23 | 0 | 0 |
| 11.7 | 2020-02-13 | 56 | 29 | 0 | 2 |
| 11.6 | 2019-11-14 | 67 | 31 | 0 | 0 |
| 11.5 | 2019-08-08 | 47 | 18 | 0 | 3 |
| 11.4 | 2019-06-20 | 26 | 16 | 0 | 1 |
| 11.3 | 2019-05-09 | 63 | 40 | 0 | 3 |
| 11.2 | 2019-02-14 | 73 | 37 | 0 | 0 |
| 11.1 | 2018-11-08 | 22 | 12 | 0 | 1 |
| 11.0 | 2018-10-18 | 170 | 1 | 20 | 0 |
Initial release changes
Original entries from 11.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
170 of 170 original entries.
Make pg_dump dump the properties of a database, not just its contents Compatibility Migration
Make pg_dump dump the properties of a database, not just its contents (Haribabu Kommi)
Previously, attributes of the database itself, such as database-level
GRANT/REVOKEpermissions andALTER DATABASE SETvariable settings, were only dumped by pg_dumpall. Nowpg_dump --createandpg_restore --createwill restore these database properties in addition to the objects within the database.pg_dumpall -gnow only dumps role- and tablespace-related attributes. pg_dumpall's complete output (without-g) is unchanged.pg_dump and pg_restore, without
--create, no longer dump/restore database-level comments and security labels; those are now treated as properties of the database.pg_dumpall's output script will now always create databases with their original locale and encoding, and hence will fail if the locale or encoding name is unknown to the destination system. Previously,
CREATE DATABASEwould be emitted without these specifications if the database locale and encoding matched the old cluster's defaults.pg_dumpall --cleannow restores the original locale and encoding settings of thepostgresandtemplate1databases, as well as those of user-created databases.Original release occurrence ·
11.0/migration/001Consider syntactic form when disambiguating function versus column references Compatibility Migration
Consider syntactic form when disambiguating function versus column references (Tom Lane)
When
xis a table name or composite column, PostgreSQL has traditionally considered the syntactic formsandf(x)to be equivalent, allowing tricks such as writing a function and then using it as though it were a computed-on-demand column. However, if both interpretations are feasible, the column interpretation was always chosen, leading to surprising results if the user intended the function interpretation. Now, if there is ambiguity, the interpretation that matches the syntactic form is chosen.x.fOriginal release occurrence ·
11.0/migration/002Fully enforce uniqueness of table and domain constraint names Compatibility Migration
Fully enforce uniqueness of table and domain constraint names (Tom Lane)
PostgreSQL expects the names of a table's constraints to be distinct, and likewise for the names of a domain's constraints. However, there was not rigid enforcement of this, and previously there were corner cases where duplicate names could be created.
Original release occurrence ·
11.0/migration/003Make power(numeric, numeric) and power(float8, float8) handle NaN inputs according to the POSIX standard Compatibility Migration
Make
power(numeric, numeric)andpower(float8, float8)handleNaNinputs according to the POSIX standard (Tom Lane, Dang Minh Huong)POSIX says that
NaN ^ 0 = 1and1 ^ NaN = 1, but all other cases withNaNinput(s) should returnNaN.power(numeric, numeric)just returnedNaNin all such cases; now it honors the two exceptions.power(float8, float8)followed the standard if the C library does; but on some old Unix platforms the library doesn't, and there were also problems on some versions of Windows.Original release occurrence ·
11.0/migration/004Prevent to_number() from consuming characters when the template separator does not match Compatibility Migration
Prevent
to_number()from consuming characters when the template separator does not match (Oliver Ford)Specifically,
SELECT to_number('1234', '9,999')used to return134. It will now return1234.LandTHnow only consume characters that are not digits, positive/negative signs, decimal points, or commas.Original release occurrence ·
11.0/migration/005Fix to_date(), to_number(), and to_timestamp() to skip a character for each template character Compatibility Migration
Fix
to_date(),to_number(), andto_timestamp()to skip a character for each template character (Tom Lane)Previously, they skipped one byte for each byte of template character, resulting in strange behavior if either string contained multibyte characters.
Original release occurrence ·
11.0/migration/006Adjust the handling of backslashes inside double-quotes in template strings for to_char(), to_number(), and to_timestamp(). Compatibility Migration
Adjust the handling of backslashes inside double-quotes in template strings for
to_char(),to_number(), andto_timestamp().Such a backslash now escapes the character after it, particularly a double-quote or another backslash.
Original release occurrence ·
11.0/migration/007Correctly handle relative path expressions in xmltable(), xpath(), and other XML-handling functions Compatibility Migration
Correctly handle relative path expressions in
xmltable(),xpath(), and other XML-handling functions (Markus Winand)Per the SQL standard, relative paths start from the document node of the XML input document, not the root node as these functions previously did.
Original release occurrence ·
11.0/migration/008In the extended query protocol, make statement_timeout apply to each Execute message separately, not to all commands before Sync Compatibility Migration
In the extended query protocol, make
statement_timeoutapply to each Execute message separately, not to all commands before Sync (Tatsuo Ishii, Andres Freund)Original release occurrence ·
11.0/migration/009Remove the relhaspkey column from system catalog pg_class Compatibility Migration
Remove the
relhaspkeycolumn from system catalogpg_class(Peter Eisentraut)Applications needing to check for a primary key should consult
pg_index.Original release occurrence ·
11.0/migration/010Replace system catalog pg_proc's proisagg and proiswindow columns with prokind Compatibility Migration
Replace system catalog
pg_proc'sproisaggandproiswindowcolumns withprokind(Peter Eisentraut)This new column more clearly distinguishes functions, procedures, aggregates, and window functions.
Original release occurrence ·
11.0/migration/011Correct information schema column tables.table_type to return FOREIGN instead of FOREIGN TABLE Compatibility Migration
Correct information schema column
tables.table_typeto returnFOREIGNinstead ofFOREIGN TABLE(Peter Eisentraut)This new output matches the SQL standard.
Original release occurrence ·
11.0/migration/012Change the ps process display labels for background workers to match the pg_stat_activity.backend_type labels Compatibility Migration
Change the ps process display labels for background workers to match the
pg_stat_activity.backend_typelabels (Peter Eisentraut)Original release occurrence ·
11.0/migration/013Cause large object permission checks to happen during large object open, lo_open(), not when a read or write is attempted Compatibility Migration
Cause large object permission checks to happen during large object open,
lo_open(), not when a read or write is attempted (Tom Lane, Michael Paquier)If write access is requested and not available, an error will now be thrown even if the large object is never written to.
