This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryFixed self‑updater not restarting container properly.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bumped github.com/nicholas-fedor/shoutrrr from 0.15.1 to 0.16.0 in /backend. Bumped github.com/nicholas-fedor/shoutrrr from 0.15.1 to 0.16.0 in /backend. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Bumped TanStack Table to v9.b7. Bumped TanStack Table to v9.b7. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Bumped svelte from 5.56.2 to 5.56.3. Bumped svelte from 5.56.2 to 5.56.3. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Bumped golang.org/x/sync from 0.20.0 to 0.21.0 in /backend. Bumped golang.org/x/sync from 0.20.0 to 0.21.0 in /backend. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Dependency | Low |
Bumped github.com/aws/aws-sdk-go-v2/credentials from 1.19.22 to 1.19.23 in /backend. Bumped github.com/aws/aws-sdk-go-v2/credentials from 1.19.22 to 1.19.23 in /backend. Source: granite4.1:30b@2026-06-12-audit Confidence: low |
— |
| Dependency | Low |
Bumped github.com/aws/aws-sdk-go-v2/config from 1.32.23 to 1.32.24 in /backend. Bumped github.com/aws/aws-sdk-go-v2/config from 1.32.23 to 1.32.24 in /backend. Source: granite4.1:30b@2026-06-12-audit Confidence: low |
— |
| Dependency | Low |
Bumped github.com/aws/aws-sdk-go-v2/service/ecr from 1.58.3 to 1.58.4 in /backend. Bumped github.com/aws/aws-sdk-go-v2/service/ecr from 1.58.3 to 1.58.4 in /backend. Source: granite4.1:30b@2026-06-12-audit Confidence: low |
— |
| Dependency | Low |
Bumped @sveltejs/kit from 3.0.0-next.1 to 3.0.0-next.2. Bumped @sveltejs/kit from 3.0.0-next.1 to 3.0.0-next.2. Source: granite4.1:30b@2026-06-12-audit Confidence: low |
— |
| Dependency | Low |
Bumped pnpm to v11.6.0. Bumped pnpm to v11.6.0. Source: granite4.1:30b@2026-06-12-audit Confidence: low |
— |
| Bugfix | Medium |
Self updater now correctly restarts the container. Self updater now correctly restarts the container. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
Dashboard environment counts now display in a timely manner. Dashboard environment counts now display in a timely manner. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
API keys are now capped at the user's permission level. API keys are now capped at the user's permission level. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
Webhooks are now served from the manager, closing edge command allowlist gaps. Webhooks are now served from the manager, closing edge command allowlist gaps. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
Compose updater now correctly falls back to standalone container update. Compose updater now correctly falls back to standalone container update. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
Image update checks are skipped for locally built images. Image update checks are skipped for locally built images. Source: llm_adapter@2026-06-12 Confidence: high |
— |
Full changelog
Bug fixes
- self updater not restarting container properly (#2897 by @kmendell)
- dashboard env counts not displaying in a timley manner (#2901 by @kmendell)
- user based api keys are capped at users permissions check (#2918 by @kmendell)
- serve webhooks from the manager and close edge command allowlist gaps (#2922 by @kmendell)
- compose updater not correctly falling back to standalone container update (#2923 by @kmendell)
- dont check image updates on locally built images (#2924 by @kmendell)
Dependencies
- bump github.com/nicholas-fedor/shoutrrr from 0.15.1 to 0.16.0 in /backend (#2867 by @dependabot[bot])
- bump tanstack table to v9.b7(67e00af by @kmendell)
- bump svelte from 5.56.2 to 5.56.3 (#2913 by @dependabot[bot])
- bump golang.org/x/sync from 0.20.0 to 0.21.0 in /backend (#2915 by @dependabot[bot])
- bump golang.org/x/mod from 0.36.0 to 0.37.0 in /backend (#2907 by @dependabot[bot])
- bump golang.org/x/text from 0.37.0 to 0.38.0 in /backend (#2905 by @dependabot[bot])
- bump golang.org/x/crypto from 0.52.0 to 0.53.0 in /backend (#2906 by @dependabot[bot])
- bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.22 to 1.19.23 in /backend (#2916 by @dependabot[bot])
- bump github.com/aws/aws-sdk-go-v2/config from 1.32.23 to 1.32.24 in /backend (#2914 by @dependabot[bot])
- bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.58.3 to 1.58.4 in /backend (#2912 by @dependabot[bot])
- bump @sveltejs/kit from 3.0.0-next.1 to 3.0.0-next.2 (#2909 by @dependabot[bot])
- bump pnpm to v11.6.0(3eec6c7 by @kmendell)
Full Changelog: https://github.com/getarcaneapp/arcane/compare/v2.0.2...v2.0.3
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]