Skip to content

Cronicle

v0.9.120 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cron crontab multiserver scheduler

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Upgrade the sanitize-html dependency to version 2.17.5 to apply the vulnerability fix.

Why it matters: The security issue has a severity score of 90; updating resolves it and protects applications using this library.

Summary

AI summary

Fixes pending queue and log watcher edge cases.

Changes in this release

Security Critical

Bump sanitize-html dependency to version 2.17.5 for vulnerability fix.

Bump sanitize-html dependency to version 2.17.5 for vulnerability fix.

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Fix pending queue and log watcher edge cases in job.js.

Fix pending queue and log watcher edge cases in job.js.

Source: llm_adapter@2026-06-14

Confidence: high

Full changelog
  • Bump sanitize-html to v2.17.5 for vuln fix.
  • job.js: Fix pending queue and log watcher edge cases. Fixes #982.

Security Fixes

  • dep: sanitize-html v2.17.5 — vulnerability fix

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Cronicle

Get notified when new releases ship.

Sign up free

About Cronicle

A simple, distributed task scheduler and runner with a web based UI.

All releases →

Related context

Beta — feedback welcome: [email protected]