Skip to content

revel-backend

v1.62.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Affected surfaces

auth rbac

Summary

AI summary

Harden questionnaire/poll access control and add a Loki log‑reader CLI.

Changes in this release

Feature Low

Add Loki log-reader CLI, skill, and /logs command.

Add Loki log-reader CLI, skill, and /logs command.

Source: llm_adapter@2026-06-10

Confidence: high

Bugfix Medium

Skip non-image files in generate_thumbnails backfill.

Skip non-image files in generate_thumbnails backfill.

Source: llm_adapter@2026-06-10

Confidence: high

Bugfix Medium

Harden questionnaire and poll access control, improve observability.

Harden questionnaire and poll access control, improve observability.

Source: llm_adapter@2026-06-10

Confidence: high

Full changelog

What's Changed

  • fix(thumbnails): skip non-image files in generate_thumbnails backfill by @biagiodistefano in https://github.com/letsrevel/revel-backend/pull/477
  • feat(scripts): Loki log-reader CLI + skill + /logs command by @biagiodistefano in https://github.com/letsrevel/revel-backend/pull/481
  • fix: harden questionnaire/poll access control and improve observability by @biagiodistefano in https://github.com/letsrevel/revel-backend/pull/482

Full Changelog: https://github.com/letsrevel/revel-backend/compare/v1.62.2...v1.62.3

Security Fixes

  • Harden questionnaire/poll access control to prevent unauthorized access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track revel-backend

Get notified when new releases ship.

Sign up free

About revel-backend

The Django backend of the Revel event platform project

All releases →

Related context

Earlier breaking changes

  • v1.72.1 Makes payment base fields (`amount`, `currency`, `platform_fee`) read-only
  • v1.72.1 Restricts organization ownership transfer to superusers only
  • v1.71.0 Checkout flow now uses a two-step reserve then session creation process.
  • v1.68.0 check-in endpoint path renamed to use ticket code (UUID or series:<uuid>) instead of ticket ID.

Beta — feedback welcome: [email protected]