This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryUpdates Fixes And Improvements, Highlights, and Verification across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Hardened authentication, session revocation, public endpoints, URL handling, rate limits, and other externally exposed surfaces. Hardened authentication, session revocation, public endpoints, URL handling, rate limits, and other externally exposed surfaces. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Adds Trading 212 broker sync and additional CSV formats support. Adds Trading 212 broker sync and additional CSV formats support. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Replaces trade chart with KLineCharts and adds market-session context plus current-price display in alerts. Replaces trade chart with KLineCharts and adds market-session context plus current-price display in alerts. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Low |
Added configurable dollar‑based breakeven tolerance setting. Added configurable dollar‑based breakeven tolerance setting. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Dependency | Low |
Upgraded application dependencies and patched transitive security advisories. Upgraded application dependencies and patched transitive security advisories. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Performance | Medium |
Improves import duplicate detection, analytics caching, background recalculation queues, scheduler behavior, and frontend loading performance. Improves import duplicate detection, analytics caching, background recalculation queues, scheduler behavior, and frontend loading performance. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Preserved zero option exit prices and backfilled affected option P&L. Preserved zero option exit prices and backfilled affected option P&L. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Corrected IBKR Flex statement URL handling and OAuth sync cache invalidation. Corrected IBKR Flex statement URL handling and OAuth sync cache invalidation. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Fixed revenge‑trade grouping and cross‑symbol relationship analysis. Fixed revenge‑trade grouping and cross‑symbol relationship analysis. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Fixed health‑controller binding, malformed object log filenames, market‑status interval cleanup, and alert‑modal quote display. Fixed health‑controller binding, malformed object log filenames, market‑status interval cleanup, and alert‑modal quote display. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Refactor | Low |
Unified trade filtering so list and analytics results remain consistent. Unified trade filtering so list and analytics results remain consistent. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Refactor | Low |
Split large analytics, behavioral analytics, settings, dashboard, and CSV-parser modules for better maintainability and loading behavior. Split large analytics, behavioral analytics, settings, dashboard, and CSV-parser modules for better maintainability and loading behavior. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
Highlights
- Added Trading 212 broker sync and support for additional broker CSV formats.
- Replaced the trade chart with KLineCharts and added market-session context plus current-price display in alert creation.
- Improved import duplicate detection, analytics caching, background recalculation queues, scheduler behavior, and frontend loading performance.
- Hardened authentication, session revocation, public endpoints, URL handling, rate limits, and other externally exposed surfaces.
Fixes And Improvements
- Preserved zero option exit prices and backfilled affected option P&L.
- Added configurable dollar-based breakeven tolerance.
- Corrected IBKR Flex statement URL handling and OAuth sync cache invalidation.
- Fixed revenge-trade grouping and cross-symbol relationship analysis.
- Fixed health-controller binding, malformed object log filenames, market-status interval cleanup, and alert-modal quote display.
- Unified trade filtering so list and analytics results remain consistent.
- Split large analytics, behavioral analytics, settings, dashboard, and CSV-parser modules for better maintainability and loading behavior.
- Upgraded application dependencies and patched transitive security advisories.
Verification
- Backend:
npm test -- --runInBandpassed, 159 suites / 1,184 tests. - Frontend:
npm run test:runpassed, 22 files / 93 tests. - Frontend:
npm run buildpassed with Vite 8.1.4. - Public repository guard passed with no cloud-only paths present.
Version
- Updated both
backend/package.jsonandfrontend/package.jsonto2.8.1.
Full Changelog: https://github.com/GeneBO98/tradetally/compare/v2.8.0...v2.8.1
Security Fixes
- Hardened authentication, session revocation, public endpoints, URL handling, rate limits, and other externally exposed surfaces
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]