This release includes 1 security fix for security teams reviewing exposed deployments.
Published 26d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
ai-agents
coding
deno
embeddings
insforge
+7 more
nextjs
oauth2
pgvector
postgresql
realtime
vectors
websockets
Affected surfaces
auth
Summary
AI summaryAuth posture hardened to fix open‑redirect and information leakage.
Full changelog
What's Changed
- Update payments doc by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1211
- fix(smtp): save Custom SMTP settings when disabling by @tonychang04 in https://github.com/InsForge/InsForge/pull/1210
- INS-160: Optimize d_test install page by @CarmenDou in https://github.com/InsForge/InsForge/pull/1212
- fix: add pg_cron retention policy for schedules.job_logs (#1162) by @dashitongzhi in https://github.com/InsForge/InsForge/pull/1206
- chore(dashboard): remove unused V2/New* dashboard experiment components by @CarmenDou in https://github.com/InsForge/InsForge/pull/1217
- Add schedule log retention by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1218
- docs: align Email SDK title by @aqilaziz in https://github.com/InsForge/InsForge/pull/1219
- feat(metadata): expose auth.allowed_redirect_urls for config-as-code MVP by @tonychang04 in https://github.com/InsForge/InsForge/pull/1216
- fix(compute): use APP_KEY as Fly network name (short, validator-safe) by @tonychang04 in https://github.com/InsForge/InsForge/pull/1224
- docs: refresh README tagline, intro, and launch video by @honoyomu in https://github.com/InsForge/InsForge/pull/1225
- fix(readme): use bare URL so GitHub renders the demo video by @tonychang04 in https://github.com/InsForge/InsForge/pull/1226
- security(auth): harden auth posture (fix open-redirect & info-leak) by @hamza-hafeez82 in https://github.com/InsForge/InsForge/pull/1214
New Contributors
- @dashitongzhi made their first contribution in https://github.com/InsForge/InsForge/pull/1206
- @aqilaziz made their first contribution in https://github.com/InsForge/InsForge/pull/1219
- @hamza-hafeez82 made their first contribution in https://github.com/InsForge/InsForge/pull/1214
Full Changelog: https://github.com/InsForge/InsForge/compare/v2.1.1...v2.1.2
Security Fixes
- auth: harden posture – fix open‑redirect and info‑leak vulnerabilities
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About InsForge
All releases →Related context
Related tools
Earlier breaking changes
- v2.1.8 Restricts raw SQL permission to project_admin role only.
Beta — feedback welcome: [email protected]