This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
Summary
AI summaryFixed 45 bugs spanning provider validation, error handling, type safety, and backup guards.
Full changelog
Fixed
- Phase 2 code review: 30 bug fixes across critical, high, medium, and low severity (3C+8H+14M+5L) — provider validation, error handling, type safety improvements
- Phase 1 remaining fixes: 15 files — provider validation hardening, audit check corrections, backup safety guards
Changed
- CI: Automatic GitHub Release workflow on tag push
- Docs (TR): Security audit section, MCP server_audit, CI pipeline example added to Turkish README
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kastelldev/kastell
Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.
Related context
Related tools
Earlier breaking changes
- v2.3.0 `server_secure firewall-status` MCP output: `rules` now an object array instead of string array.
- v2.3.0 `server_fix` MCP output shape changed: non-apply actions no longer carry `dryRun` field.
- v2.3.0 `server_fix` MCP input shape changed: `dryRun` removed, replaced by `mode: 'dry-run' | 'live'`.
- v2.3.0 Plugin SDK audit checks now require apiVersion: "2" and object-shaped checkCommand.
Beta — feedback welcome: [email protected]