Original release occurrence ·
11.0/migration/014Prevent non-superusers from reindexing shared catalogs Compatibility Migration
Prevent non-superusers from reindexing shared catalogs (Michael Paquier, Robert Haas)
Previously, database owners were also allowed to do this, but now it is considered outside the bounds of their privileges.
Original release occurrence ·
11.0/migration/015Remove deprecated adminpack functions pg_file_read(), pg_file_length(), and pg_logfile_rotate() Compatibility Migration
Remove deprecated
adminpackfunctionspg_file_read(),pg_file_length(), andpg_logfile_rotate()(Stephen Frost)Equivalent functionality is now present in the core backend. Existing
adminpackinstalls will continue to have access to these functions until they are updated viaALTER EXTENSION ... UPDATE.Original release occurrence ·
11.0/migration/016Honor the capitalization of double-quoted command options Compatibility Migration
Honor the capitalization of double-quoted command options (Daniel Gustafsson)
Previously, option names in certain SQL commands were forcibly lower-cased even if entered with double quotes; thus for example
"FillFactor"would be accepted as an index storage option, though properly its name is lower-case. Such cases will now generate an error.Original release occurrence ·
11.0/migration/017Remove server parameter replacement_sort_tuples Compatibility Migration
Remove server parameter
replacement_sort_tuples(Peter Geoghegan)Replacement sorts were determined to be no longer useful.
Original release occurrence ·
11.0/migration/018Remove WITH clause in CREATE FUNCTION Compatibility Migration
Remove
WITHclause inCREATE FUNCTION(Michael Paquier)PostgreSQL has long supported a more standard-compliant syntax for this capability.
Original release occurrence ·
11.0/migration/019In PL/pgSQL trigger functions, the OLD and NEW variables now read as NULL when not assigned Compatibility Migration
In PL/pgSQL trigger functions, the
OLDandNEWvariables now read as NULL when not assigned (Tom Lane)Previously, references to these variables could be parsed but not executed.
Original release occurrence ·
11.0/migration/020Allow the creation of partitions based on hashing a key column Features
Allow the creation of partitions based on hashing a key column (Amul Sul)
Original release occurrence ·
11.0/changes/001Support indexes on partitioned tables Features
Support indexes on partitioned tables (Álvaro Herrera, Amit Langote)
An “index” on a partitioned table is not a physical index across the whole partitioned table, but rather a template for automatically creating similar indexes on each partition of the table.
If the partition key is part of the index's column set, a partitioned index may be declared
UNIQUE. It will represent a valid uniqueness constraint across the whole partitioned table, even though each physical index only enforces uniqueness within its own partition.The new command
ALTER INDEX ATTACH PARTITIONcauses an existing index on a partition to be associated with a matching index template for its partitioned table. This provides flexibility in setting up a new partitioned index for an existing partitioned table.Original release occurrence ·
11.0/changes/002Allow foreign keys on partitioned tables Features
Allow foreign keys on partitioned tables (Álvaro Herrera)
Original release occurrence ·
11.0/changes/003Allow FOR EACH ROW triggers on partitioned tables Features
Allow
FOR EACH ROWtriggers on partitioned tables (Álvaro Herrera)Creation of a trigger on a partitioned table automatically creates triggers on all existing and future partitions. This also allows deferred unique constraints on partitioned tables.
Original release occurrence ·
11.0/changes/004Allow partitioned tables to have a default partition Features
Allow partitioned tables to have a default partition (Jeevan Ladhe, Beena Emerson, Ashutosh Bapat, Rahila Syed, Robert Haas)
The default partition will store rows that don't match any of the other defined partitions, and is searched accordingly.
Original release occurrence ·
11.0/changes/005UPDATE statements that change a partition key column now cause affected rows to be moved to the appropriate partitions Features
UPDATEstatements that change a partition key column now cause affected rows to be moved to the appropriate partitions (Amit Khandekar)Original release occurrence ·
11.0/changes/006Allow INSERT, UPDATE, and COPY on partitioned tables to properly route rows to foreign partitions Features
Allow
INSERT,UPDATE, andCOPYon partitioned tables to properly route rows to foreign partitions (Etsuro Fujita, Amit Langote)This is supported by
postgres_fdwforeign tables. Since theExecForeignInsertcallback function is called for this in a different way than it used to be, foreign data wrappers must be modified to cope with this change.Original release occurrence ·
11.0/changes/007Allow faster partition elimination during query processing Performance
Allow faster partition elimination during query processing (Amit Langote, David Rowley, Dilip Kumar)
This speeds access to partitioned tables with many partitions.
Original release occurrence ·
11.0/changes/008Allow partition elimination during query execution Features
Allow partition elimination during query execution (David Rowley, Beena Emerson)
Previously, partition elimination only happened at planning time, meaning many joins and prepared queries could not use partition elimination.
Original release occurrence ·
11.0/changes/009In an equality join between partitioned tables, allow matching partitions to be joined directly Features
In an equality join between partitioned tables, allow matching partitions to be joined directly (Ashutosh Bapat)
This feature is disabled by default but can be enabled by changing
enable_partitionwise_join.Original release occurrence ·
11.0/changes/010Allow aggregate functions on partitioned tables to be evaluated separately for each partition, subsequently merging the results Features
Allow aggregate functions on partitioned tables to be evaluated separately for each partition, subsequently merging the results (Jeevan Chalke, Ashutosh Bapat, Robert Haas)
This feature is disabled by default but can be enabled by changing
enable_partitionwise_aggregate.Original release occurrence ·
11.0/changes/011Allow postgres_fdw to push down aggregates to foreign tables that are partitions Features
Allow
postgres_fdwto push down aggregates to foreign tables that are partitions (Jeevan Chalke)Original release occurrence ·
11.0/changes/012Allow parallel building of a btree index Features
Allow parallel building of a btree index (Peter Geoghegan, Rushabh Lathia, Heikki Linnakangas)
Original release occurrence ·
11.0/changes/013Allow hash joins to be performed in parallel using a shared hash table Features
Allow hash joins to be performed in parallel using a shared hash table (Thomas Munro)
Original release occurrence ·
11.0/changes/014Allow UNION to run each SELECT in parallel if the individual SELECTs cannot be parallelized Features
Allow
UNIONto run eachSELECTin parallel if the individualSELECTs cannot be parallelized (Amit Khandekar, Robert Haas, Amul Sul)Original release occurrence ·
11.0/changes/015Allow partition scans to more efficiently use parallel workers Features
Allow partition scans to more efficiently use parallel workers (Amit Khandekar, Robert Haas, Amul Sul)
Original release occurrence ·
11.0/changes/016Allow LIMIT to be passed to parallel workers Features
Allow
LIMITto be passed to parallel workers (Robert Haas, Tom Lane)This allows workers to reduce returned results and use targeted index scans.
