This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
ReleasePort's take
Moderate signalThe v0.10.2 release hardens search output sanitization to prevent XSS in search rendering and updates the quic-go dependency from 0.59.0 to 0.59.1.
Why it matters: Hardened search sanitization mitigates XSS risk (severityβ―90) for any user interacting with search results; updating quic-go addresses a lowβseverity dependency change (20).
Summary
AI summaryUpdates π Changelog for v0.10.2, π Security, and π§° Chores across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Hardens search output sanitization to prevent XSS in search rendering Hardens search output sanitization to prevent XSS in search rendering Source: llm_adapter@2026-06-04 Confidence: high |
β |
| Dependency | Low |
Updates dependency github.com/quic-go/quic-go from 0.59.0 to 0.59.1 Updates dependency github.com/quic-go/quic-go from 0.59.0 to 0.59.1 Source: llm_adapter@2026-06-04 Confidence: high |
β |
Full changelog
π Changelog for v0.10.2
v0.10.2
This patch release contains a backported security fix for search result rendering. I also includes a dependency update.
π Security
- Harden search output sanitization to address an XSS-related issue in search rendering (@perber) (reported by @shafiqaimanx and @tonghuaroot)
π§° Chores
- Bump
github.com/quic-go/quic-gofrom0.59.0to0.59.1@dependabot
Security Fixes
- Harden search output sanitization to address an XSS-related issue.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About LeafWiki
A fast wiki for people who think in folders, not feeds. Fast editing. Tree navigation. Markdown on disk.
Related context
Related tools
Beta — feedback welcome: [email protected]