This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalReleasePort v0.9.124 hardens event parameter validation and plugin handling to restrict parameters.
Why it matters: Improves security for event processing and job execution by limiting allowed parameters; severity score 70 indicates high risk.
Summary
AI summaryHarden event parameter validation to allow only plugin‑defined parameters.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Hardens event parameter validation and plugin handling to restrict parameters. Hardens event parameter validation and plugin handling to restrict parameters. Source: llm_adapter@2026-07-17 Confidence: low |
— |
| Security | Medium |
Restricts event and job parameters to those defined by plugins. Restricts event and job parameters to those defined by plugins. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
Full changelog
- Harden event parameter validation and plugin handling, so only plugin-defined params may be included in events and jobs.
Security Fixes
- Harden event parameter validation to restrict inclusion of only plugin‑defined parameters
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]