This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
Summary
AI summaryNew kastell lock, guard, and doctor commands add production hardening, autonomous monitoring, and health analysis.
Full changelog
What's New in v1.7.0 — Guard Core
New Commands
kastell lock— One-command production hardening (SSH, fail2ban, UFW, sysctl, unattended-upgrades). Shows audit score before/afterkastell guard start|stop|status— Autonomous security monitoring daemon via remote cron (disk/RAM/CPU/audit checks every 5 min)kastell backup --schedule— Cron-based automatic backups (hourly/daily/weekly/custom)kastell audit --trend— Audit score trend analysis over timekastell doctor <server>— Per-server proactive health analysis (disk trending, swap, stale packages, fail2ban bans, audit regression, Docker space)
New MCP Tools
server_guard— Start/stop/status guard daemonserver_doctor— Proactive health analysis (summary/json)server_lock— Production hardening (dry-run/production/force)
Security
- OWASP review: 10 security fixes
- flatted 3.3.3 → 3.4.1 (DoS fix)
Stats
- 571 new tests (2,467 → 3,038)
- 12 MCP tools (was 9)
- 3 new CLI commands (lock, guard, doctor --server)
Full changelog: https://github.com/kastelldev/kastell/blob/main/CHANGELOG.md
Security Fixes
- flatted upgraded from 3.3.3 to 3.4.1 — fixes denial‑of‑service vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kastelldev/kastell
Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.
Related context
Related tools
Beta — feedback welcome: [email protected]