This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThis release mitigates a possible remote code execution vulnerability in GitHub Actions workflow execution and corrects biased random number generation from the CSPRNG.
Why it matters: Severity 95 mitigation of potential RCE via GitHub Actions; severity 45 fix for biased CSPRNG output—critical for security‑sensitive workloads.
Summary
AI summaryUpdates chore, deps, and fix across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Mitigates possible RCE through Github Actions Mitigates possible RCE through Github Actions Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Dependency | Low |
Updates vue to version 3.5.38 Updates vue to version 3.5.38 Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Dependency | Low |
Updates vue-i18n to version 11.4.5 Updates vue-i18n to version 11.4.5 Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Dependency | Low |
Updates vue-router to version 5.1.0 Updates vue-router to version 5.1.0 Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Dependency | Low |
Updates rconfig/v2 to version 2.6.2 Updates rconfig/v2 to version 2.6.2 Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Dependency | Low |
Updates go-redis/v9 to version 9.20.1 Updates go-redis/v9 to version 9.20.1 Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Dependency | Low |
Updates go_helpers module to latest revision Updates go_helpers module to latest revision Source: llm_adapter@2026-06-14 Confidence: low |
— |
| Dependency | Low |
Updates github.com/luzifer/go_helpers/... module Updates github.com/luzifer/go_helpers/... module Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes broken path handling for duplicate files Fixes broken path handling for duplicate files Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Corrects biased random number generation from CSPRNG Corrects biased random number generation from CSPRNG Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Bugfix | Medium |
Forces overrides for vulnerabilities in node packages Forces overrides for vulnerabilities in node packages Source: llm_adapter@2026-06-14 Confidence: high |
— |
Full changelog
-
Improvements
- chore: specify full container image paths (by @kovmir)
-
Bugfixes
- fix: broken path handling in case of file duplicates
- fix: creating biased random numbers from a cryptographically secure source
- fix: force overrides for vulnerabilities in node packages
- fix: mitigate possible RCE through Github Actions
- chore: remove remains of pkg/errors
- fix(deps): update dependency vue to v3.5.38
- fix(deps): update dependency vue-i18n to v11.4.5
- fix(deps): update dependency vue-router to v5.1.0
- fix(deps): update module github.com/luzifer/go_helpers/...
- fix(deps): update module github.com/luzifer/rconfig/v2 to v2.6.2
- fix(deps): update module github.com/redis/go-redis/v9 to v9.20.1
-
Translations
- chore: improve German translations
- chore: improve Simplified Chinese translation (by @YongJie-Xie)
- chore: update and enhance Turkish localization (by @wd006)
- chore: update Latvian translation (by @Stegadons)
- chore: update Ukranian translations (by @t0rik)
Security Fixes
- Mitigate possible RCE through GitHub Actions
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ots
One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser
Related context
Beta — feedback welcome: [email protected]