Skip to content

PasswordPusher

v2.9.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 20d Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

communicate-passwords docker encryption file-sharing information-technology msp
+12 more
netsec netsec-tools password password-expiration password-pusher password-safety ruby secret security security-tools self-hosted upload-file

Affected surfaces

auth deps

Summary

AI summary

Updates memo: What’s Changed, arrow_up: Dependencies updates, and rocket: Features across a mixed release.

Full changelog

This release fixes GHSA-59w3-h5v2-c4xw - thanks @de3erve-hunter for reporting!

:memo: What’s Changed

  • Document notify_emails API gaps in /help/api (#4620) @pglombardo
  • Polish notify-by-email validation error copy (#4619) @pglombardo
  • API: Fix notify by email endpoint names and params (#4617) @ozovalihasan
  • Filter payload and passphrase from logs and error tracking (#4614) @pglombardo
  • Fix secret_url FORCE_SSL rewrite corrupting https URLs (#4616) @pglombardo

:rocket: Features

  • Record audit log IPs using request.remote_ip (#4615) @pglombardo

:arrow_up: Dependencies updates

  • :arrow_up: Bump docker/login-action from 4.3.0 to 4.4.0 (#4609) @dependabot[bot]
  • :arrow_up: Bump rubocop-ast from 1.49.1 to 1.50.0 (#4610) @dependabot[bot]
  • :arrow_up: Bump language_server-protocol from 3.17.0.5 to 3.17.0.6 (#4611) @dependabot[bot]

:busts_in_silhouette: List of contributors

@dependabot[bot], @ozovalihasan, @pglombardo and dependabot[bot]

:motor_boat: Docker Images

Available on Docker Hub:
https://hub.docker.com/r/pglombardo/pwpush

:running_man: Run This Version

  1. Point DNS to your server (e.g. pwpush.example.com).
  2. Download docker-compose.yml or clone the repo.
  3. In docker-compose.yml, uncomment and set:
    • TLS_DOMAIN: 'pwpush.example.com' for automatic Let’s Encrypt TLS.
  4. Run:
docker compose up -d

Open https://pwpush.example.com or alternatively http://your-ip:5100.

:link: Useful Links

Security Fixes

  • GHSA-59w3-h5v2-c4xw – security vulnerability fixed (thanks @de3erve-hunter)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track PasswordPusher

Get notified when new releases ship.

Sign up free

About PasswordPusher

Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

All releases →

Beta — feedback welcome: [email protected]