This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Media Servers
✓ No known CVEs patched
This release patches 1 known CVE
Topics
downloader
mp3
music
music-downloader
music-player
playlists
+3 more
self-hosted
spotify
spotify-downloader
Summary
AI summaryUpdates 2.8.0 (2026-06-02) Security fixes:, https://github.com/apps/dependabot, and 2026-06-02 across a mixed release.
Full changelog
2.8.0 (2026-06-02)
Security fixes:
- vulnerabilities #170
Merged pull requests:
- build(deps-dev): Bump codeflash from 0.20.5 to 0.20.6 #188 (dependabot[bot])
- feat: enrich audio tags with genre from public iTunes Search API #187 (@Ramss3s)
- build(deps-dev): Bump ruff from 0.15.14 to 0.15.15 #184 (dependabot[bot])
- build(deps): Bump uvicorn from 0.47.0 to 0.48.0 #181 (dependabot[bot])
- build(deps): Bump actions/checkout from 4 to 6 #180 (dependabot[bot])
- build(deps): Bump astral-sh/setup-uv from 6 to 7 #179 (dependabot[bot])
- Add CodeFlash GitHub Actions workflow #178 (codeflash-ai[bot])
- core: Update dependencies #177 (@henriquesebastiao)
- build(deps-dev): Bump zensical from 0.0.41 to 0.0.43 #176 (dependabot[bot])
- build(deps): Bump uvicorn from 0.46.0 to 0.47.0 #169 (dependabot[bot])
- build(deps): Bump requests from 2.34.0 to 2.34.1 #166 (dependabot[bot])
- build(deps): Bump requests from 2.33.1 to 2.34.0 #164 (dependabot[bot])
New Contributors:
- @codeflash-ai[bot] made their first contribution in https://github.com/henriquesebastiao/downtify/pull/178
- @Ramss3s made their first contribution in https://github.com/henriquesebastiao/downtify/pull/187
Full Changelog: https://github.com/henriquesebastiao/downtify/compare/2.7.0...2.8.0
Security Fixes
- CVE details omitted – security fixes addressing vulnerabilities (Issue #170)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]