This release includes 1 security fix for security teams reviewing exposed deployments.
Published 18d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ab-test
ab-testing
asp-net-core
ci-cd
c#
.net
+12 more
entitlement
experimentation
feature
feature-flags
feature-management
feature-toggles
progressive-delivery
python
release-as-code
remote-config
self-hosted
typescript
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summarySSRF protection added to the webhook sender, enhancing security.
Full changelog
What's Changed
- 🔧 chore: update streaming package version by @deleteLater in https://github.com/featbit/featbit/pull/926
- 🖍 style: dark mode initial implementation by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/919
- ✨ feat: display current version by @cosmos-explorer in https://github.com/featbit/featbit/pull/927
- ✨ feat: allow user creation if keyId unique by @jeffrey-vang in https://github.com/featbit/featbit/pull/930
- ↩️ revert: restore project switcher modal behavior by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/931
- 🚀 perf: optimize rendering of projects page by @deleteLater in https://github.com/featbit/featbit/pull/935
- 🧹 refactor: consolidated SDK token authentication flow by @CHR-LeeOlsen in https://github.com/featbit/featbit/pull/928
- 🐛 fix: redis populate race and fail fast on populate errors by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/932
- 🐛 fix: skip orphan index cache entries by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/933
- ✨ feat: validate insights data by @deleteLater in https://github.com/featbit/featbit/pull/936
- ✨ feat: permission checks for PATCH endpoints by @deleteLater in https://github.com/featbit/featbit/pull/937
- ✨ feat: add SSRF protection for the webhook sender by @tonghuaroot in https://github.com/featbit/featbit/pull/938
- ✅ tests: add tests for API and evaluation server by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/934
New Contributors
- @jeffrey-vang made their first contribution in https://github.com/featbit/featbit/pull/930
- @tonghuaroot made their first contribution in https://github.com/featbit/featbit/pull/938
Full Changelog: https://github.com/featbit/featbit/compare/5.4.2...5.4.3
Security Fixes
- Add SSRF protection for the webhook sender — mitigates server-side request forgery risk
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v5.4.1 Database schema changes require upgrade scripts for PostgreSQL and MongoDB.
- v5.4.0 Requires database schema migration scripts for PostgreSQL and MongoDB to upgrade to this release.
- v5.4.0 Migrates the `tags` parameter for tag‑management endpoints from URL query string to JSON request body.
- v5.4.0 Deprecates the standalone "Data Sync" module, integrating its capabilities into the "End Users" module.
- v5.3.4 Jwt__Key is now mandatory for HS256 signing.
Beta — feedback welcome: [email protected]