Skip to content

Hookwarden

v0.6.0 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

cli developer-tools hmac php python static-analysis
+4 more
security signature-verification typescript webhook-security

Summary

AI summary

Updates deps, engine, and chore across a mixed release.

Changes in this release

Dependency Low

Bumps @babel/traverse from 7.29.0 to 7.29.7.

Bumps @babel/traverse from 7.29.0 to 7.29.7.

Source: llm_adapter@2026-05-30

Confidence: high

Dependency Low

Bumps @actions/core from 1.11.1 to 3.0.1.

Bumps @actions/core from 1.11.1 to 3.0.1.

Source: llm_adapter@2026-05-30

Confidence: high

Dependency Low

Bumps astro from 6.3.7 to 6.3.8.

Bumps astro from 6.3.7 to 6.3.8.

Source: llm_adapter@2026-05-30

Confidence: high

Dependency Low

Bumps web-tree-sitter from 0.26.8 to 0.26.9.

Bumps web-tree-sitter from 0.26.8 to 0.26.9.

Source: llm_adapter@2026-05-30

Confidence: high

Bugfix Medium

Fixes false‑positive HMAC‑SHA256 detection in JS engine.

Fixes false‑positive HMAC‑SHA256 detection in JS engine.

Source: llm_adapter@2026-05-30

Confidence: high

Bugfix Medium

Fixes CLI single‑path no‑op and stale ENGINE_VERSION handling.

Fixes CLI single‑path no‑op and stale ENGINE_VERSION handling.

Source: llm_adapter@2026-05-30

Confidence: high

Full changelog

What's Changed

  • fix(engine): wrong-hmac-algorithm no longer false-flags correct HMAC-SHA256 in JS by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/28
  • ci(release): gate releases on actual npm installability (issue #12) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/29
  • fix(cli,engine): fix single-path no-op + stale ENGINE_VERSION by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/30
  • chore: add OSS hygiene (SECURITY.md, CONTRIBUTING, templates, dependabot) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/31
  • docs: add CI integration guide by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/37
  • docs: rule reference + coverage matrix (and fix broken docs build) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/47
  • docs(readme): slim 634→256 lines, link into docs site by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/48
  • build(deps): bump actions/create-github-app-token from 2 to 3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/32
  • build(deps): bump pnpm/action-setup from 4 to 6 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/34
  • build(deps): bump actions/upload-artifact from 4 to 7 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/33
  • build(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/35
  • build(deps): bump azure/login from 2 to 3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/36
  • build(deps): bump @babel/traverse from 7.29.0 to 7.29.7 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/46
  • build(deps): bump @actions/core from 1.11.1 to 3.0.1 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/45
  • build(deps): bump astro from 6.3.7 to 6.3.8 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/40
  • build(deps): bump web-tree-sitter from 0.26.8 to 0.26.9 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/39
  • build(deps): @babel/{parser,generator} + @actions/{exec,github} bumps (supersedes #41–#44) by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/49
  • ci: auto-merge Dependabot patch + minor bumps, hold majors by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/51
  • build(deps): bump dependabot/fetch-metadata from 2 to 3 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/52
  • build(deps): bump actions/cache from 4 to 5 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/53
  • build(deps): bump azure/trusted-signing-action from 1.2.0 to 2.0.0 by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/54
  • build(deps-dev): bump the dev-dependencies group with 10 updates by @dependabot[bot] in https://github.com/Hookwarden/hookwarden/pull/55
  • chore: first wild-scan refresh + workflow label fix by @AdelinaLipsa in https://github.com/Hookwarden/hookwarden/pull/56

New Contributors

  • @dependabot[bot] made their first contribution in https://github.com/Hookwarden/hookwarden/pull/32

Full Changelog: https://github.com/Hookwarden/hookwarden/compare/v0.5.3...v0.6.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Hookwarden

Get notified when new releases ship.

Sign up free

About Hookwarden

All releases →

Beta — feedback welcome: [email protected]