This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 5d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
ai
ai-assistant
apple
llm
claude
conversational-ai
+13 more
docker
emotional-ai
google
healthcare-ai
human-in-the-loop
langchain
langgraph
mcp
multi-agent
personal-assistant
self-hosted
skills
vision-ai
Affected surfaces
deps
breaking_upgrade
Summary
AI summarySecurity remediation of 16 alerts and 7 advisories plus dependency updates across deps, ADR documentation, and commit b3b3e01a.
Full changelog
Changes
- fix(ci): pyasn1 0.6.4 (CVE-2026-59886) + rlimit test wall-clock margin (b3b3e01a)
- test(agents): realign FakeStreamingService on the production contract (persistable_widgets) (d944de3a)
- chore(release): v1.25.11 — widget reliability end-to-end + security wave (ADR-136, ADR-137) (1d438002)
- docs(adr): reconstitute the 6 founding ADRs and resolve the ADR-007 conflict (#215) (fa5234db)
- docs: realign documentation with the codebase (215 files audited) (#214) (375f30a6)
- chore(deps): bump 109 npm minor/patch updates, with the vite override realigned (#213) (7d1c7cf4)
- build(deps): Bump the actions group with 6 updates (#209) (241a0d18)
- fix(security): remediate all 16 code scanning alerts and 7 advisories at source (#212) (37049474)
- fix(chat): open a long conversation at its last message, for real this time (48b8fd7d)
- fix(faq): wire the voice_mode section so its six answers finally render (22d85377)
- ci(a11y): give Firefox a HOME it owns in the periodic browser matrix (84afc33c)
Docker Images
docker pull ghcr.io/jgouviergmail/LIA-Assistant/api:v1.25.11
docker pull ghcr.io/jgouviergmail/LIA-Assistant/web:v1.25.11
Quick Start
git clone https://github.com/jgouviergmail/LIA-Assistant.git
cd LIA-Assistant
cp .env.example .env
docker compose up -d
What's Changed
- fix(security): remediate all 16 code scanning alerts and 7 advisories at source by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/212
- build(deps): Bump the actions group with 6 updates by @dependabot[bot] in https://github.com/jgouviergmail/LIA-Assistant/pull/209
- chore(deps): bump 109 npm minor/patch updates, with the vite override realigned by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/213
- docs: realign documentation with the codebase (215 files audited) by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/214
- docs(adr): reconstitute the 6 founding ADRs, resolve ADR-007 conflict by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/215
Full Changelog: https://github.com/jgouviergmail/LIA-Assistant/compare/v1.25.10...v1.25.11
Security Fixes
- fix(security): remediate all 16 code scanning alerts and 7 advisories at source (#212) (37049474)
- fix(ci): pyasn1 0.6.4 (CVE-2026-59886) + rlimit test wall-clock margin (b3b3e01a)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LIA
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]