This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
Affected surfaces
ReleasePort's take
Moderate signalAlways remove the Strict-Transport-Security header in NPMplus when it is not enabled.
Why it matters: Misconfigured HSTS headers can lock browsers to HTTPS and cause access issues; removal prevents unintended enforcement in NPMplus deployments.
Summary
AI summaryUpdates Image tags, UI, and breaking across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Breaking | High |
Always remove Strict-Transport-Security header if not enabled in NPMplus Always remove Strict-Transport-Security header if not enabled in NPMplus Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Add host grouping to all host types via advanced tab in UI Add host grouping to all host types via advanced tab in UI Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Allow final "allow all" access rules in UI Allow final "allow all" access rules in UI Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Medium |
Update nginx to version 1.31.3 to fix new CVEs Update nginx to version 1.31.3 to fix new CVEs Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Perform general dependency updates Perform general dependency updates Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Change default of APPSEC_DROP_UNREADABLE_BODY to false in crowdsec config, fixing broken DELETE requests with empty body Change default of APPSEC_DROP_UNREADABLE_BODY to false in crowdsec config, fixing broken DELETE requests with empty body Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Refactor | Low |
Update list of hidden headers from OWASP secure-headers project Update list of hidden headers from OWASP secure-headers project Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
What Changed since the last release
- breaking: always remove Strict-Transport-Security header if not enabled in NPMplus
- nginx: update to 1.31.3 to fix new CVEs
- UI: add host grouping to all host types (via advanced tab) #3519
- UI: merge https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5681
- UI: allow final "allow all" access rules
- initial startup: change default of APPSEC_DROP_UNREADABLE_BODY in initial crowdsec config file to false since it break DELETE requests with an empty body
- update list of hidden headers (https://raw.githubusercontent.com/OWASP/www-project-secure-headers/refs/heads/master/ci/headers_remove.json)
- dep updates
Image tags:
docker.io/zoeyvid/npmplus:2026-07-15-r1(fixed to this release)ghcr.io/zoeyvid/npmplus:2026-07-15-r1(fixed to this release)docker.io/zoeyvid/npmplus:latest(latest stable)ghcr.io/zoeyvid/npmplus:latest(latest stable)docker.io/zoeyvid/npmplus:beta(latest beta/stable)ghcr.io/zoeyvid/npmplus:beta(latest beta/stable)
Full Changelog: https://github.com/ZoeyVid/NPMplus/compare/2026-06-25-r1...2026-07-15-r1
Breaking Changes
- Always remove Strict-Transport-Security header if not explicitly enabled in NPMplus configuration.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]