Skip to content

kastelldev/kastell

v1.7.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

automation cli coolify devops digitalocean docker
+10 more
dokploy hetzner linode mcp security-audit self-hosted server-management typescript vps vultr

Affected surfaces

auth rbac deps

Summary

AI summary

New kastell lock, guard, and doctor commands add production hardening, autonomous monitoring, and health analysis.

Full changelog

What's New in v1.7.0 — Guard Core

New Commands

  • kastell lock — One-command production hardening (SSH, fail2ban, UFW, sysctl, unattended-upgrades). Shows audit score before/after
  • kastell guard start|stop|status — Autonomous security monitoring daemon via remote cron (disk/RAM/CPU/audit checks every 5 min)
  • kastell backup --schedule — Cron-based automatic backups (hourly/daily/weekly/custom)
  • kastell audit --trend — Audit score trend analysis over time
  • kastell doctor <server> — Per-server proactive health analysis (disk trending, swap, stale packages, fail2ban bans, audit regression, Docker space)

New MCP Tools

  • server_guard — Start/stop/status guard daemon
  • server_doctor — Proactive health analysis (summary/json)
  • server_lock — Production hardening (dry-run/production/force)

Security

  • OWASP review: 10 security fixes
  • flatted 3.3.3 → 3.4.1 (DoS fix)

Stats

  • 571 new tests (2,467 → 3,038)
  • 12 MCP tools (was 9)
  • 3 new CLI commands (lock, guard, doctor --server)

Full changelog: https://github.com/kastelldev/kastell/blob/main/CHANGELOG.md

Security Fixes

  • flatted upgraded from 3.3.3 to 3.4.1 — fixes denial‑of‑service vulnerability

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kastelldev/kastell

Get notified when new releases ship.

Sign up free

About kastelldev/kastell

Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

All releases →

Beta — feedback welcome: [email protected]