This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+5 more
ReleasePort's take
Light signalRelease v4.8.2 includes minor dependency updates: go‑patch‑minor receives two patches, web‑patch‑minor gets four patches, and js-cookie is bumped from 3.0.5 to 3.0.7.
Why it matters: The bump of js‑cookie to version 3.0.7 addresses bugs; teams relying on this library should verify compatibility after upgrade.
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Medium |
bump the go-patch-minor group with 2 updates by @dependabot[bot] in pull #266 bump the go-patch-minor group with 2 updates by @dependabot[bot] in pull #266 Source: llm_adapter@2026-05-23 Confidence: high |
— |
| Dependency | Medium |
bump the web-patch-minor group in /web with 4 updates by @dependabot[bot] in pull #267 bump the web-patch-minor group in /web with 4 updates by @dependabot[bot] in pull #267 Source: llm_adapter@2026-05-23 Confidence: high |
— |
| Dependency | Medium |
bump js-cookie from 3.0.5 to 3.0.7 in /web by @dependabot[bot] in pull #268 bump js-cookie from 3.0.5 to 3.0.7 in /web by @dependabot[bot] in pull #268 Source: llm_adapter@2026-05-23 Confidence: low |
— |
| Dependency | Medium |
Upgrade js-cookie from 3.0.5 to 3.0.7 in /web via Dependabot PR #268 Upgrade js-cookie from 3.0.5 to 3.0.7 in /web via Dependabot PR #268 Source: granite4.1:30b@2026-05-23-audit Confidence: low |
— |
Full changelog
🎉 Ech0 v4.8.2
Try in 60 Seconds
docker run -d \
--name ech0 \
-p 6277:6277 \
-v /opt/ech0/data:/app/data \
-e JWT_SECRET="Hello Echos" \
sn0wl1n/ech0:latest
https://github.com/lin-snow/Ech0/blob/main/CHANGELOG.md
What's Changed
- chore(deps): bump the go-patch-minor group with 2 updates by @dependabot[bot] in https://github.com/lin-snow/Ech0/pull/266
- chore(deps): bump the web-patch-minor group in /web with 4 updates by @dependabot[bot] in https://github.com/lin-snow/Ech0/pull/267
- chore(deps): bump js-cookie from 3.0.5 to 3.0.7 in /web by @dependabot[bot] in https://github.com/lin-snow/Ech0/pull/268
Full Changelog: https://github.com/lin-snow/Ech0/compare/v4.8.1...v4.8.2
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Ech0
Lightweight federated publishing platform focused on personal idea sharing (documentation in Chinese).
Beta — feedback welcome: [email protected]