Original release occurrence ·
11.0/changes/017Allow single-evaluation queries, e.g., WHERE clause aggregate queries, and functions in the target list to be parallelized Features
Allow single-evaluation queries, e.g.,
WHEREclause aggregate queries, and functions in the target list to be parallelized (Amit Kapila, Robert Haas)Original release occurrence ·
11.0/changes/018Add server parameter parallel_leader_participation to control whether the leader also executes subplans Features
Add server parameter
parallel_leader_participationto control whether the leader also executes subplans (Thomas Munro)The default is enabled, meaning the leader will execute subplans.
Original release occurrence ·
11.0/changes/019Allow parallelization of commands CREATE TABLE ... AS, SELECT INTO, and CREATE MATERIALIZED VIEW Features
Allow parallelization of commands
CREATE TABLE ... AS,SELECT INTO, andCREATE MATERIALIZED VIEW(Haribabu Kommi)Original release occurrence ·
11.0/changes/020Improve performance of sequential scans with many parallel workers Performance
Improve performance of sequential scans with many parallel workers (David Rowley)
Original release occurrence ·
11.0/changes/021Add reporting of parallel workers' sort activity in EXPLAIN Features
Add reporting of parallel workers' sort activity in
EXPLAIN(Robert Haas, Tom Lane)Original release occurrence ·
11.0/changes/022Allow B-tree indexes to include columns that are not part of the search key or unique constraint, but are available to be read by index-only scans Features
Allow B-tree indexes to include columns that are not part of the search key or unique constraint, but are available to be read by index-only scans (Anastasia Lubennikova, Alexander Korotkov, Teodor Sigaev)
This is enabled by the new
INCLUDEclause ofCREATE INDEX. It facilitates building “covering indexes” that optimize specific types of queries. Columns can be included even if their data types don't have B-tree support.Original release occurrence ·
11.0/changes/023Improve performance of monotonically increasing index additions Performance
Improve performance of monotonically increasing index additions (Pavan Deolasee, Peter Geoghegan)
Original release occurrence ·
11.0/changes/024Improve performance of hash index scans Performance
Improve performance of hash index scans (Ashutosh Sharma)
Original release occurrence ·
11.0/changes/025Add predicate locking for hash, GiST and GIN indexes Features
Add predicate locking for hash, GiST and GIN indexes (Shubham Barai)
This reduces the likelihood of serialization conflicts in serializable-mode transactions.
Original release occurrence ·
11.0/changes/026Add prefix-match operator text ^@ text, which is supported by SP-GiST Features
Add prefix-match operator
text^@text, which is supported by SP-GiST (Ildus Kurbangaliev)This is similar to using
varLIKE 'word%'with a btree index, but it is more efficient.Original release occurrence ·
11.0/changes/027Allow polygons to be indexed with SP-GiST Features
Allow polygons to be indexed with SP-GiST (Nikita Glukhov, Alexander Korotkov)
Original release occurrence ·
11.0/changes/028Allow SP-GiST to use lossy representation of leaf keys Features
Allow SP-GiST to use lossy representation of leaf keys (Teodor Sigaev, Heikki Linnakangas, Alexander Korotkov, Nikita Glukhov)
Original release occurrence ·
11.0/changes/029Improve selection of the most common values for statistics Features
Improve selection of the most common values for statistics (Jeff Janes, Dean Rasheed)
Previously, the most common values (MCVs) were identified based on their frequency compared to all column values. Now, MCVs are chosen based on their frequency compared to the non-MCV values. This improves the robustness of the algorithm for both uniform and non-uniform distributions.
Original release occurrence ·
11.0/changes/030Improve selectivity estimates for >= and <= Features
Improve selectivity estimates for
>=and<=(Tom Lane)Previously, such cases used the same selectivity estimates as
>and<, respectively, unless the comparison constants are MCVs. This change is particularly helpful for queries involvingBETWEENwith small ranges.Original release occurrence ·
11.0/changes/031Reduce var = var to var IS NOT NULL where equivalent Features
Reduce
var=vartovarIS NOT NULLwhere equivalent (Tom Lane)This leads to better selectivity estimates.
Original release occurrence ·
11.0/changes/032Improve optimizer's row count estimates for EXISTS and NOT EXISTS queries Features
Improve optimizer's row count estimates for
EXISTSandNOT EXISTSqueries (Tom Lane)Original release occurrence ·
11.0/changes/033Make the optimizer account for evaluation costs and selectivity of HAVING clauses Features
Make the optimizer account for evaluation costs and selectivity of
HAVINGclauses (Tom Lane)Original release occurrence ·
11.0/changes/034Add Just-in-Time (JIT) compilation of some parts of query plans to improve execution speed Performance
Add Just-in-Time (JIT) compilation of some parts of query plans to improve execution speed (Andres Freund)
This feature requires LLVM to be available. It is not currently enabled by default, even in builds that support it.
Original release occurrence ·
11.0/changes/035Allow bitmap scans to perform index-only scans when possible Performance
Allow bitmap scans to perform index-only scans when possible (Alexander Kuzmenkov)
Original release occurrence ·
11.0/changes/036Update the free space map during VACUUM Performance
Update the free space map during
VACUUM(Claudio Freire)This allows free space to be reused more quickly.
