This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+5 more
Summary
AI summaryUpdates deps, deps-dev, and fix across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add Next.js Pages Router webhook detection and raw‑body FP prevention (Phase 29). Add Next.js Pages Router webhook detection and raw‑body FP prevention (Phase 29). Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump js-yaml from 4.1.1 to 4.2.0. Bump js-yaml from 4.1.1 to 4.2.0. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump astro from 6.3.8 to 6.4.4. Bump astro from 6.3.8 to 6.4.4. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump tinyglobby from 0.2.16 to 0.2.17. Bump tinyglobby from 0.2.16 to 0.2.17. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Bump @astrojs/starlight from 0.39.2 to 0.39.3. Bump @astrojs/starlight from 0.39.2 to 0.39.3. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Eliminate two false‑positive classes and a Next.js false negative in audit scans. Eliminate two false‑positive classes and a Next.js false negative in audit scans. Source: llm_adapter@2026-06-09 Confidence: high |
— |
Full changelog
What's Changed
- Phase 25: Anthropic Agent SDK ruleset + verify_audit_chain MCP tool + EU AI Act pack v1.1 by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/58
- chore(deps-dev): bump the dev-dependencies group with 6 updates by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/59
- chore(deps): bump js-yaml from 4.1.1 to 4.2.0 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/63
- chore(deps): bump astro from 6.3.8 to 6.4.4 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/60
- chore(deps): bump tinyglobby from 0.2.16 to 0.2.17 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/61
- chore(deps): bump @astrojs/starlight from 0.39.2 to 0.39.3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/62
- fix: eliminate two false-positive classes + a Next.js false negative (real-repo scan audit) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/64
- feat: Next.js Pages Router webhook detection + raw-body FP-prevention (Phase 29) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/65
- test(29): lock papermark Pages Router regression (SC#6) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/66
- chore: refresh wild-scan table (2026-06-09) by @github-actions[bot] in https://github.com/Hookwarden/hookwarden/pull/68
Full Changelog: https://github.com/Hookwarden/hookwarden/compare/v0.7.2...v0.11.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hookwarden
All releases →Related context
Beta — feedback welcome: [email protected]