This release includes 1 security fix for security teams reviewing exposed deployments.
Published 23d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
airbnb-style
ashby
ats
career-ops
claude-code
cv
+11 more
express
greenhouse-api
hh-ru
job-application
job-search
lever
local-first
no-telemetry
resume
self-hosted
sse
Affected surfaces
deps
Summary
AI summaryLocalized remaining Scan UI strings across 16 locales and disabled the X‑Powered‑By header.
Full changelog
[1.88.0] — 2026-07-04
Issue #29 polish — Scan i18n gaps + API hygiene.
- Localized the last hardcoded Scan strings (roadmap v1.69.4): the source-summary pills (
N new / M matching), theN new offerstoasts, and therelocbadge now flow throught()— 4 new keys (scan.pillNew,scan.pillMatching,scan.newOffers,scan.relocBadge) across all 16 locales. Non-English users no longer see stray English in the core scan flow. - Disabled the
X-Powered-Byheader (roadmap v1.69.5):app.disable('x-powered-by')increateApp()— the server no longer advertises Express. (The rest of that epic was already shipped:parentVersionstrips its release-please comment, the light-mode theme toggle, modal-dismiss-on-route-change, and the Reports "Score" localization.)
Tests: tests/scan-i18n-gaps.test.mjs + an X-Powered-By-absence assertion in tests/security-headers.test.mjs.
Security Fixes
- Removed X-Powered-By header — server no longer advertises Express
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Career Ops UI
All releases →Beta — feedback welcome: [email protected]