This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+6 more
Affected surfaces
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bump next from 15.5.14 to 15.5.18. Bump next from 15.5.14 to 15.5.18. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Dependency | Low |
Bump fast-xml-builder from 1.1.5 to 1.2.0. Bump fast-xml-builder from 1.1.5 to 1.2.0. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Dependency | Low |
Bump postcss from 8.5.6 to 8.5.10. Bump postcss from 8.5.6 to 8.5.10. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Dependency | Low |
Bump uuid from 13.0.0 to 14.0.0. Bump uuid from 13.0.0 to 14.0.0. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Dependency | Low |
Bump lodash from 4.17.23 to 4.18.1. Bump lodash from 4.17.23 to 4.18.1. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Dependency | Low |
Bump file‑type from 21.3.0 to 21.3.2. Bump file‑type from 21.3.0 to 21.3.2. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Dependency | Low |
Add docker‑compose template for easy deployment. Add docker‑compose template for easy deployment. Source: llm_adapter@2026-06-07 Confidence: low |
— |
| Bugfix | Medium |
Prevent file uploads from leaking into memory. Prevent file uploads from leaking into memory. Source: llm_adapter@2026-06-07 Confidence: low |
— |
| Bugfix | Low |
Fix favicon upload (closes #156). Fix favicon upload (closes #156). Source: llm_adapter@2026-06-07 Confidence: high |
— |
Full changelog
What's Changed
- bump version
- fix favicon upload (closes #156)
- prevent file uploads from leaking into mem
- Bump next from 15.5.15 to 15.5.18 (#173)
- Bump fast-xml-builder from 1.1.5 to 1.2.0 (#172)
- Bump postcss from 8.5.6 to 8.5.10 (#171)
- Bump fast-xml-parser and @aws-sdk/xml-builder (#170)
- Bump uuid from 13.0.0 to 14.0.0 (#169)
- Bump dompurify from 3.3.2 to 3.4.0 (#168)
- Bump next from 15.5.14 to 15.5.15 (#167)
- Bump lodash from 4.17.23 to 4.18.1 (#166)
- Bump defu from 6.1.4 to 6.1.6 (#164)
- Bump effect and prisma (#163)
- Bump brace-expansion (#161)
- Bump yaml from 2.8.1 to 2.8.3 (#160)
- Bump picomatch (#159)
- Bump fast-xml-parser and @aws-sdk/xml-builder (#158)
- Bump next from 15.5.12 to 15.5.14 (#155)
- Bump flatted from 3.3.3 to 3.4.2 (#154)
- Bump file-type from 21.3.1 to 21.3.2 (#152)
- Add docker-compose template for easy deployment (#153)
- Bump file-type from 21.3.0 to 21.3.1 (#151)
Docker Images
docker.io/flintsh/flare:1.7.4ghcr.io/flintsh/flare:1.7.4
Deploy with Railway: https://railway.com/template/JVT41u?referralCode=R5s8WT
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Flare
A nonbloated, modern, and highly configurable file/screenshot vault server with support for ShareX, Flameshot, and Spectacle. Offers OCR search and more. `MIT` `Docker/Nodejs`
Related context
Related tools
Beta — feedback welcome: [email protected]