Skip to content

BlazeUp-AI/Observal](https:

v1.5.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

agents analytics antigravity claude-code cli-tool codex
+11 more
cursor cursor-ai insights kiro large-language-models mcp pi playground registry self-hosted skills

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release bumps aiohttp from 3.13.5 to 3.14.0, fixing CVE‑2026‑34993 and CVE‑2026‑47265.

Why it matters: Patching resolves two critical vulnerabilities (CVSS > 7) affecting the dependency surface; update immediately if using aiohttp ≤ 3.13.5.

Summary

AI summary

Updates 1.5.0] - 2026-06-09, Performance, and Other across a mixed release.

Changes in this release

Security Critical

Bump aiohttp 3.13.5 -> 3.14.0 to fix CVE-2026-34993 and CVE-2026-47265

Bump aiohttp 3.13.5 -> 3.14.0 to fix CVE-2026-34993 and CVE-2026-47265

Source: llm_adapter@2026-06-09

Confidence: high

Security High

Redact MCP clone tokens

Redact MCP clone tokens

Source: llm_adapter@2026-06-09

Confidence: high

Security High

Validate skill slash commands

Validate skill slash commands

Source: llm_adapter@2026-06-09

Confidence: high

Feature Medium

Add remote state backend for Azure Blob Storage (infra)

Add remote state backend for Azure Blob Storage (infra)

Source: llm_adapter@2026-06-09

Confidence: high

Feature Medium

Add Antigravity CLI adapter and session parser (ide)

Add Antigravity CLI adapter and session parser (ide)

Source: llm_adapter@2026-06-09

Confidence: high

Feature Medium

Add full IDE parity for diagnose, patch, and cleanup (doctor)

Add full IDE parity for diagnose, patch, and cleanup (doctor)

Source: llm_adapter@2026-06-09

Confidence: high

Feature Low

Persist JWT keys via copy-on-start/save-on-stop pattern (infra)

Persist JWT keys via copy-on-start/save-on-stop pattern (infra)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Persist JWT keys with Azure File Share volume mount (infra)

Persist JWT keys with Azure File Share volume mount (infra)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Add /health to API path rules for CLI connectivity check (ALB)

Add /health to API path rules for CLI connectivity check (ALB)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Stream Terraform apply output live instead of capturing (deploy)

Stream Terraform apply output live instead of capturing (deploy)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Detect resource conflicts before apply and show clear fix instructions (deploy)

Detect resource conflicts before apply and show clear fix instructions (deploy)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Use token auth for GHCR image validation check (deploy)

Use token auth for GHCR image validation check (deploy)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Extend refresh token to 30 days and handle session expiry UX (auth)

Extend refresh token to 30 days and handle session expiry UX (auth)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Pass aws_region_name to LiteLLM for Bedrock calls (insights)

Pass aws_region_name to LiteLLM for Bedrock calls (insights)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Feature Low

Write hook scripts to disk on pull and derive command from script_filename (hooks)

Write hook scripts to disk on pull and derive command from script_filename (hooks)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Performance Medium

Add pagination and Redis cache to registry list endpoints (server)

Add pagination and Redis cache to registry list endpoints (server)

Source: llm_adapter@2026-06-09

Confidence: low

Performance Medium

Batch component resolution to eliminate N+1 queries (server)

Batch component resolution to eliminate N+1 queries (server)

Source: llm_adapter@2026-06-09

Confidence: low

Performance Medium

Replace stdlib json with orjson in ClickHouse inserts and session ingest (server)

Replace stdlib json with orjson in ClickHouse inserts and session ingest (server)

Source: llm_adapter@2026-06-09

Confidence: low

Bugfix Medium

Resolve API OOM crash loop and pub/sub subscriber failures (#1334)

Resolve API OOM crash loop and pub/sub subscriber failures (#1334)

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Resolve Azure deployment issues (infra)

Resolve Azure deployment issues (infra)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Bugfix Medium

Fix Postgres 18 volume mount and increase init wait to 180s (aws-standard)

Fix Postgres 18 volume mount and increase init wait to 180s (aws-standard)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Bugfix Medium

Fix CI failures – coalesce null in validation, add SPDX headers and required_version (infra)

Fix CI failures – coalesce null in validation, add SPDX headers and required_version (infra)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Bugfix Medium

Stop truncating session_stats_agg on every deploy (#1345) (ClickHouse)

Stop truncating session_stats_agg on every deploy (#1345) (ClickHouse)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Bugfix Medium

Resolve verification_uri to actual deployment URL (device‑auth)

Resolve verification_uri to actual deployment URL (device‑auth)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Refactor Low

Remove Gemini CLI stubs entirely (ide)

Remove Gemini CLI stubs entirely (ide)

