Topics
+4 more
Affected surfaces
ReleasePort's take
Moderate signalThe release adds support for accepting container names or IDs in cloudβscoped tools and enforces the Secure flag on JWT session cookies for HTTPS requests.
Why it matters: Enforcing the Secure flag (severityβ―80) prevents JWT cookie leakage over insecure connections; new tooling input flexibility expands operational workflows.
Summary
AI summaryUpdates π Bug Fixes, π Features, and 6a014 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Set Secure flag on JWT cookie for HTTPS requests. Set Secure flag on JWT cookie for HTTPS requests. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Accept container name or id in cloudβscoped tools. Accept container name or id in cloudβscoped tools. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Show CPU/Mem as compact pills in container table on mobile. Show CPU/Mem as compact pills in container table on mobile. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Back off cloud notification dispatcher on invalid API key. Back off cloud notification dispatcher on invalid API key. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Bump cloud search timeout to 3β―seconds and map gRPC deadline to HTTPβ―504. Bump cloud search timeout to 3β―seconds and map gRPC deadline to HTTPβ―504. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Prevent DuckDB MAP inference from breaking log analytics. Prevent DuckDB MAP inference from breaking log analytics. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Fix stale stats charts after switching containers. Fix stale stats charts after switching containers. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Improve SQL analytics panel UX. Improve SQL analytics panel UX. Source: llm_adapter@2026-05-26 Confidence: high |
β |
Full changelog
Β Β Β π Features
- cloud: Accept container name or id in container-scoped tools Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4743 (6a014)
Β Β Β π Bug Fixes
- Stats charts stale for a few seconds after switching containers Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4738 (ab6c9)
- Set Secure flag on jwt cookie when request is HTTPS Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4740 (dd2eb)
- Show CPU/Mem as compact pills in container table on mobile Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4744 (a0744)
- Back off cloud notification dispatcher on invalid API key Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4747 (be352)
- Bump cloud search timeout to 3s and map gRPC deadline to 504 Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4748 (5bef7)
- Prevent DuckDB MAP inference from breaking log analytics Β -Β by @amir20 in https://github.com/amir20/dozzle/issues/4746 (9a99e)
- Improve SQL analytics panel UX Β -Β by @amir20 and Claude Opus 4.7 (1M context) in https://github.com/amir20/dozzle/issues/4749 (a51c7)
Β Β Β Β View changes on GitHub
Security Fixes
- Set Secure flag on JWT cookie when request is HTTPS
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]