This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalUpgrade the sanitize-html dependency to version 2.17.5 to apply the vulnerability fix.
Why it matters: The security issue has a severity score of 90; updating resolves it and protects applications using this library.
Summary
AI summaryFixes pending queue and log watcher edge cases.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Bump sanitize-html dependency to version 2.17.5 for vulnerability fix. Bump sanitize-html dependency to version 2.17.5 for vulnerability fix. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Fix pending queue and log watcher edge cases in job.js. Fix pending queue and log watcher edge cases in job.js. Source: llm_adapter@2026-06-14 Confidence: high |
— |
Full changelog
- Bump sanitize-html to v2.17.5 for vuln fix.
- job.js: Fix pending queue and log watcher edge cases. Fixes #982.
Security Fixes
- dep: sanitize-html v2.17.5 — vulnerability fix
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]