This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+11 more
Summary
AI summaryAdded two new Chinese scan providers and a contributors block with live GitHub star counter to cvstart.org.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds 2 new scan providers: Meituan and Tencent. Adds 2 new scan providers: Meituan and Tencent. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds Contributors block on cvstart.org landing showing avatars of code contributors. Adds Contributors block on cvstart.org landing showing avatars of code contributors. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds Live GitHub star counter on cvstart.org header, refreshing client‑side. Adds Live GitHub star counter on cvstart.org header, refreshing client‑side. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Fixes Workday CXS requests to include browser‑like headers (UA, accept-language, origin, referer). Fixes Workday CXS requests to include browser‑like headers (UA, accept-language, origin, referer). Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
[1.119.0] — 2026-07-13
Parent career-ops v1.19.0 parity + cvstart.org landing refresh.
Added
- 2 new scan providers — Meituan (
zhaopin.meituan.com) and Tencent (careers.tencent.com): the Chinese tech boards' zero-auth public JSON APIs, host-detected or selected via an explicitprovider:, with per-keyword server-side search, paginated fetch and URL dedup — 61 adapters now (56 EN + 5 RU). +20 tests (1844). - Contributors block on the landing — cvstart.org shows the avatars of everyone who landed code (GitHub
/contributorsAPI at build time, bots filtered), localized in all 16 languages, linking to the full contributors graph. - Live GitHub star counter on the landing — the header badge now refreshes client-side from the GitHub API on every visit (build-time snapshot as fallback), and a weekly scheduled Pages rebuild keeps the snapshot + contributors list fresh; CI API calls are token-authenticated.
Fixed
- Workday CXS requests carry browser-like headers (parent #1813) — Cloudflare-gated tenants (seen live: geico) answer 500 to requests missing an ordinary UA/
accept-language/origin/referer; the fetcher now derives origin + site slug from the CXS URL itself. Glints requests gained the same browser-like UA + origin/referer, both sourced from one sharedBROWSER_LIKE_USER_AGENTconstant inhttp-json.mjs.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Career Ops UI
All releases →Beta — feedback welcome: [email protected]