Skip to content

One Time Secret

v0.25.11 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

chat email messaging onetime onetimesecret privacy
+1 more
secrets-management

Affected surfaces

deps

Summary

AI summary

Guarantee non-null integer secret and receipt TTL values.

Full changelog

What's Changed

  • Guarantee non-null integer secret/receipt TTL (revert nullable contracts) by @syphernl in https://github.com/onetimesecret/onetimesecret/pull/3477
  • Add regression tests for SSO missing-email error handling (#3478) https://github.com/onetimesecret/onetimesecret/pull/3482
  • Collect changelog for v0.25.10 and v0.25.11 https://github.com/onetimesecret/onetimesecret/pull/3493
  • Timestamp/TTL non-null enforcement follow-up https://github.com/onetimesecret/onetimesecret/pull/3494

Fixes

  • Fix suite-order-dependent flakes in billing isolation setup https://github.com/onetimesecret/onetimesecret/pull/3476
  • Fix contradictory enable prompt under entitlement error in Incoming Secrets panel https://github.com/onetimesecret/onetimesecret/pull/3492
  • Standardize pass-through i18n pattern for component tests https://github.com/onetimesecret/onetimesecret/pull/3495

Dependencies

  • Update dependency vite to v8.0.16 [SECURITY] by @renovate[bot] in https://github.com/onetimesecret/onetimesecret/pull/3481
  • Update dependency dompurify to v3.4.9 [SECURITY] by @renovate[bot] in https://github.com/onetimesecret/onetimesecret/pull/3484
  • Bump the bundler group across 1 directory with 4 updates by @dependabot[bot] in https://github.com/onetimesecret/onetimesecret/pull/3487
  • Bump the npm_and_yarn group across 2 directories with 2 updates by @dependabot[bot] in https://github.com/onetimesecret/onetimesecret/pull/3488

Full Changelog: https://github.com/onetimesecret/onetimesecret/compare/v0.25.10...v0.25.11

Breaking Changes

  • Secret and receipt TTL fields are now guaranteed to be non‑null integers (nullable contracts reverted).

Security Fixes

  • dep: vite updated to v8.0.16 – security fix
  • dep: dompurify updated to v3.4.9 – security fix

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track One Time Secret

Get notified when new releases ship.

Sign up free

About One Time Secret

Share sensitive information securely with self-destructing links that are only viewable once.

All releases →

Related context

Earlier breaking changes

  • v0.25.5-coda Removes `site.interface.ui.homepage.trusted_ip_header` config; replaces with `site.network.trusted_proxy.header` settings.
  • v0.25.5-coda Removes `site.interface.ui.homepage.trusted_proxy_depth` config; replaces with `site.network.trusted_proxy` settings.

Beta — feedback welcome: [email protected]