Skip to content

LIA

v1.25.11 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai ai-assistant apple llm claude conversational-ai
+13 more
docker emotional-ai google healthcare-ai human-in-the-loop langchain langgraph mcp multi-agent personal-assistant self-hosted skills vision-ai

Affected surfaces

deps breaking_upgrade

Summary

AI summary

Security remediation of 16 alerts and 7 advisories plus dependency updates across deps, ADR documentation, and commit b3b3e01a.

Full changelog

Changes

  • fix(ci): pyasn1 0.6.4 (CVE-2026-59886) + rlimit test wall-clock margin (b3b3e01a)
  • test(agents): realign FakeStreamingService on the production contract (persistable_widgets) (d944de3a)
  • chore(release): v1.25.11 — widget reliability end-to-end + security wave (ADR-136, ADR-137) (1d438002)
  • docs(adr): reconstitute the 6 founding ADRs and resolve the ADR-007 conflict (#215) (fa5234db)
  • docs: realign documentation with the codebase (215 files audited) (#214) (375f30a6)
  • chore(deps): bump 109 npm minor/patch updates, with the vite override realigned (#213) (7d1c7cf4)
  • build(deps): Bump the actions group with 6 updates (#209) (241a0d18)
  • fix(security): remediate all 16 code scanning alerts and 7 advisories at source (#212) (37049474)
  • fix(chat): open a long conversation at its last message, for real this time (48b8fd7d)
  • fix(faq): wire the voice_mode section so its six answers finally render (22d85377)
  • ci(a11y): give Firefox a HOME it owns in the periodic browser matrix (84afc33c)

Docker Images

docker pull ghcr.io/jgouviergmail/LIA-Assistant/api:v1.25.11
docker pull ghcr.io/jgouviergmail/LIA-Assistant/web:v1.25.11

Quick Start

git clone https://github.com/jgouviergmail/LIA-Assistant.git
cd LIA-Assistant
cp .env.example .env
docker compose up -d

What's Changed

  • fix(security): remediate all 16 code scanning alerts and 7 advisories at source by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/212
  • build(deps): Bump the actions group with 6 updates by @dependabot[bot] in https://github.com/jgouviergmail/LIA-Assistant/pull/209
  • chore(deps): bump 109 npm minor/patch updates, with the vite override realigned by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/213
  • docs: realign documentation with the codebase (215 files audited) by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/214
  • docs(adr): reconstitute the 6 founding ADRs, resolve ADR-007 conflict by @jgouviergmail in https://github.com/jgouviergmail/LIA-Assistant/pull/215

Full Changelog: https://github.com/jgouviergmail/LIA-Assistant/compare/v1.25.10...v1.25.11

Security Fixes

  • fix(security): remediate all 16 code scanning alerts and 7 advisories at source (#212) (37049474)
  • fix(ci): pyasn1 0.6.4 (CVE-2026-59886) + rlimit test wall-clock margin (b3b3e01a)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LIA

Get notified when new releases ship.

Sign up free

Beta — feedback welcome: [email protected]