From 26de7c5eebf84bdcec3da337923fe992044aa208 Mon Sep 17 00:00:00 2001 From: opensearch-ci <83309141+opensearch-ci-bot@users.noreply.github.com> Date: Wed, 16 Sep 2026 14:28:19 -0400 Subject: [PATCH] Add release notes for 3.9.0 (#1816) Signed-off-by: opensearch-ci-bot (cherry picked from commit 965377e821eb9579d411ddba26895047f34ded51) Signed-off-by: opensearch-ci-bot --- ...ecurity-analytics.release-notes-3.9.0.0.md | 21 +++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 release-notes/opensearch-security-analytics.release-notes-3.9.0.0.md diff --git a/release-notes/opensearch-security-analytics.release-notes-3.9.0.0.md b/release-notes/opensearch-security-analytics.release-notes-3.9.0.0.md new file mode 100644 index 000000000..3d44129d2 --- /dev/null +++ b/release-notes/opensearch-security-analytics.release-notes-3.9.0.0.md @@ -0,0 +1,21 @@ +## Version 3.9.0 Release Notes + +Compatible with OpenSearch and OpenSearch Dashboards version 3.9.0 + +### Features + +* Onboard security-analytics plugin to centralized resource authorization ([#1735](https://github.com/opensearch-project/security-analytics/pull/1735)) +* Register detector and correlation-rule indices as system indices for resource-sharing framework support ([#1749](https://github.com/opensearch-project/security-analytics/pull/1749)) + +### Bug Fixes + +* Fix authorization bypass via stashContext() by adding pre-flight index permission checks and blocking cross-index terms lookup queries ([#1760](https://github.com/opensearch-project/security-analytics/pull/1760)) + +### Infrastructure + +* Fix code coverage upload action ([#1810](https://github.com/opensearch-project/security-analytics/pull/1810)) + +### Maintenance + +* Rename resource sharing feature flag to the non-experimental key ([#1815](https://github.com/opensearch-project/security-analytics/pull/1815)) +* Switch from snakeyaml to snakeyaml-engine for YAML processing ([#1812](https://github.com/opensearch-project/security-analytics/pull/1812))