This release includes 1 security fix for security teams reviewing exposed deployments.
Published 27d
API Development
✓ No known CVEs patched
This release patches 1 known CVE
Topics
authentication
backend
backend-as-a-service
database
firebase
flutter
+12 more
graphql
hasura
javascript
nextjs
nhost
postgresql
react
serverless
serverless-functions
storage
typescript
vue
Affected surfaces
auth
Summary
AI summaryUpdates 🐛 Bug Fixes, ⚙️ Miscellaneous Tasks, and nixops across a mixed release.
Full changelog
[[email protected]] - 2026-06-29
🚀 Features
- (constellation) Align SQLite LIKE and constraints (#4464)
🐛 Bug Fixes
- (storage) Authorize file replace before reading request body (#4446)
- (internal/lib) Consolidate / improve middleware into shared internal/lib/oapi (#4513)
- (storage) Add security response headers to file responses (#4503)
- (storage) Bound transform dimensions and blur (#4445)
⚙️ Miscellaneous Tasks
- (nixops) Drop nix-filter input in favor of pkgs.lib.fileset (#4377)
- (nixops) Fix repo after bumping nixpkgs (#4394)
- (nixops) Scope pinned toolchain overlays (#4506)
- (nixops) Bump oapi-codegen (#4523)
Security Fixes
- (storage) Add security response headers to file responses
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]