This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1mo
Secrets & Credentials
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
chat
email
messaging
onetime
onetimesecret
privacy
+1 more
secrets-management
Affected surfaces
deps
Summary
AI summaryGuarantee non-null integer secret and receipt TTL values.
Full changelog
What's Changed
- Guarantee non-null integer secret/receipt TTL (revert nullable contracts) by @syphernl in https://github.com/onetimesecret/onetimesecret/pull/3477
- Add regression tests for SSO missing-email error handling (#3478) https://github.com/onetimesecret/onetimesecret/pull/3482
- Collect changelog for v0.25.10 and v0.25.11 https://github.com/onetimesecret/onetimesecret/pull/3493
- Timestamp/TTL non-null enforcement follow-up https://github.com/onetimesecret/onetimesecret/pull/3494
Fixes
- Fix suite-order-dependent flakes in billing isolation setup https://github.com/onetimesecret/onetimesecret/pull/3476
- Fix contradictory enable prompt under entitlement error in Incoming Secrets panel https://github.com/onetimesecret/onetimesecret/pull/3492
- Standardize pass-through i18n pattern for component tests https://github.com/onetimesecret/onetimesecret/pull/3495
Dependencies
- Update dependency vite to v8.0.16 [SECURITY] by @renovate[bot] in https://github.com/onetimesecret/onetimesecret/pull/3481
- Update dependency dompurify to v3.4.9 [SECURITY] by @renovate[bot] in https://github.com/onetimesecret/onetimesecret/pull/3484
- Bump the bundler group across 1 directory with 4 updates by @dependabot[bot] in https://github.com/onetimesecret/onetimesecret/pull/3487
- Bump the npm_and_yarn group across 2 directories with 2 updates by @dependabot[bot] in https://github.com/onetimesecret/onetimesecret/pull/3488
Full Changelog: https://github.com/onetimesecret/onetimesecret/compare/v0.25.10...v0.25.11
Breaking Changes
- Secret and receipt TTL fields are now guaranteed to be non‑null integers (nullable contracts reverted).
Security Fixes
- dep: vite updated to v8.0.16 – security fix
- dep: dompurify updated to v3.4.9 – security fix
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About One Time Secret
Share sensitive information securely with self-destructing links that are only viewable once.
Related context
Related tools
Earlier breaking changes
- v0.25.5-coda Removes `site.interface.ui.homepage.trusted_ip_header` config; replaces with `site.network.trusted_proxy.header` settings.
- v0.25.5-coda Removes `site.interface.ui.homepage.trusted_proxy_depth` config; replaces with `site.network.trusted_proxy` settings.
Beta — feedback welcome: [email protected]