Original release occurrence ·
11.0/changes/037Allow VACUUM to avoid unnecessary index scans Performance
Allow
VACUUMto avoid unnecessary index scans (Masahiko Sawada, Alexander Korotkov)Original release occurrence ·
11.0/changes/038Improve performance of committing multiple concurrent transactions Performance
Improve performance of committing multiple concurrent transactions (Amit Kapila)
Original release occurrence ·
11.0/changes/039Reduce memory usage for queries using set-returning functions in their target lists Performance
Reduce memory usage for queries using set-returning functions in their target lists (Andres Freund)
Original release occurrence ·
11.0/changes/040Improve the speed of aggregate computations Performance
Improve the speed of aggregate computations (Andres Freund)
Original release occurrence ·
11.0/changes/041Allow postgres_fdw to push UPDATEs and DELETEs using joins to foreign servers Performance
Allow
postgres_fdwto pushUPDATEs andDELETEs using joins to foreign servers (Etsuro Fujita)Previously, only non-join
UPDATEs andDELETEs were pushed.Original release occurrence ·
11.0/changes/042Add support for large pages on Windows Performance
Add support for large pages on Windows (Takayuki Tsunakawa, Thomas Munro)
This is controlled by the huge_pages configuration parameter.
Original release occurrence ·
11.0/changes/043Show memory usage in output from log_statement_stats, log_parser_stats, log_planner_stats, and log_executor_stats Features
Show memory usage in output from
log_statement_stats,log_parser_stats,log_planner_stats, andlog_executor_stats(Justin Pryzby, Peter Eisentraut)Original release occurrence ·
11.0/changes/044Add column pg_stat_activity.backend_type to show the type of a background worker Features
Add column
pg_stat_activity.backend_typeto show the type of a background worker (Peter Eisentraut)The type is also visible in ps output.
Original release occurrence ·
11.0/changes/045Make log_autovacuum_min_duration log skipped tables that are concurrently being dropped Features
Make
log_autovacuum_min_durationlog skipped tables that are concurrently being dropped (Nathan Bossart)Original release occurrence ·
11.0/changes/046Add information_schema columns related to table constraints and triggers Features
Add
information_schemacolumns related to table constraints and triggers (Peter Eisentraut)Specifically,
triggers.action_order,triggers.action_reference_old_table, andtriggers.action_reference_new_tableare now populated, where before they were always null. Also,table_constraints.enforcednow exists but is not yet usefully populated.Original release occurrence ·
11.0/changes/047Allow the server to specify more complex LDAP specifications in search+bind mode Features
Allow the server to specify more complex LDAP specifications in search+bind mode (Thomas Munro)
Specifically,
ldapsearchfilterallows pattern matching using combinations of LDAP attributes.Original release occurrence ·
11.0/changes/048Allow LDAP authentication to use encrypted LDAP Features
Allow LDAP authentication to use encrypted LDAP (Thomas Munro)
We already supported LDAP over TLS by using
ldaptls=1. This new TLS LDAP method for encrypted LDAP is enabled withldapscheme=ldapsorldapurl=ldaps://.Original release occurrence ·
11.0/changes/049Improve logging of LDAP errors Features
Improve logging of LDAP errors (Thomas Munro)
Original release occurrence ·
11.0/changes/050Add default roles that enable file system access Features
Add default roles that enable file system access (Stephen Frost)
Specifically, the new roles are:
pg_read_server_files,pg_write_server_files, andpg_execute_server_program. These roles now also control who can use server-sideCOPYand thefile_fdwextension. Previously, only superusers could use these functions, and that is still the default behavior.Original release occurrence ·
11.0/changes/051Allow access to file system functions to be controlled by GRANT/REVOKE permissions, rather than superuser checks Features
Allow access to file system functions to be controlled by
GRANT/REVOKEpermissions, rather than superuser checks (Stephen Frost)Specifically, these functions were modified:
pg_ls_dir(),pg_read_file(),pg_read_binary_file(),pg_stat_file().Original release occurrence ·
11.0/changes/052Use GRANT/REVOKE to control access to lo_import() and lo_export() Features
Use
GRANT/REVOKEto control access tolo_import()andlo_export()(Michael Paquier, Tom Lane)Previously, only superusers were granted access to these functions.
The compile-time option
ALLOW_DANGEROUS_LO_FUNCTIONShas been removed.Original release occurrence ·
11.0/changes/053Use view owner not session owner when preventing non-password access to postgres_fdw tables Features
Use view owner not session owner when preventing non-password access to
postgres_fdwtables (Robert Haas)PostgreSQL only allows superusers to access
postgres_fdwtables without passwords, e.g., viapeer. Previously, the session owner had to be a superuser to allow such access; now the view owner is checked instead.Original release occurrence ·
11.0/changes/054Fix invalid locking permission check in SELECT FOR UPDATE on views Bug fixes
Fix invalid locking permission check in
SELECT FOR UPDATEon views (Tom Lane)Original release occurrence ·
11.0/changes/055Add server setting ssl_passphrase_command to allow supplying of the passphrase for SSL key files Features
Add server setting
ssl_passphrase_commandto allow supplying of the passphrase for SSL key files (Peter Eisentraut)Also add
ssl_passphrase_command_supports_reloadto specify whether the SSL configuration should be reloaded andssl_passphrase_commandcalled during a server configuration reload.Original release occurrence ·
11.0/changes/056Add storage parameter toast_tuple_target to control the minimum tuple length before TOAST storage will be considered Features
Add storage parameter
toast_tuple_targetto control the minimum tuple length before TOAST storage will be considered (Simon Riggs)The default TOAST threshold has not been changed.
Original release occurrence ·
11.0/changes/057Allow server options related to memory and file sizes to be specified in units of bytes Features
Allow server options related to memory and file sizes to be specified in units of bytes (Beena Emerson)
The new unit suffix is “B”. This is in addition to the existing units “kB”, “MB”, “GB” and “TB”.
Original release occurrence ·
11.0/changes/058Allow the WAL file size to be set during initdb Features
Allow the WAL file size to be set during initdb (Beena Emerson)
Previously, the 16MB default could only be changed at compile time.
Original release occurrence ·
11.0/changes/059Retain WAL data for only a single checkpoint Features
Retain WAL data for only a single checkpoint (Simon Riggs)
Previously, WAL was retained for two checkpoints.
