This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalThe v0.4.11 release fixes several frontend bugs and introduces a high‑severity security change that restricts public server asset access.
Why it matters: A severity 90 security fix limits exposure of public server assets; all teams should apply the update immediately to prevent unauthorized access.
Summary
AI summaryUpdates Bug Fixes, 0.4.11, and 2026-07-14 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Restrict public server assets to mitigate exposure. Restrict public server assets to mitigate exposure. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Preserve unusual video aspect ratios in frontend. Preserve unusual video aspect ratios in frontend. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Add direct thread message routes in frontend. Add direct thread message routes in frontend. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Support remote‑only sessions in frontend. Support remote‑only sessions in frontend. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Use origin host for message links in frontend. Use origin host for message links in frontend. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Use server logo for browser icons in frontend. Use server logo for browser icons in frontend. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Handle constant wrong‑sequence errors in presence module. Handle constant wrong‑sequence errors in presence module. Source: llm_adapter@2026-07-17 Confidence: high |
— |
Full changelog
0.4.11 (2026-07-14)
Bug Fixes
- frontend: add direct thread message routes (#1524) (6f644a0)
- frontend: preserve unusual video aspect ratios (#1521) (2f845af)
- frontend: support remote-only sessions (#1530) (af84281)
- frontend: use origin host for message links (#1526) (1448ecd)
- frontend: use server logo for browser icons (#1506) (41cffa9)
- presence: handle constant wrong-sequence errors (#1511) (c27cbee)
- security: restrict public server assets (#1499) (0a10c3f)
Security Fixes
- Restrict public server assets to prevent unauthorized access
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]