Skip to content

ots

v1.21.6 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

aes256 encryption go one-time-secret

Affected surfaces

rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 1mo

This release mitigates a possible remote code execution vulnerability in GitHub Actions workflow execution and corrects biased random number generation from the CSPRNG.

Why it matters: Severity 95 mitigation of potential RCE via GitHub Actions; severity 45 fix for biased CSPRNG output—critical for security‑sensitive workloads.

Summary

AI summary

Updates chore, deps, and fix across a mixed release.

Changes in this release

Security Critical

Mitigates possible RCE through Github Actions

Mitigates possible RCE through Github Actions

Source: llm_adapter@2026-06-14

Confidence: high

Dependency Low

Updates vue to version 3.5.38

Updates vue to version 3.5.38

Source: llm_adapter@2026-06-14

Confidence: high

Dependency Low

Updates vue-i18n to version 11.4.5

Updates vue-i18n to version 11.4.5

Source: llm_adapter@2026-06-14

Confidence: high

Dependency Low

Updates vue-router to version 5.1.0

Updates vue-router to version 5.1.0

Source: llm_adapter@2026-06-14

Confidence: high

Dependency Low

Updates rconfig/v2 to version 2.6.2

Updates rconfig/v2 to version 2.6.2

Source: llm_adapter@2026-06-14

Confidence: high

Dependency Low

Updates go-redis/v9 to version 9.20.1

Updates go-redis/v9 to version 9.20.1

Source: llm_adapter@2026-06-14

Confidence: high

Dependency Low

Updates go_helpers module to latest revision

Updates go_helpers module to latest revision

Source: llm_adapter@2026-06-14

Confidence: low

Dependency Low

Updates github.com/luzifer/go_helpers/... module

Updates github.com/luzifer/go_helpers/... module

Source: granite4.1:30b@2026-06-14-audit

Confidence: low

Bugfix Medium

Fixes broken path handling for duplicate files

Fixes broken path handling for duplicate files

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Corrects biased random number generation from CSPRNG

Corrects biased random number generation from CSPRNG

Source: llm_adapter@2026-06-14

Confidence: high

Bugfix Medium

Forces overrides for vulnerabilities in node packages

Forces overrides for vulnerabilities in node packages

Source: llm_adapter@2026-06-14

Confidence: high

Full changelog
  • Improvements

    • chore: specify full container image paths (by @kovmir)
  • Bugfixes

    • fix: broken path handling in case of file duplicates
    • fix: creating biased random numbers from a cryptographically secure source
    • fix: force overrides for vulnerabilities in node packages
    • fix: mitigate possible RCE through Github Actions
    • chore: remove remains of pkg/errors
    • fix(deps): update dependency vue to v3.5.38
    • fix(deps): update dependency vue-i18n to v11.4.5
    • fix(deps): update dependency vue-router to v5.1.0
    • fix(deps): update module github.com/luzifer/go_helpers/...
    • fix(deps): update module github.com/luzifer/rconfig/v2 to v2.6.2
    • fix(deps): update module github.com/redis/go-redis/v9 to v9.20.1
  • Translations

    • chore: improve German translations
    • chore: improve Simplified Chinese translation (by @YongJie-Xie)
    • chore: update and enhance Turkish localization (by @wd006)
    • chore: update Latvian translation (by @Stegadons)
    • chore: update Ukranian translations (by @t0rik)

Security Fixes

  • Mitigate possible RCE through GitHub Actions

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ots

Get notified when new releases ship.

Sign up free

About ots

One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser

All releases →

Beta — feedback welcome: [email protected]