Should I upgrade to 63.14?

Is there any way to know how important these patch versions are or confirm that they are safe / recommended? I think any sort of post confirming their existence would be helpful the only reference I can find to them is on metabase/metabase - Docker Image

The post-security patch versions are important to upgrade to if you want protection from those attacks.

The changelogs are now being updated again, so you can reference that:

Otherwise, here was the announcement of the security effort (note versions are now out of date, get current ones from the above URL):

does 63.15 also contain important security patches? Comparing v0.63.14...v0.63.15 · metabase/metabase · GitHub

It’s not there yet (as of the time of this post), but details on the update will appear at the link below. Generally speaking, though, I recommend applying minor updates as they release. Major upgrades should be tested before deploying to production.

How can we be promptly notified about important security updates (e.g. versions associated with CVE’s Overview · metabase/metabase · GitHub)? I know there’s a paid feature for this: Security center | Metabase Documentation But is there any way for us lowly open source users to find out if our instances need a critical update? We’ve had some regressions even in minor versions so we don’t automatically install them unless they incorporate important security fixes.

You can subscribe to releases and security notices on GitHub, it’ll fire off a flurry of emails when new releases are posted. That can point you to check the changelog page or the security notice for the details.

that makes sense thank you but the 63.15 changelog ( Metabase 63 changelog ) isn’t there yet after 24h so could you clarify whether it contains critical security fixes?

I don’t know, I’m not a Metabase employee, sorry.