Original release occurrence ·
11.0/changes/060Fill the unused portion of force-switched WAL segment files with zeros for improved compressibility Features
Fill the unused portion of force-switched WAL segment files with zeros for improved compressibility (Chapman Flack)
Original release occurrence ·
11.0/changes/061Replicate TRUNCATE activity when using logical replication Features
Replicate
TRUNCATEactivity when using logical replication (Simon Riggs, Marco Nenciarini, Peter Eisentraut)Original release occurrence ·
11.0/changes/062Pass prepared transaction information to logical replication subscribers Features
Pass prepared transaction information to logical replication subscribers (Nikhil Sontakke, Stas Kelvich)
Original release occurrence ·
11.0/changes/063Exclude unlogged tables, temporary tables, and pg_internal.init files from streaming base backups Features
Exclude unlogged tables, temporary tables, and
pg_internal.initfiles from streaming base backups (David Steele)There is no need to copy such files.
Original release occurrence ·
11.0/changes/064Allow checksums of heap pages to be verified during streaming base backup Features
Allow checksums of heap pages to be verified during streaming base backup (Michael Banck)
Original release occurrence ·
11.0/changes/065Allow replication slots to be advanced programmatically, rather than be consumed by subscribers Features
Allow replication slots to be advanced programmatically, rather than be consumed by subscribers (Petr Jelinek)
This allows efficient advancement of replication slots when the contents do not need to be consumed. This is performed by
pg_replication_slot_advance().Original release occurrence ·
11.0/changes/066Add timeline information to the backup_label file Features
Add timeline information to the
backup_labelfile (Michael Paquier)Also add a check that the WAL timeline matches the
backup_labelfile's timeline.Original release occurrence ·
11.0/changes/067Add host and port connection information to the pg_stat_wal_receiver system view Features
Add host and port connection information to the
pg_stat_wal_receiversystem view (Haribabu Kommi)Original release occurrence ·
11.0/changes/068Allow ALTER TABLE to add a column with a non-null default without doing a table rewrite Features
Allow
ALTER TABLEto add a column with a non-null default without doing a table rewrite (Andrew Dunstan, Serge Rielau)This is enabled when the default value is a constant.
Original release occurrence ·
11.0/changes/069Allow views to be locked by locking the underlying tables Features
Allow views to be locked by locking the underlying tables (Yugo Nagata)
Original release occurrence ·
11.0/changes/070Allow ALTER INDEX to set statistics-gathering targets for expression indexes Features
Allow
ALTER INDEXto set statistics-gathering targets for expression indexes (Alexander Korotkov, Adrien Nayrat)In psql,
\d+now shows the statistics target for indexes.Original release occurrence ·
11.0/changes/071Allow multiple tables to be specified in one VACUUM or ANALYZE command Features
Allow multiple tables to be specified in one
VACUUMorANALYZEcommand (Nathan Bossart)Also, if any table mentioned in
VACUUMuses a column list, then theANALYZEkeyword must be supplied; previously,ANALYZEwas implied in such cases.Original release occurrence ·
11.0/changes/072Add parenthesized options syntax to ANALYZE Features
Add parenthesized options syntax to
ANALYZE(Nathan Bossart)This is similar to the syntax supported by
VACUUM.Original release occurrence ·
11.0/changes/073Add CREATE AGGREGATE option to specify the behavior of the aggregate's finalization function Features
Add
CREATE AGGREGATEoption to specify the behavior of the aggregate's finalization function (Tom Lane)This is helpful for allowing user-defined aggregate functions to be optimized and to work as window functions.
Original release occurrence ·
11.0/changes/074Allow the creation of arrays of domains Features
Allow the creation of arrays of domains (Tom Lane)
This also allows
array_agg()to be used on domains.Original release occurrence ·
11.0/changes/075Support domains over composite types Features
Support domains over composite types (Tom Lane)
Also allow PL/Perl, PL/Python, and PL/Tcl to handle composite-domain function arguments and results. Also improve PL/Python domain handling.
Original release occurrence ·
11.0/changes/076Add casts from JSONB scalars to numeric and boolean data types Features
Add casts from
JSONBscalars to numeric and boolean data types (Anastasia Lubennikova)Original release occurrence ·
11.0/changes/077Add all window function framing options specified by SQL:2011 Features
Add all window function framing options specified by SQL:2011 (Oliver Ford, Tom Lane)
Specifically, allow
RANGEmode to usePRECEDINGandFOLLOWINGto select rows having grouping values within plus or minus the specified offset. AddGROUPSmode to include plus or minus the number of peer groups. Frame exclusion syntax was also added.Original release occurrence ·
11.0/changes/078Add SHA-2 family of hash functions Features
Add SHA-2 family of hash functions (Peter Eisentraut)
Specifically,
sha224(),sha256(),sha384(),sha512()were added.Original release occurrence ·
11.0/changes/079Add support for 64-bit non-cryptographic hash functions Features
Add support for 64-bit non-cryptographic hash functions (Robert Haas, Amul Sul)
Original release occurrence ·
11.0/changes/080Allow to_char() and to_timestamp() to specify the time zone's offset from UTC in hours and minutes Features
Allow
to_char()andto_timestamp()to specify the time zone's offset from UTC in hours and minutes (Nikita Glukhov, Andrew Dunstan)This is done with format specifications
TZHandTZM.Original release occurrence ·
11.0/changes/081Add text search function websearch_to_tsquery() that supports a query syntax similar to that used by web search engines Features
Add text search function
websearch_to_tsquery()that supports a query syntax similar to that used by web search engines (Victor Drobny, Dmitry Ivanov)Original release occurrence ·
11.0/changes/082Add functions json(b)_to_tsvector() to create a text search query for matching JSON/JSONB values Features
Add functions
json(b)_to_tsvector()to create a text search query for matchingJSON/JSONBvalues (Dmitry Dolgov)Original release occurrence ·
11.0/changes/083Add SQL-level procedures, which can start and commit their own transactions Features
Add SQL-level procedures, which can start and commit their own transactions (Peter Eisentraut)
They are created with the new
CREATE PROCEDUREcommand and invoked viaCALL.The new
ALTER/DROP ROUTINEcommands allow altering/dropping of all routine-like objects, including procedures, functions, and aggregates.Also, writing
FUNCTIONis now preferred over writingPROCEDUREinCREATE OPERATORandCREATE TRIGGER, because the referenced object must be a function not a procedure. However, the old syntax is still accepted for compatibility.Original release occurrence ·
11.0/changes/084Add transaction control to PL/pgSQL, PL/Perl, PL/Python, PL/Tcl, and SPI server-side languages Features
Add transaction control to PL/pgSQL, PL/Perl, PL/Python, PL/Tcl, and SPI server-side languages (Peter Eisentraut)
Transaction control is only available within top-transaction-level procedures and nested
DOandCALLblocks that only contain otherDOandCALLblocks.Original release occurrence ·
11.0/changes/085Add the ability to define PL/pgSQL composite-type variables as not null, constant, or with initial values Features
Add the ability to define PL/pgSQL composite-type variables as not null, constant, or with initial values (Tom Lane)
Original release occurrence ·
11.0/changes/086Allow PL/pgSQL to handle changes to composite types (e.g., record, row) that happen between the first and later function executions in the same session Features
Allow PL/pgSQL to handle changes to composite types (e.g., record, row) that happen between the first and later function executions in the same session (Tom Lane)
Previously, such circumstances generated errors.
