Skip to content

Career Ops UI

v1.88.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 23d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

airbnb-style ashby ats career-ops claude-code cv
+11 more
express greenhouse-api hh-ru job-application job-search lever local-first no-telemetry resume self-hosted sse

Affected surfaces

deps

Summary

AI summary

Localized remaining Scan UI strings across 16 locales and disabled the X‑Powered‑By header.

Full changelog

[1.88.0] — 2026-07-04

Issue #29 polish — Scan i18n gaps + API hygiene.

  • Localized the last hardcoded Scan strings (roadmap v1.69.4): the source-summary pills (N new / M matching), the N new offers toasts, and the reloc badge now flow through t() — 4 new keys (scan.pillNew, scan.pillMatching, scan.newOffers, scan.relocBadge) across all 16 locales. Non-English users no longer see stray English in the core scan flow.
  • Disabled the X-Powered-By header (roadmap v1.69.5): app.disable('x-powered-by') in createApp() — the server no longer advertises Express. (The rest of that epic was already shipped: parentVersion strips its release-please comment, the light-mode theme toggle, modal-dismiss-on-route-change, and the Reports "Score" localization.)

Tests: tests/scan-i18n-gaps.test.mjs + an X-Powered-By-absence assertion in tests/security-headers.test.mjs.

Security Fixes

  • Removed X-Powered-By header — server no longer advertises Express

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Career Ops UI

Get notified when new releases ship.

Sign up free

About Career Ops UI

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]