Skip to content

release: v0.5.1 - #59

Merged
404SecNotFound merged 1 commit into
mainfrom
release/v0.5.1
Aug 4, 2026
Merged

release: v0.5.1#59
404SecNotFound merged 1 commit into
mainfrom
release/v0.5.1

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Version bump and changelog for v0.5.1. See CHANGELOG.md for the full entry.

v0.5.0 is the current Latest release and is affected by every item in the Security section, including the cross-origin terminal hijack (F-01) and the session cookie that held the persistent master token (F-04).

Known limitations are recorded in the entry rather than omitted: F-08 (eps cap is per-process) and F-14 (remaining advisories are dev-only; their fixes drop Node 18).

952 py + 136 fe green.

A security and correctness release. Everything actionable from two independent
reviews, plus three defects found during a live LogRhythm lab session that
neither review caught.

v0.5.0 is the current Latest and is affected by all of it, including a
cross-origin hijack of the embedded terminal (F-01) and a session cookie that
was the persistent master token (F-04).

Also fixes telemetry that was simply wrong: Check Point and Palo Alto rendered
every successful REP-018 administrative login as a failed one, in exactly the
field a correlation rule matches.

Two items stay open and are recorded as known limitations rather than omitted:
F-08 (the eps cap is per-process) and F-14 (remaining advisories are dev-only
and their fixes drop Node 18).

952 py + 136 fe. black, ruff, mypy, tsc clean.
@404SecNotFound
404SecNotFound merged commit 82ab0b9 into main Aug 4, 2026
10 checks passed
@404SecNotFound
404SecNotFound deleted the release/v0.5.1 branch August 4, 2026 00:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant