This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalThe release updates the braceβexpansion and ws dependencies to fix associated CVEs, merges GraphQL request headers into nhost-js, and refactors nixops build configuration and caching storage.
Why it matters: Security advisories addressed for brace-expansion (CVE) and ws (GHSA-58qx-3vcg-4xpx); all users of @nhost/[email protected] should upgrade to obtain the headerβmerging fix and benefit from nixops refactor improvements.
Summary
AI summaryUpdates π Bug Fixes, deps, and βοΈ Miscellaneous Tasks across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Updates brace-expansion dependency to address CVE. Updates brace-expansion dependency to address CVE. Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Security | Critical |
Patches ws advisory GHSA-58qx-3vcg-4xpx. Patches ws advisory GHSA-58qx-3vcg-4xpx. Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Dependency | Low |
Updates various packages due to multiple CVEs. Updates various packages due to multiple CVEs. Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Merges GraphQL request headers into nhost-js. Merges GraphQL request headers into nhost-js. Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Refactor | Low |
Drops nix-filter input, using pkgs.lib.fileset instead. Drops nix-filter input, using pkgs.lib.fileset instead. Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Refactor | Low |
Migrates cache storage from previous backend to r2. Migrates cache storage from previous backend to r2. Source: llm_adapter@2026-06-03 Confidence: low |
β |
| Refactor | Low |
Migrates cache storage in nixops to use r2. Migrates cache storage in nixops to use r2. Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
Full changelog
[@nhost/[email protected]] - 2026-06-03
π Bug Fixes
- (deps) Update brace-expansion due to CVE (#4306)
- (deps) Fix ws advisory (GHSA-58qx-3vcg-4xpx) (#4307)
- (nhost-js) Merge GraphQL request headers (#4437)
βοΈ Miscellaneous Tasks
- (nixops) Drop nix-filter input in favor of pkgs.lib.fileset (#4377)
- (nixops) Migrate cache to r2 (#4393)
Chore
- (deps) Update various packages due to CVEs (#4328)
Breaking Changes
- Drop nix-filter input in favor of pkgs.lib.fileset (nixops)
- Migrate cache to r2 (nixops)
Security Fixes
- CVE update for brace-expansion
- GHSA-58qx-3vcg-4xpx advisory fix for ws
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]