This release includes 3 security fixes for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryBroad release touches IDOR, Raw Commits, Features No feature changes., and Performance No performance changes..
Full changelog
Proliferate v0.3.3
Production hotfix for July 2, 2026.
Reason: Desktop app v0.3.3 (Apple agreement re-accepted; completes environments release)
Release Metadata
| Field | Value |
| --- | --- |
| Version | proliferate-v0.3.3 |
| Hotfix | hotfix-2026-07-02-23 |
| Base | 0754ebe |
| Head | f3238fb |
| Compare | 0754ebe...f3238fb |
| Surfaces | desktop, runtime |
| Workflow | Actions run |
Highlights
- #874 fix(desktop): prevent path traversal in support attachment staging by @pablonyx (area:desktop)
- #875 fix(cloud/agent-run-config): require org membership for org-scoped listing (IDOR) by @pablonyx (area:server, area:cloud)
- #876 fix(cloud/github-app): verify installation ownership in install callback (IDOR) by @pablonyx (area:server, area:cloud)
Features
No feature changes.
Fixes
- #874 fix(desktop): prevent path traversal in support attachment staging by @pablonyx (area:desktop)
- #875 fix(cloud/agent-run-config): require org membership for org-scoped listing (IDOR) by @pablonyx (area:server, area:cloud)
- #876 fix(cloud/github-app): verify installation ownership in install callback (IDOR) by @pablonyx (area:server, area:cloud)
Performance
No performance changes.
Docs / Website
No docs changes.
Internal / Release
No internal release changes.
Other Changes
No other changes.
Artifacts
| Lane | Tag |
| --- | --- |
| Desktop | desktop-v0.3.3 |
| Runtime | runtime-v0.3.3 |
Raw Commits
View commits- c04adfe fix(agent-auth): fall back to native for un-configured harnesses instead of fail-closing (#889)
- 237d71b fix(desktop): prevent path traversal in support attachment staging (#874)
- 54e229a fix(cloud/agent-run-config): require org membership for org-scoped listing (IDOR) (#875)
- 3eb7b4a fix(cloud/github-app): verify installation ownership in install callback (IDOR) (#876)
- f3238fb release: prepare hotfix-2026-07-02-23
Security Fixes
- #874 fix(desktop): prevent path traversal in support attachment staging
- #875 fix(cloud/agent-run-config): require org membership for org-scoped listing (IDOR)
- #876 fix(cloud/github-app): verify installation ownership in install callback (IDOR)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Proliferate
Open-source local and cloud agent IDE for Claude Code, Codex, Gemini CLI, OpenCode, and similar coding agents; parallel workspaces, subagents, plugins, MCP, and review/merge flow around real CLI sessions.
Related context
Related tools
Beta — feedback welcome: [email protected]