This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
Summary
AI summaryRollback no longer falsely reports success or double‑records failures.
Full changelog
Bug-fix release from a full-codebase audit (2 critical, 6 high, plus medium/low). No new features.
Highlights
- Rollback no longer reports a failed reversal as applied (and no longer double-records it).
- Credentials file is never wiped on a corrupt read (backup + refuse instead of resetting to {}).
- Meta access-token auto-refresh now actually runs (was silently expiring at ~60 days).
- Google Ads campaign listing no longer crashes on budgeted campaigns; Meta insights are no longer truncated to the first page.
- Anomaly detection uses a non-overlapping prior window; the native MCP server no longer leaks HTTP connections.
- SSRF-guarded outbound fetches, durable STATE.json writes, and assorted robustness fixes.
See CHANGELOG.md for the full list. PRs #354, #355.
Security Fixes
- SSRF‑guarded outbound fetches
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About logly/mureo
Framework for AI agents (Claude Code, Cursor, Codex, Gemini) to operate Google Ads, Meta Ads, and Search Console. Grounded in a local STRATEGY.md — not metric-chasing. Defense-in-depth security, local-first. Apache 2.0.
Related context
Related tools
Beta — feedback welcome: [email protected]