Original release occurrence ·
11.0/changes/087Add extension jsonb_plpython to transform JSONB to/from PL/Python types Features
Add extension
jsonb_plpythonto transformJSONBto/from PL/Python types (Anthony Bykov)Original release occurrence ·
11.0/changes/088Add extension jsonb_plperl to transform JSONB to/from PL/Perl types Features
Add extension
jsonb_plperlto transformJSONBto/from PL/Perl types (Anthony Bykov)Original release occurrence ·
11.0/changes/089Change libpq to disable compression by default Features
Change libpq to disable compression by default (Peter Eisentraut)
Compression is already disabled in modern OpenSSL versions, so that the libpq setting had no effect with such libraries.
Original release occurrence ·
11.0/changes/090Add DO CONTINUE option to ecpg's WHENEVER statement Features
Add
DO CONTINUEoption to ecpg'sWHENEVERstatement (Vinayak Pokale)This generates a C
continuestatement, causing a return to the top of the contained loop when the specified condition occurs.Original release occurrence ·
11.0/changes/091Add an ecpg mode to enable Oracle Pro*C-style handling of char arrays. Features
Add an ecpg mode to enable Oracle Pro*C-style handling of char arrays.
This mode is enabled with
-C.Original release occurrence ·
11.0/changes/092Add psql command \gdesc to display the names and types of the columns in a query result Features
Add psql command
\gdescto display the names and types of the columns in a query result (Pavel Stehule)Original release occurrence ·
11.0/changes/093Add psql variables to report query activity and errors Features
Add psql variables to report query activity and errors (Fabien Coelho)
Specifically, the new variables are
ERROR,SQLSTATE,ROW_COUNT,LAST_ERROR_MESSAGE, andLAST_ERROR_SQLSTATE.Original release occurrence ·
11.0/changes/094Allow psql to test for the existence of a variable Features
Allow psql to test for the existence of a variable (Fabien Coelho)
Specifically, the syntax
:{?variable_name}allows a variable's existence to be tested in an\ifstatement.Original release occurrence ·
11.0/changes/095Allow environment variable PSQL_PAGER to control psql's pager Features
Allow environment variable
PSQL_PAGERto control psql's pager (Pavel Stehule)This allows psql's default pager to be specified as a separate environment variable from the pager for other applications.
PAGERis still honored ifPSQL_PAGERis not set.Original release occurrence ·
11.0/changes/096Make psql's \d+ command always show the table's partitioning information Features
Make psql's
\d+command always show the table's partitioning information (Amit Langote, Ashutosh Bapat)Previously, partition information would not be displayed for a partitioned table if it had no partitions. Also indicate which partitions are themselves partitioned.
Original release occurrence ·
11.0/changes/097Ensure that psql reports the proper user name when prompting for a password Features
Ensure that psql reports the proper user name when prompting for a password (Tom Lane)
Previously, combinations of
-Uand a user name embedded in a URI caused incorrect reporting. Also suppress the user name before the password prompt when--passwordis specified.Original release occurrence ·
11.0/changes/098Allow quit and exit to exit psql when given with no prior input Features
Allow
quitandexitto exit psql when given with no prior input (Bruce Momjian)Also print hints about how to exit when
quitandexitare used alone on a line while the input buffer is not empty. Add a similar hint forhelp.Original release occurrence ·
11.0/changes/099Make psql hint at using control-D when \q is entered alone on a line but ignored Features
Make psql hint at using control-D when
\qis entered alone on a line but ignored (Bruce Momjian)For example,
\qdoes not exit when supplied in character strings.Original release occurrence ·
11.0/changes/100Improve tab completion for ALTER INDEX RESET/SET Features
Improve tab completion for
ALTER INDEX RESET/SET(Masahiko Sawada)Original release occurrence ·
11.0/changes/101Add infrastructure to allow psql to adapt its tab completion queries based on the server version Features
Add infrastructure to allow psql to adapt its tab completion queries based on the server version (Tom Lane)
Previously, tab completion queries could fail against older servers.
