Skip to content

GlycemicGPT

v0.9.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 2 known CVEs

Topics

artificial-intelligence cgm-remote-monitor diabetes hba1c healthcare-ai insulin-pump
+6 more
medtronic nightscout omnipod tandem type-1-diabetes type-2-diabetes

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Bump pyjwt toβ€―2.13.0 and patch starlette to address PYSEC‑2026 advisories; these updates clear known security vulnerabilities.

Why it matters: PYSEC‑2026 advisories have a severity score ofβ€―90, indicating critical risk; updating pyjwt toβ€―2.13.0 and applying the starlette patch eliminates these high‑severity issues for API runtime dependencies.

Summary

AI summary

Broad release touches https://github.com/jlengelbrecht, ✨ New Features, πŸ“ Other Changes, and medtronic.

Changes in this release

Security Critical

Bump pyjwt to 2.13.0 to clear PYSEC-2026 advisories.

Bump pyjwt to 2.13.0 to clear PYSEC-2026 advisories.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Security Critical

Patch starlette PYSEC-2026-161 and harden the ecdsa OSV exception.

Patch starlette PYSEC-2026-161 and harden the ecdsa OSV exception.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Add cross‑source CGM deduplication and primary‑source picker.

Add cross‑source CGM deduplication and primary‑source picker.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Add Sentry error monitoring to the API (disabled by default).

Add Sentry error monitoring to the API (disabled by default).

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Add Sentry error monitoring to the sidecar (disabled by default).

Add Sentry error monitoring to the sidecar (disabled by default).

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Add server‑side Sentry error monitoring to the web app (disabled by default).

Add server‑side Sentry error monitoring to the web app (disabled by default).

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Add Nightscout cloud‑source plugin to the mobile app.

Add Nightscout cloud‑source plugin to the mobile app.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Resolve 500 error on caregiver invitation creation.

Resolve 500 error on caregiver invitation creation.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Stop glucose SSE proxy from leaking aborts into Sentry.

Stop glucose SSE proxy from leaking aborts into Sentry.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Refresh Glooko card status after a failed sync/import.

Refresh Glooko card status after a failed sync/import.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Full changelog

v0.9.0

πŸ“± Mobile

✨ New Features

  • feat(mobile): Nightscout cloud-source plugin @jlengelbrecht (#712)
  • feat(medtronic): advertise-and-wait pairing UX + driver kill-switch @jlengelbrecht (#704)
  • feat(medtronic): render pump connection notes in settings card @jlengelbrecht (#703)
  • feat(medtronic): poll/persist/push pipeline integration with single-flight reads @jlengelbrecht (#702)
  • feat(medtronic): on-device BluetoothGatt-client read transport @jlengelbrecht (#701)
  • feat(medtronic): capability delegates + DevicePlugin + Hilt/:app wiring @jlengelbrecht (#700)
  • feat(medtronic): IDD status + history/RACP read-only readers @jlengelbrecht (#699)
  • feat(medtronic): session-read framework + CGM/SG, Device Info, and Battery readers @jlengelbrecht (#698)
  • feat(medtronic): peripheral-mode BLE connection manager with SAKE session and reconnect @jlengelbrecht (#697)
  • feat(medtronic): read-only BLE driver module with SAKE session and protocol constants @jlengelbrecht (#694)
  • feat(mobile): wire Sentry crash/error reporting into the Android app @jlengelbrecht (#693)

πŸ› Bug Fixes

πŸ“ Other Changes

🌐 Web

✨ New Features

πŸ› Bug Fixes

  • fix(integrations): refresh Glooko card status after a failed sync/import @jlengelbrecht (#691)
  • fix(web): stop the glucose SSE proxy from leaking aborts into Sentry @jlengelbrecht (#688)

πŸ“ Other Changes

πŸ“‘ API

✨ New Features

πŸ› Bug Fixes

πŸ“ Other Changes

πŸ€– Sidecar

✨ New Features

πŸ“ Other Changes

πŸ—οΈ Infrastructure

✨ New Features

πŸ› Bug Fixes

  • fix(ci): green develop after Medtronic Connect merge (helper-src context + x/sys CVE) @jlengelbrecht (#687)

πŸ“ Other Changes

πŸ“š Documentation

  • docs(readme): add Medtronic 700-series + web dashboard demo + trim badges @jlengelbrecht (#709)
  • docs(medtronic): OpenMinimed attribution, GPL-3.0 licensing, and BLE pairing guide @jlengelbrecht (#706)
  • docs(roadmap): name the shared memory layer under AI Engine 2.0 @jlengelbrecht (#684)
  • docs: add Sentry for Good sponsor and privacy posture @jlengelbrecht (#670)

Security Fixes

  • dep: bump pyjwt toβ€―2.13.0 to clear PYSEC-2026 advisories
  • fix(deps): patch starlette PYSEC-2026-161 and harden the ecdsa OSV exception

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track GlycemicGPT

Get notified when new releases ship.

Sign up free

About GlycemicGPT

All releases β†’

Related context

Earlier breaking changes

  • v0.13.0 Medtronic history sync behavior is fixed.
  • v0.7.0 Changes CI release-body extraction to single-shot without historical bleed

Beta — feedback welcome: [email protected]