This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
Summary
AI summaryGHSA-3m74-8cg9-rp8j, GHSA-4c6j-p2cv-wf56, and Node 20 EOL removal update server images to Node 22.
Full changelog
Security
- [x] Status pages: public payloads now use a strict allowlist of monitor fields — credentials and internal configuration are never sent to visitors (GHSA-3m74-8cg9-rp8j)
- [x] Monitor advanced matching now uses RE2 with tightened regex validation — fixes ReDoS via user-controlled regex (GHSA-4c6j-p2cv-wf56)
Fixes
-
[x] Docker: server images moved from Node 20 (EOL) to Node 22 — fixes broken image builds caused by
re2native compilation -
[x] Added root
.dockerignoreso hostnode_modulesand.envfiles no longer leak into image builds -
[x] New unit suite covering the public status-page payload
Breaking Changes
- Docker server images moved from Node 20 (EOL) to Node 22 — requires rebuilds.
Security Fixes
- GHSA-3m74-8cg9-rp8j – Status pages now use a strict allowlist, preventing credentials and internal config leakage.
- GHSA-4c6j-p2cv-wf56 – Monitor advanced matching switched to RE2 with tightened regex validation, fixing ReDoS via user‑controlled regex.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Checkmate
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Don't be shy, join here: https://discord.com/invite/NAb6H3UTjK :)
Related context
Related tools
Beta — feedback welcome: [email protected]