Skip to content

PasswordPusher

v2.7.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

communicate-passwords docker encryption file-sharing information-technology msp
+12 more
netsec netsec-tools password password-expiration password-pusher password-safety ruby secret security security-tools self-hosted upload-file

Affected surfaces

deps

Summary

AI summary

Trash unnecessary workflows and harden other security components.

Full changelog

:memo: What’s Changed

  • Security: Trash unnecessary workflows; Harden Others (#4556) @pglombardo

:arrow_up: Dependencies updates

  • :arrow_up: Bump release-drafter/release-drafter from 7.4.0 to 7.5.1 (#4586) @dependabot[bot]
  • :arrow_up: Bump crass from 1.0.6 to 1.0.7 (#4587) @dependabot[bot]
  • :arrow_up: Bump actions/setup-python from 6.2.0 to 6.3.0 (#4580) @dependabot[bot]
  • :arrow_up: Bump azure/setup-helm from 5.0.0 to 5.0.1 (#4579) @dependabot[bot]
  • :arrow_up: Bump json from 2.19.9 to 2.20.0 (#4582) @dependabot[bot]
  • :arrow_up: Bump aws-partitions from 1.1261.0 to 1.1262.0 (#4578) @dependabot[bot]
  • :arrow_up: Bump mailbin from 1.1.2 to 1.2.0 (#4581) @dependabot[bot]
  • :arrow_up: Bump globalid from 1.3.0 to 1.4.0 (#4583) @dependabot[bot]
  • :arrow_up: Bump cgi from 0.5.1 to 0.5.2 (#4584) @dependabot[bot]
  • :arrow_up: Bump google-apis-iamcredentials_v1 from 0.27.0 to 0.28.0 (#4573) @dependabot[bot]
  • :arrow_up: Bump google-apis-storage_v1 from 0.63.0 to 0.64.0 (#4574) @dependabot[bot]
  • :arrow_up: Bump rubocop-rails from 2.35.4 to 2.35.5 (#4575) @dependabot[bot]
  • :arrow_up: Bump i18n from 1.15.1 to 1.15.2 (#4576) @dependabot[bot]
  • :arrow_up: Bump pp from 0.6.3 to 0.6.4 (#4577) @dependabot[bot]
  • :arrow_up: Bump kamal from 2.11.0 to 2.12.0 (#4571) @dependabot[bot]
  • :arrow_up: Bump nokogiri from 1.19.3 to 1.19.4 (#4572) @dependabot[bot]
  • :arrow_up: Bump i18n from 1.14.8 to 1.15.1 (#4568) @dependabot[bot]
  • :arrow_up: Bump selenium-webdriver from 4.44.0 to 4.45.0 (#4564) @dependabot[bot]
  • :arrow_up: Bump faraday from 2.14.2 to 2.14.3 (#4563) @dependabot[bot]
  • :arrow_up: Bump aws-sdk-s3 from 1.225.1 to 1.226.0 (#4562) @dependabot[bot]
  • :arrow_up: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 (#4561) @dependabot[bot]
  • :arrow_up: Bump googleauth from 1.17.0 to 1.17.1 (#4565) @dependabot[bot]
  • :arrow_up: Bump aws-partitions from 1.1260.0 to 1.1261.0 (#4566) @dependabot[bot]
  • :arrow_up: Bump concurrent-ruby from 1.3.6 to 1.3.7 (#4567) @dependabot[bot]
  • :arrow_up: Bump rubyzip from 3.3.1 to 3.4.0 (#4559) @dependabot[bot]
  • :arrow_up: Bump retriable from 4.1.1 to 4.2.0 (#4560) @dependabot[bot]
  • :arrow_up: Bump brakeman from 8.0.4 to 8.0.5 (#4557) @dependabot[bot]
  • :arrow_up: Bump aws-partitions from 1.1259.0 to 1.1260.0 (#4558) @dependabot[bot]

:busts_in_silhouette: List of contributors

@dependabot[bot], @pglombardo and dependabot[bot]

:motor_boat: Docker Images

Available on Docker Hub:
https://hub.docker.com/r/pglombardo/pwpush

:running_man: Run This Version

  1. Point DNS to your server (e.g. pwpush.example.com).
  2. Download docker-compose.yml or clone the repo.
  3. In docker-compose.yml, uncomment and set:
    • TLS_DOMAIN: 'pwpush.example.com' for automatic Let’s Encrypt TLS.
  4. Run:
docker compose up -d

Open https://pwpush.example.com or alternatively http://your-ip:5100.

:link: Useful Links

Security Fixes

  • Trash unnecessary workflows and harden other components (no CVE ID provided).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track PasswordPusher

Get notified when new releases ship.

Sign up free

About PasswordPusher

Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

All releases →

Beta — feedback welcome: [email protected]