Skip to content

kastelldev/kastell

v1.15.0 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

automation cli coolify devops digitalocean docker
+10 more
dokploy hetzner linode mcp security-audit self-hosted server-management typescript vps vultr

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Added Telegram bot notifications and commands, expanded audit checks to include Edge & WAF Audit and TCP Stack DDoS Hardening.

Full changelog

What's New

Added

  • Edge & WAF Audit (P88): 9 Nginx config checks + WAF detection, 30th audit category
  • TCP Stack DDoS Hardening (P89): 8 sysctl DDoS parameter checks, 31st audit category
  • kastell fix --safe (P90): SAFE/GUARDED/FORBIDDEN tier classification, mandatory backup, dry-run
  • MCP server_fix (P91): 14th MCP tool with dryRun:true default, SAFE_MODE guard
  • Telegram Bot Notifications (P92): Guard audit score monitoring, two-tier alerts
  • Telegram Bot Commands (P93): grammy bot with /status, /audit, /health, /doctor, /help
  • kastell bot start command for foreground Telegram bot
  • Interactive menu: Telegram bot entry

Changed

  • Audit categories: 29 → 31 (WAF & Reverse Proxy, DDoS Hardening)
  • Audit checks: 413 → 442
  • Tests: 5,468 → 5,499 (31 new bot module tests)

Security

  • Bot allowedChatIds middleware silently blocks unauthorized users
  • server_fix FORBIDDEN rejection blocks SSH/Firewall/Docker category fixes via MCP
  • Fix tier classification: SSH/Firewall changes always FORBIDDEN

Full Changelog: https://github.com/kastelldev/kastell/compare/v1.14.0...v1.15.0

Security Fixes

  • Bot allowedChatIds middleware silently blocks unauthorized users
  • server_fix FORBIDDEN rejection blocks SSH/Firewall/Docker category fixes via MCP
  • SSH/Firewall changes always classified as FORBIDDEN in fix tier classification

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kastelldev/kastell

Get notified when new releases ship.

Sign up free

About kastelldev/kastell

Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

All releases →

Beta — feedback welcome: [email protected]