This release adds 2 notable features for engineering teams evaluating rollout.
Published 20d
Offensive & Pentesting
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
blast-radius
go
incident-response
offensive-security
penetration-testing
security-tools
+1 more
security-triage
Affected surfaces
auth
deps
Summary
AI summaryFilestack API key validation now treats the key as a public client ID and drops severity.
Full changelog
Changelog
- ac03a7b0bf46a4e08ca8535ce2fc906dbb6cdc44: feat(netlify): recognize prefixed tokens + flag unscoped full-account privilege ( <>)
- 071f95c576a163e63d235f32d4fb5ceedd9e55e9: feat: recognize + validate Filestack credentials (api key + app secret) ( <>)
- 364d3656043d7e55f58bdc6c5a7a7d2fb76ca4d1: fix(filestack): drop severity — an api key is a public client id ( <>)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Geiger
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]