Skip to content

Featbit

v5.4.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 18d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ab-test ab-testing asp-net-core ci-cd c# .net
+12 more
entitlement experimentation feature feature-flags feature-management feature-toggles progressive-delivery python release-as-code remote-config self-hosted typescript

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

SSRF protection added to the webhook sender, enhancing security.

Full changelog

What's Changed

  • 🔧 chore: update streaming package version by @deleteLater in https://github.com/featbit/featbit/pull/926
  • 🖍 style: dark mode initial implementation by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/919
  • ✨ feat: display current version by @cosmos-explorer in https://github.com/featbit/featbit/pull/927
  • ✨ feat: allow user creation if keyId unique by @jeffrey-vang in https://github.com/featbit/featbit/pull/930
  • ↩️ revert: restore project switcher modal behavior by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/931
  • 🚀 perf: optimize rendering of projects page by @deleteLater in https://github.com/featbit/featbit/pull/935
  • 🧹 refactor: consolidated SDK token authentication flow by @CHR-LeeOlsen in https://github.com/featbit/featbit/pull/928
  • 🐛 fix: redis populate race and fail fast on populate errors by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/932
  • 🐛 fix: skip orphan index cache entries by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/933
  • ✨ feat: validate insights data by @deleteLater in https://github.com/featbit/featbit/pull/936
  • ✨ feat: permission checks for PATCH endpoints by @deleteLater in https://github.com/featbit/featbit/pull/937
  • ✨ feat: add SSRF protection for the webhook sender by @tonghuaroot in https://github.com/featbit/featbit/pull/938
  • ✅ tests: add tests for API and evaluation server by @wss-cadenwheeler in https://github.com/featbit/featbit/pull/934

New Contributors

  • @jeffrey-vang made their first contribution in https://github.com/featbit/featbit/pull/930
  • @tonghuaroot made their first contribution in https://github.com/featbit/featbit/pull/938

Full Changelog: https://github.com/featbit/featbit/compare/5.4.2...5.4.3

Security Fixes

  • Add SSRF protection for the webhook sender — mitigates server-side request forgery risk

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Featbit

Get notified when new releases ship.

Sign up free

About Featbit

Enterprise-grade feature flag platform that you can self-host.

All releases →

Related context

Earlier breaking changes

  • v5.4.1 Database schema changes require upgrade scripts for PostgreSQL and MongoDB.
  • v5.4.0 Requires database schema migration scripts for PostgreSQL and MongoDB to upgrade to this release.
  • v5.4.0 Migrates the `tags` parameter for tag‑management endpoints from URL query string to JSON request body.
  • v5.4.0 Deprecates the standalone "Data Sync" module, integrating its capabilities into the "End Users" module.
  • v5.3.4 Jwt__Key is now mandatory for HS256 signing.

Beta — feedback welcome: [email protected]