Skip to content

Open Food Network

v5.7.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 7d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

farmers food food-hubs nonprofit rails ruby
+1 more
sustainable-consumption

Affected surfaces

auth rbac

Summary

AI summary

Updates Dependencies 📦, Technical changes 🛠️, and User-facing changes 👀 None across a mixed release.

Changes in this release

Security Critical

Fixes regexp escaping vulnerability.

Fixes regexp escaping vulnerability.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Adds Grid view to display products as a grid (experimental).

Adds Grid view to display products as a grid (experimental).

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Adds security.md documentation file.

Adds security.md documentation file.

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Bumps json from 2.19.9 to 2.20.0.

Bumps json from 2.19.9 to 2.20.0.

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Bumps webpack from 5.108.3 to 5.108.4.

Bumps webpack from 5.108.3 to 5.108.4.

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Bumps webpack-cli from 7.1.0 to 7.2.1.

Bumps webpack-cli from 7.1.0 to 7.2.1.

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Bumps webpack-dev-server from 5.2.5 to 6.0.0.

Bumps webpack-dev-server from 5.2.5 to 6.0.0.

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Bumps webpack-sources from 3.5.0 to 3.5.1.

Bumps webpack-sources from 3.5.0 to 3.5.1.

Source: llm_adapter@2026-07-20

Confidence: medium

Dependency Low

Bumps tom-select from 2.6.1 to 2.6.2.

Bumps tom-select from 2.6.1 to 2.6.2.

Source: llm_adapter@2026-07-20

Confidence: medium

Bugfix Medium

Fixes flaky admin login in system specs using per-login Warden token.

Fixes flaky admin login in system specs using per-login Warden token.

Source: llm_adapter@2026-07-20

Confidence: medium

Full changelog

What's Changed

User-facing changes 👀

None.

Experimental features for testing 🚧

  • [Grid view] Display product as a grid by @rioug in https://github.com/openfoodfoundation/openfoodnetwork/pull/14345

Technical changes 🛠️

  • [Security] Fix regexp escaping by @rioug in https://github.com/openfoodfoundation/openfoodnetwork/pull/14493
  • Add security.md by @dacook in https://github.com/openfoodfoundation/openfoodnetwork/pull/14520
  • Fix flaky admin login in system specs with a per-login Warden token by @maikels-agent in https://github.com/openfoodfoundation/openfoodnetwork/pull/14527
  • Skip nodenv install when yarn is already available by @chahmedejaz in https://github.com/openfoodfoundation/openfoodnetwork/pull/14524
  • Tighten customer account transaction permission by @rioug in https://github.com/openfoodfoundation/openfoodnetwork/pull/14526
  • Include English locale digest in cache key to invalidate cached translations on locale file changes by @chahmedejaz in https://github.com/openfoodfoundation/openfoodnetwork/pull/14507

Dependencies 📦

  • Bump json from 2.19.9 to 2.20.0 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14516
  • Bump webpack from 5.108.3 to 5.108.4 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14521
  • Bump webpack-cli from 7.1.0 to 7.2.1 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14522
  • Bump the "turbo_power" group with 2 updates across multiple ecosystems by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14523
  • Bump the "shakapacker" group with 2 updates across multiple ecosystems by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14506
  • Bump webpack-dev-server from 5.2.5 to 6.0.0 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14515
  • Bump webpack-sources from 3.5.0 to 3.5.1 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14529
  • Bump tom-select from 2.6.1 to 2.6.2 by @dependabot[bot] in https://github.com/openfoodfoundation/openfoodnetwork/pull/14532

Full Changelog: https://github.com/openfoodfoundation/openfoodnetwork/compare/v5.7.3...v5.7.4

Security Fixes

  • Fix regexp escaping in Security module

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Open Food Network

Get notified when new releases ship.

Sign up free

About Open Food Network

Online marketplace for local food. It enables a network of independent online food stores that connect farmers and food hubs with individuals and local businesses.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]