Skip to content

InsForge

v2.2.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-agents coding deno embeddings insforge
+7 more
nextjs oauth2 pgvector postgresql realtime vectors websockets

Affected surfaces

auth

Summary

AI summary

Updates dashboard, INS-417, and deps across a mixed release.

Full changelog

What's Changed

  • Send CSRF token on dashboard logout by @chandranilbakshi in https://github.com/InsForge/InsForge/pull/1605
  • fix(dashboard): make Add Record dialog scroll with many columns by @junaiddshaukat in https://github.com/InsForge/InsForge/pull/1600
  • [codex] Add e2e testing skill by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1611
  • INS-417: Minor UX tweaks for backend advisor and telemetry by @CarmenDou in https://github.com/InsForge/InsForge/pull/1616
  • fix(deps): dedupe lru-cache to a single root v11 so backend resolves the named export by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1619
  • [codex] Move toast primitives into ui package by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1615
  • INS-420 by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1621
  • Switch metric info hint to click-triggered popover by @CarmenDou in https://github.com/InsForge/InsForge/pull/1620
  • Fix UI toast progress animation export by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1622
  • fix: remove obsolete version attribute from docker-compose.yml by @Amresh-01 in https://github.com/InsForge/InsForge/pull/1623
  • feat(security): Support JWKS-verifiable RS256 login tokens with HS256 fallback by @prakharsingh-74 in https://github.com/InsForge/InsForge/pull/1597
  • fix(dashboard): default project info when dashboard runs outside an iframe by @Fermionic-Lyu in https://github.com/InsForge/InsForge/pull/1632

Full Changelog: https://github.com/InsForge/InsForge/compare/v2.2.4...v2.2.5

Security Fixes

  • feat(security): Support JWKS-verifiable RS256 login tokens with HS256 fallback

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track InsForge

Get notified when new releases ship.

Sign up free

About InsForge

All releases →

Related context

Earlier breaking changes

  • v2.2.0 Rename public‑facing Deployment terminology to Sites.
  • v2.1.8 Restricts raw SQL permission to project_admin role only.

Beta — feedback welcome: [email protected]