This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+5 more
Affected surfaces
ReleasePort's take
Moderate signalThe release drops the Perl dependency to address CVE‑2026‑9538.
Why it matters: Mitigates high‑severity CVE‑2026‑9538 by removing the vulnerable Perl component; upgrade to version 2.0.64 immediately if using opik‑backend.
Summary
AI summaryDrop Perl dependency to mitigate CVE-2026-9538 security vulnerability.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Drops perl dependency to mitigate CVE-2026-9538 vulnerability. Drops perl dependency to mitigate CVE-2026-9538 vulnerability. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Feature | Medium |
Adds MCP OAuth dynamic client registration per RFC 7591. Adds MCP OAuth dynamic client registration per RFC 7591. Source: granite4.1:30b@2026-06-15-audit Confidence: low |
— |
| Performance | Medium |
Fixes sandbox‑executor per‑request latency regression by recompiling stdlib. Fixes sandbox‑executor per‑request latency regression by recompiling stdlib. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Performance | Medium |
Speeds up TraceThreadsClosingJob query using argMax deduplication. Speeds up TraceThreadsClosingJob query using argMax deduplication. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Bugfix | Medium |
Corrects health‑check URL path in the SDK. Corrects health‑check URL path in the SDK. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Bugfix | Medium |
Removes extra sidebar padding when the home group is empty. Removes extra sidebar padding when the home group is empty. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Refactor | Low |
Uses ModelPrice builder and parameterizes gemini tier tests. Uses ModelPrice builder and parameterizes gemini tier tests. Source: granite4.1:30b@2026-06-15-audit Confidence: low |
— |
Full changelog
What's Changed
- [issue-7083] [SDK] fix: correct health-check URL path by @CPUat in https://github.com/comet-ml/opik/pull/7084
- [OPIK-6666] [BE] feat: MCP OAuth dynamic client registration — RFC 7591 (PR 5/7) by @LifeXplorer in https://github.com/comet-ml/opik/pull/7093
- [BE] refactor: use ModelPrice builder + parameterize gemini tier tests by @Anuj7411 in https://github.com/comet-ml/opik/pull/7086
- [NA] [SDK] [DOCS] Update automatically OpenAPI spec and Fern code by @CometActions in https://github.com/comet-ml/opik/pull/7098
- [OPIK-6950] [FE] test: add initial Ollie E2E coverage by @AndreiCautisanu in https://github.com/comet-ml/opik/pull/7096
- [OPIK-6749][BE] Speed up TraceThreadsClosingJob query with argMax dedup by @yaricom in https://github.com/comet-ml/opik/pull/7103
- [OPIK-6952] [FE] Fix sidebar extra padding when home group is empty by @miguelgrc in https://github.com/comet-ml/opik/pull/7104
- [DND-827] [BE] perf: fix sandbox-executor per-request latency regression (recompiling stdlib) by @GuySaar8 in https://github.com/comet-ml/opik/pull/7110
- [OPIK-6944] [BE] fix(security): drop perl to clear CVE-2026-9538 in opik-backend by @JetoPistola in https://github.com/comet-ml/opik/pull/7107
New Contributors
- @CPUat made their first contribution in https://github.com/comet-ml/opik/pull/7084
Full Changelog: https://github.com/comet-ml/opik/compare/2.0.63...2.0.64
Security Fixes
- CVE-2026-9538 — drop perl dependency in opik-backend to clear vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About opik
Debug, evaluate, and monitor your LLM applications, RAG systems, and agentic workflows with comprehensive tracing, automated evaluations, and production-ready dashboards.
Related context
Related tools
Beta — feedback welcome: [email protected]