Original release occurrence ·
11.0/changes/102Add pgbench expression support for NULLs, booleans, and some functions and operators Features
Add pgbench expression support for NULLs, booleans, and some functions and operators (Fabien Coelho)
Original release occurrence ·
11.0/changes/103Add \if conditional support to pgbench Features
Add
\ifconditional support to pgbench (Fabien Coelho)Original release occurrence ·
11.0/changes/104Allow the use of non-ASCII characters in pgbench variable names Features
Allow the use of non-ASCII characters in pgbench variable names (Fabien Coelho)
Original release occurrence ·
11.0/changes/105Add pgbench option --init-steps to control the initialization steps performed Features
Add pgbench option
--init-stepsto control the initialization steps performed (Masahiko Sawada)Original release occurrence ·
11.0/changes/106Add an approximately Zipfian-distributed random generator to pgbench Features
Add an approximately Zipfian-distributed random generator to pgbench (Alik Khilazhev)
Original release occurrence ·
11.0/changes/107Allow the random seed to be set in pgbench Features
Allow the random seed to be set in pgbench (Fabien Coelho)
Original release occurrence ·
11.0/changes/108Allow pgbench to do exponentiation with pow() and power() Features
Allow pgbench to do exponentiation with
pow()andpower()(Raúl Marín Rodríguez)Original release occurrence ·
11.0/changes/109Add hashing functions to pgbench Features
Add hashing functions to pgbench (Ildar Musin)
Original release occurrence ·
11.0/changes/110Make pgbench statistics more accurate when using --latency-limit and --rate Features
Make pgbench statistics more accurate when using
--latency-limitand--rate(Fabien Coelho)Original release occurrence ·
11.0/changes/111Add an option to pg_basebackup that creates a named replication slot Features
Add an option to pg_basebackup that creates a named replication slot (Michael Banck)
The option
--create-slotcreates the named replication slot (--slot) when the WAL streaming method (--wal-method=stream) is used.Original release occurrence ·
11.0/changes/112Allow initdb to set group read access to the data directory Features
Allow initdb to set group read access to the data directory (David Steele)
This is accomplished with the new initdb option
--allow-group-access. Administrators can also set group permissions on the empty data directory before running initdb. Server variabledata_directory_modeallows reading of data directory group permissions.Original release occurrence ·
11.0/changes/113Add pg_verify_checksums tool to verify database checksums while offline Features
Add pg_verify_checksums tool to verify database checksums while offline (Magnus Hagander)
Original release occurrence ·
11.0/changes/114Allow pg_resetwal to change the WAL segment size via --wal-segsize Features
Allow pg_resetwal to change the WAL segment size via
--wal-segsize(Nathan Bossart)Original release occurrence ·
11.0/changes/115Add long options to pg_resetwal and pg_controldata Features
Add long options to pg_resetwal and pg_controldata (Nathan Bossart, Peter Eisentraut)
Original release occurrence ·
11.0/changes/116Add pg_receivewal option --no-sync to prevent synchronous WAL writes, for testing Features
Add pg_receivewal option
--no-syncto prevent synchronous WAL writes, for testing (Michael Paquier)Original release occurrence ·
11.0/changes/117Add pg_receivewal option --endpos to specify when WAL receiving should stop Features
Add pg_receivewal option
--endposto specify when WAL receiving should stop (Michael Paquier)Original release occurrence ·
11.0/changes/118Allow pg_ctl to send the SIGKILL signal to processes Features
Allow pg_ctl to send the
SIGKILLsignal to processes (Andres Freund)This was previously unsupported due to concerns over possible misuse.
Original release occurrence ·
11.0/changes/119Reduce the number of files copied by pg_rewind Features
Reduce the number of files copied by pg_rewind (Michael Paquier)
Original release occurrence ·
11.0/changes/120Prevent pg_rewind from running as root Features
Prevent pg_rewind from running as
root(Michael Paquier)Original release occurrence ·
11.0/changes/121Add pg_dumpall option --encoding to control output encoding Features
Add pg_dumpall option
--encodingto control output encoding (Michael Paquier)pg_dump already had this option.
Original release occurrence ·
11.0/changes/122Add pg_dump option --load-via-partition-root to force loading of data into the partition's root table, rather than the original partition Features
Add pg_dump option
--load-via-partition-rootto force loading of data into the partition's root table, rather than the original partition (Rushabh Lathia)This is useful if the system to be loaded to has different collation definitions or endianness, possibly requiring rows to be stored in different partitions than previously.
Original release occurrence ·
11.0/changes/123Add an option to suppress dumping and restoring database object comments Features
Add an option to suppress dumping and restoring database object comments (Robins Tharakan)
The new pg_dump, pg_dumpall, and pg_restore option is
--no-comments.Original release occurrence ·
11.0/changes/124Add PGXS support for installing include files Features
Add PGXS support for installing include files (Andrew Gierth)
This supports creating extension modules that depend on other modules. Formerly there was no easy way for the dependent module to find the referenced one's include files. Several existing
contribmodules that define data types have been adjusted to install relevant files. Also, PL/Perl and PL/Python now install their include files, to support creation of transform modules for those languages.Original release occurrence ·
11.0/changes/125Install errcodes.txt to allow extensions to access the list of error codes known to PostgreSQL Features
Install
errcodes.txtto allow extensions to access the list of error codes known to PostgreSQL (Thomas Munro)Original release occurrence ·
11.0/changes/126Convert documentation to DocBook XML Features
Convert documentation to DocBook XML (Peter Eisentraut, Alexander Lakhin, Jürgen Purtz)
The file names still use an
sgmlextension for compatibility with back branches.Original release occurrence ·
11.0/changes/127Use stdbool.h to define type bool on platforms where it's suitable, which is most Features
Use
stdbool.hto define typeboolon platforms where it's suitable, which is most (Peter Eisentraut)This eliminates a coding hazard for extension modules that need to include
stdbool.h.Original release occurrence ·
11.0/changes/128Overhaul the way that initial system catalog contents are defined Features
Overhaul the way that initial system catalog contents are defined (John Naylor)
The initial data is now represented in Perl data structures, making it much easier to manipulate mechanically.
Original release occurrence ·
11.0/changes/129Prevent extensions from creating custom server parameters that take a quoted list of values Features
Prevent extensions from creating custom server parameters that take a quoted list of values (Tom Lane)
This cannot be supported at present because knowledge of the parameter's property would be required even before the extension is loaded.
Original release occurrence ·
11.0/changes/130Add ability to use channel binding when using SCRAM authentication Features
Add ability to use channel binding when using SCRAM authentication (Michael Paquier)
Channel binding is intended to prevent man-in-the-middle attacks, but SCRAM cannot prevent them unless it can be forced to be active. Unfortunately, there is no way to do that in libpq. Support for it is expected in future versions of libpq and in interfaces not built using libpq, e.g., JDBC.
Original release occurrence ·
11.0/changes/131Allow background workers to attach to databases that normally disallow connections Features
Allow background workers to attach to databases that normally disallow connections (Magnus Hagander)
Original release occurrence ·
11.0/changes/132Add support for hardware CRC calculations on ARMv8 Features
Add support for hardware CRC calculations on ARMv8 (Yuqi Gu, Heikki Linnakangas, Thomas Munro)
Original release occurrence ·
11.0/changes/133Speed up lookups of built-in functions by OID Performance
Speed up lookups of built-in functions by OID (Andres Freund)
The previous binary search has been replaced by a lookup array.
Original release occurrence ·
11.0/changes/134Speed up construction of query results Performance
Speed up construction of query results (Andres Freund)
Original release occurrence ·
11.0/changes/135Improve speed of access to system caches Features
Improve speed of access to system caches (Andres Freund)
Original release occurrence ·
11.0/changes/136Add a generational memory allocator which is optimized for serial allocation/deallocation Features
Add a generational memory allocator which is optimized for serial allocation/deallocation (Tomas Vondra)
This reduces memory usage for logical decoding.
