This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
ReleasePort's take
Moderate signalThe release bumps the click dependency from version 8.3.1 to 8.4.2, addressing CVE PYSEC‑2026‑2132.
Why it matters: Patch any project using click ≤ 8.3.1 immediately; CVE severity is high (severity 90).
Summary
AI summaryBump click to 8.4.2 clears PYSEC-2026-2132 and rebuilds the hero animation as a 4‑act faithful app miniature with a backstage reveal.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Bumps click from 8.3.1 to 8.4.2 to clear PYSEC-2026-2132. Bumps click from 8.3.1 to 8.4.2 to clear PYSEC-2026-2132. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Rebuilds the hero animation as a 4‑act faithful app miniature with a backstage reveal. Rebuilds the hero animation as a 4‑act faithful app miniature with a backstage reveal. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Changes
- chore(release): v1.25.1 — security hardening (audit Lot 1) (f896c5ce)
- fix(security): bump click 8.3.1 -> 8.4.2 to clear PYSEC-2026-2132 (5df45a63)
- feat(landing): rebuild the hero animation as a 4-act faithful app miniature with a backstage reveal (49865dff)
Docker Images
docker pull ghcr.io/jgouviergmail/LIA-Assistant/api:v1.25.1
docker pull ghcr.io/jgouviergmail/LIA-Assistant/web:v1.25.1
Quick Start
git clone https://github.com/jgouviergmail/LIA-Assistant.git
cd LIA-Assistant
cp .env.example .env
docker compose up -d
Full Changelog: https://github.com/jgouviergmail/LIA-Assistant/compare/v1.25.0...v1.25.1
Security Fixes
- click 8.3.1 -> 8.4.2 bumps to clear PYSEC-2026-2132
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LIA
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]