Skip to content

Cronicle

v0.9.124 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cron crontab multiserver scheduler

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 9d

ReleasePort v0.9.124 hardens event parameter validation and plugin handling to restrict parameters.

Why it matters: Improves security for event processing and job execution by limiting allowed parameters; severity score 70 indicates high risk.

Summary

AI summary

Harden event parameter validation to allow only plugin‑defined parameters.

Changes in this release

Security High

Hardens event parameter validation and plugin handling to restrict parameters.

Hardens event parameter validation and plugin handling to restrict parameters.

Source: llm_adapter@2026-07-17

Confidence: low

Security Medium

Restricts event and job parameters to those defined by plugins.

Restricts event and job parameters to those defined by plugins.

Source: granite4.1:30b@2026-07-17-audit

Confidence: low

Full changelog
  • Harden event parameter validation and plugin handling, so only plugin-defined params may be included in events and jobs.

Security Fixes

  • Harden event parameter validation to restrict inclusion of only plugin‑defined parameters

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Cronicle

Get notified when new releases ship.

Sign up free

About Cronicle

A simple, distributed task scheduler and runner with a web based UI.

All releases →

Related context

Beta — feedback welcome: [email protected]