Skip to content

perminder-klair/subwave

v0.7.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Affected surfaces

auth

Summary

AI summary

Updates 0.7.0, Bug Fixes, and 2026-06-02 across a mixed release.

Changes in this release

Security High

Authenticates admin archive downloads to prevent unauthorized access.

Authenticates admin archive downloads to prevent unauthorized access.

Source: llm_adapter@2026-06-02

Confidence: high

Feature Low

Adds 'The Stack' landing section showcasing swappable LLMs, TTS & voice cloning.

Adds 'The Stack' landing section showcasing swappable LLMs, TTS & voice cloning.

Source: llm_adapter@2026-06-02

Confidence: high

Feature Low

Adds payload and recipe examples to the webhooks admin page.

Adds payload and recipe examples to the webhooks admin page.

Source: llm_adapter@2026-06-02

Confidence: high

Feature Low

Makes admin header Listen button open /listen in a new tab.

Makes admin header Listen button open /listen in a new tab.

Source: llm_adapter@2026-06-02

Confidence: high

Feature Low

Enhances landing feature strip with real capabilities.

Enhances landing feature strip with real capabilities.

Source: llm_adapter@2026-06-02

Confidence: high

Feature Low

Renders admin/debug DJ context as a human‑friendly summary.

Renders admin/debug DJ context as a human‑friendly summary.

Source: llm_adapter@2026-06-02

Confidence: high

Bugfix Medium

Fixes picker agent missing current track ID, preventing similarSongs/tracksLikeThis failures.

Fixes picker agent missing current track ID, preventing similarSongs/tracksLikeThis failures.

Source: llm_adapter@2026-06-02

Confidence: high

Bugfix Medium

Fixes DJ tools returning empty for titles and vibe queries.

Fixes DJ tools returning empty for titles and vibe queries.

Source: llm_adapter@2026-06-02

Confidence: high

Bugfix Medium

Retries controller model/binary downloads to survive transient 5xx errors from HF/GitHub.

Retries controller model/binary downloads to survive transient 5xx errors from HF/GitHub.

Source: llm_adapter@2026-06-02

Confidence: high

Bugfix Low

Keeps masthead navigation on one row on mobile devices.

Keeps masthead navigation on one row on mobile devices.

Source: llm_adapter@2026-06-02

Confidence: high

Full changelog

0.7.0 (2026-06-02)

Features

  • web: add 'The Stack' landing section on swappable LLMs, TTS & voice cloning (#260) (f4c94d1)
  • web: add payload & recipe examples to the webhooks admin page (#266) (106a23c)
  • web: make admin header Listen button open /listen in a new tab (#263) (0efd06b)
  • web: punch up landing feature strip with real capabilities (#258) (ead5450)
  • web: render admin/debug DJ context as a human-friendly summary (#265) (aaf462f)

Bug Fixes

  • controller: give picker agent the current track id so similarSongs/tracksLikeThis stop failing (#267) (d33cd6e)
  • controller: stop DJ tools returning empty for titles & vibe queries (#268) (2411337)
  • docker: retry controller model/binary downloads to survive transient HF/GitHub 5xx (#257) (db66817)
  • web: authenticate admin archive downloads (#264) (683ff1d)
  • web: keep masthead nav on one row on mobile (#261) (0f130e2)

Security Fixes

  • Authenticated admin archive downloads to prevent unauthorized access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track perminder-klair/subwave

Get notified when new releases ship.

Sign up free

About perminder-klair/subwave

All releases →

Beta — feedback welcome: [email protected]