✓ No known CVEs patched
This release patches 2 known CVEs
Topics
docker
go
kubernetes
log
logging
logging-server
+4 more
real-time
sever-events
swarm
vuejs
Affected surfaces
auth
rbac
Summary
AI summaryUpdates 🐞 Bug Fixes, 🚀 Features, and GHSA-p66q-2gfp-8v55 across a mixed release.
Full changelog
🚀 Features
- Command palette in Cmd+K search - by @amir20 and Claude Opus 4.8 in https://github.com/amir20/dozzle/issues/4861 (f348b)
- ui: Small improvements and polishments - by @LBYPatrick in https://github.com/amir20/dozzle/issues/4862 (49f62)
🐞 Bug Fixes
- Prompt for generate password on stdin when --password omitted - by @amir20 and Claude Opus 4.8 in https://github.com/amir20/dozzle/issues/4852 (73099)
- deps:
- Update all non-major dependencies - by @amir20 in https://github.com/amir20/dozzle/issues/4850 (de70c)
- security:
- Require auth for /cloud/callback (GHSA-p66q-2gfp-8v55) - by @amir20 and Claude Opus 4.8 in https://github.com/amir20/dozzle/issues/4863 (9c665)
- Scope MCP read tools to the requesting user's filter (GHSA-p66q-2gfp-8v55) - by @amir20 and Claude Opus 4.8 in https://github.com/amir20/dozzle/issues/4864 (df5a6)
View changes on GitHub
Security Fixes
- GHSA-p66q-2gfp-8v55 – Require authentication for /cloud/callback endpoint
- GHSA-p66q-2gfp-8v55 – Scope MCP read tools to the requesting user's filter
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]