This release includes 1 security fix for security teams reviewing exposed deployments.
Published 2mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
api
journal
stocks
trading
Affected surfaces
deps
breaking_upgrade
Summary
AI summaryUpdates Included changes, Verification, and TradeTally v2.6.2 across a mixed release.
Full changelog
TradeTally v2.6.2
Included changes
- Remediated backend dependency vulnerabilities identified during Snyk review by removing vulnerable runtime paths and refreshing the dependency graph.
- Replaced runtime Swagger spec generation with a checked-in generated OpenAPI spec artifact to eliminate the vulnerable
swagger-jsdocdependency while keeping/api-docsworking. - Removed the unused
autocannondependency from the backend dependency set. - Hardened background schedulers and queue workers so long-lived timers do not block clean shutdown, and removed Jest
forceExitnow that test teardown is clean. - Bumped backend and frontend versions to
2.6.2for release detection. - Hardened the marketing unsubscribe flow and added registration copy clarifying marketing email deliverability behavior.
- Added unsubscribe-related backend test coverage for controller, service, scheduler, and email behavior.
- Included the continuous futures migration repair already present in the patch release range.
Verification
snyk test --all-projectsreports no vulnerable paths.- Backend Jest suite passes on
2.6.2.
Breaking Changes
- Removed the vulnerable `swagger-jsdoc` dependency; runtime Swagger generation replaced with a checked-in OpenAPI spec artifact.
Security Fixes
- Removed vulnerable runtime paths identified by Snyk, eliminating dependency vulnerabilities.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]