This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 0.1.1, and 2026-07-11 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Resolve CodeQL alerts by scoping analysis to product code. Resolve CodeQL alerts by scoping analysis to product code. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bump @types/node from 20.19.43 to 26.1.1 in /ui. Bump @types/node from 20.19.43 to 26.1.1 in /ui. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bump eslint from 9.39.5 to 10.7.0 in /ui. Bump eslint from 9.39.5 to 10.7.0 in /ui. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bump next from 16.2.6 to 16.2.10 in /ui. Bump next from 16.2.6 to 16.2.10 in /ui. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bump react from 19.2.4 to 19.2.7 in /ui. Bump react from 19.2.4 to 19.2.7 in /ui. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Bump react-dom from 19.2.4 to 19.2.7 in /ui. Bump react-dom from 19.2.4 to 19.2.7 in /ui. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Update anthropic requirement from >=0.40 to >=0.116.0. Update anthropic requirement from >=0.40 to >=0.116.0. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Update google‑genai requirement from >=1.0 to >=2.11.0. Update google‑genai requirement from >=1.0 to >=2.11.0. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Update uvicorn requirement from >=0.30 to >=0.51.0. Update uvicorn requirement from >=0.30 to >=0.51.0. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Repair slack-notify YAML multiline string block scalar issue. Repair slack-notify YAML multiline string block scalar issue. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
0.1.1 (2026-07-11)
Bug Fixes
- ci: repair slack-notify YAML — multiline strings broke block scalar (955ac67)
- security: resolve CodeQL alerts — scope analysis to product code (39727f9)
Dependencies
- deps: Bump @types/node from 20.19.43 to 26.1.1 in /ui (#14) (c2c275d)
- deps: Bump eslint from 9.39.5 to 10.7.0 in /ui (#16) (4494869)
- deps: Bump next from 16.2.6 to 16.2.10 in /ui (#15) (528077c)
- deps: Bump react from 19.2.4 to 19.2.7 in /ui (#13) (027075c)
- deps: Bump react-dom from 19.2.4 to 19.2.7 in /ui (#17) (a26da11)
- deps: Update anthropic requirement from >=0.40 to >=0.116.0 (#7) (70707c7)
- deps: Update google-genai requirement from >=1.0 to >=2.11.0 (#8) (e1aa575)
- deps: Update playwright requirement from >=1.40 to >=1.61.0 (#6) (71c9d1e)
- deps: Update pydantic requirement (#12) (ff76243)
- deps: Update uvicorn requirement from >=0.30 to >=0.51.0 (#9) (451dcbe)
- launch hygiene — badges, Dependabot, CodeQL (aa8fbf2)
- release-please: clean v-tags (no component prefix) + manual dispatch (8f36b63)
Documentation
Security Fixes
- Resolve CodeQL alerts — scope analysis to product code
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About isitsecure
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]