This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
Summary
AI summaryUpdates Dependencies 📦, Technical changes 🛠️, and User-facing changes 👀 None across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes regexp escaping vulnerability. Fixes regexp escaping vulnerability. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Feature | Low |
Adds Grid view to display products as a grid (experimental). Adds Grid view to display products as a grid (experimental). Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Feature | Low |
Adds security.md documentation file. Adds security.md documentation file. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Bumps json from 2.19.9 to 2.20.0. Bumps json from 2.19.9 to 2.20.0. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Bumps webpack from 5.108.3 to 5.108.4. Bumps webpack from 5.108.3 to 5.108.4. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Bumps webpack-cli from 7.1.0 to 7.2.1. Bumps webpack-cli from 7.1.0 to 7.2.1. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Bumps webpack-dev-server from 5.2.5 to 6.0.0. Bumps webpack-dev-server from 5.2.5 to 6.0.0. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Bumps webpack-sources from 3.5.0 to 3.5.1. Bumps webpack-sources from 3.5.0 to 3.5.1. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Dependency | Low |
Bumps tom-select from 2.6.1 to 2.6.2. Bumps tom-select from 2.6.1 to 2.6.2. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Bugfix | Medium |
Fixes flaky admin login in system specs using per-login Warden token. Fixes flaky admin login in system specs using per-login Warden token. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
Full changelog
What's Changed
User-facing changes 👀
None.
Experimental features for testing 🚧
- [Grid view] Display product as a grid by @rioug in https://github.com/openfoodfoundation/openfoodnetwork/pull/14345
Technical changes 🛠️
- [Security] Fix regexp escaping by @rioug in https://github.com/openfoodfoundation/openfoodnetwork/pull/14493
- Add security.md by @dacook in https://github.com/openfoodfoundation/openfoodnetwork/pull/14520
- Fix flaky admin login in system specs with a per-login Warden token by @maikels-agent in https://github.com/openfoodfoundation/openfoodnetwork/pull/14527
- Skip nodenv install when yarn is already available by @chahmedejaz in https://github.com/openfoodfoundation/openfoodnetwork/pull/14524
- Tighten customer account transaction permission by @rioug in https://github.com/openfoodfoundation/openfoodnetwork/pull/14526
- Include English locale digest in cache key to invalidate cached translations on locale file changes by @chahmedejaz in https://github.com/openfoodfoundation/openfoodnetwork/pull/14507
Dependencies 📦
- Bump json from 2.19.9 to 2.20.0 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14516
- Bump webpack from 5.108.3 to 5.108.4 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14521
- Bump webpack-cli from 7.1.0 to 7.2.1 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14522
- Bump the "turbo_power" group with 2 updates across multiple ecosystems by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14523
- Bump the "shakapacker" group with 2 updates across multiple ecosystems by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14506
- Bump webpack-dev-server from 5.2.5 to 6.0.0 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14515
- Bump webpack-sources from 3.5.0 to 3.5.1 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14529
- Bump tom-select from 2.6.1 to 2.6.2 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14532
Full Changelog: https://github.com/openfoodfoundation/openfoodnetwork/compare/v5.7.3...v5.7.4
Security Fixes
- Fix regexp escaping in Security module
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Open Food Network
Online marketplace for local food. It enables a network of independent online food stores that connect farmers and food hubs with individuals and local businesses.
Beta — feedback welcome: [email protected]