This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryUpdates deps, engine, and chore across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bumps @babel/traverse from 7.29.0 to 7.29.7. Bumps @babel/traverse from 7.29.0 to 7.29.7. Source: llm_adapter@2026-05-30 Confidence: high |
— |
| Dependency | Low |
Bumps @actions/core from 1.11.1 to 3.0.1. Bumps @actions/core from 1.11.1 to 3.0.1. Source: llm_adapter@2026-05-30 Confidence: high |
— |
| Dependency | Low |
Bumps astro from 6.3.7 to 6.3.8. Bumps astro from 6.3.7 to 6.3.8. Source: llm_adapter@2026-05-30 Confidence: high |
— |
| Dependency | Low |
Bumps web-tree-sitter from 0.26.8 to 0.26.9. Bumps web-tree-sitter from 0.26.8 to 0.26.9. Source: llm_adapter@2026-05-30 Confidence: high |
— |
| Bugfix | Medium |
Fixes false‑positive HMAC‑SHA256 detection in JS engine. Fixes false‑positive HMAC‑SHA256 detection in JS engine. Source: llm_adapter@2026-05-30 Confidence: high |
— |
| Bugfix | Medium |
Fixes CLI single‑path no‑op and stale ENGINE_VERSION handling. Fixes CLI single‑path no‑op and stale ENGINE_VERSION handling. Source: llm_adapter@2026-05-30 Confidence: high |
— |
Full changelog
What's Changed
- fix(engine): wrong-hmac-algorithm no longer false-flags correct HMAC-SHA256 in JS by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/28
- ci(release): gate releases on actual npm installability (issue #12) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/29
- fix(cli,engine): fix single-path no-op + stale ENGINE_VERSION by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/30
- chore: add OSS hygiene (SECURITY.md, CONTRIBUTING, templates, dependabot) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/31
- docs: add CI integration guide by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/37
- docs: rule reference + coverage matrix (and fix broken docs build) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/47
- docs(readme): slim 634→256 lines, link into docs site by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/48
- build(deps): bump actions/create-github-app-token from 2 to 3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/32
- build(deps): bump pnpm/action-setup from 4 to 6 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/34
- build(deps): bump actions/upload-artifact from 4 to 7 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/33
- build(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/35
- build(deps): bump azure/login from 2 to 3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/36
- build(deps): bump @babel/traverse from 7.29.0 to 7.29.7 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/46
- build(deps): bump @actions/core from 1.11.1 to 3.0.1 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/45
- build(deps): bump astro from 6.3.7 to 6.3.8 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/40
- build(deps): bump web-tree-sitter from 0.26.8 to 0.26.9 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/39
- build(deps): @babel/{parser,generator} + @actions/{exec,github} bumps (supersedes #41–#44) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/49
- ci: auto-merge Dependabot patch + minor bumps, hold majors by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/51
- build(deps): bump dependabot/fetch-metadata from 2 to 3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/52
- build(deps): bump actions/cache from 4 to 5 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/53
- build(deps): bump azure/trusted-signing-action from 1.2.0 to 2.0.0 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/54
- build(deps-dev): bump the dev-dependencies group with 10 updates by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/55
- chore: first wild-scan refresh + workflow label fix by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/56
New Contributors
- @dependabot[bot] made their first contribution in https://github.com/Hookwarden/hookwarden/pull/32
Full Changelog: https://github.com/Hookwarden/hookwarden/compare/v0.5.3...v0.6.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hookwarden
All releases →Related context
Beta — feedback welcome: [email protected]