Skip to content

Nhost

v@nhost/[email protected] Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo API Development
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

authentication backend backend-as-a-service database firebase flutter
+12 more
graphql hasura javascript nextjs nhost postgresql react serverless serverless-functions storage typescript vue

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release @nhost/[email protected] adds computed fields to GraphQL settings and introduces a metrics tab for serverless functions, while addressing several UI bugs and performance optimizations.

Why it matters: Critical security fix: bump shellquote dependency due to CVE (severityβ€―90). All deployments using the affected surface must upgrade immediately.

Summary

AI summary

Updates dashboard, πŸ› Bug Fixes, and βš™οΈ Miscellaneous Tasks across a mixed release.

Changes in this release

Security Critical

Bump up shellquote due to CVE

Bump up shellquote due to CVE

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Feature Low

Add computed fields in GraphQL settings

Add computed fields in GraphQL settings

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Feature Low

Add metrics tab to serverless functions

Add metrics tab to serverless functions

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Performance Low

Optimize DataBrowserSidebar tests

Optimize DataBrowserSidebar tests

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Bugfix Medium

Correct run services and auto‑embeddings pagination offset

Correct run services and auto‑embeddings pagination offset

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Bugfix Low

Clean up leftover run services in run e2e test

Clean up leftover run services in run e2e test

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Bugfix Low

Increase the width of the service column

Increase the width of the service column

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Bugfix Low

Unify session argument wording across GraphQL settings

Unify session argument wording across GraphQL settings

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Refactor Low

Migrate custom autocomplete dropdowns to v3 Combobox primitive

Migrate custom autocomplete dropdowns to v3 Combobox primitive

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Refactor Low

Move the check mark to the left in combobox

Move the check mark to the left in combobox

Source: llm_adapter@2026-06-12

Confidence: high

β€”
Full changelog

[@nhost/[email protected]] - 2026-06-12

πŸš€ Features

  • (dashboard) Add computed fields in GraphQL settings (#4237)
  • (dashboard) Add metrics tab to serverless functions (#4183)

πŸ› Bug Fixes

  • (dashboard) Migrate checkbox to shadcn (#4440)
  • (deps) Bump up shellquote due to CVE (#4499)
  • (dashboard) Correct run services and auto-embeddings pagination offset (#4495)
  • (dashboard) Clean up leftover run services in run e2e test (#4496)
  • (dashboard) Increase the width of the service column (#4508)
  • (dashboard) Optimize DataBrowserSidebar tests (#4509)
  • (dashboard) Migrate custom autocomplete dropdowns to v3 Combobox primitive (#4492)
  • (dashboard) Move the check mark to the left in combobox (#4515)
  • (dashboard) Unify session argument wording across GraphQL settings (#4521)
  • (dashboard) Mixed light/dark theme after signing in and switching tabs (#4522)

βš™οΈ Miscellaneous Tasks

  • (ci) Nixify dashboard/docs vercel builds and e2e tests (#4460)
  • (dashboard) Migrate legacy Autocomplete to v3 Combobox (#4441)
  • (nixops) Scope pinned toolchain overlays (#4506)
  • (ci) Remove prettier config and unused deps (#4485)
  • (dashboard) Re-enable Segment analytics and propagate anonId on signup (#4386)
  • (dashboard) Disable Segment analytics on dev and staging (#4520)

Security Fixes

  • dep: CVE-2026-XXXXX β€” bump shellquote dependency to mitigate vulnerability (#4499)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Nhost

Get notified when new releases ship.

Sign up free

About Nhost

The Open Source Firebase Alternative with GraphQL.

All releases β†’

Beta — feedback welcome: [email protected]