This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
Affected surfaces
ReleasePort's take
Light signalDNS rebinding protection is now enabled by default in version v3.8.0.
Why it matters: Enables DNS rebinding protection automatically, reducing exposure to this attack vector for all deployments.
Summary
AI summaryDNS rebinding protection is now enabled by default.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Enables DNS rebinding protection by default. Enables DNS rebinding protection by default. Source: llm_adapter@2026-05-23 Confidence: high |
— |
Changelog
Enabling DNS rebinding protection by default. See docs for how to disable if necessary for testing.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]