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Refactor Low

Remove dead code, unreachable branches, and orphaned modules

Remove dead code, unreachable branches, and orphaned modules

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Full changelog

[1.5.0] - 2026-06-09

Added

  • add remote state backend (Azure Blob Storage) (infra) (86c468b)
  • add Azure Terraform module for self-hosted deployment (infra) (1c523fd)
  • add Antigravity CLI adapter and session parser (ide) (7b4883e)
  • update IDE_LAYER_CONFIGS with accurate file patterns (layer) (cd78179)
  • add full IDE parity for diagnose, patch, and cleanup (doctor) (ac92e21)
  • expand Terraform CI to all modules with env consistency checks (#1395) (ci) (6bac54e)
  • add AI assistance confirmation to the template (template) (371284c)
  • BYOVPC, sizing presets, standard tier module, unified deploy (infra) (0da964b)
  • promote OpenCode to first-class IDE integration (ide) (b5847b7)
  • complete Copilot CLI and VS Code integration with hooks and session parser (5acf73d)
  • integrate Codex into layer scanning and drift detection (codex) (ea3c119)
  • complete Codex CLI integration with hooks, session parser, and telemetry (da8ad0e)
  • revamp Agent Insights with provider-aware model selection (settings) (10f2fbd)
  • lock file, version pinning, and version-aware insights (d45ae2e)

Changed

  • remove Gemini CLI stubs entirely (ide) (1eae5bb)
  • remove dead code, unreachable branches, and orphaned modules (8eeb38f)

Documentation

  • add Antigravity support and IDE integration checklist (ide) (50cb528)
  • update README with Copilot and Codex IDE support, session replay section (2524ce5)
  • rebrand README — remove observability framing (#1335) (f24020c)

Fixed

  • persist JWT keys via copy-on-start/save-on-stop pattern (infra) (1b43cec)
  • persist JWT keys with Azure File Share volume mount (infra) (98bad04)
  • resolve Azure deployment issues (infra) (f52b0e4)
  • add /health to API path rules (CLI uses it for connectivity check) (alb) (0acc7e7)
  • add demo account env vars to init task for seeding (aws-standard) (64317f6)
  • fix Postgres 18 volume mount, increase init wait to 180s (aws-standard) (7c768b5)
  • stream terraform apply output live instead of capturing (deploy) (67db264)
  • detect resource conflicts before apply, show clear fix instructions (deploy) (d496132)
  • use token auth for GHCR image validation check (deploy) (621d634)
  • fix CI failures - coalesce null in validation, add SPDX headers and required_version (infra) (c5d6e17)
  • auto-fill owner from logged-in username (0f49c5c)
  • schema compat and session_events support (migrate) (2f5e430)
  • redact MCP clone tokens (security) (e26d046)
  • extend refresh token to 30 days and handle session expiry UX (auth) (fd366e6)
  • validate skill slash commands (security) (8ef5fa5)
  • stop truncating session_stats_agg on every deploy (#1345) (clickhouse) (dc52005)
  • pass aws_region_name to LiteLLM for Bedrock calls (insights) (baadd98)
  • bump aiohttp 3.13.5 -> 3.14.0 to fix CVE-2026-34993 and CVE-2026-47265 (dependency) (92dd08b)
  • resolve verification_uri to actual deployment URL (device-auth) (bd8ab19)
  • write hook scripts to disk on pull and derive command from script_filename (hooks) (b98973c)
  • resolve API OOM crash loop and pub/sub subscriber failures (#1334) (server) (ba37ce0)

Other

  • remove 7 unused frontend dependencies (web) (2b26261)
  • normalize changelog eof (8fba6db)

Performance

  • add pagination and Redis cache to registry list endpoints (server) (b13fa8d)
  • batch component resolution to eliminate N+1 queries (server) (553516f)
  • replace stdlib json with orjson in ClickHouse inserts and session ingest (server) (061e6c6)

Testing

  • use UTC clock for short-TTL cache timestamp (version-check) (c8e868b)

Breaking Changes

  • remove Gemini CLI stubs entirely (ide)
  • remove dead code, unreachable branches, and orphaned modules

Security Fixes

  • bump aiohttp 3.13.5 -> 3.14.0 to fix CVE-2026-34993 and CVE-2026-47265
  • CVE-2026-47265

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track BlazeUp-AI/Observal](https:

Get notified when new releases ship.

Sign up free

About BlazeUp-AI/Observal](https:

All releases →

Related context

Related CVEs

Earlier breaking changes

  • v1.6.0 rename logger alias to optic (audit)
  • v1.2.0 Removes legacy pre-JSONL modules in insights.
  • v1.2.0 Removes agent visibility and team access features.
  • v1.1.0 Replace deployment_mode API field with licensed boolean.
  • v0.8.0 Removes goal template, replaces with required prompt field in agent configuration.

Beta — feedback welcome: [email protected]