Skip to content

Loopers

v1.8.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Affected surfaces

auth rbac

Summary

AI summary

Updates Bug Fixes, 1.8.0, and 2026-07-21 across a mixed release.

Full changelog

1.8.0 (2026-07-21)

Features

  • enhance security protocols and implement governance channel (cedfbc2)

Bug Fixes

  • avoid t.Errorf inside goroutine in suspend_test.go (425a68e)
  • convert session nano values back to USD in CheckAndReserveSession (feb18b6)
  • deep-copy maps in pricing MergeRemote to prevent concurrent map mutation data race (55bd3e2)
  • e2e: update E2E test to use loopers hostname instead of localhost to bypass SSRF protection (6fd4f22)
  • resolve budget config parsing format mismatch for redis clustering (66c3dbc)
  • resolve data race in budget LeaseID assignment (efed8eb)
  • security: resolve VULN-010 Lua scientific notation and VULN-048 leaked budget headers (572662e)

Security Fixes

  • VULN-010 — Lua scientific notation leakage
  • VULN-048 — Budget headers leaked

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Loopers

Get notified when new releases ship.

Sign up free

About Loopers

All releases →

Related context

Beta — feedback welcome: [email protected]