This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort v0.8.5 redacts credentials and sensitive HTTP headers from logs to address CodeQL clear‑text logging alerts.
Why it matters: Redacting credentials prevents accidental exposure in logs, satisfying CodeQL clear‑text logging alerts with severity 90.
Summary
AI summaryRedacts credentials and sensitive HTTP headers from logs to address CodeQL clear‑text logging alerts.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Redacts credentials and sensitive HTTP headers from logs to prevent exposure. Redacts credentials and sensitive HTTP headers from logs to prevent exposure. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | Critical |
Breaks data flow to satisfy CodeQL clear‑text logging alerts. Breaks data flow to satisfy CodeQL clear‑text logging alerts. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
Changelog
- de9568cd921a1683409cebe5197442e0d7271041 fix(security): break data flow to satisfy CodeQL clear-text logging alerts
- 8a97ff7543c0e681ae4de8d1d866c243daedf37b fix(security): redact credentials and sensitive HTTP headers from logs
Security Fixes
- Redacts credentials and sensitive HTTP headers from logs to satisfy CodeQL clear‑text logging alerts.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Nenya
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]