This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+11 more
Affected surfaces
Summary
AI summaryAdded SECURITY.md with policy, supported versions, private vulnerability reporting, threat model, and hardening baseline.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Enables GitHub private vulnerability reporting via Security tab. Enables GitHub private vulnerability reporting via Security tab. Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Security | Medium |
Adds SECURITY.md with supported versions, private reporting flow, threat model, and hardening baseline. Adds SECURITY.md with supported versions, private reporting flow, threat model, and hardening baseline. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
Full changelog
[1.119.3] — 2026-07-13
Added
- SECURITY.md — the security policy the CONTRIBUTING guide pointed to now exists: supported versions, private reporting flow (GitHub private vulnerability reporting is now enabled on the repo — Security tab → "Report a vulnerability"), the threat model for a localhost-bound single-user app (XSS via hostile job postings / SSRF / path traversal / secret leakage / CSP weakening in scope; localhost DoS and parent-project issues out of scope) and the hardening baseline for reviewers.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Career Ops UI
All releases →Beta — feedback welcome: [email protected]