This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
ReleasePort's take
Moderate signalv1.118.2 removes an unused import and adds four executable guards to landing build scripts while ensuring the i18n parity gate fails on broken dictionaries and preventing `sync-assets` from writing outside `site/`. It also resolves two CodeQL alerts.
Why it matters: Addresses a high‑severity (70) security issue by resolving two CodeQL alerts, improving script safety with boundary checks and guard additions for landing build workflows.
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Resolved two CodeQL alerts (one fixed, one dismissed). Resolved two CodeQL alerts (one fixed, one dismissed). Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Added +4 executable guards to landing build scripts. Added +4 executable guards to landing build scripts. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Removed unused import in landing scripts. Removed unused import in landing scripts. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Ensured i18n parity gate fails on broken dictionary. Ensured i18n parity gate fails on broken dictionary. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Prevented `sync-assets` from writing outside `site/` directory. Prevented `sync-assets` from writing outside `site/` directory. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
[1.118.2] — 2026-07-10
Maintenance
- Landing follow-up (#118) —
site/README.mdreconciled to Astro 7 (the security upgrade in #116), unused import removed, and +4 executable guards for the landing build scripts: the i18n parity gate provably fails on a broken dictionary, andsync-assetsnever writes outsidesite/— suite 1822. Two CodeQL alerts resolved (one fixed at source, one dismissed as intended build-time behavior).
Security Fixes
- Resolved two CodeQL alerts (one fixed at source, one dismissed as intended build‑time behavior).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Career Ops UI
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]