This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
Summary
AI summaryAdded Telegram bot notifications and commands, expanded audit checks to include Edge & WAF Audit and TCP Stack DDoS Hardening.
Full changelog
What's New
Added
- Edge & WAF Audit (P88): 9 Nginx config checks + WAF detection, 30th audit category
- TCP Stack DDoS Hardening (P89): 8 sysctl DDoS parameter checks, 31st audit category
- kastell fix --safe (P90): SAFE/GUARDED/FORBIDDEN tier classification, mandatory backup, dry-run
- MCP server_fix (P91): 14th MCP tool with dryRun:true default, SAFE_MODE guard
- Telegram Bot Notifications (P92): Guard audit score monitoring, two-tier alerts
- Telegram Bot Commands (P93): grammy bot with /status, /audit, /health, /doctor, /help
kastell bot startcommand for foreground Telegram bot- Interactive menu: Telegram bot entry
Changed
- Audit categories: 29 → 31 (WAF & Reverse Proxy, DDoS Hardening)
- Audit checks: 413 → 442
- Tests: 5,468 → 5,499 (31 new bot module tests)
Security
- Bot allowedChatIds middleware silently blocks unauthorized users
- server_fix FORBIDDEN rejection blocks SSH/Firewall/Docker category fixes via MCP
- Fix tier classification: SSH/Firewall changes always FORBIDDEN
Full Changelog: https://github.com/kastelldev/kastell/compare/v1.14.0...v1.15.0
Security Fixes
- Bot allowedChatIds middleware silently blocks unauthorized users
- server_fix FORBIDDEN rejection blocks SSH/Firewall/Docker category fixes via MCP
- SSH/Firewall changes always classified as FORBIDDEN in fix tier classification
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kastelldev/kastell
Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.
Related context
Related tools
Beta — feedback welcome: [email protected]