This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
Summary
AI summaryUpdates memo: What’s Changed, arrow_up: Dependencies updates, and rocket: Features across a mixed release.
Full changelog
This release fixes GHSA-59w3-h5v2-c4xw - thanks @de3erve-hunter for reporting!
:memo: What’s Changed
- Document notify_emails API gaps in /help/api (#4620) @pglombardo
- Polish notify-by-email validation error copy (#4619) @pglombardo
- API: Fix notify by email endpoint names and params (#4617) @ozovalihasan
- Filter payload and passphrase from logs and error tracking (#4614) @pglombardo
- Fix secret_url FORCE_SSL rewrite corrupting https URLs (#4616) @pglombardo
:rocket: Features
- Record audit log IPs using request.remote_ip (#4615) @pglombardo
:arrow_up: Dependencies updates
- :arrow_up: Bump docker/login-action from 4.3.0 to 4.4.0 (#4609) @dependabot[bot]
- :arrow_up: Bump rubocop-ast from 1.49.1 to 1.50.0 (#4610) @dependabot[bot]
- :arrow_up: Bump language_server-protocol from 3.17.0.5 to 3.17.0.6 (#4611) @dependabot[bot]
:busts_in_silhouette: List of contributors
@dependabot[bot], @ozovalihasan, @pglombardo and dependabot[bot]
:motor_boat: Docker Images
Available on Docker Hub:
https://hub.docker.com/r/pglombardo/pwpush
:running_man: Run This Version
- Point DNS to your server (e.g.
pwpush.example.com). - Download docker-compose.yml or clone the repo.
- In
docker-compose.yml, uncomment and set:TLS_DOMAIN: 'pwpush.example.com'for automatic Let’s Encrypt TLS.
- Run:
docker compose up -d
Open https://pwpush.example.com or alternatively http://your-ip:5100.
:link: Useful Links
Security Fixes
- GHSA-59w3-h5v2-c4xw – security vulnerability fixed (thanks @de3erve-hunter)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About PasswordPusher
Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
Related context
Beta — feedback welcome: [email protected]