Skip to content

Nhost

[email protected] scope: storage Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 27d API Development
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

authentication backend backend-as-a-service database firebase flutter
+12 more
graphql hasura javascript nextjs nhost postgresql react serverless serverless-functions storage typescript vue

Affected surfaces

auth

Summary

AI summary

Updates 🐛 Bug Fixes, ⚙️ Miscellaneous Tasks, and nixops across a mixed release.

Full changelog

[[email protected]] - 2026-06-29

🚀 Features

  • (constellation) Align SQLite LIKE and constraints (#4464)

🐛 Bug Fixes

  • (storage) Authorize file replace before reading request body (#4446)
  • (internal/lib) Consolidate / improve middleware into shared internal/lib/oapi (#4513)
  • (storage) Add security response headers to file responses (#4503)
  • (storage) Bound transform dimensions and blur (#4445)

⚙️ Miscellaneous Tasks

  • (nixops) Drop nix-filter input in favor of pkgs.lib.fileset (#4377)
  • (nixops) Fix repo after bumping nixpkgs (#4394)
  • (nixops) Scope pinned toolchain overlays (#4506)
  • (nixops) Bump oapi-codegen (#4523)

Security Fixes

  • (storage) Add security response headers to file responses

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Nhost

Get notified when new releases ship.

Sign up free

About Nhost

The Open Source Firebase Alternative with GraphQL.

All releases →

Beta — feedback welcome: [email protected]