Original release occurrence ·
11.0/changes/137Make the computation of pg_class.reltuples by VACUUM consistent with its computation by ANALYZE Features
Make the computation of
pg_class.reltuplesbyVACUUMconsistent with its computation byANALYZE(Tomas Vondra)Original release occurrence ·
11.0/changes/138Update to use perltidy version 20170521 Features
Update to use perltidy version
20170521(Tom Lane, Peter Eisentraut)Original release occurrence ·
11.0/changes/139Allow extension pg_prewarm to restore the previous shared buffer contents on startup Features
Allow extension
pg_prewarmto restore the previous shared buffer contents on startup (Mithun Cy, Robert Haas)This is accomplished by having
pg_prewarmstore the shared buffers' relation and block number data to disk occasionally during server operation, and at shutdown.Original release occurrence ·
11.0/changes/140Add pg_trgm function strict_word_similarity() to compute the similarity of whole words Features
Add
pg_trgmfunctionstrict_word_similarity()to compute the similarity of whole words (Alexander Korotkov)The function
word_similarity()already existed for this purpose, but it was designed to find similar parts of words, whilestrict_word_similarity()computes the similarity to whole words.Original release occurrence ·
11.0/changes/141Allow btree_gin to index bool, bpchar, name and uuid data types Features
Allow
btree_ginto indexbool,bpchar,nameanduuiddata types (Matheus Oliveira)Original release occurrence ·
11.0/changes/142Allow cube and seg extensions to perform index-only scans using GiST indexes Features
Original release occurrence ·
11.0/changes/143Allow retrieval of negative cube coordinates using the ~> operator Features
Allow retrieval of negative cube coordinates using the
~>operator (Alexander Korotkov)This is useful for KNN-GiST searches when looking for coordinates in descending order.
Original release occurrence ·
11.0/changes/144Add Vietnamese letter handling to the unaccent extension Features
Add Vietnamese letter handling to the
unaccentextension (Dang Minh Huong, Michael Paquier)Original release occurrence ·
11.0/changes/145Enhance amcheck to check that each heap tuple has an index entry Features
Enhance
amcheckto check that each heap tuple has an index entry (Peter Geoghegan)Original release occurrence ·
11.0/changes/146Have adminpack use the new default file system access roles Features
Have
adminpackuse the new default file system access roles (Stephen Frost)Previously, only superusers could call
adminpackfunctions; now role permissions are checked.Original release occurrence ·
11.0/changes/147Widen pg_stat_statement's query ID to 64 bits Features
Widen
pg_stat_statement's query ID to 64 bits (Robert Haas)This greatly reduces the chance of query ID hash collisions. The query ID can now potentially display as a negative value.
Original release occurrence ·
11.0/changes/148Remove the contrib/start-scripts/osx scripts since they are no longer recommended (use contrib/start-scripts/macos instead) Features
Remove the
contrib/start-scripts/osxscripts since they are no longer recommended (usecontrib/start-scripts/macosinstead) (Tom Lane)Original release occurrence ·
11.0/changes/149Remove the chkpass extension Features
Remove the
chkpassextension (Peter Eisentraut)This extension is no longer considered to be a usable security tool or example of how to write an extension.
Original release occurrence ·
11.0/changes/150
Security evidence
38 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
Fixed in this branch: 11.22. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
Fixed in this branch: 11.22. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
Fixed in this branch: 11.22. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
Fixed in this branch: 11.21. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
Fixed in this branch: 11.20. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 11.20. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
Fixed in this branch: 11.17. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 11.16. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2021-3677 · Memory disclosure in certain queries CVSS 6.5
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
Fixed in this branch: 11.13. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-3449 · CVE-2021-3449
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2021-3393 · Partition constraint violation errors leak values of denied columns CVSS 3.1
A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
Fixed in this branch: 11.11. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING CVSS 6.5
Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 11.12. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 11.12. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 11.12. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Release-note mentions:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 11.14. Component: client.
Official affected-branch entry: 11.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 11.14. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
Fixed in this branch: 11.10. Component: client.
Official affected-branch entry: 11.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
Fixed in this branch: 11.10. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
Fixed in this branch: 11.10. Component: client.
Official affected-branch entry: 11.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1
The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 11.7. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 11.9. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-14349 · Uncontrolled search path element in logical replication CVSS 7.5
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 11.9. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
Fixed in this branch: 11.8. Component: packaging.
Official affected-branch entry: 11.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
Fixed in this branch: 11.6. Component: packaging.
Official affected-branch entry: 11.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory CVSS 7.8
When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.
Fixed in this branch: 11.5. Component: packaging.
Official affected-branch entry: 11.
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file CVSS 6.7
The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 11.5. Component: packaging.
Official affected-branch entry: 11.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-10209 · Memory disclosure in cross-type comparison for hashed subplan CVSS 3.1
In a database containing hypothetical, user-defined hash equality operators, an attacker could read arbitrary bytes of server memory. For an attack to become possible, a superuser would need to create unusual operators. It is possible for operators not purpose-crafted for attack to have the properties that enable an attack, but we are not aware of specific examples. The PostgreSQL project thanks Andreas Seltenreich for reporting this problem.
Fixed in this branch: 11.5. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution CVSS 7.5
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 11.5. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2019-10164 · Stack-based buffer overflow via setting a password CVSS 7.5
An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account. Additionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account. This issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations. The PostgreSQL Project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 11.4. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2019-10130 · Selectivity estimators bypass row security policies CVSS 3.1
PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
Fixed in this branch: 11.3. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2019-10129 · Memory disclosure in partition routing CVSS 6.5
Prior to this release, a user running PostgreSQL 11 can read arbitrary bytes of server memory by executing a purpose-crafted INSERT statement to a partitioned table.
Fixed in this branch: 11.3. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 11.3. Component: packaging.
Official affected-branch entry: 11.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 11.3. Component: packaging.
Official affected-branch entry: 11.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-16850 · SQL injection in pg_upgrade and pg_dump, via CREATE TRIGGER ... REFERENCING. CVSS 8.8
Fixed in this branch: 11.1. Component: core server.
Official affected-branch entry: 11.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
No fixed version for this branch is recorded. Component: client.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases