This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 5d
Reverse Proxies & Load Balancers
✓ No known CVEs patched
This release patches 2 known CVEs
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Bug Fixes, 1.8.0, and 2026-07-21 across a mixed release.
Full changelog
1.8.0 (2026-07-21)
Features
- enhance security protocols and implement governance channel (cedfbc2)
Bug Fixes
- avoid t.Errorf inside goroutine in suspend_test.go (425a68e)
- convert session nano values back to USD in CheckAndReserveSession (feb18b6)
- deep-copy maps in pricing MergeRemote to prevent concurrent map mutation data race (55bd3e2)
- e2e: update E2E test to use loopers hostname instead of localhost to bypass SSRF protection (6fd4f22)
- resolve budget config parsing format mismatch for redis clustering (66c3dbc)
- resolve data race in budget LeaseID assignment (efed8eb)
- security: resolve VULN-010 Lua scientific notation and VULN-048 leaked budget headers (572662e)
Security Fixes
- VULN-010 — Lua scientific notation leakage
- VULN-048 — Budget headers leaked
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Loopers
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]