This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalThe release updates API endpoints and client routing logic while changing CSP header handling to use express instead of helmet.
Why it matters: Security: Sets Content-Security-Policy headers via express (severity 90). Bugfix: Adjusts user task move route for Challenge tasks (severity 40).
Summary
AI summaryUpdates API, @SabreCat, and Client across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Sets Content-Security-Policy headers using express instead of helmet Sets Content-Security-Policy headers using express instead of helmet Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Uses user task move route when rearranging Challenge tasks Uses user task move route when rearranging Challenge tasks Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
API
- Security: Set Content-Security-Policy headers within
expressinstead ofhelmet(@SabreCat) - Chore: Locale files updated (@weblate contributors)
Client
- Fix: Employ user task move route, not group, when rearranging Challenge tasks (@Hafizzle)
Repo
- Docs: Add No-AI note (@SabreCat)
Security Fixes
- API security improvement – CSP headers configured directly in express instead of relying on helmet
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]