This release includes 1 security fix for security teams reviewing exposed deployments.
Published 28d
Reverse Proxies & Load Balancers
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
auth
rbac
Summary
AI summaryUpdates 1.1.0, Bug Fixes, and 2026-06-28 across a mixed release.
Full changelog
1.1.0 (2026-06-28)
Features
- Deterministic loop detection engine (f5680fd)
- Enterprise architecture hardening and stability updates (9d55de1)
- Generic providers, dynamic pricing, and Python SDK integrations (9717c43)
- MCP Domination Phase 1 implementation (74467a4)
- sdk: support Phase 1 session headers (ec81008)
- security: Phase 0 Hardening - OWASP v2 Security Events and OpenTelemetry Tracing (2b3cf8a)
- Structured Security Event Emission with OWASP Top 10 2025 integration (3f74756)
Bug Fixes
- ensure alerter is initialized even without webhook URL (7a42408)
- go mod tidy for golang 1.26.4 pipeline (2fa97e0)
- gofmt and go mod tidy for pipeline (024b3bb)
- oss: harden enforcement engine (phase 1 audit remediation) (104a1ba)
- resolve CI formatting and demo E2E tests (92623b5)
- sdk: add Phase 1 headers to all adapters, bump to v1.2.0, expand test coverage (9a40389)
- update cosign args to use --bundle (a15a022)
Security Fixes
- Phase 0 Hardening – OWASP v2 Security Events and OpenTelemetry Tracing with Structured Security Event Emission (OWASP Top 10 2025 integration)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Loopers
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]