This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+10 more
Summary
Routine maintenance release for kastelldev/kastell.
Changelog
Release v1.6.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kastelldev/kastell
Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.
Related context
Related tools
Earlier breaking changes
- v2.3.0 `server_secure firewall-status` MCP output: `rules` now an object array instead of string array.
- v2.3.0 `server_fix` MCP output shape changed: non-apply actions no longer carry `dryRun` field.
- v2.3.0 `server_fix` MCP input shape changed: `dryRun` removed, replaced by `mode: 'dry-run' | 'live'`.
- v2.3.0 Plugin SDK audit checks now require apiVersion: "2" and object-shaped checkCommand.
Beta — feedback welcome: [email protected]