Skip to content

Haraka

v3.3.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

dkim haraka javascript mta nodejs smtp
+1 more
spf

Affected surfaces

deps

Summary

AI summary

Updates outbound/hmail, plugins.js, and server across a mixed release.

Full changelog
  • security: bump dep versions to latest
  • lint(outbound/hmail): == -> ===
  • lint(plugins.js): var -> const
  • chore(server): add node: prefix
  • npm ignore, remove tests and clutter (#3602)
  • remove tooling from NPM release

Security Fixes

  • Bumped dep versions to latest — includes unspecified CVE mitigations

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Haraka

Get notified when new releases ship.

Sign up free

About Haraka

Fast, highly extensible, and event driven SMTP server.

All releases →

Related context

Related tools

Earlier breaking changes

  • v3.2.0 Replaces address-rfc2821 and address-rfc2822 dependencies with @haraka/email-address.

Beta — feedback welcome: [email protected]