This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryAdded Cc and Bcc support to dev sendmail, hardened MS OAuth2 email extraction options.
Full changelog
To update the prebuilt executable you can run
./pocketbase update.
-
Added
CcandBccrecipients to the devsendmailcommand for consistency with the SMTP mailer. -
Added extra hardening options to the Microsoft OAuth2 provider allowing developers to specify the preferred safe email extraction method (#7756).
-
Updated goja and the related
golang.org/x/*dependencies (WeakMapregression fixes). -
Bumped the min Go GitHub action version to 1.26.5 as it includes some minor security fixes.
Security Fixes
- dep: goja and golang.org/x/* dependencies updated; includes minor security fixes from Go 1.26.5 (GitHub Action version bump).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]